D913 is Risk Management and Compliance, listed at WGU as MHA 6914 and carrying three competency units. The catalog covers risk exposure, response and mitigation together with the regulatory environment healthcare organizations operate inside. Two jobs live in that sentence. Risk management is a prioritization discipline: you cannot address everything, so you rank by likelihood and consequence and spend where the product is largest. Compliance is an evidence discipline: the requirement exists whether or not it is likely to bite, and the organization has to be able to prove it met the requirement. Aspects usually target one or the other.
Ranking versus proving
A risk section that lists twenty exposures without ordering them has not done the work. Ranking is the analysis, and it requires two judgments per item: how likely is this, and how bad is it if it happens. Both can be estimated on a simple scale with the reasoning written down. The value is not in the precision, it is in forcing a comparison, because that comparison is what tells an executive where to put money.
Compliance works differently. A requirement is not ranked away because it is unlikely to be tested. It is met, or the organization can show it tried. The scored skill is naming the requirement, the control that satisfies it, the owner of that control and the artifact that proves it happened. Policies, training records, audit logs, attestations and monitoring reports are all artifacts, and a compliance answer with no artifact in it is an intention.
Healthcare adds several risk categories that students outside the sector miss: clinical risk from patient harm, regulatory and billing risk, privacy and information security risk, workforce risk including staffing shortfalls and workplace violence, supply chain risk, and reputational risk which often follows any of the others. A submission that treats only financial and legal risk has left categories on the table that the rubric probably named.
Turning the aspects into a two part document
Your aspects sit in the Course of Study, not the catalog. Sort them into risk aspects and compliance aspects before drafting, because they call for different formats. Risk material belongs in a ranked register with prose around it. Compliance material belongs in a mapping of requirement to control to evidence.
The word budget, worked. Assume 2,100 words with ten scored aspects. Take 130 for a scope paragraph naming the organization and the boundary of the assessment, leaving 1,970, or 197 per aspect flat. Registers and mapping tables carry a lot of information without prose, so the aspects that produce a table can run at 140 words of surrounding text each. If four aspects are table backed, that releases about 230 words. Give those to the response aspects, where you explain why a particular treatment was chosen for a particular exposure, taking them to 300. The reasoning for a choice is what an evaluator can score. The table alone is data.
Build the register first and write around it. Students who draft prose first end up with a register that contradicts the paragraphs, and reconciling the two costs more than building in the right order would have.
A risk register that can be defended
Where directions supply a format, use it. Where they do not, these columns hold everything a rubric in this subject usually asks for, and they make the ranking visible instead of implied.
| Column | What it holds | Why evaluators look for it |
|---|---|---|
| Exposure | The event described as something that could happen, not as a topic | Topics cannot be ranked; events can |
| Category | Clinical, regulatory, financial, privacy, workforce, supply, reputational | Shows coverage across the organization rather than one department |
| Likelihood | A scale value with the reason for it | The reason is the analysis, the number is shorthand |
| Consequence | Harm, cost, penalty or disruption if it occurs | Forces the writer to size the event honestly |
| Current controls | What already exists to prevent or limit it | Prevents proposals that duplicate existing safeguards |
| Residual rating | Where it sits after current controls | This is the number that drives priority |
| Response | Avoid, reduce, transfer or accept, with the reason | Accepting a risk deliberately is a legitimate answer and shows judgment |
| Owner and review | Role accountable and the date it is next examined | Turns a document into a management process |
The response column is where graduate work shows. Transferring risk through insurance or contract, accepting a small exposure explicitly rather than pretending to fix it, and reducing an exposure through a control that costs less than the harm it prevents are all defensible choices, and saying which one you chose and why is the scored act.
Evidence craft in compliance writing
Compliance sections fail on specificity more than on knowledge. These habits fix most of it.
- Name the requirement and its source. Federal statute, implementing regulation, state rule, accreditation standard and payer contract term are all different kinds of obligation with different consequences.
- Pair every requirement with a control and an artifact. The artifact is what an auditor would ask to see.
- Distinguish a policy from a practice. Having a policy is not evidence of compliance, and monitoring is what closes that gap.
- Write about program elements concretely: written standards, an accountable officer, training, communication channels, auditing, enforcement, and response to detected problems.
- Handle reporting obligations carefully and accurately, since deadlines and thresholds vary by requirement and by state.
- Cite in APA at the claim, and prefer the issuing body's own material over secondary summaries.
The sentence that most improves a compliance section is the one describing what happens when a problem is found. An organization that detects, investigates, corrects and documents is in a different position from one that has never looked, and saying so demonstrates you understand what a compliance program is for.
What separates Competent from a submission sent back
The same three problems come back again and again. The unranked risk list, which fails the analysis aspects because no comparison happened. The compliance section with no artifacts, where controls are named but nothing would prove they operate. And the response that does not match the rating, such as an expensive mitigation proposed for a low residual risk while a high one is left with an existing control that clearly is not working.
Work that passes on the first read looks like a document an organization would actually keep. Exposures written as events. A visible ranking with the reasoning attached. Controls that already exist described accurately before new ones are proposed. Responses matched to ratings. Owners named by role. Requirements mapped to controls and to evidence. And a review cadence, because risk registers that are never revisited are decoration.
Performance assessment work at WGU can be revised and resubmitted without a grade penalty, so a return costs queue time inside a six month flat rate term rather than a score. In this course the cheapest insurance against a return is building the register before the prose, because most rebuild requests point at the ranking.
If a proctored objective assessment sits beside this course in your plan, our support is preparation only. We drill terminology and program elements, work practice questions and give an honest readiness call. We take no part in the assessment itself and we never ask for a portal login.
Six mistakes that cost time in D913
- Risks written as topics. Cybersecurity is a category. Ransomware encrypting the scheduling system during a weekend is an exposure you can rate.
- No existing controls described. Proposing safeguards that already exist tells an evaluator you did not examine the organization.
- Compliance without artifacts. If nothing would show an auditor that the control ran, the requirement is not demonstrably met.
- Treating acceptance as failure. Deliberately accepting a small, well understood exposure is a professional decision when it is documented.
- One category only. A register full of financial risks in a healthcare organization has missed clinical, privacy and workforce exposures.
- No owner or review date. Both are one column each and both are frequently scored.
How we work this course with you
Send the task directions and your rubric and you get a starter register scoped to your organization with categories covered, a rating scale with written criteria so your likelihood and consequence values are defensible, a requirement to control to evidence mapping for the compliance aspects, and a section plan with word counts. On review we check that every response matches its residual rating and that every compliance claim has an artifact behind it.
Questions D913 students ask
How many risks should a register contain for an assignment?
Do I need to use a specific rating scale?
Where does insurance fit into a risk response?
Building the D913 register?
Send the MHA 6914 directions. You get a scoped register, a defined rating scale and a compliance mapping back.
Where D913 sits in WGU's programs
The July 2026 catalog places this code in 1 current WGU program. Open a program page for the complete standard path and term positions. The live Degree Plan remains authoritative after transfer credit, substitutions, and mentor planning.
The assessments, one by one
The public catalog does not publish this course's PA/OA identity or task count. WGU Tutors publishes at most one PA manual per course and only from a WGU-controlled public rubric. Until that source exists, PA help begins from the student's real Course of Study and OA support remains preparation only.