GRC maturity model
Five levels, from governance that lives in people's heads to a programme that tests and improves itself. The readiness check places you on this scale from 20 questions.
The five levels
| Level | Overall score | What it looks like |
|---|---|---|
| 1. Initial | under 20% | Governance depends on individuals; little is written down. |
| 2. Developing | 20 to 39% | Some policies and a risk list exist, but ownership and evidence are patchy. |
| 3. Defined | 40 to 59% | Policies, a risk register and mapped controls are in place; evidence is gathered mostly before audits. |
| 4. Managed | 60 to 79% | Owners, schedules and metrics keep the programme running; evidence is collected continuously. |
| 5. Optimised | 80% or more | Controls are tested and improved routinely, and AI systems are governed like any other risk. |
Policies and ownership
- Do you have a documented, approved set of core policies (information security, acceptable use, data protection)? If not: Write and approve a core policy set, and give every policy a named owner.
- Is every policy reviewed at least once a year, with the review recorded? If not: Set an annual review calendar and record each review and its outcome.
- Have staff acknowledged the policies that apply to them? If not: Collect policy acknowledgements at onboarding and after each major update.
- Is a named person or committee accountable for governance, risk and compliance? If not: Name a GRC owner and give them a written mandate from leadership.
Risk register
- Do you keep a risk register listing your key business, security and compliance risks? If not: Start a risk register covering business, security and compliance risks.
- Is each risk rated for likelihood and impact using a written method? If not: Adopt a short written scoring method, for example 1-5 likelihood times 1-5 impact.
- Does each risk have an owner and a treatment decision (reduce, accept, transfer or avoid)? If not: Give every risk an owner and a recorded treatment decision.
- Is the register reviewed at least quarterly and after major changes? If not: Review the register every quarter and after any major change.
Controls
- Have you mapped your controls to a framework such as ISO/IEC 27001, SOC 2 or the NIST Cybersecurity Framework? If not: Pick one framework and map your existing controls to it.
- Are access rights reviewed regularly and removed promptly when people leave? If not: Run quarterly access reviews and remove leavers' access on their last day.
- Are vendors assessed before onboarding and re-checked periodically? If not: Add a vendor risk assessment before contracts are signed and a yearly re-check.
- Do you have an incident response plan that has been tested? If not: Write an incident response plan and test it with a tabletop exercise.
Evidence and monitoring
- Is evidence for each control collected and stored in one place? If not: Create one evidence library organised by control.
- Is evidence collection scheduled with owners and due dates, rather than done just before audits? If not: Schedule recurring evidence tasks with owners and due dates.
- Do leaders see regular GRC metrics (open risks, overdue actions, control test results)? If not: Report a short set of GRC metrics to leadership every month or quarter.
- Are controls tested or internally audited, with findings tracked to closure? If not: Test key controls on a schedule and track every finding to closure.
AI governance
- Do you keep an inventory of the AI systems and AI tools in use, including those staff adopted on their own? If not: Build an AI inventory, including tools staff adopted on their own.
- Do you have an approved AI acceptable use policy? If not: Publish an AI acceptable use policy and train staff on it.
- Are AI systems risk-assessed before use (data, bias, security, legal)? If not: Add an AI risk assessment step before any AI system goes live.
- Do AI agents and automations that act for you have named owners, limited permissions and human approval for high-impact actions? If not: Give every AI agent an owner, least-privilege access and human approval for high-impact actions.