You know something is not quite working
The framework exists, but it is not producing the decisions, outcomes or behaviours management intended.
Sometimes the problem does not require a large transformation programme. It requires someone experienced enough to get underneath a defined issue quickly, distinguish the important from the incidental and tell management what should change.
The framework exists, but it is not producing the decisions, outcomes or behaviours management intended.
The CEO, CRO or Board wants to know whether a specific approach genuinely represents good practice.
Growth, automation, new products or regulatory expectations mean an existing policy or framework needs to evolve.
The people who built the process may not be best placed to challenge whether it is still required or still proportionate.
A Targeted Risk Review starts with a defined question. The scope stays narrow enough to produce clear recommendations without turning into a whole-function diagnostic.
Targeted Risk Reviews answer a defined, narrower question. Risk Function Benchmarking is a holistic deep dive into the whole Risk function — structure, resource, governance, MI, assurance, capability and how capacity is deployed.
Explore the holistic Risk Function Benchmarking review →Agree what decision, concern or outcome the review needs to address and keep the scope disciplined.
Review the actual MI, policies, governance, processes and outputs, supported by targeted conversations with the people involved.
Apply CRO experience, lender context and relevant sector evidence to separate genuine risk issues from legacy process or convention.
Leave management with a concise assessment of what should change, why it matters and what should happen first.
A UK building society asked Dharma Risk for an independent view of its lending policy and decisioning approach because underwriting had become highly risk-averse and management wanted credible external challenge on what good looks like.
The review identified areas where policy could improve business and customer outcomes and produced a detailed roadmap for change, including the work needed to enable greater automation.
Across four organisations, risk appetite frameworks had become long lists of measures disconnected from strategic decision-making, with incomplete risk coverage and unclear escalation.
The redesigned approach introduced clearer Board and management hierarchies, stronger linkage to strategy and explicit escalation routes.
A large quarterly Board Risk pack took weeks to produce and described movements in metrics without enough insight into root cause or action.
The pack was stopped and replaced with a smaller dashboard focused on what was happening, why it mattered and what management needed to do.
The first conversation is simply to define the question and decide whether a targeted review is the right intervention.