From Red–Amber–Green to Real Insight: Why Your Project Dashboards Are Lying to You 7 min read There’s a familiar moment in executive meetings:"But the project was green last month - what changed?" Nothing changed overnight. The reality is it was never green. As organisations accelerate large-scale transformation programmes, the cost of misplaced confidence in schedules and outcomes has never been higher. Delivery environments are becoming more complex, expectations from boards are increasing and tolerance for failure is shrinking. In this context, the gap between perceived progress and actual delivery is where many programmes begin to unravel.Results from Protiviti’s recent Global Transformation Survey underscore this issue. They show that executives designing or delivering change (for example, the CIO/CTO) assess transformation initiatives as more successful, while those responsible for the performance of the business and the workforce (such as the CEO/board) are least confident in the outcomes of transformation initiatives.This often results from a problem termed “watermelon reporting” - green on the outside, red at the core. It’s a common challenge across private and public sector organisations running large-scale transformation programmes. And it’s one of the clearest signals that traditional reporting is no longer fit for purpose.In our view, this isn’t a failure of data. It’s a failure of assurance. And this is where internal audit can leverage its assurance expertise to deliver value. Topics Internal Audit and Corporate Governance Risk Management and Regulatory Compliance Business Performance The problem with RAG reporting — and why it persistsRed-Amber-Green (RAG) reporting has become the default approach to project governance. It’s simple, familiar and easy to digest. But that simplicity is exactly the issue. RAG compresses complexity into a single colour. It reflects reported progress, not delivery reality.In practice:Project status is self-reported by delivery teams under pressure to demonstrate progress. Updates are retrospective, focused on milestones achieved rather than risks emerging (forward-looking).Self-reports are highly susceptible to optimism bias and organisational dynamics. RAG reporting is historically poor at surfacing early-warning signals.The result? Projects often remain “green” until they suddenly aren’t, with little meaningful amber – or nuance – in between.Watermelon reporting thrives in this environment. The dashboard indicates green. The steering committee moves on. But within the delivery team, confidence is slipping and timelines are under pressure. Teams signal control externally while internally confidence erodes.Challenging the status quo: internal audit’s assurance role in transformation programmesToo often in this operating environment, internal audit and assurance functions are called on to validate what is already being reported - effectively reinforcing the same blind spots.That must change.The real question is not “Is the project on track?” Rather, it is“How confident are we that this project will deliver its intended outcomes, and what evidence supports that view?”This is a fundamentally different lens. It shifts assurance from:Retrospective to forward-looking Compliance-driven to insight-led Passive validation to active challengeAnd critically, it creates the space to challenge reports and assumptions - including the effectiveness of governance itself.A stronger approach to assurance: embedded, targeted and influentialLeading organisations are leaning on internal audit to perform assurance over transformation programmes beyond periodic reviews into something more integrated and influential. In these organisations, assurance is:Embedded at the governance layer - supporting steering committees and boards with independent challenge rather than just periodic reporting Focused on decision quality - assessing whether governance forums are interrogating risk or simply accepting updates Targeted and risk-led - deploying deep dives into specific areas based on emerging signals, not just during audit cycles Continuous rather than episodic - providing real-time insight as risk evolvesIn this model, assurance becomes part of the control environment. It strengthens governance through internal audit asking the difficult questions:Are we making the right decisions, or are we looking to reach decisions quickly? Are risks being surfaced, or are they managed through narrative? Is confidence justified, or is it assumed?Six assurance lenses to assess transformation programme progressAt the core of effective transformation programme assurance are six critical lenses to move beyond surface-level RAG reporting to a more structured, evidence-based approach:Transformation and visionIs the purpose of the project still clear, and is the case for change still valid? Are target outcomes defined and benefits owned? Or has the vision drifted?Governance and leadershipAre decisions being made with clarity and challenge, or are they simply accepted? Is senior executive support visible and active? Does reporting tell the real story and is it validated?Capability and engagementDo we have the right people, capacity and vendor oversight to deliver expected results and achieve agreed-upon milestones? Are stakeholders genuinely engaged? Are single points of failure being mitigated?Delivery managementIs the transformation project plan achievable and being delivered with discipline? Is the critical path monitored and contingency protected? Is the RAID log actively closing items?SolutionIs the solution to come from the transformation initiative being defined, designed, built and deployed to work on a practical level? Are requirements stable and quality embedded? Is business readiness independently assessed?TechnologyIs the underlying technology fit, secure and supportable? Are cyber, data, integration and migration risks built in from the start as opposed to bolted on at the end?Individually, these lenses reveal early-warning signals. Together, they provide a far more reliable view of delivery confidence than any RAG dashboard.The signals that matter and why they’re missedThe earliest indicators of delivery failure with transformation programmes rarely appear in formal reports. Instead, they show up in patterns, inconsistencies and often in what isn’t being said - signals that sit beneath formal reporting but speak volumes about delivery risk.Here are some “red flag” signals to watch for:Repeated re-baselining of schedules without clear rationale RAID logs growing faster than issues are resolved, or RAID logs failing to grow at allMisalignment on priorities between sponsor and delivery team Scope expanding while timelines remain fixed Business readiness consistently deprioritised Clear gaps between formal reporting and informal sentimentThese are not “issues” yet. They are conditions for failure.And they are only visible through independent, triangulated assurance – dashboards won’t reveal such red flags.Reporting focused decisions vs. documentationEven when assurance identifies the right risks, its impact is often diluted in how those insights are communicated and acted on.Traditional reporting tends to:Document findings rather than articulate risk. Focus on process rather than outcomes. Inform, but not influence.High-impact assurance reporting achieves the opposite. It:Leads with a clear confidence assessment. Connects issues directly to delivery outcomes (cost, time, benefits). Surfaces trade-offs and decisions required. Enables boards and executives to act — not just observe.A simple test:Does your assurance report change the conversation in the room, or is it merely documenting lists and results?The opportunity for internal auditExpectations of assurance are shifting.Executives don’t want more reporting.They want better insight, earlier. Such insight, which we call decision intelligence, is the focus of our recent whitepaper, From Assurance to Decision Intelligence: The Future of Internal Audit.This creates a significant opportunity for internal audit to step into a more strategic role by:Providing independent views on delivery confidence Challenging optimism and narrative bias Strengthening governance through informed questioning Identifying systemic risks before they become visible failuresThe capabilities already exist within internal audit when it comes to evidence gathering, structured thinking and risk communication. The shift is in how it is applied.Final thoughtsRAG reporting isn’t going away. But it should no longer be relied upon as the single source of truth and insight. Because when everything looks green but confidence is quietly collapsing, the real risk isn’t what’s being reported. It’s what isn’t.