Government modernization post-mortems: what the audit reports keep repeating

Auditor-general reports from three continents keep finding the same five structural defects in failed modernization programs. The findings are public, the pattern is clear, and the next RFP usually ignores both.

Government modernization post-mortems are public documents. They get commissioned after an executive sponsor leaves, after a legislative committee asks questions, or after a payment goes wrong badly enough that it becomes a news cycle. The auditor-general or the national audit office publishes, the report circulates, and then the next program repeats the same structural mistakes under a new name. The pattern is not a mystery. The pattern is an industry that treats procurement incentives as someone else's department.

What the reports keep finding

Read enough of these documents across enough jurisdictions and the findings cluster into the same five or six defects. Not technical defects — structural ones. The technology rarely gets more than a paragraph in the executive summary. What fills the pages is governance, scope management, vendor accountability, and testing regimes that reported green the entire time something was going wrong.

  • Scope was never fixed. The program started with a requirements document that was either incomplete or treated as a living artifact. Both produce the same outcome: the vendor's original estimate and the final cost share nothing but a project name. The Queensland Health payroll replacement — documented at length in the Queensland Auditor-General's 2010 and 2012 reports — moved from an estimated A$6.19 million to over A$1.2 billion in total costs when corrections and remediation were included. The requirements were not unknown; they were undiscovered at the time the contract was signed and discovered at the rate the vendor could bill for them.
  • Testing validated artifacts, not behavior. The conversion or build was demonstrated against prepared scenarios. The prepared scenarios matched what the vendor understood. What the vendor did not understand — edge cases in payroll calculations, fiscal-year boundary handling, legislative rate changes applied mid-period — surfaced after cutover, when the system was the only system. The Queensland case produced incorrect pay for tens of thousands of public servants for years after go-live. The test suite had been green the entire time.
  • No defined exit condition for acceptance. When the acceptance criteria are vague enough, the program cannot fail on paper even when it has failed in practice. The UK National Audit Office's reports on Universal Credit — particularly the 2013, 2014, and 2018 publications — document a program that repeatedly redefined "on track" to match whatever had been delivered so far. This is the descope spiral wearing a governance badge: the definition of done contracts until it fits around whatever shipped.
  • The vendor's incentive pointed away from finishing. Time-and-materials contracts, or fixed-price contracts with change-order mechanisms that effectively made them T&M, meant the vendor's revenue was a function of duration. Finishing fast meant billing less. Discovering a new requirement meant billing more. The audit reports note this without usually naming it as the root cause, but it is present in the cost curves of nearly every report that publishes them.
  • Parallel run was either absent or decorative. In programs that ran old and new systems side-by-side, the comparison was either manual, tolerance-based, or staffed by people who did not have the authority to halt cutover when the results disagreed. A parallel run without a defined, enforceable halt condition is not a safety net — it is a checkbox that protects the project plan from being interrupted by its own evidence.

The same report written five years later

What makes these post-mortems frustrating to read in sequence is not the individual findings. It is the repetition. The US Government Accountability Office has published reports on federal IT modernization failures for decades. The findings from the IRS modernization program in the early 2000s read almost identically to findings from programs ten and fifteen years later: unclear requirements, testing that did not cover production conditions, vendor lock-in through proprietary tooling, and cost overruns that became politically impossible to cancel because of sunk-cost pressure.

The pattern repeats because the structure that produces it has not changed. Procurement still rewards the lowest bid on a loosely specified scope. Vendors still build their margin into the change orders, not the base contract. Testing still gets treated as a gate the vendor passes rather than an ongoing proof the buyer owns. And the people who write the next RFP are usually not the people who read the last post-mortem — or if they are, they lack the procurement authority to act on what they read.

What a post-mortem cannot tell you

Audit reports are backward-looking by design. They document what went wrong after the budget is spent. They are useful as a catalog of structural risks — a checklist of things that have been proven to fail in exactly this way before. What they cannot do is tell you whether a specific vendor on a specific proposal is going to repeat the pattern, because the pattern is not vendor-specific. It is contract-specific and incentive-specific.

A vendor who has delivered successfully under a contract that aligned their incentives with finishing can fail catastrophically under a contract that rewards duration. A vendor who failed on a T&M engagement with open-ended scope can succeed on a fixed-deliverable contract with byte-exact acceptance criteria. The vendor's track record matters less than the structure of the deal in front of you — and the post-mortems, if you read them carefully, are making exactly that point.

The one thing the reports agree on

Across jurisdictions, across decades, across wildly different program sizes, every one of these reports lands in the same place: the programs that failed expensively all lacked a concrete, testable, enforceable definition of done that the buyer controlled and could verify independently. The programs did not fail because mainframe modernization is impossible. They failed because nobody with budget authority required proof — mechanical, reproducible, deterministic proof — that the work was correct before accepting it as complete. That requirement is cheap to add to a contract. Its absence is the most expensive line item that never appears on a statement of work.

Proof beats promises

Torsova modernizes mainframes the only way that should be legal: deterministic translation (no AI in the conversion path), byte-for-byte parity against your real data, and a reproducible demo you can run before you sign anything.

Ask for the proof demo