KITE 2025 New Product Award โ€” Local IT | SACEEC
Risk

PSRMF coverage that turns maturity from a claim into evidence

Governance roles occupied, assessments running on cycle, combined assurance mapped and maturity demonstrated from the platform's own history rather than a narrative.

app.dimeri.ai/compliance
87%Compliant
24Controls
3Pending
Access control policy
Incident response plan
Vendor assessments
Awareness training

Compliance at a glance

What the PSRMF sets out

Governance roles that are occupied

Committee charters, meeting calendars, attendance records and risk champion assignments tracked against real people and real dates, not just described in policy.

Assessments on a defensible cycle

Risk identification, scoring and response running on schedule with version history showing how the picture changed, exactly what a maturity review tests.

Combined assurance that maps through

Management, internal audit and external assurance mapped against significant risks, exposing both the gaps and the duplication before the audit plan is finalised.

Maturity you can demonstrate

The platform's own history provides the evidence: assessments completed on schedule, treatments closed, committee minutes acted on, KRIs reviewed.

PSRMF compliance, covered by default

The difference between a framework that is filed and one that is implemented is the difference between describing risk management and demonstrating it. Dimeri delivers the governance, assessment, assurance and maturity structure the PSRMF calls for.

app.dimeri.ai/compliance
87%Compliant
24Controls
3Pending
Access control policy
Incident response plan
Vendor assessments
Awareness training

Governance structure configured

Risk management committee, audit committee, chief risk officer and risk champion roles set up with charters, meeting calendars, attendance records and escalation routes from day one.

app.dimeri.ai/controls
RefControlStatus
A.5.1Information security policiesโœ“ Implemented
A.6.1Screeningโœ“ Implemented
A.7.4Physical security monitoringIn progress
A.8.2Privileged access rightsโœ“ Implemented

Full assessment cycle

Risk identification, assessment and response running on a defined cycle, with cause-event-consequence descriptions, configurable criteria and inherent, residual and target ratings held separately.

Exposure heatmapResidual
Likelihood
213114223512621431
LowImpactSevere
Critical 4High 10Medium 17Low 11

Combined assurance map

Management assurance, internal audit and external assurance mapped against significant risks, exposing both the gaps and the duplication before the audit plan is finalised.

Control libraryISO 31000
Segregation of duties92%Preventive
Exception reporting74%Detective
Incident escalation61%Corrective

Maturity evidence

Maturity self-assessment held against the evidence the platform already captures, including version history, assessment frequency and committee actions, so movement is demonstrable rather than asserted.

Board packGenerated
Audit & risk committeeQ3 ยท 18 pp
12Above appetite โ†“ 387%Controls tested โ†‘ 9
01Risk appetite position3 pp02Movements since last meeting2 pp03Control effectiveness4 pp04Overdue treatment actions1 p

Key risk indicators

KRIs tracked with thresholds and trends, feeding the standing reporting pack and giving the risk committee something to act on between formal assessment cycles.

The obligations Dimeri tracks

Dimeri implements the PSRMF as working structure rather than a policy annexure, because that is the difference the maturity review is looking for.

Risk management governance

Clear roles for the accounting officer or authority, the risk management committee, the audit committee, the chief risk officer and risk champions.

  • Committee charters held with their review dates
  • Meeting calendar, attendance and quorum records
  • Role assignments recorded against named individuals
  • Escalation routes configured to match the structure

Risk identification

Systematic identification across strategic, operational, financial, compliance, project and fraud risk, refreshed as the environment changes.

  • Register segmented by risk category and directorate
  • Workshop and interview inputs captured with their source
  • Emerging risk capture between formal cycles
  • Risk descriptions written as cause, event and consequence

Risk assessment

Likelihood and impact assessed against defined criteria, with inherent and residual positions distinguished and the basis recorded.

  • Configurable impact and likelihood criteria
  • Inherent, residual and target ratings held separately
  • Rating rationale recorded with the assessor and date
  • Heat map and ranked exposure views

Risk response

A chosen response for each risk, whether treat, tolerate, transfer or terminate, with the actions that carry it out.

  • Response strategy recorded per risk
  • Treatment actions with owners and due dates
  • Cost and benefit of response documented where material
  • Residual position reassessed after treatment

Combined assurance

Coordination of management, internal audit and external assurance so coverage is deliberate rather than accidental.

  • Assurance map by risk and assurance provider
  • Over-assured and unassured risks surfaced
  • Internal audit plan aligned to significant risks
  • Assurance results fed back into control ratings

Monitoring, reporting and maturity

Continuous monitoring, reporting to the committees and the executive authority, and periodic assessment of maturity against the framework.

  • Standing reporting pack generated from live data
  • Key risk indicators tracked with thresholds
  • Maturity self assessment held with supporting evidence
  • Year on year movement visible rather than asserted

Getting PSRMF coverage in place

4 steps from where you are today to a PSRMF position your auditor can rely on.

Book a demo

Committees, charters, the chief risk officer role and risk champions per directorate are configured so the platform reflects how the institution is actually governed.

How Dimeri covers PSRMF

Maturity you can evidence

Because the register carries its own history, maturity movement is demonstrable. You can show that risks were reassessed on schedule, that treatments closed, and that the committee acted on what it was shown, which is exactly what a maturity review is looking for.

Combined assurance that maps through

The assurance map is generated from the register and the audit plan rather than drawn by hand each year. Risks with three assurance providers and risks with none are both visible in the same view.

One assessment, three frameworks

The assessment that satisfies the PSRMF also satisfies the corresponding Treasury Regulation and PFMA risk management duties, or the MFMA equivalents. Dimeri records it once and credits all of them.

PSRMF questions

Is the PSRMF compulsory?

The PSRMF is a framework issued by National Treasury to support the risk management duties under the PFMA, MFMA and Treasury Regulations. Institutions are expected to implement risk management in line with it, and the Auditor-General and internal audit commonly assess maturity against it. Your legal advisers should confirm how it applies to your specific institution.

How does the PSRMF relate to ISO 31000?

They are compatible. The PSRMF is written for South African public institutions and carries the governance roles and maturity expectations that the public sector environment requires, while ISO 31000 is a general international guideline. Institutions that work to both will find the process steps map closely, and Dimeri holds one control set behind both scorecards.

What is combined assurance and why does it keep coming up?

Combined assurance means coordinating the assurance provided by management, internal audit and external providers so significant risks are covered without duplicating effort. It comes up because the alternative is common: several assurance providers testing the same well controlled process while a material risk goes untested for years. Dimeri generates the assurance map from live data so that imbalance is visible.

Can we use our own scoring criteria?

Yes. Impact and likelihood criteria, rating scales, appetite and tolerance thresholds are all configurable. Most institutions start from the framework's approach and adjust the impact definitions to their own budget and service delivery context.

Is this a substitute for legal advice?

No. This page describes how Dimeri implements the PSRMF structure for tracking and evidence. It is not legal advice, and your legal advisers should confirm what applies to your institution.

Ready to Transform Your GRC?

Join governance, risk, and compliance teams using AI to work smarter.