Skip to content
Sentinel Unity
Back to blog
Practitioner Guide

Everybody Is at Level 3

Run a maturity self-assessment across a large organisation and the results cluster in the middle with suspicious consistency. It is not that everyone is genuinely at the same level. It is that the middle is the safest place to stand. Here is what the levels are supposed to mean and why the jump to level 4 is the one that actually costs something.

Sentinel Unity GRC Team18 August 20268 min read
Maturity ModelCompliance OperationsAssessmentEvidence
Two colleagues in discussion at a table, one gesturing while explaining, a laptop showing a diagram beside them

The first maturity assessment across a big organisation always produces the same picture. Everything lands on 3.

A few brave teams put a 2 somewhere. Almost nobody claims a 5. The distribution is a spike in the middle, and if you plot it next to a genuine measurement of anything, it looks nothing like it.

This is not fraud and it is not laziness. Level 3 is simply the safest answer available to a person filling in a form about their own work.

Claim a 2 and you have volunteered a weakness that becomes an action item with your name on it. Claim a 4 and somebody will ask for the measurements, which you may not have. Level 3 sounds responsible, sounds honest, and invites the fewest follow-up questions. Of course everyone is at level 3.

What the levels are supposed to mean

The levels only work if they describe observable facts about a process rather than a feeling about how well it is going. The scale we use runs from 0 to 5, and each level has a written descriptor:

0, Not Performed. The practice does not happen. Worth having as an explicit level, because a blank in a spreadsheet is ambiguous in a way that a recorded zero is not. Somebody assessed this and the answer was nothing.

1, Performed Informally. It happens. It happens because a particular person knows to do it, and it would stop if that person left. No plan, no tracking, no consistency between one occurrence and the next.

2, Planned and Tracked. Somebody decided this should happen, resourced it, and monitors whether it does. Practice still varies between teams, because planning is not the same as standardising.

3, Well Defined. There is a defined standard process, and the organisation follows it. Two teams doing the same thing do it the same way, because they are working from the same definition rather than local habit.

4, Quantitatively Controlled. The process is measured against targets, and deviation is detected from the measurements rather than from someone noticing. This is the level where you can answer "is this working" with data instead of belief.

5, Continuously Improving. The measurements drive change to the process itself. Not more reporting on the same process: a different process, because the data said so.

Read those and the spike at 3 gets harder to defend. Level 3 requires a defined standard process that is genuinely applied across teams. In most organisations assessing themselves at 3, two teams doing the same task do it differently, and everybody knows it.

The wall between 3 and 4

Levels 1 to 3 are mostly about documentation and discipline. You can get there with effort, good writing, and a leadership team that keeps asking.

Level 4 is different in kind, and this is where maturity programmes stall.

Going from "we have a defined process" to "we measure the process against targets" means committing to numbers. It means someone has to define what good looks like as a figure, instrument the process to produce that figure, and then live with what the figure says, including in the months where it says something unwelcome.

That is why so many programmes sit at 3 for years. Not because people are not trying, but because the next step involves creating evidence that can embarrass you, and there is rarely a forcing function for that.

Worth being clear about something: level 3 is a perfectly respectable place to be for most controls. Not everything needs to be quantitatively controlled. The problem is not sitting at 3, it is claiming 3 while operating at 1, which happens more often than anyone would like.

Descriptors do more work than definitions

Here is the practical fix, and it is unglamorous.

If your assessment form asks "rate the maturity of access reviews from 1 to 5", you will get noise. Everyone brings their own idea of what a 4 means, and the scores from different business units cannot be compared even though they will be put in the same table.

If the form asks the assessor to pick between written descriptions of what each level looks like for that specific control, you get something much closer to a measurement.

Compare:

Level 3: Access reviews are performed on a defined schedule using a documented procedure, and the same procedure is used by every business unit.

Level 4: Review completion rates and exception counts are tracked against targets, and a unit falling behind is detected from those figures rather than reported by the unit itself.

Now the assessor is not rating a feeling. They are answering a question with a right answer, and if they claim 4 the next question is obvious: show me the figures.

This is why per-control level descriptors matter more than the scale itself. The scale is just labels. The descriptors are where the meaning lives.

Evidence, and the review step

Every maturity programme collects evidence, and most collect it in a way that quietly undermines the whole exercise.

Someone claims a level. Someone attaches a document. The claim is now considered supported, and the assessment moves on.

Nobody opened the document.

This is extremely common and produces a specific failure mode: assessments resting on the wrong attachment. The policy is out of date, or it is the right policy but does not actually cover the control in question, or it is a screenshot of a configuration screen from a system that has since been replaced. Nobody finds out until an external assessor opens the same file and asks a question that nobody in the room can answer.

The fix is procedural rather than technical. Evidence should pass an explicit review step, performed by somebody other than the person who uploaded it, before the assessment treats it as supporting anything. It slows the process down. It also means the number at the end is worth something.

What maturity does not tell you

Two limits worth stating, because maturity scores get over-read constantly.

Maturity is not effectiveness. A control can be well defined, consistently applied, and thoroughly measured while doing very little about the risk it was meant to address. You have matured the operation of the control, not its usefulness. A quarterly access review executed flawlessly against the wrong system is a mature control and a pointless one.

A high average hides the thing that will hurt you. An average maturity of 3.4 across a domain is a comfortable number that can conceal a single control sitting at 0 in the place where you are most exposed. The distribution matters far more than the mean, and the lowest score is usually the most interesting number on the page.

Report both. If you only have room for one, report the low scores.

What this looks like in Sentinel Unity

  • Six levels, 0 to 5, each with a written descriptor rather than a bare number, so a score means the same thing in two different business units.
  • Descriptors are held per control, which is what makes an assessment answer a question instead of collecting an opinion.
  • Evidence requirements are defined at control level, so the assessor knows what would count before they go looking.
  • Evidence passes a review step rather than being accepted on upload.
  • Gaps raise findings with severity, an owner, and a remediation plan that can depend on other plans, so the sequence of work is part of the record.
  • The same score carries across frameworks where controls are mapped, so maturity is assessed once rather than re-argued per standard.

Where to start

Do not run a full assessment. Take one domain, and do this instead.

Pick five controls. For each one, write the level 3 and level 4 descriptors yourself, in plain sentences, specific to that control. Then ask two people in different teams to score it.

Where they agree, your descriptor is doing its job. Where they disagree by two levels, you have found something better than a maturity score: you have found a control that two parts of your organisation understand completely differently.

That disagreement was there before the assessment. The assessment just made it visible, which is the only thing a maturity model is really for.


Sentinel Unity scores every control on a 0 to 5 scale with descriptors held per control, and puts evidence through an explicit review step. Request a demo, or read more about compliance management.

See the platform on your frameworks

Request a walkthrough with our team, tailored to your entity structure and regulatory scope.

Request a demo