Service 08 — Governance

Corporate Governance

Riskweise designs Board-level corporate governance frameworks for GCC financial institutions — aligned with CBUAE, SAMA, CBK, QCB, CBB and CBO corporate governance regulations and Basel Committee Corporate Governance Principles — covering Board charters, committee structures, risk appetite, three lines of defence, and Pillar III disclosure support.

Engagements cover everything from greenfield governance design (banks adopting formal frameworks for the first time, often in preparation for IPO or regulatory licensing) to remediation of governance gaps following regulatory thematic review or supervisory feedback.

Methodology

How we approach it.

01 — Component

Board & committee frameworks

Board charter design, committee structures (audit, risk, remuneration, nomination), Terms of Reference, meeting governance and effectiveness reviews. Calibrated to the supervisory expectations of the home regulator.

02 — Component

Risk Appetite Framework

RAF design linking strategic objectives to quantitative risk limits. KRI dashboards, escalation protocols, breach management, and Board reporting integration. Designed so RAF is operationally connected to business decisions, not a once-a-year compliance artefact.

03 — Component

Three Lines of Defence

Implementation of the 3LoD model across risk, compliance, and internal audit. Role clarity, accountability mapping, and reporting line design — addressing the common failure mode where lines blur and ownership of issues becomes ambiguous.

04 — Component

Governance gap assessment

Assessment against central bank corporate governance regulations, Basel principles, and local listing authority requirements. Remediation roadmap with explicit prioritisation and ownership.

05 — Component

Board training & capacity

Tailored training for Board members and senior management on risk governance, IFRS 9 implications, capital adequacy, model risk, and regulatory expectations. Designed to raise governance literacy without overwhelming Boards with technical detail.

06 — Component

Corporate governance reporting

Annual governance reports, regulatory disclosures, Pillar III reporting, and governance sections for annual reports. Policy and charter drafting where institutions are starting from a low base.

What we deliver

Concrete outputs.

  • Board charter and committee Terms of Reference
  • Risk Appetite Framework (RAF) with quantitative limits
  • KRI dashboards and escalation protocols
  • Three Lines of Defence policy and role mapping
  • Governance gap assessment against regulatory expectations
  • Pillar III disclosure templates and narrative
  • Board training materials and capacity building
  • Annual governance reports and supervisory submissions
Who this is for

The fit.

  • Banks adopting or refreshing corporate governance framework
  • Banks under regulatory thematic review on governance
  • Banks preparing for IPO or new market listing
  • Newly-licensed banks needing first-time governance setup
  • Banks consolidating governance across cross-border subsidiaries
  • Banks needing Pillar III disclosure capability
Common questions

Questions we get asked.

What corporate governance regulations apply in the GCC?

CBUAE Corporate Governance Regulation; SAMA Principles for Corporate Governance; CBK Instructions on Corporate Governance; QCB Corporate Governance Guidelines; CBB High-Level Controls Module; CBO Banking Law requirements; Basel Committee Corporate Governance Principles for banks; and listing authority requirements at DFM, ADX, Tadawul, BHB, QSE, Boursa Kuwait and MSX. Each has nuances around Board composition, committee independence, risk oversight, and disclosure.

What does a Risk Appetite Framework actually include?

A RAF connects strategic objectives to specific, measurable risk limits. It includes: a Board-approved risk appetite statement; quantitative limits across credit, market, liquidity and operational risk; KRI thresholds with explicit breach and escalation triggers; reporting integration with Board pack and Executive Risk Committee; and an annual recalibration process. The RAF is what makes "risk-aware decision making" operational rather than rhetorical.

How does Three Lines of Defence work in practice?

First line: business teams own and manage risk in their day-to-day activities. Second line: risk and compliance functions provide oversight, methodology, and challenge. Third line: internal audit provides independent assurance. The model only works if reporting lines and accountability are clear — common failure modes include risk teams operating as first line (compromising oversight) or audit teams operating as second line (compromising independence). Riskweise builds explicit role separation into the policy and reporting structures.

Do you support Pillar III disclosures?

Yes. Pillar III is one of the most under-invested governance areas in many GCC banks — a source of regulator findings and reputation risk. We design the disclosure framework, draft the standard sections (capital adequacy, risk exposures, remuneration), and build the data process so disclosures are produced reliably each cycle without ad-hoc fire drills.

How long does a corporate governance build take?

Greenfield framework for a new institution: 12-16 weeks. Refresh and remediation following supervisory review: 8-12 weeks. RAF design and implementation only: 6-10 weeks. Pillar III disclosure framework: 4-6 weeks. Multi-jurisdictional consolidation across cross-border subsidiaries: 16-24 weeks.

Do you provide Board training?

Yes. Tailored Board and senior management training on risk governance, IFRS 9, capital adequacy, model risk, and regulatory expectations. Sessions are calibrated to existing Board literacy — a Board with strong financial backgrounds needs different content from a Board where directors come from non-financial backgrounds. Training is one of the most cost-effective governance investments available.

Get in touch

Tell us about your governance engagement.

We respond within one business day. No agency-style discovery process — straight to scope, fit, and what you actually need.

Start the conversation