Integration: The Missing Discipline in Project Assurance
Project professionals have expended a considerable amount of effort on strengthening governance, risk management, assurance and project controls. Yet major programmes continue to suffer cost overruns, delays and delivery failures. If projects now have more oversight than ever, why do so many still struggle to deliver?
The solution may lie less in the effectiveness of individual disciplines and more in the relationships between them. Many project failures are not caused by a lack of governance, risk management or assurance, but by a failure to connect these disciplines in ways that support timely, informed decision-making.
Symptoms of failing projects may include commercial disputes, unrealistic schedules, poor stakeholder alignment, weak challenge or risks that materialise unexpectedly. But, often, beneath them lies the same root cause: poor integration.
In this context, integration should be understood as Management Integration: the leadership competence and capability required to connect objectives, assumptions, risks, controls, performance information and assurance insight so that decision-makers receive a coherent view of delivery reality.
Looking Beyond the Symptoms
Recent conversations in the project assurance arena have reinforced this point. Most assurance tends to consider the performance of the processes but fails to check whether there is integration at the project level. Projects might be under good governance, have comprehensive risk registers, thorough review processes, and highly competent people but can still fail if the crucial interfaces of these processes are not well-managed.
This scenario continues to play out in many complicated delivery settings. Programmes continue to struggle despite having good management structures in place, generally because assumptions, dependencies and decisions are not joined up. The issue is not usually a lack of professional competence; it is about alignment of technical, commercial, operational and governance perspectives.
Integration is not only a project controls or technical systems engineering problem; it is also a governance issue, a leadership issue, and increasingly an assurance issue.
The Missing Capability
Integration touches almost every aspect of delivery: strategy, governance, risk, engineering, commercial management, stakeholder engagement and culture. Precisely because it is so pervasive, assurance professionals should care about it.
There are two related challenges. The first is integrated assurance – ensuring assurance activity is coordinated, aligned and proportionate[1]. Many organisations have made progress here through assurance strategies, coordinated review plans and structured oversight.
The second challenge is more important and less developed, namely the assurance of integration itself. Are objectives aligned with delivery decisions? Are assumptions visible and challenged? Are risks influencing behaviour, or merely being recorded? Are governance bodies receiving insight that reflects reality?
These questions rarely feature explicitly in assurance frameworks. One reason may be that integration has not achieved the status of a recognised professional discipline. It often appears indirectly through configuration management, change control or systems engineering, which can make it look like a technical process rather than a leadership capability.
In complex projects, uncertainty, ambiguity and interdependency are constant. As complexity increases, success depends less on the strength of individual components and more on the quality of the connections between them.
Integration can therefore be understood as the deliberate alignment of objectives, decisions, assumptions, risks, technical solutions, delivery activities, commercial arrangements and assurance mechanisms in support of a common outcome.
[1] APM Assurance Interest Network. (2025). Guide to Integrated Assurance Management. Association for Project Management. ISBN 978-1-913305-49-9.
Why GRC Matters
This is where management integration and GRC[1] meet. Both are concerned with ensuring that governance, risk, controls, assurance and performance information are not separate activities, but connected sources of insight for leadership decision-making. Although GRC is generally associated with corporate compliance, its central aim is to connect disciplines that often operate in silos.
At its heart, GRC ensures that governance supports objectives, risk informs decisions, controls influence behaviour, assurance provides meaningful confidence and performance information drives action. In other words, integration occurs where there could be separate activities.
This makes GRC highly relevant to project assurance. It does not mean the introduction of new disciplines; it helps connect the existing governance structures, risk frameworks, controls, compliance obligations, assurance reviews and performance reporting.
The concept of GRC 6.0[2] is useful for this reason. GRC is not just one more framework imposed on projects, but an integrated decision-support system which links objectives, uncertainty, controls, assurance and performance. Like any effective discipline, it should be adapted to the operating model and delivery context in which its principles are applied.
[1] OCEG (Open Compliance and Ethics Group) is the originator of the GRC Capability Model™ and the Principled Performance® framework.
[2] Rasmussen, M. (2024). Next Generation GRC: Business Integrated/Aligned GRC. GRC 20/20 Research
From Process Assurance to Delivery Confidence
The most critical change might well be in the questions posed by the assurance professionals. Rather than being concerned with whether processes were followed, documentation was updated, or reviews done, assurance must now be concerned with whether the process has been operating as an integrated system.
Are decisions in line with goals? Do assumptions hold? Does risk determine behaviour? Are governance bodies gaining insights? Are there actions resulting from the assurance review? The questions lead assurance beyond compliance and into confidence.
Project management has become remarkably effective in managing individual disciplines. Now comes the test of how well these disciplines fit together. As projects grow bigger and more complex, it will not matter what the components are; rather, it will matter whether the connections work.
Conclusion: Making Integration the Focus of Assurance
Project assurance is already very good at assessing component elements of delivery. However, it can be postulated that programme failures result precisely from those elements being poorly integrated. So, integration must be seen not as an optional extra or a purely technical exercise, but as a core leadership function and competence that enables delivery assurance.
The challenge for the assurance professional community is to widen the discussion to encompass not just how well governance, risk management, and controls are working, but also whether they are linked up. Because if assurance is all about successful delivery, then management integration may be one of the most important leadership capabilities we should be assuring.
Authors
Andy Krolikowski is an experienced independent project, programme, and portfolio management (P3M) consultant with a background in the clean energy, defence, nuclear, and aerospace sectors.
Pamela Stacey is an experienced governance, risk, and compliance (GRC) professional and the founder of GRC Catalyst.
Disclaimer
This article reflects the views and professional judgement of the authors. Where external concepts, frameworks or sources have informed the discussion, they have been referenced as appropriate. The authors are responsible for the substance, interpretation and final editorial review of the article. AI tools were used to support research, drafting refinement and factual checking, but responsibility for the final content rests with the authors.