Technology control assessment

Your technology, scored against the Sixteen Pillars framework, in writing, in days.

You suspect there are gaps in your technology governance, but you do not have weeks to find out. You may be preparing for a board meeting, a customer audit, a refinancing, or a regulatory event. You may want to test what a full Review would cover before you commit to one. What you need is a fast, scored read of where you actually stand.

That is what this engagement is.

€4,950. Three to five working days. Delivered in writing, with a thirty-minute findings session.

Fixed fee. Fixed scope. No implementation work. No commissions. No product recommendations influenced by suppliers.

Technology Control Assessment infographic using a vehicle inspection metaphor. On the left, a polished executive view shows a well-maintained luxury car representing what leadership sees: dashboards, policies, compliance coverage, documented ownership, security controls, and positive performance indicators. The vehicle appears healthy, compliant, and operating correctly. In the centre, a Technology Control Assessment independently reviews evidence through interviews, document analysis, framework scoring, and validation against the Sixteen Pillars framework. On the right, the bodywork has been removed to reveal the engine and internal systems underneath. The exposed engine represents the actual control posture, highlighting governance gaps, architectural complexity, technical debt, data quality issues, security weaknesses, compliance drift, key-person dependencies, vendor risks, and assurance limitations. The image illustrates how a Technology Control Assessment looks beneath the visible presentation to understand how the organisation is really operating and where the most important risks and priorities exist.

Why clients commission an assessment

The assessment is usually triggered by a specific event with a fixed deadline. Most often, one of these:

  • A board meeting is approaching and leadership needs a written technology view before it.
  • A major customer or partner is asking about technology governance and a documented response is required.
  • A regulatory consultation, inspection, or self-assessment is upcoming and a baseline read is needed.
  • An RFP, tender, or framework response requires evidence of technology governance and control.
  • A management team is considering a full Technology Control Review and wants to test the framework first.
  • A newly-appointed CTO or IT Director wants a fast independent read of what they have inherited.
  • An insurance renewal, refinancing, or deal event is coming and the technology evidence needs gathering.
  • The board has been receiving conflicting information about the state of technology and wants an independent third view, quickly.

If one of these is the position you are in, the assessment is built for it.

Who this is for

Owners, MDs, and CEOs of established businesses who need a fast, written reading of their technology governance — typically ahead of a specific event with a deadline.

Management teams preparing for board presentations, customer audits, regulatory events, refinancing, or deal events where documented technology evidence is required.

Newly-appointed CTOs and IT Directors who want a baseline of what they have inherited in days, not weeks.

Leadership teams considering a full Technology Control Review or Architecture Review who want to test the framework and the working relationship first.

Who this is not for

Pre-revenue businesses or technology startups. The framework assumes an established operating business with technology that has accumulated over time.

Buyers and investors on a live deal. That work is Technology Due Diligence, with a different scope and different commercial terms.

Owners wanting an architectural deep-dive into one area. The assessment is a fast read across the whole framework; depth in any single pillar is an Architecture Review.

Buyers wanting validation of decisions already made. The assessment will tell you what the scoring is, including where the scoring is uncomfortable.

What you receive

The assessment tells you three things in writing: where you stand against the framework, what matters most, and what to do next. Five deliverables, in plain language, ready in days.

Sixteen Pillars Assessment infographic showing the output of a Technology Control Assessment using a two-dimensional assessment model. The centre of the image contains a large four-quadrant matrix with the organisation positioned in the middle and sixteen technology governance pillars plotted as individual markers. The horizontal axis represents Importance or Business Impact, ranging from lower impact on the left to higher impact on the right. The vertical axis represents Control or Maturity, ranging from weaker control at the bottom to stronger control at the top. Together, the two axes show not only how important each pillar is to the business, but also how effectively it is governed and controlled.

The upper-right quadrant represents critical strengths: areas that are highly important to the business and also well controlled. Example pillars plotted in this area include Governance, Compliance, Policies and Standards, Risk and Assurance, and Business Continuity. These are areas where controls are mature and aligned with business priorities.

The lower-right quadrant represents high-priority risks: areas with high business impact but weaker control maturity. Example pillars shown here include Architecture and Systems, Data, Security, and Vendors and Third Parties. These are the areas requiring the greatest leadership attention because weaknesses in these domains create material organisational risk.

The upper-left quadrant represents lower-priority strengths: areas with lower business impact but relatively strong controls. Example pillars include Operations, Change and Release, Monitoring and Reporting, and Financial Management. These areas are functioning effectively and generally require maintenance rather than significant intervention.

The lower-left quadrant represents lower-priority risks: areas with weaker controls but lower business impact. Example pillars shown include People and Capacity, Systems and Tools, and Strategy and Alignment. These areas should be monitored and improved over time but are not typically the most urgent governance concerns.

Supporting panels explain the assessment methodology. The left side of the image defines the two assessment dimensions. Importance measures how critical a pillar is to business objectives, operational resilience, and risk exposure. Control measures the maturity and effectiveness of governance, processes, ownership, standards, and oversight within that pillar. A second panel lists the sixteen pillars that make up the framework, including Governance, Architecture and Systems, Data, Security, Compliance, People and Capacity, Systems and Tools, Vendors and Third Parties, Risk and Assurance, Policies and Standards, Operations, Change and Release, Monitoring and Reporting, Business Continuity, Financial Management, and Strategy and Alignment.

The right side of the image explains how to interpret the assessment map using colour-coded categories. Green markers represent strengths, orange markers represent areas to watch, red markers represent areas requiring focused attention, and purple markers represent areas that should be maintained. A summary chart provides an overall count of strengths, risks, and focus areas identified during the assessment.

A scored framework reading. Your business assessed against the Sixteen Pillars framework, with a score for each pillar and the evidence behind it. Written, defensible, repeatable in twelve months to track change.

A pillar-by-pillar summary. What we found in each area — governance, architecture, data, security, compliance, people, standards, and the others. Written in plain language so non-technical leadership can read it.

A risk snapshot. The findings that should not wait — identified separately from the scoring so leadership can act on them without rereading the report.

Top three priorities. What to address first, in order, with a rough effort estimate against each. The list a board can act on without further discussion.

A findings session. A thirty-minute session to walk through the report — findings presented, scoring challenged, priorities discussed. Held in person, by video, or by phone, as you prefer.

Typical outcomes

Most assessments result in one of four conclusions.

Your governance is sound across the framework. No material gaps identified. Future investment can focus on growth rather than governance.

Specific gaps are identified. The framework reading surfaces particular areas where governance has not kept pace with the business. The report names them and the rough effort to address.

Multiple gaps suggest a deeper review. The fast read surfaces enough to warrant a full Technology Control Review or a targeted Architecture Review to go deeper before acting.

Critical exposure requires immediate attention. Specific findings should be addressed before any major change, investment, audit, or deal event.

The assessment tells you which of these your business is in, and what to do next.

How the assessment runs

Three to five working days, in three phases.

Day one — scoping and kickoff. A short call to confirm scope, identify stakeholders for interviews, and request the documents we need. Diagrams, vendor list, policy register, incident reports, prior audits.

Days two to four — interviews and review. Short interviews with your technology lead and one or two senior staff. Review of the documents provided. Where there are gaps, we identify them rather than assume.

Day five — written report and findings session. The report delivered in writing, then the thirty-minute findings session to walk through it.

Everything is written before it is said. Nothing is presented to your board that you have not read first.

What this is not

An architectural deep-dive. The assessment is a fast read across the framework. For depth in a single area, see the Architecture Review.

A full audit in the regulatory sense. The assessment can inform one, and is often used as preparation for one, but it does not substitute for one.

A remediation engagement. We identify and prioritise; we do not implement.

A penetration test or security audit. Security architecture is in scope as one pillar; offensive testing is a specialist engagement.

The Technology Control Assessment is not a technology purchase. It is a checkpoint — a fast, scored read that tells you whether you have a problem worth addressing, what kind of problem, and what to do next.

The purpose of the engagement is not to give you every answer. It is to give leadership a defensible baseline, in writing, in days — so you know whether to act, what to act on, and whether a deeper Review is the right next step.

Proof

References available on request. Anonymised excerpts from prior assessments available on request.

What happens next

Start a Conversation

Fifteen minutes. We confirm scope, timing, and stakeholders. You decide whether to proceed. No proposal is sent unless you ask for one.

Start with the Technology Control Snapshot — €495

A scored online self-assessment, returned with a written summary within five working days. The Snapshot is the right place to start if you want to test the framework before committing to a paid engagement.

For a deeper engagement across the framework, see Technology Control Review.

Free interactive tool

Interactive deadline calculator

Check which regulations apply to you and when

Regulation across the EU, UK, US and Asia-Pacific has moved considerably in the past eighteen months, and several headline dates have shifted more than once. Twelve questions, about three minutes.

Results are shown on screen — no email required. A dated summary is available to download, and can be sent on if that's more useful. What we do with your answers.

Book a Technology control assessment scoping call