Engagement · Programme & portfolio management · Advise · 2022–2024

A national customs administration, running its own version of an EU-mandated modernisation programme to a timeline it did not control and on a fraction of a larger neighbour's budget. The EU set the deadlines and the EU kept moving them. Every time the target shifted, the dependencies and timelines across the projects had to be re-evaluated, so the work was to see those dependencies early enough to re-draw the plan in days, and to hold the line where holding it mattered most.

The European deadlines were met through schedule churn the administration could not control. MOBIAS ran the integrated programme as interim programme & portfolio manager, with the project managers reporting in, chaired the programme's digital steering committee, and represented the administration at the EU table.

€30M+

programme scope, total over ~2 years

8

strategic projects kept integrable while the plan churned

~130

contributors at programme peak

~1/5

of a larger member state's budget, for comparable national scope

The principle · Foresight + discipline

You cannot avoid what you cannot see. The target kept moving: an externally set timeline that was rescheduled every few weeks, with a legacy system being replaced while it ran and eight projects depending on each other. Most of the trouble was there to find if you looked. An integrated schedule and formal dependency tracking made the cascade visible early, so each time the dates shifted the plan could be re-evaluated and re-drawn in days rather than discovered too late. One risk lens ran through the whole programme. The same judgement that surfaced what was most at risk of cascading also decided where the scarce testing and scarce scope went, covering the highest-risk work first and phasing the scenarios that judgement placed lowest. Foresight kept up with the moving target; discipline governed by the same risk it surfaced. Nobody holds the line perfectly. The discipline was holding it where it counted, and being honest about where it bent.

Section A · The work

The deadlines kept shifting under the programme, so the work was to re-evaluate the dependencies fast enough to keep eight projects integrable each time they moved.

A deadline the administration did not set, on a timeline it could not hold still, on a fraction of a peer's budget

An EU-mandated programme runs to deadlines set in law and shared across every member state, with late-fines for any state that misses them. Each state builds its own national implementation to that one shared timeline. A small member state has little leverage: it cannot move the timeline itself, but the larger states can and do, so the shared dates were asked for and then rescheduled, again and again, while the administration still had to hit them. That recurring churn is the honest source of the difficulty. The constraint was structural and external, not a failing of the organisation. The deadlines could not be relaxed and they would not hold still, the budget was roughly a fifth of a larger state's for comparable national scope, and the core system was being replaced while it kept running.

Bring delivery in-house without losing the dates

Delivery had run through a global offshore partner, with the administration's analysts working directly across the distance. The programme moved that delivery to newly hired local teams while the timelines held, so delivery ownership came to sit inside the organisation. It was a shift in where the work was done and who owned it, carried out under live deadlines rather than paused to make room for it. Bringing the work closer also changed the operating model underneath it, which the closing beat returns to.

Make the dependencies visible enough to re-plan in days each time the target moved

The deadlines kept being rescheduled by forces outside the programme, and underneath them a legacy monolith was being phased out to micro-services while it stayed in production. That combination is where the foresight had to live. If a single shared component slipped, a core accounting component for instance, every other application kept integrating against the legacy version of it for longer than planned, and the slip cascaded through the schedule. Internal dependencies, cross-programme dependencies, and the occasional supplier slipping all stacked together on top of dates that moved, so plans did not stay stable beyond about three weeks. The answer was to see the cascade before it landed. The programme put in formal dependency tracking and one integrated master schedule across the projects, a single agile way of working shared between the teams, and modern modelling tooling to hold the picture. None of that stopped the dates from moving. It meant that every time they did, the programme could re-evaluate the dependencies and re-draw the plan in days instead of being surprised by the consequences a quarter later.

Spend scarce capacity where it buys down the most risk

Two scarce things were governed the same way, by risk. Testing capacity was the first. Quality testers were hard to recruit and the partners could not supply enough of them, so the programme built its testing as a pyramid that put the scarce capacity where it mattered. The base was that the code compiles. Above it, every developer wrote and ran the tests for their own work. Above that, manual scripts covered the business functionality. At the top, automated regression went to the highest-risk items only. Every story carried a risk assessment for things like data corruption, large financial impact and reputational damage, and the automation effort went to the highest-risk items first and worked down until they were all covered before lower-risk work was automated. Scope was governed the same way, by the same risk assessment. Under the pressure of non-negotiable deadlines and a tight budget, the programme deliberately deferred the long-tail scenarios that assessment placed lowest, as known and documented gaps to deliver after go-live, so the European deadline could be met. Those corners were chosen, risk-assessed, documented and scheduled for the work after go-live, which is what phased delivery by risk means. And because dates were asked for and then rescheduled, asking the teams for extra effort had to be spent like capital, carefully, so trust was not burned on a plan that might shift again.

Govern it: chair the committee, hold the EU table, move IT from supplier to partner

A programme this exposed needs a clear place where its decisions get made. MOBIAS represented the administration at the EU technical meetings, chaired the programme's digital steering committee, and set priorities across the components where the work overlapped with other member states. Underneath the governance sat a quieter change. The administration's IT had run the delivery relationship through the offshore partner, with the business analysts working directly across that line. Bringing delivery in-house changed that relationship and grew IT into a strategic delivery partner, and steering that shift in how the two sides worked together was part of the mandate. Two of the components built here were taken up and funded by other member states for their own implementations, which is the kind of reuse a programme earns when its parts are built to hold.

Section B · What changed

The European dates were held through churn, and the administration kept a way of seeing the next one coming.

The European deadlines were met through schedule churn the administration did not control, deadlines it could not relax yet could not hold still either, with the long-tail cases the risk assessment placed lowest deliberately phased to follow go-live as known, documented work rather than as surprises. Underneath that, the programme left the administration able to see its own dependencies. One integrated schedule and formal dependency tracking turned a target that moved every few weeks into something the programme could re-evaluate and re-draw in days, so a shift in the dates or a slip in one component was caught before it cascaded through the rest. Delivery had moved from an offshore partner to local teams, with the timelines intact and delivery ownership now sitting inside the organisation, and the live legacy system was phased to micro-services without breaking business continuity or losing feature parity. Two of the components were taken up and funded by other member states for their own implementations. When the mandate closed, a clean handover to an internal successor let staffing and budget come down, and the programme governance, the integrated schedule and the risk-based way of working stayed behind for the administration to keep steering with.

8

interlocking projects kept integrable as the European timeline shifted

2

components taken up and funded by other member states

~100

contributors after a clean handover let budgets come down from ~130

The plan would not hold still, so the work was to see it move early. You cannot stop a deadline you did not set, but you can see the dependency that threatens it, and decide where the scarce effort goes.

Is your deadline fixed while the plan keeps moving under it?

MOBIAS helps you see the dependencies early enough to re-plan fast, and spend scarce testing, scope and goodwill where they buy down the most risk. You keep the integrated view and the risk-based way of working after the mandate ends.