Swiss Federal Audit Office SFAO

Key projects of the Federal Administration - summary report on the audits of the Swiss Federal Audit Office

2026 CH2026keyProjectsFederalAdmin — Categorised against INTOSAI ICS (GuidICS)
SCALE
  • 24 audit reports from 2024 and 2025 were analysed, covering the federal administration's key ICT projects.
  • The projects considered represent an investment volume of 3 to 5 billion francs.
  • Five significant shortcomings named in a first synthesis ten years earlier are still present.
COMPLIANCE
  • A federal information security act sets a binding framework for secure information handling and cyber resilience, and whole-of-government ICT minimum standards have been repeatedly revised since.
  • Federal public procurement law governs how these projects buy, and shapes the tension between fixed-scope contracting and iterative delivery.
  • The audit office works to its own published guide for programme and project audits, whose six themes give this report its structure.
ECONOMY
  • The projects examined carry an investment volume of 3 to 5 billion francs.
  • Projects that set out to cut IT operating costs are finding those costs rise rather than fall, as technology prices and security requirements climb during the project.
  • One renewal project dropped its target of cutting annual operating costs by 15 to 20 percent and now aims only to hold them at the current level.
EFFICIENCY
  • Half-yearly reporting to the general secretaries' conference and to parliamentary oversight arrives three months after the reference date.
  • Overall planning is often rudimentary: milestones are not planned through to the end of the project and the critical path is not consistently maintained.
  • Cost estimates rest on rough assumptions and omit whole items, such as technical migration and the optimisation that follows it.
EFFECTIVENESS
  • Five of the shortcomings identified ten years earlier persist, because improvements are not embedded in the parent organisation or carried into follow-up projects.
  • Indicators and methods for measuring benefits are largely absent, so the cost-effectiveness of projects cannot be demonstrated.
  • Only about 10 percent of the recommendations address the framework conditions that projects cannot put right by themselves.
1. Benefits are promised in ambitious terms and then never measured Goal-setting Benefits management

Project mandates 'formulate mostly ambitious intentions regarding the planned benefit, but leave wide scope for interpretation in the later measurement of effect' (p.17). One digital-agriculture programme announces 'added value for our partners' without defining quantified targets for any of the actors involved; a health-digitalisation programme sets out ambitious aims with measurable objectives to be worked out only during the implementation phase. A Goal-setting failure that removes any Benefit control: where the promise is unquantified, achievement cannot be shown, and the money cannot be tied to what it bought.

  • Function: Strategy
  • Value: Finance
  • Stakeholders: Management
  • Quality: Clear objectives and goal-setting Cost control and value for money
2. A cost-reduction target was abandoned mid-project and replaced by holding costs level Benefits management Monitoring

Several projects aim to improve cost-effectiveness by lowering IT operating costs, but the audits show those costs 'tend to rise rather than fall', partly because the technologies become more expensive and partly because availability and security requirements grow during the project (p.17). The migration-system renewal 'moved away from the original goal of reducing annual operating costs by 15-20 percent in the longer term. These are no longer to be reduced; the current level is to be held.' The original benefit promise is not kept and the economic case for the project remains unclear.

  • Function: Finance
  • Value: Finance
  • Quality: Cost control and value for money Clear objectives and goal-setting
3. Planning stops short of the end, and risk management records risks without testing the remedies Design Monitoring

'Several projects plan only rudimentarily and so create no adequate basis for effective steering. They do not map central dependencies and necessary preconditions, and do not consistently maintain the time-determining sequence of project tasks (critical path)' (p.20). Risk and quality management exists everywhere, but 'an effective measurement of the effect of risk-reducing measures is rarely implemented', leaving gaps in risk catalogues, no costing of mitigations, and an external quality assurance that is not independent. Design and Monitoring that satisfy the form of project governance without producing anything a decision-maker can steer by.

  • Function: Project methodology
  • Quality: Sound risk management Reliable, integrated information base
4. Cost estimates rest on rough assumptions and leave whole items out Design Reporting

Initial cost figures 'are based on first rough estimates, which either follow previous IT investment costs or simplified estimating models'. Estimates are also incomplete: 'financial outlays for the technical migration and the subsequent optimisation are missing, for example. The cost drivers are not known across the entire project duration' (p.21). The audit office has judged the cost estimate invalid in several audits and recommended a fresh assessment; on two projects the costs rose drastically once replanned. A Design weakness with a direct Finance consequence, since the figure that authorises the project is not the figure the project will cost.

  • Function: Finance
  • Value: Finance
  • Quality: Cost control and value for money Reliable, integrated information base
5. Reporting to oversight arrives three months late, so it records rather than steers Reporting

The half-yearly reporting to the general secretaries' conference and to parliamentary oversight 'is available three months after the respective reference date and thus permits no forward-looking steering, but only a retrospective determination of the project status. As a result, timely information is lacking in order to be able to take short-term corrective measures' (p.20). A Reporting line that satisfies its obligation while failing its purpose: the oversight bodies learn what happened, never in time to change it.

  • Function: Governance
  • Stakeholders: Lawmaker, Oversight
  • Quality: Functioning oversight and governance Reliable, integrated information base
6. No portfolio management above the individual projects, so dependencies and people are allocated blind Coordination

Most audited projects are delayed by resource commitments that are not honoured, by missing resources generally, or by dependencies on other projects. The audit office identifies the absence of portfolio management across offices and programmes as a main cause: with it, 'dependencies, resources and risks between the projects could be actively managed and steered at strategic and operational level' (p.14). One federal office keeps a list of projects that shows neither resource use nor dependencies. Some units are waiting for a central solution, and the audit office notes plainly that its absence is no justification for inaction. A Coordination gap one level above the projects, where no single project can close it.

  • Function: Planning
  • Stakeholders: Management
  • Quality: Avoidance of duplication and fragmentation Adequate resources and competences
7. Thin supplier markets leave the state with little leverage once the contract is awarded Business continuity Coordination

Procurement repeatedly causes delays and additional costs, often because it takes place 'in markets with few suppliers, proprietary technologies and high user requirements', producing a pronounced supplier dependence: 'after the award, the federal government has only limited influence over national or international suppliers' (p.15). Individual measures exist - withholding payment until defects are fixed, examining a change of supplier - but effective options and worked-out scenarios to strengthen the state's negotiating position are missing. On a security radio system, stalled negotiations over key components strained the supplier relationship and raised the risk that operation could not be assured; if that system fails, emergency and rescue services lose reliable communications. Continuity exposed through an Asset the state cannot readily replace.

  • Function: Product/service purchase
  • Value: Assets
  • Stakeholders: Supplier
  • Quality: Reliability and availability Sound risk management
8. Agile working is adopted as a promise, without the target picture or the people planning it needs Training Goal-setting

Agile methods 'are regarded in many projects as promising in themselves'. In practice they demand a high level of method competence that the administrative units usually have to build first, a process that 'as a rule takes three to four years'; where short-term performance gains are expected at the same time, the result is unrealistic expectations, delays and additional effort (p.19). The investment in know-how only holds if the way of working continues after the project closes - if the parent organisation does not support that, the progress is lost. The argument that the law prevents the cross-cutting collaboration agile methods need 'often turns out to be an excuse'; two federal offices lack both a binding target picture and any medium- or long-term personnel development strategy for the agile direction they have chosen. Training and Goal-setting missing behind a method adopted on faith.

  • Function: Human resources
  • Value: Human capital
  • Stakeholders: Staff
  • Quality: Adequate resources and competences Clear objectives and goal-setting
9. Without binding architecture specifications, standardisation and reuse never arrive Design Data integration

'Missing or non-binding architecture specifications frequently mean that economies of scale, standardisation or integration cannot be realised. This leads to inefficient solutions and additional costs' (p.17). Several projects lack essential architecture results such as the target data architecture or the transition architectures describing how to get from the current state to it, 'which can lead to a lack of interoperability - a central point precisely in federal projects, where data have to be exchanged' (p.18). On a project separating mission-critical from non-critical military ICT, savings depend on decommissioning applications, but the enterprise architecture needed to judge current and future need 'is not yet sufficiently established'. A Design gap at the level above the project, which makes Data integration between projects a matter of chance.

  • Function: IT
  • Value: Assets
  • Quality: Interoperability that spares users redundant effort Avoidance of duplication and fragmentation
10. Testing is underestimated, so defects surface late and cost more to fix Testing

'The projects sometimes underestimate the importance of comprehensive testing, with the result that errors are recognised late and additional effort, delays or quality problems can arise in later operation' (p.21). In the migration-system renewal the test coverage for individual critical functionalities was inadequate and several relevant errors were identified only at a late project stage; in other projects the test concept does not adequately cover the end-to-end view. A Testing gap whose cost is paid after go-live, by the operating organisation rather than the project.

  • Function: Project methodology
  • Stakeholders: Operator
  • Quality: Reliability and availability Streamlined, standardized processes
Control focus
ICS phaseControl functionCases
Initial phaseGoal-setting1. Benefits are promised in ambitious terms and then never measured<br/>8. Agile working is adopted as a promise, without the target picture or the people planning it needs
Design3. Planning stops short of the end, and risk management records risks without testing the remedies<br/>4. Cost estimates rest on rough assumptions and leave whole items out<br/>9. Without binding architecture specifications, standardisation and reuse never arrive
Training8. Agile working is adopted as a promise, without the target picture or the people planning it needs
Completion of processBenefits management1. Benefits are promised in ambitious terms and then never measured<br/>2. A cost-reduction target was abandoned mid-project and replaced by holding costs level
Work processesMonitoring2. A cost-reduction target was abandoned mid-project and replaced by holding costs level<br/>3. Planning stops short of the end, and risk management records risks without testing the remedies
Testing10. Testing is underestimated, so defects surface late and cost more to fix
Functions applied to all stagesReporting4. Cost estimates rest on rough assumptions and leave whole items out<br/>5. Reporting to oversight arrives three months late, so it records rather than steers
Coordination6. No portfolio management above the individual projects, so dependencies and people are allocated blind<br/>7. Thin supplier markets leave the state with little leverage once the contract is awarded
Organic elements of a processBusiness continuity7. Thin supplier markets leave the state with little leverage once the contract is awarded
Data managementData integration9. Without binding architecture specifications, standardisation and reuse never arrive
This page is part of CUBE, a knowledge-sharing initiative of the EUROSAI IT Working Group. Its purpose is to make what supreme audit institutions find easier to search, compare and reuse — by auditors, and by the wider public who rarely reach these reports in their original form. It presents an analysis prepared, with AI assistance, by Paweł Banaś (NIK — Najwyższa Izba Kontroli, Poland) on the basis of the publicly available report of Swiss Federal Audit Office, categorised against the internal-control terminology of INTOSAI's Guidance on Auditing Internal Control (ICS), drafted by the Internal Control Standards Subcommittee, which NIK (Poland) chairs. The categorisation and the case selection are ours, not the audit institution's, and so is any error in them. Readers are warmly encouraged to go to the original report, linked above; this page is a way in, never a substitute. Underlying data.