Compliance Risk Calculator – How to Calculate & Measure Compliance Risk

How to Calculate and Measure Compliance Risk: A Nordic Method

Most compliance risk assessments are a heat map produced once, filed, and never looked at again. The colours were assigned in a workshop by the people who happened to be in the room, the scoring logic lives in nobody’s head, and when a supervisor asks why a particular group was left out of training, the answer is a shrug.

This guide sets out a method that produces a number you can trace, a register you can defend, and a list of the things you decided not to do. It is the method behind the Datafisher compliance risk calculator, and it works on paper just as well.

What compliance risk actually is

Compliance risk is the risk that the organisation fails to meet a legal or contractual obligation that applies to it, and that the failure is not caught by a control before it causes harm.

Each clause in that sentence does work. An obligation that does not apply to you is not a risk, however loudly a vendor says otherwise. A failure that is caught by a working control before harm is a near miss, and a system that produces near misses is doing its job. What you are measuring is the gap between what you must do and what you can show you actually do.

That framing also tells you what the output should be. Not a colour. A statement, per obligation and per entity, of how likely a failure is, how bad it would be, how much of that is already controlled, and whether the duty applies at all.

The formula

Inherent risk = Likelihood × Impact
Residual risk = Inherent risk × (1 − Control effectiveness)
Priority score = Residual risk × Applicability weight
Likelihood and impact are scored 1 to 5. Control effectiveness runs from 0 to 0.8. Applicability is 1.0, 0.7 or 0. The result is a score from 0 to 25.

This is a residual-risk model, and the choice matters. Inherent risk on its own tells you where an obligation would bite if you had done nothing. Residual risk tells you where it still bites given what you have done. A programme that has trained procurement thoroughly on competition law and never mentioned it to sales has a very different residual profile from one that has done the reverse, even though the inherent risk is the same.

The test of a good scoring model is not sophistication. It is that every number on the page can be traced back to an answer someone gave, and that two people scoring the same entity from the same facts arrive at roughly the same result.

The unit of analysis is entity, not group

A Nordic group is not one organisation for compliance purposes. It is several, in different countries, under different thresholds and different supervisors. Whistleblowing routines are required from five employees in Norway and from fifty in Finland, Sweden and Denmark. The NIS2 management-body training duty is expressly statutory in Sweden and sits differently in Finland. Finnish entities carry the working-life privacy act on top of the GDPR. Swedish entities carry an express duty under AFS 2023:2 that managers know how to prevent and handle kränkande särbehandling.

So the assessment runs per obligation area per entity. A thirty-person Norwegian subsidiary and a thirty-person Finnish subsidiary of the same group get different whistleblowing scores because one has a statutory duty and the other does not.

When you roll up to group level, use the maximum across entities, not the average. Averaging hides the entity that will actually be inspected. The weakest entity defines the group’s exposure, because that is where the regulator will be standing.

Likelihood: score by activity, not job title

Likelihood is where most assessments go wrong, because they ask who holds which title. Nordic organisations are flat, job scopes are broad, and a single person in a forty-person subsidiary may set prices, submit tenders and approve payments in the same week. A title tells you much less about exposure here than it does in a hierarchical structure.

Ask instead how many people perform each exposed activity, in bands. The activities that drive most compliance risk are a short list.

Competition. Setting prices, attending trade association forums, employing competitors’ former staff, preparing public tenders.

Anti-bribery. Public-sector sales, use of agents or intermediaries, approving payments, hospitality.

Data protection. Recruitment, handling health information, monitoring employees, answering customer data requests.

Security. Approving payments or changing supplier bank details, opening attachments from unknown senders as part of the job, holding administrative access.

AI literacy. Using AI tools at work including features inside existing software, selecting or configuring systems with AI components. If the honest answer is “we don’t know who uses what”, score it as everyone.

Sustainability. Making environmental claims in marketing, sales or bids; generating figures that end up in sustainability or financial reports.

Start each area at a base likelihood of 2. Add half a point for each activity band above none, capped at two points. Add a point for country-specific amplifiers, for trade association membership in the competition area, for public tendering, and for AI in use without an inventory. Add a point for any incident, complaint or regulator contact in the last twenty-four months. Cap at 5.

The result is a likelihood score that rises with what people actually do, and that changes when the organisation changes, which a title-based score never does.

Impact: fixed by obligation, adjusted by exposure

Impact is more stable than likelihood because it is mostly a property of the law rather than of your organisation. Competition and anti-bribery infringements sit at the top of the scale: fines of up to ten percent of turnover, criminal exposure for individuals in some regimes, follow-on damages, trading prohibitions in Sweden. Data protection and NIS2 sit just below, with administrative fines and, under NIS2, the possibility of a temporary ban on holding management functions. Whistleblowing and workplace conduct sit in the middle. AI literacy sits lower, since the Article 4 duty carries no standalone penalty tier, but rises sharply if the organisation deploys AI anywhere near recruitment, credit, performance or access decisions, because that is Annex III territory and the December 2027 date is closer than it looks.

Obligation area Base impact Raise by one where
Competition law 5 Already at maximum
Anti-bribery and corruption 5 Already at maximum
GDPR and employee data 4 Special-category data at scale; Finnish entity (working-life privacy layer)
Security awareness / NIS2 4 In-scope essential entity; six or more people approve payments
Whistleblowing 3 250 or more employees; incident in last 24 months
Workplace conduct 3 Swedish entity with untrained managers
Sustainability and green claims 3 Consumer-facing claims; supplier to an in-scope group
AI literacy 2 AI used in recruitment, credit, performance or access decisions

Resist the temptation to model impact in euros. Fine modelling produces false precision, invites argument about the number rather than the exposure, and distracts from the point that reputational and contractual consequences usually arrive before any fine does. Bands are enough.

Controls: three questions, and why “don’t know” scores as no

Control effectiveness is where the assessment connects to the training programme, and it needs to be assessed the same way for every obligation area so that the results are comparable. Three questions do it.

Does it exist? Is there a policy, a channel, a procedure? Yes scores 0.3, partial 0.15, no scores 0.

Are people trained? Has the relevant population received training in the last twelve months? All scores 0.3, some 0.15, none or don’t know 0.

Is it owned and evidenced? Is there a named owner, and could you produce a record for a specific person on request? Yes scores 0.2, no scores 0.

The maximum is 0.8, deliberately. A control never removes risk entirely, and a model that lets an organisation score itself to zero produces exactly the complacency the assessment exists to prevent.

“Don’t know” scores as no throughout. A control you cannot evidence is not a control a supervisor will recognise. If you do not know whether your Swedish managers have been trained on kränkande särbehandling, then for the purposes of the assessment they have not, and finding out is your first task.

Note what the third question does. It separates organisations that ran a course from organisations that can prove who took it. The difference is invisible in a completion dashboard and decisive in an inspection.

Applicability: mandatory, contractual or not applicable

The final multiplier is whether the obligation applies to this entity at all, and it has three values rather than two.

Mandatory, weight 1.0. A statutory duty applies to this entity: it is above the whistleblowing threshold, it is in a NIS2 sector at the relevant size, it deploys an AI system, it is above the revised CSRD thresholds.

Contractual, weight 0.7. No statutory duty, but the obligation arrives anyway: through supply-chain clauses from in-scope customers, security questionnaires, lender criteria, public procurement award criteria. Most Nordic mid-caps sit here for NIS2 and sustainability. The weight is below 1.0 because the consequence of failure is commercial rather than regulatory, and above 0.5 because losing a tender is still a loss.

Not applicable, weight 0. Below the threshold, outside the sector, no such activity. The score is zero, but the line stays in the register with the reason, which is the subject of the section below.

Reading the score

Band Score What it means
Critical 15–25 Statutory duty, high exposure, little or no evidenced control. Act this quarter.
High 9–14.9 Material gap. Plan within the year.
Moderate 4–8.9 Covered in part. Maintain and document.
Low 0.1–3.9 Proportionate to leave thin. Record the decision.
Not applicable 0 Record why.

Two sanity rules should hold whatever the inputs. No entity with a mandatory duty and every control at “no” should land below High. No entity with every control at “yes” should land above Moderate unless there has been an incident. If either rule breaks, the weights need adjusting, not the formula.

Attach a confidence rating to the whole assessment: the number of “don’t know” answers. An entity scored Critical on low confidence is telling you something different from one scored Critical on high confidence. The first needs facts before it needs training.

A worked example

Swedish manufacturing subsidiary, 300 employees, competition law

Likelihood. Base 2. Six to twenty people set prices and attend industry forums, plus one to five prepare public tenders: two activity bands, +1. Management sits on the trade association board: +1. Regular public tendering: +1. Cap applies. Likelihood 5.

Impact. Competition law, base 5.

Inherent risk 5 × 5 = 25.

Controls. A competition policy exists, 0.3. Sales were trained three years ago, nothing since: none in twelve months, 0. There is no named owner and no per-person records: 0. Control effectiveness 0.3.

Residual risk 25 × (1 − 0.3) = 17.5.

Applicability. Statutory, weight 1.0.

Priority score 17.5. Critical. The report sentence writes itself: competition law is Critical for the Swedish entity because six to twenty people set prices and attend trade association forums, the company tenders publicly, and nobody has been trained in the last twelve months. The first action is a scenario-based module for sales and management and a named owner, not a group-wide awareness course.

Run the same entity through whistleblowing and the answer is different: 300 employees, statutory duty, channel exists, staff trained last year, owner named and records exportable. Likelihood 3, impact 4, control 0.8, applicability 1.0. Score 2.4. Low. Maintain and document. The programme’s effort goes where the number says, not where the last vendor conversation pointed.

The register of what you decided not to do

This is the output that matters most and the one almost no assessment produces.

Risk-based programmes are defensible, but only where the negative decisions are documented. The exposure is never the training you delivered; it is the group you decided to leave out and cannot explain. A supervisor who finds that your Danish sales office received no whistleblowing training will accept “six employees, below the threshold, decision recorded on this date” and will not accept silence.

So every line that scores zero for applicability, and every line you consciously leave at Low, goes into a register with three fields: the obligation, the entity, and the reason with a date. Where the reason is a threshold, name it. Where the reason is proportionality, say what the residual risk was and who accepted it.

Keep the register with the assessment, version both, and review both on the same cycle. A negative decision made in 2025 about NIS2 scope may not survive 2026, and a decision about CSRD made under the original thresholds needs re-taking under the Omnibus ones.

Measuring whether risk is actually falling

A score is a snapshot. Whether risk is falling is a trend, and it needs a small set of indicators that move when behaviour moves.

Residual score by area and entity, quarter on quarter. The direct measure. Falling scores should be explainable by controls that were added, not by answers that became more optimistic.

Control coverage. The proportion of exposed people, by activity, trained within twelve months and evidenced by name. This is the number that connects the assessment to the LMS export.

Confidence. The count of “don’t know” answers. It should fall to zero within the first year and stay there.

Behavioural proxies. Reports through the whistleblowing channel, pre-approval requests to legal, questions to the compliance inbox, suspicious messages reported and time to report them. Rising numbers are usually good news and should be framed for the board as such before the numbers arrive.

Time to evidence. How long it takes one person to produce the audit pack for one entity for one year. Measure it once a quarter by actually doing it. If the answer is more than an afternoon, the evidence control is not at 0.2 whatever the questionnaire says.

Review the whole assessment annually as a minimum, and additionally when the risk picture changes, an incident occurs, or a material regulatory change lands. 2026 has delivered three of those in AI, cyber and sustainability. An assessment dated before any of them is describing a different organisation.

Frequently asked questions

How is compliance risk calculated?

Likelihood times impact gives inherent risk. Multiply by one minus control effectiveness for residual risk, then by an applicability weight. Each factor comes from answers about what the organisation actually does, what controls exist and can be evidenced, and whether the duty applies to that entity.

What is the difference between inherent and residual compliance risk?

Inherent risk is the exposure if nothing had been done. Residual risk is the exposure after existing controls are taken into account. Programmes should be prioritised on residual risk, because that is where the gap is.

Why score by activity rather than job title?

Nordic organisations are flat and roles are broad. What a person does predicts exposure; what they are called does not. Asking how many people perform each exposed activity produces a score that changes when the organisation changes.

Why is “don’t know” scored as no?

Because a control that cannot be evidenced is not one a supervisor will recognise. Unknowns become the first task rather than a reason for a softer score.

Why does the group score use the highest entity rather than the average?

Regulators supervise entities, not groups. The weakest entity defines the group’s exposure, and averaging hides it.

What is a compliance risk matrix?

A grid of likelihood against impact, usually five by five. It is a useful display and a poor method on its own, because it omits controls and applicability. Use it to show residual scores, not to generate them.

How often should a compliance risk assessment be repeated?

Annually as a minimum, and whenever the risk picture changes, an incident occurs or a material regulatory change lands. Version each assessment and keep the previous ones.

Is a risk score legal advice?

No. It is a structured, dated judgement built on published thresholds and duties, designed to be checked by counsel and to give a defensible starting point rather than an opinion.

Sources and further reading