This lesson provides an in-depth examination of the Compliance Risk Management framework, the cornerstone of modern tax administration. It covers the key steps in the CRM process and how tax administrations identify, assess, and manage compliance risks.

 

  • The CRM Framework: The compliance risk management process, as described in the 2004 OECD guidance note, has remained largely unchanged and still serves as a blueprint for managing compliance risks. Its key steps provide a structured approach to understanding and addressing non-compliance .

  • Key Steps in CRM:

    1. Understand the environment: Analyse the external and internal factors affecting taxpayer compliance

    2. Identify risks: Identify areas where non-compliance is most likely to occur

    3. Assess and prioritise risks: Evaluate the likelihood and impact of identified risks

    4. Develop treatment strategies: Design interventions to address prioritised risks

    5. Implement and monitor: Execute treatment strategies and monitor their effectiveness

    6. Evaluate and review: Assess outcomes and adjust strategies as needed 

  • Understanding Tax Compliance Risks: Understanding tax compliance risks is crucial for tax administrations as it enables them to identify areas where non-compliance is most likely to occur, whether due to error, negligence, or deliberate action .

  • Adoption of Formal CRM Strategies: Around 85% of administrations report having a formal compliance risk management strategy, with almost all having dedicated approaches for identifying, assessing, and prioritising key compliance risks .

  • Risk-Based Resource Allocation: By analysing and managing compliance risks, administrations can allocate resources more effectively, tailor enforcement strategies, and design programmes to improve voluntary compliance .

  • Evolution of CRM: The 2017 OECD report “The Changing Tax Compliance Environment and the Role of Audit” examined a range of incremental changes that, taken together, were changing the nature of the tax compliance environment, allowing for more targeted and managed compliance .