Services

Six domains. Take the ones you need.

Our services are modular. Most organisations do not need all six at once; they need one done properly, then the next. Whatever the scope, the same scale is applied, which is what makes a finding defensible when somebody asks how it was reached.

What we do

The six governance domains

These are the domains we assess and the areas we work in. They are the same six throughout: on this page, in the assessment, and in the profile your leadership team receives. Take one, a few, or all six.

  1. 01 IT strategy and accountability

    Direction is either set deliberately, or it is set by whoever is loudest.

    We establish who decides, who is accountable, and whether priorities follow your objectives rather than a supplier’s renewal cycle. You get decision rights recorded in one place, a strategy your leadership can approve, and a road map against which progress is visible.

    What this domain covers

  2. 02 Investment and delivery

    Approved on a business case, then rarely measured against it.

    We establish what is being spent, what it is delivering against the case that was made for it, how change is authorised and recorded, and where the portfolio has grown commitments nobody deliberately chose. You get investment criteria, a portfolio view and a change route that holds.

    What this domain covers

  3. 03 Operational resilience

    The question is not whether something fails. It is what happens when it does.

    We establish which services the organisation cannot operate without, how long it could run without them, and whether the arrangements for a critical system, site or supplier becoming unavailable have ever been tested rather than assumed. You get a continuity position based on evidence, with the gaps ranked by consequence.

    What this domain covers

  4. 04 Cybersecurity

    Control coverage measured against the exposure you actually carry.

    We assess the controls in place against your organisation’s real exposure rather than a generic checklist, and separate what is documented from what is working. You get a gap assessment, a ranked exposure register, and a remediation order that starts with consequence rather than convenience.

    What this domain covers

  5. 05 AI governance and literacy

    Your people are already using it. The question is on what terms.

    We establish where it is in use, on what information, under whose authority, and what has to be true before it influences a decision affecting a customer or an employee. You get an acceptable-use policy people can actually follow, a register of where it is used, a review route for anything high consequence, and a clear view of whether your people understand the rules.

    What this domain covers

  6. 06 Enterprise architecture

    Systems accumulate faster than anyone maps them.

    We set out how your systems, data and dependencies actually connect, where duplication and single points of failure sit, and what a realistic target state looks like. You get a current-state picture, a target state and a sequenced route between them.

    What this domain covers

Start here

The Preliminary Maturity Assessment

The usual way in. A scored, written picture of where you stand in the domains you choose, with a ranked plan for the next ninety days.

What you receive

  • Governance profile with maturity ratings for the domains in scope
  • One-page summary written for your leadership team
  • Full assessment report, 10 to 12 pages
  • Ranked exposure register, highest consequence first
  • Prioritised 90-day action plan, with owners and effort estimates
  • Sixty-minute findings presentation to your executive team
  • Thirty-day follow-up call
Scope
Modular. Choose the domains where you need support. Most begin with one or two.
Evidence gathered
Structured interviews across executive, finance, technology and one business function, plus document and systems review.
How it is scored
A five-level maturity scale, applied against recognised frameworks selected to suit the domains in scope. Commonly COBIT 2019, ISO/IEC 38500, ISO/IEC 27001, TOGAF, NIST and DORA, and not limited to those. The scale itself stays constant, so a later assessment is comparable.
Turnaround
Findings your leadership can act on within ten working days of the final interview.
Price
SCR 20,000 to 40,000 per domain, VAT exclusive. Where a domain sits in that band depends on the size and scope of your organisation, not on which domain you choose. All six together are quoted on request, priced as six with a discount for taking the whole position at once. Building what the assessment recommends is a separate engagement, scoped and quoted against what you need.

Scope honesty

What we do not do

Not our work

  • IT support, helpdesk or fixing equipment
  • Selling or reselling hardware and software
  • Building software or websites
  • Installing or managing networks
  • Supplier and third-party risk assessment
  • Open-ended consulting with no defined end

Why that matters

We sell no technology and take no commission from anyone. Nothing sits behind the assessment, which is the point of commissioning it from outside rather than asking the supplier who installed the system.

It also means we will tell you when the answer is to do nothing, or to fix a process rather than buy a tool.

Next step

Take the first step

Most engagements start with a short discussion about what your organisation is trying to achieve and where technology is getting in the way. From there we agree a clear scope and a fixed price before any work begins.