CLA EmiratesStart the diagnostic

Methodology

How the GRC Maturity Index is scored

The Index rates your organisation across eight weighted dimensions using 40 questions, each anchored to a named UAE or global standard. Scores reflect self-reported answers and are a starting point for board discussion, not an audit opinion.

How scores are calculated

1. Each answer is a maturity level

Every question offers five descriptions, from Level 1 (ad-hoc) to Level 5 (optimised). You pick the one that best fits today.

2. Dimensions normalise to 100

A dimension score is the mean of its applicable question levels, multiplied by 20. Questions that do not apply to you are excluded from the mean.

3. A weighted composite

The composite is the weighted sum of the eight dimension scores, using the weights below to reflect regulatory exposure. It runs from 0 to 100.

The maturity bands

BandCompositeWhat it means
Ad-hoc0 to 20Informal and reactive; controls exist only in individuals.
Initial21 to 40Some structure emerging; inconsistent and largely undocumented.
Defined41 to 60Documented frameworks in place; execution is uneven.
Managed61 to 80Frameworks operate consistently and are monitored.
Optimised81 to 100Embedded, evidenced and continuously improved.

The eight dimensions

Each dimension carries a weight toward the composite. The weights sum to 100 and reflect the relative regulatory and board exposure of each area.

1. Governance Foundation

15% weight

The board and committee architecture that sets direction and holds management accountable: board independence, committee charters, delegation of authority and, for family groups, the separation of ownership from management.

Regulatory anchor: SCA Chairman Decision 3/R.M/2020 as amended by Decision 2/R.M/2024; UAE Family Business Law (Federal Decree-Law 37 of 2022); CBUAE Circular 83/2019.

2. Enterprise Risk Management

15% weight

How the organisation identifies, rates and governs risk: a board-approved framework, a live risk register and heat map, a defined risk appetite, emerging-risk scanning and a risk-aware culture.

Regulatory anchor: COSO ERM 2017; ISO 31000:2018; CBUAE Circular 153/2018 (Risk Governance Framework for regulated entities); IIA Three Lines Model (2020).

3. Internal Audit Function

15% weight

The independent assurance function: whether it exists and reports to the audit committee, aligns to the 2024 IIA Global Internal Audit Standards, runs a risk-based plan, is adequately resourced and is quality-assured.

Regulatory anchor: IIA Global Internal Audit Standards 2024 (effective 9 Jan 2025); five Domains, 15 Principles, 52 Standards; Topical Requirement on Cybersecurity (effective 5 Feb 2026); SCA Article 47; ADAA Financial Audit Manual for GREs.

4. Compliance and Regulatory Monitoring

12% weight

Ownership of the compliance obligation: a named function, a maintained obligations register, Corporate Tax and transfer-pricing controls, AML, sanctions, ESR and substance monitoring, and horizon scanning for regulatory change.

Regulatory anchor: SCA, CBUAE, DFSA, ADGM FSRA, MoF (Corporate Tax), FTA (TP), NESA/SIA, UAE Family Business Law, ESR (Cabinet Decision 98/2024), UAE Climate Law (Federal Decree-Law 11/2024).

5. Internal Controls over Financial Reporting (ICoFR)

12% weight

The controls that make the financial statements reliable: documented controls, independent testing, timely remediation of deficiencies, readiness for the SCA ICFR regime and process automation that reduces manual error.

Regulatory anchor: SCA ICFR Circular (first phase extended to end-2026; full internal control reports and auditor opinion from 2027; risk management inclusion from 2028); COSO 2013 Internal Control Framework.

6. IT Governance and Cyber Risk

12% weight

The governance of technology and cyber exposure: a cyber governance structure, alignment to a recognised framework, tested incident response, emerging AI governance and control over third-party technology risk.

Regulatory anchor: NESA / SIA UAE IA Standards; CBUAE Cyber Risk Management Standards; DFSA Cyber and Technology Risk Rules; ADGM FSRA IT Risk Management Guidance (updated 2024); IIA Cybersecurity Topical Requirement (effective 5 Feb 2026).

7. ESG Governance and Sustainability

10% weight

The governance of sustainability: clear ESG ownership, reporting aligned to IFRS S1 and S2, UAE Climate Law readiness, ESG built into strategy and incentives, and readiness for external assurance.

Regulatory anchor: SCA Article 76 (sustainability report within 90 days of FY-end); UAE Climate Law (Federal Decree-Law 11/2024, in force 30 May 2025, full compliance 30 May 2026, penalties AED 50K to AED 2M); IFRS S1 and S2 (ISSB); ADX ESG Disclosure Guidance (31 KPIs); DFM ESG Reporting Guide (32 KPIs).

8. Ethics, Culture and Third-Party Risk

9% weight

The integrity layer: a live code of conduct and training, a trusted whistleblowing channel, fraud-risk management, third-party due diligence and a measured speak-up culture.

Regulatory anchor: SCA Code of Conduct requirements; ADGM Whistleblower Protection Regulations 2024; UAE Anti-Fraud provisions; IIA Third-Party Topical Requirement (effective Dec 2026).