The situation
The organisation was happy with its IT service delivery. This was not a rescue engagement: services worked, the provider relationship was sound, and nobody was agitating for change.
The board’s concern was different, and more sophisticated: business risk. The organisation depended heavily on one support arrangement, and the board recognised that satisfaction with day-to-day service says nothing about the risk concentrated in that dependency. As part of appropriate governance practices, the board requested an independent IT review and vendor assessment.
Why independent advice mattered
Assurance sourced from the party being assured about is not assurance. The incumbent provider could hardly assess the risk of depending on itself, and internal IT, however capable, sits inside the arrangement being reviewed.
This is governance work in its purest form: the board discharging its duty by obtaining a view that no interested party could shape. Our only role was to give the board an honest, independent answer.
What we did
The review tested the arrangement the organisation depended on, not just the service it received.
Reviewed IT service delivery independently
We assessed the actual quality and fitness of the IT service delivery, testing whether the organisation’s satisfaction was well founded.
Assessed the vendor and the arrangement
We conducted a vendor assessment covering capability, commercial position and the organisation’s dependency on the arrangement.
Examined the concentrated business risk
We assessed the risk position created by the support arrangement: continuity, key dependencies, and what would happen to the business if the arrangement failed or changed.
Reported to the board
We delivered findings in governance terms the board could act on: what is sound, what carries risk, and what prudent mitigation looks like.
The outcome
- Independent confirmation of where the organisation’s satisfaction with IT service delivery was well founded
- An objective assessment of the vendor and the organisation’s dependency on the support arrangement
- A clear view of the concentrated business risk and the practical mitigations available
- Board-level assurance obtained the way good governance requires: independently
The board did not have to choose between trusting its provider and doubting it. It had an independent basis for confidence, and a clear-eyed view of the risks that confidence should be conditioned on.
Is your assurance independent, or just familiar?
If the board’s comfort about IT rests on reporting from the parties being assessed, an independent review is the governance step that fixes it.
No pitch, no sales process. Just a senior view.





