Blog Post

Compliance Risk Assessment Framework (RAF): A Step-by-Step Guide for 2026

Richard P. Kusserow | September 2026

Every healthcare organization understands the importance of risk management, but most do not have a solid foundation for their programs. 53 percent of healthcare compliance, risk, and legal leaders cite resource constraints in budget, staffing, or technology as a top challenge. Most organizations, as a result, don’t have an accurate view of their existing compliance risk exposure.

This article reveals a proven method to solve this problem: the Compliance Risk Assessment Framework. But first, we need to explore why this framework is so important. 

A Compliance Risk Assessment Framework (RAF) is a repeatable process for identifying, scoring, and mitigating compliance risk across your organization. Below, you’ll find the 10-step framework broken into concrete actions, a sample risk matrix showing what a completed assessment looks like, and the four types of risk assessment healthcare organizations use most.

What is a Compliance Risk Assessment? 

A compliance risk assessment systematically evaluates your systems, policies, and operations to uncover factors that could lead to non-compliance. For example, a HIPAA compliance risk assessment might reveal that your employees lack regular training in updates to the HIPAA Security or Privacy Rules. This increases the likelihood that they will mishandle data and ultimately cause your organization to breach HIPAA’s guidelines.

Running this evaluation well takes more than a checklist. For a full walkthrough of how to scope, schedule, and execute one, see our guide to conducting a compliance risk assessment.

What Happens When Risk Assessments Aren’t Completed? 

Healthcare organizations that fail to run regular assessments are at far higher risk of non-compliance. This can result in fines, penalties, or other costs regulators might impose. However, there are other potential consequences, such as exposure to tort liability from civil lawsuits, loss of reputation and standing in the community, negative impacts on business relationships, weakening of employee confidence, financial impact, etc.  

The Benefits of Healthcare Compliance Risk Management Framework and Assessment 

Healthcare compliance is an ever-evolving landscape, with new legislation passed every year, which organizations must factor into their daily operations. From new cybersecurity requirements to higher financial penalties for HIPAA violations, organizations must stay on top of these changes to understand their changing compliance risk exposure. 

Risk assessments, therefore, provide several benefits: 

  • Risk Identification: Risk assessments ensure you understand the areas where your organization is at risk of non-compliance. Routine assessments ensure you factor in new requirements and do not develop compliance blind spots. 
  • Risk Prioritization: Assessments also provide essential data to determine which challenges are most urgent and should, therefore, be remediated first. This ensures organizations with limited budgets can still maintain reliable compliance programs. 
  • Regulatory Reporting: Regular, accurate assessments provide clear documentation, which can simplify and accelerate regulatory reporting. This can save your compliance team a lot of time and resources. 

The only problem is how to run regular assessments without creating a huge amount of confusion and extra work for your teams. 

Why Are Risk Assessments Difficult? 

Despite the evident value of regular risk assessments, most healthcare organizations find assessments difficult. There are several reasons for this, including: 

  • Resource Constraints: Most healthcare organizations have limited funds available for risk assessments. This means teams often do not have enough time to devote to assessments, especially when the assessments are often messy and unsystematic. 
  • Time Constraints: Risk assessments can be time-consuming, and many organizations believe they should be focused on remediating problems rather than identifying new ones. 
  • Complexity and Data: Assessments are often highly complicated; you need to source information from across the entire organization to fully understand the existing risk exposure and identify compliance risks. However, this data is rarely stored in a centralized location, creating headaches for those tasked with parsing it out and drawing conclusions from the assessments.  

These issues are all substantially lessened when you have a reliable framework to use when conducting assessments.

What is the Compliance Risk Assessment Framework?

The Compliance Risk Assessment Framework (RAF) is a methodology designed to enable consistent, ongoing compliance risk assessments. It includes an inventory of compliance risks with respect to applicable laws, regulations, rules, standards, and guidelines by providing a structure for assessing compliance with them. On the other hand, evidence of effective compliance risk management often results in more favorable treatment by government regulators.

The OIG’s November 2023 General Compliance Program Guidance treats risk assessment as a practical tool for prioritizing the auditing and monitoring work required under its seven elements of an effective compliance program, not a one-time exercise. That is part of why the RAF below is built as a repeatable cycle rather than a single audit.

The compliance risk framework process should include analyzing where regulatory compliance obligations are weak or not being adequately addressed. This process is primarily a program manager function who should identify, address, and then manage risks within their program operations. This function involves evaluating and specifically identifying, prioritizing, and controlling risks associated with the threat of non-compliance.

The 10 Elements of the RAF, Step by Step

  1. Identify risks affecting the operational areas. This belongs to the compliance officer or program manager, working with department leads who know where operations actually happen day to day. Walk through billing, HR, clinical operations, IT, and vendor relationships area by area. The output is a written risk inventory, not a mental list, that covers every area where non-compliance could occur, including the ones nobody has flagged a problem in yet.
  2. Analyze risks in terms of vulnerability, likelihood, and consequences. For each risk on the inventory, score how exposed you are (vulnerability), how likely the risk is to materialize (likelihood), and what it would cost you if it did (consequences). This is typically a joint effort between the compliance team and the operational owner of that risk area. The output is a scored risk profile you can compare across the whole organization.
  3. Rank risks from high to low as to probability and negative consequences for failure. Plot the scored risks from step two on a simple grid, likelihood on one axis, impact on the other, and rank them highest to lowest priority. The compliance officer typically owns this ranking, reviewed with executive leadership. The output is a prioritized list your team can act on instead of trying to fix everything at once.
  4. Begin with the highest compliance risk exposure; review existing controls. Start at the top of the ranked list and take inventory of what controls already exist for that risk: policies, training, monitoring, technical safeguards. The risk owner and compliance team do this together. The output is a clear picture of what is already in place versus what is missing.
  5. Determine the adequacy of policies and procedures to control risks. Test whether the controls from step four actually hold up: are policies current, enforced, and understood by staff, or do they exist on paper only? Compliance and legal typically share ownership here. The output is a gap list showing exactly where policy or procedure falls short of the risk it is meant to control.
  6. Plan steps to reduce or mitigate risk levels with new or modified policies and procedures. Turn the gap list into an action plan: new policies, revised procedures, additional safeguards, or added resources. Program managers usually draft these plans with compliance sign-off. The output is a documented mitigation plan with owners and target dates attached to each fix.
  7. Train staff on following the compliance risk assessment guidance. Roll out training on the new or updated policies to everyone the risk touches, not just the compliance team. Training and HR typically co-own delivery. The output is documented training completion tied to the specific risks it addresses. See our guide to compliance training effectiveness for how to prove training actually changed behavior.
  8. Conduct ongoing monitoring to ensure staff is adhering to the compliance risk guidance. Monitoring is the ongoing check that mitigation steps are actually being followed day to day. Compliance and department managers typically split this work. The output is a monitoring log that flags drift before it becomes a violation. 
  9. Conduct an internal audit review to test and validate controls are effective. Audit periodically verifies what monitoring cannot catch in real time, using a sample of transactions or records to confirm controls are actually working. Internal audit typically owns this, independent from the teams being reviewed. The output is an audit report confirming controls are effective or flagging where they have failed.
  10. Routinely repeat the process to test controls and adjust as needed. Set a cadence: most healthcare organizations run this cycle annually, more often for high-risk areas, and repeat steps one through nine. Compliance owns the calendar; leadership owns holding the organization to it. The output is a living risk assessment that stays accurate as regulations and operations change, instead of a report that is outdated within months.

Note that there are other areas of risk assessment in addition to compliance (e.g., strategic planning, mergers/acquisitions, clinical, financial, etc.). For how those risk types fit into a broader program, see our guide to enterprise risk management.

What Does a Compliance Risk Assessment Look Like?

Here is what that ranking looks like in practice for a mid-size healthcare organization running its first RAF cycle:

RiskLikelihoodImpactPriority
Billing and coding errorsMediumHighHigh
Gaps in HIPAA-required staff trainingHighMediumHigh
Physician arrangements not reviewed against Stark/Anti-KickbackMediumHighHigh
Missed OIG exclusion screening (staff or vendors)LowHighMedium
Vendor and business associate agreement (BAA) gapsMediumMediumMedium

A full assessment covers dozens of risks across every operational area; this is a sample, not a template.

What Are the Four Types of Risk Assessments?

Risk assessments generally fall into four types.

  • Qualitative: uses descriptive judgment, ranking risk as low, medium, or high based on likelihood and impact, without assigning hard numbers
  • Quantitative: attaches dollar values or statistical probabilities to that same likelihood and impact.
  • Generic: covers risks that show up across multiple departments or locations, using standard controls you can reuse as-is.
  • Site-specific: customizes those controls to the real conditions of one location, department, or vendor relationship.

The RAF above is primarily qualitative and generic: it ranks risk by vulnerability, likelihood, and consequence rather than by calculated dollar exposure, and it’s built to apply across your organization’s operational areas rather than to one location. As your program matures, you can layer in quantitative scoring, cost of a HIPAA breach, dollars at risk from a billing error, or run a site-specific version of the same framework for a single high-risk facility or vendor.

What’s New for 2026

Two things have shifted since this guide was first published.

1) OIG’s General Compliance Program Guidance, paired with its industry-specific guidance for hospitals, nursing facilities, and other segments, has made a documented risk assessment process a baseline expectation rather than a best practice.

2) Enforcement activity tied to gaps in that documentation has increased alongside it. For the specifics of what changed and how to respond this year, see our 2026 compliance risk assessments roundup.

Take Control of Your Compliance Risk with SMS 

Healthcare compliance can be stressful and time-consuming – but not when you have the right partner to simplify, accelerate, and improve your approach to risk. 

Strategic Management Services has developed a four-step process to make risk management easy for healthcare providers. While this includes the compliance RAF we’ve discussed here, it also features powerful methodologies for risk remediation, risk management, monitoring, and reporting. 

Want to explore how it could help your organization stay safe? 

Book a Meeting 

Frequently Asked Questions 

Q. How Often Should I Assess Compliance Risk? 

While the answer will vary for every organization, we strongly believe compliance risk assessments should be an always-on process. Along with ongoing monitoring and auditing, it provides a foundation for your compliance program and ensures you can be confident hidden risks are not about to take you by surprise.  

Q. What are the Differences Between Compliance Risk Assessments and Monitoring? 

A risk assessment looks for aspects of your operations that could lead to non-compliance, while risk monitoring looks for changes in how policies and controls are administered to identify emerging risks. 

Q. Do I Need Help to Run a Compliance Risk Assessment? 

Healthcare organizations can run these assessments internally, and many do. The tradeoff is usually thoroughness: without a dedicated team, internal assessments tend to stop at the departments most visible to compliance staff and miss the harder-to-see areas, vendor relationships, physician arrangements, newer service lines. An external review, or an internal one built on the 10-step framework above, closes that gap by forcing a structured pass through every operational area instead of just the obvious ones.

Q. What Is an Example of a Compliance Risk?

Common examples in healthcare include billing and coding errors, gaps in HIPAA-required staff training, missed exclusion screening for employees or vendors, physician arrangements that have not been reviewed against the Stark Law or Anti-Kickback Statute, and vendor or business associate agreements that lack current safeguards. Each becomes a real compliance risk when there is no process in place to catch it before a regulator does.

Q. What Are Five Things a Risk Assessment Should Include?

At minimum: a documented inventory of risks by operational area, a scored likelihood and impact for each risk, a ranked priority list, an evaluation of existing controls against that list, and a mitigation plan with named owners. That is the 10-step framework above, condensed to its five core components.

Q. What Are the Seven Pillars of Compliance?

The OIG’s General Compliance Program Guidance lists seven elements every compliance program should have: written policies and procedures, compliance leadership and oversight, training and education, effective communication channels, auditing and monitoring, consistent enforcement and discipline, and prompt response to detected issues. A compliance risk assessment feeds nearly all seven, most directly auditing and monitoring, since you cannot monitor what you have not identified as a risk.


About the Author

Richard P. Kusserow established Strategic Management Services, LLC, after retiring from being the DHHS Inspector General, and has assisted over 3,000 health care organizations and entities in developing, implementing and assessing compliance programs.

Subscribe to blog