Methodology
Every assessment in the portfolio runs through the same six phases, is scored on the same five-level maturity scale, and ends with the same board-ready deliverable set. The subject changes; the discipline does not.
The six phases
Phase 1 Scope and Planning
Activity
Confirm business units, systems, locations, vendors, assessment objectives, stakeholders, and success criteria.
Output
Approved scope, stakeholder list, assessment plan, and document request list.
Phase 2 Evidence Collection
Activity
Review policies, procedures, system configurations, audit logs, architecture diagrams, contracts, recovery plans, and prior audit findings.
Output
Evidence inventory and initial control observations.
Phase 3 Interviews and Workshops
Activity
Conduct interviews with IT, security, risk, compliance, business continuity, legal, procurement, and business process owners.
Output
Validated process understanding, control ownership, and dependency mapping.
Phase 4 Control and Maturity Testing
Activity
Evaluate design effectiveness, operating effectiveness, maturity level, risk exposure, and control gaps.
Output
Assessment results, maturity ratings, and risk-ranked findings.
Phase 5 Validation
Activity
Discuss findings with control owners to confirm accuracy, context, root cause, and remediation feasibility.
Output
Management-validated findings and agreed action owners.
Phase 6 Executive Reporting
Activity
Prepare a board-level summary, heatmap, roadmap, risk themes, and priority decisions.
Output
Final board report, action plan, and implementation roadmap.
Scoring
Findings are rated on a five-level maturity scale, applied per control domain, so results can be compared across assessments and tracked over time.
- 1 Initial / Ad Hoc
- Controls are informal, inconsistent, undocumented, or dependent on individual effort.
- 2 Developing
- Some controls exist, but coverage, ownership, testing, or evidence is incomplete.
- 3 Defined
- Controls are documented, assigned, and implemented across most relevant areas.
- 4 Managed
- Controls are monitored, tested, measured, and supported by regular reporting.
- 5 Optimized
- Controls are continuously improved, automated where practical, and aligned with risk appetite and business resilience objectives.
Deliverables
| Deliverable | Purpose |
|---|---|
| Executive Summary | Board-level view of current state, major risks, priority actions, and decisions required. |
| Assessment Report | Detailed findings, evidence reviewed, control gaps, maturity scores, and observations. |
| Risk Heatmap | Visual prioritization of high, medium, and low risks by likelihood and impact. |
| Maturity Scorecard | Capability rating by domain, category, or control area. |
| Remediation Roadmap | Prioritized action plan with owners, timelines, dependencies, and expected risk reduction. |
| Management Action Plan | Agreed corrective actions, accountable owners, target dates, and a tracking mechanism. |
| Board Dashboard | Concise metrics for ongoing oversight, trend monitoring, and investment decisions. |
An illustrative five-by-five risk heatmap plotting likelihood against impact, with risk intensity increasing toward the top right.
Assessments align with NIST CSF 2.0, ISO 27001, CIS Controls, PCI DSS, GDPR, and Zero Trust architecture principles.
Start with a scoping conversation
Phase one begins with your objectives, stakeholders, and systems. The document request list follows from scope, so nothing is collected that is not needed.