Digital transformation 7 min read
The job that replaced the transformation CTO
Regulators and a governance code have started naming who is answerable for technology. In finance it has a code number. In listed firms it lands in 2026.
The transformation chief technology officer was a job with a shape. Arrive with a mandate, hold it for three or four years, run a programme, hand over a modernised estate, leave before the second rollout. The role assumed that technology change was a project, and projects end.
What has replaced it is not a title. It is a set of accountabilities that other people have started writing down, with dates, in documents that were not drafted by anyone in technology. That is the substantive change, and it is easier to see in the financial sector than anywhere else, because there the regulator got there first and gave the job a number.
In financial services it is SMF24
The FCA Handbook defines the chief operations function at SUP 10C.6B as the function of having overall responsibility for managing all or substantially all the internal operations or technology of the firm, or of a part of the firm. Technology, the guidance explains, refers principally to the firm’s information and communications technology systems and services, including the mechanisms and networks supporting data entry, storage, processing and reporting. The function can take in business continuity, cyber security, outsourcing, operational resilience and shared group services. It excludes acting in the capacity of chief executive, and matters relating to internal audit, compliance and risk control are left out when deciding whether someone holds overall responsibility.
Three features of that definition matter more than the label.
It is held by a named individual, approved by the regulator, with a statement of responsibilities that says which parts of the firm’s operations are theirs. It covers operations and technology together, which is a recognition that the separation between running a service and running the systems underneath it stopped meaning anything. And it is defined by scope of responsibility rather than by deliverable, which is a different kind of job from one measured by whether a programme landed.
The exclusions are instructive too. Internal audit, compliance and risk control are disregarded when working out whether someone holds overall responsibility, and the legal function is not part of the firm’s internal operations or technology for this purpose. Those carve-outs exist because the second line has to be able to challenge the first, and a definition that swept them in would have merged the person running the systems with the people checking them. Most organisations outside financial services have never made that separation explicit, which is why their technology function is routinely asked to assure its own work and routinely does.
There is a further structural point buried in the phrase “or of a part of the firm”. The function does not assume one person owns everything. It permits a firm to allocate overall responsibility for a defined part of the operation to a named person, which is a far more honest model of how large estates are actually run than a single accountable technologist at the top of a chart.
The scope now includes suppliers the firm does not control
The regulators’ policy statement on critical third parties to the UK financial sector, whose rules took effect on 1 January 2025, adds the other half of this job. Designation sits with HM Treasury under powers in the Financial Services and Markets Act 2023, and the rationale given is that disruption or failure at one of these providers could affect many firms and consumers at once. The designations made under it, and what they change about buying decisions, are covered in this desk’s reporting on the hybrid estate.
The leadership consequence is what matters here, and it is uncomfortable. The accountable person’s responsibility already extended to services their organisation buys, operates through and cannot inspect. Now a supervisory relationship exists between the regulator and that provider directly, running alongside and sometimes ahead of the firm’s own commercial one. The old chief technology officer role was defined by what the technology function built. Its successor is defined by what the organisation depends on, which is a much larger set and mostly not yours to change.
That is the split the title obscures. Building things and being answerable for things stopped being one job somewhere around the point when most of the estate arrived as a subscription. Plenty of organisations still advertise a single role covering both, and the people who take it discover that the second half consumes the first.
For listed companies it arrives in 2026, through the audit committee
The Financial Reporting Council’s 2024 UK Corporate Governance Code applies to financial years beginning on or after 1 January 2025, with one significant exception. Provision 29, which asks boards to make a declaration on the effectiveness of their material internal controls, applies to financial years beginning on or after 1 January 2026.
The declaration is about material controls rather than every control, and materiality is for the board to determine, taking account of matters such as the company’s size, business model, strategy and complexity. The FRC’s own guidance is that the board should reach its view using evidence obtained through the monitoring and review of the risk and internal control framework.
Follow that through to what it means operationally. In a large modern company, most material controls run in software. Segregation of duties is a permissions model. Payment approval is a workflow. Revenue recognition depends on how a billing system classifies an event. A board that has never had to describe its technology controls in the annual report is about to, on a comply-or-explain basis, and it will need somebody to have collected the evidence during the year rather than in the fortnight before the report is drafted.
That is the mechanism by which digital leadership quietly became a reporting job rather than a strategy job. Nobody announced it. It came in through the audit and risk section of a governance code.
Government drew it as an organisation chart
The public sector version is more explicit, because it was published as a plan.
A blueprint for modern digital government, published on 21 January 2025 by DSIT and the Government Digital Service, sets out a strengthened digital centre led by a Government Chief Digital Officer, with the role raised to Second Permanent Secretary level. GDS and the Central Digital and Data Office merged into one organisation inside DSIT. Departmental chief digital officers acquire a dotted reporting line to the GCDO. Secretaries of State are drawn in through regular reviews with a Digital Inter-Ministerial Group measuring departmental performance against digital metrics, annually for the major operational departments. The parallel commitment on board and executive committee membership, and the date attached to it, is examined at why departments keep merging digital into technology.
The dotted line is the instrument to watch. It gives a central function influence over standards and appointments without giving it budget or line management, which is exactly how the finance and commercial functions are held together across Whitehall, and it works about as well as the centre’s ability to say no during a spending round.
What is genuinely new is the ministerial review. Digital performance has previously been reported to Parliament through programme assurance, which measures whether things were delivered. A regular review of a department against digital metrics measures whether the estate works, which is a different question and a much harder one to answer without somebody employed to keep the answer current.
What the job is now, and what disappeared
Three differences from the role it replaced.
The output is an assertion that somebody else relies on. A statement of responsibilities, a board declaration, an annual return. Not a delivery milestone. The unit of work has changed from a thing built to a claim that can be tested by a regulator, an auditor or a select committee.
The scope includes things the organisation does not run. Suppliers, platforms, models and the automation stitched between them. An automated process that moves money or changes a record is a control, and it has to be evidenced as one, which means somebody owns the cost of keeping it correct every year rather than the cost of building it once. That arithmetic is set out in our intelligent automation guide.
And the tenure is indefinite, because the declarations are annual. This is the loss that is felt most and discussed least. A transformation CTO could finish. The successor role has no completion state, only a next reporting period, which changes who is willing to take it and what they should be paid for doing so.
The test
Ask who signs.
In a regulated financial firm, a named individual holds SMF24 and their statement of responsibilities says what falls inside it. In a listed company, for financial years beginning in 2026, the board signs a declaration on material internal controls, and someone has to have made that defensible. In a public body, by the end of 2026, there should be a named executive committee member and a named non-executive director.
Outside those three regimes, in most large private British organisations, the honest answer is that nobody signs. That absence is not neutral. It means the answer to any question about whether the estate works will be produced by whoever happens to be asked in the week the question arrives, assembled from whatever they can gather, and nobody will have had a duty to make it true in advance.
The specific organisational failure this accountability exists to catch, a platform that works and an adoption curve that never arrives, is examined at pilots clear, rollouts do not. Related coverage is gathered under digital transformation.
Sources
- FCA Handbook, SUP 10C.6B, the chief operations function (SMF24) handbook.fca.org.uk
- FCA, PS24/16 Operational resilience: critical third parties to the UK financial sector, 12 November 2024 fca.org.uk
- Financial Reporting Council, UK Corporate Governance Code frc.org.uk
- DSIT and GDS, A blueprint for modern digital government, 21 January 2025 gov.uk