TrustviewSample report
This is a sample report for a fictional organisation, using illustrative data. Your own report is generated from your assessment responses.

Risk Maturity Assessment

Demo Mutual Assurance (Pty) Ltd

Assessment Report

OrganisationDemo Mutual Assurance (Pty) Ltd
CountryEswatini
IndustryInsurance
Assessment typeSelf-assessment (sample)
Assessment date6 August 2026
ReferenceRMA/SAMPLE/000
Report version1.0

This report reflects a self-assessment completed by the respondent and has not been independently validated by Trustview Business Consultants.

Confidential, prepared for the named organisation only. Not for distribution without Trustview's written consent.

Prepared by Trustview Business Consultants

Trusted and Dependable Business Solutions

1. Board snapshot

1. Overall position
1352.5OUT OF 5.0Developing

Developing

Developing / progressing towards Established

Target: Level 4 (your target) · Gap: 1.5

2. Performance by domain

Risk Governance & Oversight

3.0

Strategy, Risk Appetite & Decision-Making

2.0

Framework, Policy & Resources

3.0

Risk Management Process

2.0

Risk Culture & Capability

1.0

Monitoring, Review & Improvement

2.0

Risk Information, Communication & Reporting

3.0

Compliance & Regulatory Alignment

4.0

3. Action status
0–3 MONTHSHigh priority
24
3–9 MONTHSMedium priority
0
9–12+ MONTHSLower priority
0

Total actions

24

KEY PRIORITY: Strengthen Risk Culture & Capability (1.0) to close the maturity gap and move towards Level 4.

Board conclusion

Risk maturity is Developing (2.5), 1.5 below the target. Priority attention is needed in Risk Culture & Capability. 24 immediate actions are recommended.

2. Executive summary

Overall conclusion

Demo Mutual Assurance (Pty) Ltd is at Level 2, Developing (2.5). The overall maturity index of 2.5 is 1.5 below your target of Level 4. These results are an estimated indication, not an absolute or audited measure.

Key strengths

  • Compliance & Regulatory Alignment (4.0)

Priority concerns

  • Risk Culture & Capability (1.0)
  • Strategy, Risk Appetite & Decision-Making (2.0)
  • Risk Management Process (2.0)
  • Monitoring, Review & Improvement (2.0)

Regulatory exposure

Maturity is below target in Risk Governance & Oversight, Strategy, Risk Appetite & Decision-Making, Framework, Policy & Resources, Risk Management Process, Risk Culture & Capability, Monitoring, Review & Improvement, Risk Information, Communication & Reporting, areas subject to Critical regulatory obligations. The organisation may be exposed from a regulatory perspective until these gaps are closed.

Immediate management focus

  • Redesign board risk reporting to shift from a descriptive risk list to a decision-useful report that highlights what has changed since the last meeting, which risks are approaching or have breached appetite thresholds, and what management is doing in response. Implement the new format for the next two board cycles and refine based on feedback.
  • Develop a formal risk appetite statement with defined tolerance thresholds for the organisation's principal risk categories (financial, operational, regulatory, reputational). Present it to the board for approval as a standalone document, not embedded in the risk policy. Link the thresholds explicitly to strategic objectives.
  • Establish a defined risk assessment cycle: all business units must complete a full risk assessment (identification, analysis, evaluation, treatment plan update) at least annually, with the risk register updated in between for material changes. The risk function should facilitate and review assessments for quality and consistency before they are finalised.
  • The chief executive or equivalent should make a written statement of personal commitment to risk management, to be communicated to all staff, included in the next town hall or all-staff meeting, and referenced in the organisation's next available external communication (annual report, website, stakeholder update). The statement should be specific, not generic.

Points to verify, possible inconsistencies

The responses produced some combinations that are unusual in practice. They do not change the scores, but they should be checked in case any answer was captured incorrectly.

  • Compliance & Regulatory Alignment (4.0) is rated well above Risk Culture & Capability (1.0). A high Compliance & Regulatory Alignment rating is difficult to sustain without comparable maturity in Risk Culture & Capability; please verify these responses for a possible inconsistency.
  • Compliance & Regulatory Alignment is rated Sound (4.0) while overall maturity (2.5) is below the regulated-entity minimum. This combination is unusual and may indicate inconsistent responses; please review.

3. Maturity dashboard

2.5out of 5

Gold tick marks the target (Level 4).

Risk Governance & Oversight3.0
Strategy, Risk Appetite & Decision-Making2.0
Framework, Policy & Resources3.0
Risk Management Process2.0
Risk Culture & Capability1.0
Monitoring, Review & Improvement2.0
Risk Information, Communication & Reporting3.0
Compliance & Regulatory Alignment4.0

Bars show the current domain score; the gold line marks the target (Level 4). RAG: Priority attention below 2.5, Developing 2.5 to 3.4, Sound 3.5 and above.

4. Domain maturity heatmap

DomainScoreTargetGapRatingStatus
Risk Governance & Oversight3.041.0DevelopingBelow target
Strategy, Risk Appetite & Decision-Making2.042.0Priority attentionBelow target
Framework, Policy & Resources3.041.0DevelopingBelow target
Risk Management Process2.042.0Priority attentionBelow target
Risk Culture & Capability1.043.0Priority attentionBelow target
Monitoring, Review & Improvement2.042.0Priority attentionBelow target
Risk Information, Communication & Reporting3.041.0DevelopingBelow target
Compliance & Regulatory Alignment4.04MetSoundOn / above target

5. Current vs target maturity

D1D2D3D4D5D6D7D8
CurrentTarget
CodeDomainCurrentTarget
D1Risk Governance & Oversight3.04
D2Strategy, Risk Appetite & Decision-Making2.04
D3Framework, Policy & Resources3.04
D4Risk Management Process2.04
D5Risk Culture & Capability1.04
D6Monitoring, Review & Improvement2.04
D7Risk Information, Communication & Reporting3.04
D8Compliance & Regulatory Alignment4.04

6. Key findings

Finding 1

Observation
Risk Culture & Capability is at Level 1 (1.0), 3.0 below the target of Level 4.
Impact
Heightened regulatory exposure: Risk Culture & Capability carries Critical regulatory criticality for this profile, and current maturity is below the expected standard.
Recommended response
The chief executive or equivalent should make a written statement of personal commitment to risk management, to be communicated to all staff, included in the next town hall or all-staff meeting, and referenced in the organisation's next available external communication (annual report, website, stakeholder update). The statement should be specific, not generic.

Finding 2

Observation
Strategy, Risk Appetite & Decision-Making is at Level 2 (2.0), 2.0 below the target of Level 4.
Impact
Heightened regulatory exposure: Strategy, Risk Appetite & Decision-Making carries Critical regulatory criticality for this profile, and current maturity is below the expected standard.
Recommended response
Develop a formal risk appetite statement with defined tolerance thresholds for the organisation's principal risk categories (financial, operational, regulatory, reputational). Present it to the board for approval as a standalone document, not embedded in the risk policy. Link the thresholds explicitly to strategic objectives.

Finding 3

Observation
Risk Management Process is at Level 2 (2.0), 2.0 below the target of Level 4.
Impact
Heightened regulatory exposure: Risk Management Process carries Critical regulatory criticality for this profile, and current maturity is below the expected standard.
Recommended response
Establish a defined risk assessment cycle: all business units must complete a full risk assessment (identification, analysis, evaluation, treatment plan update) at least annually, with the risk register updated in between for material changes. The risk function should facilitate and review assessments for quality and consistency before they are finalised.

Finding 4

Observation
Monitoring, Review & Improvement is at Level 2 (2.0), 2.0 below the target of Level 4.
Impact
Heightened regulatory exposure: Monitoring, Review & Improvement carries Critical regulatory criticality for this profile, and current maturity is below the expected standard.
Recommended response
Define formal KRIs for each of the organisation's principal risks: for each KRI, specify the data source, measurement frequency, amber threshold (early warning) and red threshold (escalation required). Have KRIs approved by the risk committee and incorporate them into the quarterly risk report.

Finding 5

Observation
Risk Governance & Oversight is at Level 3 (3.0), 1.0 below the target of Level 4.
Impact
Heightened regulatory exposure: Risk Governance & Oversight carries Critical regulatory criticality for this profile, and current maturity is below the expected standard.
Recommended response
Redesign board risk reporting to shift from a descriptive risk list to a decision-useful report that highlights what has changed since the last meeting, which risks are approaching or have breached appetite thresholds, and what management is doing in response. Implement the new format for the next two board cycles and refine based on feedback.

7. Prioritised improvement roadmap

Stabilise · 0-3 months

Redesign board risk reporting to shift from a descriptive risk list to a decision-useful report that highlights what has changed since the last meeting, which risks are approaching or have breached appetite thresholds, and what management is doing in response. Implement the new format for the next two board cycles and refine based on feedback.

Domain: Risk Governance & OversightMovement: Level 3 to 4Priority: 3.0Criticality: CriticalOwner: Board / Risk Committee

Develop a formal risk appetite statement with defined tolerance thresholds for the organisation's principal risk categories (financial, operational, regulatory, reputational). Present it to the board for approval as a standalone document, not embedded in the risk policy. Link the thresholds explicitly to strategic objectives.

Domain: Strategy, Risk Appetite & Decision-MakingMovement: Level 2 to 3Priority: 3.0Criticality: CriticalOwner: Executive Committee / CEO

Establish a defined risk assessment cycle: all business units must complete a full risk assessment (identification, analysis, evaluation, treatment plan update) at least annually, with the risk register updated in between for material changes. The risk function should facilitate and review assessments for quality and consistency before they are finalised.

Domain: Risk Management ProcessMovement: Level 2 to 3Priority: 3.0Criticality: CriticalOwner: Risk Manager / Risk Function

The chief executive or equivalent should make a written statement of personal commitment to risk management, to be communicated to all staff, included in the next town hall or all-staff meeting, and referenced in the organisation's next available external communication (annual report, website, stakeholder update). The statement should be specific, not generic.

Domain: Risk Culture & CapabilityMovement: Level 1 to 2Priority: 3.0Criticality: CriticalOwner: CEO / HR & Risk Function

Define formal KRIs for each of the organisation's principal risks: for each KRI, specify the data source, measurement frequency, amber threshold (early warning) and red threshold (escalation required). Have KRIs approved by the risk committee and incorporate them into the quarterly risk report.

Domain: Monitoring, Review & ImprovementMovement: Level 2 to 3Priority: 3.0Criticality: CriticalOwner: Risk Manager / Internal Audit

Conduct an annual risk committee effectiveness review: assess whether the committee's composition, frequency, information quality and interaction with management are delivering effective oversight. Present findings and improvement actions to the full board. Consider using an established governance assessment framework or external facilitator for the first review.

Domain: Risk Governance & OversightMovement: Level 3 to 4Priority: 2.4Criticality: CriticalOwner: Board / Risk Committee

Expand the risk committee's oversight mandate to explicitly include strategic, emerging and conduct risks, not only operational risk register items. Add a standing agenda item for horizon risk (what is emerging in the external environment that could affect strategy in the next one to three years) and a periodic conduct risk review.

Domain: Risk Governance & OversightMovement: Level 3 to 4Priority: 2.4Criticality: CriticalOwner: Board / Risk Committee

Formalise the annual strategic planning process to include a risk assessment step: the risk function should be involved in strategy development, not only consulted after the strategy is set. Introduce a risk register of strategic risks that is maintained alongside the operational risk register.

Domain: Strategy, Risk Appetite & Decision-MakingMovement: Level 2 to 3Priority: 2.4Criticality: CriticalOwner: Executive Committee / CEO

Embed a risk assessment requirement in the business case or decision paper template for all decisions above defined approval thresholds. The template should require proposers to state the principal risks, the residual risk after proposed mitigations, and whether the risk falls within the board-approved appetite.

Domain: Strategy, Risk Appetite & Decision-MakingMovement: Level 2 to 3Priority: 2.4Criticality: CriticalOwner: Executive Committee / CEO

Evaluate and implement a risk management technology solution appropriate to the organisation's size and complexity: this could range from a structured GRC system for larger organisations to a well-architected SharePoint-based risk register for smaller ones. The key requirements are: single system of record, audit trail, access controls, and the ability to produce consistent reports.

Domain: Framework, Policy & ResourcesMovement: Level 3 to 4Priority: 2.4Criticality: CriticalOwner: Chief Risk Officer / Risk Manager

Conduct annual risk resource benchmarking against peer organisations: compare the risk function's size, qualifications, budget and tools against available industry data or regulatory expectations. Use findings to make an evidence-based case for resource investments or to confirm adequacy.

Domain: Framework, Policy & ResourcesMovement: Level 3 to 4Priority: 2.4Criticality: CriticalOwner: Chief Risk Officer / Risk Manager

Integrate the risk framework into all major governance processes: reference it explicitly in the board charter, all committee terms of reference, the internal audit charter, HR policies (performance management) and the strategic planning process. The framework should be the thread connecting all governance activities, not a standalone risk document.

Domain: Framework, Policy & ResourcesMovement: Level 3 to 4Priority: 2.4Criticality: CriticalOwner: Chief Risk Officer / Risk Manager

Establish a root-cause analysis standard: define the methodology to be used (e.g. 5-Whys, fishbone/Ishikawa, fault tree analysis), train relevant managers in its use, and make completion of a root-cause analysis mandatory for all incidents meeting defined significance criteria. Record findings in the incident log and track corrective actions.

Domain: Risk Management ProcessMovement: Level 2 to 3Priority: 2.4Criticality: CriticalOwner: Risk Manager / Risk Function

Introduce an emerging risk review as a standing item in the annual risk assessment cycle: at least once a year, facilitate a management discussion on what is changing in the external environment (regulatory, technological, economic, geopolitical) that could create new risks or alter the profile of existing ones. Document findings and update the risk register.

Domain: Risk Management ProcessMovement: Level 2 to 3Priority: 2.4Criticality: CriticalOwner: Risk Manager / Risk Function

Establish a basic risk training module for all staff, a one to two hour session covering what risk management means for the organisation, why it matters, the individual's role in managing risk, and how to report a risk concern. Deliver the training within the next 90 days and track completion.

Domain: Risk Culture & CapabilityMovement: Level 1 to 2Priority: 2.4Criticality: CriticalOwner: CEO / HR & Risk Function

Establish an escalation channel: define (in writing) how staff can raise risk concerns, near-misses or potential compliance issues. This need not be a sophisticated whistleblower programme at this stage, a named contact (the risk officer), a documented process and a clear statement that concerns will be taken seriously and that the raiser will not face adverse consequences.

Domain: Risk Culture & CapabilityMovement: Level 1 to 2Priority: 2.4Criticality: CriticalOwner: CEO / HR & Risk Function

Implement a combined assurance approach: map which risks and controls are covered by first-line self-assessment, second-line risk function review, and third-line internal audit. Identify gaps (risks or controls with no assurance coverage) and agree with the risk committee how to address them within the current year.

Domain: Monitoring, Review & ImprovementMovement: Level 2 to 3Priority: 2.4Criticality: CriticalOwner: Risk Manager / Internal Audit

Conduct a lessons-learned review of all significant incidents from the past two years: identify whether root causes were addressed, whether the same incident types have recurred, and what systemic patterns exist. Present findings to management with a time-bound improvement plan addressing the most significant systemic gaps.

Domain: Monitoring, Review & ImprovementMovement: Level 2 to 3Priority: 2.4Criticality: CriticalOwner: Risk Manager / Internal Audit

Redesign board and management risk reports to be decision-useful rather than descriptive: shift from listing risks to highlighting what has changed, what is approaching an appetite threshold, what management is doing about it, and what the board's attention or decision is required on. Pilot the new format with the risk committee and refine based on feedback before full implementation.

Domain: Risk Information, Communication & ReportingMovement: Level 3 to 4Priority: 2.4Criticality: CriticalOwner: Chief Risk Officer / Risk Function

Implement a GRC (governance, risk and compliance) system or an equivalent structured risk information platform that serves as the single system of record for risk data, provides access controls and audit trail, enables automated reporting, and integrates risk, compliance and assurance data. Develop a user adoption plan to ensure the system is actively used by risk owners.

Domain: Risk Information, Communication & ReportingMovement: Level 3 to 4Priority: 2.4Criticality: CriticalOwner: Chief Risk Officer / Risk Function

Formally assure risk data quality: establish a data quality review process that is conducted before each major reporting cycle, defines quality metrics (completeness, accuracy, timeliness), reports quality findings to the risk function management, and tracks quality improvement over time. Present data quality trends to the risk committee annually.

Domain: Risk Information, Communication & ReportingMovement: Level 3 to 4Priority: 2.4Criticality: CriticalOwner: Chief Risk Officer / Risk Function

Automate compliance monitoring for key controls: implement technology-enabled monitoring (e.g. transaction monitoring for AML/CFT, automated data quality checks for regulatory reporting, automated access control reviews for data protection) that provides real-time or near-real-time compliance status and alerts for potential breaches.

Domain: Compliance & Regulatory AlignmentMovement: Level 4 to 5Priority: 2.4Criticality: CriticalOwner: Compliance Officer

Become a recognised contributor to regulatory dialogue: respond formally to regulatory consultation papers in the organisation's sector; contribute to industry body working groups developing regulatory standards; present at regulatory forums. Position the organisation's compliance expertise as a public good as well as a competitive asset.

Domain: Compliance & Regulatory AlignmentMovement: Level 4 to 5Priority: 2.4Criticality: CriticalOwner: Compliance Officer

Use ethical compliance as a market differentiator: document the organisation's compliance standards and ethical commitments, publish them in client-facing materials and tenders, and demonstrate compliance strength through independent assurance (third-party audits, regulatory commendations, industry certifications). Market compliance excellence as a client benefit.

Domain: Compliance & Regulatory AlignmentMovement: Level 4 to 5Priority: 2.4Criticality: CriticalOwner: Compliance Officer

8. Detailed domain analysis

Risk Governance & Oversight

Developing
Score: 3.0Target: 4Gap: 1.0

What this means

Board-approved risk policy and framework aligned to ISO 31000. A functioning risk committee (board or executive level) with a charter meets at least quarterly. A designated risk function with a defined mandate and reporting line. Three-lines responsibilities documented and broadly understood.

Recommended next steps

  • Redesign board risk reporting to shift from a descriptive risk list to a decision-useful report that highlights what has changed since the last meeting, which risks are approaching or have breached appetite thresholds, and what management is doing in response. Implement the new format for the next two board cycles and refine based on feedback.
  • Conduct an annual risk committee effectiveness review: assess whether the committee's composition, frequency, information quality and interaction with management are delivering effective oversight. Present findings and improvement actions to the full board. Consider using an established governance assessment framework or external facilitator for the first review.
  • Expand the risk committee's oversight mandate to explicitly include strategic, emerging and conduct risks, not only operational risk register items. Add a standing agenda item for horizon risk (what is emerging in the external environment that could affect strategy in the next one to three years) and a periodic conduct risk review.

Strategy, Risk Appetite & Decision-Making

Priority attention
Score: 2.0Target: 4Gap: 2.0

What this means

A broad risk appetite statement exists in policy but is not operationalised. Risk is considered informally in some decisions but without a consistent framework. Tolerance thresholds are undefined or untested.

Recommended next steps

  • Develop a formal risk appetite statement with defined tolerance thresholds for the organisation's principal risk categories (financial, operational, regulatory, reputational). Present it to the board for approval as a standalone document, not embedded in the risk policy. Link the thresholds explicitly to strategic objectives.
  • Formalise the annual strategic planning process to include a risk assessment step: the risk function should be involved in strategy development, not only consulted after the strategy is set. Introduce a risk register of strategic risks that is maintained alongside the operational risk register.
  • Embed a risk assessment requirement in the business case or decision paper template for all decisions above defined approval thresholds. The template should require proposers to state the principal risks, the residual risk after proposed mitigations, and whether the risk falls within the board-approved appetite.

Framework, Policy & Resources

Developing
Score: 3.0Target: 4Gap: 1.0

What this means

A documented framework aligned to ISO 31000 is in place and reviewed at least every two years. Common risk taxonomy, definitions and procedures are established and communicated. Dedicated risk resources with appropriate skills are in place; budget is allocated.

Recommended next steps

  • Evaluate and implement a risk management technology solution appropriate to the organisation's size and complexity: this could range from a structured GRC system for larger organisations to a well-architected SharePoint-based risk register for smaller ones. The key requirements are: single system of record, audit trail, access controls, and the ability to produce consistent reports.
  • Conduct annual risk resource benchmarking against peer organisations: compare the risk function's size, qualifications, budget and tools against available industry data or regulatory expectations. Use findings to make an evidence-based case for resource investments or to confirm adequacy.
  • Integrate the risk framework into all major governance processes: reference it explicitly in the board charter, all committee terms of reference, the internal audit charter, HR policies (performance management) and the strategic planning process. The framework should be the thread connecting all governance activities, not a standalone risk document.

Risk Management Process

Priority attention
Score: 2.0Target: 4Gap: 2.0

What this means

Risk assessments occur periodically (often annually) using basic likelihood/impact matrices. A risk register exists but may be static and owned by the risk function alone. Treatment plans exist for some risks. Root-cause analysis is applied inconsistently after significant incidents.

Recommended next steps

  • Establish a defined risk assessment cycle: all business units must complete a full risk assessment (identification, analysis, evaluation, treatment plan update) at least annually, with the risk register updated in between for material changes. The risk function should facilitate and review assessments for quality and consistency before they are finalised.
  • Establish a root-cause analysis standard: define the methodology to be used (e.g. 5-Whys, fishbone/Ishikawa, fault tree analysis), train relevant managers in its use, and make completion of a root-cause analysis mandatory for all incidents meeting defined significance criteria. Record findings in the incident log and track corrective actions.
  • Introduce an emerging risk review as a standing item in the annual risk assessment cycle: at least once a year, facilitate a management discussion on what is changing in the external environment (regulatory, technological, economic, geopolitical) that could create new risks or alter the profile of existing ones. Document findings and update the risk register.

Risk Culture & Capability

Priority attention
Score: 1.0Target: 4Gap: 3.0

What this means

Risk culture is absent or counterproductive: bad news is suppressed, accountability is avoided, and risk is seen as the risk function's problem alone. No risk training or awareness programme. Incentives do not consider risk behaviour.

Recommended next steps

  • The chief executive or equivalent should make a written statement of personal commitment to risk management, to be communicated to all staff, included in the next town hall or all-staff meeting, and referenced in the organisation's next available external communication (annual report, website, stakeholder update). The statement should be specific, not generic.
  • Establish a basic risk training module for all staff, a one to two hour session covering what risk management means for the organisation, why it matters, the individual's role in managing risk, and how to report a risk concern. Deliver the training within the next 90 days and track completion.
  • Establish an escalation channel: define (in writing) how staff can raise risk concerns, near-misses or potential compliance issues. This need not be a sophisticated whistleblower programme at this stage, a named contact (the risk officer), a documented process and a clear statement that concerns will be taken seriously and that the raiser will not face adverse consequences.

Monitoring, Review & Improvement

Priority attention
Score: 2.0Target: 4Gap: 2.0

What this means

Some monitoring of top risks exists but is inconsistent and largely manual. Incident recording is ad hoc; lessons learned are not systematically captured. Framework review occurs infrequently and is driven by external events rather than planned cadence.

Recommended next steps

  • Define formal KRIs for each of the organisation's principal risks: for each KRI, specify the data source, measurement frequency, amber threshold (early warning) and red threshold (escalation required). Have KRIs approved by the risk committee and incorporate them into the quarterly risk report.
  • Implement a combined assurance approach: map which risks and controls are covered by first-line self-assessment, second-line risk function review, and third-line internal audit. Identify gaps (risks or controls with no assurance coverage) and agree with the risk committee how to address them within the current year.
  • Conduct a lessons-learned review of all significant incidents from the past two years: identify whether root causes were addressed, whether the same incident types have recurred, and what systemic patterns exist. Present findings to management with a time-bound improvement plan addressing the most significant systemic gaps.

Risk Information, Communication & Reporting

Developing
Score: 3.0Target: 4Gap: 1.0

What this means

Structured risk reports are produced for management (monthly or quarterly) and the board (quarterly minimum) using a consistent format. A maintained risk register is accessible to relevant stakeholders. Regulatory reporting obligations are met on time. Data quality is considered in reporting.

Recommended next steps

  • Redesign board and management risk reports to be decision-useful rather than descriptive: shift from listing risks to highlighting what has changed, what is approaching an appetite threshold, what management is doing about it, and what the board's attention or decision is required on. Pilot the new format with the risk committee and refine based on feedback before full implementation.
  • Implement a GRC (governance, risk and compliance) system or an equivalent structured risk information platform that serves as the single system of record for risk data, provides access controls and audit trail, enables automated reporting, and integrates risk, compliance and assurance data. Develop a user adoption plan to ensure the system is actively used by risk owners.
  • Formally assure risk data quality: establish a data quality review process that is conducted before each major reporting cycle, defines quality metrics (completeness, accuracy, timeliness), reports quality findings to the risk function management, and tracks quality improvement over time. Present data quality trends to the risk committee annually.

Compliance & Regulatory Alignment

Sound
Score: 4.0Target: 4Gap: Met

What this means

Compliance risk management is integrated with operational risk. The obligations register is maintained in near-real-time as regulations change. Regulatory relationships are proactive: the organisation engages with regulators on policy developments. Compliance risk appetite is defined.

Recommended next steps

  • Automate compliance monitoring for key controls: implement technology-enabled monitoring (e.g. transaction monitoring for AML/CFT, automated data quality checks for regulatory reporting, automated access control reviews for data protection) that provides real-time or near-real-time compliance status and alerts for potential breaches.
  • Become a recognised contributor to regulatory dialogue: respond formally to regulatory consultation papers in the organisation's sector; contribute to industry body working groups developing regulatory standards; present at regulatory forums. Position the organisation's compliance expertise as a public good as well as a competitive asset.
  • Use ethical compliance as a market differentiator: document the organisation's compliance standards and ethical commitments, publish them in client-facing materials and tenders, and demonstrate compliance strength through independent assurance (third-party audits, regulatory commendations, industry certifications). Market compliance excellence as a client benefit.

9. Regulatory compliance matrix

RegulationRegulatorCriticalityApplicabilityRisk implicationRecommended response
Financial Services Regulatory Authority Act, 2010Financial Services Regulatory Authority (FSRA)CriticalInsuranceRelevant to: Risk Governance & Oversight, Strategy, Risk Appetite & Decision-Making, Framework, Policy & Resources, Risk Information, Communication & Reporting, Compliance & Regulatory AlignmentEnsure full compliance now; board-level oversight and independent assurance.
Money Laundering and Financing of Terrorism Prevention Act, 2011 (as amended by the 2016 Amendment Act and the Anti-Money Laundering, Counter Financing of Terrorism and Proliferation Financing (Miscellaneous Amendments) Act, 2024)Eswatini Financial Intelligence Unit (EFIU); FSRA for non-bank FSPsCriticalInsuranceRelevant to: Risk Governance & Oversight, Framework, Policy & Resources, Risk Management Process, Risk Culture & Capability, Compliance & Regulatory AlignmentEnsure full compliance now; board-level oversight and independent assurance.
Insurance Act, 2005 and Retirement Funds Act, 2005Financial Services Regulatory Authority (FSRA)CriticalInsuranceRelevant to: Risk Governance & Oversight, Strategy, Risk Appetite & Decision-Making, Framework, Policy & Resources, Risk Information, Communication & Reporting, Compliance & Regulatory AlignmentEnsure full compliance now; board-level oversight and independent assurance.
Companies Act, 2009Registrar of Companies / Ministry of Commerce, Industry and TradeHighInsuranceRelevant to: Risk Governance & Oversight, Strategy, Risk Appetite & Decision-Making, Compliance & Regulatory AlignmentMaintain compliance; obtain periodic independent assurance.
Data Protection Act, 2022 (Act No. 5 of 2022)Eswatini Data Protection CommissionCriticalInsuranceRelevant to: Framework, Policy & Resources, Risk Management Process, Risk Information, Communication & Reporting, Compliance & Regulatory AlignmentEnsure full compliance now; board-level oversight and independent assurance.
Occupational Safety and Health Act, 2001Ministry of Labour and Social SecurityModerateInsuranceRelevant to: Framework, Policy & Resources, Risk Management Process, Monitoring, Review & Improvement, Compliance & Regulatory AlignmentMonitor and close any gaps through management review.
Computer Crime and Cybercrime Act, 2022 (Act No. 6 of 2022)Eswatini Communications Commission (ESCCOM); National Cybersecurity Advisory CouncilCriticalInsuranceRelevant to: Framework, Policy & Resources, Risk Management Process, Monitoring, Review & Improvement, Risk Information, Communication & Reporting, Compliance & Regulatory AlignmentEnsure full compliance now; board-level oversight and independent assurance.

Criticality is an estimated indication of regulatory exposure for this profile, not a legal determination.

10. Management action plan

RefActionOwnerPriorityTimelineStatus
A1Redesign board risk reporting to shift from a descriptive risk list to a decision-useful report that highlights what has changed since the last meeting, which risks are approaching or have breached appetite thresholds, and what management is doing in response. Implement the new format for the next two board cycles and refine based on feedback.Board / Risk Committee3.00-3 monthsNot started
A2Develop a formal risk appetite statement with defined tolerance thresholds for the organisation's principal risk categories (financial, operational, regulatory, reputational). Present it to the board for approval as a standalone document, not embedded in the risk policy. Link the thresholds explicitly to strategic objectives.Executive Committee / CEO3.00-3 monthsNot started
A3Establish a defined risk assessment cycle: all business units must complete a full risk assessment (identification, analysis, evaluation, treatment plan update) at least annually, with the risk register updated in between for material changes. The risk function should facilitate and review assessments for quality and consistency before they are finalised.Risk Manager / Risk Function3.00-3 monthsNot started
A4The chief executive or equivalent should make a written statement of personal commitment to risk management, to be communicated to all staff, included in the next town hall or all-staff meeting, and referenced in the organisation's next available external communication (annual report, website, stakeholder update). The statement should be specific, not generic.CEO / HR & Risk Function3.00-3 monthsNot started
A5Define formal KRIs for each of the organisation's principal risks: for each KRI, specify the data source, measurement frequency, amber threshold (early warning) and red threshold (escalation required). Have KRIs approved by the risk committee and incorporate them into the quarterly risk report.Risk Manager / Internal Audit3.00-3 monthsNot started
A6Conduct an annual risk committee effectiveness review: assess whether the committee's composition, frequency, information quality and interaction with management are delivering effective oversight. Present findings and improvement actions to the full board. Consider using an established governance assessment framework or external facilitator for the first review.Board / Risk Committee2.40-3 monthsNot started
A7Expand the risk committee's oversight mandate to explicitly include strategic, emerging and conduct risks, not only operational risk register items. Add a standing agenda item for horizon risk (what is emerging in the external environment that could affect strategy in the next one to three years) and a periodic conduct risk review.Board / Risk Committee2.40-3 monthsNot started
A8Formalise the annual strategic planning process to include a risk assessment step: the risk function should be involved in strategy development, not only consulted after the strategy is set. Introduce a risk register of strategic risks that is maintained alongside the operational risk register.Executive Committee / CEO2.40-3 monthsNot started
A9Embed a risk assessment requirement in the business case or decision paper template for all decisions above defined approval thresholds. The template should require proposers to state the principal risks, the residual risk after proposed mitigations, and whether the risk falls within the board-approved appetite.Executive Committee / CEO2.40-3 monthsNot started
A10Evaluate and implement a risk management technology solution appropriate to the organisation's size and complexity: this could range from a structured GRC system for larger organisations to a well-architected SharePoint-based risk register for smaller ones. The key requirements are: single system of record, audit trail, access controls, and the ability to produce consistent reports.Chief Risk Officer / Risk Manager2.40-3 monthsNot started
A11Conduct annual risk resource benchmarking against peer organisations: compare the risk function's size, qualifications, budget and tools against available industry data or regulatory expectations. Use findings to make an evidence-based case for resource investments or to confirm adequacy.Chief Risk Officer / Risk Manager2.40-3 monthsNot started
A12Integrate the risk framework into all major governance processes: reference it explicitly in the board charter, all committee terms of reference, the internal audit charter, HR policies (performance management) and the strategic planning process. The framework should be the thread connecting all governance activities, not a standalone risk document.Chief Risk Officer / Risk Manager2.40-3 monthsNot started
A13Establish a root-cause analysis standard: define the methodology to be used (e.g. 5-Whys, fishbone/Ishikawa, fault tree analysis), train relevant managers in its use, and make completion of a root-cause analysis mandatory for all incidents meeting defined significance criteria. Record findings in the incident log and track corrective actions.Risk Manager / Risk Function2.40-3 monthsNot started
A14Introduce an emerging risk review as a standing item in the annual risk assessment cycle: at least once a year, facilitate a management discussion on what is changing in the external environment (regulatory, technological, economic, geopolitical) that could create new risks or alter the profile of existing ones. Document findings and update the risk register.Risk Manager / Risk Function2.40-3 monthsNot started
A15Establish a basic risk training module for all staff, a one to two hour session covering what risk management means for the organisation, why it matters, the individual's role in managing risk, and how to report a risk concern. Deliver the training within the next 90 days and track completion.CEO / HR & Risk Function2.40-3 monthsNot started
A16Establish an escalation channel: define (in writing) how staff can raise risk concerns, near-misses or potential compliance issues. This need not be a sophisticated whistleblower programme at this stage, a named contact (the risk officer), a documented process and a clear statement that concerns will be taken seriously and that the raiser will not face adverse consequences.CEO / HR & Risk Function2.40-3 monthsNot started
A17Implement a combined assurance approach: map which risks and controls are covered by first-line self-assessment, second-line risk function review, and third-line internal audit. Identify gaps (risks or controls with no assurance coverage) and agree with the risk committee how to address them within the current year.Risk Manager / Internal Audit2.40-3 monthsNot started
A18Conduct a lessons-learned review of all significant incidents from the past two years: identify whether root causes were addressed, whether the same incident types have recurred, and what systemic patterns exist. Present findings to management with a time-bound improvement plan addressing the most significant systemic gaps.Risk Manager / Internal Audit2.40-3 monthsNot started
A19Redesign board and management risk reports to be decision-useful rather than descriptive: shift from listing risks to highlighting what has changed, what is approaching an appetite threshold, what management is doing about it, and what the board's attention or decision is required on. Pilot the new format with the risk committee and refine based on feedback before full implementation.Chief Risk Officer / Risk Function2.40-3 monthsNot started
A20Implement a GRC (governance, risk and compliance) system or an equivalent structured risk information platform that serves as the single system of record for risk data, provides access controls and audit trail, enables automated reporting, and integrates risk, compliance and assurance data. Develop a user adoption plan to ensure the system is actively used by risk owners.Chief Risk Officer / Risk Function2.40-3 monthsNot started
A21Formally assure risk data quality: establish a data quality review process that is conducted before each major reporting cycle, defines quality metrics (completeness, accuracy, timeliness), reports quality findings to the risk function management, and tracks quality improvement over time. Present data quality trends to the risk committee annually.Chief Risk Officer / Risk Function2.40-3 monthsNot started
A22Automate compliance monitoring for key controls: implement technology-enabled monitoring (e.g. transaction monitoring for AML/CFT, automated data quality checks for regulatory reporting, automated access control reviews for data protection) that provides real-time or near-real-time compliance status and alerts for potential breaches.Compliance Officer2.40-3 monthsNot started
A23Become a recognised contributor to regulatory dialogue: respond formally to regulatory consultation papers in the organisation's sector; contribute to industry body working groups developing regulatory standards; present at regulatory forums. Position the organisation's compliance expertise as a public good as well as a competitive asset.Compliance Officer2.40-3 monthsNot started
A24Use ethical compliance as a market differentiator: document the organisation's compliance standards and ethical commitments, publish them in client-facing materials and tenders, and demonstrate compliance strength through independent assurance (third-party audits, regulatory commendations, industry certifications). Market compliance excellence as a client benefit.Compliance Officer2.40-3 monthsNot started

11. Methodology and maturity levels

This diagnostic evaluates risk maturity across eight domains using anchored behavioural questions. For each, the respondent selects the statement that best describes the organisation, mapped to a maturity level from 1 (Initial) to 5 (Optimised). Domain scores are the average of their question levels; the overall index is a weighted mean across the eight domains. The methodology is anchored in ISO 31000:2018 and overlaid with the regulatory obligations of the organisation's country and industry. Scoring is deterministic: the same answers always produce the same result.

The five maturity levels at a glance

1

Initial

Ad hoc

Risk is handled reactively and informally, with no framework or board visibility.

2

Developing

Basic elements present but inconsistent

Basic policies and registers exist but are inconsistent and compliance-driven.

3

Established

Documented and implemented

A documented, ISO 31000-aligned framework is implemented across the organisation.

4

Advanced

Embedded and quantified

Risk is embedded in decisions and performance, with quantified appetite and assurance.

5

Optimised

Leading practice

Predictive, continuously improving risk capability that drives strategic advantage.

Level 3 (Established) is the minimum credible position for a regulated entity. The detailed descriptors for each domain are available on request.

12. Important notes and disclaimer

This report reflects a self-assessment completed by the respondent and has not been independently validated by Trustview Business Consultants.

This report is provided for risk assessment purposes only and does not constitute legal, regulatory or audit advice. Maturity ratings and regulatory criticality are estimated indications based on the responses provided and should not be treated as absolute or audited measures. Where maturity falls below the regulated-entity minimum, the organisation may be exposed from a regulatory perspective. Organisations should seek independent professional advice to confirm their specific obligations.

Data protection: the information provided is held to produce this report. Trustview will not use it for any other purpose without consent.

Sample report — illustrative data only · RMA/SAMPLE/000 · Version 1.0 · 6 August 2026 · Trustview Business Consultants

Confidential, prepared for the named organisation only. Not for distribution without Trustview's written consent.

Ready to see where your organisation stands?

Start your assessment