Phase 7: Evaluation & Audit

Weak records management and lack of transparent performance data

Incomplete records and limited disclosure of performance, costs, and contract changes weaken auditability, organisational learning, and accountability across the project life cycle.

Red Flags & Indicators

  • Key contracts, variations, change orders, payment certificates, and project correspondence are missing, fragmented, or hard to trace.
  • Incomplete close-out files.
  • Records lack version control and are edited after the fact.
  • Approvals are not traceable (who approved, when, and on what basis).
  • Performance metrics vary across reports.
  • Underlying and source data are unavailable.
  • KPIs are not defined or standardised.
  • Variations and costs are not reconciled to budgets and as-built outputs, creating mismatches between financial spend and physical progress.
  • Lessons learned, defects, and claims registers are absent, incomplete, or not shared.
  • Handover and archiving are not finalised.

Stakeholder Guidance

Stakeholder Exposure

Exposure includes missing records; higher rsk of disputed payments and variations; poor traceability; delayed close‑out and retention release; and reputational risk.

Decision Point

Before submitting the close-out records and data pack, verify document and evidence traceability; pause close-out until gaps are corrected.

Mitigation Actions

• Maintain a complete and auditable performance and close-out record set (contract set, variations, approvals, payment certificates, correspondence, quality assurance and quality control records, as-builts, reasons for material changes)
• Define and apply a formal document retention schedule
• Ensure auditors have timely and compete access to all relevant files and supporting documentation upon request
• Apply version control and an audit trail for changes in the close-out record (who/when/why)
• Require controlled access to the close-out pack, with automatic logging of all views, downloads, and edits
• Reconcile financial and physical progress, ensuring consistency between payments, measured quantities, certified milestones, and actual work completed on site
• Standardise KPIs and ensure they are fully traceable to underlying raw data, source documents, or system extracts
• Use internal compliance escalation processes and whistleblower channels, where available, to report any request to alter, destroy, backdate, or withhold records
• Suspend submission or approval of close-out documentation until the record set is complete, verified, and internally consistent

Mitigation Resources

Maintain internal oversight of the company’s close-out records, performance data, and disclosure controls; require complete, traceable records, version control, and corrective action where control failures are identified.

Risk-based internal audit planning — https://toolbox.infrastructuretransparency.org/resource/risk-based-internal-audit-planning/

Use the company’s compliance process to review and escalate requests to alter, destroy, backdate, or withhold key records; require documented rationale and compliance or legal sign-off before close-out submissions, responses to auditors, or data releases proceed.

Compliance management system — https://toolbox.infrastructuretransparency.org/resource/compliance-management-system/