1. Behaviour-based metrics and qualitative risk assessments are difficult to define and quantify but provide important insights about an organization's risk culture and compliance maturity.
2. Emerging regulatory requirements are increasing in number and scope, requiring firms to implement horizon scanning to understand changing rules.
3. A proposed compliance assessment approach uses a dynamic set of key risk indicators, benchmarking, sensitivity analysis and monitoring to provide a transparent and strategic view of compliance weaknesses and improvement impacts over time.