← Back to blog

Maturity assessment framework: a UK practitioner's guide

August 8, 2026
Maturity assessment framework: a UK practitioner's guide

A maturity assessment framework is a structured, evidence-based method for measuring an organisation's current capability across defined domains and producing a prioritised roadmap for improvement. If you are trying to benchmark where your organisation stands, build a case for investment, or satisfy a regulator that your processes are under control, this is the tool that makes that conversation concrete.

Three reference points anchor most serious work in this space:

  • CMM/SEI (Capability Maturity Model, Software Engineering Institute): the originating five-level model that shaped virtually every framework that followed; GOV.UK Data Maturity Assessment for Government: the UK public sector's matrix-style toolkit, structured around four levels (Emerging to Leading); ISO/IEC 33004: the international standard governing how process assessment and maturity models should be constructed.
  • Run one well and you get three things immediately: a baseline benchmark across your chosen domains, a prioritised improvement roadmap grounded in evidence, and documented assurance output you can put in front of a board or auditor.

A maturity assessment framework does not tell you how good you are in absolute terms. It tells you where you are on a defined scale, which gaps matter most, and what to fix next. That distinction is what separates a useful assessment from a box-ticking exercise.


Key takeaways

A maturity assessment framework delivers value only when it produces a prioritised, evidence-backed improvement roadmap, not just a score.

PointDetails
Start with level descriptorsWrite observable, evidenced descriptors for each domain before designing questions.
Use a matrix, not a single scoreReport maturity by domain and theme; a single aggregated number hides the variation that drives decisions.
Digitise from the first cycleEvidence-attached, repeatable digital assessments are auditable and far faster to re-run than spreadsheets.
Align to UK standardsReference GOV.UK DMA, ISO/IEC 33004, and sector toolkits to give your framework credibility with regulators and auditors.
Intelligentassessments for continuous assuranceIntelligentassessments provides weighted RAG scoring, evidence management, template libraries, and automated reporting for regulated UK organisations running ongoing maturity programmes.

Table of Contents

What a maturity assessment framework actually is

The term covers two related but distinct things: the model (the scale, the domains, the level descriptors) and the assessment process (how you collect evidence, score responses, validate findings, and report). Conflating them is one of the most common mistakes practitioners make. You can have a well-designed model and a sloppy process, and the output will be unreliable regardless.

A maturity model defines an ordinal progression, typically five levels, from reactive or ad hoc practice through to optimised, continuously improving capability. The assessment process is the structured activity that places your organisation at a point on that scale, domain by domain.

Where organisations use maturity assessment frameworks:

  • Benchmarking current capability before a transformation programme
  • Regulatory and assurance submissions (demonstrating process control to Ofwat, the FCA, NHS England, or internal audit)
  • Supplier and third-party capability evaluation
  • Prioritising investment across competing improvement initiatives
  • Post-merger integration: understanding where two organisations actually are before combining operations

Scope options vary considerably:

  • Single process (e.g. incident management, procurement, data quality)
  • Single domain or function (e.g. data governance, cybersecurity, HR capability)
  • Enterprise-wide, covering multiple domains simultaneously

Choosing the right scope before you start is not a formality. An enterprise-wide assessment run with the same rigour as a single-process one will either take too long or produce shallow results. Most practitioners start narrower than they think they need to.


Common maturity models and the five-level scale

The Capability Maturity Model for Software, developed at Carnegie Mellon's Software Engineering Institute in the late 1980s and published in its 1.1 form in 1993, established the five-level ordinal scale that almost every subsequent framework has adopted or adapted. The five levels, in their most widely recognised form, run as follows:

  1. Initial (ad hoc): Processes are unpredictable, poorly controlled, and reactive. Success depends on individual effort.
  2. Managed: Basic project management is in place. Processes are planned and tracked at the project level.
  3. Defined: Processes are documented, standardised, and integrated into a consistent organisational approach.
  4. Quantitatively managed: Processes are measured and controlled using quantitative data.
  5. Optimising: Continuous improvement is embedded; the organisation adapts proactively to change.

The five-level scale is a convention, not a law. Some frameworks use four levels, some six. What matters is that each level has clear, observable descriptors so two assessors reach the same conclusion independently.

A selection of widely used models:

ModelDomain focusTypical levels
CMMI (SEI)Software and systems engineering5
GovPublic sector data capability4 (Emerging to Leading)
OWASP SAMMSoftware security assurance3 practice levels per domain
Digital maturity (academic DMM-OP)Organisation and process dimensionsContinuous scoring
HESA data capability toolkitHigher education data practiceBlock-based descriptors

Comparison chart of common maturity models and levels

The GOV.UK Data Maturity Assessment is worth noting separately. Rather than producing a single aggregated score, it returns a matrix view across ten topics and six themes, which means an organisation can be at a leading level in data infrastructure and still be emerging in data literacy. That nuance is exactly what makes it useful for public sector organisations planning targeted investment.

ISO/IEC 33004 sits above individual models as the international standard that sets requirements for how process assessment and maturity models should be constructed, including how process reference models and assessment indicators should integrate. If you are building a bespoke framework rather than adopting an existing one, ISO/IEC 33004 is the specification you are working to.


Core domains and dimensions that frameworks assess

Most maturity assessment models organise their questions around a set of standard domains. The specific labels vary by framework, but the underlying territory is consistent across serious implementations.

Standard assessment domains:

  • Governance: Decision-making structures, accountability, policy frameworks, and oversight mechanisms. Weak governance is almost always the root cause of low scores in every other domain.
  • People and skills: Workforce capability, training, role clarity, and succession. Processes cannot be defined if the people running them do not understand them.
  • Process: How work is actually done, documented, and controlled. This is the domain CMM was originally built around.
  • Data: Quality, availability, lineage, and management of organisational data. The GOV.UK Data Maturity Assessment treats this as its entire scope.
  • Technology: Systems, tools, integration, and infrastructure maturity. Technology scores that outpace process scores are a warning sign, not a success.
  • Metrics and measurement: Whether the organisation can actually tell how well it is performing. Without this domain, improvement is guesswork.
  • Supplier and sourcing: Third-party capability, contract management, and supply chain risk. Increasingly relevant in regulated sectors.
  • Culture and leadership: Attitudes towards improvement, risk appetite, and senior sponsorship. The hardest domain to score objectively, but often the most predictive of whether improvements actually stick.

Multi-dimensional versus single-dimension assessments:

A single-dimension assessment (e.g. scoring only process maturity) is faster and easier to validate, but it misses the interactions between domains. Academic research on digital maturity, including work proposing two-dimensional models covering both organisational and process dimensions, suggests that continuous scoring across multiple areas gives finer granularity and more defensible results than a simple five-level ordinal applied to a single axis.

The practical implication: structure your assessment as a matrix with domains as rows and maturity levels as columns. Each cell contains the evidence criteria for that combination. This makes scoring transparent and makes it obvious where an organisation is strong in one domain but weak in an adjacent one.


How to plan and run a maturity assessment

A repeatable, defensible assessment follows a consistent sequence. The steps below reflect good practice drawn from the IIA's guidance on selecting and using maturity models and the HESA data capability toolkit.

Step-by-step process:

  1. Define scope and objectives. Decide which domains, processes, or functions you are assessing, who the assessment is for (board, regulator, internal improvement), and what decisions it will inform. Write this down before touching a question set.
  2. Select or design the model. Choose an existing framework (GOV.UK DMA, CMMI, HESA toolkit) or build a bespoke one. If building bespoke, define your level descriptors first, then write questions that map to them. Every question should be traceable to a specific level in a specific domain.
  3. Define scoring rules. Decide whether you are using simple ordinal scoring (Level 1–5), weighted scoring (where some domains count more than others), or a RAG (Red/Amber/Green) approach. A weighted scoring model is worth considering when some domains carry disproportionate regulatory or operational risk.
  4. Plan evidence collection. Surveys alone are not sufficient for a defensible assessment. Combine self-assessment surveys with structured interviews, document and artefact review, and where possible, automated evidence collection from systems. The HESA toolkit uses block-based question groupings (people/culture, business process, data activities, technology) as a practical starting structure.
  5. Run data collection. Brief assessors and respondents on the scoring criteria before they start. Inconsistent interpretation of level descriptors is the single biggest source of unreliable results.
  6. Score and analyse. Aggregate responses by domain. For a weighted model, apply domain weights before rolling up. Produce a matrix view, not a single number. The GOV.UK Data Maturity Assessment explicitly recommends reporting by topic and theme rather than a single aggregated score, for good reason: a single number hides the variation that drives improvement decisions.
  7. Validate findings. Run a calibration session with at least two assessors reviewing the same sample of responses independently, then compare. Resolve disagreements by reference to the level descriptors, not by averaging. This step is what separates an assessment from a survey.
  8. Report and present. Produce a matrix output showing current levels by domain, a gap analysis against target levels, and a prioritised list of recommended actions. Keep the executive summary to one page.

Scoring example (simplified):

Suppose you are assessing data governance across five domains, each scored 1–5, with governance weighted at 30% and the remaining four domains at 17.5% each. An organisation scoring 2 on governance, 3 on process, 4 on technology, 3 on people, and 3 on metrics produces a weighted composite of approximately 2.9. But the governance score of 2 is the finding that drives the roadmap, not the composite.

Rough cost and timeline for a UK engagement:

A focused single-domain assessment (e.g. data maturity for a mid-size public sector body) typically runs over four to eight weeks, depending on evidence collection complexity. Enterprise-wide assessments covering six or more domains in a regulated organisation commonly take three to six months. Costs vary significantly by scope and whether you use an external facilitator, internal resource, or a digitised platform.

Pro Tip: Before you write a single question, write the level descriptors for each domain. If you cannot describe what Level 3 looks like in observable, evidenced terms, your questions will be ambiguous and your scores will be inconsistent.


How to plan and run a maturity assessment — overview diagram

How to turn assessment results into a prioritised roadmap

Scores on their own do not drive improvement. The output of a maturity assessment framework is only useful if it feeds directly into decisions about what to fix, in what order, and with what resources.

Translating matrix outputs into priorities:

  • Identify domains where current level is furthest below target level. These are your capability gaps.
  • Separate quick wins (high impact, low effort) from strategic shifts (high impact, high effort). Quick wins build momentum and demonstrate value to sponsors.
  • Flag domains where a low score creates regulatory exposure or blocks other improvements. These jump the queue regardless of effort.
  • Use the gap analysis to frame funding asks: a board is far more likely to approve investment when you can show a specific domain at Level 2 and a defined path to Level 3 with measurable outcomes.

Prioritisation matrix:

Capability gapImpactEffortPriority
Data governance (Level 2 → 3)HighMedium1
Metrics and measurement (Level 1 → 2)HighLow2
Technology integration (Level 3 → 4)MediumHigh3
Supplier management (Level 2 → 3)MediumMedium4

Setting measurable success criteria:

Each priority action should carry a measurable outcome. For a data governance gap, that might be: "All data assets have a named owner and a documented quality standard by Q3 2026." Framing improvements as OKRs or KPIs makes the next assessment cycle a genuine re-test rather than a fresh exercise from scratch.

Benchmarking your scores against sector peers adds a further layer of context. The GOV.UK Data Maturity Assessment provides aggregate sector data for public bodies, which lets you normalise your scores and understand whether a Level 2 in data quality is typical for your sector or an outlier. For regulated utilities and finance, sector-specific benchmarks are increasingly available through trade bodies and regulators. A project portfolio dashboard can help assurance leaders track improvement actions alongside other governance metrics in a single view.


Common pitfalls and how to avoid them

The most persistent problems in maturity assessment programmes are not technical. They are behavioural and structural.

Common pitfalls:

  • Treating levels as trophies. The point of a maturity assessment is to identify the next set of capabilities to develop, not to achieve a particular level for its own sake. An organisation that optimises its responses to score Level 4 without the underlying capability has wasted everyone's time.
  • Over-scoping the first assessment. Trying to assess twelve domains simultaneously in a first cycle produces shallow results and assessor fatigue. Start with three to five domains that matter most to your current strategic or regulatory context.
  • Opaque scoring. If respondents cannot see how their answers translate to a level, they will not trust the output. Publish your level descriptors and scoring logic.
  • Single assessor bias. One person's interpretation of "defined process" will differ from another's. Always involve at least two assessors and run a calibration step.
  • Document-heavy processes. Assessments that require respondents to upload dozens of artefacts before scoring can begin will stall. Design for minimum viable evidence at each level, then request additional artefacts only where a score is borderline.

Best practices:

  • Keep assessments evidence-based: every score should be traceable to an observable artefact or a structured interview response.
  • Digitise evidence capture from the start. Spreadsheet-based assessments become unmanageable quickly and make re-assessment almost impossible without starting from scratch.
  • Run short, rapid cycles aligned to PDCA (Plan-Do-Check-Act). A quarterly pulse assessment on two or three domains is more useful than an annual enterprise-wide exercise that takes six months to produce a report.
  • Involve mixed stakeholders: operational staff, process owners, and senior leaders. Assessments conducted only at the senior level systematically overestimate maturity.

Pro Tip: Use your first assessment cycle primarily to calibrate your level descriptors, not to produce a definitive score. The descriptors will almost certainly need refinement once real respondents encounter them. Build in a feedback loop after the first cycle.


UK-specific standards, toolkits and regulatory considerations

UK practitioners have access to a set of authoritative, publicly available frameworks that reduce the need to build from scratch.

Key UK and international references:

  • GOV.UK Data Maturity Assessment: The Cabinet Office's Data Maturity Assessment for Government is the primary toolkit for UK public sector organisations. It covers ten topics across six themes and returns a matrix view rather than a single score. Central government departments, arm's-length bodies, and local authorities all use it as a self-assessment baseline.
  • ISO/IEC 33004 is an international standard that sets requirements for constructing process assessment and maturity models.: Sets the international requirements for constructing process assessment and maturity models. If you are designing a bespoke framework for a regulated organisation, alignment with ISO/IEC 33004 gives your model credibility with auditors and regulators.
  • HESA data capability toolkit: A practical, sector-specific example for higher education, with block-based question groupings and level descriptors that translate well to other knowledge-intensive organisations.
  • OWASP SAMM: For organisations with significant software development or digital service delivery, OWASP SAMM provides a security-focused maturity model with practice areas and maturity levels that can sit alongside a broader organisational framework.

Sector-specific notes:

  • NHS and health: NHS England has published digital maturity self-assessment tools for trusts, aligned to the NHS Long Term Plan's digital ambitions. These use domain-level scoring across clinical systems, infrastructure, and workforce capability.
  • Regulated utilities: Ofwat, Ofgem, and the Environment Agency increasingly expect regulated entities to demonstrate process maturity as part of periodic review submissions. A documented maturity assessment, with evidence, is stronger than a narrative assertion.
  • Financial services: The FCA's operational resilience framework and the Bank of England's CBEST programme both implicitly require organisations to demonstrate capability maturity in risk, technology, and third-party management.

Regulatory and compliance reminders:

  • Assessment outputs that contain personal data (e.g. named respondents, HR capability data) are subject to UK GDPR and the Data Protection Act 2018. Anonymise or aggregate where possible.
  • In public sector procurement, maturity assessment evidence may be requested as part of supplier due diligence or framework qualification. Maintain an audit trail of how scores were derived.

Why digitising your maturity assessment changes the outcome

Running a maturity assessment in a spreadsheet is possible. Running it repeatedly, at scale, with defensible evidence, is not. The practical ceiling of a spreadsheet-based approach becomes apparent the moment you try to re-run the assessment six months later and reconcile the changes.

Benefits of digitisation:

  • Evidence management: Attach documents, screenshots, and links directly to individual scoring criteria. Every score has a traceable source.
  • Real-time dashboards: Stakeholders see current scores as evidence is collected, not three weeks after the assessment closes.
  • Repeatability: A digitised template runs the same assessment in the same way every cycle. Drift in question interpretation is eliminated.
  • Lower assessor bias: Structured question sets with defined level descriptors, delivered consistently through a platform, reduce the variation that comes from different assessors interpreting the same question differently.
  • Automated roll-ups: Weighted scoring and RAG aggregation happen automatically. No manual formula errors, no version control issues.

The IIA's practice guide on selecting and using maturity models specifically recommends digitising assessments to keep them evidence-based and dynamic rather than static documents that age quickly.

Digitised assessments do not just save time. They change what is possible: continuous monitoring, automated executive summaries, and an evidence trail that holds up under scrutiny. That is a fundamentally different proposition from a spreadsheet that someone updates once a year.

Consider a regulated infrastructure organisation running quarterly delivery assurance reviews across six domains. With a spreadsheet approach, each cycle requires a project manager to rebuild the scoring template, chase evidence by email, and manually compile a board report. With a digitised platform, the template is fixed, evidence is attached in-platform, and the executive summary is generated automatically. The cycle time drops from weeks to days, and the output is auditable.

Pro Tip: When evaluating maturity model software, test the evidence attachment workflow before anything else. A platform that makes evidence capture cumbersome will be abandoned in favour of a spreadsheet within two assessment cycles.


The gap between what maturity assessments promise and what actually matters

Most organisations approach a maturity assessment looking for a number. They want to know if they are at Level 3 or Level 4, as if the level itself were the deliverable. That framing almost always produces a worse outcome than the alternative: treating the assessment as a diagnostic tool whose primary output is a ranked list of capability gaps.

The frameworks that work in practice, whether that is the GOV.UK Data Maturity Assessment in a central government department or a CMMI-derived model in a regulated utility, share one characteristic: they are designed to be uncomfortable. A well-run assessment should surface things the organisation does not want to hear. If every domain comes back at Level 3 or above on the first cycle, either the level descriptors are too loose or the evidence bar is too low.

There is also a structural problem with how maturity assessments are commissioned in regulated sectors. They tend to be triggered by an external event: a regulatory review, an audit finding, a transformation programme kick-off. That means they are run once, produce a report, and then sit on a shelf until the next external trigger. The organisations that get the most value from maturity frameworks are the ones that treat them as a continuous monitoring tool, running shorter, targeted assessments on a quarterly or half-yearly basis and tracking movement over time.

The PDCA framing from CMM's original design is still the right mental model. Each assessment cycle should produce a re-testable set of changes. If you cannot answer the question "how will we know we have improved?" for each priority action, the roadmap is not finished.

For regulated UK organisations, the compliance dimension adds a further layer. An assessment that produces a documented, evidence-backed baseline is not just useful for internal improvement. It is the kind of artefact that satisfies an auditor, supports a regulatory submission, and gives a board genuine confidence rather than a narrative assertion. That is the case for doing this properly, not just doing it.


Intelligentassessments: continuous, evidence-based maturity assessment for regulated organisations

Spreadsheets and annual review cycles leave regulated organisations exposed. Intelligentassessments is built specifically for the problems this guide has described: evidence that needs to be attached to scores, weighted RAG roll-ups that need to be consistent across assessors, and board-level reporting that needs to be produced quickly and accurately.

Intelligentassessments

The platform provides structured assessment frameworks with template libraries covering governance, data, delivery assurance, and operational performance. Evidence is attached directly to scoring criteria, weighted scoring and RAG aggregation are automated, and AI-generated executive summaries reduce the time from assessment close to board report from weeks to hours. For regulated utilities, infrastructure operators, and public sector bodies, the audit trail is built in from the first response.

A typical deployment starts with a pilot assessment on one or two domains, using an existing template or a bespoke framework configured in-platform. Once the scoring logic and evidence requirements are validated, the same framework scales across the organisation with no rebuild required.

If you are preparing for a regulatory submission, a transformation programme, or simply want to replace a spreadsheet-based assessment process with something auditable and repeatable, book a demo with Intelligentassessments to see the evidence management and weighted scoring workflow in action.


Sources

The sources below are the authoritative references cited throughout this guide. Each is publicly available and worth bookmarking for any serious maturity assessment programme.