Skip to content

Is Your Testing Producing Evidence or Merely Activity?

    Decision-specific assurance insight

    Testing activity does not prove that a programme is safe to accept, deploy or operate.

    Boards are often shown test counts, execution percentages and defect totals. Those measures describe activity. They do not establish whether the material risks to services, users, data, security and operations have been reduced to an acceptable level.

    The decision is not whether enough tests have run. It is whether the available quality evidence is sufficient to support the next commitment.

    Quality assurance must answer a decision

    A credible quality conclusion begins with the decision facing the client: enter system integration testing, begin user acceptance testing, approve migration rehearsal, authorise cutover or accept the service into operation. Each decision requires a defined evidence threshold and an explicit statement of residual risk.

    • Proceed: The critical risks are covered and the evidence meets the agreed threshold.
    • Proceed with conditions: Specific gaps remain, but named controls, owners and dates contain the exposure.
    • Hold: Evidence is incomplete, contradictory or too weak to justify the next commitment.
    • Reject: The solution or delivery position is outside agreed tolerances and cannot safely progress without material correction.
    Six-stage quality evidence model connecting test basis, traceability, risk coverage, execution integrity and defect exposure to an acceptance decision.

    Six tests for decision-grade quality evidence

    Enigma applies six linked tests to determine whether quality reporting supports a decision:

    1. Risk alignment: Test objectives and priorities trace to material business, service, technical, security, data and operational risks.
    2. Coverage sufficiency: Requirements, processes, integrations, roles, controls, non-functional characteristics and failure paths have appropriate coverage.
    3. Environment and data validity: Test environments, interfaces, configurations and data are representative enough for the conclusion being drawn.
    4. Result integrity: Outcomes are repeatable, evidenced and traceable. Pass status is not based on informal confirmation or unsupported supplier assertion.
    5. Defect exposure: Open defects, workarounds, retest results, regression impact and accepted residual risks are visible in business terms.
    6. Independence and confidence: The conclusion is formed by people who did not directly own the delivery being assured, with confidence calibrated to the strength and completeness of the evidence.

    These tests operate together. Strong execution numbers cannot compensate for unrealistic data. Good functional coverage cannot compensate for absent performance or resilience evidence. Closed defects do not prove readiness if closure was not independently verified.

    Six large evidence tests covering risk alignment, coverage, environments, result integrity, defect exposure and independent confidence.

    Activity measures that boards should challenge

    • A high percentage of tests passed without showing which critical risks remain untested.
    • A falling defect count without explaining severity, age, recurrence or business impact.
    • Requirements coverage that excludes end-to-end processes, integrations or non-functional risks.
    • User acceptance testing treated as a substitute for incomplete supplier system testing.
    • Tests marked blocked or not applicable to protect a completion percentage.
    • Defects closed on supplier assertion without retest evidence.
    • Regression testing reduced to recover schedule without a quantified exposure statement.
    • Known workarounds accepted without operational ownership, rehearsal or support impact.

    These weaknesses must be visible in disciplined Confidence Rating Model. Concealing them behind aggregated status creates false confidence and transfers unmanaged risk to the client.

    What independent quality assurance changes

    The supplier should produce and explain its test evidence. Delivery leadership should manage the plan and resolve constraints. Business representatives should validate that the service supports real operating needs. None of those responsibilities removes the need for an independent client-side conclusion.

    Enigma sits on the client’s side of the table. We combine Head of Test leadership, senior quality engineering, programme direction, programme management, agile delivery challenge and technical architecture with migration and cutover assurance. This is one multidisciplinary assurance capability, not a catalogue of contractors.

    The control is absolute: nobody should assure delivery they directly own. Our client-side approach separates delivery accountability from independent examination, confidence assessment and advice to the decision-maker.

    The minimum evidence a board should receive

    • the decision being requested and the applicable acceptance threshold;
    • the material risks that testing was intended to address;
    • coverage achieved and important exclusions;
    • environment, configuration and test-data limitations;
    • results supported by traceable execution evidence;
    • open defects, workarounds and residual operational exposure;
    • evidence gaps, contradictions and assumptions;
    • the independent confidence rating and its basis;
    • the recommended decision and any conditions, owners and dates;
    • the accountable authority accepting any residual risk.

    A practical resource for the decision

    Use a Quality Evidence Sufficiency Checklist before each major test or release gate. It should force the programme to connect risks, coverage, results, defects and evidence limitations to the actual decision required from the board.

    The board-level conclusion

    A programme is not ready because a test phase has ended or a pass percentage is high. It is ready only when the evidence is sufficiently complete, credible and relevant to justify the next commitment.

    Where the evidence cannot support that conclusion, the correct response is not optimistic reporting. It is a controlled decision to close the gap, impose conditions, hold progression or reject acceptance.


    To discuss the decision and available evidence, use Enigma’s contact page.