Arrio

For the CIO and CDOAn objective baseline for every technology decision

Programmes, platforms and vendors on one independent measure, before and after each call you make. So the decisions you are accountable for start from evidence, not from the status report of the team being assessed.

The problem

Decisions made without a baseline

You are accountable for a portfolio of programmes, platforms and vendors, and for the risk carried in all of them. Yet most of the inputs to your decisions come from the people whose work the decision judges, filtered on the way up.

The risk is compounding while it stays invisible. The share of new code rewritten within two weeks has more than doubled since AI, from 3.3% to 7.1%, and duplicated code blocks are up 81% (GitClear, 2026), while the AI shift is adding defects even to healthy codebases, up 60% (CodeScene, 2026). None of it shows in a delivery update.

What is missing is an independent baseline: one measure that reads the work itself, holds steady across programmes and vendors, and lets you see the effect of each decision before and after you make it.

Of new code is now rewritten within two weeks, up from 3.3% before AI. (GitClear, 2026)
7.1%
Of new code is now rewritten within two weeks, up from 3.3% before AI. · GitClear, 2026
Increase in duplicated code blocks, most of it invisible in status reports. (GitClear, 2026)
+81%
Increase in duplicated code blocks, most of it invisible in status reports. · GitClear, 2026
More AI-induced defects, even in codebases rated healthy. (CodeScene, 2026)
+60%
More AI-induced defects, even in codebases rated healthy. · CodeScene, 2026

What you get

01

One measure across the portfolio

Programmes, platforms and vendors read on the same independent scale, so like is compared with like.

02

Before and after every decision

A baseline you can hold a call against, to see whether a rationalisation, a migration or a vendor change actually moved the number.

03

Ahead of the risk

Technical debt, security and architecture read from the code as it stands, so the exposures are on the table before they price themselves in.

04

Delivery assurance

Real progress read from the work, not from the deck, so course corrections happen in weeks rather than at year end.


How a CIO uses it

One measure that holds from the board meeting down to the delivery teams, so the same picture works in both directions.

01Establish the baseline before the next decision

Before rationalising a platform, renewing a vendor or funding a modernisation, take an independent read of where the portfolio actually stands. Every argument that follows dates from this line.

02Put every programme on one comparable measure

In-house teams, offshore partners and acquired estates stop being separate conversations with separate reporting. One scale, so you can see which parts are carrying the organisation and which are being carried.

03Prove the AI transformation, or redirect it

How much of the work is now AI-built, and whether that is reaching delivered value. This is the question the board will ask, and the one hardest to answer from internal reporting.

04See the risk before it arrives

Security, architecture and technical-debt findings read from the code as it stands, rather than from a status update written by the team being assessed.

05Take the same picture in both directions

Upwards it is a board-ready read in business language. Downwards it is specific enough for your teams to act on, and it shows them which parts of the organisation are worth learning from.

Questions

The questions worth asking

We already have DORA and engineering metrics. Why this?

Keep them; they are useful for how teams run, and they measure flow and activity. They cannot tell you what the spend produced, what better would be worth, or whether the AI investment is paying off. Arrio adds that value layer on top, and it is independent of the teams it measures.

How does it fit our existing security posture?

Arrio supports multiple deployment and security models, chosen to suit your business: multi-tenant with read-only repository access, or running inside your own cloud so nothing leaves your estate. Access is read-only, sandboxed and audit-trailed, and source code is not stored. The current detail lives at docs.arrio.ai.

Does it replace our engineering tooling?

No. It sits above it. Your teams keep the tools that run delivery; Arrio provides the independent read that leadership governs by.

Sources

  1. GitClear, 2026 Maintainability Gap study, 211M lines of code: the share of new code rewritten within two weeks rose from 3.3% to 7.1%; duplicated code blocks up 81%; cross-file reuse down 35%; refactoring moves down 70%.
  2. CodeScene, 2026 60% increase in AI-induced defects even in codebases rated healthy.
  3. DX, 2026 Survey of 121,000 developers across 450+ companies: 26.9% of production code is AI-authored, up from 22% the previous quarter, while productivity gains plateaued at about 10% despite 93% adoption.

Give every technology decision an independent baseline.