Last reviewed: 27 July 2026.
What a digital maturity assessment is for
A digital maturity assessment reviews how effectively an organisation actually uses technology — not how much of it has been bought. The distinction matters, because the two frequently move in opposite directions. Organisations with the largest software estates are often the least mature, because nothing connects and staff have built parallel spreadsheet systems to bridge the gaps.
Most maturity models fail at the last step. They produce a composite score — 2.7 out of 5, "developing", amber — and the organisation is no clearer about what to do on Monday than it was before. A score describes a condition without identifying a cause.
The version below is built to produce a decision instead. It scores seven areas independently across five levels, identifies the single area holding the others back, and sequences work from there.
Digital maturity describes the general state of your technology, data and ways of working. AI readiness tests whether a specific use case can succeed in that environment. Maturity is the foundation; readiness is the test on top of it. Organisations at level 1 or 2 reliably fail AI readiness on data and technology no matter how strong the appetite — which is why running an AI pilot before a maturity assessment so often produces an expensive answer to a question nobody needed asked.
The five levels
| Level | Name | What it looks like in practice |
|---|---|---|
| 1 | Ad hoc | Tools chosen locally, nothing connects, knowledge sits with individuals |
| 2 | Repeatable | Core systems exist but are used inconsistently; spreadsheets fill the gaps |
| 3 | Defined | Systems and processes documented and standard across teams |
| 4 | Integrated | Systems exchange data automatically; reporting is trusted without manual reconciliation |
| 5 | Optimising | Digital operations are measured and improved as routine, not as projects |
Two practical notes. Level 4 is the realistic target for most organisations; level 5 is expensive to reach and rarely justified outside technology-led businesses. And maturity is not uniform — a finance function at level 4 frequently sits alongside an operations function at level 2 in the same organisation, which is why assessing at organisation level produces averages that describe nobody.
The seven areas to assess
1. Systems and applications
Inventory what exists, including what is paid for and unused. Record the owner, the renewal date, the cost and the actual usage rate for each system. Shelfware is common and is worth finding early — it funds the rest of the programme.
2. Integration
Assess how systems exchange data, and how much of that exchange is a person exporting a CSV on a Friday. Manual transfer points are where data quality degrades and where staff time disappears without appearing in any budget line. Count them.
3. Data
Assess availability, quality, ownership and accessibility. The practical test is whether two people asked the same question produce the same number. Where they do not, the cause is usually that a definition was never agreed rather than that a system is faulty — a distinction that determines whether you need a data project or a governance conversation.
4. Digital customer experience
Assess how customers actually interact with you: what they can self-serve, where they are forced into a phone call, and how much of what they experience is shaped by your internal system boundaries rather than by their needs.
5. Ways of working
Assess collaboration, remote and hybrid working, document management, and how knowledge is stored and found. The recurring failure here is knowledge that exists only in individuals' inboxes, which surfaces as a resilience risk long before anyone frames it as a digital maturity problem.
6. Security and resilience
Assess access control, backup and recovery, patching, supplier risk and incident response. Note that maturity here is frequently higher than in other areas — security tends to get board attention that integration does not — and a strong score here should not be allowed to lift the overall picture.
7. Digital skills
Assess capability by role rather than in aggregate, covering everyday tool fluency, data literacy, and the specialist skills needed to maintain what you have. This is the area most often scored generously and most often responsible for a stalled programme: an organisation that buys level 4 systems and staffs them with level 2 skills has purchased complexity rather than capability. Our guide to the UK digital skills gap covers the sector picture.
Finding the binding constraint
Score each area 1 to 5. Then resist the request for a single number.
An organisation scoring 4 on systems, security and customer experience but 1 on data does not have a maturity of 3. It has a data problem that will defeat anything it attempts in the other six areas. Averaging is popular because it produces a figure for a board pack, and harmful because it conceals precisely the finding the board needs.
The binding constraint is the lowest-scoring area that other areas depend on. Dependencies run in a fairly consistent direction:
- Integration depends on systems — you cannot connect what nobody owns.
- Data quality depends on integration — every manual transfer point is a place accuracy is lost.
- Customer experience depends on data — self-service fails when the underlying record is wrong.
- Everything depends on skills — capability sets the ceiling on what any of the others can reach.
This is why "buy better software" is usually the wrong first move. New systems inherit the data problems of the old ones, and are operated by the same people with the same skills. An organisation constrained on data or skills that responds by procuring a platform has bought a more expensive version of its existing situation.
Sequencing the work
Convert the scores into three tracks, and run them in this order rather than in parallel:
| Track | Contains | Typical horizon |
|---|---|---|
| Remove | Unused licences, duplicated systems, manual steps that exist only from habit | 0–3 months, self-funding |
| Fix the constraint | The single lowest dependent area — usually data ownership or skills | 3–9 months |
| Build | Integration, automation, new capability — only after the constraint is addressed | 9 months+ |
The "remove" track matters more than its unglamorous name suggests. It produces visible results quickly, it frequently pays for the tracks that follow, and it builds the credibility a longer programme needs. A workflow mapping exercise is the fastest way to populate it.
Running the assessment
Three days of structured work covers a single organisation or division.
- Day one: systems and licence inventory, including actual usage rates rather than seat counts
- Day two: interviews with the people who use the systems daily, plus a trace of two or three real processes end to end
- Day three: scoring workshop, constraint identification, track allocation with owners and dates
Trace real processes rather than accepting described ones. Ask someone to show you how an order actually gets from enquiry to invoice, and the manual transfer points, shadow spreadsheets and workarounds appear immediately — none of which will be in the process documentation. That single exercise usually produces more of the assessment's value than the rest of the interviews combined.
Assess at division or function level. An organisation-wide average recommends investment for a function that cannot absorb it and overlooks the one that needs it.
The output should be seven scores, one named binding constraint, a three-track plan with owners and dates, and an explicit list of what you are deliberately not doing this year. Where the constraint turns out to be skills — which it frequently does — the follow-on is a structured skills gap analysis rather than another technology decision.
Frequently asked questions
What is a digital maturity assessment?
A digital maturity assessment is a structured review of how effectively an organisation uses technology, scored across defined areas and levels. It covers systems, integration, data, digital customer experience, ways of working, security and digital skills. Its purpose is to identify which constraint is holding the others back, not to award an overall grade.
What are the levels of digital maturity?
Most usable models run five levels. Level 1 is ad hoc, where tools are chosen locally and nothing connects. Level 2 is repeatable, where core systems exist but are used inconsistently. Level 3 is defined, where systems and processes are documented and standard. Level 4 is integrated, where systems exchange data automatically and reporting is reliable. Level 5 is optimising, where the organisation measures and improves its digital operations as routine.
How is digital maturity different from AI readiness?
Digital maturity describes the general state of an organisation's technology, data and ways of working. AI readiness assesses whether a specific AI use case can succeed in that environment. Digital maturity is the foundation and AI readiness is the test applied on top of it: an organisation at level 1 or 2 will usually fail an AI readiness assessment on the data and technology dimensions regardless of how strong its AI ambitions are.
Why do digital maturity scores rarely change anything?
Because a single composite score describes a condition without identifying a cause. An organisation told it is 2.7 out of 5 has no more idea what to do than before. A useful assessment scores each area separately, names the lowest-scoring area as the binding constraint, and sequences work so that constraint is addressed before anything that depends on it.
How long should a digital maturity assessment take?
Two to three days of structured work for a single organisation or division: a systems and licence inventory, interviews with the people who use the systems daily, and a scoring workshop. Assessments that run for months tend to produce more precise scores of a situation that has already changed.