Internal QA, supplier governance and independent assurance perform different control functions. Treating them as interchangeable leaves the client exposed where evidence crosses organisational boundaries.

Key judgement
Good governance uses all three layers. Duplication occurs only when mandates, evidence tests, reporting lines and decision rights are unclear.
The operational problem
A supplier should test its own work and operate effective quality controls. The client should govern obligations, dependencies, decisions and risk. Internal QA may set standards, support delivery teams or monitor compliance. None of those activities automatically provides an independent opinion on whether supplier claims are safe for the client to rely on.
The existence of a QA lead, PMO or supplier test report is therefore not proof that assurance is covered. The control depends on what the function is authorised to examine, which source evidence it can access, where it reports and whether it owns the work being judged.
Three control layers
| Layer | Core question | Typical output |
|---|---|---|
| Supplier delivery quality | Are we building and managing the deliverable correctly? | Plans, tests, defects, technical controls and corrective action. |
| Client governance and internal QA | Are obligations, standards, risk and acceptance being controlled for the client? | Governance challenge, standards, decisions and escalation. |
| Independent delivery assurance | Can the client rely on the material claims supporting this decision? | Evidence-based opinion, confidence, findings, limitations and conditions. |
Where arrangements commonly fail
- Supplier test completion is treated as proof that the service is ready for the client’s operating context.
- The PMO republishes workstream status without testing source evidence.
- Internal QA designs the strategy and is later asked to independently assure its effectiveness.
- Commercial governance confirms deliverable submission without testing outcome evidence.
- Internal audit examines policy after the operational decision window has closed.
Responsibility and independence test
| Question | Risk if yes | Required control |
|---|---|---|
| Does the reviewer own the deliverable or corrective action? | Self-review. | Separate the assurance judgement from delivery ownership. |
| Does the reviewer report through the delivery line? | Constrained escalation. | Create direct reporting to accountable client governance. |
| Can the supplier select the evidence and interviewees? | Filtered evidence. | Authorise direct access and record restrictions. |
| Did the function design the control being examined? | Cognitive and operational conflict. | Use separate verification or disclose and safeguard the conflict. |
| Is the conclusion supporting a material client decision? | Client accountability is exposed. | Apply a formal mandate and evidence standard. |
How the layers interact
1. Supplier produces evidence
2. Client governance challenges
3. Independent review tests
4. Board decides
5. Supplier remediates
Preventing unnecessary duplication
- Start with the decision rather than requesting a standard document pack.
- Reuse controlled programme records and test their reliability.
- Map each assurance test to an existing governance or quality control.
- Sample proportionately where the population is controlled.
- Escalate findings that affect the decision or reveal a systemic control gap.
- Return remedial action to the supplier or accountable client owner.

Application by client context
| Context | Assurance focus |
|---|---|
| Central Government | Evidence for SRO and programme board decisions, multi-supplier dependency, major approvals and public accountability. |
| Local Government | Citizen service continuity, supplier challenge and proportionate scrutiny without creating a permanent council function. |
| SME | Protection of investment and operations where the technology supplier holds most technical knowledge and evidence. |
The consequence for client governance
The supplier remains responsible for delivery and for producing the evidence behind its claims. The client retains accountability for approval, acceptance and residual risk. Independent assurance gives that client a defensible basis for deciding what to rely on, what to condition and when to intervene.
Related Enigma framework pages
Independence boundary
No practitioner independently assures delivery that they directly own. Delivery support, management action and independent verification must be separated and disclosed.