The Risk Maturity Gap: Examining the Disconnect Between Organizational Confidence and Effective Risk Mitigation | Research Square window.SnipcartSettings = { analytics: { enabled: false } }; (function() { var accessVector = localStorage.getItem('access_vector') || ''; window.dataLayer = window.dataLayer || []; if (accessVector) { window.dataLayer.push({ user: { profile: { profileInfo: { snid: accessVector } } } }); } })(); (function(w,d,s,l,i){w[l]=w[l]||[];w[l].push({'gtm.start':new Date().getTime(),event:'gtm.js'});var f=d.getElementsByTagName(s)[0],j=d.createElement(s),dl=l!='dataLayer'?'&l='+l:'';j.async=true;j.src='https://www.googletagmanager.com/gtm.js?id='+i+dl;f.parentNode.insertBefore(j,f);})(window,document,'script','dataLayer','GTM-K279D39R'); Browse Preprints In Review Journals COVID-19 Preprints AJE Video Bytes Research Tools Research Promotion AJE Professional Editing AJE Rubriq About Preprint Platform In Review Editorial Policies Our Team Advisory Board Help Center Sign In Submit a Preprint Cite Share Download PDF Research Article The Risk Maturity Gap: Examining the Disconnect Between Organizational Confidence and Effective Risk Mitigation Dickson Mdhlalose This is a preprint; it has not been peer reviewed by a journal. https://doi.org/ 10.21203/rs.3.rs-9032336/v1 This work is licensed under a CC BY 4.0 License Status: Posted Version 1 posted You are reading this latest preprint version Abstract This study investigated the structural, behavioural, and cultural mechanisms that sustain the gap between perceived risk management maturity and actual risk reduction outcomes in South African enterprise contexts, a phenomenon termed the maturity gap. Employing an exploratory sequential mixed-methods design grounded in critical realism, the study conducted 26 semi-structured in-depth interviews and administered a structured survey to 214 risk and governance professionals across financial services, insurance, mining, healthcare, retail, and public administration sectors. Quantitative analysis using multiple linear regression confirmed that self-assessed risk maturity was not a significant predictor of reduced incident frequency (β = .09, p = .21), while governance quality (β = −.34, p < .001) and technology integration (β = −.27, p = .003) emerged as the strongest protective factors. ERM framework adoption status similarly failed to predict incident reduction (β = −.11, p = .22). Thematic analysis identified four mechanisms sustaining the maturity gap. risk maturity gap enterprise risk management organisational overconfidence governance quality performative risk management resilience cognitive bias risk intelligence South Africa INTRODUCTION Background and Context Something quietly strange has happened to risk management over the past two decades. What began as a back-office compliance function, a necessary but largely administrative obligation performed at the edges of organisational life, has been elevated, refined, and institutionalised into a board-level discipline with its own frameworks, professional bodies, international standards, and dedicated executive roles. Organisations across virtually every sector have poured significant resources into risk governance: building enterprise risk management (ERM) infrastructures, commissioning assessments, constructing elaborate heat maps, and pursuing certification against benchmarks like Committee of Sponsoring Organizations of the Treadway Commission (COSO) and International Organization for Standardization ( ISO) 31000 (Hopkin, 2022). By almost every visible measure, the risk management profession has come of age. And yet, for all of that maturation, organisations keep getting hurt by risks they should have seen coming or by risks their own documentation suggested were well under control. This is not a marginal or sector-specific observation. The World Economic Forum (2025) characterises the current decade as an era of polycrisis, the simultaneous convergence of geopolitical instability, economic volatility, climate disruption, and technological acceleration into a compounding risk environment with no clear precedent in the history of enterprise governance. Against that backdrop, the limitations of conventional risk management paradigms have become very difficult to ignore. Frameworks built on periodic assessments, static heat maps, and backward-looking metrics were designed for a different kind of risk landscape one that was more stable, more predictable, and considerably more forgiving of slow analytical cycles (Aven, 2021). Today's operating environment, characterised by deep organisational interdependence through global supply chains and digital integration, has exposed those frameworks as structurally inadequate for the kinds of emergent, interconnected threats that now routinely materialise into consequential harm. The discipline is beginning to reckon with this. There is a visible and growing movement in both the scholarly and practitioner literature away from process-centric definitions of risk management, the idea that having the right framework in place is the same as managing risk effectively, toward outcome-oriented, adaptive models that ask a simpler and more demanding question: is actual harm being reduced? (Lam, 2022). At the same time, the technological landscape is shifting the possibilities for what real-time risk insight can look like, with artificial intelligence and continuous monitoring tools offering organisations the capacity to detect and respond to emerging threats far faster than traditional review cycles allow (Gartner, 2024). And the third-party risk domain, long treated as a secondary concern, has moved sharply to the foreground: Verizon (2025) reports that supply chain and vendor-related incidents are now among the fastest-growing categories of organisational breach, a development that calls into question the adequacy of risk perimeters drawn primarily around internal operations. What these trends collectively signal is a discipline that knows its inherited tools are falling short and is actively, if unevenly, searching for better ones. Problem Statement There is a particular kind of evidence that should give any risk professional pause, and the most recent industry research provides it in abundance. While organisations have invested steadily and substantially in risk frameworks, compliance structures, and assessment processes over more than two decades, the rate at which risk events continue to materialise offers a pointed challenge to the confidence embedded in those investments. HUB International (2026) found that a third of North American companies operate without mature risk strategies, and that only 5% had reached what the report classified as advanced risk maturity — a figure that is difficult to square with the widespread formal adoption of ERM. Third-party risk data sharpens the picture further: organisations experience an average of twelve vendor-related breaches annually, yet more than half rate their own assessment processes as effective at reducing risk (Protiviti & RIMS, 2024). The gap between those two facts is not a statistical curiosity. It is the central problem this research investigates. That gap, which this study terms the maturity gap, points toward something more troubling than poor execution: the possibility that current risk management approaches are generating a form of institutional confidence that is not warranted by actual capability (Beasley et al., 2021). Boards are beginning to feel the edges of this problem, even if they have not always named it directly. Nearly one-third of directors report that their greatest concern relates to risks they have not yet imagined, an admission that sits uneasily alongside the elaborate risk registers and governance structures many of those same organisations maintain (NACD, 2025). Deloitte (2024) identified a related symptom at the executive level: senior leaders routinely receive extensive risk data while simultaneously reporting limited confidence in their ability to use it to make meaningful decisions. That is not a data problem. It is an insight problem a failure not of information volume but of the quality and nature of the intelligence that governance systems are producing. Beneath these institutional symptoms lies a layer of cognitive and behavioural dynamics that the organisational psychology literature has documented with considerable precision. Overconfidence bias, optimism bias, and the illusion of control operate systematically and predictably in environments where the consequences of errors are delayed, feedback is infrequent, and social norms reward expressions of capability over admissions of uncertainty (Kahneman et al., 2021; Weick & Sutcliffe, 2021). What the risk management context adds to these well-established individual-level phenomena is the institutional amplification effect: when these biases become embedded in reporting structures, governance norms, and risk rating processes, they stop being individual cognitive tendencies and become organisational features durable, self-reinforcing, and very difficult to dislodge. The maturity gap, on this account, is not primarily a technical failure. It is a structural and cultural one, and the distinction matters enormously for how organisations should respond to it (Power, 2022; Mikes & Kaplan, 2023). Research Gap The scholarly literature on ERM is not thin; there is no shortage of frameworks, standards, prescriptions, and case analyses available to the practitioner or researcher who goes looking. What is thin is the explanatory literature: the body of work that tries to account for why organisations that have done all the right things on paper continue to experience the consequences of inadequate risk governance in practice. The existing research has concentrated heavily on process maturity, mapping the presence and quality of documented policies, governance structures, and assessment workflows while investing far less in the harder question of programme maturity, defined as the actual reduction of harmful risk outcomes (Beasley et al., 2021; Hopkin, 2022). The result is a literature that can describe what mature risk management is supposed to look like but cannot fully explain why possessing those structures does not reliably produce the protection they promise. Two specific gaps are most consequential for this research. The first concerns the institutional dimension of cognitive bias. Overconfidence, optimism bias, and the noise that corrupts human judgment have been theorised extensively at the individual level (Kahneman et al., 2021), but the mechanisms by which these individual tendencies aggregate into collective organisational overconfidence and then become self-sustaining through governance structures, reporting cultures, and board-level norms remain insufficiently understood. Similarly, while the tension between compliance-oriented and resilience-oriented risk practice is openly acknowledged in practitioner discourse, the scholarly literature has not yet produced robust frameworks for distinguishing the two in operational terms, or for identifying the conditions under which organisations can move from one to the other (Aven, 2021; Sull & Sull, 2023). Power's (2022) sociological account of the risk management of everything, the proliferation of risk governance activity as a form of institutional performance rather than genuine harm reduction, provides the most incisive diagnosis of the problem, but does not offer an organisational-level prescription for breaking the cycle. The second gap concerns governance and leadership. Research on board-level risk oversight has been largely structural in its orientation, examining committee composition, reporting frequency, and regulatory compliance rather than the qualitative question of how boards actually receive, interpret, and act on risk intelligence (McKinsey & Company, 2023). The communication dynamics between risk professionals and executive decision-makers, the role of organisational culture in shaping what information travels upward and in what form, and the conditions under which leadership fosters genuine risk learning rather than performative reassurance remain poorly theorised and empirically underexamined (PwC, 2024). This research addresses both gaps by drawing together behavioural theory, governance scholarship, and current practice evidence to construct an integrated explanatory account of why the risk maturity gap persists and what structural and cultural conditions would need to change for it to close. Research Aim This research sets out to investigate, with both theoretical rigour and practical intent, why organisations continue to experience recurrent risk events despite having established risk management frameworks, and to identify the structural and behavioural factors that sustain the gap between perceived risk maturity and actual risk reduction outcomes. Four interrelated objectives guide the inquiry. The first examines the psychological and organisational literature on cognitive bias to understand how overconfidence, optimism, and the illusion of control at the individual level aggregate into durable collective dysfunction at the institutional level (Kahneman et al., 2021; Weick & Sutcliffe, 2021). The second traces the historical evolution of risk management paradigms, critically evaluating whether the dominant frameworks COSO and ISO 31000 inadvertently encourage performative compliance rather than genuine resilience (COSO, 2023; Aven, 2021). The third interrogates the metrics and maturity models through which organisations assess their own effectiveness, examining how the systematic conflation of input metrics assessments completed, policies documented with output metrics incident reduction, loss containment, distorts organisational self-perception and undermines accountability (Lam, 2022; Protiviti & RIMS, 2024). The fourth examines the governance and leadership dynamics that shape the quality and utility of risk intelligence reaching board and executive decision-makers, including the increasingly significant role of AI-enabled continuous monitoring in providing real rather than retrospective risk insight (Gartner, 2024; Verizon, 2025). These objectives are not pursued in isolation. They are designed to speak to one another, because the maturity gap is not produced by any single failure; it emerges from the interaction of cognitive tendencies, framework limitations, metric dysfunctions, and governance deficits that reinforce each other in ways that make the problem both persistent and, with the right analytical tools, tractable. The study contributes to scholarly literature by developing an integrated explanatory framework for the maturity gap, and to practice by identifying the specific organisational conditions under which risk management can transition from activity-based assurance to outcome-based resilience (Deloitte, 2024; World Economic Forum, 2025). The evidence that current approaches are failing, however well-designed and well-intentioned they may be, is, at this point, too substantial to defer. The urgency of a better answer is the premise from which this research proceeds. RESEARCH METHODOLOGY Research Design and Philosophical Orientation This study employed an exploratory sequential mixed-methods research design to investigate the structural, behavioural, and cultural mechanisms that sustain the disconnect between perceived risk management maturity and actual risk reduction outcomes in South African organisations. The philosophical foundation of this research is critical realism, a paradigm that acknowledges the existence of objective organisational structures and mechanisms while recognising that their effects are mediated by context, interpretation, and human agency (Saunders et al., 2023). Critical realism is particularly well-suited to this inquiry because the risk maturity gap is not merely a perceptual phenomenon it is produced by identifiable structural and cognitive mechanisms that operate beneath the surface of documented frameworks and formal governance processes (Bhaskar, 2023, as cited in Creswell & Creswell, 2023). The sequential exploratory design proceeded in two phases: a qualitative phase that identified the mechanisms and conditions sustaining the maturity gap, followed by a quantitative phase that tested the prevalence and relative influence of those mechanisms across a broader cross-sectoral sample within South Africa. Research Setting and Justification The study was conducted within the South African enterprise context, encompassing organisations in the financial services, mining, insurance, healthcare, retail, and public administration sectors. South Africa represents a compelling research setting for several reasons. As a middle-income economy with sophisticated financial markets, advanced regulatory infrastructure, and significant exposure to both global and domestic risk events, South Africa occupies a transitional position in risk management maturity sophisticated enough to have institutionalised ERM frameworks, yet sufficiently exposed to systemic failures to render the maturity gap acutely visible (Institute of Risk Management South Africa [IRMSA], 2025). Furthermore, the post-pandemic operating environment in South Africa has intensified polycrisis dynamics, the simultaneous convergence of geopolitical, economic, climatic, and technological risk pressures documented globally by the World Economic Forum (2025), making the adequacy of existing risk paradigms an urgent local concern. South African organisations are also navigating heightened third-party risk exposure, consistent with Verizon's (2025) finding that vendor-related breaches represent one of the fastest-growing categories of organisational harm internationally. Phase One: Qualitative Data Collection and Analysis The qualitative phase employed semi-structured in-depth interviews as the primary data collection instrument. This method was selected because the research problem requires the exploration of subjective perceptions, institutional norms, and governance dynamics that cannot be adequately captured by pre-structured survey instruments (Bryman, 2022). Semi-structured interviews provide the flexibility to probe contextually specific phenomena such as how boards receive and act upon risk intelligence, or how overconfidence becomes institutionalised through reporting structures while maintaining sufficient consistency across participants to enable meaningful thematic comparison (Creswell & Poth, 2024). A purposive, criterion-based sampling strategy was employed, targeting professionals with direct, substantive involvement in ERM, board-level governance, organisational strategy, or internal audit functions within South African organisations. A total of 26 participants were interviewed, drawn from organisations headquartered or operating in Johannesburg, Pretoria, Cape Town, Durban, and Port Elizabeth. The sample included Chief Risk Officers (CROs), Chief Financial Officers (CFOs), board-level non-executive directors, internal audit executives, risk management consultants, and representatives from professional bodies, including the Institute of Risk Management South Africa (IRMSA) and the Chartered Institute of Management Accountants (CIMA) South Africa chapter. Theoretical saturation, the point at which additional interviews yielded no substantively new themes, was used as the criterion for determining sample sufficiency (Saunders et al., 2023). Interviews were conducted between February and June 2025, each lasting between 50 and 85 minutes. All sessions were audio-recorded with informed consent and transcribed verbatim. Member-checking was conducted by sharing transcripts with participants before analysis, enhancing the credibility of interpretive findings (Creswell & Poth, 2024). Qualitative data were analysed using reflexive thematic analysis following the six-phase framework of Braun and Clarke (2022): familiarisation, initial coding, theme generation, theme review, theme definition, and write-up. The entire analytical process was managed using NVivo 15 (QSR International, 2023), which facilitated systematic organisation of codes and themes, transparent audit trails, and inter-coder comparison. A second independent researcher reviewed a randomised 20% subsample of coded data to calculate inter-coder reliability; Cohen's kappa values exceeding 0.75 were achieved across all thematic domains, indicating strong agreement (McHugh, 2012, as cited in Pallant, 2024). Emergent themes centred on the institutionalisation of overconfidence, the performative function of risk frameworks, and the governance conditions that either perpetuate or disrupt the maturity gap. Phase Two: Quantitative Data Collection and Analysis The quantitative phase deployed a structured, self-administered online survey instrument developed from the theoretical constructs and thematic findings of Phase One. Survey items drew additionally on established frameworks, including the COSO ERM Framework (COSO, 2023), the ISO 31000 risk management standard, and the Protiviti and RIMS (2024) executive risk perspectives survey, ensuring theoretical grounding and content validity. The final instrument comprised 54 items across six validated constructs: risk maturity self-assessment, risk incident frequency, governance quality, cognitive bias susceptibility, leadership risk intelligence, and technology integration. All Likert-scale constructs used five-point response formats. The survey was piloted with 15 practitioners before full deployment to assess readability, face validity, and internal consistency. Cronbach's alpha coefficients for all multi-item scales ranged from 0.73 to 0.89, meeting the conventional reliability threshold (Pallant, 2024). The survey was administered to 214 risk management and governance professionals across South African organisations using a combination of professional network outreach, targeted LinkedIn recruitment, and distribution through IRMSA and the Southern African Institute of Management Scientists (SAIMS). Respondents were required to confirm active involvement in risk management or executive governance to qualify for participation. Quantitative data were analysed using IBM SPSS Statistics Version 29 (IBM Corp., 2023) and R Statistical Software Version 4.3.2 (R Core Team, 2023). Descriptive statistics summarised sample characteristics and response distributions. Pearson correlation analysis and multiple linear regression were used to examine relationships between risk maturity self-assessment scores, governance quality indices, and reported risk incident rates. Independent-samples t-tests and one-way ANOVA were applied to assess group-level differences by sector, organisation size, and ERM framework adoption. Confirmatory factor analysis, conducted in R using the lavaan package, validated the latent structure of the risk maturity and governance quality scales. Statistical significance was assessed at α = 0.05 across all inferential analyses. Integration of Qualitative and Quantitative Findings In accordance with the sequential exploratory design, qualitative and quantitative findings were integrated at the interpretation stage, a process referred to in mixed-methods scholarship as meta-inference (Tashakkori et al., 2021). Qualitative themes provided the explanatory layer for patterns identified in the quantitative data for instance, the statistical finding that organisations with high self-assessed maturity scores reported disproportionately high incident rates was contextualised through interview data revealing how governance structures and reporting norms institutionalise overconfidence. This integration strengthens the explanatory power of the research beyond what either method could achieve independently and directly responds to the theoretical gap identified by Beasley et al. (2021), Kahneman et al. (2021), and Power (2022) regarding the behavioural and structural mechanisms underlying performative risk management. Ethical Considerations Ethical clearance was obtained from the relevant institutional review board before the commencement of data collection. All participants provided written informed consent and were explicitly advised of their unconditional right to withdraw at any stage without consequence. Confidentiality was maintained throughout: participating organisations are identified only by sector and size category, and individual participants are described by role type alone. All digital data, including audio recordings and interview transcripts, was stored on encrypted, password-protected institutional servers. Audio recordings were permanently deleted upon completion of transcription. The study was conducted in full compliance with the Protection of Personal Information Act (POPIA) (Republic of South Africa, 2013) and the ethical guidelines of the hosting institution. No financial incentives were offered to participants, mitigating the risk of response bias (Flick, 2022). Validity, Reliability, and Limitations Methodological rigour was ensured through multiple triangulation strategies: data source triangulation (interviews and survey data), methodological triangulation (qualitative and quantitative approaches), and analyst triangulation (independent coding review). The use of NVivo 15 and IBM SPSS Statistics Version 29 across both phases ensured systematic, transparent, and reproducible analytical procedures. Notwithstanding these measures, several limitations are acknowledged. The South African setting, while internally diverse, limits the direct generalisability of findings to other national contexts with substantially different regulatory regimes, ERM adoption histories, or economic risk environments. Self-report data in both phases are susceptible to social desirability bias, particularly given the sensitive nature of questions relating to governance failures and risk incidents a limitation partially mitigated through anonymous data collection and the non-attribution of organisational identifiers (Podsakoff et al., 2024). Cross-sectional data collection also precludes causal inference; longitudinal designs in future research would strengthen the temporal validity of findings relating to maturity gap persistence. LITERATURE REVIEW There is a particular kind of organisational failure that is harder to explain than incompetence: the failure of organisations that are doing everything they are supposed to do and still getting it wrong. This is the central puzzle of the risk maturity gap, and it is a puzzle the existing literature has been circling without fully resolving for the better part of two decades. Four bodies of scholarship are directly relevant to understanding the psychology of risk perception and collective overconfidence, the historical evolution of risk management paradigms, the metrics and models through which organisations assess their own effectiveness, and the governance dynamics that either perpetuate or disrupt the gap between perceived capability and actual resilience. Together, these literatures build the theoretical scaffolding for this study's core argument: that the risk maturity gap is not a knowledge problem, a resource problem, or even primarily a framework problem; it is a structural and behavioural problem that requires a different kind of diagnosis (Beasley et al., 2021; Power, 2022). Theoretical Foundations of Risk Perception and Organisational Overconfidence The most durable insight in the behavioural risk literature is also one of the most uncomfortable: human beings are systematically, predictably overconfident about their ability to anticipate and manage uncertainty. Kahneman et al. (2021) provided the most comprehensive recent account of this phenomenon, distinguishing between the classical notion of individual overconfidence bias and the less-examined concept of noise the inconsistency and variability in human judgment that compound bias into structural unreliability at the organisational level. Their argument is not that risk professionals are careless or unintelligent; it is that the cognitive architecture of human judgment produces predictable distortions, particularly in domains characterised by ambiguity, low feedback frequency, and high personal stakes, which is to say, precisely the domains in which ERM operates. Tversky and Kahneman's prospect theory, while originating in the 1970s, has been substantially extended in recent scholarship to illuminate how organisations, not just individuals, assess risk (Aven, 2021). The optimism bias, the systematic tendency to underestimate the probability of adverse outcomes relative to favourable ones, manifests in enterprise contexts as the routine production of risk registers that emphasise manageable, familiar risks while undercounting tail risks and emergent threats. Weick and Sutcliffe (2021) named this tendency the normalisation of deviance: the gradual organisational habituation to warning signals that, because they have not yet produced catastrophe, are reclassified as tolerable. Their updated account of high-reliability organisations argues that what distinguishes resilient organisations from fragile ones is not the absence of risk but the active, institutionalised refusal to let anomalies be explained away. The leap from individual bias to collective overconfidence is where the literature becomes most directly relevant to this study's problem statement. Janis's (1982) foundational concept of groupthink, the suppression of dissent within cohesive groups under pressure, has been revisited and extended by Sull and Sull (2023), who demonstrate that execution failures in organisations are frequently attributable not to poor strategy but to cultural norms that discourage the escalation of uncomfortable information. In the risk context, this dynamic translates into governance structures where red-rated risks are quietly reclassified before reaching the boardroom, not through deliberate deception but through the accumulated weight of social norms that treat reassurance as professionalism and alarm as alarmism. Mikes and Kaplan (2023) revisited their influential risk management typology with precisely this insight: that the governance conditions designed to promote accountability can paradoxically become mechanisms through which risk exposure is concealed. This argument, grounded in decades of empirical case study research, provides the behavioural foundation for the maturity gap hypothesis this study tests. It would be misleading, however, to present the overconfidence literature as entirely settled. Taleb (2020) argued that the risk management profession's reliance on statistical probability models creates a false precision that is itself a form of institutional overconfidence, which he terms the fourth quadrant problem, in which the risks most likely to cause catastrophic harm are precisely those that standard models cannot adequately capture. This sceptical position challenges not just poor risk management practice but the foundational assumptions of quantitative risk modelling, a provocation that Aven (2021) engages directly in his critique of how risk science has evolved in ways that may reinforce rather than resolve the confidence-capability gap. The Evolution from Compliance-Based to Resilience-Based Risk Management Risk management as an institutionalised discipline has a relatively short history, but within that history there is a visible and consequential trajectory: from informal, judgement-based practice, through the codification of processes and standards, toward a growing recognition that codification alone is insufficient. The Committee of Sponsoring Organizations of the Treadway Commission's ERM framework (COSO, 2023) and the ISO 31000 standard represent the apex of the compliance-based paradigm internationally recognised, widely adopted, and, the evidence increasingly suggests, consistently inadequate as guarantors of genuine resilience. Hopkin (2022) traces this trajectory with clarity, noting that each successive iteration of ERM standards has expanded the scope of what risk management is supposed to encompass without addressing the more fundamental question of whether the activities prescribed actually reduce harmful outcomes. The distinction that the current literature most forcefully draws is between process maturity and programme maturity (Beasley et al., 2021). Process maturity describes the presence and quality of documented governance structures, risk registers, heat maps, assessment schedules, and committee charters. Programme maturity describes something far more difficult to measure and far more consequential: the demonstrated reduction of actual risk incidents and adverse outcomes. Beasley and colleagues' empirical analysis of ERM investment across a large sample of organisations found that organisations with highly developed ERM processes did not necessarily experience fewer damaging events a finding that crystallises the problem this study investigates and that its quantitative results extend into the South African enterprise context. Power (2022) offered the most sociologically incisive critique of this trajectory. His concept of the risk management of everything describes a phenomenon in which the expansion of formal risk governance activity has become decoupled from its stated purpose, not through bad faith, but through the institutional logic of accountability systems that reward demonstrated activity over achieved outcomes. In a regulatory and stakeholder environment that demands visible risk management, organisations rationally invest in the performance of risk management: the documentation, the assessments, the certifications. What they do not necessarily invest in because it is harder to demonstrate and less directly rewarded is the harder, slower work of embedding genuine adaptive capacity. Lam (2022) characterised this as the compliance trap: a governance equilibrium in which risk management is simultaneously everywhere and, in the most important sense, nowhere. There are dissenting voices in this debate. Hopkin (2022) argued that the compliance-versus-resilience framing, while intellectually provocative, risks undervaluing the real governance benefits that structured ERM frameworks provide, particularly in organisations that previously had no systematic approach to risk at all. The World Economic Forum (2024) similarly contended that resilience-based frameworks are most effective when built upon, rather than in opposition to, the documentation and process discipline that compliance-oriented approaches establish. This is a reasonable counterargument, and it points toward a more nuanced conclusion than a simple dismissal of compliance-based ERM: the problem is not the frameworks themselves but the conflation of framework adoption with framework effectiveness a conflation this study's findings consistently identify as a driver of the maturity gap. Measuring What Matters: Metrics, Maturity Models, and the Activity-Outcome Disconnect If the compliance-versus-resilience debate identifies the wrong destination, the metrics literature identifies the wrong map. Risk maturity models, the tools organisations use to assess and report their own risk management capability, are now ubiquitous in corporate governance practice, yet the scholarly literature on their validity is notably thin relative to their practical influence. Most widely used maturity models, including those embedded in COSO and ISO 31000 assessments and those produced by consultancies and professional bodies, evaluate maturity through input metrics: the number and comprehensiveness of risk assessments conducted, the coverage of documented policies, the frequency of committee meetings, and the proportion of risks with assigned owners (Lam, 2022). These are process indicators, not outcome indicators. They measure activity, not impact. Protiviti and RIMS (2024) documented the practical consequences of this measurement approach in their most recent executive risk perspectives survey, finding that more than half of participating organisations rated their own risk assessment processes as effective while simultaneously reporting persistently high rates of adverse risk events. This self-assessment inflation is not random noise it reflects a structural feature of how maturity is defined and measured. When the criteria for success are drawn from the same compliance-oriented paradigm that the organisation is executing, the assessment tool cannot detect the gap between execution and outcome. Gartner (2024) identified this as one of the most significant limitations of current risk governance practice and projected that organisations able to shift toward continuous, technology-enabled outcome monitoring would develop a durable competitive differentiation in resilience. The deeper methodological critique in the literature concerns not just what is being measured but what is being missed. Aven (2021) argued that traditional risk assessments, periodic, expert-led, backward-looking, are structurally unable to identify the emergent, interconnected risks that characterise the contemporary operating environment, and which the World Economic Forum (2025) has described as polycrisis: the simultaneous convergence of multiple, reinforcing risk streams that static heat maps and siloed assessments simply cannot represent. This critique is supported by Verizon's (2025) empirical finding that the fastest-growing categories of organisational breach vendor-related incidents, supply chain compromises were frequently risks that appeared manageable in isolation but escalated catastrophically through interconnection. IRMSA (2025) reported the same dynamic in the South African context, noting that organisations' over-reliance on self-assessment tools contributed to delayed recognition of third-party and systemic exposures. McKinsey and Company (2023) made the strongest practical case for reorienting risk measurement toward output metrics, arguing that organisations that define risk management success in terms of incident frequency, recovery time, and loss mitigation rather than policy coverage and assessment completion demonstrate meaningfully superior resilience outcomes over time. HUB International (2026) corroborated this in their most recent North American risk outlook, finding that only 5% of surveyed organisations had reached what they classified as advanced risk maturity, defined by outcome-oriented measurement, adaptive governance, and real-time risk intelligence, while a third operated without what the report characterised as a mature risk strategy at all. These figures are sobering, and they frame the South African context examined in this study within a global pattern of maturity overestimation. Governance, Leadership, and the Challenge of Risk Insight The governance literature on risk management has focused primarily on structural questions, board committee composition, reporting lines, audit cycles, and regulatory compliance and has devoted considerably less attention to the qualitative dimensions of risk oversight: whether the right information is reaching the right people in a form that enables genuine judgment rather than mere documentation. This is a significant gap, because the evidence suggests that governance structure and governance quality are not the same thing. Deloitte (2024), in its thirteenth global risk management survey, found that senior executives routinely receive voluminous risk data while simultaneously reporting low confidence in their ability to act on it meaningfully, a failure not of information quantity but of insight quality that represents one of the most consequential unresolved challenges in corporate governance. The National Association of Corporate Directors (NACD, 2025) survey found that nearly one-third of directors are most concerned about risks they have not yet imagined, which is, on first reading, startling. On reflection, it is an honest acknowledgment of the limits of retrospective, curated risk reporting the kind of reporting that tells a board what was true about risk at the time the report was compiled, filtered through management assessments, and formatted for reassurance rather than interrogation. PwC (2024) identified the communication gap between risk professionals and executive decision-makers as a structural feature of many organisations' governance arrangements, noting that risk professionals frequently possess considerably more nuanced views of organisational exposure than board-level reporting reflects, but lack either the mandate or the relational capital to convey it without sanitisation. Mikes and Kaplan (2023) described this as the risk intelligence deficit: an organisational condition in which the formal governance apparatus produces comfort rather than clarity. There are two credible responses to this deficit in the current literature, and they are not mutually exclusive. The first is cultural and leadership-based: organisations must create environments in which uncomfortable information travels upward rather than being smoothed away before it reaches the boardroom. Weick and Sutcliffe (2021) argued that high-reliability organisations achieve this not through structural mandate alone but through leadership cultures that actively reward the escalation of uncertainty treating surprise as signal rather than failure. Sull and Sull (2023) extended this argument into strategy execution research, demonstrating that organisations where middle managers feel safe to report bad news to senior leadership consistently outperform those where the opposite culture prevails. The implications for risk governance are direct. The second response is technological. Gartner (2024) projected that AI-enabled continuous risk monitoring, real-time integration of operational data, external signals, and anomaly detection would become a primary differentiator of risk management quality over the coming decade, precisely because it bypasses the human filtering processes through which risk intelligence is diluted before reaching decision-makers. This projection is supported by the emerging practice evidence reviewed by Lam (2022) and corroborated by this study's quantitative finding that technology integration is one of the strongest predictors of reduced risk incident frequency. The HUB International (2026) report similarly identified real-time monitoring adoption as a key characteristic of the small cohort of genuinely advanced-maturity organisations in their survey. What the governance and technology literatures together suggest is that the risk intelligence deficit is a solvable problem, but solving it requires simultaneous investment in cultural conditions that welcome unwelcome information and technological tools that surface it before it can be reclassified, diluted, or delayed. Neither alone is sufficient; together, they represent the most promising pathway from performative assurance to genuine resilience. RESULTS AND DISCUSSION Sample Profile and Descriptive Overview The combined study sample comprised 240 participants: 26 individuals engaged in the qualitative phase and 214 in the quantitative survey phase. Qualitative participants were drawn from organisations headquartered or operating across Johannesburg, Pretoria, Cape Town, Durban, and Port Elizabeth, representing six sectors: financial services (31%), mining and resources (15%), insurance (19%), healthcare (12%), retail (12%), and public administration (11%). The quantitative sample mirrored this cross-sectoral distribution. Of the 214 survey respondents, 68% represented large organisations with more than 500 employees, 22% represented medium-sized enterprises, and 10% represented smaller organisations. Senior risk and governance professionals including Chief Risk Officers (CROs), Chief Financial Officers (CFOs), and board-level non-executive directors constituted 61% of the quantitative sample, lending high practitioner authority to the findings. Descriptive statistics generated using IBM SPSS Statistics Version 29 (IBM Corp., 2023) confirmed that the sample was adequately diverse across sector, organisational size, and ERM framework adoption status to support meaningful inferential analysis. Table 1 Sample Characteristics by Sector and Organisational Size (N = 214) Sector n % Mean Maturity Score Financial Services 66 30.8% 3.62 Insurance 41 19.2% 3.71 Mining & Resources 32 15.0% 3.44 Healthcare 26 12.1% 3.28 Retail 26 12.1% 3.19 Public Administration 23 10.7% 2.91 Note. Self-assessed risk maturity scores are based on a five-point Likert scale. Higher scores indicate greater perceived maturity. Risk Maturity Overconfidence: Quantitative Findings The central quantitative finding of this study confirms and extends the maturity gap hypothesis advanced in the introduction and substantiated in the theoretical literature. Pearson correlation analysis revealed a statistically significant negative relationship between self-assessed risk maturity scores and actual risk incident rates (r = −.18, p = .008), indicating that organisations rating themselves more highly on risk capability did not, in practice, experience fewer risk events. More strikingly, multiple linear regression analysis with risk incident frequency as the dependent variable and self-assessed maturity, governance quality, ERM framework adoption, and technology integration as predictors produced an overall model that was statistically significant (F(4, 209) = 11.43, p < .001, R² = .18). However, self-assessed maturity was not a significant predictor of reduced incidents (β = .09, p = .21), while governance quality (β = −.34, p < .001) and technology integration (β = −.27, p = .003) emerged as the strongest protective factors. These findings directly validate the concern raised by Beasley et al. (2021) that process maturity, the presence of documented frameworks, is a poor proxy for program maturity, defined as the demonstrable reduction of harmful outcomes. One-way ANOVA further revealed significant differences in the maturity gap across sectors (F(5, 208) = 6.82, p < .001). Post-hoc Tukey HSD analysis identified public administration organisations as exhibiting the largest divergence between self-assessed maturity (M = 2.91, SD = 0.63) and incident frequency rates, followed by the retail sector (M = 3.19, SD = 0.71). Financial services and insurance organisations demonstrated comparatively tighter alignment between perceived maturity and outcome metrics, likely reflecting the more robust regulatory oversight imposed by frameworks such as the Financial Sector Conduct Authority (FSCA) requirements and the Prudential Authority's directives in South Africa. Confirmatory factor analysis conducted in R Version 4.3.2 (R Core Team, 2023) using the lavaan package validated the six-factor structure of the governance readiness scale (CFI = 0.96, RMSEA = 0.048, SRMR = 0.061), confirming acceptable model fit and supporting the structural validity of the measurement instrument. Table 2 Multiple Linear Regression: Predictors of Risk Incident Frequency (N = 214) Predictor β SE t p Self-Assessed Maturity .09 .07 1.26 .21 Governance Quality -.34 .06 -5.67 < .001 Technology Integration -.27 .08 -3.38 .003 ERM Framework Adoption -.11 .09 -1.22 .22 Note. R² = .18, F(4, 209) = 11.43, p < .001. β = standardised regression coefficient; SE = standard error. Qualitative Findings: Mechanisms Sustaining the Maturity Gap Thematic analysis of the 26 qualitative interviews, conducted using NVivo 15 (QSR International, 2023), yielded four overarching themes aligned with the four literature review subtopics: (1) the institutionalisation of cognitive bias in risk reporting; (2) the performative function of ERM frameworks; (3) the activity-outcome metric disconnect; and (4) governance and leadership deficits in risk intelligence. These themes are discussed in sequence below. The Institutionalisation of Cognitive Bias The most pervasive theme emerging from interviews was the systematic embedding of overconfidence bias within organisational reporting structures. Participants across all sectors described risk committees and board presentations as environments where risk scores were routinely inflated to avoid executive discomfort, a dynamic consistent with the institutionalisation of optimism bias theorised by Kahneman et al. (2021). A CRO in the financial services sector described an environment in which red-rated risks were regularly reclassified to amber before board reporting, not because mitigating actions had been implemented, but because red ratings attracted uncomfortable scrutiny. This phenomenon, which Weick and Sutcliffe (2021) term the normalisation of deviance, was identified across all six sectors in the sample, though it was most pronounced in public administration and retail sectors that also exhibited the largest statistical maturity gaps. These findings align with the behavioural risk literature reviewed by Mikes and Kaplan (2023), who contend that governance structures designed for accountability can paradoxically become mechanisms for the concealment of risk exposure. Performative Risk Management and Framework Limitations A second dominant theme concerned the performative function of ERM frameworks such as COSO and ISO 31000. Participants frequently distinguished between what one internal audit executive described as "the theatre of risk management" and genuine organisational risk reduction. The qualitative data suggest that framework compliance, including the completion of risk registers, the documentation of heat maps, and the conduct of periodic assessments, generates institutional legitimacy without proportionally reducing actual exposure. This observation resonates with Power's (2022) sociological critique of the "risk management of everything," in which the proliferation of risk management activity serves primarily to demonstrate accountability rather than to reduce harm. Participants noted that the COSO framework (COSO, 2023), while comprehensive in its prescriptions, provides insufficient guidance on the distinction between documented compliance and demonstrated resilience a gap that this study's quantitative findings confirm, given that ERM framework adoption was not a statistically significant predictor of reduced incident frequency (β = −.11, p = .22). The Activity-Outcome Metric Disconnect Participants across all sectors consistently articulated a disconnect between the metrics used to evaluate risk management performance and the outcomes those metrics were intended to reflect. Maturity assessments overwhelmingly focused on input indicators the number of risk assessments completed, the frequency of committee meetings, and the coverage of policy documentation, rather than on output metrics such as incident reduction rates, recovery times, or financial loss containment. This finding is consistent with the critique advanced by Lam (2022) and empirically supported by Protiviti and RIMS (2024), who found that over half of surveyed organisations conflate activity volume with risk effectiveness. The IRMSA (2025) South Africa Risk Report similarly notes that South African organisations remain disproportionately focused on compliance-based risk activity, a trend this study confirms across the sample. Participants from the insurance and financial services sectors, whose outcomes showed tighter maturity-incident alignment in the quantitative data, were notably more likely to reference output-focused KPIs such as claims frequency, near-miss reporting rates, and post-incident recovery benchmarks as primary governance instruments. Governance and Leadership Deficits in Risk Intelligence The fourth theme concerned the quality of risk intelligence reaching executive and board-level decision-makers. Consistent with findings reported by the National Association of Corporate Directors (NACD, 2025) that nearly one-third of directors are most concerned about risks they have not yet imagined, interview participants described board risk oversight as reactive, backward-looking, and heavily mediated by management filters that prioritise reassurance over accuracy. Deloitte's (2024) finding that executives receive extensive risk data while lacking confidence in their ability to act on it was directly echoed by non-executive directors in this sample, who described risk reports as voluminous but insufficiently actionable. Participants highlighted the role of AI-enabled continuous monitoring tools, deployed in several financial services and insurance organisations, as a meaningful disruptor of this dynamic providing real-time risk signals that reduced dependence on periodic, curated reporting. This finding supports Gartner's (2024) projection that technology integration will become a primary differentiator of genuine risk maturity, a conclusion reinforced by the significant negative regression coefficient for technology integration in the quantitative model (β = −.27, p = .003). Integrated Discussion and Theoretical Implications Taken together, the qualitative and quantitative findings of this study provide robust, triangulated evidence for the existence and structural persistence of the risk maturity gap in South African enterprise contexts. The quantitative finding that self-assessed maturity does not significantly predict reduced risk incidents, while governance quality and technology integration do, situates the maturity gap firmly in the realm of governance architecture and capability deployment rather than framework adoption per se. This is a theoretically significant distinction. It suggests that the problem identified by Beasley et al. (2021) that organisations possessing formal ERM structures continue to faiL is not attributable to an absence of frameworks but to the conditions under which those frameworks are embedded, operationalised, and reported upon. The qualitative evidence of pervasive cognitive bias institutionalisation corroborates and extends Kahneman et al.'s (2021) individual-level theory of overconfidence into the organisational domain, demonstrating that reporting norms, governance structures, and leadership dynamics aggregate individual biases into durable collective overconfidence. This institutional amplification mechanism, which has remained undertheorised in the ERM literature, is a central theoretical contribution of this research. Furthermore, the finding that technology integration, specifically AI-enabled continuous monitoring functions as a structural disruptor of performative risk management, offers a practically actionable pathway for organisations seeking to transition from activity-based assurance to outcome-based resilience, as envisioned by Lam (2022) and validated empirically by this study's regression results. The South African context adds a further layer of complexity. The polycrisis conditions documented by the World Economic Forum (2025) — encompassing economic volatility, load-shedding infrastructure disruptions, and heightened third-party vendor risk — create an environment in which the costs of performative risk management are acutely tangible. Verizon's (2025) identification of vendor-related breaches as among the fastest-growing risk categories is borne out in this sample, with 71% of survey respondents reporting at least one significant third-party incident in the preceding 24 months. These findings collectively underscore the urgency of transitioning South African risk governance from compliance performance toward genuine adaptive resilience, informed by real-time intelligence and outcome-focused accountability structures. CONCLUSION This study set out to investigate why organisations continue to experience recurrent risk events despite having established ERM frameworks, and to identify the structural and behavioural mechanisms that sustain the gap between perceived risk maturity and actual risk reduction outcomes. The evidence gathered is unambiguous on the central argument: the risk maturity gap is not produced by an absence of risk management activity, but by a fundamental disconnect between process execution and meaningful harm reduction. Self-assessed maturity scores did not significantly predict reduced incident frequency, while governance quality and technology integration did, confirming that possessing a framework and genuinely embedding adaptive risk capability are two very different things. The study further demonstrated that cognitive biases, particularly overconfidence and the normalisation of deviance, are institutionalised through reporting structures and board-level governance norms in ways that make collective overconfidence self-reinforcing and durable. Organisations that measure their risk management effectiveness primarily through input metrics, such as assessments completed, policies documented, are, in effect, measuring their own reassurance rather than their resilience. The study carries important limitations. The South African research context, while rich and representative of a middle-income economy navigating ERM maturation, limits direct generalisation to jurisdictions with substantially different regulatory histories or risk cultures. Cross-sectional data collection precludes causal inference, and self-report instruments on governance failures remain susceptible to social desirability bias despite anonymous collection. The sample, while senior-heavy and cross-sectoral, did not include external auditors or regulators, whose perspectives would add a valuable independent layer to the findings. Several recommendations follow from these findings. Organisations should urgently reorient their risk maturity assessments toward output metrics, incident frequency, recovery time, and loss containment, and treat self-assessed capability scores with appropriate scepticism unless validated against outcome data. Boards must demand risk intelligence that is actionable and forward-looking, not merely voluminous. Investment in AI-enabled continuous monitoring should be prioritised as a structural disruptor of performative risk governance. Future research should pursue longitudinal designs to assess whether governance quality improvements demonstrably reduce incident rates over time, and cross-national studies to examine how different regulatory environments shape the maturity gap's persistence. The gap between confidence and capability is not inevitable, but closing it requires organisations to measure what actually matters. REFERENCES Aven, T. (2021). Risky business or risky society? On the use of risk science to understand and govern societal risks. Risk Analysis, 41(3), 439–452. https://doi.org/10.1111/risa.13555 Beasley, M. S., Branson, B. C., & Pagach, D. (2021). An analysis of the maturity and strategic impact of investments in enterprise risk management. Journal of Accounting and Public Policy, 40(2), Article 106847. https://doi.org/10.1016/j.jaccpubpol.2021.106847 Braun, V., & Clarke, V. (2022). Thematic analysis: A practical guide. SAGE Publications. Bryman, A. (2022). Social research methods (6th ed.). Oxford University Press. Committee of Sponsoring Organizations of the Treadway Commission (COSO). (2023). Strengthening enterprise risk management for strategic advantage. COSO. Creswell, J. W., & Creswell, J. D. (2023). Research design: Qualitative, quantitative, and mixed methods approaches (6th ed.). SAGE Publications. Creswell, J. W., & Poth, C. N. (2024). Qualitative inquiry and research design: Choosing among five approaches (5th ed.). SAGE Publications. Deloitte. (2024). Global risk management survey: Navigating uncertainty in a complex world (13th ed.). Deloitte Insights. https://www2.deloitte.com/global/en/pages/financial-services/articles/global-risk-management-survey.html Flick, U. (2022). An introduction to qualitative research (7th ed.). SAGE Publications. Gartner. (2024). Top risk management trends: Building resilient organizations in 2024 and beyond. Gartner Research. Hopkin, P. (2022). Fundamentals of risk management: Understanding, evaluating and implementing effective risk management (6th ed.). Kogan Page. HUB International. (2026). 2026 HUB North American outlook report: Risk and talent strategies for a resilient future . HUB International Limited. IBM Corp. (2023). IBM SPSS Statistics for Windows, Version 29.0. IBM Corp. Institute of Risk Management South Africa (IRMSA). (2025). South Africa risk report 2025. IRMSA. https://www.irmsa.org.za Kahneman, D., Sibony, O., & Sunstein, C. R. (2021). Noise: A flaw in human judgment. Little, Brown Spark. Lam, J. (2022). Transforming enterprise risk management: From compliance to competitive advantage. Wiley. McKinsey & Company. (2023). Risk and resilience: Closing the gap between intent and execution . McKinsey Global Institute. https://www.mckinsey.com/capabilities/risk-and-resilience Mikes, A., & Kaplan, R. S. (2023). Managing risks: A new framework revisited. Harvard Business Review, 101(2), 48–60. National Association of Corporate Directors (NACD). (2025). 2025 NACD director survey: Board oversight in an era of complexity. NACD. https://www.nacdonline.org Pallant, J. (2024). SPSS survival manual: A step-by-step guide to data analysis using IBM SPSS (8th ed.). McGraw-Hill. Podsakoff, P. M., MacKenzie, S. B., & Podsakoff, N. P. (2024). Common method biases in behavioral research: A critical review and future directions. Journal of Applied Psychology, 108(4), 542–568. https://doi.org/10.1037/apl0000533 Power, M. (2022). The risk management of everything: Rethinking the politics of uncertainty (2nd ed.). Demos. PricewaterhouseCoopers (PwC). (2024). Global risk survey 2024: Building trust in an age of disruption. PricewaterhouseCoopers International Limited. https://www.pwc.com/global-risk-survey Protiviti & Risk and Insurance Management Society (RIMS). (2024). Executive perspectives on top risks 2024: Navigating third-party and strategic uncertainty. Protiviti Inc. https://www.protiviti.com/top-risks QSR International. (2023). NVivo (Version 15) [Computer software]. QSR International Pty Ltd. https://www.qsrinternational.com R Core Team. (2023). R: A language and environment for statistical computing (Version 4.3.2). R Foundation for Statistical Computing. https://www.R-project.org Republic of South Africa. (2013). Protection of Personal Information Act 4 of 2013. Government Gazette. https://www.gov.za/documents/protection-personal-information-act Saunders, M. N. K., Lewis, P., & Thornhill, A. (2023). Research methods for business students (9th ed.). Pearson Education. Sull, D., & Sull, C. (2023). Why strategy execution unravels—and what to do about it: Lessons for risk-integrated management. MIT Sloan Management Review, 64 (1), 22–31. Taleb, N. N. (2020). Statistical consequences of fat tails: Real world preasymptotics, epistemology, and applications. STEM Academic Press. Tashakkori, A., Johnson, R. B., & Teddlie, C. (2021). Foundations of mixed methods research: Integrating quantitative and qualitative approaches in the social and behavioral sciences (2nd ed.). SAGE Publications. Verizon. (2025). 2025 Data breach investigations report. Verizon Business. https://www.verizon.com/business/resources/reports/dbir/ Verizon. (2025). 2025 data breach investigations report. Verizon Business. https://www.verizon.com/business/resources/reports/dbir/ Weick, K. E., & Sutcliffe, K. M. (2021). Managing the unexpected: Sustained performance in a complex world (4th ed.). Wiley. Weick, K. E., & Sutcliffe, K. M. (2021). Managing the unexpected: Sustained performance in a complex world (4th ed.). Wiley. World Economic Forum. (2024). Resilience frameworks and organizational adaptation: Bridging strategy and risk practice . World Economic Forum Insight Report. https://www.weforum.org World Economic Forum. (2025). The global risks report 2025 (20th ed.). World Economic Forum. https://www.weforum.org/reports/global-risks-report-2025 Additional Declarations The authors declare no competing interests. Cite Share Download PDF Status: Posted Version 1 posted You are reading this latest preprint version Research Square lets you share your work early, gain feedback from the community, and start making changes to your manuscript prior to peer review in a journal. As a division of Research Square Company, we’re committed to making research communication faster, fairer, and more useful. We do this by developing innovative software and high quality services for the global research community. Our growing team is made up of researchers and industry professionals working together to solve the most critical problems facing scientific publishing. Also discoverable on Platform About Our Team In Review Editorial Policies Advisory Board Help Center Resources Author Services Accessibility API Access RSS feed Manage Cookie Preferences © Research Square 2026 | ISSN 2693-5015 (online) Privacy Policy Terms of Service Do Not Sell My Personal Information {"props":{"pageProps":{"initialData":{"identity":"rs-9032336","acceptedTermsAndConditions":true,"allowDirectSubmit":true,"archivedVersions":[],"articleType":"Research Article","associatedPublications":[],"authors":[{"id":610109699,"identity":"db4d5d45-4bc4-4d28-b353-2885bc98e40a","order_by":0,"name":"Dickson Mdhlalose","email":"data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAZAAAAAyAQMAAABI0h/eAAAABlBMVEX///8AAABVwtN+AAAACXBIWXMAAA7EAAAOxAGVKw4bAAAA00lEQVRIiWNgGAWjYDCCAwzMEAZ7A5AwsCBFC88BkBYJUrRIJIBJwjr4zh9/bPDhj10e/8znVzf8KJBg4G/vTsCrRfJGjnHizLbkYonbOWU3e4AOkzhzdgNeLQY3eJgP8zYwJzbczkm7wQPUYiCRS0AL0GGHef7UJ86/eSbt5h+itBxIME7mYTucuOEG+7HbRNkC8ovhzLbjiRvP5LDdljGQ4CHoF1CISXz4U5047/jxZzff/LGR42/vxa8FCfAYgElilYMA+wNSVI+CUTAKRsEIAgCTtU1R0MAmKgAAAABJRU5ErkJggg==","orcid":"","institution":"National Electronic Media Institute of South Africa","correspondingAuthor":true,"prefix":"","firstName":"Dickson","middleName":"","lastName":"Mdhlalose","suffix":""}],"badges":[],"createdAt":"2026-03-04 16:23:12","currentVersionCode":1,"declarations":{"humanSubjects":false,"vertebrateSubjects":false,"conflictsOfInterestStatement":false,"humanSubjectEthicalGuidelines":false,"humanSubjectConsent":false,"humanSubjectClinicalTrial":false,"humanSubjectCaseReport":false,"vertebrateSubjectEthicalGuidelines":false},"doi":"10.21203/rs.3.rs-9032336/v1","doiUrl":"https://doi.org/10.21203/rs.3.rs-9032336/v1","draftVersion":[],"editorialEvents":[],"editorialNote":"","failedWorkflow":false,"files":[{"id":105727910,"identity":"499d9f6f-f36c-44a7-b1aa-b6d69e79f0e0","added_by":"auto","created_at":"2026-03-30 11:05:26","extension":"pdf","order_by":0,"title":"","display":"","copyAsset":false,"role":"manuscript-pdf","size":847143,"visible":true,"origin":"","legend":"","description":"","filename":"manuscript.pdf","url":"https://assets-eu.researchsquare.com/files/rs-9032336/v1/f1270a9c-0289-464d-9c07-a4884aaae5c2.pdf"}],"financialInterests":"The authors declare no competing interests.","formattedTitle":"\u003cp\u003eThe Risk Maturity Gap: Examining the Disconnect Between Organizational Confidence and Effective Risk Mitigation\u003c/p\u003e","fulltext":[{"header":"INTRODUCTION","content":"\u003cp\u003e\u003cstrong\u003eBackground and Context\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003eSomething quietly strange has happened to risk management over the past two decades. What began as a back-office compliance function, a necessary but largely administrative obligation performed at the edges of organisational life, has been elevated, refined, and institutionalised into a board-level discipline with its own frameworks, professional bodies, international standards, and dedicated executive roles. Organisations across virtually every sector have poured significant resources into risk governance: building enterprise risk management (ERM) infrastructures, commissioning assessments, constructing elaborate heat maps, and pursuing certification against benchmarks like Committee of Sponsoring Organizations of the Treadway Commission (COSO) and International Organization for Standardization\u003cstrong\u003e\u0026nbsp;(\u003c/strong\u003eISO) 31000 (Hopkin, 2022). By almost every visible measure, the risk management profession has come of age. And yet, for all of that maturation, organisations keep getting hurt by risks they should have seen coming or by risks their own documentation suggested were well under control.\u003c/p\u003e\n\u003cp\u003eThis is not a marginal or sector-specific observation. The World Economic Forum (2025) characterises the current decade as an era of polycrisis, the simultaneous convergence of geopolitical instability, economic volatility, climate disruption, and technological acceleration into a compounding risk environment with no clear precedent in the history of enterprise governance. Against that backdrop, the limitations of conventional risk management paradigms have become very difficult to ignore. Frameworks built on periodic assessments, static heat maps, and backward-looking metrics were designed for a different kind of risk landscape one that was more stable, more predictable, and considerably more forgiving of slow analytical cycles (Aven, 2021). Today\u0026apos;s operating environment, characterised by deep organisational interdependence through global supply chains and digital integration, has exposed those frameworks as structurally inadequate for the kinds of emergent, interconnected threats that now routinely materialise into consequential harm.\u003c/p\u003e\n\u003cp\u003eThe discipline is beginning to reckon with this. There is a visible and growing movement in both the scholarly and practitioner literature away from process-centric definitions of risk management, the idea that having the right framework in place is the same as managing risk effectively, toward outcome-oriented, adaptive models that ask a simpler and more demanding question: is actual harm being reduced? (Lam, 2022). At the same time, the technological landscape is shifting the possibilities for what real-time risk insight can look like, with artificial intelligence and continuous monitoring tools offering organisations the capacity to detect and respond to emerging threats far faster than traditional review cycles allow (Gartner, 2024). And the third-party risk domain, long treated as a secondary concern, has moved sharply to the foreground: Verizon (2025) reports that supply chain and vendor-related incidents are now among the fastest-growing categories of organisational breach, a development that calls into question the adequacy of risk perimeters drawn primarily around internal operations. What these trends collectively signal is a discipline that knows its inherited tools are falling short and is actively, if unevenly, searching for better ones.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eProblem Statement\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003eThere is a particular kind of evidence that should give any risk professional pause, and the most recent industry research provides it in abundance. While organisations have invested steadily and substantially in risk frameworks, compliance structures, and assessment processes over more than two decades, the rate at which risk events continue to materialise offers a pointed challenge to the confidence embedded in those investments. HUB International (2026) found that a third of North American companies operate without mature risk strategies, and that only 5% had reached what the report classified as advanced risk maturity \u0026mdash; a figure that is difficult to square with the widespread formal adoption of ERM. Third-party risk data sharpens the picture further: organisations experience an average of twelve vendor-related breaches annually, yet more than half rate their own assessment processes as effective at reducing risk (Protiviti \u0026amp; RIMS, 2024). The gap between those two facts is not a statistical curiosity. It is the central problem this research investigates.\u003c/p\u003e\n\u003cp\u003eThat gap, which this study terms the maturity gap, points toward something more troubling than poor execution: the possibility that current risk management approaches are generating a form of institutional confidence that is not warranted by actual capability (Beasley et al., 2021). Boards are beginning to feel the edges of this problem, even if they have not always named it directly. Nearly one-third of directors report that their greatest concern relates to risks they have not yet imagined, an admission that sits uneasily alongside the elaborate risk registers and governance structures many of those same organisations maintain (NACD, 2025). Deloitte (2024) identified a related symptom at the executive level: senior leaders routinely receive extensive risk data while simultaneously reporting limited confidence in their ability to use it to make meaningful decisions. That is not a data problem. It is an insight problem a failure not of information volume but of the quality and nature of the intelligence that governance systems are producing.\u003c/p\u003e\n\u003cp\u003eBeneath these institutional symptoms lies a layer of cognitive and behavioural dynamics that the organisational psychology literature has documented with considerable precision. Overconfidence bias, optimism bias, and the illusion of control operate systematically and predictably in environments where the consequences of errors are delayed, feedback is infrequent, and social norms reward expressions of capability over admissions of uncertainty (Kahneman et al., 2021; Weick \u0026amp; Sutcliffe, 2021). What the risk management context adds to these well-established individual-level phenomena is the institutional amplification effect: when these biases become embedded in reporting structures, governance norms, and risk rating processes, they stop being individual cognitive tendencies and become organisational features durable, self-reinforcing, and very difficult to dislodge. The maturity gap, on this account, is not primarily a technical failure. It is a structural and cultural one, and the distinction matters enormously for how organisations should respond to it (Power, 2022; Mikes \u0026amp; Kaplan, 2023).\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eResearch Gap\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003eThe scholarly literature on ERM is not thin; there is no shortage of frameworks, standards, prescriptions, and case analyses available to the practitioner or researcher who goes looking. What is thin is the explanatory literature: the body of work that tries to account for why organisations that have done all the right things on paper continue to experience the consequences of inadequate risk governance in practice. The existing research has concentrated heavily on process maturity, mapping the presence and quality of documented policies, governance structures, and assessment workflows while investing far less in the harder question of programme maturity, defined as the actual reduction of harmful risk outcomes (Beasley et al., 2021; Hopkin, 2022). The result is a literature that can describe what mature risk management is supposed to look like but cannot fully explain why possessing those structures does not reliably produce the protection they promise.\u003c/p\u003e\n\u003cp\u003eTwo specific gaps are most consequential for this research. The first concerns the institutional dimension of cognitive bias. Overconfidence, optimism bias, and the noise that corrupts human judgment have been theorised extensively at the individual level (Kahneman et al., 2021), but the mechanisms by which these individual tendencies aggregate into collective organisational overconfidence and then become self-sustaining through governance structures, reporting cultures, and board-level norms remain insufficiently understood. Similarly, while the tension between compliance-oriented and resilience-oriented risk practice is openly acknowledged in practitioner discourse, the scholarly literature has not yet produced robust frameworks for distinguishing the two in operational terms, or for identifying the conditions under which organisations can move from one to the other (Aven, 2021; Sull \u0026amp; Sull, 2023). Power\u0026apos;s (2022) sociological account of the risk management of everything, the proliferation of risk governance activity as a form of institutional performance rather than genuine harm reduction, provides the most incisive diagnosis of the problem, but does not offer an organisational-level prescription for breaking the cycle.\u003c/p\u003e\n\u003cp\u003eThe second gap concerns governance and leadership. Research on board-level risk oversight has been largely structural in its orientation, examining committee composition, reporting frequency, and regulatory compliance rather than the qualitative question of how boards actually receive, interpret, and act on risk intelligence (McKinsey \u0026amp; Company, 2023). The communication dynamics between risk professionals and executive decision-makers, the role of organisational culture in shaping what information travels upward and in what form, and the conditions under which leadership fosters genuine risk learning rather than performative reassurance remain poorly theorised and empirically underexamined (PwC, 2024). This research addresses both gaps by drawing together behavioural theory, governance scholarship, and current practice evidence to construct an integrated explanatory account of why the risk maturity gap persists and what structural and cultural conditions would need to change for it to close.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eResearch Aim\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003eThis research sets out to investigate, with both theoretical rigour and practical intent, why organisations continue to experience recurrent risk events despite having established risk management frameworks, and to identify the structural and behavioural factors that sustain the gap between perceived risk maturity and actual risk reduction outcomes. Four interrelated objectives guide the inquiry. The first examines the psychological and organisational literature on cognitive bias to understand how overconfidence, optimism, and the illusion of control at the individual level aggregate into durable collective dysfunction at the institutional level (Kahneman et al., 2021; Weick \u0026amp; Sutcliffe, 2021). The second traces the historical evolution of risk management paradigms, critically evaluating whether the dominant frameworks COSO and ISO 31000 inadvertently encourage performative compliance rather than genuine resilience (COSO, 2023; Aven, 2021). The third interrogates the metrics and maturity models through which organisations assess their own effectiveness, examining how the systematic conflation of input metrics assessments completed, policies documented with output metrics incident reduction, loss containment, distorts organisational self-perception and undermines accountability (Lam, 2022; Protiviti \u0026amp; RIMS, 2024). The fourth examines the governance and leadership dynamics that shape the quality and utility of risk intelligence reaching board and executive decision-makers, including the increasingly significant role of AI-enabled continuous monitoring in providing real rather than retrospective risk insight (Gartner, 2024; Verizon, 2025).\u003c/p\u003e\n\u003cp\u003eThese objectives are not pursued in isolation. They are designed to speak to one another, because the maturity gap is not produced by any single failure; it emerges from the interaction of cognitive tendencies, framework limitations, metric dysfunctions, and governance deficits that reinforce each other in ways that make the problem both persistent and, with the right analytical tools, tractable. The study contributes to scholarly literature by developing an integrated explanatory framework for the maturity gap, and to practice by identifying the specific organisational conditions under which risk management can transition from activity-based assurance to outcome-based resilience (Deloitte, 2024; World Economic Forum, 2025). The evidence that current approaches are failing, however well-designed and well-intentioned they may be, is, at this point, too substantial to defer. The urgency of a better answer is the premise from which this research proceeds.\u003c/p\u003e"},{"header":"RESEARCH METHODOLOGY","content":"\u003ch2\u003e\u003cstrong\u003eResearch Design and Philosophical Orientation\u003c/strong\u003e\u003c/h2\u003e\n\u003cp\u003eThis study employed an exploratory sequential mixed-methods research design to investigate the structural, behavioural, and cultural mechanisms that sustain the disconnect between perceived risk management maturity and actual risk reduction outcomes in South African organisations. The philosophical foundation of this research is critical realism, a paradigm that acknowledges the existence of objective organisational structures and mechanisms while recognising that their effects are mediated by context, interpretation, and human agency (Saunders et al., 2023). Critical realism is particularly well-suited to this inquiry because the risk maturity gap is not merely a perceptual phenomenon it is produced by identifiable structural and cognitive mechanisms that operate beneath the surface of documented frameworks and formal governance processes (Bhaskar, 2023, as cited in Creswell \u0026amp; Creswell, 2023). The sequential exploratory design proceeded in two phases: a qualitative phase that identified the mechanisms and conditions sustaining the maturity gap, followed by a quantitative phase that tested the prevalence and relative influence of those mechanisms across a broader cross-sectoral sample within South Africa.\u003c/p\u003e\n\u003ch2\u003e\u003cstrong\u003eResearch Setting and Justification\u003c/strong\u003e\u003c/h2\u003e\n\u003cp\u003eThe study was conducted within the South African enterprise context, encompassing organisations in the financial services, mining, insurance, healthcare, retail, and public administration sectors. South Africa represents a compelling research setting for several reasons. As a middle-income economy with sophisticated financial markets, advanced regulatory infrastructure, and significant exposure to both global and domestic risk events, South Africa occupies a transitional position in risk management maturity sophisticated enough to have institutionalised ERM frameworks, yet sufficiently exposed to systemic failures to render the maturity gap acutely visible (Institute of Risk Management South Africa [IRMSA], 2025). Furthermore, the post-pandemic operating environment in South Africa has intensified polycrisis dynamics, the simultaneous convergence of geopolitical, economic, climatic, and technological risk pressures documented globally by the World Economic Forum (2025), making the adequacy of existing risk paradigms an urgent local concern. South African organisations are also navigating heightened third-party risk exposure, consistent with Verizon\u0026apos;s (2025) finding that vendor-related breaches represent one of the fastest-growing categories of organisational harm internationally.\u003c/p\u003e\n\u003ch2\u003e\u003cstrong\u003ePhase One: Qualitative Data Collection and Analysis\u003c/strong\u003e\u003c/h2\u003e\n\u003cp\u003eThe qualitative phase employed semi-structured in-depth interviews as the primary data collection instrument. This method was selected because the research problem requires the exploration of subjective perceptions, institutional norms, and governance dynamics that cannot be adequately captured by pre-structured survey instruments (Bryman, 2022). Semi-structured interviews provide the flexibility to probe contextually specific phenomena such as how boards receive and act upon risk intelligence, or how overconfidence becomes institutionalised through reporting structures while maintaining sufficient consistency across participants to enable meaningful thematic comparison (Creswell \u0026amp; Poth, 2024). A purposive, criterion-based sampling strategy was employed, targeting professionals with direct, substantive involvement in ERM, board-level governance, organisational strategy, or internal audit functions within South African organisations.\u003c/p\u003e\n\u003cp\u003eA total of 26 participants were interviewed, drawn from organisations headquartered or operating in Johannesburg, Pretoria, Cape Town, Durban, and Port Elizabeth. The sample included Chief Risk Officers (CROs), Chief Financial Officers (CFOs), board-level non-executive directors, internal audit executives, risk management consultants, and representatives from professional bodies, including the Institute of Risk Management South Africa (IRMSA) and the Chartered Institute of Management Accountants (CIMA) South Africa chapter. Theoretical saturation, the point at which additional interviews yielded no substantively new themes, was used as the criterion for determining sample sufficiency (Saunders et al., 2023). Interviews were conducted between February and June 2025, each lasting between 50 and 85 minutes. All sessions were audio-recorded with informed consent and transcribed verbatim. Member-checking was conducted by sharing transcripts with participants before analysis, enhancing the credibility of interpretive findings (Creswell \u0026amp; Poth, 2024).\u003c/p\u003e\n\u003cp\u003eQualitative data were analysed using reflexive thematic analysis following the six-phase framework of Braun and Clarke (2022): familiarisation, initial coding, theme generation, theme review, theme definition, and write-up. The entire analytical process was managed using NVivo 15 (QSR International, 2023), which facilitated systematic organisation of codes and themes, transparent audit trails, and inter-coder comparison. A second independent researcher reviewed a randomised 20% subsample of coded data to calculate inter-coder reliability; Cohen\u0026apos;s kappa values exceeding 0.75 were achieved across all thematic domains, indicating strong agreement (McHugh, 2012, as cited in Pallant, 2024). Emergent themes centred on the institutionalisation of overconfidence, the performative function of risk frameworks, and the governance conditions that either perpetuate or disrupt the maturity gap.\u003c/p\u003e\n\u003ch2\u003e\u003cstrong\u003ePhase Two: Quantitative Data Collection and Analysis\u003c/strong\u003e\u003c/h2\u003e\n\u003cp\u003eThe quantitative phase deployed a structured, self-administered online survey instrument developed from the theoretical constructs and thematic findings of Phase One. Survey items drew additionally on established frameworks, including the COSO ERM Framework (COSO, 2023), the ISO 31000 risk management standard, and the Protiviti and RIMS (2024) executive risk perspectives survey, ensuring theoretical grounding and content validity. The final instrument comprised 54 items across six validated constructs: risk maturity self-assessment, risk incident frequency, governance quality, cognitive bias susceptibility, leadership risk intelligence, and technology integration. All Likert-scale constructs used five-point response formats. The survey was piloted with 15 practitioners before full deployment to assess readability, face validity, and internal consistency. Cronbach\u0026apos;s alpha coefficients for all multi-item scales ranged from 0.73 to 0.89, meeting the conventional reliability threshold (Pallant, 2024).\u003c/p\u003e\n\u003cp\u003eThe survey was administered to 214 risk management and governance professionals across South African organisations using a combination of professional network outreach, targeted LinkedIn recruitment, and distribution through IRMSA and the Southern African Institute of Management Scientists (SAIMS). Respondents were required to confirm active involvement in risk management or executive governance to qualify for participation. Quantitative data were analysed using IBM SPSS Statistics Version 29 (IBM Corp., 2023) and R Statistical Software Version 4.3.2 (R Core Team, 2023). Descriptive statistics summarised sample characteristics and response distributions. Pearson correlation analysis and multiple linear regression were used to examine relationships between risk maturity self-assessment scores, governance quality indices, and reported risk incident rates. Independent-samples t-tests and one-way ANOVA were applied to assess group-level differences by sector, organisation size, and ERM framework adoption. Confirmatory factor analysis, conducted in R using the lavaan package, validated the latent structure of the risk maturity and governance quality scales. Statistical significance was assessed at \u0026alpha; = 0.05 across all inferential analyses.\u003c/p\u003e\n\u003ch2\u003e\u003cstrong\u003eIntegration of Qualitative and Quantitative Findings\u003c/strong\u003e\u003c/h2\u003e\n\u003cp\u003eIn accordance with the sequential exploratory design, qualitative and quantitative findings were integrated at the interpretation stage, a process referred to in mixed-methods scholarship as meta-inference (Tashakkori et al., 2021). Qualitative themes provided the explanatory layer for patterns identified in the quantitative data for instance, the statistical finding that organisations with high self-assessed maturity scores reported disproportionately high incident rates was contextualised through interview data revealing how governance structures and reporting norms institutionalise overconfidence. This integration strengthens the explanatory power of the research beyond what either method could achieve independently and directly responds to the theoretical gap identified by Beasley et al. (2021), Kahneman et al. (2021), and Power (2022) regarding the behavioural and structural mechanisms underlying performative risk management.\u003c/p\u003e\n\u003ch2\u003e\u003cstrong\u003eEthical Considerations\u003c/strong\u003e\u003c/h2\u003e\n\u003cp\u003eEthical clearance was obtained from the relevant institutional review board before the commencement of data collection. All participants provided written informed consent and were explicitly advised of their unconditional right to withdraw at any stage without consequence. Confidentiality was maintained throughout: participating organisations are identified only by sector and size category, and individual participants are described by role type alone. All digital data, including audio recordings and interview transcripts, was stored on encrypted, password-protected institutional servers. Audio recordings were permanently deleted upon completion of transcription. The study was conducted in full compliance with the Protection of Personal Information Act (POPIA) (Republic of South Africa, 2013) and the ethical guidelines of the hosting institution. No financial incentives were offered to participants, mitigating the risk of response bias (Flick, 2022).\u003c/p\u003e\n\u003ch2\u003e\u003cstrong\u003eValidity, Reliability, and Limitations\u003c/strong\u003e\u003c/h2\u003e\n\u003cp\u003eMethodological rigour was ensured through multiple triangulation strategies: data source triangulation (interviews and survey data), methodological triangulation (qualitative and quantitative approaches), and analyst triangulation (independent coding review). The use of NVivo 15 and IBM SPSS Statistics Version 29 across both phases ensured systematic, transparent, and reproducible analytical procedures. Notwithstanding these measures, several limitations are acknowledged. The South African setting, while internally diverse, limits the direct generalisability of findings to other national contexts with substantially different regulatory regimes, ERM adoption histories, or economic risk environments. Self-report data in both phases are susceptible to social desirability bias, particularly given the sensitive nature of questions relating to governance failures and risk incidents a limitation partially mitigated through anonymous data collection and the non-attribution of organisational identifiers (Podsakoff et al., 2024). Cross-sectional data collection also precludes causal inference; longitudinal designs in future research would strengthen the temporal validity of findings relating to maturity gap persistence.\u003c/p\u003e"},{"header":"LITERATURE REVIEW","content":"\u003cp\u003eThere is a particular kind of organisational failure that is harder to explain than incompetence: the failure of organisations that are doing everything they are supposed to do and still getting it wrong. This is the central puzzle of the risk maturity gap, and it is a puzzle the existing literature has been circling without fully resolving for the better part of two decades. Four bodies of scholarship are directly relevant to understanding the psychology of risk perception and collective overconfidence, the historical evolution of risk management paradigms, the metrics and models through which organisations assess their own effectiveness, and the governance dynamics that either perpetuate or disrupt the gap between perceived capability and actual resilience. Together, these literatures build the theoretical scaffolding for this study\u0026apos;s core argument: that the risk maturity gap is not a knowledge problem, a resource problem, or even primarily a framework problem; it is a structural and behavioural problem that requires a different kind of diagnosis (Beasley et al., 2021; Power, 2022).\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eTheoretical Foundations of Risk Perception and Organisational Overconfidence\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003eThe most durable insight in the behavioural risk literature is also one of the most uncomfortable: human beings are systematically, predictably overconfident about their ability to anticipate and manage uncertainty. Kahneman et al. (2021) provided the most comprehensive recent account of this phenomenon, distinguishing between the classical notion of individual overconfidence bias and the less-examined concept of noise the inconsistency and variability in human judgment that compound bias into structural unreliability at the organisational level. Their argument is not that risk professionals are careless or unintelligent; it is that the cognitive architecture of human judgment produces predictable distortions, particularly in domains characterised by ambiguity, low feedback frequency, and high personal stakes, which is to say, precisely the domains in which ERM operates.\u003c/p\u003e\n\u003cp\u003eTversky and Kahneman\u0026apos;s prospect theory, while originating in the 1970s, has been substantially extended in recent scholarship to illuminate how organisations, not just individuals, assess risk (Aven, 2021). The optimism bias, the systematic tendency to underestimate the probability of adverse outcomes relative to favourable ones, manifests in enterprise contexts as the routine production of risk registers that emphasise manageable, familiar risks while undercounting tail risks and emergent threats. Weick and Sutcliffe (2021) named this tendency the normalisation of deviance: the gradual organisational habituation to warning signals that, because they have not yet produced catastrophe, are reclassified as tolerable. Their updated account of high-reliability organisations argues that what distinguishes resilient organisations from fragile ones is not the absence of risk but the active, institutionalised refusal to let anomalies be explained away.\u003c/p\u003e\n\u003cp\u003eThe leap from individual bias to collective overconfidence is where the literature becomes most directly relevant to this study\u0026apos;s problem statement. Janis\u0026apos;s (1982) foundational concept of groupthink, the suppression of dissent within cohesive groups under pressure, has been revisited and extended by Sull and Sull (2023), who demonstrate that execution failures in organisations are frequently attributable not to poor strategy but to cultural norms that discourage the escalation of uncomfortable information. In the risk context, this dynamic translates into governance structures where red-rated risks are quietly reclassified before reaching the boardroom, not through deliberate deception but through the accumulated weight of social norms that treat reassurance as professionalism and alarm as alarmism. Mikes and Kaplan (2023) revisited their influential risk management typology with precisely this insight: that the governance conditions designed to promote accountability can paradoxically become mechanisms through which risk exposure is concealed. This argument, grounded in decades of empirical case study research, provides the behavioural foundation for the maturity gap hypothesis this study tests.\u003c/p\u003e\n\u003cp\u003eIt would be misleading, however, to present the overconfidence literature as entirely settled. Taleb (2020) argued that the risk management profession\u0026apos;s reliance on statistical probability models creates a false precision that is itself a form of institutional overconfidence, which he terms the fourth quadrant problem, in which the risks most likely to cause catastrophic harm are precisely those that standard models cannot adequately capture. This sceptical position challenges not just poor risk management practice but the foundational assumptions of quantitative risk modelling, a provocation that Aven (2021) engages directly in his critique of how risk science has evolved in ways that may reinforce rather than resolve the confidence-capability gap.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eThe Evolution from Compliance-Based to Resilience-Based Risk Management\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003eRisk management as an institutionalised discipline has a relatively short history, but within that history there is a visible and consequential trajectory: from informal, judgement-based practice, through the codification of processes and standards, toward a growing recognition that codification alone is insufficient. The Committee of Sponsoring Organizations of the Treadway Commission\u0026apos;s ERM framework (COSO, 2023) and the ISO 31000 standard represent the apex of the compliance-based paradigm internationally recognised, widely adopted, and, the evidence increasingly suggests, consistently inadequate as guarantors of genuine resilience. Hopkin (2022) traces this trajectory with clarity, noting that each successive iteration of ERM standards has expanded the scope of what risk management is supposed to encompass without addressing the more fundamental question of whether the activities prescribed actually reduce harmful outcomes.\u003c/p\u003e\n\u003cp\u003eThe distinction that the current literature most forcefully draws is between process maturity and programme maturity (Beasley et al., 2021). Process maturity describes the presence and quality of documented governance structures, risk registers, heat maps, assessment schedules, and committee charters. Programme maturity describes something far more difficult to measure and far more consequential: the demonstrated reduction of actual risk incidents and adverse outcomes. Beasley and colleagues\u0026apos; empirical analysis of ERM investment across a large sample of organisations found that organisations with highly developed ERM processes did not necessarily experience fewer damaging events a finding that crystallises the problem this study investigates and that its quantitative results extend into the South African enterprise context.\u003c/p\u003e\n\u003cp\u003ePower (2022) offered the most sociologically incisive critique of this trajectory. His concept of the risk management of everything describes a phenomenon in which the expansion of formal risk governance activity has become decoupled from its stated purpose, not through bad faith, but through the institutional logic of accountability systems that reward demonstrated activity over achieved outcomes. In a regulatory and stakeholder environment that demands visible risk management, organisations rationally invest in the performance of risk management: the documentation, the assessments, the certifications. What they do not necessarily invest in because it is harder to demonstrate and less directly rewarded is the harder, slower work of embedding genuine adaptive capacity. Lam (2022) characterised this as the compliance trap: a governance equilibrium in which risk management is simultaneously everywhere and, in the most important sense, nowhere.\u003c/p\u003e\n\u003cp\u003eThere are dissenting voices in this debate. Hopkin (2022) argued that the compliance-versus-resilience framing, while intellectually provocative, risks undervaluing the real governance benefits that structured ERM frameworks provide, particularly in organisations that previously had no systematic approach to risk at all. The World Economic Forum (2024) similarly contended that resilience-based frameworks are most effective when built upon, rather than in opposition to, the documentation and process discipline that compliance-oriented approaches establish. This is a reasonable counterargument, and it points toward a more nuanced conclusion than a simple dismissal of compliance-based ERM: the problem is not the frameworks themselves but the conflation of framework adoption with framework effectiveness a conflation this study\u0026apos;s findings consistently identify as a driver of the maturity gap.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eMeasuring What Matters: Metrics, Maturity Models, and the Activity-Outcome Disconnect\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003eIf the compliance-versus-resilience debate identifies the wrong destination, the metrics literature identifies the wrong map. Risk maturity models, the tools organisations use to assess and report their own risk management capability, are now ubiquitous in corporate governance practice, yet the scholarly literature on their validity is notably thin relative to their practical influence. Most widely used maturity models, including those embedded in COSO and ISO 31000 assessments and those produced by consultancies and professional bodies, evaluate maturity through input metrics: the number and comprehensiveness of risk assessments conducted, the coverage of documented policies, the frequency of committee meetings, and the proportion of risks with assigned owners (Lam, 2022). These are process indicators, not outcome indicators. They measure activity, not impact.\u003c/p\u003e\n\u003cp\u003eProtiviti and RIMS (2024) documented the practical consequences of this measurement approach in their most recent executive risk perspectives survey, finding that more than half of participating organisations rated their own risk assessment processes as effective while simultaneously reporting persistently high rates of adverse risk events. This self-assessment inflation is not random noise it reflects a structural feature of how maturity is defined and measured. When the criteria for success are drawn from the same compliance-oriented paradigm that the organisation is executing, the assessment tool cannot detect the gap between execution and outcome. Gartner (2024) identified this as one of the most significant limitations of current risk governance practice and projected that organisations able to shift toward continuous, technology-enabled outcome monitoring would develop a durable competitive differentiation in resilience.\u003c/p\u003e\n\u003cp\u003eThe deeper methodological critique in the literature concerns not just what is being measured but what is being missed. Aven (2021) argued that traditional risk assessments, periodic, expert-led, backward-looking, are structurally unable to identify the emergent, interconnected risks that characterise the contemporary operating environment, and which the World Economic Forum (2025) has described as polycrisis: the simultaneous convergence of multiple, reinforcing risk streams that static heat maps and siloed assessments simply cannot represent. This critique is supported by Verizon\u0026apos;s (2025) empirical finding that the fastest-growing categories of organisational breach vendor-related incidents, supply chain compromises were frequently risks that appeared manageable in isolation but escalated catastrophically through interconnection. IRMSA (2025) reported the same dynamic in the South African context, noting that organisations\u0026apos; over-reliance on self-assessment tools contributed to delayed recognition of third-party and systemic exposures.\u003c/p\u003e\n\u003cp\u003eMcKinsey and Company (2023) made the strongest practical case for reorienting risk measurement toward output metrics, arguing that organisations that define risk management success in terms of incident frequency, recovery time, and loss mitigation rather than policy coverage and assessment completion demonstrate meaningfully superior resilience outcomes over time. HUB International (2026) corroborated this in their most recent North American risk outlook, finding that only 5% of surveyed organisations had reached what they classified as advanced risk maturity, defined by outcome-oriented measurement, adaptive governance, and real-time risk intelligence, while a third operated without what the report characterised as a mature risk strategy at all. These figures are sobering, and they frame the South African context examined in this study within a global pattern of maturity overestimation.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eGovernance, Leadership, and the Challenge of Risk Insight\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003eThe governance literature on risk management has focused primarily on structural questions, board committee composition, reporting lines, audit cycles, and regulatory compliance and has devoted considerably less attention to the qualitative dimensions of risk oversight: whether the right information is reaching the right people in a form that enables genuine judgment rather than mere documentation. This is a significant gap, because the evidence suggests that governance structure and governance quality are not the same thing. Deloitte (2024), in its thirteenth global risk management survey, found that senior executives routinely receive voluminous risk data while simultaneously reporting low confidence in their ability to act on it meaningfully, a failure not of information quantity but of insight quality that represents one of the most consequential unresolved challenges in corporate governance.\u003c/p\u003e\n\u003cp\u003eThe National Association of Corporate Directors (NACD, 2025) survey found that nearly one-third of directors are most concerned about risks they have not yet imagined, which is, on first reading, startling. On reflection, it is an honest acknowledgment of the limits of retrospective, curated risk reporting the kind of reporting that tells a board what was true about risk at the time the report was compiled, filtered through management assessments, and formatted for reassurance rather than interrogation. PwC (2024) identified the communication gap between risk professionals and executive decision-makers as a structural feature of many organisations\u0026apos; governance arrangements, noting that risk professionals frequently possess considerably more nuanced views of organisational exposure than board-level reporting reflects, but lack either the mandate or the relational capital to convey it without sanitisation. Mikes and Kaplan (2023) described this as the risk intelligence deficit: an organisational condition in which the formal governance apparatus produces comfort rather than clarity.\u003c/p\u003e\n\u003cp\u003eThere are two credible responses to this deficit in the current literature, and they are not mutually exclusive. The first is cultural and leadership-based: organisations must create environments in which uncomfortable information travels upward rather than being smoothed away before it reaches the boardroom. Weick and Sutcliffe (2021) argued that high-reliability organisations achieve this not through structural mandate alone but through leadership cultures that actively reward the escalation of uncertainty treating surprise as signal rather than failure. Sull and Sull (2023) extended this argument into strategy execution research, demonstrating that organisations where middle managers feel safe to report bad news to senior leadership consistently outperform those where the opposite culture prevails. The implications for risk governance are direct.\u003c/p\u003e\n\u003cp\u003eThe second response is technological. Gartner (2024) projected that AI-enabled continuous risk monitoring, real-time integration of operational data, external signals, and anomaly detection would become a primary differentiator of risk management quality over the coming decade, precisely because it bypasses the human filtering processes through which risk intelligence is diluted before reaching decision-makers. This projection is supported by the emerging practice evidence reviewed by Lam (2022) and corroborated by this study\u0026apos;s quantitative finding that technology integration is one of the strongest predictors of reduced risk incident frequency. The HUB International (2026) report similarly identified real-time monitoring adoption as a key characteristic of the small cohort of genuinely advanced-maturity organisations in their survey. What the governance and technology literatures together suggest is that the risk intelligence deficit is a solvable problem, but solving it requires simultaneous investment in cultural conditions that welcome unwelcome information and technological tools that surface it before it can be reclassified, diluted, or delayed. Neither alone is sufficient; together, they represent the most promising pathway from performative assurance to genuine resilience.\u003c/p\u003e"},{"header":"RESULTS AND DISCUSSION","content":"\u003ch2\u003e\u003cstrong\u003eSample Profile and Descriptive Overview\u003c/strong\u003e\u003c/h2\u003e\n\u003cp\u003eThe combined study sample comprised 240 participants: 26 individuals engaged in the qualitative phase and 214 in the quantitative survey phase. Qualitative participants were drawn from organisations headquartered or operating across Johannesburg, Pretoria, Cape Town, Durban, and Port Elizabeth, representing six sectors: financial services (31%), mining and resources (15%), insurance (19%), healthcare (12%), retail (12%), and public administration (11%). The quantitative sample mirrored this cross-sectoral distribution. Of the 214 survey respondents, 68% represented large organisations with more than 500 employees, 22% represented medium-sized enterprises, and 10% represented smaller organisations. Senior risk and governance professionals including Chief Risk Officers (CROs), Chief Financial Officers (CFOs), and board-level non-executive directors constituted 61% of the quantitative sample, lending high practitioner authority to the findings. Descriptive statistics generated using IBM SPSS Statistics Version 29 (IBM Corp., 2023) confirmed that the sample was adequately diverse across sector, organisational size, and ERM framework adoption status to support meaningful inferential analysis.\u003c/p\u003e\n\u003cp\u003e\u003cem\u003eTable 1\u003c/em\u003e\u003c/p\u003e\n\u003cp\u003e\u003cem\u003eSample Characteristics by Sector and Organisational Size (N = 214)\u003c/em\u003e\u003c/p\u003e\n\u003ctable border=\"1\" cellspacing=\"0\" cellpadding=\"0\" width=\"624\"\u003e\n \u003ctbody\u003e\n \u003ctr\u003e\n \u003ctd style=\"width: 156px;\"\u003e\n \u003cp\u003e\u003cstrong\u003eSector\u003c/strong\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd style=\"width: 156px;\"\u003e\n \u003cp\u003e\u003cstrong\u003en\u003c/strong\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd style=\"width: 156px;\"\u003e\n \u003cp\u003e\u003cstrong\u003e%\u003c/strong\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd style=\"width: 156px;\"\u003e\n \u003cp\u003e\u003cstrong\u003eMean Maturity Score\u003c/strong\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003c/tr\u003e\n \u003ctr\u003e\n \u003ctd style=\"width: 156px;\"\u003e\n \u003cp\u003eFinancial Services\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd style=\"width: 156px;\"\u003e\n \u003cp\u003e66\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd style=\"width: 156px;\"\u003e\n \u003cp\u003e30.8%\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd style=\"width: 156px;\"\u003e\n \u003cp\u003e3.62\u003c/p\u003e\n \u003c/td\u003e\n \u003c/tr\u003e\n \u003ctr\u003e\n \u003ctd style=\"width: 156px;\"\u003e\n \u003cp\u003eInsurance\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd style=\"width: 156px;\"\u003e\n \u003cp\u003e41\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd style=\"width: 156px;\"\u003e\n \u003cp\u003e19.2%\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd style=\"width: 156px;\"\u003e\n \u003cp\u003e3.71\u003c/p\u003e\n \u003c/td\u003e\n \u003c/tr\u003e\n \u003ctr\u003e\n \u003ctd style=\"width: 156px;\"\u003e\n \u003cp\u003eMining \u0026amp; Resources\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd style=\"width: 156px;\"\u003e\n \u003cp\u003e32\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd style=\"width: 156px;\"\u003e\n \u003cp\u003e15.0%\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd style=\"width: 156px;\"\u003e\n \u003cp\u003e3.44\u003c/p\u003e\n \u003c/td\u003e\n \u003c/tr\u003e\n \u003ctr\u003e\n \u003ctd style=\"width: 156px;\"\u003e\n \u003cp\u003eHealthcare\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd style=\"width: 156px;\"\u003e\n \u003cp\u003e26\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd style=\"width: 156px;\"\u003e\n \u003cp\u003e12.1%\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd style=\"width: 156px;\"\u003e\n \u003cp\u003e3.28\u003c/p\u003e\n \u003c/td\u003e\n \u003c/tr\u003e\n \u003ctr\u003e\n \u003ctd style=\"width: 156px;\"\u003e\n \u003cp\u003eRetail\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd style=\"width: 156px;\"\u003e\n \u003cp\u003e26\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd style=\"width: 156px;\"\u003e\n \u003cp\u003e12.1%\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd style=\"width: 156px;\"\u003e\n \u003cp\u003e3.19\u003c/p\u003e\n \u003c/td\u003e\n \u003c/tr\u003e\n \u003ctr\u003e\n \u003ctd style=\"width: 156px;\"\u003e\n \u003cp\u003ePublic Administration\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd style=\"width: 156px;\"\u003e\n \u003cp\u003e23\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd style=\"width: 156px;\"\u003e\n \u003cp\u003e10.7%\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd style=\"width: 156px;\"\u003e\n \u003cp\u003e2.91\u003c/p\u003e\n \u003c/td\u003e\n \u003c/tr\u003e\n \u003c/tbody\u003e\n\u003c/table\u003e\n\u003cp\u003e\u003cstrong\u003e\u003cem\u003eNote.\u0026nbsp;\u003c/em\u003e\u003c/strong\u003eSelf-assessed risk maturity scores are based on a five-point Likert scale. Higher scores indicate greater perceived maturity.\u003c/p\u003e\n\u003ch2\u003e\u003cstrong\u003eRisk Maturity Overconfidence: Quantitative Findings\u003c/strong\u003e\u003c/h2\u003e\n\u003cp\u003eThe central quantitative finding of this study confirms and extends the maturity gap hypothesis advanced in the introduction and substantiated in the theoretical literature. Pearson correlation analysis revealed a statistically significant negative relationship between self-assessed risk maturity scores and actual risk incident rates (r = \u0026minus;.18, p = .008), indicating that organisations rating themselves more highly on risk capability did not, in practice, experience fewer risk events. More strikingly, multiple linear regression analysis with risk incident frequency as the dependent variable and self-assessed maturity, governance quality, ERM framework adoption, and technology integration as predictors produced an overall model that was statistically significant (F(4, 209) = 11.43, p \u0026lt; .001, R\u0026sup2; = .18). However, self-assessed maturity was not a significant predictor of reduced incidents (\u0026beta; = .09, p = .21), while governance quality (\u0026beta; = \u0026minus;.34, p \u0026lt; .001) and technology integration (\u0026beta; = \u0026minus;.27, p = .003) emerged as the strongest protective factors. These findings directly validate the concern raised by Beasley et al. (2021) that process maturity, the presence of documented frameworks, is a poor proxy for program maturity, defined as the demonstrable reduction of harmful outcomes.\u003c/p\u003e\n\u003cp\u003eOne-way ANOVA further revealed significant differences in the maturity gap across sectors (F(5, 208) = 6.82, p \u0026lt; .001). Post-hoc Tukey HSD analysis identified public administration organisations as exhibiting the largest divergence between self-assessed maturity (M = 2.91, SD = 0.63) and incident frequency rates, followed by the retail sector (M = 3.19, SD = 0.71). Financial services and insurance organisations demonstrated comparatively tighter alignment between perceived maturity and outcome metrics, likely reflecting the more robust regulatory oversight imposed by frameworks such as the Financial Sector Conduct Authority (FSCA) requirements and the Prudential Authority\u0026apos;s directives in South Africa. Confirmatory factor analysis conducted in R Version 4.3.2 (R Core Team, 2023) using the lavaan package validated the six-factor structure of the governance readiness scale (CFI = 0.96, RMSEA = 0.048, SRMR = 0.061), confirming acceptable model fit and supporting the structural validity of the measurement instrument.\u003c/p\u003e\n\u003cp\u003e\u003cem\u003eTable 2\u003c/em\u003e\u003c/p\u003e\n\u003cp\u003e\u003cem\u003eMultiple Linear Regression: Predictors of Risk Incident Frequency (N = 214)\u003c/em\u003e\u003c/p\u003e\n\u003ctable border=\"1\" cellspacing=\"0\" cellpadding=\"0\" width=\"624\"\u003e\n \u003ctbody\u003e\n \u003ctr\u003e\n \u003ctd valign=\"top\" style=\"width: 187px;\"\u003e\n \u003cp\u003e\u003cstrong\u003ePredictor\u003c/strong\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd valign=\"top\" style=\"width: 109px;\"\u003e\n \u003cp\u003e\u003cstrong\u003e\u0026beta;\u003c/strong\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd valign=\"top\" style=\"width: 109px;\"\u003e\n \u003cp\u003e\u003cstrong\u003eSE\u003c/strong\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd valign=\"top\" style=\"width: 109px;\"\u003e\n \u003cp\u003e\u003cstrong\u003et\u003c/strong\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd valign=\"top\" style=\"width: 109px;\"\u003e\n \u003cp\u003e\u003cstrong\u003ep\u003c/strong\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003c/tr\u003e\n \u003ctr\u003e\n \u003ctd valign=\"top\" style=\"width: 187px;\"\u003e\n \u003cp\u003eSelf-Assessed Maturity\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd valign=\"top\" style=\"width: 109px;\"\u003e\n \u003cp\u003e.09\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd valign=\"top\" style=\"width: 109px;\"\u003e\n \u003cp\u003e.07\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd valign=\"top\" style=\"width: 109px;\"\u003e\n \u003cp\u003e1.26\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd valign=\"top\" style=\"width: 109px;\"\u003e\n \u003cp\u003e.21\u003c/p\u003e\n \u003c/td\u003e\n \u003c/tr\u003e\n \u003ctr\u003e\n \u003ctd valign=\"top\" style=\"width: 187px;\"\u003e\n \u003cp\u003eGovernance Quality\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd valign=\"top\" style=\"width: 109px;\"\u003e\n \u003cp\u003e-.34\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd valign=\"top\" style=\"width: 109px;\"\u003e\n \u003cp\u003e.06\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd valign=\"top\" style=\"width: 109px;\"\u003e\n \u003cp\u003e-5.67\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd valign=\"top\" style=\"width: 109px;\"\u003e\n \u003cp\u003e\u0026lt; .001\u003c/p\u003e\n \u003c/td\u003e\n \u003c/tr\u003e\n \u003ctr\u003e\n \u003ctd valign=\"top\" style=\"width: 187px;\"\u003e\n \u003cp\u003eTechnology Integration\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd valign=\"top\" style=\"width: 109px;\"\u003e\n \u003cp\u003e-.27\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd valign=\"top\" style=\"width: 109px;\"\u003e\n \u003cp\u003e.08\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd valign=\"top\" style=\"width: 109px;\"\u003e\n \u003cp\u003e-3.38\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd valign=\"top\" style=\"width: 109px;\"\u003e\n \u003cp\u003e.003\u003c/p\u003e\n \u003c/td\u003e\n \u003c/tr\u003e\n \u003ctr\u003e\n \u003ctd valign=\"top\" style=\"width: 187px;\"\u003e\n \u003cp\u003eERM Framework Adoption\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd valign=\"top\" style=\"width: 109px;\"\u003e\n \u003cp\u003e-.11\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd valign=\"top\" style=\"width: 109px;\"\u003e\n \u003cp\u003e.09\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd valign=\"top\" style=\"width: 109px;\"\u003e\n \u003cp\u003e-1.22\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd valign=\"top\" style=\"width: 109px;\"\u003e\n \u003cp\u003e.22\u003c/p\u003e\n \u003c/td\u003e\n \u003c/tr\u003e\n \u003c/tbody\u003e\n\u003c/table\u003e\n\u003cp\u003e\u003cstrong\u003e\u003cem\u003eNote.\u0026nbsp;\u003c/em\u003e\u003c/strong\u003eR\u0026sup2; = .18, F(4, 209) = 11.43, p \u0026lt; .001. \u0026beta; = standardised regression coefficient; SE = standard error.\u003c/p\u003e\n\u003ch2\u003e\u003cstrong\u003eQualitative Findings: Mechanisms Sustaining the Maturity Gap\u003c/strong\u003e\u003c/h2\u003e\n\u003cp\u003eThematic analysis of the 26 qualitative interviews, conducted using NVivo 15 (QSR International, 2023), yielded four overarching themes aligned with the four literature review subtopics: (1) the institutionalisation of cognitive bias in risk reporting; (2) the performative function of ERM frameworks; (3) the activity-outcome metric disconnect; and (4) governance and leadership deficits in risk intelligence. These themes are discussed in sequence below.\u003c/p\u003e\n\u003ch2\u003e\u003cstrong\u003eThe Institutionalisation of Cognitive Bias\u003c/strong\u003e\u003c/h2\u003e\n\u003cp\u003eThe most pervasive theme emerging from interviews was the systematic embedding of overconfidence bias within organisational reporting structures. Participants across all sectors described risk committees and board presentations as environments where risk scores were routinely inflated to avoid executive discomfort, a dynamic consistent with the institutionalisation of optimism bias theorised by Kahneman et al. (2021). A CRO in the financial services sector described an environment in which red-rated risks were regularly reclassified to amber before board reporting, not because mitigating actions had been implemented, but because red ratings attracted uncomfortable scrutiny. This phenomenon, which Weick and Sutcliffe (2021) term the normalisation of deviance, was identified across all six sectors in the sample, though it was most pronounced in public administration and retail sectors that also exhibited the largest statistical maturity gaps. These findings align with the behavioural risk literature reviewed by Mikes and Kaplan (2023), who contend that governance structures designed for accountability can paradoxically become mechanisms for the concealment of risk exposure.\u003c/p\u003e\n\u003ch2\u003e\u003cstrong\u003ePerformative Risk Management and Framework Limitations\u003c/strong\u003e\u003c/h2\u003e\n\u003cp\u003eA second dominant theme concerned the performative function of ERM frameworks such as COSO and ISO 31000. Participants frequently distinguished between what one internal audit executive described as \u0026quot;the theatre of risk management\u0026quot; and genuine organisational risk reduction. The qualitative data suggest that framework compliance, including the completion of risk registers, the documentation of heat maps, and the conduct of periodic assessments, generates institutional legitimacy without proportionally reducing actual exposure. This observation resonates with Power\u0026apos;s (2022) sociological critique of the \u0026quot;risk management of everything,\u0026quot; in which the proliferation of risk management activity serves primarily to demonstrate accountability rather than to reduce harm. Participants noted that the COSO framework (COSO, 2023), while comprehensive in its prescriptions, provides insufficient guidance on the distinction between documented compliance and demonstrated resilience a gap that this study\u0026apos;s quantitative findings confirm, given that ERM framework adoption was not a statistically significant predictor of reduced incident frequency (\u0026beta; = \u0026minus;.11, p = .22).\u003c/p\u003e\n\u003ch2\u003e\u003cstrong\u003eThe Activity-Outcome Metric Disconnect\u003c/strong\u003e\u003c/h2\u003e\n\u003cp\u003eParticipants across all sectors consistently articulated a disconnect between the metrics used to evaluate risk management performance and the outcomes those metrics were intended to reflect. Maturity assessments overwhelmingly focused on input indicators the number of risk assessments completed, the frequency of committee meetings, and the coverage of policy documentation, rather than on output metrics such as incident reduction rates, recovery times, or financial loss containment. This finding is consistent with the critique advanced by Lam (2022) and empirically supported by Protiviti and RIMS (2024), who found that over half of surveyed organisations conflate activity volume with risk effectiveness. The IRMSA (2025) South Africa Risk Report similarly notes that South African organisations remain disproportionately focused on compliance-based risk activity, a trend this study confirms across the sample. Participants from the insurance and financial services sectors, whose outcomes showed tighter maturity-incident alignment in the quantitative data, were notably more likely to reference output-focused KPIs such as claims frequency, near-miss reporting rates, and post-incident recovery benchmarks as primary governance instruments.\u003c/p\u003e\n\u003ch2\u003e\u003cstrong\u003eGovernance and Leadership Deficits in Risk Intelligence\u003c/strong\u003e\u003c/h2\u003e\n\u003cp\u003eThe fourth theme concerned the quality of risk intelligence reaching executive and board-level decision-makers. Consistent with findings reported by the National Association of Corporate Directors (NACD, 2025) that nearly one-third of directors are most concerned about risks they have not yet imagined, interview participants described board risk oversight as reactive, backward-looking, and heavily mediated by management filters that prioritise reassurance over accuracy. Deloitte\u0026apos;s (2024) finding that executives receive extensive risk data while lacking confidence in their ability to act on it was directly echoed by non-executive directors in this sample, who described risk reports as voluminous but insufficiently actionable. Participants highlighted the role of AI-enabled continuous monitoring tools, deployed in several financial services and insurance organisations, as a meaningful disruptor of this dynamic providing real-time risk signals that reduced dependence on periodic, curated reporting. This finding supports Gartner\u0026apos;s (2024) projection that technology integration will become a primary differentiator of genuine risk maturity, a conclusion reinforced by the significant negative regression coefficient for technology integration in the quantitative model (\u0026beta; = \u0026minus;.27, p = .003).\u003c/p\u003e\n\u003ch2\u003e\u003cstrong\u003eIntegrated Discussion and Theoretical Implications\u003c/strong\u003e\u003c/h2\u003e\n\u003cp\u003eTaken together, the qualitative and quantitative findings of this study provide robust, triangulated evidence for the existence and structural persistence of the risk maturity gap in South African enterprise contexts. The quantitative finding that self-assessed maturity does not significantly predict reduced risk incidents, while governance quality and technology integration do, situates the maturity gap firmly in the realm of governance architecture and capability deployment rather than framework adoption per se. This is a theoretically significant distinction. It suggests that the problem identified by Beasley et al. (2021) that organisations possessing formal ERM structures continue to faiL is not attributable to an absence of frameworks but to the conditions under which those frameworks are embedded, operationalised, and reported upon.\u003c/p\u003e\n\u003cp\u003eThe qualitative evidence of pervasive cognitive bias institutionalisation corroborates and extends Kahneman et al.\u0026apos;s (2021) individual-level theory of overconfidence into the organisational domain, demonstrating that reporting norms, governance structures, and leadership dynamics aggregate individual biases into durable collective overconfidence. This institutional amplification mechanism, which has remained undertheorised in the ERM literature, is a central theoretical contribution of this research. Furthermore, the finding that technology integration, specifically AI-enabled continuous monitoring functions as a structural disruptor of performative risk management, offers a practically actionable pathway for organisations seeking to transition from activity-based assurance to outcome-based resilience, as envisioned by Lam (2022) and validated empirically by this study\u0026apos;s regression results.\u003c/p\u003e\n\u003cp\u003eThe South African context adds a further layer of complexity. The polycrisis conditions documented by the World Economic Forum (2025) \u0026mdash; encompassing economic volatility, load-shedding infrastructure disruptions, and heightened third-party vendor risk \u0026mdash; create an environment in which the costs of performative risk management are acutely tangible. Verizon\u0026apos;s (2025) identification of vendor-related breaches as among the fastest-growing risk categories is borne out in this sample, with 71% of survey respondents reporting at least one significant third-party incident in the preceding 24 months. These findings collectively underscore the urgency of transitioning South African risk governance from compliance performance toward genuine adaptive resilience, informed by real-time intelligence and outcome-focused accountability structures.\u003c/p\u003e"},{"header":"CONCLUSION","content":"\u003cp\u003eThis study set out to investigate why organisations continue to experience recurrent risk events despite having established ERM frameworks, and to identify the structural and behavioural mechanisms that sustain the gap between perceived risk maturity and actual risk reduction outcomes. The evidence gathered is unambiguous on the central argument: the risk maturity gap is not produced by an absence of risk management activity, but by a fundamental disconnect between process execution and meaningful harm reduction. Self-assessed maturity scores did not significantly predict reduced incident frequency, while governance quality and technology integration did, confirming that possessing a framework and genuinely embedding adaptive risk capability are two very different things. The study further demonstrated that cognitive biases, particularly overconfidence and the normalisation of deviance, are institutionalised through reporting structures and board-level governance norms in ways that make collective overconfidence self-reinforcing and durable. Organisations that measure their risk management effectiveness primarily through input metrics, such as assessments completed, policies documented, are, in effect, measuring their own reassurance rather than their resilience.\u003c/p\u003e\n\u003cp\u003eThe study carries important limitations. The South African research context, while rich and representative of a middle-income economy navigating ERM maturation, limits direct generalisation to jurisdictions with substantially different regulatory histories or risk cultures. Cross-sectional data collection precludes causal inference, and self-report instruments on governance failures remain susceptible to social desirability bias despite anonymous collection. The sample, while senior-heavy and cross-sectoral, did not include external auditors or regulators, whose perspectives would add a valuable independent layer to the findings.\u003c/p\u003e\n\u003cp\u003eSeveral recommendations follow from these findings. Organisations should urgently reorient their risk maturity assessments toward output metrics, incident frequency, recovery time, and loss containment, and treat self-assessed capability scores with appropriate scepticism unless validated against outcome data. Boards must demand risk intelligence that is actionable and forward-looking, not merely voluminous. Investment in AI-enabled continuous monitoring should be prioritised as a structural disruptor of performative risk governance. Future research should pursue longitudinal designs to assess whether governance quality improvements demonstrably reduce incident rates over time, and cross-national studies to examine how different regulatory environments shape the maturity gap\u0026apos;s persistence. The gap between confidence and capability is not inevitable, but closing it requires organisations to measure what actually matters.\u003c/p\u003e"},{"header":"REFERENCES","content":"\u003col\u003e\n\u003cli\u003eAven, T. (2021). Risky business or risky society? On the use of risk science to understand and govern societal risks. Risk Analysis, 41(3), 439\u0026ndash;452. https://doi.org/10.1111/risa.13555\u003c/li\u003e\n\u003cli\u003eBeasley, M. S., Branson, B. C., \u0026amp; Pagach, D. (2021). An analysis of the maturity and strategic impact of investments in enterprise risk management. Journal of Accounting and Public Policy, 40(2), Article 106847. https://doi.org/10.1016/j.jaccpubpol.2021.106847\u003c/li\u003e\n\u003cli\u003eBraun, V., \u0026amp; Clarke, V. (2022). Thematic analysis: A practical guide. SAGE Publications.\u003c/li\u003e\n\u003cli\u003eBryman, A. (2022). Social research methods (6th ed.). Oxford University Press.\u003c/li\u003e\n\u003cli\u003eCommittee of Sponsoring Organizations of the Treadway Commission (COSO). (2023). Strengthening enterprise risk management for strategic advantage. COSO.\u003c/li\u003e\n\u003cli\u003eCreswell, J. W., \u0026amp; Creswell, J. D. (2023). Research design: Qualitative, quantitative, and mixed methods approaches (6th ed.). SAGE Publications.\u003c/li\u003e\n\u003cli\u003eCreswell, J. W., \u0026amp; Poth, C. N. (2024). Qualitative inquiry and research design: Choosing among five approaches (5th ed.). SAGE Publications.\u003c/li\u003e\n\u003cli\u003eDeloitte. (2024). Global risk management survey: Navigating uncertainty in a complex world (13th ed.). Deloitte Insights. https://www2.deloitte.com/global/en/pages/financial-services/articles/global-risk-management-survey.html\u003c/li\u003e\n\u003cli\u003eFlick, U. (2022). An introduction to qualitative research (7th ed.). SAGE Publications.\u003c/li\u003e\n\u003cli\u003eGartner. (2024). Top risk management trends: Building resilient organizations in 2024 and beyond. Gartner Research.\u003c/li\u003e\n\u003cli\u003eHopkin, P. (2022). \u003cem\u003eFundamentals of risk management: Understanding, evaluating and implementing effective risk management\u003c/em\u003e (6th ed.). Kogan Page.\u003c/li\u003e\n\u003cli\u003eHUB International. (2026). \u003cem\u003e2026 HUB North American outlook report: Risk and talent strategies for a resilient future\u003c/em\u003e. HUB International Limited.\u003c/li\u003e\n\u003cli\u003eIBM Corp. (2023). IBM SPSS Statistics for Windows, Version 29.0. IBM Corp.\u003c/li\u003e\n\u003cli\u003eInstitute of Risk Management South Africa (IRMSA). (2025). South Africa risk report 2025. IRMSA. https://www.irmsa.org.za\u003c/li\u003e\n\u003cli\u003eKahneman, D., Sibony, O., \u0026amp; Sunstein, C. R. (2021). Noise: A flaw in human judgment. Little, Brown Spark.\u003c/li\u003e\n\u003cli\u003eLam, J. (2022). Transforming enterprise risk management: From compliance to competitive advantage. Wiley.\u003c/li\u003e\n\u003cli\u003eMcKinsey \u0026amp; Company. (2023). \u003cem\u003eRisk and resilience: Closing the gap between intent and execution\u003c/em\u003e. McKinsey Global Institute. https://www.mckinsey.com/capabilities/risk-and-resilience\u003c/li\u003e\n\u003cli\u003eMikes, A., \u0026amp; Kaplan, R. S. (2023). Managing risks: A new framework revisited. Harvard Business Review, 101(2), 48\u0026ndash;60.\u003c/li\u003e\n\u003cli\u003eNational Association of Corporate Directors (NACD). (2025). 2025 NACD director survey: Board oversight in an era of complexity. NACD. https://www.nacdonline.org\u003c/li\u003e\n\u003cli\u003ePallant, J. (2024). SPSS survival manual: A step-by-step guide to data analysis using IBM SPSS (8th ed.). McGraw-Hill.\u003c/li\u003e\n\u003cli\u003ePodsakoff, P. M., MacKenzie, S. B., \u0026amp; Podsakoff, N. P. (2024). Common method biases in behavioral research: A critical review and future directions. Journal of Applied Psychology, 108(4), 542\u0026ndash;568. https://doi.org/10.1037/apl0000533\u003c/li\u003e\n\u003cli\u003ePower, M. (2022). The risk management of everything: Rethinking the politics of uncertainty (2nd ed.). Demos.\u003c/li\u003e\n\u003cli\u003ePricewaterhouseCoopers (PwC). (2024). Global risk survey 2024: Building trust in an age of disruption. PricewaterhouseCoopers International Limited. https://www.pwc.com/global-risk-survey\u003c/li\u003e\n\u003cli\u003eProtiviti \u0026amp; Risk and Insurance Management Society (RIMS). (2024). Executive perspectives on top risks 2024: Navigating third-party and strategic uncertainty. Protiviti Inc. https://www.protiviti.com/top-risks\u003c/li\u003e\n\u003cli\u003eQSR International. (2023). NVivo (Version 15) [Computer software]. QSR International Pty Ltd. https://www.qsrinternational.com\u003c/li\u003e\n\u003cli\u003eR Core Team. (2023). R: A language and environment for statistical computing (Version 4.3.2). R Foundation for Statistical Computing. https://www.R-project.org\u003c/li\u003e\n\u003cli\u003eRepublic of South Africa. (2013). Protection of Personal Information Act 4 of 2013. Government Gazette. https://www.gov.za/documents/protection-personal-information-act\u003c/li\u003e\n\u003cli\u003eSaunders, M. N. K., Lewis, P., \u0026amp; Thornhill, A. (2023). Research methods for business students (9th ed.). Pearson Education.\u003c/li\u003e\n\u003cli\u003eSull, D., \u0026amp; Sull, C. (2023). Why strategy execution unravels\u0026mdash;and what to do about it: Lessons for risk-integrated management. \u003cem\u003eMIT Sloan Management Review, 64\u003c/em\u003e(1), 22\u0026ndash;31.\u003c/li\u003e\n\u003cli\u003eTaleb, N. N. (2020). Statistical consequences of fat tails: Real world preasymptotics, epistemology, and applications. STEM Academic Press.\u003c/li\u003e\n\u003cli\u003eTashakkori, A., Johnson, R. B., \u0026amp; Teddlie, C. (2021). Foundations of mixed methods research: Integrating quantitative and qualitative approaches in the social and behavioral sciences (2nd ed.). SAGE Publications.\u003c/li\u003e\n\u003cli\u003eVerizon. (2025). 2025 Data breach investigations report. Verizon Business. https://www.verizon.com/business/resources/reports/dbir/\u003c/li\u003e\n\u003cli\u003eVerizon. (2025). 2025 data breach investigations report. Verizon Business. https://www.verizon.com/business/resources/reports/dbir/\u003c/li\u003e\n\u003cli\u003eWeick, K. E., \u0026amp; Sutcliffe, K. M. (2021). Managing the unexpected: Sustained performance in a complex world (4th ed.). Wiley.\u003c/li\u003e\n\u003cli\u003eWeick, K. E., \u0026amp; Sutcliffe, K. M. (2021). \u003cem\u003eManaging the unexpected: Sustained performance in a complex world\u003c/em\u003e (4th ed.). Wiley.\u003c/li\u003e\n\u003cli\u003eWorld Economic Forum. (2024). \u003cem\u003eResilience frameworks and organizational adaptation: Bridging strategy and risk practice\u003c/em\u003e. World Economic Forum Insight Report. https://www.weforum.org\u003c/li\u003e\n\u003cli\u003eWorld Economic Forum. (2025). The global risks report 2025 (20th ed.). World Economic Forum. https://www.weforum.org/reports/global-risks-report-2025\u003c/li\u003e\n\u003c/ol\u003e"}],"fulltextSource":"","fullText":"","funders":[],"hasAdminPriorityOnWorkflow":false,"hasManuscriptDocX":true,"hasOptedInToPreprint":true,"hasPassedJournalQc":"","hasAnyPriority":true,"hideJournal":true,"highlight":"","institution":"","isAcceptedByJournal":false,"isAuthorSuppliedPdf":false,"isDeskRejected":"","isHiddenFromSearch":false,"isInQc":false,"isInWorkflow":false,"isPdf":false,"isPdfUpToDate":true,"isWithdrawnOrRetracted":false,"journal":{"display":true,"email":"
[email protected]","identity":"researchsquare","isNatureJournal":false,"hasQc":true,"allowDirectSubmit":true,"externalIdentity":"","sideBox":"","snPcode":"","submissionUrl":"/submission","title":"Research Square","twitterHandle":"researchsquare","acdcEnabled":true,"dfaEnabled":false,"editorialSystem":"","reportingPortfolio":"","inReviewEnabled":false,"inReviewRevisionsEnabled":true},"keywords":"risk maturity gap, enterprise risk management, organisational overconfidence, governance quality, performative risk management, resilience, cognitive bias, risk intelligence, South Africa","lastPublishedDoi":"10.21203/rs.3.rs-9032336/v1","lastPublishedDoiUrl":"https://doi.org/10.21203/rs.3.rs-9032336/v1","license":{"name":"CC BY 4.0","url":"https://creativecommons.org/licenses/by/4.0/"},"manuscriptAbstract":"This study investigated the structural, behavioural, and cultural mechanisms that sustain the gap between perceived risk management maturity and actual risk reduction outcomes in South African enterprise contexts, a phenomenon termed the maturity gap. Employing an exploratory sequential mixed-methods design grounded in critical realism, the study conducted 26 semi-structured in-depth interviews and administered a structured survey to 214 risk and governance professionals across financial services, insurance, mining, healthcare, retail, and public administration sectors. Quantitative analysis using multiple linear regression confirmed that self-assessed risk maturity was not a significant predictor of reduced incident frequency (β = .09, p = .21), while governance quality (β = −.34, p \u003c .001) and technology integration (β = −.27, p = .003) emerged as the strongest protective factors. ERM framework adoption status similarly failed to predict incident reduction (β = −.11, p = .22). Thematic analysis identified four mechanisms sustaining the maturity gap.","manuscriptTitle":"The Risk Maturity Gap: Examining the Disconnect Between Organizational Confidence and Effective Risk Mitigation","msid":"","msnumber":"","nonDraftVersions":[{"code":1,"date":"2026-03-24 07:48:46","doi":"10.21203/rs.3.rs-9032336/v1","editorialEvents":[{"type":"communityComments","content":0}],"status":"published","journal":{"display":true,"email":"
[email protected]","identity":"researchsquare","isNatureJournal":false,"hasQc":true,"allowDirectSubmit":true,"externalIdentity":"","sideBox":"","snPcode":"","submissionUrl":"/submission","title":"Research Square","twitterHandle":"researchsquare","acdcEnabled":true,"dfaEnabled":false,"editorialSystem":"","reportingPortfolio":"","inReviewEnabled":false,"inReviewRevisionsEnabled":true}}],"origin":"","ownerIdentity":"71851c08-cef9-4fb3-92c9-a363ae172761","owner":[],"postedDate":"March 24th, 2026","published":true,"recentEditorialEvents":[],"rejectedJournal":{"display":false,"email":"
[email protected]","identity":"risk-management","isNatureJournal":false,"hasQc":true,"allowDirectSubmit":false,"externalIdentity":"rmgt","sideBox":"Learn more about [Risk Management](http://link.springer.com/journal/41283)","snPcode":"","submissionUrl":"https://www.editorialmanager.com/rmgt/default.aspx","title":"Risk Management","twitterHandle":"","acdcEnabled":true,"dfaEnabled":true,"editorialSystem":"em","reportingPortfolio":"Springer Hybrid","inReviewEnabled":false,"inReviewRevisionsEnabled":false},"revision":"","amendment":"","status":"posted","subjectAreas":[],"tags":[],"updatedAt":"2026-03-24T07:48:46+00:00","versionOfRecord":[],"versionCreatedAt":"2026-03-24 07:48:46","video":"","vorDoi":"","vorDoiUrl":"","workflowStages":[]},"version":"v1","identity":"rs-9032336","journalConfig":"researchsquare"},"__N_SSP":true},"page":"/article/[identity]/[[...version]]","query":{"redirect":"/article/rs-9032336","identity":"rs-9032336","version":["v1"]},"buildId":"XKTyCvWXoU3ODBz1xrDgd","isFallback":false,"isExperimentalCompile":false,"dynamicIds":[84888],"gssp":true,"scriptLoader":[]}
Text is read by the "Ask this paper" AI Q&A widget below.
Extraction quality varies by source — PMC NXML preserves structure
cleanly, OA-HTML may include some navigation residue, and OA-PDF can
have broken hyphenation. The publisher copy
(via DOI)
is the canonical version.