Executive intelligence

Nordvik Logistik ApS — Digital Trust Twin

Open all findings →
Demo dataNordvik Logistik ApS is a fictional organisation. All figures are illustrative and must not be used as real assurance.
27/ 100

Readiness Score

EarlyBased on: assessment responses and control weights. Methodology

Are the controls in place? Based on your answers (self-reported).

Readiness 27/100 is the weighted average of six domain scores. Each question carries a fixed weight; "yes" counts fully, "partial" counts half, "no" and "unknown" count zero. Strongest domain: Cyber Readiness (50).

29/ 100

Evidence Confidence

Low4 of 12 claimed controls currently have linked evidenceBased on: linked posture evidence records and v0.2 evidence methodology. Methodology

Can you prove it? Based only on evidence records, never on answers.

Evidence Confidence 29/100: 4 of 12 claimed controls have evidence records. Each record is scored on presence, source authority, verification, freshness and confidence (methodology v0.2); claims with no record score zero.

How this score is calculated
  • Only controls you claim (answered "yes" or "partial") need proof: 12 claimed, 4 with an evidence record.
  • A record must exist to count. It is then scored on source authority (20%), verification (35%), freshness (25%) and confidence (20%).
  • A claimed control with no evidence record scores zero, whatever the answer.
  • With no evidence records at all, the score is shown as unknown.

Methodology v0.2 — pilot methodology, calibration stage. These are EvidentraIQ design choices, not regulatory thresholds. Read the full methodology

72/ 100

Exposure Score

HighBased on: missing or weak controls and configured exposure weights. Methodology

What is at risk? Business impact of missing or unknown controls. Higher is worse.

Exposure 72/100 (higher means more exposure) weights each missing control by its business impact. Largest contributors: AI Governance (81), Policies & Evidence (81). "Unknown" is treated as 85% of a missing control, because undocumented controls fail under scrutiny.

Bands are the EvidentraIQ v0.2 interpretation (Pilot / calibration stage), not external standards. Treat scores as indicative: a difference of a few points is not meaningful on its own.

Management summary

Nordvik Logistik ApS scores 27/100 on readiness with evidence confidence at 29/100 and exposure at 72/100. 24 findings are open, of which 3 are critical and must be closed within 30 days. The largest concentration of exposure is in AI Governance. Evidence confidence is the binding constraint on enterprise sales: until unverified items are reviewed and dated, claims cannot be published or shown to customers. This summary is generated from the current answers only and is not a compliance statement.

What changed

  • 2026-09-14MFA enforcement evidence verified for administrative accounts.
  • 2026-09-02New AI support assistant onboarded without a signed data processing agreement.
  • 2026-08-21Primary cloud supplier agreement verified as own-posture evidence.
  • 2026-07-30Backup restore test is older than the 12-month threshold.

Demo change log. Automatic change detection arrives with Continuous Monitoring.

Score trend

Illustrative demo trend

Not calculated from the current methodology and not customer history. Real trends start once an organisation re-assesses over time.

2026-04-01R 28 · E 22 · X 78
2026-06-01R 34 · E 29 · X 72
2026-08-01R 39 · E 35 · X 68
2026-10-01R 44 · E 41 · X 63

Illustrative demo trend — not calculated from current methodology.

Top exposures

AI Governance81/100

19/100 readiness from 5 weighted questions (5 answered). 5 control(s) not fully in place, 1 answered as unknown. Exposure 81/100 is driven by the weighted impact of those gaps.

Policies & Evidence81/100

22/100 readiness from 4 weighted questions (4 answered). 4 control(s) not fully in place. Exposure 81/100 is driven by the weighted impact of those gaps.

Third-Party Risk78/100

17/100 readiness from 4 weighted questions (4 answered). 4 control(s) not fully in place, 1 answered as unknown. Exposure 78/100 is driven by the weighted impact of those gaps.

Evidence gaps & overdue actions

5 evidence items are not verified and are excluded from anything published.

  • Backup restore test recordin review
  • Supplier register (draft)unverified
  • AI acceptable use guidance for staffunverified
  • Retention schedule for customer recordsunverified
  • Draft marketing statement: "Regulators expect SMEs to document staff AI use."unverified

3 critical actions are inside the 30-day window and at risk of becoming overdue.

Open the Evidence Center →

30 / 60 / 90 day priorities

Next 30 days

3 actions

  • Missing: Do you maintain a current inventory of AI systems and AI-enabled tools in use.Owner: Managing Director
  • Missing: Are high-impact AI outputs reviewed by a person before they affect customers.Owner: Managing Director
  • Missing: Is there a documented leaver process that removes access within a defined time.Owner: IT Lead

Days 31–60

5 actions

  • Missing: Do you have a written incident response plan with contact points.Owner: IT Lead
  • Partially in place: Is multi-factor authentication enforced on email and administrative accounts.Owner: IT Lead
  • Missing: Are data processing terms in place with critical suppliers.Owner: Operations Lead
  • Missing: Is customer data separated from test, demo and AI experimentation environments.Owner: Managing Director
  • Missing: Can you produce evidence for your security claims within one working day.Owner: Operations Lead

Days 61–90

11 actions

  • Partially in place: Is there a named human accountable for approving new AI use cases.Owner: Managing Director
  • Not confirmed: Do you record which data is sent to external AI providers.Owner: Managing Director
  • Partially in place: Are backups taken, stored separately and restore-tested in the last 12 months.Owner: IT Lead
  • Missing: Have you run any incident or ransomware walkthrough in the last 12 months.Owner: IT Lead
  • Not confirmed: Are administrative rights limited and reviewed at least annually.Owner: IT Lead
  • Partially in place: Do you maintain a list of suppliers that process your data or run critical services.Owner: Operations Lead

Supplier exposure summary

SupplierServiceCriticalityAgreementExposure
Northbridge Cloud (demo)Core hosting and storagecriticalsigned
Lumen Assist AI (demo)Customer support AI assistantcriticalmissing
Pay&Ledger (demo)Payroll and bookkeepingimportantunder review
RouteSense Telemetry (demo)Fleet telemetrystandardsigned

Demo supplier register. Vendor monitoring is part of the Ultimate package and is not active in this version.