Compliance risk quantification is the practice of expressing the potential financial consequence of a compliance weakness as a dollar amount or range, so that weaknesses can be compared and remediation can be ranked. It borrows the expected-loss framing of operational risk (likelihood multiplied by impact) and sizes the impact side with the factors that authorities publish for setting penalties, such as the organizational guidelines in Chapter 8 of the US Sentencing Guidelines, the OCC civil money penalty matrix, and FinCEN's 2020 statement on enforcement. The output is a range used for prioritization, not a statement of what any authority will do.
Compliance risk quantification is the practice of expressing the potential financial consequence of a compliance weakness as a dollar figure or, more commonly, a dollar range. Its purpose is comparison: once weaknesses are stated in the same unit, management and the board can rank them, weigh remediation cost against exposure, and allocate a limited budget. It is an extension of the qualitative risk assessment, not a replacement for it. The ordinal ratings in an AML risk assessment matrix (low, moderate, high) describe relative risk; quantification attaches an order of magnitude to it.
The expected-loss framework
Quantification draws on operational risk practice. The Basel Framework defines operational risk as the risk of loss resulting from inadequate or failed internal processes, people and systems, or from external events, and states that the definition includes legal risk (Basel Framework, OPE10). Compliance failures fall within that definition. The Basel Committee's Principles for the Sound Management of Operational Risk, revised in March 2021, describe the identification and assessment tools banks use for this category of risk, including risk and control self-assessments, key risk indicators, and analysis of internal and external loss data.
The basic expression is expected loss: the likelihood that a loss event occurs over a period, multiplied by its impact if it occurs. A weakness with a moderate likelihood of producing a finding and a large potential impact may deserve more attention than one that is likely but inexpensive. In practice both terms are uncertain, so each is expressed as a range and the result is a range as well.
Components of the impact estimate
Impact is the sum of several cost categories, not only a penalty:
| Cost category | What it covers |
|---|---|
| Monetary penalties | Civil money penalties, criminal fines, and forfeitures. |
| Remediation | Lookbacks, file remediation, system changes, additional staff, and independent consultants or monitors required by an order. |
| Restitution | Amounts returned to harmed customers, most common in consumer protection matters. |
| Business restrictions | Lost revenue from growth limits, product exits, or restrictions on new customers or partners. |
| Legal and advisory costs | Outside counsel, forensic work, and response to regulatory requests. |
Remediation and business restrictions often exceed the penalty itself, which is why estimates that model only the penalty understate impact.
Published factors used to size penalties
The penalty component is sized with reference to the factors that authorities publish. These documents do not produce a fixed number for any case; they describe what is weighed.
US Sentencing Guidelines, Chapter 8
Chapter 8 of the US Sentencing Guidelines Manual governs the sentencing of organizations convicted of federal offenses. It is more arithmetic than the other frameworks described here. Under §8C2.4, the base fine is the greatest of an amount from the offense level fine table, the pecuniary gain to the organization from the offense, or the pecuniary loss caused by the organization to the extent caused intentionally, knowingly, or recklessly. Under §8C2.5, a culpability score starts at 5 points and is adjusted: points are added for involvement in or tolerance of criminal activity by high-level personnel, prior history, violation of an order, and obstruction of justice; points are subtracted for an effective compliance and ethics program (§8C2.5(f), defined in §8B2.1) and for self-reporting, cooperation, and acceptance of responsibility (§8C2.5(g)). Under §8C2.6, the culpability score maps to a minimum and a maximum multiplier, and §8C2.7 sets the guideline fine range as the base fine multiplied by each. The guidelines therefore produce a range by design.
OCC civil money penalty matrix
For national banks and federal savings associations, the OCC's Policies and Procedures Manual 5000-7, Civil Money Penalties (revised effective January 1, 2023), contains a matrix for institutions and a separate matrix for institution-affiliated parties. The matrices give effect to the four statutory factors in 12 U.S.C. 1818(i)(2)(G) (the size of financial resources and good faith of the party, the gravity of the violation, the history of previous violations, and such other matters as justice may require) and the 13 factors in the 1998 FFIEC Interagency Policy on civil money penalties. Weighted factors include intent, continuation after notification, and concealment, among others. The PPM states that the matrices are guidance, do not reduce the process to a mathematical equation, and are not a substitute for supervisory judgment.
FinCEN statement on enforcement
FinCEN's Statement on Enforcement of the Bank Secrecy Act (August 18, 2020) lists the dispositions available to FinCEN, from no action through warning letters, settlements, civil money penalties, and criminal referral, and a non-exhaustive list of factors. These include the nature and seriousness of the violations and the amounts involved, the pervasiveness of wrongdoing including management's involvement, history of similar violations, financial gain, prompt remedial action, voluntary disclosure, cooperation, the systemic nature of the violations (including number, failure rates, and duration), and whether another agency took action. Statutory maximum penalties for BSA violations are set in 31 U.S.C. 5321 and adjusted for inflation annually in 31 CFR 1010.821.
Why estimates are ranges
Every published framework above is either explicitly a range (the sentencing guidelines) or explicitly subject to judgment (the OCC matrix and FinCEN statement). Several inputs also cannot be known in advance: whether a weakness will be found, how an authority will characterize intent, how long a violation will be deemed to have run, and whether the institution will receive credit for disclosure and cooperation. A defensible estimate therefore states a low and a high value, the assumptions that drive each end, and the factors that would move the result. Presenting a single figure implies a precision the inputs do not support.
Two related distinctions are standard. Inherent exposure is estimated before controls are considered; residual exposure is estimated after credit for controls that are designed and operating. And frequency and severity are kept separate, since a weakness that affects many transactions at low value behaves differently from one that affects few transactions at high value.
Data limits
Public enforcement data is the usual reference for severity, and it has known limits. It records resolved public actions only, so matters closed without action, informal supervisory findings, and confidential supervisory information are absent. Settlement amounts reflect negotiation and the facts of individual cases, and public orders often do not break a total into its components. Penalty practice also changes over time with agency leadership and policy. Internal loss data at a single institution is usually too thin to support statistical estimates. These limits are reasons to use ranges and to document sources, not reasons to avoid quantification.
Use as a prioritization aid
A quantified range is an input to decisions about remediation order, budget, and risk acceptance. It is used together with the qualitative risk assessment, the institution's risk appetite, and legal advice. It is not a statement of what an authority will do in a given case, and it does not substitute for fixing a weakness that the law requires to be fixed regardless of its estimated cost. Within an institution, quantification is usually performed by the compliance or risk function, with input from legal and finance, and presented to senior management and the board alongside the underlying assumptions.
Primary sources
- US Sentencing Guidelines Manual, Chapter 8 (Sentencing of Organizations): Base fine (§8C2.4), culpability score (§8C2.5), multipliers (§8C2.6), fine range (§8C2.7), and effective compliance and ethics program (§8B2.1).
- OCC PPM 5000-7, Civil Money Penalties (effective January 1, 2023): The OCC's civil money penalty policy and matrices for institutions and institution-affiliated parties.
- 12 U.S.C. 1818(i)(2): Statutory civil money penalty authority for federal banking agencies, including the factors in (G).
- FinCEN, Statement on Enforcement of the Bank Secrecy Act (August 18, 2020): FinCEN's enforcement dispositions and the factors it considers.
- 31 CFR 1010.821: Inflation-adjusted civil money penalty amounts for BSA violations, including 31 U.S.C. 5321.
- Basel Framework, OPE10: Definition of operational risk, including legal risk.
- Basel Committee, Revisions to the Principles for the Sound Management of Operational Risk (March 2021): Operational risk identification and assessment tools, including key risk indicators and loss data.