Organizations are faced with the fact that risk is everywhere, but governance, IT, and security still work in silos. Traditional frameworks such as NIST, COBIT, ISO, SABSA, COSO, ESRM and others help, but they were never designed to unify risk across the full operating model. That is where the Integrated Assurance Maturity Model (IAMM) comes in.
IAMM is more than a checklist. It is a way of embedding assurance directly into how organizations design, build, operate, and govern their systems. Instead of measuring maturity through policies or one-off assessments, IAMM defines progress in terms of execution, cultural adoption, and measurable outcomes.
IAMM spans six domains and measures against five levels of organizational maturity.

Leading up to the release on my book Integrated Assurance: Unified Risk Strategy on September 25th, I’ll explore each domain in depth. I’ll walk through the maturity levels, provide the guiding questions that organizations can use to measure progress, and share practical recommendations for adoption.
While IAMM does not claim to replace existing frameworks, it does connect them in a strategic and meaningful way. So where COBIT provides governance design, NIST describes risk tiers, and ISO sets global standards, IAMM turns those frameworks into operational reality.
If your organization is pursuing digital transformation, strengthening resilience, or simply looking to align IT and security with the business, Integrated Assurance: Unified Risk Strategy will give you a structured way to assess and improve.
