On this page
Governance is often described through structures: boards, committees, working groups and reporting cycles. Those structures matter only where they perform a defined function.
The Public Governance, Performance and Accountability framework places responsibility on Commonwealth entities to govern resources, performance and accountability. At program level, that requires more than regular reporting. It requires a reliable path from source evidence to analysis, recommendation, authorised decision and implementation.
Begin with decision rights
A governance model should start with the decisions the program expects to make.
For each material decision, define:
- the decision owner and approving authority
- any delegation or reserved matter
- the evidence required
- contributors and advisers
- consultation or concurrence requirements
- escalation threshold
- required timing
- the record that will show what was decided and why
This decision map should cover routine and exceptional matters. Examples include approval of baselines, acceptance, variations, risk treatment, use of commercial levers, release of contingency, re-prioritisation and closure of assurance findings.
Terms of reference should then reflect those functions. A forum that cannot decide, direct, recommend or assure a defined matter is likely to duplicate another part of the system.
Decision rights also need to match actual delegations and organisational responsibilities. Finance’s guidance on officials’ duties is part of that accountability setting. A paper can be well written and still fail if it reaches a forum without authority or arrives after the practical decision has already been made.
Define a minimum evidence set
Each decision should have a minimum evidence set proportionate to its consequence.
That set may include:
- the approved requirement or outcome
- current technical, cost and schedule baselines
- contractual obligations and available mechanisms
- performance and risk information
- dependencies and interface positions
- options and trade-offs
- stakeholder or specialist advice
- affordability and value-for-money implications
- recommendation, dissent and consequence of delay
The purpose is not to create a standard pack for every issue. It is to make clear what information must be available before the decision can be responsibly made.
Evidence should be attributable. Papers should distinguish source fact, management assessment, forecast, assumption and recommendation. Where evidence is incomplete or contested, that condition should be visible rather than resolved through confident drafting.
Keep baselines and reports connected
Program reports are reliable only where they can be traced to controlled source records.
A reported milestone should connect to the integrated schedule and evidence of completion. A cost position should connect to the approved baseline, actuals, commitments and forecast. A technical status should connect to configuration, review or test evidence. A contract-performance statement should connect to obligations, deliverables, acceptance and notices.
The program should define:
- the authoritative source for each reported measure
- the owner responsible for its accuracy
- the reporting cut-off and currency
- tolerances and escalation thresholds
- treatment of assumptions and missing data
- reconciliation between technical, cost, schedule and commercial positions
A dashboard cannot correct inconsistent baselines. It can only present them more efficiently.
Where positions differ, the report should identify the variance and required decision. The objective is not a single reassuring number. It is a usable account of the delivery position.
Make the decision record usable
A decision record should allow another informed person to understand:
- what was decided
- who had authority
- what evidence was considered
- which options and risks were material
- what advice or dissent was recorded
- what action follows
- how the decision changes the baseline, contract or controls
Minutes that state only that a matter was discussed are not a reliable decision record. Nor is a paper complete where the approved outcome is not carried into the schedule, budget, contract register, risk position or action system.
A decision log can help where it records the decision, date, authority, rationale, conditions, affected baselines and implementation owner. It should link to the underlying paper and evidence rather than repeat them.
The record is part of delivery control. It prevents later teams from treating an assumption as an approval or reopening a settled issue without understanding why the original decision was made.
Use assurance to test the management system
Assurance is most useful where it tests whether the management system supports the required outcome.
Commonwealth assurance-review guidance explains that assurance reviews support evidence-based decision-making and do not replace entity responsibility for implementation and delivery.
A targeted review should have:
- a defined question and criteria
- identified users and decision context
- access to authoritative evidence
- clear limitations
- findings linked to consequence
- practical recommendations
- an accountable response and closure process
The review should distinguish the existence of a control from evidence that it operates. A current policy, template or register may show design. It does not, by itself, show that the control is used, timely or effective.
Mayport’s work in this area is management assurance, audit readiness, targeted review and remediation support, working alongside the client’s own audit and decision-making accountability.
Build audit readiness through routine work
Audit readiness is the ability to explain and evidence the program’s decisions and controls without reconstructing them after the event.
It depends on routine disciplines:
- approved baselines and controlled changes
- clear accountabilities and delegations
- attributable source records
- complete decision and approval records
- traceable procurement and contract files
- current risk, issue, dependency and finding registers
- evidence-based closure
- retention and access arrangements appropriate to the information
A late document-collection exercise can identify missing material. It cannot recreate a contemporaneous decision rationale or prove that a control operated when required.
Readiness should be tested periodically against the questions an authorised reviewer, internal assurance function or external scrutiny body would reasonably ask. The purpose is to improve management control, not to prepare a polished archive that is disconnected from current delivery.
The ANAO’s 2024–25 Major Projects Report and Defence portfolio audit work program provide public scrutiny context. They do not replace a program’s own assurance plan or establish findings beyond the work and periods they address.
Close the loop after a decision
Governance is incomplete until the decision is implemented and its effects are visible.
After a material decision, the program should confirm:
- the decision and conditions are recorded
- affected baselines and registers are updated
- contractual notices or variations are issued where required
- owners understand the required action
- dependencies and stakeholders are informed
- new risks or assurance needs are captured
- implementation evidence is reviewed
The same discipline applies to findings. A finding should remain open until the agreed control has been implemented and the required evidence has been accepted by the authorised owner.
Closure is not the end of the record. Material decisions should remain traceable through later reporting, change and review.
Effective governance therefore has a simple test: did reliable evidence reach the right authority in time, was the decision recorded, and did the management system change accordingly?