Assurance planning requirements

Use structured assurance planning to proactively design fit-for-purpose and proportionate assurance arrangements for in-scope investments. Effectively applied assurance supports the successful delivery and the realisation of expected benefits for funded investments. 

Regardless of tier, all in-scope investments are required to agree an Assurance Plan with the Digital Transformation Agency (DTA) prior to investment decision. This plan must show how the investment will meet the 5 Key Principles for Good Assurance as well as the requirements applicable to the tier. Investment submissions must include a specific recommendation to seek Cabinet agreement for the Assurance Plan. The DTA will support you to prepare the Assurance Plan and provide advice.

Minimum requirements by tier

Assurance arrangements must address the 5 Key Principles for Good Assurance and meet the minimum requirements laid out below. 

Tier 1 and Tier 2 minimum requirements 

The DTA must be satisfied you have: 

  • budgeted for independent assurance
  • mapped planned assurance activities to key risks, milestones and decision points – the DTA will assess whether there is a sufficiently clear link between planned activities and achieving investment outcomes and benefits. The DTA will also check overlap is minimised and assurance is proportionate to risk
  • integrated assurance into your governance approach – this includes in the terms of reference for governance boards 
  • identified who is accountable for achieving and maintaining a fit for purpose assurance approach for the investment – this includes regularly reviewing the Assurance Plan
  • put arrangements in place to meet the mandatory DTA assurance oversight requirements during implementation
  • planned for regular assurance activities that provide a Delivery Confidence Assessment (DCA) rating, undertaken by suitably skilled, independent and objective assurance providers – you must use the DCA scale during implementation. DCA cadence should align with assurance implementation requirements.

Tier 3 minimum requirements

The level of detail required for Tier 3 investments will be agreed between the DTA and the agency. 

The DTA must be satisfied that you have: 

  • put assurance arrangements in place which align to the 5 Key Principles for Good Assurance
  • planned assurance arrangements which are commensurate to the risk and complexity of the proposed investment, which will support good decision-making 
  • considered and included assurance activities that result in DCA ratings – as needed. 

How DTA assesses Assurance Plans 

The level of assurance applied to an investment must always be commensurate to risk and complexity. The DTA will assess Assurance Plans with a focus on ensuring that they meet the 5 Key Principles for Good Assurance. This includes by ensuring all plans are: 

  • focussed on key risks and the areas of most importance to successful delivery 
  • designed to maximise the value of assurance to decision-making, including by timing activities to feed into key decisions 
  • have clear governance of assurance arrangements, with a focus on maximising the value of assurance including through timely implementation of recommendations 
  • manage the compliance burden placed on teams through assurance activities, including by avoiding overlap. 

The DTA does not start from a position that every investment requires more assurance. In fact, if the DTA’s assessment of proposed arrangements suggests that there is excessive assurance, or that assurance from multiple sources needs to be better coordinated, the DTA may encourage an agency to reconsider the coverage or frequency of assurance activities. 

Assurance and Benefits Management Policy

Better practice benefits management applies to all digital investments irrespective of size, scale, and complexity. 

Without a clear understanding of the benefits an investment is funded to realise, decisions made during an investment’s implementation can result in the investment failing to achieve its intended outcomes. 

Suitable and measurable benefits should be identified during planning and a culture of reporting benefits embedded in the governance and assurance activity arrangements. This approach not only enables governance boards to manage and monitor investments to determine whether change is required but can be used as a recovery action to refocus investments on delivering what is important or essential. 

The DTA assess alignment and compliance with the Benefits Management Policy (BMP) during the Digital Capability Assessment Process (DCAP). Learn more about the DCAP process. 

Benefits management remains central to investment delivery, including tracking and capturing new benefits, managing variations, reporting progress, implementing change management, adopting behavioural strategies to maximise benefits, and formally transferring responsibility for benefits realisation and monitoring to Benefits Owners at project closure. Regular reviews of benefits realisation progress occur throughout and beyond delivery.

Governance board participation

For all Tier 1 and some Tier 2 investments, the DTA participates as an observer on investment governance boards to monitor assurance arrangements. 

This role includes ensuring that the arrangements agreed in the Assurance Plan are implemented and the 5 Key Principles for Good Assurance are effectively applied. 

Lead agencies are responsible for advising the DTA of governance board information. Agencies must also ensure the governance board terms of reference clearly identify DTA participation as an observer, as well as the role of the governance board. This includes monitoring progress and implementing agreed recommendations.

Relationship with the Gateway Review Process 

You may be required to engage with the Department of Finance to determine if any Australian Government Assurance Reviews, including Gateway Reviews, will be recommended for an investment.

Assurance arrangements coordinated by the Department of Finance and the DTA are complementary to one another. When determining whether an investment’s proposed assurance arrangements are fit-for-purpose and meet the requirements under the Assurance Framework, the DTA takes into consideration whether Australian Government Assurance Reviews are expected to be applied.

The Digital Experience Policy

Excellent digital services focus on the end-user. The Digital Experience Policy (DX Policy) ensures this by mandating 4 standards that prioritise usability and accessibility from the outset of digital investments. Agencies are required to demonstrate compliance with the DX Policy and any applicable standards, including during project delivery. More information on how the DTA is ensuring compliance with the DX Policy is outlined in the Digital Experience Policy (DX Policy): compliance, reporting and exemption guide.

Investments in-scope of the DX Policy should include relevant assurance activities in their Assurance Plans which ensure digital experiences enabled through the project will meet the policy requirements. This might include requiring that DX Policy compliance be assessed as part of a solution design review and/or as part of go-live assessments.

Assurance implementation requirements

Connect with the digital community

Share, build or learn digital experience and skills with training and events, and collaborate with peers across government.