Home/Platform/Projects
Module · Built · Gate-readiness scoring

Project gating. Built for the committee.

A project gate-readiness assessment built for investment committees, change boards and steering committees. 21 inherent risk markers, 41 delivery capability checkpoints, 30 cross-domain triggers. Aligned to Project Management Institute PMBOK 7, AXELOS PRINCE2, ISO 21500:2021 (Project, programme and portfolio management) and APRA Prudential Standard CPS 230 (Australia). Output is a Green / Amber / Red / Black gate decision - not a maturity score on a dashboard.

Projects
Project risk gate
Built
PJ
Projects
21
Inherent risk markers
41
Delivery capability checkpoints
30
Cross-domain triggers
RAG
Black gating decision
🇦🇺🇳🇿🇭🇰🇻🇳🇲🇾🇹🇼🇦🇪🇸🇦🇶🇦🇵🇰
01What it covers

Two questions. Twenty-two domains.

Project gating answers two questions. How risky is this project, inherently? (12 inherent-risk domains, 21 markers.) How well is it being managed, right now? (10 delivery-capability domains, 41 checkpoints.) The combined answer is the gate decision.
- A · Inherent risk · 12 domains · 21 markers
A.1 · GOV
Governance & Sponsorship
Project sponsor seniority, decision rights clarity, governance forum cadence.
A.2 · ORG
Organisational Impact
Number of business units, geographies, customers and processes affected.
A.3 · SKL
Skills & Capability
Specialist skill availability, capability gaps, dependency on external talent.
A.4 · CAP
Capacity & Workload
Team capacity, competing priorities, peak-load concentration risk.
A.5 · TRN
Training & Change
Workforce readiness, change-impact, training investment vs delivery scope.
A.6 · APP
Approach & Methodology
Methodology fit, agile/waterfall mix, hybrid coordination, vendor methodology fit.
A.7 · RPT
Reporting & Transparency
Reporting cadence to steerco, escalation thresholds, surprise-avoidance discipline.
A.8 · CTL
Control Environment
Stage gates, schedule controls, cost controls, scope controls, dependency controls.
A.9 · FRM
Framework Compliance
Adherence to PMO standards, methodology compliance, audit-ready documentation.
A.10 · RES
Resource & Vendor
Vendor concentration, key-person risk, contractor coverage, supply chain exposure.
A.11 · TEC
Technology Risk
Technology novelty, integration complexity, legacy interdependency, platform risk.
A.12 · AIR
AI & Emerging Risk
AI/ML scope, model risk, autonomous decisioning, novel-tech regulatory exposure.
- B · Delivery capability · 10 domains · 41 checkpoints
B.1 · 5 checks
Sponsorship & Decision Rights
Active sponsor, RACI clarity, escalation paths, decision velocity.
B.2 · 4 checks
Risk Ownership & Escalation
Risk register quality, owner accountability, escalation discipline.
B.3 · 4 checks
Risk Management Practices
Risk identification cadence, mitigation plans, residual risk acceptance.
B.4 · 4 checks
Controls-by-Design
Security, privacy and compliance controls baked into design, not bolted on.
B.5 · 4 checks
Delivery & Change Management
Change-request discipline, scope-creep controls, change-impact assessment.
B.6 · 4 checks
Assurance Planning & Independence
Internal audit involvement, second-line oversight, independent assurance plan.
B.7 · 4 checks
Technical Capability & Architecture
Architecture discipline, design authority, tech debt visibility, NFR rigour.
B.8 · 4 checks
Operational Readiness & Resilience
Go-live readiness, runbook quality, BCP / DR alignment, monitoring readiness.
B.9 · 4 checks
Vendor Governance
Vendor SOWs, SLAs, exit plans, fourth-party visibility, contract obligations.
B.10 · 4 checks
Evidence & Documentation
Decision logs, risk acceptance records, audit-ready evidence discipline.
02Gate decision · RAG/Black

Four outcomes. One committee decision.

Projects is the only module that doesn't use the 0–4 scale. Project gating uses Green / Amber / Red / Black because that's how investment committees and steering committees actually decide. The output answers a binary question: does this project proceed, hold, escalate or stop?
G
Green
Proceed
A
Amber
Conditional · proceed with actions
R
Red
Hold · deep review
B
Black
Stop · do not proceed
Why RAG/Black, not 0–4? Project gate committees don't need a maturity score - they need a defensible decision. Green / Amber / Red / Black is the language stakeholders already use. The cyber, AI, privacy and compliance triggers feed in as auto-Red flags. The combined IR + DC + trigger picture lands as one of these four outcomes, with full traceability back to the input data.
03Cross-domain triggers

Thirty triggers. Auto-escalation built in.

A "Yes" answer on any of these triggers auto-escalates the gate decision. A high-severity Yes triggers a mandatory review by the relevant function (cyber, privacy, compliance) before the gate can be cleared. This is where Projects connects to the rest of the platform.
Cyber + Privacy triggers15 triggers · auto-escalate to Black
Live
Cyber and privacy auto-escalation triggers. Includes: handling of sensitive personal data, cross-border data flows, novel cryptography, identity and access changes, third-party data sharing, AI/ML on personal data, regulated-customer impact, public-facing system changes, and operational technology / OT scope. Critical-severity Yes = Auto-Red.
15 triggersSeverity: Low → Critical
Compliance triggers15 triggers · auto-escalate to Black
Live
Regulatory and compliance auto-escalation triggers. Includes: regulated-entity scope, financial-services obligations, healthcare data, prudential reporting impact, cross-jurisdiction obligations, modern slavery scope, AML/CTF scope, environmental obligations, and consumer-protection-law impact. Critical-severity Yes triggers mandatory compliance review.
15 triggersCross-jurisdiction
Customisable trigger setsPer-organisation
Live
Trigger sets are customisable per organisation. Admins can adjust severity thresholds, add organisation-specific triggers (e.g. board-mandated review thresholds, sector-specific obligations), or scope triggers to specific business units. Default set is practitioner-authored; override is admin-only.
ConfigurableAdmin-controlled
AI & Emerging Tech triggersComing next
Next
Dedicated AI / emerging tech trigger set. Coming next - separating AI-specific risk triggers from the generic cyber/privacy set. Will cover model-risk classification, EU AI Act tier triggers, autonomous decision-making, generative AI scope, and ISO 42001 conformity scope.
Coming nextEU AI Act + ISO 42001 aligned
ESG & Climate triggersRoadmap
Roadmap
Sustainability, climate, environmental and social impact triggers - including TCFD, AASB S2 climate-related disclosures, modern slavery scope and Indigenous engagement obligations. Particularly relevant for infrastructure and resources projects. Mapping in development.
Roadmap · 2026TCFD · AASB S2
Sector-specific trigger packsRoadmap
Roadmap
Pre-built trigger packs for specific sectors - financial services (APRA, ASIC), healthcare (TGA, HPRA), telco (ACMA, TIO), critical infrastructure (SOCI Act). Reduces the customisation burden for organisations operating in heavily regulated sectors.
Roadmap · 2026FS · Healthcare · Telco · CI
04Cross-domain integration

Project risk is cross-discipline by definition.

Major projects touch every risk discipline - cyber, privacy, compliance, third-party, resilience. Most project risk tools score these as part of a single inherent-risk questionnaire. MaturityOne wires Projects into the specialist modules that own those exposures. The 15 cyber triggers and 15 compliance triggers in this module open assessments in those specialist modules automatically - no manual handoff.
- Appetite cascades in
From Enterprise Risk to project gates
Board-set risk appetite - "low" cyber, "low" third-party - translates into gating thresholds for new projects. A project with high cyber risk faces Black-gating automatically; a project using a Tier-1 vendor faces tighter due-diligence gating.
- Findings cascade out
From project failures to residual risk
Failed gates, missed milestones, and post-implementation incident findings flow back into Enterprise Risk as residual risk signals. Compliance findings on regulatory project failures flow into Compliance. Vendor delivery failures flow into Third Party Risk for re-tier.
- Triggers fire sideways
Triggers fire into specialist modules
The 15 cyber/privacy triggers and 15 compliance triggers in this module open assessments in Cyber, Privacy and Compliance automatically. The project does not get green-gated until those specialist assessments clear. No manual handoff, no missed coverage.
What this looks like in practice. A new digital transformation project enters intake. The 21 inherent risk questions classify it as Amber. The 15 cyber triggers fire - Cyber assessment opens for the new payments rails. The 15 compliance triggers fire - Compliance review opens for AML implications. Two of the 41 delivery capability checks flag - delivery uplift required before next gate. One intake. Three specialist modules engage. Gate decision integrated.
Pulls from
Enterprise RiskGate threshold
Cyber SecurityCyber trigger
PrivacyPrivacy trigger
ComplianceCompliance trigger
PJ
- Projects risk gate
Feeds
Enterprise RiskResidual risk
ComplianceProject failure
Third Party RiskVendor delivery
ResilienceCritical service
05Sample output

Two views. One gate decision.

The project manager sees the granular IR + DC + trigger breakdown. The investment committee sees a single decision (Green / Amber / Red / Black) with a board-ready narrative. Both views derive from the same signed-off data - the gate decision is auditable back to source.
PM viewCapture · evidence

IR + DC breakdown with trigger flags.

Amber/ ConditionalProceed with actions
Inherent risk score
Delivery capability score
Cyber/Privacy triggers · 2 high
Compliance triggers · 1 critical
Evidence completeness
Vendor governance

PM sees per-question scores, evidence references, trigger severities, and the specific actions required to clear each Amber or Red flag. Drillable to source.

Committee viewRead-only · gate

Single gate decision with required actions.

Amber/ ConditionalProceed with actions
→ Cyber review · required
→ Privacy DPIA · required
→ Compliance review · required
Vendor due diligence · required
Re-gate when actions cleared

Committee sees the gate decision, required actions, owner and target date for each, and a plain-English narrative - generated automatically from the signed-off PM data.

06See it work

Thirty minutes. A practitioner.

A walkthrough of the Projects module isn't a product demo. It's a practitioner showing you how inherent risk and delivery capability score, how the 30 cross-domain triggers auto-escalate, how the gate decision lands as Green / Amber / Red / Black, and the honest picture of what it can and can't do. If we're not the right fit, we'll tell you.