Skip to content
  • Home
  • Recent
  • Tags
  • Popular
  • Groups
Skins
  • Light
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Brand Logo

Compliance in risk taxonomy

Scheduled Pinned Locked Moved Regulatory Compliance
compliance riskrisk taxonomyrisk identification
3 Posts 1 Posters 2 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • U Offline
    U Offline
    User 340
    wrote last edited by
    #1

    Dear RiskBowl,

    Thoughts on where Compliance typically sits in the risk taxonomy? We’ve gathered examples of Compliance as a Level 1 risk category, but have you seen examples of when Compliance is at Level 2 under Operational Risk at Level 1?

    Thanks

    U 2 Replies Last reply
    0
    • U Offline
      U Offline
      User 340
      replied to User 340 last edited by
      #2

      It’s a tricky question as compliance doesn’t fit too neatly into the typical risk taxonomy, and there are more complex taxonomy structures that can better facilitate compliance as a type of impact from a risk event. This is what we would typically see as best practice.

      To answer your question directly, I’ve probably seen compliance as an L2 under an overall ops risk once or twice, but its not what I would suggest as best practice and is something we would recommend avoiding. Peer L1s is much more common

      1 Reply Last reply
      0
      • U Offline
        U Offline
        User 340
        replied to User 340 last edited by
        #3

        The ORX global reference taxonomy was developed based on 60+ risk taxonomies used by financial institutions around the globe is probably the best representation of peer practices and has been adopted, with tailoring for the specific organization, by many since the taxonomy was developed ~5 years ago.

        Within the ORX global reference taxonomy, regulatory compliance is a separate L2 category within the NFR taxonomy, and is defined as “the failure to comply with any legal or regulatory obligations that are not captured through other Level 1 risks within the NFR taxonomy”, because the risk of non-compliance with specific legal or regulatory obligations is relevant to most Level 1 risks in the NFR taxonomy and therefore we wanted to avoid overlap with these risks

        1 Reply Last reply
        0

        Terms of Use Privacy Notice Cookie Notice Manage Cookies
        • Login

        • First post
          Last post
        0
        • Home
        • Recent
        • Tags
        • Popular
        • Groups