Service 05 · Technology Assessment & Selection

IT Systems Audit& Improvement Review

An independent, evidence-based read on the systems you run today: what exists, what duplicates, what constrains the business, what carries risk — and the order in which to deal with it.

Indicative price
From £1,500
Capability area
A3 — Technology Assessment & Selection
Activity
62020 IT consultancy
05 A consultant assessing an organisation's existing systems landscape
Positioning

The cheapest engagement we offer, and usually the one to start with.

Organisations frequently arrive certain that a particular system is the problem. Sometimes they are right. Often the constraint sits somewhere else entirely — in a process, in a data quality issue, in a configuration nobody has revisited since it was installed.

A systems review establishes what is actually true before money is committed to changing anything. It looks at the whole landscape rather than one product, because the friction is usually at the joins between systems rather than inside them.

We take no commission from any vendor and we are not trying to sell you a build. If the honest finding is that your current systems are adequate and the difficulty is elsewhere, the report will say exactly that.

Business problems

Situations that warrant a review.

“We are about to spend a significant sum and we are not certain it is the right thing.”

A review costs a fraction of the decision and frequently changes its shape — sometimes by making the project smaller.

“Everything technically works, but everything takes too long.”

Duplicate entry, manual reconciliation and workarounds are invisible on a budget line and expensive in aggregate. A review quantifies them.

“We have inherited systems nobody chose.”

After growth, staff changes or an acquisition, the estate reflects a series of individual decisions rather than a design. Establishing the current state is the first step.

“Different teams have built their own solutions.”

Departmental tools solve local problems and create organisational ones. A review identifies which to adopt formally and which to retire.

“A supplier has told us we need to upgrade.”

Sometimes accurate, sometimes commercially convenient for them. Independent assessment establishes whether the recommendation serves you.

“We do not know what we would do if that system failed.”

A review identifies dependencies and risk. Where the exposure is significant, it points towards continuity planning.

Service diagram

From current estate to improvement plan.

Findings are separated from risks, and risks from priorities, because conflating them is how review reports become unactionable.

IT systems review process The current estate is assessed, producing findings and risks, which are ranked into priorities and assembled into an improvement plan. Step 01 Current estate Core systems Departmental tools Spreadsheets Step 02 Assessment Interviews with users Process observation Configuration & data review Step 03 Findings Step 04 Risks Step 05 Priorities Impact × effort Dependency order What can wait Step 06 Improvement plan Sequenced Costed Recommendations are graded, not listed flat Do now Low effort, immediate benefit Plan this year Material change, needs budget Monitor Not yet a problem, may become one Deliberately leave alone Working; no change justified The fourth category matters — a review that recommends changing everything has not been an assessment
Evidence gathering Ranked output Deliverable
What Alvoris can deliver

What the review examines.

The scope is agreed in advance. A focused review of one process is a legitimate engagement; so is a whole-estate assessment.

01Systems inventoryEvery system in scope, what it does, who uses it, who owns it, what it costs and how it relates to the others.
02Process and usage observationHow the systems are actually used, which differs from how they were intended to be used more often than not.
03Duplication analysisWhere the same information is entered twice, held in two places, or reconciled by hand between systems.
04Constraint identificationWhere a system limits what the business can offer, how fast it can respond, or how large it can grow.
05Data quality assessmentWhether the information held is complete and consistent enough to rely on for reporting, planning or migration.
06Technical and operational riskUnsupported software, key-person dependency, absent backups, systems with no owner and suppliers with no exit route.
07Improvement opportunitiesConfiguration changes, process changes, training, consolidation or replacement — each with an indication of effort and benefit.
08Prioritised recommendationsGraded into do now, plan this year, monitor, and deliberately leave alone — with the reasoning for each grading.
Common use cases

When organisations commission this.

Before investmentPre-decision assessmentCommissioned before committing to a replacement, to establish whether replacement is genuinely the answer.
New leadershipBaseline reviewA new managing director, finance director or operations lead wanting an independent picture of what they have inherited.
Post-acquisitionTwo estates, one businessAssessment of overlapping systems following a merger, with recommendations on what to retain, retire and migrate.
GrowthScalability checkAn honest read on whether the current arrangement survives significant growth, and where the first constraint will appear.
Recurring frictionDiagnosisWhere the same operational complaints recur and nobody has established whether the cause is the system, the process or the data.
GovernanceBoard assuranceAn independent written assessment for a board or trustee group that wants a view not produced by the people running the systems.
How the engagement works

Five stages over two to four weeks.

The demand on your team is modest — typically a series of short interviews and access to systems for observation.

  1. Stage 01Scoping and accessWhat is in scope, who we need to speak to, and what access is required. Output: an agreed terms of reference so the review cannot drift.
  2. Stage 02Discovery and interviewsStructured conversations with users at every level, plus observation of the work as it happens. The people doing the work know where the friction is.
  3. Stage 03Technical examinationConfiguration, data quality, integration points, licensing, support status and dependency mapping for the systems in scope.
  4. Stage 04Analysis and draftingFindings assembled, risks assessed, recommendations graded. A draft is shared with you so factual errors can be corrected before the report is final.
  5. Stage 05Presentation and handoverA working session walking your team through the findings and answering questions, followed by the final written report.
Outputs and deliverables

What you hold at the end.

  • A written review report in plain, non-technical language
  • A systems inventory you can maintain afterwards
  • Findings supported by evidence and attributed to sources
  • A technology risk summary suitable for a board paper
  • Graded, sequenced recommendations with indicative effort
  • A walkthrough session with your team
Indicative pricing and timing
Indicative starting price From £1,500 Final pricing depends on scope, complexity, requirements, existing systems and delivery timeframe. The starting figure reflects a focused review of a small estate or a single business area. More systems, more sites or more people to interview will increase it.
Typical engagement range 2–4 weeks From kick-off to final report. Timing depends on scope and, most commonly, on how quickly interviews can be arranged with the people who understand the systems.
Who it is suitable for

And who it is not for.

A good fit

  • Organisations facing a significant technology decision
  • Businesses whose systems have accumulated rather than been designed
  • New leadership wanting an independent baseline
  • Boards seeking assurance from outside the operational team
  • Anyone unsure whether their frustration is the system or the process

Probably not a fit

  • Organisations wanting day-to-day IT support or a managed service
  • Penetration testing or formal information security certification
  • Hardware, network or infrastructure engineering work
  • Anyone seeking a report to justify a decision already made

To be explicit: we will not write a report to support a predetermined conclusion. If you need independent evidence, that independence is the product.

Questions about this service

Frequently asked.

Less than most people expect. Typically thirty to sixty minutes each with a handful of people, some read-only access for observation, and a nominated internal contact to answer questions as they arise. We work around your operational commitments rather than the other way round.

The report addresses systems, processes and risks — not individuals. Where a supplier arrangement is not serving you, we will state that factually and evidence it, because you are paying us to be straight with you. We do not editorialise about people, and interview contributions are not attributed to named individuals unless you ask for that.

Usually read-only access is sufficient, and it is what we prefer. Where configuration needs to be examined more deeply, we will ask for specific access, explain why, and work under your own security arrangements. We do not make changes to live systems during a review.

Then it says so, and the engagement has done its job. Establishing that current systems are adequate is a legitimate and valuable outcome — particularly where it prevents an expensive replacement that would not have improved matters.

In practice, most reviews land somewhere in between: a small number of worthwhile improvements, several things to leave alone, and one or two risks worth attending to.

Yes. The report is yours. Many clients use it as the basis for conversations with other providers, or to brief an internal team. We have no expectation of being engaged for the work the report recommends, and no clause requiring it.

No. The review covers operational and technical risk at a practical level — unsupported software, absent backups, single points of failure, access arrangements that have not been reviewed. It is not a penetration test, a vulnerability assessment or a formal information security audit, and we will say so plainly if that is what your situation actually requires.

Start a conversation

Establish what is true before you spend against an assumption.

Tell us which decision is coming up, or which complaint keeps recurring. We will tell you whether a review would help and what it would cover.