Pre-purchase diagnostic

Run a digital transformation audit before buying software

The purpose of the audit is not to produce another score. It is to establish which business problem is worth solving, whether the organisation is ready, and what evidence a safe pilot must produce before a larger commitment.

Search intent: informational · Updated 2026-09-05 · Advice, software and implementation scopes are confirmed separately.

Audit the workflow and customer impact

Choose one journey and follow real work through it. Record entry points, wait times, rework, approvals, exceptions, customer updates, abandoned cases and informal fixes. Distinguish a painful inconvenience from a constraint that materially affects customers, revenue, cost, risk or management capacity.

Document the baseline with available operational evidence. If the data is weak, say so and include better measurement as the first step. A precise invented number is more dangerous than an honest evidence gap.

Audit people, ownership and adoption capacity

Identify the executive sponsor, process owner, daily users, approvers, administrators and support route. Estimate the time needed for configuration, data cleanup, testing, training and transition. A team that is already overloaded may need a smaller change or dedicated capacity before a new system can succeed.

The World Bank case study of ERP adoption in Viet Nam found that initial use fell over time and highlighted the importance of an internal point person with management support. Treat that result as context from one study, not a universal forecast, but use it to ask who will own adoption after the consultant leaves.

Audit data and integration readiness

List the records the workflow depends on, their owners, required fields, duplicates, retention rules, export formats and systems of record. Sample the data rather than assuming it is clean. Clarify which integrations are required for the pilot and which are merely desirable later.

Avoid using a new platform to hide unresolved ownership. If no one can decide which customer status is correct or which system is authoritative, synchronising the ambiguity will make the problem faster, not smaller.

  • Systems of record and authoritative fields.
  • Data quality, duplication and reconciliation rules.
  • Import/export and exit options.
  • Permissions, privileged roles and offboarding.
  • Third-party APIs, rate limits and failure handling.
  • Retention, deletion, backup and recovery requirements.

Audit security, privacy and recovery

Record what customer, employee, financial or operational information will be accessed and where it will move. Identify least-privilege access, authentication, logging, breach or error response, vendor dependencies and a tested recovery route.

NIST’s small-business quick-start guide is designed for organisations with modest or no cybersecurity plans. Its outcome structure can help an audit ask who governs the risk, what must be identified and protected, how failures will be detected, and how the business will respond and recover.

Turn the audit into a decision

End with a decision, not a maturity score: do nothing yet, improve the existing process, run a small pilot, procure a product, commission implementation or seek specialist advice. State the evidence, assumptions, dependencies and unresolved risks behind that recommendation.

If a pilot is justified, define the user group, workflow boundary, baseline, acceptance threshold, stop conditions, rollback method, owner and review date before purchase. The audit has succeeded when the business can make a smaller and better-informed commitment.

Related guidance

Continue by search intent

Questions

Frequently asked questions

What should a digital transformation audit include?

It should cover the business outcome, current workflow, customer impact, people and ownership, data, integrations, security, adoption capacity, costs, dependencies, baseline evidence and a clear next decision.

Is a digital maturity score enough?

No. A score can start a conversation, but it rarely explains which workflow to change, who owns it, what evidence matters or whether the organisation is ready.

Can the audit recommend keeping the current software?

Yes. Improving configuration, ownership, data or procedures may produce more value than replacing a system. The audit should not assume that a purchase is necessary.

How much data is needed before a pilot?

Enough to establish a credible baseline and test the important cases, including exceptions. When reliable data is unavailable, measurement and cleanup may need to precede automation.

Should cybersecurity wait until implementation?

No. Access, sensitive data, logging, vendor dependence and recovery affect the requirements and product choice, so they belong in the diagnostic stage.

What comes after the audit?

The next step may be process repair, a roadmap, a bounded pilot, procurement, implementation or no action. The recommendation should reflect evidence and readiness rather than pressure to buy.

Evidence used

These sources support the general operating principles. They do not prove a guaranteed commercial outcome for any specific business.