Delivery & Controls
Governance, cost, schedule and risk during construction, and the difference between progress and health.
6 domains. Each one names a question with a checkable answer. A domain you cannot answer is uncovered, whatever the assurance plan says about it.
Baseline integrity
Is the baseline currently being reported against the one that was sanctioned, and if not, is every step between the two documented?
Performance reporting is only meaningful relative to a baseline, so a baseline that has quietly moved makes every subsequent report defensible and useless. Programmes rarely lose the baseline in one visible event. It goes in a series of small re-baselines, each individually reasonable, none of which is wrong on its own terms. The cumulative movement is what nobody is looking at, because no single report shows it.
What to examine
- Reconcile the current baseline to the sanctioned baseline in one continuous chain. The inability to do this is the finding, and it is common.
- Count the re-baselines and read the approval for each. Check who approved them and whether that person also owned the performance being re-based.
- Compare current forecast against the original sanction figure, not against the most recent baseline. This is usually the only number that surprises anybody.
- Check whether scope was removed to hold cost. Descoping presented as underspend is the most common quiet failure at this stage.
Required by
- ISO 21502:2020, Clause 7, management practices covering planning, scope, schedule, cost and change control.
- PMBOK Guide, Eighth Edition, November 2025, scope, schedule and finance performance domains.
Change, planned and unplanned
Are changes assessed before they are made, and does anyone examine changes that were made without being assessed?
Change control functions well on changes that enter it. Its weakness is definitional: it can only govern what somebody classified as a change. The consequential ones are usually reclassified as clarifications, design development, or site instructions, and they are invisible to the register that was built to catch them. Asset management now treats planned change as a requirement in its own right, separately from change control, which is a distinction most organisations have not yet absorbed.
What to examine
- Sample instructions, technical queries and site decisions that did not enter the change register, and test whether any altered cost, programme or operating characteristics.
- Check whether the change assessment considers operating consequence, or only capital cost and time.
- Establish whether changes are assessed before implementation or ratified afterwards. Retrospective approval rates tell you what the control actually is.
- Confirm planned changes to the asset management system itself are assessed for risk and carried out in a planned manner, which the second edition requires separately.
Required by
- ISO 55001:2024, Clause 6.3, planning of changes, new in the second edition.
- ISO 55001:2024, Clause 8.2, control of change.
- ISO 21502:2020, Clause 7, change control practice.
Forecast credibility
Does the forecast reflect what is now known, or does it reflect what was committed?
A forecast that never moves is not stable, it is unexamined. Programmes routinely hold a forecast at the approved figure until the evidence becomes undeniable, at which point the whole variance appears in one period and is reported as a sudden deterioration. It was not sudden. The information existed and the forecast was not permitted to carry it.
What to examine
- Plot the forecast over time. A flat line followed by a step is the signature of a suppressed forecast, not a well-controlled one.
- Check whether known risks that have already materialised are in the forecast or still in the risk register.
- Establish who is permitted to move the forecast, and whether that person reports to whoever is accountable for the number.
- Test contingency drawdown against progress. Contingency consumed faster than scope completed is an early and legible warning.
Required by
- AACE International Recommended Practice 56R-08 and 18R-97 on estimate classification and expected accuracy.
- PMBOK Guide, Eighth Edition, November 2025, finance performance domain.
- ISO 21502:2020, Clause 7, cost management practice.
Externally provided processes and services
Where activities that affect the asset have been placed outside the organisation, has the organisation retained the ability to know whether they were done?
Outsourcing transfers activity, not accountability, and the gap between the two is where assurance quietly stops. The 2024 edition widened the requirement deliberately, from outsourcing to externally provided processes, products, technologies and services, which now captures arrangements most organisations never treated as outsourcing at all: platforms, data services, proprietary systems whose behaviour the owner cannot inspect.
What to examine
- List what has been externally provided, including technologies and data services, not only contracted works and consultancy.
- For each, identify what the organisation retains that lets it verify performance independently of the provider.
- Check whether the owner holds more or less programme information than its tier one contractors. Where the imbalance is wide, note it as a transfer risk crystallising at handover rather than as a delivery issue.
- Confirm the contract requires the information the owner will need to operate, and not merely the information the provider finds convenient to produce.
Required by
- ISO 55001:2024, Clause 8.3, externally provided processes, products, technologies and services, renamed and widened from Outsourcing in the 2014 edition.
- PMBOK Guide, Eighth Edition, November 2025, which expands coverage of procurement.
- FIDIC Conditions of Contract, 2017 edition, Sub-Clause 10.1.
Interfaces between packages and functions
Has anyone examined the seams, as distinct from examining each of the things the seams join?
Assurance is bought by function and by package, and each buyer receives a report on their own scope. The arithmetic error is to assume that adding those reports produces coverage of the programme. It does not, because programme risk is not additive across functions: the interactions between packages generate exposures that no single package review is scoped to see, and the failure appears in whichever package is least able to absorb it.
What to examine
- Draw the interfaces. Then ask whose assurance scope each one falls inside. The ones falling inside nobody are the finding.
- Check whether any review has been scoped across two packages rather than within one.
- Test the schedule logic between packages, in particular where one package holds float that another package is relying on.
- Establish who owns interface risk in the contract structure, and whether that party has the information to manage it.
Required by
- Global Internal Audit Standards, Institute of Internal Auditors, effective 9 January 2025, on risk-based planning.
- ISO 21502:2020, Clause 6, integrated project management practices.
This one is ours
The standards require risk-based planning and integrated practice. Neither states that coverage is non-additive across functions, or that interfaces generate exposures invisible to package-level review. That reading is this publication’s, argued from how assurance is procured on large programmes rather than from any clause.
Competence of whoever is assuring
Do the people performing this assurance understand the thing they are examining, and where they do not, is the gap covered by someone who does?
A reviewer who cannot read a programme, price a variation or interpret a technical query will examine the controls surrounding those activities and report on the controls. That is a real finding about a real control environment, and it is not a finding about the programme. The distinction is rarely drawn in the report, so the reader concludes the programme was examined when the paperwork around it was.
What to examine
- Read the team composition against the subject matter. Then read the conclusions and ask which of them required knowledge the team did not have.
- Where a specialist was used, check the reviewer retained responsibility for the conclusion rather than adopting the specialist opinion wholesale.
- Establish whether competence requirements were determined and documented before the work was scoped.
- Check whether the assurance provider has ever declined a scope on competence grounds. A provider that never has may not be assessing it.
Required by
- ISO 55001:2024, Clause 7.2, competence, requiring the organisation to determine necessary competence and retain documented information as evidence.
- ISO 55012, people involvement and competence in asset management.
- Global Internal Audit Standards, Institute of Internal Auditors, effective 9 January 2025, on proficiency and due professional care.
- ISA 620, using the work of an auditor’s expert, and ISA 610, using the work of internal auditors.
Engaging an engineer satisfies the standard. Deferring to one does not.
Correspondence
If something here is wrong, that is worth more than agreement.
Corrections are published. There is nothing to buy and nobody follows up with an offer.
Write to the publication