Two-tier model unique in market. Standard runs 8 core domains for rapid board-ready baseline. Comprehensive extends to 15+ domains with hundreds of practitioner-authored markers for enterprise rigour. Aligned to ISO 31000:2018, COSO Enterprise Risk Management and APRA Prudential Standard CPS 220 (Australia). NZISM (New Zealand) and HKMA Supervisory Policy Manual IC-1 (Hong Kong) on the roadmap. Built from twenty years of enterprise risk practice across financial services, telecommunications, ports and government.

A fast-growth Series B company and an ASX-listed conglomerate need different depths of assessment. Most tools force both into the same 200-question questionnaire. Standard scales down for rapid baseline. Comprehensive scales up for enterprise rigour. Both use the unified 0–4 scale and feed the cross-domain engine.
Eight core enterprise risk domains for organisations establishing or refreshing ERM. Suitable for mid-market organisations, fast-growth technology companies, NFPs, and entities establishing ERM for the first time. Delivers a board-ready maturity baseline in half a day, with a defensible action plan.
Fifteen-plus specialist domains with hundreds of practitioner-authored markers - built for ASX-listed, APRA-regulated, multinational and government organisations that need enterprise rigour. The same depth that audit committees, prudential regulators and rating agencies expect.
Every enterprise risk domain is scored on the 0-4 maturity scale - the same scale every other MaturityOne module uses, so enterprise risk reconciles with cyber, AI governance, third party risk, resilience and the rest of the platform without translation. Standard and Comprehensive use the same scale - upgrade tier without re-scoring.
Every regulatory add-on is a clause-level mapping from the maturity score to a specific enterprise risk standard. Run the assessment once; produce conformity evidence against multiple frameworks. ISO 31000:2018 is the live anchor, with COSO ERM and APRA CPS 220 next, and broader Asia-Pacific frameworks on the roadmap - covering Australia, New Zealand, the United States, Hong Kong and beyond for genuine global reach.
Most ERM tools operate as a self-contained register - risks logged in, reports generated out, no live connection to the disciplines that actually feed and consume them. MaturityOne wires Enterprise Risk into every other module on the platform. Board-set risk appetite cascades out to all eleven specialist modules; findings from those modules cascade back as residual risk signals. The register stops being a snapshot and becomes a live signal.
Findings from eleven specialist modules - cyber gaps, AI deployment risks, third-party incidents, project gate failures, compliance breaches, tolerance breaches - all flow back as residual risk signals. The next board review sees what actually happened, not what was reported last quarter.
Board-approved risk appetite set once at the top - translates automatically into module-level targets in each specialist module. No spreadsheets. No manual translation. Eleven modules update their targets in minutes.
When a residual risk signal exceeds appetite, cross-discipline triggers fire. A breach of cyber appetite triggers Cyber assessment refresh; a breach of third-party appetite triggers TP re-tier and Trailing fragment - likely meant to be a closing sentence like One signal, multiple modules respond.
The risk lead sees granular detail across all 15 domains. The board sees a single score, the cascade impact across the platform, and ISO 31000 / COSO ERM conformity. Both views derive from the same signed-off data - there's no "executive summary" that diverges from the underlying numbers.
Risk lead sees per-marker scores, evidence references, and reviewer comments for every domain. Drillable to source. Standard tier shows 8 core domains; Comprehensive shows all 15+ with hundreds of underlying markers.
Board sees a single number, the cascade across all 12 disciplines, regulatory conformity, and a plain-English narrative - generated automatically from the signed-off risk lead data.
A walkthrough of the Enterprise Risk module isn't a product demo. It's a practitioner showing you how the two-tier model works in practice - how Standard delivers a board-ready baseline in half a day, how Comprehensive scales to the depth that ASX-listed and APRA-regulated entities need, how ISO 31000:2018, COSO ERM and APRA Prudential Standard CPS 220 (Australia) map clause-by-clause, and how risk appetite cascades into every other module on the platform. If we're not the right fit, we'll tell you.