Internal Audit and Programme Delivery Must Stop Meeting at the Scene of the Failure
Assurance that arrives after the irreversible decision is not assurance; it is an autopsy.
Two Functions, One Blind Spot
At the end of a recent programme review, the delivery director closed a thick action log and declared the work “under control”. The internal auditor sitting opposite had reached a different conclusion. The programme could account for its actions, milestones and expenditure, but it could not demonstrate that its most consequential assumptions had ever been independently tested.
Both professionals were competent. Both were doing what their disciplines expected. The delivery team was managing towards the next gate; internal audit was working through an annual plan built around financial processes and established controls. They met only because the programme had already become visible as a risk.
That late encounter is becoming a defining weakness in large change programmes.
The governance debate of 2002–03 has concentrated minds on boards, audit committees, financial reporting and the reliability of control. That attention is necessary. Yet many organisations are applying it to the permanent business while leaving their largest temporary organisations — programmes — governed by a parallel language. Internal audit asks whether controls are designed and operating. Programme delivery asks whether milestones can still be met. Each question is legitimate; neither is sufficient on its own.
Why the Gap Has Become Material
The programme portfolio has changed faster than the assurance model around it. A major systems replacement or shared-service programme now moves processes, responsibilities, data and authority together. It can alter the control environment months before the new operation formally begins. Waiting until implementation to audit the resulting process is therefore waiting until the most important design choices have become expensive to reverse.
Consider a composite programme replacing finance and purchasing systems across eleven business units. The approved cost is £38 million. The steering group receives a monthly dashboard showing expenditure within tolerance and testing broadly on schedule. Internal audit, following its annual plan, is due to examine purchasing controls six months after implementation.
Three weeks before the go-live decision, the programme discovers that 2,400 supplier records still lack validated bank details and that the proposed access model gives 160 users both requisition and approval rights during the transition. The issues are described as “operational workarounds” because neither affects the technology launch date. Delivery accepts them to protect the timetable. Audit has not seen them because the programme is not yet part of the live control environment.
The programme has not failed its own reporting rules. Internal audit has not failed its mandate. Governance has failed to connect the two.
- Delivery sees reversibility poorly. A milestone may be green even when a decision is about to lock in a weak operating model.
- Audit sees temporariness poorly. Traditional audit plans are designed for repeatable processes, not for a sequence of one-off decisions whose risk expires once the gate has passed.
- Committees receive two partial truths. One describes progress; the other describes control. Few reports show where progress is being purchased by accepting control debt.
This matters particularly now because boards are being asked to take greater responsibility for the credibility of control. A board cannot discharge that responsibility by examining the steady-state business while assuming that programme governance will protect the transition. Programmes are where tomorrow’s control environment is being designed today.
Assurance that arrives after the irreversible decision is not assurance; it is an autopsy.
The Serious Objection
Programme leaders have a strong objection to bringing internal audit closer: auditors can slow decisions, duplicate existing reviews and judge uncertain delivery against standards designed for stable operations. That objection deserves respect. An auditor who arrives with a generic checklist, asks for complete evidence during a fluid design phase and reports every open issue as a control failure will add friction without adding judgement.
But the answer is not separation. It is a more precise compact.
Internal audit should not become another layer of programme management, and it should not approve delivery decisions. Its value is independence: testing whether the evidence behind a decision is adequate, whether the accepted risk is visible to the right authority, and whether the claimed remedy can still be delivered before the choice becomes irreversible.
Programme assurance, for its part, should not be dismissed as management marking its own homework. Good programme assurance understands dependencies, technical sequence and delivery feasibility in ways a periodic audit may not. The two disciplines are complementary when their roles are explicit.
| Question | Programme assurance contributes | Internal audit contributes |
|---|---|---|
| Can the plan be delivered? | Dependency, capacity and schedule judgement | Challenge to the reliability of evidence |
| Will the design work? | Technical and operational readiness | Control design and authority analysis |
| Can this risk be accepted? | Delivery impact and mitigation options | Independence, escalation and risk visibility |
| Has the gate been earned? | Completion evidence | Test of the decision process |
Meet at the Decision, Not After It
The practical change is modest. Internal audit does not need a permanent seat in every workstream. It needs access at the few points where a programme converts uncertainty into commitment.
- Map the irreversible decisions. At initiation, identify the gates that commit capital, select a design, migrate data, change authorities or release a service.
- Agree the assurance question for each gate. Do not ask vaguely whether the programme is “well controlled”. Ask whether the evidence is sufficient for this particular decision.
- Separate advice from accountability. Delivery management owns the recommendation; the sponsor owns the decision; internal audit records its independent view of the evidence and escalation.
- Follow accepted risk into operations. Any control weakness accepted for schedule reasons must have an owner, a dated remedy and visibility after implementation.
For the £38 million programme, this would not require an audit of the entire implementation. A short review before the go-live gate could sample supplier records, test segregation of duties, examine the authority for temporary access and ask whether the remediation window was credible. The steering group might still proceed. The difference is that it would proceed with a conscious decision, not a scheduling euphemism.
The most mature outcome is not that audit “wins” and delivery slows. It is that both functions become clearer about what they know. Delivery can say whether an action is feasible. Audit can say whether the evidence and authority are adequate. The sponsor must then decide.
This is the governance lesson hiding inside the present concern with corporate control: the boundary of assurance must follow the boundary of consequential decision-making. If internal audit and programme delivery continue to inhabit separate worlds, they will keep meeting — but only when the cost of their separation has already appeared.