Ever wonder what the risk is that you’ve wrongly assessed how you’re supposed to do risk assessments?

Sarbanes-Oxley has certainly put the concept of analyzing risks at the forefront of most compliance executives’ minds. But many companies often conflate the idea of a risk assessment under SOX (or under the U.S. Sentencing Guidelines, for that matter) with enterprise risk management. If you’re in compliance with SOX risk assessments, this thinking goes, you’re “doing ERM,” and vice-versa.

Jaclyn Jaeger is a freelance contributor to Compliance Week after working for the company for 15 years. She writes on a wide variety of topics, including ethics and compliance, risk management, legal,...