
Products / RiskReady
The risk assessment your regulator expects, built around your business.
RiskReady is Taft’s enterprise compliance risk assessment, the engagement the industry calls a risk 360. Every regulatory obligation you carry, the inherent risk in your products, customers, geographies and channels, the controls that address it, and the residual risk that is left, in one document a board and an examiner can read.
Who it’s for
For firms whose risk assessment is missing, out of date, or nobody’s.
- A newly licensed business that has to show a documented risk assessment before its first examination.
- A firm whose assessment is a spreadsheet built for a product set and a customer base it no longer has.
- A group with several entities and no consistent way of measuring the same risk across them.
- A board or audit committee that wants the firm’s compliance risk stated plainly, with the controls that hold it and the gaps that do not.
What you get
What you receive.
A risk assessment is not a heat map. It is the reasoning behind the heat map, written so that the next person can follow it and the examiner can test it.
Regulatory inventory
Every obligation that applies to you, by regulator, license, product and jurisdiction, and the ones that do not, with the reason.
Inherent risk assessment
The risk your business carries before any control: products and services, customers, geographies, channels and transactions, rated on a scale you can defend.
Control assessment
The controls that address each risk, whether they exist, whether they are designed well, and whether there is evidence they operate.
Residual risk and heat map
What is left after the controls, on one page, by risk area and by entity.
Prioritized action plan
The gaps that matter, in order, with owners and dates.
Methodology and board paper
How the assessment was done, in a form the board can approve and the examiner can read, so the next refresh starts from a record rather than a memory.
Options
Three depths.
Scoped to the firm: one risk area, the whole enterprise, or a group with several regulated entities.
RiskReady Focus
- One risk area, such as financial crime, sanctions or conduct
- One entity
- Inventory, inherent risk, controls, residual risk and actions for that area
RiskReady 360
- The enterprise compliance risk assessment
- Every applicable risk area for one entity
- Methodology and board paper included
RiskReady Group
- Several entities, licenses or jurisdictions
- One methodology, entity-level results and a group view
- Group requirements against local ones
How we assess
Obligation, inherent risk, control, residual risk. In that order, every time.
The order matters because examiners read it that way. A control without an obligation behind it is noise; an obligation without a control behind it is a finding.
Obligations
What the rules require of a firm with your licenses, products and customers, and what they do not.
Inherent risk
How much risk each product, customer type, geography and channel brings on its own, rated consistently and explained.
Controls
What you do about it, tested against design and against evidence of operation, not against the policy’s description of itself.
Residual risk
What is left, whether it is within your appetite, and what to do where it is not.
When to do it
Before the examiner asks for it.
After licensing
A documented risk assessment is usually the first thing an examiner asks a new firm to produce.
After growth or a new product
New customers, new geographies and new channels change the inherent risk. The assessment has to move with them.
After a finding
A regulator that has questioned one control will want to see how the firm rates the risk behind it.
Every year
A risk assessment is a living document. An annual refresh keeps it current and keeps the board’s approval meaningful.
How it runs
How it runs.
Scope
Entities, licenses, products, customers, geographies and channels, agreed before anything is assessed.
Gather
Policies, procedures, control inventories, testing results, data on customers and transactions, previous assessments and regulatory correspondence, through a secure channel.
Assess
Obligations mapped, inherent risk rated, controls tested against design and evidence, residual risk calculated on a method we write down.
Challenge
Senior Taft practitioners test the ratings against how the business actually operates and against what examiners are asking firms like yours.
Report
The assessment, the heat map, the action plan and the board paper, presented to management and, if you want, to the board.
Questions
Asked before, answered plainly.
- Is RiskReady a risk 360?
- Yes. Risk 360 is the industry term for an enterprise-wide compliance risk assessment, and RiskReady is Taft’s version of it: obligations, inherent risk, controls and residual risk, across every applicable risk area, in one document.
- How is it different from the Compliance X-Ray?
- The X-Ray tests whether your framework holds together, from obligation to policy to control to evidence. RiskReady measures the risk itself and whether the controls bring it within your appetite. Firms often do the X-Ray first and RiskReady second; either can stand alone.
- Do regulators require a risk assessment?
- Most regimes expect a regulated firm to run a risk-based compliance program, and anti-money laundering rules in particular expect the risk assessment to be documented and current. Whatever your regime says, examiners commonly ask for the risk assessment first, because it tells them how you think.
- Can you refresh an assessment we already have?
- Yes. If the method is sound we keep it and update the inputs. If it is not, we say so and rebuild it, keeping whatever history is worth keeping.
RiskReady is an assessment by compliance practitioners. It is not legal advice, not an audit, and it does not replace independent testing required by your regulator.