GRC Maturity IndexStart the diagnosticMethodology
How the GRC Maturity Index is scored
The Index rates your organisation across eight weighted dimensions using 40 questions, each anchored to a named UAE or global standard. Scores reflect self-reported answers and are a starting point for board discussion, not an audit opinion.
How scores are calculated
1. Each answer is a maturity level
Every question offers five descriptions, from Level 1 (ad-hoc) to Level 5 (optimised). You pick the one that best fits today.
2. Dimensions normalise to 100
A dimension score is the mean of its applicable question levels, multiplied by 20. Questions that do not apply to you are excluded from the mean.
3. A weighted composite
The composite is the weighted sum of the eight dimension scores, using the weights below to reflect regulatory exposure. It runs from 0 to 100.
The maturity bands
| Band | Composite | What it means |
|---|---|---|
| Ad-hoc | 0 to 20 | Informal and reactive; controls exist only in individuals. |
| Initial | 21 to 40 | Some structure emerging; inconsistent and largely undocumented. |
| Defined | 41 to 60 | Documented frameworks in place; execution is uneven. |
| Managed | 61 to 80 | Frameworks operate consistently and are monitored. |
| Optimised | 81 to 100 | Embedded, evidenced and continuously improved. |
The eight dimensions
Each dimension carries a weight toward the composite. The weights sum to 100 and reflect the relative regulatory and board exposure of each area.
1. Governance Foundation
15% weightThe board and committee architecture that sets direction and holds management accountable: board independence, committee charters, delegation of authority and, for family groups, the separation of ownership from management.
Regulatory anchor: SCA Chairman Decision 3/R.M/2020 as amended by Decision 2/R.M/2024; UAE Family Business Law (Federal Decree-Law 37 of 2022); CBUAE Circular 83/2019.
2. Enterprise Risk Management
15% weightHow the organisation identifies, rates and governs risk: a board-approved framework, a live risk register and heat map, a defined risk appetite, emerging-risk scanning and a risk-aware culture.
Regulatory anchor: COSO ERM 2017; ISO 31000:2018; CBUAE Circular 153/2018 (Risk Governance Framework for regulated entities); IIA Three Lines Model (2020).
3. Internal Audit Function
15% weightThe independent assurance function: whether it exists and reports to the audit committee, aligns to the 2024 IIA Global Internal Audit Standards, runs a risk-based plan, is adequately resourced and is quality-assured.
Regulatory anchor: IIA Global Internal Audit Standards 2024 (effective 9 Jan 2025); five Domains, 15 Principles, 52 Standards; Topical Requirement on Cybersecurity (effective 5 Feb 2026); SCA Article 47; ADAA Financial Audit Manual for GREs.
4. Compliance and Regulatory Monitoring
12% weightOwnership of the compliance obligation: a named function, a maintained obligations register, Corporate Tax and transfer-pricing controls, AML, sanctions, ESR and substance monitoring, and horizon scanning for regulatory change.
Regulatory anchor: SCA, CBUAE, DFSA, ADGM FSRA, MoF (Corporate Tax), FTA (TP), NESA/SIA, UAE Family Business Law, ESR (Cabinet Decision 98/2024), UAE Climate Law (Federal Decree-Law 11/2024).
5. Internal Controls over Financial Reporting (ICoFR)
12% weightThe controls that make the financial statements reliable: documented controls, independent testing, timely remediation of deficiencies, readiness for the SCA ICFR regime and process automation that reduces manual error.
Regulatory anchor: SCA ICFR Circular (first phase extended to end-2026; full internal control reports and auditor opinion from 2027; risk management inclusion from 2028); COSO 2013 Internal Control Framework.
6. IT Governance and Cyber Risk
12% weightThe governance of technology and cyber exposure: a cyber governance structure, alignment to a recognised framework, tested incident response, emerging AI governance and control over third-party technology risk.
Regulatory anchor: NESA / SIA UAE IA Standards; CBUAE Cyber Risk Management Standards; DFSA Cyber and Technology Risk Rules; ADGM FSRA IT Risk Management Guidance (updated 2024); IIA Cybersecurity Topical Requirement (effective 5 Feb 2026).
7. ESG Governance and Sustainability
10% weightThe governance of sustainability: clear ESG ownership, reporting aligned to IFRS S1 and S2, UAE Climate Law readiness, ESG built into strategy and incentives, and readiness for external assurance.
Regulatory anchor: SCA Article 76 (sustainability report within 90 days of FY-end); UAE Climate Law (Federal Decree-Law 11/2024, in force 30 May 2025, full compliance 30 May 2026, penalties AED 50K to AED 2M); IFRS S1 and S2 (ISSB); ADX ESG Disclosure Guidance (31 KPIs); DFM ESG Reporting Guide (32 KPIs).
8. Ethics, Culture and Third-Party Risk
9% weightThe integrity layer: a live code of conduct and training, a trusted whistleblowing channel, fraud-risk management, third-party due diligence and a measured speak-up culture.
Regulatory anchor: SCA Code of Conduct requirements; ADGM Whistleblower Protection Regulations 2024; UAE Anti-Fraud provisions; IIA Third-Party Topical Requirement (effective Dec 2026).