Skip to content
BetterOps logo

The CORE Framework

The CORE Technology & Operations Assessment

A structured review of the technology and operational controls your firm depends on - producing a clear current-state picture and a prioritized roadmap you can act on, with or without us.

Built exclusively for RIAs and wealth management firms Works alongside your existing IT and vendors Fixed-scope assessment, no long-term commitment Senior practitioners - no junior handoff

Why we start here

Nearly every engagement we are asked about starts with a version of the same question: is our technology environment in reasonable shape, and how would we know? It is a hard question to answer from inside the firm, because the people closest to it are the same people who built it.

The CORE Assessment answers it. It is deliberately the first thing we do, deliberately fixed in scope, and deliberately useful on its own. You should not have to commit to an ongoing relationship to find out where you stand - and we would rather not propose ongoing work before we understand your environment properly.

CORE is our own methodology, refined against the firms we work with. It examines four dimensions.

What the assessment covers

Controls

What is genuinely protecting the firm - and what only appears to be.

  • Cybersecurity readiness and current control coverage
  • Identity and access: accounts, privileges, multi-factor, offboarding
  • Microsoft 365 / cloud environment configuration and tenant hygiene
  • Endpoint and email protection
  • Data protection: where client data lives, who can reach it, how it leaves

Ownership

Who is accountable for each part of the environment, and how decisions get made.

  • Technology governance: how decisions, spend, and priorities are set
  • Vendor and third-party inventory, responsibilities, and access
  • Technology ownership across internal staff and external providers
  • Contract, renewal, and licence visibility
  • Escalation paths when something goes wrong

Resilience

What actually happens when a system, a vendor, or a person is unavailable.

  • Business continuity planning against the environment you run today
  • Backup coverage, retention, and tested recovery
  • Incident readiness: roles, decisions, and communication
  • Single points of failure across systems and people
  • Dependency on any individual vendor or key employee

Evidence

Whether the firm can demonstrate how it operates without reconstructing it from memory.

  • Documentation of critical operational workflows
  • Written policies and standards, and whether they match practice
  • Records of reviews, approvals, and changes
  • Onboarding and offboarding procedures
  • Automation opportunities worth pursuing - and ones worth avoiding

Not every area applies to every firm. Scope is confirmed with you in writing before the assessment begins, and CORE continues to evolve as we work with more firms.

What you receive

Four deliverables. All of them yours to keep, share with your board, or hand to another provider.

01

Current-state assessment

A written picture of your technology and operational environment as it actually is, organized across the four CORE dimensions. Plain language, written for leadership rather than for engineers.

02

Prioritized findings

Gaps, risks, ownership ambiguities, and documentation weaknesses - each rated by consequence and effort, so the important items are distinguishable from the merely untidy.

03

Improvement roadmap

A sequenced plan: what to address first, what it involves, roughly what it takes, and what the exposure is if you defer it. Yours to keep and execute however you choose.

04

Leadership readout

A working session with your founder, COO, or CCO to walk through the findings, challenge them, and agree what matters. The conversation is usually where the real value shows up.

How the engagement runs

  1. Discovery call

    Thirty minutes to understand your firm and confirm fit. We will tell you directly if an assessment is not the right next step.

  2. Scope & schedule

    We agree scope, timing, and a fixed fee in writing before anything begins. No open-ended discovery, no hourly drift.

  3. Assessment

    Structured interviews with the people who run the firm, plus a review of your environment, vendor arrangements, and existing documentation. Designed to be light on your team's time.

  4. Findings & roadmap

    Written assessment and prioritized roadmap, delivered and walked through with leadership. Then the decision about what happens next is entirely yours.

Find out whether a CORE Assessment fits your firm.

A 30-minute call. No preparation needed, and no obligation to proceed.

Questions we get about the assessment

How long does the assessment take?
Scope depends on the size and complexity of the firm, and we confirm the timeline in writing before we start. For a typical firm in our range it is measured in weeks, not months, and the demand on your team is a handful of scheduled conversations rather than an open-ended project.
What does it cost?
The assessment is a paid, fixed-fee engagement quoted after the discovery call, once we understand your environment. We do not quote a price before we know what we would be assessing, and we do not bill it hourly.
How much of our team's time does it consume?
A series of scheduled interviews with the people who know how the firm runs - usually leadership, operations, and whoever coordinates your IT provider - plus read-only visibility into your environment. We work around your calendar, not the reverse.
Will this disrupt our systems?
No. The assessment is observational. We are not making changes to your environment, and nothing we do requires downtime.
Do we have to work with you afterwards?
No, and it is designed that way deliberately. The assessment and roadmap are standalone deliverables you own. Some firms execute the roadmap with their existing providers. Others ask us to run it with them. Both are fine outcomes.
Does this make us compliant?
No - and be cautious of anyone who says otherwise. BetterOps is not a law firm, an auditor, or a compliance consultancy, and we do not provide legal or regulatory advice or guarantee any regulatory outcome. What the assessment does is help your firm become better organized, better documented, and more resilient. Firms generally find that this makes compliance work substantially easier, and we are glad to work alongside your compliance counsel or consultant.
We already have an IT provider. Does this conflict with them?
It usually complements them. Your provider was engaged to keep systems running; the assessment looks at how the estate is governed, owned, documented, and made resilient. Those are different jobs. We involve your provider where it helps and we are not looking to displace them.
What if you find something serious?
We tell you immediately rather than saving it for the report. If something represents active, material exposure, you will hear about it the day we find it.

Schedule your discovery call.

Thirty minutes with the people who would actually do the work.