Enterprise Risk Score Calculator
Combine cyber, operational, compliance, third-party, financial and strategic risk into one weighted enterprise score against your stated appetite.
Inputs
Residual Enterprise Risk Score
32.0of 100
Inherent Composite Score
49.1of 100
Reduction from Controls
17.1points
Points Above Appetite
0.0points
Spread Across Domains
27points
Risk Level
Low
Dominant Risk Domain
Cyber and information security
Appetite Verdict
Residual enterprise risk sits inside the stated appetite, so the job is holding it there through the next set of changes
Step by step
Values used
Cyber and information security risk = 62 of 100; Operational and technology resilience risk = 48 of 100; Regulatory compliance risk = 40 of 100; Third-party and supply chain risk = 55 of 100; Financial risk = 35 of 100; Strategic and market risk = 45 of 100; Overall control maturity = 58 %; Appetite threshold on the 100-point scale = 40 points
Enterprise Risk Score
Inherent composite = weighted mean of six domain scores (cyber 25, operational 20, compliance 15, third-party 15, financial 15, strategic 10); residual = inherent × (1 − 0.6 × control maturity).
Residual Enterprise Risk Score
= 32.0 of 100
Inherent Composite Score
= 49.1 of 100
Reduction from Controls
= 17.1 points
Points Above Appetite
= 0.0 points
Spread Across Domains
= 27 points
Risk Level
= Low
How it works
The weights lean towards cyber and operational risk because that is where most organisations' loss events actually originate, and control maturity is capped at removing 60% of the composite since no control estate addresses strategic or market risk at all. Dispersion is reported because a moderate composite built from one severe domain and five mild ones needs a completely different response from an evenly moderate profile. Boards want one number and then immediately want to know which domain drives it, and an average that hides a single severe domain is worse than no number at all. This is a management roll-up of your own domain assessments, not a modelled loss distribution.
Formula
Enterprise Risk Score
Inherent composite = weighted mean of six domain scores (cyber 25, operational 20, compliance 15, third-party 15, financial 15, strategic 10); residual = inherent × (1 − 0.6 × control maturity).
- domain weights
- Sum to 100, so the composite reads directly on a 100-point scale
- maturityFactor
- Control maturity can remove at most 60% of the composite
- dispersion
- Highest domain minus lowest, showing how concentrated the risk is
Frequently Asked Questions
How is Enterprise Risk Score calculated?
Inherent composite = weighted mean of six domain scores (cyber 25, operational 20, compliance 15, third-party 15, financial 15, strategic 10); residual = inherent × (1 − 0.6 × control maturity). The weights lean towards cyber and operational risk because that is where most organisations' loss events actually originate, and control maturity is capped at removing 60% of the composite since no control estate addresses strategic or market risk at all. Dispersion is reported because a moderate composite built from one severe domain and five mild ones needs a completely different response from an evenly moderate profile.
Why does Enterprise Risk Score matter?
Boards want one number and then immediately want to know which domain drives it, and an average that hides a single severe domain is worse than no number at all. This is a management roll-up of your own domain assessments, not a modelled loss distribution.
What values do I need to enter?
This calculator takes 8 inputs: Cyber and information security risk, Operational and technology resilience risk, Regulatory compliance risk, Third-party and supply chain risk, Financial risk, Strategic and market risk, Overall control maturity, Appetite threshold on the 100-point scale. The pre-filled defaults are a realistic starting point — replace them with figures from your own environment for a result you can act on.
Should I change the domain weights?
You should, if your risk profile justifies it — a bank will weight financial risk far higher, a manufacturer operational risk. Just fix the weights, document them and keep them stable, because a composite whose weights move each quarter cannot show a trend, which is the main reason to compute it.
Why can control maturity only remove 60%?
Because controls do not touch every domain equally. They act strongly on cyber and compliance risk, partially on operational and third-party risk, and barely at all on strategic and market risk. A cap keeps a high maturity score from producing a comfortable composite that ignores the risks controls cannot reach.