Skip to main content
The Economy Wiki

Risk compliance

Risk, compliance and governance form the institutional system through which an organization directs conduct, allocates accountability, manages uncertainty and demonstrates that it operates within law and accepted standards.

Entry type: Umbrella concept

Field: Governance and Risk Advisory

Last reviewed: 24 August 2026

Definition

Risk, compliance and governance encompass the structures, policies, controls, information and assurance processes by which organizations are directed, risks are managed, obligations are met and decision-makers are held accountable.

Overview

Governance determines who has authority, how decisions are supervised and what information reaches boards and stakeholders. Risk management addresses uncertainty in relation to objectives. Compliance organizes adherence to laws, regulations, contractual duties and internal standards. The three disciplines are distinct but mutually dependent.

A technically complete control framework can still fail if incentives, culture or escalation mechanisms are weak. Conversely, excessive control can impede legitimate decision-making without materially reducing risk. Effective systems are proportionate to the organization’s activities, regulatory exposure, risk appetite and capacity to monitor outcomes.

System components

Governance

  • Board and committee structures
  • Delegations and decision rights
  • Policies, incentives and culture
  • Reporting and accountability

Risk and compliance

  • Enterprise and operational risk
  • Regulatory compliance
  • Financial crime and conduct
  • Privacy, cyber and third-party risk

Assurance and response

  • Internal controls and testing
  • Internal audit and assurance
  • Investigations
  • Remediation and monitoring

Risk and compliance cycle

  1. Context and obligations: identify objectives, stakeholders, laws, standards and risk appetite.
  2. Assessment: evaluate events, exposures, likelihood, impact and existing controls.
  3. Response design: avoid, reduce, transfer, accept or monitor risk and assign responsibility.
  4. Control operation: embed policies, procedures, systems, training and escalation routes.
  5. Assurance and learning: test effectiveness, investigate failures, report findings and remediate weaknesses.

Roles and boundaries

ActorCore responsibilityIndependence consideration
Board and senior managementDirection, oversight, risk appetite and accountabilityCannot outsource ultimate responsibility
Business managementOwns risks and operates controlsFirst-line ownership remains with the business
Risk and compliance functionsFrameworks, challenge, monitoring and adviceRequire authority and access independent of commercial pressure
Internal auditIndependent assurance on governance, risk and controlsShould not audit decisions it owns

External advisers can design frameworks, perform reviews, investigate misconduct and support remediation, but they do not replace the organization’s accountability. The scope and reporting line of an investigation or independent review should be established carefully, particularly where privilege, regulatory notification or conflicts may arise.

Sources and further reading

View sources and editorial notes
  • ISO 31000, Risk management — Guidelines.
  • COSO, Enterprise Risk Management and Internal Control frameworks.
  • Institute of Internal Auditors, Three Lines Model and Global Internal Audit Standards.
  • OECD, G20/OECD Principles of Corporate Governance.

Editorial note: Legal and regulatory requirements vary by sector and jurisdiction. This entry describes the institutional architecture rather than jurisdiction-specific obligations.