Advisory & assurance

An independent evaluation of where you actually stand.

A four to six week programme that examines your process, your technology, your AI readiness, your security posture and your leadership alignment — and hands you a written report with the reasoning attached.

It is deliberately uncomfortable reading in places. That is the point: you are paying for an opinion that is not coming from the people who want the next project.

4–6 weeksTechnology and leadership Pay when satisfiedNo strings attached
The deal

You pay once you are satisfied

You settle the invoice after you have read the report and you are satisfied with what it found. Not before.

  • Sixteen areas examined, or a scoped subset if that is what you need
  • Every finding carries its evidence and our reasoning
  • Strengths reported as plainly as weaknesses
  • Written so another supplier could act on it — no lock-in
  • No obligation to engage us for any of the remediation
Start with a free hour

The first conversation is free and carries no commitment.

The uncomfortable industry numbers

It is almost never the engineering that fails.

It is the system around it: leadership gaps meeting execution gaps, strategy that stays in PowerPoint, teams building without direction, and AI hype standing in for AI strategy. These are not fringe problems — they are the industry norm.

70%of digital transformations failMcKinsey
68%of IT projects run over budgetStandish Group, CHAOS report
~50%of leaders have no clear AI strategyMIT Sloan, 2024
40%of enterprise apps will feature task-specific AI agents by 2026, up from under 5% in 2025Gartner

Figures as cited by their publishers. We quote them because they match what we see, not to sell fear — the same reports show what the successful minority do differently.

Our methodology

We do not just listen. We work inside the flow.

Most reviews are conducted from a meeting room: interviews, a document request, a survey. You get an accurate account of what people believe happens. We take real work through your actual process — your tools, your approvals, your constraints — and simulate exactly how your teams operate. Friction you have experienced yourself is very hard to argue with, and impossible to overlook.

The Aitina evaluation method A six-stage cycle: participate in the flow, observe the real path, listen to each side separately, execute the steps ourselves, gather evidence from your systems of record, then benchmark the findings against established industry frameworks — and repeat for the next area. 01Participate02Observe03Listen04Execute05Evidence06Benchmark HOW WE GATHER IT We work inside the flow not outside it, asking about it
01ParticipateWe join the flow

We do not sit outside the process asking about it. We take real work items through your actual workflow, with your tools, your approvals and your constraints — simulating exactly how your teams operate.

02ObserveWe watch the real path

What the process does under load, at handoffs, and on the cases nobody designed for. The documented flow and the real flow are rarely the same, and the gap between them is usually where the cost is.

03ListenSeparately, and to both sides

The people doing the work, the people managing it and the people describing it to the board are interviewed separately. Where their accounts diverge is a finding in itself.

04ExecuteWe feel the friction ourselves

We run the steps rather than reading about them. A handoff that takes four days is an abstraction in a report and a fact when it happens to you. This is the part most reviews skip.

05EvidenceNumbers, not impressions

Everything observed is backed out of your own systems of record — cycle times, volumes, error and rework rates, cost per case. Opinion becomes arithmetic, and arithmetic survives a board meeting.

06BenchmarkMapped to the industry

Findings are placed against established frameworks and industry data — PMI, PRINCE2, TOGAF, DORA, Team Topologies, Scaling Up — so you can see not just what is happening, but how far it sits from the standard.

The cycle repeats per area under review. What is learned benchmarking one process sharpens how we participate in the next — which is why a six-week programme surfaces more in week five than in week one.

What it examines

Sixteen areas, across four dimensions.

Most reviews look only at technology, which is why most of them miss the actual problem. Process, leadership alignment and how AI is really being used matter at least as much, and they are where the expensive surprises hide.

Process & delivery

Process gapsWhere work stalls, doubles back or depends on one person knowing something nobody wrote down.
Documentation gapsWhat exists, what is out of date, and what only lives in someone's head — the single biggest key-person risk in most organisations.
Productivity matrixOutput measured against effort, team by team, so improvement can be argued from numbers rather than impressions.
Micro-management problemsWhere decision-making has drifted upward, what it costs in cycle time, and which approvals could safely be delegated.

Technology & architecture

Tech stack competitivenessA standard matrix scoring your stack against what comparable organisations are running, and what your choices will cost you in three years.
Architecture adviceAn independent read on the design: what will scale, what will not, and what should be replaced before it becomes the reason a project slips.
Security problemsPosture, exposure, access management, dependency risk and the gaps that would be found by someone less friendly than us.
ISO certification distanceHow far you actually are from ISO 27001 or ISO 9001, control by control, and a realistic timeline rather than an optimistic one.

AI readiness

AI readiness assessmentWhether your data, processes and people can support AI in production — and, just as usefully, where they cannot yet.
Usage of AI toolsWhat your teams are actually using, what it is costing, what is duplicated, and where it is creating risk nobody has assessed.
Where AI pays backThe specific processes worth automating, ranked, and the ones that should be simplified or deleted instead.
Governance and evidenceWhat an auditor or a risk committee will ask about your AI systems, and whether you can currently answer.

Leadership & alignment

CEO vision driftThe distance between the strategy as stated at the top and the work as it is actually being done. Usually the most uncomfortable finding, and the most valuable.
Team and key-person riskWho genuinely holds the knowledge, what happens if they leave, and whether the organisation can grow into the plan.
Vendor and outsourcing reviewWhether your suppliers are delivering what the contract says, measured rather than assumed — including us.
Cost and unit economicsWhat it costs to serve a customer today, and what that curve looks like at ten times the volume.
How it runs

Four to six weeks, mostly spent listening.

Light on your calendar — typically two to four hours per role involved, spread across the programme, plus read-only access for the evidence.

1

Scope and access

We agree what the report has to answer and for whom. Read-only access to the systems and calendar time with the people who do the work. A vague scope produces a report nobody acts on, so this week is deliberately specific.

2

Evidence

Interviews, system review, code and cloud inspection, document review and the numbers from your own systems of record. Most of it is spent listening to the people doing the work, because that is where the real process lives.

3

Analysis

Findings are written up with the evidence attached and graded by severity and by effort to fix. Anything we are not confident about is marked as such rather than rounded up into certainty.

4

Report and walkthrough

You get the written report, a ranked findings register, a remediation estimate and a session to walk your board or leadership team through it. Then you decide whether you are satisfied.

Week 1 Scope and access · Weeks 2–3 Evidence · Weeks 3–5 Analysis · Weeks 4–6 Report and walkthrough

On project management

It is not only about day-to-day tasks and checking timesheets.

Project management is one of the most underestimated disciplines in our industry, and most organisations reduce it to administration — status updates, Gantt charts, timesheet approval. That is where execution dies.

The discipline has four classical pillars: planning, organising, leading and controlling. The science of it is well documented — PMI gives us the PMBOK, PRINCE2 gives us governance, agile frameworks give us adaptability. The art is harder: influence, communication, stakeholder navigation, and the instinct to unblock what the metrics cannot see. Both are learnable. Mastering both is what moves delivery from adequate to exceptional.

When an organisation gives the discipline the weight it deserves — proper training, proper authority, proper respect — execution transforms and everything downstream strengthens. When it treats it as coordination, the execution gap widens and no framework rescues it.

Frameworks we assess against
PMI / PMBOKPRINCE2TOGAFSAFeDADDORA metricsFlow metricsScaling UpOKRsWardley MapsTeam TopologiesConway's LawValue stream mappingADRs

Everything is grounded in practice rather than the textbook. We have watched most of these frameworks meet real organisations and break in specific, repeatable ways — and that is the useful part.

“Strategy without execution is a hallucination. Execution without strategy is just expensive chaos.”

The questions

The questions nobody in the building will ask out loud.

Technology reviews are the easy half. The findings that change a company are usually about how it is run — and they are the ones your own people have the least freedom to raise. These are the 20 we are asked about most, grouped by where the friction sits.

The Clarity Gap

Vision & strategy

Strategy that never reaches the engineering floor, and a vision the organisation has quietly drifted away from.

4 questions
01

Does our strategy survive contact with the engineering floor?

The problem

Brilliant strategies die in execution, and the strategy is rarely the problem — the translation layer between the boardroom and the people building is. Decks are written, presented, applauded and never referred to again, because nothing in them tells an engineer what to do differently on Monday.

What we bring

We follow the strategy down through the organisation and find where it stops being actionable. Then we rebuild that translation layer so the intent survives the journey.

02

Are we drifting from the vision we set?

The problem

Vision drift is gradual and nobody announces it. Priorities get added, none get removed, and eighteen months later the work being done is a reasonable-looking set of activities that no longer adds up to the thing you set out to build.

What we bring

We compare the vision as stated at the top with the work actually in flight, and quantify the distance. It is usually the most uncomfortable finding in the report, and the one that changes the most.

03

Do our OKRs change behaviour, or just get written down?

The problem

OKRs fail in a predictable way: objectives that are really projects, key results that are really tasks, and a quarterly ritual producing a document nobody consults in week five. The framework gets blamed; the implementation was the problem.

What we bring

We review how yours are set, cascaded and measured, then fix the mechanics — outcome-shaped objectives, key results somebody can actually move, and a cadence that surfaces bad news early rather than at quarter end.

04

Can we each explain why we are building this?

The problem

Ask five people in different functions why a given initiative exists and count how many answers you get. Where there is no shared why, there are no shared success metrics, and every prioritisation argument becomes a matter of seniority rather than evidence.

What we bring

We run that exact test, then work with you on the decision framework that settles those arguments without escalating every one of them to you.

The Execution Gap

Management & execution

Good plans, poor delivery — and a project management discipline that has been reduced to administration.

5 questions
05

Are we treating project management as administration?

The problem

Most organisations reduce project management to status updates, Gantt charts and timesheet approval — and then wonder why delivery does not improve. Planning, organising, leading and controlling are the four classical pillars of the discipline. Strip out leading and controlling and what remains is coordination, which cannot fix anything.

What we bring

We assess the PM function against the full discipline, not the administrative residue of it: the science (PMI, PRINCE2, agile governance) and the art (influence, stakeholder navigation, unblocking what the metrics cannot see).

06

Are we agile, or running waterfall with standups?

The problem

The ceremonies are in place, the board is groomed, and the release still lands in one large batch six months late. Adopting the vocabulary of a delivery method without adopting its feedback loops is one of the most common and most expensive patterns in the industry.

What we bring

We measure what is actually happening — batch size, cycle time, deployment frequency, change failure rate — using DORA and flow metrics rather than self-assessment, and show you where the loop is open.

07

Are we working on big rocks, or on gravel?

The problem

The few initiatives that would genuinely change the trajectory keep slipping, because the calendar filled with urgent small things first. Everyone is busy, utilisation looks excellent, and the strategy has not moved in three quarters.

What we bring

We identify the actual big rocks — usually three, never eleven — and show you what is consuming the capacity they need. That conversation is uncomfortable, because the gravel is always somebody's priority.

08

Is our PMO helping delivery, or reporting on it?

The problem

A PMO that has drifted into status collection adds cost to every project and removes risk from none. The reports are accurate, beautifully formatted, and arrive after the decision they were meant to inform.

What we bring

We assess what your PMO measures against what your delivery teams need, and reshape it toward what genuinely helps: dependency management, honest capacity, and escalation that reaches a decision-maker in time.

09

Am I micro-managing, or is my team under-owning?

The problem

Genuinely hard to tell from the inside, and the two look identical on a Tuesday. A leader pulled into detail concludes the team cannot be trusted; a team whose decisions keep being overturned concludes there is no point deciding. Both read the same evidence and reach opposite conclusions, and the loop tightens.

What we bring

We interview both sides separately and map where decisions actually get made against where the org chart says they should. The answer is usually specific and fixable — three or four decision types sitting one level too high.

Design that has to outlive the plan

Architecture & technology

Whether the system you have can carry the strategy you have written.

4 questions
10

Will this architecture still be right in two years?

The problem

Architecture decisions are cheap to make and expensive to reverse, and the cost of the wrong one usually lands at exactly the moment the business can least afford it — the quarter growth finally arrives.

What we bring

An independent read on the design: what will scale, what will not, what should be replaced before it becomes the reason a project slips, and what is fine despite looking untidy. With the reasoning shown, so you can disagree.

11

Is our org chart designing our system?

The problem

Conway's Law is not a theory, it is an observation: your architecture will mirror your communication structure whether you plan for it or not. Teams that cannot talk to each other build services that cannot either.

What we bring

We look at team topology and system topology together, because changing one without the other does not hold. Often the cheapest architectural fix is an organisational one.

12

How competitive is our stack, honestly?

The problem

It is difficult to judge your own stack from inside it. What felt modern at adoption may now be a hiring problem, a licensing problem, or a ceiling you will hit at the next scale step.

What we bring

A standard matrix scoring your stack against what comparable organisations are running, plus what your current choices will cost you over three years in licence, hiring and migration terms.

13

Where would somebody less friendly than us get in?

The problem

Security debt accumulates silently: access that was never revoked, dependencies nobody owns, a staging environment with production data. None of it shows up in a feature roadmap.

What we bring

Posture, exposure, access management and dependency risk assessed against what an auditor or an attacker would actually look for — and how far that leaves you from ISO 27001.

The Growth Gap

Scale & growth

What worked at fifty people breaking at five hundred — in process and culture as much as in code.

3 questions
14

What worked at fifty — will it work at five hundred?

The problem

Scaling breaks architecture, process and culture at different rates, and organisations usually only budget for the first. The elegant microservices do not help if nobody has clear objectives and strategy is defined in one room and executed in another.

What we bring

We assess all three dimensions together and tell you which will break first at your growth rate. Fixing the code while ignoring leadership and process is the most common way scaling programmes fail.

15

Are we a victim of our own silos?

The problem

Every department is hitting its own targets and the company as a whole is still slow. That is the signature of local optimisation: teams rewarded for their own numbers, handoffs owned by nobody, and the same customer request touched by four functions that never speak. From inside each silo, everything looks fine.

What we bring

We map the value stream end to end, across the department boundaries rather than within them, and show you where the work actually waits. The bottleneck is usually not in any one team — it is in the space between them.

16

Is our flywheel actually turning?

The problem

A flywheel only compounds if each turn makes the next one cheaper. Most organisations have the shape of one — acquire, deliver, learn, improve — without the connection: what is learned in delivery never reaches sales, what sales promises never reaches engineering, and every cycle costs what the last one did.

What we bring

We trace the loop and find where it is broken, then work out what has to be captured, and by whom, for the next turn to cost less — which is also the foundation for anything useful you want to do with AI.

The AI Trap

AI readiness

Layering AI on top of foundations that have not been fixed.

4 questions
17

Are we building AI on a cracked foundation?

The problem

You would not build a skyscraper on a cracked foundation, but that is exactly what happens when an organisation chases AI headlines before addressing its systemic gaps. AI without strategy is expensive experiments; AI without governance is a compliance problem; AI without architecture is technical debt at scale.

What we bring

We assess AI readiness against the gaps we find elsewhere in the review, because the two are not separable. Sometimes the honest recommendation is to fix the foundation for two quarters first.

18

Do we actually know what AI tools our teams are using?

The problem

Shadow AI adoption is near-universal and rarely measured. Individual subscriptions, company data pasted into consumer tools, three teams paying for overlapping products, and no view of any of it at board level.

What we bring

We inventory what is genuinely in use, what it costs in aggregate, what is duplicated, and where it is creating a data or compliance exposure nobody has assessed.

19

Could we prove how our AI systems behave?

The problem

The question a risk committee or an auditor will ask is not whether the model is clever. It is which version answered, on what data, who reviewed it, and how you know behaviour has not regressed since last month.

What we bring

We check whether you can answer: model and prompt versioning, evaluation sets, retention and PII policy, human review points and decision logging. Usually the gap is documentation rather than engineering.

20

Where does AI genuinely pay back for us?

The problem

The processes people most want to automate are frequently the wrong ones — too variable, too low-volume, or existing only because of a policy nobody has revisited. Meanwhile the unglamorous high-volume process nobody mentions would pay for the whole programme.

What we bring

We rank candidate processes by volume, cycle time, error cost and stability, and say plainly which should be automated, which simplified, and which deleted.

Every one of these sits inside the programme. If one of them is the reason you are reading this page, we can scope the engagement around it.

Talk it through, free
Why you can believe it

An audit is only worth what its independence is worth.

Six commitments that make this report usable in a board pack rather than filed and forgotten.

We audit ourselves too

If you have outsourced work to our own delivery team, our Audit & Compliance function does not go soft on it. The report names what is working and what needs to improve, on our work as readily as on anyone else's. A review that only ever flatters the reviewer is worth nothing to you.

Reasoning, not verdicts

Every finding carries the evidence and the reasoning behind it. You are free to disagree with our conclusion — you should be able to see exactly how we got there. Credibility is the entire product here, and unexplained assertions destroy it.

Both sides of the ledger

The report says what is genuinely good as clearly as it says what is broken. Sugar-coating wastes your money; so does a report written to look thorough by finding fault everywhere.

You pay when you are satisfied

You settle the invoice once you have the report and you are satisfied with the findings. If it does not tell you something you did not already know, that conversation is ours to have, not yours.

Tailored to your question

The sixteen areas above are the full programme. If only four of them matter to you, we scope it to four and price it accordingly.

No strings attached

The programme is not a route into a delivery contract. There is no obligation to engage us for the remediation, and the report is written so that another supplier could act on it.

Straight answers

Questions we get asked

What does it cost?

It is scoped to what you need examined, so the price depends on the number of areas and the size of the estate. The free hour is where we establish that, and you will have a fixed figure before anything starts. You then settle it once you have the report and you are satisfied with the findings.

What if we have already outsourced development to you?

Then your own delivery work is inside the scope, and our Audit and Compliance function reviews it on the same terms as anything else. We would rather tell you about a problem in our own work than have you find it later - and a review that cannot criticise the reviewer is not a review.

Will this turn into a sales pitch for a bigger project?

No. The report is written so that another supplier could act on it, and there is no obligation to engage us for any of the remediation. If the right answer is to fix something in-house or to keep your current supplier, that is what it will say.

How much of our team's time does it take?

Typically two to four hours per role involved, spread across the four to six weeks, plus read-only access to the relevant systems. We work around operational peaks rather than through them.

Can you sign an NDA?

Yes, before anything begins. Say so when you book the first conversation and we will have one in place beforehand.

What do we actually receive?

A written report, a findings register graded by severity and by effort to fix, a remediation estimate, and a session to walk your board or leadership team through it. All of it yours, in editable formats, to use however you like.

Start here

One free hour. No pitch, no obligation.

Bring the problem you are stuck on — an integration that keeps breaking, a cloud bill nobody can explain, an AI project that is all demo and no product, or a platform you are about to invest in. You will leave with a straight answer and a written summary, whether or not you ever work with us.

  • Architecture and integration review
  • AI feasibility — what will actually work, and what will not
  • AWS, Azure and Google Cloud cost and design
  • Business process audit and ISO readiness
  • Technical due diligence before you invest or acquire