The audit should protect the investment by revealing how the delivery system behaves, not by searching for an individual to blame.
The announcement of a project audit can improve discipline immediately. Records are updated, decisions documented and unresolved actions revisited. It can also produce the opposite result: defensive reporting, curated evidence and reluctance to discuss emerging problems.
The difference lies in how the audit is designed and how leadership uses its findings. If the process is perceived as a search for fault, people protect themselves. If it is credible, independent and focused on the project system, it can expose weaknesses while corrective action remains possible.
The Strategic Context
Executives commission audits because they need confidence that authorised methods, controls and decisions are protecting an investment. The audit may examine compliance with plans and governance, the quality of management processes or the project's ability to achieve its objectives.
This differs from reviewing a deliverable. A quality review may test whether an output meets requirements. A project audit examines the processes, evidence and governance through which delivery is controlled.
Audits are especially valuable where consequences are high, information asymmetry is significant or a governing body is approaching an irreversible commitment. Their value declines when they become routine ceremonies detached from real decisions.
What Leaders Commonly Misread
The first error is treating the existence of documents as proof that controls are effective. A risk register can exist without active risk management. A schedule can exist without credible logic. A change process can exist while decisions occur informally.
The second is assuming external auditors are automatically independent and internal auditors are not. Credibility depends on reporting lines, incentives, competence, access and freedom to reach evidence-based conclusions.
The third is asking auditors to implement their recommendations. This shifts ownership from the sponsor and project team and creates a parallel management structure.
The fourth is using an audit report as a performance judgement on the project manager. Individual accountability matters, but many failures arise from sponsor behaviour, portfolio overload, governance ambiguity or enterprise capability gaps.
Reframing the Issue
A project audit should be reframed as a structured intervention in the organisation's control and learning system.
It has three potential purposes:
- Provide confidence that material controls are suitable and operating.
- Identify weaknesses early enough for corrective action.
- Generate learning that improves future projects and enterprise capability.
These purposes should be explicit. An audit designed for regulatory compliance will not automatically answer whether the business case remains credible. A health check designed to support delivery may not provide the independence required for a major investment gate.
Audit Scope Should Follow the Decision
The scope should begin with the governing question. Is leadership concerned about schedule credibility, commercial exposure, technical maturity, operational readiness or governance compliance? A broad checklist can identify symptoms, but a decision-specific audit produces stronger evidence.
The audit agreement should define objectives, criteria, access, confidentiality, reporting, response rights and follow-up. It should also clarify what is outside scope so that absence of a finding is not mistaken for positive assurance.
Documentation analysis is necessary. Plans, schedules, cost data, risk records, change decisions and assurance evidence reveal whether the control system is coherent. Interviews and observation reveal how that system operates in practice. The difference between the documented process and actual behaviour is often the most valuable finding.
Related article: Assurance and Control Are Different Executive Responsibilities
Independence Requires Competence and Access
An auditor should be sufficiently separate from the work, but separation alone is not enough. The person or team must understand project delivery, the relevant industry and the methods required to test evidence.
An internal PMO may provide effective audit capability if it has a clear mandate and does not report findings through the delivery chain it is reviewing. A peer review may be suitable for lower-consequence learning. External specialists may be appropriate where technical complexity, stakeholder sensitivity or perceived conflict is high.
Auditors need access to sponsors, delivery teams, suppliers, users and source records. Limiting access to prepared presentations weakens the result.
Findings Should Describe Systems and Consequences
A useful finding explains:
- The expected criterion or control.
- The evidence observed.
- The gap or weakness.
- The consequence for objectives or governance.
- The recommended management response.
Findings should distinguish critical exposure from improvement opportunity. A long undifferentiated list encourages superficial closure and makes material issues harder to see.
Recommendations should be constructive and proportionate. The auditor advises; the sponsor and project retain responsibility for deciding and implementing action. If management accepts the risk rather than implementing a recommendation, that decision should be explicit.
The Behavioural Contract Matters
People will cooperate when they understand that the project system is being assessed fairly and that context will be considered. This does not mean avoiding accountability. It means preventing the audit from becoming a retrospective search for someone to blame.
Confidentiality needs judgement. Sensitive personal or commercial evidence should be protected. Material governance concerns must still reach the authorised decision-maker. “Criticise in private” should not become “conceal from governance”.
Auditors must also invite factual correction before finalising conclusions. This improves accuracy without allowing the delivery team to negotiate away uncomfortable evidence.
Decision Framework
Before commissioning an audit, leaders should define:
| Design question | Required choice |
|---|---|
| Purpose | Compliance, confidence, recovery, gate decision or learning |
| Timing | When findings can still change an important decision |
| Scope | Controls, evidence, interfaces and outcomes to examine |
| Auditor | Required independence, competence and authority |
| Method | Document review, interviews, observation, testing or sampling |
| Reporting | Audience, confidentiality, severity and response process |
| Follow-through | Action owners, decision rights, deadlines and verification |
An audit should proceed only when leaders are prepared to act on credible findings. Commissioning a review and ignoring its conclusions damages future cooperation and governance legitimacy.
From Strategy to Execution
Immediately, link each planned audit to a specific decision, concern or control objective. Remove review activity that has no clear consumer.
Over the medium term, establish common finding classifications, escalation thresholds and follow-up controls. Recommendations should enter governed action and change systems. Closure should require evidence, not a status update.
Long-term capability depends on analysing patterns across audits. Recurring weaknesses may show that project teams are operating within an enterprise system that produces poor estimates, slow decisions, unclear sponsorship or weak commercial interfaces. The appropriate response may be portfolio-level capability investment rather than another local corrective action.
Related article: Executive Reporting Should Drive Decisions, Not Describe Activity
Signals to Monitor
Leaders should investigate when:
- Teams update documents only immediately before audits.
- Audit scope emphasises document presence rather than control effectiveness.
- Findings repeatedly close without evidence.
- Reports criticise individuals without examining governance conditions.
- Auditors lack access to source records or key stakeholders.
- The same weakness appears across multiple projects.
- Sponsors commission audits but do not decide on recommendations.
Questions for the Leadership Team
- What decision or uncertainty is this audit intended to address?
- Does the auditor have sufficient independence, competence and access?
- Are we examining how controls operate or merely whether documents exist?
- Which findings indicate systemic portfolio or organisational weakness?
- Who will decide and own the response to each material finding?
- Does our culture encourage candid evidence or defensive compliance?
Closing Perspective
A credible audit creates temporary independence so the organisation can see its delivery system more clearly. Its success is not measured by the number of findings or documents inspected. It is measured by stronger decisions, corrected weaknesses and learning that changes future practice. Accountability is preserved when leaders act on evidence; blame is merely what remains when they do not.
About EraNorth Insights
EraNorth Insights publishes practical analysis on strategy, projects, operations, transformation and decision intelligence for professional and organisational use. About EraNorth.
