Self Assessment Step 2 — The Part Everyone Rushes Through
Most people treat Self Assessment Step 2 as a checkbox exercise. They move through the rating scale, slap some scores on paper, and hand it to management. I've seen it hundreds of times. The results are either garbage or misleading, sometimes both. Here's what actually happens when you do it right, and where it falls apart in practice. Step 2 is the evaluation phase. Step 1 documents your current processes and policies. Step 2 takes those documented processes and measures them against a set of criteria — usually capability, maturity, or compliance standards — to determine where you stand. You're not building anything new. You're being honest about what exists versus what's claimed to exist. The criteria framework you use depends on your context. ISO-based assessments use clause-by-clause evaluation. Business continuity frameworks like ISO 22301 use capability tiers from informal to optimized. Internal audit programs might use a 1-to-5 maturity scale. Pick one and stick with it. Don't mix frameworks mid-assessment because that just creates noise.
How It Works in Practice
You go criterion by criterion. For each one, you answer: does a process exist? Is it documented? Is it followed? Is it measured? Is it improved? That last question is where most organizations stall. Every prior question above it demands evidence — a procedure document, a training record, an audit log. The improvement question demands trend data showing that measurements actually led to changes. If you don't have at least three months of measurable data on a process, you can't credibly answer the improvement question. Period. I've seen people argue they "fix things when we find problems," which sounds like improvement but isn't verifiable improvement. Improvement requires recorded corrective actions with outcomes. A gut feeling doesn't count.
A Specific Problem I Ran Into
Working with a mid-size logistics company a few years back, their Self Assessment Step 2 kept producing contradictory results on the same criterion. On one floor, warehouse staff followed a documented staging procedure. On the adjacent floor, they used a different method that wasn't written down but somehow produced better on-time delivery numbers. The assessment framework asked a single yes-or-no question about procedural compliance, but the reality was two competing processes in the same facility. The workaround was to split the assessment by operational unit rather than applying a blanket score. Each unit got its own evaluation path, and then we documented the variance between them as a risk item. That variance itself became part of the improvement backlog. Without that split, the assessment would have either ignored the non-documented floor entirely or penalized it unfairly without recognizing it was outperforming the documented one.
Get the Full Details

Counter-Intuitive Things Beginners Miss
First, lower scores on Step 2 are sometimes better than higher scores if the evidence supports them. An organization that rates itself a 2 with detailed proof of what's missing and a concrete plan to close the gap will audit cleaner than one that rates itself a 4 with vague assertions and no supporting records. Auditors will dig into the discrepancies. When there aren't any, you look prepared. When there are unexplained gaps between your claimed maturity and your evidence, you look dishonest. Second, over-documentation hurts your Step 2 results. Writing a five-page procedure for something that should take three steps to execute creates compliance theater. Audit teams will spot it immediately. The procedure won't match what people actually do, and your Step 2 score for that criterion drops because the documented process and the actual process diverge. Keep documentation proportional to risk. Simple processes deserve simple documentation.
Limitations and When It Fails
Self Assessment Step 2 is a point-in-time snapshot. It tells you where you stand on the date of assessment, not where you'll stand next quarter. If your environment changes rapidly — which it does in most tech organizations — you're measuring a moving target. That doesn't make the step worthless, but it does mean you need to repeat it frequently, ideally every six months, not annually. It also doesn't tell you how to improve. That's a separate exercise. Step 2 identifies gaps. Closing them requires a remediation plan, resource allocation, and follow-through. I've seen organizations complete the assessment, publish the results, and never circle back. The assessment becomes a PDF that sits in a shared drive. There are scenarios where Step 2 simply won't work. If your organization lacks basic record-keeping discipline, you won't have the evidence needed to score any criterion meaningfully. In that case, you're not ready for a formal self-assessment. You need to build foundational documentation and data collection practices first, then return to Step 2. Trying to force it early just produces fabricated scores that give you a false sense of security.
Another failure mode is when the assessment criteria don't match your actual operations. This happens when you adopt a framework wholesale from another industry without adaptation. A healthcare compliance framework applied to a software company will produce nonsensical results because the criteria assume regulatory constraints that don't exist in your context. Always map criteria to your actual processes before you start scoring.

What I Use Instead When Step 2 Isn't Enough
For organizations with serious compliance requirements, I pair Step 2 with periodic external audits. Self-assessment is valuable for internal awareness, but you need an independent eye to catch blind spots. I've also used control self-assessment workshops where cross-functional teams evaluate each other's processes. It surfaces issues that a single assessor would miss because nobody in that team assumed the process worked the way it was documented. If your goal is continuous monitoring rather than periodic assessment, consider implementing control telemetry — automated checks that feed into a dashboard. This replaces the annual Step 2 exercise with real-time visibility. It costs more upfront in tooling and configuration, but it eliminates the once-a-year scramble that makes most self-assessments unreliable.