Well-articulated benefits are critical in informing digital and ICT funding decisions. However, the DTA acknowledges that benefits articulation and management requires ongoing refinement throughout the life of an investment. As such, the DTA differentiates requirements for early and final-stage investments in the Digital Capability Assessment Process provided that the proposal:
From 1 July 2021, the DTA has whole-of-government responsibility for managing strategic coordination and oversight functions for Australian Government’s digital and ICT investments across their project lifecycle. To give effect to the DTA’s mandate, the Government has agreed to the Whole-of-Government Digital and ICT Investment Oversight Framework (IOF).
Aligning to the Government’s Budget cycles, the IOF provides a way for the DTA to engage and support the Government in effectively overseeing its digital and ICT-enabled investment portfolio. The IOF outlines six states across the investment lifecycle where agencies are required to engage with the DTA: Strategic Planning, Prioritisation, Contestability, Assurance, Sourcing and Operations.
Agencies bringing forward or implementing digital and ICT investments must plan for and implement assurance arrangements which meet the requirements of the Assurance Framework.
The Assurance Framework must be adhered to if:
The Assurance Framework defines assurance as 'independent and objective assessments and evaluations undertaken by people and entities separate to the delivery team and the Senior Responsible Official (SRO), to support decision-making'.
The DTA is responsible for providing Ministers, the Secretaries’ Digital and Data Committee and other key stakeholders with confidence that digital investments are being designed well, are optimised to deliver value – and if funded, will achieve their investment objectives. This is achieved through the DTA’s assurance oversight role during key states of the investment.
During the proposal stage, the DTA will engage to support the agency to develop and agree an Assurance Plan. During the delivery stage, the DTA will engage to ensure proposed assurance is mobilised and to monitor those assurance activities and their outputs.
To ensure fit-for-purpose assurance is planned for digital and ICT investments, agencies are required to engage with the DTA during the Contestability state. Planning also continues throughout the Assurance state. This engagement follows a four-step process outlined in the Assurance Framework:
Step 1 Confirm the applicable investment tier: The Tier of an investment is determined by the DTA, in consultation with the agency and in context of the risk, complexity and strategic importance.
Step 2 Plan for assurance: Applying the Key Principles for Good Assurance, agencies are required to plan for assurance, addressing the minimum requirements applicable to the investment’s Tier rating.
Step 3 Use assurance effectively during delivery: Agencies must deliver according to the approved Assurance Plan, continue to apply the Key Principles for Good Assurance, and meet ongoing reporting and engagement requirements.
Step 4 Follow the escalation protocols (if required): Investments which encounter difficulty during delivery will receive additional DTA oversight and support.
The tier determined during the Contestability state will drive the assurance requirements for that investment.
Regardless of tier, all in-scope investments are required to agree an Assurance Plan with the DTA prior to Cabinet decision (some exceptions apply) – which drives the mobilising and monitoring of assurance during delivery.
Tier 1 investments must show that assurance is being applied effectively during delivery, aligning to the Key Principles for Good Assurance, by meeting the following minimum requirements:
Tier 2 investments must show that assurance is being applied effectively during delivery, aligning to the Key Principles for Good Assurance by meeting the following minimum requirements:
Tier 3 investments must show that assurance is being applied effectively during delivery, aligning to the Key Principles for Good Assurance by meeting the following minimum requirements:
Once an investment is funded by Cabinet through a Budget cycle, the DTA’s focus turns to monitoring the implementation of agreed assurance arrangements and to ensuring minimum assurance requirements (aligning to the Tier) are met.
The DTA will start its assurance oversight engagement when delivery of an approved investment commences (or when an in-flight program/project adopts the Assurance Framework requirements). The DTA will request the relevant SRO and investment delivery team to:
Further information and enquiries:
In-scope digital investments are assigned one of three tiers under the DTA’s Investment Tiering Model. This model is designed to focus oversight attention on the most important investments and ensure lower risk and/or lower value investments are not unnecessarily burdened by excessive levels of assurance oversight.
The tier is determined by the DTA in consultation with the proponent agency for an in-scope digital investment.
All three tiers must show that assurance is being applied effectively throughout delivery and must also meet the minimum requirements.
For more information, refer to the Assurance Framework for Digital & ICT Investments.
| Minimum Requirements | Tier 1 Flagship Digital Investments | Tier 2 Strategically Significant Digital Investments | Tier 3 Significant Digital Investments |
|---|---|---|---|
Assurance Plan updates Regularly update the Assurance Plan to maintain its currency, incorporating DTA reviews and gaining endorsement at the relevant governance body. Provide the updated version to the DTA. | Yes. Every 6 months | Yes. Every 12 months or as otherwise stated in Assurance Plan | Yes. As needed |
Delivery Confidence Assessment (DCA)
| Yes. Quarterly | Yes. Biannual | Yes. As needed |
Material Variations to Assurance Advise the DTA when there is a material variation from planned assurance arrangements. | Yes | Yes | Yes |
Assurance Reports Provide final assurance reports to the DTA for oversight purposes. Note: Gateway Review reports will be handled in accordance with agreed protocols for the handling of Gateway material. | Yes. Also provide draft assurance reports and regular reporting on progress implementing agreed assurance recommendations | Yes. Also provide summary reporting to the DTA on recommendation implementation progress | Yes |
| Terms of Reference (ToR) for External Assurance Activities | Yes. Agree ToR for external assurance activities with the DTA prior to commencement | Yes. Share ToR for external assurance activities as endorsed by the Senior Responsible Official to the DTA for comment prior to commencement | N/A |
| DTA Representation on Governance | Yes. Must include DTA on the investment’s primary governance committee, as an observer | Yes. DTA representation on the investment’s governance committee as an observer – if required | N/A |
| Approach to Market for Assurance | Yes. When approaching the market for independent assurance providers, agree approach to market materials with the DTA | N/A | N/A |