Happy Tuesday, Transformation Friends. Another week, another opportunity to go Beyond the Status Quo.
It’s worth saying up front that running a major federal IT transformation is genuinely hard, and the people doing it are good at their jobs. Currently, several major transformations are underway. The systems behind Old Age Security (OAS), Employment Insurance (EI), and the Global Case Management System for immigration (GCMS), are knit into legislation and policy in ways that make every change consequential, and serve millions of Canadians who can’t afford a bad rollout… Not to mention the whole HR and Pay system debacle. Oversight machinery exists for real reasons. Treasury Board submissions are meant to induce disciplined thinking. Audits surface what would otherwise stay hidden. Cost authorities create accountability.
And yet, we have ESDC’s Benefits Delivery Modernization (BDM), IRCC’s Digital Platform Modernization (DPM), and PSPC’s post-Phoenix HR and pay work all running concurrently, and the same story keeps coming back. Original commitments slip, and re-baselining gets harder to explain each time. The Auditor General writes a report warning the next programme not to repeat the mistakes of the last one (e.g. Office of the Auditor General of Canada, 2023). Inside the programmes, leaders who clearly see the trade-offs of their decisions take them, but we rarely document the rationale or decision process in a way that makes them easy for others to find or fully understand.
While working on something else, I recently came across a framework that names the trade-offs we’re being asked to take and gives us a way to defend the responsible ones. From my time doing oversight at the Treasury Board Secretariat (TBS), I saw many of these projects up close. Even a couple of years on, I keep coming back to the question of why the same pattern keeps repeating, and this framework gave me an interesting way to look at it.
This week, we’ll start by walking through that framework, then look at why one of its four boxes is the one any serious transformation has to live inside, and finally, why our governance regime structurally has difficulty supporting this. Then we’ll talk about what to do about it (yes, with kindsight, and I fully acknowledge I’m playing Monday morning quarterback here).
Grab your morning coffee, and let’s get started.
The quadrant we need most
The framework I want to use comes from a metaphor that’s been kicking around software engineering since the early 1990s. Ward Cunningham (1992) introduced “technical debt” to describe what happens when a team ships a shortcut in software design. I’m sure many of you have heard this term before, but are we using it effectively? For Cunningham, he meant that the system works in the short run, but every future change has to push through the shortcut, as interest payments compound on a loan. The shortcut is the principal. The extra effort to work around it later is the interest. The metaphor caught on partly because it gave engineers a way to talk to executives in language executives understood.
The trouble is that it’s too easy to use loosely.
“Technical debt” gets used more and more as a euphemism for “we cut corners, and the system is now hard to work with,” or, more so in my experience, “the system is old and failing.” This is a bit of a soapbox of mine, and could fill its own post sometime. In my role at Shared Services Canada, I often hear IT executives use “technical debt” as if it’s always a bad thing, when what they really mean is “aging or legacy IT,” which carries a very different context. It’s a bit like calling all financial debt bad. We intuitively know that a frivolous high-interest credit card balance is a very different beast from a 25-year mortgage.
Technical debt has flavours too.
Martin Fowler’s 2009 essay was a response to this pattern. Fowler (2009) argued that the metaphor only does useful work when we distinguish between debts taken responsibly and debts taken carelessly, and between debts we knew about at the time and debts we only see in retrospect. He laid out a 2x2 matrix across those two dimensions, which Kruchten, Nord and Ozkaya (2012) later picked up and built on.
Here’s what the 4-quadrants look like:
Inadvertent-reckless debt is what you take when you don’t know what you don’t know. The team that didn’t realize it should design for layered architecture lives here.
Inadvertent-prudent debt is what good teams notice after the fact: “Now we know how we should have done it.”
Deliberate-reckless debt is the dangerous quadrant: “We don’t have time to think about design, just ship it.”
Deliberate-prudent debt is the most mature posture available to anyone running a serious build: “We have to ship in the next quarter, so we’ll defer the proper data model and put it on the roadmap, and here’s how we’ll live with the cost in the meantime.”
For any real transformation, the no-debt plan is fictional. BDM’s original 2017 plan, costed at $1.75B with a 2030 finish line and full transformation included (Office of the Auditor General of Canada, 2023), was as fictional as any transformation plan ever is. The question that’s actually in front of a senior leader is which debts to take with eyes open. Deliberate-prudent debt, the kind that gets named, justified, and managed, is the quadrant where ambitious transformations have to live.
ESDC’s choice to migrate OAS ahead of EI is recognizable as exactly this kind of decision. The OAS systems were the oldest and at highest risk of failure (OAG, 2023). Moving them first protected continuity, at the cost of delaying the transformation work originally scheduled for EI. That’s a sequencing trade taken on purpose, with a clear reason and a plan.
Textbook deliberate-prudent debt.
Why our governance can’t hear it
Here’s where things get a little uncomfortable. Things like Treasury Board submissions, gating reviews, and audit follow-ups share a structural feature: any acknowledged trade-off becomes a finding, a risk to manage, or a deficiency. There is no part of the template for “we’re taking this debt on purpose because the alternative is worse.” The AG’s critique of BDM’s “inflexible funding approach” (OAG, 2023) is exactly this dynamic. Gated tranches require the next tranche to be justified by the previous one’s claimed success, leaving no room to say “the prudent debt we took on phase one needs to be settled now, before we go further.”
Two theories help explain why this dysfunction is tough to crack. The first comes from Nils Brunsson, whose work on organizational hypocrisy (Brunsson, 2002) argues that when an organization faces incompatible external demands, the functional response is decoupling: talk, decision, and action are separated. Applying this to our context, the public service is asked to deliver an ambitious transformation while demonstrating no compromise, no risk, and no debt, all at the same time. Those demands cannot both be satisfied. So the formal record denies the trade-off (talk), the actual programme takes it (action), and the retrospective renames it (talk again). The institution is functioning as designed.
The second comes from Christopher Hood (2011), who argues that public-sector decision-making is strongly influenced by a blame-avoidance bias. The political asymmetry between blame and credit means most senior moves are shaped by “how do I avoid being blamed” before “how do I succeed.” Phoenix is the canonical example, of course. The 2018 OAG report found that the executives who briefed the Deputy Minister on Phoenix’s readiness emphasized adherence to budget and schedule and omitted critical concerns about testing and unresolved defects (Office of the Auditor General of Canada, 2018). These were people responding rationally to asymmetric incentives. Naming the debt openly was a free gift to future critics, with no offsetting upside if the bet paid off.
The two theories stack. Brunsson explains why the institution demands decoupling. Hood explains why individual leaders rationally provide it. The result is the pattern we see across BDM, DPM, and the post-Phoenix HR and pay work: debt taken and disguised, debt refused that should have been taken, debt buried with no documentation of why. The AG’s explicit warning to BDM that ongoing pressure could lead the programme to scale back transformation or take shortcuts the way Phoenix did (OAG, 2023) is the OAG telling the programme it can see the dynamic forming again.
The translation
Here’s the kindsight part: Treasury Board and the central agencies should change how they frame oversight so that prudent debt has somewhere to live in the formal record, or even stronger perhaps, obligies it be documented and followed.
I’d like to propose that a translation of language is needed, and I see three pieces to it.
1. Speak the language oversight already accepts
The substance of “we are taking this debt on purpose” maps cleanly onto vocabulary the system already understands. A deferred technical decision becomes a risk register entry with explicit trigger conditions for revisiting. A phasing choice becomes a sequencing decision tied to a specific future review gate. Partial scope becomes MVP or stabilize-before-transform, costed at the level of detail the system requires. This changes the vocabulary, but the underlying decision is identical to what the technical-debt literature would call deliberate-prudent debt. IRCC’s DPM did this when it named Phase 1 as a stabilization phase aimed at reducing accumulated technical debt in the legacy, and structured Phase 3 as iterative tranches that release capabilities as they’re ready.
Likewise, PSPC’s $135M Budget 2024 allocation, framed as “testing and design” (PSPC, 2024) and deliberately stopping short of a committed end-state build, does the same job at the front end of a programme: refusing to commit to a fixed end-state until learning has happened, in language oversight can receive.
2. Keep an internal record that survives the transition
This is the part that protects future leaders from inheriting decisions they cannot reconstruct. Inside the programme, maintain something like a debt register that lists each deferred item, the rationale at the time the decision was made, the conditions that would trigger revisiting it, and the cost of leaving it unresolved. Pair this with architecture decision records, which capture what alternatives were considered and why the chosen option was selected.
Go further and tag each entry to the specific TB submission paragraph or gate review it relates to, so the parallel record and the formal record can be read together. When mandates change or senior leaders rotate out, brief the incoming team on the debt register first, before the formal record.
In general: any decision-making system that requires public denial of trade-offs needs an internal record to keep the trade-offs survivable.
3. Hold the line between translation and cover
Translation works only if it stops short of “air cover.” Its purpose is to name the trade-off in a form that oversight can receive, and to leave a real record for the people who come next. A submission that translates “we will take three months of schedule debt to migrate the highest-risk legacy first” into “we are sequencing the highest-risk migration ahead of full transformation to protect benefit continuity” is doing translation. A submission that omits the trade-off entirely and describes only the nominal end-state is doing cover.
The first description is recognizable in how ESDC handled OAS sequencing, where the trade-off was named in the formal record. The second is closer to what the 2018 audit found PSPC had done with Phoenix, where critical readiness concerns were omitted from briefings to leadership.
Here’s an honesty test for any leader accountable for a TB submission: would a successor, reading both the formal record and the internal debt register five years from now, recognize the same trade-off in both? When the formal record and the internal record line up, that’s translation. When they diverge in substance, that’s cover.
Wrap up
I believe one reason why our largest transformations like BDM, DPM, and the post-Phoenix work, keep producing the same story arc is that the culture of oversight they’re given makes it difficult for prudent trade-offs to be documented honestly. They either get refused, disguised, or buried for the next person to discover. Changing the narrative might be a way to overcome this: speaking deliberate-prudent debt in language the system can receive, and building the parallel record that lets today’s prudent choice still look prudent to the people who inherit it.
Let’s end with some self-reflection:
In your current or most recent transformation, what debts did the formal plan claim were not being taken, that the actual delivery has had to take?
Who, if anyone, in your organization knows the real rationale for the trade-offs embedded in your major IT systems, and what happens to that knowledge when they leave or when the mandate changes?
What would change in your next Treasury Board submission if you committed to translating the prudent debt you intend to take in a form that leaves it visible to your successor?
Until next time, stay curious and I’ll see you Beyond the Status Quo.
References
Brunsson, N. (2002) The Organization of Hypocrisy: Talk, Decisions and Actions in Organizations. 2nd edn. Copenhagen: Copenhagen Business School Press.
Cunningham, W. (1992) ‘The WyCash Portfolio Management System’, ACM SIGPLAN OOPS Messenger, 4(2), pp. 29–30.
Fowler, M. (2009) ‘Technical Debt Quadrant’, martinfowler.com, 14 October. Available at: https://martinfowler.com/bliki/TechnicalDebtQuadrant.html.
Hood, C. (2011) The Blame Game: Spin, Bureaucracy, and Self-Preservation in Government. Princeton: Princeton University Press.
Immigration, Refugees and Citizenship Canada (2023) IRCC Minister Transition Binder 2023: Digital Platform Modernization and IT Upgrades. Ottawa: IRCC.
Kruchten, P., Nord, R.L. and Ozkaya, I. (2012) ‘Technical Debt: From Metaphor to Theory and Practice’, IEEE Software, 29(6), pp. 18–21.
Office of the Auditor General of Canada (2018) 2018 Spring Reports of the Auditor General of Canada, Report 1: Building and Implementing the Phoenix Pay System. Ottawa: OAG.
Office of the Auditor General of Canada (2023) 2023 Reports of the Auditor General of Canada, Report 8: The Benefits Delivery Modernization Programme. Ottawa: OAG.
Public Services and Procurement Canada (2024) The Government of Canada provides update on progress toward a new human resources and pay solution to replace the Phoenix pay system and its human resources systems. News release, 9 July. Ottawa: PSPC. Available at: https://www.canada.ca/en/public-services-procurement/news/2024/07/the-government-of-canada-provides-update-on-progress-toward-a-new-human-resources-and-pay-solution-to-replace-the-phoenix-pay-system-and-its-human-.html



