A compliance risk hides for one of two reasons. Either nobody is looking, or nobody knows they’re supposed to.
The first kind is annoying and fixable. Stale policies, an offboarding process that leaks access, a vendor somebody expensed on a personal card three years ago that now holds customer data. All of it is discoverable by a determined person with a spreadsheet and a free week. It’s a discipline problem, and discipline problems respond to effort.
The second kind doesn’t respond to effort, because the effort is pointed in the wrong direction. Nobody’s looking outside the building.
This piece covers both, plus how to assess and map them. The internal half first, because that’s the half you can genuinely fix this month, and because I’d rather not be the vendor who skims past the free fixes on the way to the paid one.
What is compliance risk?
Compliance risk is the exposure you carry when your organisation fails, or might fail, to meet a legal, regulatory or contractual obligation that applies to it.
Three words in that sentence do heavy lifting.
“Organisation” is the one people get wrong, and most of this piece is about why. It does not stop at your payroll.
“Might” matters because compliance risk exists before anything has gone wrong. A gap is a risk whether or not it has been exploited, and a firm that has never had an incident is not necessarily a firm with a functioning programme. It might just be lucky, and from the outside those two look identical.
“Applies to it” matters because half the compliance anxiety in most firms is attached to obligations that don’t actually bind them, while the ones that do bind them sit unattended. Working out which is genuinely the first task, and it’s usually shorter and stranger than people expect.
Worth distinguishing this from adjacent things. Legal risk is the exposure to litigation. Operational risk is the exposure to your own processes breaking. Reputational risk is what happens after any of the above becomes public. Compliance risk overlaps with all three and is identical to none of them.
What non-compliance actually costs
Non-compliance is the state of being in breach. The interesting question isn’t what it means, it’s what it costs, and the answer is layered in a way that most calculations miss.
The fine is the visible part and frequently the smallest. Underneath it sits the remediation programme the regulator requires, which is a multi-quarter project with headcount attached. Then legal costs, which accrue whether or not a penalty ever lands. Then the disclosure obligations, to customers, to LPs, to co-investors, to banking partners.
Then the part nobody models properly: senior people spending three months on incident response instead of running the business. For a small firm this is often the largest line on the bill and it never appears on anyone’s spreadsheet.
We built an actual arithmetic model for this rather than another page of scare statistics, because if you have to defend a budget line in a partner meeting you need a number that survives being taken apart.
Why compliance stopped being a back-office problem
Something shifted in the last few years and it’s worth naming, because it changes who cares about this.
Compliance used to be a cost centre that reported upward once a quarter and was otherwise left alone. It has become a gating factor on enterprise deals, on fundraising, and on banking relationships. That’s a commercial change dressed up as a governance one.
The mechanism is fairly simple. Enterprise buyers now run security and compliance reviews before they sign. LPs now ask about operational due diligence as a matter of routine rather than as a special request. Banks ask their partners the questions their own regulator asks them, which pushes the same expectations down the chain to firms that sit nowhere near a supervisor.
So a compliance gap is no longer a thing you might get penalised for eventually. It’s a thing that slows down a deal next month. That reframing is what put it on the board agenda, and it’s why the budget conversation has got easier even as the work has got harder.
The top 10 compliance risks, ranked by how long they stay hidden
Most “top 10” lists rank by severity, which is a bit useless, because severity depends entirely on your sector and your size.
A more useful ranking is by dwell time.
Security teams borrowed that term to describe how long an intruder sits inside a network before anyone notices. It transfers to compliance almost perfectly, and it tells you something a severity ranking can’t: not what the risk is, but how much time it gets to compound before you find out about it.
Ranked from longest-hiding to shortest. The first five are the dangerous ones, and you’ll notice they have something in common.
1. Impersonation and brand attacks
Fake support channels. Cloned social accounts. Spoofed founder profiles soliciting investment from people who believe they’re dealing with a company you own part of.
This one is structurally undiscoverable at onboarding, and I mean that literally rather than as a flourish. At the moment you closed the deal, the product hadn’t launched. There was nothing to impersonate. It could not have been in the data room because it did not exist.
Firms usually find out when a founder rings in a panic. Sometimes they find out from a screenshot posted by a user who has already lost money, which is considerably worse.
2. Founder and officer background changes
You screened them at close. The check came back clean, because it was clean. Nothing has been screened since.
Eighteen months later a suit is filed naming the founder personally, in a matter relating to a company they ran before yours. It’s public. It’s in a court filing. It would take roughly four minutes to find, for anyone who thought to look.
Nobody thinks to look, because looking was something you did once, during the deal, and the deal ended a year and a half ago.
3. Sanctions exposure through a counterparty
You screened the company. Fine. Did you screen its bank? Its exchange? Its largest customer? OFAC and its equivalents publish designations on a rolling basis, and a designation against a company’s principal counterparty drops that company, and therefore your position, into a compliance problem it did not create and may not have noticed.
The first anyone usually hears about it is a frozen account. By then the conversation has moved from risk management to crisis management, which is a much more expensive kind of conversation to be in.
4. Entity restructuring
Redomiciliation. New directors. Share transfers to parties nobody diligenced. Subsidiaries appearing in jurisdictions that weren’t in the picture at close. In crypto this is routine rather than exceptional: raise the round, migrate to the BVI or the UAE, restructure the cap table, and the company you diligenced no longer exists in that shape. Registries like OpenCorporates will show you all of it, assuming somebody is looking.
Usually nobody is. The discovery tends to happen at the next round’s diligence, when another firm’s analyst finds it and asks why you didn’t.
5. Regulatory reclassification
The company did nothing at all. The rules moved.
A token becomes a security. A service becomes a money services business in a jurisdiction where it wasn’t one last year. A product that was legal when you wired is now sitting inside a licensing regime that didn’t exist.
Invisible to any onboarding process, by definition, and typically discovered when an enforcement letter arrives or a bank starts asking pointed questions.
6. Vendors nobody procured
The tools were bought on a personal card. The AI transcription service somebody signed up for that is now processing your partner meetings. The scheduling tool with read access to every calendar in the firm.
You can’t govern what you don’t know exists. Start with the expense reports, which are unglamorous and work.
7. Offboarding gaps
Access that outlives employment. Boring, and everywhere.
Somebody left in March. Their email was disabled the same day. Their access to the deal CRM, the shared drive, the Slack workspace connected to a portfolio company, and the cloud console they set up two years ago was not, because all of that was provisioned individually by whoever needed it at the time.
A written checklist and a quarterly access review. An afternoon’s work, and it closes one of the most reliably exploited gaps in any small organisation.
8. The one person who knows how everything works
Every small firm has one. Competent, four years in the building, and if they leave the compliance function leaves with them, because none of it is written down anywhere except inside their head.
Almost nobody puts this in a risk register, because naming it feels like an accusation. Write it down anyway.
9. Policies written once and never opened again
Somebody produced a beautiful information security policy in 2023 because a customer demanded one. It went into a folder. The firm has since changed its cloud provider, its payroll system and half its headcount.
The fix costs nothing. Every policy gets a named owner and a review date, and the date goes in a calendar rather than in a plan.
10. Training people completed and didn’t absorb
Everyone did the module. Completion is at a hundred percent. And then somebody wires forty thousand dollars to a spoofed vendor account anyway, because the module was twenty minutes of clicking through slides at four in the afternoon.
I don’t have a clever fix for this. The honest version is that short, specific and frequent beats long, general and annual. Five minutes on the actual attack your firm will actually face, four times a year.
The same list, as a map
| Risk | Where it lives | How long it typically stays hidden |
| 1. Impersonation | Outside | Until users have already lost money |
| 2. Founder background changes | Outside | Until it’s public and somebody else tells you |
| 3. Counterparty sanctions | Outside | Until a bank freezes an account |
| 4. Entity restructuring | Outside | Until the next round’s diligence |
| 5. Regulatory reclassification | Outside | Until an enforcement letter arrives |
| 6. Unmanaged vendors | Inside | Until a breach, or a renewal invoice |
| 7. Offboarding gaps | Inside | Until an ex-employee’s access gets flagged |
| 8. Single-person dependency | Inside | Until they resign |
| 9. Stale policies | Inside | Until the next audit |
| 10. Training that didn’t land | Inside | Until somebody gets it wrong |
Those dwell times are observed patterns rather than measurements, and your own experience will differ. But look at the shape of the thing.
Everything in the top half lives outside your organisation. Everything in the bottom half lives inside it.
The internal risks surface through ordinary process, in weeks or months, because something eventually forces the issue. An audit. A renewal. A mistake. The external ones surface when somebody outside your firm finds them for you. Which is another way of saying they don’t surface. They arrive.
Which raises the question: where does your organization end?
You have a legal entity. You have an org chart. Neither describes your risk surface, and if you build a compliance programme around them you’ll produce something internally coherent and externally blind.
Think about what actually lands on your desk. A portfolio company’s founder appears in a sanctions designation. Your fund administrator’s sub-processor gets breached, with your data inside it. The exchange a portfolio company settles through collapses over a weekend, and you hear about it from a Telegram group before you hear about it from the company.
None of those people are on your payroll. All of them are, functionally, inside your compliance perimeter.
The regulatory position isn’t ambiguous, and it’s worth knowing even if you sit outside supervision. Guidance is explicit that a firm can outsource an operation but not the responsibility for it, and ongoing due diligence and oversight of third parties is treated as a component of a compliance management system in its own right. The same principle sits inside FATF’s recommendations on ongoing customer due diligence.
Most VC and crypto funds aren’t subject to that supervision, and I want to be careful about that, because overclaiming here would be easy and dishonest. Nobody is examining you next quarter. But the reasoning holds whether or not somebody is enforcing it, and LPs have started asking the questions regulators ask.
How to assess compliance risk
The standard method has four steps and a missing fifth.
Step one: inventory the obligations that actually bind you
Not the frameworks that would look impressive. The rules, contracts and regulatory commitments you would have to explain in a room if they went wrong. This list is usually shorter than people fear and stranger than they expect, and it will contain one or two things somebody has been ignoring because nobody realised they applied.
Step two: inventory the entities, not just the processes
This is the step that standard methodology skips and it’s the reason most assessments are incomplete.
Conventional risk assessment inventories processes: onboarding, payments, data handling, reporting. Fine for a company whose risk is internal.
If your exposure is external, you also need an inventory of entities. Every portfolio company. Every counterparty of consequence. Your administrator, custodian, key vendors. Anyone whose failure lands on your desk.
Most firms have never produced this list. It always comes out longer than expected, and producing it changes the conversation before you’ve scored a single thing.
Step three: score likelihood and impact
The familiar part. How likely is this, and how bad is it if it happens. Use whatever scale you like, three points or five, it genuinely doesn’t matter as much as people argue about it.
Step four: score detectability, which nobody does
How long would this take you to find out about?
Not “could we find it if we looked”. How long, in practice, given what you actually have running, between the thing happening and somebody at your firm knowing.
Score it in days. Be honest. If the truthful answer is “we’d find out when the founder tells us,” write down a number that reflects that.
Step five: prioritise on all three
Which brings us to the bit I think is genuinely missing from the standard frameworks.
How to build a compliance risk map (and the axis everyone forgets)
The conventional risk map is a two-by-two. Likelihood on one axis, impact on the other. Plot your risks, and whatever ends up in the top right gets the budget. ISO 31000 and COSO both broadly work this way, and it has served corporate risk management perfectly well for decades.
It contains a hidden assumption, though, and the assumption is doing a lot of damage.
It assumes you’ll know when a risk materialises.
Look at the map and you’ll see that detection is nowhere on it. Likelihood is there. The impact is there. The time between the event and your awareness of the event is simply absent, as though it were zero, as though risks announce themselves.
They don’t. And time is a multiplier on impact, not a footnote to it.
Take a medium-likelihood, medium-impact risk. If you’d spot it inside a day, it’s manageable. You intervene early, the exposure is contained, the remediation is cheap, and the regulatory position is that you found it yourself, which counts for a great deal.
Take the identical risk with a fourteen-month dwell time. The exposure compounds. Every cheap intervention point has gone past. The remediation is now a project. And you didn’t find it, somebody else did, which is a materially worse position to be explaining from.
Same likelihood. Same nominal impact. Wildly different reality.
The formulation
So the map needs a third dimension, and the simplest way to express it is:
Effective exposure = likelihood × impact × time to detection.
You can plot this on a flat page if you keep the two-by-two and use dot size or colour for detectability. In practice most teams just weight the score, which is fine. The formalism matters less than the discipline of asking the third question at all.
Run your existing risk map through that adjustment and something uncomfortable happens. Risks you’d scored as medium, sitting harmlessly in the middle of the grid, move sharply toward the corner. Almost all of them turn out to be external, because external risks are the ones with nothing running against them.
That reordering is, in a sentence, the argument for continuous monitoring. And it arrives from inside the methodology rather than from a vendor.
The mistakes almost everyone makes when mapping
Six, and the first is fatal.
Mapping only what you control. The map covers your processes, your systems, your staff, and stops at the door. Which produces a document that is internally rigorous and describes maybe fifteen percent of your actual exposure.
Mapping once. A risk map built in March and never reopened is a photograph. The world it describes has moved. This is a more dangerous state than having no map, because now you have a documented impression of a control that isn’t running.
Confusing likelihood with detectability. “We’ve never seen this happen” is frequently mistaken for “this is unlikely.” Sometimes it means “we wouldn’t see it if it did.” Those two produce identical evidence and require opposite responses.
Mapping at entity level instead of relationship level. You mapped your portfolio company. You didn’t map its bank, its exchange, or its largest customer, all of which can put that company into a compliance problem it didn’t create.
Letting everyone score their own area. People score their own domains as low risk. This isn’t dishonesty so much as proximity, and the fix is to have somebody from outside the function do the scoring, or at least challenge it.
Letting the map become a document rather than a tool. If the map isn’t driving what gets monitored, what gets escalated and what gets budgeted, then it isn’t a map. It’s a deliverable, and it was produced for somebody else’s benefit.
Risk mapping looks different depending on what you are
The shape of the map varies enormously by sector, which is why generic templates disappoint almost everyone who downloads one.
A manufacturer or a traditional corporate has risk that is overwhelmingly internal. Supply chain, plant, staff, data. Things it owns and directs. The standard frameworks were built for this and they work.
A SaaS company is also mostly inward-facing, with the risk concentrated in data handling and security controls. SOC 2, ISO 27001, GDPR. This is why the security compliance automation category exists and why it grew so fast.
Fintech is split. Inward for its own controls, outward for its customers, who need verifying at onboarding and monitoring afterwards. Two different programmes, frequently run by the same overstretched person.
A regulated institution carries heavy inward obligations plus formal third-party oversight requirements, which is why it usually ends up buying a GRC platform and hiring someone to run it.
A venture or private equity fund is inverted. Eleven people internally, two hundred million deployed across thirty-eight companies it doesn’t control. Internal risk is real but small. Almost all the exposure sits in entities outside the firm, and no standard framework describes this situation.
A crypto fund is the most inverted of all, and it carries two separate outward surfaces that don’t overlap. On-chain risk, which wallet analytics covers. And off-chain entity risk — founders, corporate structures, impersonation — which it doesn’t. Funds that have bought the first and assume they’ve covered the second are making the most common expensive mistake in this market, and we’ve mapped the whole category landscape here if that distinction is unfamiliar.
Best practices, most of which are free
Five things. Three of them cost nothing, which is worth saying up front, because the usual version of this section is a vendor explaining that the fix is a purchase order.
Draw the real boundary first. List every entity whose failure lands on your desk. Portfolio companies, their key counterparties, your administrator, your custodian, your outsourced providers. Free, and it takes an afternoon.
Set your detection latency as a number, not a word. Not “ongoing.” A number. If the honest answer is quarterly, you have accepted a worst case of around ninety days between a signal appearing publicly and anyone at your firm seeing it. That might be entirely fine. It should be a decision you made rather than a gap you inherited, and it belongs in your risk management policy rather than in somebody’s head.
Give every risk an owner before you need one. A risk with no name against it has no response, and this is far and away the most common reason alerts go unactioned. It isn’t a tooling problem and no software will solve it for you. More on routing here.
Automate the watching. Do not automate the deciding. A machine can read ten thousand articles overnight across six languages and surface the four that concern entities you care about. No human team does that. What a machine cannot do is decide what you do next. Any system that hands you a conclusion rather than a sourced signal is a liability, because you now hold a document that looks authoritative attached to a decision you can’t audit. Insist on the link back to the primary source. Insist on it from us, too.
Then test whatever you’ve built, which brings me to the last thing.
The one-hour audit
You can find out where you stand this afternoon.
Pick three portfolio companies at random. Not your problem children. Random ones, ideally including one you feel entirely relaxed about.
For each, answer four questions. Have the directors changed since we closed? Has the jurisdiction or corporate structure changed? Who are its major counterparties now, and were any of them counterparties at close? Is anyone impersonating it on social channels right now?
Time yourself. Then multiply that time by the number of companies in the portfolio.
If the resulting number exceeds the time you actually have, you don’t have a monitoring process. You have an intention. There’s a meaningful difference between the two, and it tends to get discovered at the worst possible moment.
One more thing. If you can’t answer those four questions for a single company without emailing the founder, that’s the finding. You don’t need to run it on the other thirty-seven.
Frequently Asked Questions
They’re worth fixing, and they’re also the easy half. The risks that actually cost money sit outside the building — a founder’s background changing, a counterparty getting designated, a company quietly redomiciling — and most firms have nothing at all watching for those.
An internal control map can probably survive a year. A map covering thirty-eight portfolio companies cannot, because those companies are changing directors, jurisdictions, and counterparties on their own schedule rather than yours. Review the internal half-yearly. Review the external half continuously, or admit you’re not really reviewing it.
Where that leaves you
The risks inside your building are findable. Tedious, but findable, and this has told you roughly where to look. Give them owners and dates and most of them stop being risks at all.
The ones outside your building won’t be found by looking harder, because nobody is looking at all. That isn’t a discipline failure, and effort won’t close it.
That gap is what Beady AI exists to close. Continuous monitoring of the entities you’re exposed to — portfolio companies, founders, counterparties — across sanctions lists, adverse media, corporate registries and social impersonation, with every signal linked back to the source it came from. Book a session and we’ll run it against your real holdings rather than a demo set. Most funds find something on the first pass, which is either reassuring or not, depending on your temperament.