Our client, a Dutch insurer, asked us to support them with their Systematic Integrity Risk Analysis, or SIRA. We mapped the organisation’s integrity risks, facilitated workshops to formulate recommendations, validated these recommendations with management and closed the loop by communicating management decisions back to the workshop participants. The result was a greater willingness to change across the organisation, a list of actionable improvements and increased efficiency.
Buy-in at the top
Our client, a Dutch insurer, engaged us to support them with their Systematic Integrity Risk Analysis, or SIRA. This involved not only conducting the analysis itself, but also ensuring that its outcomes were genuinely supported by senior management.
“The purpose of the SIRA is to provide insight into the integrity risks an organisation faces,” explains Johan Septer, an expert in this field. “This involves identifying risks and developing scenarios in which the integrity of the organisation could come under pressure. These may be internal risks, such as inappropriate behaviour, discrimination or bullying, but also external risks, such as money laundering or terrorist financing.”
In practice, however, it is often difficult to keep the SIRA closely connected to the business. As supervisory expectations have increased, the methodology has developed into a complex and technical process in many organisations. As a result, ownership regularly shifts away from the first line towards risk and compliance functions.
Consequently, the SIRA is sometimes primarily regarded as a mandatory exercise for the supervisory authority, rather than as an instrument for developing a better understanding of risks and implementing targeted improvements. At the same time, the need for external support is increasing, as organisations find it increasingly challenging to perform all the required analyses independently.
“To truly understand what is happening within an organisation and which scenarios may result in integrity risks, you need input from the business.”
Keep it manageable
The content of the SIRA is primarily the responsibility of the business. At the same time, management must be sufficiently involved to identify and assess risks and manage them effectively. The challenge is therefore to make the SIRA accessible and practical.
A thematic approach can help achieve this. By grouping risks around specific subjects, the SIRA becomes more concrete, tangible and manageable. Although periodic validation remains important, an increasing number of organisations are moving towards continuous risk management. This means that not every risk is analysed to the same level of detail each year. Instead, additional attention is given during a particular period to themes that are affected by relevant developments.
When updating the SIRA, it is therefore important not only to consider existing risks, but particularly to examine changes that may affect the risk profile. Examples include new products or services, changes in the customer portfolio, the outsourcing of activities, the digitalisation of processes, incidents, complaints or changes in legislation and regulations. Such developments often provide a good reason to reassess risks or scenarios.
A great deal of valuable information may also already be available within the organisation. The results of employee satisfaction surveys may, for example, provide insight into integrity culture, employees’ willingness to report concerns or inappropriate behaviour. Internal audits, compliance monitoring, incident reports and management information may also contain important signals regarding changes in integrity risks. This turns the SIRA into a continuous process rather than an annual exercise.
“Ultimately, a SIRA is nothing more than a collection of individual risk assessments. You do not have to analyse every aspect in depth every year. You can select several topics to work on and rotate them from year to year,” says Johan Septer.
“By aligning attention, capacity and control measures with the nature, scale and complexity of the organisation, the SIRA remains both manageable and relevant. Risks with a potentially material impact receive more attention, while lower-risk topics can be assessed proportionately.”
“I would say that every topic should be examined in depth at least once every three years. Naturally, when something changes within the organisation that affects its integrity risks, you should review it sooner. Dividing the analysis into smaller components keeps the process manageable.”
“By aligning attention, capacity and control measures with the nature, scale and complexity of the organisation, the SIRA remains both manageable and relevant.”
Ask the experts: SIRA workshops
We organised workshops with first-line managers and other employees outside the risk and compliance functions. Their knowledge of daily activities, processes and customer interactions helps make integrity risks more concrete and supports better-informed risk assessments. Combining this knowledge with the expertise of risk and compliance professionals creates a more complete and balanced risk picture.
“We discussed the scenarios from the previous SIRA. Are these still the most important risks, or are employees identifying other risks that deserve attention?” says Johan Septer. “For the external fraud theme, we brought together employees from different departments. It is interesting to see that people have sometimes worked together for years without knowing exactly what each other’s roles involve. Everyone sees part of the process, but no one sees the whole picture. By bringing together all this knowledge and experience, you gain much better insight than when the entire analysis is left to the risk and compliance department.”
During the workshops, the emphasis was not on assigning risk scores.
“The supervisory authority expects risks to be quantified, but instead of having lengthy discussions about whether a risk should receive a score of four or five, we focused on the questions that truly matter,” Septer explains. “Which risks do we face? Have any new risks emerged or have any risks disappeared? Are these risks sufficiently controlled? Are the control measures effective? And what evidence supports that conclusion?”
These are also the questions that are most relevant to management. By focusing on the substance rather than the score, the SIRA results in concrete improvement actions and better-informed decision-making. In this way, the SIRA becomes more than a mandatory risk assessment and delivers genuine value to the organisation.
Data and geopolitical developments
Workshops and expert judgement remain essential to an effective SIRA. At the same time, we are seeing an increasing number of organisations use data analysis to better substantiate their risks. Supervisory authorities are also placing greater emphasis on a data-driven approach, as demonstrated by De Nederlandsche Bank’s 2025 Good Practices on SIRA.
Analysing complaints, incidents, transactions, customer characteristics or reports can reveal patterns that may otherwise remain unnoticed. Geopolitical developments have also demonstrated how quickly the risk landscape can change. Sanctions regimes, international conflicts, supply-chain dependencies and societal developments may create new integrity risks that received little attention only a few years ago.
Organisations would therefore be well advised not to base their SIRA solely on historical risks and workshops, but also to use data, internal signals and external developments as input. Combining qualitative insights with quantitative analyses often results in a stronger, more up-to-date and better-substantiated risk picture.
“The strongest SIRA results from combining practical knowledge and experience with data-driven insights. This often provides better insight than leaving the entire analysis to Risk and Compliance.”
To-the-point reporting
After actively involving management in the SIRA, we also decided to present the results differently. We did not use the usual enormous spreadsheet: complex, filled with colours and barely readable. After all, when a report becomes too complicated, it loses its value.
“We deliberately kept the reporting concise and only provided additional detail where necessary: for material risks, the most important scenarios, differing risk assessments and proposed measures,” explains Johan Septer. “Questions such as ‘What is our risk profile?’ often lead to interesting discussions. One person may regard a particular risk as limited, while someone else sees the same risk as one of the greatest threats to the organisation’s continuity or reputation.”
In addition to the risk analysis, the recommendations from the workshops were included in the report. One question was central: what do the employees who work with these products, processes and risks every day experience in practice? Their insights are often a valuable source for identifying improvements.
Management subsequently assesses the proposed measures and decides which improvements will be implemented. It is equally important that these decisions are communicated back to the employees who contributed to the process. This ensures that everyone can see what has been done with the input provided during the workshops.
“People want to know that their efforts have had an effect. Moreover, they are often much more receptive to changes when they have contributed to developing the solutions themselves,” says Septer.
“It is about increasing risk awareness across the organisation while recognising and valuing employees’ knowledge and expertise.”
The power of interaction
Based on the results of the workshops, we formulated recommendations that were subsequently validated by the employees who had participated in the sessions. Following this validation, the recommendations were discussed with management, which decided which improvement measures would be taken forward.
“Management responded positively to many of the recommendations,” says Johan Septer. “In some cases, it even turned out that action had already been taken, while employees on the work floor were unaware of it. This provided management with an important signal that decisions needed to be communicated more effectively.”
It is precisely this interaction between management and employees that makes the process valuable. By gathering insights from across the organisation, communicating what is being done with them and jointly implementing improvements, engagement, support and ownership increase. This interaction within the organisation is particularly powerful and contributes to a better-functioning organisation as a whole.
What comes next?
The process does not stop once the SIRA has been completed. Organisations must also implement and embed the identified improvement measures. Additional support can be valuable in this phase.
“We agreed with this client that we would support them throughout the entire three-year SIRA cycle,” explains Johan Septer. “When you only start thinking about the SIRA in the fourth quarter, when everyone’s calendars are already filled with other priorities, it becomes difficult to give it sufficient attention. Organisations should therefore schedule workshops in good time and keep the subject on the agenda throughout the year.”
The support required differs from one organisation to another. Some organisations mainly need a critical sparring partner, while others require assistance with the further design and execution of their SIRA process.
The greatest value is created when the SIRA is integrated into existing processes. Examples include project governance, product development, incident management, HR initiatives, outsourcing processes and IT risk analyses.
“If IT is conducting a cyber risk analysis, why would we not immediately include the behavioural and integrity components as well?” says Septer.
By taking integrity risks into account throughout the year as part of existing decision-making processes, organisations create not only a more efficient approach, but also a more current and better-substantiated risk picture. The SIRA therefore becomes an integral part of business operations rather than an annual project.
Monitoring and testing activities can also provide valuable input. Examples include reviews of customer files, transaction monitoring, sanctions screening, compliance monitoring, control testing and periodic evaluations of control measures. Organisations that use a GRC tool can collect and analyse this information throughout the year. This allows changes in the risk profile to be identified in good time and the effectiveness of control measures to be monitored more effectively.
“The greatest value is created when the SIRA is no longer an annual exercise, but an integral part of day-to-day business operations.”
About Projective Group
Established in 2006, Projective Group is a leading Financial Services change specialist. With deep expertise across practices in Data, Payments, Transformation and Risk & Compliance.
We are recognised within the industry as a complete solutions provider, partnering with clients in Financial Services to provide resolutions that are both holistic and pragmatic. We have evolved to become a trusted partner for companies that want to thrive and prosper in an ever-changing Financial Services landscape.