Services
One assessment. One deterministic scoring engine.
Your service provider answers Yes / No / N/A across all twelve DOL EBSA domains. The same math runs every time — no LLM touches the score, and the result is mapped directly to the specific DOL best practice it answers for.

Self-Assessment
The starting point for every engagement.
Your service provider answers Yes / No / N/A across all twelve DOL domains, scored immediately against a deterministic engine — the same math every time, published openly so fiduciaries can verify it themselves.
- Yes / No / N/A per question, all twelve DOL domains
- Instant deterministic scoring — no LLM touches the number
- Board-ready output, mapped directly to DOL best practices
- One assessment, one consistent scoring engine, no black box
The twelve domains
Every question traces to a specific DOL best practice.
No generic IT checklist. The assessment scores against the same twelve domains the DOL’s EBSA guidance lists for plan fiduciaries and their service providers — so a result doubles as evidence of a prudent, DOL-aligned process, not just a security opinion.
- 1Cybersecurity ProgramHigh
- 2Annual Risk AssessmentsHigh
- 3Annual Third-Party Audit of ControlsHigh
- 4Security Roles & ResponsibilitiesMedium
- 5Access ControlsHigh
- 6Cloud & Sub-Processor SecurityHigh
- 7Cybersecurity Awareness TrainingMedium
- 8Secure System Development LifecycleMedium
- 9Business Resiliency (BCP / DR / IR)High
- 10EncryptionHigh
- 11Strong Technical ControlsHigh
- 12Response to Past IncidentsMedium
The scoring engine
Every number is deterministic and auditable.
No LLM touches the score itself. The formula runs the same way every time and is published here so fiduciaries can verify it themselves.
How the score is calculated
Each domain is scored independently: answered questions earn 1 point for Yes, 0 for No. N/A answers are excluded from the denominator — they don’t penalise providers for genuinely inapplicable controls.
Domain score = Yes answers ÷ Applicable questions × 100
Overall score = Σ (domain score × weight) ÷ 20
8
High-weight domains
Count 2×
4
Medium-weight domains
Count 1×
20
Total weight units
Denominator
High-weight domains cover controls where failures directly expose participant funds or PII — Access Controls, Encryption, and Business Resiliency among them. 7 specific failures (like no MFA, no encryption, or an unassessed sub-processor) are automatic red flags — see the risk bands to the right for what a red flag does to the final score.
Risk rating bands
The overall score maps to one of four risk bands. Band thresholds are fixed and auditable — no LLM adjusts them at runtime.
Strong
90–100%
Adequate
75–89%
Needs Improvement
60–74%
High Risk
0–59%
Any single red flag — an automatic-fail control, such as no MFA or unencrypted data — forces the band straight to High Risk, regardless of the numeric score. Red flags are disclosed explicitly in the report so fiduciaries can act on them.
You can’t N/A your way out of a domain
Because N/A answers leave the denominator, marking an entire domain N/A would quietly remove it from the score. Exactly one domain may be excluded that way — Domain 8, the software-development lifecycle, since most plan and fund offices don’t build software. Every other domain must be genuinely answered: a submission that blanks one out is rejected rather than scored, so a weak area can’t be hidden by omission.
What the AI does — and never does
The score above is computed entirely in deterministic code. The AI layer does one thing: it reads the free-text comment behind each “Yes” and grades how well that comment substantiates the claim — a named tool, document, or date scores high; boilerplate scores low; answering Yes with no evidence at all never earns full credit. That produces a second, clearly-labelled evidence-adjusted score shown beside the official one.
It never sets a Yes or No, never moves the official score, and never cancels a red flag. If the AI is unavailable, the assessment still scores normally.
The difference
Other providers let service providers grade their own homework.
Most service-provider security platforms are a questionnaire the service provider fills out about itself, run through an automated score. A near-perfect result on that kind of self-assessment tells you the questionnaire was completed, not that the controls exist.
Other providers
Paladin Assurance
Pricing
Run the assessment for free. Pay for what you do with it.
The assessment and the score cost nothing — a service provider can always complete one and see where they stand. The paid tiers are for the plan sponsor: the answer-level data behind every score, and the AI reports that turn it into a remediation plan.
Start here
Assessment
Free
No card required
Run the assessment and get the score. No cost, no card.
- All twelve DOL EBSA domains
- Deterministic weighted score and risk band
- Red-flag pass/fail outcome
- Emailed PDF of your own result
Most chosen
Full data & dashboard
$3,500
Up to 6 members · additional members priced on top
Covers up to six members. Additional members are priced on top — talk to us.
- Everything in Assessment
- Per-domain and per-question breakdown
- Complete multi-vendor dashboard
- Cross-vendor domain comparison and control gaps
- Score trends over time
Scoped to you
Intelligence
Let's talk
Priced on scope
AI reports and policy-document oversight, scoped to your fund.
- Everything in Full data & dashboard
- AI narrative report per assessment
- Prioritised remediation recommendations
- Board-ready export
Paid tiers are for pension funds and plan sponsors. Service providers are never charged — a service provider completing an assessment sees their own score and can email themselves a copy at no cost.