- 1
Apply a curated risk library
Operations lead · ≈ 15 minutesPick the library that matches the firm (e.g. UK Wealth Manager, EU MiFID Firm, US RIA). Each library ships with categories, baseline risks, and indicative likelihood/impact pre-scored. You inherit the structure; you control the scores.
A starting register with 40–80 risks across 8–12 categories.
- 2
Define entities and ownership
Risk owner · ≈ 20 minutesAdd the legal entities, business lines, and named owners. Risks attach to entities; ownership attaches to people. Compass uses these relationships to scope every later view (cockpit, board pack, attestations).
A register that knows who owns what, and where each risk sits in the group.
- 3
Set appetite and tolerance
CRO / Risk Committee · ≈ 30 minutesFor each category, set a board-readable appetite statement and a residual-score limit. Breaches surface in the cockpit and in the board pack — they are not silently absorbed.
A clear line between within-appetite and out-of-appetite for every category.
- 4
Ratify and freeze the methodology
Risk Committee · ≈ 10 minutes (at next meeting)The methodology (5×5 scale, control-effectiveness model, evidence-sufficiency model) is shown verbatim. The committee ratifies it. From that point, every score is traceable to a named, dated methodology version — the foundation of defensibility.
A versioned methodology and a traceable record of how the firm scores risk — designed for independent review.