Assessments

Most assessments give you a flattering number. This one refuses to.

You have probably sat through a maturity assessment before. Someone scored you against a model, most scores landed comfortably in the middle, the report said you were “developing” with “opportunities to mature,” and everyone moved on feeling roughly fine. It told you almost nothing, because it was built to be survivable rather than true.

Mine is built differently, and the difference is one axis.

The second axis

Every control area gets scored twice.

Once for how strong the control is — the thing every assessment measures.

And once for whether you can prove it — the thing almost none of them measure, and the thing a supervisor, an auditor, an acquirer or an insurer actually asks about.

Those two numbers are almost never the same, and the gap between them is the whole point. A firm can have a genuinely strong control and be completely unable to evidence it on demand — the resilience plan that’s real but untested, the access model that’s correct but unattestable, the data quality that’s fine in practice but can’t be demonstrated on a clock. On a one-axis assessment, that firm scores well and gets blindsided in an inspection. On this one, the gap shows up in an afternoon, which is a much better afternoon than the one where a regulator finds it for you.

This is the same logic as the way I work, turned into a measurement. Having a control and proving a control are different things, and the space between them is where organisations discover, always at the worst moment, that their data model was never asked to carry the obligation.

The instruments

Technology maturity assessment. The full estate across the sixteen pillars — can you see it, do you govern it, can you run it safely, can it change — each scored on both axes. The output is not a grade. It’s a map of exactly where your controls are real but unprovable, which is the list worth having before someone external comes looking.

Taxonomy maturity assessment. The same dual-axis discipline aimed at the data model. How well your organisation classifies the things that matter, and whether that classification is coherent enough to carry an obligation or feed an AI. Most firms score worse here than they expect, and it’s usually the most valuable surprise on offer.

Product data health. For manufacturers and distributors: a focused look at what your product data is actually doing to you — the duplicate SKUs, the unmanaged supersessions, the attribute chaos — and what it’s costing downstream in every system that depends on it.

How it runs

It is not a questionnaire you fill in and score yourself, because self-scored maturity assessments measure optimism, not maturity. It runs as a structured examination: I look at the actual artefacts — the architecture, the registers, the evidence you’d hand a supervisor, the places where the answer currently lives in someone’s head — and I score against what I can see rather than what you tell me is true. The gap between those two is often the finding.

It is deliberately fast. A maturity assessment across the estate is a matter of days, not a quarter-long engagement that bills by the month and delivers a binder. The point is to find the unprovable-but-real controls quickly, while there’s still time to fix them on your schedule instead of a regulator’s. You get a map of where you stand on both axes, a short list of the exposures that matter ranked by how badly they’d read in an inspection, and a clear sense of which gaps are cheap to close and which are the data-model kind that take real work. No filler. No flattering middle grade.

Where it uncovers a data-model problem — and it usually does — that’s the handoff to taxonomy and information architecture, because a control you can’t evidence is almost always a control your model can’t express.

What you get, and what you don’t

You get the honest version. Where you’re strong, where you’re exposed, and specifically where the exposure is the unprovable kind rather than the absent kind — because those need different fixes and most assessments can’t tell them apart.

You don’t get a flattering middle score you can put in a board pack and forget. If that’s what you’re after, they’re easy to find elsewhere, and cheaper.