Blue Top ConsultingCOMPASS
Menu

FOR IT AUDIT & TECHNOLOGY RISK

Extend your technical capability.

Your client relationship. Our specialist technical capability.

Talk to Blue Top →

The technical question behind the decision.

Audit and risk teams may identify the right areas of concern but need deeper software-engineering evidence to examine implementation, architecture and delivery risk with confidence.

AUDIT EVIDENCE FLOW

Audit observationTechnical examinationEngineering evidence
Management finding

WHAT COMPASS ADDS

Your client relationship. Our specialist technical capability.

Blue Top adds deeper software-engineering examination where audit or technology-risk work requires technical material beyond the team’s internal capability.

01
OUTSIDE-IN

Compass Scan

Automated external assessment

Compass Scan examines what can be observed from a deployed application, including security basics, privacy signals, runtime behaviour, performance, production readiness and public search visibility.

02
INSIDE THE CODE

Compass Code

Customer-controlled repository assessment

Analyse repository and engineering evidence inside your controlled environment without requiring source code to be transferred to Blue Top.

03
SPECIALIST REVIEW

Compass Assessment

Specialist independent assessment

Examine the software alongside its architecture, delivery history, vendor model, operating environment and business constraints.

Extend the engagement without building a software-engineering team.

YOUR TEAM

Audit methodology

Client relationship · Risk expertise · Business context

combined with
BLUE TOP

Software engineering

Architecture · Technical examination · Engineering evidence

produces
THE RESULT

Management-ready technical findings

Technical evidence connected to risk, delivery and remediation decisions.

Questions the assessment can address.

  • Are engineering controls working in practice?
  • What technical evidence supports the risk view?
  • Is the vendor delivering maintainable software?
  • Where is remediation exposure accumulating?
  • Which findings matter to management?

Material examined.

  • Technical examination
  • Engineering evidence
  • Architecture observations
  • Delivery and vendor indicators
  • Decision-ready findings

RELEVANT CASE STUDY

Recurring patterns across a complex software estate.

Our anonymised healthcare assessment connected implementation evidence with security, operational and remediation exposure.

View the full case study →

Obsolete technology

Unsupported and end-of-life components

Dependency exposure

Vulnerable and unmanaged packages

NEXT STEP

Examine the software before the next decision.

Run Compass Scan Explore Compass CodeDiscuss an Assessment →