Weak records management and lack of transparent performance data
Incomplete records and limited disclosure of performance, costs, and contract changes weaken auditability, organisational learning, and accountability across the project life cycle.
Red Flags & Indicators
- Key contracts, variations, change orders, payment certificates, and project correspondence are missing, fragmented, or hard to trace.
- Incomplete close-out files.
- Records lack version control and are edited after the fact.
- Approvals are not traceable (who approved, when, and on what basis).
- Performance metrics vary across reports.
- Underlying and source data are unavailable.
- KPIs are not defined or standardised.
- Variations and costs are not reconciled to budgets and as-built outputs, creating mismatches between financial spend and physical progress.
- Lessons learned, defects, and claims registers are absent, incomplete, or not shared.
- Handover and archiving are not finalised.
Stakeholder Guidance
Stakeholder Exposure
Exposure includes missing records; higher rsk of disputed payments and variations; poor traceability; delayed close‑out and retention release; and reputational risk.
Decision Point
Before submitting the close-out records and data pack, verify document and evidence traceability; pause close-out until gaps are corrected.
Mitigation Actions
• Define and apply a formal document retention schedule
• Ensure auditors have timely and compete access to all relevant files and supporting documentation upon request
• Apply version control and an audit trail for changes in the close-out record (who/when/why)
• Require controlled access to the close-out pack, with automatic logging of all views, downloads, and edits
• Reconcile financial and physical progress, ensuring consistency between payments, measured quantities, certified milestones, and actual work completed on site
• Standardise KPIs and ensure they are fully traceable to underlying raw data, source documents, or system extracts
• Use internal compliance escalation processes and whistleblower channels, where available, to report any request to alter, destroy, backdate, or withhold records
• Suspend submission or approval of close-out documentation until the record set is complete, verified, and internally consistent
Mitigation Resources
Maintain internal oversight of the company’s close-out records, performance data, and disclosure controls; require complete, traceable records, version control, and corrective action where control failures are identified.
Risk-based internal audit planning — https://toolbox.infrastructuretransparency.org/resource/risk-based-internal-audit-planning/Use the company’s compliance process to review and escalate requests to alter, destroy, backdate, or withhold key records; require documented rationale and compliance or legal sign-off before close-out submissions, responses to auditors, or data releases proceed.
Compliance management system — https://toolbox.infrastructuretransparency.org/resource/compliance-management-system/Failure Cases
Good Practices
Stakeholder Exposure
Exposure includes lack of reliable data; weak ability to validate costs; higher fraud and claim risk; and delayed close‑out and exit decisions.
Decision Point
Before approving reporting and close-out, request a complete, traceable data room; withhold sign-off and require records remediation.
Mitigation Actions
• Treat missing and edited records as a suspension trigger
• Condition final payments and consents on complete handover documentation, performance datasets (KPIs, source raw extracts or references) and reconciliation of payments and physical progress
• Include audit/verification rights
• Commission independent review when records are fragmented, approvals lack traceability, or performance data are missing and inconsistent, pausing close-out decisions pending review and corrective action remediation
Mitigation Resources
Conduct integrity due diligence and issue tracking on close-out records, performance datasets, and handover documentation; require a data-room index, version control, retention schedule, access logs, and audit or information rights, and pause final payments or consents where records are incomplete, edited without explanation, or lack traceability.
Investor integrity due diligence and monitoring — https://toolbox.infrastructuretransparency.org/resource/investor-integrity-due-diligence-and-monitoring/Require, through financing conditions, complete handover documentation, performance datasets, payment-to-progress reconciliation, and formal evidence supporting close-out decisions before final payments or consents.
Change control, delivery verification, and payment integrity — https://toolbox.infrastructuretransparency.org/resource/change-control-delivery-verification-and-payment-integrity/Use an independent technical adviser or assurance provider to verify the completeness, traceability, and consistency of close-out records, performance data, and supporting evidence, and to challenge fragmented records, missing approvals, or unexplained gaps before close-out decisions proceed.
Independent technical due diligence and monitoring — https://toolbox.infrastructuretransparency.org/resource/independent-technical-due-diligence-and-monitoring/Failure Cases
Good Practices
Stakeholder Exposure
Exposure includes limited ability to verify value-for-money and delivery performance; weak asset handover and inadequate operations and maintenance planning; increased risk of audit qualifications, disputes, and legal liability; and loss of public trust.
Decision Point
Before accepting completion and release the close-out disclosure package, verify whether records are complete and traceable; refuse acceptance and require document completion and standardisation in case of lack of documentation.
Mitigation Actions
• Apply version control and an audit trail for changes in the close-out record (who/when/why)
• Require proof of completion before final acceptance and final payments
• Publish close-out and performance records based on recognised infrastructure data standards such as the OC4IDS
• Require controlled access to the close-out pack, with automatic logging of all views, downloads, and edits
• Conduct audit records
• Refer credible signs of suspected tampering, withholding, backdating, or destruction of records to independent oversight bodies
Mitigation Resources
Publish and maintain public access to close-out and performance records, including contracts, variations, approvals, payment certificates, QA/QC records, as-builts, key KPIs, and reasons for material changes, with only lawful redactions.
Transparency and data disclosure standards — https://toolbox.infrastructuretransparency.org/resource/transparency-and-data-disclosure-standards/Maintain and use digital records and publication logs for close-out files, including document indexes, version history, release dates, retention schedules, and access or change logs, through an auditable trail.
Digital procurement, traceability, and audit logs — https://toolbox.infrastructuretransparency.org/resource/digital-procurement-traceability-and-audit-logs/Set clear approval limits, sign-off steps, and separation of duties for close-out records, version control, access changes, and final release or payment approvals; ensure no single official can alter, approve, and record the same change.
Approval authority and segregation of duties — https://toolbox.infrastructuretransparency.org/resource/approval-authority-and-segregation-of-duties/Failure Cases
Good Practices
Stakeholder Exposure
Exposure includes limited access to performance and cost records; constrained scrutiny of closeout; accountability gaps across the project life cycle; reduced oversight; and risk of retaliation when requesting disclosure.
Decision Point
During project operation, submit access to information to obtain performance documentation. Decide whether to (a) escalate through oversight channels to report transparency gaps, or (b) monitor while safely gathering evidence.
Mitigation Actions
• Mobilise communities to highlight the importance of complete disclosure of performance information
• Engage available grievance channels and oversight bodies to report signs of record manipulation (use safe, confidential reporting and anonymisation where the risk of retaliation is significant)
• Advocate for disclosure of project information based on recognised infrastructure data standards such as the OC4IDS
Mitigation Resources
Request access to non-public close-out and performance records, such as underlying KPI datasets, change logs, version histories, payment and contract-change records, as-built summaries, or records explaining withheld or altered documents, so missing items, version gaps, or suspected record manipulation can be examined and raised through oversight channels.
Access-to-information and demand-side transparency — https://toolbox.infrastructuretransparency.org/resource/access-to-information-and-demand-side-transparency/Review publicly disclosed close-out records and performance datasets, such as KPIs, service levels, change orders, payments, as-built summaries, and closure documentation; identify disclosure gaps, missing items, unexplained version gaps, or withheld records, and raise concerns about non-disclosure with an oversight body.
Transparency and data disclosure standards — https://toolbox.infrastructuretransparency.org/resource/transparency-and-data-disclosure-standards/