ABCDEFGHIJKLMNOPQRSTUVWXYZ
1
2
3
Maturity LevelsAS-ISTO-BE
4
Area of ControlSpecific control1 -Ad-Hoc2 - Opportunistic3 - Systematized4 - Optimized
5
GovernanceLeadershipNo evident ownership for IT:
- Initiatives, projects and demands are deluded over areas/business lines
- Decision process, regarding initiatives and investments, is not clear nor repeatable
- Roles and responsibilities for IT are non-existent or not clear
Ownership of IT exists but it is not managed nor repeatable:
- There may be roles & responsibilities for IT but are not empowered nor a mandate is always evident
- Some initiatives are managed and mandated by a figure of IT leadership, but not all of them and there are not clear criteria do set the mandate
- Decision process, regarding initiatives and investments, is applied occasionally but is not well defined nor repeatable
IT ownership is well defined:
- Roles & responsibilities are clear, a specialized structure is in place
- Decision process, regarding initiatives and investments, is clear and known to the whole organization
- A clear mandate exists to lead, supervise and /or assess all initiatives and investments
IT ownership is well defined, and organizational models are reviewed and improved. Level 3 - Systematized is achieved and:
-Organizational models are review and adjusted according to the needs of speed of delivery, innovation enablement, budgetary context and other criteria relevant to the organization current context
6
Business alignmentNo clear alignment:
- IT initiatives and business objectives and not clearly related
- IT initiatives occur typically to address or solve urgent issues
- Inexistence of an IT roadmap
A request/response relation:
- The relation between business lines and IT is purely transactional
- Heavily based on a request/response model
- An IT roadmap (planning) may exist, but the scope of the roadmap does not cover all the initiatives
- The IT roadmap is mainly a backlog of business requests
IT is also a contributor:
-IT is consulted when business solution are designed
- IT is informed about business problems and challenges
- IT has a business immersion posture. IT has a deep knowledge of the business, its customers, context and business culture. IT solutions are designed and built considering all these inputs
IT as a business partner. Level 3 - Systematized is achieved and:
- An IT roadmap exists and contains IT sustainability initiatives such as infrastructure/application modernization and technical debt reduction
- IT helps create and deliver digital products or digital components to the company, if applicable
- IT enables and facilitates the adoption or understanding of existent/new/emerging technologies to business. E.g. proactively delivering PoC or MVP of products or features
7
IT OperationProcessesProcesses are not managed:
- No practices in place. Execution is mainly supported by empiric knowledge of the current context
- Processes are not documented
- Interventions are typically reactions to incidents
Practices are in place but not managed/repeatable:
- There are defined practices in place, but are not documented
- Low level or inexistence of measurement techniques, such as KPIs or SLAs
- Lack of proactive monitoring processes to prevent and anticipate disruptions
Processes are managed:
- There is a well-defined catalog of services available and the practices are documented;
- There are in place quality, efficiency and effectiveness measurements such as SLAs, KPIs and others
- IT support operations are aligned with business needs, such as operating hours and geographical coverage
- Monitoring practices and tools are available to prevent disruptions, and cover a vast part of the IT operations landscape
Best practices are in place. Level 3 - Systematized is achieved and:
- Practices are aligned with best-in-class frameworks, such as ITIL, ISO standards or other similar
- Processes and documentation are audited, at least yearly and CAPA plans are executed
- Business alignment is reviewed at least yearly or when relevant business events occur, such as expansions, new products, M&A etc.
8
Continuous ImprovementImprovement is not addressed:
- Improvement initiatives rarely occur normally are a reaction to a severe incident
- Implemented measures do not become permanent and the context usually revert to the previous scenario
Improvement practices exist but are not sustained:
- Lessons learned are taken from incidents and mitigation Ans contingency measures are implemented, but inconsistently
- Improvement opportunities when detected are implemented, but inconsistently
- Implemented measures became permanent, but inconsistently
Improvement is managed and sustained:
- Improvement opportunities are assed in terms of cost/benefit
- Root cause analysis techniques, such as 5 Why's, are applied
- There are in place target values for KPIs and SLAs and deviations trigger improvement plans
- There is a formal procedure for lesson learned after an incident response
Continuous improvement is a mindset. Level 3 - Systematized is achieved and:
- Continuous improvement programs are in place, using best-in class frameworks such as Kaizen, Lean IT, PDCA and others
- A benefit tracker is maintained, quantifying gains and benefits, such as cost savings, quality improvements, customer satisfaction and others
9
Development/ProductSoftware DevelopmentSoftware is built/modified without control:
- Teams/staff builds or applies changes to software with little or no change or quality control
- No defined or approved architecture/pattern by organization is in place
Minimum practices are in place:
- Source code is versioned and protected against unauthorized access
- Some level of quality control or testing is executed before deploying to production
- Segregated development and production environments exists:
- Deployments to production are controlled and followed-up (hyper care)
A controlled and managed SDLC is in place:
- Requirements are managed
- DEV/QA/PROD environments exist and are segregated
- Quality Assurance practices are in place
- Change Management best practices are in place including approval and documenting
- Anomalies are documented and fully integrated on QA processes
- Source code is versioned, protected and be tracked to releases/versions
- An handover process from development to operations is defined
Software is an engineering process. Level 3 - Systematized is achieved and:
- The SDLC is documented and can be used for onboarding/training
- DevOps principles are in place (automation)
- Engineering roles are well defined
- QA, Dev and Ops KPIs exist, are monitored and deviations trigger improvement plans
- Code reviews are executed
- Audit procedures are in place
10
InnovationIT basically reacts:
- IT acts reactively and is mostly focused on operational problems
- Few or no new ideas are IT originated
Innovation initiatives exist, but are not consistent:
- Initiatives are usually led by single, top talent contributors
- Some experimentation of new technologies
- There is an interest in process improvement
Innovation is structured:
- Processes and procedures to identify and test opportunities are in place
- Emerging technologies are evaluated and selectively adopted
- Initiatives are co-shared between IT and business
Innovation is strategic pillar:
- open innovation initiatives are in place. E.g. involvement with academia, start-ups environment etc.
- IT leads initiatives
- Willingness to be an early/first adopter
11
Project/Portfolio ManagementMethodologyInitiatives are executed not managed:
- Initiatives have no clear scope, budget and timeline
Initiatives are managed as projects, in an unstructured way:
- The project objectives are defined and are communicated
- A minimum baseline of ceremonies exist, such as kickoff, status and closure meetings
- A minimum baseline of documentation exists such as meeting minutes and a project charter or vision scope
There is a formal approach to project management:
- The organization has a formal and documented methodology
- Project ceremonies and supporting tools are well defined and documented
- KPIs and measures are used to monitor execution and deviations trigger action plans
- Formal risk management procedures are part of the methodology
Project Management is managed, controlled and improved. Level 3 - Systematized is achieved and:
- The organization chooses the methodology that best suits, based on the project characteristics. E.g. agile for projects with uncertainty or waterfall for very stable contexts
- The methodology includes lesson learned techniques, such as post-mortem meetings
- KPIs that measure if the project outcomes met the project business goals are part of the methodology.
- When applicable projects are organized as programs to maximize benefits
12
Roles and ResponsibilitiesNo clear roles and responsibilities:
- No clear empowerment to a structure to manage the initiatives
Roles are assigned opportunistically:
- The Project Manager role is assigned consistently
Roles and responsibilities are well defined and ensure business alignment:
- The methodology includes a governance model that is communicated, and roles and responsibilities are clear
- The governance model includes roles at strategic level, to ensure alignment with business goals, such as a sponsor and/or steering
Project Management is strategic and specialized skills exist. Level 3 - Systematized is achieved and:
- A PMO exists and governs all aspects of project management
- Programs and portfolios are managed by a Program Manager
13
People and Talent
Talent Attraction/Retention
No strategy for recruitment and retention:
- Recruitment processes are poorly defined and tend to be long
- Turnover above industry/segment average
Fundamental practices are in place:
- Formal recruitment processes are in place
- Compensation strategies are aligned with the market and competitors
- Fringe benefits aligned with market and competitors are in place
- Adequate training programs are in place
- Adequate on-boarding procedures are in place
Talent is managed and developed:
- Periodic performance review and feedback session are in place
- Initiatives with academia are promoted such as trainee programs, presence in job fairs
- Active employer branding, such as presence in tech communities
People are a core value. Level 3 - Systematized is achieved and:
- Benchmarks are executed to support compensation strategies
- KPIs are used to monitor attraction and retention and deviations trigger action plans
- Succession plans are in place
- Exit risks assessments are in place
14
Team ManagementPoor or inexistent workforce organization:
- Poorly defined team structure
- Unclear roles and responsibilities
Basic team structures:
- There is a team structure with reasonably defined roles and responsibilities
- Basic supervision and leadership practices
Team management best practices are in place:
- Team organization model is aligned with the company context to maximize delivery, quality or knowledge management
- Regular team building initiatives occurs
- Training needs are adjusted to particular needs (e.g. inputs from 1:1 sessions or reviews)
People are a core value. Level 3 - Systematized is achieved and:
- People management or leadership training is provided to managerial roles
- Active coaching practices are in place
- Talent matrices are in place
15
Financials and EconomicsBudgetingPoor or inexistent planning:
- No annual (or periodic) planning
- Investments are mainly reactive to immediate needs
- Very low visibility or awareness about IT spending
Basic planning:
- Annual planning is in place
- Basic control and execution follow-up. E.g. only major capex or opex spending is monitored
Enterprise alignment:
- Annual planning is clearly aligned with the organization strategy
- Annual planning is co-shared between IT and business
- Time Driven ABC and/or Cost Allocation Keys are used to represent cost distribution across the organization, when applicable
- Detailed planning by the different spending categories is in place
Sector/market alignment. Level 3 - Systematized is achieved and:
- IT spending ratio (Total IT spending / Total Revenue (or Operating Margin)) is known, accurate and demonstrable
- IT spending market/competitors benchmarks are performed and are used for decision making
16
P&L ManagementLittle or no visibility over costs and revenues:
- IT spending is unclear or unknown
- IT is generally a cost center
- Spending/Investment decisions are made outside IT function
Some controlling practices are in place:
- Some level of detail on the spending nature (personnel costs, services, licensing etc.)
- Regular (monthly) costs and benefits monitoring and follow up
- Only costs/benefits under IT function are reported and monitored
The value of IT is clear:
- All IT spending is, including those outside of the IT function (direct on businesses), is reported and monitored by the IT function
- Decision making, takes P&L impact into consideration
- All forms of revenue (fees, cost allocation, services) are reported and monitored by the IT function
- The spending by nature is clearly detailed by at least: personnel costs, external professional services, licensing and subscriptions
Financial sustainability of IT. Level 3 - Systematized is achieved and:
- Capacity management practices are in place
- Contracts, license sizing and other volumes are reviewed to detect and eliminate waste
- IT function has positive operational margin
- Government and private innovation funding programs are followed and strategically exploited.
17
Sourcing and ProcurementPurchases and suppliers are poorly managed:
- Purchases are reactive and no procurement practices are in place
- Lack of a diverse, trusted network of suppliers
- No clear criteria for supplier selection
Basic practices are in place:
- Market consultations are executed, but no formal process is in place nor documented
- Basic decision criteria such as price or technical or functional coverage
Procurement is managed:
- Formal procedures exist and are documented, clearly defining decision making rules and workflows, levels of clearance and approval, suppliers qualification, definition of categories and its specifics
- Structure RFPs are conducted, including Tender Specifications documents with timelines, decision criteria, assumptions, rules of engagement and all elements relevant for a clear and transparent process
- Decision criteria include diverse, weighted, criteria, other than price and tech specs, such as suppliers business resilience, financial sustainability, ESG posture etc.
- Clear alignment between IT and company processes, when a global procurement structure outside of IT function exists
Procurement is for efficiency supported by ethics. Level 3 - Systematized is achieved and:
- Suppliers are assessed and evaluated based on company defined criteria
- Relevant categories (relevance criteria are defined) are subjected to periodic and mandatory/recommended RFP processes, for cost efficiency, innovation access and/or other defined criteria
- A Code of Conduct, for those involved in sourcing and/or procurement processes, is in place
18
Risk and ComplianceInfoSecSecurity is poorly addressed:
- Security risks are not managed
- Incident response is reactive and improvised
- Minimal technical controls are in place, such as anti-virus
Security practices are in place but are not managed nor controlled:
- Technical controls are implemented, such as Antivirus, firewall but poorly monitored
- Backups are implemented but not tested
- Some processes are in place, such as access management and asset management, but are not documented and are inconsistent
InfoSec is addressed in a managed and controlled:
- A documented and approved policy exists
- Adequate technical controls to prevent malicious code execution and network unauthorized access. E.g. Antivirus, firewall, email protection etc.
- MFA is implemented adequately, namely in external access using VPN
- Backup policy is implemented
- A documented Incident Response Plan, aligned with best-practices frameworks, exist and is regularly reviewed and tested
- Third-parties and supply chain risks are managed
- Awareness and training is provided to relevant staff and employees
- InfoSec risks are managed, using an approved company policy
- Asset management practices are in place
- Access management practices are in place, including periodic access reviews and privilege users and access
An ISMS is implemented, and security is a core value. Level 3 Systematized is achieved and:
- Policies are reviewed at least annually
- Audits are in place and corrective, preventive and improvement plans are implemented
- InfoSec KPIs are monitored and aligned with the organization strategy
19
Regulatory and ComplianceRegulatory and compliance risks are poorly managed:
- Regulatory risks are not monitored
- Responses are reactive
Regulatory and compliance is address but inconsistently:
- IT function monitors the most relevant and industry-specific compliance, impacting digital solutions
- Regulatory and compliance risks are managed in the context of new products or projects
Regulatory and compliance risk management is fully integrated across the organization:
- Close alignment between IT and Legal/Regulatory functions
- Personal data protection laws addressed and complied with
- Compliance is fully integrated across projects/product development and IT operations
Regulatory and compliance leverages business. Level 3 - Systematized is achieved and:
- Adherence to regulatory frameworks, especially those specific to the industry, is used as a competitive differentiator.
- Regulatory frameworks impacting the supply chain in which the organization operates are monitored and leveraged to gain competitive advantage
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100