The recent ABC reporting on the Australian National University is a reminder that governance issues do not stay neatly inside board papers, committee minutes or internal reviews.
They are business issues.
30 Second Take
Poor governance and risk management can affect confidence, funding, staff trust, customer decisions, regulator attention and reputation. In ANU’s case, its interim vice-chancellor reportedly told Senate estimates that governance problems had cost the university about $100 million in reputational damage.
That is a very large number.
But the bigger lesson is not just about one university,
The lesson is that every organisation needs to understand its own risk governance maturity before pressure exposes the gaps.
Leaders must want strong governance
Governance and risk management are sometimes presented as compliance activities.
That is the wrong way to think about them.
Great governance helps leaders make better decisions. It helps them move faster with more confidence. It helps them explain why a decision was made, what was considered, who was involved and what might happen next.
Good risk management is not about slowing the business down. It is about helping the business succeed without walking blindly into avoidable problems.
Every leader should want these things. Because when governance works well, it enables momentum, confidence and trust.
Risk maturity needs to be understood, not assumed
Many organisations believe they have good risk governance because they have structures in place:
- They have board and management committees, that opine on reports/paper for the purpose of the approval process not to explore and challenge.
- They have policies, that are thorough and ensure compliance but are never considered against the actual usage or consequence if not followed.
- They have reports, that provide lots of detailed information but do not explore the real issues.
- They have risk registers, that contain lots of information on risk, controls, and incidents, but are not utilised to make better business decisions.
The key questions are:
- Does your organisation make important decisions in a way that is clear, disciplined, challenged and trusted?
- Can leaders see where the pressure points are?
- Can they identify where confidence may be lost?
- Can they test whether the organisation is actually ready to deliver what it has committed to?
- Can they explain the decision in plain business language?
This is what governance and risk maturity is really about.
knowing your Risk maturity ensures you know how all people in your organisation make better decisions
Assessment should be part of how your organisation works
Risk governance maturity should not be assessed once and then placed on a shelf.
It should be checked, discussed and reassessed as part of normal business practice continuously. The focus on risk management through GRC tools, has resulted in organisations seeing the outputs as the measure of success. Risk governance maturity is about assessing the end-to-end of the inputs, process and outputs (the GRC tool outcomes) to determine where potential gaps exist.
Not in a complicated way. Not in a way that creates more unnecessary paperwork. But through a simple, consistent approach, such as surveys and simple assessment models, that helps leaders see where the organisation is strong, where it is exposed and where it needs to improve.
That is why maturity assessment tools matter.
A good enterprise risk maturity assessment gives leaders a practical way to step back and ask:
- Are we clear on how decisions are made?
- Are we clear on who owns what?
- Are we clear on how we determine the risks that matter most?
- Are we clear on whether our controls and actions are actually working?
- Are we clear on where our governance is helping performance, and where it is getting in the way?
These are not technical questions.
They are leadership questions.
Confidence is built before the crisis
The ANU example shows how quickly governance concerns can become confidence concerns.
Donors, students, staff, partners and regulators do not judge an organisation only by what it says it is trying to do. They judge it by how decisions are made, how impacts are understood, how people are engaged and how leaders respond when things become difficult.
That is why governance maturity needs constant attention.
Not because leaders need more process. But because leaders need better visibility.
They need to know whether the organisation can make hard decisions well, whether people trust the way decisions are being made, and whether the organisation can adapt without losing confidence.
A simple standard approach helps
The answer is not to make governance more complicated.
The answer is to make it more visible, more practical and more useful.
A simple enterprise risk maturity assessment can help leaders regularly test the health of their governance and risk management approach.
It can show whether the organisation is still relying on informal judgement, whether it has a basic framework in place, whether it is operating consistently, or whether it is using risk and governance as a genuine leadership tool.
That progression matters.
the goal is not to be perfect. The goal is to keep improving.
The leadership question…
Every organisation should be asking itself:
- Do we understand our current governance and risk maturity?
- Are we reassessing it often enough?
- Are we using that insight to improve how we lead, decide and deliver?
And most importantly:
Is our governance helping our leaders be successful?
Because that is what good governance should do. It should help the organisation make better decisions, protect trust, deliver outcomes and avoid unnecessary damage.
Governance maturity is not an administrative exercise.
It is one of the clearest indicators of whether an organisation is ready to succeed under pressure.
Innovation of Risk provides risk maturity and assessment tools to help organisations have better internal risk, governance and assurance discussions.

