Services

One assessment. One deterministic scoring engine.

Your service provider answers Yes / No / N/A across all twelve DOL EBSA domains. The same math runs every time — no LLM touches the score, and the result is mapped directly to the specific DOL best practice it answers for.

Self-Assessment

The starting point for every engagement.

Your service provider answers Yes / No / N/A across all twelve DOL domains, scored immediately against a deterministic engine — the same math every time, published openly so fiduciaries can verify it themselves.

  • Yes / No / N/A per question, all twelve DOL domains
  • Instant deterministic scoring — no LLM touches the number
  • Board-ready output, mapped directly to DOL best practices
  • One assessment, one consistent scoring engine, no black box

The twelve domains

Every question traces to a specific DOL best practice.

No generic IT checklist. The assessment scores against the same twelve domains the DOL’s EBSA guidance lists for plan fiduciaries and their service providers — so a result doubles as evidence of a prudent, DOL-aligned process, not just a security opinion.

  1. 1Cybersecurity ProgramHigh
  2. 2Annual Risk AssessmentsHigh
  3. 3Annual Third-Party Audit of ControlsHigh
  4. 4Security Roles & ResponsibilitiesMedium
  5. 5Access ControlsHigh
  6. 6Cloud & Sub-Processor SecurityHigh
  7. 7Cybersecurity Awareness TrainingMedium
  8. 8Secure System Development LifecycleMedium
  9. 9Business Resiliency (BCP / DR / IR)High
  10. 10EncryptionHigh
  11. 11Strong Technical ControlsHigh
  12. 12Response to Past IncidentsMedium

The scoring engine

Every number is deterministic and auditable.

No LLM touches the score itself. The formula runs the same way every time and is published here so fiduciaries can verify it themselves.

How the score is calculated

Each domain is scored independently: answered questions earn 1 point for Yes, 0 for No. N/A answers are excluded from the denominator — they don’t penalise providers for genuinely inapplicable controls.

Domain score = Yes answers ÷ Applicable questions × 100

Overall score = Σ (domain score × weight) ÷ 20

8

High-weight domains

Count 2×

4

Medium-weight domains

Count 1×

20

Total weight units

Denominator

High-weight domains cover controls where failures directly expose participant funds or PII — Access Controls, Encryption, and Business Resiliency among them. 7 specific failures (like no MFA, no encryption, or an unassessed sub-processor) are automatic red flags — see the risk bands to the right for what a red flag does to the final score.

Risk rating bands

The overall score maps to one of four risk bands. Band thresholds are fixed and auditable — no LLM adjusts them at runtime.

  1. Strong

    90–100%

  2. Adequate

    75–89%

  3. Needs Improvement

    60–74%

  4. High Risk

    0–59%

Any single red flag — an automatic-fail control, such as no MFA or unencrypted data — forces the band straight to High Risk, regardless of the numeric score. Red flags are disclosed explicitly in the report so fiduciaries can act on them.

You can’t N/A your way out of a domain

Because N/A answers leave the denominator, marking an entire domain N/A would quietly remove it from the score. Exactly one domain may be excluded that way — Domain 8, the software-development lifecycle, since most plan and fund offices don’t build software. Every other domain must be genuinely answered: a submission that blanks one out is rejected rather than scored, so a weak area can’t be hidden by omission.

What the AI does — and never does

The score above is computed entirely in deterministic code. The AI layer does one thing: it reads the free-text comment behind each “Yes” and grades how well that comment substantiates the claim — a named tool, document, or date scores high; boilerplate scores low; answering Yes with no evidence at all never earns full credit. That produces a second, clearly-labelled evidence-adjusted score shown beside the official one.

It never sets a Yes or No, never moves the official score, and never cancels a red flag. If the AI is unavailable, the assessment still scores normally.

The difference

Other providers let service providers grade their own homework.

Most service-provider security platforms are a questionnaire the service provider fills out about itself, run through an automated score. A near-perfect result on that kind of self-assessment tells you the questionnaire was completed, not that the controls exist.

Other providers

Paladin Assurance

Survey tool
A licensed third-party platform they don't own
Proprietary survey built on the DOL's 12 EBSA domains
Assessment type
Service-provider self-assessment — graded with no verification
Deterministic rubric, plus AI-graded evidence quality — vague answers score lower
Report audience
IT-oriented output, not written for trustees
Board-ready reports in plain language for fiduciaries

Pricing

Run the assessment for free. Pay for what you do with it.

The assessment and the score cost nothing — a service provider can always complete one and see where they stand. The paid tiers are for the plan sponsor: the answer-level data behind every score, and the AI reports that turn it into a remediation plan.

Start here

Assessment

Free

No card required

Run the assessment and get the score. No cost, no card.

  • All twelve DOL EBSA domains
  • Deterministic weighted score and risk band
  • Red-flag pass/fail outcome
  • Emailed PDF of your own result
Run an assessment

Most chosen

Full data & dashboard

$3,500

Up to 6 members · additional members priced on top

Covers up to six members. Additional members are priced on top — talk to us.

  • Everything in Assessment
  • Per-domain and per-question breakdown
  • Complete multi-vendor dashboard
  • Cross-vendor domain comparison and control gaps
  • Score trends over time
Talk to us

Scoped to you

Intelligence

Let's talk

Priced on scope

AI reports and policy-document oversight, scoped to your fund.

  • Everything in Full data & dashboard
  • AI narrative report per assessment
  • Prioritised remediation recommendations
  • Board-ready export
Get a quote

Paid tiers are for pension funds and plan sponsors. Service providers are never charged — a service provider completing an assessment sees their own score and can email themselves a copy at no cost.

Get a defensible answer before your next audit does.

Start an assessment