Programme Governance Fails When It Behaves Like Financial Audit
Audit can tell a programme whether its controls operated; governance must decide whether its next commitment is still justified.
Beyond the Audit Trail
The gate pack contains 57 documents. The business case is signed. Risks have owners. The project plan has been baselined. Procurement has confirmed the contract route. Finance has reconciled the £28 million funding request. Internal audit has reviewed the governance arrangements and raised no critical finding.
The steering committee approves the next stage.
What it does not discuss is that demand has fallen 12 per cent since the business case was prepared, the supplier estimate assumes a volume that no longer appears credible and nearly half the contingency will be committed before the design is tested.
The governance process has proved that the programme followed its controls. It has not proved that the decision remains sound.
This is the error at the centre of much programme governance. Organisations have borrowed the habits of financial audit — evidence, compliance, independence, traceability and retrospective assurance — and applied them to decisions that must be made forward, under uncertainty. The result looks disciplined because every required document exists. Yet leaders can approve an unwise commitment with a perfect audit trail.
Programme governance does not fail because it lacks reporting. It fails because reporting is allowed to stand in for judgement.
Audit and Governance Face Opposite Directions
Financial audit asks whether a statement can be supported by evidence and whether controls operated as expected. Its strength is disciplined examination against an established standard. It looks backward because the transaction, period or control has already occurred.
Programme governance faces a different object. It must decide whether to commit money, people and reputation to a future that is not yet known. The plan is an estimate. Benefits depend on assumptions. Risks interact. Evidence is incomplete precisely when the largest choices are made.
The two disciplines therefore ask different questions.
| Audit question | Governance question |
|---|---|
| Was the approved process followed? | Is the approved process still appropriate? |
| Does evidence support the reported position? | What remains uncertain, and can we tolerate it? |
| Did the control operate? | What should we commit before the control can be proven? |
| Was authority used correctly? | Does the authorised person have a real choice? |
| Can the result be traced? | Can the decision be reversed if the assumptions fail? |
Confusing the questions produces a governance system that is strongest where programmes are least difficult: proving that known procedures were followed.
Assurance Became the Meeting
The borrowed audit model shapes the steering committee’s agenda. The programme team presents status against plan, budget, risk, issues and actions. Exceptions receive attention; areas within tolerance pass without discussion. Papers seek approval by demonstrating that required conditions have been satisfied.
This encourages a particular form of behaviour:
- project teams assemble evidence that the gate is complete;
- assurance functions test the evidence against the gate criteria;
- the programme office reports gaps and overdue actions;
- the steering committee resolves exceptions and grants authority.
The machinery is orderly. Its weakness is that everyone works towards passing the gate.
In one composite programme, a design gate requires 23 artefacts. Twenty-one are complete. The two outstanding items concern training schedules and a minor interface. The pack is therefore reported as 91 per cent complete and amber. Considerable attention is devoted to closing the two gaps.
Buried in the approved business case is a more consequential assumption: six business units will adopt one standard process. Two units have since refused, but no gate criterion requires the assumption to be revalidated. Their resistance will add interfaces, local controls and support cost. The programme can close all 23 artefacts and still proceed on a broken premise.
The audit-shaped process finds missing evidence. It does not naturally find obsolete logic.
Audit can tell a programme whether its controls operated; governance must decide whether its next commitment is still justified.
The Strong Case for Audit Discipline
There is a powerful defence of the borrowed model. Programmes have a history of informal promises, optimistic reporting and undocumented decisions. Without independent assurance, stage criteria and traceable authority, executives can commit substantial funds on little more than confidence. Audit disciplines impose evidence where enthusiasm once prevailed.
That defence is correct. Programme governance needs independence, traceability and proof that agreed controls operate. Removing those disciplines would not create better judgement; it would create less accountable optimism.
The error is not borrowing from audit. It is assuming that audit disciplines are sufficient.
Assurance should establish whether the decision process is reliable:
- required evidence is present;
- figures reconcile;
- risks and conflicts are disclosed;
- authority is clear;
- conditions from earlier decisions were honoured.
Governance must then use that reliable process to exercise judgement:
- assumptions remain credible;
- options are still open;
- uncertainty is understood;
- consequences are acceptable;
- the next commitment is proportionate to the evidence available.
One discipline protects the integrity of the process. The other determines the wisdom of the choice.
Replace Compliance Gates with Commitment Decisions
Most programme gates are defined as collections of deliverables. The programme passes when enough evidence is complete. This is convenient for administration but weak for governance because it makes artefact completion the subject of the decision.
A proper gate should instead be framed around the commitment being requested.
For example:
The programme requests authority to commit £8.5 million to configuration and integration, reducing remaining contingency to £2.1 million, on the assumption that all six business units adopt the standard process. If that assumption fails, the estimated additional cost is £3 million and implementation may move by four months.
That statement forces the governing body to confront:
- the amount becoming irreversible;
- the assumption carrying the decision;
- the remaining capacity to absorb error;
- the consequence if the assumption fails;
- the authority required to accept the exposure.
The supporting documents remain necessary, but they serve the decision rather than become the decision.
Every gate should therefore contain five explicit elements:
- Commitment: what money, scope or dependency becomes fixed.
- Evidence: what is known and how reliable it is.
- Assumptions: what must be true but remains unproven.
- Alternatives: what other choices remain, including delay or reduction.
- Reversal: what would cause the commitment to stop or be reconsidered.
The steering committee should approve the commitment in those terms, including any conditions. A minute stating “gate passed” is too weak. It records compliance without preserving judgement.
Separate Assurance from Advice
Audit-shaped governance also becomes confused when assurance functions are asked to recommend the decision. If a reviewer both defines the criteria and advises whether to proceed, independence can blur into shadow management.
The roles should be distinct:
- Programme management assembles the case and states the recommendation.
- Business ownership confirms outcomes, operating consequences and benefits.
- Independent assurance reports whether evidence is reliable, criteria are met and material uncertainty is disclosed.
- The governing body weighs the evidence and accepts, rejects or conditions the commitment.
Independent assurance may say that the process is sound and still decline to judge whether the commercial exposure is worthwhile. Conversely, a steering committee may proceed despite an assurance exception, but it must record why the exposure is acceptable and who owns the consequence.
This is not a weakening of control. It makes accountability visible.
Governance Begins Where the Checklist Ends
The influence of financial audit has improved programme discipline. Plans are more traceable, authority is clearer and evidence is less easily replaced by confidence. Those gains should be retained.
But a programme is not a financial period waiting to be examined. It is a sequence of choices whose consequences are still forming. Governance must work before certainty exists and while alternatives remain open.
The test of a gate is therefore not whether every prescribed document is present. It is whether leaders understand what they are about to make irreversible, which assumptions carry the decision and what they will do if those assumptions fail.
Reporting can describe the programme. Assurance can test the description. Only governance can decide whether the next commitment is justified.
When those roles are confused, the organisation may possess an impeccable record of how it approved the wrong decision.