You prepared for the audit committee meeting the way you always do, with current scores, a clean register, and a clear narrative about how the cycle ran. Your enterprise risk management program was running on schedule. The meeting went sideways anyway. The questions weren’t about whether you had a process. They were about the reasoning behind specific scores: why this risk sits where it does, how it compares to last quarter, whether the methodology is consistent across business units. You had answers, but not the kind that fully satisfied the room. The Meeting That Changed the Standard For most of the last decade, the primary goal of enterprise risk management reporting was demonstrating that a process existed. Audit committees wanted assurance that someone was watching, and a documented process covering the register, scores, and assessment cycle ran on schedule and provided it. The question being asked was simple: do you have a program? That standard shifted for two reasons: High-profile failures at organizations with documented ERM programs raised pointed questions about whether process maturity translated to actual risk awareness. Regulatory expectations around enterprise resilience pushed boards to get more specific about what they were signing off on and what board risk management oversight actually required. Audit committees now ask a second layer of questions, and that layer is about reasoning, not existence. Why “We Ran the Assessments” Is No Longer Enough The shift shows up clearly in the kind of ERM reporting questions risk leaders are fielding today. A decade ago, presenting the heat map was the deliverable. Now the heat map is the starting point. Audit committees want to trace the reasoning behind the scores. Why did this risk move? What drove the likelihood rating up? Are the business units applying the same criteria, or is each team effectively running its own program? Most ERM programs were built to answer the first generation of questions. The architecture, built on annual cycles, spreadsheet-based registers, and assessment templates circulated by email, was designed to demonstrate process maturity. According to a 2025 Baker Tilly and IIA Foundation report, nearly 60% of organizations still manage ERM primarily through spreadsheets and manual processes. That infrastructure made sense when the goal was documentation. It creates friction when the goal is ERM defensibility. The result is a risk leader who ran a clean process, produced current scores, and still couldn’t fully answer the room. That is the gap most programs have not yet closed. Documented vs. Defensible: What the Distinction Actually Means A documented risk assessment shows that scores were assigned. A defensible ERM framework shows why. The difference surfaces in any real audit committee conversation. A documented program can tell the room how many risks were assessed, which ones ranked highest, and where they sit on the heat map. A defensible ERM framework can explain how the likelihood scale was calibrated, why operational risk moved from a 3 to a 4 this quarter, and how the finance team and supply chain team are rating risks on the same basis. Defensibility requires traceability. If the reasoning behind a score lives in someone’s memory, or if each business unit quietly applies criteria differently, the score becomes difficult to stand behind under questioning. Audit committees can tell when a risk leader is reconstructing rationale on the spot. The loss of credibility in that moment is harder to recover from than the gap itself. Programs were built to meet the standard of their time. The standard changed faster than most program architectures could follow. Three Things Audit Committees Want to Trace Back Through Your Scores Understanding what audit committees are actually looking for makes it easier to close the gap. The scrutiny tends to cluster around three areas: Methodology consistency. Risks rated on the same scale, using the same criteria, across every business unit. Inconsistent methodology produces scores that cannot be compared and that inconsistency is exactly what surfaces in a risk management audit. Quarter-over-quarter reasoning. Effective risk management reporting captures the reasoning behind score changes, not just the scores themselves. A shift in underlying conditions, a reassessment of impact, a change in controls: the reasoning should be part of the record, captured at the time of assessment. Connection between scores and decisions. Audit committees increasingly want to see how risk ratings informed actual resource allocation, mitigation priorities, or strategic choices. Scores that exist in isolation from decision-making raise questions about whether the program is driving the organization or documenting it. What a Defensible Program Actually Requires The organizations moving past this friction share a few characteristics. Their ERM framework is documented and applied consistently. Scoring rationale is captured at the point of assessment. Risk data is structured to support comparison over time, quarter to quarter and cycle to cycle. That last point is structural. When risk data lives in spreadsheets, building an audit trail is largely manual work done after the fact. When it lives in a platform designed for ERM defensibility, the methodology, the rationale, and the history are part of the record by default. Origami Risk gives ERM leaders the infrastructure to run ERM reporting the way audit committees now expect to examine them. Configurable methodology frameworks, consistent scoring across business units, and a complete history of how scores have moved and why, all in one place. The goal is a risk leader who walks into the next meeting ready to answer what the scores are and how they got there. Ready to build a program that holds up in the room? Download Beyond the Score: What It Actually Takes to Run a Defensible ERM Program.