Confidence in delivery requires both capable management and credible challenge; one cannot substitute for the other.
When a troubled program reaches the executive committee, leaders often respond by asking for more assurance. Additional reviews are commissioned, dashboards expand and specialists are added. Yet the underlying problem may remain because the organisation has not distinguished three different responsibilities: controlling work, assuring the processes used to control it and independently assessing whether the investment remains credible.
The terms sound similar, but their purposes are not. Blurring them creates duplicated oversight in some areas and dangerous gaps in others.
The Strategic Context
Senior leaders need confidence that an investment is being governed effectively, that deliverables will be fit for purpose and that reported information is reliable. They cannot acquire this confidence simply by receiving more data from the delivery team.
Every delivery system has inherent conflicts. Project managers are accountable for progress and naturally seek to resolve issues without unnecessary escalation. Suppliers are motivated to demonstrate contractual performance. Sponsors want the business case protected. Operational leaders may prioritise service continuity over project milestones. None of these perspectives is illegitimate, but each is partial.
Assurance exists because decision-makers need a sufficiently independent view of whether plans, controls and evidence can be trusted. Its value depends less on the volume of review than on clarity of purpose, competence, access and authority.
What Leaders Commonly Misread
The first error is treating quality control, quality assurance and project assurance as interchangeable.
Quality control examines outputs. It uses inspection, testing and measurement to determine whether deliverables meet defined criteria.
Quality assurance examines the processes intended to produce those outputs. It asks whether methods, responsibilities and controls are suitable and are being followed.
Project or program assurance takes a wider investment view. It may examine whether the business case remains valid, risks are understood, governance is effective, stakeholders are aligned and the delivery system is capable of achieving the intended outcome.
The second error is assuming independence means distance from operational knowledge. An assessor who is structurally independent but lacks technical or contextual competence may produce formal findings with little decision value.
The third is using assurance to compensate for weak management. Reviewers can identify deficiencies and recommend action. They should not quietly become a parallel delivery team, because that obscures accountability.
Reframing the Issue
Assurance should be designed as an information and challenge system serving defined decision-makers.
The core question is not, "Have we completed an assurance review?" It is, "What uncertainty does the governing body need reduced before making its next commitment?"
That uncertainty may relate to technical feasibility, commercial exposure, schedule realism, operational readiness or benefits. Different questions require different expertise and evidence. A generic checklist is unlikely to provide equal confidence across all of them.
Assurance should also be timed around reversibility. Independent challenge has greater value before a major contract, design freeze, migration, commissioning event or operational handover than after the commitment becomes difficult to reverse.
The Three Lines of Delivery Confidence
A practical delivery model separates responsibilities without isolating them.
The first line is management control. Delivery leaders plan work, manage risks, inspect outputs, correct defects and report performance. They own the result.
The second line provides specialist oversight and quality assurance. It establishes methods, verifies compliance, tests control effectiveness and supports consistent practice. It should remain sufficiently separate from the work being assessed.
The third line provides independent confidence to the sponsor, executive or governing body. Its scope can include strategic alignment, business-case viability, governance, risk concentration and readiness for irreversible decisions.
The exact organisational arrangement will vary. Smaller organisations may not sustain dedicated teams, but the functions still need to exist. A competent peer from another business unit, an external specialist or a temporary review panel can provide independence when roles and conflicts are explicit.
Independence Is a Design Choice
Independence is not binary. It has several dimensions:
- Structural independence: the reviewer does not report to the person whose work is being assessed.
- Financial independence: the reviewer is not rewarded for achieving the delivery outcome under review.
- Cognitive independence: the review includes perspectives not shaped by the same assumptions.
- Evidentiary independence: conclusions are tested against source data rather than management summaries alone.
- Access independence: reviewers can reach relevant people, records and sites without undue restriction.
A review may be formally independent yet cognitively captured if every participant shares the same baseline assumptions. Conversely, an internal expert may provide valuable challenge if conflicts are visible and the governing body retains decision authority.
Related article: Project Audits Should Strengthen Learning, Not Police Delivery
Assurance Must Follow Risk
Uniform assurance wastes capacity. Review intensity should follow consequence, novelty, complexity and reversibility.
A familiar, low-value and reversible initiative may need lightweight peer review. A major technology migration, defence capability, clinical system or capital investment may require staged technical, commercial, safety and operational assurance.
Programs create another challenge. A component project can appear healthy while shared dependencies, transition states or benefits remain exposed. Program assurance must therefore look across projects and test whether separate outputs will combine into the intended capability.
Portfolio leaders should also examine assurance capacity as a scarce resource. If every initiative demands the same specialists at the same gate, reviews become a bottleneck or ceremonial exercise. Sequencing assurance work is part of portfolio design.
Decision Framework
For each major decision, leaders should define an assurance mandate containing:
| Element | Required decision |
|---|---|
| Decision served | What commitment or judgement will the review inform? |
| Scope | Which claims, risks, controls and interfaces will be examined? |
| Independence | What separation is necessary for credibility? |
| Competence | Which technical, commercial and operational expertise is required? |
| Evidence | What source information must be available? |
| Thresholds | Which findings require correction, escalation or refusal to proceed? |
| Accountability | Who owns recommendations and decides the response? |
Findings should distinguish among non-conformance, control weakness, emerging risk, unsupported assumption and strategic concern. Treating every finding as equivalent creates noise and weakens attention to matters that could change the investment decision.
Leaders should also specify how disagreements will be handled. Assurance does not remove the sponsor's authority to accept risk, but it should make the decision and its rationale visible.
From Strategy to Execution
Immediately, programs should map existing review activities against the three functions. Duplicated reviews can be consolidated, while unexamined strategic or operational exposures should receive attention.
Over the medium term, organisations should develop risk-based assurance plans aligned to major decision gates. Plans should identify required expertise, evidence, reporting routes and follow-up responsibilities. Assurance findings should enter controlled action systems rather than remain in static reports.
Long-term capability depends on learning across investments. Repeated findings may indicate an enterprise weakness in estimating, requirements, commercial management, data quality or operational transition. Portfolio governance should fund systemic improvement when patterns emerge.
Related article: Acceptance Criteria Are the Contract Between Strategy and Delivery
Signals to Monitor
Concern is warranted when:
- Assurance reports repeat the same unresolved findings.
- Reviewers receive only curated summaries rather than source evidence.
- The delivery team marks its own high-consequence decisions as independently assured.
- Reviews occur after commitments rather than before them.
- Findings are counted but not ranked by consequence.
- Sponsors accept risks without recording the basis or downstream owner.
- Assurance specialists are overloaded across too many initiatives.
Questions for the Leadership Team
- Which current decision requires independent confidence, and what uncertainty must be reduced?
- Are we asking reviewers to assess delivery or quietly manage it for us?
- Does the assurance team have the competence and access needed to challenge the underlying evidence?
- Which program dependencies fall outside the assurance scope of individual projects?
- How do we distinguish accepted risk from an unresolved finding that has simply aged?
- Are repeated findings exposing a portfolio-level capability problem?
Closing Perspective
Management control produces the outcome. Quality assurance tests whether the production system is dependable. Independent assurance helps governing bodies judge whether the investment remains credible. Mature organisations protect these distinctions while connecting the evidence they produce. The purpose is not oversight for its own sake. It is better judgement before consequential decisions become irreversible.
About EraNorth Insights
EraNorth Insights publishes practical analysis on strategy, projects, operations, transformation and decision intelligence for professional and organisational use. About EraNorth.
