
Organisations should not need a permanent assurance function to govern important technology delivery properly. Fractional assurance leadership gives the client a senior, independent capability at the points where evidence, challenge and decisions matter.
Enigma sits on the client’s side of the table. We help public-sector bodies, local authorities and SMEs that need stronger delivery assurance but do not have sufficient internal capacity, specialist coverage or a continuing requirement for a full-time assurance leader.
The problem: assurance responsibility exists even when the capability does not
An SRO, programme board or business owner remains accountable for delivery decisions regardless of the organisation’s size. Yet many organisations rely on supplier reporting, project management controls or occasional expert reviews because they cannot justify a permanent multidisciplinary assurance team.
The result can be a gap between governance and evidence. Boards meet, reports are produced and actions are tracked, but nobody on the client side consistently defines what evidence is required, tests whether it is sufficient, connects specialist concerns and follows findings through to closure.
The control gap
Programme and delivery management are responsible for getting work done. Contract management governs obligations and commercial remedies. Internal audit usually works to a broader organisational plan. None of these functions automatically provides continuing, decision-specific technology delivery assurance.
Buying isolated specialists does not close the gap either. A test expert, programme manager or architect can provide valuable advice, but separate assignments can create fragmented conclusions and unclear accountability. Fractional assurance leadership integrates the relevant disciplines into one client-side view.
When fractional assurance leadership fits
- The organisation has important supplier-led delivery but no internal assurance function.
- An SRO or board needs continuing challenge between formal review points.
- Several specialist concerns need to be combined into one decision view.
- Internal capacity is temporary, overstretched or focused on delivery ownership.
- A programme is entering procurement, mobilisation, recovery, migration or cutover.
- The client wants a repeatable assurance framework without building a permanent team.
- Senior assurance input is needed periodically rather than five days a week.

How the Enigma model works
The service applies the evidence-to-decision model described in How We Assure. It is not an open-ended consultancy retainer. The mandate, decisions, reporting line, cadence, access and independence constraints are agreed at the outset.
- Set the Assurance Mandate. We define who assurance serves, which decisions are in scope and where delivery ownership sits.
- Build the assurance plan. We map critical decisions, evidence needs, suppliers, dependencies and review points.
- Establish evidence standards. We define the minimum evidence expected before status, acceptance or readiness claims can be relied upon.
- Coordinate multidisciplinary review. We bring together programme, quality, agile, architecture, migration and cutover perspectives as required.
- Report to the client. We provide concise conclusions, confidence, conditions and unresolved exposure directly to the agreed client authority.
- Verify closure and adapt. We track whether findings are closed with evidence and adjust the assurance plan as delivery changes.
The independence boundary
Fractional leadership must not become disguised delivery ownership. Enigma can define assurance requirements, challenge plans, evaluate evidence, advise governance and verify closure. If Enigma is asked to manage a delivery workstream, produce the evidence or execute the control being assessed, that work is removed from our independent assurance scope.
Where support and assurance both exist, they require explicit separation through scope, personnel, reporting and decision rights. The client receives a clear record of any conflict and how it is controlled. Nobody assures delivery they directly own.
Evidence required
The continuing evidence set commonly includes programme and supplier plans, governance packs, decisions, RAID records, delivery metrics, contractual milestones, quality and test evidence, architecture decisions, financial forecasts, migration and cutover readiness, operational acceptance and closure evidence from previous findings.
Evidence requests are proportionate to the next decision. The objective is not to create a parallel reporting bureaucracy. It is to make sure claims can be traced, challenged and converted into action before exposure becomes irreversible.
What the client receives
- A documented Assurance Mandate, plan and reporting route.
- A decision calendar showing when assurance input is required.
- Proportionate evidence requests aligned to material risks and milestones.
- Independent conclusions and confidence ratings for governance.
- Conditions, actions, owners and required closure evidence.
- Coordinated access to the six assurance disciplines where the decision requires it.
- A continuing record of findings, decisions, accepted risk and closure.
Focused reviews can be commissioned through Independent Delivery Assurance, Supplier Delivery Assurance or Programme Health Checks and Recovery. Practical checklists and sample outputs are available in Resources.
For organisations without an internal assurance function, download the Fractional SME Assurance Brief and the Independent Assurance Readiness Checklist.
Decision value
Fractional assurance gives accountable leaders continuity without creating unnecessary permanent overhead. The board gains a consistent client-side evidence standard, earlier visibility of weak claims and an integrated view of delivery exposure. Suppliers receive clearer expectations, while the client retains ownership of decisions and accepted risk.
Commission fractional assurance leadership
The initial discussion establishes the delivery portfolio, governance structure, upcoming decisions, internal capability, supplier landscape and conflicts. We then define a proportionate mandate and cadence that can expand or reduce as the risk profile changes.
Discuss fractional assurance leadership or review the full range of Advisory Services.