driven by structured risk-ratings that have been assigned to audit areas, after a risk assessment has been completed. Within the risk-categories used for such risk-categorization,fraud risk in included as a sub-component of operational risk, and legal exposure as part of reputational risk. The audit universe also includes an internal review of the system of governance, which the compliance function is part of