
If the organisation delivering the work is also the organisation telling the board that delivery is safe, the client does not have independent assurance. It has supplier self-assessment.
That does not mean the supplier is dishonest. It means the governance structure is asking one party to perform two roles that cannot be fully reconciled: achieve the delivery commitment and independently judge whether its own work, controls and evidence are sufficient.
The conflict becomes most dangerous when delivery is under pressure. Dates harden, sunk cost increases and senior attention focuses on recovery. Evidence thresholds begin to move. Exceptions become temporary, then normal. Work that should have been completed in system testing is transferred into user acceptance testing. Migration defects are reframed as operational workarounds. A red position is converted to amber because a plan exists, even though the plan has not yet produced a result.
Reporting is not assurance
Programme reporting describes what the delivery organisation believes has happened and what it expects to happen next. Assurance tests whether the reported position is supported by sufficient evidence, whether the controls are operating and whether the residual risk is understood by the people accepting it.
The distinction is material.
| Delivery reporting | Independent assurance |
|---|---|
| Reports milestone status | Tests whether the milestone criteria have actually been met |
| Describes completed activity | Examines whether the activity produced adequate evidence and outcomes |
| Owns the recovery plan | Assesses whether the recovery plan is credible and working |
| Proposes risk acceptance | States the exposure, control gap and consequence of acceptance |
| Optimises for delivery | Optimises for an informed client decision |
A programme can have detailed reporting, multiple governance forums and a large quality team while still lacking independent assurance. Volume of oversight does not solve structural dependence.
Public bodies and SMEs face the same structural problem
For central and local government, the assurance gap threatens public accountability, service continuity and the ability of programme boards to defend major acceptance decisions. Delivery may span several suppliers, contractual boundaries and internal teams, while the client retains responsibility for the public outcome.
For an SME, the same gap is smaller in scale but often more concentrated in consequence. A failed ERP, CRM, e-commerce or cloud transformation can consume cash, interrupt operations and absorb the attention of the entire leadership team. Yet the business may have no independent test, quality or programme-assurance function at all.
Public bodies need assurance that can withstand scrutiny. SMEs need assurance they can obtain without building a department. Neither should depend on a supplier marking its own homework.
The conflict is usually structural, not personal
Most suppliers want to deliver well. Most programme teams believe the position they report. The problem is that incentives and reporting lines influence what is challenged, how strongly it is stated and when it reaches the client.
A test lead employed by the supplier may be highly capable, but remains part of the organisation accountable for the date. A client quality lead reporting to the programme director may be expected to challenge a plan that the same director has committed to governance. A systems integrator may provide extensive test evidence, but it still defines much of the process used to demonstrate its own compliance.
None of these arrangements is inherently improper. None is independent.
Where the assurance gap becomes visible
Entry and exit criteria move
Criteria intended to protect the next phase are reinterpreted once they threaten the schedule. Open defects are accepted without a complete impact assessment. Evidence that was mandatory during planning becomes desirable during execution.
Activity substitutes for outcome
The programme reports test cases executed, defects closed or records migrated. Those numbers may be correct and still prove little. They do not establish that critical business processes work end to end, that closure was valid or that migrated data is complete, accurate and usable.
Risks lose their consequence
Risks are written as process statements rather than decisions. “Continue to monitor” replaces a defined trigger. “Business to accept” appears without a named owner, explicit exposure or confirmation that the person accepting the risk has the authority to do so.
UAT becomes the final safety net
User acceptance testing is expected to compensate for incomplete supplier testing, unstable environments, unresolved integration defects and poor data. This is not UAT. It is late system testing performed by business users under schedule pressure.
Readiness becomes a negotiation
A go/no-go decision should test evidence against agreed tolerances. In weak governance, it becomes a negotiation between the cost of delay and confidence that unresolved issues will somehow remain manageable in production.
What independent assurance must do
Independence is not achieved by adding an observer or commissioning a review with a predetermined conclusion. A credible assurance function needs five things.
- A client mandate. The assurance role must serve the client’s decision-makers, not the supplier or delivery hierarchy.
- Access to evidence. Assurance cannot operate through curated presentations alone. It needs access to plans, controls, traceability, defects, test evidence, migration results, decisions and accountable owners.
- Explicit criteria. Findings must be tested against contractual obligations, agreed controls, acceptance criteria and the consequence of failure.
- A direct reporting route. Material findings must reach governance without being softened by the function whose performance is being assessed.
- Closure based on proof. A promise, plan or revised date does not close a finding. Closure requires evidence that the problem has been resolved and the control is effective.
Independent does not mean adversarial
Poor assurance behaves like an audit ambush: detached from delivery, late to engage and more interested in recording failure than preventing it. That produces defensive suppliers and little practical value.
Good assurance works closely enough to understand the delivery mechanics, tests claims fairly and makes expectations clear. It distinguishes between a recoverable evidence gap, an ineffective control and a fundamental threat to the outcome. It challenges the supplier without taking over the supplier’s role.
The relationship should be constructive. The conclusion must remain independent.
The client cannot outsource accountability
A client may outsource design, build, testing, migration and service transition. It cannot outsource the consequence of accepting a system that is not ready. Operational disruption, public scrutiny, regulatory exposure, financial loss and damage to services remain with the client.
That is why independent delivery assurance is not another supplier layer. It is a client control. It gives leadership an evidence-based view of delivery confidence and makes explicit the risk being accepted when the evidence is incomplete.
The supplier owns delivery. The client owns acceptance. Independent assurance protects the decision between them.
A practical test for governance
Ask four questions before the next major decision:
- Who produced the evidence supporting readiness?
- Who independently tested whether that evidence was sufficient?
- Can material findings reach client governance without supplier or delivery approval?
- Is every accepted exception explicit about consequence, mitigation, owner and authority?
If the answers collapse back to the same delivery organisation, the assurance gap is real. It may not have caused a failure yet. That is not evidence that the structure is safe.
Enigma sits on the client’s side of the table. We provide independent delivery, quality, supplier, migration and cutover assurance for central and local government, and a fractional assurance capability for SMEs that do not maintain their own internal team.
Where the answers expose a structural conflict, use Enigma’s contact route to define the decision, evidence boundary and required assurance mandate before delivery pressure narrows the available options.
Download the Supplier Self-Assessment Executive Briefing.

