Written Evidence: National Preparedness and Resilience
House of Commons Public Accounts Committee
Date: 22 April 2026
Submitted by: Vsevolod Shabad, Independent Researcher; Principal Enterprise Architect at a FTSE 100 company. This submission is made in a personal capacity.
AI Disclosure: Generative AI (Claude, Anthropic) was used for structuring and editing. As a non-native English speaker, the author used AI to ensure clarity of expression. All arguments, findings, and recommendations are the author's own.
Summary
This submission addresses the Committee's three areas of inquiry on shared services. On the question of progress since 2022, the author's contribution is not to assess whether milestones have been met but to examine whether the governance framework is capable of detecting the failure modes that matter. Regarding whether clusters are on track on time and budget, the author does not have access to cluster-specific delivery data but offers a structural prediction from governance research about how such data can be systematically misleading[1]. Regarding interdependencies and interoperability, the submission draws on the author's empirical research and professional experience as a principal enterprise architect at a FTSE 100 company.
The central argument: when shared services programmes fall short of their intended outcomes, it is rarely because the technology is wrong — it is because the governance architecture treats technology investment as a procurement problem when it is a decision-making-under-deep-uncertainty problem. The same structural pattern has produced cost overruns and delivery shortfalls across UK public sector technology programmes for decades, and the Shared Services Strategy is architecturally exposed to the same failure modes.
Evidence
The governance architecture problem
- The Committee asks whether the government understands the progress made on shared services since 2022. The more consequential question is whether the governance framework through which progress is measured can detect the failure modes that matter — not whether milestones are being met, but whether the assumptions embedded in the original business case remain valid as the programme evolves.
- Research into technology investment governance in the UK public sector identifies a four-stage failure chain that recurs across UK public sector technology programmes:
- Stage 1 — Measurement failure: Forecasts used to justify investment commitments systematically overestimate benefits and underestimate costs. Flyvbjerg's meta-analysis of 258 infrastructure projects across 20 countries found average cost overruns of 28% across all types and 45% for rail.[2] The EU TEN-T programme averaged 17 years of delays across five projects, with 47% real cost increases across eight flagships.[3]
- Stage 2 — Reporting failure: Once commitments are made, reporting structures incentivise continuation. Multi-year CAPEX commitments create institutional momentum: the sunk cost is visible; the opportunity cost of continuing is not. Governance layers report progress against the plan rather than progress against reality.
- Stage 3 — Design assumption failure: The original business case embeds assumptions about technology evolution, user adoption, interoperability requirements, and the stability of the policy environment. These assumptions are treated as fixed parameters rather than testable hypotheses. When they fail — as they inevitably do over multi-year programmes — the governance framework has no mechanism for structured revision.
- Stage 4 — Scaling failure: Programmes that survived Stages 1–3 encounter scaling effects that the original design did not anticipate. Coordination costs grow faster than capability. Integration complexity increases non-linearly with the number of participating departments — a structural property observed in software engineering since at least Brooks's canonical analysis of interconnection overhead.[4]
- UK shared services history illustrates all four stages. £1.15 billion has been spent since 2021, with £459 million in costs since 2020.[5] The current Shared Services Strategy assumes that clustering departments around shared platforms will deliver efficiencies. This assumption depends on interoperability between legacy systems, consistent data standards across departments, and stable requirements over the programme's lifetime — precisely the conditions that large-scale government technology programmes have historically struggled to sustain.
Whether clusters are on track to deliver on time and within budget
- The author does not have access to cluster-specific delivery data and is not in a position to offer competent evidence on whether individual clusters are meeting their milestones, budget envelopes, or intended longer-term improvement targets. The Committee will have access to better-informed witnesses on these specifics.
- What the governance research does support is a structural prediction: programmes organised under forecast-dependent capital commitment architectures — where multi-year budgets are committed against an original business case rather than annually revised against current conditions — will systematically underreport delivery risk until the risk materialises as cost overrun or schedule slippage. The reporting problem (Stage 2 above) means that cluster delivery data reported to the Cabinet Office may show acceptable progress against plan even as underlying assumptions deteriorate. The Committee should therefore examine not only whether clusters are reporting on-track delivery but also whether the reporting framework is capable of detecting off-track delivery before it becomes irreversible.
Interdependencies and interoperability
- The Committee specifically asks whether government can manage interdependencies between shared services and other developments. The author's professional experience as an enterprise architect at an FTSE 100 company provides a directly relevant perspective.
- Interoperability in shared services is not a technical problem with a technical solution. It is a governance problem that manifests technically. Technical interoperability — the capacity to exchange data — is a necessary but not sufficient condition. Semantic interoperability — shared taxonomy and shared meaning, so that data carries the same interpretation on both sides — is the condition most commonly neglected when programmes focus on system integration.[6] When two departments share a finance platform, the technical integration may succeed while the governance integration fails — because each department's chart of accounts reflects different policy assumptions, different reporting obligations, and different audit requirements. The platform works; the shared interpretation of what the platform produces does not.
- This governance interoperability gap becomes critical when shared services interact with other government digital programmes. The Government Digital Service (GDS), the Central Digital and Data Office (CDDO), and departmental digital teams each operate with different architectural standards, different procurement frameworks, and different timelines. A shared services platform designed against 2022 requirements must interoperate with departmental systems being redesigned against 2025 requirements, using standards that may not have existed when the shared services architecture was specified.
- Research on technology investment governance identifies this as a predictable consequence of forecast-dependent capital commitment architecture. When a programme commits to a technology architecture based on multi-year forecasts, it necessarily commits to a set of interoperability assumptions. Those assumptions become progressively less valid as the environment evolves, but the governance framework treats them as fixed. The result is that interoperability is tested at delivery, when the cost of failure is highest, rather than at design, when the cost of revision is lowest.
The Annual Portfolio Model alternative
- Research into technology investment governance proposes an alternative approach called the Annual Portfolio Model, whose core principles are directly applicable to shared services governance:[7]
- Annually revised expenditure envelopes replace multi-year CAPEX commitments. Rather than committing £X over five years, the programme is funded in annual tranches with explicit decision points. At each decision point, the business case is tested against current reality, not against the original forecast.
- Staged commitments with exit options replace binary go/no-go gates. Each stage of the programme includes a pre-defined exit option — not as an admission of failure but as a governance mechanism that makes continuation a deliberate decision rather than a default.
- Fast-and-frugal prioritisation rules replace comprehensive cost-benefit analysis for in-programme decisions. Research in ecological rationality demonstrates that simple decision rules outperform complex optimisation models in environments characterised by uncertainty, time pressure, and incomplete information — precisely the conditions of large-scale technology programme management.[8]
- The HM Treasury Green Book provides a theoretically sound appraisal framework for estimable risks. However, technology investments — and shared services programmes specifically — operate under conditions of deep uncertainty,[9] where the probability distributions required for conventional cost-benefit analysis cannot be reliably estimated. Applying an estimable-risk framework to a deep-uncertainty problem produces the systematic overconfidence that underlies the UK's persistent pattern of technology programme cost overruns and delivery shortfalls.
What the Committee should examine
- Based on the evidence above, the author recommends that the Committee examine:
- Whether the Shared Services Strategy's business case has been formally revised since 2022. If the original assumptions about technology standards, departmental readiness, and interoperability requirements have not been tested against current conditions, the programme is navigating by a map that may no longer match the terrain.
- Whether exit options exist at each programme stage. If the governance framework does not include structured exit points with pre-defined criteria, then continuation is a default rather than a decision. The history of UK technology programmes shows that defaults are the mechanism through which costs escalate — not because anyone decides to overspend, but because no one has the authority, information, or institutional incentive to stop.
- Whether interoperability is being tested against current requirements or original specifications — and whether testing covers semantic interoperability as well as technical integration. If shared services platforms are being assessed for interoperability against the technical standards that existed when the programme was designed, rather than the standards being implemented by the departments they will serve, then a delivery-stage interoperability failure is predictable. If testing validates only data exchange capacity without verifying shared taxonomy and shared interpretation of outputs, the same failure can occur even when the technical integration succeeds.
- Whether decision latency within the programme governance structure is measured. Large shared services programmes generate governance layers — programme boards, design authorities, change advisory boards, cluster governance groups. Each layer adds decision latency. If the time between a problem being identified and a decision being made is longer than the time between technology standard changes, the programme cannot adapt fast enough to remain interoperable. This is a structural property of the governance architecture, not a failure of individual decision-making.
- Whether the programme accounts for capability erosion. Technology programmes that automate functions progressively erode the human judgment needed to manage exceptions, respond to failures, and satisfy regulatory scrutiny.[10] If shared services automation reduces departmental capacity to manage finance, HR, or procurement independently, the government's resilience to shared platform failure is reduced in proportion to the efficiency gained. This trade-off should be explicitly governed, not discovered in a crisis.
Lessons from private sector enterprise architecture
- The author's professional role as a principal enterprise architect at an FTSE 100 company provides additional perspective. Private sector shared services programmes face the same structural challenges but operate with three governance advantages that government programmes typically lack:
- Market discipline. If a private sector shared services platform fails to interoperate, the cost is visible in operational performance and ultimately in financial results. Government programmes lack this feedback mechanism; failure manifests as delayed policy outcomes, which are attributable to multiple causes and therefore to none.
- Architecture governance authority. In well-governed private sector programmes, an enterprise architecture function has the authority to enforce interoperability standards across participating business units. Government shared services programmes typically lack equivalent authority; departmental sovereignty creates negotiation where enforcement is needed.
- Technology refresh cycles. Private sector organisations routinely refresh technology platforms on 3–5 year cycles. Government programmes often operate on 7–10 year cycles or longer. Shared services designed for a 5-year lifecycle that operate for 10 years accumulate technical debt that degrades interoperability progressively.
- The Committee may wish to examine whether the Shared Services Strategy has equivalent governance mechanisms — specifically, whether there is a function with authority to enforce interoperability standards across clusters, and whether the programme's governance accounts for the divergence between planned and actual technology refresh timelines.
[1] Vsevolod Shabad et al., Technology Investment Governance under Deep Uncertainty: The Case for Annual Portfolio Models in Public Infrastructure, 2026, 6469862, SSRN.
[2] Bent Flyvbjerg et al., Megaprojects and Risk: An Anatomy of Ambition (Cambridge University Press, 2003), https://doi.org/10.1017/CBO9781107050891.
[3] European Court of Auditors, EU Transport Infrastructure: Further Delays and Some Cost Increases, but a Reinforced Governance Framework Is in Place for the Future (an Update of ECA Special Report 10/2020) (ECA, 2026), https://doi.org/10.2865/6744858 .
[4] Frederick P. Brooks, The Mythical Man-Month, Anniversary ed (Addison-Wesley, 1995).
[5] National Audit Office, Update on Government Shared Services (2026), https://www.nao.org.uk/reports/update-on-government-shared-services-2026/.
[6] European Commission, European Interoperability Framework – Implementation Strategy (2017), https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:52017DC0134.
[7] Shabad et al., Technology Investment Governance under Deep Uncertainty: The Case for Annual Portfolio Models in Public Infrastructure.
[8] Gerd Gigerenzer, Simple Heuristics That Make Us Smart (Oxford University Press, 2000).
[9] Frank H Knight, Risk, Uncertainty, and Profit (Houghton Mifflin Company, 1921), https://oll.libertyfund.org/titles/knight-risk-uncertainty-and-profit.
[10] Vsevolod Shabad, "The Three-Year Test: Will Accountability Remain When the Agency Goes?," I by IMD (2026), https://www.imd.org/ibyimd/artificial-intelligence/the-three-year-test-will-accountability-remain-when-the-agency-goes/.