1.5 Programme Strategy, Governance & the PDCA Cycle
Key Takeaways
- Programme governance exists to establish the accountabilities, decision rights, and controls that keep a programme aligned with the principles and with corporate strategy.
- The programme strategy is a single document made up of named approaches — governance, stakeholder engagement, design, funding, delivery, resourcing, knowledge and learning, information, assurance, decision-making, issue resolution, and risk response.
- The programme plans are the five time-phased plans: the stakeholder engagement and communications plan, the financial plan, the delivery plan, the assurance plan, and the benefits realization plan.
- Approaches describe how the programme will work; plans describe what will happen and when — an approach without a plan is unexecutable, and a plan without an approach is ungoverned.
- MSP applies the Plan-Do-Check-Act (PDCA) cycle to risks and issues so that responses are planned, enacted, checked for effect, and then adjusted rather than logged and forgotten.
1.5 Programme Strategy, Governance & the PDCA Cycle
[!NOTE] Why this section exists: Before studying the seven themes individually, you need three pieces of shared vocabulary that the syllabus tests directly: the purpose of programme governance, the purpose of the programme strategy, the purpose of the programme plans, and the Plan-Do-Check-Act (PDCA) cycle as MSP applies it to risks and issues.
The Purpose of Programme Governance
Programme governance is the framework of authority, accountability, decision rights, and controls through which a programme is directed. Its purpose is to ensure that the programme stays aligned with the MSP principles and with the strategy of the investing organization(s), and that the people making decisions have both the mandate and the information to make them.
Governance answers four questions continuously:
- Who decides? Which body or role holds the authority for each class of decision, and within what delegated limits.
- On what basis? What information, standards, and criteria must inform the decision.
- With what independence? How the programme obtains objective confidence rather than self-reported optimism.
- How is it recorded? How decisions, and the reasoning behind them, are captured so they can be revisited.
Governance in MSP is delegated downwards and reported upwards: the corporate governing body delegates to the sponsoring group, the sponsoring group delegates to the programme board, and the programme board delegates within defined tolerances to the programme manager and business change manager. Each layer reports back on the exercise of that delegated authority.
The Purpose of the Programme Strategy
The programme strategy sets out how the programme will be governed and managed. In MSP 5th edition it is a single document assembled from a set of named approaches. This is a genuine change from earlier editions, where each of these was a separate "strategy" document.
| Theme | Approaches held in the programme strategy |
|---|---|
| Organization | Governance approach (including organization structure); stakeholder engagement approach |
| Design | Design approach |
| Justification | Funding approach |
| Structure | Delivery approach; resourcing approach |
| Knowledge | Knowledge and learning approach; information approach |
| Assurance | Assurance approach |
| Decisions | Decision-making approach; issue resolution approach; risk response approach |
Each approach records the same kinds of content for its own domain: the objectives and scope, the roles and responsibilities, the standards and techniques to be used, the tools and registers, the review cadence, and the escalation rules.
[!TIP] Exam tip — "approach" vs "plan": If a question asks how something will be done, who is responsible, or which standards apply, the answer is an approach (part of the programme strategy). If it asks when something will happen, in what sequence, or at what cost, the answer is a plan.
The Purpose of the Programme Plans
The programme plans are the time-phased documents that turn the approaches into a schedule of what will actually happen. MSP 5th edition defines five:
| Plan | What it schedules | Primary owner |
|---|---|---|
| Stakeholder engagement and communications plan | Who is engaged, by whom, with what message, and when | Programme manager, with BCM input |
| Financial plan | Expenditure, funding drawdown, and cash flow across the lifecycle | Programme manager, approved by SRO |
| Delivery plan | The projects and other work, grouped into tranches, with dependencies | Programme manager |
| Assurance plan | The scheduled assurance activities and reviews | Programme manager / assurance lead |
| Benefits realization plan | When benefits are expected, measured, and reviewed | Business change manager |
The plans are developed in design the outcomes, validated and completed in plan progressive delivery, and revisited at every tranche boundary. They are baselined together, because a change to one almost always moves another: pulling a tranche forward changes the financial plan's drawdown profile and the benefits realization plan's measurement dates.
PROGRAMME STRATEGY PROGRAMME PLANS
(how we will work) (what happens and when)
┌──────────────────────────┐ ┌──────────────────────────────┐
│ governance approach │ │ stakeholder engagement and │
│ stakeholder engagement │ │ communications plan │
│ design approach │ ──────────► │ financial plan │
│ funding approach │ informs │ delivery plan │
│ delivery approach │ and │ assurance plan │
│ resourcing approach │ constrains │ benefits realization plan │
│ knowledge and learning │ └──────────────────────────────┘
│ information approach │
│ assurance approach │
│ decision-making approach │
│ issue resolution approach│
│ risk response approach │
└──────────────────────────┘
The Plan-Do-Check-Act (PDCA) Cycle
MSP uses the Plan-Do-Check-Act (PDCA) cycle — a general continual improvement loop — as the control pattern for managing risks and issues. The point of applying PDCA is that recording a risk or an issue is not managing it: a response must be enacted, its effect measured, and the approach adjusted.
| Stage | Applied to a risk | Applied to an issue |
|---|---|---|
| Plan | Identify and assess the risk; select a response (avoid, reduce, transfer, accept, share — or exploit, enhance, share, reject for opportunities); assign a risk owner and actionee | Capture and categorize the issue; assess impact on the business case, TOM, and plans; identify options and assign an issue owner |
| Do | Enact the planned response actions within the agreed delegated authority | Enact the chosen resolution, escalating if it exceeds tolerance |
| Check | Re-assess probability, impact, and proximity — did the response actually change the exposure? | Confirm the issue is resolved and that the resolution has not created new problems |
| Act | Adjust the response, escalate, or close the risk; feed the lesson into the knowledge theme | Update the issue register and decision register; adjust the issue resolution approach if the pattern recurs |
Two consequences of the cycle are worth remembering for the exam:
- PDCA makes risk and issue management continuous, not periodic. A risk register reviewed only at tranche boundaries fails the Check stage for months at a time.
- PDCA is where the knowledge theme connects to the decisions theme. The Act stage generates lessons, and lessons change the approach used next time.
[!CAUTION] Common trap — logging is not managing: Distractors often describe a programme that maintains an immaculate risk register with owners and scores but takes no action and never re-scores. Under PDCA that programme has completed Plan only.
A programme manager is documenting which standards, techniques, and roles will be used to obtain independent confidence in the programme, but has not yet scheduled any reviews. Which management product is being produced?
Which of the following is a programme plan in MSP 5th edition?
A programme has assessed a supplier insolvency risk, appointed a risk owner, and enacted a dual-sourcing response. Under the Plan-Do-Check-Act cycle, what must happen next?