Skip to main content
← Back to Case Studies

Banking

Change Risk Oversight Diagnostic Review

The engagement delivered a diagnostic review of change risk oversight for a major building society. It focused on assessing governance, reporting, and risk management approaches and providing recommendations to strengthen second-line assurance.

Background

The client required a review to improve how the second line oversees and assures change activity, including assessment of management information, reporting, escalation, and governance arrangements.

The Challenge

The engagement needed to assess current approaches to change risk oversight, including management information, reporting routes, escalation processes, and governance structures. It required identifying gaps in how change risks were defined, monitored, and escalated across initiatives of differing materiality, and ensuring appropriate coverage of risk taxonomy and control checkpoints.

Our Approach

The consultant conducted a time-bound diagnostic review, including mobilisation, scoping, and stakeholder engagement across Risk and Change functions. They assessed current-state reporting, management information, governance arrangements, and oversight processes to identify gaps and improvement opportunities. They developed options for second-line oversight, including conceptual definitions for change risk KRIs and KCIs, escalation logic, and proportional oversight based on materiality. They produced future-state recommendations, including roles and responsibilities, escalation thresholds, governance alignment, and a forward-looking risk lens covering emerging risks and portfolio complexity. They developed supporting materials including a recommendations document, presentation, quick wins charter, RAID log, and conceptual dashboard outputs.

Results

The engagement delivered a structured set of recommendations and supporting artefacts to strengthen second-line oversight of change. It enabled improved governance, clearer risk identification and escalation processes, and alignment with the Enterprise Risk Management Framework.

Facing a similar challenge?

Discuss a similar challenge