IRM maturity self-check

Integrated Risk Management maturity self-check

Use 25 questions to see where risk work connects well, where it depends on individuals and where the next practical improvement may be.

Published by Hot Desk Consultancy Services Limited

Conceptual illustration for Integrated Risk Management maturity self-check

A useful conversation, not an external rating

This self-check is designed to help a team talk honestly about how risk work operates. It covers governance, ownership, connected information, controls, assurance, reporting and improvement.

Complete it with people from more than one part of the organisation if you can. A difference in ratings is often more useful than the total score because it shows where teams experience the same process differently.

How to use it

Choose the statement that best matches current practice. Use what can be demonstrated now rather than what a policy says should happen. Your ratings and notes stay in this browser page and are not sent to Hot Desk.

  1. 0: No reliable evidence: the practice is absent, unknown or cannot currently be demonstrated.
  2. 1: Informal or inconsistent: it happens in places, but depends on individuals or varies materially.
  3. 2: Defined and usually applied: there is an agreed method that is normally followed, although coverage may be incomplete.
  4. 3: Operated, reviewed and evidenced: the practice is used, monitored and improved, with current evidence that it supports decisions.

The scale is a working self-assessment rubric. It is not an external maturity standard or industry benchmark.

0No reliable evidence1Informal or inconsistent2Defined and usually applied3Operated, reviewed and evidenced

Governance and decision use

Consider whether risk information is connected to purpose, authority and real decisions.

1Governing-body and executive decision needs, risk appetite and risk tolerance are explicit.
2IRM objectives are linked to strategy, organisational outcomes and material obligations.
3Accountable owners exist for material risks and accepted exposures.
4Risk information is considered in planning, investment and change decisions.
5Escalation, exception and risk-acceptance thresholds are defined and evidenced.

Scope, ownership and integration

Consider the boundaries, responsibilities and connections across risk domains and the organisation.

6The risk domains in scope and their boundaries are agreed.
7Responsibilities across governing body, management, risk and compliance, and independent assurance are clear and coordinated.
8A shared ownership model and common terminology are used where risk domains need to connect.
9Business services, assets, processes and suppliers are connected to relevant risks and obligations.
10Duplication and gaps across registers, tools and teams are known and actively managed.

Risk information and relationships

Consider whether risk information is comparable, traceable and connected to the context needed for decisions.

11Risk definitions, scales and criteria are consistent enough to compare and aggregate information appropriately.
12Risks are connected to relevant causes, events, impacts and organisational objectives.
13Risks can be traced to relevant obligations, controls, assets, services, suppliers, findings and actions.
14The source, currency, quality, ownership and permitted access of material risk information are defined.
15Material business or technology changes can be traced to affected risks and relationships.

Controls, assurance and action

Consider whether controls, assurance activity and remediation produce usable operating evidence.

16Material controls have an owner, purpose, frequency, evidence requirement and exception route.
17Control design and evidence of operating performance are assessed separately.
18Assurance work is coordinated to reduce gaps and repeated evidence requests.
19Findings, issues and actions are connected to relevant risks and controls, with accountable owners and dates.
20Overdue or ineffective actions and accepted exceptions are escalated and reviewed.

Reporting, operations and improvement

Consider whether reporting supports decisions and whether the IRM capability is maintained as an operating service.

21Risk reporting is tailored to the decisions and accountabilities of its audience.
22Aggregated reporting preserves material context, dependencies and uncertainty.
23Monitoring identifies relevant changes in exposure, controls, incidents and dependencies.
24IRM process and platform ownership, access, support, change and continuity responsibilities are defined.
25Measures and periodic reviews lead to agreed improvements with evidence of completion.

What to do with the result

Do not try to improve every low score at once. Look for one decision that is currently difficult because ownership, information, controls or assurance do not connect. Agree what better would look like, who owns the change and what evidence will show that it is working.

Repeat the self-check after a meaningful change or review cycle. A higher score is useful only when the underlying practice has genuinely improved.

Framework context

The questions are informed by established risk and assurance ideas, including ISO 31000, NIST SP 800-39, NIST IR 8286 and the Institute of Internal Auditors' Three Lines Model. It is not an assessment against those publications.

Where Hot Desk fits

Hot Desk provides Integrated Risk Management advisory and develops the Parapet IRM platform. We can help interpret the result, define a focused improvement path or assess platform requirements without assuming a Parapet outcome.

Discuss your IRM priorities or read how IRM relates to GRC.

A note about this self-check

This is general information from Hot Desk Consultancy Services Limited. It is not an audit, certification, compliance assessment, external maturity benchmark or guarantee of risk-management performance.

Start a conversation

Bring us the challenge, not a finished specification.

We will help clarify the current state, the decisions that matter and a practical next step.