An evidence-based assessment workbook for finding the next constraint to remove
Altivate | Published 26 July 2026
1. Start with the target, not the questionnaire
Digital maturity is contextual. A regulated infrastructure operator, a fast-growing retailer and a public authority do not need the same capability profile. Even two business units in one organisation may need different targets.
Before assessing, write:
- the strategy or service outcome the assessment supports;
- the business units, journeys and regions in scope;
- the decisions it must inform;
- the time horizon;
- the risks and obligations that constrain the target;
- who can commit resources after the assessment.
Without that frame, respondents tend to score aspiration, tool ownership or personal confidence. The result becomes a generic statement that the organisation should be more digital.
The European Commission, Australian Digital Transformation Agency and ISO capability materials all treat maturity as multi-dimensional and repeatable. Their dimensions and audiences differ. That is the point: the useful model fits the decision context.
This workbook uses seven domains as an Altivate synthesis. It is not a certification and does not claim equivalence to any government or standards framework.
Rate operating evidence, preserve uncertainty, and sequence the gaps that unlock others.
2. Assess seven connected domains
Strategy and outcomes
Can the organisation translate strategy into owned digital outcomes, investment choices and measures?
Evidence: portfolio decisions, outcome measures, investment criteria, benefit owners, stopped initiatives.
Customer and service
Can it understand journeys, design around user need, measure service performance and improve the whole experience across channels?
Evidence: journey data, research, accessibility testing, service measures, complaint-to-change records.
Operating model and process
Can cross-functional teams own outcomes, improve end-to-end processes and make decisions at the right level?
Evidence: process ownership, decision rights, product funding, improvement backlog, lead-time and quality data.
Data and AI
Can it create trustworthy data products, govern access and quality, and deploy analytics or AI inside accountable decisions?
Evidence: data ownership, quality controls, lineage, access decisions, evaluation, model or agent inventories, monitored outcomes.
Platforms and integration
Can its architecture support secure change, reliable reuse, interoperability, observability and retirement?
Evidence: platform standards, APIs and contracts, automated delivery, service levels, dependency maps, technical-debt decisions, decommissioned systems.
People and change
Can leaders and teams develop skills, redesign roles, adopt new ways of working and sustain the change?
Evidence: capability plans, protected learning time, role changes, adoption measures, manager reinforcement, hiring and partner strategy.
Governance, risk and resilience
Can governance enable timely decisions while maintaining security, privacy, continuity, regulatory compliance and accountable control?
Evidence: risk decisions, threat models, privacy reviews, recovery tests, access reviews, incident learning, exception expiry.
The domains interact. Better platforms cannot overcome unclear ownership. Better data cannot create value if the process does not use it. Faster delivery can increase risk if recovery and controls do not mature with it.
3. Rate evidence, not confidence
Use a five-level evidence scale:
| Level | Evidence condition | Typical signs |
|---|---|---|
| 0 | Unexamined | No owner, definition or reliable evidence |
| 1 | Claimed | Intent or isolated example, dependent on individuals |
| 2 | Repeatable | Defined practice used in part of the scope |
| 3 | Measured | Practice is widespread, measured and governed |
| 4 | Adaptive | Evidence routinely changes priorities, controls and practice |
The rating belongs to a scoped capability, not to an organisation in the abstract.
For each rating, record:
- two or more evidence artefacts;
- the population or process covered;
- a contrary example or limitation;
- the evidence owner;
- the calibration group that accepted it;
- evidence confidence: high, medium or low, with the reason;
- the target and why it matters.
Do not award level 3 because a policy exists. A measured level needs evidence that the practice operates, not only that it was designed.
Do not award level 4 because an organisation uses advanced technology. Adaptive maturity means evidence changes decisions and the operating system learns.
4. Use the assessment workbook
For each domain, answer four questions.
Strategy and outcomes
- Which digital outcomes are explicitly tied to strategy?
- How are investment, continuation and stop decisions made?
- Which outcomes have named business owners and baselines?
- What recent evidence changed the portfolio?
Customer and service
- Which complete journeys are measured across channels?
- How are user research, accessibility and operational data combined?
- What service failure has been removed at its process root?
- Which user group remains poorly served?
Operating model and process
- Who owns each priority outcome end to end?
- Where do handoffs or functional budgets block flow?
- Which process measures guide weekly decisions?
- What authority do product and process teams actually hold?
Data and AI
- Which critical data has an accountable owner and tested quality?
- How are access, lineage, retention and permitted use governed?
- Which analytics or AI output is embedded in a real decision?
- How are errors, drift, override and impact evaluated?
Platforms and integration
- How quickly can a safe change move from decision to production?
- Which dependencies are contractually visible and observable?
- Where does legacy complexity constrain strategic change?
- Which component was deliberately retired in the last year?
People and change
- Which capabilities will the strategy require in twelve to twenty-four months?
- How are roles, incentives and manager behaviour changing?
- Is adoption measured as behaviour rather than attendance?
- Where does critical capability depend on one person or supplier?
Governance, risk and resilience
- Which decisions are slowed without reducing risk?
- Are security, privacy and controls built into delivery?
- When was recovery tested under realistic conditions?
- Which exception has an owner, compensating control and expiry?
Capture the answer, artefact, scope, rating, target, dependency and next decision. The workbook is complete when another reviewer can follow the evidence, not when every cell contains a number.
5. Calibrate with mixed evidence and mixed voices
A self-assessment by one function reproduces that function’s worldview.
Include:
- executive leaders who set outcomes and resources;
- front-line teams who experience the process;
- product, process and service owners;
- technology, data and architecture;
- security, privacy, risk and internal control;
- finance and transformation;
- representative users or customers where appropriate.
Run individual evidence collection before the calibration workshop. In the workshop, examine the largest rating disagreements first. They often reveal scope boundaries, shadow processes, missing measures or a difference between policy and practice.
Use an independent facilitator where the result affects funding, executive performance or supplier selection. Have at least two reviewers rate material domains before calibration and record their initial ratings. Repeated one-level disagreement is useful evidence of ambiguous criteria or uneven coverage; resolve the definition or narrow the scope rather than averaging it away.
Calibration rules
- A title or tool is not evidence.
- One successful team does not prove enterprise capability.
- One failing team does not erase a repeatable practice elsewhere.
- A rating cannot exceed the coverage of its evidence.
- Material contrary evidence stays visible.
- The facilitator records uncertainty rather than forcing agreement.
The result should be defensible and useful, not artificially precise.
Worked example: a platform claim becomes a scoped rating
A group reports level 3 platform maturity because it owns a cloud integration platform. Evidence shows automated deployment and monitoring for two digital products, but manual release and no recovery test across the remaining estate. Two reviewers score 3 and 1. The calibrated result is level 2 for the named product scope, level 1 elsewhere, with medium confidence until recovery is tested. The next move is not “buy more platform”; it is to extend the proven release practice and run a realistic recovery exercise.
6. Do not average away the constraint
An average turns materially different profiles into the same score.
Consider two organisations:
| Domain pattern | Organisation A | Organisation B |
|---|---|---|
| Strategy and outcomes | Strong | Weak |
| Customer and service | Strong | Moderate |
| Operating model and process | Weak | Strong |
| Data and AI | Weak | Strong |
| Platforms and integration | Moderate | Moderate |
| People and change | Moderate | Weak |
| Governance, risk and resilience | Strong | Moderate |
They may share an average. They do not share a roadmap.
Report instead:
- the current evidence level by domain;
- the required target by domain;
- the confidence and coverage of the evidence;
- the material dependencies among gaps;
- the limiting constraint for the strategy;
- the next decision and owner.
A domain with a small gap can be more urgent than a domain with a large gap if it blocks several outcomes. A low target can be entirely rational where the strategy does not require greater capability.
7. Find the limiting constraint
Map dependencies between gaps.
Examples:
- weak outcome ownership blocks portfolio prioritisation and benefit realisation;
- weak data ownership blocks analytics, AI, personalization and process measurement;
- fragmented integration blocks service redesign and operating visibility;
- weak change capability blocks adoption across every technology programme;
- slow risk decisions block delivery even when engineering capability is strong;
- weak process ownership turns automation into faster local optimisation.
Ask:
Then test the opposite:
This produces a sequence rather than a shopping list.
8. Turn the profile into a ninety-day roadmap
Choose no more than three constraint-led moves for the first cycle.
| Move | Outcome it unlocks | Evidence gap | First 30 days | By day 60 | By day 90 | Owner |
|---|---|---|---|---|---|---|
| [enter] | [enter] | [enter] | [enter] | [enter] | [enter] | [enter] |
| [enter] | [enter] | [enter] | [enter] | [enter] | [enter] | [enter] |
| [enter] | [enter] | [enter] | [enter] | [enter] | [enter] | [enter] |
Download the editable evidence-based digital maturity workbook. It opens with the strategic frame, in-scope boundary, decisions, horizon, obligations and resource-committing sponsor, followed by explicit 0-to-4 rating definitions before the 28 evidence questions.
Good moves create operating evidence:
- appoint an end-to-end process owner with decision rights;
- establish one reproducible data-quality control on a critical data product;
- instrument one priority journey across channels;
- introduce a risk-decision service level and exception expiry;
- move one product from project funding to an owned outcome backlog;
- test recovery for one critical digital service;
- retire one dependency whose cost and risk are understood.
Avoid roadmap items such as “improve culture” or “implement AI” without a changed practice, population, measure and owner.
9. Reassess evidence, not sentiment
Reassessment should ask what changed in the operating system.
For each move:
- Did the planned practice operate?
- Did the intended population use it?
- Did an outcome or decision improve?
- What contrary evidence appeared?
- Did the constraint move or expose a new one?
- Should the target, sequence or investment change?
Run a focused review every quarter and a broader recalibration when strategy, regulation, leadership, operating model or platform direction materially changes.
Do not optimise for a higher score. Optimise for a stronger ability to execute the strategy, serve users, learn and control risk.
10. The assessment-quality checklist
- ☐ The scope and strategic decision are explicit.
- ☐ Targets differ where strategy requires them to differ.
- ☐ Seven domains are assessed as a connected profile.
- ☐ Ratings cite operating evidence and coverage.
- ☐ Contrary evidence and uncertainty remain visible.
- ☐ Multiple functions and front-line perspectives were calibrated.
- ☐ No average hides a limiting constraint.
- ☐ Dependencies among gaps are mapped.
- ☐ The first roadmap cycle has no more than three moves.
- ☐ Every move has a changed practice, measure and owner.
- ☐ Reassessment dates and decision triggers are set.
- ☐ The result is not presented as certification or a market benchmark.
The assessment is ready when leaders can explain why one capability must move before another and what evidence will prove the move worked.
Explore the other tools in White Papers, or use the profile as the starting evidence for an AI Agent Business Case.
Sources and verification status
Checked 26 July 2026. The seven-domain workbook and five-level evidence scale are an Altivate synthesis. They are not an ISO, European Commission, Australian Government or NHS certification.
- European Commission, Digital Maturity Assessment Tool FAQ and framework
- a multi-dimensional assessment framework for SMEs and public service organisations.
- Australian Digital Transformation Agency, Digital Maturity Assessment
- a repeatable government approach for common language, priorities and progress over time.
- ISO Capacity Building, Digital Capability Maturity Assessment Models
- capability-oriented guidance covering culture, operations, ecosystem, people, process and technology.
- NHS England, Digital Maturity Assessment
- a sector-specific example of structured digital-maturity assessment.
