Enterprise Risk Management

What Your ERM Maturity Score Leaves Out

An ERM maturity rating should show what the business can rely on. Here is how to test the evidence, expose gaps an average hides, and commission a useful assessment.

By Eric Kennedy · Originally published Thu Sep 10 2026 · Updated Thu Sep 10 2026 · 9 min read

What Your ERM Maturity Score Leaves Out

An ERM maturity assessment evaluates how reliably a company identifies, evaluates, responds to, and uses risk in business decisions. A useful assessment produces an evidence-backed view of current capability, a target suited to the business, and a prioritized improvement plan. A score alone does none of that.

Before accepting a rating, ask the assessor to trace one material risk from the person who noticed it to the executive who decided what to do. Which evidence supports each step? Where did the process stop?

That is a more demanding test than asking whether the company has a risk policy.

Start by separating the two assessments

An enterprise risk assessment examines exposures: what could affect the plan, how serious the consequences could be, and what response is warranted.

An ERM maturity assessment examines the capability used to manage those exposures. Does the process reach the right people? Are assessments challenged? Can an owner secure a decision when an exposure exceeds an agreed limit?

A company can have serious risks and a capable management process. It can also face a quiet quarter with a weak process. Do not rate maturity by the absence of a recent incident.

COSO's ERM executive summary places risk within strategy and performance, and explicitly rejects treating ERM as a checklist or simply an inventory of risks. That supports a practical assessment question: can leadership show how its risk process was used, not merely that it was designed?

The method below is KRG's proposed approach to evaluating evidence. It is not a COSO scoring system, a certification, or a claim about results from KRG client engagements.

Ask what the rating actually proves

For each capability, separate evidence of design from evidence of use. These are evidence checks, not standardized maturity levels.

Three evidence checks for an ERM maturity rating: documented policy, operating escalation, and a decision-tested response with follow-up.

Documented: An escalation policy exists. This tells you how the process is supposed to work. Check its scope, approval, owner, and whether the people expected to use it can find it.

Operating: A threshold breach reached the right executive. Trace the underlying information, when the breach became visible, who sent it, and when it was received. A meeting invitation does not establish that the issue was discussed.

Decision-tested: The executive recorded a response and follow-up. That response might be a change in funding, a restriction, a request for better evidence, or a reasoned decision to accept the exposure. The test is not whether someone always chose mitigation.

More evidence, not more paperwork. An existing decision memo may be stronger evidence than a newly completed maturity questionnaire.

There is an important boundary here. One traced decision shows what happened in that instance. It does not establish consistent operation across every business unit or reporting cycle. Record the period reviewed, the cases selected, and why they were selected. If the sample covers only headquarters, do not describe the conclusion as enterprise-wide.

A process that has not yet faced a relevant event is not automatically ineffective. Use a walkthrough or an explicitly constructed scenario to test the proposed response, then identify the result as simulated evidence. Do not quietly give a simulation the same weight as observed operation.

The IIA's Global Internal Audit Standards, Standard 14.1 requires internal auditors to assess whether information is relevant, reliable, and sufficient to support their work. That standard governs internal audit practice. It does not convert a management diagnostic into an audit opinion, but its evidence discipline is a useful reference point.

Choose a target before calculating the gap

A $100 million manufacturer and a $700 million company integrating acquisitions may need different risk capabilities. Those revenue figures are illustrative, not thresholds for a prescribed maturity level.

Begin with the decisions the company must make over its planning horizon. A business adding a production line may need dependable escalation of capacity and supplier constraints. A company making acquisitions may need a consistent way to compare inherited exposures and assign responsibility after closing.

Neither need is answered by a target that says only “reach level four.”

Define the target in observable language. For example: “Before a material capital commitment, the investment paper identifies the assumptions that could change the return, the executive responsible for each exposure, and the conditions requiring reconsideration.” This is an illustrative target, not a universal requirement.

NIST's guide to organizational profiles provides a useful comparison method: assess the current position, define prioritized target outcomes, identify gaps, and develop an action plan. Its scope is cybersecurity, not enterprise-wide maturity. KRG is applying the current-to-target logic here, not presenting NIST as an ERM certification standard.

A sensible target can also say “maintain.” If a process meets the company's needs and the evidence holds up, leave it alone. An assessment should not manufacture an upgrade project for every dimension.

A practical scope for a mid-market review

Use the following as an initial evidence request, then adjust it to the company's objectives and material exposures. It is a working checklist, not a substitute for judgment.

CapabilityEvidence to examineQuestion the evidence should answer
Ownership and authorityRole assignments, delegated authority, actual escalationsCan the named owner obtain a decision, or only update a register?
Assessment qualityAssessment inputs, challenge notes, revised assumptionsWhat changed after management challenged the initial view?
Risk appetite and escalationLimits, indicators, breach records, exception decisionsWhat specifically causes leadership to reconsider an exposure?
Response follow-throughActions, resources, completion evidence, subsequent reviewWas the response implemented, and was its effect checked?
Planning and reportingInvestment papers, forecasts, committee papers, decision recordsWhere did risk information enter a business decision?

For the limits themselves, see KRG's guide to risk appetite for mid-market CFOs. This assessment should test whether those limits function, not reopen every appetite discussion.

Do not average away a missing decision path

Consider an illustrative scenario, constructed for this article. A company has an approved risk policy, named risk owners, and a quarterly risk report. The assessor can verify that all of those documents exist.

But the policy contains no escalation threshold. The named owner has no decision authority. The report records no response.

Illustrative scenario: an approved policy lacks an escalation threshold, a named owner lacks decision authority, and a quarterly report lacks a response record. Fix the trigger, decision assignment, and action record.

The findings are specific. An approved risk policy with no escalation threshold needs leadership to define the trigger. A named risk owner with no decision authority needs leadership to assign the decision. A quarterly risk report with no response record needs leadership to record the action.

A polished report cannot offset a missing decision path.

If an overall rating averages documentation quality with escalation capability, it can conceal that dependency. Keep the dimension-level findings visible and flag any gap that prevents a material exposure from reaching a decision-maker.

That does not mean every weakness is a stop sign. A formatting problem in a committee paper and an unresolved authority gap are not equivalent. Explain the business consequence of each finding before assigning its priority.

Nor does every risk owner need unrestricted spending authority. The relevant question is whether the owner can reach someone with the authority to choose and fund a response. A clear escalation route can satisfy that need.

What the deliverable should contain

Ask to see the proposed report structure before commissioning the work. You should be able to distinguish an evidence-based diagnostic from a questionnaire summary without waiting for the final presentation.

The report should state its scope and assessment criteria, show the evidence behind its conclusions, and make the improvement choices usable. At minimum, expect:

For the illustrative escalation gap above, “improve governance” is not an adequate action. “Agree the escalation trigger, identify the executive authorized to respond, and test the route using a documented scenario” is a usable starting point.

Completion should mean more than issuing a revised policy. The follow-up could inspect an actual escalation if one occurs, or test the route in a clearly labeled exercise. State which kind of evidence was obtained.

Keep the executive summary short enough to discuss. Put the evidence detail behind it so the CFO or audit committee can challenge the conclusion without commissioning another review.

When a maturity score is useful

Scores can help organize a baseline and track progress when the criteria, scope, and evidence rules remain stable. They also provide a common vocabulary for teams that currently describe the same process differently.

The problem is false precision, not measurement itself.

If an assessor says the company is ahead of peers, ask which peers, how they were selected, when they were assessed, and whether the same evidence rules were applied. A benchmark assembled from self-assessments is not directly equivalent to one based on tested operation. Without that context, present the comparison as directional or leave it out.

Similarly, do not interpret a higher rating after a model change as proof of improvement. Explain what changed in the assessment method and what changed in the business.

A maturity assessment is most useful when leadership is deciding what to fix before expanding the program. It is less useful when the material problem is already clear and the immediate need is execution. If a critical exposure has no owner, assign one now. A rating can wait.

Where to Start

If you need to decide which ERM gaps warrant investment, start with a bounded diagnostic rather than a company-wide scoring exercise. KRG's ERM Program Diagnostic is priced at $4,500 to $6,500 and takes 1 to 2 weeks. Review the scope and agree the evidence, decisions, and deliverables before beginning.

Review the ERM Program Diagnostic

Frequently Asked Questions

What is an ERM maturity assessment?

It is an evaluation of the capabilities a company uses to manage enterprise risk. It should compare evidence of current practice with a defined target and identify prioritized improvements. It is different from an enterprise risk assessment, which evaluates the exposures themselves.

What is a good ERM maturity score?

A score is meaningful only within a defined model, scope, and evidence standard. A useful target reflects the company's objectives and exposures. Ask what each rating proves and which material gaps remain, rather than treating the highest possible score as the default goal.

Can we assess ERM maturity internally?

Yes. An internal review can establish a useful baseline if the team defines its criteria, tests management assertions, and records limitations. Independent challenge is more useful when the assessment will support board reliance or a significant investment decision. Do not describe a self-assessment as independent assurance.

What should an ERM maturity assessment deliver?

Expect a current-capability profile, a justified target, evidence-backed findings, and a prioritized action plan with accountable executives and completion criteria. The report should disclose its scope, sample, untested areas, and any benchmark limitations.