Show what actually moved.
Re-scoring a system or programme against the baseline we already established, using the same anchors, so the difference between the two is real movement rather than a change of opinion.
What triggers this engagement.
Remediation is complete and you need to show it worked, or a year has passed and the register has stopped reflecting the environment.
Same scale, same anchors, same method. The gap is movement, not a change of opinion.
Where the boundary sits.
A scope that is not written down is a scope that grows. Ours is agreed before work starts and it is printed in the report.
- Every risk carried forward from the baseline register
- New risks introduced since the baseline was set
- Verification that the controls credited last time are in place
- A delta view showing which scores moved and which did not
- Rebuilding the method or the scale, which would break comparability
- Silent re-rating, since any anchor change is documented
- Credit for controls that were bought but not deployed
- The previous assessment, ideally ours
- Evidence of the remediation carried out since
- Access to the same system owners where possible
Shorter than the original, because the model and the boundary already exist.
What you receive.
One document, layered so that a board and an engineering team can both work from it.
Is this the right scope for you?
Tell us the decision you are facing. If a different engagement fits better, we will say so before you commit to this one.