Showing posts with label Compliance. Show all posts
Showing posts with label Compliance. Show all posts

AI Governance Frameworks For Risk Managers

 

Corporate environments are adopting autonomous systems at a pace that outstrips traditional oversight mechanisms. Engineering teams ship automated workflows daily. Business units integrate external models into core operations without formal review. The resulting environment creates massive blind spots for risk professionals. You cannot manage what you cannot see, and you certainly cannot audit what you do not understand. The era of treating artificial intelligence as a mere productivity enhancement is over. It is now a foundational component of enterprise architecture. This shift demands a complete rethinking of control environments.

Risk managers, compliance officers, and cybersecurity experts must transition from passive observers to active architects of machine behavior. The theoretical debates about future capabilities no longer matter. The immediate reality involves managing current deployments that process sensitive data, execute financial transactions, and interact directly with customers. Professionals who master this transition will define the next decade of corporate governance. Those who fail will preside over catastrophic compliance failures and severe reputational damage.

This guide provides a direct, actionable blueprint for securing autonomous systems. We will explore five essential pillars of modern risk management. These pillars move beyond basic policy documents. They focus on the practical implementation of controls, the integration of global standards, and the strategic career positioning of governance leaders. You will learn how to validate machine outputs, secure third-party integrations, assign legal accountability, capture institutional context, and manage the hidden costs of automated code generation.

AI Agent Segregation of Duties Guide for GRC and SOX Compliance

 

Finance leaders are under constant pressure to cut costs, and automation is the fastest lever available. IT teams are asked to hand AI agents more autonomy every quarter, and in many workflows that autonomy now stretches across the full transaction lifecycle: an agent reads customer or financial data, produces a recommendation, approves it, executes the action through an API, and writes the log entry that documents what happened.

No serious organization would hand a single employee that combination of powers without a control wrapped around every step. Yet that is precisely the architecture some companies are building today, one agent deployment at a time, often without anyone deciding to do so on purpose. This piece walks through why that pattern is a genuine segregation of duties problem, what Sarbanes-Oxley actually requires when an agent touches a financially relevant process, and what a control owner can do about it in practice.

The Risk Management Blueprint: A Practitioner's Guide to Quantitative GRC

 

Risk management has a credibility problem. Not because the profession lacks talent, but because color-coded heat maps, ordinal scoring matrices, and quarterly dashboard reviews were never built to change decisions. They exist to document that a compliance process took place. Executive teams know this. They react accordingly by treating risk departments as corporate overhead instead of strategic assets.

I wrote this book to help my peers turn that dynamic around.

After 25 years leading risk functions and advising executive boards across complex multinational companies, I needed a manual that actually bridges advanced quantitative methods with the daily decisions that determine business outcomes. That drive is why The Risk Management Blueprint hit #9 among the most sold risk management books in the weeks after publishing.

At 867 pages, it gives practitioners a single unified methodology across every major risk domain, covering AI systems, cyber exposure, financial cash flows, sustainability transitions, and human behavior. The framework rests on probability theory, financial modeling, and decision science so you can swap subjective scores for numbers that stand up in the boardroom.

You can preview the first four chapters and access the book here: https://amzn.to/4ciag1F

This is not a textbook. It does not spend the majority of its pages diagnosing what is broken in the profession before gesturing toward improvement in a final chapter. More than 70 percent of the book's total length is allocated to domain applications and advanced analytical infrastructure, meaning the bulk of every page is spent on how to build, calibrate, and apply quantitative and predictive risk models across the decisions that actually shape organizational outcomes.

The Risk Management Blueprint for Quantitative and Predictive Models by Prof. Hernan Huwyler, MBA CPA CAIO | Quantitative Risk Management, Predictive Analytics, Probabilistic Risk Models, Monte Carlo Simulation, Financial Risk Modeling, Enterprise Risk Management, Operational Risk, Cyber Risk, AI Risk Management, Risk Analytics, Loss Distributions, Value at Risk, Expected Shortfall, Risk Exposure, Risk-Adjusted Decision Making, Automated Risk Controls and Agentic AI


SOC 2 Is Not Security: A Critical Guide for GRC Managers

Let us be direct. SOC 2 is not a security certification. It is an attestation report issued under AICPA standards in which a licensed public accounting firm expresses an opinion on whether a service organization controls met the selected trust services criteria. The report does not declare that your product is safe. It does not certify that your penetration test was rigorous. It does not prove that your attack surface is small or that your customers are protected from a breach. It states that management described a system, selected criteria, asserted controls, and the auditor found those controls suitably designed and, for a Type II report, operating effectively during the specified period.

That distinction matters more than many teams are willing to admit. The report can create a polished artifact that procurement teams accept, but the underlying controls may still be thin, poorly scoped, or disconnected from the technical reality of the product. The phrase SOC 2 is the audit version of trust me bro became popular for a reason. When the PDF is stronger than the security program, the market starts rewarding documentation rather than operational resilience. As a GRC leader, your job is to reverse that sequence. Build the controls, operate them, collect evidence continuously, and let the SOC 2 report fall out as a byproduct rather than serving as the starting point.

This guide walks through the exact gaps that make SOC 2 incomplete as a security signal, how to read a report without wasting your review cycle, how to build a security-first program that makes SOC 2 the output, how to use continuous assurance strategically, and how to govern vendors that hand you a SOC 2 report and expect instant approval. The focus is practical because the risk owner in the room rarely needs another abstract debate. You need a method for using SOC 2 as one piece of evidence among many.

The article is intended for a global audience. SOC 2 is a US-origin AICPA attestation product, but it is now exchanged across borders by cloud providers, software vendors, data processors, and AI product teams. It often sits alongside ISO/IEC 27001, NIST Cybersecurity Framework, CIS Controls, GDPR, HIPAA, NIS2, and emerging AI governance obligations. That means the underlying discipline remains the same. Understand the limitations, own the controls, and never outsource your risk judgment to a report.

 

Stop Chasing Evidence to Start Informing Decision-Making

Walk into most GRC departments in large global companies and you'll find talented professionals spending their weeks on the same treadmill: updating a register, chasing a control owner for evidence, formatting a report nobody outside compliance will read. That work isn't worthless, audits need it and regulators expect it, but it has quietly become the entire job for a lot of practitioners, and that's a problem nobody in the function wants to say out loud. Paper compliance was built for a slower, less automated world. The world asking for your risk function’s input now needs something else: probabilistic insight that turns uncertainty into measurable exposure, decision thresholds, planning choices, and control responses that improve performance.

uncertainty → exposure → thresholds → decisions → treatment actions → performance 

 

AI Isn't Coming for GRC Jobs. It's Coming For The Manual Review Part of Every GRC Job

Here's the uncomfortable part nobody says out loud in a GRC conference room. AI is not replacing risk managers, compliance officers, auditors, cyber teams, controllers, or sustainability experts. It's replacing the manual review work that used to justify half of those job descriptions. What's left after that work disappears is judgment, and judgment is either your biggest career asset right now or the skill you never actually built because the manual work always came first.

Every one of these six professions is being pulled through the same transformation at the same time, just wearing different clothes. Risk teams are using AI to process larger volumes of exposure data faster than any analyst could by hand. Audit is automating the routine testing that used to eat most of fieldwork season. Cyber teams are automating alert triage and first-line response. Compliance is watching AI surface policy conflicts across thousands of documents in the time it used to take to review one contract. Controllers are automating reconciliations and close procedures. Sustainability teams are automating ESG data extraction and disclosure drafting.

None of that is a headcount story on its own. It becomes one for the people who don't adapt, because the professionals who can validate AI outputs, challenge exceptions, and decide where a human still has to sign off are becoming the only ones a board actually needs in the room.

 

S/4HANA Role Redesign: Fix Segregation of Duties Before Go-Live or Pay the Audit Bill After

 

Why Privilege Creep Kills SAP Migrations Before the First Production Transaction Runs

Your migration to SAP S/4HANA is six months out. The project team is focused on data migration, Fiori tile configuration, and cutover planning. Meanwhile, 847 user roles built across eight years of organizational changes, job transfers, emergency firefighter access, and M&A integrations are being lifted wholesale into the new system. Nobody has reviewed them. Nobody has mapped them against the new S/4HANA authorization model. And your external auditors are already asking for the SoD conflict report.

This is the standard failure mode. And it is expensive to fix after go-live.

Migrating unremediated ECC roles into S/4HANA production does not just inherit old access risk. It amplifies it. S/4HANA's simplified data model, new Fiori authorization objects, and transaction replacements create net-new SoD conflicts from role content that was previously clean.

This article gives you the technical remediation workflow to stop that from happening. It covers the SAP-native tools, the sequencing logic, the role design architecture that prevents re-accumulation, and the automated tooling that makes the process viable at enterprise scale.


 

SR 26-2 Is Here: The 2026 Model Risk Guidance That Finally Gives Validators Teeth

On April 17, 2026, the Federal Reserve, the FDIC, and the OCC (collectively, "the agencies") issued SR Letter 26-2, which replaces prior model risk management guidance, the SR 11-7 issued in 2011. This update refines supervisory expectations regarding how banking organizations should calibrate their model risk management frameworks. The guidance is most directly applicable to institutions with total assets exceeding $30 billion, though smaller institutions with complex modeling activities are advised to consider its principles.

The guidance formally excludes simple arithmetic calculations, deterministic rule-based processes, and notably, generative artificial intelligence and agentic artificial intelligence models from the definition of a model. However, the agencies explicitly state that traditional statistical, quantitative, and non-generative artificial intelligence models remain within scope. The primary audience is organizations with over $30 billion in assets, reflecting a tailored supervisory approach that recognizes the lower inherent risk profiles of most community banking institutions.


 

How to Stop Producing Risk Registers Nobody Uses

Enterprise Risk Management programs fail in the same quiet way. They produce polished registers, colorful heat maps, and quarterly reports that look impressive in board packs. Then the organization makes its next major capital allocation, acquisition, or vendor choice using a single-page summary with one projected number and zero reference to the risk framework that consumed thousands of hours to build.

I've watched this pattern destroy the credibility of risk functions across industries. The risk team works hard. Stakeholders get interviewed. Likelihood and impact get scored. And none of it touches the actual decisions that determine whether the organization wins or loses. The gap between risk reporting quality and decision quality is where ERM programs go to die.

This article addresses that gap directly. It provides a stage-by-stage implementation approach for building an ERM program that changes how your organization decides, plans, and allocates resources. Every recommendation comes from field-tested practice, not theory. If your ERM program currently produces documents that live in SharePoint between annual reviews, this post shows you how to fix that.

 

How to Use Large Language Models Securely in Risk Management, Compliance, Cybersecurity, and Audit

 

A compliance officer asked an LLM to analyze a vendor contract for GDPR obligations. The prompt included the full contract text. The contract contained employee names, personal email addresses, salary data from an embedded compensation schedule, and a confidential arbitration clause. All of it went into a third-party API. The compliance officer received a helpful analysis. The organization received a data privacy incident.

Nobody planned for this. The compliance officer was doing good work. The tool produced a useful output. And the organization now had regulated personal data sitting in an external system with no data processing agreement, no retention controls, and no way to request deletion.

That is the paradox of LLMs in GRC. The same capability that makes them powerful for regulatory analysis, risk assessment, and audit automation makes them dangerous when deployed without guardrails. An LLM will process whatever you feed it. It does not distinguish between public regulatory text and confidential personal data. It does not know that the regulation it cited does not exist. It does not understand that the risk score it generated was influenced by training data biases that systematically underweight emerging market vendors.


 

How to Audit the SAP S/4HANA Order-to-Cash Cycle

Practical Audit Controls for the SAP S/4HANA Order-to-Cash Cycle

Revenue problems rarely begin in the income statement.

They begin earlier. In customer master data. In pricing conditions. In credit limits. In copy control. In blocked deliveries that no one resolves. In incomplete sales documents that sit too long. In manual overrides that looked harmless at the time.

That is why a strong SAP S/4HANA order-to-cash audit is never just a sales process walkthrough. It is a control review across sales, shipping, billing, receivables, customer master data, pricing, credit management, and the handoff into financial accounting.

I have seen organizations with healthy top-line growth discover margin leakage only after audit tested pricing overrides and free-of-charge processes in detail. I have also seen teams with good commercial discipline still struggle because customer business partner data, incompleteness procedures, or credit checking were only partially configured. The process looked fine on paper. The exceptions told a different story.

This article gives you a practical framework for auditing the SAP S/4HANA order-to-cash cycle. It covers new S/4HANA features, enterprise structure, master data, security, common configurable controls, high-value reports, and the technical details needed for a serious audit or GRC review. As requested, I include transaction codes, tables, authorization objects, and field-level references where they are relevant.


 

How to Execute a Complete SAP S/4HANA Audit: ITGCs, Basis Security, Process Controls, and Every T-Code You Need

 Most SAP S/4HANA audits fail before fieldwork even begins. The planning is shallow, the scope misses entire control layers, and the team lacks the technical depth to distinguish a real finding from a false positive. I have seen audit reports with 40 findings that missed the three issues that actually mattered. That is expensive failure.

Getting the SAP S/4HANA audit right matters because the system sits at the center of financial reporting, procurement, inventory management, and dozens of other processes that carry real organizational risk. A weak audit gives false assurance. A strong audit identifies quantifiable business impact and drives measurable control improvement.

This post walks through the complete SAP S/4HANA audit framework, from IT General Controls through business process validation, with every T-code, table, and configuration parameter you need to execute at a high level. Each section includes implementation tips drawn from field experience across financial services, manufacturing, and public sector engagements.


 

Practical Audit Controls for SAP HANA in IT General Controls Reviews

SAP audits slow down for a simple reason. The team asks good control questions, but they pulls evidence the hard way. That is expensive. It is also risky. When GRC teams run IT General Controls reviews, Basis reviews, security assessments, and compliance testing without a clear SAP HANA evidence model, they miss population-level issues, they over-rely on screenshots, and they burn weeks reconciling exceptions that should have been identified in hours.

I have seen this firsthand. In one global SAP program, the audit team had strong control design knowledge but no HANA-native audit approach. They extracted data into spreadsheets, sampled manually, and escalated dozens of false positives. The rework took three extra weeks. The actual root cause was not weak audit judgment. It was weak technical evidence strategy.

This post fixes that problem.


AI Governance Essentials

Why AI Deployment Now Requires Governance, Not Just Engineering

Artificial intelligence deployment has moved well beyond a technical exercise. What was once framed primarily as model development, application hosting, and iterative improvement now sits squarely within the remit of governance, risk management, compliance, and internal audit. That shift reflects regulatory change, market expectations, and a more mature understanding of how AI systems create both value and exposure across the enterprise.

The original draft focused heavily on product iteration, deployment mechanics, and general technology trends. Those topics matter, but in a professional GRC context they are incomplete unless anchored in accountability, risk ownership, control design, performance monitoring, and assurance. AI systems are not governed effectively merely because they are deployed through modern engineering practices such as CI/CD or MLOps. They require a structured governance model that aligns with recognized frameworks such as ISO/IEC 42001, NIST AI RMF 1.0, COSO Enterprise Risk Management, the IIA Global Internal Audit Standards, and applicable legal obligations including the EU AI Act, privacy laws, sector regulations, and financial reporting requirements where AI affects significant processes.

A practical governance perspective begins with one foundational point. AI is not a single risk category. It is a capability that can introduce, amplify, or obscure multiple risk types at once, including operational risk, model risk, legal risk, compliance risk, information security risk, privacy risk, conduct risk, third-party risk, and reputational risk. In many organizations, this is where governance breaks down. The enterprise treats AI as an innovation program when it should also be treated as a governed business capability subject to the same rigor applied to other material systems and processes.

This distinction matters because controls that are adequate for conventional software may be insufficient for AI-enabled systems. A deterministic business rule can usually be traced to fixed logic. A machine learning model may change behavior as a result of retraining, data drift, feature changes, prompt changes, or vendor model updates. A generative AI application may also produce variable outputs for the same input. For GRC professionals, that means control design must account for non-determinism, data dependency, explainability constraints, and lifecycle volatility.

Effective AI governance therefore starts with a simple but often neglected question. What decision, action, or business process is the AI system influencing, and what is the consequence if it fails or behaves unexpectedly? This framing is more useful than beginning with the underlying algorithm. It allows leaders to assess impact on customers, employees, financial reporting, safety, privacy, regulatory obligations, and organizational objectives.


 

Prof. Hernan Huwyler, MBA, CPA, CAIO: AI Governance, Risk & Compliance Executive | Speaker, Trainer & Advisor

 

I am an AI Risk Manager and Governance, Risk, and Compliance (GRC) executive dedicated to empowering business leaders to achieve strategic objectives through robust AI governance, digital compliance, and responsible AI frameworks. With over two decades of global executive experience spanning four continents, I specialize in guiding Fortune 500 organizations toward financial success and operational excellence by transforming regulatory pressure into a competitive advantage -1.

Tips and example on assurance mapping


Post by Prof. Hernan Huwyler, MBA, CPA, CAIO
AI GRC Director | AI Risk Manager | Quantitative Risk Lead
Speaker, Corporate Trainer and Executive Advisor
Top 10 Responsible AI and Risk Management by Thinkers360

Risk is a pervasive force across all business activities. Every strategic and operational decision depends on producing reliable information about the probability and impact of different outcomes. Assurance services exist to enhance the quality and credibility of this information, enabling leadership to make well-founded decisions with confidence.

The AICPA Special Committee on Assurance Services, commonly known as the Elliott Committee, articulated this principle in its 1997 report, establishing that assurance improves the reliability of information for decision makers. Since then, the scope of assurance has expanded well beyond statutory financial reporting to encompass ESG disclosures, cybersecurity attestations, data privacy compliance, and emerging areas such as AI governance.

The Institute of Internal Auditors defines assurance as the objective examination of evidence for the purpose of providing an independent assessment of governance, risk management, and control processes. This assessment adds credibility to both financial and non-financial information, from audited financial statements to environmental and social reports. In practical terms, assurance delivers the confidence that what needs to be controlled is actually being controlled.

Boards bear ultimate responsibility for ensuring that robust internal control arrangements exist across the entire organization, making assurance a first-order governance obligation rather than a purely operational concern.

Most corporate governance frameworks reinforce this expectation. The UK Corporate Governance Code, NYSE listing requirements, King IV in South Africa, and the EU Corporate Sustainability Reporting Directive all require the board to attest to the effectiveness of internal control and risk management systems. In the United States, SOX Section 404 specifically mandates that management assess and report on the effectiveness of internal controls over financial reporting.

Without a structured approach to coordinating assurance across these requirements, boards risk blind spots, redundant coverage, and misallocated resources. These are precisely the conditions that erode stakeholder trust and invite regulatory scrutiny.

What Is an Assurance Map and Why It Matters

An assurance map is a visual coordination tool that links assurance activities from all providers to the risks threatening organizational objectives. Structured as a matrix, it plots key risks or sequential process steps along the vertical axis against assurance activities along the horizontal axis.

The assurance activities are typically organized according to the IIA Three Lines Model, which was updated in 2020 to replace the former Three Lines of Defense terminology. Under this model, the first line consists of operational management, which owns and manages risk and controls. The second line encompasses risk management, compliance, and other oversight functions that provide expertise, monitoring, and challenge. The third line is internal audit, which delivers independent and objective assurance. Some organizations extend the framework to incorporate external audit and regulatory or board-level oversight as additional assurance layers, though these extensions fall outside the IIA formal model.

The strategic value of an assurance map lies in four dimensions. First, it provides board-level visibility through a consolidated, single-page view of risk coverage across the enterprise. Second, it promotes consistency by establishing a common methodology and language for management, oversight, and reporting. Third, it fosters cross-functional collaboration by making interdependencies between departments visible and actionable. Fourth, it drives cost efficiency by revealing redundancies and enabling reallocation of assurance resources toward areas of genuine exposure.

Keys to Making Decisions on Assurance

Assurance mapping is only as valuable as the decisions it informs. The following principles are critical to leveraging these maps effectively.

Identify Gaps and Eliminate Redundancies

The primary objective of assurance mapping is to detect areas where assurance is absent or unnecessarily duplicated across departments. A well-constructed map reveals the true level of oversight for each risk area, enabling leadership to reduce low-value and redundant efforts while strengthening coverage where it is most needed.

Standardize the Risk Methodology

For assurance mapping to deliver a coherent enterprise-wide view, the underlying risk methodology must be standardized. This includes the risk taxonomy, exposure modeling, and risk appetite thresholds. A common risk language is what enables meaningful coordination and interaction between business owners and assurance providers across all three lines. Without standardization, the map becomes a patchwork of incompatible assessments rather than a reliable decision-making tool.

Align Assurance Effort to Risk Exposure

Link the risk exposure of each process to its current assurance coverage to determine whether assurance costs are proportionate to the organization's risk tolerance. This is the practical application of the concept of reasonable assurance. When excessive assurance concentrates on a single process, leadership should investigate the root causes, such as historical incidents, regulatory mandates, or organizational inertia, before redistributing controls and responsibilities.

Update Governance Documents

When assurance programs are combined or activities reassigned, the governing documents must reflect these changes. This includes organizational policies, the internal audit charter, and departmental mandates. The assurance map is a coordination and visualization tool. It is not a policy instrument in itself and should not be treated as one.

Maintain Information Flow Across All Lines

Consolidating or reassigning assurance responsibilities does not eliminate the need for information sharing. Even when a department no longer directly assures a process, it should continue to receive relevant reporting about the reliability of related controls and the quality of associated outputs. Effective remediation depends on transparent communication of issues and action plans across all functions involved.

Leverage Technology for Continuous Assurance

Modern GRC platforms and data analytics capabilities enable real-time monitoring and continuous assurance, moving organizations beyond periodic point-in-time assessments. Integrating automated controls, exception-based reporting, and interactive dashboards into the assurance map strengthens both coverage and responsiveness. Organizations that embed technology into their assurance architecture gain a significant advantage in the speed and reliability of their risk oversight.

An Assurance Map in Practice

To illustrate the concept, consider a simplified financial month-end closing process at a company operating on SAP. The process-based map below plots process steps and their associated risks along the vertical axis against assurance providers organized by the Three Lines Model along the horizontal axis. It consolidates controls from each line to assess the extent and adequacy of coverage, designed for alignment with SOX Section 404 requirements and the COSO Internal Control Integrated Framework.




  

Each cell in the map reflects the quality and depth of evidence provided by the relevant assurance function, assessed according to three levels.

H stands for High Assurance. Assurance is detailed and performed on a recurring cycle. The depth of audit evidence reduces residual risk to an acceptable level, for example by maintaining low material misstatement risk in accounting processes. Controls are in place and adequately mitigate identified risks. Policies are documented and communicated throughout the organization. IT and business intelligence tools automate controls and flag exceptions for follow-up. Performance metrics are actively monitored by management.

M stands for Medium Assurance. Assurance is not performed on a regular cycle. Controls are not in place to cover all relevant risks. Policies are incomplete or not fully communicated to the responsible parties. Manual controls that could be automated remain in their current state, increasing the likelihood of human error.

L stands for Low Assurance. Little or no assurance is provided over the process. Significant concerns exist regarding the adequacy of controls relative to the risk profile. Few governing policies are documented or enforced.

The governance case for assurance mapping

In the United States, boards oversee risk management and internal control, while management is responsible for establishing, maintaining, and assessing those controls. This governance distinction is important. It would be inaccurate to say that boards directly operate or certify every control across the enterprise. Their role is to oversee whether the organization has an effective system of internal control and risk management, and whether that system is supported by credible reporting and challenge.

That oversight burden has grown significantly. Public companies face Sarbanes Oxley requirements for internal control over financial reporting. Regulated sectors face heightened scrutiny over operational resilience, model risk, privacy, third party dependencies, and cyber controls. Sustainability reporting is also increasing expectations around governance, controls, and attestable data. As complexity rises, boards and executive committees need a clearer and more integrated view of assurance coverage.

Recognized frameworks support this approach. The Institute of Internal Auditors Three Lines Model clarifies the roles of management, oversight functions, and internal audit. The COSO Internal Control Integrated Framework remains the leading basis for evaluating the design and effectiveness of internal control. COSO Enterprise Risk Management links risk oversight to strategy and performance. ISO 31000 provides a widely accepted foundation for risk management principles and governance. Together, these frameworks reinforce the same point. Assurance should be coordinated, risk based, and tied to decision making.

How Assurance Mapping Creates Management Value

The strongest reason to implement assurance mapping is not administrative efficiency. It is better risk oversight.

A well designed assurance map helps leadership answer questions that are often difficult to resolve through fragmented reporting. Which enterprise risks receive strong and recurring challenge. Which critical processes depend too heavily on self assessment or management judgment. Where are multiple teams reviewing the same controls with similar methods. Which material risks are supported by evidence based assurance and which rely on assumptions. Where does remediation stall because findings remain within one function instead of moving through a common governance process.

These insights matter because organizations rarely fail due to a total absence of controls. More often, they fail because risk ownership is unclear, challenge is inconsistent, and fragmented assurance gives leadership a false sense of confidence.

What a Strong Assurance Map Should Include

A useful assurance map begins with the business objectives, risk universe, and critical processes that matter most to the enterprise. The goal is not to map everything. The goal is to make visible the quality and sufficiency of assurance where failure would materially affect performance, compliance, resilience, or reporting integrity.

The structure usually starts with a defined scope such as financial reporting, cybersecurity, third party risk, privacy, revenue, procurement, product quality, or end to end operational processes. For each area, the map should identify the principal risks, the key controls or oversight mechanisms, the functions providing assurance, the nature of that assurance, the frequency of review, the degree of independence, the quality of evidence, and the current assessment of coverage.

This does not require an overly complex model. In fact, one of the most common mistakes is overengineering the framework to the point that it becomes difficult to maintain. The best assurance maps are disciplined, comparable, and practical enough to support real decisions.

 

From Assurance Mapping to Strategic Confidence

Assurance mapping is not an end in itself. It is a means of translating fragmented risk oversight into boardroom confidence and organizational resilience. When executed with disciplined methodology, standardized risk language, and genuine cross-functional commitment, it becomes one of the most powerful tools available to the GRC leader.

The goal is never to eliminate risk entirely. The goal is to ensure that the organization's assurance architecture is proportionate to its risk profile, coordinated across all lines, and transparent to the stakeholders who depend on it. In an era of expanding regulatory expectations, proliferating risk domains, and heightened scrutiny from investors and regulators alike, the organizations that master assurance coordination will be the ones that earn and sustain trust.



Get the latest in corporate governance, risk, and compliance on Twitter

Combining internal audits with anti-corruption compliance monitoring


 
Internal Audit Automatic queries tax haven countries Specific anti-bribery controls bribery risk map extra-territorial anti-corruption legislation compliance payments payments Hernan Huwyler

Post by Prof. Hernan Huwyler, MBA, CPA, CAIO
AI GRC Director | AI Risk Manager | Quantitative Risk Lead
Speaker, Corporate Trainer and Executive Advisor
Top 10 Responsible AI and Risk Management by Thinkers360

Why Detecting Concealed Payments Has Become A Board Level Priority

Detecting illegal payments concealed in accounting records remains a top priority for both internal audit and anti-bribery compliance functions. Corruption risk is a significant and growing concern for global organizations, driven by an expanding web of extraterritorial anti-corruption legislation. The U.S. Foreign Corrupt Practices Act, the UK Bribery Act 2010, France's Sapin II, and Brazil's Clean Company Act all impose obligations that extend well beyond domestic borders, creating overlapping enforcement regimes that demand coordinated internal controls.

Enforcement activity continues to intensify. The U.S. Department of Justice and the Securities and Exchange Commission have collectively imposed billions of dollars in FCPA-related penalties over the past decade. Whistleblower programs, particularly under the Dodd-Frank Act, have created powerful financial incentives for individuals to report suspected violations directly to regulators, with the SEC Whistleblower Program having awarded over two billion dollars since its inception. These dynamics make it essential for organizations to detect and prevent improper payments before they surface externally.

Identifying illegal payments hidden in accounting records is no longer a narrow compliance exercise. It is a core governance issue that sits at the intersection of anti bribery compliance, financial controls, internal audit, third party risk management, and investigations. For global companies, the stakes are high. Enforcement authorities continue to pursue cases under extra territorial anti corruption laws, whistleblower activity has increased, and regulators now expect companies to demonstrate not only that they have policies in place, but that they can identify and respond to suspicious transactions in practice.

Improper payments are rarely recorded as bribes. They are usually disguised as legitimate business expenses. In many cases, they appear as commissions, consulting fees, rebates, customs charges, facilitation arrangements, marketing support, travel expenses, charitable contributions, or vendor payments that appear ordinary on the surface. In more sophisticated schemes, illegal payments are concealed through inflated invoices, success fee arrangements with vague deliverables, layered subcontracting, shell entities, or payment flows involving offshore accounts and unrelated jurisdictions.

That is why anti bribery risk cannot be addressed through policy language alone. It requires a control architecture capable of identifying transactions that are technically booked within approved accounting categories but are economically inconsistent with the underlying business purpose.

Why Accounting Records Remain Central To Anti Bribery Detection

Under major anti corruption enforcement regimes, including the US Foreign Corrupt Practices Act, the integrity of books and records remains a central issue. Companies can face enforcement not only for improper payments themselves, but also for failures in internal accounting controls and the maintenance of inaccurate records. This is one of the most important practical realities in anti bribery compliance. Illegal payments are often detected not from direct evidence of intent, but from inconsistencies in documentation, approval logic, service validation, pricing patterns, vendor onboarding, or payment behavior.

For that reason, the most effective anti bribery programs do not separate ethics risk from financial control design. They treat accounting data, procurement data, third party due diligence, and approval workflows as connected evidence streams.

Why Improper Payments Are Difficult To Detect

Improper payments are deliberately designed to evade detection. The most straightforward schemes disguise bribes as legitimate business expenses such as agent commissions, third-party fees, consulting charges, or reimbursed travel and entertainment costs. More sophisticated arrangements involve inflated invoices, deceptive commission structures, fictitious services, and the use of complex webs of intermediaries, shell companies, and offshore bank accounts.

Under the FCPA, even when a substantive bribery charge cannot be proven, organizations face significant liability for books and records violations and failures to maintain adequate internal accounting controls. This means that the quality of accounting records and the integrity of the control environment are themselves compliance obligations, not merely audit concerns.

Mapping The Risk Factors Behind Improper Payments

Effective corruption risk assessment requires evaluating the full environment surrounding each transaction rather than relying on a single risk indicator. Organizations that anchor their bribery risk maps exclusively to country-level corruption indices, such as the Transparency International Corruption Perceptions Index, miss the broader transactional context that drives actual exposure.

A robust risk mapping framework balances four dimensions.

Where the transaction occurs encompasses the jurisdiction where the service is provided, the location from which payment is requested, and the domicile of the supplier. High perceived corruption jurisdictions, tax haven countries, new market sectors, and offshore locations all elevate this dimension of risk.

Who is involved examines the parties to the transaction, including public officials, politically exposed persons, small or newly established companies, new vendors without established track records, subcontractors, joint venture partners, associations, and any associated persons as defined by applicable legislation. The completeness and findings of due diligence, including any unresolved red flags, and the verification of beneficial ownership are critical elements of this assessment.

What service is provided evaluates the nature of the engagement. Consulting and advisory services, government licenses and permits, customs and logistics services, public procurement, complex or first-of-their-kind projects, and transactions where incentives or pressures exist to complete a deal on aggressive timelines all carry elevated risk.

How the service is contracted and paid focuses on the commercial and financial mechanics. The payment method, flat-fee structures versus success-based compensation, commission clauses, reimbursed expenses, upfront payments, the use of cash, and the routing of payments through jurisdictions unrelated to the underlying service are all relevant indicators.

Balancing these four dimensions provides a holistic view of corruption exposure. Organizations that assess only one or two of these factors, typically the country dimension alone, create gaps in their risk coverage that more sophisticated bribery schemes are specifically designed to exploit.

 

How Corruption Risk Should Be Assessed In Practice

Many companies still make a basic but costly mistake in corruption risk assessments. They over concentrate on country risk and assume that corruption exposure is driven primarily by geography. Geography matters, but it is only one element of the transaction risk profile. A stronger model evaluates corruption risk through the interaction of location, counterparties, business purpose, and payment mechanics.

A more complete risk view starts with where the service is delivered, where the payment is requested, where the third party is domiciled, and whether the transaction touches jurisdictions associated with weak transparency, sanctions concerns, customs complexity, or tax opacity. It also considers who is involved, including public officials, state owned entities, politically exposed persons, newly formed vendors, subcontractors, joint venture partners, customs brokers, commercial agents, and intermediaries with limited operating history or negative due diligence findings.

The nature of the service is equally important. Certain services are structurally higher risk because they are difficult to verify or can be used to justify discretionary payments. These often include consulting, licensing support, customs clearance, permit acquisition, business development, logistics support, market access work, and public procurement support. Risk also rises when a project is unusually complex, commercially pressured, fast tracked, or dependent on external approvals.

The final dimension is how the transaction is structured and paid. Payment method, fee logic, reimbursement provisions, use of advances, round sum compensation, success based compensation, vague statements of work, accelerated approvals, split invoices, foreign currency requests, or payments to accounts in unrelated jurisdictions can all materially elevate risk.

A mature corruption risk model balances all of these dimensions. It does not treat any single factor as determinative. It recognizes that a low transparency jurisdiction does not automatically make a transaction improper, and that a payment in a lower risk country may still be highly suspicious if the service cannot be substantiated or the payment structure lacks economic logic.

Why Compliance And Internal Audit Need A Shared Detection Model

Compliance and internal audit both play important but distinct roles in detecting illicit payments. Compliance typically owns anti bribery policy, third party due diligence standards, training requirements, escalation protocols, and ongoing monitoring of high risk transactions and third parties. Internal audit provides independent assurance over the design and operating effectiveness of controls, the adequacy of governance, and the consistency of execution across business units.

These roles should not be merged, but they should be coordinated. In practice, both functions rely on overlapping risk indicators, control points, and transactional evidence. If they use different definitions of bribery risk, different red flag criteria, or different scopes for testing, the result is fragmented oversight and duplicated effort. If they align on risk factors, data triggers, and control objectives, they can achieve stronger coverage with less burden on the business.

The most effective model is one in which compliance and internal audit share a common view of transaction risk, while preserving their separate mandates. Compliance performs targeted monitoring and program oversight. Internal audit independently evaluates whether the anti bribery control environment is designed and operating effectively. Each function benefits from the work of the other, but neither substitutes for the other.

A Better Way To Structure Collaborative Reviews

A practical way to coordinate anti bribery detection is to organize the review model around control design, operating effectiveness, and risk based monitoring. This structure is more useful than dividing work only by function because it aligns the assurance approach to how illicit payments actually bypass controls.

When organizations evaluate control design, they assess whether the preventive and detective control framework is capable of stopping or surfacing improper payments before they are embedded in normal accounting activity. When they evaluate operating effectiveness, they test whether those controls are consistently functioning in real transactions and whether exceptions are being challenged. When they monitor, they use data and trigger based review to identify payment behavior that warrants additional investigation or targeted audit attention.

This three part structure creates a practical bridge between governance, transaction testing, and analytics.

Evaluating Control Design Through An Anti Bribery Lens

Control design reviews should go beyond traditional financial authorization logic. They should assess whether the process architecture makes concealment difficult.

A strong design review examines segregation of duties across vendor onboarding, contract approval, service confirmation, invoice approval, master data changes, and payment release. The objective is not simply to confirm that different individuals are involved, but to ensure that the sequence of approvals creates meaningful challenge and that approval authority is appropriate to transaction risk and value.

Contracting controls also deserve close attention. Agreements with third parties should include anti corruption clauses, audit rights where appropriate, compliance with applicable laws, cooperation obligations, and termination rights tied to misconduct or control failures. It is equally important that the actual statement of work be specific enough to allow later verification of what the third party was expected to deliver.

The integrity of accounting descriptions is another underappreciated control. Accounting teams should be trained to use booking categories that reflect the economic substance of the transaction and to maintain meaningful entry descriptions. Large manual journal entries supported only by auxiliary spreadsheets, especially where line item support is missing or vague, create opportunities for concealment and should be tightly controlled.

Financial controllers and approvers should also be trained to identify anti bribery red flags in routine finance activity. This includes unusual travel and entertainment patterns, unsupported reimbursements, high risk petty cash usage, weak service confirmations, inconsistent vendor banking details, and commercially irrational pricing patterns.

Testing Operating Effectiveness Where Illegal Payments Actually Hide

Testing for operating effectiveness should focus on whether the control framework can withstand real world pressure. This means selecting transactions not only through conventional statistical sampling, but also through judgment based selection informed by known bribery risk patterns and red flags. Statistical samples are useful for some control objectives, but on their own they may miss the very transactions that merit scrutiny because corruption schemes are often low frequency, non random, and intentionally structured to look exceptional but explainable.

A stronger testing approach includes payments across multiple risk levels, with deliberate inclusion of transactions that are not necessarily high value but display unusual characteristics. These may include unnecessary intermediaries, vague consulting arrangements, success based compensation with no measurable output, emergency vendor onboarding, repeat reimbursements without adequate support, unusual discounts or rebates, or payments approved shortly before key regulatory or commercial milestones.

Third party testing is especially important. Reviews should examine whether due diligence was completed before engagement, whether red flags were resolved rather than simply documented, whether the third party had the capability to perform the service, whether beneficial ownership and control were understood, whether screening was refreshed appropriately, and whether the actual service provided can be corroborated through evidence beyond the invoice itself.

Approvals should also be tested for substance. Effective approval is not the presence of a signature in workflow. It is evidence that the approver assessed legitimacy, reasonableness, service performance, pricing, and potential conflicts of interest. If a company cannot demonstrate how an approver validated the business purpose of a payment, then the approval may have limited control value even if it was technically completed.

Using Monitoring To Surface Concealed Risk Earlier

Ongoing monitoring is one of the highest value areas in anti bribery detection because it can identify suspicious activity before it becomes systemic. The most effective monitoring models use data analytics to identify transactions and vendor behavior that deviate from expected patterns and then route those signals into compliance review, finance challenge, or internal audit follow up.

Monitoring should focus on transaction types that historically present bribery and fraud exposure, including gifts, meals, entertainment, travel, sponsorships, charitable donations, political contributions where permitted by law, agent commissions, distributor rebates, consulting fees, customs and logistics charges, and manual adjustments that affect vendor balances or expense classifications.

It is also important to monitor payment destinations and methods. Payments to offshore accounts, payments in currencies that do not align with the contractual arrangement, split payments, advances, round dollar payments, unusual prepayments, credits and rebates without clear commercial support, and sudden changes in bank account details all warrant closer review.

Trend analysis can be particularly effective. Out of pattern commissions by service type, abrupt pricing increases or decreases, changes in lease or equipment related expenses, repeated invoice amounts just below approval thresholds, and recurring payments to recently created vendors can all signal elevated risk. On their own, these indicators do not prove misconduct. Their value lies in helping the organization prioritize review where the transaction logic appears economically weak or control behavior appears abnormal.

What High Performing Programs Do Differently

Organizations with stronger anti bribery detection capability do not rely on isolated controls. They connect due diligence, contracting, procurement, accounts payable, general ledger data, employee expenses, and issue management into a coherent control environment. They also understand that corruption risk overlaps with fraud risk, sanctions risk, and money laundering exposure. That overlap matters because the same transactional patterns that indicate a bribery concern may also indicate vendor fraud, collusion, false billing, or concealment of beneficial ownership.

High performing programs also avoid treating anti bribery testing as a once a year review. They use targeted analytics and focused assurance cycles that adapt as the business changes. Market entry, distributor model changes, public sector expansion, customs intensive operations, and urgent project delivery environments all create periods where transaction scrutiny should increase.

Most importantly, mature programs ensure that findings lead to response. A red flag is only useful if the organization has a clear process to investigate it, escalate it, document conclusions, and adjust controls where necessary.

Common Weaknesses That Undermine Detection

Several recurring weaknesses tend to reduce the effectiveness of anti bribery detection even in otherwise mature organizations.

One is overreliance on due diligence at onboarding without enough scrutiny of what happens after the third party is engaged. A third party may pass initial screening and still become a bribery risk through changes in ownership, personnel, subcontracting, payment structure, or business pressure.

Another is excessive dependence on form based approvals. If the approval process captures signatures but not real challenge, then improper payments can move through the system with apparent control compliance.

A third weakness is insufficient integration between compliance monitoring and internal audit assurance. If compliance identifies recurring anomalies but audit does not assess whether the underlying control design is flawed, the organization treats symptoms instead of causes. If internal audit identifies design weaknesses but compliance does not adapt monitoring to reflect those weaknesses, risk remains under observed.

A final weakness is poor accounting transparency. Ambiguous general ledger descriptions, inconsistent use of expense categories, unsupported manual journal entries, and poor vendor master governance can make even a good anti bribery program far less effective.

Final Perspective

Detecting illegal payments in accounting records requires more than vigilance and more than policy. It requires a transaction level view of corruption risk supported by control discipline, data analysis, and coordinated assurance. Companies that treat anti bribery compliance, internal audit, and financial control as separate worlds will continue to miss important signals. Companies that connect them through a shared risk model and a common evidence base will be far better positioned to prevent, detect, and respond to concealed payments.

For boards, audit committees, chief compliance officers, and heads of internal audit, the practical question is no longer whether anti bribery controls exist. The more important question is whether those controls can detect a payment that was intentionally designed to look ordinary. That is the standard that matters.

References

US Department of Justice and US Securities and Exchange Commission. A Resource Guide To The US Foreign Corrupt Practices Act

US Department of Justice. Evaluation Of Corporate Compliance Programs

Organisation For Economic Co operation and Development. Good Practice Guidance On Internal Controls, Ethics, And Compliance

International Organization for Standardization. ISO 37001 Anti Bribery Management Systems Requirements With Guidance For Use

Committee of Sponsoring Organizations of the Treadway Commission. Internal Control Integrated Framework

Institute of Internal Auditors. Global Internal Audit Standards and guidance relevant to fraud and corruption risk oversight

Association of Certified Fraud Examiners. Occupational Fraud Reports and anti fraud control guidance



Get the latest in corporate governance, risk, and compliance on Twitter

Business intelligence in governance, risk and compliance

Business intelligence in governance, risk and compliance Audit, Compliance, Risk Mapping, SAP Hernan Huwyler


Post by Prof. Hernan Huwyler, MBA, CPA, CAIO
AI GRC Director | AI Risk Manager | Quantitative Risk Lead
Speaker, Corporate Trainer and Executive Advisor
Top 10 Responsible AI and Risk Management by Thinkers360


Corporate Criminal Liability And The Regulatory Case For Risk Mapping

The Spanish Criminal Code, as reformed by Organic Law 1/2015, establishes specific requirements for corporate compliance programs that regulate the criminal liability of legal entities. Article 31 bis sets out the conditions under which an organization may be exempted from or receive a reduction in criminal liability, provided it demonstrates that an effective compliance program was in place before the offense occurred. Among the program requirements enumerated in Article 31 bis paragraph 5, the organization must identify the activities within whose scope criminal offenses that must be prevented are likely to be committed. This requirement is, in substance, a mandate for criminal compliance risk mapping.

The Spanish framework shares a common logic with the U.S. Federal Sentencing Guidelines for Organizations under Chapter 8 of the USSG, which recognize an effective compliance and ethics program as a mitigating factor at sentencing. Similarly, the DOJ Evaluation of Corporate Compliance Programs guidance evaluates whether the organization has conducted a bona fide risk assessment that informs the design and resourcing of its compliance program. In both jurisdictions, the core principle is the same: demonstrated and adequate oversight efforts to prevent compliance breaches can materially reduce penalties and, in the Spanish case, provide a complete defense.

The Circular 1/2016 of the Spanish Attorney General's Office provides additional interpretive guidance on the elements of an effective compliance program under Article 31 bis, reinforcing that a meaningful risk assessment is foundational rather than optional. Organizations operating in Spain should also consider alignment with UNE 19601, the Spanish national standard for criminal compliance management systems, which provides a structured framework for implementing these requirements.

The Strategic Purpose Of A Compliance Risk Map

Building a compliance program that achieves high business values requires the chief compliance officer to address criminal, regulatory, and ethical risks in a coordinated and systematic manner. A compliance risk map is the instrument that makes this possible. It assesses business activities that may result in criminal offenses or, more broadly, in regulatory, legal, contractual, or ethical breaches.

The risk map serves two fundamental purposes. First, it guides prevention actions such as targeted training programs, the development of policies and procedures, and the design of internal controls proportionate to identified risks. Second, it informs contingency and response actions such as incident management, internal investigations, regulatory notifications, and remediation planning. Without a well-constructed risk map, the compliance program lacks a defensible basis for how it allocates its resources and prioritizes its activities.

Defining The Risk Mapping Scope

The foundation of any credible compliance risk map is a comprehensive risk universe. This universe should encompass all criminal offenses applicable to the organization under the relevant jurisdiction, including those enumerated under Article 31 bis of the Spanish Criminal Code, together with applicable regulations, contractual obligations, voluntary commitments such as industry codes of conduct, and known fraud schemes relevant to the organization's sector.

This risk universe allows the compliance function to classify risk factors in a way that facilitates both mitigation planning and communication to leadership. The compliance risk landscape should address industry-specific regulations, counterparty-related requirements such as anti-money laundering and sanctions obligations, and general regulatory frameworks including data protection, competition law, environmental standards, and occupational health and safety.

For multinational organizations, the risk universe must account for the jurisdictional complexity inherent in operating across multiple legal systems. A practical approach is to group compliance risk domains by general topic, such as bribery and corruption, fraud, data privacy, trade controls, or environmental compliance, and then map each topic to the specific local requirements applicable in each jurisdiction. This structure enables both enterprise-level aggregation and local operational relevance. The compliance requirement inventory should be validated by subject matter specialists from the compliance, legal, and where appropriate, regulatory affairs departments.

Integrating The Compliance Risk Map Into Enterprise Risk Management

A compliance risk map should not exist in isolation. It should be built upon and integrated into the organization's existing enterprise risk management framework. While ERM practices and internal audit risk assessments are not specifically designed to identify legal and regulatory compliance risks, they can be combined, calibrated, or linked to a compliance-specific risk map. The objective is to ensure that compliance risks are visible within the broader risk governance structure rather than siloed in a parallel process.

Following a global ERM policy ensures that the compliance risk map can be readily integrated into the organization's GRC management and reporting architecture. It also ensures that the risk taxonomy, rating scales, likelihood and impact definitions, and risk appetite thresholds are consistent across functions, enabling meaningful comparison and aggregation.

Assessing the financial impact of compliance risks is particularly important. A risk map that relies exclusively on qualitative categories without quantifying potential exposure, including regulatory fines, litigation costs, remediation expenses, and reputational harm, will struggle to compete for leadership attention and resource allocation against commercially quantified risks.

The methodological framework should be supported by recognized international standards. ISO 31000 provides the overarching principles and guidelines for risk management. ISO 37001 establishes requirements for anti-bribery management systems. ISO 37301, which replaced the former ISO 19600 in 2021, sets out requirements for compliance management systems. Alignment with these standards strengthens both the credibility and the defensibility of the risk assessment methodology.

Planning The Risk Assessment From The Top Down

Developing a comprehensive compliance risk map across a large or multinational organization can be time-consuming and resource-intensive. A pragmatic approach is to plan the assessment in phases, beginning at the enterprise level and progressively expanding into greater operational detail.

The chief compliance officer should perform an initial top-down risk assessment to identify the highest-priority risk domains and the organizational units, jurisdictions, and transaction types that warrant the most detailed analysis. This initial assessment should draw on available internal and external data sources to direct effort toward areas of greatest exposure.

The following is a simplified example of how a multinational organization might plan the phased expansion of its compliance risk mapping.




This initial framework can be progressively enriched with additional data from compliance exception reports, detailed whistleblowing and ethics hotline statistics, external audit and tax audit findings, transactional records, regulatory examination results, client complaints, employee surveys, and where relevant, social media and adverse media monitoring data.

Ensuring Broad Coverage And Operational Proximity

An effective compliance risk map must cover the actions and decisions of all individuals who act on behalf of or in connection with the organization, including board members, directors, managers, executives, employees, consultants, agents, and suppliers. Article 31 bis of the Spanish Criminal Code specifically addresses offenses committed by senior officers and by individuals subject to their authority or supervision, making breadth of coverage a legal requirement as well as a best practice.

The assessment process should involve personnel at multiple organizational levels, across jurisdictions and functional areas, to limit the cognitive and positional biases that inevitably arise when risk assessments are conducted exclusively by headquarters functions. Capturing perspectives from both senior leadership and operational staff ensures that the map reflects both strategic and ground-level risks. Performing assessments close to operations, at the site, business unit, or country level, significantly increases the probability of identifying the most relevant and material risks rather than generic or theoretical ones.

Clear ownership of each compliance risk must be established to facilitate the management of action plans, the tracking of remediation, and the escalation of issues through the governance structure. The chief compliance officer must maintain a comprehensive understanding of the full spectrum of compliance requirements and emerging issues across the organization's operating footprint. External legal advisors and specialized consultants can provide valuable support, particularly for jurisdictional-specific requirements and novel risk areas.

Building Trust To Surface Genuine Risks

The quality of a compliance risk assessment depends directly on the willingness of risk owners and operational managers to disclose their genuine risks and vulnerabilities. This willingness is a function of trust. Risk owners will provide candid and complete information only when they have confidence in the integrity and competence of the individuals conducting the assessment and believe that the process will lead to constructive action rather than punitive consequences.

Involving locally recognized and respected leaders in the risk mapping process is essential. Their participation signals organizational commitment and encourages open engagement from operational teams. Introducing the risk mapping initiative through compliance training sessions also creates a positive working environment and ensures that participants understand the purpose, methodology, and expected outcomes before they are asked to contribute.

Dynamic Follow-Up And The Compliance Culture

A compliance risk map that is produced once and then archived is not a compliance program. It is a document. In Spain, commentators and practitioners refer to this failure as compliance cosmético, the appearance of compliance without operational substance. The English-language equivalent is often described as paper compliance or window-dressing. Under both the Spanish Criminal Code and the DOJ Evaluation of Corporate Compliance Programs guidance, regulators evaluate whether the program is implemented and enforced in practice, not merely whether it exists on paper.

Compliance risks must be followed up dynamically and with a frequency proportionate to their exposure. This ongoing process includes reviewing the results of action plans against defined milestones, producing and monitoring key risk indicators, and escalating emerging or deteriorating risks to the appropriate risk committees, executive leadership, or the board.

The compliance risk landscape is not static. New risks emerge continuously from regulatory changes, enforcement trends, strategic decisions such as market entry or acquisitions, organizational restructuring, technological change, and the evolving sophistication of cybercrime and fraud schemes. A compliance risk map that does not evolve with the organization and its environment will rapidly become obsolete and will fail to provide the defensibility that the legal framework requires.

The dynamic follow-up of compliance risks and action plans is what transforms a risk map from a static inventory into a living instrument of the compliance culture. It is this ongoing discipline, visible to employees at all levels, that demonstrates the organization's genuine commitment to ethical and lawful conduct.

References

Spanish Criminal Code, including the framework relevant to legal entity liability and Article 31 bis

US Federal Sentencing Guidelines for Organizations

US Department of Justice. Evaluation Of Corporate Compliance Programs

ISO 31000 Risk Management Guidelines

ISO 37001 Anti Bribery Management Systems Requirements With Guidance For Use

ISO 37301 Compliance Management Systems Requirements With Guidance For Use

Committee of Sponsoring Organizations of the Treadway Commission. Enterprise Risk Management Integrating With Strategy And Performance



Get the latest in corporate governance, risk, and compliance on  Twitter

Corporate compliance and stock volatility in top 35 Spanish companies

Post by Prof. Hernan Huwyler, MBA, CPA, CAIO
AI GRC Director | AI Risk Manager | Quantitative Risk Lead
Speaker, Corporate Trainer and Executive Advisor
Top 10 Responsible AI and Risk Management by Thinkers360


Compliance Maturity And Stock Volatility: An Empirical Study Of Spain's IBEX 35

The Strategic Relevance Of Compliance In The Spanish Market

Compliance is a major ethical and strategic consideration that directly affects financial performance and determines whether the risk of organizational failure is contained within tolerable levels. In Spain, compliance risk has moved from a peripheral concern to a mainstream governance issue, driven by the introduction of corporate criminal liability through the reform of the Spanish Criminal Code by Organic Law 1/2015 and by the increasing exposure of Spanish companies to cross-border regulatory frameworks.

In response to this shifting landscape, Spanish companies across all sectors undertook significant revisions of their codes of conduct, ethics policies, and whistleblowing mechanisms. Many organizations established formal compliance functions for the first time. However, the relationship between the maturity of these compliance programs and the organization's observable risk profile as measured by financial market indicators has received limited empirical attention, particularly in the Spanish context.

This study examines that relationship by analyzing whether a measurable correlation exists between the compliance maturity of publicly listed Spanish companies and their stock price volatility, used here as a market-based proxy for perceived risk.

Study Design And Methodology

To investigate the correlation between compliance maturity and market risk, this study analyzed the 35 public companies that compose Spain's benchmark IBEX 35 index. The methodology comprised three components: a compliance maturity assessment based on publicly available governance documents, a market risk measure derived from historical stock price data, and a weighting mechanism based on relative market capitalization.

Compliance Maturity Assessment

The compliance maturity of each company was evaluated by analyzing its code of ethics and other publicly available ethics and corporate governance documents. Ten compliance domains were assessed, each representing a material area of legal and regulatory exposure for companies operating in Spain and internationally.

The domains evaluated were corruption, business conduct, and gifts. Antitrust and market abuse. Worker protection, discrimination, and harassment. Environmental protection and urban planning compliance. Copyright and intellectual property protection. Data protection and privacy, including obligations under the General Data Protection Regulation and Spain's Organic Law 3/2018. Tax compliance. Anti-money laundering. Occupational fraud. And whistleblowing policy, including the availability and accessibility of reporting channels and the disclosed management framework for handling reports, which was weighted at thirty percent of the total score to reflect the central role that reporting mechanisms play in the effectiveness of a compliance program under both Spanish and international standards.

For each domain, a complete score was assigned when the code of ethics and related governance policies established standard controls to mitigate the principal compliance risks associated with that domain. Where coverage was partial or where compensating controls were documented, the score was adjusted proportionately based on the nature and adequacy of the disclosed mitigating measures.

It is important to acknowledge that this scoring methodology relies on the quality and completeness of publicly disclosed documents. It therefore measures the stated maturity of the compliance program as presented to the market and regulators, not the operating effectiveness of that program in practice. Companies with sophisticated compliance programs that disclose limited public information may be underscored, while companies with well-drafted but weakly implemented programs may be overscored.

Market Risk Measure

The risk level for each company was defined as the historical 250-day volatility, calculated as the annualized standard deviation of daily stock returns over a 250-trading-day period. This measure captures the total variability of a stock's returns and is widely used as a proxy for the overall risk perceived by the market.

It is important to distinguish this measure from beta, which captures only the systematic component of risk, meaning the sensitivity of a stock's returns to movements in the broader market. Historical volatility, by contrast, reflects total risk, encompassing both systematic risk arising from general market movements and idiosyncratic risk arising from company-specific factors such as governance quality, regulatory exposure, operational disruptions, and reputational events. For the purposes of this study, total risk is the more appropriate measure because compliance program quality is more likely to influence idiosyncratic risk factors than systematic market-wide movements.

Weighting By Market Capitalization

To reflect the relative economic significance of each company within the index, the dataset of 35 companies and their associated compliance and risk observations was expanded into 700 weighted data points. Each company's observations were replicated in proportion to its relative market capitalization within the IBEX 35, based on the most recent statistics published by Bolsas y Mercados Españoles. This weighting approach ensures that larger companies, which have greater market impact and typically face more complex regulatory environments, exert proportionate influence on the aggregate findings.

The sector classification used in the analysis follows the criteria established by Bolsas y Mercados Españoles for the IBEX 35 index.

Findings






On balance, companies with strong and transparent ethics and compliance policies has better risk management in creating stakeholder value.

There are 2 types of outliners in the analysis:
  • Santander Bank, Repsol, OHL and Acciona have a mature compliance model according to the information in this study, but the stock value was highly volatile in the last 250 trading days, and
  • AENA, Endesa, Gas Natural, Dia and Iberdrola have low market value volatility, but opportunities to strengthen their compliance programs.



You can find the supporting data from these links:

MS Access Datasets 
Summary of dataset
Supporting Code of Ethics and Documents

The data analysis revealed a weak negative linear correlation with a Pearson coefficient of negative 0.18 between compliance maturity and historical stock volatility. This result suggests a modest inverse relationship: companies with higher compliance maturity scores tended to exhibit slightly lower stock price volatility.

However, the magnitude of this correlation is small, and several important qualifications apply.

First, correlation does not imply causation. The observed relationship may reflect the influence of confounding variables. Larger and more established companies tend to have both more developed compliance programs and lower stock volatility for reasons unrelated to compliance, including greater analyst coverage, higher institutional ownership, more diversified revenue streams, and more stable earnings profiles. Without controlling for these variables through multivariate regression or other techniques, it is not possible to attribute the observed relationship to compliance maturity itself.

Second, statistical significance should be evaluated in the context of the effective sample size. While the weighting procedure produced 700 data points, the underlying number of independent observations remains 35, which limits the statistical power of the analysis. With a correlation coefficient of negative 0.18 and an effective sample size of 35, the result is unlikely to achieve conventional levels of statistical significance at the 95 percent confidence threshold.

Third, the analysis identified sector-level variation in the strength of the correlation. The compliance and volatility relationship was stronger in the retailing and telecommunications sectors than in the index as a whole. This finding may reflect the fact that companies in consumer-facing and heavily regulated sectors face more direct reputational and regulatory consequences from compliance failures, making their market risk more sensitive to the quality of disclosed compliance programs.

Implications For Compliance Leaders

Despite the modest magnitude of the observed correlation, the findings offer several insights relevant to compliance and governance professionals.

The existence of any negative correlation between compliance maturity and market volatility, even a weak one, is directionally consistent with the broader body of research suggesting that strong governance and compliance practices contribute to reduced risk premiums and lower cost of capital. Studies published in journals including the Journal of Financial Economics and the Journal of Business Ethics have documented similar relationships between governance quality and market-based risk measures in larger international datasets.

For chief compliance officers and boards, the practical implication is that compliance program maturity may contribute to risk reduction as perceived by the market, but it is unlikely to be the dominant factor. The primary drivers of stock volatility remain macroeconomic conditions, sector dynamics, earnings quality, and company-specific operational performance. Compliance maturity is best understood as one component of a broader governance quality signal that the market incorporates into its risk assessment.

The sector-level variation in the findings suggests that compliance investments may generate more visible risk reduction benefits in industries with higher regulatory exposure and greater reputational sensitivity. Compliance leaders in these sectors have a stronger empirical basis for making the case that compliance program investment contributes to measurable risk outcomes.

Finally, this study highlights the limitations of relying solely on publicly disclosed compliance documents as a measure of program maturity. Organizations that invest in building effective compliance programs but do not communicate their efforts transparently through public disclosures may fail to capture the market-signaling benefits that a well-disclosed program can provide. This finding reinforces the importance of compliance communication and transparency, not only for regulatory purposes but as a component of investor relations and enterprise risk management.

Directions For Further Research

This study represents an initial exploration of the compliance-risk relationship in the Spanish market. Future research could strengthen the analysis in several ways. Expanding the sample beyond the IBEX 35 to include mid-cap and small-cap companies listed on the Spanish continuous market would increase statistical power and allow for more granular sector-level analysis. Incorporating multivariate regression to control for firm size, leverage, sector, profitability, and institutional ownership would help isolate the independent contribution of compliance maturity to volatility reduction. Extending the time horizon to examine whether compliance program improvements precede subsequent reductions in volatility would provide stronger evidence regarding the direction of the relationship. And supplementing the public document analysis with proprietary compliance program data, where available, would address the measurement limitation inherent in relying exclusively on disclosed information.

A More Defensible Interpretation

The most defensible takeaway is not that better compliance lowers market risk in a direct or measurable way across all companies. The stronger conclusion is that visible compliance maturity may be associated with aspects of governance quality that investors and stakeholders value, and that this relationship may be more visible in sectors where trust, conduct, and regulatory exposure are especially relevant.

This is a more modest conclusion, but it is also a more credible one. In governance analysis, precision matters. Overclaiming causation where only weak correlation exists can quickly undermine a good idea.

Final Perspective

Compliance maturity should not be viewed only as a defensive cost center or as a legal safeguard against misconduct. It is part of the broader institutional quality of a company. It can influence how risks are surfaced, how issues are escalated, how decisions are challenged, and how the organization protects value over time.

The analysis of the IBEX 35 does not prove that stronger compliance maturity reduces market risk. But it does suggest that the relationship between governance quality, visible compliance discipline, and market perception deserves more attention, especially in jurisdictions and sectors where corporate conduct has become a defining element of enterprise trust.

For boards and compliance leaders, that should be the practical message. If compliance maturity is visible only on paper, its value will remain limited. If it is embedded into governance, conduct, and decision making, it becomes part of the company’s resilience story.

References

Spanish legal and governance developments related to corporate criminal liability and whistleblowing frameworks

US Department of Justice. Evaluation Of Corporate Compliance Programs

Organisation For Economic Co operation and Development. Corporate governance and business integrity guidance

Committee of Sponsoring Organizations of the Treadway Commission. Enterprise Risk Management Integrating With Strategy And Performance

Academic literature on governance quality, disclosure quality, and market risk relationships

 


Get the latest in corporate governance, risk, and compliance on  Twitter