Skip to content

Independent Delivery Assurance

Independent assurance positioned between public-sector and SME clients and their technology delivery suppliers.

Independent delivery assurance gives leadership a reliable view of whether a technology programme is controlled, evidenced and capable of achieving its intended outcome.

It is designed for central and local government bodies that require independent oversight of complex supplier delivery, and for SMEs that need senior assurance without establishing a permanent internal function. Enigma provides the missing client-side capability: proportionate, evidence-led scrutiny that is independent of the organisations being assessed.

The problem

Outsourcing delivery does not outsource accountability. The client still owns the business outcome, operational consequence and acceptance decision. Yet many organisations retain too little internal capability to test whether supplier reporting is complete, whether quality controls are working or whether a programme is genuinely ready to proceed.

The predictable result is an assurance gap:

  • suppliers define the evidence used to judge their own delivery;
  • programme reporting prioritises milestone status over outcome confidence;
  • quality concerns are escalated through the same structure that owns the delivery date;
  • critical gaps are pushed into user acceptance testing, migration or cutover;
  • client governance is asked to accept risk without a complete statement of exposure.

Independent assurance for public bodies and growing businesses

Central and local government

Public bodies need assurance that is independent of the delivery chain and capable of standing up to programme boards, audit, scrutiny and public accountability. Enigma tests supplier evidence, exposes unresolved dependencies and gives governance a clear record of readiness, exceptions, ownership and accepted risk.

  • Protect critical public services and operational continuity.
  • Strengthen multi-supplier governance and accountability.
  • Support defensible investment, acceptance and go-live decisions.
  • Create an auditable evidence trail without duplicating delivery.

SMEs without an internal assurance team

An SME buying a major system or transformation should not have to build a permanent QA department merely to challenge its supplier. Enigma provides proportionate, senior assurance at the points where supplier claims become commercial, operational or investment risk.

  • Avoid suppliers marking their own homework.
  • Gain independent challenge without permanent headcount.
  • Focus assurance on the decisions where failure would matter.
  • Protect cash, operations and management attention.

The client-side assurance boundary

Delivery suppliers

Own delivery, controls, outputs, remediation and supporting evidence.

Enigma assurance

Tests the evidence, challenges the position and states residual exposure.

Client governance

Owns the outcome, accepts risk and makes the decision.

Supplier evidence → independent challenge → informed client decision

The Enigma role

Enigma sits between client governance and the delivery ecosystem. We do not replace the programme team or duplicate supplier management. We independently assess whether the controls, evidence and reported position justify the decisions being requested of the client.

We assure the delivery on behalf of the client; we do not become another part of the supplier delivery chain.

The control gap

Programme governance often receives more reporting than evidence. Delivery suppliers report against plans they maintain, using completion measures they define and exceptions they interpret. Internal teams may understand parts of the position but lack the authority, capacity or independence to form one defensible view across the whole programme.

The gap is not solved by adding another status meeting. It requires a separate client-side mandate, explicit evidence standards and a reporting route to the body that owns the decision. No person should assure delivery they directly own.

The Enigma method

Enigma establishes the decision to be supported, the evidence required and the independence boundary before examining delivery. The work is proportionate to the consequence of the decision and draws on programme direction, programme management, quality assurance, test leadership, agile delivery and technical architecture as one multidisciplinary capability.

  • Frame the decision: define what governance is being asked to approve, accept or fund.
  • Set the evidence threshold: state what must be demonstrated and what cannot be accepted as assertion.
  • Test the position: sample records, challenge owners and reconcile evidence across workstreams and suppliers.
  • Rate confidence: distinguish demonstrated fact, conditional confidence, material uncertainty and unsupported claim.
  • State the consequence: explain what proceeding, pausing or imposing conditions means for the client.
  • Verify closure: close findings only when corrective evidence has been examined.

The full operating model is set out in How We Assure. Supplier-specific scrutiny is explained under Supplier Delivery Assurance.

Independent assurance guidance

Use these decision-focused guides to understand when assurance is required, what it should examine and how to commission it with a clear mandate.

Independent assurance specialist examining supplier plans, delivery evidence and risks before the client makes a decision.

Evidence required

The exact evidence set depends on the decision and delivery model. It commonly includes:

  • approved outcomes, scope, obligations and acceptance criteria;
  • integrated plans, dependencies, decision points and resource commitments;
  • supplier deliverables, status evidence and recovery commitments;
  • architecture decisions, interface definitions and non-functional evidence;
  • test strategy, traceability, execution records, defects and exit evidence;
  • migration controls, reconciliation, business validation and trial results;
  • cutover rehearsals, operational readiness, rollback and early-life support evidence;
  • risk, issue, assumption, decision and exception records with accountable ownership.

Evidence that is incomplete, out of date, untraceable or produced solely for the review is treated as a limitation. Assurance does not convert missing evidence into confidence.

Scope of assurance

Delivery governance

  • programme controls, reporting and decision rights;
  • milestone credibility and dependency management;
  • risk, issue, assumption and decision governance;
  • ownership, escalation and closure discipline.

Quality engineering and testing

  • test strategy, plans, coverage and traceability;
  • supplier system testing and evidence;
  • system integration and end-to-end testing;
  • user acceptance readiness and business ownership;
  • non-functional testing and operational quality;
  • defect governance, severity, priority and acceptance.

Data migration and cutover

  • migration scope, transformation and reconciliation controls;
  • trial migration and rehearsal evidence;
  • business validation and data acceptance;
  • cutover planning, command structure and decision criteria;
  • rollback, continuity and early-life support readiness.

Supplier performance

  • delivery evidence against obligations and acceptance criteria;
  • quality of estimates, plans and recovery commitments;
  • completeness and accuracy of status reporting;
  • cross-supplier boundaries, gaps and disputed responsibilities.

Engagement models

Independent health check

A focused assessment of delivery confidence at programme, workstream or critical-phase level. It establishes the evidenced position, material gaps and immediate decisions.

Continuous client-side assurance

An embedded but independent assurance capability operating across the delivery lifecycle, reporting directly to client governance and tracking findings through verified closure.

Critical decision assurance

Targeted scrutiny before contract acceptance, phase entry or exit, production cutover, service transition or another high-consequence decision.

Recovery assurance

An objective assessment of a programme in difficulty, followed by a controlled recovery baseline, explicit accountabilities and independent verification of progress.

Typical outputs

  • executive assurance opinion and delivery confidence rating;
  • evidence-based findings with impact and required action;
  • control-gap and accountability analysis;
  • readiness assessment against explicit criteria;
  • governance and reporting improvements;
  • risk acceptance and exception record;
  • prioritised recovery or remediation plan;
  • verification that agreed findings have been closed effectively.

Decision value

Independent assurance gives the SRO, programme board or business owner a position they can act upon and defend. It identifies which claims are supported, which conditions must be met, who owns unresolved exposure and what consequence follows from proceeding.

Where the programme is unstable, Programme Health Checks and Recovery tests continued viability and recovery realism. Where risk concentrates in testing or transition, Quality and Test Assurance and Data Migration and Cutover Assurance provide the required specialist depth.

What good looks like

Independent assurance should reduce uncertainty, not merely produce observations. Leadership should know which claims are evidenced, which risks remain, who owns each action, what decisions are required and what consequence follows if the programme proceeds without resolution.

The test is simple: governance should be better able to make and defend its decision after assurance than before it.

Discuss an independent assurance review. Initial scoping should identify the decision, delivery context, independence requirements and evidence likely to be available.

Review supporting material in Resources or download the Independent Delivery Assurance service sheet.