A Compliance Risk Assessment Framework (CRAF) translates risk theory into a repeatable corporate process. A CRAF must systematically map business units, identify regulatory intersections, and inventory existing controls.
The Five Step CRAF Workflow
[Step 1: Inventory Business Elements] ---> [Step 2: Map Regulatory Intersections]
                                                    |
                                                    v
[Step 4: Assess Control Effectiveness] <--- [Step 3: Calculate Inherent Risk]
                                                    |
                                                    v
                                      [Step 5: Compute Residual Risk]

Step 1: Inventory Business Elements
Identify and list every product, service line, target jurisdiction, delivery channel, and customer type across the organization.
Step 2: Map Regulatory Intersections
Connect each inventoried element to its specific regulatory requirements. For example, map a digital wallet feature to domestic money transmitter laws, electronic fund transfer acts, and local data privacy regulations.
Step 3: Calculate Inherent Risk
Evaluate the baseline risk level of each business activity assuming no internal controls or mitigation measures are in place.
Step 4: Assess Control Effectiveness
Analyze the design and operational strength of the internal controls designed to prevent or catch infractions (e.g., automated reconciliations, transaction monitoring, mandatory employee training).
Step 5: Compute Residual Risk
Calculate the remaining risk exposure after accounting for the mitigating impact of your internal controls. This final value is compared directly against the firm’s approved risk appetite.

Â