Culture & Conduct Diagnostics
Understand the Root Causes of Conduct Risk
If your organisation is struggling with repeated incidents, inconsistent behaviour, or a lack of trust in reporting channels, the root issue may not be isolated—it’s likely cultural. You may see signs of misalignment between your values and the behaviours playing out day to day, or between what leaders say and what teams actually experience. You might sense hesitation, silence, or fear around escalation, but find it difficult to pinpoint why.
Many organisations want to embed ethical decision-making, accountability, and transparency—but aren’t sure where the disconnect lies. That’s where a culture and conduct diagnostic becomes essential: to reveal the invisible dynamics shaping risk and conduct before they escalate into bigger failures.

What We Assess
To manage conduct risk effectively, you need to understand how your people experience risk, how your leaders influence behaviours, and where your culture may be misaligned with your values or risk appetite.
This diagnostic helps you uncover the invisible dynamics shaping risk across your organisation:
-
Behavioural Norms: How your people actually make decisions, escalate concerns, and respond to pressure.
-
Values Alignment: Gaps between your stated values (e.g. integrity, fairness) and the behaviours people see day to day.
-
Leadership Signals: What your leaders reward, ignore, or discourage—intentionally or not.
-
Cultural Indicators: Speak-up culture, challenge dynamics, tone from the top, and ethical grey zones.
-
Risk Blind Spots: Where silence, fear, or learned helplessness may suppress vital risk signals.
Testimonials
David Partridge, Become Charity
Director of Finance and People
"The tool is very useful and I'll be thinking about what it tells us as we develop our risk management processes further."
Why should you assess the strength of your organisation's governance and risk arrangements?
The success of your mission and your ability to support the community you serve are highly dependent on your organisation's resilience, regulatory compliance, and risk and governance arrangements.
The assessment will tell you where you need to improve your risk and governance arrangements to ensure compliance with the Charity Commission's requirements and ultimately stay safe. In addition, our scorecard methodology provides you with a score that allows you to track your progress over time.
In the United Kingdom, charities and non-profit organisations must comply with many regulatory requirements, starting with the Charity Commissions. As a trustee, you bear personal responsibility for the financial performance of the organisation you manage. With that, you are also responsible for your management account's risk management statement.
Whether you are part of the management or act as a trustee, you are expected to enable and support all key aspects of the risk management process, particularly in setting the parameters of the process and reviewing and considering the results.

Case Study: UK Charity
This case study is a reminder that risk management is, by its very nature, a pro-active, people-centric mindset. Many charities find staying on top of governance and risk management difficult. Often, they lack the resources and expertise to assess themselves on their own. And sourcing external assistance can be beyond their financial reach.
Four warning signs your risk and governance arrangements are not effective
01.
You cannot remember of the last time your risk register was discussed at the board.
02.
You have limited bandwidth to manage evolving legal obligations, potentially inadequate governance structures, and cybersecurity weaknesses that could result in data breaches.
03.
When was the last time you reviewed your policies? Well, you don't know. When the board last reviewed any of these documents, none of the current board trustees or directors were present.
04.
You only hear from the same person. No one else from the management team ever attends any board meetings or sub-committee.
Next Steps
Congratulations! You have completed the assessment, and you know how protected you really are. What's next?
Leave your findings for another day!
You have a top score, or you don't feel this warrants any more of your time. If so, thank you for completing the assessment, and we are here to help whenever you might need some support in the future. In the meantime, feel free to read our additional resources on our blog.
Disclaimer
We only provide the Charity Maturity Assessment Scorecard for informational purposes. This assessment generates results and recommendations based on user-provided information, aiming to offer general guidance on governance and risk management practices. Please read our Terms of Use for more information and confidentiality.