Please feel free to contact me anytime to share your thoughts.
Recently I was involved in a conversation about compliance risk assessments, and the topic of whether a law or regulation will be enforced came up. Interestingly, there seemed to be mixed opinions.
On one hand, if a law exists and it applies to an organization, it should be considered as part of the compliance risk universe for that organization. That seemed to be agreed upon by everybody. But when it came to assessing the risk, some people felt that the level of enforcement makes no difference while others felt that it does. And this is where things got interesting.