Executive intelligence
Nordvik Logistik ApS — Digital Trust Twin
Open all findings →Readiness Score
Are the controls in place? Based on your answers (self-reported).
Readiness 27/100 is the weighted average of six domain scores. Each question carries a fixed weight; "yes" counts fully, "partial" counts half, "no" and "unknown" count zero. Strongest domain: Cyber Readiness (50).
Evidence Confidence
Can you prove it? Based only on evidence records, never on answers.
Evidence Confidence 29/100: 4 of 12 claimed controls have evidence records. Each record is scored on presence, source authority, verification, freshness and confidence (methodology v0.2); claims with no record score zero.
How this score is calculated
- Only controls you claim (answered "yes" or "partial") need proof: 12 claimed, 4 with an evidence record.
- A record must exist to count. It is then scored on source authority (20%), verification (35%), freshness (25%) and confidence (20%).
- A claimed control with no evidence record scores zero, whatever the answer.
- With no evidence records at all, the score is shown as unknown.
Methodology v0.2 — pilot methodology, calibration stage. These are EvidentraIQ design choices, not regulatory thresholds. Read the full methodology
Exposure Score
What is at risk? Business impact of missing or unknown controls. Higher is worse.
Exposure 72/100 (higher means more exposure) weights each missing control by its business impact. Largest contributors: AI Governance (81), Policies & Evidence (81). "Unknown" is treated as 85% of a missing control, because undocumented controls fail under scrutiny.
Bands are the EvidentraIQ v0.2 interpretation (Pilot / calibration stage), not external standards. Treat scores as indicative: a difference of a few points is not meaningful on its own.
Management summary
Nordvik Logistik ApS scores 27/100 on readiness with evidence confidence at 29/100 and exposure at 72/100. 24 findings are open, of which 3 are critical and must be closed within 30 days. The largest concentration of exposure is in AI Governance. Evidence confidence is the binding constraint on enterprise sales: until unverified items are reviewed and dated, claims cannot be published or shown to customers. This summary is generated from the current answers only and is not a compliance statement.
What changed
- 2026-09-14MFA enforcement evidence verified for administrative accounts.
- 2026-09-02New AI support assistant onboarded without a signed data processing agreement.
- 2026-08-21Primary cloud supplier agreement verified as own-posture evidence.
- 2026-07-30Backup restore test is older than the 12-month threshold.
Demo change log. Automatic change detection arrives with Continuous Monitoring.
Score trend
Illustrative demo trendNot calculated from the current methodology and not customer history. Real trends start once an organisation re-assesses over time.
Illustrative demo trend — not calculated from current methodology.
Top exposures
19/100 readiness from 5 weighted questions (5 answered). 5 control(s) not fully in place, 1 answered as unknown. Exposure 81/100 is driven by the weighted impact of those gaps.
22/100 readiness from 4 weighted questions (4 answered). 4 control(s) not fully in place. Exposure 81/100 is driven by the weighted impact of those gaps.
17/100 readiness from 4 weighted questions (4 answered). 4 control(s) not fully in place, 1 answered as unknown. Exposure 78/100 is driven by the weighted impact of those gaps.
Evidence gaps & overdue actions
5 evidence items are not verified and are excluded from anything published.
- Backup restore test recordin review
- Supplier register (draft)unverified
- AI acceptable use guidance for staffunverified
- Retention schedule for customer recordsunverified
- Draft marketing statement: "Regulators expect SMEs to document staff AI use."unverified
3 critical actions are inside the 30-day window and at risk of becoming overdue.
Open the Evidence Center →30 / 60 / 90 day priorities
Next 30 days
3 actions
- Missing: Do you maintain a current inventory of AI systems and AI-enabled tools in use.Owner: Managing Director
- Missing: Are high-impact AI outputs reviewed by a person before they affect customers.Owner: Managing Director
- Missing: Is there a documented leaver process that removes access within a defined time.Owner: IT Lead
Days 31–60
5 actions
- Missing: Do you have a written incident response plan with contact points.Owner: IT Lead
- Partially in place: Is multi-factor authentication enforced on email and administrative accounts.Owner: IT Lead
- Missing: Are data processing terms in place with critical suppliers.Owner: Operations Lead
- Missing: Is customer data separated from test, demo and AI experimentation environments.Owner: Managing Director
- Missing: Can you produce evidence for your security claims within one working day.Owner: Operations Lead
Days 61–90
11 actions
- Partially in place: Is there a named human accountable for approving new AI use cases.Owner: Managing Director
- Not confirmed: Do you record which data is sent to external AI providers.Owner: Managing Director
- Partially in place: Are backups taken, stored separately and restore-tested in the last 12 months.Owner: IT Lead
- Missing: Have you run any incident or ransomware walkthrough in the last 12 months.Owner: IT Lead
- Not confirmed: Are administrative rights limited and reviewed at least annually.Owner: IT Lead
- Partially in place: Do you maintain a list of suppliers that process your data or run critical services.Owner: Operations Lead
Supplier exposure summary
| Supplier | Service | Criticality | Agreement | Exposure |
|---|---|---|---|---|
| Northbridge Cloud (demo) | Core hosting and storage | critical | signed | |
| Lumen Assist AI (demo) | Customer support AI assistant | critical | missing | |
| Pay&Ledger (demo) | Payroll and bookkeeping | important | under review | |
| RouteSense Telemetry (demo) | Fleet telemetry | standard | signed |
Demo supplier register. Vendor monitoring is part of the Ultimate package and is not active in this version.