When the Rulebook Outruns the Roadmap

Essay·Giovanni Leonardi·December 2006·11 min read

A strategy asks the organisation to believe in a future; a regulation asks only that it survive a date.

Executive Summary

A capability sits on the technology roadmap for three years, admired by everyone and funded by no one. Then a supervisor publishes a reporting deadline, and the same capability is built in a single quarter. This essay is about that reversal, and about why it recurs so reliably across regulated organisations that it has stopped surprising the people who live through it.

The argument runs against the grain of how we usually talk about compliance. We treat regulation as a tax on transformation — a cost centre, a drag, the line item that consumes the budget the business wanted for something more ambitious. Yet watch what actually gets built, and a stranger picture emerges. Regulation is, more often than we care to admit, transformation’s most effective sponsor. It supplies the three things a strategy can seldom summon on its own: an unarguable mandate, a fixed external date, and sustained attention at the top of the house.

This essay traces the structural forces that give a compliance deadline that force, then turns the observation over, because the pattern is not an unmixed good. Capability bought under a deadline tends to be shaped like the deadline — narrow, defensive, and costly to live with once the auditors have gone. It closes on what the pattern reveals about the distance between transformation intent and transformation reality, and on what a clear-eyed practitioner does with a sponsor they did not choose.

The quarter that funded three years of roadmap

Every organisation of any size carries a small graveyard of sensible ideas. The customer data that lives in nine systems and agrees with itself in none. The reference-data store that everyone knows should be single and is stubbornly plural. The identity and access tangle that the security team has flagged in every annual review for as long as anyone can remember. These are not secrets. They sit on the roadmap, in the risk register, in the architecture board’s minutes. They are endorsed by all and funded by none, because there is always something with a nearer return.

Then the letter arrives. A supervisor sets out a new transaction-reporting obligation, or a capital calculation that must be evidenced, or a client-classification rule that must be enforced at the point of sale — with a date attached. And the capability that could not command a quarter of a million pounds across three planning cycles is suddenly resourced, staffed, and delivered inside two.

I have watched a data-quality programme that had been “next year’s priority” for four consecutive years complete in eleven weeks once a reporting deadline made its absence a regulatory breach rather than an architectural regret. Nothing about the underlying problem had changed. The data was no dirtier and no cleaner than the month before. What changed was that the cost of inaction acquired a date and a signature. The strategy had described the destination for years. The rulebook simply made not-arriving unaffordable.

The capability was never the hard part. Securing the mandate to build it was. Regulation does not solve the engineering problem — it dissolves the political one.

Why the roadmap stalls where the rulebook moves

To understand the reversal, it helps to be honest about why good technology strategy stalls in the first place. It rarely stalls for want of a good idea. It stalls because a discretionary investment must win an argument it can never quite win.

Consider what a strategic capability — a unified customer view, say — has to overcome to get funded on its own merits:

  • Its benefits are diffuse and deferred. They accrue to several functions, none of which owns the cost, over a horizon longer than the budget cycle that must approve it.
  • Its sponsor is internal and outrankable. However senior the architect, someone with a revenue number can always argue that this quarter’s pipeline matters more, and usually will.
  • Its business case rests on contestable assumptions. Every figure in it can be discounted, deferred, or disputed, because nothing external compels agreement.
  • It competes in an open field. It must beat every other good idea for the same money, every planning round, indefinitely.

Now set beside it the same capability wearing a compliance badge. A regulatory obligation inverts each of those weaknesses in turn:

  1. The benefit is no longer diffuse; it is binary and immediate — remain licensed, or do not.
  2. The sponsor is no longer outrankable; it is external and unarguable — no revenue number outranks the regulator.
  3. The assumptions are no longer contestable; the date is fixed and published by someone the board cannot overrule.
  4. The field is no longer open; the work is ring-fenced — mandatory spend does not compete with discretionary spend, it precedes it.

This is the whole mechanism. A strategy asks the organisation to believe in a future; a regulation asks only that it survive a date. Belief is negotiable and can be deferred a quarter at a time forever. Survival is not. The regulator does for the architect what the architect could never do for himself: it removes the option of saying no.

There is a temporal dimension too, and it is underrated. Strategy operates on a horizon the annual budget keeps truncating; each planning round is an opportunity to defer. A regulatory deadline is immovable and external — it cannot be slipped by the internal politics that slip everything else. That immovability is precisely what converts a permanent “soon” into an actual “by March”.

The accelerator is real — and so is the debt it leaves

It would be a comfortable essay that stopped there, with regulation cast as the unlikely hero that funds the work strategy could not. The honest version is less tidy, and anyone who has lived through the aftermath of a large compliance programme knows why.

Capability bought under a deadline tends to be shaped like the deadline. And a compliance deadline has a particular shape: it is narrow, it is defensive, and it is indifferent to everything the obligation does not explicitly require.

The strongest case against celebrating the accelerator is worth stating at full strength, because it is largely correct. When a data-quality platform is built to satisfy a transaction-reporting rule, it is built to satisfy that rule — for the fields the report needs, to the tolerance the report demands, on the timetable the report imposes. The wider prize the strategy was chasing — the same clean data serving pricing, servicing, and risk alike — is not on the critical path, so it is not built. What gets delivered is a reporting engine wearing the costume of a data strategy. It clears the audit and leaves the architecture no better arranged than before, sometimes worse, because now there is a second data store to reconcile rather than one to replace.

The same deadline that funds the work also deforms it. Under time pressure, teams retrofit rather than redesign; they bolt the control onto the system that exists rather than building the system that should. Point solutions multiply, each mandated, each defensible in isolation, each adding to the tangle the strategy was meant to resolve. The organisation ends a compliance cycle having spent heavily and moved, in architectural terms, sideways. It has bought motion and called it progress.

“Regulation funds the work that strategy could not — and then, left alone, builds the wrong version of it in the wrong place at the wrong tempo.”

So the accelerator cuts both ways. It is genuinely the most reliable source of sponsorship a transformation agenda will ever encounter. It is also the least discriminating architect in the building. To treat it as an unqualified good is as naive as treating it as a pure cost. It is neither. It is a force — and a force is defined by how it is harnessed, not by whether one approves of it.

Harnessing a sponsor you did not choose

What, then, does the practitioner do who has understood all this? Not resist the accelerator — that is both futile and wasteful — and not surrender to it either, taking whatever narrow thing the deadline would build by default. The craft lies in the space between: using the mandate’s force to move the strategy’s payload.

The organisations that do this well share a habit of mind. They treat every compliance programme as a delivery vehicle that has, unusually, already been funded and sponsored — and they ask what strategic capability could ride inside it without jeopardising the date.

  • Keep a costed roadmap ready to be adopted. The firms that convert compliance spend into strategic capability are the ones that had the target architecture drawn before the letter arrived. When the mandate appears, they do not scramble to invent a solution; they reach for the design already on the shelf and let the deadline fund it. The unfunded roadmap is not a failure — it is the ammunition, waiting for a mandate to fire it.
  • Distinguish the two costs explicitly. For every mandated build, separate the cost of mere compliance from the marginal cost of doing it in the strategically right place. The gap is usually far smaller than anyone assumes, because the expensive part — securing the mandate, mobilising the programme, disturbing the systems — has already been paid for by the obligation. Building the reporting store as a proper reference-data service rather than a throwaway extract is often a modest increment on a cost the firm is already bearing.
  • Govern for the strategic tail, not just the compliance head. Put someone in the programme whose success is measured by what the organisation still owns twelve months after the audit closes — not by the audit itself. Without that person, the deadline optimises ruthlessly for the date and leaves nothing behind. With them, the same spend can leave a genuine capability standing.
  • Refuse the false economy of the retrofit. The bolt-on that saves a fortnight against the deadline routinely costs years against the architecture. Someone senior has to be willing to spend the fortnight — and to defend spending it — knowing the deadline will punish them for it in the short run and the architecture will reward them for it in the long one.

None of this is free, and it is right to acknowledge the counter-pressure honestly. Riding strategy on a compliance programme adds scope, and scope adds risk to a date that must not slip. There will always be a voice — often a sensible one — arguing to strip the programme back to the bare obligation and do the strategic version “properly, later”. That voice is not foolish; it is simply mistaken about “later”, which in a regulated organisation rarely comes. The discipline is to load the vehicle heavily enough to carry the strategy, and never so heavily that it misses the date. That judgement is the whole of the craft, and it cannot be proceduralised.

What the pattern tells us about ourselves

Step back from the mechanics and the pattern says something uncomfortable about how transformation actually works, as opposed to how we describe it.

We like to believe that organisations change because they choose to — that a compelling strategy, well argued, mobilises the will and the money to reshape the enterprise. The evidence of the compliance accelerator suggests something humbler. Large organisations are extraordinarily good at deferring discretionary change and extraordinarily bad at deferring mandated change, and the gap between those two capacities is where most real transformation quietly happens. We do not change because we are persuaded. We change because we are compelled, and we dress the compulsion up as strategy afterwards.

That is not cynicism; it is a design insight. If mandate, deadline, and unarguable sponsorship are the active ingredients — and the compliance accelerator strongly suggests they are — then the leadership task is not merely to produce better strategies. It is to manufacture, for the changes that matter most, some of the same binding force that regulation supplies for free. Internal deadlines that cannot be moved. Sponsorship that cannot be outranked. Consequences for inaction that are real rather than rhetorical. The organisations that transform without waiting for a regulator are the ones that have learned to impose that discipline on themselves — to treat their own most important commitments with the seriousness they would only otherwise extend to a supervisor’s letter.

Most do not manage it, which is why the regulator remains the most effective change sponsor many organisations will ever have. The lesson is not to be grateful for that. It is to notice, with some honesty, what it reveals: that transformation intent, however sincere, is weaker than we like to think, and that the gap between intent and reality is closed most reliably not by persuasion but by compulsion.

The rulebook will keep outrunning the roadmap for as long as we let survival do the work that belief could not. The practitioner’s task is not to resent that, nor to depend on it, but to be ready for it — roadmap costed, architecture drawn, and the strategic payload packed and waiting for the next mandate that comes through the door.


More from Transformation