Free Consultation
Enterprise governance, not governance theatre

Most governance scores measure activity. This one measures proof.

Policies written, meetings completed, training delivered, documents approved — these may be useful, but they don't prove an organization is governed. Real governance measures whether the business can see risk, assign responsibility, verify controls, produce evidence, and respond before damage spreads. Adjust the sliders below with your own numbers to calculate your Governance Effectiveness Score and see exactly where to focus next.

The formula

Governance Effectiveness Score

Multiplication is deliberate: strong documentation shouldn't hide weak controls, good visibility shouldn't hide missing ownership, and fast response shouldn't hide repeated failures.

G = 100 × C × (V^0.15 × O^0.20 × K^0.25 × E^0.15 × R^0.15 × I^0.10) × (1 − P)
C — Coverage: how much of your critical systems, data, vendors, processes, and AI use cases are inside governance.
V — Visibility: can you see important access, actions, changes, and decisions?
O — Ownership: does every risk, control, exception, and decision have a named owner?
K — Key Control Reliability: do your most important controls work when tested?
E — Evidence: can you prove your controls and governance processes are actually working?
R — Response: are serious issues contained and resolved within the required time?
I — Improvement: are you preventing repeated failures, or just recording them again?
P — Critical Exposure Penalty: overdue and unaccepted risk currently above your approved risk level.
Calculate

Enter your organization's numbers

Sliders are pre-loaded with the worked example from the formula (score = 57). Drag any slider to replace it with your own estimate.

Your score
/ 100
80–100 · Strong, evidence-backed
65–79 · Working, gaps remain
50–64 · Weak, action required
Below 50 · Serious unmanaged exposure
All calculations run in your browser. Nothing you enter here is sent to a server or stored.
What to do next

Your biggest opportunities, in priority order

Ranked by which factor is weakest today. Each card also notes how heavily the formula weights that factor, since a low score on a heavily-weighted factor (like Key Control Reliability) is worth fixing sooner than the same gap on a lightly-weighted one.

Reference

The daily governance work queue

A score of 57 doesn't mean "write more policies." Every morning, leaders should look at these five things — regardless of what your sliders say today.

1

Critical risks without owners. Every serious risk needs one named, accountable person — not a team, not "pending."

2

Failed key controls. Any control that failed testing gets a fix owner and a retest date immediately.

3

Overdue corrective actions. Reduce the backlog before adding new commitments — overdue actions are the clearest sign of unmanaged exposure.

4

Expired risk exceptions. An exception past its expiry date is unaccepted risk sitting above your approved threshold.

5

Critical systems not yet in governance coverage. Find them before an incident does.

See these inputs measured continuously

Visibility, ownership, key control reliability, and response times are exactly what the Governance Workbench tracks — instead of once a quarter on a spreadsheet.