| A | B | C | D | E | F | G | H | I | J | K | L | M | N | O | P | Q | R | S | T | U | V | W | X | Y | Z | |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
1 | ||||||||||||||||||||||||||
2 | ||||||||||||||||||||||||||
3 | Maturity Levels | AS-IS | TO-BE | |||||||||||||||||||||||
4 | Area of Control | Specific control | 1 -Ad-Hoc | 2 - Opportunistic | 3 - Systematized | 4 - Optimized | ||||||||||||||||||||
5 | Governance | Leadership | No evident ownership for IT: - Initiatives, projects and demands are deluded over areas/business lines - Decision process, regarding initiatives and investments, is not clear nor repeatable - Roles and responsibilities for IT are non-existent or not clear | Ownership of IT exists but it is not managed nor repeatable: - There may be roles & responsibilities for IT but are not empowered nor a mandate is always evident - Some initiatives are managed and mandated by a figure of IT leadership, but not all of them and there are not clear criteria do set the mandate - Decision process, regarding initiatives and investments, is applied occasionally but is not well defined nor repeatable | IT ownership is well defined: - Roles & responsibilities are clear, a specialized structure is in place - Decision process, regarding initiatives and investments, is clear and known to the whole organization - A clear mandate exists to lead, supervise and /or assess all initiatives and investments | IT ownership is well defined, and organizational models are reviewed and improved. Level 3 - Systematized is achieved and: -Organizational models are review and adjusted according to the needs of speed of delivery, innovation enablement, budgetary context and other criteria relevant to the organization current context | ||||||||||||||||||||
6 | Business alignment | No clear alignment: - IT initiatives and business objectives and not clearly related - IT initiatives occur typically to address or solve urgent issues - Inexistence of an IT roadmap | A request/response relation: - The relation between business lines and IT is purely transactional - Heavily based on a request/response model - An IT roadmap (planning) may exist, but the scope of the roadmap does not cover all the initiatives - The IT roadmap is mainly a backlog of business requests | IT is also a contributor: -IT is consulted when business solution are designed - IT is informed about business problems and challenges - IT has a business immersion posture. IT has a deep knowledge of the business, its customers, context and business culture. IT solutions are designed and built considering all these inputs | IT as a business partner. Level 3 - Systematized is achieved and: - An IT roadmap exists and contains IT sustainability initiatives such as infrastructure/application modernization and technical debt reduction - IT helps create and deliver digital products or digital components to the company, if applicable - IT enables and facilitates the adoption or understanding of existent/new/emerging technologies to business. E.g. proactively delivering PoC or MVP of products or features | |||||||||||||||||||||
7 | IT Operation | Processes | Processes are not managed: - No practices in place. Execution is mainly supported by empiric knowledge of the current context - Processes are not documented - Interventions are typically reactions to incidents | Practices are in place but not managed/repeatable: - There are defined practices in place, but are not documented - Low level or inexistence of measurement techniques, such as KPIs or SLAs - Lack of proactive monitoring processes to prevent and anticipate disruptions | Processes are managed: - There is a well-defined catalog of services available and the practices are documented; - There are in place quality, efficiency and effectiveness measurements such as SLAs, KPIs and others - IT support operations are aligned with business needs, such as operating hours and geographical coverage - Monitoring practices and tools are available to prevent disruptions, and cover a vast part of the IT operations landscape | Best practices are in place. Level 3 - Systematized is achieved and: - Practices are aligned with best-in-class frameworks, such as ITIL, ISO standards or other similar - Processes and documentation are audited, at least yearly and CAPA plans are executed - Business alignment is reviewed at least yearly or when relevant business events occur, such as expansions, new products, M&A etc. | ||||||||||||||||||||
8 | Continuous Improvement | Improvement is not addressed: - Improvement initiatives rarely occur normally are a reaction to a severe incident - Implemented measures do not become permanent and the context usually revert to the previous scenario | Improvement practices exist but are not sustained: - Lessons learned are taken from incidents and mitigation Ans contingency measures are implemented, but inconsistently - Improvement opportunities when detected are implemented, but inconsistently - Implemented measures became permanent, but inconsistently | Improvement is managed and sustained: - Improvement opportunities are assed in terms of cost/benefit - Root cause analysis techniques, such as 5 Why's, are applied - There are in place target values for KPIs and SLAs and deviations trigger improvement plans - There is a formal procedure for lesson learned after an incident response | Continuous improvement is a mindset. Level 3 - Systematized is achieved and: - Continuous improvement programs are in place, using best-in class frameworks such as Kaizen, Lean IT, PDCA and others - A benefit tracker is maintained, quantifying gains and benefits, such as cost savings, quality improvements, customer satisfaction and others | |||||||||||||||||||||
9 | Development/Product | Software Development | Software is built/modified without control: - Teams/staff builds or applies changes to software with little or no change or quality control - No defined or approved architecture/pattern by organization is in place | Minimum practices are in place: - Source code is versioned and protected against unauthorized access - Some level of quality control or testing is executed before deploying to production - Segregated development and production environments exists: - Deployments to production are controlled and followed-up (hyper care) | A controlled and managed SDLC is in place: - Requirements are managed - DEV/QA/PROD environments exist and are segregated - Quality Assurance practices are in place - Change Management best practices are in place including approval and documenting - Anomalies are documented and fully integrated on QA processes - Source code is versioned, protected and be tracked to releases/versions - An handover process from development to operations is defined | Software is an engineering process. Level 3 - Systematized is achieved and: - The SDLC is documented and can be used for onboarding/training - DevOps principles are in place (automation) - Engineering roles are well defined - QA, Dev and Ops KPIs exist, are monitored and deviations trigger improvement plans - Code reviews are executed - Audit procedures are in place | ||||||||||||||||||||
10 | Innovation | IT basically reacts: - IT acts reactively and is mostly focused on operational problems - Few or no new ideas are IT originated | Innovation initiatives exist, but are not consistent: - Initiatives are usually led by single, top talent contributors - Some experimentation of new technologies - There is an interest in process improvement | Innovation is structured: - Processes and procedures to identify and test opportunities are in place - Emerging technologies are evaluated and selectively adopted - Initiatives are co-shared between IT and business | Innovation is strategic pillar: - open innovation initiatives are in place. E.g. involvement with academia, start-ups environment etc. - IT leads initiatives - Willingness to be an early/first adopter | |||||||||||||||||||||
11 | Project/Portfolio Management | Methodology | Initiatives are executed not managed: - Initiatives have no clear scope, budget and timeline | Initiatives are managed as projects, in an unstructured way: - The project objectives are defined and are communicated - A minimum baseline of ceremonies exist, such as kickoff, status and closure meetings - A minimum baseline of documentation exists such as meeting minutes and a project charter or vision scope | There is a formal approach to project management: - The organization has a formal and documented methodology - Project ceremonies and supporting tools are well defined and documented - KPIs and measures are used to monitor execution and deviations trigger action plans - Formal risk management procedures are part of the methodology | Project Management is managed, controlled and improved. Level 3 - Systematized is achieved and: - The organization chooses the methodology that best suits, based on the project characteristics. E.g. agile for projects with uncertainty or waterfall for very stable contexts - The methodology includes lesson learned techniques, such as post-mortem meetings - KPIs that measure if the project outcomes met the project business goals are part of the methodology. - When applicable projects are organized as programs to maximize benefits | ||||||||||||||||||||
12 | Roles and Responsibilities | No clear roles and responsibilities: - No clear empowerment to a structure to manage the initiatives | Roles are assigned opportunistically: - The Project Manager role is assigned consistently | Roles and responsibilities are well defined and ensure business alignment: - The methodology includes a governance model that is communicated, and roles and responsibilities are clear - The governance model includes roles at strategic level, to ensure alignment with business goals, such as a sponsor and/or steering | Project Management is strategic and specialized skills exist. Level 3 - Systematized is achieved and: - A PMO exists and governs all aspects of project management - Programs and portfolios are managed by a Program Manager | |||||||||||||||||||||
13 | People and Talent | Talent Attraction/Retention | No strategy for recruitment and retention: - Recruitment processes are poorly defined and tend to be long - Turnover above industry/segment average | Fundamental practices are in place: - Formal recruitment processes are in place - Compensation strategies are aligned with the market and competitors - Fringe benefits aligned with market and competitors are in place - Adequate training programs are in place - Adequate on-boarding procedures are in place | Talent is managed and developed: - Periodic performance review and feedback session are in place - Initiatives with academia are promoted such as trainee programs, presence in job fairs - Active employer branding, such as presence in tech communities | People are a core value. Level 3 - Systematized is achieved and: - Benchmarks are executed to support compensation strategies - KPIs are used to monitor attraction and retention and deviations trigger action plans - Succession plans are in place - Exit risks assessments are in place | ||||||||||||||||||||
14 | Team Management | Poor or inexistent workforce organization: - Poorly defined team structure - Unclear roles and responsibilities | Basic team structures: - There is a team structure with reasonably defined roles and responsibilities - Basic supervision and leadership practices | Team management best practices are in place: - Team organization model is aligned with the company context to maximize delivery, quality or knowledge management - Regular team building initiatives occurs - Training needs are adjusted to particular needs (e.g. inputs from 1:1 sessions or reviews) | People are a core value. Level 3 - Systematized is achieved and: - People management or leadership training is provided to managerial roles - Active coaching practices are in place - Talent matrices are in place | |||||||||||||||||||||
15 | Financials and Economics | Budgeting | Poor or inexistent planning: - No annual (or periodic) planning - Investments are mainly reactive to immediate needs - Very low visibility or awareness about IT spending | Basic planning: - Annual planning is in place - Basic control and execution follow-up. E.g. only major capex or opex spending is monitored | Enterprise alignment: - Annual planning is clearly aligned with the organization strategy - Annual planning is co-shared between IT and business - Time Driven ABC and/or Cost Allocation Keys are used to represent cost distribution across the organization, when applicable - Detailed planning by the different spending categories is in place | Sector/market alignment. Level 3 - Systematized is achieved and: - IT spending ratio (Total IT spending / Total Revenue (or Operating Margin)) is known, accurate and demonstrable - IT spending market/competitors benchmarks are performed and are used for decision making | ||||||||||||||||||||
16 | P&L Management | Little or no visibility over costs and revenues: - IT spending is unclear or unknown - IT is generally a cost center - Spending/Investment decisions are made outside IT function | Some controlling practices are in place: - Some level of detail on the spending nature (personnel costs, services, licensing etc.) - Regular (monthly) costs and benefits monitoring and follow up - Only costs/benefits under IT function are reported and monitored | The value of IT is clear: - All IT spending is, including those outside of the IT function (direct on businesses), is reported and monitored by the IT function - Decision making, takes P&L impact into consideration - All forms of revenue (fees, cost allocation, services) are reported and monitored by the IT function - The spending by nature is clearly detailed by at least: personnel costs, external professional services, licensing and subscriptions | Financial sustainability of IT. Level 3 - Systematized is achieved and: - Capacity management practices are in place - Contracts, license sizing and other volumes are reviewed to detect and eliminate waste - IT function has positive operational margin - Government and private innovation funding programs are followed and strategically exploited. | |||||||||||||||||||||
17 | Sourcing and Procurement | Purchases and suppliers are poorly managed: - Purchases are reactive and no procurement practices are in place - Lack of a diverse, trusted network of suppliers - No clear criteria for supplier selection | Basic practices are in place: - Market consultations are executed, but no formal process is in place nor documented - Basic decision criteria such as price or technical or functional coverage | Procurement is managed: - Formal procedures exist and are documented, clearly defining decision making rules and workflows, levels of clearance and approval, suppliers qualification, definition of categories and its specifics - Structure RFPs are conducted, including Tender Specifications documents with timelines, decision criteria, assumptions, rules of engagement and all elements relevant for a clear and transparent process - Decision criteria include diverse, weighted, criteria, other than price and tech specs, such as suppliers business resilience, financial sustainability, ESG posture etc. - Clear alignment between IT and company processes, when a global procurement structure outside of IT function exists | Procurement is for efficiency supported by ethics. Level 3 - Systematized is achieved and: - Suppliers are assessed and evaluated based on company defined criteria - Relevant categories (relevance criteria are defined) are subjected to periodic and mandatory/recommended RFP processes, for cost efficiency, innovation access and/or other defined criteria - A Code of Conduct, for those involved in sourcing and/or procurement processes, is in place | |||||||||||||||||||||
18 | Risk and Compliance | InfoSec | Security is poorly addressed: - Security risks are not managed - Incident response is reactive and improvised - Minimal technical controls are in place, such as anti-virus | Security practices are in place but are not managed nor controlled: - Technical controls are implemented, such as Antivirus, firewall but poorly monitored - Backups are implemented but not tested - Some processes are in place, such as access management and asset management, but are not documented and are inconsistent | InfoSec is addressed in a managed and controlled: - A documented and approved policy exists - Adequate technical controls to prevent malicious code execution and network unauthorized access. E.g. Antivirus, firewall, email protection etc. - MFA is implemented adequately, namely in external access using VPN - Backup policy is implemented - A documented Incident Response Plan, aligned with best-practices frameworks, exist and is regularly reviewed and tested - Third-parties and supply chain risks are managed - Awareness and training is provided to relevant staff and employees - InfoSec risks are managed, using an approved company policy - Asset management practices are in place - Access management practices are in place, including periodic access reviews and privilege users and access | An ISMS is implemented, and security is a core value. Level 3 Systematized is achieved and: - Policies are reviewed at least annually - Audits are in place and corrective, preventive and improvement plans are implemented - InfoSec KPIs are monitored and aligned with the organization strategy | ||||||||||||||||||||
19 | Regulatory and Compliance | Regulatory and compliance risks are poorly managed: - Regulatory risks are not monitored - Responses are reactive | Regulatory and compliance is address but inconsistently: - IT function monitors the most relevant and industry-specific compliance, impacting digital solutions - Regulatory and compliance risks are managed in the context of new products or projects | Regulatory and compliance risk management is fully integrated across the organization: - Close alignment between IT and Legal/Regulatory functions - Personal data protection laws addressed and complied with - Compliance is fully integrated across projects/product development and IT operations | Regulatory and compliance leverages business. Level 3 - Systematized is achieved and: - Adherence to regulatory frameworks, especially those specific to the industry, is used as a competitive differentiator. - Regulatory frameworks impacting the supply chain in which the organization operates are monitored and leveraged to gain competitive advantage | |||||||||||||||||||||
20 | ||||||||||||||||||||||||||
21 | ||||||||||||||||||||||||||
22 | ||||||||||||||||||||||||||
23 | ||||||||||||||||||||||||||
24 | ||||||||||||||||||||||||||
25 | ||||||||||||||||||||||||||
26 | ||||||||||||||||||||||||||
27 | ||||||||||||||||||||||||||
28 | ||||||||||||||||||||||||||
29 | ||||||||||||||||||||||||||
30 | ||||||||||||||||||||||||||
31 | ||||||||||||||||||||||||||
32 | ||||||||||||||||||||||||||
33 | ||||||||||||||||||||||||||
34 | ||||||||||||||||||||||||||
35 | ||||||||||||||||||||||||||
36 | ||||||||||||||||||||||||||
37 | ||||||||||||||||||||||||||
38 | ||||||||||||||||||||||||||
39 | ||||||||||||||||||||||||||
40 | ||||||||||||||||||||||||||
41 | ||||||||||||||||||||||||||
42 | ||||||||||||||||||||||||||
43 | ||||||||||||||||||||||||||
44 | ||||||||||||||||||||||||||
45 | ||||||||||||||||||||||||||
46 | ||||||||||||||||||||||||||
47 | ||||||||||||||||||||||||||
48 | ||||||||||||||||||||||||||
49 | ||||||||||||||||||||||||||
50 | ||||||||||||||||||||||||||
51 | ||||||||||||||||||||||||||
52 | ||||||||||||||||||||||||||
53 | ||||||||||||||||||||||||||
54 | ||||||||||||||||||||||||||
55 | ||||||||||||||||||||||||||
56 | ||||||||||||||||||||||||||
57 | ||||||||||||||||||||||||||
58 | ||||||||||||||||||||||||||
59 | ||||||||||||||||||||||||||
60 | ||||||||||||||||||||||||||
61 | ||||||||||||||||||||||||||
62 | ||||||||||||||||||||||||||
63 | ||||||||||||||||||||||||||
64 | ||||||||||||||||||||||||||
65 | ||||||||||||||||||||||||||
66 | ||||||||||||||||||||||||||
67 | ||||||||||||||||||||||||||
68 | ||||||||||||||||||||||||||
69 | ||||||||||||||||||||||||||
70 | ||||||||||||||||||||||||||
71 | ||||||||||||||||||||||||||
72 | ||||||||||||||||||||||||||
73 | ||||||||||||||||||||||||||
74 | ||||||||||||||||||||||||||
75 | ||||||||||||||||||||||||||
76 | ||||||||||||||||||||||||||
77 | ||||||||||||||||||||||||||
78 | ||||||||||||||||||||||||||
79 | ||||||||||||||||||||||||||
80 | ||||||||||||||||||||||||||
81 | ||||||||||||||||||||||||||
82 | ||||||||||||||||||||||||||
83 | ||||||||||||||||||||||||||
84 | ||||||||||||||||||||||||||
85 | ||||||||||||||||||||||||||
86 | ||||||||||||||||||||||||||
87 | ||||||||||||||||||||||||||
88 | ||||||||||||||||||||||||||
89 | ||||||||||||||||||||||||||
90 | ||||||||||||||||||||||||||
91 | ||||||||||||||||||||||||||
92 | ||||||||||||||||||||||||||
93 | ||||||||||||||||||||||||||
94 | ||||||||||||||||||||||||||
95 | ||||||||||||||||||||||||||
96 | ||||||||||||||||||||||||||
97 | ||||||||||||||||||||||||||
98 | ||||||||||||||||||||||||||
99 | ||||||||||||||||||||||||||
100 | ||||||||||||||||||||||||||