Fund the Evidence, Then Fund the Scale

Analysis·Giovanni Leonardi·August 2026·10 min read

The failure is not a lack of information. It is a lack of decision rights attached to new information.

Approval is not control

A digital programme enters its first approval meeting with an awkward burden. It must describe the service, cost, benefits, timetable and risks before discovery has resolved the most important uncertainties. The team responds rationally: it turns assumptions into scope, combines uncertain work into a programme large enough to survive the funding process, and presents a confidence level the evidence does not yet justify. Once approved, that description becomes a commitment. Changing it looks like failure; stopping it looks worse.

This is often treated as a delivery problem. It begins earlier. The control system has asked for the wrong evidence at the wrong time.

New Zealand’s July 2026 Digital Reset Plan makes this diagnosis unusually explicit. Its reviewers describe fragmented investment, weak portfolio visibility, limited central authority and approval models designed for major capital infrastructure being applied to smaller, iterative and increasingly operating-expenditure digital work [S1]. The plan proposes portfolio reprioritisation, a narrower but stronger central digital authority, lead-agency delivery and changes to funding, risk and reporting.

The plan is a current signal, not proof that the proposed model will work. It was produced through a rapid, three-week review using documents, interviews and desktop research. It has no implemented counterfactual. Its value lies in exposing a wider pattern: funding, delivery, assurance and decision rights often operate on different clocks.

Four clocks, one programme

The distortion becomes clearer when the four clocks are separated.

The funding clock allocates money annually or through multi-year business cases. It favours bounded scope, forecast benefits and planned expenditure.

The delivery clock produces evidence through discovery, releases, operational use and technical learning. Its useful intervals may be weeks or months rather than budget years.

The assurance clock often concentrates scrutiny before commitment and at formal gateways. It can be weak between those events, precisely when evidence improves.

The authority clock determines how quickly someone can change priority, resolve a dependency, redirect funds or stop work. In federated systems, this clock can be the slowest because accountability sits with one organisation while authority is distributed across several.

When these clocks diverge, teams learn without being able to act on the learning. A discovery phase reveals that a shared identity service is the critical dependency, but the programme is funded to build a local solution. A pilot shows that user demand is concentrated in one transaction, but the approved benefits depend on delivering the full suite. An architecture review identifies duplication, but no portfolio body has authority to reallocate funds across agencies.

The failure is not a lack of information. It is a lack of decision rights attached to new information.

How certainty becomes lock-in

The mechanism has five steps.

  1. Early certainty is demanded. Approval requires detail before the work can produce it.
  1. The proposal is distorted. Teams enlarge scope, suppress uncertainty or hide small improvements in operating budgets.
  1. Commitment hardens. Procurement, funding and public promises attach to the proposed scope, making redirection politically and administratively costly.
  1. The portfolio loses sight. Inconsistent cost and outcome data prevent comparison, reuse and movement of resources.
  1. Delivery inherits the design error. Maintenance is deferred, common capabilities are duplicated and compliance with process becomes a proxy for progress.

The New Zealand review reports this sequence as a system diagnosis: cumbersome approval can encourage larger business cases, concealed discretionary work, delayed incremental improvement and accumulating technology debt [S1]. A 2025 UK review reached a parallel conclusion about complex governance, slow decisions, weak maintenance funding and the need for better portfolio metrics [S5]. OECD guidance likewise treats digital investment as a lifecycle of strategic planning, implementation and oversight, rather than a single approval event [S2].

These sources converge, but they do not establish that capital controls alone cause failure. Leadership, capability, procurement, fiscal pressure and fragmented mandates can produce the same symptoms. The defensible conclusion is conditional: fixed-scope control becomes damaging when uncertainty is material, learning is available during delivery and the organisation cannot convert that learning into funding decisions.

The strongest case for conventional gates

The sceptical argument deserves more than a ritual acknowledgement. Flexible funding can become a polite name for indefinite experimentation. Teams can repeatedly claim that the next increment will reveal the answer while total cost rises, benefits remain vague and dependencies grow. Central portfolio bodies can add another queue. Lead agencies can receive accountability without authority over partners. Method labels can conceal weak planning.

The UK National Audit Office found that agile approaches at scale still require long-term planning, coordination and truthful reporting, and that agile is not suitable for every programme [S4]. The US Government Accountability Office presents incremental development as a risk-control practice, not an exemption from programme monitoring [S3]. The New Zealand review itself points to a large, multi-year Inland Revenue transformation as a positive example of stable funding, executive accountability, strong capability and staged delivery [S1].

This evidence rules out an easy “agile good, gates bad” answer. Conventional gates remain appropriate when commitments are irreversible, safety-critical, procurement-heavy or tied to fixed legal deadlines. A data-centre contract, core-system cutover or long-term vendor commitment cannot always be broken into low-consequence experiments.

The sharper distinction is between evidence-matched gates and calendar-matched gates. The first intensify with exposure, dependency and irreversibility. The second occur because the process says it is time, regardless of what the programme has learned.

Fund evidence before scale

Evidence-matched governance changes what each funding increment is buying.

The first increment buys the right evidence: user need, service demand, technical feasibility, dependency mapping and realistic operating cost. The next buys a bounded release that can test adoption, performance and delivery capability. Later increments buy scale only when working-service and benefits evidence justify greater exposure.

This is not rolling approval without limit. Each increment needs a defined question, maximum exposure, evidence standard and decision owner. The control is a repeated choice to continue, scale, redirect or stop.

Consider an illustrative cross-agency benefits service. Under a conventional model, one agency seeks full funding for a three-year platform, specifies all participating services and commits to a common data model before testing the hardest exchanges. Under an evidence-matched model, the portfolio first funds discovery across agencies. It then funds one high-volume transaction and the minimum shared capability needed to support it. The release is judged on completion time, error rate, operating cost, user take-up, reuse and unresolved legal or data dependencies. Only then does the portfolio decide whether to scale the shared service, redirect to a different architecture or stop.

The illustration is not a claim that staged delivery guarantees success. It shows where control moves: from confidence in promised scope to evidence about the next unit of commitment.

Three levels of authority

Funding reform without decision-rights reform will disappoint. The operating model needs three distinct levels.

Portfolio authority

A central portfolio body sets priorities, owns the comparative view of investment and resolves trade-offs across organisations. It decides which common capabilities deserve funding and which work should pause or retire. It must have credible technical, commercial and financial capability; formal power without expertise simply centralises delay.

Sponsor accountability

The programme sponsor owns the outcome, the case for continued funding and the integrity of total-cost reporting. The sponsor cannot delegate benefits to the delivery team or treat approval as permanent entitlement to the remaining budget.

Delivery ownership

The lead delivery unit owns increments, operations and the evidence produced by real use. It needs authority over resources and a workable route to resolve dependencies. “Accountable” without control of people, contracts or partner decisions is a label, not an operating model.

The centre should not own every delivery decision. Its role is to set standards, arbitrate shared concerns and move resources at portfolio level. Delivery units need room to learn inside bounded exposure. The boundary between them should be written as decision rights, not implied by committee membership.

Assurance should follow exposure

A practical assurance model asks two questions at every stage: what have we learned, and what becomes harder to reverse if we continue?

Decision Evidence required Assurance focus
Fund discovery User need, options, dependencies Learning quality and bounded cost
Fund first release Working scope, architecture, delivery capability Service risk and operational readiness
Scale Adoption, performance, unit cost, benefits Total exposure and cross-portfolio trade-offs
Continue operations Service outcomes, lifecycle cost, technical debt Value, resilience and retirement options
Commit irreversibly Mature design, procurement and risk evidence Independent challenge and conventional gate

This model preserves the discipline of a business case while allowing the case to evolve. Forecasts remain necessary, but they are labelled as forecasts. Actual service evidence progressively replaces assumption. Assurance becomes more demanding as the cost of being wrong rises.

It also makes stopping visible. A portfolio that never stops or redirects work is not demonstrating confidence; it is revealing that learning has no resource consequence. Stop decisions need agreed triggers, a named authority and a way to release people and money. Otherwise staged funding merely divides one large commitment into a series of automatic smaller ones.

What to measure

The dashboard should reveal whether governance is producing better decisions, not simply faster approvals.

  • Time from identified need to first usable outcome.
  • Forecast error in cost, timetable and demand at each funding stage.
  • Benefits realised and operating cost after release.
  • Technical-debt movement and maintenance funded versus deferred.
  • Reuse of common capabilities across organisational boundaries.
  • Decision lead time for scale, redirect and stop choices.
  • The number and quality of actual resource reallocations.

These measures need context. A programme with high uncertainty should not be punished for revising its forecast after discovery; that revision is evidence the control worked. A programme should be challenged when uncertainty remains unchanged after funded learning, or when reported progress cannot support a decision.

Comparisons also require care. There is no robust evidence yet that New Zealand’s proposed combination of central authority, lead-agency delivery and funding reform will outperform its current system. Differences in capability and programme complexity can easily masquerade as differences in governance. Matched cohorts, explicit baselines and recorded decision histories would strengthen future evaluation.

The changed question

Digital governance fails when it confuses the approval of a plan with control of an evolving commitment. The alternative is not permissive agility, weaker fiscal discipline or the abolition of business cases. It is a system in which evidence, authority and exposure move together.

That system funds learning before scale, preserves a complete view of cost, keeps conventional gates for irreversible commitments and gives someone real authority to act on what delivery reveals. Central coordination is valuable where priorities, standards and dependencies cross organisational boundaries. It is harmful when it becomes another place where decisions wait.

The decisive assurance question is no longer “Was the business case approved?” It is “What evidence now justifies the next unit of commitment?”

Sources

  1. New Zealand Public Service Commission — Delivering Digital Government: Reset Plan — July 2026 — https://www.publicservice.govt.nz/assets/DirectoryFile/Digital-Reset-Plan-2026.pdf
  2. OECD — Effectively Managing Investments in Digital Government — June 2025 — https://www.oecd.org/content/dam/oecd/en/publications/reports/2025/06/effectively-managing-investments-in-digital-government_2fc9fbbf/5c324e91-en.pdf
  3. US Government Accountability Office — GAO Agile Assessment Guide: Best Practices for Adoption and Implementation — 15 December 2023 — https://www.gao.gov/products/gao-24-105506
  4. UK National Audit Office — The challenges in implementing digital change — 21 July 2021 — https://www.nao.org.uk/wp-content/uploads/2021/07/The-challenges-in-implementing-digital-change.pdf
  5. UK Government — Performance Review of Digital Spend: Enabling Strategic Investment and Innovation — 12 March 2025 — https://www.gov.uk/government/publications/performance-review-of-digital-spend/performance-review-of-digital-spend-enabling-strategic-investment-and-innovation

Giovanni Leonardi  ·  About  ·  LinkedIn

Leave a Reply

Your email address will not be published. Required fields are marked *