FREQUENTLY ASKED QUESTIONS (FAQs')

What does a risk audit tell me?

Because it has been developed to be in direct alignment with the principles of the ISO 31000:2018 Risk Management Standard the audit will quickly inform you as to the level of risk governance your organisation is currently achieving. You are provided with a scoring table which will indicate both your level of risk governance against the Standard as well as the period of professional services recommended.

What is a Risk Context Profile (RCP)?

A Risk Context Profile (RCP) is a thoroughly researched applied instrument enabling a company to both identify and assess the key risk areas which the company must manage in order to remain competitive.

What is a Business Impact Rating (BIR)?

A Business Impact Rating (BIR) links the results of the company's RCP to the key business elements underpinning the company thereby providing the company with a metered record of the impact of the assessed risk areas on its key business activities

What is a Risk Surveillance Centre (RSC)?

The Risk Surveillance Centre (RSC) is an interactive visual representation depicting dedicated controls for previously assessed key risk areas together with both company and external personnel charged with their management.

What risk services can I expect over 12 months?

In accordance with your 'Contract of Services' GRPA will:

• both guide and quality assure your company's application and interpretation of the completed RCP, BIR, and RSC.

• Undertake verification of all controls submitted to GRPA for review

• Provide 24 /7 specialist risk advice to your company upon email/telephone request

• Assist in the quarterly re-application of the RCP and BIR.

• Asist in the quarterly review of the RSC

• Respond to any ad hoc risk-related queries

When do the 12 months risk services start?

Once you have completed the RCP, BIR, and constructed a RSC it is at that point that your 12 months of services commence.

Can we extend the risk services at the end of 12 months?

Yes, resulting in a 25% discount on fees.

If we have an in-house risk person does this mean that GRPA services are not really required?

If your company has a dedicated risk professional on its books this assists both your company and GRPA in ensuring the guidance of effective and efficient company-appropriate risk services. Definitely a value-add.

If we have more than one site how would this affect the costs of services?

• One Site $18,995

• Two Sites $14,246 per site 25% discount

• Three Sites $12,536 per site 30% discount

• More than Three $10,000 flat fee per site

Do we have to pay a deposit?

No -GRPA does not require a deposit

Are the fees inclusive of GST and VAT?

Yes

Are our communications (inclusive of documents) to GRPA considered to be confidential?

A Non -Disclosure Agreement forms an Annex to the 'Contract of Services'

Will we have a dedicated risk specialist assigned to us?

Yes

Will we get a discount if we re-contract GRPA after the initial 12 months of services?

Yes- 25% discount

At what point to we pay the fees?

You will only pay your fees after the RCP, BIR, and RSC are complete

Will GRPA verify our successful completion of the RCP, BIR, and RSC?

Yes- a Framed and Duly Verified GRPA Certificate will be issued upon receipt of fees as stated in the SLA

Does GRPA pay commissions on referrals made?

A 25 % Commission is paid upon receipt of fees from the referred company