Eight areas in which a technology estate is tested — the portfolio, sourcing and concentration, legacy, AI, data, cyber accountability, resilience and the board briefing — each as the questions a CIO and a board should be able to answer without notice, and the hesitation that gives a weak answer away.
In short
- Technology estates are rarely found wanting in one decisive way. They drift: the portfolio mix stops matching the strategy, concentration builds unnoticed, legacy is deferred, adoption becomes theatre, and the board is briefed on systems instead of decisions.
- The eight areas below are where an estate is most consistently tested — by the board, by the day something stops, and by the person who asks for the number behind the adjective.
- Every question is answerable at altitude, in the board’s terms. An answer that needs a system name or a demo is not yet an answer.
- The most diagnostic areas are exposure and resilience, because they are the ones the board has never accepted if they have never been stated.
- Run the checklist against the single most exposed component of the estate before running it across the whole. Most of what is wrong will appear there, while it is still cheap to say.
On this page
Technology estates are rarely found wanting in one decisive way. They drift. The mix of what the institution spends to run, grow and transform stops matching the strategy it is meant to serve; concentration in a few providers builds without anyone deciding it; the legacy question is deferred one more year; an adoption that began as capability settles into theatre; and the board goes on being briefed on systems rather than on the decisions it is being asked to take.
The eight areas below are where an estate is most consistently tested — by the board, by the day something stops, and by the person who asks for the number behind the adjective. Each is stated as the questions a chief information officer and a board should be able to answer without notice. A hesitation is the finding.
The portfolio — run, grow, transform#
- What share of the estate’s spend runs the institution, what share grows it, and what share transforms it — and can the board be shown the split on one page?
- What does that mix say about the institution, and is it the institution the strategy describes?
- Which items in the transform share are transforming anything, and which have become run cost under another name?
- Who decides when the mix should move, and when did it last move deliberately?
- Could the CFO sign the portfolio as an investment case rather than a budget?
Sourcing and concentration — build, buy, rent#
- For each major component, was the build, buy or rent decision taken as a balance-sheet commitment, and does anyone still hold the reasoning?
- Where is the estate concentrated in a single provider, and has that concentration been stated to the board as an exposure it is accepting?
- What would it cost, and how long would it take, to leave the provider the institution depends on most?
- Which commitments does the institution have to keep skills for, and is it keeping them?
- Who signs a new sourcing commitment, and is the CFO in the room?
The legacy question#
- Has the legacy estate been costed on all four lines — what it costs to run, what it prevents, what it exposes, and what it would cost to leave?
- Has the exposure line been shown to the board, in terms it could have refused?
- Is there a retirement sequence, ordered by exposure first, and does the board know the order and the reason?
- What in the estate should simply be switched off rather than replaced, and has anyone said so?
- What moved in the sequence this year, what did not, and was the board told?
AI with owners, controls and returns#
- For each adoption in production, who owns it, what controls it operates under, and where is the audit trail?
- Which adoptions are capability — used, measured, returning something — and which are theatre kept alive because retiring them would be an admission?
- What does the board understand it has approved, and does that match what is running?
- What should the board be asking about AI that it has not asked, and has the CIO volunteered it?
- Where the institution needs a definition of the governance itself, does it have one it could show a supervisor?
Data as an asset#
- Does the institution’s data have an owner for its quality, its access and its accountability, or only a custodian for its storage?
- Could the CIO state what the data is worth to the institution and what its poor quality costs, in the CFO’s terms?
- Which decisions at the top table are taken on data nobody in the room trusts, and does the board know which?
- Who can get the data out of the legacy estate, and how long does it take?
- What would a supervisor find if asked to trace a reported figure back to its source?
Cyber accountability#
- Has the division of accountability — CISO for the defence, CIO for the exposure, board for what it accepts — been stated to the board in those words?
- Could the CIO brief the board on cyber exposure without the CISO in the room?
- What could the institution lose, where is it most concentrated, and has that been put to the board as a choice?
- What is the one component that cannot be patched or replaced, and who knows about it?
- When the board last asked about cyber, did the answer come from the seat or from the function?
Resilience — the day the institution stops#
- What happens on the day the estate stops — which services, which customers, which obligations — and can the CIO describe it without notes?
- Which providers, if they stopped, would stop the institution, and has each been named to the board?
- What has actually been rehearsed, with whom, and what was learned the last time?
- Who commands on the day, and does the COO agree?
- Has the board been told what resilience the institution does not have, or only what it has?
The board briefing#
- Does the last technology paper answer the three questions — right investment, safe, what happens when it stops — with every system name struck out?
- What decision was the board asked to take, and did it know it was being asked?
- What did the CIO volunteer that the board had not asked?
- When bad news last reached the board, did it arrive from the seat first?
- Was there a demo, and what answer did it stand in for?
Every question is answerable at altitude, in the board’s terms. An answer that needs a system name or a demo is not yet an answer.
How to use it#
Every question is answerable at altitude, in the board’s terms. An answer that needs a system name or a demo is not yet an answer. Run the checklist against the single most exposed component of the estate before running it across the whole: most of what is wrong will appear there, while it is still cheap to say. The two most diagnostic areas are exposure and resilience, because they are the ones the board has never accepted if they have never been stated. A CIO who wants to work the answers with peers who carry the same three questions will find that ground in The CIO Mandate.
Frequently asked
What is a technology estate review?
A technology estate review is a structured test of whether the institution’s technology, taken as a whole, still serves its strategy, is safe, and would survive the day it stops — asked at board altitude rather than system by system. It covers the portfolio, sourcing and concentration, legacy, AI, data, cyber accountability, resilience and the quality of what the board is told.
Who should run the review — the CIO or the board?
The CIO runs it and the board tests it. The chief information officer owns the answers and should be able to give them without notice; the board, or its risk committee, owns the questions and should ask the ones it would be embarrassed to learn the answers to from someone else. A review that only one side has seen is not yet complete.
Which area of the checklist matters most?
Exposure and resilience — what the institution could lose, where it is concentrated, and what happens on the day the estate stops. These are the areas a board has never accepted if they have never been stated to it, and they are the ones that are paid for all at once, in the worst week, if the review is skipped.
What does a hesitation on a question mean?
It is the finding. A question the CIO cannot answer without a system name, a demo or a call to the function marks an area where the estate is being managed rather than owned, and where the board has been briefed on something other than the decision it is being asked to take. The hesitation, not the eventual answer, is what to write down.
The programme behind this article
Work through this material with the practitioners who wrote it.
The CIO Mandate: Technology as Institutional Strategy
For CIOs, CTOs and chief digital officers — the technology estate as a board matter: investment, AI, cyber accountability and the legacy question.
View the programme →Board-Level Risk Oversight: The Questions Directors Must Ask
Risk oversight for non-specialists — appetite, models, culture and crisis — taught as the questions that expose what reports conceal.
View the programme →The CFO Agenda: Finance Leadership at the Top Table
For sitting and incoming CFOs — capital allocation, the numbers as one defensible narrative, the board relationship and the finance function itself.
View the programme →