Element 10 · IOGP 510

Assurance, Review and Improvement

To define how the management system is independently assured, reviewed and improved — applying three lines of defence across every function. Findings requiring change flow into MoC in Element 5.

"This element is most often performed for paper rather than substance. Audits that rediscover the same finding for five years running have stopped being assurance and started being archaeology. The test is whether the organisation acts differently afterwards — and whether senior management is uncomfortable with at least some of what comes out of it. Comfort here is a warning sign."
  • ·Audit programmes and schedules (Engineering Audit Process, PSCM Audit Schedule, HR Audit Schedule)
  • ·Independent verification (Well Examination, TA Verification Process, Independent Technical Review)
  • ·Stage-gate and decision-gate assurance
  • ·Peer review and challenge processes (Peer Reviews of Well Design, Peer Assist)
  • ·Management review and improvement planning (Management Review Inputs, Engineering Improvement Plan)
  • ·External and regulatory reviews
  • →The KPI data being reviewedE9 Monitoring
  • →The standard against which performance is judgedE2 Policies
  • →The risk acceptance behind a deviation, and MoC closure following an audit findingE5 Risk
  • 10.1A documented, risk-based assurance programme — three lines of defence: first line (function), second line (functional assurance), third line (independent: internal audit, external audit, regulator) — is established and covers all functions.
  • 10.2Consolidated performance information is prepared for management review and benchmarking.
  • 10.3Data and KPIs are assessed to understand control and barrier weaknesses and identify improvements.
  • 10.4Improvements based on assurance findings and lessons are planned, communicated and embedded; findings requiring change trigger an MoC.
  • 10.5Managers formally review effectiveness and fitness-for-purpose of the management system; improvement actions are tracked to completion.

Status:Same as IOGP, applied at full enterprise scope; assurance findings flow into MoC

The company applies this element to assurance across every function — operations, engineering, finance, legal, HR, commercial. One assurance discipline, every function.

  • ·Three lines of defence model: first line (function), second line (functional assurance), third line (independent — internal audit, external audit, regulator). All three lines map here.
  • ·Findings flow into MoC (Element 5). Audit findings requiring change trigger an MoC.
IOGP 510 base expectations
  1. 1.A documented, risk-based assurance process including scheduled independent audits is established.
  2. 2.Consolidated performance information is prepared for management review and benchmarking.
  3. 3.Data and KPIs are assessed to understand control weaknesses and identify improvements.
  4. 4.Improvements based on assurance findings and lessons are planned, communicated and embedded.
  5. 5.Managers formally review effectiveness and fitness-for-purpose; improvement actions are tracked to completion.
Upstream O&G adapted expectations
  1. 1.A documented, risk-based assurance programme — three lines of defence: first line (function), second line (functional assurance), third line (independent: internal audit, external audit, regulator) — is established and covers all functions.
  2. 2.Consolidated performance information is prepared for management review and benchmarking.
  3. 3.Data and KPIs are assessed to understand control and barrier weaknesses and identify improvements.
  4. 4.Improvements based on assurance findings and lessons are planned, communicated and embedded; findings requiring change trigger an MoC.
  5. 5.Managers formally review effectiveness and fitness-for-purpose of the management system; improvement actions are tracked to completion.
Engineering
This element holds the independent challenge of engineering — TA verification, independent technical review, audit, stage-gate assurance and the systematic improvement of the engineering function itse…
8 docs →
Operations & Maintenance
This element holds the independent challenge of asset operations — operational assurance, integrity verification, audit and post-event review.
7 docs →
HSSE
This element holds HSSE assurance — the HSE audit programme, field evaluations, legislative compliance and the annual improvement plan.
7 docs →
Commercial
This element holds the independent challenge of commercial activity — contractor assurance, PSCM audit, contract compliance audits and DoA audit.
6 docs →
Finance & Legal
This element holds the independent assurance of finance and legal — external audit, internal audit, legal review and compliance assurance.
5 docs →
HR / People
This element holds the independent challenge of HR — audit, management review, policy review and continuous improvement.
2 docs →
Business Services
This element holds assurance of information and access — access-right recertification, controlled-document inspections and improvement prioritisation.
3 docs →
Subsurface
This element holds independent challenge of subsurface — independent technical reviews, reserves audits, peer review processes and external expert reviews.
5 docs →
Wells
This element holds the independent assurance of wells — well examination, TA review, peer review, audit and management review.
4 docs →