The Programmes Outside the List

Analysis·Giovanni Leonardi·July 2026·9 min read

Researched by an agentic pipeline · reviewed and gated by the author

The centre can assure fewer programmes only if it can still see—and reach—the programmes it does not routinely touch.

The programmes outside the list

Central assurance has a capacity problem.

The most experienced reviewers, commercial specialists and delivery leaders are scarce. Spread them across every major programme and their attention becomes shallow. Concentrate them on a small number of exceptional programmes and important risks may grow elsewhere without challenge.

The United Kingdom is now running a live test of that trade-off. From 1 April 2026, the Government Major Projects Portfolio was reduced from more than 200 programmes and projects to about 80. Entry now depends not only on strategic importance and whole-life cost above £1 billion, but on whether central intervention is likely to add substantial value. New entrants generally need an early feasibility study. Mega projects above £10 billion receive differentiated treatment. Qualifying work reports through a common platform, while departments carry clearer responsibility for the rest. [S1] [S2]

The reform is too new to have demonstrated better outcomes. Its architecture nevertheless raises a question that every large delivery organisation should confront: what should the centre actually assure?

The answer cannot be everything. It also cannot be only what appears on a central list.

Selective assurance works as a two-layer system: universal visibility and minimum local standards across the whole portfolio, combined with scarce independent intervention allocated by risk, complexity and expected value-add.

The attraction of a smaller centre

Universal central control feels safe because it promises consistency. Every programme submits the same information, passes the same gates and receives an official view. In practice, equal process does not produce equal assurance.

A novel digital service, a decade-long nuclear programme and a departmental policy implementation do not carry the same risk. Their failure mechanisms, evidence cycles and specialist needs differ. Applying a common review with finite expertise can create ceremonial compliance: extensive preparation, predictable findings and limited time for the risks that require genuine judgement.

The 2026 Treasury process explicitly makes assurance proportional. Risk Potential Assessments help determine the level required. Later independent reviews are normally reserved for the highest-priority projects. Red assessments trigger structured response and possible reset, while mega projects have a dedicated decision panel. [S3]

That design has a strong logic. The centre should intervene where its independence, cross-government perspective or specialist capability changes the decision. Work that a competent department can govern itself should not consume the same intensity.

Concentration also creates room for earlier involvement. The new feasibility requirement asks whether a proposal is achievable and worthwhile before a detailed business case hardens the solution. It calls for outside input and evidence while ownership remains with the sponsoring organisation. [S4] This is more valuable than discovering at a late gate that the programme began with an impossible premise.

Visibility is the price of selectivity

Delegation without sight is abdication.

When programmes leave a central portfolio, their risk does not leave the enterprise. A two-layer model therefore starts with common information. The UK process requires qualifying projects to use the Government Reporting Integration Platform, with a lighter template for work outside the central portfolio. [S3]

The purpose is not to create a vast reporting warehouse. It is to preserve the centre’s ability to detect changes in cost, delivery confidence, dependency, public consequence or departmental capability that justify escalation.

Four conditions are essential.

First, the boundary must be transparent. Leaders should know why a programme receives central intervention, why another does not and what change would move it between tiers.

Second, classification must be dynamic. A programme that was routine can become novel after a supplier failure, policy change or technical discovery. Entry cannot be a one-time status awarded at initiation.

Third, local assurance must be credible. Departments need people with sufficient expertise, organisational standing and independence to challenge their own sponsors.

Fourth, the centre must be able to act on signals. Visibility without an escalation route produces a comprehensive view of deterioration.

The centre can assure fewer programmes only if it can still see—and reach—the programmes it does not routinely touch.

The departmental test

Imagine a central portfolio office that removes 40 programmes from enhanced assurance. One is a departmental data modernisation programme with moderate cost and no immediate national priority. Its delivery-confidence rating is amber but stable.

Six months later, three facts change. The programme becomes a dependency for a new regulatory commitment. Its prime supplier loses two key subcontractors. The department’s assurance lead moves to another role and is not replaced.

In a static model, the programme remains outside the central list until a missed milestone or spending approval forces attention. In a selective system, the common data identifies dependency and supplier changes, while capability monitoring exposes the loss of independent challenge. A predefined trigger moves it into deeper review.

The centre does not need permanent control. It may run one focused assessment, convene specialist commercial support and require a recovery plan before returning oversight to the department. Selectivity refers to the intensity and timing of intervention, not abandonment of enterprise responsibility.

That distinction matters for corporate programmes too. A group transformation office may deeply assure only the most cross-functional initiatives. Business units can govern the rest—provided the group sees material dependencies, uses common minimum standards and can intervene when local capability or risk changes.

Where the model can fail

The strongest criticism is selection bias.

A smaller central portfolio can look healthier simply because difficult programmes move outside it. Before the April reform, the GMPP contained 189 projects with £924.2 billion in whole-life cost. NISTA’s 2025–26 report shows the snapshot before the boundary changed, so a simple before-and-after comparison would be misleading. [S2]

Cost thresholds are another weakness. A programme below £1 billion can still be politically contentious, technologically novel or systemically important. The Public Accounts Committee warned in 2025 that critical programmes could fall outside stronger mega-project governance, noting that cost and formal classification did not capture every complex case. [S8]

Departments also have an independence problem. The same organisation sponsors the work, depends on its success and reports its condition. Local reviewers may lack the authority to challenge an influential senior responsible owner. The centre may delegate precisely because departmental capability appears mature, then discover that capability was concentrated in a few people.

Finally, common reporting can become compliance at scale. The OECD’s 2026 Digital Government Outlook finds that 86 per cent of surveyed countries have central monitoring of digital projects, but only one quarter conduct ex-post cost-benefit analysis. Monitoring is common; learning whether investments delivered is not. [S5]

These risks do not argue for universal central assurance. They define the controls that make selectivity defensible.

Five controls for assurance by exception

Control Question
Universal sight Can the centre see every material programme and dependency?
Explicit tiers Is intervention intensity based on published risk and value-add criteria?
Local capability Who independently tests the sponsor’s account outside the central tier?
Dynamic escalation What evidence moves a programme into deeper assurance?
Outcome learning Do reviews and completed programmes improve future selection?

Leaders should test these controls on real decisions, not policy descriptions.

Choose programmes retained in the central tier and a matched group managed locally. Compare time from material risk signal to decision, forecast accuracy, review cost, benefit delivery and the number of late escalations. Track whether local assurance findings differ from sponsor reporting. Examine programmes that cross the boundary in both directions and ask whether the trigger worked early enough.

Do not reward the centre for the average delivery rating of its selected list. That invites favourable composition. Measure the health of the whole system, including excluded work, and whether specialist intervention changed a decision that otherwise would have persisted.

Capability before subsidiarity

Subsidiarity places decisions at the lowest competent level. The final word is competent.

NISTA’s public rationale is that departments should have clearer accountability while central expertise focuses where it has greatest impact. In parliamentary evidence, its chief executive stressed that independent assurance, advice and capability uplift had not disappeared, but were being targeted more thoughtfully. [S6] The Institution of Civil Engineers broadly supported the refocus while calling for stronger capability and mandatory good practice across government. [S7]

This is the central tension. The centre reduces direct involvement only by investing in the conditions that make local ownership safe. It needs common methods, professional standards, peer review, accessible specialist panels and honest information about departmental capacity. It must be willing to intervene when the local system cannot assure itself.

Capability is also specific. A department can be strong at construction assurance and weak at digital delivery. A business unit may manage ordinary technology programmes well but lack expertise in agentic AI, cybersecurity or complex ecosystem change. Tiering should reflect the delivery environment, not institutional reputation alone.

Evidence from the reform

The UK change deserves attention because it is not merely a new framework. The portfolio boundary, reporting requirements, feasibility rules and approval process have changed in operation.

But architecture is not outcome. It is not yet possible to say that reducing the central list improved delivery, shortened escalation or strengthened departments. Nor is 80 an intrinsically correct number. The useful evidence will come from what happens to programmes outside the list.

Do they receive credible independent challenge? Are risks escalated earlier or later? Does common reporting expose dependencies before they become crises? Does the centre reach high-risk work regardless of political prominence? Do departments build lasting capability, or does expertise continue to pool at the centre and with consultants?

A selective assurance system succeeds when it makes central attention rarer and more consequential without making the rest of the portfolio less visible. It fails when a smaller list becomes a smaller field of responsibility.

The most important programme may be the one the centre chose not to assure last quarter. A mature system knows why, watches what changes and can change its mind before the programme forces the decision.

Sources

  1. Government Project Delivery — Government strengthens project delivery and accountability — 1 April 2026 — https://projectdelivery.gov.uk/2026/04/01/government-strengthens-project-delivery-and-accountability/
  1. NISTA — Major Projects Annual Report 2025–26 — 13 July 2026 — https://www.gov.uk/government/publications/nista-major-projects-annual-report-2025-26/nista-major-projects-annual-report-2025-26
  1. HM Treasury — Treasury Approvals Process for projects and programmes — 1 April 2026 — https://www.gov.uk/government/publications/treasury-approvals-process-for-programmes-and-projects/treasury-approvals-process-for-projects-and-programmes
  1. Government Project Delivery — GMPP feasibility studies — 1 April 2026 — https://projectdelivery.gov.uk/library-products/gpd-pn-02-26-gmpp-feasibility-studies-html/
  1. OECD — Governing digital investment and capabilities to deliver at scale — June 2026 — https://www.oecd.org/en/publications/2026/06/digital-government-outlook_4585678e/full-report/governing-digital-investment-and-capabilities-to-deliver-at-scale_d775f3d4.html
  1. UK Parliament Treasury Committee — Oral evidence from NISTA — 23 June 2026 — https://committees.parliament.uk/oralevidence/17813/html/
  1. Institution of Civil Engineers — Evidence to the Treasury Committee on NISTA — July 2026 — https://committees.parliament.uk/writtenevidence/167682/default/
  1. Public Accounts Committee — Critical programmes slip through net — 10 September 2025 — https://committees.parliament.uk/committee/127/public-accounts-committee/news/209194/critical-programmes-slip-through-net-of-new-governance-plans-for-govt-megaprojects/

More from Programme