What Is Jigsaw Risk Management?
The Short Version
Sexual abuse safety is the discipline of building, sustaining, and measuring the systems that keep people safe from sexual abuse — the same kind of discipline that patient safety became in healthcare, and workplace safety became in manufacturing.
Jigsaw Risk Management is how organizations practice it: a system that supports judgment under uncertainty, identifies concerns earlier, and produces defensibility as a byproduct — integrated with insurance and specialist support so the whole works as one.
It brings together three capabilities that work as a single integrated system:
A risk management system that helps your team identify where uncertainty is greatest, build customized controls around those risk zones, monitor whether they’re working, and measure the whole system continuously — producing a Governance Maturity Rating (GMR) updated in real time.
Specialist support from sexual abuse risk experts — including a dedicated response guide available 24/7/365 who helps your organization build its incident response plan before anything happens, and is there when it does.
Insurance underwritten by certain underwriters at Lloyd’s. When coverage reflects how well risk is managed, insurance drives the quality of risk management — and the system produces evidence to support it.
The system measures. Experts support it. Insurance reflects what it measures.
Why sexual abuse has lacked a discipline of its own
Every other high-risk sector — healthcare, manufacturing, cybersecurity — has built a safety discipline of its own. The work of keeping people safe from sexual abuse hasn’t.
A safety discipline is the practice of building, sustaining, and measuring systems that keep people safe — not just on paper, but in reality. The discipline supports judgment where uncertainty is highest, monitors whether the work is actually being done, and measures whether the system is producing safety, continuously.
Every field built one because they discovered rules weren’t enough. Patients kept dying in hospitals that followed every procedure. Workers kept getting hurt in plants that followed every procedure. Their toolkits were working as designed — the outcomes weren’t following. So those fields built disciplines to close the gap.
Sexual abuse has until now had a toolkit: policies, training, background checks, accreditations, codes of conduct. Organizations have adopted these tools over the past twenty years because they want to protect the people in their care, and the toolkit looks proactive and is easy to explain.
But the toolkit was built for reassurance — confirming that steps have been taken — not for risk management. That distinction creates three problems that persist no matter how seriously an organization takes its responsibilities:
Protection that can't be seen.
Sexual abuse continues to occur in organizations that have done all the prescribed steps, because the toolkit can’t tell you whether any of those steps is actually working. They measure that a control is in place, not whether it’s producing safety. An organization can be fully compliant, completely exposed, and totally unaware.
Warning signs that aren't caught early enough.
Maintaining attention to sexual abuse risk is hard. Competing pressures — operational demands, staffing and program changes, budget cycles, the sheer volume of everything else an organization has to manage — constantly pull at focus. The traditional toolkit doesn’t sustain attention between compliance events, surface the early signals that something might need a closer look, or tell you when vigilance has quietly drifted.
No credible defense when something goes wrong.
Evidence that the right policies were in place hasn’t been enough to mount a defense. If insurers — with all their resources and every incentive to make it work — have walked away from insuring sexual abuse because they couldn’t credibly defend claims with evidence that “steps were taken,” no individual organization can either. Reassurance doesn’t hold up. Risk management has a strong track record of doing so.
Who Is Jigsaw For?
Jigsaw serves organizations working with children and vulnerable adults — schools, churches, sports clubs, hospitals, youth organizations, residential care facilities, camps, and nonprofits. Any organization that takes responsibility for the safety of people in its care and wants to know that its protection system is actually working — and be able to show it.
How Does the System Work?
Your team builds it. The system holds it together.
The team starts wherever it wants or needs to start. Maybe a control that isn’t working. Maybe an incident response that needs structure. Maybe a risk zone where judgment is under strain. Whatever the entry point, the team gets value right away — and the system holds the work together as the team grows the system at its own pace.
Risk zones are the situations where judgment is under the most strain — the specific, real moments your people navigate every day. Not theoretical risks from a textbook. They’re identified in facilitated sessions, where your team thinks calmly and deliberately about where uncertainty is greatest, where decisions are hardest, and where the consequences of getting it wrong matter most.
Controls are practical measures designed to support judgment where it matters most. Some are already in place when the team starts. Some are developed from risk-zone work. Some emerge in response to flagged items or incidents. The new ones become candidate controls — tested in practice before promotion. As candidate controls prove effective, they’re promoted into the permanent system — becoming elements that get monitored and reviewed.
The system organizes your operation across 26 sets of elements — 13 for context (your risk environment, organizational purpose, assets, and risks) and 13 for controls (intake, training, supervision, reporting, incident response, and the supporting structures that keep them alive).
Each individual element is monitored on a short cycle (is it still working?) and reviewed on a longer cycle (is it still right?). The system prompts reviews, tracks whether controls are being maintained, and flags when something needs attention. Your team does the work. The system makes sure it doesn’t drift.
But not everything can be anticipated. Flagged items are the concerns that come out of the blue — something a staff member noticed, a pattern that doesn’t feel right, a question from a worried parent. These need somewhere to go and a process to address them. The system tracks flagged items from the moment they’re raised through to resolution — whether that means investigating further, adjusting a control, initiating an incident response, or recognizing that the concern has been addressed and closing it out. Some flagged items, once resolved, lead to permanent changes in the system — a new control, a revised procedure, a risk zone the team hadn’t previously identified.
Some events require more than a flag. When an allegation is made, a disclosure surfaces, or a pattern resolves into something concrete, the system has an incident response plan ready — built ahead of time with the help of the same specialist who will be there when it’s needed. From the moment a response is triggered, the system records every action, decision, and notification as the response unfolds.
Over time, as the team builds the system, it gets better at each part. Better at identifying uncertainty before it becomes risk. Better at building controls that work in practice. Better at sustaining attention when competing pressures pull at focus. Better at making decisions at the right level. Its capability compounds.
What Is a Governance Maturity Rating (GMR)?
The GMR is how Jigsaw measures whether sexual abuse safety is being practiced. Without it, even a system built around judgment and uncertainty would be no different from the tools it replaces: you’d know you’d built something, but not whether it was working.
It’s a letter grade from A+ through NR, updated continuously, with every grade traceable to source data. It measures four dimensions, with one modifier on top:
- Monitoring coverage — Are your protection measures being actively monitored? Because a control that isn’t being monitored is a control you’re assuming still works.
- Reviewing coverage — Are reviews happening on schedule? Because the organization you are today isn’t the organization you were when those controls were designed.
- Rhythm — Is your team meeting at the cadence they’ve committed to? Because discipline is what sustains attention when competing pressures pull at focus.
- Responsiveness — When concerns are surfaced, are they progressing toward resolution? Because a system that accepts concerns but doesn’t act on them teaches people to stop raising them.
- Emergence — the modifier — Are new concerns still being raised? Because a system that goes quiet isn’t getting safer. It’s going blind.
The GMR answers five questions at once:
- Your board asks: “Is our sexual abuse safety working?”
- Your insurer asks: “Is the risk being managed?”
- A parent asks: “Is my child safe here?”
- A regulator asks: “Can you demonstrate this?”
- A court asks: “What did you actually do?”
The GMR answers all five — with evidence, not assurance.
What Is Jigsaw Comply?
Jigsaw Comply is a platform that enables organizations to quickly and easily access the sexual abuse liability insurance (SML) they need to meet contractual requirements. Coverage is arranged by Tuckerman Underwriting, a coverholder at Lloyd’s, and underwritten by certain underwriters at Lloyd’s (A+ A.M. Best). Available at sml.jigsawrisk.com.
What Is the Relationship Between Jigsaw and BOKRIM?
Jigsaw Risk Management is the successor to BOKRIM. BOKRIM pioneered the application of enterprise risk management principles to sexual abuse risk. Jigsaw builds on that foundation with a purpose-built platform, integrated insurance, and specialist support — bringing the approach into a single, measurable system.
How Is Jigsaw Different from Traditional Abuse Prevention Tools?
Traditional abuse prevention tools were built for reassurance — confirming that steps were taken. Jigsaw practices sexual abuse safety — the discipline of identifying uncertainty and reducing it, supporting judgment where decisions actually get made, measuring whether the protection system is working, and creating defensibility as a byproduct. It’s a different approach, grounded in what every other high-risk field learned.
See the full comparison: Jigsaw vs. Traditional Abuse Prevention Tools.
How Do I Get Started?
- Talk to us — We’ll learn about your organization and walk you through the program.
- Onboard — Your team gets the Jigsaw system, training courses, and the SAM Risk Body of Knowledge.
- Start where you are — Bring your existing work into the system. Surface your first risk zones. Set your rhythm.
- See your GMR emerge — As your team works, the system measures. Your rating reflects what your organization actually does — from day one.
You can have a system producing value in a few days and initial GMR evidence within a few weeks. Because review cycles vary so much, and can span years, a mature system for one organization might be evident in a year, but for another, it might take two.
