risk
Litigation, investigation and enforcement exposure
Adverse judgments, class actions, contract/IP disputes, government subpoenas, DOJ/FTC/SEC investigations, consent decrees, or deferred-prosecution agreements imposing penalties, remediation, and management distraction.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- category
- compliance_regulatory
- domain
- Compliance, Audit & Assurance
- Governance, Policy & Oversight
- taxonomy
- enterprise-risk
- coso-erm-risk
- inherent_rating
- high
Details
- risk_id
- compliance-litigation-enforcement
- category
- compliance_regulatory
- likelihood
- medium
- impact
- high
- inherent_rating
- high
- treatment
- transfer
- taxonomies
- enterprise-risk
- coso-erm-risk
Source
No record-specific source URL is provided.
Connections
- UC-GOV-14 — Establish and maintain approved security policies and procedures mitigates Litigation, investigation and enforcement exposure
- strength
- related
- rationale
- Maintaining policies required by HIPAA/PCI/regulators reduces enforcement exposure for missing governance documentation.
- UC-GOV-27 — Manage privacy complaints and account for disclosures mitigates Litigation, investigation and enforcement exposure
- strength
- primary
- rationale
- Tracking and resolving privacy complaints and accounting for disclosures satisfies data-subject rights, reducing regulatory escalation.
- UC-GOV-03 — Identify and manage legal, regulatory, and contractual obligations mitigates Litigation, investigation and enforcement exposure
- strength
- primary
- rationale
- Maintaining a current register of legal/regulatory/contractual obligations and assigning how each is met reduces enforcement and litigation exposure.
- UC-GOV-23 — Maintain contacts with authorities and special interest groups mitigates Litigation, investigation and enforcement exposure
- strength
- related
- rationale
- Maintaining authority contacts and staying abreast of regulatory expectations is a supporting relationship/awareness control, not the operative enforcement-avoidance defense.
- UC-GOV-26 — Enforce personal-data processing principles and minimization mitigates Litigation, investigation and enforcement exposure
- strength
- primary
- rationale
- Enforcing lawful, purpose-limited, minimized data processing (GDPR Art5) directly reduces data-protection enforcement exposure.
- UC-GOV-30 — Maintain asset, media, and physical protection policies mitigates Litigation, investigation and enforcement exposure
- strength
- related
- rationale
- Retention limits and secure disposal of nonpublic data reduce over-retention and legal exposure.
- UC-GOV-24 — Notify regulators of incidents and file required certifications mitigates Litigation, investigation and enforcement exposure
- strength
- primary
- rationale
- Notifying regulators within mandated timelines and filing required certifications avoids penalties for late or missing regulatory reporting.
- UC-GOV-25 — Operate a privacy program with accountable leadership mitigates Litigation, investigation and enforcement exposure
- strength
- primary
- rationale
- A privacy program that ensures and demonstrates compliance directly reduces privacy regulatory enforcement (GDPR).
- UC-AUDIT-24 — Manage compliance with external legal and regulatory requirements mitigates Litigation, investigation and enforcement exposure
- strength
- related
- rationale
- Documented compliance evaluation and remediation of non-compliance reduces exposure to enforcement actions and litigation.