v2.2 · built 2 September 2026

National Regulatory Services Agency - IT Portfolio and Roadmap (illustrative demonstration)

Decision support for the application estate and the programme changing it - demonstration build, illustrative data · source: Illustrative application register, dependency record and information security pack
ILLUSTRATIVE DEMONSTRATION - THE NATIONAL REGULATORY SERVICES AGENCY DOES NOT EXIST. It is a fictional New Zealand Crown regulator, invented for this demonstration and not modelled on any real agency. Every application name, rating, date, dollar figure, owner, supplier and agreement in this artefact is INVENTED. Nothing here describes any real organisation's systems, spend, risk exposure or security posture. What is real is the STRUCTURE - the way a regulator's estate, its change programme and its contracts relate to each other - and that structure is the point of the demonstration.

Summary

8 COMPUTED FINDINGS

Executive summary

T3 modelled / inferred
33applications assessed
22initiatives
$53,750,000plan value
25%modelled risk reduction
8findings below

The 8 things this pack found, each with what it means for a decision. Every figure is computed when the pack is built, so nothing here is a headline somebody typed once and forgot to update — if the data moves, these cards move with it. Each card says which tab states it in full.

What the plan does not fix

T1 documented · Applications · Estate health

This programme is not a plan to remove the estate’s risk. It removes part of it. Budgeting or briefing as though it removes the rest is the mistake this figure exists to prevent.

25% of the risk in today’s estate is modelled to be removed by the funded plan. The other 75% is still there the day the last initiative lands. That is the plan working as designed — it was never scoped to reach the rest.

Risk reduction nobody is paying for

T1 documented · Applications · Estate health

The register credited the plan with work no initiative funds. Left uncorrected, every risk figure in this pack would flatter the programme — and the flattery would compound as the plan was cut.

The correction is applied before anything here is drawn: 5 applications carried modelled risk reduction (61.59 units) with no initiative behind it, and that credit is set to zero. The headline reduction on every tab is the corrected one.

Reachable from outside, and no longer supported

T1 documented · Exposure and cyber

Either problem on its own is ordinary and manageable. Both on the same application is the combination worth a decision this quarter, because there is no patch coming for the way in.

4 applications are rated at or above the threshold on both exposure to untrusted networks and support lifecycle risk. Treat the number as a floor, not a total: 3 more assessed applications carry no score on one or both, so they are untested rather than safe.

Agreements that have run out, or are about to

T2 asserted or draft · Agreements

An agreement past its expiry date is one of two things: renewed and never written down, or a service being used with no cover behind it. The register cannot tell you which — a person has to, and soon, because a notice period that has already closed cannot be reopened.

2 already past their recorded expiry, 3 more inside 91 days, and 5 with no date held at all.

Dates that cannot both be true

T2 asserted or draft · Plan · Roadmap

Something in this schedule is going to move. These are the places it will move first — and the plan does not record which side gives, so today that decision belongs to whoever notices last.

2 recorded dependencies cannot hold as scheduled: the follower is booked to start before the initiative it depends on finishes, by as much as 1171 days.

How far the plan has already slipped

T2 asserted or draft · Plan · Roadmap

This is movement that has already happened, not a forecast. The initiatives with no baseline are the ones to ask about first: nobody wrote down where they started, so no one can say whether they have moved.

4 of 6 initiatives that have a recorded baseline have moved out, the worst by +182 days. A further 16 have no baseline at all, which is not the same as not having moved.

Two freezes covering the same days

T3 modelled or inferred · Plan · Change freezes

Anything scheduled to land inside this window needs either a new date or a named exception. It is cheap to decide now and expensive to discover in the week it happens.

Disbursement cutover change freeze and Financial year-end freeze are both in effect for 30 days (2027-06-01 to 2027-07-01). Disbursement cutover change freeze is only proposed, so the collision is not yet a fact.

What this pack cannot see

T3 modelled or inferred · Applications · Estate health

Nothing here says these are safe, or that they are a problem. It says nobody wrote down enough for them to be tested — so every count above is drawn from a smaller estate than the one you actually run.

5 applications appear nowhere in the plan, and 2 initiatives name no application at all. Neither can be scored, segmented or ranked. That is a gap in the register, not a finding about the estate. These are the same 5 rows as the phantom-credit card above, read a second way: an application no initiative touches is exactly an application whose modelled reduction had nothing funding it.

Read this before quoting any number above. A summary is a way in, not a replacement for the tab that owns the finding. Every card but one repeats a figure the named tab already publishes in full, with its caveats — and the caveats are where the meaning is. “Two freezes covering the same days” is computed here from rows the named tab publishes but never compares, so it is the only line in this pack you will not find stated anywhere else, and is tiered accordingly. The tier chip on this panel is the WEAKEST tier on the page, not the best, so nothing here can be read as better-sourced than its weakest line. And nothing is ranked: the order is fixed, the numeral on each card is an index, not a rank, and this pack does not know which of these matters most to your organisation.

Recomputed on every build from the same derived objects as every other tab — if a figure changes, this changes with it. Each card carries the provenance tier of the finding it names, not the tier of this panel.

4 CRITERIA · 22% RING-FENCED FIRST

How the ranking works

T2 asserted / draft

The plan is ranked, and the ranking is arguable — so here is what it is made of before you read anything that depends on it. Four criteria, weighted. The weights are a choice, not a finding, and a different defensible choice reorders the list.

Strategic alignment

35% of the score · authored

How strongly the initiative serves a named institutional objective. Authored 1-5, and the objective it is scored against is named on every row.

Risk reduction

30% of the score · derived

The engine’s own modelled reduction in assessed portfolio risk, after the unfunded-credit correction. Derived, not authored.

Value for money

20% of the score · derived

Risk reduction per million of spend — the Value for money pane’s figure. A proxy for return, and a poor one where the benefit is not risk.

Contract urgency

15% of the score · derived

Whether the initiative touches an application with an agreement already expired or expiring inside the decision horizon. Derived from the register.

Delivery risk is applied last, as a confidence discount on the total (low 100%, medium 90%, high 80%) rather than as a fifth criterion. A shaky initiative is not less worth doing — it is less likely to deliver what it promises, and blending that into the case for the work would hide it.

Three rules that decide more than the weights do

RuleWhyWhat it costs here
Obligations are ring-fenced above the model, never weighted inside itWeight an obligation and a sufficiently attractive option eventually outranks it. An obligation is not a high-scoring choice; it is not a choice.7 initiatives, $11,840,00022% of the plan committed before a single discretionary decision
A missing component is never scored as zeroZero is a score. Absent is not. Defaulting a gap to zero silently ranks an initiative last and then presents that position as a finding.1 initiative left the ranking entirely and is named rather than placed at the bottom of it
The weights are published and varied, not assertedA ranking nobody can argue with is a ranking nobody argues with. The only honest way to say whether an order is settled is to move the weights and look.6 of 14 initiatives change funding outcome by more than 10 points under a different defensible weighting — the rest are decided by the size of the envelope, not by the weights

This model ranks; it does not decide. It carries no benefit in money, because the dataset carries none — so there is no NPV, no IRR and no payback anywhere in this pack, and "value for money" is risk reduction per million, a proxy that fails wherever the benefit of an initiative is not risk. Scores are normalised WITHIN this portfolio, so 100 means best of these and never good. Nothing here says what to cut.

Read from the same model object the ranking itself uses, so this explanation cannot drift away from the thing it explains. Strategic alignment is an authored input; the other three are derived.

Applications

Portfolio health

T1 documented
33applications assessed
22initiatives
$53,750,000plan value
25%modelled risk reduction

The funded plan is modelled to remove 25% of current assessed risk. The remaining 75% is what PERSISTS after the plan lands, and 85% of that sits on applications the plan does touch. It is not "unfunded risk".

5 applications carried modelled risk reduction while no initiative touches them (61.59 units). That credit is ZEROED before anything is drawn: a plan cannot be credited with fixing something nobody is paying to fix.

Consenting and licensing 9

Consents Portal - Inspection4
Consents Portal - Determinations4
Consents Portal - Assessment4
Licence Renewals System4
Consents Portal - Lodgement4
Consents Portal - Closure3
Enforcement and Compliance Register3
Regulatory Performance Platform3
Consents Portal (target)4

Revenue and levies 5

Revenue Collection Platform4
Payments Gateway4
Levy Administration System4
Infringement Fees Ledger3
Sector Reporting Workspace3

Corporate services 6

Corporate Finance Ledger4
Payroll and Benefits Engine4
Procurement and Supplier Portal3
Human Resources Core3
Records and Correspondence Archive3
Travel and Expense System3

Applicant and regional platforms 5

Regional Office Network Gateway4
Applicant Services Portal4
Open Data Catalogue3
Complaints and Review Intake3
External Collaboration Workspace3

Data and information 4

Enterprise Data Warehouse3
Guidance and Standards Repository3
Regulatory Analysis Environment3
Executive Reporting Workspace2

Infrastructure and workplace 5

Identity and Access Directory3
Endpoint Management Service3
Backup and Recovery Service4
Legacy Reporting Warehouse4
Storage Array (primary data centre)4
rating 54321
Risk driverWhat it measures
Exposure to Untrusted NetworksHow reachable the application is from a network the Agency does not control - the public internet, a client network, or a regional office circuit carried by a third party.
Support Lifecycle RiskHow far past supported release, patch or hardware life the application is.
Business CriticalityConsequence to lending, disbursement or corporate operations if the application is unavailable.
ResilienceAbility to continue or recover without the application. Higher is better.
Supplier ConcentrationReliance on a single supplier for continued operation.
12 APPLICATIONS APPEAR IN AT LEAST ONE SIGNAL

Consolidation signals

T3 modelled / inferred
8consolidation signals
1one procurement, several modules
3one supplier, several applications
1superseded by a target state
3untouched and not critical

These are questions worth asking, not decisions. Four signals, each computed from the data and each shown with the evidence behind it. None of them says an application should be consolidated. That call needs an assessment of what the applications actually do, and this dataset does not contain one.

One procurement, several modules

FamilyModulesCurrent health unitsInitiatives touching them
Consents PortalConsents Portal - Lodgement
Consents Portal - Assessment
Consents Portal - Inspection
Consents Portal - Determinations
Consents Portal - Closure
279.0NRSA-001, NRSA-002, NRSA-015

These arrived under one name and one agreement. That makes them one commercial decision even where they are 5 operational ones - which cuts both ways, and is the reason the cluster is drawn.

One supplier, several applications

SupplierApplications named against themCount
Aventine AnalyticsLegacy Reporting Warehouse
Regulatory Analysis Environment
2
Calderon SystemsConsents Portal - Assessment
Licence Renewals System
2
Verity RecordsGuidance and Standards Repository
Records and Correspondence Archive
2

Taken from the agreement register's own curated linked_entity column. Nothing is joined on name similarity: a name-matched supplier map is a guess wearing the appearance of a join.

Superseded by a recorded target state

Target-state rowDomainLabels merged into it
Consents Portal (target)Consenting and licensingConsents Portal - target state

A target-state row is excluded from every assessed count. It is shown here because it is the one place the register states an intended consolidation outright.

Untouched by the plan, and not business-critical

ApplicationDomainCriticalityCurrent health units
Open Data CatalogueApplicant and regional platforms351.0
External Collaboration WorkspaceApplicant and regional platforms345.0
Legacy Reporting WarehouseInfrastructure and workplace242.0

This list is a question, not a recommendation: retire it, or fund it. An application can be absent from the plan because it is fine, because nobody owns it, or because it was forgotten - and nothing in this dataset distinguishes those three.

No saving is estimated and no candidate is ranked. A consolidation saving needs licence terms, exit costs, functional overlap and migration effort, none of which is in this dataset; a number produced without them would be a guess wearing a currency symbol. Nothing here says two applications do the same thing - only that something about them is shared.

Every signal is derived at build time from the register, the initiative footprints, the agreement register and the config's own family and identity declarations. Change the data and these change with it.

Initiatives

Initiative register

T1 documented
RankInitiativeOwnerPriorityEntitiesPlan valueStartEnd
1Consents Portal re-platform - assessment and inspectionRegulatory SystemsCritical4$10,000,0002026-09-012029-03-31
2Determinations modernisationRegulatory SystemsCritical2$6,200,0002026-01-152029-06-30
3Regional office network renewalInfrastructure and NetworksCritical2$5,300,0002026-10-012029-02-28
4Licence renewals platform migrationFinancial SystemsCritical1$4,800,0002026-03-012029-04-30
5Levy administration upliftLevies and RevenueHigh2$3,400,0002026-11-012028-12-31
6Identity and access modernisationSecurity and IdentityHigh2$3,000,0002026-02-012028-11-30
7Payroll and benefits replacementCorporate SystemsHigh2$2,700,0002027-01-152029-03-31
8Enterprise data warehouse consolidationData and AnalyticsHigh2$2,500,0002026-04-012029-01-31
9Records archive remediationCorporate SystemsMedium2$1,800,0002026-09-152028-10-31
10Procurement and supplier portal rebuildCorporate ProcurementMedium1$1,700,0002027-09-012030-03-31
11Enforcement register upliftRegulatory RiskMedium2$1,320,0002027-02-012028-09-30
12Revenue collection platform upgradeRevenueMedium2$1,500,0002026-10-152028-12-15
13Applicant services portal accessibility and hardeningApplicant ServicesMedium1$1,050,0002027-03-012029-01-31
14Corporate finance ledger upgradeFinancial SystemsMedium1$980,0002026-08-012028-08-31
15Regulatory performance automationRegulatory PerformanceMedium2$870,0002027-04-012029-02-28
16Sector reporting refreshLevies and RevenueMedium2$760,0002027-01-012028-11-30
17Guidance repository migrationGuidance and StandardsLow1$640,0002027-05-012029-04-30
18Complaints intake channel upliftComplaints and ReviewLow1$540,0002027-06-012029-05-31
19Travel and expense refreshCorporate SystemsLow1$460,0002026-12-012028-07-31
20Executive reporting workspace refreshData and AnalyticsLow1$400,000
-IT operating model and sourcing reviewOffice of the CIOMedium0$680,0002026-08-152028-03-31
-Information security uplift programme (portfolio-wide)Security and IdentityHigh0$3,150,0002026-01-012029-06-30
14 RANKED · 7 RING-FENCED · 1 UNSCORED

Prioritisation

T2 asserted / draft
14ranked on the model
7ring-fenced as mandatory
$11,840,000committed before any choice
1cannot be scored
6funding outcome weight-sensitive

A weighted multi-criteria ranking of the discretionary plan. Work the institution has no choice about is ring-fenced above the model, not given a high weight — weight an obligation and a sufficiently attractive option eventually outranks it. Every score is shown as its parts, because a single number nobody can decompose is a number nobody can argue with.

The model, and the choice inside it

CriterionWeightSourceWhat it is
Strategic alignment35%authoredHow strongly the initiative serves a named institutional objective. Authored 1-5, and the objective it is scored against is named on every row.
Risk reduction30%derivedThe engine’s own modelled reduction in assessed portfolio risk, after the unfunded-credit correction. Derived, not authored.
Value for money20%derivedRisk reduction per million of spend — the Value for money pane’s figure. A proxy for return, and a poor one where the benefit is not risk.
Contract urgency15%derivedWhether the initiative touches an application with an agreement already expired or expiring inside the decision horizon. Derived from the register.

Delivery risk is applied last, as a confidence discount on the total (low 100%, medium 90%, high 80%) rather than as a criterion. A shaky initiative is not less worth doing — it is less likely to deliver what it promises, and blending that into the case FOR the work would hide it.

Ring-fenced: not ranked, because not optional

InitiativeObligationStated sourcePlan value
Information security uplift programme (portfolio-wide)Security control upliftInformation security assurance framework$3,150,000
Identity and access modernisationAccess control baselineInformation security assurance framework$3,000,000
Records archive remediationRecords retention scheduleInstitutional records policy$1,800,000
Enforcement register upliftSafeguards reporting obligationEnvironmental and social framework$1,320,000
Applicant services portal accessibility and hardeningDigital accessibility conformanceAccessibility standard$1,050,000
Corporate finance ledger upgradeFinancial reporting controlsExternal audit requirement$980,000
Complaints intake channel upliftGrievance redress obligationComplaints and Review mechanism$540,000

These consume 22% of the plan before a single discretionary choice is made. That is the real starting point of any funding conversation, and it is the number most portfolio ranking hides by listing obligations alongside options.

The ranking, with its working shown

#Initiative and the objective it is scored againstScore, by componentRank bandPlan valueFunded from
1Sector reporting refresh
Evidence and results
56
1–3$760,00025%
2Regulatory performance automation
Evidence and results
56
1–3$870,00030%
3Consents Portal re-platform - assessment and inspection
Operational effectiveness of lending
54
1–5$10,000,00045%
4Enterprise data warehouse consolidation
Evidence and results
47
3–5$2,500,00050%
5Revenue collection platform upgrade
Financial integrity and controls
46
4–6$1,500,00055%
6Determinations modernisation
Operational effectiveness of lending
43
5–6$6,200,00065%
7Licence renewals platform migration
Financial integrity and controls
36
7–8$4,800,00075%
8Levy administration uplift
Financial integrity and controls
31
7–10$3,400,00080%
9Regional office network renewal
Client and country responsiveness
30
8–13$5,300,00090%
10Executive reporting workspace refresh
Evidence and results
26
8–13$400,00090%
11Payroll and benefits replacement
Institutional resilience
25
10–14$2,700,00095%
12Guidance repository migration
Evidence and results
25
11–12$640,00095%
13Travel and expense refresh
Institutional resilience
22
9–14$460,000100%
14Procurement and supplier portal rebuild
Operational effectiveness of lending
22
11–14$1,700,000100%
Strategic alignmentRisk reductionValue for moneyContract urgency

Funded from is the lowest funding level at which the initiative survives the cut, with obligations committed first. It is a property of this ranking, not a plan.

Rank band is how far the row moves across 8 runs that vary one weight by half in either direction. A band is information, not an alarm: sliding two places inside the funded block changes no decision. What does change a decision is crossing the line where the money runs out, and that is measured separately below.

6 of 14 initiatives change funding outcome by more than 10 percentage points when the weights move. These are the rows where the weighting is doing real work: Sector reporting refresh (funded from 25%, or 45% under a different weighting); Enterprise data warehouse consolidation (funded from 50%, or 30% under a different weighting); Revenue collection platform upgrade (funded from 55%, or 35% under a different weighting); Travel and expense refresh (funded from 100%, or 80% under a different weighting); Regulatory performance automation (funded from 30%, or 45% under a different weighting); Executive reporting workspace refresh (funded from 90%, or 75% under a different weighting). Everything else is funded or deferred at the same level whichever defensible weighting is used, so arguing about the weights will not change what happens to it.

1 initiative cannot be scored at all and is absent from the ranking rather than placed at the bottom of it: IT operating model and sourcing review. It is missing at least one component, and a missing component is not a zero — scoring it as one would manufacture a last place out of a gap in the register.

Three panels in this pack count “initiatives the model cannot place” and get three different numbers. They are not in conflict, they are three questions: 1 cannot be scored at all (missing a component, above); 2 carry no modelled risk reduction, so they are absent from the value-for-money ranking; and 2 are held in the funding stepper’s manual-only tray, which takes either of those two faults. Read the noun, not the number.

It also sits outside the funding lever on Funding scenarios: it is neither funded nor cut at any level, because a model that could not rank it cannot decide to drop it either.

The weights are a choice, not a finding, and a different defensible choice reorders this list — which is why the rank band under weight variation sits beside every row. The scores are normalised WITHIN this portfolio, so 100 means best of these, never good. There is no benefit in money anywhere in the dataset, so there is no NPV, no IRR and no payback here; “value for money” is risk reduction per million, which is a proxy and fails wherever the benefit of an initiative is not risk. Nothing here says what to cut. It says what the model says, how much of that survives the model being wrong, and what it could not look at.

Strategic alignment and the obligations are AUTHORED inputs in this dataset. Risk reduction, value for money and contract urgency are derived by the engine from the register. The tab marks which is which per row.

Value for money - risk reduction per unit of spend

T2 asserted / draft
InitiativeRisk reduced (units)Plan valueUnits per million
Travel and expense refresh13.7$460,00029.67
Regulatory performance automation25.6$870,00029.48
Sector reporting refresh20.1$760,00026.46
Executive reporting workspace refresh10.3$400,00025.67
Complaints intake channel uplift13.7$540,00025.28
Guidance repository migration13.7$640,00021.33
Revenue collection platform upgrade24.4$1,500,00016.28
Enforcement register uplift20.9$1,320,00015.86
Records archive remediation22.7$1,800,00012.61
Payroll and benefits replacement29.9$2,700,00011.09
Levy administration uplift29.9$3,400,0008.80
Procurement and supplier portal rebuild14.6$1,700,0008.56
Enterprise data warehouse consolidation20.9$2,500,0008.37
Corporate finance ledger upgrade8.1$980,0008.31
Applicant services portal accessibility and hardening7.7$1,050,0007.32
Identity and access modernisation20.9$3,000,0006.98
Consents Portal re-platform - assessment and inspection57.3$10,000,0005.73
Regional office network renewal24.8$5,300,0004.68
Licence renewals platform migration16.3$4,800,0003.39
Determinations modernisation16.7$6,200,0002.69

2 initiative(s) carry no modelled risk reduction and are absent from this ranking. They are not shown to be low-value: the model cannot score them at all, which is a coverage gap, not a result.

This ranks RISK REDUCTION per unit of spend and nothing else. It omits benefit, capability and statutory-obligation value entirely. It is not a value ranking and must not be read as one.

A shared entity's reduction is SPLIT EQUALLY between the initiatives that touch it, so no initiative is credited twice for the same entity.

Delivery risk

T2 asserted / draft
InitiativeDelivery riskOwnerPlan valueNote
Consents Portal re-platform - assessment and inspectionHighRegulatory Systems$10,000,000
Determinations modernisationHighRegulatory Systems$6,200,000
Information security uplift programme (portfolio-wide)HighSecurity and Identity$3,150,000
Licence renewals platform migrationHighFinancial Systems$4,800,000
Regional office network renewalHighInfrastructure and Networks$5,300,000
Applicant services portal accessibility and hardeningMediumApplicant Services$1,050,000
Enterprise data warehouse consolidationMediumData and Analytics$2,500,000
IT operating model and sourcing reviewMediumOffice of the CIO$680,000
Identity and access modernisationMediumSecurity and Identity$3,000,000
Levy administration upliftMediumLevies and Revenue$3,400,000
Payroll and benefits replacementMediumCorporate Systems$2,700,000
Procurement and supplier portal rebuildMediumCorporate Procurement$1,700,000
Revenue collection platform upgradeMediumRevenue$1,500,000
Complaints intake channel upliftLowComplaints and Review$540,000
Corporate finance ledger upgradeLowFinancial Systems$980,000
Enforcement register upliftLowRegulatory Risk$1,320,000
Executive reporting workspace refreshLowData and Analytics$400,000
Guidance repository migrationLowGuidance and Standards$640,000
Records archive remediationLowCorporate Systems$1,800,000
Regulatory performance automationLowRegulatory Performance$870,000
Sector reporting refreshLowLevies and Revenue$760,000
Travel and expense refreshLowCorporate Systems$460,000
13% OF PLAN VALUE, AUTHORED CLASSIFICATION

AI portfolio

T2 asserted / draft
5 of 22AI-classified initiatives
$7,030,000plan value
13%share of the plan
0rated high delivery risk
8applications touched

One question: is the AI spend a portfolio, or a scattering? This is the AI-classified slice of the same plan, on the same figures. It is not a separate portfolio and not a separate budget. Every initiative below also appears in the register, the roadmap and the funding stepper — cutting it here cuts it everywhere.

RankInitiativeOwnerDelivery riskFY25/26 FY26/27 FY27/28 FY28/29 FY29/30 FY30/31 FY31/32Plan valueApplications
8Enterprise data warehouse consolidationData and AnalyticsMedium
$2,500,0002
10Procurement and supplier portal rebuildCorporate ProcurementMedium
$1,700,0001
11Enforcement register upliftRegulatory RiskLow
$1,320,0002
15Regulatory performance automationRegulatory PerformanceLow
$870,0002
17Guidance repository migrationGuidance and StandardsLow
$640,0001

Applications these initiatives change

Consents Portal - Closure, Enforcement and Compliance Register, Enterprise Data Warehouse, Guidance and Standards Repository, Identity and Access Directory, Procurement and Supplier Portal, Regulatory Analysis Environment, Regulatory Performance Platform

The AI classification is an AUTHORED field on the initiative record, not a derivation. The engine cannot tell whether an initiative uses AI from its name, its owner or its spend, and does not try - so this tab is exactly as good as whoever filled the field in. No benefit, no productivity gain and no return is modelled anywhere on it: nothing in the dataset supports one.

Phasing bars are the same fiscal-year budget phasing used on the Roadmap tab, at the same scale. They are budget intent, not a delivery schedule.

Plan

22 INITIATIVES · 8 TIES · 2 DEPENDENCY CONTRADICTIONS

Roadmap timeline and dependencies

T2 asserted / draft

The plan by who it lands on, not by what it costs. Initiatives sit in 7 swimlanes, one per business area, taken from the applications each initiative changes. One that spans several areas is drawn once — in the area it touches most, with the others named on its row. Drawing it in every lane would make the plan look bigger than it is. 2 initiatives could not be attributed to any area and sit in a lane of their own at the bottom rather than being dropped.

The Budget phasing pane shows budget phasing — how much falls in each fiscal year. This shows the schedule: when each initiative actually runs, on real dates, and what it is tied to. Two different questions about the same plan, from two different fields in the register.

The timeline, in start-date order so the plan reads as a cascade. Zoom widens the time axis — a quarter takes a quarter's worth of space — and the initiative column stays put while the plot scrolls. Milestones and change freezes sit in their own lane above the bars rather than cutting across them.

Zoom
Initiative
Consenting and licensing5
2Determinations modernisation+1+91d21H
4Licence renewals platform migration0·H
1Consents Portal re-platform - assessment and inspection+90d11H
11Enforcement register uplift+11L
15Regulatory performance automation·L
Infrastructure and workplace1
6Identity and access modernisation1M
Data and information4
8Enterprise data warehouse consolidation1M
20Executive reporting workspace refresh·L
16Sector reporting refresh+11L
17Guidance repository migration·L
Corporate services5
14Corporate finance ledger upgrade1L
9Records archive remediation1L
19Travel and expense refresh·L
7Payroll and benefits replacement-91d·M
10Procurement and supplier portal rebuild+182d·M
Applicant and regional platforms3
3Regional office network renewal+151d11H
13Applicant services portal accessibility and hardening11M
18Complaints intake channel uplift·L
Revenue and levies2
12Revenue collection platform upgrade1M
5Levy administration uplift·M
Not attributed to a business area2
·Information security uplift programme (portfolio-wide)·H
·IT operating model and sourcing review·M
FY25/26
FY26/27
FY27/28
FY28/29
FY29/30
FY25/26H1H2
FY26/27H1H2
FY27/28H1H2
FY28/29H1H2
FY29/30H1H2
FY25/26Q1Q2Q3Q4
FY26/27Q1Q2Q3Q4
FY27/28Q1Q2Q3Q4
FY28/29Q1Q2Q3Q4
FY29/30Q1Q2Q3Q4
Disbursement cutover change freeze — proposed, 2027-04-01 to 2027-07-01Financial year-end freeze — in-force, 2027-06-01 to 2027-07-151Loan servicing vendor support ends — 2026-06-302Regional office network contract expiry — 2026-12-313Disbursement request cutover — 2027-04-014Endpoint fleet end of life — 2027-09-305Primary data centre hosting agreement expiry — 2028-03-31Determinations modernisation — 2026-01-15 to 2029-06-30Previously planned 2026-01-15 to 2029-03-31 — the end date has moved out 91 daysFY25/26 $500,000FY26/27 $2,600,000FY27/28 $2,400,000Licence renewals platform migration — 2026-03-01 to 2029-04-30Previously planned 2026-03-01 to 2029-04-30 — the end date has not movedFY25/26 $300,000FY26/27 $1,600,000FY27/28 $2,000,000Consents Portal re-platform - assessment and inspection — 2026-09-01 to 2029-03-31Previously planned 2026-07-01 to 2028-12-31 — the end date has moved out 90 daysFY26/27 $3,200,000FY27/28 $4,600,000Enforcement register uplift — 2027-02-01 to 2028-09-30FY26/27 $420,000FY27/28 $620,000Regulatory performance automation — 2027-04-01 to 2029-02-28FY26/27 $280,000FY27/28 $400,000Identity and access modernisation — 2026-02-01 to 2028-11-30FY25/26 $400,000FY26/27 $1,000,000FY27/28 $1,100,000Enterprise data warehouse consolidation — 2026-04-01 to 2029-01-31FY25/26 $200,000FY26/27 $800,000FY27/28 $1,000,000Executive reporting workspace refresh — no dates recorded; drawn across its funded fiscal yearsSector reporting refresh — 2027-01-01 to 2028-11-30FY26/27 $240,000FY27/28 $350,000Guidance repository migration — 2027-05-01 to 2029-04-30FY26/27 $200,000FY27/28 $300,000Corporate finance ledger upgrade — 2026-08-01 to 2028-08-31FY26/27 $320,000FY27/28 $450,000Records archive remediation — 2026-09-15 to 2028-10-31FY26/27 $600,000FY27/28 $850,000Travel and expense refresh — 2026-12-01 to 2028-07-31FY26/27 $150,000FY27/28 $210,000Payroll and benefits replacement — 2027-01-15 to 2029-03-31Previously planned 2027-04-01 to 2029-06-30 — the end date has pulled in 91 daysFY26/27 $900,000FY27/28 $1,200,000Procurement and supplier portal rebuild — 2027-09-01 to 2030-03-31Previously planned 2027-09-01 to 2029-09-30 — the end date has moved out 182 daysFY27/28 $750,000FY28/29 $450,000Regional office network renewal — 2026-10-01 to 2029-02-28Previously planned 2026-10-01 to 2028-09-30 — the end date has moved out 151 daysFY26/27 $1,900,000FY27/28 $2,300,000Applicant services portal accessibility and hardening — 2027-03-01 to 2029-01-31FY26/27 $340,000FY27/28 $480,000Complaints intake channel uplift — 2027-06-01 to 2029-05-31FY26/27 $170,000FY27/28 $250,000Revenue collection platform upgrade — 2026-10-15 to 2028-12-15FY26/27 $480,000FY27/28 $700,000Levy administration uplift — 2026-11-01 to 2028-12-31FY26/27 $1,200,000FY27/28 $1,500,000Information security uplift programme (portfolio-wide) — 2026-01-01 to 2029-06-30FY25/26 $250,000FY26/27 $1,100,000FY27/28 $1,100,000IT operating model and sourcing review — 2026-08-15 to 2028-03-31FY26/27 $420,000Coupled — Determinations modernisation and Consents Portal re-platform - assessment and inspection both change Consents Portal - Determinations. No sequence is implied.Coupled — Determinations modernisation and Revenue collection platform upgrade both change Payments Gateway. No sequence is implied.Coupled — Enforcement register uplift and Identity and access modernisation both change Identity and Access Directory. No sequence is implied.Coupled — Enterprise data warehouse consolidation and Sector reporting refresh both change Enterprise Data Warehouse. No sequence is implied.Coupled — Corporate finance ledger upgrade and Records archive remediation both change Corporate Finance Ledger. No sequence is implied.Coupled — Regional office network renewal and Applicant services portal accessibility and hardening both change Applicant Services Portal. No sequence is implied.CONTRADICTION: Consents Portal re-platform - assessment and inspection is recorded as a predecessor of Determinations modernisation, but Determinations modernisation starts 1171 days before Consents Portal re-platform - assessment and inspection finishes.CONTRADICTION: Regional office network renewal is recorded as a predecessor of Applicant services portal accessibility and hardening, but Applicant services portal accessibility and hardening starts 730 days before Regional office network renewal finishes.Disbursement cutover change freeze — proposed, 2027-04-01 to 2027-07-01Financial year-end freeze — in-force, 2027-06-01 to 2027-07-151Loan servicing vendor support ends — 2026-06-302Regional office network contract expiry — 2026-12-313Disbursement request cutover — 2027-04-014Endpoint fleet end of life — 2027-09-305Primary data centre hosting agreement expiry — 2028-03-31Determinations modernisation — 2026-01-15 to 2029-06-30Previously planned 2026-01-15 to 2029-03-31 — the end date has moved out 91 daysFY25/26 $500,000FY26/27 $2,600,000FY27/28 $2,400,000Licence renewals platform migration — 2026-03-01 to 2029-04-30Previously planned 2026-03-01 to 2029-04-30 — the end date has not movedFY25/26 $300,000FY26/27 $1,600,000FY27/28 $2,000,000Consents Portal re-platform - assessment and inspection — 2026-09-01 to 2029-03-31Previously planned 2026-07-01 to 2028-12-31 — the end date has moved out 90 daysFY26/27 $3,200,000FY27/28 $4,600,000Enforcement register uplift — 2027-02-01 to 2028-09-30FY26/27 $420,000FY27/28 $620,000Regulatory performance automation — 2027-04-01 to 2029-02-28FY26/27 $280,000FY27/28 $400,000Identity and access modernisation — 2026-02-01 to 2028-11-30FY25/26 $400,000FY26/27 $1,000,000FY27/28 $1,100,000Enterprise data warehouse consolidation — 2026-04-01 to 2029-01-31FY25/26 $200,000FY26/27 $800,000FY27/28 $1,000,000Executive reporting workspace refresh — no dates recorded; drawn across its funded fiscal yearsSector reporting refresh — 2027-01-01 to 2028-11-30FY26/27 $240,000FY27/28 $350,000Guidance repository migration — 2027-05-01 to 2029-04-30FY26/27 $200,000FY27/28 $300,000Corporate finance ledger upgrade — 2026-08-01 to 2028-08-31FY26/27 $320,000FY27/28 $450,000Records archive remediation — 2026-09-15 to 2028-10-31FY26/27 $600,000FY27/28 $850,000Travel and expense refresh — 2026-12-01 to 2028-07-31FY26/27 $150,000FY27/28 $210,000Payroll and benefits replacement — 2027-01-15 to 2029-03-31Previously planned 2027-04-01 to 2029-06-30 — the end date has pulled in 91 daysFY26/27 $900,000FY27/28 $1,200,000Procurement and supplier portal rebuild — 2027-09-01 to 2030-03-31Previously planned 2027-09-01 to 2029-09-30 — the end date has moved out 182 daysFY27/28 $750,000FY28/29 $450,000Regional office network renewal — 2026-10-01 to 2029-02-28Previously planned 2026-10-01 to 2028-09-30 — the end date has moved out 151 daysFY26/27 $1,900,000FY27/28 $2,300,000Applicant services portal accessibility and hardening — 2027-03-01 to 2029-01-31FY26/27 $340,000FY27/28 $480,000Complaints intake channel uplift — 2027-06-01 to 2029-05-31FY26/27 $170,000FY27/28 $250,000Revenue collection platform upgrade — 2026-10-15 to 2028-12-15FY26/27 $480,000FY27/28 $700,000Levy administration uplift — 2026-11-01 to 2028-12-31FY26/27 $1,200,000FY27/28 $1,500,000Information security uplift programme (portfolio-wide) — 2026-01-01 to 2029-06-30FY25/26 $250,000FY26/27 $1,100,000FY27/28 $1,100,000IT operating model and sourcing review — 2026-08-15 to 2028-03-31FY26/27 $420,000Coupled — Determinations modernisation and Consents Portal re-platform - assessment and inspection both change Consents Portal - Determinations. No sequence is implied.Coupled — Determinations modernisation and Revenue collection platform upgrade both change Payments Gateway. No sequence is implied.Coupled — Enforcement register uplift and Identity and access modernisation both change Identity and Access Directory. No sequence is implied.Coupled — Enterprise data warehouse consolidation and Sector reporting refresh both change Enterprise Data Warehouse. No sequence is implied.Coupled — Corporate finance ledger upgrade and Records archive remediation both change Corporate Finance Ledger. No sequence is implied.Coupled — Regional office network renewal and Applicant services portal accessibility and hardening both change Applicant Services Portal. No sequence is implied.CONTRADICTION: Consents Portal re-platform - assessment and inspection is recorded as a predecessor of Determinations modernisation, but Determinations modernisation starts 1171 days before Consents Portal re-platform - assessment and inspection finishes.CONTRADICTION: Regional office network renewal is recorded as a predecessor of Applicant services portal accessibility and hardening, but Applicant services portal accessibility and hardening starts 730 days before Regional office network renewal finishes.Disbursement cutover change freeze — proposed, 2027-04-01 to 2027-07-01Financial year-end freeze — in-force, 2027-06-01 to 2027-07-151Loan servicing vendor support ends — 2026-06-302Regional office network contract expiry — 2026-12-313Disbursement request cutover — 2027-04-014Endpoint fleet end of life — 2027-09-305Primary data centre hosting agreement expiry — 2028-03-31Determinations modernisation — 2026-01-15 to 2029-06-30Previously planned 2026-01-15 to 2029-03-31 — the end date has moved out 91 daysFY25/26 $500,000FY26/27 $2,600,000FY27/28 $2,400,000Licence renewals platform migration — 2026-03-01 to 2029-04-30Previously planned 2026-03-01 to 2029-04-30 — the end date has not movedFY25/26 $300,000FY26/27 $1,600,000FY27/28 $2,000,000Consents Portal re-platform - assessment and inspection — 2026-09-01 to 2029-03-31Previously planned 2026-07-01 to 2028-12-31 — the end date has moved out 90 daysFY26/27 $3,200,000FY27/28 $4,600,000Enforcement register uplift — 2027-02-01 to 2028-09-30FY26/27 $420,000FY27/28 $620,000Regulatory performance automation — 2027-04-01 to 2029-02-28FY26/27 $280,000FY27/28 $400,000Identity and access modernisation — 2026-02-01 to 2028-11-30FY25/26 $400,000FY26/27 $1,000,000FY27/28 $1,100,000Enterprise data warehouse consolidation — 2026-04-01 to 2029-01-31FY25/26 $200,000FY26/27 $800,000FY27/28 $1,000,000Executive reporting workspace refresh — no dates recorded; drawn across its funded fiscal yearsSector reporting refresh — 2027-01-01 to 2028-11-30FY26/27 $240,000FY27/28 $350,000Guidance repository migration — 2027-05-01 to 2029-04-30FY26/27 $200,000FY27/28 $300,000Corporate finance ledger upgrade — 2026-08-01 to 2028-08-31FY26/27 $320,000FY27/28 $450,000Records archive remediation — 2026-09-15 to 2028-10-31FY26/27 $600,000FY27/28 $850,000Travel and expense refresh — 2026-12-01 to 2028-07-31FY26/27 $150,000FY27/28 $210,000Payroll and benefits replacement — 2027-01-15 to 2029-03-31Previously planned 2027-04-01 to 2029-06-30 — the end date has pulled in 91 daysFY26/27 $900,000FY27/28 $1,200,000Procurement and supplier portal rebuild — 2027-09-01 to 2030-03-31Previously planned 2027-09-01 to 2029-09-30 — the end date has moved out 182 daysFY27/28 $750,000FY28/29 $450,000Regional office network renewal — 2026-10-01 to 2029-02-28Previously planned 2026-10-01 to 2028-09-30 — the end date has moved out 151 daysFY26/27 $1,900,000FY27/28 $2,300,000Applicant services portal accessibility and hardening — 2027-03-01 to 2029-01-31FY26/27 $340,000FY27/28 $480,000Complaints intake channel uplift — 2027-06-01 to 2029-05-31FY26/27 $170,000FY27/28 $250,000Revenue collection platform upgrade — 2026-10-15 to 2028-12-15FY26/27 $480,000FY27/28 $700,000Levy administration uplift — 2026-11-01 to 2028-12-31FY26/27 $1,200,000FY27/28 $1,500,000Information security uplift programme (portfolio-wide) — 2026-01-01 to 2029-06-30FY25/26 $250,000FY26/27 $1,100,000FY27/28 $1,100,000IT operating model and sourcing review — 2026-08-15 to 2028-03-31FY26/27 $420,000Coupled — Determinations modernisation and Consents Portal re-platform - assessment and inspection both change Consents Portal - Determinations. No sequence is implied.Coupled — Determinations modernisation and Revenue collection platform upgrade both change Payments Gateway. No sequence is implied.Coupled — Enforcement register uplift and Identity and access modernisation both change Identity and Access Directory. No sequence is implied.Coupled — Enterprise data warehouse consolidation and Sector reporting refresh both change Enterprise Data Warehouse. No sequence is implied.Coupled — Corporate finance ledger upgrade and Records archive remediation both change Corporate Finance Ledger. No sequence is implied.Coupled — Regional office network renewal and Applicant services portal accessibility and hardening both change Applicant Services Portal. No sequence is implied.CONTRADICTION: Consents Portal re-platform - assessment and inspection is recorded as a predecessor of Determinations modernisation, but Determinations modernisation starts 1171 days before Consents Portal re-platform - assessment and inspection finishes.CONTRADICTION: Regional office network renewal is recorded as a predecessor of Applicant services portal accessibility and hardening, but Applicant services portal accessibility and hardening starts 730 days before Regional office network renewal finishes.
  1. 1Loan servicing vendor support ends2026-06-30 · 64 days ago
  2. 2Regional office network contract expiry2026-12-31 · in 120 days
  3. 3Disbursement request cutover2027-04-01 · in 211 days
  4. 4Endpoint fleet end of life2027-09-30 · in 393 days
  5. 5Primary data centre hosting agreement expiry2028-03-31 · in 576 days
recorded start to endhigh delivery riskno dates recordedmilestonechange freezeshared application — no directionrecorded predecessorpredecessor contradicted by the datesprevious plan

2 recorded dependencies are contradicted by the dates. A follower cannot start before its predecessor finishes — that is the rule a scheduling tool enforces when you drag a bar. This artefact is read-only, so it checks the rule instead: Determinations modernisation starts 1171 days before Consents Portal re-platform - assessment and inspection finishes; Applicant services portal accessibility and hardening starts 730 days before Regional office network renewal finishes. The arrow is drawn in red and the contradiction is named rather than quietly straightened out.

1 of 22 initiatives carries no recorded start or end date. It is drawn hatched across the fiscal years it is funded in — Executive reporting workspace refresh. Zooming does not sharpen it: annual budget phasing is the only timing this dataset holds for it.

6 coordination links (two initiatives change the same application — they must talk, but neither waits for the other) and 2 blocking links (a recorded predecessor — this one genuinely waits). The distinction is the point: treating every relationship as blocking is what makes a schedule rigid, so only the 2 recorded predecessors get an arrow. The number beside each row is its own count of each, so the structure is readable without drawing every line; the lines themselves come forward on hover or focus. Click a bar or a row name for the initiative's detail.

What moved. 6 of 22 initiatives carry a previous plan, drawn as a thin bar beneath the current one with the shift shown beside the name. 4 moved out (worst +182d), 1 pulled in (best -91d), 1 unchanged. The other 16 have no baseline recorded — which is not the same as not having moved.

Zoom changes the AXIS, never the data. A quarterly gridline does not make an annual figure quarterly, and an initiative with no recorded dates is never given a quarter it does not have. No critical path and no derived running order is drawn: a tie means two initiatives change the same application, carries no arrowhead, and only a recorded predecessor gets one. The previous plan is a recorded baseline, not a reconstruction: where none was recorded, none is drawn, and no movement is inferred from anything else.

Bars use recorded start and end dates where the register holds them. Fiscal-year spend is budget intent, not a delivery schedule, and a divider inside a bar is where a year ends, not where a phase does.

Roadmap and phasing

T2 asserted / draft
InitiativeFY25/26 FY26/27 FY27/28 FY28/29 FY29/30 FY30/31 FY31/32Plan value
Consents Portal re-platform - assessment and inspection
$10,000,000
Determinations modernisation
$6,200,000
Regional office network renewal
$5,300,000
Licence renewals platform migration
$4,800,000
Levy administration uplift
$3,400,000
Identity and access modernisation
$3,000,000
Payroll and benefits replacement
$2,700,000
Enterprise data warehouse consolidation
$2,500,000
Records archive remediation
$1,800,000
Procurement and supplier portal rebuild
$1,700,000
Enforcement register uplift
$1,320,000
Revenue collection platform upgrade
$1,500,000
Applicant services portal accessibility and hardening
$1,050,000
Corporate finance ledger upgrade
$980,000
Regulatory performance automation
$870,000
Sector reporting refresh
$760,000
Guidance repository migration
$640,000
Complaints intake channel uplift
$540,000
Travel and expense refresh
$460,000
Executive reporting workspace refresh
$400,000
Information security uplift programme (portfolio-wide)
$3,150,000
IT operating model and sourcing review
$680,000

Dated anchors and agreement cliffs

AnchorDateAge at buildKindNote
Loan servicing vendor support ends2026-06-30EXPIRED 64 days agocliffSupport has already lapsed at build time. Extended support is being purchased year by year.
Regional office network contract expiry2026-12-31in 120 dayscliffRight of renewal must be exercised 90 days before expiry.
Disbursement request cutover2027-04-01in 211 daysmilestonePlanned cutover date. Every freeze window and the milestone simulation are derived from this one date.
Endpoint fleet end of life2027-09-30in 393 dayscliffReplacement lead time is 6 months across regional offices.
Primary data centre hosting agreement expiry2028-03-31in 576 dayscliffTwo-year notice period.

Anchor dates are the single source of truth. Every freeze window and every simulation in this artefact is derived from them, so moving a date here moves everything that depends on it.

Sequencing between initiatives is an editable T3 assumption, not a schedule of record. Coupling (shared entities, must coordinate) is derived and real; a running order is not.

Dependencies

T2 asserted / draft
108dependency edges
61%typed
42unclassified
2manual overrides
integration: 3030hardware: 2626software: 1010unclassified: 4242
integrationhardwaresoftwareunclassified
Most-named shared platform (keyword bucket over dependency text - not a failure domain; counts are floors)Entities
Network / connectivity20
Shared database service6
Primary data centre6
Identity directory4

No attack path and no attack graph is drawn. That needs vulnerability and telemetry data this dataset does not contain, and a path drawn without it is a picture of an assumption.

22 x 22 · CLUSTERED

Dependency matrix

T2 asserted / draft

Use this when the network diagram gets too busy to read. Past roughly twenty initiatives a matrix is easier than a web of lines. Every initiative is a row and a column, and a mark means the pair is related. means coordination: they change the same application, in no particular order. means a recorded predecessor, and it points — read it as this row waits for that column.

NRSA-002NRSA-001NRSA-012NRSA-003NRSA-013NRSA-006NRSA-011NRSA-008NRSA-016NRSA-009NRSA-014NRSA-004NRSA-005NRSA-007NRSA-010NRSA-015NRSA-017NRSA-018NRSA-019NRSA-020NRSA-021NRSA-022
Determinations modernisation NRSA-002
Consents Portal re-platform … NRSA-001
Revenue collection platform … NRSA-012
Regional office network rene… NRSA-003
Applicant services portal ac… NRSA-013
Identity and access modernis… NRSA-006
Enforcement register uplift NRSA-011
Enterprise data warehouse co… NRSA-008
Sector reporting refresh NRSA-016
Records archive remediation NRSA-009
Corporate finance ledger upg… NRSA-014
Licence renewals platform mi… NRSA-004
Levy administration uplift NRSA-005
Payroll and benefits replace… NRSA-007
Procurement and supplier por… NRSA-010
Regulatory performance autom… NRSA-015
Guidance repository migration NRSA-017
Complaints intake channel up… NRSA-018
Travel and expense refresh NRSA-019
Executive reporting workspac… NRSA-020
IT operating model and sourc… NRSA-021
Information security uplift … NRSA-022
coordination — shared applicationblocking — recorded predecessorboth — coordinated and blockingthe diagonal, an initiative against itself

Rows and columns are clustered: a greedy bandwidth-reducing pass puts related initiatives next to each other, so blocks near the diagonal are groups that move together. Clustering is a permutation — it reorders the same matrix and changes no relationship. 11 of 22 initiatives sit in at least one coordination pair; the rest are isolated rows, which is a finding about the register as much as about the plan.

Both forms are here because each is better at a different job. A network diagram is easier for following one chain from end to end; a matrix is easier for everything else once there are more than about twenty things in it. The relationship graph carries 55, so neither replaces the other.

A cell is a recorded relationship, nothing more. The matrix does not rank initiatives, does not compute a coupling score, and does not claim the clusters are teams, releases or workstreams — it claims only that those initiatives touch the same applications. An empty cell means no relationship is RECORDED, never that none exists.

Built from the same two sources as every other dependency surface here: the intersection of initiative footprints, and the recorded predecessor field.

THREE READINGS OF THE SAME RECORD

Relationship graph

T2 asserted / draft

Three questions, three readings of the same data. Applications answers what feeds what. Initiatives answers how the programme is tied to itself — a dashed curve where two initiatives change the same application, a solid arrow only where a predecessor is actually recorded. Both puts the programme inside the estate it changes.

Consents Portal - Assessment feeds Enterprise Data WarehouseConsents Portal - Inspection feeds Enterprise Data WarehouseConsents Portal - Determinations feeds Payments GatewayConsents Portal - Determinations feeds Licence Renewals SystemConsents Portal - Lodgement feeds Consents Portal - AssessmentConsents Portal - Closure feeds Regulatory Performance PlatformLicence Renewals System feeds Corporate Finance LedgerPayments Gateway feeds Corporate Finance LedgerLevy Administration System feeds Infringement Fees LedgerLevy Administration System feeds Enterprise Data WarehouseInfringement Fees Ledger feeds Corporate Finance LedgerRevenue Collection Platform feeds Payments GatewaySector Reporting Workspace feeds Enterprise Data WarehouseEnforcement and Compliance Register feeds Consents Portal - InspectionRegulatory Performance Platform feeds Enterprise Data WarehouseApplicant Services Portal feeds Consents Portal - DeterminationsRegional Office Network Gateway feeds Consents Portal - InspectionComplaints and Review Intake feeds Enforcement and Compliance RegisterOpen Data Catalogue feeds Enterprise Data WarehouseHuman Resources Core feeds Payroll and Benefits EngineHuman Resources Core feeds Identity and Access DirectoryProcurement and Supplier Portal feeds Corporate Finance LedgerTravel and Expense System feeds Corporate Finance LedgerGuidance and Standards Repository feeds Records and Correspondence ArchiveLegacy Reporting Warehouse feeds Enterprise Data WarehouseEnterprise Data Warehouse feeds Executive Reporting WorkspaceEnterprise Data Warehouse feeds Regulatory Analysis EnvironmentEnterprise Data Warehouse feeds Open Data CatalogueConsents Portal - Assessment — Consenting and licensing, rating 4Consents Portal - Closure — Consenting and licensing, rating 3Consents Portal - Determinations — Consenting and licensing, rating 4Consents Portal - Inspection — Consenting and licensing, rating 4Consents Portal - Lodgement — Consenting and licensing, rating 4Enforcement and Compliance Register — Consenting and licensing, rating 3Licence Renewals System — Consenting and licensing, rating 4Regulatory Performance Platform — Consenting and licensing, rating 3Infringement Fees Ledger — Revenue and levies, rating 3Levy Administration System — Revenue and levies, rating 4Payments Gateway — Revenue and levies, rating 4Revenue Collection Platform — Revenue and levies, rating 4Sector Reporting Workspace — Revenue and levies, rating 3Corporate Finance Ledger — Corporate services, rating 4Human Resources Core — Corporate services, rating 3Payroll and Benefits Engine — Corporate services, rating 4Procurement and Supplier Portal — Corporate services, rating 3Records and Correspondence Archive — Corporate services, rating 3Travel and Expense System — Corporate services, rating 3Applicant Services Portal — Applicant and regional platforms, rating 4Complaints and Review Intake — Applicant and regional platforms, rating 3External Collaboration Workspace — Applicant and regional platforms, rating 3Open Data Catalogue — Applicant and regional platforms, rating 3Regional Office Network Gateway — Applicant and regional platforms, rating 4Enterprise Data Warehouse — Data and information, rating 3Executive Reporting Workspace — Data and information, rating 2Guidance and Standards Repository — Data and information, rating 3Regulatory Analysis Environment — Data and information, rating 3Backup and Recovery Service — Infrastructure and workplace, rating 4Endpoint Management Service — Infrastructure and workplace, rating 3Identity and Access Directory — Infrastructure and workplace, rating 3Legacy Reporting Warehouse — Infrastructure and workplace, rating 4Storage Array (primary data centre) — Infrastructure and workplace, rating 4Consents Portal - AssessmentConsents Portal - ClosureConsents Portal - Determinat…Consents Portal - InspectionConsents Portal - LodgementEnforcement and Compliance R…Licence Renewals SystemRegulatory Performance Platf…Infringement Fees LedgerLevy Administration SystemPayments GatewayRevenue Collection PlatformSector Reporting WorkspaceCorporate Finance LedgerHuman Resources CorePayroll and Benefits EngineProcurement and Supplier Por…Records and Correspondence A…Travel and Expense SystemApplicant Services PortalComplaints and Review IntakeExternal Collaboration Works…Open Data CatalogueRegional Office Network Gate…Enterprise Data WarehouseExecutive Reporting WorkspaceGuidance and Standards Repos…Regulatory Analysis Environm…Backup and Recovery ServiceEndpoint Management ServiceIdentity and Access DirectoryLegacy Reporting WarehouseStorage Array (primary data …Consents Portal re-platform - assessment and inspection and Determinations modernisation both change Consents Portal - Determinations. No sequence is implied.Determinations modernisation and Revenue collection platform upgrade both change Payments Gateway. No sequence is implied.Regional office network renewal and Applicant services portal accessibility and hardening both change Applicant Services Portal. No sequence is implied.Identity and access modernisation and Enforcement register uplift both change Identity and Access Directory. No sequence is implied.Enterprise data warehouse consolidation and Sector reporting refresh both change Enterprise Data Warehouse. No sequence is implied.Records archive remediation and Corporate finance ledger upgrade both change Corporate Finance Ledger. No sequence is implied.Recorded predecessor: Consents Portal re-platform - assessment and inspection before Determinations modernisationRecorded predecessor: Regional office network renewal before Applicant services portal accessibility and hardeningConsents Portal re-platform - assessment and inspection (NRSA-001)Determinations modernisation (NRSA-002)Regional office network renewal (NRSA-003)Licence renewals platform migration (NRSA-004)Levy administration uplift (NRSA-005)Identity and access modernisation (NRSA-006)Payroll and benefits replacement (NRSA-007)Enterprise data warehouse consolidation (NRSA-008)Records archive remediation (NRSA-009)Procurement and supplier portal rebuild (NRSA-010)Enforcement register uplift (NRSA-011)Revenue collection platform upgrade (NRSA-012)Applicant services portal accessibility and hardening (NRSA-013)Corporate finance ledger upgrade (NRSA-014)Regulatory performance automation (NRSA-015)Sector reporting refresh (NRSA-016)Guidance repository migration (NRSA-017)Complaints intake channel uplift (NRSA-018)Travel and expense refresh (NRSA-019)Executive reporting workspace refresh (NRSA-020)Consents Portal re-platform …Determinations modernisationRegional office network rene…Licence renewals platform mi…Levy administration upliftIdentity and access modernis…Payroll and benefits replace…Enterprise data warehouse co…Records archive remediationProcurement and supplier por…Enforcement register upliftRevenue collection platform …Applicant services portal ac…Corporate finance ledger upg…Regulatory performance autom…Sector reporting refreshGuidance repository migrationComplaints intake channel up…Travel and expense refreshExecutive reporting workspac…Consents Portal - Assessment feeds Enterprise Data WarehouseConsents Portal - Inspection feeds Enterprise Data WarehouseConsents Portal - Determinations feeds Payments GatewayConsents Portal - Determinations feeds Licence Renewals SystemConsents Portal - Lodgement feeds Consents Portal - AssessmentConsents Portal - Closure feeds Regulatory Performance PlatformLicence Renewals System feeds Corporate Finance LedgerPayments Gateway feeds Corporate Finance LedgerLevy Administration System feeds Infringement Fees LedgerLevy Administration System feeds Enterprise Data WarehouseInfringement Fees Ledger feeds Corporate Finance LedgerRevenue Collection Platform feeds Payments GatewaySector Reporting Workspace feeds Enterprise Data WarehouseEnforcement and Compliance Register feeds Consents Portal - InspectionRegulatory Performance Platform feeds Enterprise Data WarehouseApplicant Services Portal feeds Consents Portal - DeterminationsRegional Office Network Gateway feeds Consents Portal - InspectionComplaints and Review Intake feeds Enforcement and Compliance RegisterOpen Data Catalogue feeds Enterprise Data WarehouseHuman Resources Core feeds Payroll and Benefits EngineHuman Resources Core feeds Identity and Access DirectoryProcurement and Supplier Portal feeds Corporate Finance LedgerTravel and Expense System feeds Corporate Finance LedgerGuidance and Standards Repository feeds Records and Correspondence ArchiveLegacy Reporting Warehouse feeds Enterprise Data WarehouseEnterprise Data Warehouse feeds Executive Reporting WorkspaceEnterprise Data Warehouse feeds Regulatory Analysis EnvironmentEnterprise Data Warehouse feeds Open Data CatalogueConsents Portal re-platform - assessment and inspection changes Consents Portal - AssessmentConsents Portal re-platform - assessment and inspection changes Consents Portal - InspectionConsents Portal re-platform - assessment and inspection changes Consents Portal - LodgementConsents Portal re-platform - assessment and inspection changes Consents Portal - DeterminationsDeterminations modernisation changes Consents Portal - DeterminationsDeterminations modernisation changes Payments GatewayRegional office network renewal changes Regional Office Network GatewayRegional office network renewal changes Applicant Services PortalLicence renewals platform migration changes Licence Renewals SystemLevy administration uplift changes Levy Administration SystemLevy administration uplift changes Infringement Fees LedgerIdentity and access modernisation changes Identity and Access DirectoryIdentity and access modernisation changes Endpoint Management ServicePayroll and benefits replacement changes Payroll and Benefits EnginePayroll and benefits replacement changes Human Resources CoreEnterprise data warehouse consolidation changes Enterprise Data WarehouseEnterprise data warehouse consolidation changes Regulatory Analysis EnvironmentRecords archive remediation changes Records and Correspondence ArchiveRecords archive remediation changes Corporate Finance LedgerProcurement and supplier portal rebuild changes Procurement and Supplier PortalEnforcement register uplift changes Enforcement and Compliance RegisterEnforcement register uplift changes Identity and Access DirectoryRevenue collection platform upgrade changes Revenue Collection PlatformRevenue collection platform upgrade changes Payments GatewayApplicant services portal accessibility and hardening changes Applicant Services PortalCorporate finance ledger upgrade changes Corporate Finance LedgerRegulatory performance automation changes Regulatory Performance PlatformRegulatory performance automation changes Consents Portal - ClosureSector reporting refresh changes Sector Reporting WorkspaceSector reporting refresh changes Enterprise Data WarehouseGuidance repository migration changes Guidance and Standards RepositoryComplaints intake channel uplift changes Complaints and Review IntakeTravel and expense refresh changes Travel and Expense SystemExecutive reporting workspace refresh changes Executive Reporting WorkspaceConsents Portal - AssessmentConsents Portal - ClosureConsents Portal - DeterminationsConsents Portal - InspectionConsents Portal - LodgementEnforcement and Compliance RegisterLicence Renewals SystemRegulatory Performance PlatformInfringement Fees LedgerLevy Administration SystemPayments GatewayRevenue Collection PlatformSector Reporting WorkspaceCorporate Finance LedgerHuman Resources CorePayroll and Benefits EngineProcurement and Supplier PortalRecords and Correspondence ArchiveTravel and Expense SystemApplicant Services PortalComplaints and Review IntakeExternal Collaboration WorkspaceOpen Data CatalogueRegional Office Network GatewayEnterprise Data WarehouseExecutive Reporting WorkspaceGuidance and Standards RepositoryRegulatory Analysis EnvironmentBackup and Recovery ServiceEndpoint Management ServiceIdentity and Access DirectoryLegacy Reporting WarehouseStorage Array (primary data centre)Consents Portal re-platform - assessment and inspectionDeterminations modernisationRegional office network renewalLicence renewals platform migrationLevy administration upliftIdentity and access modernisationPayroll and benefits replacementEnterprise data warehouse consolidationRecords archive remediationProcurement and supplier portal rebuildEnforcement register upliftRevenue collection platform upgradeApplicant services portal accessibility and hardeningCorporate finance ledger upgradeRegulatory performance automationSector reporting refreshGuidance repository migrationComplaints intake channel upliftTravel and expense refreshExecutive reporting workspace refreshConsents Portal - AssessmentConsents Portal - ClosureConsents Portal - Determinat…Consents Portal - InspectionConsents Portal - LodgementEnforcement and Compliance R…Licence Renewals SystemRegulatory Performance Platf…Infringement Fees LedgerLevy Administration SystemPayments GatewayRevenue Collection PlatformSector Reporting WorkspaceCorporate Finance LedgerHuman Resources CorePayroll and Benefits EngineProcurement and Supplier Por…Records and Correspondence A…Travel and Expense SystemApplicant Services PortalComplaints and Review IntakeExternal Collaboration Works…Open Data CatalogueRegional Office Network Gate…Enterprise Data WarehouseExecutive Reporting WorkspaceGuidance and Standards Repos…Regulatory Analysis Environm…Backup and Recovery ServiceEndpoint Management ServiceIdentity and Access DirectoryLegacy Reporting WarehouseStorage Array (primary data …
applicationexposed and past supported lifeinitiativeapplication feeds applicationshared application — no directionrecorded predecessorinitiative changes application

33 applications, 20 initiatives, 28 application-to-application edges, 6 couplings, 2 recorded predecessors and 34 footprint links. Ring position carries no meaning — it is alphabetical within a group, not a rank, a score or a distance. 1 recorded edge not drawn: it attaches to a target state, which is a plan rather than something running, so it has no node here. That is why this count is 28 where the register's own reconciliation says 29.

This is a record of what the register says connects to what. It is NOT an attack graph, a data-flow diagram or a failure model: nothing in this dataset describes what happens when a node fails. An edge that is not drawn means the relationship is UNRECORDED, never that it does not exist.

Edges are the dependency records, the initiative footprints and the recorded predecessors — the same data the Dependencies, Register and Plan tabs count.

Trade-off - funding level

T3 modelled / inferred

Cut the plan in 5% steps and watch what it costs. The cap is a share of the AUTO-RANKABLE pool ($49,920,000 across 20 initiatives), not of the whole plan: left on the whole plan the lever is inert whenever the unrankable tray is large.

100%

2 initiative(s) ($3,830,000) are held in a MANUAL-ONLY tray. They have no priority rank or no modelled reduction, so the automatic cut order cannot rank them. They are never defunded first - using the coverage gap as a defund pool is the exact behaviour the funding stepper is gated against.

21 LEVELS · 22 INITIATIVES

Funding scenarios

T3 modelled / inferred

The same plan at every funding level. Obligations are committed first; the discretionary set is then funded in Prioritisation rank order until the money runs out. Move the slider and the schedule redraws — a deferred initiative is drawn hollow, not deleted, because deferring is a decision that stays visible.

1 initiative has no start or finish date and is drawn hatched, across the fiscal years the money is phased into rather than the period it actually runs: Executive reporting workspace refresh. The bar is a funding window, not a schedule.

100%
2026202720282029Information security uplift programme…Information security uplift programme (portfolio-wide) · $3,150,000 · obligationIdentity and access modernisationIdentity and access modernisation · $3,000,000 · obligationRecords archive remediationRecords archive remediation · $1,800,000 · obligationEnforcement register upliftEnforcement register uplift · $1,320,000 · obligationApplicant services portal accessibili…Applicant services portal accessibility and hardening · $1,050,000 · obligationCorporate finance ledger upgradeCorporate finance ledger upgrade · $980,000 · obligationComplaints intake channel upliftComplaints intake channel uplift · $540,000 · obligationSector reporting refreshSector reporting refresh · $760,000 · rank 1Regulatory performance automationRegulatory performance automation · $870,000 · rank 2Consents Portal re-platform - assessm…Consents Portal re-platform - assessment and inspection · $10,000,000 · rank 3Enterprise data warehouse consolidati…Enterprise data warehouse consolidation · $2,500,000 · rank 4Revenue collection platform upgradeRevenue collection platform upgrade · $1,500,000 · rank 5Determinations modernisationDeterminations modernisation · $6,200,000 · rank 6Licence renewals platform migrationLicence renewals platform migration · $4,800,000 · rank 7Levy administration upliftLevy administration uplift · $3,400,000 · rank 8Regional office network renewalRegional office network renewal · $5,300,000 · rank 9Executive reporting workspace refreshExecutive reporting workspace refresh · $400,000 · rank 10 · no dates recorded; drawn across its funded yearsPayroll and benefits replacementPayroll and benefits replacement · $2,700,000 · rank 11Guidance repository migrationGuidance repository migration · $640,000 · rank 12Travel and expense refreshTravel and expense refresh · $460,000 · rank 13Procurement and supplier portal rebui…Procurement and supplier portal rebuild · $1,700,000 · rank 14IT operating model and sourcing reviewIT operating model and sourcing review · $680,000 · cannot be ranked
Obligation — committed first, never cutRanked by the modelCannot be ranked — held, never auto-cutDeferred at this level

A cut can break the plan, not just shorten it. At 0% funding, Applicant services portal accessibility and hardening is funded while Regional office network renewal is not — and the register records the second as a predecessor of the first. The model has no way to see that: it ranks initiatives one at a time. Sequencing has to be re-checked after any cut, and this tab flags it rather than drawing a plan that cannot run.

At 50% of the plan, 11 of 22 initiatives are funded and 53% of the modelled risk reduction survives — the shape of that curve, not the endpoints, is the argument. Obligations alone are $11,840,000, so any level below 25% funds nothing discretionary at all.

This lever and the one above it do not use the same denominator. The engine's trade-off caps on its auto-rankable pool ($49,920,000 across 20 initiatives) and holds the rest in a manual tray; this ladder caps on the whole plan ($53,750,000 across 22) and ring-fences obligations before anything is cut. Two levers, two different meanings for the same percentage — so 50% here is not 50% there, and the two are not to be read against each other.

Funding stops at the first initiative that does not fit, not at the last one that does. Skipping over an unaffordable item to buy cheaper ones further down is a different decision from funding in priority order — and it lets an initiative be funded at one level and cut at a higher one, which is not a plan anyone can act on. The price of the stricter rule is headroom left unspent at most levels; the readout above names it at every step rather than quietly filling it.

A deferred initiative does not return its money today. Spend is phased across years, and cutting an initiative that is already part-delivered recovers only what has not been committed — the dataset holds no commitment position, so this tab shows the plan value, not the recoverable amount. Nor is anything rescheduled: the surviving bars sit exactly where they sat, because freeing budget does not by itself pull work forward, and drawing it as though it did would invent a schedule nobody has agreed. The cut order comes from a model whose weights are a choice — see Prioritisation for how much of this order survives that choice being made differently.

Every level is computed at build time and embedded; the slider selects between precomputed sets and calculates nothing. Rank order comes from the Prioritisation tab, obligations from the register.

FY26/27 budget scenario

T1 documented
OPTION - not yet decided. Not included in the baseline plan total. As at 2026-08-01.
$15,450,000FY26/27 budget scenario total
$10,400,000option one
$15,450,000option two
$2,500,000proposed for deferral

This sits BESIDE the baseline plan and is never added into it. The baseline plan total on every other tab is unchanged by this layer, and a gate fails the build if it moves.

Initiativebaseline plan (FY26/27)ProposedDelta
Consents Portal re-platform - assessment and inspection$3,200,000$3,200,000$0
Determinations modernisation$2,600,000$2,600,000$0
Regional office network renewal$1,900,000$1,900,000$0
Licence renewals platform migration$1,600,000$1,600,000$0
Levy administration uplift$1,200,000$1,200,000$0
Identity and access modernisation$1,000,000$1,000,000$0
Payroll and benefits replacement$900,000$900,000$0
Records archive remediation$600,000$600,000$0
Revenue collection platform upgrade$480,000$480,000$0
Enforcement register uplift$420,000$420,000$0
Enterprise data warehouse consolidation$800,000$800,000$0name drift

Line-to-initiative matching: 10 clean, 1 name drift, 0 ambiguous, 2 unmatched. Ambiguous lines are reported, never split by rule.

Change freezes register

T2 asserted / draft
WindowStateStartEndScopeDerived from anchorTier
Disbursement cutover change freezePROPOSED2027-04-012027-07-01All change to disbursement, settlement and client-facing applicationsDisbursement request cutoverT3
Financial year-end freezeIN-FORCE2027-06-012027-07-15All change to financial and levy scheme applicationsT1

A PROPOSED window is not an agreed one and is never drawn as though it were. Each window is derived from its anchor date plus an offset, so it moves when the anchor moves.

Change load

7 GROUPS · PEAK 5 AT ONCE · LONGEST RUN 4 YEARS

Change pressure, by group and year

T3 modelled / inferred

The chart below counts money. This counts what it is like to be on the receiving end. A funding view puts an initiative in a year because spend is phased there. This view asks two different questions: how many things are happening to each group at once, and how many years in a row. It uses start and finish dates rather than funding, because an initiative funded across three years is one long imposition, not three.

Business areaFY25/26FY26/27FY27/28FY28/29FY29/30FY30/31FY31/32Longest run
Applicant and regional platforms3 initiatives · peak 3 at once·333···3consecutive years
Consenting and licensing5 initiatives · peak 5 at once2555···4consecutive years
Corporate services5 initiatives · peak 5 at once·4551··4consecutive years
Data and information4 initiatives · peak 4 at once1444···4consecutive years
Infrastructure and workplace2 initiatives · peak 2 at once1222···4consecutive years
Revenue and levies4 initiatives · peak 4 at once1444···4consecutive years
Not attributed to a business area2 initiatives · peak 2 at once1221···4consecutive years
Cell = initiatives running on that group in that year1–2345

What the shape says

These row counts deliberately add up to more than the plan. A group’s count is the initiatives that land on it, and an initiative touching three business areas lands three times — it is three groups’ problem, not a third of one. The roadmap draws the same initiative once, in the area it touches most, so the lane totals there are smaller and both are right. Do not add these rows together and compare the result with the plan.

The longest unbroken run is 4 consecutive years of change, carried by 6 of the 7 groups; the highest concurrency is 5 initiatives at once, on consenting and licensing and corporate services. Concurrency and consecutive exposure are the two things change practice treats as load at group level, and both need start and finish dates rather than funded years to mean anything.

1 initiative has no start or finish date, so it is drawn across its funded years instead — which is wider than it actually runs and overstates the run length for every group it touches: Executive reporting workspace refresh.

What would have to be gathered before anyone says “too much”

Capacity per group

the missing denominator

Headcount, and how much of it is available for change rather than run. Saturation is load above capacity; without a denominator there is no saturation figure, only a count.

What each group has already absorbed

the change history behind this plan

A group finishing a two-year migration starts this one tired. Nothing in the register knows that.

Effort, not just money

the register holds spend

A $400k process change can cost a team more than a $4m platform swap. Spend is a poor proxy for disruption and it is the only proxy here.

Sponsor bandwidth

who is sponsoring how many

Sponsor capacity is a harder constraint than budget on most programmes, and it is not recorded anywhere in this dataset.

Readiness

awareness, desire, knowledge, ability, reinforcement

Per group, before and during. None of it is here — which is why this panel counts and does not judge.

There is no saturation score here, and no red-amber-green, because saturation is load above CAPACITY and this dataset holds no capacity of any kind — no headcount, no availability, no change history, no readiness, no sponsor coverage. Colouring a cell red for holding three initiatives would invent the denominator, and an invented denominator is worse than an absent one because it looks like an answer. The shading below is a COUNT rendered darker, nothing more; a dark cell means many things at once, never "too much". Nor is anything weighted: the register carries no measure of how disruptive any one initiative is to the people receiving it, so a platform replacement and a reporting refresh count the same here, and they are not the same.

Concurrency is computed from each initiative's start and finish dates and the fiscal-year boundaries; business area comes from the application footprint, as on the chart below. Both are already in the register.

6 BUSINESS AREAS · PEAK FY27/28

Change load by business area

T3 modelled / inferred

Where the change actually lands, and on whom. The plan is split by the business area each initiative touches, derived from its application footprint, and phased by the years its funding falls in. Click any segment for the initiatives driving it in that year.

06121723FY25/26 — Consenting and licensing: 2 initiatives. Click for what is driving it.FY25/26 — Data and information: 1 initiative. Click for what is driving it.FY25/26 — Infrastructure and workplace: 1 initiative. Click for what is driving it.FY25/26 — Revenue and levies: 1 initiative. Click for what is driving it.FY25/265FY26/27 — Applicant and regional platforms: 3 initiatives. Click for what is driving it.FY26/27 — Consenting and licensing: 5 initiatives. Click for what is driving it.FY26/27 — Corporate services: 4 initiatives. Click for what is driving it.FY26/27 — Data and information: 4 initiatives. Click for what is driving it.FY26/27 — Infrastructure and workplace: 2 initiatives. Click for what is driving it.FY26/27 — Revenue and levies: 4 initiatives. Click for what is driving it.FY26/2722FY27/28 — Applicant and regional platforms: 3 initiatives. Click for what is driving it.FY27/28 — Consenting and licensing: 5 initiatives. Click for what is driving it.FY27/28 — Corporate services: 5 initiatives. Click for what is driving it.FY27/28 — Data and information: 4 initiatives. Click for what is driving it.FY27/28 — Infrastructure and workplace: 2 initiatives. Click for what is driving it.FY27/28 — Revenue and levies: 4 initiatives. Click for what is driving it.FY27/2823FY28/29 — Applicant and regional platforms: 3 initiatives. Click for what is driving it.FY28/29 — Consenting and licensing: 5 initiatives. Click for what is driving it.FY28/29 — Corporate services: 5 initiatives. Click for what is driving it.FY28/29 — Data and information: 4 initiatives. Click for what is driving it.FY28/29 — Infrastructure and workplace: 2 initiatives. Click for what is driving it.FY28/29 — Revenue and levies: 4 initiatives. Click for what is driving it.FY28/2923FY29/30 — Corporate services: 1 initiative. Click for what is driving it.FY29/301
Applicant and regional platformsConsenting and licensingCorporate servicesData and informationInfrastructure and workplaceRevenue and levies

Peak segmented load falls in FY27/28, carrying 23 initiative-to-area landings across 6 of the 6 business areas; the largest single share is Consenting and licensing with 5. FY27/28 and FY28/29 carry the same load and the earliest is named; nothing in the data breaks the tie. Numbers above each column are that year's total landings. FY25/26 had already ended when this was built and is excluded from the peak — an elapsed year cannot drive a forward-looking recommendation, which is the engine’s own rule for this. The column is still drawn. FY30/31 and FY31/32 carry no funded phasing at all and therefore have no column here — absent because nothing lands, not because anything was dropped.

2 initiatives cannot be segmented at all — IT operating model and sourcing review and Information security uplift programme (portfolio-wide) name no application footprint, so there is nothing to attribute them to. They are absent from every column above and are named here rather than quietly dropped.

The columns count landings, not initiatives, and they deliberately add up to more than the plan. An initiative touching three business areas is counted once in each of them, because it genuinely lands on three groups — so summing a column gives the number of initiative-to-area landings that year, and summing every column gives more than 22. Nothing here weights an initiative by size, effort or disruption either: the dataset carries no measure of how much change any one initiative represents to the people receiving it, so a tall column means MANY things arriving, never a hard year.

Business area comes from the domain of each application an initiative touches; the years come from its funded phasing. Both are already in the register — this is a re-cut of them, not a new measure.

Agreements

Agreements · the agreement register, in one place

18agreements in the agreement register
13with a recorded expiry date
5no date held — cannot be aged
2already expired
5 (1 with cover stated)expired or within 91 days
Read the day counts with the route status, never without it. 2 rows whose own route status or next action states approved cover or no action beyond the recorded date are shown in blue or grey, never in an urgency colour — a red countdown against a row whose own register text says cover is approved past that date would be wrong. Every day count on this tab carries its route status and next action in the same block, so the two cannot be cropped apart. The rule is derived from the text, not a list of row names, so a new such row is caught the day it appears.

Every agreement this build knows about, aged at build time against 2026-09-02, with the register’s own route status and next action beside every day count. One table, one day-count implementation, one tier statement. transcription T1 - name, supplier, date, route status and next action are reproduced VERBATIM from the agreement register, including its own spelling; date accuracy T2 - the register is a planning snapshot maintained by the IT vendor-management function, not an extract from executed agreements.

Already expired · 2 of 18

2 agreements in the agreement register carry an expiry date that has already passed, and the register’s stated next action for each is written as something to be done rather than something done. The register records a remediation status for 2 of them, reproduced above verbatim; for the other 0 it records none, and this page asserts nothing either way about those. It states what the register holds: a date that has passed, and an action still phrased as an instruction.

Loan servicing extended supportCalderon Systems64 days overdue EXPIRED
Recorded expiry 2026-06-30 · Route status Extended support purchased annually · Register’s stated next action “Confirm the next extension before the migration milestone.”
Recorded remediation status Extension purchased; term recorded in the vendor file, not yet in this register
Correspondent banking connectivityNordvale Payments18 days overdue EXPIRED
Recorded expiry 2026-08-15 · Route status Rolled forward pending the settlement review · Register’s stated next action “Reconcile against the settlement gateway roadmap.”
Recorded remediation status Rollover agreed verbally; nothing executed

Sorted most overdue first. Day counts are computed at build time from 2026-09-02 and re-age on every rebuild — they are not stored figures. transcription T1 - name, supplier, date, route status and next action are reproduced VERBATIM from the agreement register, including its own spelling; date accuracy T2 - the register is a planning snapshot maintained by the IT vendor-management function, not an extract from executed agreements.

COVERAGE VERIFIED BY GATE

Notice terms: what the agreement register holds, and what it does not

6 of 18 agreements carry a recorded term in one of the declared fields (notice_period_days). Those terms are rendered from the data in the table below and in the row cells on this tab. The remaining 12 carry none.

This is not a statement that the other 12 have no notice period. Almost every agreement of this kind has one. It is a statement that this build cannot see them. The distinction matters because the two are indistinguishable on screen if the gap is drawn as an empty column, and only one of them is true.

The consequence. An expiry date is not a decision date. Every day count on this tab for a row with no recorded term is an upper bound on the time available, not the time available.

AgreementSupplierRecorded term, verbatim
Loan servicing extended supportCalderon Systemsnotice_period_days 90
Endpoint management subscriptionRedgate Mobilitynotice_period_days 60
Regional office network servicesRidgeline Telecomnotice_period_days 90
Operations portal maintenanceCalderon Systemsnotice_period_days 180
Revenue dealing platform licenceHalbeck Marketsnotice_period_days 90
Records archive storageVerity Recordsnotice_period_days 30

The ask, and where it goes. The terms live in the executed agreements themselves and in the vendor files. Sourcing notice periods, termination-for-convenience windows and extension-option terms from those, per agreement, is the single highest-value addition to this dataset. It is a data ask for the IT vendor-management function and the named agreement owners, not a derivation this engine can make — nothing in the data supports inventing a term. Add the field to the register, list its name in cliffs.notice_fields, and this panel switches to reporting coverage.

Second ask. Only 17 of 18 agreements are linked to an entity in this model, and those links are curated in the data. The other 1 are not linked, and are not auto-joined on name similarity: a name-matched mapping is a guess wearing the appearance of a join. Agreement-to-entity coverage is a data ask, not a derivation.

Verified, not asserted: a build gate scans agreements[], anchors[], every key in the build data object and every key in the payload embedded in this file (420 distinct across the two, walked recursively and unioned) and the header row of the agreements CSV for any notice / termination / extension / renewal field, and stops the build if an undeclared one appears — because the correct response to real notice data is to render it and retire this panel, not to leave the panel standing beside it. It is a scan of field names: it cannot see a notice period written into free text, which is why the claim above is about fields. 42 key(s) exist only in the embedded payload and are covered by the union: align, apps, broken, budget, cells, criterion, critical_points, currency, cut, days, domain, exposure_driver, funded_from, funding, fys, group, groups, headroom, horizon, inits, level, levels, mandated, monitored, objective, obsolescence_driver, over, parts, phasing, points, rank_high, rank_low, rating, scored, scores, segments, spend, stopped, swing, tray, window, year_index.

The 10 things that come closest — and why none of them is a notice period

WhereWhat it actually saysWhy it is not a notice periodTier
Loan servicing extended support — Calderon Systemsroute status: “Extended support purchased annually” · next action: “Confirm the next extension before the migration milestone.”Mentions extend. That is a route through a process or a stated intention, not an option term held in an instrument. No length, no trigger, no notice.T1 as text, T3 as a statement about the agreement
Statistical software licences — Aventine Analyticsroute status: “Renewal not approved until 2028 budget round”Mentions renewal. That is a route through a process or a stated intention, not an option term held in an instrument. No length, no trigger, no notice.T1 as text, T3 as a statement about the agreement
Endpoint management subscription — Redgate Mobilityroute status: “Cover approved to 2028”An assertion of approved cover, stated to a year with no day. It is not a notice period, and a bare year is not a date.T1 verbatim
Regional office network services — Ridgeline Telecomnext action: “Exercise or decline the right of renewal 90 days out.”Mentions renewal. That is a route through a process or a stated intention, not an option term held in an instrument. No length, no trigger, no notice.T1 as text, T3 as a statement about the agreement
Legacy reporting warehouse licence — Aventine Analyticsroute status: “Being retired with the warehouse consolidation” · next action: “No action is required; the licence lapses when the warehouse is decommissioned.”A planning position. It is not a notice period and not a termination right.T1 verbatim
Revenue dealing platform licence — Halbeck Marketsnext action: “Review value before the next renewal window.”Mentions renewal. That is a route through a process or a stated intention, not an option term held in an instrument. No length, no trigger, no notice.T1 as text, T3 as a statement about the agreement
Payroll bureau services — Thornbury Payrollroute status: “Two-year extension option under discussion with the provider” · next action: “Decide whether to take the extension or go to market.”Mentions extension. That is a route through a process or a stated intention, not an option term held in an instrument. No length, no trigger, no notice.T1 as text, T3 as a statement about the agreement
anchor “core_support”“Support has already lapsed at build time. Extended support is being purchased year by year.”Notice or option language in free text, not in a field. No row can be aged from it, no count can be taken off it, and the field scan below cannot see it — which is why the claim above is about fields.T1 as text, T3 as a term
anchor “network_contract”“Right of renewal must be exercised 90 days before expiry.”Notice or option language in free text, not in a field. No row can be aged from it, no count can be taken off it, and the field scan below cannot see it — which is why the claim above is about fields.T1 as text, T3 as a term
anchor “dc_hosting”“Two-year notice period.”Notice or option language in free text, not in a field. No row can be aged from it, no count can be taken off it, and the field scan below cannot see it — which is why the claim above is about fields.T1 as text, T3 as a term

Shown in the source’s own words so the reader can judge the reading rather than take it. None of the 10 is a notice period, a termination right or an option term.

The most decision-relevant fact on this tab is a GAP. It is stated in words, and deliberately NOT drawn as an empty column: blank cells read as "no notice requirements apply", which is the opposite of what is known, and an empty column is byte-identical to a renderer that failed.

Every agreement in the agreement register · 18 rows

AgreementSupplierRecorded expiryAged at build time — with the register’s own route status and next action
Loan servicing extended supportCalderon Systems2026-06-30
64 days overdue EXPIRED
Route status: Extended support purchased annually
Next action: Confirm the next extension before the migration milestone.
Recorded term: notice_period_days 90
Correspondent banking connectivityNordvale Payments2026-08-15
18 days overdue EXPIRED
Route status: Rolled forward pending the settlement review
Next action: Reconcile against the settlement gateway roadmap.
Endpoint management subscriptionRedgate Mobility2026-09-20
expiry date in 18 days COVER STATED
Route status: Cover approved to 2028
Next action: Fold into the identity and access modernisation scope.
Recorded term: notice_period_days 60
COVER STATED BEYOND EXPIRY
The register’s own route status for this row states approved cover past the date being counted down to — it reads “Cover approved to 2028”. No end date is stated for that cover and none is inferred here. Read the day count as the age of the RECORDED EXPIRY DATE, not as an exposure.
Statistical software licencesAventine Analytics2026-09-30
28 days ACT NOW
Route status: Renewal not approved until 2028 budget round
Next action: Hold. Re-test demand after the analysis environment consolidation.
Levy scheme sector partner portal supportBellhouse Digital2026-11-30
89 days PLAN
Route status: Sole provider?
Next action: Obtain a quotation for continued support and record the decision.
Regional office network servicesRidgeline Telecom2027-01-31
151 days PLAN
Route status: Managed service, multi-region
Next action: Exercise or decline the right of renewal 90 days out.
Recorded term: notice_period_days 90
Legacy reporting warehouse licenceAventine Analytics2027-03-31
expiry date in 210 days NO ACTION STATED
Route status: Being retired with the warehouse consolidation
Next action: No action is required; the licence lapses when the warehouse is decommissioned.
REGISTER STATES NO ACTION REQUIRED
The register’s own next action for this row states that no action is required (route status: “Being retired with the warehouse consolidation”). The day count is the age of the recorded date only, and this page does not assert that the agreement is covered.
Operations portal maintenanceCalderon Systems2027-06-30
301 days PLAN
Route status: Open market process planned
Next action: Start the market process 12 months out.
Recorded term: notice_period_days 180
Revenue dealing platform licenceHalbeck Markets2027-09-30
393 days PLAN
Route status: Annual subscription
Next action: Review value before the next renewal window.
Recorded term: notice_period_days 90
Identity directory subscriptionArdua Identity2027-12-31
485 days PLAN
Route status: Enterprise agreement
Next action: Align with the identity and access modernisation initiative.
Records archive storageVerity Records2028-06-30
667 days PLAN
Route status: Standing arrangement
Next action: Confirm the retention obligations are written down.
Recorded term: notice_period_days 30
Payroll bureau servicesThornbury Payroll2028-12-31
851 days PLAN
Route status: Two-year extension option under discussion with the provider
Next action: Decide whether to take the extension or go to market.
Client portal accessibility auditCartway Assurance2029-06-30
1032 days PLAN
Route status: Multi-year arrangement
Next action: Nothing before the portal hardening completes.
NO EXPIRY DATE HELD — 5 of 18 agreements
These 5 rows exist in the agreement register with the expiry cell blank. They are not shown as low priority, distant, or safe — they are shown as not aged, because the register holds nothing to age them from. There are exactly two states on this tab: date held, and date not held. Nothing is estimated, bucketed, ranked by date shape or defaulted.
Capital works scheduling licenceArdua Civilnot held
no date held NO DATE HELD
Route status: not set
Next action: Locate the signed document. The register has never held a date for this row.
Data centre hosting (disaster recovery)Aventine Cloud Servicesnot held
no date held NO DATE HELD
Route status: Under negotiation
Next action: Record the executed end date once signed.
Knowledge repository hostingVerity Recordsnot held
no date held NO DATE HELD
Route status: Inherited arrangement
Next action:
Primary data centre hostingAventine Cloud / Servicesnot held
no date held NO DATE HELD
Route status: Under negotiation
Next action: Record the executed end date once signed.
Safeguards case management supportThornbury Analyticalnot held
no date held NO DATE HELD
Route status: Being transitioned to the operations suite
Next action: Confirm the provider’s intent to continue before the safeguards uplift lands.

All 18 rows in full, nothing hidden behind a filter: 13 with a recorded expiry date (aged from 2026-09-02) and 5 without, grouped and labelled at the end. transcription T1 - name, supplier, date, route status and next action are reproduced VERBATIM from the agreement register, including its own spelling; date accuracy T2 - the register is a planning snapshot maintained by the IT vendor-management function, not an extract from executed agreements.

Curated links to assessed applications · 17 of 18

AgreementLinked entityCoarse viewDay count (authoritative)
Loan servicing extended supportLicence Renewals SystemEXPIRED64 days ago
Correspondent banking connectivityPayments GatewayEXPIRED18 days ago
Endpoint management subscriptionEndpoint Management Servicethis month18 days
Statistical software licencesRegulatory Analysis Environmentthis month28 days
Levy scheme sector partner portal supportSector Reporting Workspacein 2 months89 days
Regional office network servicesRegional Office Network Gatewayin 4 months151 days
Legacy reporting warehouse licenceLegacy Reporting Warehousein 6 months210 days
Operations portal maintenanceConsents Portal - Assessmentin 9 months301 days
Revenue dealing platform licenceRevenue Collection Platformin 12 months393 days
Identity directory subscriptionIdentity and Access Directoryin 15 months485 days
Records archive storageRecords and Correspondence Archivein 21 months667 days
Payroll bureau servicesPayroll and Benefits Enginein 27 months851 days
Client portal accessibility auditApplicant Services Portalin 33 months1032 days
Capital works scheduling licenceWorks Scheduling Systemno date heldno date held
Knowledge repository hostingGuidance and Standards Repositoryno date heldno date held
Primary data centre hostingStorage Array (primary data centre)no date heldno date held
Safeguards case management supportEnforcement and Compliance Registerno date heldno date held

These links are CURATED in the data. Nothing here is auto-joined on name similarity: a name match between a register row and an entity is a guess, and a guess drawn as a join is indistinguishable from a confirmed mapping once it is on a page.

The coarse column is a display granularity, never a verdict. A row that passed its date earlier in the current month reads EXPIRED here, not "this month": the expired decision is taken from the day count on the right, and a build gate fails if the two ever disagree.

Where the agreement register and the roadmap anchors contradict each other · 2 cases

Primary data centre hosting agreement expiry — two screens, two different answers
The register holds “Primary data centre hosting” and “Data centre hosting (disaster recovery)”, with the expiry cell blank. The dc_hosting anchor holds a hard date, 2028-03-31: “Two-year notice period.”

A reader who opens the Roadmap tab sees a dated cliff. A reader who opens this tab sees “no expiry date held”. Both are in the same artefact. This page does not resolve it, because nothing in the data says which is right, or even that the anchor and the register rows describe the same commercial instrument.
To resolve: Ask the owner of “Primary data centre hosting” and “Data centre hosting (disaster recovery)” for the executed end date, then write it into the agreement register so both surfaces read one source.
Regional office network contract expiry — a 31-day gap between two dates, and no source says whether they are the same thing
The register holds Regional office network services (Ridgeline Telecom), expiring 2027-01-31 — 151 days. The network_contract anchor holds 2026-12-31: “Right of renewal must be exercised 90 days before expiry.”

These are plausibly two different instruments covering one service. That reading is ours, and it is not written anywhere: nothing on either screen, and nothing in either source, states whether they are one commercial instrument or two. So the honest answer is: unknown. Both are shown, neither is reconciled into the other, and the earlier register date is not quietly superseded by the later anchor date.
To resolve: Ask the owner of “Regional office network services” for the executed end date, then write it into the agreement register so both surfaces read one source.

Contradictions are NAMED, not resolved. Picking whichever date is more comfortable and publishing that one would make the artefact internally consistent and externally wrong.

This artefact carries agreement dates in TWO places: the register, and the dated anchors that drive the roadmap cliff markers. They are not the same source and they do not agree. The pairs compared here are DECLARED in cliffs.anchor_links, never inferred from name similarity.

How to read this agreement register · stated once, not per row

T2 asserted / draft
  • Dates cluster on month boundaries. 11 of 13 recorded dates (85%) fall on the first or last day of a month, and 4 of them on the last day of the configured fiscal year (06-30). That is the signature of dates entered at planning granularity. Treat any single date as accurate to about a month unless the executed agreement has been checked.
  • The stated period moves independently of the date on some rows. 1 rows have one without the other, computed at build time, so the field is not purely derived from the date on this data and may carry information. It is still not used as a cross-check here: a 12-month bucket cannot see most date errors, and the co-presence test says only that the two are not identical, not that either is right.
  • The route status field is populated for 17 of 18. The other 1 row is blank. Blank means not recorded, never “nothing needed”.
  • The effort field is 56% blank — never sort, rank or colour by it. Populated on only 8 of 18 rows. A sort on this column would order the agreement register by which cells someone happened to fill in. It is not rendered as a sortable or coloured dimension anywhere on this tab, and should not be added as one.
  • Hand-entry artefacts are reproduced as-is · 4 found. Found by shape, not by a list in the code: status on Levy scheme sector partner portal support has a trailing question mark - the register hedging in its own hand; counterparty on Regional office network services has leading or trailing whitespace; counterparty on Primary data centre hosting has an embedded line break; action on Safeguards case management support has a typographic character left by a paste. They are not corrected here. This tab must reconcile line by line against the source file, and a silent tidy-up is an undocumented edit to someone else’s register. They are also the clearest available evidence of how the register is maintained.
  • Only 17 of 18 agreements are linked to an entity in this model. Those links are curated in the data. The remaining 1 are not auto-joined on name similarity. Coverage is a data ask, not a derivation.
  • Free text on this tab is rendered as visible, screenshot-able text. The register’s own route status and next-action strings are reproduced verbatim. If they name individuals or commercially sensitive detail, that is a wider surface than the same strings sitting in a data file. Stated so the release owner can decide, not silently widened — and the withheld-content guard runs over this tab like every other.

No per-row confidence band and no date-shape ranking is published. There are two states on this tab, date held and date not held. A confidence score would have to be built out of the register’s own fields, and the co-presence test above is how you find out whether those fields are independent enough to carry one.

These qualifications apply to the whole file. Repeating them on every row would train the reader to skip them; stating them once, here, is the alternative. Every figure in this list is derived at build time from the register itself.

Exposure and cyber

4 COMPUTED READINGS

Where the cyber risk is

T2 asserted / draft

What this tab says, before the caveats that qualify it. Every figure below is repeated in full — with its caveats, which are where the meaning is — in the sub-tabs that follow.

Exposed and past supported life

Stated in full in · the exposure map

4 applications score at or above 4 on both exposure to untrusted networks and support lifecycle risk. Every one is touched by at least one initiative. Touched is not fixed: the plan funds work on them, which is a different claim from the risk being closed. The count is a floor — 4 entities could not be tested at all.

Monitoring, live versus planned

Stated in full in · monitoring coverage

7 log sources live and 10 planned. A planned source monitors nothing today, and the whole pack relabels it as not monitored today on every surface it appears — a roadmap entry is not a control.

Where the concentration sits

Stated in full in · the concentration table

20 of the 33 assessed applications depend on a shared platform the register names. Concentration is not a finding on its own — it is why a single failure is not a single application. And it is a floor: only 30 of the 33 carry any dependency text at all, so anything not written down is invisible to this.

What the plan does not close

Stated in full in · estate health

25% of current assessed risk is modelled to be removed by the funded plan, so 75% persists after it lands — and 85.2% of that residue sits on applications the plan does touch. It is not "unfunded risk"; it is what the plan was never going to fix.

There is no posture score here, and there will not be one. Every number on this card set already exists below with the caveat that qualifies it, and each card says where. A composite would average an exposure score against a monitoring count against a concentration ratio — three different kinds of thing — and produce one number that hides the maximum, which is the only one worth acting on. Nothing here is ranked either: the order is what an executive needs first, not what is worst.

Read from the engine's derived cyber layer and risk-reach model at build time. If a layer is absent, its card is absent — nothing here is a written headline that outlives the data behind it.

30 PLOTTED · 4 IN THE CORNER · 0 UNFUNDED THERE

The exposure map

T2 asserted / draft

A count tells you how many. This tells you whether they are a cluster or a scattering, and whether anyone is paying for them. Every application that carries both scores is placed by the two drivers the exposure count is built from; the ones that carry only one are named underneath rather than plotted. The shaded corner is that count — 4 applications at or above 4 on both. Watch what sits just outside it: those are one authored point from being in the corner, and they never appear in the number.

1122334455Exposure to Untrusted NetworksSupport Lifecycle RiskConsents Portal - Assessment — exposure 3, support lifecycle 5, criticality 5. 1 initiative funds itConsents Portal - Inspection — exposure 4, support lifecycle 5, criticality 5. 1 initiative funds itConsents Portal - Determinations — exposure 4, support lifecycle 5, criticality 5. 2 initiatives funds itLicence Renewals System — exposure 2, support lifecycle 5, criticality 5. 1 initiative funds itLevy Administration System — exposure 2, support lifecycle 4, criticality 5. 1 initiative funds itRevenue Collection Platform — exposure 2, support lifecycle 3, criticality 5. 1 initiative funds itPayments Gateway — exposure 3, support lifecycle 4, criticality 5. 2 initiatives funds itCorporate Finance Ledger — exposure 2, support lifecycle 3, criticality 5. 2 initiatives funds itPayroll and Benefits Engine — exposure 2, support lifecycle 5, criticality 5. 1 initiative funds itRegional Office Network Gateway — exposure 5, support lifecycle 4, criticality 5. 1 initiative funds itIdentity and Access Directory — exposure 3, support lifecycle 3, criticality 5. 2 initiatives funds itConsents Portal - Lodgement — exposure 3, support lifecycle 4, criticality 4. 1 initiative funds itEnforcement and Compliance Register — exposure 3, support lifecycle 3, criticality 4. 1 initiative funds itInfringement Fees Ledger — exposure 2, support lifecycle 4, criticality 4. 1 initiative funds itProcurement and Supplier Portal — exposure 4, support lifecycle 3, criticality 4. 1 initiative funds itHuman Resources Core — exposure 2, support lifecycle 3, criticality 4. 1 initiative funds itApplicant Services Portal — exposure 5, support lifecycle 4, criticality 4. 2 initiatives funds itEnterprise Data Warehouse — exposure 2, support lifecycle 4, criticality 4. 2 initiatives funds itEndpoint Management Service — exposure 3, support lifecycle 3, criticality 4. 1 initiative funds itConsents Portal - Closure — exposure 2, support lifecycle 4, criticality 3. 1 initiative funds itRegulatory Performance Platform — exposure 2, support lifecycle 3, criticality 3. 1 initiative funds itSector Reporting Workspace — exposure 3, support lifecycle 3, criticality 3. 1 initiative funds itTravel and Expense System — exposure 3, support lifecycle 3, criticality 3. 1 initiative funds itRecords and Correspondence Archive — exposure 3, support lifecycle 5, criticality 3. 1 initiative funds itExternal Collaboration Workspace — exposure 4, support lifecycle 3, criticality 3. NO initiative funds itComplaints and Review Intake — exposure 4, support lifecycle 3, criticality 3. 1 initiative funds itOpen Data Catalogue — exposure 5, support lifecycle 3, criticality 3. NO initiative funds itGuidance and Standards Repository — exposure 3, support lifecycle 4, criticality 3. 1 initiative funds itRegulatory Analysis Environment — exposure 3, support lifecycle 3, criticality 3. 1 initiative funds itExecutive Reporting Workspace — exposure 2, support lifecycle 2, criticality 2. 1 initiative funds it
Funded — at least one initiative touches itNot funded by any initiativeInside the exposed-and-unsupported cornerWithin one point of itBubble size = business criticality

Every application in that corner is touched by at least one initiative. Being touched is not being fixed — the plan funds work on them, which is a different claim from the risk being closed.

15 applications sit within one point of the corner without being counted in it: Consents Portal - Lodgement, Consents Portal - Assessment, Enforcement and Compliance Register, Payments Gateway, Sector Reporting Workspace, Procurement and Supplier Portal, Travel and Expense System, Records and Correspondence Archive, External Collaboration Workspace, Complaints and Review Intake, Open Data Catalogue, Guidance and Standards Repository, Regulatory Analysis Environment, Identity and Access Directory, Endpoint Management Service. On a five-point authored scale that is one assessor's judgement, not a real boundary, which is why the band is drawn rather than left off the picture.

3 applications cannot be placed at all — they carry no score on one or both drivers, so they are absent from the plot rather than drawn at the origin. Plotting an unrated application at zero would draw it as the safest thing in the estate: Backup and Recovery Service, Storage Array (primary data centre), Legacy Reporting Warehouse.

The panel below counts 4 untestable, this map counts 3. The difference is Consents Portal (target): the exposure count runs across every entity in the register, and this map plots only what is running today, so the recorded target state is left out — a target state is a plan, not a thing that can be exposed. Neither figure is wrong; they are counting different sets.

Both axes and the bubble size are authored scores, not measurements, and the threshold is a configured choice — so the corner is a convention, not a cliff. There is no composite here and there will not be: averaging exposure against support life would hide the maximum, and the maximum is the number that matters. There is no likelihood, no attack path and no exploitability, because the dataset carries no vulnerability or telemetry data and a path drawn without it is a picture of an assumption. Position says where an application sits on two named drivers; it says nothing about whether anyone is trying to attack it.

Plotted from the same authored driver scores the exposure count is derived from, and the quadrant is reconciled against that count at build time — if the two disagreed, this panel would fail the build rather than publish a second number.

PLAIN ENGLISH

The finding, in four readings

T1 documented

The engine's lead finding, in the order a person would say it. The panel itself sits underneath, collapsed — it is written to be correct before it is written to be quick, so it opens with its own caveats, and those are the last thing a reader needs first. It remains the authority: where it and this differ in wording, believe it.

4

applications

are rated 4 or more out of 5 on both exposure to untrusted networks and support lifecycle risk. Either alone is common; both at once is the finding.

30 of 34

could be tested

carry both scores. The other 4 are unmeasured, not safe — which is why the count above is a floor and not a total.

0

at the extreme

sit at 5 on both, and 0 are left with neither an initiative nor funding. Both are genuinely zero; the panel below states them so the sentence stays true when they are not.

2 of 4

are one product

are modules of Consents Portal — arguably one procurement decision rather than 2, which cuts both ways.

On each row of that panel the circle is Exposure to Untrusted Networks and the square is Support Lifecycle Risk, on the 0–5 scale above them. They are never added: a 5 and a 2 would total the same as a 4 and a 4, and only one of those is this finding.

Read from the same derived object the panel below renders from, so the two cannot disagree.

THE LEAD FINDING

Exposed and unsupported

T1 documented

4 entities score 4 or above on BOTH Exposure to Untrusted Networks and Support Lifecycle Risk. 0 sit at the maximum on both. 0 of them have no initiative touching them and no funding - and those two facts are one finding, not two.

Coloured by the two exposure dimensions only. The composite risk_rating is NOT used here: 3 of its drivers (Business Criticality, Resilience, Supplier Concentration) are not measures of exposure.

012345Applicant Services Portal5 / 4Regional Office Network Gateway5 / 4Consents Portal - Determinations4 / 5Consents Portal - Inspection4 / 5
Exposure to Untrusted Networks (circle)Support Lifecycle Risk (square)no initiative and no funding
4at or above 4 on both
0at the maximum on both
0no initiative and no funding
30 of 34Exposure to Untrusted Networks / Support Lifecycle Risk coverage

"No initiative" and "no funding" are ONE finding, not two. The funded flag is derived from initiative coverage - it agrees with "an initiative touches this entity" on 34 of the 34 register entities - so the two clauses are collinear and must not be read as two converging lines of evidence.

THIS COUNT IS A FLOOR. 4 of the 34 register entities carry no Exposure to Untrusted Networks and/or no Support Lifecycle Risk score at all, so they could not be tested against the threshold and are absent from the plot rather than shown to be safe: Backup and Recovery Service; Consents Portal (target); Legacy Reporting Warehouse; Storage Array (primary data centre).

2 of the 4 belong to one entity family (Consents Portal).

Monitoring and telemetry coverage

T1 documented

7 of the 17 log sources are live. 10 are PLANNED - which is labelled NOT MONITORED TODAY throughout, because a roadmap entry is not a control. 1 of the unmonitored sources map to entities in the exposed-and-unsupported set, covering 2 of those entities. 2 of the exposed set belong to one entity family (Consents Portal), and that family is on the not-monitored list.

live: 77NOT MONITORED TODAY: 1010deferred and accepted: 22
live todayplanned = NOT MONITORED TODAYgap accepted and unfunded

"Planned" is labelled NOT MONITORED TODAY throughout. A roadmap entry is not a control, and counting planned sources as coverage is the most common way a monitoring picture flatters itself.

Source with no monitoring todayStateExposed-and-unsupported entities it stands for
Consents Portalintersects the exposed setConsents Portal - Determinations; Consents Portal - Inspection
Licence Renewals SystemNOT ASSESSED - no ruleno name-prefix rule exists for this source
Payments GatewayNOT ASSESSED - no ruleno name-prefix rule exists for this source
Applicant Services PortalNOT ASSESSED - no ruleno name-prefix rule exists for this source
Regional Office Network GatewayNOT ASSESSED - no ruleno name-prefix rule exists for this source
Procurement and Supplier Portaltested, no intersection-
Records and Correspondence Archivetested, no intersection-
DatabasesNOT ASSESSED - no rulea GENERIC source label. It names no application family, so no prefix rule can be written for it - but on any reasonable reading it covers register databases, including at least one member of the exposed-and-unsupported set
Regional office network switchingNOT ASSESSED - no rulenetwork infrastructure underneath many applications, not an application family with a name prefix
Virtualisation platformNOT ASSESSED - no rulea hosting platform underneath many applications, not an application family with a name prefix
1 of the unmonitored sources map to entities in the exposed-and-unsupported set, covering 2 of those entities.

The link from a log source to register entities is a name-prefix match declared in config, not a field in either source document - T3. The two underlying lists are T1. T3 modelled / inferred

THE INTERSECTION IS A FLOOR, NOT A TOTAL. Only 3 of the 10 unmonitored sources have a name-prefix rule that can be tested against the 4 exposed-and-unsupported entities; the remaining 7 (Licence Renewals System, Payments Gateway, Applicant Services Portal, Regional Office Network Gateway, Databases, Regional office network switching, Virtualisation platform) have NO rule and were NOT assessed - they are not sources that were checked and came back clear.

2 monitoring gap(s) are recorded as accepted and unfunded. The aggregate is published; which ones they are is on the in-tenant dashboard.

Gap accepted and unfunded
Data loss prevention across collaboration storage - accepted, unfunded
External threat monitoring for country-office managed devices - accepted, unfunded

Information Security Assurance Framework (illustrative) maturity: current to post-programme

T1 documented

3 of the 10 Information Security Assurance Framework (illustrative) standards are unchanged by the programme (post == current): Asset and configuration management; Third-party and supply chain assurance; Security awareness. A further 2 move by no more than 0.25 of a point on the 0-5 scale (Response planning 2.50->2.75; Network segmentation 2.00->2.25), so 5 of 10 end the programme at or within 0.25 of a point of where they started. The lowest-scoring standard that does not move at all is Asset and configuration management at 1.75.

012345Governance and accountability2.75 -> 3.25Asset and configuration managementNO CHANGEMulti-factor authentication2.00 -> 2.50Least privilege1.50 -> 2.00Patch and vulnerability management1.75 -> 3.00Detect unusual behaviour1.50 -> 2.50Response planning2.50 -> 2.75Third-party and supply chain assuranceNO CHANGENetwork segmentation2.00 -> 2.25Security awarenessNO CHANGE
currentpost-programmedoes not move

6 of 11 change band; 4 strengthen within band

00.511.522.5Network segmentation1.0 -> 2.0Privileged access management0.0 -> 1.0Endpoint protectionNO BAND CHANGESecurity event logging0.0 -> 1.0Backup and restore assuranceNO BAND CHANGEVulnerability remediation0.0 -> 1.0Third-party access reviewNO BAND CHANGESecure development practiceNO BAND CHANGEConfiguration baselines1.0 -> 2.0Awareness and phishing simulationNO BAND CHANGEIncident response exercising0.0 -> 1.0

Ordinal band positions: 0 = Not Effective · 1 = Partially Effective · 2 = Effective.

6 of the 11 controls change effectiveness band. The other 5 do not: their label gains a qualifier while the band stays the same, which is a wording change in the source, not a measured band change. They are ringed and labelled NO BAND CHANGE for that reason.

The controls dumbbell places effectiveness labels on an ordinal axis so the pairs can be drawn. The source carries 3 bands; a qualifier suffix is not a band of its own, and the half-step it is drawn at is a drawing device (T3). Every count on this panel is computed on the RAW BAND with the suffix stripped, never on the drawn position. The labels themselves are T1. T3 modelled / inferred

11 SUB-RISKS · 7 HIGH · 7 DISPUTED

Risk register, both destinations

T1 documented

The same 11 sub-risks the panel below holds, with the two stated destinations shown side by side instead of suppressed. The engine declines to draw a single target because the registers disagree, and it is right to — but “they disagree” does not say whether the gap is Low against Medium or Low against High, and those are different arguments to walk into. Showing both, attributed, decides nothing.

IDSub-riskCurrentDestination · Operational risk registerDestination · Information security assurance packRegistersPlanned controlsHeld in
CR01Unsupported core loan servicing platformHighMediumLowdisagreecopy of presentboth
CR02Disbursement instruction integrityHighMediumLowdisagreecopy of presentboth
CR03Client data exposure through externally reachable portalsHighLowLowagreecopy of presentboth
CR04Regional office connectivity and third-party circuitsHighMediumLowdisagreecopy of presentboth
CR06Privileged access sprawlHighMediumLowdisagreecopy of presentboth
CR07Monitoring coverage of operations applicationsHighMediumLowdisagreecopy of presentboth
CR11Remote administration channels into regional office equipmentHighnot heldMediumone register onlynone recordedinformation security assurance pack
CR05Backup and recovery assuranceMediumLowMediumdisagreecopy of presentboth
CR08Supplier concentration in the operations suiteMediumMediumLowdisagreecopy of presentboth
CR09Records retention and disposalMediumLowLowagreecopy of presentboth
CR10Change control during the disbursement cutoverMediumLowLowagreecopy of presentboth
↓ expected to fall→ expected to hold↑ expected to RISEno destination held

7 of 11 rows have two registers pointing at different destinations; 1 exists in only one of the two registers; 10 of 10 carry a planned control that is a character-for-character copy of the existing one. Each of those is a property of the register entry, not of the risk.

A planned control identical to the existing one is not a plan. 10 rows here state the same string twice, which is a data-entry artefact rather than evidence that a barrier is being added — and it is why neither this panel nor the one below will draw a barrier or bowtie view from these fields.

These risks are not linked to anything else in this pack, and that is a property of the data rather than an omission here. A register row carries an id, a title, two ratings and two free-text control strings — there is no application reference, no initiative reference and no owner anywhere on it. Joining these rows to the estate by matching words in their titles would manufacture a link the register does not hold, which is the one defect this pack refuses hardest. Nothing is averaged either: three ordinal bands on an authored scale are counted and compared, never scored. Where this panel and the one below differ in wording, <b>the panel below is the authority</b> — this one adds columns, not judgements.

Read from the same derived register object the panel below renders from. Every column here is a field that already exists on the row; nothing is inferred, joined or scored.

Risk register - current rating only

T1 documented
CURRENT RATING ONLY. CURRENT RATING ONLY. No target and no residual is drawn here, because the two registers that hold this data disagree: on 7 of the 10 sub-risks held in both, the operational risk register residual and the information security assurance pack target are different ratings, and CR11 exists in the information security assurance pack but is absent from the operational risk register payload. Picking one silently would publish a decided number over an undecided one.
IDSub-riskCurrent ratingHeld in
CR01Unsupported core loan servicing platformHighboth registersregisters disagree on the target
CR02Disbursement instruction integrityHighboth registersregisters disagree on the target
CR03Client data exposure through externally reachable portalsHighboth registers
CR04Regional office connectivity and third-party circuitsHighboth registersregisters disagree on the target
CR06Privileged access sprawlHighboth registersregisters disagree on the target
CR07Monitoring coverage of operations applicationsHighboth registersregisters disagree on the target
CR11Remote administration channels into regional office equipmentHighinformation security assurance pack
CR05Backup and recovery assuranceMediumboth registersregisters disagree on the target
CR08Supplier concentration in the operations suiteMediumboth registersregisters disagree on the target
CR09Records retention and disposalMediumboth registers
CR10Change control during the disbursement cutoverMediumboth registers

10 of the 10 register rows carry an IDENTICAL existing-controls and planned-controls string (only 9 distinct values across the whole register). That is a data-entry artefact, not evidence that planned barriers exist. No barrier / bowtie view is drawn from these fields.

No barrier / bowtie view is drawn from these fields.

Concentration - a labelled table, not bars

T2 asserted / draft

KEYWORD BUCKET, NOT A FAILURE DOMAIN. "Network / connectivity" is a normalised label applied to dependency TEXT. The text underneath it mixes regional office circuits carried by third parties, internet egress for client and public channels, WAN circuits to the primary data centre, and cloud interconnect to the identity, dealing and payments services. Those are unrelated failure events: one bucket is not one thing that can fail. The sub-buckets below are a keyword split of the same text (T3) offered so the bucket is not read as a single point of failure; an entity can appear in more than one.

Most-named shared platform (keyword bucket)Entities naming it
Network / connectivity20
Shared database service6
Primary data centre6
Identity directory4
Sub-bucket of "Network / connectivity" (keyword rule, T3)EntitiesExamples
Regional office circuits3Consents Portal - Determinations; Consents Portal - Inspection; Regional Office Network Gateway
Internet / egress / VPN12Applicant Services Portal; Complaints and Review Intake; Consents Portal - Determinations
WAN / LAN / data centre4Enterprise Data Warehouse; Licence Renewals System; Regional Office Network Gateway
Cloud interconnect4Endpoint Management Service; Identity and Access Directory; Payments Gateway
not sub-classified by any rule3Consents Portal - Assessment; Consents Portal - Lodgement; Levy Administration System

5 entities match more than one sub-bucket, so this column deliberately does not sum. T3 modelled / inferred

Only 30 of the 33 assessed entities carry any dependency text at all, so every count on this table is a FLOOR, not a count. An entity absent from a bucket has not been shown to be independent of it. These are floors.

Dependency coverage, reconciled

T1 documented
RECONCILIATION STATEMENT. The two coverage percentages on this dashboard describe the SAME 108-edge dependency universe on two different axes, and are not competing measures of one thing. WHAT KIND of dependency it is: 66 of 108 = 61% typed as hardware / software / integration (the published figure). WHERE THE FAR END POINTS: 29 resolved to a modelled entity or component (26.9%), 36 bucketed to an indicative platform hub (33.3%), 1 named external party, 42 still free text (38.9%). The typed figure is the larger of the two because 36 edges are typed only by virtue of the indicative hub they were bucketed to - a hub bucket is enough to say what KIND of dependency it is, and not enough to say WHAT it points at.
resolved to a modelled entity: 2929bucketed to an indicative hub: 3636named external party: 1still free text: 4242
resolvedbucketednamed external partyfree text

"Resolved" means the far end names something we model - it does NOT mean the edge is verified. Of the 29 resolved edges, 11 are T1; 12 are T2; 6 are T3. Only 11 of the 29 entity-to-entity edges is documented in a non-draft source at all.

A fifth thing no edge can show: 3 of the 33 assessed entities carry no dependency text at all. They are never not connected - they are unrecorded.

Data corrections applied before rendering

T1 documented

Provenance re-tier

29 entity-to-entity edges were re-tiered from each edge's own recorded source string. Before: T1 29. After: T1 11, T2 12, T3 6.

New tierBecause the source saysEdges
T1documented in a non-draft source11
T2documented in a DRAFT / pre-review source (asserted, not signed off)12
T3co-mention in free-text dependency data - undirected, unvalidated4
T3target-state intent (a future decomposition, not a current dependency)2

Node identity

1 dependency endpoint reference(s) were merged onto their canonical register entity (Consents Portal - target state -> Consents Portal (target)). 0 self-loop(s) and 0 duplicate edge(s) created by the merge were dropped; pre-existing duplicates elsewhere in the graph are deliberately left alone, because removing them would move a published denominator as a side effect of an identity fix.

An unresolved endpoint is silently dropped by a force graph and renders as white space, which reads as "no dependency". A gate now fails the build if any entity-typed endpoint is outside the register.

Direction

Enterprise Data Warehouse has 7 inbound dependency edge(s) - entities that feed it - and 3 outbound edge(s) to register entities (7 to endpoints of any kind). INBOUND IS NOT BLAST RADIUS. Downstream blast radius is the outbound side, and the register-entity figure is a floor because components and named external parties are downstream too.

DirectionEndpoints
inbound (feeds the hub)Consents Portal - Assessment; Consents Portal - Inspection; Legacy Reporting Warehouse; Levy Administration System; Open Data Catalogue; Regulatory Performance Platform; Sector Reporting Workspace
outbound (the hub feeds)Executive Reporting Workspace; Network / connectivity; Open Data Catalogue; Partner statistical exchange; Regulatory Analysis Environment; internal WAN circuits; shared database service

inbound is not blast radius.

Assumptions

Assumptions and methodology

T3 modelled / inferred
IDAssumptionTierOwnerNote
A1A fiscal-year label leads with the START year: "FY25/26" is the year 1 July 2025 - 30 June 2026.T1Portfolio OfficeAn organisation on a July-June calendar would normally call this FY26. Every date derivation in the engine reads the leading year, so the label carries it.
A2Fiscal-year phasing is used as a timeline proxy where no dated schedule exists.T2Portfolio OfficePhasing is budget intent, not a delivery schedule.
A3Sequencing between initiatives is an editable assumption.T3Portfolio OfficeCoupling is derived from shared applications; running order is not.
A4A shared application's modelled risk reduction is split equally between the initiatives that touch it.T3Portfolio OfficePrevents double-counting; it is not an attribution of credit.
A5The monitoring source to application mapping is a name-prefix rule declared in config.T3Security and IdentityNot a field in any source document.
A6Change-freeze length is three months from the cutover date.T3Change Advisory BoardProposed, not agreed.
A7Every figure in this artefact is synthetic.T1Kyt ServicesThe portfolio is SHAPED like a New Zealand Crown regulator's IT estate so the engine can be judged on a familiar structure. The structure is representative; every name, rating, date and figure in it is invented, and none of it is drawn from any National Regulatory Services Agency system, register or record.

What this engine refuses to do

No risk matrix is used to RANK anything. A 5x5 matrix compresses two ordinal scales into an ordinal product, and the product is not a quantity: it cannot be summed, averaged or ranked without inventing information.

No attack path, attack graph or control-coverage heat map is drawn without vulnerability and telemetry data. Drawn from a dependency register alone, they are pictures of an assumption.

No barrier or bowtie view is drawn from existing-controls and planned-controls text fields. Identical strings across a register are a data-entry artefact, not evidence that planned barriers exist.

No target or residual rating is drawn where two sources disagree. The disagreement is published instead. Picking one silently publishes a decided number over an undecided one.

No dependency is inferred from name similarity. A co-mention is recorded as a co-mention and tiered T3.

No count is presented as complete when the underlying field is optional. Those counts are labelled FLOORS, and what could not be tested is named rather than dropped.

No empty notice-period column is drawn. Where the register records an expiry but not a notice period, the gap is stated in words: blank cells read as "no notice requirements apply", which is the opposite of what is known, and an empty column is byte-identical to a renderer that failed. Every agreement day count is therefore an upper bound on the time available.

No confidence band and no date-shape ranking is drawn on an expiry. There are two states: date held, and date not held. A field that is present if and only if the date is present is derived from it and cannot corroborate it, so the engine computes that co-presence test and publishes the result instead of a score.

No urgency colour is drawn on a row whose own register text states cover or no action beyond its recorded date, and no qualification is placed anywhere a screenshot could crop it away from the number it qualifies.

No agreement is joined to a application on name similarity, and no anchor date is reconciled into a register row. Declared links only; where two sources disagree the contradiction is named and the answer published is unknown.

No date is invented from a partial one. A bare year is not a date, and no notice period, termination window or option term is ever computed for agreements that does not record one.

7 RECORDED · NONE PATCHED

Defects this build knows it contains

T2 asserted / draft

This pack is a presentation layer over a separate engine, and the engine has defects that are visible on these pages. They are listed here rather than fixed, because the one claim this presentation layer makes is that every panel it did not write renders word for word as the engine emits it. A layer that edits the text it is meant to be faithfully re-presenting has no claim left to make.

If you find a contradiction in this artefact, check it against this list. If it is here, it is known and the reason is stated. If it is not, we would like to know — that is the more useful outcome of reading a demonstration.

Agreements · Notice terms

what you will see

States that 17 of 18 agreements are linked to an entity in this model. It is 16 — one names an entity that is not in the register, and it is printed in the Linked entity column as though it were.

Why it is still here. The engine tests that the field is a non-empty string, never that the string resolves to a register entity. It is the exact defect class the engine’s own documentation is proudest of catching.

Applications · Estate health

what you will see

States 33 applications assessed and draws 34 tiles. The domain headings sum to 34 because they include a target-state row.

Why it is still here. The Consolidation panel states the governing rule correctly — a target state is excluded from every assessed count — so the two disagree on the same tab.

Applications · Estate health

what you will see

“The remaining 75% is what persists … and 85% of that sits on applications the plan does touch.” The 85% is a percentage of a different quantity from the 75%.

Why it is still here. Two residual measures are wearing one sentence. The correct figure on the stated basis is 87%, and on the other basis the arithmetic does not close.

Plan · Budget scenario

what you will see

A headline $15,450,000 above a table whose column sums to $14,700,000. The $750,000 gap is two unmatched lines that appear nowhere on the page.

Why it is still here. The panel states that ambiguous lines are reported rather than split by rule; unmatched lines are counted but not reported, and there is no total row.

History

what you will see

The header and the artefact metadata declare v2.2; the newest row of the version history is v2.1.

Why it is still here. The release-version gate checks that an artefact declares a version, not that the declared version exists in the history the same artefact publishes.

Exposure and cyber · Monitoring

what you will see

A sentence says which monitoring gaps are accepted and unfunded is held elsewhere; the block immediately beneath it lists both by name.

Why it is still here. A withholding claim falsified by the element under it. On invented data it is a demonstration that the withholding logic does not fire; on a real estate it would be a disclosure.

Several panels

what you will see

Number and verb disagree in seven places (“1 rows have”, “a application”), and nine counts render as “2 initiative(s)” where the number is known.

Why it is still here. Cosmetic, and worth listing because a reader who spots one wonders what else was not checked.

A separate set of findings was raised against the presentation layer itself by the same review and every one of them was fixed, because that half is ours to fix. Both lists ship with the pack in full.

This panel is recorded, not computed. Every other panel in this artefact is derived at build time and moves when the data moves; this one is a written list from a review of engine v2.2 taken on 1 September 2026, and it will go stale the day the engine is fixed and nobody updates it. That is the failure mode this pack warns about everywhere else, so it is tiered as an assertion and carries its own date. The list is what a review found; it is not a claim that nothing else is wrong.

Recorded from a review of the stock engine at v2.2 on 1 September 2026. Not derived from the data, and not updated by the build.

History

Version history

T1 documented

6 releases since 2 March 2026. 1 have no contemporaneous record and say so.

VersionDateHeadlineEstablished by
v2.1 (inexact)Exposure, monitoring and circulation variantsthis-build
v2.020 Jul 2026Two-pager and print-fit gatelog | readme
v1.315 Jun 2026Value lens and trade-off stepperlog
v1.211 May 2026No source describes this releasearchiveno contemporaneous record
v1.113 Apr 2026Dependency typing addedlog | readme
v1.02 Mar 2026First IT portfolio dashboard buildlog