KITE 2025 New Product Award — Local IT | SACEEC
Risk

The Public Sector Risk Management Framework, running rather than filed

National Treasury issued the PSRMF as the implementation detail behind the risk management duties in the PFMA and MFMA. It is the framework the Auditor-General reads your maturity against. Dimeri carries its structure directly: the committee, the officer, the assessment cycle, the combined assurance view and the maturity position.

What the PSRMF sets out

The Public Sector Risk Management Framework was issued by the National Treasury to give institutions a common method for the risk management duties the PFMA and MFMA impose in general terms. Where the Treasury Regulations say conduct a regular risk assessment, the PSRMF describes what that assessment should look like, who should govern it, how responses should be chosen and how the whole arrangement should be assured and matured over time.

Its structure is governance first. The framework sets expectations for the accounting officer or authority, the risk management committee, the audit committee, the chief risk officer and the risk champions who operate within line functions. It then moves through the risk management process itself: establishing the context, identifying risk, assessing likelihood and impact, selecting and implementing responses, and monitoring and reporting. Combined assurance sits over the top, coordinating management assurance, internal audit and external assurance so the same control is not tested three times while another is never tested at all.

The framework also carries a maturity model, and this is where most institutions find themselves measured. Maturity is not a matter of having documents. It is a matter of whether risk management is embedded in how decisions are actually taken, whether risk information reaches the people who set strategy, and whether the process improves cycle on cycle. That is difficult to demonstrate from a spreadsheet and straightforward to demonstrate from a live register with a history.

The obligations Dimeri tracks

Dimeri implements the PSRMF as working structure rather than as a policy annexure, because that is the difference the maturity assessment is looking for.

Risk management governance

Clear roles for the accounting officer or authority, the risk management committee, the audit committee, the chief risk officer and risk champions.

  • Committee charters held with their review dates
  • Meeting calendar, attendance and quorum records
  • Role assignments recorded against named individuals
  • Escalation routes configured to match the structure

Risk identification

Systematic identification across strategic, operational, financial, compliance, project and fraud risk, refreshed as the environment changes.

  • Register segmented by risk category and directorate
  • Workshop and interview inputs captured with their source
  • Emerging risk capture between formal cycles
  • Risk descriptions written as cause, event and consequence

Risk assessment

Likelihood and impact assessed against defined criteria, with inherent and residual positions distinguished and the basis recorded.

  • Configurable impact and likelihood criteria
  • Inherent, residual and target ratings held separately
  • Rating rationale recorded with the assessor and date
  • Heat map and ranked exposure views

Risk response

A chosen response for each risk, whether treat, tolerate, transfer or terminate, with the actions that give effect to it.

  • Response strategy recorded per risk
  • Treatment actions with owners and due dates
  • Cost and benefit of response documented where material
  • Residual position reassessed after treatment

Combined assurance

Coordination of management assurance, internal audit and external assurance so coverage is deliberate rather than accidental.

  • Assurance map by risk and assurance provider
  • Over-assured and unassured risks surfaced
  • Internal audit plan aligned to significant risks
  • Assurance results fed back into control ratings

Monitoring, reporting and maturity

Continuous monitoring, reporting to the committees and the executive authority, and periodic assessment of maturity against the framework.

  • Standing reporting pack generated from live data
  • Key risk indicators tracked with thresholds
  • Maturity self assessment held with supporting evidence
  • Year on year movement visible rather than asserted

How Dimeri covers PSRMF

The PSRMF asks for a way of working. Dimeri supplies the structure so the institution can demonstrate the way of working rather than describe it.

Maturity you can evidence

Because the register carries its own history, maturity movement is demonstrable. You can show that risks were reassessed on schedule, that treatments closed, and that the committee acted on what it was shown, which is exactly what a maturity assessment is trying to establish.

Combined assurance that actually maps

The assurance map is generated from the register and the audit plan rather than drawn by hand each year. Risks with three assurance providers and risks with none are both visible in the same view.

One assessment, three frameworks

The assessment that satisfies the PSRMF also satisfies Treasury Regulation 3.2 and PFMA section 38(1)(a)(i), or the MFMA equivalents. Dimeri records it once and credits all of them.

Risk champions with something to work in

Line function risk champions own their directorate's register section directly, with their own view and their own reminders, rather than sending updates to a central spreadsheet owner once a quarter.

Implementing the PSRMF in Dimeri

  1. 1

    Set the governance structure

    Committees, charters, the chief risk officer role and risk champions per directorate are configured so the platform reflects how the institution is actually governed.

  2. 2

    Build the register by category

    Strategic, operational, financial, compliance, project and fraud risks are captured with a consistent cause, event and consequence structure and scored against your own criteria.

  3. 3

    Map assurance

    Management assurance, internal audit and external assurance are mapped against the significant risks, exposing both the gaps and the duplication before the audit plan is finalised.

  4. 4

    Run the cycle and assess maturity

    Reviews, reporting and committee meetings run on schedule, and the maturity assessment is completed against evidence the platform already holds rather than against recollection.

PSRMF questions

Is the PSRMF compulsory?

The PSRMF is a framework issued by National Treasury to support the risk management duties that the PFMA, MFMA and Treasury Regulations impose. Institutions are expected to implement risk management in line with it, and the Auditor-General and internal audit commonly assess maturity against it. Your legal advisers should confirm how it applies to your specific institution.

How does the PSRMF relate to ISO 31000?

They are compatible. The PSRMF is written for South African public institutions and carries the governance roles and maturity expectations that the public sector environment requires, while ISO 31000 is a general international guideline. Institutions that work to both will find the process steps map closely, and Dimeri holds one control set behind both scorecards.

What is combined assurance and why does it keep coming up?

Combined assurance means coordinating the assurance provided by management, internal audit and external providers so significant risks are covered without duplicating effort. It comes up because the alternative is common: several assurance providers testing the same well controlled process while a material risk goes untested for years. Dimeri generates the assurance map from live data so that imbalance is visible.

Can we use our own scoring criteria?

Yes. Impact and likelihood criteria, rating scales, appetite and tolerance thresholds are all configurable. Most institutions start from the framework's approach and adjust the impact definitions to their own budget and service delivery context.

Is this a substitute for legal advice?

No. This page describes how Dimeri implements the PSRMF structure for tracking and evidence. It is not legal advice, and your legal advisers should confirm what applies to your institution.

Put PSRMF on one register

Every requirement mapped to a control with a named owner, the evidence held against it, and one view of where you stand.