D913

D913 Risk Management and Compliance help

Risk work is ranking work. Compliance work is evidence work. Write them as two disciplines and both sets of aspects get easier.

The short answer

D913 is Risk Management and Compliance, listed at WGU as MHA 6914 and carrying three competency units. The catalog covers risk exposure, response and mitigation together with the regulatory environment healthcare organizations operate inside. Two jobs live in that sentence. Risk management is a prioritization discipline: you cannot address everything, so you rank by likelihood and consequence and spend where the product is largest. Compliance is an evidence discipline: the requirement exists whether or not it is likely to bite, and the organization has to be able to prove it met the requirement. Aspects usually target one or the other.

D913 grading scale at WGU, how the work is graded, from WGU Tutors
How WGU grades D913, visualized by WGU Tutors.

Ranking versus proving

A risk section that lists twenty exposures without ordering them has not done the work. Ranking is the analysis, and it requires two judgments per item: how likely is this, and how bad is it if it happens. Both can be estimated on a simple scale with the reasoning written down. The value is not in the precision, it is in forcing a comparison, because that comparison is what tells an executive where to put money.

Compliance works differently. A requirement is not ranked away because it is unlikely to be tested. It is met, or the organization can show it tried. The scored skill is naming the requirement, the control that satisfies it, the owner of that control and the artifact that proves it happened. Policies, training records, audit logs, attestations and monitoring reports are all artifacts, and a compliance answer with no artifact in it is an intention.

Healthcare adds several risk categories that students outside the sector miss: clinical risk from patient harm, regulatory and billing risk, privacy and information security risk, workforce risk including staffing shortfalls and workplace violence, supply chain risk, and reputational risk which often follows any of the others. A submission that treats only financial and legal risk has left categories on the table that the rubric probably named.

Turning the aspects into a two part document

Your aspects sit in the Course of Study, not the catalog. Sort them into risk aspects and compliance aspects before drafting, because they call for different formats. Risk material belongs in a ranked register with prose around it. Compliance material belongs in a mapping of requirement to control to evidence.

The word budget, worked. Assume 2,100 words with ten scored aspects. Take 130 for a scope paragraph naming the organization and the boundary of the assessment, leaving 1,970, or 197 per aspect flat. Registers and mapping tables carry a lot of information without prose, so the aspects that produce a table can run at 140 words of surrounding text each. If four aspects are table backed, that releases about 230 words. Give those to the response aspects, where you explain why a particular treatment was chosen for a particular exposure, taking them to 300. The reasoning for a choice is what an evaluator can score. The table alone is data.

Build the register first and write around it. Students who draft prose first end up with a register that contradicts the paragraphs, and reconciling the two costs more than building in the right order would have.

A risk register that can be defended

Where directions supply a format, use it. Where they do not, these columns hold everything a rubric in this subject usually asks for, and they make the ranking visible instead of implied.

ColumnWhat it holdsWhy evaluators look for it
ExposureThe event described as something that could happen, not as a topicTopics cannot be ranked; events can
CategoryClinical, regulatory, financial, privacy, workforce, supply, reputationalShows coverage across the organization rather than one department
LikelihoodA scale value with the reason for itThe reason is the analysis, the number is shorthand
ConsequenceHarm, cost, penalty or disruption if it occursForces the writer to size the event honestly
Current controlsWhat already exists to prevent or limit itPrevents proposals that duplicate existing safeguards
Residual ratingWhere it sits after current controlsThis is the number that drives priority
ResponseAvoid, reduce, transfer or accept, with the reasonAccepting a risk deliberately is a legitimate answer and shows judgment
Owner and reviewRole accountable and the date it is next examinedTurns a document into a management process

The response column is where graduate work shows. Transferring risk through insurance or contract, accepting a small exposure explicitly rather than pretending to fix it, and reducing an exposure through a control that costs less than the harm it prevents are all defensible choices, and saying which one you chose and why is the scored act.

Evidence craft in compliance writing

Compliance sections fail on specificity more than on knowledge. These habits fix most of it.

  • Name the requirement and its source. Federal statute, implementing regulation, state rule, accreditation standard and payer contract term are all different kinds of obligation with different consequences.
  • Pair every requirement with a control and an artifact. The artifact is what an auditor would ask to see.
  • Distinguish a policy from a practice. Having a policy is not evidence of compliance, and monitoring is what closes that gap.
  • Write about program elements concretely: written standards, an accountable officer, training, communication channels, auditing, enforcement, and response to detected problems.
  • Handle reporting obligations carefully and accurately, since deadlines and thresholds vary by requirement and by state.
  • Cite in APA at the claim, and prefer the issuing body's own material over secondary summaries.

The sentence that most improves a compliance section is the one describing what happens when a problem is found. An organization that detects, investigates, corrects and documents is in a different position from one that has never looked, and saying so demonstrates you understand what a compliance program is for.

What separates Competent from a submission sent back

The same three problems come back again and again. The unranked risk list, which fails the analysis aspects because no comparison happened. The compliance section with no artifacts, where controls are named but nothing would prove they operate. And the response that does not match the rating, such as an expensive mitigation proposed for a low residual risk while a high one is left with an existing control that clearly is not working.

Work that passes on the first read looks like a document an organization would actually keep. Exposures written as events. A visible ranking with the reasoning attached. Controls that already exist described accurately before new ones are proposed. Responses matched to ratings. Owners named by role. Requirements mapped to controls and to evidence. And a review cadence, because risk registers that are never revisited are decoration.

Performance assessment work at WGU can be revised and resubmitted without a grade penalty, so a return costs queue time inside a six month flat rate term rather than a score. In this course the cheapest insurance against a return is building the register before the prose, because most rebuild requests point at the ranking.

If a proctored objective assessment sits beside this course in your plan, our support is preparation only. We drill terminology and program elements, work practice questions and give an honest readiness call. We take no part in the assessment itself and we never ask for a portal login.

Six mistakes that cost time in D913

  • Risks written as topics. Cybersecurity is a category. Ransomware encrypting the scheduling system during a weekend is an exposure you can rate.
  • No existing controls described. Proposing safeguards that already exist tells an evaluator you did not examine the organization.
  • Compliance without artifacts. If nothing would show an auditor that the control ran, the requirement is not demonstrably met.
  • Treating acceptance as failure. Deliberately accepting a small, well understood exposure is a professional decision when it is documented.
  • One category only. A register full of financial risks in a healthcare organization has missed clinical, privacy and workforce exposures.
  • No owner or review date. Both are one column each and both are frequently scored.

How we work this course with you

Send the task directions and your rubric and you get a starter register scoped to your organization with categories covered, a rating scale with written criteria so your likelihood and consequence values are defensible, a requirement to control to evidence mapping for the compliance aspects, and a section plan with word counts. On review we check that every response matches its residual rating and that every compliance claim has an artifact behind it.

Questions D913 students ask

How many risks should a register contain for an assignment?
Fewer than students expect, analyzed properly. Eight to twelve well specified exposures spread across categories will demonstrate more than thirty one line entries, because the scored material is the reasoning behind each rating and the fit between rating and response. If your directions specify a number, use theirs. Otherwise aim for enough to show coverage of the organization and few enough that you can write a real likelihood rationale for each one without running out of words.
Do I need to use a specific rating scale?
Any defensible scale works as long as you define it. A five point scale for likelihood and a five point scale for consequence, each with written descriptions of what a given value means, is enough. The definitions are what matter: a likelihood of four should mean something concrete such as expected at least once a year based on internal history or sector reporting. Undefined scales are the reason risk sections read as arbitrary, and defining them takes about a hundred words.
Where does insurance fit into a risk response?
Insurance is a transfer response and it is worth writing about precisely, because students often treat it as though it removes risk. It converts an uncertain large loss into a predictable premium, and it typically leaves substantial parts of the exposure with the organization: the deductible, the disruption, the reputational effect and anything the policy excludes. A strong paragraph says what the coverage does and does not move, and pairs the transfer with a reduction control so the underlying exposure still gets addressed.

Building the D913 register?

Send the MHA 6914 directions. You get a scoped register, a defined rating scale and a compliance mapping back.

Where D913 sits in WGU's programs

The July 2026 catalog places this code in 1 current WGU program. Open a program page for the complete standard path and term positions. The live Degree Plan remains authoritative after transfer credit, substitutions, and mentor planning.

The assessments, one by one

The public catalog does not publish this course's PA/OA identity or task count. WGU Tutors publishes at most one PA manual per course and only from a WGU-controlled public rubric. Until that source exists, PA help begins from the student's real Course of Study and OA support remains preparation only.

Keep going

Online now