A risk assessment identifies where the organisation could violate the law, rates those risks, and drives where controls and resources go. Without one, a compliance programme cannot be shown to be designed for the business it serves.
Inventory the risks. By business line, geography, function and third-party channel. Sources include the regulatory inventory, past issues, internal audit findings, complaint data, industry enforcement actions and peer experience.
Rate them. Inherent risk on likelihood and impact; then the control environment; then residual risk. The methodology should be documented and consistent so that ratings can be compared over time.
Interviews matter more than surveys. Business leaders know where the pressure points are, and they will describe them in conversation more candidly than in a questionnaire.
Output. A prioritised register with named owners, mitigation plans and dates, and an explicit statement of accepted risk where the organisation chooses not to mitigate.
Frequency. At least annually, and on significant change — a new product, market, acquisition or regulation.
Board reporting. The assessment and the resulting plan, with a clear account of the highest residual risks. Boards that receive only assurance are not exercising oversight, and that is a governance finding rather than a compliance one.