How a Risk Control Matrix Improves Audit Readiness
A risk control matrix maps each business risk to the specific control that mitigates it, names the control owner, states how the…
Evaluate an IT consulting partner on the people who will actually do the work, not on the firm's credentials or the pitch team. Ask for named consultants with their availability, a reference client of similar size and complexity, a written scope with explicit exclusions, and the commercial terms covering change, escalation and exit.
The gap between the people who present and the people who deliver is the largest single source of disappointment in consulting engagements. A firm’s overall track record tells you what its best teams have achieved; it tells you nothing about the team you will be assigned.
Ask for named individuals for the key roles, with CVs, current commitments and start availability. Ask what happens if one of them becomes unavailable, and whether replacement requires your approval. A partner confident in its bench answers this straightforwardly.
A reference from a very large client tells a mid-sized business little, because the team, governance and attention applied were different. Ask for a client of comparable size and complexity, and ask to speak with them directly rather than reading a case study.
The questions that produce useful answers are specific: what went wrong and how was it handled, did the named team stay for the duration, how were change requests priced in practice, and would you engage them again for the same work. General satisfaction questions produce general answers.
The exclusions list is more informative than the inclusions list. Common exclusions that surprise clients later include data cleansing, end-user training, third-party licence costs, integration with systems not explicitly named, and post-go-live support beyond a short window.
Change pricing needs to be agreed before signature, when you have leverage. A rate card for change work, a threshold below which minor changes are absorbed, and a stated turnaround for change estimates all prevent the pattern where a project becomes progressively more expensive through unpriced additions.
| Term | What to specify |
|---|---|
| Exclusions | Written list, not inferred from silence |
| Change pricing | Rate card plus absorption threshold |
| Named staff | Approval required for substitution |
| Escalation | Named contact and response commitment |
| Acceptance | Objective criteria per deliverable |
| Exit | Handover contents, format and transition support rate |
| IP and documentation | Client ownership stated explicitly |
Day rates are not comparable without knowing the seniority mix behind them. A lower blended rate delivered by a junior-heavy team can cost more in elapsed time and rework than a higher rate applied to an experienced one.
Compare on total cost to a defined outcome, with the same scope and the same assumptions, and require each proposal to state its assumptions explicitly. Where two proposals differ substantially in effort, the difference is almost always in what each assumed the client would do.
Who specifically will do the work and what are their current commitments; can we approve substitutions; what is explicitly excluded from scope; how is change priced and what is absorbed; who is the escalation contact; what are the acceptance criteria per deliverable; and what does handover include if we part ways.
Compare total cost to the same defined outcome under the same assumptions, and require each proposal to state its assumptions explicitly. Day rates are not comparable without the seniority mix behind them, and large effort differences between proposals almost always come from differing assumptions about what the client will do.
Neither is inherently safer. Large firms offer bench depth and continuity if a person leaves, but mid-sized clients may receive junior teams and limited partner attention. Smaller firms often provide more senior involvement with less resilience to staff departure. Assess the specific team and the continuity arrangements rather than the firm's size.
A risk control matrix maps each business risk to the specific control that mitigates it, names the control owner, states how the…
Most manual work in business operations exists because data stops at a system boundary and a person carries it across. Fixing that…
A dashboard gets used when each metric on it is tied to a decision someone makes and an action they can take.…
If this article covers a problem you are dealing with, tell us where you have got to and we will tell you what we would do next.