A programme can report green while confidence in the evidence is low. Enigma’s confidence rating expresses how strongly the available evidence supports a defined delivery claim or decision. It is not another RAG status.
Key judgement
Confidence must never be averaged into comfort. A single material control failure or unresolved dependency can cap the overall rating when it threatens the decision.

What confidence means
Confidence is the strength of the evidence-based basis for relying on a delivery claim. It considers whether the evidence is sufficient, whether the relevant controls are operating, whether material dependencies are understood, whether the trend is stable and how much residual uncertainty remains.
It does not predict the future with certainty. It does not replace delivery status, risk severity or professional judgement. Its purpose is to show the accountable client how much reliance can reasonably be placed on the position presented.
The four ratings
| Rating | Meaning | Decision implication |
|---|---|---|
| High | Material claims are supported by complete, current and consistent evidence. Controls are operating and residual uncertainty is bounded. | The client can place substantial reliance on the claim, while retaining normal governance oversight. |
| Moderate | The principal claim is supported, but one or more limitations, dependencies or control weaknesses require active management. | A decision may proceed with explicit conditions, owners and verification dates. |
| Low | Material evidence is weak, contradictory or shows ineffective controls. Significant uncertainty could change the decision. | Do not rely on the stated position without intervention, further evidence or a revised decision. |
| Insufficient Evidence | The evidence base cannot support a defensible conclusion in either direction. | The client must not treat lack of proof as confidence. Obtain evidence, narrow the decision or defer it. |
Five assessment dimensions
| Dimension | Question |
|---|---|
| Evidence sufficiency | Is the claim supported by relevant, complete, current, traceable and corroborated evidence? |
| Control effectiveness | Are the controls designed appropriately, operating in practice and producing the required result? |
| Dependency exposure | Are material internal, supplier and external dependencies understood, owned and achievable? |
| Trend and stability | Is performance improving, stable or deteriorating, and is the trend supported over a meaningful period? |
| Residual uncertainty | What remains unknown, how material is it and could it alter the client decision? |
Rating mechanics
1. Define the claim
2. Assess each dimension
3. Identify material caps
4. Record limitations
5. Set decision conditions
Materiality cap
The weakest score does not automatically determine every rating, but it must cap the opinion when the weakness could invalidate the decision. For example, strong testing cannot create high confidence in go-live if cutover dependencies remain unowned. A well-maintained plan cannot create high confidence if the critical supplier deliverable has not been accepted.
No arithmetic averaging
Numerical averages can conceal a critical failure behind several stronger dimensions. Ratings are reached through structured judgement, with the material evidence and any cap recorded. If the evidence does not permit that judgement, the correct rating is Insufficient Evidence.
Rating decision guide
| Evidence and control position | Likely rating | Required governance response |
|---|---|---|
| Material evidence complete, controls effective, dependencies bounded | High | Continue oversight and monitor known residual risks. |
| Evidence largely sufficient, manageable limitations remain | Moderate | Proceed only with named conditions and closure verification. |
| Material gaps or ineffective controls could alter the outcome | Low | Intervene, reduce exposure or reconsider the proposed decision. |
| Key claims cannot be tested | Insufficient Evidence | Do not approve on assertion. Require evidence or defer. |
How boards should use the rating
- Apply the rating to a specific claim or decision, not to the programme as a vague whole.
- Read the evidence basis and limitations alongside the rating.
- Challenge any change in confidence that is unsupported by new evidence.
- Treat conditions as governance commitments, not optional recommendations.
- Record who accepts residual risk when the client proceeds below High confidence.
What the rating cannot prove
A High rating does not guarantee delivery success. It means the current claim has a strong evidential basis within the stated scope and cut-off date. A Low rating does not prove inevitable failure. It means the client does not yet have a defensible basis for reliance and should act accordingly.
Board test
If a rating cannot be explained in terms of evidence, controls, dependencies, trend and uncertainty, it is an opinion label rather than an assurance judgement.

How this standard supports client governance
This standard gives the client a repeatable basis for challenging delivery claims without taking ownership away from the supplier. It enables proportionate scrutiny, records the reasoning behind material decisions and makes residual uncertainty visible to the accountable decision maker.
Use with
Independence safeguard
No practitioner may independently assure delivery that they directly own. Where advisory support and assurance are both required, roles, reporting lines and review responsibility must be separated and recorded.