A programme board cannot make a sound delivery decision from supplier narrative alone. It needs evidence that is current, attributable, internally consistent and sufficient for the decision being requested.
This checklist gives senior responsible owners, programme directors and programme boards a controlled basis for requesting supplier evidence. Enigma sits on the client’s side of the table. The supplier may explain and evidence its work, but nobody should independently assure delivery that they directly own.
For the wider principles, read How We Assure and the Evidence Sufficiency Standard. Where the request identifies material uncertainty, use the Enigma contact route to scope independent review.
How to use this checklist
Define the decision the evidence must support.
Set the evidence period and submission deadline.
Name the supplier owner and client-side reviewer for each item.
Require source evidence, not a rewritten status summary.
Record gaps, contradictions and qualifications.
Keep delivery ownership separate from independent assurance.
1. Governance and accountability
Current delivery organisation chart with named client and supplier accountabilities.
Approved governance structure, terms of reference and meeting cadence.
Responsibility matrix covering delivery, acceptance, assurance and decision authority.
Decision and action logs with owners, dates, conditions and closure evidence.
Escalation routes for delivery, commercial, security, data and operational risks.
Declared conflicts affecting reporting, quality control or assurance.
Test: Can the client identify who owns each outcome, who accepts it and who can independently challenge it?
2. Scope, requirements and acceptance
Approved scope baseline and controlled record of changes.
Prioritised requirements with source, owner and measurable acceptance criteria.
Traceability from business outcome to requirement, design, build, test and acceptance.
Exclusions, assumptions, dependencies and deferred requirements.
Change impact across cost, schedule, quality, risk, resources and benefits.
Ambiguous, disputed or unapproved requirements.
Test: Is progress measured against an agreed baseline or a moving interpretation of scope?
3. Plan, milestones and dependencies
Integrated plan across supplier, client and third parties.
Milestones with entry criteria, exit criteria, owner and acceptance authority.
Critical path and near-critical path analysis.
Dependency register with dates, owners, consequences and escalation status.
Baseline versus forecast with reasons for material variance.
Resource capacity against demand and evidence supporting forecast assumptions.
Recovery plans with measurable recovery tests.
Test: Does the forecast follow from demonstrated delivery performance?
4. Financial and commercial control
Approved financial baseline and forecast at completion.
Actual, committed and forecast spend reconciled to one cut-off.
Milestone payments linked to contractual acceptance conditions.
Open claims, changes, disputes and licence or third-party commitments.
Cost consequences of delay, rework and extended support.
Benefits assumptions affected by delivery change.
Test: Can the board see the full cost exposure, including amounts not yet invoiced?
5. Architecture, engineering and non-functional quality
Approved architecture decisions and outstanding decisions.
Technical requirements traced to implemented controls and verification.
Build and release records for every environment.
Code quality, configuration, integration and technical debt evidence.
Performance, resilience, availability, capacity, accessibility and supportability results.
Technical waivers and deviations with approval authority and expiry conditions.
Evidence that production-like constraints were represented in testing.
Test: Is the solution proven fit for intended operating conditions?
6. Quality and test assurance
Approved strategy and phase plans aligned to programme risks.
Entry and exit criteria for every test phase.
Requirements coverage and outcomes by business-critical area.
Defects by severity, age, owner, cause and resolution forecast.
Closure and regression evidence.
Accepted defects and workarounds with named authority.
Environment and test-data constraints affecting confidence.
Independent challenge where the supplier owns both delivery and test reporting.
Test: Do results demonstrate acceptable residual risk, or merely report activity?
7. Data migration and cutover
Migration scope, data ownership and source-to-target mapping.
Data-quality profile, cleansing rules and unresolved exceptions.
Reconciliation controls, tolerances and accountable sign-off.
Rehearsal results including leakage and duration.
Cutover sequence, dependencies, decision points and rollback conditions.
Go or no-go criteria linked to named evidence.
Post-cutover validation and early-life support.
Test: Can the client prove complete and accurate migration and control the transition if events depart from plan?
8. Security, privacy and information governance
Applicable security, privacy, records and information requirements.
Threat, risk and privacy assessments with current actions.
Control implementation and security testing evidence.
Access and privileged-access controls.
Personal-data flows, retention and processor responsibilities.
Risk acceptances and compensating controls approved by the correct authority.
Incident, backup, recovery and continuity evidence.
Test: Are conclusions based on implemented and tested controls, not intended design?
9. Operational readiness
Target operating model with named service ownership.
Support model, service levels, escalation and supplier hand-offs.
Procedures, monitoring and service-management integration.
Training, communications and readiness evidence by affected group.
Support capacity and knowledge transfer.
Early-life support entry and exit criteria.
Outstanding operational risks and temporary workarounds.
Test: Is there demonstrable capacity to operate the change safely from day one?
10. Risk, issue and assumption integrity
Current risk, assumption, issue and dependency records.
Ratings that reflect present exposure.
Quantified impact where practicable.
Mitigation evidence showing effect, not merely activity.
Common-cause and aggregate-risk analysis.
Explicit treatment of unknowns and evidence gaps.
Test: Does the risk position describe the programme that exists?
Evidence submission standard
Each item should record a unique reference, supported assertion, accountable owner, originating source, effective date, version, approval status, limitations, reviewer, validation result and client-accessible retention location.
Evidence that should be challenged
Undated screenshots without source references.
Percentages without a denominator or acceptance basis.
Slide summaries that cannot be reconciled to source records.
Plans with overwritten baselines.
Defect totals without severity, age, impact or closure evidence.
Pass rates excluding blocked, not-run or de-scoped tests.
Risk ratings reduced because mitigation was planned rather than proven.
Minutes used as proof of completion.
Supplier self-certification of delivery it owns.
Minimum client-side review output
Evidence received and validated.
Evidence received but qualified.
Evidence missing or inaccessible.
Contradictions requiring resolution.
Material findings and decision consequences.
Actions, owners, dates and decision conditions.
A confidence statement separating fact, judgement and uncertainty.