No complete inventory
Build it from the directory rather than from procurement records. The gap between the two is itself the finding.
Twenty checks on who outside your organization can reach your systems, and what would happen if one of them were compromised.
Public sector organizations work with many suppliers, and each one that reaches your systems extends your attack surface into an organization whose security you do not control.
This audit is about knowing the extent of that, which most organizations have never established.
CIO or Head of Digital
Security and identity teams
Procurement and contract managers
Tick only what you can genuinely evidence today. An item you intend to do is not an item you have done, and scoring yourself generously here only produces a comfortable number and an uncomfortable project.
Establishing who actually has access.
Whether the access is appropriately constrained.
Whether the obligations are written down.
Whether this stays current.
These bands are deliberately blunt. The middle band is where most organizations honestly sit, and it is a perfectly reasonable place to proceed from — provided the gaps are written down with owners rather than carried as optimism.
Do not proceed yet. More than four in ten items are unaddressed, and the ones that fail here are usually the foundational ones that make everything after them harder.
Proceed on a defined scope, with the outstanding items written into the plan as risks with owners and dates. This is the most common honest position.
The remaining gaps are small enough to handle during delivery rather than before it. Confirm the unticked items are genuinely minor rather than simply unexamined.
Your score highlights automatically as you tick items above. Nothing is saved, sent or tracked — refreshing the page clears it.
The four items below are the ones whose absence causes the most trouble downstream. If your unticked items include any of these, they are worth addressing before the rest.
Build it from the directory rather than from procurement records. The gap between the two is itself the finding.
Close the exemption. These are among the most targeted accounts you have and the exemption is almost always for convenience.
Move to time-bound. Access that must be manually revoked depends on somebody remembering after a project ended.
Name one accountable person. Shared ownership of third-party risk reliably means nobody reviews it.
We will build the third-party access inventory from your directory and produce a prioritised remediation list, which usually starts with a number nobody expected.
Twenty checks covering the governance, procurement and technical questions a council review will ask.
Whether your retention schedule is operating or merely documented, across twenty specific checks.
Twenty checks before publishing spending or performance data, covering accuracy, accessibility and the questions members will ask.
Describe the situation in your own words.