Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
192 changes: 192 additions & 0 deletions .arckit/templates/uk-teal-assurance-template.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,192 @@
# Integrated Assurance and Approval Plan (IAAP) — [INITIATIVE_NAME]

> **Template Origin**: Community | **ArcKit Version**: [VERSION] | **Command**: `/arckit:uk-teal-assurance`

## Document Control

<!-- DOC-CONTROL-HEADER -->
<!-- Resolved at command-execution time per _partials/RENDERING.md. -->

## Revision History

| Version | Date | Author | Changes | Approved By | Approval Date |
|---|---|---|---|---|---|
| [VERSION] | [YYYY-MM-DD] | ArcKit AI | Initial creation from `/arckit:uk-teal-assurance` command | PENDING | PENDING |

---

## Teal Book Version

This Integrated Assurance and Approval Plan is aligned to the **UK Government Teal Book V1** (in trial period to **31 December 2026**), **GovS 002 (Project Delivery Functional Standard)**, and the **IPA / NISTA assurance and approvals regime**. Verify every cited part, chapter, gate name, and threshold against the live sources — <https://projectdelivery.gov.uk/teal-book/home/> and <https://www.gov.uk/government/collections/assurance-and-approvals> — before reliance, as terminology and structure may change during or after the trial.

> ⚠️ This is a **planning artefact only**. It is **not** an assurance opinion and does **not** constitute an IPA/NISTA assurance review, a Gateway Review, or any formal departmental assurance verdict. It must be agreed with the SRO, the department's assurance function, and — for GMPP / major projects — NISTA before reliance.

---

## Executive Summary

[One to two paragraphs: the initiative under assurance; whether it is a portfolio, programme, or project and its risk/value tier; the number of approval points and planned assurance activities; the headline of how assurance has been made proportionate and joined-up; confirmation that each major approval point has aligned assurance timed to inform it; any misalignment, duplication, or evidence gap flagged for the SRO; and the recommended next assurance steps.]

| Field | Value |
|---|---|
| **Initiative type** | [Portfolio / Programme / Project] |
| **Risk / value tier** | [Low / Medium / High / GMPP] |
| **GMPP entry** | [Yes / No / Likely — confirm with NISTA] |
| **SRO** | [Name and role] |
| **Department / arm's-length body** | [Organisation] |
| **Approval points mapped** | [N] |
| **Planned assurance activities** | [N] |
| **Next assurance milestone** | [Type + indicative date] |
| **Plan owner** | [Name and role] |
| **Assessment date** | [YYYY-MM-DD] |

---

## 1. Purpose and Scope

[State the purpose of this IAAP: to coordinate all planned assurance against the initiative's approval points so assurance is proportionate to risk and value, joined-up across providers, and timed to inform decisions rather than duplicate effort. Define the scope — which life-cycle stages, which delivery components, and which assurance providers are in and out of scope. Reference the Teal Book and GovS 002 [TEAL-CN] [GOVS002-CN].]

### 1.1 Objectives of integrated assurance

- Ensure each key decision is informed by timely, independent assurance.
- Avoid duplicate, overlapping, or uncoordinated reviews of the same evidence.
- Scale assurance intensity to the initiative's risk, value, and complexity.
- Maintain a single, current view of planned and completed assurance for the SRO.

### 1.2 Out of scope

[State what this plan does not cover — e.g. business-as-usual operational audit, statutory financial audit, supplier-internal assurance.]

---

## 2. Assurance Governance and Accountability

| Role | Holder | Assurance responsibility |
|---|---|---|
| Senior Responsible Owner (SRO) | [Name] | Owns the IAAP; accountable for delivery and for acting on assurance findings |
| Departmental assurance function / PMO | [Function] | Agrees and coordinates the plan; 2nd-line oversight |
| Internal audit | [Function] | 3rd-line independent assurance |
| IPA / NISTA | [Contact] | Independent Gateway / PAR / PVR reviews; GMPP oversight |
| Approving authority / investment committee | [Body] | Takes approval decisions at each point |
| Project / programme board | [Body] | Day-to-day governance; commissions 1st/2nd-line assurance |

---

## 3. Approvals Map

[The business-case approval points (Green Book five-case model — SOBC → OBC → FBC [GREENBOOK-CN]) and any portfolio, spend-control, departmental investment-committee, or HMT/NISTA approval gates. If the business case is absent, mark provisional points `[PENDING — run /arckit:sobc]`.]

| # | Approval point | Decision authorised | Approving authority | Delegation threshold engaged | Expected date | Status |
|---|---|---|---|---|---|---|
| AP1 | Strategic Outline Case (SOBC) | Strategic fit / programme start | [Investment committee / HMT] | [£ threshold] | [YYYY-MM] | [Planned] |
| AP2 | Outline Business Case (OBC) | Preferred option / procurement strategy | [Authority] | [£ threshold] | [YYYY-MM] | [Planned] |
| AP3 | Full Business Case (FBC) | Investment / contract award | [Authority] | [£ threshold] | [YYYY-MM] | [Planned] |
| AP4 | Delivery / go-live decision | Readiness for service | [Authority] | [n/a] | [YYYY-MM] | [Planned] |
| AP5 | Operations / benefits decision | Continuation / benefits realisation | [Authority] | [n/a] | [YYYY-MM] | [Planned] |

---

## 4. Integrated Assurance Schedule

The central coordinated schedule of planned assurance activities across the life cycle. Each activity is timed to *precede* the approval point it informs, with adequate lead time for findings to be actioned.

| ID | Assurance type | Line of defence | Timing (stage / relative to approval point) | Decision it informs | Responsible body | Status |
|---|---|---|---|---|---|---|
| AS1 | IPA Gateway Review 0 — Strategic Assessment | 3rd | Programme inception | AP1 (SOBC) | IPA / NISTA | [Planned] |
| AS2 | IPA Gateway Review 1 — Business Justification | 3rd | Before SOBC approval | AP1 (SOBC) | IPA / NISTA | [Planned] |
| AS3 | IPA Gateway Review 2 — Delivery Strategy | 3rd | Before OBC / procurement | AP2 (OBC) | IPA / NISTA | [Planned] |
| AS4 | IPA Gateway Review 3 — Investment Decision | 3rd | Before FBC / award | AP3 (FBC) | IPA / NISTA | [Planned] |
| AS5 | IPA Gateway Review 4 — Readiness for Service | 3rd | Before go-live | AP4 | IPA / NISTA | [Planned] |
| AS6 | IPA Gateway Review 5 — Operations & Benefits | 3rd | Post-implementation | AP5 | IPA / NISTA | [Planned] |
| AS7 | Project Assessment Review (PAR) | 3rd | [Stage, GMPP] | [AP] | IPA / NISTA | [Planned] |
| AS8 | Project Validation Review (PVR) | 3rd | [If at-risk] | [AP] | IPA / NISTA | [Conditional] |
| AS9 | Internal audit | 2nd / 3rd | [Periodic] | [Control assurance] | Internal audit | [Planned] |
| AS10 | Technical / architecture review (conformance) | 2nd | [Design stages] | [AP2 / AP3] | [Design authority] | [Planned] |
| AS11 | Commercial assurance | 2nd | [Procurement] | AP3 (FBC) | [Commercial function] | [Planned] |
| AS12 | Management self-assurance (stage-gate readiness) | 1st | Continuous | [All] | Project team | [Ongoing] |

> Lead-time check: confirm each 3rd-line review above completes with sufficient lead time for its recommendations to be acted on before the corresponding approval-point date. Flag any activity that does not precede its decision.

---

## 5. Three Lines of Defence Mapping

| Line | Role | Planned activities (from §4) | Independence check |
|---|---|---|---|
| **1st line** | Management / delivery owns risk and control | [AS12, stage-gate readiness, self-assessment] | Owned by delivery team |
| **2nd line** | Functional oversight & assurance | [AS10 technical/architecture, AS11 commercial, departmental PMO oversight] | Independent of delivery team; reports to assurance function |
| **3rd line** | Independent assurance | [AS1–AS9 — IPA/NISTA reviews and internal audit] | Fully independent of management and 2nd line |

[Confirm the third line is genuinely independent and not conflated with first- or second-line activity. Each activity in §4 maps to exactly one line.]

---

## 6. Proportionality Assessment

[Scale assurance intensity to the initiative's risk, value, and complexity per GovS 002 and the IPA/NISTA risk tiering. Justify the chosen intensity. The final tiering is set by the department's assurance function / NISTA, not by this artefact.]

| Factor | Assessment | Implication for assurance intensity |
|---|---|---|
| Whole-life value | [£] | [Drives spend-control / GMPP threshold] |
| Innovation / novelty | [Low / Medium / High] | [More novel → more frequent review] |
| Delivery complexity | [Low / Medium / High] | |
| Risk profile (from RISK register) | [Highest residual risks] | [Assurance targets these] |
| GMPP status | [Yes / No / Likely] | [GMPP → mandated PARs, IPA reporting, DCAs] |
| **Resulting tier** | **[Low / Medium / High / GMPP]** | **[Light-touch / standard / full Gateway sequence]** |

---

## 7. Gateway / Assurance-Review Readiness Checklist

Evidence and artefacts a review team will expect. Status reflects current readiness, with the owning ArcKit artefact cross-referenced where it supplies the evidence.

| Evidence / artefact | Required for | Owning source | Readiness status |
|---|---|---|---|
| Business case (five-case) | Gates 1–3 | `ARC-{PID}-SOBC-*` / OBC / FBC | [Ready / Partial / Pending] |
| Risk register (Orange Book) | All gates | `ARC-{PID}-RISK-*` | [ ] |
| Delivery plan / schedule | Gates 2–4 | `ARC-{PID}-PLAN-*` | [ ] |
| Benefits map / realisation plan | Gates 1, 5 | [Source] | [ ] |
| Architecture / design artefacts | Gates 2–4 | `ARC-{PID}-HLDR-*` / `DLDR-*` | [ ] |
| Architecture conformance assessment | Gates 2–4 (technical assurance) | `ARC-{PID}-CONF-*` | [ ] |
| Commercial / procurement documents | Gates 2–3 | [Source] | [ ] |
| Dependency / interface map | Gates 2–4 | [Source] | [ ] |
| Delivery Confidence Assessment (if GMPP) | PAR / GMPP reporting | [Source] | [ ] |
| Stakeholder / governance evidence | All gates | `ARC-{PID}-STKE-*` | [ ] |

---

## 8. Action and Recommendation Tracker

[Seed from any prior Gateway / PAR / PVR recommendations found in `external/`. Track each to closure.]

| Ref | Source review | Recommendation | Priority | Owner | Due date | Status |
|---|---|---|---|---|---|---|
| R1 | [Review] | [Recommendation] | [Critical / High / Medium] | [Owner] | [YYYY-MM-DD] | [Open / In progress / Closed] |

---

## 9. Plan Maintenance

This IAAP is a living document. It is reviewed and re-agreed at each approval point and whenever the initiative's risk profile, scope, or schedule changes materially. The review cadence is recorded in Document Control. The plan must be re-agreed with the SRO and the department's assurance function (and NISTA for GMPP) after any major change.

---

## External References

| Doc ID | Title | Source | Used in |
|---|---|---|---|
| TEAL | The Teal Book (V1, trial to 31 Dec 2026) | Government Project Delivery / NISTA | Throughout |
| GOVS002 | GovS 002 Project Delivery Functional Standard | Cabinet Office / GPDF | §1, §6 |
| GREENBOOK | The Green Book — appraisal and evaluation | HM Treasury | §3 |
| IPA-ASSURE | Assurance and approvals (collection) | IPA / Cabinet Office | §4, §5 |
| NISTA | National Infrastructure and Service Transformation Authority | NISTA | §2, §4, §6 |

> Verify each reference against its source before reliance — gov.uk pages may return HTTP 403 to automated fetches and are updated without notice. The Teal Book is in a trial period and its structure may change.

---

**Generated by**: ArcKit `/arckit:uk-teal-assurance` command
**Generated on**: [YYYY-MM-DD]
**ArcKit Version**: [VERSION]
**Project**: [PROJECT_NAME]
**Model**: [AI_MODEL]
Loading
Loading