An ERM maturity model is a structured way to describe how well developed an organization’s enterprise risk management is, and what the next step of improvement would look like. It gives boards and executives a shared language for questions such as how good is our risk management, how good does it need to be, and what would it take to get there. Used sensibly, it turns a vague ambition to improve risk management into a plan with stages. This guide explains what an ERM maturity model contains, typical levels and attributes, how to assess your current position, how to choose a target that suits your organization, and how to plan improvements without building a bureaucracy.
What an ERM maturity model measures
Most models describe a progression from informal, person-dependent risk handling to a disciplined approach that is embedded in strategy and decisions, and eventually to one that uses risk information to gain advantage. They assess several attributes at each level, so that you can see where you are strong and where you lag. Different bodies publish models, including the Risk and Insurance Management Society, whose risk maturity model is widely used. You can find more at RIMS. No single model is required, and you may adapt one to your context.
A model is a diagnostic, not a standard to certify against. Our guides to the COSO ERM principles and to ISO 31000 risk management describe frameworks of practice, while a maturity model tells you how fully you have adopted them.
Typical levels in an ERM maturity model
| Level | Name | What it looks like |
|---|---|---|
| 1 | Ad hoc | Risk handled informally, by individuals, with no common method |
| 2 | Initial | Some processes exist in pockets, such as a register in one function |
| 3 | Repeatable | Common method and policy across the organization, regular reporting |
| 4 | Managed | Risk integrated in strategy and decisions, appetite set, indicators tracked, portfolio view |
| 5 | Leading | Risk information used to improve performance, continuous improvement and challenge |
Level names differ between models, but the progression is similar. Note that a higher level is not always better. A small organization with a simple risk profile may be well served at level three, and spending to reach level five would add cost without matching benefit.
Attributes to assess
Break maturity into attributes so that you can assess and improve each. A common set includes the following.
- Governance and accountability. Board oversight, roles, committees, ownership of risks.
- Strategy and objectives. Whether risk is considered in planning and major decisions.
- Risk appetite and tolerance. Whether limits are set, communicated and used.
- Process. Consistent identification, assessment, response and monitoring.
- Information and reporting. Quality of data, aggregation, indicators and board reporting.
- Culture and capability. Behaviors, skills, training and incentives.
- Technology and data. Tools that support the process without becoming the goal.
- Integration. Links to compliance, audit, business continuity, information security and finance.
Our guides to risk culture, risk appetite and risk aggregation cover three of these in depth.
Free enterprise risk assessment
Which of your business risks sit above your appetite?
Set your criteria and appetite, pick from 36 strategic, financial, operational and compliance scenarios, rate them and decide how to treat each. Built to ISO 31000, and free.
Run the free enterprise risk assessment → or View premium report sample
How to assess where you are
Use evidence, not opinion. A self-assessment by the risk team alone tends to overrate, so include people from the business and, if possible, an independent reviewer such as internal audit.
- Choose the model and adapt it. Keep attributes that matter to you and simplify the rest.
- Define what each level means for each attribute, with observable indicators.
- Collect evidence. Policies, registers, reports, minutes, surveys and interviews.
- Score each attribute and record the evidence behind the score.
- Calibrate. Compare scores across attributes and units, and challenge outliers.
- Validate with leaders. Discuss results and agree on a shared view.
Look at practice, not documents
A policy that says risk is considered in strategic decisions proves little. Check board papers and decision records to see whether risk information actually appears and whether it changed anything. Look at whether the register is used in meetings, whether risk owners know their risks and whether indicators trigger action. Attributes that look strong on paper and weak in practice are common, and finding them is the value of the exercise.
Choosing a sensible target
The right target depends on size, sector, regulation, complexity of operations and the leadership’s appetite for risk. A bank or an insurer faces regulators who expect a higher level than a small retailer would need. Set targets by attribute: you might want managed governance and reporting but repeatable technology. Base the target on what the organization needs, for example to meet regulators, to support growth or to reduce losses, and be ready to explain why. Our guide to the enterprise risk register and the risk management policy show foundational elements at level three.
Building an improvement roadmap
List the gaps between current and target for each attribute, and choose actions that close them in a sensible order. Some actions unlock others: define roles and a common method before building aggregated reporting, and set appetite before asking for indicators. Group actions into stages of six to twelve months, assign owners and resources, and define what evidence will show that a stage is complete. Be cautious about attempting to advance every attribute at once. Focus on two or three areas of greatest benefit and consolidate before moving on.
Roles and reporting for the assessment
Give the assessment a sponsor at executive level, usually the chief risk officer or the finance director, and a lead who runs the method. The board or its risk committee should receive the results and endorse the target, since maturity is partly a question of how much the leadership wants to invest. Involve internal audit in an independent role, either as reviewer of the self-assessment or as the assessor, and agree in advance how disagreements will be resolved. Publish a short summary to participants so they see what was concluded and what will change.
Present results as a simple profile across the attributes, with current and target shown together, and add a short narrative for each gap. Avoid a single overall score that hides differences. Two organizations with the same average can have very different problems, and the profile shows which one you have.
Link maturity to outcomes
Whenever possible, connect improvements to results the business cares about: fewer surprises, faster decisions, lower insurance cost, better regulator relations or smoother audits. Leaders sustain support for a program when they can see the effect, and the evidence also helps you decide which improvements were worth the effort.
A short worked example
A regional manufacturer scores itself at level two overall: risk registers exist in operations and finance, but there is no common method, appetite or board reporting. Interviews show that the executive team decides major investments without risk information. The target is level three for most attributes and level four for reporting, within two years. The first stage adopts a common scale and register across units, names risk owners and starts quarterly reporting to the board. The second stage adds appetite statements and indicators for the five largest risks, and the third adds aggregation and links to strategy. Internal audit repeats the assessment each year and reports the movement.
Avoiding the traps
Common problems include treating the model as a scorecard to boast about, scoring generously to please leaders, chasing the highest level regardless of need, measuring only documentation, ignoring culture and letting the roadmap stall after the first stage. Another is using a model designed for large financial institutions in a small organization without adapting it. Keep the ERM maturity model simple, evidence-based and tied to decisions the organization actually needs to make.
How often to reassess
Reassess annually or every two years, using the same method so that movement is visible. Report the result to the board with the changes made and the next steps. Use interim checks after significant events, such as an acquisition, a new regulation or a major loss, since these can change the level of maturity you need.
Using a ready structure
If you want a structure to gather the underlying risk data that a maturity assessment will examine, the Enterprise Risk Assessment Report and Workbook provides a structured assessment, scoring and register. Whatever tool you use, apply an ERM maturity model to identify realistic improvements and check their effect over time.
ERM maturity model FAQ
What is an ERM maturity model?
It is a framework that describes levels of development of enterprise risk management across attributes such as governance, process, culture and reporting, used to assess the current state and plan improvements.
Which model should I use?
No single model is required. Choose one such as the RIMS risk maturity model or adapt one to your organization, keeping the attributes that matter and defining levels clearly.
Should we aim for the highest level?
Not necessarily. The right target depends on size, sector, regulation and risk profile. A lower level may be entirely adequate, and pursuing the highest level can add cost without benefit.
Who should carry out the assessment?
The risk function can coordinate it, but include business leaders and, where possible, an independent reviewer such as internal audit to avoid overrating.
How often should we reassess maturity?
Every one to two years with the same method so that movement is visible, and after significant events that change your risk profile.