John Salter’s Blog
Follow my ruminations
Get new content delivered directly to your inbox.
- The Cartographer’s Lantern
In a valley often swallowed by fog, the village of Bellmere chose a new warden each year to keep its people safe from flood, fire, and storm.
One autumn, a clever merchant arrived with a polished brass lantern.
“This lantern,” he announced, “measures the village’s readiness. Hold it near your granaries, bridges, wells, and watchtowers. If it shines green, you are prepared. If it shines amber, you need improvement. If it shines red, you are in danger.”
The council was delighted. The lantern was quick, tidy, and far less troublesome than inspecting muddy riverbanks, climbing old towers, testing the fire pumps, or asking weary villagers whether they knew what to do.
For three days, the council walked through Bellmere holding up the lantern.
At the granary, it glowed green.
At the bridge, green.
At the watchtower, green.
At the well, green.
The council prepared a handsome report. It declared Bellmere “Highly Capable in Emergency Readiness.” They hung it in the town hall beside a painting of the founder.
Only Mara, the old keeper of the river gate, frowned.
“Did anyone test whether the gate still closes?” she asked.
“The lantern shone green,” replied the mayor.
“Did anyone open the granary stores and see whether the grain is dry?”
“Green.”
“Did anyone climb the watchtower at night and see whether the bell rope reaches the bell?”
“Green, green, green,” said the council, growing impatient. “Must we doubt every good result?”
That winter, rain fell in the hills for six straight days.
When the river rose, Mara ran to the gate. The wooden mechanism had rotted behind its iron fittings. The gate would not move.
The watchman pulled the bell rope. It came loose in his hands.
Villagers rushed to the granary, only to find that a crack in the roof had spoiled much of the grain months before.
The bridge, certified green by the lantern, had a weakened foundation. It collapsed beneath the first wagon sent to carry children to higher ground.
Bellmere survived, but only because neighbours from the next valley saw the flood coming and arrived with ropes, boats, and food.
When the water receded, the council found the merchant’s lantern floating in the mud. Its brass was still bright. Its green light still shone.
The mayor took it to Mara.
“Why did it tell us we were ready?” he asked.
Mara turned the lantern over and opened its base. Inside was a small painted wheel with only one colour.
“It did not tell you that you were ready,” she said. “It told you what it had been made to show.”
From then on, Bellmere still used lanterns, lists, and reports. But before declaring anything green, the council demanded to see the river gate close, the bell ring, the grain inspected, the bridge tested, and the villagers practise their roles.
And each report began with a new question:
“What evidence would prove us wrong?”
- Minimum Client Evidence Requirements
- The road ahead for the Sydney Swans
The comparison below treats Ms Ley’s quoted line “accountability must be extended to anyone who was aware of what was happening and had the power to act” as given and compares it against the well-documented legal/coronial “ought to have known” standard.

AFRWEEKEND 29-30 August 2026, p.43 The Core Overlap
Both formulations reject a purely formal test of accountability — “were you the person who did the act?” – in favour of a broader test based on knowledge and capacity to intervene. Ley’s standard (“aware of what was happening and had the power to act”) and the coronial test (“what ought you have known and done about the risk and its management”) share the same two-part logic:
- A knowledge element – actual or constructive awareness of the problem.
- A power/capacity element – the ability to have done something about it.
Under Australian negligence law, this is essentially the codified breach-of-duty test: a person is not liable unless the risk “was foreseeable (that is, a risk of which the person knew or ought reasonably to have known)” and a reasonable person in their position would have taken precautions. Coroners apply an analogous logic when examining whether an organisation or individual identified a risk, or should have, and whether the response was adequate given what was known or knowable at the time.[1][2]
Where the Two Diverge

The Key Legal Nuance Ley’s Line Skips
The negligence/coronial standard explicitly includes constructive knowledge – you don’t escape accountability just because nobody told you. The test is whether a reasonable person in your position, given your role, seniority, and access to information, ought to have known, regardless of actual awareness. The Australian civil liability framework specifically instructs courts to weigh the probability of harm, its likely seriousness, the burden of taking precautions, and the social utility of the activity, when deciding whether a “reasonable person” would have acted.[1][3]
Ley’s phrasing — “anyone who was aware” — reads as a narrower, actual-knowledge standard on its face. If someone plausibly claims they didn’t know, her framing arguably lets them escape scrutiny, whereas the coronial test would still ask whether they should have known given their position and the information reasonably available to them. This is precisely the gap that recurs in institutional failure findings: senior figures often argue ignorance, and the coronial/negligence standard is specifically constructed to prevent that defence from being conclusive on its own.
Practical Read the Universal Framework
This maps neatly onto the E1/E2/E3 logic in the Universal Framework.
A “knew or ought to have known” standard is really an E1/E2 test – did an information/escalation process exist, and was the person enabled (through position, access, or reporting lines) to receive that information – regardless of whether they personally chose to look.
Ley’s narrower “was aware” framing risks collapsing accountability down to E3 only (did they demonstrably know and fail to act), which is a materially easier bar for an accountable person to clear than the coronial standard most governance and audit findings are actually built on.
Sources
[1] Understanding the Elements of Negligence https://www.odysseylegal.com.au/understanding-the-elements-of-negligence/
[2] Negligence https://content.nfplaw.org.au/wp-content/uploads/2024/09/Negligence.pdf
[3] LAWS1061 Revision Notes https://s3.studentvip.com.au/notes/15859-sample.pdf
[4] Review of the Law of Negligence Final Report https://treasury.gov.au/sites/default/files/2019-03/R2002-001_Law_Neg_Final.pdf
[5] principle in the duty of care in negligence https://www.unsw.edu.au/content/dam/pdfs/law/unsw-law-journal/2000-2009/Vol-No-23-2-11.pdf
[6] 7. Foreseeability, Standard of Care, Causation and Remoteness of … https://treasury.gov.au/sites/default/files/2019-03/R2002-001_Foreseeability.pdf
[7] file https://judicialcollege.vic.edu.au/media/886/file
[8] MEDICAL NEGLIGENCE: THE CONTOURS OF … https://law.nus.edu.sg/sjls/wp-content/uploads/sites/14/2024/07/1584-1997-sjls-jul-86.pdf
[9] Chapter summary – ch 3 – introduction to torts (negligence) https://store.thomsonreuters.com.au/product/AU/files/720506676/chapter_summary_21e___ch_3.pdf
[10] Secretary of State for Justice, R (on the application of) v HM Deputy … https://www.casemine.com/judgement/uk/5a8ff7b960d03e7f57eb18c5
[11] 1 https://s3.studentvip.com.au/notes/17847-sample.pdf
[12] Determining Breach of Duty of Care in Negligence Cases https://www.studocu.com/en-au/document/university-of-melbourne/torts/breach/61954198
[13] 2A. Breach of Duty of Care (Different Attempt) Flashcards https://www.brainscape.com/flashcards/2a-breach-of-duty-of-care-different-atte-6319539/packs/9395429
[14] Table of Contents https://s3.studentvip.com.au/notes/6260-sample.pdf
[15] Deprivation of liberty, death and Article 2 https://www.ukinquestlawblog.co.uk/dols-death-and-art2/
[16] Transcript 40682 https://pmtranscripts.pmc.gov.au/release/transcript-40682
[17] How the Liberals’ first female leader found herself here https://www.abc.net.au/news/2026-02-13/sussan-ley-liberals-leadership-spill/106325896
[18] Australian minister Sussan Ley resigns over expenses scandal https://www.bbc.com/news/world-australia-38592391
[19] Sussan Ley https://en.wikipedia.org/wiki/Sussan_Ley
[20] Sussan Ley praised for ‘standing up for democracy’ as Labor’s freedom of information crackdown looks set to fail https://www.theguardian.com/australia-news/2025/oct/13/sussan-ley-praised-for-standing-up-for-democracy-as-labors-freedom-of-information-crackdown-looks-set-to-fail
[21] Sussan Ley: Does Liberal Party drama show Australian politics still has a problem with women? https://www.bbc.com/news/articles/c4g5pjn3p50o
[22] 7.30: What Sussan Ley did to recover after 25 years in … https://iview.abc.net.au/show/7-30/series/0/video/SEGS2026107025616
[23] Sussan Ley: From punk pilot to a scandal-triggered resignation https://www.abc.net.au/news/2017-01-13/sussan-leys-time-in-the-office/8180824
[24] Tim Wilson gives second first speech https://www.theguardian.com/australia-news/live/2025/jul/29/australia-politics-live-albanese-tariff-trade-trump-us-question-time-sussan-ley-net-zero-parliament-gaza-palestine-ntwnfb
[25] How the Liberals will justify Sussan Ley’s ousting https://www.abc.net.au/news/2026-02-08/sussan-ley-liberals-coalition-leadership-spill-angus-taylor/106295860
[26] As Liberals’ New Leader, Sussan Ley Makes History https://thediplomat.com/2025/05/as-liberals-new-leader-sussan-ley-makes-history-but-faces-unprecedented-difficulties/
[27] Paddy Gourley https://johnmenadue.com/authors/paddygourley/
[28] Coalition Calls for Commonwealth Royal Commission into … https://www.liberal.org.au/2025/12/22/coalition-calls-for-commonwealth-royal-commission-into-the-bondi-attack-and-antisemitism
[29] Statement – The Coalition – The Hon. Sussan Ley MP https://sussanley.com/statement-the-coalition/
[30] Andrew Hastie’s resignation is a grenade in the lap of Sussan Ley. With the Liberal leader’s weakness now out in the open, the Opposition need to act fast to avoid an all-out mutiny: PETER VAN ONSELEN https://www.dailymail.co.uk/news/article-15159381/Andrew-Hasties-resignation-sussan-ley-PVO.html - How to avoid the normalization of deviance in organizations
Avoiding normalization of deviance means treating every recurring workaround, unexplained anomaly, or missed control as evidence to investigate—not proof that the underlying risk is acceptable. The core discipline is simple: past success must not redefine the standard. NASA’s safety guidance expressly warns against using prior successful outcomes to redefine acceptable performance and calls for evidence-based assessment of probability and severity.^1
What it is
Normalization of deviance is the gradual process through which people depart from an agreed standard, experience no immediate disaster, and begin to regard the departure as normal practice. Over time, the workaround stops feeling like a deviation at all.^2
It rarely starts with recklessness. It often begins with a rational local response:
- “The approval takes too long; we will obtain it afterwards.”
- “The alarm always triggers; it is probably a false positive.”
- “We cannot fill that role this month; the team will cover it.”
- “The project is late, so we will skip the readiness review.”
- “The risk has been open for ages, but nothing has happened.”
The danger is the inference: nothing bad happened last time, therefore the risk is tolerable. That conclusion confuses luck, low frequency, or incomplete observation with demonstrated control effectiveness.

Design the countermeasures
Avoiding normalization of deviance means treating every recurring workaround, unexplained anomaly, or missed control as evidence to investigate—not proof that the underlying risk is acceptable. The core discipline is simple: past success must not redefine the standard. NASA’s safety guidance expressly warns against using prior successful outcomes to redefine acceptable performance and calls for evidence-based assessment of probability and severity.[1]
What it is
Normalization of deviance is the gradual process through which people depart from an agreed standard, experience no immediate disaster, and begin to regard the departure as normal practice. Over time, the workaround stops feeling like a deviation at all.[2][3]
It rarely starts with recklessness. It often begins with a rational local response:
- “The approval takes too long; we will obtain it afterwards.”
- “The alarm always triggers; it is probably a false positive.”
- “We cannot fill that role this month; the team will cover it.”
- “The project is late, so we will skip the readiness review.”
- “The risk has been open for ages, but nothing has happened.”
The danger is the inference: nothing bad happened last time, therefore the risk is tolerable. That conclusion confuses luck, low frequency, or incomplete observation with demonstrated control effectiveness.
Design the countermeasures
The strongest defences combine clear standards, visible operational evidence, independent challenge, and consequences for unresolved deviation.

NASA’s own guidance is especially useful as a concise design test: require the system to be proven safe and effective to an acceptable risk level, rather than requiring someone to prove it is unsafe; deliberately prevent groupthink; keep safety assurance independent; and balance schedule and operational tempo against a comprehensive risk assessment. The Columbia Accident Investigation Board similarly identified organisational barriers to critical-safety communication, suppressed professional disagreement, fragmented management, and informal decision routes that operated outside formal rules.[1][4]
Make it operational
A practical way to turn the principle into routine management is to create a Deviation Review Loop.
1. Detect: Capture every material deviation from a standard, control, tolerance, approval route, or expected result—including near misses and “successful” workarounds.
2. Classify: Separate one-off human error, necessary emergency action, authorised exception, recurring workaround, and systemic control failure. The distinction matters because recurring workarounds are often the earliest warning.
3. Assess: Ask four questions:
- What standard or control was bypassed?
- Why did normal work require the bypass?
- What could plausibly happen under worse conditions?
- What evidence shows the risk is, or is not, controlled?
4. Decide formally: Either restore compliance, redesign the process/control, resource the required fix, or formally accept the residual risk at the right authority level. Do not leave the workaround unofficial.
5. Verify: Test whether the action changed behaviour and outcomes. For example, if a change was intended to prevent a repeat incident, look for a sustained fall in recurrence rather than merely a closed action item.
6. Escalate recurrence: A second or third instance should automatically attract more senior review. Repetition is not reassurance; it is evidence that the system may be adapting around a weakness.
Leadership behaviours
Leaders determine whether deviations are surfaced or buried. The most valuable behaviours are:
- Ask, “What are we doing outside the stated process to get the work done?”
- Ask for the uncomfortable data: overdue high-risk actions, repeated exceptions, near misses, control-test failures, unresolved audit findings, and red performance trends.
- Separate the question “Did we meet the deadline?” from “Did we meet the operating standard safely and reliably?”
- Thank people who expose problems early, especially when doing so delays a decision or delivery milestone.
- Do not reward heroic recovery from chronic under-resourcing while ignoring the conditions that made the heroics necessary.
- Personally test whether dissent reached the final decision-maker—not merely whether a meeting occurred.
A just culture is important here: people need confidence that reporting an error, near miss, or unsafe shortcut will trigger learning and improvement rather than automatic punishment. That does not mean no accountability; it means distinguishing deliberate disregard from a reasonable response to a poorly designed, poorly resourced, or contradictory system. Open communication, prompt treatment of deviations, continuous learning, and leaders willing to challenge unsafe practices even when it delays production are all highlighted as key prevention measures.[5][6]
Use the E1–E3 model
The Universal Framework is well suited to diagnosing this risk because it prevents an organisation from mistaking a written policy for a working capability. The useful test is:
For example, a project may have a formal stage-gate procedure at E1. It reaches E2 only when governance forums receive meaningful schedule, cost, risk, and readiness information and can intervene. It reaches E3 only when records show gates actually stop, redirect, rescope, or defer unready initiatives—and delivery outcomes improve as a result.
That is the broader lesson: a process that exists but is routinely bypassed is not a mature control; it is evidence of a capability gap.
Sources
[1] The Cost of Silence: Normalization of Deviance and Groupthink https://sma.nasa.gov/docs/default-source/safety-messages/safetymessage-normalizationofdeviance-2014-11-03b.pdf?sfvrsn=4
[2] Normalization of Deviance Is Contrary to the Principles … https://pubmed.ncbi.nlm.nih.gov/36971528/
[3] A Qualitative Systematic Review on the Application of the … https://safetyinsights.org/2022/02/17/a-qualitative-systematic-review-on-the-application-of-the-normalisation-of-deviance-phenomenon-within-high-risk-industries/
[4] Columbia Accident Investigation Board Report Executive … https://www.nasa.gov/wp-content/uploads/2024/03/sept4-caib-report-executive-summary.pdf?emrc=f4843a
[5] When Cutting Corners Becomes the Norm: How Normalizing Deviance … https://www.army.mil/article/286745/when_cutting_corners_becomes_the_norm_how_normalizing_deviance_can_lead_to_disaster
[6] The normalization of deviance in healthcare delivery – PMC https://pmc.ncbi.nlm.nih.gov/articles/PMC2821100/
[7] NASA’s Understanding of Risk in Apollo and Shuttle https://ntrs.nasa.gov/api/citations/20190002249/downloads/20190002249.pdf
[8] [PDF] Lessons Learned from the Aerospace Industry https://ehss.energy.gov/deprep/archive/documents/PM031023_CAIB.pdf
[9] Safety Culture Threat: Normalization of Deviance https://www.cer-rec.gc.ca/en/safety-environment/safety-culture/safety-culture-learning-portal/safety-culture-threat-normalization-deviance.pdf
[10] SEDLAR, N., IRWIN, A., MARTIN, D. and ROBERTS, R. 2023. A qualitative systematic review on the application of the https://rgu-repository.worktribe.com/preview/1822740/SEDLAR%202022%20A%20qualitative%20systematic%20review%20(AAM).pdf
[11] Marie Yolande Djedje https://researchportal.lsbu.ac.uk/ws/portalfiles/portal/11522043/Exploring_Normalization_of_Deviance_and_Examining_Factors_that_Predict_Negative_Patient_Safety_Outcomes_the_Case_of_the_Ivory_Coast_1_.pdf
[12] A qualitative systematic review on the application of … https://rgu-repository.worktribe.com/OutputFile/1822740
[13] ASHRM Patient Safety Tip Sheet: Normalization of Deviance in …www.ashrm.org › system › files › media › file › 2021/02 › Normalization-… https://www.ashrm.org/system/files/media/file/2021/02/Normalization-of-Deviance-in-Healthcare.pdf
[14] [PDF] Columbia and Challenger: organizational failure at NASA https://josephhall.org/papers/nasa.pdf - How could a Capability Assessment have helped the Sydney Swans
Given this is a live, real, and highly sensitive situation – an active police investigation into alleged sexual assault, real named individuals, and potential legal action, I’ll reflect on the organisational-capability question responsibly: focusing on the governance/culture/risk lessons in the abstract, grounded in what’s publicly reported, without speculating on guilt, criminal outcomes, or unverified claims.
Governance & Accountability – The core failure pattern here isn’t the absence of a code of conduct; the Swans have “Bloods culture” standards. It’s the gap between E1 (a defined standard exists) and E3 (the standard is executed and enforced before a crisis, not after). Reports describe the club discovering the incident, investigating, and sanctioning within about 48 hours – reactive, not preventative. A capability assessment would have surfaced, well before this week, whether the club’s behavioural standards had E2 evidence: active monitoring, a lived escalation pathway, and consequences applied consistently to star players, not just written policy.[4]
Risk & Resilience – Elite sporting clubs carry a foreseeable risk category: high-profile young athletes, alcohol, travel, hotel stays, media exposure. A mature risk domain would have this specific risk on the register with defined treatments (curfews, chaperoning protocols, post-match travel conduct rules) rather than relying on general conduct policy. The AFR’s read on this as “a cultural lesson for CEOs” is exactly this point – foreseeable risks that weren’t proactively treated.[18]
People Leadership & Culture – This is the domain most clearly exposed. Former co-captain Kieren Jack described the club’s “Bloods culture” as feeling “broken,” and reporting describes “strong resentment” within the playing group over how the situation was handled. A capability assessment doesn’t just check whether a values statement exists – the E2/E3 evidence would test whether leaders are equipped and are actually intervening on lower-level warning signs (out-of-hours conduct, past incidents, dressing-room dynamics) long before conduct escalates to something requiring police involvement.[5]
Decision-Making Quality – The club’s own chair and CEO have had to repeatedly clarify, across multiple statements, exactly what the sanctions do and don’t relate to. That kind of public re-explanation under pressure is often a symptom of decision rights and crisis-communication authority not being clearly pre-defined – precisely the E1 evidence (a defined decision framework with escalation paths) this domain tests for.[8]
Learning & Improvement – Chairman Andrew Pridham has now announced “a comprehensive review of the club’s culture” — which is the right instinct, but it’s happening after sponsors have paused partnerships, players have lost individual endorsements, and the club’s on-field season is compromised. A functioning Learning & Improvement capability would have been running this kind of review continuously (drawing on prior incidents across the AFL more broadly – this isn’t the code’s first such episode) rather than initiating it only once the story became a national one.[23]
The honest caveat
A capability assessment is a governance and organisational-design tool – it can surface whether the right structures, ownership, and enforcement patterns exist before a crisis, and it can prompt a club to close E1→E3 gaps ahead of time. It cannot predict or prevent individual criminal conduct, and it’s not a substitute for the active police investigation, which is still ongoing with no charges laid. The value here would have been entirely upstream: reducing the odds that gaps in enforcement, risk treatment, and culture accountability were allowed to sit at “Ad hoc” for as long as they evidently did.
Sources
[1] Swans players apologise after being banned for rest of … https://www.abc.net.au/news/2026-08-19/we-are-deeply-sorry-swans-players-break-silence-alleged-incident/107055864
[2] Fresh details emerge as Swans squad feels ‘strong resentment’ in wake of player bans https://www.news.com.au/sport/afl/moved-on-afl-legends-speak-out-as-sydney-swans-bloods-culture-in-tatters/news-story/b494d629599862eb75ebb0d88423b4f6
[3] Victoria Police issue warning to media over alleged sexual … https://www.theguardian.com/sport/2026/aug/20/sydney-swans-incident-coach-shock-anger-players-ban-ntwnfb
[4] Sydney Swans scandal is cultural lesson for CEOs https://www.afr.com/work-and-careers/workplace/swans-scandal-is-cultural-lesson-for-business-from-the-ceo-down-20260820-p60pym
[5] Sydney Swans face fresh assault allegations amid culture review https://www.youtube.com/watch?v=ux7gF9IzOkg
[6] AFL Players Association labels Swans allegations ‘very serious’ https://www.abc.net.au/news/2026-08-20/afl-players-association-labels-swans-allegations-serious/107055982
[7] Sydney Swans say players ‘in serious breach’ of club … https://www.abc.net.au/news/2026-08-18/sydney-swans-players-in-serious-breach-of-club-standards/107051708
[8] Advocates welcome official responses to Sydney Swans … https://www.abc.net.au/news/2026-08-19/sydney-swans-questions-afl-policy-sexual-assault-allegations/107051552
[9] Sexual assault allegation involving Sydney Swans a sign … https://www.abc.net.au/news/2026-08-21/sydney-swans-allegations-reflects-misogyny-in-afl-culture/107056180
[10] ‘Awful mess’: Swans’ standing ‘out the window’… and trade scenario they ‘won’t shy away from’ https://www.foxsports.com.au/afl/teams/sydney-swans/afl-news-2026-sydney-swans-player-incident-five-starts-stood-down-bloods-culture-crisis-isaac-heeney-nick-blakey-chad-warner-trade-contract-status/news-story/1b62eb1dea14961e6407c7a44a364909
[11] Anger and hurt across AFLW after Sydney Swans allegations https://www.abc.net.au/news/2026-08-20/aflw-put-under-uncomfortable-spotlight-after-mens-players-saga/107054688
[12] Sydney Swans sponsors suspend partnerships with … https://www.abc.net.au/news/2026-08-20/sydney-swans-sponsors-suspend-partnerships/107058932
[13] Sydney Swans scandal deepens as women raise safety fears https://www.nation.com.pk/20-Aug-2026/sydney-swans-scandal-deepens-women-raise-safety-fears
[14] Sydney Swans coach ‘extremely disappointed’ as club faces call on … https://www.theguardian.com/sport/2026/aug/18/sydney-swans-coach-extremely-disappointed-as-club-faces-call-on-standing-down-players-over-alleged-sexual-assault-ntwnfb
[15] Sydney Swans involved in ‘alleged incident’ as police … https://www.abc.net.au/news/2026-08-17/sydney-swans-afl-footballers-involved-in-incident-in-melbourne/107046058
[16] Sydney Swans scandal deepens with new allegations | 7NEWS https://www.youtube.com/watch?v=nGtV5e_ZU9A
[17] Sydney Swans AFLW Captain opens up about a club in crisis https://www.sbs.com.au/news/podcast-episode/sydney-swans-aflw-captain-opens-up-about-a-club-in-crisis-evening-news-bulletin-21-august-2026/xquk5kc5f
[18] Sydney Swans under investigation over alleged sexual … https://www.youtube.com/watch?v=Ktov0YQjrgc
[19] The Swans abandoned the old-school script. What happens next will shape the club’s future https://www.theage.com.au/sport/afl/the-swans-abandoned-the-old-school-script-what-happens-next-will-shape-the-club-s-future-20260819-p60pks.html
[20] Sydney Swans will sanction players for ‘serious breach’ over … https://www.theguardian.com/australia-news/2026/aug/18/afl-chief-breaks-silence-over-deeply-concerning-sydney-swans-sexual-assault-allegations-ntwnfb
[21] Sydney Swans fans grapple with scandal ahead of double- … https://www.abc.net.au/news/2026-08-23/swans-fans-grapple-with-scandal-ahead-of-double-header/107066804
[22] Sydney Swans suspend five players for rest of season | 7NEWS https://www.youtube.com/watch?v=9GzFQv3DzaI
[23] Suspended Sydney Swans players issue apology for their behaviour | 7.30 https://www.youtube.com/watch?v=eXTWRmjhzyA
[24] Swans CEO ‘shocked’ by allegations https://www.theage.com.au/sport/afl/swans-ceo-shocked-by-allegations-20260817-p60p33.html
[25] AFL referred to antisemitism royal commission after opening round speech controversy https://www.abc.net.au/news/2026-03-16/afl-antisemitism-royal-commission-sydney-swans/106460880
[26] Swans private ownership: the soaring highs but inevitable lows https://www.espn.com/afl/story/_/id/45833015/afl-sydney-swans-40-years-vfl-private-ownership-geoffrey-edelsten-part-2
[27] “Culture is fluid, it’s not a tattoo” is the biggest lesson for Bob … https://www.facebook.com/abcsport.au/videos/culture-is-fluid-its-not-a-tattoo-is-the-biggest-lesson-for-bob-murphy-out-of-th/2281712042368710/
[28] New Twist In Sydney Swans Hotel Saga As Two Women Try Sue For Their ‘Suffering’ | 10 News https://www.youtube.com/watch?v=Cxl0aKXBgns
[29] WATCH: AFL CEO questioned about Sydney Swans Scandal … https://www.youtube.com/watch?v=Sm4XnMrrFgY
[30] ‘Embarrassed & Ashamed’ 🗣️ Swans bosses front media as ‘culture problem’ questioned | Fox Footy https://www.youtube.com/watch?v=OL6deqU9cNo - How could Candid Cycle have helped the Sydney Swans?
“If this needs explaining tomorrow, it needs challenging tonight.”
Candid Cycles could not guarantee that the Sydney Swans avoided an alleged incident, nor should it replace police processes. But it could help a club make its behavioural standards real in high-risk settings—especially away trips, alcohol, group dynamics and team hotels—through reflection, peer challenge, early intervention and accountable follow-through.

Candid Cycle Shift from rules to practice
Most clubs already have codes of conduct, alcohol rules and education programs. The weakness is often the gap between knowing a rule and applying judgement in a live social situation.
The aim is not paternalism. It is to make personal responsibility and peer intervention concrete before judgement is impaired or group norms take over.
Strengthen group accountability
Where several players are involved in an off-field episode, the core control is not merely individual compliance—it is collective responsibility. A Candid Cycle-based process could equip leaders, senior players and teammates to interrupt emerging risk rather than treat it as someone else’s private matter.
Practical controls might include:
- A designated player leadership pair and welfare contact for each away trip.
- Explicit expectations that players intervene or report where another person may be unsafe, impaired or unable to consent.
- A confidential, no-delay pathway for players, staff, hotel personnel or guests to raise concerns.
- A protected post-event debrief that separates welfare and safeguarding facts from rumour, media management and disciplinary decision-making.
- A recurring thematic review of alcohol-related incidents, near misses, complaints and policy exceptions.
The key distinction is between an incident and a near miss. A player who intervenes, leaves a situation, calls for help or reports concern should be reinforcing the culture—not “dobbing.”
Improve crisis learning
After an event, Candid Cycle could provide a defensible learning system without prejudging an ongoing investigation. It would document:
- What standards, travel controls and support arrangements were in place.
- What warning signs, decisions and interventions occurred before and during the event.
- What the club knew, when it knew it, and which escalation paths were activated.
- Which actions are appropriate immediately—such as welfare support, evidence preservation, stand-down decisions and safeguarding changes.
- What longer-term corrective actions need board-level ownership and assurance.
That is particularly important because advocates have welcomed firm responses while also raising questions about timing and AFL policy settings. The club’s current sanctions are substantial, but sanctions are retrospective. A disciplined capability cycle is designed to create prevention, early interruption and organisational learning.^3
Candid Cycle proposition
For the Swans—or any elite sporting organisation—the proposition would be:
Turn values, consent and behavioural standards into a repeatable team practice: anticipate risk, challenge early, act safely, learn without defensiveness, and verify that safeguards work.
This would complement, not substitute for, independent safeguarding, employment processes, police investigation and legal advice. It also preserves the crucial principle that no conclusion should be drawn about alleged criminal conduct before the relevant investigation is complete.
- How Could Candid Cycle have helped KPMG?
Candid Cycle could not guarantee that misconduct never occurred, but it could have made it harder to normalise, conceal, and mishandle. Its greatest value would be as a structured, evidenced learning-and-escalation system around sensitive engagements, bid decisions, and whistleblower concerns.

KPMG Australia’s crisis reportedly centres on alleged misuse of confidential client material to pursue other audit work, alongside serious criticism of how a whistleblower’s concerns were handled. The fallout has included leadership departures, client distrust, parliamentary scrutiny and regulatory investigation.[1][2][3]
Where the control system failed
The apparent issue was not merely an individual breach of confidentiality. It was a breakdown across several organisational capabilities: Capability Apparent failure Consequence Information stewardship Confidential client information was allegedly accessed or used outside an authorised purpose Fundamental loss of client trust Ethical decision-making Commercial incentives may have overpowered professional obligations Conduct perceived as “revenue growth at all costs” Speak-up culture The whistleblower was reportedly pressured and subject to a covert computer search Deterrence of future reporting Escalation and assurance Concerns were not independently and transparently resolved early A manageable internal issue became a public institutional crisis Organisational learning Similar warning signals were not converted into systemic corrective action Repetition, delay and reputational contagion
Clients including Lendlease, Westpac, Optus, Dexus and Macquarie subsequently expressed or signalled doubts about KPMG’s trustworthiness; Lendlease moved away from the firm after the breach.[3][4]
How Candid Cycle could help
1. Turn sensitive work into a deliberate reflection point
For each high-risk audit, tender, client transition or cross-account pursuit, Candid Cycle could require a short structured debrief:
- What confidential information did we encounter?
- What was the authorised purpose, access basis and retention rule?
- Did anyone suggest using insights, documents or relationships beyond that purpose?
- What conflicts or incentives affected judgement?
- What action is required before the next bid, client interaction or decision?
This changes “ethical conduct” from a policy people attest to annually into a recurring operational practice. It also provides early visibility where teams are rationalising boundary-crossing behaviour.

2. Make the conflict visible before a bid
A useful Candid Cycle workflow would link the learning cycle to a formal confidentiality-and-independence challenge before a tender is approved:
- Experience: Identify relevant existing client knowledge, systems access, documents and personnel involvement.
- Reflection: Ask whether any of that knowledge creates actual or perceived misuse risk.
- Sense-making: Compare the situation with professional standards, client commitments and internal policy.
- Action: Record a decision—ring-fence, remove people, seek client consent, decline the opportunity, or escalate for independent review.
- Review: Assess whether the controls worked after the bid or engagement.
The critical point is that the record should preserve not only the conclusion, but the reasoning, dissenting views, mitigation owners and review date.
Whistleblowing is the sharper use case
The most consequential Candid Cycle application may have been after the first concern was raised. A properly governed issue-learning cycle would distinguish a concern about misconduct from a people-management problem.
It could establish:
- A protected, independently administered channel for issue capture and follow-up.
- A prohibition on investigating the reporter except where narrowly necessary, independently authorised and legally justified.
- A transparent case pathway: allegation, containment, evidence preservation, conflict check, independent investigator, findings, remediation, assurance review.
- Anonymous or confidential thematic reporting to a board-level ethics, audit or risk body.
- A tracked “lessons-to-controls” register so that findings produce changes to access controls, tender governance, training, incentives and quality assurance.
That matters because public reporting indicates the whistleblower’s treatment became a major part of the trust damage—not simply the original allegations.[3][5]
Design principles for Candid Cycle
For an organisation such as KPMG, Candid Cycle should not be positioned as a generic retrospective tool or culture survey. It should operate as a capability-assurance layer with clear safeguards:
- Independence: High-severity cases route outside the implicated business line.
- Evidence integrity: Time-stamped records, defined permissions, auditable amendments and retention controls.
- Psychological safety: Confidential reporting, explicit non-retaliation protections and monitored retaliation indicators.
- Decision accountability: Named decision owners, due dates and escalation thresholds.
- Thematic intelligence: Detect recurring patterns across service lines, offices and clients without exposing unnecessary case detail.
- Board-ready reporting: Aggregate indicators on confidentiality, conflicts, speak-up health, overdue actions and control effectiveness.
For example, a dashboard might show that five separate bid debriefs flagged “informal use of client intelligence” as a concern. That is not a training issue to file away; it is a leading indicator demanding immediate intervention.
The strategic proposition
Candid Cycle’s pitch in this setting is not “help people be more candid.” It is:
Help organisations convert uncomfortable signals into protected escalation, defensible decisions, verified corrective action and demonstrable learning—before those signals become a crisis.
KPMG’s case illustrates that trust is lost through a sequence: boundary crossing, rationalisation, weak challenge, poor response to dissent, opacity, and then external exposure. A disciplined cycle of reflection, escalation, action and independent verification could interrupt several of those links—even if it cannot eliminate every instance of misconduct.
Sources
[1] Breakingviews – KPMG’s self-destruction puts Big Four on notice https://www.reuters.com/commentary/breakingviews/kpmgs-self-destruction-puts-big-four-notice-2026-06-26/
[2] Australia regulator reviews audit conduct complaints at Big Four … https://www.reuters.com/sustainability/australia-watchdog-reviews-big-four-audit-complaints-after-kpmg-allegations-2026-07-08/
[3] KPMG Australia under fire as parliamentary committee … https://www.abc.net.au/news/2026-06-19/kpmg-inquiry-scandal-accounting-industry-parliamentary-hearing/106817096
[4] Macquarie, Westpac, Dexus, Optus cast doubt over ‘ … https://www.abc.net.au/news/2026-08-14/macquarie-westpac-dexus-optus-grilled-kpmg-audit-leaks-inquiry/107034656
[5] Leaks, lawyers and a whistleblower: how did KPMG’s failings emerge – and could more have been done? https://www.theguardian.com/australia-news/2026/jun/28/kpmg-failings-leaks-lawyers-whistleblowers-partners-consultancy-firm
[6] Navigating an erosion in trust https://kpmg.com/us/en/articles/2026/february-2026-economic-compass.html
[7] ‘Fundamental breach of trust’ by KPMG: Lendlease chairman https://www.afr.com/companies/professional-services/fundamental-breach-of-trust-by-kpmg-lendlease-chairman-20260619-p608bi
[8] KPMG lost its clients’ trust, yet kept winning government contracts. Here’s what needs to change https://theconversation.com/kpmg-lost-its-clients-trust-yet-kept-winning-government-contracts-heres-what-needs-to-change-284733
[9] KPMG the latest example of accountants being … https://www.abc.net.au/news/2026-06-18/kpmg-scandals-in-accounting/106810630
[10] KPMG partners scramble for exits as whistleblower fallout escalates https://www.afr.com/companies/professional-services/kpmg-partners-scramble-for-exits-as-whistleblower-fallout-escalates-20260604-p603u3
[11] KPMG faces first major client loss from whistleblower scandal https://www.smh.com.au/business/companies/kpmg-faces-first-major-client-loss-from-whistleblower-scandal-20260601-p602rf.html
[12] AI hallucinations spark a trust crisis for consulting firms https://www.emarketer.com/content/ai-hallucinations-spark-trust-crisis-consulting-firms
[13] Inquiry: KPMG has lost public confidence https://greens.org.au/news/media-release/inquiry-kpmg-has-lost-public-confidence
[14] Trust breaks down in a predictable order: Big challenge for … https://www.crikey.com.au/2026/07/10/big-four-kpmg-ey-deloitte-pwc-trust-accountability/
[15] Weekend Reading: KPMG — Trust as a Service … https://www.linkedin.com/pulse/weekend-reading-kpmg-trust-service-accountability-threat-bt7hc - Push the envelope
- “Missed it by that much” …
is an old joke from the TV series ‘Get Smart”
https://youtube.com/shorts/PmMjifK0L5A?is=tO52zmmDYGT3cxcVThis week I missed a connecting flight in Frankfurt. Having come from Australia I needed to clear the new border entry requirements.

I appreciate the strategy of needing to check at the first point of entry.
I did not appreciate how poorly the integration of this requirement was being implemented in airport systems.
The failure to have adequately premised this fundamental “what if” is fairly widespread in scope, because the new EU Entry/Exit System now applies across the 29-country Schengen area, but the actual disruption is uneven rather than universal at every airport all day. The biggest problems have been reported at external-border passport control points during peak waves of arrivals, where airports and airlines have recorded missed flights and typical waits of 2–3 hours, with some cases even longer.[2][4][5]Where it is happening
Airports Council International Europe said data from airports in 15 countries showed border-control waiting times had “significantly increased” after full operation began. Reported trouble spots have included airports in France, Germany, Belgium, Italy, Spain, and Greece, while other reporting also highlighted major issues in Spain, Portugal, France, and Italy.[7][1]
How uneven it is
This is not a case of every passenger everywhere facing the same delay: the European Commission said the system was working “very well” in most countries and that the average registration took just over a minute, though it acknowledged technical issues in a few countries. Separate reporting also noted that some travelers clear controls quickly in quieter periods, while queues spike when several flights arrive close together or equipment and staffing fall short.[8][1]
What it means for connections
The risk is highest for passengers who must clear Schengen external-border control during a connection, because that is where the biometric registration happens for eligible non-EU travelers. Industry groups have warned that these checks have already increased processing times by several multiples and, during peaks, created enough delay for passengers to miss onward flights.[4][5]
How long this may last
There is some built-in flexibility while authorities stabilize the rollout: under the current rules, certain border points can temporarily suspend biometric collection in exceptional circumstances when queues become excessive, with this flexibility available through July and, under conditions, likely into September. That suggests the bottleneck is likely to remain a recurring issue through the busy summer period, but probably as a patchy, airport-by-airport problem rather than a constant continent-wide shutdown.[1]
I should have done my homework and been better prepared (a one hour and 48 minute layover was inadequate) – so revisiting your upcoming schedule might be worth considering.
Sources
[1] Travelers Flying to Europe Face Long Lines Due to New Immigration … https://www.businessinsider.com/europe-travel-airport-lines-immigration-passport-control-border-checks-2026-4
[2] ‘A systemic failure’: How the new Entry/Exit System (EES) … https://www.euronews.com/travel/2026/04/14/a-systemic-failure-how-the-new-entryexit-system-ees-brought-chaos-to-eu-border-control
[3] Entry/Exit System (EES) is fully operational https://home-affairs.ec.europa.eu/news/entryexit-system-ees-fully-operational-2026-04-10_en
[4] EES: The new European border Entry/Exit System goes live on 10 … https://www.diplomatie.gouv.fr/en/presse-et-ressources/decouvrir-et-informer/actualites/ees-le-nouveau-systeme-europeen-de-gestion-des-frontieres-entre-en-service-le-10-avril-2026
[5] Entry Exit System disruptions on first day of full operations … https://www.aci-europe.org/media-room/590-entry-exit-system-disruptions-on-first-day-of-full-operations-affirm-yet-again-the-immediate-need-for-flexibility.html
[6] Travel industry fears summer disruption amid new biometric checks at European borders https://www.theguardian.com/world/2026/feb/05/travel-industry-fears-summer-disruption-biometric-checks-controls-ees-european-borders
[7] New EU entry-exit system causing up to three-hour delays, say airports https://www.theguardian.com/world/2026/apr/15/eu-entry-exit-system-ees-delays-airports-border-checks
[8] Warning of long airport queues under new EU border control system https://www.bbc.com/news/articles/cn0k699pxwzo
[9] EES checks paused? EU responds over … – Connexion France https://www.connexionfrance.com/news/ees-checks-paused-european-commission-responds-to-media-reports/789666
[10] New airport ESS border check delays and how to avoid them – BBC https://www.bbc.com/news/articles/c5yvv7jjny4o
[11] New European border rules have caused delays at airports across … https://www.facebook.com/bbcmanchester/posts/new-european-border-rules-have-caused-delays-at-airports-across-the-continent-af/1387431516752858/
[12] New border rules could mean longer airport queues – LARA https://www.laranews.net/new-border-rules-could-mean-longer-airport-queues/
[13] Passenger misses flight after 3 hour queue caused by new EU entry … https://www.youtube.com/watch?v=C_dQsW6sv8s
[14] Travel Disrupted By New EU Border Control System – Aviation Week https://aviationweek.com/air-transport/airports-networks/travel-disrupted-new-eu-border-control-system
[15] Travellers Told to Expect Long Delays Ahead of New EU Entry Rules https://www.businesstraveller.com/news/travellers-told-to-expect-long-delays-ahead-of-new-eu-entry-rules/
[16] Long queues have built up at some airports around Europe as the … https://www.facebook.com/Channel4News/videos/long-queues-have-built-up-at-some-airports-around-europe-as-the-eus-new-digital-/1298777608889495/
[17] The system has resulted in long waits at EU borders, which has … https://www.facebook.com/ManchesterEveningNews/posts/%EF%B8%8F-the-system-has-resulted-in-long-waits-at-eu-borders-which-has-even-caused-some/1449018343927193/
[18] ‘Chaos’: German opposition slams EU’s new entry-exit system at … https://www.aa.com.tr/en/europe/chaos-german-opposition-slams-eu-s-new-entry-exit-system-at-borders/3917001
[19] EasyJet passengers describe new EU border controls ‘nightmare’ https://www.reddit.com/r/worldnews/comments/1skfqfh/easyjet_passengers_describe_new_eu_border/
[20] EU postpones full EES until September 2026 – Tragento https://tragento.com/en/the-eu-postpones-the-full-ees-until-September-2026–the-goal-is-to-avoid-summer-congestion-at-the-borders/
[21] Italy to Suspend Biometric Border Checks at Busy Airports, Reverts … https://www.visahq.com/news/2026-05-05/it/italy-to-suspend-biometric-border-checks-at-busy-airports-reverts-to-passport-stamps-until-30-september/
[22] The Entry/Exit System will become fully operational on 10 April 2026 https://home-affairs.ec.europa.eu/news/entryexit-system-will-become-fully-operational-10-april-2026-2026-03-30_en
[23] RYANAIR CALLS ON FRENCH GOVT TO SUSPEND EES UNTIL … https://corporate.ryanair.com/news/ryanair-calls-on-french-govt-to-suspend-ees-until-sept-to-prevent-passengers-families-suffering-long-passport-control-queues-this-summer/
[24] EES: The new European border Entry/Exit System goes live on 10 … https://www.diplomatie.gouv.fr/en/services-to-foreigners/visiting-france/ees-the-new-european-border-entryexit-system-goes-live-on-10-april-2026
[25] The European Union has postponed the rollout of its Entry/Exit … https://www.instagram.com/p/DVJyK5GAV9l/
[26] Airports and airlines call for immediate Schengen Entry/Exit … https://www.aci-europe.org/press-release/582-airports-and-airlines-call-for-immediate-schengen-entry-exit-system-ees-review-ahead-of-peak-summer-months-traffic.html
[27] Europe’s Digital Border Entry and ETIAS Launching in 2026 – AFAR https://www.afar.com/magazine/europes-etias-travel-entry-requirement-delayed-until-2026
[28] New EU entry rules and safety warnings for 2026 travel – Facebook https://www.facebook.com/groups/727019224852007/posts/1936630327224218/The new strategy (the EU Entry/Exit System and related border-police procedures) came in the way it did mainly because political and security pressures to “modernise” and digitise borders outweighed the practical preparation needed in airports, IT systems, and staffing.[1][2]
What the EU was trying to do
The Entry/Exit System is a long‑planned project to replace manual passport stamps with a shared EU database containing biometric data (fingerprints and facial images) and entry/exit records for all non‑EU nationals. EU institutions sold it as the “digital backbone” of a new migration and security framework: a way to track overstayers, combat identity fraud, and harmonise fragmented national border records.[2]
Why preparation lagged behind
Although the idea dates back years, the project suffered repeated delays due to technical and budget issues, leaving a compressed window to get infrastructure, training, and staffing ready before the final legal “go live” date. Analysts and lobby groups note that, by launch, many border posts still had understaffed control booths, incomplete or poorly tested equipment, and unclear procedures for handling people already in the database.[1][2]
Warnings that were not fully heeded
Airport and airline associations had warned for months that the new checks, if introduced without extra staff and real stress‑testing at busy hubs, would inevitably create bottlenecks and missed connections. Reporting after rollout quotes industry voices saying EU decision‑makers underestimated operational realities and pushed ahead despite these warnings, leading to gridlock that was “predictable” from an airport-operations point of view.[2][1]
Politics versus practicality
Commentary from both media and policy analysts suggests there was strong political desire to show visible progress on “stronger borders” and migration control after years of debate. That made it harder to delay again, even though many practical pieces (hardware reliability, phased passenger trials, and common fallback procedures) were not fully in place, so the system arrived more on political schedule than on operational readiness.[1][2]
Structural design choices that made it rough
The EU chose a relatively short transition period where old manual passport stamping coexists with the new biometric system, which experts say is “a recipe for confusion and delay” because it doubles complexity at the frontier. Responsibility is also split between Brussels (which builds the rules and central system) and member states (which must staff and equip the actual border posts), so any weak link in that chain shows up as queues for passengers.[2][1]
If you’re mainly worried about your own trips, do you mostly connect through big hubs like Paris/Frankfurt/Amsterdam, or are your connections usually within Italy and other Schengen countries only?
Sources
[1] EUROPE’S BORDER TEST FALTERS! New Digital Checks Triggers Airport Gridlock | Times Now World https://www.youtube.com/watch?v=7CEopNG_LkY
[2] Europe’s new border control system faces early turbulence https://eualive.net/europes-new-border-control-system-faces-early-turbulence/
[3] Europe’s Border Test Backfires, Airports Struggle With New Digital Controls | Watch https://www.youtube.com/watch?v=cLrAiP-AmUw
[4] [PDF] Challenges for Integrated Border Management in the European Union https://www.dcaf.ch/sites/default/files/publications/documents/OP17_Marenin.pdf
[5] [PDF] Restoring the Borderless Schengen Area: Mission Impossible? https://sieps.se/media/4ylfst2h/2024_12epa.pdf
[6] Frontex – Wikipedia https://en.wikipedia.org/wiki/Frontex
[7] Border controls and pushbacks as the new normal? The … https://www.aisdue.eu/wp-content/uploads/2025/01/Post-Anna-Kompatscher.pdf
[8] NEW_DOKLAD.indd https://csd.eu/fileadmin/user_upload/publications_library/files/2011/2011_04_ENG_Better_Management_of_EU_Borders.pdf
[9] Frontex Failing to Protect People at EU Borders – Human Rights Watch https://www.hrw.org/news/2021/06/23/frontex-failing-protect-people-eu-borders
[10] Microsoft Word – EUborderpolice3.doc https://www.statewatch.org/media/1101/cover-up-proposed-regulation-on-european-border-guard-hides-unaccountable.pdf - Capability Assessment Method – Overview
Purpose
This assessment provides a concise, evidence‑based view of how well the organisation is set up to run, grow, and handle shocks, not just how much documentation it has. It combines a practical business lens with proven public‑sector and private‑sector capability models.
Framework structure
The method assesses capability across 11 domains that together describe how the business works:
- Context, Scope, Stakeholders & Strategy
- Leadership, Governance, Culture & Accountability
- Integrated Risk & Opportunity Management
- Framework, Design & Integration into Operations
- Planning, Objectives, Strategies & Change
- People, Capability, Culture, Communication & Awareness
- Customers, Markets, Stakeholders & Supply Chain
- Operational Control, Design, BCM Plans & Emergency Response
- Information, Data, Documentation & Digital
- Performance Measurement, Monitoring, Exercising & Review
- Learning, Improvement, Innovation & Resilience Evolution
Each domain is assessed using evidence questions tailored to the organisation’s size, context, and sector.
Three evidence tests (E1–E3)
For each domain we look for three levels of evidence:
- E1 – Exists
Do the core structures and processes exist?
(Policies, frameworks, processes, roles, plans, registers, documented approaches.) - E2 – Enabled
Are they supported and usable?
(Clear owners, resources, training, tools, data, and regular review cycles.) - E3 – Executed
Are they actually used and making a difference?
(Real examples where they shape decisions, behaviours, investments, and outcomes.)
In practical terms, E1/E2 tell you “have we built the system?” and E3 asks “does the system change what happens?”
Maturity scale (N–P–L–F)
Evidence across E1–E3 is then converted into a four‑step maturity rating for each domain:
- N – Absent
No meaningful evidence; capability does not meet current needs. - P – Ad hoc
Informal, person‑dependent, inconsistent; pockets of good practice but not reliable. - L – Defined
Documented and repeatable, but weakly enforced; often strong on design, weaker on routine use. - F – Operational
Embedded, consistent, tested, and reviewed; good evidence that it works in practice.
The assessment also considers how well each domain is positioned for future challenges, using concepts like Emerging, Developing, Embedded, and Leading as narrative descriptors, but N/P/L/F remains the formal rating scale.
Outputs
A typical assessment delivers:
- Overall maturity position (e.g. percentage at Defined vs Operational).
- Domain‑by‑domain ratings and commentary, highlighting strengths, gaps, and underlying evidence.
- A simple heat‑map or scorecard showing current and target maturity across the 11 domains.
- A short list of priority gaps and practical actions, sequenced so effort is focused where it matters most.































