Why Maturity Matters: The Case for Embedding Risk Management
There is a fundamental question that every organisation must eventually confront: Is our risk management a bolted-on compliance activity, or is it woven into the fabric of how we think, plan, and decide?
The answer determines whether risk management is a cost centre that produces documents no one reads, or a strategic capability that protects programmes, creates competitive advantage, and enables confident decision-making. In defence and heavy engineering — where programmes span decades, involve billions of dollars, and carry consequences measured in sovereign capability and human safety — the maturity of an organisation's risk management capability is not an abstract concern. It is a direct predictor of programme outcomes.
Enterprise Risk Management (ERM) represents the destination: a fully integrated, organisation-wide approach to managing uncertainty. The Risk Maturity Model provides the roadmap for getting there. And the Conscious-Competence Model explains why the journey is so difficult — and why organisations at the lowest levels of maturity often do not even know they need to make it.
What Is Enterprise Risk Management?
The Paradigm Shift
Enterprise Risk Management represents a fundamental transformation in how organisations approach risk. A risk practitioner, writing about the ERM implementation at a large organisation, captured this shift as a movement across eight dimensions:
| FROM (Traditional) | TO (Enterprise) |
|---|---|
| Fragmented risk approach | Integrated risk response |
| Negative perception of risk | Positive perception of risk |
| Reactive risk management | Proactive risk management |
| Ad hoc risk activities | Continuous risk processes |
| Cost-based justification | Value-based justification |
| Narrowly focused on threats | Broadly focused on threats and opportunities |
| Functionally driven silos | Process-driven integration |
This shift is not merely structural — it is cultural and philosophical. Moving from a fragmented to an integrated approach requires changing how every manager in the organisation thinks about uncertainty. Moving from negative to positive perception requires reframing risk as a source of opportunity, not just a source of loss. Moving from reactive to proactive requires investing in risk identification and analysis before events occur, which means spending resources on activities whose value is measured by what did not happen — always a difficult proposition in organisations under budget pressure.
ISO 31000 on Integration
ISO 31000 makes a pointed observation that its integration mandate stands in contrast to common practice. The standard requires that:
- All key risk management processes are not stand-alone but integrated into the main activities and processes of the organisation — every manager is a risk manager
- Risk management is viewed as a core process, with risks considered in terms of sources of uncertainty that can be treated to maximise the chance of gain while minimising the chance of loss
- Risk management is regarded by senior managers as essential for the achievement of objectives
- The governance structure is founded on risk management
This raises a challenging question for any organisation: What changes would your organisation have to make to meet this standard? For most, the answer involves not just process redesign but fundamental cultural transformation — a transformation that the maturity models attempt to map and guide.
Risk Management Maturity Models
A project risk maturity model Project Risk Maturity Model (PRMM)
A project-risk maturity practitioner developed the Project Risk Maturity Model as a practical tool for measuring and improving risk management capability. The PRMM provides a structured framework for:
- Benchmarking current risk management capability against defined maturity levels
- Identifying gaps between current practice and desired capability
- Planning improvement initiatives with clear targets and milestones
- Tracking progress over time as the organisation develops its risk management capability
A project risk maturity model aligns with the concept of managing the Known Knowns, Known Unknowns, and Unknown Unknowns — a framework that maps directly to the Conscious-Competence model discussed later in this article.
The five-level risk maturity model Model: Five Levels of Maturity
A five-level risk maturity model, adapted from the capability-maturity research body Capability Maturity Model (CMM), defines five levels of risk management maturity:
| Level | Name | Description | Defence/Engineering Example |
|---|---|---|---|
| 1 | Initial | Ad hoc and chaotic; no institutionalised processes; reliance on individual competence | A small fabrication shop where the owner personally manages all risk based on gut feel |
| 2 | Repeatable | Processes established and repeating; intuitive; reliance on individuals reduced | A mid-size contractor that runs risk workshops on major bids but has no standard methodology |
| 3 | Defined | Policies, processes, and standards defined and uniformly applied; qualitative and quantitative methods used | A Tier-2 defence contractor with a documented RMP, standard risk register template, and trained risk facilitators |
| 4 | Managed | Risks measured and managed quantitatively; risks aggregated enterprise-wide; risk/reward trade-offs considered | A Tier-1 prime contractor with enterprise risk dashboards, Monte Carlo capability, and integrated portfolio risk views |
| 5 | Optimizing | Continuous feedback; emphasis on taking and exploiting risk; knowledge accumulated and shared | A mature defence organisation where risk intelligence informs strategic decisions, and lessons learned from every programme feed back into organisational capability |
The Four-Level Risk Maturity Model
Project-risk guidance proposed a simpler four-level model, arguing that fewer levels reduce ambiguity:
| Level | Name | Culture | Process | Experience | Application |
|---|---|---|---|---|---|
| 1 | Naïve | No structured approach; reactive crisis management | No formal risk processes | Reliance on individual competence | Ad hoc, inconsistent |
| 2 | Novice | Experimentation via nominated individuals | No organisation-wide process effectively implemented | Limited to specific projects | Pilot applications |
| 3 | Normalised | Generic policies and procedures formalised and widespread | Standard processes and tools tailored to specific applications | Formal assignment of risk management responsibility | Consistent application across projects |
| 4 | Natural | Proactive approach required in all aspects of the organisation | Organisation-wide training; common understanding of roles and responsibilities | Risk management embedded in organisational DNA | Fully integrated into all decision-making |
Comparing the Models: Strengths and Limitations
Uncertainty-management sources offer an important critique of both models: they are fundamentally one-dimensional. Both a five-level risk maturity model and project-risk guidance assume that maturity in all relevant dimensions (culture, process, tools, experience, application) will be correlated — that an organisation progresses uniformly across all dimensions simultaneously.
In practice, this is rarely the case. An organisation may have sophisticated quantitative risk analysis tools (Level 4 in process maturity) while maintaining a blame culture that suppresses honest risk reporting (Level 1 in cultural maturity). Uncertainty-management sources argue that a multi-dimensional model — with separate dimensions for each aspect of risk management capability — would be more accurate, even if more complex.
ISO 31000 Risk Management Maturity Indicators
The draft ISO 31000 documentation provides a complementary set of maturity indicators that can be used to assess organisational progress:
| Indicator | What to Look For |
|---|---|
| Risk management mandated by Board/senior management | Formal governance requirement, not optional practice |
| Established risk management organisation | Dedicated roles, reporting lines, and governance structures |
| Risk management policy | Documented, approved, and communicated policy |
| Risk management process | Defined, repeatable process aligned with ISO 31000 |
| Defined method for embedding risk management | Explicit integration plan, not aspirational statements |
| Explicit reporting requirements | Defined frequency, format, and audience for risk reports |
| Type of risk management tools used | Appropriate tools for the organisation's maturity level |
| Risk management information captured consistently | Standardised data collection enabling trend analysis |
| Frequency of risk management activities | Regular, scheduled activities — not event-driven responses |
| Organisational activities that include risk management | Risk considered in all major decisions, not just project reviews |
| Risk management supporting opportunity-seeking | Positive risk management for upside potential |
| Increased Board confidence in pursuing new opportunities | Risk intelligence enabling strategic risk-taking |
| Process of continual improvement | Systematic review and enhancement of risk capability |
The Conscious-Competence Model: Understanding the Learning Journey
Origins and Framework
The conscious-competence model describes a four-stage learning progression. Applied to project risk, it helps a team distinguish hidden capability gaps, recognised gaps, deliberate competent practice and competence that has become routine.
The model describes four stages through which individuals (and, by extension, organisations) progress when developing any new capability — including risk management:
Stage 1: Unconscious Incompetence — "You Don't Know What You Don't Know"
At this stage, the individual or organisation lacks knowledge and skills in risk management and is unaware of this lack. Two sub-states exist:
- Blissful ignorance: The organisation has never experienced a significant risk event and assumes that risk management is unnecessary overhead. Projects succeed (or appear to succeed) despite the absence of formal risk processes, reinforcing the belief that they are not needed.
- False competence: The organisation believes it is managing risk effectively — perhaps because it has a risk register and holds occasional risk meetings — but its processes are superficial and its risk information is unreliable. This state is particularly dangerous because it provides a false sense of security.
In a defence context, an organisation at Stage 1 might bid aggressively on complex programmes, underestimate technical risks, and discover their incompetence only when a critical milestone is missed or a system fails in testing.
Stage 2: Conscious Incompetence — "You Know You Don't Know"
The transition to conscious incompetence is often triggered by a shocking event — a risk incident that exposes the gap between perceived and actual capability. A major cost overrun, a safety incident, a failed acceptance test, or an external audit finding can all serve as the triggering event.
At this stage, the organisation recognises that its risk management capability is inadequate. This recognition is uncomfortable but essential — it creates the motivation for improvement. However, organisations can remain at this stage for a long time, depending on:
- The strength of their determination to improve
- The availability of resources for capability development
- The degree to which they genuinely accept their incompetence (versus merely acknowledging it publicly while privately believing "it won't happen to us again")
Stage 3: Conscious Competence — "You Know You Know"
Becoming consciously competent requires sustained effort — learning through formal training, mentoring, and accumulated experience. Progress is rarely linear; it proceeds in fits and starts as the organisation learns, forgets, plateaus, and restarts.
At this stage, risk management works but requires deliberate attention. Risk workshops must be formally scheduled. Risk registers must be actively maintained. Risk reviews must be consciously prioritised against competing demands. The processes function, but they have not yet become automatic — and they may be abandoned under pressure if leadership attention lapses.
The good news is that many organisations have achieved remarkable levels of risk management capability through sheer persistence, even starting from a very low base.
Stage 4: Unconscious Competence — "Second Nature"
At this final stage, risk management is so deeply embedded in organisational behaviour that it no longer requires conscious effort. Risk thinking is integrated into every decision, every meeting, every process. Team members instinctively consider uncertainty when planning, executing, and reviewing work. Risk information flows naturally through the organisation without requiring formal prompting.
This stage corresponds to the "Natural" level in a recognised project-risk framework's maturity model and the "Optimizing" level in a five-level risk maturity model. It is the destination that ERM frameworks aspire to — and it is achieved by very few organisations.
Mapping the Models Together
The Conscious-Competence Model maps directly onto the Risk Maturity Models, providing an explanatory framework for why organisations are at their current maturity level and what must change for them to progress:
| Conscious-Competence Stage | project-risk guidance Maturity Level | a five-level risk maturity model Maturity Level | Key Transition Mechanism |
|---|---|---|---|
| Unconscious Incompetence | Naïve (Level 1) | Initial (Level 1) | Triggering event or external mandate |
| Conscious Incompetence | Novice (Level 2) | Repeatable (Level 2) | Commitment to learning and investment |
| Conscious Competence | Normalised (Level 3) | Defined/Managed (Level 3–4) | Sustained practice and standardisation |
| Unconscious Competence | Natural (Level 4) | Optimizing (Level 5) | Cultural embedding and continuous improvement |
Building a Risk Management Competence Culture
The literature on risk management competence identifies five basic organisational competencies that characterise successful risk management organisations:
- Active training and development in risk planning and management — building the knowledge base across all levels
- Strong linkage between corporate planning and project planning — particularly between business-level threat/opportunity analysis and project-level risk analysis
- Deep project experience in the industry — organisations that "stick to the knitting" are better positioned to recognise and offset risks inherent in their core business
- Capacity to document project experience and learn as an organisation — a learning organisation, as organisational-learning guidance describes it, does not reinvent the wheel each time it plans and implements a project
- Strong functional managers who address product quality as a risk reduction issue — disciplined configuration management, process documentation, and quality systems reduce the risk of product failures
Common Pitfalls
Assuming maturity is linear and irreversible. Organisations can and do regress. Loss of key personnel, budget cuts, leadership changes, or a prolonged period without risk events can cause an organisation to slide from Conscious Competence back to Unconscious Incompetence. Pursuing maturity uniformly across all dimensions. As uncertainty-management sources note, one-dimensional maturity models obscure the reality that organisations may be mature in some dimensions (e.g., tools and processes) and immature in others (e.g., culture and communication). Improvement efforts should be targeted at the weakest dimensions. Treating maturity assessment as a one-time exercise. Maturity assessments should be repeated periodically to track progress, identify regression, and adjust improvement plans. Mistaking process compliance for genuine maturity. An organisation can have every process in place and every template completed while remaining fundamentally immature in its risk culture. Maturity is about how people think and behave, not just what documents they produce. Underestimating the difficulty of the transition from Level 3 to Level 4. The jump from Conscious Competence to Unconscious Competence — from standardised processes to culturally embedded risk thinking — is the most difficult transition in the maturity journey. It cannot be achieved through training or process design alone; it requires sustained cultural reinforcement over years.
Key Takeaways
- Enterprise Risk Management transforms risk from a fragmented, reactive, cost-based activity into an integrated, proactive, value-based organisational capability.
- Risk maturity models (a recognised project-risk framework's four-level and a five-level risk maturity model five-level frameworks) provide structured benchmarking tools, but both are limited by their one-dimensional nature — real organisations have uneven maturity across different dimensions.
- ISO 31000 mandates integration of risk management into all organisational activities and processes, requiring that every manager be a risk manager — a standard that stands in contrast to common practice.
- The Conscious-Competence Model explains the learning journey from Unconscious Incompetence (you don't know what you don't know) through to Unconscious Competence (risk thinking as second nature).
- Five organisational competencies underpin effective risk management: training, corporate-project planning linkage, deep industry experience, learning capability, and quality-focused functional management.
- Maturity is not permanent — organisations can regress, and sustained leadership attention is required to maintain and advance risk management capability.
