Decision-specific assurance insight
A migration can complete on time, reconcile at a headline level and still leave the organisation with data that is incomplete, distorted or unusable in the processes that matter.
The board-level question is not whether the supplier ran the migration. It is whether the client has enough independent evidence to accept the migrated data, enter cutover and operate safely.
Enigma sits on the client’s side of the table. We assess whether the evidence is sufficient for the decision being made. We do not allow the team that designed, transformed or loaded the data to provide the only assurance over its own work.
A completed load is not an assured migration
Delivery reporting often treats technical completion as proof of success. Extracts ran. Transformation jobs completed. Records loaded. Exception counts fell. The supplier declared the rehearsal complete.
None of those facts alone proves that the right data reached the right destination, retained its intended meaning and can support real business activity.
Migration assurance must connect technical evidence to operational consequences. That requires programme, quality, architecture, business process, migration and cutover perspectives to be tested together. Enigma uses those disciplines as one multidisciplinary assurance capability, not as a catalogue of individual contractors.

The six tests for decision-grade migration evidence
1. Scope and population integrity
The board needs evidence that the migration population is defined, controlled and complete. That includes the systems, entities, records, time periods, attachments, reference data and historical data in scope, plus a justified treatment for anything excluded.
Counts must reconcile at the right level. A single total can conceal missing records in one business unit and duplicate records in another. Reconciliation should be stratified by data domain, organisational unit, status and other material dimensions.
2. Transformation correctness
Mapping documents do not prove that transformation logic is correct. Rules must be traceable to an approved business requirement, technically implemented as specified and tested against normal, boundary and exceptional data.
Where source and target models differ, assurance must test whether meaning has been preserved. Default values, merged fields, derived values, code conversions and date handling can all produce technically valid records that are operationally wrong.
Enigma’s published primer on Data Migration and Cutover Assurance explains the core migration stages. Independent assurance adds the decision control: whether those stages produced evidence strong enough for acceptance.
3. Reconciliation depth
Record counts are necessary but weak. Decision-grade reconciliation also tests financial values, balances, relationships, status distributions, duplicate rates, mandatory-field completeness and referential integrity.
Every material variance needs a cause, an owner and a disposition. “Known issue” is not a disposition. The board must know whether the variance will be corrected before cutover, corrected after cutover under control, accepted as harmless or treated as a reason not to proceed.
4. Business usability
Data can pass technical validation and still fail the user. Assurance must prove that migrated data supports priority end-to-end processes, reports, interfaces, statutory duties and operational decisions.
Samples should be risk-based, not merely convenient. High-value, high-volume, sensitive and operationally complex cases require explicit coverage. Business owners must be able to trace a result back to the migrated record and confirm that it is understandable and usable.
5. Control, security and auditability
Migration introduces temporary data stores, elevated access, manual interventions and exceptional processing. Assurance must confirm how sensitive data was protected, who could access it, what changed, and whether the transformation and load history can be reconstructed.
The evidence should cover access controls, segregation of duties, audit logs, retention, deletion of temporary extracts, exception handling and approval of manual corrections. A technically correct result is not acceptable if the route used to create it was uncontrolled.
6. Cutover readiness and residual risk
The final rehearsal must demonstrate more than a successful load. It must establish realistic duration, resource demand, dependency timing, rollback feasibility, reconciliation turnaround and the point at which reversal is no longer viable.
Open defects, unresolved variances and deferred cleansing must be converted into explicit acceptance conditions. Each condition needs an owner, due date, impact statement, contingency and governance route. The decision should be proceed, proceed with conditions, hold or reject. It should never be inferred from a green status.

Warning signs that assurance is weak
- The supplier defines the acceptance criteria and then reports whether it met them.
- Reconciliation relies on total record counts without domain-level or value-level analysis.
- Business validation uses small, convenient samples selected by the delivery team.
- Transformation rules have no clear business owner or approval history.
- Exceptions are carried as narrative rather than quantified risk.
- The final rehearsal differs materially from the planned cutover in volume, sequence, tooling or staffing.
- Rollback is described but has not been timed and tested.
- Migration, testing and cutover teams use different definitions of complete.
What the programme board should require
- A controlled migration scope and approved data-quality baseline.
- Traceable transformation rules with named business owners.
- Reconciliation results at record, value, relationship and business-process levels.
- Risk-based business validation with documented sample selection.
- A complete exception register with impact, ownership and disposition.
- Evidence from production-like rehearsals, including timing and recovery.
- An independent confidence assessment that distinguishes fact, inference and supplier assertion.
- A formal migration acceptance decision recorded with conditions and residual risks.
Platform-specific migration guidance can help teams understand execution concerns. It does not replace the Evidence Sufficiency Standard or independent assessment of the programme’s actual controls and readiness.
The practical resource
The proposed checklist will structure the evidence request across scope, mapping, reconciliation, business validation, controls, rehearsals, cutover and residual risk. It should be used before the final migration rehearsal, not after the programme has already committed to go-live.
The decision Enigma supports
Enigma does not take ownership of the supplier’s migration delivery. We establish what evidence exists, test whether it is sufficient, identify contradictions and omissions, rate confidence, and present the client with a defensible decision.
That decision may be to proceed, proceed with conditions, hold or reject. The purpose is not to manufacture certainty. It is to stop unsupported confidence being mistaken for control.
Organisations preparing for migration acceptance or cutover can use Enigma’s contact route to define the decision, evidence scope and independence boundary for an assurance review.