The question nobody answers

Governance, Risk and Compliance Maturity

The question nobody answers - Governance, Risk and Compliance Maturity

Somewhere in Dubai this quarter, a board is going to ask how mature the organisation's GRC posture is.

Someone will open the risk register. Forty-two risks, colour-coded, owners assigned, last reviewed in March. It will be a good register. The work behind it will be real.

Everyone will nod. The item will close. The meeting will move on.

And nobody will have answered the question.

I have sat in a lot of these meetings, on both sides of the table. The pattern is consistent enough that I stopped noticing it for a while, which is usually the sign that something is worth noticing.

The register is not the problem. The register is often excellent. The problem is that a question about eight things received an answer about one of them, and nobody in the room felt the gap. Not through inattention. Because "how mature is our GRC" sounds like one question.

It is not one question. It is eight.

1.   Is the board set up to govern, or set up to meet?
2.   Does the risk register inform strategy, or sit beside it?
3.   Is internal audit aligned to the 2024 IIA Standards, or the 2017 ones?
4.   Does compliance scale with the volume of new regulation, or is it running to keep up?
5.   Are you ready for the SCA ICFR opinion, counting backwards from 2027?
6.   Is cyber inside the risk conversation, or still an IT problem?
7.   Has ESG moved from communications to controlled data?
8.   Would the culture survive the question a regulator asks first?

Read those and something predictable happens.

Three of them you can answer immediately. You know where the organisation stands, you could produce the evidence without preparation, and you are almost certainly right.

Two more you could answer with a week and a few conversations.

And three you have never actually been asked.

That last group is the interesting one. Not because the organisation is weak there. Often it is perfectly fine. But nobody has looked, so nobody knows, and "we assume it is fine" is a different statement from "we checked." The distance between those two is where most unpleasant surprises live.

Here is what I have noticed about which three go unexamined. It is rarely random. They tend to be the ones without a natural owner. Enterprise risk belongs to someone. Internal audit belongs to someone. But third-party risk sits between procurement, legal and the business. AI governance sits between IT, compliance and nobody. Culture sits with everyone, which means it sits with no one. Orphaned questions do not get asked, and they do not get asked for years.

The other thing worth saying is that this is not a competence problem. The management teams I am describing are good. They are running functions that were sized for a lighter regulatory environment than the one that now exists, and they are triaging. Triage is the correct response to overload. It is also how five of eight conversations quietly stop happening.

What changes things is smaller than people expect. Someone takes the eight questions into an audit committee meeting and asks which three the organisation can answer well. The answers come quickly, and they are usually right. Then they ask who owns the other five.

That second question is where the room goes quiet, and it is the useful part of the exercise.

We built the GRC Maturity Index to make that conversation easier to start. It scores an organisation across all eight, returns a maturity level, and names the three weakest areas specifically rather than generally. Fifteen minutes. No cost. No sales call unless you want one. If you want the methodology behind the scoring, the whitepaper sets it out in full.

But you do not need the tool to run the exercise. Take the eight questions to your next audit committee. Ask which three you can answer.

Then ask about the other five.

[LINK TO TOOL] · [LINK TO WHITEPAPER]

Copyright © 2026 CLA Emirates