A technology control framework. Sixteen control areas across four questions every business should be able to answer about its technology: can you see it, do you govern it, can you operate it safely, and can it change. Each pillar is scored on two axes — how strong the control is, and how well it can be proven.

The Framework
Most assessments of technology collapse into a single flattering number. This one does not. The sixteen pillars are grouped under four domains — See, Govern, Operate, Evolve — and each is judged on what the control actually is and on whether that can be evidenced. It is the structure behind every engagement: where we look first, what we measure, and how a finding is defended.


See — can you see your estate?
You cannot govern what you cannot see. The first four pillars establish whether the business actually knows what it runs and how it fits together.
Pillar 01 — Asset & Estate Visibility
Whether the business knows what it runs — the systems, services, and software in use, including what no one formally approved.
Pillar 02 — Architecture Comprehension
Whether how the estate fits together is understood and documented, rather than held in one person’s head or buried in a slide deck.
Pillar 03 — Data Trust & Lineage
Whether the numbers can be trusted — one agreed source of truth, shared definitions, and lineage that can be traced.
Pillar 04 — Dependency Mapping
Whether the business knows what it depends on — libraries, vendors, end-of-life components — and what breaks if one of them fails.

Govern — do you control it?
Visibility without control is just awareness. These four pillars establish who decides, how change happens, where the money goes, and who holds the suppliers to account.
Pillar 05 — Decision Rights & Accountability
Whether technical decisions have clear owners and defined authority, rather than defaulting to whoever shouts loudest.
Pillar 06 — Change Governance
Whether changes ship under control — reviewed, reversible, and traceable — rather than feared or made in the dark.
Pillar 07 — Investment & Portfolio Control
Whether technology spend is understood and directed: what it buys, what should be retired, and where the value actually is.
Pillar 08 — Supplier & Third-Party Control
Whether vendors operate within defined boundaries, with exit options and oversight, rather than quietly setting the direction.

Operate — can you run it safely?
Day-to-day, under real conditions. These four pillars establish whether the estate is defended, access is controlled, the business can recover, and the team can sustain it.
Pillar 09 — Security Posture
Whether the estate is defended and patched, and exposure is known rather than assumed.
Pillar 10 — Identity & Access Control
Whether access is governed — who can reach what, granted deliberately and removed when it should be.
Pillar 11 — Resilience & Continuity
Whether the business can keep operating — and recover — when something fails.
Pillar 12 — Operational Capability
Whether the team can sustain delivery without depending on a single person who cannot be replaced.

Evolve — can it change?
Technology that cannot adapt becomes a liability on a timer. These four pillars establish whether the estate can meet what is coming — regulation, growth, and the cost of change itself.
Pillar 13 — Regulatory Adaptability
Whether the estate can meet regulatory obligations and adapt as they change — with the evidence to show it.
Pillar 14 — Scalability & Performance Headroom
Whether systems hold up as load and the business grow, with room to spare before they don’t.
Pillar 15 — Technical Debt & Sustainability
Whether the cost of change is understood and managed, rather than quietly compounding until it stops everything.
Pillar 16 — Adaptability & Strategic Optionality
Whether technology keeps options open for where the business is going, rather than locking it into where it has been.
How it is scored
Every pillar is judged on two independent axes: Control (1–5), how strong the control actually is, and Evidence (A–D), how well it can be proven. Separating them is the point — it stops a confident claim from passing as a proven one.

The credibility rule. A high control score on D-grade evidence is an assertion, not a control. Because the two axes are scored separately, a flattering self-assessment cannot masquerade as a verified one — which is exactly what makes the result defensible in due diligence, M&A, and regulatory review, where every other maturity model flattens into one number nobody can stand behind.
How the framework is applied
The framework is not a document that sits on a shelf. It is how an engagement is run: it sets where we look first, what gets measured, and how each finding is defended rather than asserted. The diagnostic value lies in the pattern, not the individual score — a single weak pillar may be survivable, but a weak domain points to a structural deficiency no single project will fix.
In practice this runs through a Technology Control Assessment or a lighter Technology Control Review, and feeds directly into technology due diligence and a First 90 Days engagement. The full set of pillars, with every post mapped to each, is catalogued in the pillar index.

Start the conversation.
Start a ConversationThe Sixteen Pillars Technology Control Framework is © Sixteen Pillars, released under Creative Commons Attribution-NonCommercial 4.0 (CC BY-NC 4.0). Commercial licence available.