everydev.

The technology audit

Find out what your technology is actually doing.

Most technology audits are security reviews wearing a bigger hat, or a two-hundred-row spreadsheet nobody opens twice. This one is built around the question a leadership team actually has: where is our time going, what is it costing us, and what should we do about AI?

Workflow, automation and AI governance are first-class domains here — not an appendix.

Security and compliance matter, and they are scored properly. But nobody hires a practice for a firewall review. The tier that earns its fee is the one measuring where the organisation's hours actually go, and whether the AI already running inside your vendors was ever a decision anyone made.

Eleven domains, three tiers.

The tiers are a narrative, and they are the order of the readout.

Foundation

Can this organisation be trusted with its data?

Table stakes. Nobody hires a practice for a firewall review, but nothing above this tier survives a failure in it.

A1

Governance & Operating Model

Who holds the decision rights, and is anyone accountable for them?

A2

Application Portfolio & Spend

What do they run, what does it cost, and what should go?

A3

Data & Integration

Where does the truth live, and how does it move?

A4

Security & Access

Who can get in, and what happens when someone should not?

A5

Privacy, Compliance & Accessibility

What did they promise the people in their data, and can everyone use what they build?

A6

Resilience & Continuity

What happens when it breaks, and how do they know it will work?

Leverage

Is this organisation getting compounding return?

Workflow, automation and AI governance — scored with the same rigour as security, because this is where the return lives.

B1

Workflow & Process

Where does the organisation's time actually go?

B2

Automation

What runs without a human, and who is looking after it?

B3

AI Use & Governance

What is AI doing here, who decided, and how would anyone know if it went wrong?

Capacity

Can they sustain any of it?

A roadmap nobody has the hands or skills to execute is a wish list.

C1

People & Capability

Who does this work, and can they do what the roadmap needs?

C2

Delivery & Engineering

If they build software, can they ship it safely?

Three rules that make it an audit.

Every score carries its evidence

Observed, because I saw the configuration. Demonstrated, because they showed me. Asserted, because they told me and I could not check. A domain scoring well on entirely asserted evidence is a finding in itself, and it gets reported as one.

Two axes, never one

Maturity alone gives you a flat scorecard and a four-hundred-item backlog. Maturity against criticality — weighted for your organisation, not a generic one — gives you a roadmap that falls out of the matrix.

Findings are priced

Severity, effort in person-weeks, named owner. An unpriced finding is an opinion. So is a recommendation your team has no capacity to act on, which is why capacity is scored too.

The maturity ladder

0Absent
Does not exist.
1Ad hoc
Happens, undocumented, dependent on one person remembering.
2Defined
Written down. Followed inconsistently.
3Managed
Consistently followed, owned by a named person, measured.
4Optimised
Measured, improved on a cadence, automated where automation is correct.

Four weeks.

00

Scope

Domains agreed, criticality set per control for your organisation, artifacts requested, read-only access arranged. Without access the whole audit degrades to hearsay.

01

Discover

Portfolio sweep, spend pull, integration map. A self-assessment goes out widely, because the gap between what leadership believes and what staff report is itself data.

02

Evidence

Interviews with leadership, every system owner, and the people doing the work daily. Process walk-throughs where I sit and watch, because the description is always the happy path and the work never is.

03

Score

Maturity with evidence grades, TIME dispositions, the opportunity register, findings priced in person-weeks.

04

Deliver

Written report, live readout, and a 90-day plan with named owners. The 90-day plan is the product; the report is what justifies it.

What you get

  • A one-page scorecard: eleven domains, maturity against criticality
  • System inventory with TIME dispositions and total spend
  • Integration and data-flow map
  • Process portfolio with the toil number
  • Automation and AI opportunity register, scored and routed
  • AI governance assessment, with a starter policy if none exists
  • Risk register — severity, effort, owner
  • A 90-day plan and a twelve-month roadmap
  • The scored dataset, so next year shows movement

Built on standards, not opinions

The framework is a synthesis, and it says where each piece came from. What these sources agree on matters more than where they differ.

COBIT
governance separated from management — someone owns the decision rights
NIST CSF 2.0
Govern as a sixth function; audits show risk governance, not point-in-time compliance
CIS Controls v8.1
an honest security floor calibrated to the size of the organisation
Gartner TIME
a disposition for every system — tolerate, invest, migrate, eliminate
NIST AI RMF
govern, map, measure, manage — the spine of the AI domain
ISO/IEC 42001
AI as a management system rather than a collection of experiments
EU AI Act
risk tiers that force the question: how bad if this is wrong?
NTEN Tech Accelerate
a yardstick calibrated to mission organisations, not enterprises

The re-audit is where it compounds.

Every audit is stored as scored data against the same framework, so running it again next year shows movement rather than producing a second opinion. That is the difference between a report and a practice.