From IT Compliance to Evidence-Based Assurance (SkillsTX)

Featured Article from SkillsTX, a CIPS Partner

What do you think the word “assurance” actually means? Take a moment to consider your answer. Assurance is not simply a policy; it is defensible confidence.

A supplier may state that its personnel are qualified, present polished policies, fulfill required training, secure managerial approval of the skills matrix, and meet compliance requirements. However, these points do not by themselves establish assurance.

Compliance confirms that prescribed requirements were followed.

A policy outlines intended actions.

A control enforces those actions.

However, none of these alone demonstrates capability.

This distinction is critical in procurement, cybersecurity, data protection, digital transformation, and business continuity. Organizations routinely assess supplier finances, insurance, contracts, access controls, and certifications. Yet the capabilities of individuals responsible for outcomes are often accepted based on self-declaration, job titles, course completions, or managerial approval.

This approach does not provide assurance; it reflects organized optimism.

Evidence consists of documented materials supporting a claim. Proof is evidence sufficient to establish credibility. Assurance is justified confidence, achieved when relevant evidence is assessed against a clear and consistent standard.

Sequence matters. A policy without evidence is merely an intention. A control without testing is only a design. Compliance without proof may only confirm the process’s completion. Assurance begins when an independent party can review the claim, standard, evidence, assessment method, and decision.

Workforce assurance must advance in this area, and SFIA offers a practical way forward.

The Skills Framework for the Information Age (SFIA) provides organizations with a common language for professional skills and levels of responsibility. In this way, it helps replace vague statements such as “experienced in cyber security” with defined expectations linked to autonomy, influence, complexity, knowledge, and business responsibility.

Independent assessment boosts trust. SFIA digital badges are more than decorative credentials; they provide third-party confirmation that individuals have been evaluated against defined SFIA skill and responsibility levels. With evidence and assessment records, these credentials act as valuable indicators for procurement, deployment, mobility, and risk decisions.

For over a decade, including more than five years as a CIPS partner, SkillsTX has focused on capturing, documenting, reviewing, and applying skills evidence. That experience has solidified a key insight: skills data is valuable only when leaders comprehend its origin, validation process, and current relevance.

A practical test is simple: select a role within your supply chain, define the required skills, expected SFIA levels, acceptable evidence, validator, and evidence expiration date. If this information is scattered across spreadsheets, emails, or assumptions, a governance gap exists that should be tackled proactively.

For CIPS members and procurement leaders, the commercial question is critical. When selecting a supplier, approving a key partner, or evaluating a transformation bid, do not simply ask whether the organization has sufficient personnel with a list of expensive certification requirements.

Instead, ask whether there is verifiable proof that these individuals possess the required skills at the necessary levels.

Then review the supporting documentation. Organizations able to provide this level of evidence will distinguish themselves, while those unable to do so are simply meeting your compliance requirements.

They are not assured; they only comply.

Learn more about SkillsTX at: skillstx.com


Support Canada’s IT Community and Become a CIPS Partner Today! Learn More