A one-off health check answers the question at a point in time. Continuous Programme Assurance keeps answering it, every week, for the life of the programme. Independent visibility of programme health on a standing cadence, delivered by a senior practitioner, so risk surfaces the week it emerges and not three steering packs later. It sits between a point-in-time Health Check and a full client-side embed.
A point-in-time diagnostic is the right tool when you need a read before a decision. But programmes move. The governance that was sound in March drifts by June, the risk register goes stale, and the next independent read is another engagement away. For programmes in active delivery, the need is not a snapshot. It is a standing discipline that keeps the read current and keeps the parties delivering it honest.
The structural argument underneath both tiers is set out in a three-minute film on the Project Health Check page: why the only account of a programme that reaches its sponsor is written by the people that account describes, and what the Auditor-General found when the reported position was checked against evidence.
Three and a half minutes on why a single reading carries no direction, what a 2012 study of project owners in Australia, Norway and the United Kingdom found about detecting early warning signs, and what continuous assurance actually involves week to week.
Your programme is amber. Is that getting better, or worse? Continuous Programme Assurance. A health check answers that question, once, before a decision. It is accurate on the day you take it. Then it starts ageing. The governance that was sound in March has drifted by June.
A snapshot gives you a position. It cannot give you a direction. A risk that has been amber for eleven weeks is a different risk from one that turned amber last Tuesday. Both read amber. Only one of them is a warning.
This is not only our observation. Someone has studied how well a periodic assessment catches what is coming. In twenty twelve researchers in Australia, Norway and the United Kingdom studied how project owners detect early warning signs. Formal assessments at gateways catch the formalities. As complexity increases, they have more limited use.
So the answer is not a deeper assessment. A trend that moves inside a quarter is invisible at four samples a year. And four samples miss everything that never crosses a reporting threshold. A decision deferred at three consecutive steerings. A forecast revised four times. None of that triggers a report. All of it is movement. The answer is a shorter interval.
There is a second finding, and it cuts against the instrument. Two projects running formal health checks were studied as an early warning system. It worked, to a point. How well depended on how complex the project was, among other things. Complexity you cannot change. So what else decides it? As projects grow more complex, detection depends less on the instrument and more on experience and judgement.
So one senior practitioner holds the engagement. That is the whole model. Reading a risk register is not the same as recognising the silence that precedes a slipped milestone.
A week starts with the data the programme already produces. Where the numbers disagree, that is the finding. Mid-week we talk to the people doing the work, not only the people reporting on it. The week closes with a written read. One page. Not a dashboard. If nothing material moved, it says so, in three lines. Once a month the four weeks go in front of your sponsor and steering committee. We name the trend, not the incident.
Every quarter, the same assessment, scored against the same lenses. The instrument does not change. That is what makes a trend line mean something. The instrument is not what finds things. That happens in the week. And a practitioner scores it, not a model. A score a model produced cannot be cross-examined.
Assurance that cannot describe its own end is a subscription, not a discipline. Most engagements finish when the programme does. The better ending is your own governance getting strong enough that the second line is internal. The steering committee starts asking the questions we used to ask. When that happens we will say so, in the assessment. We have nothing to protect in your outcome. Not even this engagement.
A snapshot tells you where you are. Only a line tells you where you are going.
You are probably seeing one of these.
The health check you commissioned in March described a programme that no longer exists.
A risk has been amber for eleven weeks and nobody has named the pattern.
The vendor forecast has been revised four times and each revision was reasonable on its own.
A decision has been deferred at three consecutive steering committees.
You know the programme is drifting. You cannot evidence it to a board.
The next independent read is another engagement, another scoping conversation, and another six weeks away.
The same independence and senior read as a Health Check, held continuously across the delivery lifecycle.
A written read, one page, drawn from the data the programme already produces. RAG status with trend, risk movement, and milestone projection. The filter comes off the status so leadership sees the reality, not the version that survived the reporting line.
A facilitated forum with the sponsor and steering committee. The risk register is kept live, decisions are logged with owners and dates, and vendor and system integrator behaviour is challenged where it needs to be.
Trend analysis, intervention recommendations, and an independent read on partner-side performance and the outlook for the quarter ahead. The strategic view that keeps the programme aligned to its business intent.
An owner's representative posture from the client side. No stake in the systems being implemented, no vendor or integrator commissions. The judgement is ours and it answers to you alone.
Predictable, consistent, and defensible. A rhythm the sponsor can rely on and the delivery parties cannot quietly dismiss.
Written health read, one page. RAG with trend, risk movement, milestone projection. Behavioural signals tracked across the programme.
Facilitated QA forum with the sponsor and steering committee. Risk register reviewed. Decisions and actions logged with owners and dates.
Executive review. Trend analysis, intervention recommendations, and partner-side performance assessment.
Direct access to your practitioner for technical and methodology questions, and a read on vendor responses, within one business day.
A retainer invoiced quarterly, on a cycle that runs from six months to thirty-six. Two of the three tiers are a fixed price. You can read the number, pick the shape that matches your programme, and know what it costs without a conversation first.
$6,700 a month
per programme · invoiced quarterly
A single workstream, or a smaller programme that needs a standing independent read without the weight of a full-programme cadence. The rhythm is the same. The surface area is narrower.
$9,200 a month
per programme · invoiced quarterly
The default shape. A programme in active delivery, with real executive visibility, a live risk posture, and enough moving parts that a quarterly snapshot is out of date by the time it lands.
From $12,500 a month
per programme · invoiced quarterly
Larger or higher-risk transformation. Multi-vendor, board-reported, or carrying regulatory or public exposure. Principal-level engagement at the monthly forum and a read that holds up in front of a board.
All prices exclude GST. What sets the tier is the scale of what is under assurance. A single workstream and a multi-vendor transformation carry different risk, need a different cadence, and are worth different amounts to have independently watched. Enterprise is quoted rather than fixed because above a certain size the programme sets the number, not the tier.
Assurance that runs continuously has to be light enough to sustain. If it becomes a second programme, it competes with the one it is meant to protect.
A week starts with the data the programme already produces. Plans, risk and issue registers, change requests, test results, defect counts, financial actuals. We read what is there rather than asking anyone to prepare something for us. Where the numbers disagree with each other, that disagreement is itself a finding.
Mid-week is where the judgement happens. We talk to the people doing the work, not only the people reporting on it. A workstream lead who is confident on Tuesday and hedging on Thursday is telling you something a status report will not. That conversation takes twenty minutes and it is usually the most valuable twenty minutes of the week.
The week closes with a short written read. Not a dashboard. A page that says what changed, what it means, and what decision it creates. If nothing material moved, it says that too, and it says it in three lines. An assurance function that manufactures significance every week trains people to stop reading it.
One senior practitioner. That is the whole model and it is the part most often got wrong.
Continuous assurance fails when it is staffed by people who have not run a programme. Reading a risk register is not the same as recognising the specific silence that precedes a slipped milestone. The engagement is deliberately held by one practitioner because the value is in pattern recognition, and pattern recognition does not scale by adding people who lack the pattern.
The practitioner who scopes the engagement is the practitioner who delivers it. There is no handover to a delivery team after the sale. On a standing engagement that matters more than it does on a one-off diagnostic, because the value compounds with familiarity. Someone who has watched your programme for four months sees things in week seventeen that nobody could see in week one.
The obvious question is whether continuous assurance is just four health checks a year. It is not, and the difference is structural rather than commercial.
A health check is a point-in-time diagnostic. It goes deep, it produces a ranked set of findings, and it is designed to be commissioned when confidence has already dropped. Its strength is depth. Its limit is that it describes a programme as it was on the day you looked.
Continuous assurance trades some of that depth for continuity. It sees trajectory. A risk that has been amber for eleven weeks is a different risk from one that turned amber last Tuesday. Only one of those is visible in a snapshot. It also sees the things that never appear in a review because they never reach the threshold. Decisions that keep getting deferred. A vendor forecast that has been revised four times without anyone naming the pattern.
The practical distinction is when they help. A health check answers “is this programme in trouble”. Continuous assurance answers “is this programme still on the path we agreed”, every week, before the answer becomes obvious to everybody.
Four things, and deliberately no more.
A weekly written read, one page, covering what changed and what decision it creates. A monthly consolidated view that puts the four weeks together and names the trend rather than the incident. A quarterly assessment scored on the same five lenses used in the Project Health Check, governance, delivery, risk and issues, stakeholder and benefits, so the two are directly comparable. And direct access to the practitioner between those points. Assurance loses most of its value if you have to wait for the next scheduled output to ask a question.
What you do not receive is a portal to log into, a dashboard to interpret, or a monthly deck that restates the programme’s own reporting back to you. Those are the failure modes of assurance, not the product of it.
We run the five-lens assessment used in the Project Health Check across governance, delivery, risk and issues, stakeholder and benefits. That produces a scored opening position, agreed with you and written into the engagement before the standing cadence begins.
Everything after it is measured against that baseline. When the quarterly assessment says governance has moved, it is moving against a number you signed off in week four, not against a recollection of how things felt in March.
Five lenses, 120 diagnostic questions, 20 domains. Your opening position, agreed and signed off.
A written statement of what we report on, how often, and what triggers an out-of-cycle escalation.
Issued in the first delivery week. There is no onboarding period before the cadence starts.
Where a Project Health Check has been run in the preceding six months, it becomes the baseline and is not charged again.
The quarterly assessment is scored across five lenses, 20 domains and 120 diagnostic questions. They do not change between quarters, which is what makes a trend line mean something.
Is there clear accountability, and are decisions actually being made at the right level? The decision framework, the sponsorship model, escalation pathways, and whether the commercial terms are protecting you.
What is actually happening in delivery versus what leadership believes is happening. Schedule trajectory, quality, resource adequacy, and whether the team has the capability to execute.
What is being actively managed and what is being quietly ignored. Hidden dependencies, capability gaps, external constraint, and emerging risk that formal reporting has not surfaced yet.
Are expectations aligned with delivery reality, and is the sponsor present at the moments that matter? Whether the organisation is being carried with the programme or dragged behind it.
Is the outcome clearly defined, and is the programme still on course to deliver it? Business case rigour, scope stability, and whether the benefits that justified the investment remain achievable.
The assessment is scored by the person who has watched your programme. Five lenses, 120 diagnostic questions, 20 domains, and a judgement a human is accountable for.
Tooling has a place. It collects the data, it holds the trend, and it makes a weekly cadence affordable. It does not decide whether your governance is sound.
There is a reason we hold that line. A score a model produced cannot be cross-examined. When a board asks why a lens moved from amber to red, the answer has to come from someone who can be asked a second question.
Engagement cycles run from six months through to thirty-six. A shorter cycle suits a programme with a defined window, a stage gate to clear, or a delivery phase that ends on a known date. A longer cycle suits a programme where the read needs to hold across the whole lifecycle.
Length is where the value compounds. Someone who has watched your programme for two years sees things nobody could see in month one, and that pattern recognition is the part of this that cannot be bought quickly. Whichever cycle you choose, three things hold.
Your price is held for the full term. No annual escalation, no CPI adjustment, no renegotiation at renewal.
Where the engagement starts with a Project Health Check, that diagnostic is absorbed into the engagement rather than charged on top.
If we miss our cadence commitments more than twice in any rolling quarter, you can terminate on 60 days' notice with no balance payable.
The exit is tied to our performance, not to the programme's outcome. We do not own the programme, so we will not pretend to guarantee it. Outputs rescheduled by agreement, with planned absence notified in advance, are not misses.
An assurance engagement that cannot describe its own end is a subscription, not a discipline. So here is what finishing looks like.
Most engagements end with the programme. The system lands, the benefits case moves into the business, and the thing being assured stops existing. What happens to the benefits case after that handover is its own discipline. That is the ordinary case and we plan for it from the start.
The better ending is the other one. Your own governance gets strong enough that the second line is internal. The risks we would have surfaced are already on your register before we raise them. The steering committee is asking the questions we used to ask. When the quarterly assessment stops telling you anything you did not already know, we will say so, and we will say it in the assessment rather than waiting for you to notice.
We have nothing to protect in your outcome. That is the whole basis of the read, and it applies to our own engagement as much as it applies to anyone else's.
The committee's problem with a major programme is structural. You are asked to accept assurance about a programme from the programme, and the papers you receive have been written by the people whose performance they describe.
That is not a claim about honesty. It is what a single reporting line does. It is also the reason a second line exists everywhere else in your organisation, and the reason its absence around a large technology investment is usually the last thing anyone notices.
Continuous Programme Assurance gives the committee a read it did not commission from the party being read. Scored on the same five lenses every quarter, so the movement is comparable. Evidenced, so a position can be defended. And independent, because we hold no stake in the systems being implemented and take no vendor or integrator commissions.
What the committee gets is not a better report. It is a second opinion that was not written by the first.
Four situations where we will tell you to buy something else, or nothing.
If the programme lacks a delivery leader, assurance will describe the problem accurately every week and change nothing. That is Client-Side Delivery Leadership, and it is a different engagement.
Assurance is a second line. If there is no first line, there is nothing to be second to. Build the function first. That is Strategic PMO.
Continuous assurance earns its value through trajectory, and trajectory needs runway. With a few months left, a point-in-time Health Check will tell you more for a fraction of the cost.
If the read is wanted to settle an internal argument or support a decision already taken, we are the wrong firm. We will write what we find. That is the only thing we are actually selling.
Continuous Programme Assurance holds no stake in the systems being implemented and takes no vendor or integrator commissions. The read is a peer review, unfiltered because we have nothing to protect in the outcome. The tooling we use to hold the trend is a means. The judgement stays independent of it.
Independent assurance over the implementation partner, held on a standing weekly cadence for the life of the programme. A weekly written read, a monthly consolidated view, a quarterly assessment scored on five lenses, and direct access to the practitioner between those points. We hold an owner's representative posture from the client side. It is assurance over the programme, not management of it.
A health check is a point-in-time diagnostic. It goes deep and it describes the programme as it was on the day we looked. Continuous assurance trades some of that depth for continuity, so it sees trajectory. A risk that has been amber for eleven weeks is a different risk from one that turned amber last Tuesday. Only one of those is visible in a snapshot.
One senior practitioner. The practitioner who scopes the engagement is the practitioner who delivers it, and there is no handover to a delivery team after the sale. Continuous assurance fails when it is staffed by people who have not run a programme. The value is in pattern recognition, and pattern recognition does not scale by adding people who lack the pattern.
No. The five-lens assessment is scored by the practitioner who has watched the programme, against 120 diagnostic questions across 20 domains. Tooling collects the data and holds the trend. It does not form the judgement, and no part of the assurance read is generated by a model. Our free online assessments are a different thing and we are explicit about it. Those are self-scored by you, in a few minutes, to give you a starting position. They are not the assurance read and we never present them as one.
Focused is $6,700 a month, Programme is $9,200, and Enterprise starts at $12,500. Per programme, excluding GST, invoiced quarterly on a cycle of your choosing from six months to thirty-six. The number is set by the scale of what is under assurance, not by hours worked. Enterprise is quoted rather than fixed because above a certain programme size the programme sets the number.
Because below a certain programme size, a proportionate fee buys nothing. A weekly cadence, a monthly forum and a quarterly scored assessment cost what they cost. We would rather name a floor and hold it than sell a thinner version of the same thing and call it assurance.
If we miss our cadence commitments more than twice in any rolling quarter, you can terminate on 60 days' notice with no balance payable. The commitments are ours to keep, so the exit is tied to our performance and not to the programme's outcome. We do not own the programme, so we will not pretend to guarantee it.
No. We do not own delivery, approve scope changes, sign off vendor invoices or direct workstreams. Those accountabilities belong to you and to the parties contracted to deliver. Where you need embedded delivery leadership rather than independent oversight, that is Client-Side Delivery Leadership and it is a different engagement.
If your programme is in active delivery and you want an independent read that never goes stale, let's talk about what Continuous Programme Assurance looks like for your programme.