IRM maturity self-check
Integrated Risk Management maturity self-check
Use 25 questions to see where risk work connects well, where it depends on individuals and where the next practical improvement may be.
Published by Hot Desk Consultancy Services Limited
Published Updated
A useful conversation, not an external rating
This self-check is designed to help a team talk honestly about how risk work operates. It covers governance, ownership, connected information, controls, assurance, reporting and improvement.
Complete it with people from more than one part of the organisation if you can. A difference in ratings is often more useful than the total score because it shows where teams experience the same process differently.
How to use it
Choose the statement that best matches current practice. Use what can be demonstrated now rather than what a policy says should happen. Your ratings and notes stay in this browser page and are not sent to Hot Desk.
- 0: No reliable evidence: the practice is absent, unknown or cannot currently be demonstrated.
- 1: Informal or inconsistent: it happens in places, but depends on individuals or varies materially.
- 2: Defined and usually applied: there is an agreed method that is normally followed, although coverage may be incomplete.
- 3: Operated, reviewed and evidenced: the practice is used, monitored and improved, with current evidence that it supports decisions.
The scale is a working self-assessment rubric. It is not an external maturity standard or industry benchmark.
What to do with the result
Do not try to improve every low score at once. Look for one decision that is currently difficult because ownership, information, controls or assurance do not connect. Agree what better would look like, who owns the change and what evidence will show that it is working.
Repeat the self-check after a meaningful change or review cycle. A higher score is useful only when the underlying practice has genuinely improved.
Framework context
The questions are informed by established risk and assurance ideas, including ISO 31000, NIST SP 800-39, NIST IR 8286 and the Institute of Internal Auditors' Three Lines Model. It is not an assessment against those publications.
Where Hot Desk fits
Hot Desk provides Integrated Risk Management advisory and develops the Parapet IRM platform. We can help interpret the result, define a focused improvement path or assess platform requirements without assuming a Parapet outcome.
Discuss your IRM priorities or read how IRM relates to GRC.
A note about this self-check
This is general information from Hot Desk Consultancy Services Limited. It is not an audit, certification, compliance assessment, external maturity benchmark or guarantee of risk-management performance.
Start a conversation
Bring us the challenge, not a finished specification.
We will help clarify the current state, the decisions that matter and a practical next step.