GRC Maturity Index

GRC Maturity Index.

A five-minute diagnostic scored across eight dimensions. Board-grade output. Regulatory anchors included. Built for UAE mid-market family businesses, listed mid-caps, GREs and free-zone entities.

Start the diagnosticFive minutes. No account required.

8 dimensions scored to 100

Governance, ERM, internal audit, compliance, ICoFR, IT and cyber, ESG, and ethics and third-party risk.

§

Grounded in real standards

Regulatory anchors from IIA 2024, SCA, ADAA, CBUAE, DFSA, and IFRS S1/S2.

Board-ready PDF in one click

A clean, navy-headed board report with your scores, priority actions and regulatory watch.

The eight dimensions

Each dimension is scored on a five-point maturity scale, from ad-hoc to optimised, and normalised to 100. Every question is anchored to a named UAE or global standard.

1. Governance Foundation

15%

SCA Chairman Decision 3/R.M/2020 as amended by Decision 2/R.M/2024; UAE Family Business Law (Federal Decree-Law 37 of 2022); CBUAE Circular 83/2019.

2. Enterprise Risk Management

15%

COSO ERM 2017; ISO 31000:2018; CBUAE Circular 153/2018 (Risk Governance Framework for regulated entities); IIA Three Lines Model (2020).

3. Internal Audit Function

15%

IIA Global Internal Audit Standards 2024 (effective 9 Jan 2025); five Domains, 15 Principles, 52 Standards; Topical Requirement on Cybersecurity (effective 5 Feb 2026); SCA Article 47; ADAA Financial Audit Manual for GREs.

4. Compliance and Regulatory Monitoring

12%

SCA, CBUAE, DFSA, ADGM FSRA, MoF (Corporate Tax), FTA (TP), NESA/SIA, UAE Family Business Law, ESR (Cabinet Decision 98/2024), UAE Climate Law (Federal Decree-Law 11/2024).

5. Internal Controls over Financial Reporting (ICoFR)

12%

SCA ICFR Circular (first phase extended to end-2026; full internal control reports and auditor opinion from 2027; risk management inclusion from 2028); COSO 2013 Internal Control Framework.

6. IT Governance and Cyber Risk

12%

NESA / SIA UAE IA Standards; CBUAE Cyber Risk Management Standards; DFSA Cyber and Technology Risk Rules; ADGM FSRA IT Risk Management Guidance (updated 2024); IIA Cybersecurity Topical Requirement (effective 5 Feb 2026).

7. ESG Governance and Sustainability

10%

SCA Article 76 (sustainability report within 90 days of FY-end); UAE Climate Law (Federal Decree-Law 11/2024, in force 30 May 2025, full compliance 30 May 2026, penalties AED 50K to AED 2M); IFRS S1 and S2 (ISSB); ADX ESG Disclosure Guidance (31 KPIs); DFM ESG Reporting Guide (32 KPIs).

8. Ethics, Culture and Third-Party Risk

9%

SCA Code of Conduct requirements; ADGM Whistleblower Protection Regulations 2024; UAE Anti-Fraud provisions; IIA Third-Party Topical Requirement (effective Dec 2026).

Why this is credible

Grounded in the 2024 IIA Global Internal Audit Standards, SCA Corporate Governance Reform (Board Resolution 24/2025), UAE Family Business Law, UAE Climate Law and IFRS S1/S2. Built by CLA Emirates as part of its productised diagnostic suite.

Your anonymised responses will contribute to the annual Middle East GRC Maturity Report. You can opt in on the last screen. No individual data is ever published.