Assessment frameworks
31 assessment frameworks. 9 consulting practices.
Every framework runs an evidence-based maturity or readiness assessment from the client's own documents, scores it on the standard's own scale, ranks the gaps, and auto-generates a board-ready deck and report — with an AI interviewer to fill anything missing.
UK-regulatory coverage built in: 12 of the 31 frameworks are UK-specific — a differentiator for firms advising regulated UK clients.
Cybersecurity · Data & AI · Technology · Finance & Risk · Operations · Growth · Strategy & Transformation · Sustainability · Human Capital
How every assessment works
Standards-aligned. Evidence-grounded. Exec-ready.
1 · Evidence in
Upload the client's documents — policies, reports, data. An AI interviewer asks targeted follow-ups to fill anything missing.
2 · Scored on the standard
Every dimension is scored on the framework's own scale, with each score traceable to the evidence behind it — gaps ranked by severity.
3 · Board-ready out
A board-ready slide deck and HTML report are generated automatically — executive summary, maturity landscape and a sequenced plan.
Browse by practice
Frameworks by consulting practice
Nine practices, 31 frameworks. Open a practice to see how each one is scored.
Cybersecurity
7 frameworks · 3 UK-specific
- NIST CSF 2.0 — Score maturity across all six CSF 2.0 functions, evidenced from the client's own controls.
- ISO/IEC 27001 ISMS Readiness — Gauge ISMS readiness against the Annex A controls before committing to certification.
- Zero Trust (CISA ZTMM) — Rate zero-trust maturity across the five CISA pillars and the gaps to close first.
- CIS Controls v8 — Benchmark the 18 CIS Controls and implementation groups against real evidence.
- Cyber Essentials (NCSC) UK — Check readiness against the five NCSC Cyber Essentials controls before assessment.
- NCSC Cyber Assessment Framework (CAF) UK — Assess against the 14 CAF principles for NIS-regulated and critical services.
- NHS Data Security & Protection Toolkit (DSPT) UK — Evidence the NHS DSPT standards for health and care organisations.
Data & AI
4 frameworks · 2 UK-specific
- AI Governance & Responsible AI Maturity — Measure responsible-AI maturity across governance, risk, transparency and oversight.
- Data Management Maturity — Score data management across governance, quality, architecture and operations.
- UK AI Regulation (DSIT Principles & Assurance) UK — Check alignment to the UK's five AI-regulation principles and assurance expectations.
- UK GDPR & Data Protection / ICO Accountability UK — Assess UK GDPR accountability against the ICO's accountability framework.
Technology
5 frameworks · 2 UK-specific
- Engineering Excellence & DevOps — Benchmark delivery performance, DevOps practice and engineering health.
- Cloud Well-Architected Review — Review workloads across the well-architected pillars — reliability, security, cost and more.
- ITIL 4 Service Management — Assess service-management maturity across the ITIL 4 practices.
- GDS Service Standard & Technology Code of Practice UK — Check public-sector services against the GDS Service Standard and Technology Code of Practice.
- NHS Digital Technology Assessment Criteria (DTAC) UK — Evidence the NHS DTAC criteria for digital health technology.
Finance & Risk
7 frameworks · 4 UK-specific
- Finance Function & FP&A Maturity — Score the finance function and FP&A across planning, reporting and partnering.
- Enterprise Risk Management (COSO ERM) — Assess enterprise risk management against the COSO ERM framework.
- Operational Resilience (EU DORA) — Gauge digital operational resilience readiness against EU DORA.
- FCA Operational Resilience (PS21/3) UK — Map important business services and impact tolerances to FCA PS21/3.
- FCA Consumer Duty UK — Assess Consumer Duty outcomes — products, price and value, understanding and support.
- Senior Managers & Certification Regime (SM&CR) UK — Check SM&CR readiness across responsibilities, certification and conduct rules.
- UK Corporate Governance Code (FRC) UK — Evidence compliance with the FRC UK Corporate Governance Code.
Operations
2 frameworks
- Operational Excellence & Lean Maturity — Benchmark operational excellence and Lean maturity across the value stream.
- Supply Chain Resilience & Maturity — Score supply-chain resilience, visibility and risk readiness.
Growth
2 frameworks
- Customer Experience Maturity — Measure CX maturity across strategy, journey, measurement and culture.
- Revenue Operations (RevOps) Maturity — Assess RevOps alignment across sales, marketing and customer success.
Strategy & Transformation
1 frameworks
- Digital Transformation Readiness — Gauge readiness to transform across strategy, capability, technology and culture.
Sustainability
2 frameworks · 1 UK-specific
- ESG & Sustainability Maturity — Score ESG and sustainability maturity across environment, social and governance.
- UK Sustainability Disclosure (SDR, TCFD & SECR) UK — Check readiness for UK SDR, TCFD and SECR climate and sustainability disclosure.
Human Capital
1 frameworks
- Organizational Health — Assess organizational health across leadership, culture, capability and engagement.
UK regulatory coverage
Built for regulated UK clients.
From FCA Consumer Duty and SM&CR to Cyber Essentials, NHS DSPT/DTAC and UK Sustainability Disclosure — assess against the UK rules your clients are held to, scored on each standard's own scale.
- Financial services — FCA Operational Resilience, Consumer Duty, SM&CR, FRC Governance Code
- Public sector & health — GDS Service Standard, NHS DSPT, NHS DTAC
- Data, AI & ESG — UK GDPR/ICO, UK AI regulation (DSIT), SDR, TCFD & SECR

See a framework run on real data.
Pick any of the 31 frameworks and we'll score it live from a client's own documents.