IRM maturity self-check

Integrated Risk Management maturity self-check

A free, ungated self-check for reviewing governance, connected risk information, controls, assurance, reporting and continuous improvement.

Published by Hot Desk Consultancy Services Limited

What this self-check does

This practical self-check helps an organisation review how well its risk activities work together and support decisions. It covers governance, scope, ownership, connected information, controls, assurance, reporting, operations and improvement.

Use it for an initial conversation, an internal workshop or preparation for a more detailed review. It is free to use and does not require an email address.

Before you begin

Base each rating on evidence that can be identified, dated and owned. A policy or system feature may show that a practice has been designed. It does not, by itself, show that the practice operates consistently or influences decisions.

Your ratings and notes stay in this browser page. The self-check does not send or save them to Hot Desk. You can print the completed page or save it as a PDF using your browser.

How to rate each statement

  1. 0: No reliable evidence. The practice is absent, unknown or cannot be supported with current evidence.
  2. 1: Informal or inconsistent. Some activity occurs, but it depends on individuals or varies materially.
  3. 2: Defined and usually applied. The practice has an agreed method and is normally followed, although evidence or coverage may be incomplete.
  4. 3: Operated, reviewed and evidenced. The practice is applied, monitored and improved, with current evidence of operation and decision use.

The scale is a working self-assessment rubric. It is not an external maturity standard or industry benchmark.

0No reliable evidence1Informal or inconsistent2Defined and usually applied3Operated, reviewed and evidenced

Governance and decision use

Consider whether risk information is connected to purpose, authority and real decisions.

1Governing-body and executive decision needs, risk appetite and risk tolerance are explicit.
2IRM objectives are linked to strategy, organisational outcomes and material obligations.
3Accountable owners exist for material risks and accepted exposures.
4Risk information is considered in planning, investment and change decisions.
5Escalation, exception and risk-acceptance thresholds are defined and evidenced.

Scope, ownership and integration

Consider the boundaries, responsibilities and connections across risk domains and the organisation.

6The risk domains in scope and their boundaries are agreed.
7Responsibilities across governing body, management, risk and compliance, and independent assurance are clear and coordinated.
8A shared ownership model and common terminology are used where risk domains need to connect.
9Business services, assets, processes and suppliers are connected to relevant risks and obligations.
10Duplication and gaps across registers, tools and teams are known and actively managed.

Risk information and relationships

Consider whether risk information is comparable, traceable and connected to the context needed for decisions.

11Risk definitions, scales and criteria are consistent enough to compare and aggregate information appropriately.
12Risks are connected to relevant causes, events, impacts and organisational objectives.
13Risks can be traced to relevant obligations, controls, assets, services, suppliers, findings and actions.
14The source, currency, quality, ownership and permitted access of material risk information are defined.
15Material business or technology changes can be traced to affected risks and relationships.

Controls, assurance and action

Consider whether controls, assurance activity and remediation produce usable operating evidence.

16Material controls have an owner, purpose, frequency, evidence requirement and exception route.
17Control design and evidence of operating performance are assessed separately.
18Assurance work is coordinated to reduce gaps and repeated evidence requests.
19Findings, issues and actions are connected to relevant risks and controls, with accountable owners and dates.
20Overdue or ineffective actions and accepted exceptions are escalated and reviewed.

Reporting, operations and improvement

Consider whether reporting supports decisions and whether the IRM capability is maintained as an operating service.

21Risk reporting is tailored to the decisions and accountabilities of its audience.
22Aggregated reporting preserves material context, dependencies and uncertainty.
23Monitoring identifies relevant changes in exposure, controls, incidents and dependencies.
24IRM process and platform ownership, access, support, change and continuity responsibilities are defined.
25Measures and periodic reviews lead to agreed improvements with evidence of completion.

How to use the result

The total provides a compact view of the 25 responses. The five dimension scores help show where evidence appears stronger or weaker. Start with the lowest-scoring dimension, then consider material risk, decision need, regulatory exposure, dependencies and the effort required before setting priorities.

Do not treat a high total as proof that the organisation's risks are acceptable. A single weak practice can remain material even when the combined score is high. Likewise, a low score can reflect missing evidence, incomplete scope or a newly established programme rather than poor intent.

What the five dimensions cover

  • Governance and decision use: purpose, appetite, authority, accountability, escalation and risk-informed decisions.
  • Scope, ownership and integration: agreed boundaries, coordinated roles, common terminology and links across domains.
  • Risk information and relationships: comparable definitions, information quality and traceability among objectives, risks, obligations, controls, assets, services, suppliers, findings and actions.
  • Controls, assurance and action: control ownership and evidence, coordinated assurance, remediation and exception management.
  • Reporting, operations and improvement: decision-focused reporting, monitoring, service ownership, support, change, continuity and evidence-led improvement.

Turn the review into action

  1. Confirm the scope, decision and accountable sponsor for the review.
  2. Record the evidence that supports each rating and identify where evidence is missing.
  3. Validate ratings with the people who own, operate, challenge and assure the activity.
  4. Identify material weaknesses and dependencies rather than ranking only by score.
  5. Assign an owner, target state, action, evidence requirement and review date.
  6. Decide whether the need is governance, process, information, control, assurance, technology or a combination.
  7. Repeat the self-check after agreed changes and compare the evidence, not only the number.

Framework context

The dimensions draw on established risk-management concepts rather than reproducing a proprietary maturity model. ISO 31000:2018 describes principles, a framework and a process for managing risk, including integration, customisation, stakeholder inclusion and continual improvement.

NIST Special Publication 800-39 connects risk management across organisation, mission and business processes, and information systems. NIST Interagency Report 8286 Revision 1 addresses integration of cybersecurity risk with enterprise risk management, including links between cybersecurity and enterprise risk registers and profiles.

The Institute of Internal Auditors' current Statements of Position include the Three Lines Model and related guidance on governance, roles, coordination and assurance. Apply each source according to its scope and the requirements that govern your organisation.

Where Hot Desk fits

Hot Desk provides product-neutral Integrated Risk Management consultancy. An engagement can focus on enterprise and strategic risk, technology and cyber risk, regulatory compliance and controls, or third-party and supplier risk. Each area can be commissioned independently or combined according to the client's need.

The recommendation may be Parapet, another platform, improvement around an existing tool or no platform change. If Parapet is selected, its dedicated product team is responsible for product implementation, configuration and support.

Hot Desk can help validate the self-check, gather and map evidence, define an operating model, prioritise improvements, support implementation or provide separately scoped ongoing operations and support. The client retains its governance, risk, legal, regulatory and operating decisions.

Continue the discussion

Read Integrated Risk Management versus GRC, review how to replace disconnected risk registers, or book a free one-hour discovery conversation. The conversation has no obligation and can focus on one dimension or a combined IRM programme.

About this resource

This self-check is published by Hot Desk Consultancy Services Limited as general information. It is not an audit, certification, compliance assessment, external maturity benchmark or guarantee of risk-management performance. It does not provide legal, regulatory, assurance, security, procurement or implementation advice. Confirm the evidence, materiality, requirements and decisions that apply to your organisation.

Start a conversation

Bring us the challenge, not a finished specification.

We will help clarify the current state, the decisions that matter and a practical next step.