Requirements - Strategic Alignment, Vision, and Roadmap - S02 - Capability Model

We should be able to demonstrate which capabilities from the NHSE Business Capability Model the solution is realising, and any potential duplication identified.

Requirement description

The solution should be mapped to the relevant capabilities in the NHSE Business Capability Model. The mapping should show what the solution enables, supports or changes. It should also identify where the same or a similar capability may already be provided elsewhere.

This allows assessors to understand the solution’s place in the wider organisation and the risk of investing in overlapping capabilities.

In simple terms:
Can the team show which business capabilities the solution realises and demonstrate that possible duplication has been identified and considered?

Scoring rubric: Business capability mapping and duplication

Score What it looks like Typical evidence Key gaps / risks
0 No evidence that the solution has been considered against the NHSE Business Capability Model. The team cannot identify which capabilities the solution realises. No capability mapping.
No recorded capability analysis.
No assessment of existing or overlapping solutions.
Significant risk of duplicated investment.
The purpose and organisational fit of the solution are unclear.
Opportunities to reuse existing capabilities may be missed.
1 The team has an informal view of the relevant business capabilities, but this has not been mapped or validated. Duplication is discussed only at a general level. Verbal descriptions.
Informal workshop notes.
Unstructured references to capabilities or similar services.
High-risk gaps in coverage and traceability.
Capability names may not align with the current model.
Existing provision may not have been identified.
2 Some solution functions have been mapped to business capabilities. The mapping is incomplete, inconsistent or not based on an agreed version of the capability model. Some possible duplication has been identified, but it has not been fully analysed. Partial capability-to-solution mapping.
Early architecture diagrams or spreadsheets.
A list of potentially similar products or services.
Initial workshop outputs.
A significant number of capabilities or solution components remain unmapped.
Duplication analysis lacks owners, conclusions or actions.
The evidence may not be maintained.
3 Much of the solution is mapped to the relevant business capabilities using an identifiable version of the model. Potential duplication has been reviewed for the main capabilities. Notable gaps remain and require mitigating action. A documented capability-to-solution mapping covering most of the solution scope.
References to the capability model version used.
A comparison with known existing solutions or services.
Recorded duplication risks, assumptions and proposed actions.
Some components or capability relationships remain unclear.
The duplication review may be limited to the immediate directorate or portfolio.
Actions may lack agreed owners, dates or governance oversight.
4 Most of the solution is clearly and consistently mapped to the current agreed capability model. The mapping has a named owner, is maintained and is used in architecture or planning decisions. Potential duplication has been assessed and the outcome is recorded. Remaining gaps do not present significant risk. A maintained capability map linked to solution architecture artefacts.
Clear ownership and review dates.
Evidence of stakeholder or architecture governance review.
Documented analysis of overlapping capability provision.
Decisions to reuse, consolidate, differentiate or accept duplication, with rationale.
Minor mapping or coverage gaps only.
A small number of dependencies may still require validation.
Residual duplication risks are understood and controlled.
5 Comprehensive and maintained evidence shows how the solution realises business capabilities at an appropriate level of detail. Capability mapping is embedded in governance, portfolio planning and architecture decision-making. Duplication is proactively identified and the approach is considered exemplary. Complete, version-controlled capability-to-solution mapping.
Traceability from capabilities to architecture components, roadmap items and investment decisions.
Evidence of review with relevant capability owners and governance bodies.
Cross-portfolio analysis of overlapping provision.
Measurable actions to reuse, consolidate or retire duplicate capability provision.
Evidence that findings have improved the wider capability model or organisational planning.
Minimal gaps.
Any accepted duplication has a clear rationale, owner and review mechanism.
Changes to the solution or capability model are actively monitored.

The score progression follows the SAF model from no supporting evidence and significant service risk at score 0, through to comprehensive, above-expectation evidence and exemplar practice at score 5.

What assessors should look for

  1. Capability coverage: The solution’s main functions and components are mapped to named capabilities in the NHSE Business Capability Model.
  2. Model currency: The evidence identifies which version or baseline of the capability model was used.
  3. Traceability: The mapping is connected to relevant solution architecture, scope, roadmap or investment decisions.
  4. Duplication analysis: Existing solutions that realise the same or similar capabilities have been identified and considered.
  5. Decision and rationale: The team has recorded whether to reuse, consolidate, differentiate or accept overlapping capability provision.
  6. Ownership and maintenance: The mapping has an owner, review arrangements and evidence that it is updated when the solution or capability model changes.
  7. Governance and use: The evidence has been reviewed by relevant stakeholders and is actively used in delivery, planning or architecture decisions.

Assessors should focus on the outcome and the sufficiency of the evidence, rather than requiring one fixed document format. The SAF states that a requirement may be met in different ways and that assessment should be risk-based.

What separates a 3 from a 4 or 5

A score of 3 usually means that most of the solution has been mapped and the main duplication risks have been considered, but notable gaps remain. The mapping may not cover the full solution, may not be regularly maintained, or may not have clear ownership and governance.

A score of 4 requires a maintained mapping, clear ownership, stakeholder or governance review, and evidence that duplication analysis has informed decisions. Gaps should be minor and should not present significant risk.

A score of 5 requires comprehensive traceability and proactive cross-portfolio analysis. Capability information should be embedded in governance and planning, and there should be evidence that the practice improves wider organisational decision-making. Score 5 is exemplar practice, not simply the absence of gaps.

Suggested evidence examples (not SAF-mandated artefacts)

  • A capability-to-solution matrix
  • Architecture model view
  • Heat map
  • Portfolio overlap assessment
  • Capability owner review
  • Architecture decision record
  • Documented reuse assessment

Updated: 04 September 2026 (SAF Version 1.1)