Read me Page help ↗
Free Consultation
Enterprise governance, not governance theatre

Most governance scores measure activity. This one measures proof.

Policies written, meetings completed, training delivered, documents approved — these may be useful, but they don't prove an organization is governed. Real governance measures whether the business can see risk, assign responsibility, verify controls, produce evidence, and respond before damage spreads. Adjust the sliders below with your own numbers to calculate your Governance Effectiveness Score and see exactly where to focus next.Every number used in this report, and what to do about it, is listed in full below.

The formula

Governance Effectiveness Score

Multiplication is deliberate: strong documentation shouldn't hide weak controls, good visibility shouldn't hide missing ownership, and fast response shouldn't hide repeated failures.

G = 100 × C × (V^0.15 × O^0.20 × K^0.25 × E^0.15 × R^0.15 × I^0.10) × (1 − P)
C — Coverage: how much of your critical systems, data, vendors, processes, and AI use cases are inside governance.
V — Visibility: can you see important access, actions, changes, and decisions?
O — Ownership: does every risk, control, exception, and decision have a named owner?
K — Key Control Reliability: do your most important controls work when tested?
E — Evidence: can you prove your controls and governance processes are actually working?
R — Response: are serious issues contained and resolved within the required time?
I — Improvement: are you preventing repeated failures, or just recording them again?
P — Critical Exposure Penalty: overdue and unaccepted risk currently above your approved risk level.

The weakest-factor rule. Multiplication alone does not deliver the promise above — with everything else perfect, key controls failing nine times in ten still scored 56. So no score may exceed 64 while any factor sits at or below 40%, or 49 while any factor sits at or below 20%. When a cap applies, the page shows what the score would have been without it, and which factor caused it.

Calculate

Enter your organization's numbers

Sliders are pre-loaded with the worked example from the formula (score = 57). Drag any slider to replace it with your own estimate. Each factor carries a definition of how to measure it — the same definition the measured version uses.

Your score
/ 100
80–100 · Strong, evidence-backed
65–79 · Working, gaps remain
50–64 · Weak, action required
Below 50 · Serious unmanaged exposure
A self-assessed estimate. These are your own numbers, not verified ones — see the published methodology for the formula, the weakest-factor rule and the version. All calculations run in your browser. Nothing you enter here is sent to a server or stored.
The printed sheet carries your score, the full calculation, and every factor's explanation and next action.
What to do next

Your biggest opportunities, in priority order

Ranked by what each move is actually worth: every card shows the points your score gains from a ten-point improvement in that factor, computed by recomputing the score rather than by guessing which factor looks weakest. Those two orders disagree more often than not.

Reference

The daily governance work queue

A low score doesn't mean "write more policies." Every morning, leaders should look at these five things — regardless of what your sliders say today.

1

Critical risks without owners. Every serious risk needs one named, accountable person — not a team, not "pending."

2

Failed key controls. Any control that failed testing gets a fix owner and a retest date immediately.

3

Overdue corrective actions. Reduce the backlog before adding new commitments — overdue actions are the clearest sign of unmanaged exposure.

4

Expired risk exceptions. An exception past its expiry date is unaccepted risk sitting above your approved threshold.

5

Critical systems not yet in governance coverage. Find them before an incident does.

Stop estimating these eight numbers

Signed in, the same eight factors are computed from your own records — your registry, controls, ledger activity, incidents and open exceptions — and every factor opens the rows behind it. A factor with no data says so instead of being guessed.