Risk Maturity Assessment
Demo Mutual Assurance (Pty) Ltd
Assessment Report
| Organisation | Demo Mutual Assurance (Pty) Ltd |
| Country | Eswatini |
| Industry | Insurance |
| Assessment type | Self-assessment (sample) |
| Assessment date | 6 August 2026 |
| Reference | RMA/SAMPLE/000 |
| Report version | 1.0 |
This report reflects a self-assessment completed by the respondent and has not been independently validated by Trustview Business Consultants.
Confidential, prepared for the named organisation only. Not for distribution without Trustview's written consent.
Prepared by Trustview Business Consultants
Trusted and Dependable Business Solutions
1. Board snapshot
Developing
Developing / progressing towards Established
Target: Level 4 (your target) · Gap: 1.5
Risk Governance & Oversight
3.0
Strategy, Risk Appetite & Decision-Making
2.0
Framework, Policy & Resources
3.0
Risk Management Process
2.0
Risk Culture & Capability
1.0
Monitoring, Review & Improvement
2.0
Risk Information, Communication & Reporting
3.0
Compliance & Regulatory Alignment
4.0
Total actions
24
KEY PRIORITY: Strengthen Risk Culture & Capability (1.0) to close the maturity gap and move towards Level 4.
Board conclusion
Risk maturity is Developing (2.5), 1.5 below the target. Priority attention is needed in Risk Culture & Capability. 24 immediate actions are recommended.
2. Executive summary
Overall conclusion
Demo Mutual Assurance (Pty) Ltd is at Level 2, Developing (2.5). The overall maturity index of 2.5 is 1.5 below your target of Level 4. These results are an estimated indication, not an absolute or audited measure.
Key strengths
- Compliance & Regulatory Alignment (4.0)
Priority concerns
- Risk Culture & Capability (1.0)
- Strategy, Risk Appetite & Decision-Making (2.0)
- Risk Management Process (2.0)
- Monitoring, Review & Improvement (2.0)
Regulatory exposure
Maturity is below target in Risk Governance & Oversight, Strategy, Risk Appetite & Decision-Making, Framework, Policy & Resources, Risk Management Process, Risk Culture & Capability, Monitoring, Review & Improvement, Risk Information, Communication & Reporting, areas subject to Critical regulatory obligations. The organisation may be exposed from a regulatory perspective until these gaps are closed.
Immediate management focus
- Redesign board risk reporting to shift from a descriptive risk list to a decision-useful report that highlights what has changed since the last meeting, which risks are approaching or have breached appetite thresholds, and what management is doing in response. Implement the new format for the next two board cycles and refine based on feedback.
- Develop a formal risk appetite statement with defined tolerance thresholds for the organisation's principal risk categories (financial, operational, regulatory, reputational). Present it to the board for approval as a standalone document, not embedded in the risk policy. Link the thresholds explicitly to strategic objectives.
- Establish a defined risk assessment cycle: all business units must complete a full risk assessment (identification, analysis, evaluation, treatment plan update) at least annually, with the risk register updated in between for material changes. The risk function should facilitate and review assessments for quality and consistency before they are finalised.
- The chief executive or equivalent should make a written statement of personal commitment to risk management, to be communicated to all staff, included in the next town hall or all-staff meeting, and referenced in the organisation's next available external communication (annual report, website, stakeholder update). The statement should be specific, not generic.
Points to verify, possible inconsistencies
The responses produced some combinations that are unusual in practice. They do not change the scores, but they should be checked in case any answer was captured incorrectly.
- Compliance & Regulatory Alignment (4.0) is rated well above Risk Culture & Capability (1.0). A high Compliance & Regulatory Alignment rating is difficult to sustain without comparable maturity in Risk Culture & Capability; please verify these responses for a possible inconsistency.
- Compliance & Regulatory Alignment is rated Sound (4.0) while overall maturity (2.5) is below the regulated-entity minimum. This combination is unusual and may indicate inconsistent responses; please review.
3. Maturity dashboard
Gold tick marks the target (Level 4).
Bars show the current domain score; the gold line marks the target (Level 4). RAG: Priority attention below 2.5, Developing 2.5 to 3.4, Sound 3.5 and above.
4. Domain maturity heatmap
| Domain | Score | Target | Gap | Rating | Status |
|---|---|---|---|---|---|
| Risk Governance & Oversight | 3.0 | 4 | 1.0 | Developing | Below target |
| Strategy, Risk Appetite & Decision-Making | 2.0 | 4 | 2.0 | Priority attention | Below target |
| Framework, Policy & Resources | 3.0 | 4 | 1.0 | Developing | Below target |
| Risk Management Process | 2.0 | 4 | 2.0 | Priority attention | Below target |
| Risk Culture & Capability | 1.0 | 4 | 3.0 | Priority attention | Below target |
| Monitoring, Review & Improvement | 2.0 | 4 | 2.0 | Priority attention | Below target |
| Risk Information, Communication & Reporting | 3.0 | 4 | 1.0 | Developing | Below target |
| Compliance & Regulatory Alignment | 4.0 | 4 | Met | Sound | On / above target |
5. Current vs target maturity
| Code | Domain | Current | Target |
|---|---|---|---|
| D1 | Risk Governance & Oversight | 3.0 | 4 |
| D2 | Strategy, Risk Appetite & Decision-Making | 2.0 | 4 |
| D3 | Framework, Policy & Resources | 3.0 | 4 |
| D4 | Risk Management Process | 2.0 | 4 |
| D5 | Risk Culture & Capability | 1.0 | 4 |
| D6 | Monitoring, Review & Improvement | 2.0 | 4 |
| D7 | Risk Information, Communication & Reporting | 3.0 | 4 |
| D8 | Compliance & Regulatory Alignment | 4.0 | 4 |
6. Key findings
Finding 1
- Observation
- Risk Culture & Capability is at Level 1 (1.0), 3.0 below the target of Level 4.
- Impact
- Heightened regulatory exposure: Risk Culture & Capability carries Critical regulatory criticality for this profile, and current maturity is below the expected standard.
- Recommended response
- The chief executive or equivalent should make a written statement of personal commitment to risk management, to be communicated to all staff, included in the next town hall or all-staff meeting, and referenced in the organisation's next available external communication (annual report, website, stakeholder update). The statement should be specific, not generic.
Finding 2
- Observation
- Strategy, Risk Appetite & Decision-Making is at Level 2 (2.0), 2.0 below the target of Level 4.
- Impact
- Heightened regulatory exposure: Strategy, Risk Appetite & Decision-Making carries Critical regulatory criticality for this profile, and current maturity is below the expected standard.
- Recommended response
- Develop a formal risk appetite statement with defined tolerance thresholds for the organisation's principal risk categories (financial, operational, regulatory, reputational). Present it to the board for approval as a standalone document, not embedded in the risk policy. Link the thresholds explicitly to strategic objectives.
Finding 3
- Observation
- Risk Management Process is at Level 2 (2.0), 2.0 below the target of Level 4.
- Impact
- Heightened regulatory exposure: Risk Management Process carries Critical regulatory criticality for this profile, and current maturity is below the expected standard.
- Recommended response
- Establish a defined risk assessment cycle: all business units must complete a full risk assessment (identification, analysis, evaluation, treatment plan update) at least annually, with the risk register updated in between for material changes. The risk function should facilitate and review assessments for quality and consistency before they are finalised.
Finding 4
- Observation
- Monitoring, Review & Improvement is at Level 2 (2.0), 2.0 below the target of Level 4.
- Impact
- Heightened regulatory exposure: Monitoring, Review & Improvement carries Critical regulatory criticality for this profile, and current maturity is below the expected standard.
- Recommended response
- Define formal KRIs for each of the organisation's principal risks: for each KRI, specify the data source, measurement frequency, amber threshold (early warning) and red threshold (escalation required). Have KRIs approved by the risk committee and incorporate them into the quarterly risk report.
Finding 5
- Observation
- Risk Governance & Oversight is at Level 3 (3.0), 1.0 below the target of Level 4.
- Impact
- Heightened regulatory exposure: Risk Governance & Oversight carries Critical regulatory criticality for this profile, and current maturity is below the expected standard.
- Recommended response
- Redesign board risk reporting to shift from a descriptive risk list to a decision-useful report that highlights what has changed since the last meeting, which risks are approaching or have breached appetite thresholds, and what management is doing in response. Implement the new format for the next two board cycles and refine based on feedback.
7. Prioritised improvement roadmap
Stabilise · 0-3 months
Redesign board risk reporting to shift from a descriptive risk list to a decision-useful report that highlights what has changed since the last meeting, which risks are approaching or have breached appetite thresholds, and what management is doing in response. Implement the new format for the next two board cycles and refine based on feedback.
Develop a formal risk appetite statement with defined tolerance thresholds for the organisation's principal risk categories (financial, operational, regulatory, reputational). Present it to the board for approval as a standalone document, not embedded in the risk policy. Link the thresholds explicitly to strategic objectives.
Establish a defined risk assessment cycle: all business units must complete a full risk assessment (identification, analysis, evaluation, treatment plan update) at least annually, with the risk register updated in between for material changes. The risk function should facilitate and review assessments for quality and consistency before they are finalised.
The chief executive or equivalent should make a written statement of personal commitment to risk management, to be communicated to all staff, included in the next town hall or all-staff meeting, and referenced in the organisation's next available external communication (annual report, website, stakeholder update). The statement should be specific, not generic.
Define formal KRIs for each of the organisation's principal risks: for each KRI, specify the data source, measurement frequency, amber threshold (early warning) and red threshold (escalation required). Have KRIs approved by the risk committee and incorporate them into the quarterly risk report.
Conduct an annual risk committee effectiveness review: assess whether the committee's composition, frequency, information quality and interaction with management are delivering effective oversight. Present findings and improvement actions to the full board. Consider using an established governance assessment framework or external facilitator for the first review.
Expand the risk committee's oversight mandate to explicitly include strategic, emerging and conduct risks, not only operational risk register items. Add a standing agenda item for horizon risk (what is emerging in the external environment that could affect strategy in the next one to three years) and a periodic conduct risk review.
Formalise the annual strategic planning process to include a risk assessment step: the risk function should be involved in strategy development, not only consulted after the strategy is set. Introduce a risk register of strategic risks that is maintained alongside the operational risk register.
Embed a risk assessment requirement in the business case or decision paper template for all decisions above defined approval thresholds. The template should require proposers to state the principal risks, the residual risk after proposed mitigations, and whether the risk falls within the board-approved appetite.
Evaluate and implement a risk management technology solution appropriate to the organisation's size and complexity: this could range from a structured GRC system for larger organisations to a well-architected SharePoint-based risk register for smaller ones. The key requirements are: single system of record, audit trail, access controls, and the ability to produce consistent reports.
Conduct annual risk resource benchmarking against peer organisations: compare the risk function's size, qualifications, budget and tools against available industry data or regulatory expectations. Use findings to make an evidence-based case for resource investments or to confirm adequacy.
Integrate the risk framework into all major governance processes: reference it explicitly in the board charter, all committee terms of reference, the internal audit charter, HR policies (performance management) and the strategic planning process. The framework should be the thread connecting all governance activities, not a standalone risk document.
Establish a root-cause analysis standard: define the methodology to be used (e.g. 5-Whys, fishbone/Ishikawa, fault tree analysis), train relevant managers in its use, and make completion of a root-cause analysis mandatory for all incidents meeting defined significance criteria. Record findings in the incident log and track corrective actions.
Introduce an emerging risk review as a standing item in the annual risk assessment cycle: at least once a year, facilitate a management discussion on what is changing in the external environment (regulatory, technological, economic, geopolitical) that could create new risks or alter the profile of existing ones. Document findings and update the risk register.
Establish a basic risk training module for all staff, a one to two hour session covering what risk management means for the organisation, why it matters, the individual's role in managing risk, and how to report a risk concern. Deliver the training within the next 90 days and track completion.
Establish an escalation channel: define (in writing) how staff can raise risk concerns, near-misses or potential compliance issues. This need not be a sophisticated whistleblower programme at this stage, a named contact (the risk officer), a documented process and a clear statement that concerns will be taken seriously and that the raiser will not face adverse consequences.
Implement a combined assurance approach: map which risks and controls are covered by first-line self-assessment, second-line risk function review, and third-line internal audit. Identify gaps (risks or controls with no assurance coverage) and agree with the risk committee how to address them within the current year.
Conduct a lessons-learned review of all significant incidents from the past two years: identify whether root causes were addressed, whether the same incident types have recurred, and what systemic patterns exist. Present findings to management with a time-bound improvement plan addressing the most significant systemic gaps.
Redesign board and management risk reports to be decision-useful rather than descriptive: shift from listing risks to highlighting what has changed, what is approaching an appetite threshold, what management is doing about it, and what the board's attention or decision is required on. Pilot the new format with the risk committee and refine based on feedback before full implementation.
Implement a GRC (governance, risk and compliance) system or an equivalent structured risk information platform that serves as the single system of record for risk data, provides access controls and audit trail, enables automated reporting, and integrates risk, compliance and assurance data. Develop a user adoption plan to ensure the system is actively used by risk owners.
Formally assure risk data quality: establish a data quality review process that is conducted before each major reporting cycle, defines quality metrics (completeness, accuracy, timeliness), reports quality findings to the risk function management, and tracks quality improvement over time. Present data quality trends to the risk committee annually.
Automate compliance monitoring for key controls: implement technology-enabled monitoring (e.g. transaction monitoring for AML/CFT, automated data quality checks for regulatory reporting, automated access control reviews for data protection) that provides real-time or near-real-time compliance status and alerts for potential breaches.
Become a recognised contributor to regulatory dialogue: respond formally to regulatory consultation papers in the organisation's sector; contribute to industry body working groups developing regulatory standards; present at regulatory forums. Position the organisation's compliance expertise as a public good as well as a competitive asset.
Use ethical compliance as a market differentiator: document the organisation's compliance standards and ethical commitments, publish them in client-facing materials and tenders, and demonstrate compliance strength through independent assurance (third-party audits, regulatory commendations, industry certifications). Market compliance excellence as a client benefit.
8. Detailed domain analysis
Risk Governance & Oversight
DevelopingWhat this means
Board-approved risk policy and framework aligned to ISO 31000. A functioning risk committee (board or executive level) with a charter meets at least quarterly. A designated risk function with a defined mandate and reporting line. Three-lines responsibilities documented and broadly understood.
Recommended next steps
- Redesign board risk reporting to shift from a descriptive risk list to a decision-useful report that highlights what has changed since the last meeting, which risks are approaching or have breached appetite thresholds, and what management is doing in response. Implement the new format for the next two board cycles and refine based on feedback.
- Conduct an annual risk committee effectiveness review: assess whether the committee's composition, frequency, information quality and interaction with management are delivering effective oversight. Present findings and improvement actions to the full board. Consider using an established governance assessment framework or external facilitator for the first review.
- Expand the risk committee's oversight mandate to explicitly include strategic, emerging and conduct risks, not only operational risk register items. Add a standing agenda item for horizon risk (what is emerging in the external environment that could affect strategy in the next one to three years) and a periodic conduct risk review.
Strategy, Risk Appetite & Decision-Making
Priority attentionWhat this means
A broad risk appetite statement exists in policy but is not operationalised. Risk is considered informally in some decisions but without a consistent framework. Tolerance thresholds are undefined or untested.
Recommended next steps
- Develop a formal risk appetite statement with defined tolerance thresholds for the organisation's principal risk categories (financial, operational, regulatory, reputational). Present it to the board for approval as a standalone document, not embedded in the risk policy. Link the thresholds explicitly to strategic objectives.
- Formalise the annual strategic planning process to include a risk assessment step: the risk function should be involved in strategy development, not only consulted after the strategy is set. Introduce a risk register of strategic risks that is maintained alongside the operational risk register.
- Embed a risk assessment requirement in the business case or decision paper template for all decisions above defined approval thresholds. The template should require proposers to state the principal risks, the residual risk after proposed mitigations, and whether the risk falls within the board-approved appetite.
Framework, Policy & Resources
DevelopingWhat this means
A documented framework aligned to ISO 31000 is in place and reviewed at least every two years. Common risk taxonomy, definitions and procedures are established and communicated. Dedicated risk resources with appropriate skills are in place; budget is allocated.
Recommended next steps
- Evaluate and implement a risk management technology solution appropriate to the organisation's size and complexity: this could range from a structured GRC system for larger organisations to a well-architected SharePoint-based risk register for smaller ones. The key requirements are: single system of record, audit trail, access controls, and the ability to produce consistent reports.
- Conduct annual risk resource benchmarking against peer organisations: compare the risk function's size, qualifications, budget and tools against available industry data or regulatory expectations. Use findings to make an evidence-based case for resource investments or to confirm adequacy.
- Integrate the risk framework into all major governance processes: reference it explicitly in the board charter, all committee terms of reference, the internal audit charter, HR policies (performance management) and the strategic planning process. The framework should be the thread connecting all governance activities, not a standalone risk document.
Risk Management Process
Priority attentionWhat this means
Risk assessments occur periodically (often annually) using basic likelihood/impact matrices. A risk register exists but may be static and owned by the risk function alone. Treatment plans exist for some risks. Root-cause analysis is applied inconsistently after significant incidents.
Recommended next steps
- Establish a defined risk assessment cycle: all business units must complete a full risk assessment (identification, analysis, evaluation, treatment plan update) at least annually, with the risk register updated in between for material changes. The risk function should facilitate and review assessments for quality and consistency before they are finalised.
- Establish a root-cause analysis standard: define the methodology to be used (e.g. 5-Whys, fishbone/Ishikawa, fault tree analysis), train relevant managers in its use, and make completion of a root-cause analysis mandatory for all incidents meeting defined significance criteria. Record findings in the incident log and track corrective actions.
- Introduce an emerging risk review as a standing item in the annual risk assessment cycle: at least once a year, facilitate a management discussion on what is changing in the external environment (regulatory, technological, economic, geopolitical) that could create new risks or alter the profile of existing ones. Document findings and update the risk register.
Risk Culture & Capability
Priority attentionWhat this means
Risk culture is absent or counterproductive: bad news is suppressed, accountability is avoided, and risk is seen as the risk function's problem alone. No risk training or awareness programme. Incentives do not consider risk behaviour.
Recommended next steps
- The chief executive or equivalent should make a written statement of personal commitment to risk management, to be communicated to all staff, included in the next town hall or all-staff meeting, and referenced in the organisation's next available external communication (annual report, website, stakeholder update). The statement should be specific, not generic.
- Establish a basic risk training module for all staff, a one to two hour session covering what risk management means for the organisation, why it matters, the individual's role in managing risk, and how to report a risk concern. Deliver the training within the next 90 days and track completion.
- Establish an escalation channel: define (in writing) how staff can raise risk concerns, near-misses or potential compliance issues. This need not be a sophisticated whistleblower programme at this stage, a named contact (the risk officer), a documented process and a clear statement that concerns will be taken seriously and that the raiser will not face adverse consequences.
Monitoring, Review & Improvement
Priority attentionWhat this means
Some monitoring of top risks exists but is inconsistent and largely manual. Incident recording is ad hoc; lessons learned are not systematically captured. Framework review occurs infrequently and is driven by external events rather than planned cadence.
Recommended next steps
- Define formal KRIs for each of the organisation's principal risks: for each KRI, specify the data source, measurement frequency, amber threshold (early warning) and red threshold (escalation required). Have KRIs approved by the risk committee and incorporate them into the quarterly risk report.
- Implement a combined assurance approach: map which risks and controls are covered by first-line self-assessment, second-line risk function review, and third-line internal audit. Identify gaps (risks or controls with no assurance coverage) and agree with the risk committee how to address them within the current year.
- Conduct a lessons-learned review of all significant incidents from the past two years: identify whether root causes were addressed, whether the same incident types have recurred, and what systemic patterns exist. Present findings to management with a time-bound improvement plan addressing the most significant systemic gaps.
Risk Information, Communication & Reporting
DevelopingWhat this means
Structured risk reports are produced for management (monthly or quarterly) and the board (quarterly minimum) using a consistent format. A maintained risk register is accessible to relevant stakeholders. Regulatory reporting obligations are met on time. Data quality is considered in reporting.
Recommended next steps
- Redesign board and management risk reports to be decision-useful rather than descriptive: shift from listing risks to highlighting what has changed, what is approaching an appetite threshold, what management is doing about it, and what the board's attention or decision is required on. Pilot the new format with the risk committee and refine based on feedback before full implementation.
- Implement a GRC (governance, risk and compliance) system or an equivalent structured risk information platform that serves as the single system of record for risk data, provides access controls and audit trail, enables automated reporting, and integrates risk, compliance and assurance data. Develop a user adoption plan to ensure the system is actively used by risk owners.
- Formally assure risk data quality: establish a data quality review process that is conducted before each major reporting cycle, defines quality metrics (completeness, accuracy, timeliness), reports quality findings to the risk function management, and tracks quality improvement over time. Present data quality trends to the risk committee annually.
Compliance & Regulatory Alignment
SoundWhat this means
Compliance risk management is integrated with operational risk. The obligations register is maintained in near-real-time as regulations change. Regulatory relationships are proactive: the organisation engages with regulators on policy developments. Compliance risk appetite is defined.
Recommended next steps
- Automate compliance monitoring for key controls: implement technology-enabled monitoring (e.g. transaction monitoring for AML/CFT, automated data quality checks for regulatory reporting, automated access control reviews for data protection) that provides real-time or near-real-time compliance status and alerts for potential breaches.
- Become a recognised contributor to regulatory dialogue: respond formally to regulatory consultation papers in the organisation's sector; contribute to industry body working groups developing regulatory standards; present at regulatory forums. Position the organisation's compliance expertise as a public good as well as a competitive asset.
- Use ethical compliance as a market differentiator: document the organisation's compliance standards and ethical commitments, publish them in client-facing materials and tenders, and demonstrate compliance strength through independent assurance (third-party audits, regulatory commendations, industry certifications). Market compliance excellence as a client benefit.
9. Regulatory compliance matrix
| Regulation | Regulator | Criticality | Applicability | Risk implication | Recommended response |
|---|---|---|---|---|---|
| Financial Services Regulatory Authority Act, 2010 | Financial Services Regulatory Authority (FSRA) | Critical | Insurance | Relevant to: Risk Governance & Oversight, Strategy, Risk Appetite & Decision-Making, Framework, Policy & Resources, Risk Information, Communication & Reporting, Compliance & Regulatory Alignment | Ensure full compliance now; board-level oversight and independent assurance. |
| Money Laundering and Financing of Terrorism Prevention Act, 2011 (as amended by the 2016 Amendment Act and the Anti-Money Laundering, Counter Financing of Terrorism and Proliferation Financing (Miscellaneous Amendments) Act, 2024) | Eswatini Financial Intelligence Unit (EFIU); FSRA for non-bank FSPs | Critical | Insurance | Relevant to: Risk Governance & Oversight, Framework, Policy & Resources, Risk Management Process, Risk Culture & Capability, Compliance & Regulatory Alignment | Ensure full compliance now; board-level oversight and independent assurance. |
| Insurance Act, 2005 and Retirement Funds Act, 2005 | Financial Services Regulatory Authority (FSRA) | Critical | Insurance | Relevant to: Risk Governance & Oversight, Strategy, Risk Appetite & Decision-Making, Framework, Policy & Resources, Risk Information, Communication & Reporting, Compliance & Regulatory Alignment | Ensure full compliance now; board-level oversight and independent assurance. |
| Companies Act, 2009 | Registrar of Companies / Ministry of Commerce, Industry and Trade | High | Insurance | Relevant to: Risk Governance & Oversight, Strategy, Risk Appetite & Decision-Making, Compliance & Regulatory Alignment | Maintain compliance; obtain periodic independent assurance. |
| Data Protection Act, 2022 (Act No. 5 of 2022) | Eswatini Data Protection Commission | Critical | Insurance | Relevant to: Framework, Policy & Resources, Risk Management Process, Risk Information, Communication & Reporting, Compliance & Regulatory Alignment | Ensure full compliance now; board-level oversight and independent assurance. |
| Occupational Safety and Health Act, 2001 | Ministry of Labour and Social Security | Moderate | Insurance | Relevant to: Framework, Policy & Resources, Risk Management Process, Monitoring, Review & Improvement, Compliance & Regulatory Alignment | Monitor and close any gaps through management review. |
| Computer Crime and Cybercrime Act, 2022 (Act No. 6 of 2022) | Eswatini Communications Commission (ESCCOM); National Cybersecurity Advisory Council | Critical | Insurance | Relevant to: Framework, Policy & Resources, Risk Management Process, Monitoring, Review & Improvement, Risk Information, Communication & Reporting, Compliance & Regulatory Alignment | Ensure full compliance now; board-level oversight and independent assurance. |
Criticality is an estimated indication of regulatory exposure for this profile, not a legal determination.
10. Management action plan
| Ref | Action | Owner | Priority | Timeline | Status |
|---|---|---|---|---|---|
| A1 | Redesign board risk reporting to shift from a descriptive risk list to a decision-useful report that highlights what has changed since the last meeting, which risks are approaching or have breached appetite thresholds, and what management is doing in response. Implement the new format for the next two board cycles and refine based on feedback. | Board / Risk Committee | 3.0 | 0-3 months | Not started |
| A2 | Develop a formal risk appetite statement with defined tolerance thresholds for the organisation's principal risk categories (financial, operational, regulatory, reputational). Present it to the board for approval as a standalone document, not embedded in the risk policy. Link the thresholds explicitly to strategic objectives. | Executive Committee / CEO | 3.0 | 0-3 months | Not started |
| A3 | Establish a defined risk assessment cycle: all business units must complete a full risk assessment (identification, analysis, evaluation, treatment plan update) at least annually, with the risk register updated in between for material changes. The risk function should facilitate and review assessments for quality and consistency before they are finalised. | Risk Manager / Risk Function | 3.0 | 0-3 months | Not started |
| A4 | The chief executive or equivalent should make a written statement of personal commitment to risk management, to be communicated to all staff, included in the next town hall or all-staff meeting, and referenced in the organisation's next available external communication (annual report, website, stakeholder update). The statement should be specific, not generic. | CEO / HR & Risk Function | 3.0 | 0-3 months | Not started |
| A5 | Define formal KRIs for each of the organisation's principal risks: for each KRI, specify the data source, measurement frequency, amber threshold (early warning) and red threshold (escalation required). Have KRIs approved by the risk committee and incorporate them into the quarterly risk report. | Risk Manager / Internal Audit | 3.0 | 0-3 months | Not started |
| A6 | Conduct an annual risk committee effectiveness review: assess whether the committee's composition, frequency, information quality and interaction with management are delivering effective oversight. Present findings and improvement actions to the full board. Consider using an established governance assessment framework or external facilitator for the first review. | Board / Risk Committee | 2.4 | 0-3 months | Not started |
| A7 | Expand the risk committee's oversight mandate to explicitly include strategic, emerging and conduct risks, not only operational risk register items. Add a standing agenda item for horizon risk (what is emerging in the external environment that could affect strategy in the next one to three years) and a periodic conduct risk review. | Board / Risk Committee | 2.4 | 0-3 months | Not started |
| A8 | Formalise the annual strategic planning process to include a risk assessment step: the risk function should be involved in strategy development, not only consulted after the strategy is set. Introduce a risk register of strategic risks that is maintained alongside the operational risk register. | Executive Committee / CEO | 2.4 | 0-3 months | Not started |
| A9 | Embed a risk assessment requirement in the business case or decision paper template for all decisions above defined approval thresholds. The template should require proposers to state the principal risks, the residual risk after proposed mitigations, and whether the risk falls within the board-approved appetite. | Executive Committee / CEO | 2.4 | 0-3 months | Not started |
| A10 | Evaluate and implement a risk management technology solution appropriate to the organisation's size and complexity: this could range from a structured GRC system for larger organisations to a well-architected SharePoint-based risk register for smaller ones. The key requirements are: single system of record, audit trail, access controls, and the ability to produce consistent reports. | Chief Risk Officer / Risk Manager | 2.4 | 0-3 months | Not started |
| A11 | Conduct annual risk resource benchmarking against peer organisations: compare the risk function's size, qualifications, budget and tools against available industry data or regulatory expectations. Use findings to make an evidence-based case for resource investments or to confirm adequacy. | Chief Risk Officer / Risk Manager | 2.4 | 0-3 months | Not started |
| A12 | Integrate the risk framework into all major governance processes: reference it explicitly in the board charter, all committee terms of reference, the internal audit charter, HR policies (performance management) and the strategic planning process. The framework should be the thread connecting all governance activities, not a standalone risk document. | Chief Risk Officer / Risk Manager | 2.4 | 0-3 months | Not started |
| A13 | Establish a root-cause analysis standard: define the methodology to be used (e.g. 5-Whys, fishbone/Ishikawa, fault tree analysis), train relevant managers in its use, and make completion of a root-cause analysis mandatory for all incidents meeting defined significance criteria. Record findings in the incident log and track corrective actions. | Risk Manager / Risk Function | 2.4 | 0-3 months | Not started |
| A14 | Introduce an emerging risk review as a standing item in the annual risk assessment cycle: at least once a year, facilitate a management discussion on what is changing in the external environment (regulatory, technological, economic, geopolitical) that could create new risks or alter the profile of existing ones. Document findings and update the risk register. | Risk Manager / Risk Function | 2.4 | 0-3 months | Not started |
| A15 | Establish a basic risk training module for all staff, a one to two hour session covering what risk management means for the organisation, why it matters, the individual's role in managing risk, and how to report a risk concern. Deliver the training within the next 90 days and track completion. | CEO / HR & Risk Function | 2.4 | 0-3 months | Not started |
| A16 | Establish an escalation channel: define (in writing) how staff can raise risk concerns, near-misses or potential compliance issues. This need not be a sophisticated whistleblower programme at this stage, a named contact (the risk officer), a documented process and a clear statement that concerns will be taken seriously and that the raiser will not face adverse consequences. | CEO / HR & Risk Function | 2.4 | 0-3 months | Not started |
| A17 | Implement a combined assurance approach: map which risks and controls are covered by first-line self-assessment, second-line risk function review, and third-line internal audit. Identify gaps (risks or controls with no assurance coverage) and agree with the risk committee how to address them within the current year. | Risk Manager / Internal Audit | 2.4 | 0-3 months | Not started |
| A18 | Conduct a lessons-learned review of all significant incidents from the past two years: identify whether root causes were addressed, whether the same incident types have recurred, and what systemic patterns exist. Present findings to management with a time-bound improvement plan addressing the most significant systemic gaps. | Risk Manager / Internal Audit | 2.4 | 0-3 months | Not started |
| A19 | Redesign board and management risk reports to be decision-useful rather than descriptive: shift from listing risks to highlighting what has changed, what is approaching an appetite threshold, what management is doing about it, and what the board's attention or decision is required on. Pilot the new format with the risk committee and refine based on feedback before full implementation. | Chief Risk Officer / Risk Function | 2.4 | 0-3 months | Not started |
| A20 | Implement a GRC (governance, risk and compliance) system or an equivalent structured risk information platform that serves as the single system of record for risk data, provides access controls and audit trail, enables automated reporting, and integrates risk, compliance and assurance data. Develop a user adoption plan to ensure the system is actively used by risk owners. | Chief Risk Officer / Risk Function | 2.4 | 0-3 months | Not started |
| A21 | Formally assure risk data quality: establish a data quality review process that is conducted before each major reporting cycle, defines quality metrics (completeness, accuracy, timeliness), reports quality findings to the risk function management, and tracks quality improvement over time. Present data quality trends to the risk committee annually. | Chief Risk Officer / Risk Function | 2.4 | 0-3 months | Not started |
| A22 | Automate compliance monitoring for key controls: implement technology-enabled monitoring (e.g. transaction monitoring for AML/CFT, automated data quality checks for regulatory reporting, automated access control reviews for data protection) that provides real-time or near-real-time compliance status and alerts for potential breaches. | Compliance Officer | 2.4 | 0-3 months | Not started |
| A23 | Become a recognised contributor to regulatory dialogue: respond formally to regulatory consultation papers in the organisation's sector; contribute to industry body working groups developing regulatory standards; present at regulatory forums. Position the organisation's compliance expertise as a public good as well as a competitive asset. | Compliance Officer | 2.4 | 0-3 months | Not started |
| A24 | Use ethical compliance as a market differentiator: document the organisation's compliance standards and ethical commitments, publish them in client-facing materials and tenders, and demonstrate compliance strength through independent assurance (third-party audits, regulatory commendations, industry certifications). Market compliance excellence as a client benefit. | Compliance Officer | 2.4 | 0-3 months | Not started |
11. Methodology and maturity levels
This diagnostic evaluates risk maturity across eight domains using anchored behavioural questions. For each, the respondent selects the statement that best describes the organisation, mapped to a maturity level from 1 (Initial) to 5 (Optimised). Domain scores are the average of their question levels; the overall index is a weighted mean across the eight domains. The methodology is anchored in ISO 31000:2018 and overlaid with the regulatory obligations of the organisation's country and industry. Scoring is deterministic: the same answers always produce the same result.
The five maturity levels at a glance
Initial
Ad hoc
Risk is handled reactively and informally, with no framework or board visibility.
Developing
Basic elements present but inconsistent
Basic policies and registers exist but are inconsistent and compliance-driven.
Established
Documented and implemented
A documented, ISO 31000-aligned framework is implemented across the organisation.
Advanced
Embedded and quantified
Risk is embedded in decisions and performance, with quantified appetite and assurance.
Optimised
Leading practice
Predictive, continuously improving risk capability that drives strategic advantage.
Level 3 (Established) is the minimum credible position for a regulated entity. The detailed descriptors for each domain are available on request.
12. Important notes and disclaimer
This report reflects a self-assessment completed by the respondent and has not been independently validated by Trustview Business Consultants.
This report is provided for risk assessment purposes only and does not constitute legal, regulatory or audit advice. Maturity ratings and regulatory criticality are estimated indications based on the responses provided and should not be treated as absolute or audited measures. Where maturity falls below the regulated-entity minimum, the organisation may be exposed from a regulatory perspective. Organisations should seek independent professional advice to confirm their specific obligations.
Data protection: the information provided is held to produce this report. Trustview will not use it for any other purpose without consent.
Confidential, prepared for the named organisation only. Not for distribution without Trustview's written consent.
Ready to see where your organisation stands?
Start your assessment