Compliance Risk Assessment: What It Is and Who Needs One

What Is a Compliance Risk Assessment, and Does Your Business Need One?

A compliance risk assessment is a documented review of where your sensitive data lives, what could go wrong with it, and which safeguards you need. If a framework you follow requires one, it's usually the first document an examiner or auditor asks for.

The assessment identifies your systems and data, who and what can reach them, the threats and weaknesses that apply, and how likely and damaging each risk is. That tells you which controls you actually need. It's also one of the most commonly skipped requirements in small and midsize businesses. Owners aren't careless; "risk assessment" just sounds abstract, and nobody explains what it involves. Here's what it involves.

Which frameworks require one

  • HIPAA: covered entities and business associates must conduct an accurate and thorough risk analysis of electronic protected health information. HHS's Office for Civil Rights frequently cites a missing or inadequate risk analysis in its enforcement actions.
  • GLBA (FTC Safeguards Rule): non-bank financial institutions must base their information security program on a written risk assessment and repeat it periodically. Our FTC Safeguards Rule WISP guide shows how the assessment feeds the rest of the program.
  • PCI DSS v4.0.1: requires targeted risk analyses for specific requirements (for example, to justify how often certain controls are performed). These became mandatory on March 31, 2025, replacing the older annual formal risk assessment requirement.
  • SOC 2: auditors look for a documented risk assessment process under the Trust Services Criteria.
  • SEC-registered advisers and broker-dealers: amended Regulation S-P requires a written incident response program and oversight of service providers, and the Advisers Act compliance rule (Rule 206(4)-7) expects policies designed around your actual risks. A documented risk assessment is the practical way to show that.
  • CMMC and NIST SP 800-171: include risk assessment as its own control family.

If you operate under any of these and don't have a current, documented assessment, that's a gap worth closing first.

What a risk assessment covers

Asset inventory. Every system, device, application and data store in your environment, and what kind of sensitive data each one touches. You can't assess risk to assets you don't know you have.

Threat identification. The realistic threats: ransomware, phishing, credential theft, insider misuse, stolen devices, vendor breaches and accidental disclosure.

Vulnerability identification. Where the gaps are: unpatched systems, loose access controls, missing MFA, untested backups, unencrypted devices, or staff who haven't been trained.

Risk scoring. For each threat and weakness, how likely it is and what the impact would be. The result is a ranked list of risks.

Control evaluation. Which safeguards are working, which are partly effective and which are missing.

Remediation roadmap. A prioritized, documented list of what needs to change and in what order.

Documentation. The finished assessment, which your auditor will review, your compliance officer will rely on, and your cyber insurance carrier may request.

How often you need one

Annually is the widely recommended baseline, plus whenever something significant changes: new systems, a new location, major new software, staff changes or a security incident. The HIPAA Security Rule doesn't set a fixed frequency, though annual review is standard guidance and is part of the Security Rule changes HHS proposed in January 2025 (still a proposal). An assessment done once and filed away goes stale quickly. Treat it as a working document and formally revisit it at least once a year.

What happens without one

In an examination or audit, a missing risk assessment is usually an immediate finding. HIPAA enforcement actions have cited this gap on its own, even where no breach occurred. After a breach, a missing assessment makes things harder: it suggests obligations weren't taken seriously and weakens any argument that the incident was unforeseeable. Cyber insurance applications also increasingly ask about risk management, and inaccurate answers can complicate a claim. See What does your cyber insurance policy require?

How NerdSquad helps

We conduct technology risk assessments for clients, document the findings, prioritize the fixes and then implement the technical controls the assessment calls for, from MFA and encryption to endpoint detection and response and tested backups. Because we manage the environment afterward, the assessment becomes the plan we work from rather than a report that sits in a drawer. Financial firms can see how this fits their obligations on our IT for financial advisers and wealth managers page.

For framework-specific detail, see Do you help us stay HIPAA compliant? and Can you help us meet compliance requirements like HIPAA, PCI, and SOC 2?

NerdSquad is not a law firm; confirm your obligations with your compliance counsel.


Talk to NerdSquad

Already a client? Call (239) 465-0079 or submit a ticket. If something is down, call so we can start right away.

Not a client yet? NerdSquad Managed IT Services is a Managed Service Provider (MSP) based in Naples, Florida. We support businesses onsite across Southwest Florida and remotely nationwide. Book a discovery call or call (239) 465-0079.

Related: Cybersecurity and compliance services