Targeted Risk Reviews

An independent CRO-level view.
Focused on the issue that matters.

Sometimes the problem does not require a large transformation programme. It requires someone experienced enough to get underneath a defined issue quickly, distinguish the important from the incidental and tell management what should change.

When a targeted review makes sense

A narrow question. A clear answer.

01

You know something is not quite working

The framework exists, but it is not producing the decisions, outcomes or behaviours management intended.

02

You want an independent benchmark

The CEO, CRO or Board wants to know whether a specific approach genuinely represents good practice.

03

The business is changing

Growth, automation, new products or regulatory expectations mean an existing policy or framework needs to evolve.

04

Internal teams are too close to the issue

The people who built the process may not be best placed to challenge whether it is still required or still proportionate.

Typical review areas

Focused enough to get to an answer quickly.

A Targeted Risk Review starts with a defined question. The scope stays narrow enough to produce clear recommendations without turning into a whole-function diagnostic.

Risk appetiteDoes appetite reflect strategy, cover the material risks and create useful escalation and decision-making?
Board and management MIDoes reporting explain what is happening, why and what needs to be done — or simply reproduce numbers?
Governance and decision ownershipAre the right decisions being taken in the right forums by the right people?
Lending and credit policyIs policy proportionate, commercially effective and capable of supporting better decisioning or automation?
Affordability and credit strategyAre assumptions, thresholds and methodologies accurately reflecting the risks the lender intends to take?
A defined risk operating issueWhere a CEO, CRO or Board wants independent senior judgement on a specific problem rather than a broad review of the entire function.
Important distinction

Targeted Risk Review or Risk Function Benchmarking?

Targeted Risk Reviews answer a defined, narrower question. Risk Function Benchmarking is a holistic deep dive into the whole Risk function — structure, resource, governance, MI, assurance, capability and how capacity is deployed.

Explore the holistic Risk Function Benchmarking review
How a review works

Go to the work. Find the issue. Prioritise what matters.

01

Define the question

Agree what decision, concern or outcome the review needs to address and keep the scope disciplined.

02

Go to the work

Review the actual MI, policies, governance, processes and outputs, supported by targeted conversations with the people involved.

03

Challenge and compare

Apply CRO experience, lender context and relevant sector evidence to separate genuine risk issues from legacy process or convention.

04

Prioritise action

Leave management with a concise assessment of what should change, why it matters and what should happen first.

Examples

What a focused intervention can change.

Current Dharma Risk engagement · Building society

Lending policy and decisioning

A UK building society asked Dharma Risk for an independent view of its lending policy and decisioning approach because underwriting had become highly risk-averse and management wanted credible external challenge on what good looks like.

The review identified areas where policy could improve business and customer outcomes and produced a detailed roadmap for change, including the work needed to enable greater automation.

Next stepDharma Risk is facilitating a management workshop to redesign the lending policy for a more automated future state.
Raj's practitioner track record

Risk appetite made usable

Across four organisations, risk appetite frameworks had become long lists of measures disconnected from strategic decision-making, with incomplete risk coverage and unclear escalation.

The redesigned approach introduced clearer Board and management hierarchies, stronger linkage to strategy and explicit escalation routes.

Shift in the conversationFrom “Are the metrics green?” to “Are we taking the right risks to deliver the strategy?”
Raj's practitioner track record · Large building society

Board Risk MI that drives discussion

A large quarterly Board Risk pack took weeks to produce and described movements in metrics without enough insight into root cause or action.

The pack was stopped and replaced with a smaller dashboard focused on what was happening, why it mattered and what management needed to do.

OutcomeLess production effort and better-quality Board discussion centred on decisions and action.
What you leave with

Clarity, not consultancy volume.

What is workingSo good practice is protected rather than changed for the sake of it.
What is notThe specific issue, gap or activity that is getting in the way.
Why it mattersThe business, customer, risk or governance consequence of leaving it unchanged.
What should happen nextPrioritised actions delivered through a concise diagnostic, roadmap, workshop or senior readout depending on the problem.
Start with the question

Know the issue you want independently challenged?

The first conversation is simply to define the question and decide whether a targeted review is the right intervention.