Compliance risk is an umbrella term for several distinct risk categories. Mixing these categories up can lead to gaps in your controls, as each type of risk requires different detection and mitigation strategies.
1. Regulatory Risk
The risk of financial loss, operational disruption, or structural restrictions resulting from changes in regulatory laws, administrative rules, or enforcement policies.
  • Example: A sudden increase in capital reserve requirements that limits a bank’s lending capacity.
2. Legal Risk
The risk of losses from contracts that prove unenforceable, lawsuits filed against the firm, or an inability to defend intellectual property. Legal risk stems from a failure to comply with statutory duties, contract terms, or asset protections.
  • Example: A counterparty suing a firm because an ambiguous clause in an options contract led to unexpected financial losses.
3. Conduct Risk
The risk that an organization’s behavior, actions, or omissions cause poor outcomes for its customers, undermines market integrity, or harms fair competition. Conduct risk focuses on employee behavior and corporate culture.
  • Example: Account managers inflating sales metrics by opening unapproved customer accounts to hit internal bonus targets.
4. Reputational Risk
The risk of a loss of trust, a drop in customer loyalty, or a falling stock price caused by public exposure of unethical behavior, compliance failures, or operational slip-ups. Reputational risk is often a secondary effect triggered by a primary regulatory or conduct failure.
  • Example: Public backlash and an exodus of users following a poorly managed data breach that exposed sensitive personal information.