Self assessment

Which level is your organisation at

Six questions. Five minutes. Not a sales call.

Your answers are not sent to a server. The result is computed in your browser. No email is asked for.

1. Can you show under which rule a change running in production was approved, together with the rule as it stood that day?
2. Can you see in one place who read production data and for what stated reason?
3. Are the steps skipped during an emergency recorded with their justification?
4. Can your audit evidence be verified independently of the person and the system that keeps it?
5. How many separate paths deliver change to your production database, and how many of them sit inside the same governance model?
6. If your most senior database administrator took a month of leave, where is the release order written down?
Final step: scope

You are at the highest level on all six questions. One condition remains for level 5: complete scope. Which of the eight paths below sit inside the same governance model?

All eight ticked means level 5. Otherwise level 4, and the missing paths become your next step.

Level 1: Improvised

Your organisation has rules. They live in people rather than in a system.

In practice: whether things are done correctly depends on who is on duty that day. When a person leaves, part of the rule leaves with them. In an audit, answers come from memory.

Next step: not writing the rule down. Routing the work through one place. A written rule is not a rule until work passes through it.

Level 2: Coordinated

All the parts exist and all of them work. None of them knows about the others.

In practice: your investments were right. What is missing is not a tool. When an auditor arrives, screenshots are gathered from several systems and it costs someone a week.

Next step: a shared record that connects the parts. It begins with the approval carrying the rule it rested on.

Level 3: Documented

The rule is written down. The system does not enforce it.

In practice: you already know there is a gap between your process document and reality. The gap is small on a normal day and wide under pressure. This is the hardest level to defend in an audit, because the document exists and the proof of compliance does not.

Next step: take enforcement out of human willingness. A step that can be skipped will be skipped.

Level 4: Enforced

The rule lives in the system and leaves a trail even in an emergency. The evidence still rests on your own system's word.

In practice: you are sufficient for internal audit. In an external audit, or after an incident, the question "what shows this record was not altered" is answered from inside the same system.

Next step: evidence that can be verified from outside, and complete scope. If your scope list has a missing path, close that first.

Level 5: Provable

Evidence is a by product of the work. Scope is complete.

In practice: audit preparation is not a task you have. Which rule an action followed can still be read even after the rules change.

Next step: staying here. Without a versioned rule set the level drops quietly, because old records start being read against new rules.

This result is not a list of shortcomings. It is a map of the next step. Levels are not skipped, and moving up starts by fixing one area.

Read the full maturity model