A maturity model answers the question of how reliably a process operates in practice, irrespective of whether a document formally exists. Compliance with established requirements is a different question, assessed under a separate part of the engagement and by a separate methodology.
BTCMMI is the model used by the practice to assess the maturity of information technology and information security management processes in engagements with financial sector organisations of the Kyrgyz Republic and the wider region. Assessment is made on an L0–L5 scale in two dimensions at once — the state of the process and the state of its documentation — which distinguishes an organisation where a process is performed but not described from one where the description exists and the process does not.
This page describes the 2026 edition: the composition of the model, the rules preserving continuity of scores on transition from the previous edition, and the manner of its introduction. A full account is set out in the document available for download.
BTCMMI methodology for assessing the maturity of IT processes, 2026 edition: composition of the model, migration rules for scores, and regional comparability.
Методология оценки зрелости - 2026
BTCMMI — модель оценки зрелости процессов управления информационными технологиями и информационной безопасностью, применяемая практикой при аудитах организаций финансового сектора региона.
Письмо со ссылкой для скачивания придет на ваш e-mail. Обязательно проверьте папки «Спам», «Промоакции» и «Рассылки».
The 2026 edition in figures
|
34 processes
|
L0–L5
|
22 processes
|
|
Processes assessed in the 2026 edition, against 22 previously. The total number of sub-processes has risen from 70 to 94. |
The level scale, the two-dimensional principle of assessment and the method of computing composite indicators are unchanged. |
Form the comparable base: their series carry across directly and are used to compute year-on-year movement. |
The expansion reflects a change in the actual technology landscape of the financial sector rather than a change in the scale itself. It does not affect the scope of audit procedures: the areas added to the model as separate processes were for the most part examined before as well, but had no scale of their own and were absorbed into adjacent processes. The update renders measurable what was previously assessed only indirectly.
Why the model required updating
A maturity model reflects the body of technology practices upon which the resilience of an organisation depends. Over the period during which the previous edition applied, changes occurred in the financial sector of the region that no longer fitted within the former processes.
- The network perimeter ceased to be homogeneous. Remote access, contractors and distributed branch networks have made segmentation a discipline in its own right.
- Part of the processing moved to external providers. Cloud mail, file services and sector solutions have divided responsibility for data between the organisation and the provider.
- The payment environment became the subject of distinct payment system requirements and, at the same time, the most attractive target for attack.
- Cryptographic assets reached a number at which manual record-keeping ceased to work, and the expiry of keys and certificates became a routine cause of customer service outages.
- Generative AI services entered the working practice of staff faster than organisations established rules for handling corporate information.
Each of these changes was observed in the course of actual engagements. The external statistics cited in the paper serve to corroborate the direction of travel rather than as its source.
Composition of the changes
The expansion falls into four categories, each with its own status as to comparability.
| Direct carry-over — 22 processes | Carried into the 2026 edition unchanged; direct comparability of series is preserved. |
| Separation and refinement — 7 processes | Separated from broader areas or refined; the practices concerned were assessed before but had no scale of their own. |
| New scale, existing coverage — 3 areas | Fell within the scope of procedures but were measured indirectly; they now receive a maturity score of their own. |
| New discipline — 2 processes | No systematic procedures were performed previously: the practices concerned are only now taking shape in organisations of the region. |
What has not changed
- the L0–L5 level scale
- two-dimensional assessment: process and documentation
- the method of computing composite indicators
- the scope of audit procedures
- the rule fixing the methodology as at the commencement of an engagement
Processes separated from existing ones
Six disciplines have been separated from broader processes and one has been refined. All were assessed before, but within consolidated areas in which strong and weak elements were averaged into a single score. Separation improves the resolution of the assessment: an organisation can see which part of a broad area lags, and direct its effort there rather than at the area as a whole.
| New process | Separated from | Now assessed separately |
| IT operations management | Service catalogue and service level management | Scheduled jobs, capacity management, operational monitoring |
| Physical security and disposal | Business continuity and recovery | Protection of offices and media, assured destruction of data on decommissioning |
| Security configuration management | Asset and configuration management | Secure configuration baselines and control of deviations |
| Endpoint and user environment protection | Vulnerability management | Media encryption, removable devices, end-user computing |
| Audit log management | Incident management | Completeness, retention period, protection of logs from alteration by administrators |
| Database and test environment management | Data management | Direct data amendments bypassing applications, anonymisation of test copies |
| IT and information security organisation | Architecture and strategy management | Independence of the information security function, segregation of duties, composition of committees |
Areas receiving a scale of their own
These areas fell within the scope of audit procedures before as well: examinations were performed, observations and recommendations were raised, and regulatory requirements apply to them. What has changed is not coverage but measurability — an area now receives a direct maturity score instead of influencing adjacent processes indirectly.
|
Network security management
|
Payment infrastructure security
|
Cryptography and key management
|
|
Segmentation, perimeter, remote access by contractors. Procedures were performed previously — review of segmentation and firewall configurations, perimeter scanning — and the results bore on the assessment of vulnerability and incident management. A flat network turns a single compromise into the compromise of the whole infrastructure. |
Isolation of the payment environment and integrity control over inter-system exchange. The payment environment has always been within the scope of the audit; a scale of its own was absent. It bears directly on customer funds and on compliance with payment system requirements. |
The lifecycle of keys and certificates, and the storage of secrets. Individual aspects were examined previously — secure channels, certificates of remote banking services. Certificate expiry remains a routine cause of customer service outages. |
New disciplines
Two areas are introduced for the first time. No systematic procedures were performed on them previously — not through oversight, but because the practices concerned are only now taking shape in organisations of the region.
|
Cloud service management
|
Management of AI use
|
|
The schedule of approved services, the division of responsibility with the provider, and access control. Data leave the perimeter of an organisation in practice before rules for handling them come into being. |
Rules for transmitting information to external artificial intelligence services, the schedule of what is permitted, and monitoring of compliance. Confidential information leaves the organisation through tools that appear in no policy currently in force. |
Continuity of results
Organisations assessed under the previous edition do not lose their accumulated history. The migration rules are documented and applied mechanically: each carried-over score creates a new record referencing its source, the type of transition and the coefficient applied. Historical scores are not rewritten, and a carried-over score is flagged as derived and remains distinguishable from a measured one.
| Type of transition | Migration rule | Comparability of series |
| Direct carry-over — 22 processes | The score carries across unchanged | Full; used to compute movement |
| Separation — 6 processes | The parent score with a reducing coefficient of 0.85: the score of a broad area systematically overstates the maturity of a narrow discipline drawn from it | Limited: the value serves as a starting point and is confirmed at the first assessment under the new edition |
| Refinement — 1 process | The parent score with a reducing coefficient of 0.90 | Limited, as for separation |
| New scale, existing coverage — 3 areas | No retrospective score is derived by formula; an expert assessment by the auditor is permitted, based on documented materials of the previous engagement and referencing its source | Limited; an expert point is distinguishable from a measured one |
| New discipline — 2 processes | No retrospective score is derived | Absent; the base begins to accumulate from 2026 |
Retrospective values are not constructed by calculation. For none of the processes receiving a scale for the first time is a retrospective score derived from related processes or from averages across the organisation or the market. An assessment that was never performed cannot be reconstituted by computation, and simulating one would deprive subsequent comparison of meaning. The first score for such processes is a baseline, not the result of a decline.
An expert retrospective assessment is a judgement on evidence, not a calculation. For areas with prior audit coverage, a retrospective assessment may be made by the auditor on the basis of documented materials of the previous engagement — observations and working papers of the year in question — with reference to the source. Such a point is flagged separately and is not included in aggregated regional movement.
Regional statistics and comparability
The practice maintains aggregated, anonymised maturity statistics for financial sector organisations of the region. With the introduction of the 2026 edition the published indicators are divided into three series, so that comparability is not eroded by the expansion of the model. Comparison is meaningful only within one and the same set of processes: expanding the model must not create the appearance of a rise or fall in the maturity of the sector.
|
Principal movement series
|
Extended view
|
2026 baseline
|
|
Base: 22 comparable processes. Shows the change in maturity year on year. Separated and new processes are excluded from the calculation. |
Base: the 22 comparable processes together with the 7 separated and refined. Gives a fuller picture of the model; derived values are flagged expressly. |
Base: the 3 areas receiving a new scale and the 2 new disciplines. Shows the starting level of the sector; no assertions as to movement are made. |
The composition of the comparable base is stated in every publication presenting regional movement. For organisations assessed for the first time, comparison against the regional benchmark is presented for the comparable part of the model; for areas with a 2026 baseline, the distribution of levels is presented without assertions as to movement, pending a second point of measurement.
Relationship to regulatory requirements
The maturity model neither replaces nor duplicates regulatory requirements. Compliance answers the question whether a control exists and is documented. Maturity answers the question how reliably that control operates in practice. The two conclusions do not stand in place of one another and are presented separately.
Areas with requirements in force. For network security, payment infrastructure and cryptographic protection, regulatory requirements apply and procedures were performed previously. The update improves measurability: an organisation obtains not only a conclusion on compliance but a position on the maturity scale and a comparison with the market.
Areas ahead of rule-making. For cloud service management and the use of artificial intelligence, detailed requirements applying to organisations of the sector were not established as at the date of publication. These areas were introduced on the basis of actual risk observed in the practice of audit, not by the calendar of rule-making. An organisation that raises its maturity in such an area in advance meets formal requirements, when they appear, at lower cost.
Introduction of the edition
The 2026 edition applies to all engagements commencing after the date of its introduction. Engagements begun under the previous edition are completed under it: the methodology is fixed as at the commencement of work and does not change during the engagement. The active period of application is from 2027. The next revision of the composition of processes is planned as the technology landscape changes, rather than on a fixed calendar.
Maturity assessment is performed as part of the engagements of the practice. The course of work is described on the page Regulatory and group compliance →.
Frequently asked questions
Does maturity assessment replace a compliance examination
No. These are different questions, assessed by different methodologies and presented separately in the report. Compliance establishes the existence of a control and its documentation; maturity characterises how reliably it operates in practice.
What becomes of the results of a previous assessment
They are preserved and not rewritten. For 22 processes the series are directly comparable; for 7 separated and refined processes a documented migration rule with a reducing coefficient applies; for 5 processes a scale is introduced for the first time. No separate reassessment of the past is required.
Why is no retrospective score derived for the new processes
An assessment that was never performed cannot be reconstituted by computation. Deriving one from adjacent processes or from averages would create the appearance of a historical series where no measurement took place, and would deprive subsequent comparison of meaning.
Does expanding the model increase the burden on the organisation’s staff
Not in proportion to the number of processes. Self-assessment is carried out through short thematic questionnaires routed by area of responsibility, so each member of staff answers only on their own area.
Which edition applies to an engagement already under way
The one in force when the work commenced. The methodology is fixed in the engagement contract and does not change during performance.
Is the full set of sub-processes and assessment cards published
No. This page and the accompanying paper describe the composition of the model and the rules for its application. The detailed set of sub-processes, the wording of the assessment cards and the method of computation are provided to the client as part of the engagement.