The go/no-go pack has thirty slides. Twenty-six of them describe what has been finished.
Testing complete. Data migrated. Training delivered to 96 per cent. Cutover plan approved. Command centre stood up. Each slide is accurate, each was expensive to produce, and together they answer a question nobody in the room needs answered: how much of the programme has been done.
The question in the room is different. It is how much risk remains, who carries it, and what happens if the answer turns out to be wrong. Almost nothing in the pack speaks to that.
The finding that names the problem
The clearest published statement of this failure comes from the UK National Audit Office. Reviewing Crossrail in 2019, the auditors observed that the progress reports Crossrail Ltd gave its board and sponsors emphasised what had been achieved and how much of the programme had been completed — and that they did not adequately consider the level of risk to successful delivery that remained.
That sentence describes most go/no-go packs in most organisations. Completion is easy to evidence, flattering to present, and cumulative — it only ever goes up. Remaining risk is contestable, unflattering, and can rise the week before go-live. A reporting culture optimising for board comfort will produce the first and quietly drop the second.
Completion and readiness are not the same measurement. Ninety-six per cent of training delivered is compatible with a warehouse that cannot pick an order.
Why committees are structurally inclined to say yes
It is worth being honest about the forces in the room, because they are not primarily about evidence.
Information systems research has studied this for thirty years under the heading of escalation of commitment — continued investment in a failing course of action. Mark Keil’s Pulling the Plug: Software Project Management and the Problem of Project Escalation in MIS Quarterly set out why software projects in particular resist cancellation: sunk costs, the self-justification of the people who approved the plan, and the fact that abandonment is a visible, attributable decision while continuation is not. Nobody is ever blamed for the go-live that was allowed to proceed. Somebody is always blamed for the delay.
The NAO found exactly this dynamic in government. In its 2023 report Lessons learned: Resetting major programmes, workshop participants said resets were generally viewed negatively — with the consequence that bodies would keep trying to resolve unresolvable issues, wasting effort and cost, rather than admit a reset was needed. In a survey of representatives from fourteen programmes, half reported multiple resets, totalling twenty-four.
The most damning detail is what actually triggered those decisions. Respondents most commonly identified product or output failure as the factor that pushed the decision to reset. Not a checkpoint. Not an early warning. The failure itself.
A go/no-go meeting held in that culture is not a decision point. It is a ratification.
What the pack usually shows, and what would decide it
| Usually shown | What would actually decide it |
|---|---|
| Training completion 96% | Which roles cannot yet complete their core task unaided, and how many people that is |
| Open defects: 9, none severity one | Which business processes those nine defects touch, and the manual workaround for each |
| Cutover plan approved | Whether it has been rehearsed end to end, and what broke when it was |
| Data migration reconciled | Whether the people who own that data agree the content is usable, not just that volumes match |
| Command centre stood up | Rotas, escalation thresholds and the named person with authority to stop processing |
| Benefits case unchanged | The cost of a four-week delay, quantified, next to the cost of a bad go-live |
The right-hand column is harder to produce. That is the entire reason the left-hand column dominates.
Four things a committee actually needs
1. Criteria agreed before the evidence arrives. Thresholds set two weeks before go-live are negotiated against the answer. Thresholds set three months out are a genuine test. This is the same discipline that makes a readiness score worth reporting: decide in advance what number means stop, and decide which measures cannot be compensated for by strength elsewhere. A brilliant finance function does not offset a warehouse that cannot pick.
2. Remaining risk, stated as consequence rather than count. “Nine open defects” is not a risk statement. “Three of the nine sit in credit checking, so orders above the credit limit will need manual release by two named people for the first fortnight, at an expected volume of forty a day” is. The first invites a nod. The second invites a question about whether two people can do forty a day.
3. The delay option, costed. The Gateway assurance process is explicit about this. Its Gate 4: Readiness for service review asks directly: if there are unresolved issues, what are the risks of implementing rather than delaying? The evidence expected is a documented evaluation of cancelling, delaying or proceeding — covering benefits realisation, consequences for users and stakeholders, and financial impact — with options and management plans for all scenarios, ratified by the board. Delay is treated as a real option with a real price, not as failure.
Most commercial packs contain no costed delay option at all, which means the committee is not choosing between two things. It is being asked to approve one thing.
4. A tested way back. The same Gate 4 purpose statement expects feasible and tested business contingency, continuity and reversion arrangements. In practice, rollback is usually a paragraph asserting that rollback is possible, written by someone who knows it will never be exercised. If reversion is genuinely impossible after hour six of cutover — which is often true — that is a material fact the committee should be told in those words, because it changes what the decision is.
Who should actually make the call
There is a real tension here. The committee has the authority but not the visibility. The people with the visibility are usually too junior, or too invested, to be trusted with the decision.
The Bank of England’s Real-Time Gross Settlement renewal offers a resolution worth copying. In its December 2025 report on the programme — which replaced infrastructure settling around £790 billion a day, and which the NAO judged well managed — the auditors describe the split: the Renewal Executive Board gave overall approval for go-live decisions using set readiness criteria, then delegated the final go-live decision to the programme’s senior owner and technical director, so that the decision was made by those with detailed knowledge of the programme’s readiness.
The board owned the standard. The people closest to the evidence applied it. That separation is the useful part: it removes the committee’s incentive to negotiate its own criteria at the moment of decision, and it stops a summary slide from standing in for operational knowledge.
The same report contains the most instructive delay in recent public record. One of four replans was triggered when the European Central Bank moved its own migration date close to the Bank’s, creating what the NAO describes as too high a level of change for users to manage safely. A technically capable programme delayed because the people receiving the change could not absorb that much of it at once. If your own users are simultaneously receiving three other rollouts, that is a go/no-go input, not background noise.
The question to ask when everything looks green
The NAO’s reset report offers three questions for decision-makers, and the first is the most uncomfortable one available to a sponsor: when did you last challenge the programme as to whether everything is going to plan?
Uniform green is not usually evidence of health. It is evidence of a reporting line where amber has a social cost. The NAO’s 2020 report on Digital Services at the Border found that programme leadership had bred a culture of tightly controlled and manipulated communications towards stakeholders and senior leadership — which made honest discussion of options difficult. Nobody in that programme set out to mislead a board. The reporting simply optimised for the reaction it received.
Three practical counters, none of which require a new governance layer:
- Ask for the dissent. Who on the programme thinks this date is wrong, and what do they say? If the answer is that nobody does, the answer is wrong.
- Ask a receiving manager directly, not the programme. One question, no programme staff present: what will your team stop doing in the first three weeks? Silence is a finding.
- Ask what would have to be true for this to fail. Then ask how you would know whether it is true, and whether anyone has checked.
These work because they cannot be answered from the completion pack. They also reveal, quickly, whether the reporting was ever built to support a decision or only to describe progress.
Going with known gaps — which is usually the right answer
None of this is an argument for delaying. Most go-lives should proceed, and a programme that waits for every claim to be green will never launch and will burn its credibility waiting.
The distinction that matters is between carried risk and unexamined risk. A gap that has been named, quantified, resourced and assigned to a person is a managed condition. The same gap, unrecorded, becomes the thing that nobody could have predicted — and then becomes the reason for a recovery effort that costs several times what the mitigation would have.
So a defensible go decision has a shape:
- Here are the criteria we set in advance, and here is where we landed against each.
- These three are not met. Here is who is affected, how many, and for how long.
- Here is the mitigation for each, the person accountable, and what it costs.
- Here is what we will watch in the first fortnight, and the threshold at which we escalate.
- Here is the cost of delaying instead. We recommend proceeding, and this is why.
That is a five-slide pack. It is more useful than the thirty-slide version, and considerably harder to write, because every line commits somebody to something. The first fortnight of watching is not optional either — hypercare ticket volumes will not tell you whether people can work, and the gaps you carried across the line are precisely the things that need their own measures.
What the decision is really about
A go/no-go decision is not a judgement about whether the programme is finished. It is a judgement about how much unresolved risk the organisation is willing to carry into the first weeks of live operation, and whether it has the capacity to absorb it.
Committees that are shown completion cannot make that judgement, however senior they are. They can only agree that a lot of work has been done, which is true, and irrelevant.
The change worth making is small and awkward: agree the criteria early, report remaining risk as consequence, cost the delay, and let the decision be taken by people who know what the evidence means. None of it requires new tooling. It requires a sponsor willing to ask, in front of everyone, what would have to be true for this to fail — and to be genuinely willing to hear the answer.
The gate decision also depends on what the standing governance body does the rest of the time. A committee that spends its meetings receiving status has no practice at deciding anything, which is why what belongs on a steering committee agenda matters well before the go/no-go paper is written.
More on turning readiness evidence into leadership decisions in the Change Readiness Hub, or see how a Readiness Diagnostic Sprint assembles gate evidence in two to three weeks when the date is already fixed.
