Assurance Versus Delivery — The Structural Tension That Never Resolves
Assurance that arrives too late to change the outcome is not assurance at all — it is an autopsy with recommendations.
Two Functions, One Programme
Every programme of any scale contains within it a fundamental tension. On one side sits the delivery function — the people building, integrating, testing, and deploying. Their currency is progress, momentum, and the management of the hundred daily decisions that keep a complex undertaking moving forward. On the other side sits the assurance function — the people whose role is to stand back from that momentum and ask whether the programme is actually heading where it claims to be heading, whether its risks are understood, and whether its controls are functioning.
Both functions are necessary. Neither is sufficient. And in my experience, the relationship between them is one of the most consistently mismanaged aspects of programme delivery.
The tension is not a failure of individuals. It is structural. Delivery and assurance have different time horizons, different incentive structures, different definitions of success, and fundamentally different relationships with the truth about how a programme is performing. Understanding why this tension persists — and why well-intentioned efforts to resolve it so often make it worse — is essential for anyone responsible for governing complex programmes.
The Nature of the Tension
Delivery teams live inside the programme. They know its texture — which workstreams are genuinely on track, which are being held together by the efforts of two or three individuals, which dependencies are fragile. They operate in a world of trade-offs: scope against schedule, quality against cost, the ideal solution against the one that can be delivered with the resources available. Good delivery managers make these trade-offs constantly, often without escalating them, because escalation takes time and the programme cannot afford to pause while a committee deliberates.
Assurance teams stand outside. Their role is to provide an independent view — to challenge the programme’s own assessment of its health, to test whether controls are working, to identify risks that the delivery team may be too close to see. Good assurance is genuinely valuable: it catches problems early, it provides confidence to sponsors and boards, and it creates a structured opportunity for the programme to confront uncomfortable truths.
But the structural position of these two functions creates a set of dynamics that repeatedly undermine the value that assurance is supposed to provide.
Delivery teams experience assurance as a tax on their time. Assurance teams experience delivery teams as unreliable narrators of their own progress. Both perceptions contain truth, and neither side can see the other’s clearly.
The first dynamic is one of timing. Delivery operates continuously — decisions are made daily, risks materialise and are managed in real time, the shape of the programme changes week by week. Assurance operates periodically — a review every quarter, a gateway assessment at each stage boundary, an audit triggered by a concern. The assurance snapshot captures a moment, but by the time the findings are written up, reviewed, and acted upon, the programme has moved on. The issues identified may have been resolved, superseded, or — more damagingly — allowed to compound because the programme was waiting for the assurance report before acting.
The second dynamic is one of authority. Assurance reviews produce recommendations, but recommendations without authority are suggestions. The assurance function can identify that a programme’s risk management is inadequate, that its benefits case is eroding, or that its timeline is unrealistic. What it cannot do, in most governance structures, is compel the programme to change course. That authority rests with the sponsor, the board, or the steering committee — bodies that may or may not act on assurance findings, depending on appetite, politics, and the persuasiveness of the delivery team’s counter-narrative.
The third dynamic is one of information asymmetry. The delivery team controls the information. They produce the reports, they manage the plan, they own the risk register. Assurance can request data, conduct interviews, and observe, but it is fundamentally dependent on the programme’s willingness and ability to provide an honest picture. In programmes that are struggling, this is precisely the moment when the information becomes least reliable — not necessarily through deliberate deception, but through the optimism bias that is endemic to delivery under pressure.
The Assurance Theatre Problem
These dynamics produce a phenomenon that is widespread but rarely named: assurance theatre. This is assurance that looks comprehensive, follows established methodologies, produces detailed reports, and has no meaningful impact on the programme’s trajectory.
Assurance theatre takes several forms:
- The retrospective review. Assurance arrives after a decision has been made, a commitment entered into, or a phase completed. Its findings are technically accurate but practically irrelevant — the programme cannot undo what has been done, and the review becomes an exercise in documenting what should have happened differently.
- The checklist assessment. Assurance measures whether processes exist and are documented, rather than whether they are effective. The programme has a risk register — tick. The programme has a change control process — tick. Whether the risk register reflects reality, or whether the change control process is actually followed, is a harder question and one the checklist does not ask.
- The diplomatic finding. Assurance identifies a significant issue but frames it in language designed to avoid confrontation. “The programme would benefit from enhanced stakeholder engagement” is a diplomatic way of saying “the sponsor has lost interest and nobody is making decisions.” The diplomatic version allows everyone to nod and move on. The blunt version might have prompted action.
- The ignored report. Assurance produces a thorough, honest, well-evidenced assessment. The steering committee receives it, thanks the assurance team, notes the recommendations, and takes no action. The report is filed. The next assurance review finds the same issues, slightly worse.
Assurance that arrives too late to change the outcome is not assurance at all — it is an autopsy with recommendations.
Why Resolution Fails
The obvious response to this tension is to integrate assurance more closely with delivery — to embed assurance resources within the programme, to make assurance continuous rather than periodic, to create a collaborative rather than adversarial relationship. This sounds right. In practice, it creates its own problems.
Embedded assurance faces a fundamental independence problem. An assurance professional who sits within the programme team, attends their stand-ups, shares their pressures, and builds relationships with the delivery leads will, over time, lose the independence that makes assurance valuable. They begin to see the world through the programme’s eyes. They understand why the risk register is optimistic — because the team is managing those risks actively and does not want to alarm the board. They appreciate why the timeline has not been revised — because the team believes they can recover the slippage. Empathy replaces challenge, and assurance becomes advocacy.
The alternative — maintaining strict independence — preserves the challenge function but at the cost of relevance. An assurance team that parachutes in quarterly, spends a week reviewing documents and conducting interviews, and then departs to write its report has independence but lacks the contextual understanding to distinguish genuine risks from managed ones, systemic problems from transient difficulties. Their findings are often technically correct but contextually wrong, and the delivery team dismisses them on those grounds.
“The closer assurance gets to delivery, the less independent it becomes. The more independent it remains, the less relevant its findings. This is not a problem to be solved. It is a tension to be managed.”
Some organisations have attempted a middle path: assurance functions that are structurally independent but have continuous access to programme information through shared reporting systems, attendance at key meetings, and regular informal contact. This can work, but it requires a level of organisational maturity and mutual respect that is rarer than governance frameworks assume. It also requires assurance professionals who can maintain intellectual independence while being socially embedded — a combination of skills that is genuinely difficult to find.
The Accountability Gap
Beneath the structural tension lies a deeper problem: the accountability gap between assurance findings and governance action.
Assurance produces findings. Governance is supposed to act on them. But the governance bodies that receive assurance reports are often the same bodies that approved the programme’s business case, appointed its leadership, and reported its progress to their own superiors. Acting decisively on an assurance finding that says the programme is in trouble means acknowledging, implicitly, that their own oversight has been inadequate. The incentive to accept the delivery team’s reassurance — “we are aware of these issues and are managing them” — is powerful.
This creates a cycle that is corrosive to the credibility of assurance as a function:
- Assurance identifies a significant issue and reports it to the governance body.
- The governance body notes the finding and asks the programme to respond.
- The programme produces an action plan that addresses the symptoms without changing the underlying trajectory.
- The governance body accepts the action plan because it provides cover for inaction.
- The next assurance review finds the issue unresolved or worsened.
- The assurance function is quietly blamed for crying wolf, and its future findings carry less weight.
The accountability gap is not a gap in the framework. The framework typically defines responsibilities clearly enough. It is a gap in will — in the willingness of governance bodies to act on information that is uncomfortable, inconvenient, or politically costly.
Living With the Tension
The organisations that handle this tension best are the ones that stop trying to eliminate it and instead design their structures to make it productive. Several principles distinguish them.
The first is clarity of purpose. Assurance exists to inform decisions, not to produce reports. Every assurance activity should be traceable to a decision that someone needs to make. If no decision hangs on the outcome, the assurance activity should not happen.
The second is timeliness over thoroughness. A focused, timely assessment that reaches decision-makers while they can still act is worth more than a comprehensive review that arrives after the window has closed. Assurance functions that prioritise completeness over speed consistently fail to influence outcomes.
The third is honest escalation. When assurance findings are not acted upon, that fact itself should be escalated — not as an act of institutional warfare, but as a legitimate governance concern. A programme that receives repeated assurance warnings without changing course is a programme whose governance has failed, and someone above the steering committee needs to know.
The fourth is appropriate independence. Complete separation produces irrelevance; complete integration produces capture. The practical answer is structural independence — separate reporting line, separate budget, no career dependency on the programme’s success — combined with sufficient access to maintain contextual relevance.
The fifth is mutual respect for the difficulty of both roles. Delivery under pressure is hard. Independent challenge under pressure is also hard. The organisations that manage this tension well are the ones where both functions understand that the other is doing something necessary and difficult, and that the friction between them is a feature, not a defect.
The tension between assurance and delivery will not resolve. It cannot, because it is rooted in a genuine and permanent conflict between the need for momentum and the need for scrutiny. The goal is not to eliminate the tension but to ensure that it produces better decisions rather than better theatre.