You have commissioned a readiness review, or you are about to. A few weeks later someone presents you with a deck.
How do you tell whether it is any good?
This is a harder question than it looks, because the failure mode of a bad readiness review is not that it is obviously wrong. It is that it is reassuring. It confirms what the programme has been reporting, contains no unwelcome surprises, and recommends more communication and training. Everyone leaves the room feeling better, and nothing that mattered was found.
Here is what to expect from a review worth its fee, what to ask at the readout, and what you have to supply for it to work.
Why you need one at all
Start from an uncomfortable premise: the reporting reaching you is probably more optimistic than reality, and not because anyone is lying to you.
Bent Flyvbjerg’s work on major projects separates two distinct causes of this. Optimism bias is cognitive — a general human tendency to judge future events more positively than experience warrants. Strategic misrepresentation is deliberate: overstating benefits and understating costs and risks in order to secure and retain approval. His remedy, reference class forecasting, works by taking an outside view — comparing against how similar efforts actually turned out rather than how this one is described from inside.
Layered on top is a reporting problem. Information systems research calls it the mum effect: the reluctance to pass on unwelcome messages, recognised as a contributor to project failure. Bad news is softened at each reporting layer until the version that reaches you no longer sounds like a reason to act.
A readiness review is a correction for known, systematic distortion. Framing it that way also matters politically: it is not a vote of no confidence in your team, and saying so explicitly at the outset will materially improve what the review is able to find.
The one-line test
A readiness review exists to change a decision.
If there is no decision in front of you — go or no-go, invest more or hold, resequence or proceed, extend hypercare or stand down — then what you are buying is documentation, and you should either identify the decision or save the money.
Government has formalised this. The Infrastructure and Projects Authority’s assurance review toolkit places independent reviews at key decision points in a project lifecycle, conducted by people independent of the team, producing an explicit delivery-confidence assessment addressed to the Senior Responsible Owner. Independence, a decision point, and a stated confidence judgement addressed to the accountable person. That is a reasonable bar for a commercial readiness review too.
Six things to expect in the output
- Evidence with its source and its limits. Every material claim should be traceable to something — observed behaviour, documents, interviews, test data, survey results — and the review should say how confident it is in each. “Users are not ready” is an opinion. “Unaided completion in the finance workflow was 55% across nine observed sessions” is evidence.
- Prioritised risks, not a catalogue. Forty findings ranked equally is a list. You should receive a small number of risks ordered by consequence, with the rest available underneath but not competing for your attention.
- A named owner against each one. A person, not a function. If everything is owned by “the programme,” nothing is.
- A plan anchored to your milestone. Actions with dates counted backwards from cutover or wave two, not forwards from the day the report was written. A 30/60/90-day plan dated from the readout is a plan that has not been connected to anything.
- An explicit judgement. Not just findings — a view. Would the reviewer proceed on this date, and on what conditions? Reviewers who will not commit to a position are protecting themselves rather than helping you.
- A statement of what was not examined. Every review has boundaries: areas not covered, people unavailable, documents that did not exist. A review that does not declare its blind spots is inviting you to treat partial coverage as full assurance.
Six questions to ask at the readout
These take ten minutes and separate a considered review from a well-formatted one.
- “What did you expect to find that you did not?” A reviewer who went in with hypotheses and updated them was thinking. One with no expectations was collecting.
- “What is the spread behind that average?” Readiness is about shared confidence. A team averaging 3.8 might be uniformly moderate or split into enthusiasts and refusers — different problems, same number.
- “What could you not get access to?” The answer often locates the risk. Groups that were unavailable are frequently the ones under most pressure.
- “Which of these would you personally escalate this week?” Forces a ranking that a RAG table lets people avoid.
- “What happens if we do nothing?” Some risks are survivable. Knowing which is how you spend remediation effort well.
- “What would have to be true for your conclusion to be wrong?” The best question in the set. It surfaces the assumptions the whole assessment rests on.
Warning signs
| Warning sign | What it usually means |
|---|---|
| Nothing contradicts existing project reporting | The review consumed the programme’s own view rather than testing it |
| Every recommendation is communication or training | The diagnosis stopped at symptoms; process, data and decision rights were not examined |
| Averages presented without variance | The signal that matters most has been aggregated away |
| Risks with no named owner | Nothing will move after the readout |
| No view on the decision in front of you | The reviewer is avoiding accountability for their own judgement |
| No stated limitations or gaps | Partial coverage is being presented as full assurance |
| Findings you already knew, restated | You paid for confirmation, which is the most expensive thing to buy |
What you have to supply
This is the part sponsors are rarely told, and it determines the quality of what you receive more than the reviewer’s method does.
Access without minders. If every conversation happens with a programme representative in the room, you will receive the programme’s view with an external logo on it. Frontline users, upstream teams and sceptics need to be reachable directly.
Explicit permission for bad news. Say publicly, before the review starts, that you want to know what is wrong and that nobody will be penalised for saying it. This one sentence, said by you rather than by the reviewer, changes what people are willing to describe.
Your own availability afterwards. A review generates decisions only you can take — funding, resequencing, releasing people, changing decision rights. If your next window is in six weeks, the findings will age past usefulness before you act on them.
A genuine willingness to change the plan. If the date cannot move, the scope cannot change and the budget is fixed, say so at the start. A competent reviewer will then focus entirely on mitigation within those constraints, which is a legitimate and useful engagement — but it is a different one, and discovering the constraint at the readout wastes everyone’s time.
Your involvement is not administrative. Prosci’s benchmarking has identified active and visible sponsorship as the top contributor to change success in every study since 1998, reporting that projects with extremely effective sponsors met objectives 79% of the time against 27% for those with extremely ineffective sponsors. You are not the commissioner of the review. You are one of the variables it is assessing.
The two weeks after the readout
Most of the value of a readiness review is won or lost here, and it is entirely in your hands.
- Take the decisions the review surfaced, including the uncomfortable one, and minute them. Deferred decisions are how a good review turns into an expensive document.
- Confirm each owner personally. An owner who was not in the room and has not agreed is not an owner.
- Say publicly what you heard and what you are doing. Including the parts that were critical. People told the reviewer difficult things; if nothing visibly follows, they will not do it again.
- Put the actions where you will see them — your own governance forum, not a separate change workstream that reports elsewhere.
That last point is the difference between a review that changes an outcome and one that produces a well-received presentation. Actions tracked where the sponsor looks get done; actions tracked elsewhere become the mechanism by which benefits quietly leak after go-live.
What good feels like
A useful readiness review is mildly uncomfortable. It should tell you at least one thing you did not know and did not want to hear, be specific enough that you can act on Monday, and leave you with a shorter list than you started with rather than a longer one.
If it confirms everything you already believed, one of two things happened: your programme is in genuinely good shape, or the review looked where it was pointed. The questions above are how you tell those apart — and it is worth knowing which, because only one of them is a reason to relax.
The same expectation applies at the gate itself. Sponsors are usually shown how much of the programme is finished rather than how much risk remains, and the evidence a go/no-go decision actually requires is a short and quite different list.
For what a review actually examines, see what a transformation readiness diagnostic assesses and how a diagnostic sprint differs from a readiness survey. If you are preparing to brief a wider leadership group on the findings, briefing leaders on readiness without change jargon covers how to present them. The Readiness Diagnostic Sprint sets out one structured format for this kind of review.
