Assurance has no strategic value if it confirms that governance exists but does not improve the decisions governance makes.
Large programs accumulate assurance.
There are internal reviews, independent reviews, audit activity, gateway assessments, design reviews, risk committees, financial approvals and steering boards. The intention is rational: senior leaders need confidence that work is controlled, aligned and likely to deliver.
The danger is that assurance becomes a parallel industry of evidence production.
Teams prepare packs. Reviewers raise findings. Actions are logged. Gates are passed. Yet the investment continues on essentially the same path because the real decision was made before the review began.
The 2018 UK Government GovS 002 standard defines assurance as systematic action that gives senior leaders and stakeholders confidence that work is controlled, on track and aligned with policy or strategy. It also positions assurance reviews before significant decisions and connects those decisions to business justification.
The strategic lesson extends beyond government: assurance should exist to improve a choice.
The Strategic Context
Senior leaders face an information problem.
Program teams know far more about delivery detail than the governing body. Suppliers know more about their packages than the client. Optimism, incentives and organisational politics can influence what is escalated. A dashboard can show compliance with the plan without demonstrating that the plan remains sensible.
Assurance creates an additional perspective.
GovS 002 describes several assurance lines, from management controls through more independent oversight and audit. The exact model is contextual. The core logic is separation between those doing the work, those testing whether controls are effective and those providing a more independent view.
But independence alone is not enough.
An assurance review is valuable when it reaches a decision-maker at the moment a decision is still open.
What Leaders Commonly Misread
The first misread is assuming that more assurance always means more control.
Every review consumes attention. If several functions ask for similar evidence in different formats, teams can spend significant effort satisfying oversight without improving delivery.
The second misread is treating gates as permission rituals.
A gate should not ask, "Have we produced the required documents?"
It should ask, "Is the evidence strong enough to justify the next commitment?"
The third misread is using assurance to validate the delivery plan without testing continuing business justification.
GovS 002 explicitly links business cases to ongoing decisions and expects them to be updated as circumstances change. This matters because a project can remain well controlled while becoming a poor investment.
The fourth misread is allowing sponsors to treat assurance findings as operational issues for the project manager.
Some findings concern project execution. Others challenge assumptions, governance, capability, affordability or strategic fit. Those require sponsor or executive action.
Related article: Business Cases Are Investment Hypotheses, Not Permission Slips
Reframing the Issue
Assurance is part of the decision architecture.
That means every material assurance activity should have a clear decision purpose.
For example:
- before initiation: is the need credible enough to invest in further definition?
- before solution selection: is the preferred option supported by evidence?
- before major contract commitment: are requirements, risk and commercial arrangements mature enough?
- before deployment: is the organisation ready to use the output safely and effectively?
- before closure: are responsibilities, residual risks and benefit ownership transferred?
- during delivery: has evidence changed enough to justify continuation, redesign, pause or termination?
The review becomes meaningful because failure can change the decision.
If continuation is guaranteed regardless of evidence, the gate is theatre.
Assurance Must Test the Business Case and the Management System
A useful assurance review asks two different questions.
Is the investment still worth doing?
This concerns strategic relevance, expected outcomes, benefits, costs, risk, alternatives and whole-life implications.
Is the current management system capable of delivering it?
This concerns governance, capability, planning, supplier arrangements, controls, quality, integration, readiness and decision effectiveness.
A program can pass one test and fail the other.
A valuable strategic initiative can be badly organised.
A well-managed project can pursue an outcome that no longer matters.
Senior leaders need both answers.
Independence Should Be Proportionate to Consequence
Not every decision requires the same level of independent scrutiny.
Assurance intensity should rise with factors such as:
- scale of irreversible commitment;
- safety or regulatory consequence;
- novelty and technical uncertainty;
- strategic importance;
- concentration of supplier risk;
- difficulty of recovering from failure;
- political or stakeholder sensitivity;
- evidence of deteriorating performance.
This is consistent with the broader GovS principle that governance and controls should be proportionate to risk.
The aim is not to make every project major-project bureaucracy. It is to apply independent challenge where decision error would be expensive or difficult to reverse.
Decision Framework
Before commissioning an assurance review, leaders should define five things.
| Question | Purpose |
|---|---|
| Decision | What decision will this assurance inform? |
| Evidence | What evidence must be credible for the decision to proceed? |
| Independence | How independent must the review be from the delivery team? |
| Threshold | What finding would cause pause, conditions, redesign or termination? |
| Owner | Who has authority to act on the result? |
This creates a direct line from assurance activity to governance action.
It also allows conditional decisions. GovS 002 recognises that approvals may be conditional, provided responsibility for meeting the conditions is clear. This can be more practical than forcing a false binary between full approval and stop.
From Strategy to Execution
Immediate action should begin by mapping the organisation's assurance activities against actual decision points.
Remove reviews that exist only because they have always existed. Combine duplicated evidence requests where possible. Make clear which forum owns the decision arising from each review.
Next, redesign gate papers around decision questions rather than document completion. A concise decision paper should explain what has changed since the last gate, what assumptions remain, what options exist, what assurance found and why management recommends proceeding.
In the medium term, establish escalation rules for assurance findings. A high-severity issue should not disappear into an action log owned below the level where the cause can be resolved.
Longer term, use assurance data to improve the enterprise delivery system. If reviews repeatedly find weak requirements, late operational involvement or poor integration, the issue is no longer one project. It is organisational capability.
Related article: Governance Can Reduce Complexity or Become Another Layer of It
Signals to Monitor
Assurance may have become ceremonial when:
- reviews occur after the practical decision has already been made;
- teams optimise documentation for the review rather than expose uncertainty;
- the same findings recur across successive gates;
- review actions are numerous but few alter scope, governance or investment;
- senior sponsors delegate strategic findings to delivery teams;
- business cases are refreshed cosmetically without re-testing assumptions;
- all projects pass gates despite materially different risk profiles;
- independent challenge is treated as an obstacle to schedule;
- executives cannot explain what decision a major assurance review is intended to improve.
Questions for the Leadership Team
- Which upcoming decisions are important enough to require independent challenge?
- What evidence would genuinely cause us not to proceed?
- Are our assurance reviews testing continuing value as well as delivery control?
- Where are multiple assurance functions asking for the same information?
- Who is accountable for acting on findings that concern governance or strategy rather than project execution?
- Have we created any gates that cannot realistically say "not yet" or "stop"?
- What recurring assurance finding points to an enterprise capability problem?
Closing Perspective
Assurance is valuable because leaders are not omniscient and delivery systems are not neutral. Independent challenge can reveal optimism, weak evidence, ineffective controls and changing conditions before they become irreversible failures.
But assurance earns its cost only when it influences choices.
The design principle is simple: place the right challenge before the right decision, define what evidence matters and give someone authority to act on the result.
Then assurance becomes part of intelligent governance rather than another layer of process around a decision the organisation had already made.
About EraNorth Insights
EraNorth Insights publishes practical analysis on strategy, projects, operations, transformation and decision intelligence for professional and organisational use. About EraNorth.
