Diagnose the Operating Model You Actually Have
Policies, frameworks and audit reports do not always reflect how governance performs in practice.
This self-assessment helps you establish an honest baseline across five dimensions:
- Governance structures
- Risk management integration
- Control ownership and accountability
- Evidence management
- Governance culture
What the Tool Includes
- A five-stage maturity model from Reactive to Continuous.
- Observable diagnostic markers for every stage and dimension.
- A simple scoring canvas and overall maturity calculation.
- A dimension-level gap analysis.
- A prioritised twelve-month improvement roadmap.
- Six common GRC anti-patterns and practical ways to address them.
How to Use It
Allow approximately 30 minutes.
Read each stage description and select the one that best represents current performance. When the organisation sits between two stages, select the lower stage. The purpose is not to obtain the highest score; it is to establish a credible baseline for improvement.
The assessment is particularly useful for CISOs, GRC leads, Heads of Compliance, Risk Managers and senior leaders responsible for governance effectiveness.
For the reasoning behind the model, read The GRCForce Maturity Model: Building GRC That Works When the Expert Leaves the Room.