A programme board cannot govern delivery from reassurance or supplier confidence. It needs evidence that is current, attributable, sufficient for the decision, and independently challenged.
This checklist gives SROs, programme directors and boards a minimum evidence standard for material technology-delivery decisions. Enigma sits on the client’s side of the table. No supplier, workstream lead or delivery owner should independently assure work they directly own.

Use and rating
Apply the checklist to each material decision, not to the reporting pack in general. The evidence burden should reflect the consequence and reversibility of the decision. Record every item as sufficient, partially sufficient, insufficient or not applicable, with a reason. “In progress”, “not provided” and “the supplier is confident” are not evidence ratings.
1. Decision and authority
- The requested decision is stated in one sentence.
- The accountable decision owner, deadline and consequence of delay are clear.
- The decision falls within the board’s authority.
- Options include pause, rejection and further evidence.
- Irreversible commitments and conflicts of interest are explicit.
2. Scope, outcomes and acceptance
- The business outcome remains measurable.
- Scope, approved changes, deferrals and exclusions are traceable.
- Acceptance criteria are agreed by the client, not solely by the supplier.
- Requirements link to delivery, test and acceptance evidence.
- Policy, process, data, people and third-party dependencies are visible.
Informal scope movement damages governance and commercial control. Changes must remain within the approved decision boundary established through the Assurance Mandate.
3. Plan and critical path
- An integrated client, supplier and third-party plan exists.
- Milestones have objective entry and exit criteria.
- The critical path and dependencies are current.
- Forecast, contractual and target dates are distinguished.
- Variance is quantified and prior forecasts remain visible.
- Recovery actions have owners, dates and measurable effects.
- Contingency usage and resource assumptions are transparent.
4. Financial and commercial evidence
- Actual, committed and forecast cost reconcile to the approved budget.
- Contingency usage is attributable.
- Milestone payments are supported by acceptance evidence.
- Changes show cost, time, scope and risk effects.
- Claims, disputes, exclusions and assumptions are visible.
- The client retains contractual evidence and decision rights.
- The cost of delay or failure is stated where material.
5. Supplier delivery evidence
- Status is supported by artefacts, not presentation narrative.
- Deliverables trace to scope and acceptance criteria.
- Started, built, tested, accepted and operationally ready are not conflated.
- Subcontractor and product dependencies are included.
- Supplier risks reconcile with the client’s view.
- Forecast accuracy and optimism bias are visible.
- Missing evidence and exceptions are recorded.
The Evidence Sufficiency Standard defines the threshold reporting evidence must meet. Supplier reporting informs governance but cannot replace independent challenge.
6. Quality and test evidence
- The test strategy and plans define scope, ownership and acceptance.
- System testing is evidenced by the delivery party and client acceptance remains client-owned.
- Coverage maps to requirements, risks, interfaces and business processes.
- Defects show severity, age, trend, ownership, retest and residual risk.
- Exit criteria are measured and exceptions require named approval.
- Relevant performance, resilience, security, accessibility and operability testing is evidenced.
- Environments and test data are representative.
- No party independently assures testing it directly owns.
7. Data migration
- Data ownership and sources of truth are explicit.
- Mapping, transformation, cleansing and reconciliation rules are approved.
- Trial migrations demonstrate repeatability and duration.
- Control totals and record-level reconciliation prove completeness and accuracy.
- Rejected, duplicate, orphaned and transformed records are quantified.
- Protection, retention, access and audit controls are evidenced.
- Business owners accept material data-quality exceptions.
- Rollback and correction arrangements are workable.
8. Technical, security and operational readiness
- The architecture represents what is actually being delivered.
- Technical debt and exceptions are recorded.
- Security risks and vulnerabilities have treatment decisions and owners.
- Monitoring, support, escalation, backup and recovery are tested.
- Capacity, performance and resilience are evidenced.
- Operational teams accept their responsibilities.
- Knowledge transfer, licensing, hosting and third-party services are ready.
9. Cutover and business readiness
- Technical, data, business and supplier activity is integrated.
- Roles, command structure and communications are defined.
- Entry and rollback criteria are objective, with named authority.
- Continuity and manual workarounds are tested where required.
- Training, communications and support capacity are evidenced.
- Post-go-live verification, hypercare and triage are planned.
- Residual risks have authorised owners.

Board decision record
Minutes must preserve the basis, not merely the outcome. Record the decision, evidence and reporting dates, gaps and dissent, assurance opinion and independence status, approval conditions, residual risks and owners, actions and deadlines, and the point for reconsideration.
A board may knowingly accept uncertainty. It must not describe that as evidence-based confidence. The record must state what was not known, why the decision proceeded and who accepted the exposure.
Immediate red flags
- Reporting remains green while milestones move.
- Percent complete cannot reconcile to accepted deliverables.
- The supplier controls the evidence, interpretation and assurance conclusion.
- Exit criteria change after failure to meet them.
- Defects are reclassified to improve the reported position.
- Cutover is treated as inevitable.
- Missing evidence is called an administrative gap.
- Commercial pressure overrides readiness without an explicit risk decision.
Independent assurance position
Independent assurance is not another status report. It tests evidence sufficiency, omitted contrary indicators, confidence and protection of the client’s interests. Enigma’s multidisciplinary approach assesses delivery, quality, architecture, security, data and operational evidence as one connected system.
Practical output
Convert this checklist into a board evidence register. For each decision record the artefact, owner, reporting date, sufficiency rating, assurance comment, gap action and board disposition. Maintain it as a governance record, not a retrospective reconstruction.
For a client-side evidence review, use Enigma’s contact route. The starting point should be a defined decision, evidence request and independence boundary.