14.2 Sources of Specialist Advice and Standards
Key Takeaways
- Specialist advice comes from internal functions, professional bodies, regulators, and technical standards — naming the right source for a scenario is what the outcome tests.
- Standards fall into three tiers: mandatory legal and regulatory requirements, binding contractual and organisational standards, and professional or technical good practice.
- Departing from an organisational standard requires an authorised waiver rather than a silent decision.
- Advice must be sought early enough to change the decision; advice obtained after a contract is signed records the problem rather than solving it.
- Seeking specialist advice does not transfer accountability — the project remains accountable for delivering a compliant solution.
Outcome 15b requires knowledge of the sources of specialist advice and standards that need to be adhered to. It follows directly from the competence point in the previous section: once you have recognised the limit of your own expertise, the professional question becomes where do I go, and what am I bound by?
Sources of specialist advice and standards
Project professionals are not expected to be the final authority on every legal, technical, or ethical question. Knowing where to go is itself professional competence.
| Source | What it typically provides |
|---|---|
| Professional bodies (for example APM) | Codes of conduct, body of knowledge, guides, qualifications, communities |
| Organisational policies and PMO | Methods, tolerances, escalation routes, document standards |
| Legal, compliance, company secretarial | Contract, data protection, competition, corporate law advice |
| HR / employee relations | Employment law practice, grievance, diversity policy, working time |
| Health, safety and environment (HSE) | Safe systems of work, environmental controls, incident process |
| Information security / data protection officers | Cyber, privacy, retention, breach response |
| Finance and internal audit | Financial control, fraud indicators, assurance |
| Regulators and statutory guidance | Sector rules (for example healthcare, finance, construction, transport) |
| Standards bodies | Recognised standards and frameworks (quality, risk, information security, sustainability reporting) |
| External specialists / consultants | Deep technical or legal expertise when internal capacity is insufficient |
| Ethics hotlines / speak-up channels | Confidential routes for suspected misconduct |
Using advice well
- Seek advice early when uncertainty is material — not after a breach.
- Provide full facts; partial briefing produces unsafe comfort.
- Distinguish advice from decision ownership — the PM/sponsor still own project decisions within governance.
- Record advice and decisions for auditability.
- Do not shop for the answer you want by ignoring the competent function.
Scenario B — standards and advice
A supplier offers personal gifts to the project manager during a tender evaluation. The PM consults organisational gifts and hospitality policy, procurement, and if needed compliance, discloses the offer, and withdraws from biased involvement. Standards and specialist advice protect both the individual and the integrity of selection.
Knowing where to go
Specialist advice comes from inside the organisation, from the profession, and from external bodies. Being able to name the right source for a scenario is what the outcome tests.
| Source | What it provides | Typical project trigger |
|---|---|---|
| Internal legal / contracts | Contract terms, liability, dispute position | Supplier variation, termination, unusual terms |
| Finance | Funding rules, tax, capitalisation, affordability | Budget structure, capital versus revenue treatment |
| Procurement | Regulated process, market approach, supplier selection | Any purchase above a threshold |
| Health and safety | CDM-style duties, risk assessment, site safety | Physical works, hazardous activity |
| Information governance / DPO | Data protection, retention, lawful basis | Personal data in scope, new system, data migration |
| Information security | Security architecture, accreditation, cyber risk | New system, external interfaces, cloud hosting |
| HR | Employment law, consultation, restructuring | Change affecting roles or terms |
| Environmental / sustainability | Permits, assessment, reporting duties | Land, emissions, waste, ESG commitments |
| PMO | Method, templates, assurance, lessons | Any project, at every stage |
| Regulators | Binding sector requirements and formal approvals | Regulated sector, licensable activity |
| Professional bodies | Codes of conduct, bodies of knowledge, competence frameworks | Professional judgement and ethical questions |
| Technical / industry standards | Recognised specification and good practice | Design and acceptance criteria |
Standards that need to be adhered to
The syllabus wording — standards that need to be adhered to — signals obligation rather than advice. Distinguish three tiers, because the consequence of departing from each is different:
- Legal and regulatory requirements. Mandatory. Breach exposes the organisation and sometimes individuals to enforcement, penalty, or criminal liability. Examples reaching most projects: data protection law, health and safety duties, equality duties, and sector-specific licensing.
- Contractual and organisational standards. Binding by agreement or policy. Departing from them is a breach of contract or a policy exception, which requires an authorised waiver rather than a silent decision.
- Professional and technical standards and good practice. Sometimes mandatory by contract, otherwise the benchmark you will be judged against if something goes wrong. Codes of professional conduct, recognised technical standards, and bodies of knowledge sit here.
The professional behaviours around advice
Two behaviours are worth stating in a written answer:
- Seek advice early enough for it to change the decision. Advice obtained after a contract is signed or a design is frozen is a record of the problem rather than a solution to it.
- Record the advice and the decision taken. If a recommendation is not followed, the reason and the authority that accepted the residual risk should be documented. That is governance, and it protects everyone involved.
And the trap to avoid: specialist advice does not transfer accountability. Consulting the data protection officer does not make data protection the DPO's problem — the project remains accountable for delivering a compliant solution, informed by that advice.
A project manager faces a complex data-protection question during requirements design. What is the most professional first approach?
A project manager consults the organisation’s data protection officer about a new system, receives written advice, and treats data protection as now being the DPO’s responsibility. What is wrong with that position?