Skip to content

Independent Assurance, Internal QA and Supplier Governance

Internal QA, supplier governance and independent assurance perform different control functions. Treating them as interchangeable leaves the client exposed where evidence crosses organisational boundaries.

Supplier quality control, client governance, internal QA and independent assurance feeding a defensible client decision.

Key judgement

Good governance uses all three layers. Duplication occurs only when mandates, evidence tests, reporting lines and decision rights are unclear.

The operational problem

A supplier should test its own work and operate effective quality controls. The client should govern obligations, dependencies, decisions and risk. Internal QA may set standards, support delivery teams or monitor compliance. None of those activities automatically provides an independent opinion on whether supplier claims are safe for the client to rely on.

The existence of a QA lead, PMO or supplier test report is therefore not proof that assurance is covered. The control depends on what the function is authorised to examine, which source evidence it can access, where it reports and whether it owns the work being judged.

Three control layers

LayerCore questionTypical output
Supplier delivery qualityAre we building and managing the deliverable correctly?Plans, tests, defects, technical controls and corrective action.
Client governance and internal QAAre obligations, standards, risk and acceptance being controlled for the client?Governance challenge, standards, decisions and escalation.
Independent delivery assuranceCan the client rely on the material claims supporting this decision?Evidence-based opinion, confidence, findings, limitations and conditions.

Where arrangements commonly fail

  • Supplier test completion is treated as proof that the service is ready for the client’s operating context.
  • The PMO republishes workstream status without testing source evidence.
  • Internal QA designs the strategy and is later asked to independently assure its effectiveness.
  • Commercial governance confirms deliverable submission without testing outcome evidence.
  • Internal audit examines policy after the operational decision window has closed.

Responsibility and independence test

QuestionRisk if yesRequired control
Does the reviewer own the deliverable or corrective action?Self-review.Separate the assurance judgement from delivery ownership.
Does the reviewer report through the delivery line?Constrained escalation.Create direct reporting to accountable client governance.
Can the supplier select the evidence and interviewees?Filtered evidence.Authorise direct access and record restrictions.
Did the function design the control being examined?Cognitive and operational conflict.Use separate verification or disclose and safeguard the conflict.
Is the conclusion supporting a material client decision?Client accountability is exposed.Apply a formal mandate and evidence standard.

How the layers interact

1. Supplier produces evidence

2. Client governance challenges

3. Independent review tests

4. Board decides

5. Supplier remediates

Preventing unnecessary duplication

  • Start with the decision rather than requesting a standard document pack.
  • Reuse controlled programme records and test their reliability.
  • Map each assurance test to an existing governance or quality control.
  • Sample proportionately where the population is controlled.
  • Escalate findings that affect the decision or reveal a systemic control gap.
  • Return remedial action to the supplier or accountable client owner.
Clear separation between supplier delivery, independent assurance and client governance.

Application by client context

ContextAssurance focus
Central GovernmentEvidence for SRO and programme board decisions, multi-supplier dependency, major approvals and public accountability.
Local GovernmentCitizen service continuity, supplier challenge and proportionate scrutiny without creating a permanent council function.
SMEProtection of investment and operations where the technology supplier holds most technical knowledge and evidence.

The consequence for client governance

The supplier remains responsible for delivery and for producing the evidence behind its claims. The client retains accountability for approval, acceptance and residual risk. Independent assurance gives that client a defensible basis for deciding what to rely on, what to condition and when to intervene.

Related Enigma framework pages

Independence boundary

No practitioner independently assures delivery that they directly own. Delivery support, management action and independent verification must be separated and disclosed.