Project and Program Assurance

Delivering independent assurance that strengthens governance, manages risk and improves delivery confidence across transformation programs

Ways we can help

Our approach is shaped by three core pillars that guide how we deliver assurance and support program outcomes:

Governance and Risk Management

  • Strengthen governance, oversight and decision making structures within the program.
  • Identify and manage material risks, issues and interdependencies early.
  • Provide clear, decision ready insights to sponsors, steering committees and governance forums.

Integrated Assurance and Planning

  • Design integrated assurance plans across the Three Lines of Defence.
  • Align assurance activities to enterprise risk appetite, program risk profiles, milestones and critical decision points, including assessment of delivered risks and controls transitioned into BAU.
  • Maintain and update assurance plans as programs evolve, ensuring ongoing alignment to delivery risk.

Independent Assurance Delivery

  • Deliver targeted deep dive assurance reviews across high‑risk or complex areas of the program.
  • Conduct stage‑gate and delivery readiness reviews to assess whether key criteria have been met prior to exiting the stage or at program closure.
  • Provide embedded assurance support within program governance structures and forums.

Our service offering

We deliver integrated transformation assurance across the full delivery lifecycle, providing comprehensive coverage and action based outcomes.

Our approach combines integrated assurance planning, targeted assurance reviews, and ongoing embedded assurance to provide a clear, coordinated view of program risk and performance. We provide independent insight into whether programs are on track and where targeted intervention is required across the delivery lifecycle.

Integrated Assurance and Planning

We design and maintain integrated assurance plans across Line 1, Line 2, and Internal Audit, aligned to program risks, delivery milestones and assurance priorities. This includes identifying assurance gaps and overlaps, improving coordination across providers and updating plans as programs evolve.

Targeted Assurance Reviews

Program Set‑Up and Baseline Reviews

We assess whether foundational program elements are in place, including governance, business case, benefits, scope, delivery approach and risk management, third-party management, resourcing, financials and baseline planning. These reviews inform the integrated assurance plan and identify early delivery risks.

Targeted Deep‑Dive Reviews

We perform targeted deep‑dive assurance reviews across high‑risk or complex areas, including program governance, delivery controls, testing and defect management, data migration, delivered operational and technology controls, organisational change and operational readiness.

Stage‑Gate and Delivery Readiness Reviews

We conduct structured reviews at key delivery points to assess whether readiness criteria are appropriate and have been met. This includes solution viability, business readiness, test quality, data migration progress, operational transition, and go‑live governance.

Post‑Implementation and Benefits Realisation Reviews

We evaluate outcomes against objectives, including benefits realised, risks introduced and controls established by the program within BAU. We review the robustness of transition to BAU and capture lessons learned to support ongoing improvement in future program and project delivery.

Ongoing Embedded Assurance

We also operate as an embedded assurance function within the program, designing and maintaining integrated assurance plans across the Three Lines of Defence, attending key governance forums and providing independent input on the management of program risk.

What sets us apart

01

Deep expertise

Leveraging deep risk, technology, assurance, and delivery expertise, we design and implement right‑sized assurance frameworks and plans. We work across the lifecycle to identify material risks early, provide clear, decision‑ready insight, and maintain momentum as programs evolve.

02

Practical experience

Our team combines risk management and assurance expertise with practical hands-on delivery experience, reinforced by proven methodologies and tools, helping programs stay aligned to outcomes. We have supported major transformation initiatives across sectors including financial services, government, energy, and telecommunications.

03

Tailored approach

We recognise that every program is different. Our approach is pragmatic and tailored to each program, reflecting what is happening on the ground rather than applying a one-size-fits-all methodology.

04

Integrated assurance

We provide independent, decision-ready insight across governance, risk and delivery, helping sponsors and executives focus on the issues that matter most and intervene early when required.

Australian Major General Insurer

Core Banking Implementation Project Assurance

Amstelveen was engaged to support the delivery of a comprehensive assurance program for a major core platform modernisation and digitisation program at an Australian bank and their NZ-based subsidiaries. This involved working collaboratively with program management to re-design their strategic program risk profile and reporting process, which was used as an input to design a comprehensive 3-year assurance plan, aligned to the uplifted risk and complexity profile. Amstelveen supported the delivery of go-live readiness assessments, delivered risk and control audits and deep dive assessments covering compliance, organisational change, data migration, system testing, product management and model management (among others). All outcomes were presented to the Program Steering Committee, and Board Risk Committee.

State Government Agency

Program and Quality Assurance Support

As part of the PMO of a major finance transformation program, Amstelveen managed the planning and coordination of all Program Assurance and Quality Assessments. Working with the departments co-source internal audit team, and NSW Gateway reviewers, we co-designed scopes that were fit for purpose, and met the requirements of the Program Steering Committee and government policy guidelines. This included working with Workstream Leads, Project Managers and the Program Director to develop a tool that applied an agreed criteria to assess program activity to drive an appropriate assurance response.

Major Australian Bank

Non-Financial Risk Uplift Program

Amstelveen was pivotal in managing and executing a major Australian Bank's Non-Financial Risk Evolution program. This program involved designing and executing a risk uplift program covering RCSA execution, control assurance, risk reporting and risk system optimisation. This involved the complete restructuring of organisational RCSAs around ~90 product-based Value Chains and ~50 central function capability maps, the mapping of those Value Chains with stakeholders and the subsequent execution of RCSAs across them. Amstelveen resources also supported the design and implementation of operational risk frameworks and supported business areas with control uplift and control design activities.

Australian Liability Insurer

Core Transformation Program Assurance

Amstelveen was engaged by the Internal Audit department of an Australia liability insurer to perform program assurance over a Core Transformation. This involved the execution of a series of program assurance reviews during program initiation, design, build and implementation. Our reviews covered both program governance/management and technology-specific scope areas. This included performing model validation for the policy pricing model implemented within the platform. Ultimately our reports and team provided input on the Steering Committee go-live decision and we represented the client in pre go-live meetings with APRA.

Ready to strengthen delivery confidence in your program?

Get in touch for any questions, or if you’d like to discuss working together