Minimum Assurance Requirements for Investment Tiers

In-scope digital investments are assigned one of three tiers under the DTA’s Investment Tiering Model. This model is designed to focus oversight attention on the most important investments and ensure lower risk and/or lower value investments are not unnecessarily burdened by excessive levels of assurance oversight. 

The tier is determined by the DTA in consultation with the proponent agency for an in-scope digital investment. 

All three tiers must show that assurance is being applied effectively throughout delivery and must also meet the minimum requirements. 

For more information, refer to the Assurance Framework for Digital & ICT Investments.

Minimum RequirementsTier 1
Flagship Digital 
Investments
Tier 2 Strategically Significant Digital InvestmentsTier 3 Significant Digital Investments

Assurance Plan updates 

Regularly update the Assurance Plan to maintain its currency, incorporating DTA reviews and gaining endorsement at the relevant governance body. Provide the updated version to the DTA.

Yes. Every 6 monthsYes. Every 12 months or as otherwise stated in Assurance PlanYes. As needed

Delivery Confidence Assessment (DCA)


Complete regular assurance activities that provide a DCA rating on the overall health of the investment

Yes. QuarterlyYes. BiannualYes. As needed

Material Variations to Assurance 

Advise the DTA when there is a material variation from planned assurance arrangements.

YesYesYes

Assurance Reports 

Provide final assurance reports to the DTA for oversight purposes. 

Note: Gateway Review reports will be handled in accordance with agreed protocols for the handling of Gateway material.

Yes. Also provide draft assurance reports and regular reporting on progress implementing agreed assurance recommendationsYes. Also provide summary reporting to the DTA on recommendation implementation progressYes
Terms of Reference (ToR) for External Assurance ActivitiesYes. Agree ToR for external assurance activities with the DTA prior to commencementYes. Share ToR for external assurance activities as endorsed by the Senior Responsible Official to the DTA for comment prior to commencementN/A
DTA Representation on GovernanceYes. Must include DTA on the investment’s primary governance committee, as an observerYes. DTA representation on the investment’s governance committee as an observer – if requiredN/A
Approach to Market for AssuranceYes. When approaching the market for independent assurance providers, agree approach to market materials with the DTAN/AN/A

Downloadable resource

Minimum assurance requirements

Connect with the digital community

Share, build or learn digital experience and skills with training and events, and collaborate with peers across government.