The most significant risk governance gap is not between what your organization knows and what it has documented — it is between what it has documented and how it actually behaves. This diagnostic scores both. The gap between them is your most important number.
Rate your organization on what you have documented and formally established. Be honest — this is about what exists on paper, not how it performs under pressure.
Now rate how your organization actually behaves under pressure. How do people really act when a risk materializes? This is the harder, more honest score.