Skip to content

Supplier Evidence Request Checklist

A programme board cannot make a sound delivery decision from supplier narrative alone. It needs evidence that is current, attributable, internally consistent and sufficient for the decision being requested. This checklist gives senior responsible owners, programme directors and programme boards a controlled basis for requesting supplier evidence. Enigma sits on the client’s side of the table. The supplier may explain and evidence its work, but nobody should independently assure delivery that they directly own. For the wider principles, read How We Assure and the Evidence Sufficiency Standard. Where the request identifies material uncertainty, use the Enigma contact route to scope independent review.
Flow from a supplier claim through source evidence and client-side validation to a confidence judgement and programme board decision.

How to use this checklist

  1. Define the decision the evidence must support.
  2. Set the evidence period and submission deadline.
  3. Name the supplier owner and client-side reviewer for each item.
  4. Require source evidence, not a rewritten status summary.
  5. Record gaps, contradictions and qualifications.
  6. Keep delivery ownership separate from independent assurance.

1. Governance and accountability

  • Current delivery organisation chart with named client and supplier accountabilities.
  • Approved governance structure, terms of reference and meeting cadence.
  • Responsibility matrix covering delivery, acceptance, assurance and decision authority.
  • Decision and action logs with owners, dates, conditions and closure evidence.
  • Escalation routes for delivery, commercial, security, data and operational risks.
  • Declared conflicts affecting reporting, quality control or assurance.
Test: Can the client identify who owns each outcome, who accepts it and who can independently challenge it?

2. Scope, requirements and acceptance

  • Approved scope baseline and controlled record of changes.
  • Prioritised requirements with source, owner and measurable acceptance criteria.
  • Traceability from business outcome to requirement, design, build, test and acceptance.
  • Exclusions, assumptions, dependencies and deferred requirements.
  • Change impact across cost, schedule, quality, risk, resources and benefits.
  • Ambiguous, disputed or unapproved requirements.
Test: Is progress measured against an agreed baseline or a moving interpretation of scope?

3. Plan, milestones and dependencies

  • Integrated plan across supplier, client and third parties.
  • Milestones with entry criteria, exit criteria, owner and acceptance authority.
  • Critical path and near-critical path analysis.
  • Dependency register with dates, owners, consequences and escalation status.
  • Baseline versus forecast with reasons for material variance.
  • Resource capacity against demand and evidence supporting forecast assumptions.
  • Recovery plans with measurable recovery tests.
Test: Does the forecast follow from demonstrated delivery performance?

4. Financial and commercial control

  • Approved financial baseline and forecast at completion.
  • Actual, committed and forecast spend reconciled to one cut-off.
  • Milestone payments linked to contractual acceptance conditions.
  • Open claims, changes, disputes and licence or third-party commitments.
  • Cost consequences of delay, rework and extended support.
  • Benefits assumptions affected by delivery change.
Test: Can the board see the full cost exposure, including amounts not yet invoiced?

5. Architecture, engineering and non-functional quality

  • Approved architecture decisions and outstanding decisions.
  • Technical requirements traced to implemented controls and verification.
  • Build and release records for every environment.
  • Code quality, configuration, integration and technical debt evidence.
  • Performance, resilience, availability, capacity, accessibility and supportability results.
  • Technical waivers and deviations with approval authority and expiry conditions.
  • Evidence that production-like constraints were represented in testing.
Test: Is the solution proven fit for intended operating conditions?

6. Quality and test assurance

  • Approved strategy and phase plans aligned to programme risks.
  • Entry and exit criteria for every test phase.
  • Requirements coverage and outcomes by business-critical area.
  • Defects by severity, age, owner, cause and resolution forecast.
  • Closure and regression evidence.
  • Accepted defects and workarounds with named authority.
  • Environment and test-data constraints affecting confidence.
  • Independent challenge where the supplier owns both delivery and test reporting.
Test: Do results demonstrate acceptable residual risk, or merely report activity?
Matrix comparing evidence strength and decision relevance, showing reject, qualify, corroborate and sufficient outcomes.

7. Data migration and cutover

  • Migration scope, data ownership and source-to-target mapping.
  • Data-quality profile, cleansing rules and unresolved exceptions.
  • Reconciliation controls, tolerances and accountable sign-off.
  • Rehearsal results including leakage and duration.
  • Cutover sequence, dependencies, decision points and rollback conditions.
  • Go or no-go criteria linked to named evidence.
  • Post-cutover validation and early-life support.
Test: Can the client prove complete and accurate migration and control the transition if events depart from plan?

8. Security, privacy and information governance

  • Applicable security, privacy, records and information requirements.
  • Threat, risk and privacy assessments with current actions.
  • Control implementation and security testing evidence.
  • Access and privileged-access controls.
  • Personal-data flows, retention and processor responsibilities.
  • Risk acceptances and compensating controls approved by the correct authority.
  • Incident, backup, recovery and continuity evidence.
Test: Are conclusions based on implemented and tested controls, not intended design?

9. Operational readiness

  • Target operating model with named service ownership.
  • Support model, service levels, escalation and supplier hand-offs.
  • Procedures, monitoring and service-management integration.
  • Training, communications and readiness evidence by affected group.
  • Support capacity and knowledge transfer.
  • Early-life support entry and exit criteria.
  • Outstanding operational risks and temporary workarounds.
Test: Is there demonstrable capacity to operate the change safely from day one?

10. Risk, issue and assumption integrity

  • Current risk, assumption, issue and dependency records.
  • Ratings that reflect present exposure.
  • Quantified impact where practicable.
  • Mitigation evidence showing effect, not merely activity.
  • Common-cause and aggregate-risk analysis.
  • Explicit treatment of unknowns and evidence gaps.
Test: Does the risk position describe the programme that exists?

Evidence submission standard

Each item should record a unique reference, supported assertion, accountable owner, originating source, effective date, version, approval status, limitations, reviewer, validation result and client-accessible retention location.

Evidence that should be challenged

  • Undated screenshots without source references.
  • Percentages without a denominator or acceptance basis.
  • Slide summaries that cannot be reconciled to source records.
  • Plans with overwritten baselines.
  • Defect totals without severity, age, impact or closure evidence.
  • Pass rates excluding blocked, not-run or de-scoped tests.
  • Risk ratings reduced because mitigation was planned rather than proven.
  • Minutes used as proof of completion.
  • Supplier self-certification of delivery it owns.

Minimum client-side review output

  • Evidence received and validated.
  • Evidence received but qualified.
  • Evidence missing or inaccessible.
  • Contradictions requiring resolution.
  • Material findings and decision consequences.
  • Actions, owners, dates and decision conditions.
  • A confidence statement separating fact, judgement and uncertainty.