Module · Built · Two-tier

Enterprise risk. Built two ways.

Two-tier model unique in market. Standard runs 8 core domains for rapid board-ready baseline. Comprehensive extends to 15+ domains with hundreds of practitioner-authored markers for enterprise rigour. Aligned to ISO 31000:2018, COSO Enterprise Risk Management and APRA Prudential Standard CPS 220 (Australia). NZISM (New Zealand) and HKMA Supervisory Policy Manual IC-1 (Hong Kong) on the roadmap. Built from twenty years of enterprise risk practice across financial services, telecommunications, ports and government.

Enterprise Risk
Enterprise Risk
Built
ER
Enterprise Risk
2
Tiers · Standard + Comprehensive
ISO 31000:2018
COSO ERM
CPS 220 · NZISM · HKMA
Standards aligned
15+
Domains · Comprehensive tier
0–4
Maturity scale
🇦🇺🇳🇿🇭🇰🇻🇳🇲🇾🇹🇼🇦🇪🇸🇦🇶🇦🇵🇰
01What it covers

Two tiers. One scoring model.

A fast-growth Series B company and an ASX-listed conglomerate need different depths of assessment. Most tools force both into the same 200-question questionnaire. Standard scales down for rapid baseline. Comprehensive scales up for enterprise rigour. Both use the unified 0–4 scale and feed the cross-domain engine.

Standard
- Rapid baseline
Tier 1
8
Core domains
0-4
Maturity scale

Eight core enterprise risk domains for organisations establishing or refreshing ERM. Suitable for mid-market organisations, fast-growth technology companies, NFPs, and entities establishing ERM for the first time. Delivers a board-ready maturity baseline in half a day, with a defensible action plan.

  • Risk governance and accountability
  • Risk appetite and tolerance
  • Risk identification and assessment
  • Risk treatment and controls
  • Risk monitoring and KRIs
  • Risk reporting and escalation
  • Risk culture and awareness
  • Risk technology and data
- Best for · Mid-market · Tech · NFP
Comprehensive
- Enterprise rigour
Tier 2 · Featured
15+
Specialist domains
100s
Practitioner markers
0-4
Maturity scale

Fifteen-plus specialist domains with hundreds of practitioner-authored markers - built for ASX-listed, APRA-regulated, multinational and government organisations that need enterprise rigour. The same depth that audit committees, prudential regulators and rating agencies expect.

  • Everything in Standard, plus:
  • Strategic risk and emerging risk
  • Operational and process risk
  • Financial and liquidity risk
  • Compliance and conduct risk
  • Reputation and ESG risk
  • Project and transformation risk
  • Three-lines-of-defence and assurance
  • Board oversight and committee charters
- Best for · ASX-listed · APRA-regulated · Government
01.1
Risk Governance & Accountability
Board approval, executive accountability, three-lines-of-defence operating model, committee charters.
01.2
Risk Appetite & Tolerance
Board-approved appetite statement, quantified tolerance limits, cascade through business lines.
01.3
Risk Identification
Top-down and bottom-up identification, horizon-scanning, emerging risk surveillance.
01.4
Risk Assessment
Likelihood and impact methodology, inherent and residual scoring, scenario analysis discipline.
01.5
Risk Treatment & Controls
Treatment options, control design, control effectiveness testing, residual risk acceptance.
01.6
Risk Monitoring & KRIs
Key risk indicators, thresholds, breach escalation, predictive vs lagging indicators.
01.7
Risk Reporting
Board reporting cadence, executive dashboards, regulatory reporting, signal-vs-noise discipline.
01.8
Risk Culture & Awareness
Cultural indicators, training cadence, speak-up and challenge, behavioural risk signals.
01.9
Strategic & Emerging Risk
Strategy-aligned risk, opportunity-risk linkage, geopolitical scanning, technology disruption.
01.10
Operational & Process Risk
Process risk taxonomy, control inventory, RCSA discipline, operational loss data.
01.11
Financial & Liquidity Risk
Financial risk identification, liquidity stress testing, credit and market exposure, treasury risk.
01.12
Compliance & Conduct Risk
Regulatory horizon, breach management, conduct framework, customer harm indicators.
01.13
Reputation & ESG Risk
Reputation surveillance, ESG materiality, modern slavery, climate-related risk.
01.14
Project & Transformation Risk
Portfolio-level risk, project gating integration, change risk, transformation risk register.
01.15
Three-Lines & Assurance
First-line ownership, second-line oversight, third-line independence, assurance plan integration.
02How it scores

Five levels. One unified scale.

Every enterprise risk domain is scored on the 0-4 maturity scale - the same scale every other MaturityOne module uses, so enterprise risk reconciles with cyber, AI governance, third party risk, resilience and the rest of the platform without translation. Standard and Comprehensive use the same scale - upgrade tier without re-scoring.

0
Not Established
No capability
1
Ad Hoc
Reactive · undocumented
2
Defined
Documented · inconsistent
3
Managed
Measured · consistent
4
Optimised
Continuous improvement
How a score is calculated. Each question carries a 1-5 input scale that maps deterministically to the 0-4 output. Domain scores aggregate the practitioner-weighted question scores; module score aggregates domain scores. Reviewer adjustment is captured at every level - the cascade engine uses the reviewer-signed score, never the assessor draft.
03Regulatory add-ons

Score once. Map to many.

Every regulatory add-on is a clause-level mapping from the maturity score to a specific enterprise risk standard. Run the assessment once; produce conformity evidence against multiple frameworks. ISO 31000:2018 is the live anchor, with COSO ERM and APRA CPS 220 next, and broader Asia-Pacific frameworks on the roadmap - covering Australia, New Zealand, the United States, Hong Kong and beyond for genuine global reach.

ISO 31000:2018Risk management - Guidelines · International
Live
Full clause and principle mapping. The international standard for risk management. The maturity assessment maps directly to ISO 31000's eight principles, framework (leadership, integration, design, implementation, evaluation, improvement) and process (scope, identification, analysis, evaluation, treatment, monitoring, communication). Run the enterprise risk module once; export ISO 31000-aligned conformity evidence.
8 principlesFramework + Process
ISO/IEC 31010:2019Risk assessment techniques · International
Live
Mapping to 41 risk assessment techniques. The international standard for risk assessment, providing guidance on the selection and application of risk assessment techniques - from bow-tie analysis through Monte Carlo simulation to scenario analysis. Used in conjunction with ISO 31000 for organisations needing rigorous, defensible risk assessment methodology.
41 techniquesCompanion to ISO 31000
COSO Enterprise Risk ManagementIntegrating with Strategy and Performance · United States
Next
The Committee of Sponsoring Organizations of the Treadway Commission Enterprise Risk Management framework. Coming next - widely adopted across US-listed companies, multinationals and increasingly the global reference for ERM-strategy integration. Five components, twenty principles. Maps the enterprise risk module to governance, strategy, performance, review and information.
Coming next5 components · 20 principles
APRA Prudential Standard CPS 220Risk Management · Australian Prudential Regulation Authority · Australia
Next
The Australian prudential standard for risk management. Coming next - required by Australian Prudential Regulation Authority-regulated financial institutions and superannuation funds. Covers risk management framework, risk appetite, risk management strategy, board and senior management responsibilities, and the chief risk officer role. Foundational standard for APRA-regulated entities.
Coming nextAPRA-regulated entities
NZISM Risk Management FrameworkNew Zealand Information Security Manual · NZ
Roadmap
New Zealand's principal risk management framework for government and agencies. The NZISM provides standard guidelines for risk identification, assessment, and treatment. Required for all New Zealand government agencies and increasingly adopted by the private sector for consistent risk practice. Mapping in development.
Roadmap · 2026NZISM · New Zealand
HKMA Supervisory Policy Manual IC-1Risk Management Framework · Hong Kong Monetary Authority · Hong Kong
Roadmap
Hong Kong's risk management framework for authorised institutions. The Hong Kong Monetary Authority's Supervisory Policy Manual IC-1 - establishing standards for risk governance, risk appetite, risk identification and assessment, and stress testing. Required for authorised institutions operating in Hong Kong, particularly those classified as systemically important.
Roadmap · 2026Hong Kong
04Cross-domain integration

Enterprise Risk is the source of truth.

Most ERM tools operate as a self-contained register - risks logged in, reports generated out, no live connection to the disciplines that actually feed and consume them. MaturityOne wires Enterprise Risk into every other module on the platform. Board-set risk appetite cascades out to all eleven specialist modules; findings from those modules cascade back as residual risk signals. The register stops being a snapshot and becomes a live signal.

Appetite cascades in

Findings cascade in

Findings from eleven specialist modules - cyber gaps, AI deployment risks, third-party incidents, project gate failures, compliance breaches, tolerance breaches - all flow back as residual risk signals. The next board review sees what actually happened, not what was reported last quarter.

Findings cascade out

Appetite cascades out

Board-approved risk appetite set once at the top - translates automatically into module-level targets in each specialist module. No spreadsheets. No manual translation. Eleven modules update their targets in minutes.

Triggers fire sideways

Triggers fire across the cascade

When a residual risk signal exceeds appetite, cross-discipline triggers fire. A breach of cyber appetite triggers Cyber assessment refresh; a breach of third-party appetite triggers TP re-tier and Trailing fragment - likely meant to be a closing sentence like One signal, multiple modules respond.

What this looks like in practice. The board approves a Q1 risk appetite statement: low for cyber, moderate for AI, low for third-party. Within minutes: Cyber moves to ML3 across 15 domains; AI Governance moves to ML2 across 10 domains; Third Party Risk tightens DD requirements; Resilience shrinks tolerance windows; Projects adds gating thresholds. One board session. The full platform responds.
Pulls from
Cyber SecurityResidual risk
AI GovernanceResidual risk
Third Party RiskResidual risk
ResilienceTolerance breach
ER
- Enterprise risk
Feeds
All 11 modulesAppetite
ComplianceBreach trigger
ProjectsGate threshold
Board reportingLive signal
05Sample output

Two views. One source of truth.

The risk lead sees granular detail across all 15 domains. The board sees a single score, the cascade impact across the platform, and ISO 31000 / COSO ERM conformity. Both views derive from the same signed-off data - there's no "executive summary" that diverges from the underlying numbers.

Risk lead viewCapture · evidence

Per-domain breakdown with weighted markers.

2.6/ 4Defined → Managed
Risk Governance
Risk Appetite & Tolerance
Risk Identification
Risk Assessment
Risk Treatment & Controls
Strategic & Emerging Risk

Risk lead sees per-marker scores, evidence references, and reviewer comments for every domain. Drillable to source. Standard tier shows 8 core domains; Comprehensive shows all 15+ with hundreds of underlying markers.

Board viewRead-only · board

Single score with platform-wide cascade.

2.6/ 4Defined → Managed
→ Cyber Security cascade
→ AI Governance cascade
→ Third Party cascade
ISO 31000:2018 conformity
COSO ERM alignment

Board sees a single number, the cascade across all 12 disciplines, regulatory conformity, and a plain-English narrative - generated automatically from the signed-off risk lead data.

06See it work

Thirty minutes. A practitioner.

A walkthrough of the Enterprise Risk module isn't a product demo. It's a practitioner showing you how the two-tier model works in practice - how Standard delivers a board-ready baseline in half a day, how Comprehensive scales to the depth that ASX-listed and APRA-regulated entities need, how ISO 31000:2018, COSO ERM and APRA Prudential Standard CPS 220 (Australia) map clause-by-clause, and how risk appetite cascades into every other module on the platform. If we're not the right fit, we'll tell you.