Reviews are commissioned late. Not at the first slipped milestone, and not at the first re-baseline. Usually at the second re-baseline, when the sponsor has already defended the programme once to a board or a departmental director and does not want to do it again without something independent in hand. By then the programme is typically seven to ten months in, the original business case is a document nobody opens, and the steering group has developed a collective ability to hear the status report without listening to it.
I have sat on both sides of that table. What follows is what the first week of an independent review almost always turns up, why the people who commissioned it are rarely surprised by it, and what that tells you about what a review is actually for.
The five findings that recur
Every programme is different in its detail and remarkably similar in its failure. Across public-sector digitalisation, enterprise platform replacements and the current wave of AI programmes, the first week's findings cluster around five things.
Decisions have been deferred, not made. The most consequential questions on the programme — scope arbitration, a vendor's underperformance, whether the target operating model is still the target — have been raised, minuted as "under review", and recycled. The steering group has a decision backlog it has never seen as one list.
The plan describes a programme that no longer exists. The Gantt chart and the milestone report are maintained diligently against a scope that was quietly renegotiated in workstream meetings months ago. The plan is accurate to itself and unrelated to the work.
Benefits ownership evaporated after the business case. Someone signed a document that promised a number. That person has moved role, or the number was always the finance function's estimate, or the benefit depends on an operational change nobody has been asked to make. The programme is delivering outputs to a customer that does not exist.
The vendor relationship is held by the least senior person in the room. The contract was negotiated by procurement, the relationship is managed by a delivery manager, and the only person with the standing to have a hard conversation with the vendor's account director has never met them.
Green means something different here. Every organisation drifts its own definition of a green status. In week one a reviewer reads six months of RAG reports against the delivery data and finds the point — usually a specific month — where green stopped meaning "on plan" and started meaning "nothing new has gone wrong this fortnight".
None of these is exotic. That is the point. If your programme is in its second re-baseline, it has at least three of them.
The steering group already knew
The uncomfortable part of a review is not the findings. It is the readout, when the sponsor says some version of: yes, we knew that.
They did. Not as a written finding, but as an accumulation of corridor conversations, of the workstream lead who stopped attending, of the vendor invoice that was queried and then paid. Proximity is the problem. People close to a programme know what is wrong with it and have already priced in the social cost of saying so.
That cost is real, and in Nordic organisations it is higher than the flat hierarchies suggest. Consensus is how things get done here, and consensus is a genuine strength once a decision has been made. Before it has been made, consensus culture punishes the person who names the problem the group has agreed not to name. The steering group member who says "the vendor is failing and we should say so" is not being brave; they are volunteering to own a decision nobody else wants to own. So the finding stays unwritten, and the programme continues.
A review does not discover what the organisation does not know. It writes down what the organisation cannot afford to say, attaches evidence to it, and hands it to the one person who can act on it. That is a different service from discovery, and it is worth paying for on its own terms.
The public sector has a mechanism for this. The private sector does not
Danish state IT programmes above a threshold are risk-assessed by Statens It-råd before they start and reviewed as they go, and Rigsrevisionen audits the results afterwards and publishes what it finds. The reports are uncomfortable reading, and they are the reason the public sector has a vocabulary for programme failure that most private organisations lack. The UK's Infrastructure and Projects Authority runs gateway reviews on the same principle: assurance at defined points, by people who are not delivering the work.
A Danish enterprise running a DKK 80 million platform replacement has no equivalent. The board sees what the sponsor chooses to show it. Internal audit looks at controls, not at whether the target operating model was ever plausible. The only independent assurance a private programme gets is the assurance it commissions for itself — which is why it gets commissioned late, and why it is so often commissioned as cover rather than as inquiry.
What makes a review worth the fee, and what makes it theatre
Because reviews are commissioned under pressure, they are easy to get wrong. The failure modes are consistent.
A review that interviews only the steering group is a summary of the steering group's opinions. The findings live two levels down — with the workstream leads who know what was descoped and the delivery managers who know what the vendor is actually staffing. A review that does not go there is a facilitated away-day.
A review that reads only the artefacts is an audit of the PMO's document control. Artefacts are evidence of what was written, not of what happened. The delivery data — velocity, defect trends, environment availability, the invoice history — is where the plan and the work part company, and it is usually the first thing a reviewer asks for and the last thing the programme can produce.
A review conducted by the firm that hopes to run the recovery is a proposal. It will find that the programme needs more of what that firm sells. Independence is not a nicety here; it is the mechanism. If the reviewer stands to gain from the finding, the finding is worthless.
And a review whose readout the sponsor delegates has already failed. The findings are decisions. They do not survive being relayed by a programme manager to a sponsor who was not in the room, because the sponsor will hear them as the programme manager's opinion, which is exactly the status they had before the review was commissioned.
What a review should produce, in two to three weeks, is a written finding for each of the five patterns above, the evidence for it, and a recommended decision — with the sponsor in the room when it is read out. Not a fifty-page report. A short document that the steering group cannot un-hear.
When not to commission one
Two situations, and I say this to sponsors before I take the work.
If the decision has already been made — to stop the programme, to change the vendor, to replace the lead — and the review is wanted as the paper trail, say so and get a cheaper piece of paper. A review commissioned as cover produces findings shaped to fit the decision, and everyone involved knows it.
And if nobody with the authority to act will read it, do not commission it. A review that lands with a programme manager who cannot change the vendor or reopen the business case is an expensive way of making one person more anxious.
Otherwise, commission it earlier than feels necessary. The first re-baseline is the right moment. The second is late, and the third is a post-mortem.
I do independent programme reviews as fixed-scope work — two to three weeks, written findings, a readout with the sponsor present, and no follow-on delivery to sell. The reasons for that last constraint are the whole of this article. If the wider pattern is familiar, the accountability gap it grows from is the subject of Nobody Owns the Middle, and what happens to the benefits case after signature is in Closing the Returns Gap.