Methodology
A transparent method for a complex question.
JK Technology Readiness Assessment evaluates technology capabilities across strategy, digital product, architecture, integration, cybersecurity, engineering, AI and organization — to answer one question: how ready is this organization to use technology as a reliable engine for growth, efficiency, resilience and innovation?
Dimensions and capabilities
Technology Strategy & Governance
Does technology have a clear strategic relationship with the business?
- Strategy & Business Alignment
- Governance & Decision Rights
- Investment & Portfolio Management
- Enterprise Architecture & Standards
- Vendor & Sourcing Management
- Technology KPIs & Value Measurement
Digital Product & Customer Experience
Does the organization consistently turn customer needs into effective digital experiences?
- Product Strategy & Management
- Discovery & User Research
- UX, UI & Accessibility
- Digital Channels & Self-Service
- Product Analytics & Experimentation
Technology Architecture & Infrastructure
Can the technology foundation support the organization's future growth?
- Application Architecture & Scalability
- Cloud & Infrastructure
- Legacy Systems & Technical Debt
- Reliability & Disaster Recovery
- Observability & Monitoring
- Infrastructure Automation & Environments
Integration, Data & Automation
Can the organization connect systems, move information reliably, and automate repetitive work?
- API Strategy & Governance
- Integration Architecture & Interoperability
- Data Architecture, Ownership & Quality
- Reporting, BI & Analytics
- Process & Workflow Automation
- Regional & Local Integrations
Cybersecurity, Privacy & Resilience
How resilient and defensible is the organization's technology environment?
- Security Governance & Risk
- Identity & Access Management
- Application Security
- Infrastructure & Cloud Security
- Data Protection & Privacy
- Incident Response & Continuity
- Third-Party & Supply-Chain Risk
Software Engineering & Delivery
Can the organization reliably turn ideas into production outcomes?
- Delivery Planning & Predictability
- Engineering Quality
- CI/CD & Release Engineering
- DevSecOps
- Delivery Performance
- Team Effectiveness
AI, Innovation & Emerging Technology
Can the organization responsibly identify, test and operationalize technologies that create measurable value?
- AI Strategy & Governance
- AI Data & Platform Readiness
- AI Use Cases & Value Realization
- AI Risk, Security & Human Oversight
- Innovation & Emerging Technology
Organization, People & Operating Model
Is the organization structurally capable of operating and evolving its technology environment?
- Structure & Operating Model
- Skills & Talent
- Business & Technology Collaboration
- Documentation & Knowledge
- Sourcing & Vendor Dependency
- Change Management & Culture
Five maturity levels
- Reactive
Level 1 · 0–20
Capability depends on individuals and is exercised in response to problems.
- — Ad hoc and undocumented
- — Highly dependent on individuals
- — Reactive problem solving
- — Limited visibility
- — Inconsistent execution
- Developing
Level 2 · 21–40
Some practices exist, but they are applied inconsistently and significant gaps remain.
- — Some processes exist
- — Practices are inconsistent
- — Limited standardization
- — Partial ownership
- — Growing awareness
- Defined
Level 3 · 41–60
Processes, responsibilities and standards are documented and increasingly repeatable.
- — Processes are documented
- — Responsibilities are defined
- — Standards exist
- — Basic governance exists
- — Repeatability is improving
- Advanced
Level 4 · 61–80
Practices are standardized, measured, automated where appropriate and proactively managed.
- — Standardized and measured
- — Automated where appropriate
- — Proactively managed
- — Integrated across teams
- — Strong governance
- Optimized
Level 5 · 81–100
Capability is continuously improved, data-driven and able to adapt quickly.
- — Continuously improved
- — Highly automated and data-driven
- — Resilient
- — Strategically aligned
- — Adapts quickly to change
Scoring
Each answer maps to a defined maturity position. Questions carry different weights reflecting their importance — privileged access controls matter more than naming conventions — and weights are adjusted for your context, such as regulation, data sensitivity or whether you develop software internally.
Answers roll up into capability scores, capability scores into dimension scores, and dimensions into an overall readiness score (0–100). Scoring is deterministic: the same answers always produce the same result, and AI never changes a score.
Every assessment is pinned to a published framework version. When the methodology evolves, existing results do not change.
Context and target maturity
Level 5 is not automatically the goal. A 20-person company does not need the governance of a regulated multinational. The assessment sets a target maturity per dimension based on size, industry, regulatory environment, data sensitivity and strategic priorities, and reports the gap to that target.
Questions adapt as well: organizations without software development are not asked about deployment pipelines, while multi-country operations see regional integration and data-flow questions.
Risk
Risk (0–100, higher means more exposure) is calculated independently from maturity. It considers the risk impact and criticality of each answer, unanswered or unknown areas, and exposure factors such as sensitive data or public digital channels.
Critical findings — for example missing MFA on privileged accounts, untested disaster recovery or secrets in source code — are identified by explicit rules, reported separately, and set a floor on the overall risk level. A strong average never hides a critical exposure.
Evidence and confidence
Important questions ask how confident you are in the answer and invite optional evidence such as policies, reports, diagrams or metrics. “We believe we have MFA everywhere” is different from “we verified MFA coverage last quarter.”
Assessment confidence reflects coverage, evidence, self-reported confidence, unknown answers and contradictions between answers. The report lists the information that is still missing.
Opportunity prioritization
Opportunities are identified from capability gaps and findings, then prioritized by business impact, relevance to your stated objectives, risk reduction, time to value and effort. Dependencies are respected when building the roadmap.
Where a finding maps naturally to a capability JK Ventures offers, the report notes it. Recommendations are never generated to fit a service.
The role of AI
After deterministic scoring, an AI model interprets the structured results: explaining findings, identifying cross-dimension patterns, drafting recommendations and a roadmap narrative. Its output is validated against a strict structure and checked so it cannot alter scores, invent evidence or claim that an organization is “secure” or “compliant.”
The AI receives only the minimum necessary information — no company names, contact details or evidence documents — and assessment data is not used to train models.
Limits
The assessment is based on information provided by the organization. It is not a technical audit, penetration test or legal review. Security observations should be validated through technical testing, and potential regulatory considerations — including data protection requirements such as Colombian habeas data regulations — should be confirmed with qualified legal counsel.
Benchmarks are shown only when a statistically meaningful number of comparable, anonymized assessments exists. Until then, results are compared only with your own history.