The technology audit
Find out what your technology is actually doing.
Most technology audits are security reviews wearing a bigger hat, or a two-hundred-row spreadsheet nobody opens twice. This one is built around the question a leadership team actually has: where is our time going, what is it costing us, and what should we do about AI?
Workflow, automation and AI governance are first-class domains here — not an appendix.
Security and compliance matter, and they are scored properly. But nobody hires a practice for a firewall review. The tier that earns its fee is the one measuring where the organisation's hours actually go, and whether the AI already running inside your vendors was ever a decision anyone made.
Eleven domains, three tiers.
The tiers are a narrative, and they are the order of the readout.
Foundation
Can this organisation be trusted with its data?
Table stakes. Nobody hires a practice for a firewall review, but nothing above this tier survives a failure in it.
A1
Governance & Operating Model
Who holds the decision rights, and is anyone accountable for them?
A2
Application Portfolio & Spend
What do they run, what does it cost, and what should go?
A3
Data & Integration
Where does the truth live, and how does it move?
A4
Security & Access
Who can get in, and what happens when someone should not?
A5
Privacy, Compliance & Accessibility
What did they promise the people in their data, and can everyone use what they build?
A6
Resilience & Continuity
What happens when it breaks, and how do they know it will work?
Leverage
Is this organisation getting compounding return?
Workflow, automation and AI governance — scored with the same rigour as security, because this is where the return lives.
B1
Workflow & Process
Where does the organisation's time actually go?
B2
Automation
What runs without a human, and who is looking after it?
B3
AI Use & Governance
What is AI doing here, who decided, and how would anyone know if it went wrong?
Capacity
Can they sustain any of it?
A roadmap nobody has the hands or skills to execute is a wish list.
C1
People & Capability
Who does this work, and can they do what the roadmap needs?
C2
Delivery & Engineering
If they build software, can they ship it safely?
Three rules that make it an audit.
Every score carries its evidence
Observed, because I saw the configuration. Demonstrated, because they showed me. Asserted, because they told me and I could not check. A domain scoring well on entirely asserted evidence is a finding in itself, and it gets reported as one.
Two axes, never one
Maturity alone gives you a flat scorecard and a four-hundred-item backlog. Maturity against criticality — weighted for your organisation, not a generic one — gives you a roadmap that falls out of the matrix.
Findings are priced
Severity, effort in person-weeks, named owner. An unpriced finding is an opinion. So is a recommendation your team has no capacity to act on, which is why capacity is scored too.
The maturity ladder
- 0Absent
- Does not exist.
- 1Ad hoc
- Happens, undocumented, dependent on one person remembering.
- 2Defined
- Written down. Followed inconsistently.
- 3Managed
- Consistently followed, owned by a named person, measured.
- 4Optimised
- Measured, improved on a cadence, automated where automation is correct.
Four weeks.
Scope
Domains agreed, criticality set per control for your organisation, artifacts requested, read-only access arranged. Without access the whole audit degrades to hearsay.
Discover
Portfolio sweep, spend pull, integration map. A self-assessment goes out widely, because the gap between what leadership believes and what staff report is itself data.
Evidence
Interviews with leadership, every system owner, and the people doing the work daily. Process walk-throughs where I sit and watch, because the description is always the happy path and the work never is.
Score
Maturity with evidence grades, TIME dispositions, the opportunity register, findings priced in person-weeks.
Deliver
Written report, live readout, and a 90-day plan with named owners. The 90-day plan is the product; the report is what justifies it.
What you get
- A one-page scorecard: eleven domains, maturity against criticality
- System inventory with TIME dispositions and total spend
- Integration and data-flow map
- Process portfolio with the toil number
- Automation and AI opportunity register, scored and routed
- AI governance assessment, with a starter policy if none exists
- Risk register — severity, effort, owner
- A 90-day plan and a twelve-month roadmap
- The scored dataset, so next year shows movement
Built on standards, not opinions
The framework is a synthesis, and it says where each piece came from. What these sources agree on matters more than where they differ.
- COBIT
- governance separated from management — someone owns the decision rights
- NIST CSF 2.0
- Govern as a sixth function; audits show risk governance, not point-in-time compliance
- CIS Controls v8.1
- an honest security floor calibrated to the size of the organisation
- Gartner TIME
- a disposition for every system — tolerate, invest, migrate, eliminate
- NIST AI RMF
- govern, map, measure, manage — the spine of the AI domain
- ISO/IEC 42001
- AI as a management system rather than a collection of experiments
- EU AI Act
- risk tiers that force the question: how bad if this is wrong?
- NTEN Tech Accelerate
- a yardstick calibrated to mission organisations, not enterprises