Skip to content
Calcrivo

Enterprise Risk Score Calculator

Combine cyber, operational, compliance, third-party, financial and strategic risk into one weighted enterprise score against your stated appetite.

Inputs

of 100
of 100
of 100
of 100
of 100
of 100
%
points

Residual Enterprise Risk Score

32.0of 100

Inherent Composite Score

49.1of 100

Reduction from Controls

17.1points

Points Above Appetite

0.0points

Spread Across Domains

27points

Risk Level

Low

Dominant Risk Domain

Cyber and information security

Appetite Verdict

Residual enterprise risk sits inside the stated appetite, so the job is holding it there through the next set of changes

Step by step

  1. Values used

    Cyber and information security risk = 62 of 100; Operational and technology resilience risk = 48 of 100; Regulatory compliance risk = 40 of 100; Third-party and supply chain risk = 55 of 100; Financial risk = 35 of 100; Strategic and market risk = 45 of 100; Overall control maturity = 58 %; Appetite threshold on the 100-point scale = 40 points

  2. Enterprise Risk Score

    Inherent composite = weighted mean of six domain scores (cyber 25, operational 20, compliance 15, third-party 15, financial 15, strategic 10); residual = inherent × (1 − 0.6 × control maturity).

  3. Residual Enterprise Risk Score

    = 32.0 of 100

  4. Inherent Composite Score

    = 49.1 of 100

  5. Reduction from Controls

    = 17.1 points

  6. Points Above Appetite

    = 0.0 points

  7. Spread Across Domains

    = 27 points

  8. Risk Level

    = Low

How it works

The weights lean towards cyber and operational risk because that is where most organisations' loss events actually originate, and control maturity is capped at removing 60% of the composite since no control estate addresses strategic or market risk at all. Dispersion is reported because a moderate composite built from one severe domain and five mild ones needs a completely different response from an evenly moderate profile. Boards want one number and then immediately want to know which domain drives it, and an average that hides a single severe domain is worse than no number at all. This is a management roll-up of your own domain assessments, not a modelled loss distribution.

Formula

Enterprise Risk Score

Inherent composite = weighted mean of six domain scores (cyber 25, operational 20, compliance 15, third-party 15, financial 15, strategic 10); residual = inherent × (1 − 0.6 × control maturity).

domain weights
Sum to 100, so the composite reads directly on a 100-point scale
maturityFactor
Control maturity can remove at most 60% of the composite
dispersion
Highest domain minus lowest, showing how concentrated the risk is

Frequently Asked Questions

How is Enterprise Risk Score calculated?

Inherent composite = weighted mean of six domain scores (cyber 25, operational 20, compliance 15, third-party 15, financial 15, strategic 10); residual = inherent × (1 − 0.6 × control maturity). The weights lean towards cyber and operational risk because that is where most organisations' loss events actually originate, and control maturity is capped at removing 60% of the composite since no control estate addresses strategic or market risk at all. Dispersion is reported because a moderate composite built from one severe domain and five mild ones needs a completely different response from an evenly moderate profile.

Why does Enterprise Risk Score matter?

Boards want one number and then immediately want to know which domain drives it, and an average that hides a single severe domain is worse than no number at all. This is a management roll-up of your own domain assessments, not a modelled loss distribution.

What values do I need to enter?

This calculator takes 8 inputs: Cyber and information security risk, Operational and technology resilience risk, Regulatory compliance risk, Third-party and supply chain risk, Financial risk, Strategic and market risk, Overall control maturity, Appetite threshold on the 100-point scale. The pre-filled defaults are a realistic starting point — replace them with figures from your own environment for a result you can act on.

Should I change the domain weights?

You should, if your risk profile justifies it — a bank will weight financial risk far higher, a manufacturer operational risk. Just fix the weights, document them and keep them stable, because a composite whose weights move each quarter cannot show a trend, which is the main reason to compute it.

Why can control maturity only remove 60%?

Because controls do not touch every domain equally. They act strongly on cyber and compliance risk, partially on operational and third-party risk, and barely at all on strategic and market risk. A cap keeps a high maturity score from producing a comfortable composite that ignores the risks controls cannot reach.

You might also need