Skip to content

What an Independent Assurance Review Examines

An independent assurance review does not examine everything equally. It tests the evidence and controls that matter to a defined client decision, following material risks across supplier and workstream boundaries.

Six core assurance review domains: programme control, quality, architecture, security, data migration, and cutover and operations.

Key judgement

The review must be broad enough to expose connected failure, but disciplined enough to avoid becoming a parallel programme office.

Start with the decision

The review defines what the client is being asked to decide and which delivery claims must be true for that decision to be defensible. This prevents a large document request from replacing analysis.

A go-live decision may connect plan confidence, business-process testing, migration reconciliation, cutover rehearsal, operational readiness and residual defects. Examining any one area in isolation can miss the way exposure transfers between them.

Seven examination domains

DomainClaims examinedEvidence examples
GovernanceDecision rights, risk ownership and escalation operate.Mandate, decisions, tolerances, minutes and escalation records.
Plan and viabilityMilestones are achievable and dependencies controlled.Logic-linked schedule, critical path, capacity, actuals and forecasts.
Supplier deliveryObligations are evidenced and acceptance is controlled.Deliverables, obligation traceability, exceptions and acceptance criteria.
Quality and testingMaterial business and technical risk has been tested.Coverage, execution, defects, environments, data and acceptance.
ArchitectureImplemented behaviour meets technical and operational obligations.Decisions, requirements, integration, performance, resilience and security evidence.
Migration and cutoverData and transition can be executed and reconciled.Mappings, exceptions, rehearsals, runbook, timings and contingency.
OperationsPeople, process, service and technology can operate together.Support, monitoring, service scenarios, continuity and operational acceptance.

Evidence examination flow

1. Claim

2. Criteria

3. Source evidence

4. Contradiction test

5. Consequence

Trace the claim

A dashboard is treated as a summary, not as the end of the trail. The reviewer identifies the owner, source, date and records supporting the material claim.

Test the criteria

Evidence is compared with the relevant obligation, acceptance criterion, control or condition. Missing or late-changing criteria are examined as governance weaknesses.

Seek contradictions

Connected records are compared. A forecast may conflict with dependency dates. A pass rate may conflict with limited coverage. A completed rehearsal may conflict with unresolved timing failures.

Assess consequence

The reviewer decides whether the weakness changes confidence, creates a decision condition or remains a management improvement. This is what turns evidence review into an assurance opinion.

Review methods

  • Structured interviews across client, supplier and operational owners.
  • Direct examination of controlled artefacts and source records.
  • Traceability sampling across requirements, delivery, testing and acceptance.
  • Walkthroughs of critical business, migration, cutover and service scenarios.
  • Trend and exception analysis.
  • Testing whether controls have operated and produced results.
  • Triangulation where parties interpret the position differently.

Scope limits

The opinion is bounded by mandate, evidence cut-off and access. It does not imply that every record was tested or that excluded areas are satisfactory. Any restriction capable of changing the decision must be explicit.

Six stages of evidence examination from defining the decision to forming a bounded assurance opinion.

Application by client context

ContextAssurance focus
Central GovernmentEvidence for SRO and programme board decisions, multi-supplier dependency, major approvals and public accountability.
Local GovernmentCitizen service continuity, supplier challenge and proportionate scrutiny without creating a permanent council function.
SMEProtection of investment and operations where the technology supplier holds most technical knowledge and evidence.

The consequence for client governance

The supplier remains responsible for delivery and for producing the evidence behind its claims. The client retains accountability for approval, acceptance and residual risk. Independent assurance gives that client a defensible basis for deciding what to rely on, what to condition and when to intervene.

Related Enigma framework pages

Independence boundary

No practitioner independently assures delivery that they directly own. Delivery support, management action and independent verification must be separated and disclosed.