SolutionsGovern & DeliverEnterprise Standards & Controls

Policies with proof behind them — and a price on the gaps.

“Can we prove our controls were actually working on what we shipped?”

Enterprise Standards & Controls turns policy into something the company can prove. Every system has a dated compliance status against each standard, and every exception has an owner and an expiry date. Each policy is linked to its controls, how they are implemented and who signed off, with the remaining risk and the cost of the affected systems alongside. Technical debt becomes a priced list with a payback, not a “high/medium/low” rating. And the data checks itself — so the evidence is trustworthy before audit asks.

Rooms you open

  • Publish the Standards
  • Prove the Controls
  • Fund the Debt
  • Trust the Model

Methods supported

CLEARTBMSAFe

Part of Govern & Deliver · How do we turn choices into governed outcomes?

The pressure

Policy is a PDF. Delivery is a board. Audit is a scramble.

Standards get published and forgotten. Exceptions expire without anyone noticing. Before every audit, a team spends weeks piecing together evidence that should have been captured as the work happened. And technical debt is described as “high” with no price attached — so it never competes for funding.

What it looks like today

  • Standards nobody has reviewed in years
  • Systems running on an expired exception — or none at all
  • Policies with no control behind them
  • Technical debt rated, never priced

What changes

What changes.

A standards document

A standards list with a dated compliance status for every system

Evidence gathered for the audit

Evidence captured as the work happens

Debt described as a rating

Debt as priced items, with yearly cost and payback

Coverage you can see

Every type of control against every type of system — gaps in plain sight.

A compliance grid where a missing control shows up as a gap, not hidden inside a percentage. Each cell carries the cost of the systems it covers, so the compliance conversation becomes a funding conversation.

Where other tools stop

Compliance tools track controls. They cannot tell you what an unchecked system costs, or which project would close the gap.

The rooms

The rooms inside Enterprise Standards & Controls.

Each room answers one question a leader actually asks, with the view that answers it and the measures that say whether it is working.

A room is a ready-made view that answers one leadership question, built on the same shared data as every other room.

Room 01

Publish the Standards

“What are our standards, who complies, and who has an exception?”

Every standard with the board that owns it, a dated compliance status for each system, and every exception with its expiry and owner.

How you know it is working

  • Systems with a dated, owned compliance status, up
  • Non-compliant systems with an expired exception or none, down

Room 02

Prove the Controls

“Which policies have controls behind them, and where is the proof?”

Each policy linked to its controls, how they are implemented and who signed off, with the remaining risk and the cost of affected systems.

How you know it is working

  • Policies with no control behind them, down
  • Overdue sign-offs reaching the person responsible, up

Room 03

Fund the Debt

“What does our technical debt cost us each year, and what would it cost to fix?”

Technical debt as a priced list — each item with its cost to fix, what it costs each year to leave alone, and whether a project is funding it.

How you know it is working

  • Debt tracked as priced items rather than a rating, up
  • Debt that pays back within a year and gets funded, up

Room 04

Trust the Model

“Can we rely on the data itself?”

Open data problems by age and owner, missing information, likely duplicates ranked by the cost they carry, and systems with no owner.

How you know it is working

  • Average age of an open data problem, down
  • Spend on systems with no accountable owner, down

Who it is for

Who opens it, and what they ask.

Compliance lead

“Where is the evidence, and what is overdue?

CTO

“Who has an exception, and when does it expire?

CIO

“What does our technical debt cost us each year?

Governance board chair

“Can I rely on this data before I sign?

What it replaces

Retire the workarounds — on your schedule.

  • Side compliance spreadsheets
  • Exception trackers
  • Evidence hunts before every audit

How it is licensed

Enterprise Standards & Controls is licensed within Govern & Deliver, with Strategic Portfolio Management included underneath.

Start with one portfolio, one product area or your architecture team. Strategic Portfolio Management is included automatically with every module.

See pricing

Methods and frameworks

Runs the methods you already use.

Dotwork does not ask you to adopt a new method. The frameworks your teams run become views over the same model.

CLEAR

Strategy to execution, connected and measured.

TBM

Technology Business Management: a standard way to categorize IT spend and who uses it.

SAFe

Scaled Agile Framework: a widely used way to run agile delivery across many teams.

The model underneath

Every module makes the next one smarter.

Steer, Fund & Optimize and Govern & Deliver all read and write the same Enterprise Operating Model. The first module you license builds the model. Every module after it adds context instead of another silo — and Dotwork AI reads all of it, stopping where the decision is yours.

See the Enterprise Operating Model

Be Decisive.Build Fast.Connect Everything.

Start Connecting