Assess Before You Invest

We fix how work happens before we automate it.

Most large IT and ERP programs don't fail at go-live. They fail long before the assumptions nobody tested, the data nobody trusted, and the controls nobody owned. By the time the dashboard turns red, the budget is gone.

CD&A is the independent set of eyes Boards, CIOs, and Agency heads call in when a transformation stalls, a budget balloons, or leadership needs an honest read on what's really going on. We don't sell software. We hold no vendor relationships and take no referral compensation. Our methodology belongs to us, and so does the answer we give you.

Our philosophy is simple: follow the data.

The Pathway

Our assessments are modular. You don't need all of them , you need the right one, in the right order.

1. Establish the baseline → 10-Day ERP Reality Check

2. Go deep where the findings point → Data Trust Assessment, PMO & GRC Governance Assessment, or Business Process Transformation

3. Get the verdict → Consolidated Remediation Roadmap and Go / No-Go Recommendation

4. Stay verified → Independent Verification & Validation through implementation and go-live

Every step is fixed-fee, time-boxed, and built to end in a decision , not a report that sits on a shelf.

1. The 10-Day ERP Reality Check

The front door.

A rapid, fixed-fee technical and functional assessment of your current ERP environment. We establish the true condition of the system , not the condition the status report claims.

What we examine:

  • System configuration and how it actually runs against how it was designed

  • Data conversion integrity and the state of migrated records

  • Integrations between ERP and surrounding systems

  • Code hygiene and customizations that carry technical debt

Best for: Organizations starting a modernization journey, or questioning whether the roadmap they're already on is the right one.

2. Data Trust Assessment

The foundation.

A two-week, fixed-fee engagement that audits the reliability of your data before you make roadmap or migration decisions. You cannot migrate your way out of untrustworthy data , you can only carry it forward.

What we examine:

  • Master data health, duplications, and integrity gaps

  • Manual workarounds and shadow systems holding the real numbers

  • Reliability scoring by data domain and downstream impact

  • A prioritized cleanup roadmap with ownership

Best for: Organizations with fragmented legacy data, heavy manual intervention, or a legitimate fear of moving dirty data into a new platform.

3. PMO & GRC Governance Assessment

The shield.

A rapid, fixed-fee dual-lens diagnostic connecting portfolio governance to regulatory compliance , so you know where you're exposed before you invest.

Our 9-step methodology:

Phase 1 , Assess

  1. Define scope , key assets, data systems, and business units

  2. Map rules , applicable laws, industry standards, internal policies

  3. Identify gaps , current practice against recognized frameworks

  4. Rate risks , likelihood against potential harm

Phase 2 , Implement Readiness

5. Build policies , clear rules and standard
‍ operating procedures ‍
6. Assign roles , accountability through a
structured RACI
7. Deploy controls , technical and
operational controls
8. Automate tracking , real-time monitoring
operational controls
9. Train and test , staff enablement and
recurring audit

Deliverables: GRC + Portfolio Governance Maturity Scorecard Prioritized Remediation Roadmap RACI-Aligned Policy & Controls Package * Go / No-Go Recommendation

Best for: Organizations facing compliance exposure, scope creep, vendor sprawl, or stalled PMO oversight.

4. Business Process Transformation

The change.

Findings are only useful if the process behind them changes. We redesign how work actually happens: documenting the current state as it operates today, then rebuilding the future state with controls and segregation of duties designed in the application, not bolted on.

What we do:

  • Current-state process documentation across finance, payroll, procurement, cash, and grants

  • Future-state process redesign with embedded controls and clear ownership

  • Segregation of duties matrices and maker-checker gates

  • Training and monitoring routines that survive staff turnover

Why it matters: A new system running today's processes simply reproduces today's findings. Process first, platform second.

Best for: Organizations with repeat audit findings, control failures, or compliance exposure on a functioning system.

5. Independent Verification & Validation (IV&V)

The insurance.

IV&V is objective, third-party confirmation that a program is doing what it said it would do. We verify deliverables against requirements, validate that risks are being managed, and tell you : in writing whether the project is on track for successful go-live.

It is not a checkbox. It's independent verification, and it exists to catch what momentum misses.

Why independent matters: The vendor's dashboard shows green. Milestones are checked off. Everything looks on track until it isn't. A system that performs in a demo can still fail under real operational pressure. You wouldn't accept a builder's word that the wiring is safe. Same logic applies here.

10-Day IV&V Delivery

Phase 1 : Planning & Kickoff
Phase 2 : Discovery & System Deep Dive
Phase 3 : Analysis & Rapid Wins
Phase 4 : Deliverables & Debrief

Core deliverables: Comprehensive Assessment Report · Phase 2 Roadmap · Efficiency Scorecard · Application Configuration Changes

Scope: Strictly technical and functional, system configuration, data conversion, integrations, and code hygiene.

Best for: Agencies, districts, and institutions running large implementations who need independent assurance for a Board, a legislature, or a funding authority.

Why CD&A

Independent by design. We don't sell software, we don't resell it, and we take no vendor compensation. Our intellectual property belongs to us which means the recommendation we give you is the one we actually believe.

Proven depth. Consultants with 10+ years of ERP, data, and transformation experience across Infor, CGI Advantage, Workday, Oracle and SAP in State. Public Sector, Higher Education, and the Private Sector.

Industry fluent. We speak the language of CIOs, Boards, University Presidents, and Agency Heads. We understand what it means to answer to an auditor, a legislature, or a federal funding authority.

Outcome-obsessed. Every engagement is built around acceptance criteria and measurable results: governance, compliance, and go-live success.

Who We Serve

County, State, and City Government * Higher Education Research Institutions * K-12 School Districts * Aerospace and Defense * Manufacturing and Logistics