← ArticlesRisk Maturity Assessment and ImprovementProject Delivery · RiskLesson 7/7← PrevNext →
GuidePublished 13 Aug 202613 min readBy Kevin Joginrisk maturitycapability assessmentrisk culturecontinuous improvement

Project Delivery · Project Risk Management

Risk Maturity Assessment and Improvement

A multi-dimensional maturity model covering leadership, culture, process, information, tools, competence and learning, with an improvement roadmap.

14 min read Handbook guide Reviewed 2026-08-13 De-identified examples

Executive summary

A multi-dimensional maturity model covering leadership, culture, process, information, tools, competence and learning, with an improvement roadmap. The method is intended to improve decisions, not merely complete documentation. Apply it proportionately, preserve the evidence behind judgement and connect every action to an accountable owner.

Learning outcomes

  • Define maturity dimensions
  • Collect behavioural evidence
  • Rate strengths and gaps
  • Prioritise capability improvements
  • Reassess outcomes
  1. Define maturity dimensions
  2. Collect behavioural evidence
  3. Rate strengths and gaps
  4. Prioritise capability improvements
  5. Reassess outcomes

Why Maturity Matters: The Case for Embedding Risk Management

There is a fundamental question that every organisation must eventually confront: Is our risk management a bolted-on compliance activity, or is it woven into the fabric of how we think, plan, and decide?

The answer determines whether risk management is a cost centre that produces documents no one reads, or a strategic capability that protects programmes, creates competitive advantage, and enables confident decision-making. In defence and heavy engineering — where programmes span decades, involve billions of dollars, and carry consequences measured in sovereign capability and human safety — the maturity of an organisation's risk management capability is not an abstract concern. It is a direct predictor of programme outcomes.

Enterprise Risk Management (ERM) represents the destination: a fully integrated, organisation-wide approach to managing uncertainty. The Risk Maturity Model provides the roadmap for getting there. And the Conscious-Competence Model explains why the journey is so difficult — and why organisations at the lowest levels of maturity often do not even know they need to make it.

What Is Enterprise Risk Management?

The Paradigm Shift

Enterprise Risk Management represents a fundamental transformation in how organisations approach risk. A risk practitioner, writing about the ERM implementation at a large organisation, captured this shift as a movement across eight dimensions:

FROM (Traditional) TO (Enterprise)
Fragmented risk approach Integrated risk response
Negative perception of risk Positive perception of risk
Reactive risk management Proactive risk management
Ad hoc risk activities Continuous risk processes
Cost-based justification Value-based justification
Narrowly focused on threats Broadly focused on threats and opportunities
Functionally driven silos Process-driven integration

This shift is not merely structural — it is cultural and philosophical. Moving from a fragmented to an integrated approach requires changing how every manager in the organisation thinks about uncertainty. Moving from negative to positive perception requires reframing risk as a source of opportunity, not just a source of loss. Moving from reactive to proactive requires investing in risk identification and analysis before events occur, which means spending resources on activities whose value is measured by what did not happen — always a difficult proposition in organisations under budget pressure.

ISO 31000 on Integration

ISO 31000 makes a pointed observation that its integration mandate stands in contrast to common practice. The standard requires that:

This raises a challenging question for any organisation: What changes would your organisation have to make to meet this standard? For most, the answer involves not just process redesign but fundamental cultural transformation — a transformation that the maturity models attempt to map and guide.

Risk Management Maturity Models

A project risk maturity model Project Risk Maturity Model (PRMM)

A project-risk maturity practitioner developed the Project Risk Maturity Model as a practical tool for measuring and improving risk management capability. The PRMM provides a structured framework for:

A project risk maturity model aligns with the concept of managing the Known Knowns, Known Unknowns, and Unknown Unknowns — a framework that maps directly to the Conscious-Competence model discussed later in this article.

The five-level risk maturity model Model: Five Levels of Maturity

A five-level risk maturity model, adapted from the capability-maturity research body Capability Maturity Model (CMM), defines five levels of risk management maturity:

Level Name Description Defence/Engineering Example
1 Initial Ad hoc and chaotic; no institutionalised processes; reliance on individual competence A small fabrication shop where the owner personally manages all risk based on gut feel
2 Repeatable Processes established and repeating; intuitive; reliance on individuals reduced A mid-size contractor that runs risk workshops on major bids but has no standard methodology
3 Defined Policies, processes, and standards defined and uniformly applied; qualitative and quantitative methods used A Tier-2 defence contractor with a documented RMP, standard risk register template, and trained risk facilitators
4 Managed Risks measured and managed quantitatively; risks aggregated enterprise-wide; risk/reward trade-offs considered A Tier-1 prime contractor with enterprise risk dashboards, Monte Carlo capability, and integrated portfolio risk views
5 Optimizing Continuous feedback; emphasis on taking and exploiting risk; knowledge accumulated and shared A mature defence organisation where risk intelligence informs strategic decisions, and lessons learned from every programme feed back into organisational capability

The Four-Level Risk Maturity Model

Project-risk guidance proposed a simpler four-level model, arguing that fewer levels reduce ambiguity:

Level Name Culture Process Experience Application
1 Naïve No structured approach; reactive crisis management No formal risk processes Reliance on individual competence Ad hoc, inconsistent
2 Novice Experimentation via nominated individuals No organisation-wide process effectively implemented Limited to specific projects Pilot applications
3 Normalised Generic policies and procedures formalised and widespread Standard processes and tools tailored to specific applications Formal assignment of risk management responsibility Consistent application across projects
4 Natural Proactive approach required in all aspects of the organisation Organisation-wide training; common understanding of roles and responsibilities Risk management embedded in organisational DNA Fully integrated into all decision-making

Comparing the Models: Strengths and Limitations

Uncertainty-management sources offer an important critique of both models: they are fundamentally one-dimensional. Both a five-level risk maturity model and project-risk guidance assume that maturity in all relevant dimensions (culture, process, tools, experience, application) will be correlated — that an organisation progresses uniformly across all dimensions simultaneously.

In practice, this is rarely the case. An organisation may have sophisticated quantitative risk analysis tools (Level 4 in process maturity) while maintaining a blame culture that suppresses honest risk reporting (Level 1 in cultural maturity). Uncertainty-management sources argue that a multi-dimensional model — with separate dimensions for each aspect of risk management capability — would be more accurate, even if more complex.

ISO 31000 Risk Management Maturity Indicators

The draft ISO 31000 documentation provides a complementary set of maturity indicators that can be used to assess organisational progress:

Indicator What to Look For
Risk management mandated by Board/senior management Formal governance requirement, not optional practice
Established risk management organisation Dedicated roles, reporting lines, and governance structures
Risk management policy Documented, approved, and communicated policy
Risk management process Defined, repeatable process aligned with ISO 31000
Defined method for embedding risk management Explicit integration plan, not aspirational statements
Explicit reporting requirements Defined frequency, format, and audience for risk reports
Type of risk management tools used Appropriate tools for the organisation's maturity level
Risk management information captured consistently Standardised data collection enabling trend analysis
Frequency of risk management activities Regular, scheduled activities — not event-driven responses
Organisational activities that include risk management Risk considered in all major decisions, not just project reviews
Risk management supporting opportunity-seeking Positive risk management for upside potential
Increased Board confidence in pursuing new opportunities Risk intelligence enabling strategic risk-taking
Process of continual improvement Systematic review and enhancement of risk capability

The Conscious-Competence Model: Understanding the Learning Journey

Origins and Framework

The conscious-competence model describes a four-stage learning progression. Applied to project risk, it helps a team distinguish hidden capability gaps, recognised gaps, deliberate competent practice and competence that has become routine.

The model describes four stages through which individuals (and, by extension, organisations) progress when developing any new capability — including risk management:

Stage 1: Unconscious Incompetence — "You Don't Know What You Don't Know"

At this stage, the individual or organisation lacks knowledge and skills in risk management and is unaware of this lack. Two sub-states exist:

In a defence context, an organisation at Stage 1 might bid aggressively on complex programmes, underestimate technical risks, and discover their incompetence only when a critical milestone is missed or a system fails in testing.

Stage 2: Conscious Incompetence — "You Know You Don't Know"

The transition to conscious incompetence is often triggered by a shocking event — a risk incident that exposes the gap between perceived and actual capability. A major cost overrun, a safety incident, a failed acceptance test, or an external audit finding can all serve as the triggering event.

At this stage, the organisation recognises that its risk management capability is inadequate. This recognition is uncomfortable but essential — it creates the motivation for improvement. However, organisations can remain at this stage for a long time, depending on:

Stage 3: Conscious Competence — "You Know You Know"

Becoming consciously competent requires sustained effort — learning through formal training, mentoring, and accumulated experience. Progress is rarely linear; it proceeds in fits and starts as the organisation learns, forgets, plateaus, and restarts.

At this stage, risk management works but requires deliberate attention. Risk workshops must be formally scheduled. Risk registers must be actively maintained. Risk reviews must be consciously prioritised against competing demands. The processes function, but they have not yet become automatic — and they may be abandoned under pressure if leadership attention lapses.

The good news is that many organisations have achieved remarkable levels of risk management capability through sheer persistence, even starting from a very low base.

Stage 4: Unconscious Competence — "Second Nature"

At this final stage, risk management is so deeply embedded in organisational behaviour that it no longer requires conscious effort. Risk thinking is integrated into every decision, every meeting, every process. Team members instinctively consider uncertainty when planning, executing, and reviewing work. Risk information flows naturally through the organisation without requiring formal prompting.

This stage corresponds to the "Natural" level in a recognised project-risk framework's maturity model and the "Optimizing" level in a five-level risk maturity model. It is the destination that ERM frameworks aspire to — and it is achieved by very few organisations.

Mapping the Models Together

The Conscious-Competence Model maps directly onto the Risk Maturity Models, providing an explanatory framework for why organisations are at their current maturity level and what must change for them to progress:

Conscious-Competence Stage project-risk guidance Maturity Level a five-level risk maturity model Maturity Level Key Transition Mechanism
Unconscious Incompetence Naïve (Level 1) Initial (Level 1) Triggering event or external mandate
Conscious Incompetence Novice (Level 2) Repeatable (Level 2) Commitment to learning and investment
Conscious Competence Normalised (Level 3) Defined/Managed (Level 3–4) Sustained practice and standardisation
Unconscious Competence Natural (Level 4) Optimizing (Level 5) Cultural embedding and continuous improvement

Building a Risk Management Competence Culture

The literature on risk management competence identifies five basic organisational competencies that characterise successful risk management organisations:

  1. Active training and development in risk planning and management — building the knowledge base across all levels
  2. Strong linkage between corporate planning and project planning — particularly between business-level threat/opportunity analysis and project-level risk analysis
  3. Deep project experience in the industry — organisations that "stick to the knitting" are better positioned to recognise and offset risks inherent in their core business
  4. Capacity to document project experience and learn as an organisation — a learning organisation, as organisational-learning guidance describes it, does not reinvent the wheel each time it plans and implements a project
  5. Strong functional managers who address product quality as a risk reduction issue — disciplined configuration management, process documentation, and quality systems reduce the risk of product failures

Common Pitfalls

Assuming maturity is linear and irreversible. Organisations can and do regress. Loss of key personnel, budget cuts, leadership changes, or a prolonged period without risk events can cause an organisation to slide from Conscious Competence back to Unconscious Incompetence. Pursuing maturity uniformly across all dimensions. As uncertainty-management sources note, one-dimensional maturity models obscure the reality that organisations may be mature in some dimensions (e.g., tools and processes) and immature in others (e.g., culture and communication). Improvement efforts should be targeted at the weakest dimensions. Treating maturity assessment as a one-time exercise. Maturity assessments should be repeated periodically to track progress, identify regression, and adjust improvement plans. Mistaking process compliance for genuine maturity. An organisation can have every process in place and every template completed while remaining fundamentally immature in its risk culture. Maturity is about how people think and behave, not just what documents they produce. Underestimating the difficulty of the transition from Level 3 to Level 4. The jump from Conscious Competence to Unconscious Competence — from standardised processes to culturally embedded risk thinking — is the most difficult transition in the maturity journey. It cannot be achieved through training or process design alone; it requires sustained cultural reinforcement over years.

Key Takeaways

Practitioner completion checks

Use these checks before closing the analysis or taking the decision forward. Scale the evidence to the consequence, uncertainty and reversibility of the decision.

Check 01Define maturity dimensions is defined, owned, evidenced and linked to the relevant project decision.
Check 02Collect behavioural evidence is defined, owned, evidenced and linked to the relevant project decision.
Check 03Rate strengths and gaps is defined, owned, evidenced and linked to the relevant project decision.
Check 04Prioritise capability improvements is defined, owned, evidenced and linked to the relevant project decision.
Check 05Reassess outcomes is defined, owned, evidenced and linked to the relevant project decision.
How much detail is enough?

Use the least complex method that can support a defensible decision. Increase rigour when consequences are high, uncertainty is material, interfaces are complex, evidence is weak or the decision is difficult to reverse.

What should the decision record contain?

Record the objective, scope, inputs, assumptions, method, uncertainties, options, judgement, owner, approval, actions, residual exposure and the trigger or date for review.

When should the work be repeated?

Repeat it when a key assumption changes, new evidence appears, exposure crosses a threshold, a response fails, scope or interfaces change, or the next governance decision requires refreshed information.

Current authoritative reference points

Use the current published documents and the requirements adopted for the project's jurisdiction and contract. Links below support currency checking; they do not reproduce copyrighted standards.

Continue learning

Risk Escalation, Delegation and ALARPGuide · RiskRisk Appetite, Tolerance and CapacityGuide · RiskRisk Policy, Governance and AccountabilityGuide · RiskScaling Risk Management to Project ComplexityGuide · Risk