Certified but Incapable: When Process Maturity Becomes Process Paralysis

Essay·Giovanni Leonardi·December 2007·17 min read

The certificate measures the codifiable, and capability lives mostly in the un-codifiable.

Executive Summary

Somewhere in most large organisations there is a certificate on a wall, or a maturity rating in a board pack, that no longer describes anything true. The organisation has been assessed, accredited, and pronounced mature; its methods are documented, its practitioners are certified, its processes conform. And yet the programmes still slip, the benefits still fail to arrive, and the people doing the work will tell you privately that the method has become something to be survived rather than used.

This essay is an attempt to understand that gap — the distance between a method well kept and a change well made — because it is one of the most revealing features of organisational life. We have spent the better part of a decade building an elaborate apparatus of best-practice method: PRINCE2 for projects, the newly rewritten ITIL for services, CMMI and COBIT for maturity and control, gateway reviews and assurance regimes layered on top. Each was a reasonable answer to a real problem. Taken together, and taken too literally, they have produced a condition that deserves a name: process paralysis, the state in which an organisation is so busy conforming to how work should be done that it loses the capacity to actually do it.

The argument here is not that method is the enemy. That would be as foolish as the orthodoxy it criticises. Method encodes hard-won lessons; without a shared way of working, a large organisation degenerates into a thousand private improvisations. The argument is narrower and, I think, more useful: that we have confused conformance with capability, mistaken the certificate for the competence, and in doing so revealed something uncomfortable about how organisations believe change happens. They would rather buy a method than build a judgement. And a method, however good, cannot be bought — only the documentation can.

The Certificate on the Wall

Consider a scene that will be familiar to anyone who has spent time inside a transformation programme. A division has just passed its maturity assessment — let us say it has been rated at the third level of a five-level model, the level at which processes are defined, documented, and standardised across the organisation. There is genuine satisfaction in this. It took eighteen months, a dedicated process improvement team, a great deal of workshop time, and a consultancy engagement that cost more than anyone quotes out loud. The rating goes into the annual report as evidence of operational discipline. The programme director is congratulated.

In the same building, on the same week, a flagship programme is nine months late. Its stage gates have all been passed — every one of them, on time, with the required documentation signed off. Its risk register is immaculate and updated fortnightly. Its highlight reports have read amber for two quarters and are about to read amber again. Nobody involved is incompetent; several are certified to the highest available level. And yet the thing the programme exists to deliver is not arriving, and no one in the governance chain can say with confidence why.

The two facts sit side by side without touching. The maturity rating and the stalled programme are produced by the same organisation, assessed by the same standards, and they point in opposite directions. This is the pattern worth understanding. It is not an aberration or a failure of execution. It is the normal output of a system that has learned to optimise for the assessment rather than the outcome — and it recurs with such regularity, across sectors and across the years I have watched it, that it can no longer be dismissed as bad luck.

An organisation can be measurably mature and observably incapable at the same time. The two measurements are not in tension because one of them is wrong; they are in tension because they measure different things, and we have persuaded ourselves they measure the same thing.

How Seriousness Became a Synonym for Process

To understand how we arrived here, it helps to remember what the methods were reacting against, because in every case the reaction was justified.

Through the nineties and into this decade, the dominant experience of large IT-enabled change was chaos. Projects ran on the heroics of a few individuals; when they left, the knowledge left with them. Estimates were guesses. Requirements were whatever the loudest stakeholder said last. Failures were spectacular and unexamined, because there was no defined way of working against which a post-mortem could even be conducted. Into that world, method arrived as a genuine liberation. PRINCE2 gave projects a common vocabulary and a defensible structure of stages and products. The maturity models gave organisations a ladder to climb and a language for their own improvement. The service management frameworks, and this year’s substantial rewrite of ITIL in particular, gave the operational side of the house the same disciplined treatment that projects had begun to receive. And behind all of it, the compliance climate that followed the corporate scandals earlier in the decade — the demand for demonstrable control, for auditable process, for evidence that someone was in charge — made documented method not merely useful but, for a listed company, close to mandatory.

So the rise of method was not a mistake. It was a correction, and a needed one. The mistake was subtler, and it crept in through a side door. Once documented process became the visible sign of a serious organisation, it began to substitute for the thing it was meant to signify. Maturity stopped being a means to capability and became an end in itself. The question in the boardroom shifted, almost imperceptibly, from “are we delivering?” to “are we compliant with our method?” — and those are very different questions, though they wear similar clothes.

“We set out to make delivery repeatable, and somewhere along the way we made the documentation of delivery repeatable instead — and mistook the second achievement for the first.”

The shift is easy to miss because each individual step is reasonable. It is reasonable to want a defined process. It is reasonable to want that process documented. It is reasonable to assess how well the documentation is followed, and reasonable to certify the people who follow it. Every link in the chain is sound. It is only the whole chain, followed to its end, that produces the absurdity: an organisation that can prove it is doing everything right and still cannot deliver.

The Mechanism of Paralysis

It is worth being precise about how method turns into paralysis, because the mechanism is not mysterious and naming it is the first step to resisting it.

Method paralyses through accretion. No single control ever seems too expensive. A stage gate is cheap; a risk register is cheap; a quality review is cheap; a compliance checklist is cheap. But controls are added far more readily than they are ever removed, because adding one is a defensible response to any failure — “we will introduce a checkpoint to ensure this never happens again” — while removing one requires someone to accept the risk of its absence. Over years, the controls compound. The process grows a ring for every incident it survives, like a tree, and no one prunes it.

Let me put a number to it, because the abstraction understates the case. On one substantial programme I looked at closely, the team maintained a project initiation document that had grown to over two hundred pages; a change control process that required, on average, eleven days and four signatures to approve a modification that a developer could implement in an afternoon; and a governance calendar in which the programme board, three working groups, a design authority, and an assurance function each met on their own cadence and each required its own pack. When the effort was actually counted, something close to two-fifths of the senior team’s time was being spent not on the change itself but on reporting about, assuring, and governing the change. The people who understood the problem best were the people most fully occupied with describing their occupation to others.

That is the mechanism. It is not that any one activity is wasteful. It is that the aggregate of individually-defensible controls crosses a threshold beyond which the process consumes more judgement than it protects. And there is a second, quieter mechanism working alongside the first.

  • Method displaces judgement by offering to replace it. When a defined process exists for a decision, the incentive to think hard about that decision weakens, because the process will produce an answer and the process is what one will be audited against. Following the method is safe; exercising judgement against the method is exposed.
  • Method rewards the visible over the valuable. What gets measured in a maturity assessment is the existence and observance of process — artefacts, sign-offs, documented adherence. The quality of a decision is far harder to assess than the presence of a decision record, so the record becomes the proxy, and the proxy becomes the target.
  • Method migrates authority away from the people closest to the work. Once the process is the authority, the practitioner’s role narrows to feeding it. Expertise that cannot be expressed as a completed template becomes, in the eyes of the system, invisible.

Each of these would be tolerable alone. Together they produce an organisation in which the safest career move is to follow the method perfectly and deliver nothing, and the most dangerous is to deliver something by stepping outside it.

The Case for the Defence

It would be too easy to stop there, and dishonest, because the strongest argument for method has not yet been heard — and it is a good argument.

The defence runs like this. Large organisations cannot run on judgement alone, because judgement does not scale and does not survive turnover. The heroic project manager who delivers by force of personality is precisely the single point of failure that method exists to eliminate. When that person leaves, a documented method means the work can continue; an undocumented genius means it cannot. Method is how an organisation remembers — how the lessons of one failure become the standard practice that prevents the next, how a thousand people can coordinate without each pair of them negotiating a private understanding. The common vocabulary that PRINCE2 or ITIL provides is not bureaucratic overhead; it is the condition that makes it possible for a project manager in one division to be understood by an assurance reviewer in another. And certification, whatever its flaws, at least guarantees a floor — a certified practitioner may not be excellent, but they will not be ignorant of the basics, and in an organisation of thousands a reliable floor is worth a great deal.

All of this is true. I have seen the alternative — the organisation that prides itself on being too dynamic for process — and it is not a paradise of judgement. It is a place where the same mistakes are made repeatedly because nothing is written down, where every project reinvents its own governance, where the departure of a key individual is a catastrophe, and where “we trust our people” is too often a euphemism for “we have never examined how our people actually work.” Method-free is not the answer, and anyone selling it as the answer is selling the disease as the cure.

So the honest position is not method bad, judgement good. It is that method and judgement are complements that the orthodoxy has turned into substitutes. The defence of method is entirely correct about what method is for. It simply does not notice the point at which method stops serving that purpose and begins to consume it.

Why the Certificate Cannot Carry the Weight

The place where the defence quietly breaks is the certificate — and by certificate I mean the whole apparatus of assessment, accreditation, and maturity rating, not merely the individual qualification.

The problem is one that the quality profession has understood for a long time without quite applying it to itself: you can only certify what you can observe and standardise, and the most important part of capability is neither observable nor standard. A maturity assessment can verify that a defined process exists, that it is documented, and that it is followed. It cannot verify that following it produces good outcomes, because that depends on judgement exercised within the process — on whether the right risks were identified, whether the estimate was honest, whether the difficult stakeholder was managed or merely recorded, whether the amber status was a genuine warning or a ritual hedge. All of that is tacit. It lives in the heads and the hands of experienced people and it does not survive the journey onto a template.

What the maturity model measures What delivery actually requires
That a process exists and is documented That the process is worth following for this situation
That the process is followed consistently That people know when to depart from it, and are trusted to
That artefacts are produced and signed off That the thinking behind the artefacts was real
That practitioners are certified That practitioners have judgement certification cannot confer
That controls are in place That the controls are proportionate to the actual risk

This is why certification and capability come apart, and why the gap is not a temporary imperfection to be closed by better certification. It is structural. The certificate measures the codifiable, and capability lives mostly in the un-codifiable. Improve the certificate all you like — make the assessment more rigorous, the model more granular, the qualification harder to obtain — and you will measure the codifiable part more precisely while the important part continues to escape you entirely. You cannot close the gap by sharpening the instrument, because the instrument is pointed at the wrong thing.

And there is a perverse consequence. The more weight an organisation places on the certificate, the more it trains its people to produce the evidence of capability rather than the capability itself. Practitioners are not fools; they optimise for what is rewarded. If the reward is a clean assessment, they will produce a clean assessment, and the underlying judgement — being neither seen nor rewarded — will quietly atrophy for want of exercise. The measurement does not merely fail to capture capability. Over time, it erodes it.

What This Reveals About How Organisations Change

If the essay stopped at criticism it would have missed its own point, because the process orthodoxy is not really a story about process. It is a story about how organisations believe change happens, and the belief is the thing worth examining.

The maturity model embodies a particular theory of change: that an organisation improves by defining the right processes and then conforming to them ever more faithfully, climbing the ladder rung by rung. It is an attractive theory because it is legible — it turns something messy and human into something linear and measurable, with levels to achieve and a clear picture of progress. Executives love it for the same reason they love any number that goes up. It promises that transformation can be managed in the same way as a production line: specify the standard, measure the variance, drive the variance down.

But the organisations I have watched actually improve did not improve that way. They improved when a small number of capable people were given room to exercise judgement, when the lessons of real failures were absorbed into how people thought rather than merely into how they documented, and when the method was treated as a servant to be adapted rather than a master to be obeyed. Improvement was cultural and tacit before it was ever procedural. The process, where it helped, helped by codifying a capability that already existed — never by conjuring one that did not.

Process can preserve a capability an organisation already has. It cannot manufacture one it lacks. The orthodoxy’s central error is to run this backwards — to believe that installing the process will produce the capability, when in truth only capability can give the process meaning.

This is why the gap between transformation intent and transformation reality is so stubborn, and why it survives every fresh initiative to close it. The initiatives are almost always procedural — a new method, a higher maturity target, a more rigorous assurance regime — and they address the codifiable half of the problem while leaving the tacit half untouched. The organisation buys another certificate and wonders why delivery has not changed. It has mistaken the map for the territory so completely that when the territory refuses to match the map, its instinct is to draw a more detailed map.

There is, worth noting, an early counter-current gathering at the edges of the field — a growing interest in lighter-weight, more iterative ways of working, a suspicion among some practitioners that the heavyweight methods have overshot. It is too soon to know what will come of it, and much of it is as capable of hardening into its own orthodoxy as anything it reacts against; a method that promises freedom from method is still a method, and will be sold as one. But the impulse behind it is sound, and it is the right impulse: a recovery of the idea that the point of the work is the work, and that process earns its place only by serving delivery, never by replacing it.

A More Honest Relationship With Method

What follows from all this is not a programme, and I distrust any essay of this kind that ends with a five-point plan, because the five-point plan would itself be another process sold as a cure. What follows is a change of relationship, and a change of relationship is harder than a change of process precisely because it cannot be certified.

The more honest relationship treats method as a tool held lightly. It keeps the parts that encode real lessons and prunes the parts that accumulated as scar tissue from old incidents no one remembers. It measures maturity, if it must, but never confuses the measurement with the achievement, and it holds the delivery record and the maturity rating side by side and worries loudly when they diverge. Above all, it invests in the thing the certificate cannot capture: the judgement of experienced people, developed by giving them real decisions to make and real accountability for the outcomes, rather than a template to complete and an assessment to pass.

That is an uncomfortable conclusion, because judgement cannot be procured on a timescale that suits a transformation programme, and it cannot be demonstrated in an annual report. It is slow, it is human, and it is invisible to the instruments we have built to reassure ourselves that we are in control. Which is, in the end, exactly why the orthodoxy persists. Process paralysis is not the disease. It is the symptom of a deeper preference — the preference for the legible over the real, for the measurable over the important, for the certificate we can hang on the wall over the capability we would have to earn. Until an organisation is willing to face that preference in itself, it will keep climbing the ladder, rung by faithful rung, and keep wondering why the view from the top looks so much like the view from the bottom.


More from Transformation