Skip to content
02Delivery & Controls

Programme risk is not the sum of its functions

A capital programme does not simply contain larger versions of procurement, payment and resourcing. It creates chains that run through all of them, and a chain belongs to no function. That makes under-coverage a design problem in the audit plan rather than a question of materiality, and it has a method attached.

11 min read

The pattern is consistent enough to describe in the abstract. An organisation with a capital programme worth several billion under way commissions an entity-wide internal audit. The plan returns risk-assessed, resourced and approved. It contains a review of human resources, a review of finance, a review of procurement, a review of information technology. The programme appears once, described as "projects", and is allocated fewer days than the payroll review.

Nothing improper has happened. The plan was built the way audit plans are built, from the organisation chart. An organisation chart shows functions. It does not show exposure.

The obvious complaint about this is one of proportion: the programme is bigger than the functions being audited, so it should get more days. That complaint is true and it is the weaker of the two available.

Programme risk is not additive

A programme does contain its own procurement, at values the organisation's routine purchasing never approaches, and its own resourcing, payment and safety regimes. If that were the whole problem, the answer would be to weight the plan differently and move on.

The harder problem is that a programme creates interactions between controls, and those interactions disappear the moment the controls are examined separately.

Take a single design change. It becomes a contract variation. The variation drives a programme revision. The revision supports a claim for time and its associated cost. The claim resolves into a certified payment. The payment lands in a cash flow forecast that a lender or a board has already been shown.

Each of those steps sits in a different part of the organisation, and each is likely to be examined by somebody competent. What is not examined is the passage from one to the next.

Projects Advisors. Reuse: https://projects-advisors.com/licenceHow one design change propagates, and where functional reviews stopA single design change becomes a contract variation, then a programme revision, then a time and cost claim, then a payment certification, then a financing impact. Three functional reviews cover the chain between them: a technical review of the design change, a commercial audit of the variation through to the claim, and a finance audit of certification and financing. Each is competent within its own span. The two points where the chain passes from one review to the next are examined by neither.One change, six changes of handDesignchangeContractvariationProgrammerevisionTime andcost claimPaymentcertificationFinancingimpactTechnical reviewCommercial auditFinance auditEach review is competent inside its own span. The two markedtransfers belong to no function, so no functional plan schedules them.Illustrative. The number of reviews and where they abut varies by organisation; that they abut rather than overlap does not.
FIG. 01One design change, six changes of hand, and three reviews that abut rather than overlap. Illustrative: the number of reviews varies by organisation, the fact that they abut does not.

A technical reviewer can confirm the design change was necessary. A commercial audit can confirm the variation was instructed and valued under the right clause. A finance audit can confirm the certificate matched the valuation. All three can be right, and the question of whether the time claimed was actually caused by the change can still go unasked, because it belongs to the join between the second review and the third.

Interfaces are not a gap in coverage. They are a category that function-derived plans have no slot for.

Assurance already exists. That is not the same as coverage.

The strongest objection to any of this comes from the other direction, and a chief audit executive will raise it immediately. A large programme is not short of scrutiny. It has a PMO reporting progress, a commercial team administering the contract, cost consultants measuring and certifying, technical assurance reviewing design, an HSE function, a quality function, an engineer under the contract, lenders' advisers, regulators, and an external auditor looking at the numbers that come out of it. Adding internal audit to that list looks like duplication rather than coverage.

The objection is fair and it has an answer. Every one of those parties assures its own scope, on its own terms, reporting to whoever engaged it. Not one of them is positioned to say whether the whole arrangement adds up.

That is the question internal audit is uniquely placed to answer, and it is a different question from the ones above. Not "was the variation valued correctly", which the commercial team can answer, but "does the set of assurance this programme receives give the board reasonable confidence, and where does it overlap, conflict or stop". Mapping the assurance a programme actually receives, then identifying what nobody is looking at, is work that only the third line can do without a conflict, because everybody else in the list is reporting on their own work.

The IIA has since put this in its own words. The Statement of Position on the internal audit function's role in enterprise risk management, issued in July 2026, holds that the chief audit executive and the function are "uniquely positioned to help integrate organizationwide assurance and advice", and that with appropriate safeguards the chief audit executive may supervise other functions that also provide assurance services. Integration rather than addition is the stated contribution.

Coverage has depth, and a plan should be able to state it

Once interfaces are treated as a category, coverage stops being a list of engagements and becomes something with more than one axis. Functions run one way. Packages, phases or contracts run the other. Interfaces sit between cells rather than inside them.

The temptation is to draw that as a grid and count the cells that have been ticked, which is a mistake, because coverage is not binary. Auditing procurement across four packages might mean one central engagement that touches all four lightly, or one package tested to destruction while the others are assumed to behave the same way. Those produce very different assurance and a tick cannot tell them apart.

Programme audit coverage by function and package. Each function is examined to a different depth in each of four packages, and two functions, safety and environment and regulatory and stakeholder, are not covered in any package.

FunctionPackage APackage BPackage CPackage D
Procurement and awardCovered in depthTouchedTouchedTouched
Payment and certificationTouchedTouchedNot coveredNot covered
Change and variation controlNot coveredNot coveredCovered in depthNot covered
Mobilisation and resourcingTouchedNot coveredNot coveredNot covered
Safety and environmentNot coveredNot coveredNot coveredNot covered
Regulatory and stakeholderNot coveredNot coveredNot coveredNot covered

Every cell was somebody’s scope and every review reported adequate coverage of it. The finding is not in any cell. It is in the two rows that are empty across, which no individual review was scoped to notice.

FIG. 02The same grid with depth recorded rather than presence. Where a function was tested on one package only, the plan can describe that package and not the others.

Recording depth rather than presence changes what the grid is for. It stops being a scorecard and becomes a way of writing down what the plan will and will not be able to say at the end of the cycle. A function tested on one package supports a conclusion about that package. It does not support a conclusion about the programme, and the difference is invisible in a plan that lists engagements.

Depth is not the only dimension that matters. Timing, the population tested, whether the test was substantive or a walkthrough, and who performed it all change what a cell is worth. The useful discipline is not to build an elaborate matrix but to be able to answer a simple question about any part of the programme: what will this plan let us assert, and about what.

A plan that cannot explain its material coverage gaps cannot demonstrate that its omissions were risk-based. It may well have chosen them carefully. It cannot show that it did.

What the evidence shows, and where it stops

There is published evidence on the cost of finding things late, and it is worth being careful about what it covers.

The Association of Certified Fraud Examiners publishes the largest recurring study of occupational fraud, drawn from cases investigated by its own members. The 2026 edition covers 2,402 cases across 143 countries.

Median fraud loss by how long the scheme ran before detection. Schemes detected within six months had a median loss of 40,000 dollars. Schemes running more than five years had a median loss of 1.1 million dollars.

How long the scheme ranMedian loss
Detected within six months$40,000
Running more than five years$1.1m

Twenty-seven times the loss, for the same category of scheme. What changes is not the fraud but how long it was allowed to run, which is a property of the detection arrangements rather than of the fraudster.

FIG. 03Median loss per case, by how long the scheme ran before anyone found it. Only the two published points are plotted: drawing a curve between them would invent the shape of the relationship rather than show it.

Where a scheme was caught inside six months, the median loss was forty thousand dollars. Where it ran beyond five years, the median exceeded 1.1m. Across all cases the median scheme ran twelve months before detection.

Three further findings bear on a construction environment. Corruption, one of the three primary categories in the ACFE's classification and covering conflicts of interest, bribery, illegal gratuities and economic extortion, appeared in 45% of cases; bid rigging and invoice kickbacks sit inside that category. More than half of all cases involved either an absence of internal controls or the override of controls that existed, and override is the more interesting half on a programme, where schedule pressure is a standing argument for exception. And median losses caused by owners and executives ran more than nine times those caused by employees, which matters because a programme director typically holds more delegated authority than anyone else at that grade.

Now the limit. The study establishes something narrower than this argument needs. It shows that fraud losses are materially larger when detection takes longer. It does not show that auditing a capital programme earlier produces lower project losses, and no source cited here does. Fraud is also a subset of what goes wrong on a programme, and probably a small one next to weak change control and unmanaged interfaces.

What carries across is a mechanism rather than a finding: a control failure nobody is looking for compounds for as long as nobody looks. That inference is this publication's, not the ACFE's, and a reader is entitled to weigh it as an inference.

Early is not the same as embedded

There is a real objection to examining a programme continuously, and it is not about cost. A function that spends five years inside a live programme starts to be described, accurately, as part of the team that makes the programme work.

The IIA's current position on this is more permissive than a purist reading of it would be. Its July 2026 Statement of Position reaffirms that where a chief audit executive assumes second-line responsibilities, appropriate safeguards must be in place to protect the function's independence and its auditors' objectivity. So the question is whether the safeguards exist rather than whether the arrangement is permitted, whether they are written down, and whether the board can see them.

The distinction that survives is between examining a control and designing one. An audit can test whether change control operated on the variations raised last quarter without drafting the workflow, sitting on the change board, or clearing the next one. Where a function does take on the second, the safeguard has to be specific rather than asserted: whoever designed the control cannot be the person who later gives assurance over it.

The vocabulary matters more here than it looks, and it has now moved twice. The IIA retired the Three Lines of Defence in 2020, replacing it with the Three Lines Model and dropping the word "defence" because it framed risk as inherently bad and encouraged the lines to treat one another as boundaries. That 2020 paper has itself been superseded, by the July 2026 Statement of Position, which puts collaboration, coordination and reliance between the lines at the centre and addresses the board directly. The model has changed twice while the retired phrase has stayed in everyday use, including inside organisations that have formally adopted the replacement. Which is worth knowing before correcting anybody on it. The useful observation is not that the words are outdated but that a function presenting itself as a line of defence has already told the project team which side of something it is standing on.

The commercial arithmetic

The fee question does not need a survey to settle, only division.

An entity-wide internal audit engagement has a fixed number of days. Those days are allocated across the audit universe, weighted by whatever the risk assessment says. If the programme is one entry among twenty, its share starts near a twentieth and moves according to that weighting.

One of the balances that repays the days spent testing it

, read: Your contingency and their contingency are different money

Substantive testing of one significant variation, followed properly from instruction through valuation and records to certification, is not a one-day procedure. Neither is testing a claims register, or the interface agreements between packages, or the certification chain behind a monthly payment.

Any reader can do that division against their own plan, and the point of raising it is that the division is rarely done. This is not a criticism of the firms who bid. They price the scope they are given at the rates a competitive market sets. The mismatch belongs to the buyer: entity-wide coverage at a commodity rate and programme-grade probing are two specifications that cannot both be met at once.


Sources. The Institute of Internal Auditors, Statement of Position: Three Lines Model, Assurance and Advice in Support of Effective Governance and Statement of Position: The Role of the Internal Audit Function in Enterprise Risk Management, both issued 8 July 2026 and replacing the former position papers on those topics. The earlier The IIA's Three Lines Model: An Update of the Three Lines of Defense, 2020, is cited only for the retirement of the word "defence" and is marked by the IIA as superseded. The Institute of Internal Auditors, Global Internal Audit Standards, 2024 edition, effective 9 January 2025. Association of Certified Fraud Examiners, Occupational Fraud 2026: A Report to the Nations, published May 2026, covering 2,402 cases across 143 countries, and the ACFE Fraud Tree classification of occupational fraud. Figures 01 and 02 are original and illustrative; neither is derived from a published model.

ShareLinkedInX

Related reading

An extension of time is tested against records made during the delay

A claim for more time turns on three separate questions. Was the contract's notice procedure satisfied? Is the event one for which the contract allows an extension, or whose risk it otherwise places on the employer? Did it actually delay completion? Money is a separate claim, with its own proof of causation and amount. Each question is later tested against what was written down while the event was happening, by whichever party has to prove the point. Records do not create entitlement, a record of an event does not prove that it delayed completion, and the prevention principle does not rescue a claim under every contract or every governing law.

Read

Every award rule makes you publish the weighting. None makes you defend it.

The WTO agreement, the UNCITRAL Model Law and the EU directive all require the relative importance of the evaluation criteria to appear in the tender documents. None says what the weighting should be, and the Model Law's own commentary calls it discretionary. All three specify the arithmetic completely in exactly one situation, an electronic auction, where a machine does the ranking. Meanwhile a 70/30 split under the World Bank's own price formula prices one technical point at 3.4% of the contract and puts a 30 point quality lead beyond the reach of any price at all.

Read