If you're considering an ITSM maturity assessment, there's a good chance you've already asked the obvious question: do we need to bring someone in, or can we just do this ourselves?
It's a reasonable thing to ask. Your team understands your processes. You have people who know the tools, the history, and the reasons certain things work the way they do. Running an internal assessment looks like the faster, cheaper option, and in some circumstances it genuinely is.
But there's a structural problem with self-assessment that no amount of care or rigour can fully fix. And it's worth being clear about what that problem actually is before you decide which approach makes sense for your situation.
The bias isn't dishonesty. It's perspective.
When we talk about bias in a self-assessment, we're not suggesting anyone is trying to inflate their scores. The people filling in the assessment are usually thoughtful, senior, and genuinely trying to give an accurate picture.
The problem is that they can only answer from where they sit.
A head of IT service management rating their knowledge management capability will naturally draw on what they can see: the policies in place, the tools being used, the training that's been delivered. What they can't easily see is whether any of that is actually working as intended at the point where it matters most, which is when someone on the service desk is trying to resolve a P1 at 11pm on a Friday.
The processes are usually there. The tools are usually in place. What a self-assessment routinely misses is the gap between what exists and what actually happens.
This isn't a failure of attention or effort. It's a structural feature of being close to something. The further you are from day-to-day delivery, the more your view of it is shaped by what you intended, rather than what's occurring.
A framework gives you a scale. It doesn't give you an answer.
There's also a subtler issue with using a standard ITSM maturity framework, whether ITIL-based or otherwise, as the basis for a self-assessment.
Maturity frameworks describe what each level looks like in the abstract. They tell you that a "Defined" process has documented procedures and trained staff. What they can't tell you is whether your particular incident management process, with its specific quirks, workarounds, and exceptions built up over five years, actually qualifies as Defined or whether it just looks that way from the documentation.
Applying a framework to your own organisation requires interpretation at every step. And interpretation, made internally, tends to resolve in the direction of the more generous reading. Not through dishonesty, but because the person interpreting it knows all the context, understands why things are the way they are, and finds it natural to give credit for intent as well as outcome.
An independent assessor has no such context to draw on. They can only score what they actually observe and can verify. That sounds like a disadvantage. In practice, it's the point.
The challenge and coaching distinction
The most important difference between a self-assessment and a consultant-led assessment isn't the scoring scale or the methodology. It's the conversation.
In an independent assessment, the assessor's job isn't just to listen to what stakeholders say and record it. It's to challenge what they hear and coach people toward more precise, honest answers.
In practice that looks like this: a stakeholder describes their change management process as well-controlled and consistently followed. The assessor asks what happens when an emergency change comes in at short notice. The stakeholder explains the workaround that's developed over time for exactly that situation. The assessor notes that the workaround is the process, not the exception to it, and scores accordingly.
That conversation can't happen in a self-assessment. There's no one in the room whose job it is to push back, to ask the question again a different way, or to notice that the confident answer and the hesitant follow-up don't quite match.
We're not in the room to catch people out. We're there to help them see their own organisation more clearly than they can from inside it.
The coaching element matters just as much as the challenge. Good assessment conversations help stakeholders articulate things they know but haven't previously put into words, surface tensions between what different parts of the organisation believe to be true, and separate what's genuinely working from what's working well enough that nobody's complained yet.
The stakeholder evidence problem
There's a practical dimension to this that often gets overlooked. Even if a self-assessment produces accurate scores, it typically struggles to produce the kind of evidence that leadership needs to act on.
An IT director presenting internal findings to a board or executive sponsor is, in effect, presenting their own judgement about their own function. That's not an easy sell, however well-supported the findings are. The natural response is to probe the methodology, question whether the scoring was rigorous, and wonder whether the people doing the assessment had any stake in the outcome.
An independent assessment produces findings that aren't open to the same challenge. The scores came from outside. The evidence was gathered by people with no prior investment in how things look. That independence isn't just good epistemics, it's often what makes the findings actionable, because it removes the internal politics from the conversation about what to do next.
When internal assessment is genuinely the right call
It would be dishonest to suggest you always need external help. There are situations where an internal assessment is the appropriate starting point.
If you're doing an initial sense-check before deciding whether a formal assessment is warranted, an internal review can tell you whether the picture is roughly as you'd expect or whether there are obvious areas that need urgent attention. Our free ITSM maturity scorecard is built for exactly this: a quick baseline read with no commitment attached.
If your organisation is early in its ITSM journey and the main goal is building awareness rather than evidencing performance, internal review can be a useful starting point for internal conversations.
And if resource constraints make an external assessment genuinely impractical right now, an internal assessment with clearly documented limitations is better than nothing.
The honest question isn't "can we do this ourselves?" It's "what do we actually need the output of this assessment to do?" If the answer is to inform a board-level decision, justify an investment, or underpin a transformation programme, the bar for rigour is higher than an internal process can reliably clear.
What happens differently in a consultant-led assessment
To make the distinction concrete: in a Clarity Assessment, we interview stakeholders at multiple levels of the organisation, not just the people responsible for the processes we're assessing. We talk to the people doing the work, not just the people managing it. We compare what we hear from different stakeholders and surface the differences. We ask follow-up questions when an answer is too neat. We score against observable evidence, not documented intent.
The result is a picture of how your service management actually operates, not how it's designed to operate. Those two things are often closer than you'd expect. Occasionally they're further apart than anyone realised. Either way, the finding has credibility because it comes from somewhere other than inside the organisation.
If you're at the point of deciding whether to run a formal assessment, and you're weighing up the internal versus external question, that's a conversation worth having before you commit to either. We're straightforward about when an independent assessment would genuinely add value and when it wouldn't.
Start with a free baseline
Our free ITSM maturity scorecard gives you an honest starting point in under five minutes. No sales conversation attached.
Take the Free Scorecard →