
Assurance only has value when it is independent enough to challenge delivery and informed enough to understand it.
Enigma works for the client. Our responsibility is not to defend the programme narrative, protect a supplier relationship or preserve a date that the evidence no longer supports. Our responsibility is to give client leadership an accurate view of delivery confidence and the controls required to protect the outcome.
The problem
Leadership is often asked to approve funding, accept a phase, rely on a recovery plan or authorise go-live using information produced by the same delivery chain whose performance is being judged. The reporting may be extensive and professionally presented, but volume does not establish independence or evidential sufficiency.
The control gap
The missing control is a client-side function with the mandate, access and specialist capability to test material delivery claims before governance relies on them. It must remain separate from delivery ownership, report to the body that owns the decision and apply an explicit evidence standard.
- Delivery suppliers remain responsible for delivery, control operation, remediation and supporting evidence.
- Client governance remains responsible for outcomes, acceptance and risk decisions.
- Enigma independently examines evidence, challenges the reported position and states residual exposure.
- No practitioner provides independent assurance over work they directly own.
The core service proposition is explained in Independent Delivery Assurance.
The client-side assurance boundary
Delivery suppliers
Own delivery, controls, outputs, remediation and supporting evidence.
Enigma assurance
Tests the evidence, challenges the position and states residual exposure.
Client governance
Owns the outcome, accepts risk and makes the decision.
Supplier evidence → independent challenge → informed client decision
Independent assurance for public bodies and growing businesses
Central and local government
Public bodies need assurance that is independent of the delivery chain and capable of standing up to programme boards, audit, scrutiny and public accountability. Enigma tests supplier evidence, exposes unresolved dependencies and gives governance a clear record of readiness, exceptions, ownership and accepted risk.
- Protect critical public services and operational continuity.
- Strengthen multi-supplier governance and accountability.
- Support defensible investment, acceptance and go-live decisions.
- Create an auditable evidence trail without duplicating delivery.
SMEs without an internal assurance team
An SME buying a major system or transformation should not have to build a permanent QA department merely to challenge its supplier. Enigma provides proportionate, senior assurance at the points where supplier claims become commercial, operational or investment risk.
- Avoid suppliers marking their own homework.
- Gain independent challenge without permanent headcount.
- Focus assurance on the decisions where failure would matter.
- Protect cash, operations and management attention.
Our operating principles
Client-side independence
We remain organisationally and intellectually separate from the teams whose work we assure. We engage closely with suppliers, but our conclusions and reporting serve the client’s interests.
Evidence before confidence
Plans, status reports and professional confidence are inputs, not proof. We test material claims against agreed criteria, delivery artefacts, traceability, observed outcomes and accountable acceptance.
Risk stated without dilution
Where evidence is incomplete or a control has failed, we state it. Where a programme chooses to proceed, the exposure, mitigation, owner and approval must be explicit. Ambiguous language protects nobody.
Proportionate control
Assurance is not a demand for more documents, meetings or process. Controls must be proportionate to the consequence of failure. We remove low-value ceremony and concentrate on decisions, dependencies and evidence that materially affect the outcome.
Constructive challenge
Independent scrutiny is not supplier hostility. We establish clear expectations, give delivery teams the opportunity to produce evidence and distinguish recoverable gaps from fundamental failures. Challenge remains direct because delayed candour is expensive.
Accountability remains where it belongs
Enigma does not take ownership away from the client, programme or supplier. We make responsibilities visible, prevent gaps being transferred informally and ensure that acceptance of risk remains an explicit client decision.
Enigma uses a named assurance method that converts supplier evidence into an independent conclusion and a clear client decision.
Assurance standards and control models
The operating model is supported by seven explicit standards. Together they define authority, evidence, independence, findings, decision conditions, closure and the strength of the resulting assurance opinion.
- Assurance Mandate – scope, authority, access and reporting route.
- Evidence Sufficiency Standard – the threshold evidence must meet before governance relies on it.
- Independence and Conflict Standard – separation from delivery ownership and declared conflicts.
- Finding Classification Model – consistent treatment of consequence, control weakness and required action.
- Decision Condition Framework – explicit conditions for proceed, hold, reset or reject decisions.
- Closure Verification Standard – evidence required before corrective action is accepted as complete.
- Confidence Rating Model – the strength and limitations of the available evidence.
The Enigma Evidence-to-Decision Assurance Model
1. Mandate
We define the decision to be supported, the scope of assurance, reporting route, access to evidence and the authority to escalate. An assurance function without access or a direct route to governance is decorative.
2. Baseline
We identify contractual obligations, delivery milestones, acceptance criteria, dependencies, controls and existing evidence. Claims are separated from facts and missing evidence is recorded rather than assumed.
3. Examine
We examine whether plans are credible, controls operate in practice and evidence supports the reported position. Findings are assessed according to impact, urgency and the decisions they affect.
4. Conclude
Reporting distinguishes confirmed position, residual risk, required action and decisions. Material exceptions cannot disappear into narrative status updates.
5. Verify
A recommendation is not closed because an action has been promised. Closure requires evidence that the control, deliverable or decision has been completed and is effective.

Evidence required
The evidence set is determined by the decision, delivery model and consequence of failure. It normally includes:
- approved outcomes, scope, obligations and acceptance criteria;
- integrated plans, milestones, dependencies and resource commitments;
- supplier deliverables, status evidence and recovery commitments;
- governance records, risks, issues, assumptions, decisions and exceptions;
- architecture decisions, interface definitions and non-functional evidence;
- test strategy, traceability, execution results, defects and exit evidence;
- migration controls, reconciliation and business validation;
- cutover rehearsal, operational readiness, rollback and early-life support evidence.
Evidence is assessed for relevance, completeness, currency, traceability, representativeness and independent corroboration. Missing or weak evidence is recorded as a limitation. It is not replaced by confidence, seniority or repeated assertion.
What we will not do
- Mark our own homework by combining delivery ownership with independent assurance.
- Repeat supplier status as though repetition creates confidence.
- Hide material exposure behind cautious language.
- Create governance bureaucracy without a defined decision or control purpose.
- Declare readiness where acceptance criteria or evidence have been weakened to preserve a date.
The result is a client-side assurance capability that is credible to delivery teams, useful to governance and independent enough to say what must be said.
Outputs
- executive assurance opinion and confidence rating;
- evidence-based findings linked to affected decisions;
- control-gap, accountability and dependency analysis;
- readiness assessment against explicit criteria;
- conditions, actions, owners and verification requirements;
- record of exceptions, limitations and accepted residual risk;
- recovery or remediation priorities where control has been lost;
- verified closure position for agreed findings.
Decision value
The output is designed to improve a real client decision. Governance should know what has been demonstrated, what remains uncertain, what conditions must be met and what consequence follows from proceeding. The conclusion may support progression, progression with conditions, a hold, a reset or rejection.
Where the primary concern is supplier performance, review Supplier Delivery Assurance. Where programme viability or recovery is in question, use Programme Health Checks and Recovery.
Engagement route
An initial discussion should define the decision that requires assurance, the consequence of error, the delivery ownership boundary, available evidence and the governance route for findings. Scope is then set around the minimum work required to produce a defensible position.
Discuss an independent assurance review, review the practical material in Resources, or use the direct downloads below.
Download the Independent Assurance Readiness Checklist or download the Sample Independent Assurance Report.