Achieved with the use of ChatGPT by our Founder, Prof. Dr. Camilo ESCOBAR MORA:

DCLRMA™ v1.0

DIGITAL CONSUMER LEGAL RISK MATURITY ASSESSMENT™

Comprehensive Maturity Assessment Model

Developed under the DCLRAF™

Digital Consumer Legal Risk Assessment Framework™


1. PURPOSE OF THE MODEL

The Digital Consumer Legal Risk Maturity Assessment™ (DCLRMA™) is a structured methodology designed to measure an organization’s ability to identify, assess, prioritize, control, remediate, document, and monitor legal risks arising from its digital interactions with consumers.

The model evaluates, in an integrated manner:

  • Governance;
  • Risk strategy;
  • Risk identification and assessment;
  • Consumer Journey;
  • Transparency;
  • Marketing and commercial practices;
  • Digital contracting;
  • Pricing and payments;
  • UX and consumer autonomy;
  • Data, privacy and personalization;
  • Artificial intelligence and automation;
  • Consumer rights and remedies;
  • Controls and evidence;
  • Monitoring and remediation;
  • Organizational culture and capabilities.

2. CORE QUESTION

The DCLRMA™ is designed to answer:

How mature is the organization’s ability to manage digital consumer legal risk in a preventive, integrated, evidence-based, and continuous manner?

The assessment does not merely determine whether a particular practice is legally compliant.

It evaluates whether the organization has the institutional capability to identify, manage, demonstrate, and continuously improve its management of digital consumer legal risk.


3. OBJECTIVES

The DCLRMA™ enables an organization to:

  1. Establish a baseline maturity level.
  2. Identify organizational strengths.
  3. Detect capability gaps.
  4. Identify potential areas of exposure.
  5. Evaluate capabilities and controls.
  6. Measure cross-functional integration.
  7. Prioritize actions.
  8. Assign accountability.
  9. Develop a 90-Day Roadmap.
  10. Measure organizational progress over time.

4. WHAT THE DCLRMA™ IS — AND IS NOT

It is

An assessment of:

Maturity + Capability + Governance + Controls + Evidence + Monitoring

It is not

  • A legal audit;
  • A legal opinion;
  • A regulatory audit;
  • A financial audit;
  • A cybersecurity assessment;
  • A comprehensive privacy assessment;
  • A regulatory certification;
  • A guarantee of legal compliance.

The DCLRMA™ is fundamentally an:

Organizational Maturity and Capability Assessment

for the management of digital consumer legal risk.


5. METHODOLOGICAL PRINCIPLE

The model follows the chain:

CAPABILITY → PROCESS → CONTROL → EVIDENCE → OUTCOME

An organization does not receive a high maturity score simply because it has a policy.

The assessment determines whether the capability:

Exists

Is designed

Is implemented

Works

Can be demonstrated

Produces measurable outcomes


6. SCOPE

The DCLRMA™ can be applied to:

  • E-commerce;
  • Marketplaces;
  • Fintech;
  • Digital banking;
  • Insurance;
  • B2C SaaS;
  • Digital platforms;
  • Mobile applications;
  • Subscription businesses;
  • Telecommunications;
  • Streaming;
  • Travel technology;
  • Mobility;
  • Retail;
  • Digital healthcare;
  • EdTech;
  • Consumer technology.

7. APPLICATION LEVELS

The DCLRMA™ can be deployed at five levels:

LEVEL A — ENTERPRISE

Enterprise-wide assessment.

LEVEL B — BUSINESS UNIT

Assessment of a specific business unit.

LEVEL C — PRODUCT

Assessment of a specific digital product or service.

LEVEL D — CONSUMER JOURNEY

Assessment of a specific consumer experience.

LEVEL E — JURISDICTION

Assessment focused on a specific jurisdiction or market.


8. MODEL ARCHITECTURE

The DCLRMA™ consists of:

15 DIMENSIONS

Each dimension contains:

  • 5 core indicators;
  • maturity criteria;
  • assessment questions;
  • expected evidence;
  • score;
  • maturity gap;
  • priority level;
  • recommended actions.

Total:

75 ASSESSMENT INDICATORS


9. THE 15 ASSESSMENT DIMENSIONS

# Dimension Weight
1 Governance & Accountability 8%
2 Risk Strategy & Risk Appetite 6%
3 Risk Identification & Assessment 8%
4 Consumer Journey Risk Management 10%
5 Transparency & Consumer Information 7%
6 Marketing & Commercial Practices 6%
7 Digital Contracting 7%
8 Pricing, Payments & Subscriptions 7%
9 UX, Choice & Consumer Autonomy 8%
10 Data, Privacy & Personalization 7%
11 AI & Automation 7%
12 Consumer Rights & Remedies 6%
13 Controls & Evidence 7%
14 Monitoring, Incidents & Remediation 6%
15 Culture & Organizational Capability 5%
TOTAL 100%

Weights may be customized according to industry, jurisdiction, product, business model, and risk profile.


10. MATURITY SCALE

Each indicator is scored from 0 to 5.

Score Level Description
0 Non-Existent Capability does not exist
1 Reactive Risk is addressed after problems occur
2 Developing Partial capabilities exist
3 Defined Capability is formally established
4 Managed Capability is implemented, measured and monitored
5 Optimized Capability is integrated, predictive and continuously improved

11. LEVEL 0 — NON-EXISTENT

No identifiable capability exists.

There is insufficient evidence of:

  • ownership;
  • process;
  • control;
  • documentation;
  • evidence.

Core characteristic

Absence of capability.


12. LEVEL 1 — REACTIVE

The organization responds when a problem occurs.

Characteristics include:

  • case-by-case management;
  • dependency on individuals;
  • delayed intervention;
  • limited methodology;
  • limited documentation.

Core characteristic

Risk is primarily managed after it materializes.


13. LEVEL 2 — DEVELOPING

Partial initiatives or controls exist.

Characteristics include:

  • isolated processes;
  • inconsistent controls;
  • fragmented responsibilities;
  • uneven implementation;
  • limited integration.

Core characteristic

Capability exists but is not yet consolidated.


14. LEVEL 3 — DEFINED

A formal methodology exists.

Characteristics include:

  • policies;
  • procedures;
  • assigned responsibilities;
  • methodology;
  • documentation;
  • assessment criteria.

Core characteristic

Capability is formally established.


15. LEVEL 4 — MANAGED

Capability is integrated into organizational management.

Characteristics include:

  • metrics;
  • control testing;
  • evidence;
  • reporting;
  • ownership;
  • escalation;
  • monitoring.

Core characteristic

Capability is actively managed and measured.


16. LEVEL 5 — OPTIMIZED

Capability is integrated, predictive and continuously improved.

Characteristics include:

  • analytics;
  • automation;
  • continuous monitoring;
  • risk-by-design;
  • predictive indicators;
  • organizational learning;
  • continuous improvement.

Core characteristic

The organization anticipates and optimizes risk.


17. DIMENSION 1 — GOVERNANCE & ACCOUNTABILITY

GOV-01

An executive owner is accountable for digital consumer legal risk.

GOV-02

Responsibilities across Legal, Compliance, Risk, Product and Operations are formally defined.

GOV-03

A governance body or mechanism exists to review material risks.

GOV-04

A formal escalation process exists.

GOV-05

Senior management receives periodic reporting on material risks.

Suggested evidence

  • RACI;
  • Governance Charter;
  • committee minutes;
  • risk reports;
  • escalation matrix;
  • organizational responsibilities.

18. DIMENSION 2 — RISK STRATEGY & RISK APPETITE

STR-01

A strategy exists for managing digital consumer legal risk.

STR-02

Materiality criteria are defined.

STR-03

Potential consumer harm is considered.

STR-04

Criteria exist for accepting, mitigating or escalating risks.

STR-05

Digital consumer legal risk is integrated into enterprise risk management.

Evidence

  • Risk Appetite;
  • Risk Taxonomy;
  • policies;
  • strategy documents;
  • materiality criteria.

19. DIMENSION 3 — RISK IDENTIFICATION & ASSESSMENT

RSK-01

A formal methodology exists for identifying risks.

RSK-02

New products are subject to risk assessment.

RSK-03

Material changes trigger reassessment.

RSK-04

Incidents and complaints inform risk identification.

RSK-05

An up-to-date Risk Register exists.

Evidence

  • Risk Register;
  • risk assessments;
  • product approval records;
  • methodologies;
  • assessment documentation.

20. DIMENSION 4 — CONSUMER JOURNEY RISK MANAGEMENT

CJR-01

The organization identifies its key Consumer Journeys.

CJR-02

Legal risks are identified across relevant journey stages.

CJR-03

Potential Consumer Harm is assessed.

CJR-04

Legal participates in relevant stages of journey and product design.

CJR-05

Material journey changes trigger reassessment.

Reference Consumer Journey

Discovery

Acquisition

Onboarding

Contracting

Payment

Use

Support

Renewal

Cancellation

Post-Service


21. DIMENSION 5 — TRANSPARENCY & CONSUMER INFORMATION

TRN-01

Material information is presented clearly.

TRN-02

Relevant costs and conditions are visible.

TRN-03

Terms and disclosures are accessible.

TRN-04

Material changes are communicated appropriately.

TRN-05

Transparency is reviewed before launch.

Evidence

  • disclosures;
  • terms and conditions;
  • UX reviews;
  • consumer testing;
  • approval records.

22. DIMENSION 6 — MARKETING & COMMERCIAL PRACTICES

MKT-01

Marketing claims are subject to review.

MKT-02

Promotions have defined approval criteria.

MKT-03

Potentially misleading claims are subject to controls.

MKT-04

Personalization and targeting are assessed.

MKT-05

Material communications have documented approval.

Evidence

  • campaigns;
  • claims review;
  • substantiation;
  • marketing policies;
  • approval records.

23. DIMENSION 7 — DIGITAL CONTRACTING

CTR-01

A controlled digital contracting process exists.

CTR-02

Consumer acceptance or consent is recorded.

CTR-03

Terms and conditions are subject to version control.

CTR-04

Contractual changes are formally managed.

CTR-05

Sufficient evidence of contracting is retained.

Evidence

  • contracts;
  • acceptance logs;
  • version control;
  • interaction records;
  • clickstream evidence.

24. DIMENSION 8 — PRICING, PAYMENTS & SUBSCRIPTIONS

PAY-01

Pricing and charges are transparent.

PAY-02

Recurring charges are clearly communicated.

PAY-03

Renewals are appropriately managed.

PAY-04

Refunds and payment disputes are subject to defined processes.

PAY-05

Billing incidents are monitored.

Suggested indicators

  • unexpected charges;
  • refund failures;
  • chargebacks;
  • renewal complaints;
  • billing incidents.

25. DIMENSION 9 — UX, CHOICE & CONSUMER AUTONOMY

UX-01

Legal risks arising from UX design are assessed.

UX-02

Choice and consent mechanisms are reviewed.

UX-03

Defaults and nudges are assessed.

UX-04

Potential dark patterns are assessed.

UX-05

Cancellation experiences are evaluated from the consumer perspective.

Evidence

  • UX Reviews;
  • journey testing;
  • design documentation;
  • consumer testing.

26. DIMENSION 10 — DATA, PRIVACY & PERSONALIZATION

DAT-01

Consumer Risk and Privacy functions coordinate effectively.

DAT-02

Personalization is assessed from a legal risk perspective.

DAT-03

Profiling is subject to appropriate governance.

DAT-04

Material data uses are assessed before implementation.

DAT-05

Appropriate transparency and consumer choice mechanisms exist.


27. DIMENSION 11 — AI & AUTOMATION

AI-01

Governance exists for consumer-relevant AI use cases.

AI-02

Legal risks and potential Consumer Harm are assessed.

AI-03

Accountability exists for automated systems.

AI-04

Relevant automated systems are monitored.

AI-05

Appropriate escalation or human intervention mechanisms exist where required.

Evidence

  • AI inventory;
  • AI risk assessments;
  • model documentation;
  • governance records;
  • monitoring reports.

28. DIMENSION 12 — CONSUMER RIGHTS & REMEDIES

REM-01

A structured consumer complaints process exists.

REM-02

Cancellation requests are appropriately managed.

REM-03

Refund processes are controlled.

REM-04

Material cases are escalated.

REM-05

Recurring incidents trigger root-cause analysis.

Suggested indicators

  • complaint rate;
  • resolution time;
  • refund failure rate;
  • escalation rate;
  • recurring incident rate.

29. DIMENSION 13 — CONTROLS & EVIDENCE

CTL-01

Material risks have assigned controls.

CTL-02

Each control has an accountable owner.

CTL-03

Controls are tested.

CTL-04

Evidence of control operation is retained.

CTL-05

Control testing results generate corrective actions.

Control chain

Risk

Control

Owner

Evidence

Testing

Result


30. DIMENSION 14 — MONITORING, INCIDENTS & REMEDIATION

MON-01

Risk indicators are defined.

MON-02

Red Flags are identified.

MON-03

Incidents are investigated.

MON-04

A remediation process exists.

MON-05

Root Cause Analysis is performed.


31. DIMENSION 15 — CULTURE & ORGANIZATIONAL CAPABILITY

CUL-01

Relevant teams receive appropriate training.

CUL-02

Awareness of digital consumer legal risk exists across the organization.

CUL-03

Risk Owners understand their responsibilities.

CUL-04

Cross-functional collaboration exists.

CUL-05

Lessons learned are incorporated into future processes.


32. SCORING METHOD

Each indicator receives a score from:

0–5

The score for each dimension is calculated as:

Average of applicable indicators within the dimension.

Example

Governance:

4 + 3 + 4 + 3 + 4 = 18

18 ÷ 5 =

3.6


33. WEIGHTED MATURITY SCORE

The overall score is calculated using:

Σ (Dimension Score × Dimension Weight)

Example:

Governance:

3.6 × 8% = 0.288

Consumer Journey:

2.2 × 10% = 0.220

AI:

1.4 × 7% = 0.098

All dimensions are then aggregated.

Result:

OVERALL MATURITY SCORE

Scale:

0.00 – 5.00


34. PERCENTAGE CONVERSION

Maturity % = Overall Score ÷ 5 × 100

Example:

3.20 ÷ 5 × 100

=

64%


35. OVERALL MATURITY CLASSIFICATION

Score Percentage Level
0.00–0.99 0–19% Critical
1.00–1.99 20–39% Reactive
2.00–2.99 40–59% Developing
3.00–3.49 60–69% Defined
3.50–4.49 70–89% Managed
4.50–5.00 90–100% Optimized

36. EVIDENCE CONFIDENCE LEVEL

The DCLRMA™ incorporates a second variable:

EVIDENCE CONFIDENCE

Two organizations may report the same maturity score while having very different levels of supporting evidence.

E0 — No Evidence

No verifiable evidence exists.

E1 — Self-Reported

Information is based primarily on participant statements.

E2 — Documented

Formal documentation exists.

E3 — Implemented

Evidence demonstrates actual implementation.

E4 — Tested

Evidence demonstrates testing and effectiveness.

E5 — Independently Validated

Evidence has been independently reviewed or validated.


37. VALIDATION RULE

An organization should not be classified as:

Level 4 — Managed

or

Level 5 — Optimized

solely on the basis of self-reporting.

Levels 0–2

Self-assessment may be sufficient for an initial diagnostic.

Level 3

Documentary evidence is required.

Level 4

Evidence of implementation, measurement and monitoring is required.

Level 5

Evidence of outcomes, optimization and continuous improvement is required.


38. EVIDENCE-ADJUSTED MATURITY

For advanced assessments, the following concept may be used:

Declared Maturity × Evidence Confidence Factor = Validated Maturity

This creates a distinction between:

DECLARED MATURITY

What the organization says it does.

VALIDATED MATURITY

What the organization can demonstrate through evidence.


39. MATURITY GAP

For each dimension:

Gap = Target Maturity – Current Maturity

Example:

Target maturity = 4.0

Current maturity = 2.0

Gap = 2.0


40. RISK PRIORITY SCORE

Maturity gap alone does not determine priority.

Each gap should also be evaluated according to:

  • Likelihood;
  • Legal Exposure;
  • Potential Consumer Harm;
  • Business Impact;
  • Control Weakness;
  • Strategic Relevance.

Each factor may be scored from:

1 — Low

to

5 — Very High

Recommended formula

Risk Priority Score = Gap × Exposure × Consumer Harm × Control Weakness

The result may subsequently be normalized to a 100-point scale.


41. PRIORITY LEVELS

P1 — CRITICAL

Immediate action required.

P2 — HIGH

Priority action required.

P3 — MODERATE

Include in the roadmap.

P4 — LOW

Monitor or improve as resources permit.


42. MATURITY HEATMAP

GREEN

≥ 4.0

Managed capability.

YELLOW

3.0–3.99

Defined capability.

ORANGE

2.0–2.99

Developing capability.

RED

< 2.0

Reactive or non-existent capability.


43. MATURITY PROFILE

The final report should display:

OVERALL MATURITY

3.1 / 5

MATURITY LEVEL

Defined

TOP STRENGTHS

  1. Data & Privacy
  2. Digital Contracting
  3. Governance

TOP GAPS

  1. AI Governance
  2. Consumer Journey
  3. Monitoring

TOP PRIORITIES

  1. AI Risk Framework
  2. Consumer Journey Risk Mapping
  3. Red Flag Monitoring

44. EXECUTIVE RISK PROFILE

The assessment should answer five executive questions:

1. WHERE ARE WE?

Overall maturity level.

2. WHAT ARE WE DOING WELL?

Organizational strengths.

3. WHERE ARE THE GAPS?

Capability gaps.

4. WHAT MATTERS MOST?

Priority risks.

5. WHAT SHOULD WE DO NEXT?

90-Day Roadmap.


45. 90-DAY ROADMAP GENERATION

DAYS 1–30 — FOUNDATION

  • Governance;
  • accountability;
  • Risk Register;
  • critical gaps;
  • immediate controls.

DAYS 31–60 — BUILD

  • controls;
  • Consumer Journey Reviews;
  • training;
  • evidence;
  • monitoring.

DAYS 61–90 — EMBED

  • dashboards;
  • control testing;
  • governance;
  • Red Flags;
  • executive reporting.

46. COMPLETE ASSESSMENT PROCESS

PHASE 1 — PREPARATION

Define:

  • scope;
  • business units;
  • products;
  • jurisdictions;
  • participants.

PHASE 2 — SELF-ASSESSMENT

Deploy the assessment questionnaire.

PHASE 3 — EVIDENCE COLLECTION

Collect and review relevant documentation.

PHASE 4 — STAKEHOLDER INTERVIEWS

Interview relevant stakeholders.

PHASE 5 — CONSUMER JOURNEY REVIEW

Review priority journeys.

PHASE 6 — VALIDATION

Cross-check responses against available evidence.

PHASE 7 — SCORING

Calculate maturity scores.

PHASE 8 — PRIORITIZATION

Identify and rank material capability gaps.

PHASE 9 — EXECUTIVE REPORT

Present findings and recommendations.

PHASE 10 — ROADMAP

Develop the 90-Day Action Plan.


47. PARTICIPANTS

CORE TEAM

Legal

Compliance

Risk

Product

Operations

EXTENDED TEAM

As appropriate:

  • UX;
  • Marketing;
  • Privacy;
  • Data;
  • AI;
  • Technology;
  • Security;
  • Customer Experience.

The assessment should be multidisciplinary because digital consumer legal risk rarely belongs to a single organizational function.


48. QUALITY RULES

RULE 1

Do not score policies alone.

RULE 2

Request evidence.

RULE 3

Cross-check multiple functions.

RULE 4

Review the Consumer Journey.

RULE 5

Distinguish design from implementation.

RULE 6

Distinguish implementation from effectiveness.

RULE 7

Separate maturity from legal compliance.

RULE 8

Document assumptions.

RULE 9

Record N/A determinations.

RULE 10

Record evidence confidence.


49. N/A RULE

An indicator may be classified as:

N/A — Not Applicable

only where there is a reasonable and documented basis.

N/A responses should not artificially reduce an organization’s maturity score.

Scoring should be based on applicable indicators only.


50. DCLRMA™ MASTER SCORECARD

Dimension Weight Score Gap Priority Confidence
Governance 8%
Strategy 6%
Risk Identification 8%
Consumer Journey 10%
Transparency 7%
Marketing 6%
Contracting 7%
Pricing & Payments 7%
UX 8%
Data / Privacy 7%
AI 7%
Consumer Rights 6%
Controls 7%
Monitoring 6%
Culture 5%

51. ASSESSMENT DELIVERABLES

The DCLRMA™ assessment package should include:

01

DCLRMA™ Assessment Questionnaire

02

Evidence Request List

03

Maturity Scorecard

04

Maturity Heatmap

05

Evidence Confidence Profile

06

Capability Gap Analysis

07

Top 5 Priority Gaps

08

Executive Risk Profile

09

Management Recommendations

10

90-Day Roadmap

11

Executive Presentation


52. DCLRMA™ VS. LEGAL AUDIT

Legal Audit DCLRMA™
Is the organization compliant? How mature is the capability?
Primarily legal Multidisciplinary
Legal findings Capabilities + gaps
Legal obligations Risks + controls
Point-in-time review Continuous capability
Legal-centric Consumer + Business + Legal
Compliance Risk Management

53. DCLRMA™ VS. TRAINING

Assessment Training
Diagnoses Develops
Measures Teaches
Identifies gaps Builds capabilities
Produces a score Produces knowledge and skills
Defines priorities Develops competencies
Recommends roadmap Supports implementation

Accordingly, the recommended model is:

ASSESS BEFORE YOU TRAIN

The assessment results can be used to design training based on the organization’s actual capability gaps.


54. COMMERCIAL ARCHITECTURE

The DCLRMA™ can operate as a standalone product and as the entry point to the broader DCLRAF™ ecosystem.

1. DIAGNOSE

DCLRMA™ Rapid Assessment

2. REPORT

Executive Maturity Report

3. DEVELOP

DCLRAF™ Team Training

4. IMPLEMENT

DCLRAF™ 90-Day Corporate Roadmap

5. TRANSFORM

DCLRAF™ Corporate Risk Capability Program

6. CONTINUE

Continuous Monitoring / Annual Assessment


55. DCLRMA™ PRODUCT TIERS

DCLRMA™ RAPID

Purpose

Initial maturity diagnostic.

Duration

1–2 weeks.

Includes

  • 15 dimensions;
  • assessment questionnaire;
  • scoring;
  • heatmap;
  • key gaps;
  • executive report.

DCLRMA™ STANDARD

Purpose

Action-oriented organizational diagnostic.

Duration

3–4 weeks.

Includes

  • 75 indicators;
  • evidence review;
  • stakeholder interviews;
  • Consumer Journey Review;
  • scoring;
  • gap analysis;
  • risk prioritization;
  • 90-Day Roadmap.

DCLRMA™ ENTERPRISE

Purpose

Enterprise-wide capability assessment.

Duration

6–8 weeks.

Includes

  • multiple business units;
  • multiple products;
  • multiple Consumer Journeys;
  • multiple jurisdictions;
  • internal benchmarking;
  • evidence validation;
  • executive workshops;
  • transformation roadmap.

56. FINAL EXECUTIVE OUTPUT

The DCLRMA™ should enable an executive to answer five questions quickly:

WHERE ARE WE?

Maturity Level

WHAT ARE WE DOING WELL?

Strengths

WHERE ARE THE GAPS?

Capability Gaps

WHAT RISKS REQUIRE ATTENTION?

Priority Risks

WHAT SHOULD WE DO?

90-Day Roadmap

WHO OWNS THE ACTION?

Accountability


57. DCLRMA™ MASTER MODEL

DCLRMA™ v1.0

15 DIMENSIONS

75 INDICATORS

0–5 MATURITY SCALE

EVIDENCE

EVIDENCE CONFIDENCE

WEIGHTED MATURITY SCORE

GAP ANALYSIS

RISK PRIORITIZATION

MATURITY HEATMAP

TOP 5 PRIORITIES

EXECUTIVE REPORT

90-DAY ROADMAP

CAPABILITY DEVELOPMENT

CONTINUOUS MONITORING


DCLRMA™ v1.0

DIGITAL CONSUMER LEGAL RISK MATURITY ASSESSMENT™

FROM MATURITY TO RISK.

FROM RISK TO PRIORITY.

FROM PRIORITY TO ACTION.

FROM ACTION TO ORGANIZATIONAL CAPABILITY.

Developed under DCLRAF™ — Digital Consumer Legal Risk Assessment Framework™

ASSESS → IDENTIFY GAPS → PRIORITIZE → BUILD CAPABILITY → IMPLEMENT → MONITOR