Compliance Risk Matrix Calculator

Turn obligations into measurable compliance risk scores. Build a matrix, identify priorities, and document rationale. Use the controls slider to estimate residual exposure today.

Calculator

Use a short label for audit-ready records.
Choose the main regulation family impacted.
Extended mode reflects context beyond the grid.
Probability of non-compliance within the period.
Financial, legal, and operational consequence level.
Weak Value: 60% Strong
Low Value: 50% High
More occurrences raise exposure.
Expected regulatory and contractual penalties.
Customer trust, market reaction, and media visibility.
How quickly the issue can escalate.
Residual ≤ this value is Low.
Residual ≤ this value is Medium.
Residual above this becomes Critical.
Result appears above this form.

Example data table

Scenario Area L I Controls Mode Residual Level
Vendor due diligence gapsProcurement4445%EXTENDED7.269Medium
Late privacy noticesData Privacy3370%STANDARD2.700Low
Sanctions screening driftSanctions2555%EXTENDED2.997Low
Safety training overdueHealth & Safety4350%STANDARD6.000Medium
Unreconciled journal entriesFinancial Reporting3560%EXTENDED4.095Low
These examples are illustrative. Adjust thresholds to match your governance policy.

Formula used

Inherent score is calculated as:

Inherent = Likelihood × Impact

Residual score depends on the chosen mode:

Modifier adds context while staying close to 1.0:

Modifier = 1 + 0.05(Penalty−3) + 0.05(Reputation−3) + 0.04(Velocity−3) + 0.04(Frequency−3)

Risk level is assigned using your thresholds: Low ≤ t_low, Medium ≤ t_med, High ≤ t_high, else Critical.

How to use this calculator

  1. Enter a scenario name and select the compliance area.
  2. Pick likelihood and impact using the 1–5 descriptions.
  3. Move the control slider to reflect current effectiveness.
  4. Use extended mode to include detection and context drivers.
  5. Set thresholds to match your risk appetite statement.
  6. Click calculate, then download CSV or PDF for records.

FAQs

1) What is a compliance risk matrix?

It is a grid that combines likelihood and impact to rank compliance issues. It helps teams prioritize monitoring, remediation, and escalation using consistent scoring rules.

2) What is the difference between inherent and residual risk?

Inherent risk assumes no controls exist. Residual risk estimates what remains after controls and detection activities reduce exposure. Residual scores are usually used for action planning.

3) How should I choose likelihood and impact?

Use evidence such as prior incidents, audit findings, control testing, transaction volume, and regulatory history. Define scoring criteria in policy so different assessors rate scenarios consistently.

4) What does control effectiveness mean here?

It is an estimate of how well preventive and detective controls reduce the chance or consequence of non-compliance. Use control testing results, exception rates, and design reviews to set a realistic percentage.

5) Why does extended mode include a modifier?

Some scenarios are riskier due to penalty severity, reputational impact, speed of escalation, or how often the activity happens. The modifier nudges the score without overpowering the base matrix.

6) Can I align thresholds with my organization’s risk appetite?

Yes. Adjust the Low, Medium, and High maximum thresholds to match your governance rules. Keep them increasing so the categories remain consistent and easy to interpret.

7) How should I use the PDF and CSV exports?

Use CSV for tracking and dashboards, and PDF for audit or committee packets. Exported results capture inputs, scores, and thresholds so you can reproduce decisions later.

8) What if my organization uses a 1–10 scale?

You can approximate by mapping 1–10 into 1–5 bands, or adjust thresholds to reflect the larger range. Keep definitions stable so comparisons remain meaningful across periods.

Related Calculators

likelihood impact matrixrisk matrix calculatorquality risk matrixenterprise risk matrixvendor risk matrixoperational risk matrixit risk matrixstrategic risk matrixenvironmental risk matrix

Important Note: All the Calculators listed in this site are for educational purpose only and we do not guarentee the accuracy of results. Please do consult with other sources as well.