An independent assurance review does not examine everything equally. It tests the evidence and controls that matter to a defined client decision, following material risks across supplier and workstream boundaries.

Key judgement
The review must be broad enough to expose connected failure, but disciplined enough to avoid becoming a parallel programme office.
Start with the decision
The review defines what the client is being asked to decide and which delivery claims must be true for that decision to be defensible. This prevents a large document request from replacing analysis.
A go-live decision may connect plan confidence, business-process testing, migration reconciliation, cutover rehearsal, operational readiness and residual defects. Examining any one area in isolation can miss the way exposure transfers between them.
Seven examination domains
| Domain | Claims examined | Evidence examples |
|---|---|---|
| Governance | Decision rights, risk ownership and escalation operate. | Mandate, decisions, tolerances, minutes and escalation records. |
| Plan and viability | Milestones are achievable and dependencies controlled. | Logic-linked schedule, critical path, capacity, actuals and forecasts. |
| Supplier delivery | Obligations are evidenced and acceptance is controlled. | Deliverables, obligation traceability, exceptions and acceptance criteria. |
| Quality and testing | Material business and technical risk has been tested. | Coverage, execution, defects, environments, data and acceptance. |
| Architecture | Implemented behaviour meets technical and operational obligations. | Decisions, requirements, integration, performance, resilience and security evidence. |
| Migration and cutover | Data and transition can be executed and reconciled. | Mappings, exceptions, rehearsals, runbook, timings and contingency. |
| Operations | People, process, service and technology can operate together. | Support, monitoring, service scenarios, continuity and operational acceptance. |
Evidence examination flow
1. Claim
2. Criteria
3. Source evidence
4. Contradiction test
5. Consequence
Trace the claim
A dashboard is treated as a summary, not as the end of the trail. The reviewer identifies the owner, source, date and records supporting the material claim.
Test the criteria
Evidence is compared with the relevant obligation, acceptance criterion, control or condition. Missing or late-changing criteria are examined as governance weaknesses.
Seek contradictions
Connected records are compared. A forecast may conflict with dependency dates. A pass rate may conflict with limited coverage. A completed rehearsal may conflict with unresolved timing failures.
Assess consequence
The reviewer decides whether the weakness changes confidence, creates a decision condition or remains a management improvement. This is what turns evidence review into an assurance opinion.
Review methods
- Structured interviews across client, supplier and operational owners.
- Direct examination of controlled artefacts and source records.
- Traceability sampling across requirements, delivery, testing and acceptance.
- Walkthroughs of critical business, migration, cutover and service scenarios.
- Trend and exception analysis.
- Testing whether controls have operated and produced results.
- Triangulation where parties interpret the position differently.
Scope limits
The opinion is bounded by mandate, evidence cut-off and access. It does not imply that every record was tested or that excluded areas are satisfactory. Any restriction capable of changing the decision must be explicit.

Application by client context
| Context | Assurance focus |
|---|---|
| Central Government | Evidence for SRO and programme board decisions, multi-supplier dependency, major approvals and public accountability. |
| Local Government | Citizen service continuity, supplier challenge and proportionate scrutiny without creating a permanent council function. |
| SME | Protection of investment and operations where the technology supplier holds most technical knowledge and evidence. |
The consequence for client governance
The supplier remains responsible for delivery and for producing the evidence behind its claims. The client retains accountability for approval, acceptance and residual risk. Independent assurance gives that client a defensible basis for deciding what to rely on, what to condition and when to intervene.
Related Enigma framework pages
Independence boundary
No practitioner independently assures delivery that they directly own. Delivery support, management action and independent verification must be separated and disclosed.