Most governance scores measure activity. This one measures proof.
Policies written, meetings completed, training delivered, documents approved — these may be useful, but they don't prove an organization is governed. Real governance measures whether the business can see risk, assign responsibility, verify controls, produce evidence, and respond before damage spreads. Adjust the sliders below with your own numbers to calculate your Governance Effectiveness Score and see exactly where to focus next.Every number used in this report, and what to do about it, is listed in full below.
Governance Effectiveness Score
Multiplication is deliberate: strong documentation shouldn't hide weak controls, good visibility shouldn't hide missing ownership, and fast response shouldn't hide repeated failures.
The weakest-factor rule. Multiplication alone does not deliver the promise above — with everything else perfect, key controls failing nine times in ten still scored 56. So no score may exceed 64 while any factor sits at or below 40%, or 49 while any factor sits at or below 20%. When a cap applies, the page shows what the score would have been without it, and which factor caused it.
Enter your organization's numbers
Sliders are pre-loaded with the worked example from the formula (score = 57). Drag any slider to replace it with your own estimate. Each factor carries a definition of how to measure it — the same definition the measured version uses.
Your biggest opportunities, in priority order
Ranked by what each move is actually worth: every card shows the points your score gains from a ten-point improvement in that factor, computed by recomputing the score rather than by guessing which factor looks weakest. Those two orders disagree more often than not.
The daily governance work queue
A low score doesn't mean "write more policies." Every morning, leaders should look at these five things — regardless of what your sliders say today.
Critical risks without owners. Every serious risk needs one named, accountable person — not a team, not "pending."
Failed key controls. Any control that failed testing gets a fix owner and a retest date immediately.
Overdue corrective actions. Reduce the backlog before adding new commitments — overdue actions are the clearest sign of unmanaged exposure.
Expired risk exceptions. An exception past its expiry date is unaccepted risk sitting above your approved threshold.
Critical systems not yet in governance coverage. Find them before an incident does.
Stop estimating these eight numbers
Signed in, the same eight factors are computed from your own records — your registry, controls, ledger activity, incidents and open exceptions — and every factor opens the rows behind it. A factor with no data says so instead of being guessed.