Start free trial
Public sector

Four risk tiers an auditor could actually follow

Scores come out of a visible, versioned rules engine. Every tier decision lists the inputs that moved it as the auditor asked.


Eleanor Whitfield

Head of Assurance, Civic Grid

Published

2 min read

Results at the first assurance review

From kick-off to the first vendor scored under the published model
3 weeks
Of tier decisions reproducible from the recorded inputs alone
100%
Risk tiers, published and version-controlled rather than described
4

Measured at Civic Grid's first internal assurance review under the new model, February 2026.

“Explain how this vendor got a medium”

Civic Grid’s assurance team could describe its risk model in a meeting. It could not reproduce a score.

The rating came out of a spreadsheet that had been edited by eleven people over four years. Some weightings were in cells, some in a macro, and at least one adjustment existed only as a habit that two reviewers shared and had never written down. When an auditor asked why a vendor had been rated medium rather than high, the honest answer took an afternoon and ended in “because that is what the sheet returned”.

For a body operating under public contract, that answer is a finding waiting to happen.

Rules that are a document, not a habit

The model is now four tiers driven by a rules engine Civic Grid writes and versions itself. Each rule is a sentence with a weighting attached, the whole set is published internally, and every change is a dated revision with an author against it.

The consequence that mattered most was not the scoring — it was the record. A tier decision now carries the inputs that produced it: which answers, which evidence, which rule version. Re-running a 2026 decision against the 2026 rules gives the 2026 answer, permanently.

“The auditor asked the same question she asked last year. This time it took one screen instead of an afternoon, and the answer did not depend on me being in the room.”

Three weeks to live

  • Kick-off to first scored vendor was three weeks, most of it spent agreeing the rules rather than configuring anything.
  • All 310 existing vendors were re-scored under the published model, which moved 24 of them a tier — 19 down, 5 up. Each move lists the rule that caused it.
  • Every tier decision in the first assurance review was reproducible from its recorded inputs, with no reviewer present to interpret.

What’s next

Civic Grid is publishing the tier definitions to bidders as part of the procurement pack, so a supplier can see what tier it is likely to land in before it tenders.


About Civic Grid

Civic Grid operates regional water and energy infrastructure under public contract. 1,100 people across twelve offices, subject to NIS2 and to its own procurement framework. Eleanor Whitfield heads the assurance function.

More customer stories

A locked shield rendered over a data centre, representing protected clinical records
Healthcare

−84% review time

38 days to 6, across 240 clinical vendors

A hospital group routed intake by data sensitivity instead of by whoever picked up the ticket. Two analysts clear the queue weekly.


Northwind Health

A compliance monitoring dashboard on a desk display in a darkened office
Fintech

0 audit findings

Walked into a PCI audit with the evidence already collected

Control responses, SOC 2 reports and pen tests were already in the vault when the assessor asked. Nobody spent the week chasing PDFs.


Ledgerline

Glowing data pathways routing across a dense circuit landscape
Marketplace

3× volume, same team

1,200 sellers onboarded without adding a reviewer

Low-risk sellers clear an automated tier in minutes; only the top two tiers reach a human. The review team stayed at four people.


Kestrel Market