<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<dokAAPp xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:noNamespaceSchemaLocation="../../../../../../prj/bin/GuidICS/dokAAPp.xsd">
    <author>
        <individual>
            <ind firstName="Paweł" ini="pb" org="NIK" role="drafting coordination" surName="Banaś"/>
        </individual>
        <organization>
            <org kraj="Switzerland" nm="Swiss Federal Audit Office" skr="SFAO" www="www.efk.admin.ch"/>
        </organization>
    </author>
    <about caseNumber="10" file="keyProjectsFederalAdmin" folder="C:\pb\Algorytm\SAI_robo\CH\2026\keyProjectsFederalAdmin" id="CH2026keyProjectsFederalAdmin" issueYear="2026" waga="10">
        <tyt>
            <tx file="keyProjectsFederalAdmin.pdf" l="en" nm="Key projects of the Federal Administration - summary report on the audits of the Swiss Federal Audit Office" typDok="summary"/>
            <tx file="keyProjectsFederalAdmin_DE.pdf" l="de" nm="Schlüsselprojekte der Bundesverwaltung - Synthesebericht zu den Prüfungen der Eidgenössischen Finanzkontrolle" typDok="original_document"/>
        </tyt>
        <portfolio>
            <pfl zn="measurementOfProjectSuccess"/>
        </portfolio>
        <ver put="202609181636" stage="final"/>
    </about>
    <part id="lead">
        <tyt>
            <tx l="en" nm="The projects change, the weaknesses do not"/>
        </tyt>
        <narrative>
            <narr l="en">
                <ak nr="1">Ten years after a first synthesis of its work on the federal administration's largest ICT projects, the audit office looked again and found the same five shortcomings in place; the cases below set out what has not moved. Benefits are promised in ambitious terms and then never measured, so no project can show what its money bought - one renewal quietly abandoned its cost-reduction target and now aims only to hold costs level. Planning stops short of the project's end, risk management records risks without testing whether the measures against them work, cost estimates leave out whole items such as migration, and testing is underestimated until defects surface late. What reaches the oversight bodies arrives three months after the fact, too late to steer anything. Above the individual projects nobody manages the portfolio, so dependencies and scarce people are allocated blind; alongside them, missing architecture specifications block the standardisation and reuse the projects were meant to deliver, and procurement in thin supplier markets leaves the state with little leverage once a contract is awarded. Agile working is adopted as a promise rather than a capability, without the target picture or the personnel planning it needs. And at the end the move into live operation is under-prepared, with the optimisations that were promised pushed into operations or into the next project.</ak>
            </narr>
        </narrative>
    </part>
    <part id="background" v="01">
        <tyt>
            <tx l="en" nm="Background"/>
        </tyt>
        <part id="scale">
            <tyt>
                <tx l="en" nm="Scale"/>
            </tyt>
            <narrative>
                <narr l="en">
                    <ak tp="li">24 audit reports from 2024 and 2025 were analysed, covering the federal administration's key ICT projects.</ak>
                    <ak tp="li">The projects considered represent an investment volume of 3 to 5 billion francs.</ak>
                    <ak tp="li">Five significant shortcomings named in a first synthesis ten years earlier are still present.</ak>
                </narr>
            </narrative>
        </part>
        <part id="compliance">
            <tyt>
                <tx l="en" nm="Compliance"/>
            </tyt>
            <narrative>
                <narr l="en">
                    <ak tp="li">A federal information security act sets a binding framework for secure information handling and cyber resilience, and whole-of-government ICT minimum standards have been repeatedly revised since.</ak>
                    <ak tp="li">Federal public procurement law governs how these projects buy, and shapes the tension between fixed-scope contracting and iterative delivery.</ak>
                    <ak tp="li">The audit office works to its own published guide for programme and project audits, whose six themes give this report its structure.</ak>
                </narr>
            </narrative>
        </part>
        <part id="perfromance">
            <tyt>
                <tx l="en" nm="Performance"/>
            </tyt>
            <part id="economy">
                <tyt>
                    <tx l="en" nm="Economy"/>
                </tyt>
                <narrative>
                    <narr l="en">
                        <ak tp="li">The projects examined carry an investment volume of 3 to 5 billion francs.</ak>
                        <ak tp="li">Projects that set out to cut IT operating costs are finding those costs rise rather than fall, as technology prices and security requirements climb during the project.</ak>
                        <ak tp="li">One renewal project dropped its target of cutting annual operating costs by 15 to 20 percent and now aims only to hold them at the current level.</ak>
                    </narr>
                </narrative>
            </part>
            <part id="efficiency">
                <tyt>
                    <tx l="en" nm="Efficiency"/>
                </tyt>
                <narrative>
                    <narr l="en">
                        <ak tp="li">Half-yearly reporting to the general secretaries' conference and to parliamentary oversight arrives three months after the reference date.</ak>
                        <ak tp="li">Overall planning is often rudimentary: milestones are not planned through to the end of the project and the critical path is not consistently maintained.</ak>
                        <ak tp="li">Cost estimates rest on rough assumptions and omit whole items, such as technical migration and the optimisation that follows it.</ak>
                    </narr>
                </narrative>
            </part>
            <part id="effectiveness">
                <tyt>
                    <tx l="en" nm="Effectiveness"/>
                </tyt>
                <narrative>
                    <narr l="en">
                        <ak tp="li">Five of the shortcomings identified ten years earlier persist, because improvements are not embedded in the parent organisation or carried into follow-up projects.</ak>
                        <ak tp="li">Indicators and methods for measuring benefits are largely absent, so the cost-effectiveness of projects cannot be demonstrated.</ak>
                        <ak tp="li">Only about 10 percent of the recommendations address the framework conditions that projects cannot put right by themselves.</ak>
                    </narr>
                </narrative>
            </part>
        </part>
    </part>
    <part id="cases" v="01">
        <tyt>
            <tx l="en" nm="Cases"/>
        </tyt>
        <ctsy>
            <gr gn="area">
                <cts id="digitalisation"/>
                <cts id="computerisation"/>
                <cts id="public-administration"/>
                <cts id="public-procurement"/>
            </gr>
            <gr gn="ins">
                <cts id="central-government"/>
                <cts id="ministry"/>
                <cts id="government-agency"/>
                <cts id="federated-entity"/>
                <cts id="private-company"/>
            </gr>
            <gr gn="control">
                <cts id="goalsetting"/>
                <cts id="benefit"/>
                <cts id="design"/>
                <cts id="monitoring"/>
                <cts id="reporting"/>
                <cts id="coordination"/>
                <cts id="continuity"/>
                <cts id="handover"/>
                <cts id="process_optimization"/>
                <cts id="training"/>
                <cts id="dataIntegration"/>
                <cts id="testing"/>
            </gr>
            <gr gn="value">
                <cts id="finance"/>
                <cts id="asset"/>
                <cts id="human_capital"/>
            </gr>
            <gr gn="fun">
                <cts id="strategy"/>
                <cts id="projectMethodology"/>
                <cts id="finance"/>
                <cts id="governance"/>
                <cts id="planning"/>
                <cts id="productServicePurchase"/>
                <cts id="productServiceDelivery"/>
                <cts id="humanResources"/>
                <cts id="IT"/>
            </gr>
            <gr gn="quality">
                <cts id="clearObjectives"/>
                <cts id="costControlValueForMoney"/>
                <cts id="soundRiskManagement"/>
                <cts id="reliableInformationBase"/>
                <cts id="functioningOversight"/>
                <cts id="avoidanceOfDuplication"/>
                <cts id="adequateResourcesCompetences"/>
                <cts id="reliabilityAvailability"/>
                <cts id="streamlinedProcesses"/>
                <cts id="adequatelyStaffedWorkforce"/>
                <cts id="interoperabilityForUsers"/>
            </gr>
            <gr gn="sta">
                <cts id="lawmaker"/>
                <cts id="oversight-role"/>
                <cts id="management"/>
                <cts id="supplier"/>
                <cts id="operator"/>
                <cts id="staff"/>
            </gr>
        </ctsy>
        <part id="benefitsPromisedAmbitiousTerms">
            <tyt>
                <tx l="en" nm="Benefits are promised in ambitious terms and then never measured"/>
            </tyt>
            <narrative>
                <narr l="en">
                    <ak nr="2" ref="draft draft" tp="xm" zn="CH2026keyProjectsFederalAdmin">Project mandates 'formulate mostly ambitious intentions regarding the planned benefit, but leave wide scope for interpretation in the later measurement of effect' (p.17). One digital-agriculture programme announces 'added value for our partners' without defining quantified targets for any of the actors involved; a health-digitalisation programme sets out ambitious aims with measurable objectives to be worked out only during the implementation phase. A Goal-setting failure that removes any Benefit control: where the promise is unquantified, achievement cannot be shown, and the money cannot be tied to what it bought.</ak>
                </narr>
            </narrative>
            <ctsy>
                <gr gn="control">
                    <cts id="goalsetting"/>
                    <cts id="benefit"/>
                </gr>
                <gr gn="value">
                    <cts id="finance"/>
                </gr>
                <gr gn="fun">
                    <cts id="strategy"/>
                </gr>
                <gr gn="quality">
                    <cts id="clearObjectives"/>
                    <cts id="costControlValueForMoney"/>
                </gr>
                <gr gn="sta">
                    <cts id="management"/>
                </gr>
            </ctsy>
        </part>
        <part id="costReductionTargetAbandoned">
            <tyt>
                <tx l="en" nm="A cost-reduction target was abandoned mid-project and replaced by holding costs level"/>
            </tyt>
            <narrative>
                <narr l="en">
                    <ak nr="3" ref="draft draft" tp="xm" zn="CH2026keyProjectsFederalAdmin">Several projects aim to improve cost-effectiveness by lowering IT operating costs, but the audits show those costs 'tend to rise rather than fall', partly because the technologies become more expensive and partly because availability and security requirements grow during the project (p.17). The migration-system renewal 'moved away from the original goal of reducing annual operating costs by 15-20 percent in the longer term. These are no longer to be reduced; the current level is to be held.' The original benefit promise is not kept and the economic case for the project remains unclear.</ak>
                </narr>
            </narrative>
            <ctsy>
                <gr gn="control">
                    <cts id="benefit"/>
                    <cts id="monitoring"/>
                </gr>
                <gr gn="value">
                    <cts id="finance"/>
                </gr>
                <gr gn="fun">
                    <cts id="finance"/>
                </gr>
                <gr gn="quality">
                    <cts id="costControlValueForMoney"/>
                    <cts id="clearObjectives"/>
                </gr>
            </ctsy>
        </part>
        <part id="planningStopsShortEnd">
            <tyt>
                <tx l="en" nm="Planning stops short of the end, and risk management records risks without testing the remedies"/>
            </tyt>
            <narrative>
                <narr l="en">
                    <ak nr="4" ref="draft draft" tp="xm" zn="CH2026keyProjectsFederalAdmin">'Several projects plan only rudimentarily and so create no adequate basis for effective steering. They do not map central dependencies and necessary preconditions, and do not consistently maintain the time-determining sequence of project tasks (critical path)' (p.20). Risk and quality management exists everywhere, but 'an effective measurement of the effect of risk-reducing measures is rarely implemented', leaving gaps in risk catalogues, no costing of mitigations, and an external quality assurance that is not independent. Design and Monitoring that satisfy the form of project governance without producing anything a decision-maker can steer by.</ak>
                </narr>
            </narrative>
            <ctsy>
                <gr gn="control">
                    <cts id="design"/>
                    <cts id="monitoring"/>
                </gr>
                <gr gn="fun">
                    <cts id="projectMethodology"/>
                </gr>
                <gr gn="quality">
                    <cts id="soundRiskManagement"/>
                    <cts id="reliableInformationBase"/>
                </gr>
            </ctsy>
        </part>
        <part id="costEstimatesRestRough">
            <tyt>
                <tx l="en" nm="Cost estimates rest on rough assumptions and leave whole items out"/>
            </tyt>
            <narrative>
                <narr l="en">
                    <ak nr="5" ref="draft draft" tp="xm" zn="CH2026keyProjectsFederalAdmin">Initial cost figures 'are based on first rough estimates, which either follow previous IT investment costs or simplified estimating models'. Estimates are also incomplete: 'financial outlays for the technical migration and the subsequent optimisation are missing, for example. The cost drivers are not known across the entire project duration' (p.21). The audit office has judged the cost estimate invalid in several audits and recommended a fresh assessment; on two projects the costs rose drastically once replanned. A Design weakness with a direct Finance consequence, since the figure that authorises the project is not the figure the project will cost.</ak>
                </narr>
            </narrative>
            <ctsy>
                <gr gn="control">
                    <cts id="design"/>
                    <cts id="reporting"/>
                </gr>
                <gr gn="value">
                    <cts id="finance"/>
                </gr>
                <gr gn="fun">
                    <cts id="finance"/>
                </gr>
                <gr gn="quality">
                    <cts id="costControlValueForMoney"/>
                    <cts id="reliableInformationBase"/>
                </gr>
            </ctsy>
        </part>
        <part id="reportingOversightArrivesThree">
            <tyt>
                <tx l="en" nm="Reporting to oversight arrives three months late, so it records rather than steers"/>
            </tyt>
            <narrative>
                <narr l="en">
                    <ak nr="6" ref="draft draft" tp="xm" zn="CH2026keyProjectsFederalAdmin">The half-yearly reporting to the general secretaries' conference and to parliamentary oversight 'is available three months after the respective reference date and thus permits no forward-looking steering, but only a retrospective determination of the project status. As a result, timely information is lacking in order to be able to take short-term corrective measures' (p.20). A Reporting line that satisfies its obligation while failing its purpose: the oversight bodies learn what happened, never in time to change it.</ak>
                </narr>
            </narrative>
            <ctsy>
                <gr gn="control">
                    <cts id="reporting"/>
                </gr>
                <gr gn="fun">
                    <cts id="governance"/>
                </gr>
                <gr gn="quality">
                    <cts id="functioningOversight"/>
                    <cts id="reliableInformationBase"/>
                </gr>
                <gr gn="sta">
                    <cts id="lawmaker"/>
                    <cts id="oversight-role"/>
                </gr>
            </ctsy>
        </part>
        <part id="portfolioManagementAboveIndividual">
            <tyt>
                <tx l="en" nm="No portfolio management above the individual projects, so dependencies and people are allocated blind"/>
            </tyt>
            <narrative>
                <narr l="en">
                    <ak nr="7" ref="draft draft" tp="xm" zn="CH2026keyProjectsFederalAdmin">Most audited projects are delayed by resource commitments that are not honoured, by missing resources generally, or by dependencies on other projects. The audit office identifies the absence of portfolio management across offices and programmes as a main cause: with it, 'dependencies, resources and risks between the projects could be actively managed and steered at strategic and operational level' (p.14). One federal office keeps a list of projects that shows neither resource use nor dependencies. Some units are waiting for a central solution, and the audit office notes plainly that its absence is no justification for inaction. A Coordination gap one level above the projects, where no single project can close it.</ak>
                </narr>
            </narrative>
            <ctsy>
                <gr gn="control">
                    <cts id="coordination"/>
                </gr>
                <gr gn="fun">
                    <cts id="planning"/>
                </gr>
                <gr gn="quality">
                    <cts id="avoidanceOfDuplication"/>
                    <cts id="adequateResourcesCompetences"/>
                </gr>
                <gr gn="sta">
                    <cts id="management"/>
                </gr>
            </ctsy>
        </part>
        <part id="thinSupplierMarketsLeave">
            <tyt>
                <tx l="en" nm="Thin supplier markets leave the state with little leverage once the contract is awarded"/>
            </tyt>
            <narrative>
                <narr l="en">
                    <ak nr="8" ref="draft draft" tp="xm" zn="CH2026keyProjectsFederalAdmin">Procurement repeatedly causes delays and additional costs, often because it takes place 'in markets with few suppliers, proprietary technologies and high user requirements', producing a pronounced supplier dependence: 'after the award, the federal government has only limited influence over national or international suppliers' (p.15). Individual measures exist - withholding payment until defects are fixed, examining a change of supplier - but effective options and worked-out scenarios to strengthen the state's negotiating position are missing. On a security radio system, stalled negotiations over key components strained the supplier relationship and raised the risk that operation could not be assured; if that system fails, emergency and rescue services lose reliable communications. Continuity exposed through an Asset the state cannot readily replace.</ak>
                </narr>
            </narrative>
            <ctsy>
                <gr gn="control">
                    <cts id="continuity"/>
                    <cts id="coordination"/>
                </gr>
                <gr gn="value">
                    <cts id="asset"/>
                </gr>
                <gr gn="fun">
                    <cts id="productServicePurchase"/>
                </gr>
                <gr gn="quality">
                    <cts id="reliabilityAvailability"/>
                    <cts id="soundRiskManagement"/>
                </gr>
                <gr gn="sta">
                    <cts id="supplier"/>
                </gr>
            </ctsy>
        </part>
        <part id="agileWorkingAdoptedPromise">
            <tyt>
                <tx l="en" nm="Agile working is adopted as a promise, without the target picture or the people planning it needs"/>
            </tyt>
            <narrative>
                <narr l="en">
                    <ak nr="9" ref="draft draft" tp="xm" zn="CH2026keyProjectsFederalAdmin">Agile methods 'are regarded in many projects as promising in themselves'. In practice they demand a high level of method competence that the administrative units usually have to build first, a process that 'as a rule takes three to four years'; where short-term performance gains are expected at the same time, the result is unrealistic expectations, delays and additional effort (p.19). The investment in know-how only holds if the way of working continues after the project closes - if the parent organisation does not support that, the progress is lost. The argument that the law prevents the cross-cutting collaboration agile methods need 'often turns out to be an excuse'; two federal offices lack both a binding target picture and any medium- or long-term personnel development strategy for the agile direction they have chosen. Training and Goal-setting missing behind a method adopted on faith.</ak>
                </narr>
            </narrative>
            <ctsy>
                <gr gn="control">
                    <cts id="training"/>
                    <cts id="goalsetting"/>
                </gr>
                <gr gn="value">
                    <cts id="human_capital"/>
                </gr>
                <gr gn="fun">
                    <cts id="humanResources"/>
                </gr>
                <gr gn="quality">
                    <cts id="adequateResourcesCompetences"/>
                    <cts id="clearObjectives"/>
                </gr>
                <gr gn="sta">
                    <cts id="staff"/>
                </gr>
            </ctsy>
        </part>
        <part id="bindingArchitectureSpecificationsStandardisation">
            <tyt>
                <tx l="en" nm="Without binding architecture specifications, standardisation and reuse never arrive"/>
            </tyt>
            <narrative>
                <narr l="en">
                    <ak nr="10" ref="draft draft" tp="xm" zn="CH2026keyProjectsFederalAdmin">'Missing or non-binding architecture specifications frequently mean that economies of scale, standardisation or integration cannot be realised. This leads to inefficient solutions and additional costs' (p.17). Several projects lack essential architecture results such as the target data architecture or the transition architectures describing how to get from the current state to it, 'which can lead to a lack of interoperability - a central point precisely in federal projects, where data have to be exchanged' (p.18). On a project separating mission-critical from non-critical military ICT, savings depend on decommissioning applications, but the enterprise architecture needed to judge current and future need 'is not yet sufficiently established'. A Design gap at the level above the project, which makes Data integration between projects a matter of chance.</ak>
                </narr>
            </narrative>
            <ctsy>
                <gr gn="control">
                    <cts id="design"/>
                    <cts id="dataIntegration"/>
                </gr>
                <gr gn="value">
                    <cts id="asset"/>
                </gr>
                <gr gn="fun">
                    <cts id="IT"/>
                </gr>
                <gr gn="quality">
                    <cts id="interoperabilityForUsers"/>
                    <cts id="avoidanceOfDuplication"/>
                </gr>
            </ctsy>
        </part>
        <part id="testingUnderestimatedSoDefects">
            <tyt>
                <tx l="en" nm="Testing is underestimated, so defects surface late and cost more to fix"/>
            </tyt>
            <narrative>
                <narr l="en">
                    <ak nr="11" ref="draft draft" tp="xm" zn="CH2026keyProjectsFederalAdmin">'The projects sometimes underestimate the importance of comprehensive testing, with the result that errors are recognised late and additional effort, delays or quality problems can arise in later operation' (p.21). In the migration-system renewal the test coverage for individual critical functionalities was inadequate and several relevant errors were identified only at a late project stage; in other projects the test concept does not adequately cover the end-to-end view. A Testing gap whose cost is paid after go-live, by the operating organisation rather than the project.</ak>
                </narr>
            </narrative>
            <ctsy>
                <gr gn="control">
                    <cts id="testing"/>
                </gr>
                <gr gn="fun">
                    <cts id="projectMethodology"/>
                </gr>
                <gr gn="quality">
                    <cts id="reliabilityAvailability"/>
                    <cts id="streamlinedProcesses"/>
                </gr>
                <gr gn="sta">
                    <cts id="operator"/>
                </gr>
            </ctsy>
        </part>
    </part>
</dokAAPp>
