Skip to content

How We Assure

Independent assurance positioned between public-sector and SME clients and their technology delivery suppliers.

Assurance only has value when it is independent enough to challenge delivery and informed enough to understand it.

Enigma works for the client. Our responsibility is not to defend the programme narrative, protect a supplier relationship or preserve a date that the evidence no longer supports. Our responsibility is to give client leadership an accurate view of delivery confidence and the controls required to protect the outcome.

The problem

Leadership is often asked to approve funding, accept a phase, rely on a recovery plan or authorise go-live using information produced by the same delivery chain whose performance is being judged. The reporting may be extensive and professionally presented, but volume does not establish independence or evidential sufficiency.

The control gap

The missing control is a client-side function with the mandate, access and specialist capability to test material delivery claims before governance relies on them. It must remain separate from delivery ownership, report to the body that owns the decision and apply an explicit evidence standard.

  • Delivery suppliers remain responsible for delivery, control operation, remediation and supporting evidence.
  • Client governance remains responsible for outcomes, acceptance and risk decisions.
  • Enigma independently examines evidence, challenges the reported position and states residual exposure.
  • No practitioner provides independent assurance over work they directly own.

The core service proposition is explained in Independent Delivery Assurance.

The client-side assurance boundary

Delivery suppliers

Own delivery, controls, outputs, remediation and supporting evidence.

Enigma assurance

Tests the evidence, challenges the position and states residual exposure.

Client governance

Owns the outcome, accepts risk and makes the decision.

Supplier evidence → independent challenge → informed client decision

Independent assurance for public bodies and growing businesses

Central and local government

Public bodies need assurance that is independent of the delivery chain and capable of standing up to programme boards, audit, scrutiny and public accountability. Enigma tests supplier evidence, exposes unresolved dependencies and gives governance a clear record of readiness, exceptions, ownership and accepted risk.

  • Protect critical public services and operational continuity.
  • Strengthen multi-supplier governance and accountability.
  • Support defensible investment, acceptance and go-live decisions.
  • Create an auditable evidence trail without duplicating delivery.

SMEs without an internal assurance team

An SME buying a major system or transformation should not have to build a permanent QA department merely to challenge its supplier. Enigma provides proportionate, senior assurance at the points where supplier claims become commercial, operational or investment risk.

  • Avoid suppliers marking their own homework.
  • Gain independent challenge without permanent headcount.
  • Focus assurance on the decisions where failure would matter.
  • Protect cash, operations and management attention.

Our operating principles

Client-side independence

We remain organisationally and intellectually separate from the teams whose work we assure. We engage closely with suppliers, but our conclusions and reporting serve the client’s interests.

Evidence before confidence

Plans, status reports and professional confidence are inputs, not proof. We test material claims against agreed criteria, delivery artefacts, traceability, observed outcomes and accountable acceptance.

Risk stated without dilution

Where evidence is incomplete or a control has failed, we state it. Where a programme chooses to proceed, the exposure, mitigation, owner and approval must be explicit. Ambiguous language protects nobody.

Proportionate control

Assurance is not a demand for more documents, meetings or process. Controls must be proportionate to the consequence of failure. We remove low-value ceremony and concentrate on decisions, dependencies and evidence that materially affect the outcome.

Constructive challenge

Independent scrutiny is not supplier hostility. We establish clear expectations, give delivery teams the opportunity to produce evidence and distinguish recoverable gaps from fundamental failures. Challenge remains direct because delayed candour is expensive.

Accountability remains where it belongs

Enigma does not take ownership away from the client, programme or supplier. We make responsibilities visible, prevent gaps being transferred informally and ensure that acceptance of risk remains an explicit client decision.

Enigma uses a named assurance method that converts supplier evidence into an independent conclusion and a clear client decision.

Assurance standards and control models

The operating model is supported by seven explicit standards. Together they define authority, evidence, independence, findings, decision conditions, closure and the strength of the resulting assurance opinion.

The Enigma Evidence-to-Decision Assurance Model

1. Mandate

We define the decision to be supported, the scope of assurance, reporting route, access to evidence and the authority to escalate. An assurance function without access or a direct route to governance is decorative.

2. Baseline

We identify contractual obligations, delivery milestones, acceptance criteria, dependencies, controls and existing evidence. Claims are separated from facts and missing evidence is recorded rather than assumed.

3. Examine

We examine whether plans are credible, controls operate in practice and evidence supports the reported position. Findings are assessed according to impact, urgency and the decisions they affect.

4. Conclude

Reporting distinguishes confirmed position, residual risk, required action and decisions. Material exceptions cannot disappear into narrative status updates.

5. Verify

A recommendation is not closed because an action has been promised. Closure requires evidence that the control, deliverable or decision has been completed and is effective.

Independent assurance specialist examining supplier plans, delivery evidence and risks before the client makes a decision.

Evidence required

The evidence set is determined by the decision, delivery model and consequence of failure. It normally includes:

  • approved outcomes, scope, obligations and acceptance criteria;
  • integrated plans, milestones, dependencies and resource commitments;
  • supplier deliverables, status evidence and recovery commitments;
  • governance records, risks, issues, assumptions, decisions and exceptions;
  • architecture decisions, interface definitions and non-functional evidence;
  • test strategy, traceability, execution results, defects and exit evidence;
  • migration controls, reconciliation and business validation;
  • cutover rehearsal, operational readiness, rollback and early-life support evidence.

Evidence is assessed for relevance, completeness, currency, traceability, representativeness and independent corroboration. Missing or weak evidence is recorded as a limitation. It is not replaced by confidence, seniority or repeated assertion.

What we will not do

  • Mark our own homework by combining delivery ownership with independent assurance.
  • Repeat supplier status as though repetition creates confidence.
  • Hide material exposure behind cautious language.
  • Create governance bureaucracy without a defined decision or control purpose.
  • Declare readiness where acceptance criteria or evidence have been weakened to preserve a date.

The result is a client-side assurance capability that is credible to delivery teams, useful to governance and independent enough to say what must be said.

Outputs

  • executive assurance opinion and confidence rating;
  • evidence-based findings linked to affected decisions;
  • control-gap, accountability and dependency analysis;
  • readiness assessment against explicit criteria;
  • conditions, actions, owners and verification requirements;
  • record of exceptions, limitations and accepted residual risk;
  • recovery or remediation priorities where control has been lost;
  • verified closure position for agreed findings.

Decision value

The output is designed to improve a real client decision. Governance should know what has been demonstrated, what remains uncertain, what conditions must be met and what consequence follows from proceeding. The conclusion may support progression, progression with conditions, a hold, a reset or rejection.

Where the primary concern is supplier performance, review Supplier Delivery Assurance. Where programme viability or recovery is in question, use Programme Health Checks and Recovery.

Engagement route

An initial discussion should define the decision that requires assurance, the consequence of error, the delivery ownership boundary, available evidence and the governance route for findings. Scope is then set around the minimum work required to produce a defensible position.

Discuss an independent assurance review, review the practical material in Resources, or use the direct downloads below.

Download the Independent Assurance Readiness Checklist or download the Sample Independent Assurance Report.