For decades, a large part of professional advisory work has followed a surprisingly stable pattern. An organisation wants to understand the maturity, risk, compliance or quality of something. Consultants arrive. Interviews are organised. Documents are requested. Questionnaires are distributed. Evidence is collected. Workshops follow. The material is analysed and eventually condensed into findings, classifications, recommendations and a report.
The quality of the outcome may be excellent. The people involved may be highly experienced. But the operating model itself increasingly belongs to another era.
The problem is not consulting – or consultants.
The problem is that too much expert time is still spent discovering what could increasingly be established by evidence before the expert even enters the room.
A cybersecurity assessment, privacy review, AI governance assessment, cloud maturity review, architecture assessment or regulatory readiness exercise often starts by rebuilding the current state from fragments. One team has the architecture diagram. Another knows what actually happens in production. A third owns the policies. Someone else understands the exceptions. Source code says one thing, documentation another, and operating practice perhaps something else again.
The consultant becomes the integration layer. That is expensive. It is slow. More importantly, it creates an unnecessary dependency on who conducts the assessment, which questions are asked, what evidence happens to be available and how contradictions are interpreted. There is a better model emerging - and it does not remove experts. It removes a great deal of work that should no longer require experts.
From asking for the truth to assembling the evidence
The traditional assessment begins with questions. The emerging model begins with evidence. This distinction sounds small, but it changes almost everything.
Instead of asking an organisation to describe its current state and then attempting to validate the description, an evidence-driven assessment can start from the artefacts the organisation already produces through normal work: system configuration, source code, architecture material, policies, logs, tests, inventories, access models, technical documentation and operating records. Interviews and assessments still matter, but their role changes.
People are exceptionally valuable for explaining intent, exceptions, ownership, history, business constraints and why something exists. They are much less reliable as substitutes for technical reality. A workshop may explain why a security control is configured in a particular way. It should not be allowed to prove that the control exists.
- A document may describe the desired operating model. It should not automatically prove that the operating model is actually followed.
- Source code may demonstrate implementation. It does not automatically prove that the functionality has been successfully tested in the relevant environment.
Narrow assessments are becoming increasingly artificial
There is another weakness in the traditional model: assessments are often organised according to professional disciplines rather than according to the reality of the system being assessed.
- Privacy performs a privacy assessment.
- Security performs a security assessment.
- Architecture performs an architecture review.
- AI governance performs an AI assessment.
- Accessibility performs another review.
- Risk, legal, internal audit and compliance may each run their own processes.
Yet there is only one actual digital solution underneath all of them.
The same authentication mechanism may matter to cybersecurity, privacy, regulatory compliance and internal policy. The same logging architecture may be relevant to security, accountability, auditability and AI governance. The same data flow may trigger privacy, confidentiality, copyright and contractual questions.
Why should the organisation repeatedly collect essentially the same reality merely because the requirements come from different disciplines?
This is where the next generation of assurance becomes much more interesting than simply automating questionnaires. The opportunity is to move from:
toward:
The question then changes from “How mature are we according to this framework?” to something much more useful:
What does the evidence demonstrate about this actual solution, and which requirements does that evidence support, contradict or leave unresolved?
That is a much more powerful question.
Solution Assurance as an example
The Solution Assurance Assessment, supported by the Solution Assurance Engine, is one example of how this model can work. Its starting point is not a questionnaire or an assumption that documentation represents reality. It starts by using the Solution Assurance Engine to analyse and understand several representations of the same solution: the declared purpose, the documentation, the implementation, the testing and the observed behaviour. The objective is deceptively simple:
Do these representations actually describe the same solution?
A solution may be described as advisory while its implementation allows consequential decisions. Documentation may describe human approval while the code provides a bypass. A privacy boundary may exist in policy but not in configuration. Testing may demonstrate one behaviour while production monitoring reveals another. These are not merely technical inconsistencies. They are often where the most important assurance questions live.
The Engine therefore does not treat all evidence equally and does not allow every analytical statement to become a conclusion. Evidence is classified according to what it can actually prove. Candidate claims can be challenged and verified before they become findings. Contradictions can remain visible rather than disappearing inside a polished narrative. Only verified and locked findings are allowed to influence readiness conclusions, gates or proposed actions.
AI can help enormously inside such a system. It can interpret complex relationships, compare evidence, detect inconsistencies, generate alternative explanations and synthesize findings. But AI does not need to become the authority.
That distinction matters.
From evidence to verified readiness — with human authority kept outside the model.
The significance of this architecture is not that AI suddenly becomes capable of replacing every expert involved in assurance. The significance is that the system can perform much of the evidence work before scarce expertise is consumed. The effect is this: the consultant does not disappear; the consultant moves upstream.
And this is where the discussion about automation often becomes unnecessarily defensive: if software can analyse thousands of technical artefacts in hours, does that mean consultants disappear?
No.
It means we should stop paying consultants to spend most of their time doing work that software can increasingly do better. Expertise becomes more valuable when it is applied to uncertainty, materiality, consequences, competing priorities and actual change.
Imagine two consulting engagements.
- 1
In the first, specialists spend weeks requesting documentation, organising interviews, reconciling spreadsheets, reviewing technical artefacts, discovering inconsistencies and preparing a current-state presentation. Only near the end does the conversation move to what should actually change.
- 2
In the second, much of that baseline has already been assembled. Evidence has been classified. Missing areas are visible. Contradictions have been surfaced. Findings have been challenged. The expert enters the discussion with a structured view of what is known, what is uncertain and what genuinely requires judgment.
Which engagement uses expertise more intelligently? The second model does not reduce the value of consultants. It removes low-value friction around their expertise. The work shifts from collecting evidence and describing the current state toward interpreting consequences, designing change, validating priorities and helping the organisation implement what should happen next.
That is a positive transition: it moves professional services closer to value creation. The real prize is not a faster report: if an assessment that previously required several weeks can establish a credible baseline in days, the economic value is obvious.
But speed is not the most important benefit. Coverage and accuracy may be even more important.
Human-led assessments inevitably depend on what people remember to ask. A governed assessment system can maintain an explicit universe of criteria and require every relevant area to have an explicit status — assessed, unresolved, unsupported by evidence, contradictory, or not applicable. Silence does not disappear — and making evidence gaps explicitly visible can materially improve assurance quality. Consistency improves as well. Two different consultants evaluating the same environment should ideally reach similar factual conclusions. Today that is not always guaranteed because the assessment process itself contains substantial human variability. Evidence-driven systems can reduce that variability without eliminating human judgment where judgment is genuinely required.
And perhaps most importantly, the assessment does not have to end when the report is published. If the evidence model is structured, the same system can be reassessed after a release, architecture change, new provider, new regulation or material operational event. In this way, assessment becomes a capability rather than an event.
The budgets already exist
This may be the most commercially important part of changing the assessment model: organisations do not need to invent an entirely new category of expenditure to adopt it. It is primarily a question of reallocating existing budgets.
The commercial opportunity is significant because organisations already incur substantial compliance and assurance costs, parts of which can potentially be automated. The European GRC market is already measured in billions of euros, while AI governance and assurance are rapidly growing categories. In the Nordics, high digital maturity, strong AI adoption and increasing regulatory requirements create particularly favourable conditions for this transition.
Organisations already spend substantial amounts on single-domain security assessments, compliance programmes, architecture reviews, privacy work, internal audit, external audit, governance tooling, regulatory consulting, technical testing, evidence collection and remediation planning. A large amount of this work is still done through consultants, legal teams, security teams, internal assurance functions, audits, spreadsheets, questionnaires and conventional GRC platforms rather than through a dedicated technical assurance engine.
By combining concepts such as the Solution Assurance Assessment with AI-powered analytical tools, the same budgets can increasingly produce wider, deeper and faster assurance outcomes:
consulting expenditure + assurance labour + regulatory analysis + technical audit + compliance evidence gathering + security verification + GRC expenditure.
The question is not necessarily:
“Where will organisations find money for continuous assurance?”
The better question is:
“How much of the money already spent repeatedly establishing the current state could be redirected toward establishing it once, maintaining it continuously and using expert time to improve it?”
That is budget reallocation, not budget invention. And the economics become even more attractive because the same evidence can support multiple purposes. One technical artefact can be relevant to several requirements. One validated system fact may support security, privacy, governance and regulatory analysis simultaneously. One evidence acquisition process can therefore reduce or replace several overlapping evidence requests from different assessment teams.
The result is not only cheaper assurance - it is potentially better assurance with more money left for implementation.
From assessment industry to change industry
Perhaps this is the most important opportunity: organisations do not create value by discovering that they have problems. They create value by changing the things that matter.
Yet a remarkable amount of transformation budget is consumed simply proving the current state over and over again. The coming generation of assurance systems can change that balance — and I believe it will. Machines can increasingly assemble evidence, test consistency, identify gaps and prepare structured findings.
Experts can increasingly concentrate on the questions machines should not decide alone:
- What matters most?
- What is acceptable?
- What should change?
- What is technically realistic?
- What is legally or ethically ambiguous?
- What sequence will actually work?
- Who must own the decision?
- How do we make the improvement sustainable?
That is not the end of consulting. It may be the beginning of better consulting.
And it is not the end of assessment. It is the transition from assessment as a labour-intensive snapshot toward assurance as a continuously available capability.
The technology required to do this is no longer science fiction. Important parts already exist. The remaining challenge is to connect evidence, analysis, verification, requirements and human authority in a disciplined architecture.
The opportunity is therefore not merely to make assessments faster. It is to spend less time proving where we are, and more time creating where we need to be.
That is a transition worth accelerating. And it should start now. Tomorrow is already late.