Foundry4

Public sector technology 6 min read

Digital is not what holds the public sector back

Eleven government digital strategies since 1996 and few transformations at scale. The binding constraints turn out to be budget rules, pay bands and contracts.

There have been eleven government digital strategies since 1996. The Public Accounts Committee counted them in a report published on 13 September 2023, noting that all of them sought to address usability, efficiency and legacy systems, and that examples of successful digital transformation of services at scale remain rare.

Eleven strategies is not a shortage of intent. It is closer to evidence that intent is not the variable.

The diagnosis that keeps being confirmed

The committee’s central observation is worth stating precisely, because it is usually paraphrased into something softer. Improvements over twenty-five years focused on the citizen’s online experience without substantially modernising the ageing systems beneath departmental websites. The result is services that may look good on the surface while remaining costly and problematic to run, because nobody addressed the inefficiencies baked in by working around what the underlying systems cannot do.

That is a description of an incentive, not a mistake. A front end can be delivered inside one financial year by a team of thirty and demonstrated to a minister. Replacing what sits behind it takes several years, cannot be demonstrated, and its main visible output during the parliament that funds it is disruption.

Where the money actually goes

The State of digital government review of 21 January 2025 measured where the annual technology and data budget lands. Of £26 billion of public sector digital and data spend in 2023, 55%, or £14.5 billion, went to contractors, managed services providers and IT consultants, split 12%, 25% and 19% respectively. Less than 20%, around £5 billion, went on permanent public sector staff. That is just under a fifth, on a £26 billion total that takes in the NHS, local government and policing as well as departments.

Then be careful with the comparison that usually gets made next, because the two sides of it count different people. The 55% includes the staff of managed services and consultancy firms, who appear on no public sector headcount at all. The review’s own like-for-like statement is narrower and more useful: contractors are around 18% of the total headcount of the two groups, permanent staff and contractors, and around 40% of the cost of those two groups. Contractors on their own account for 12% of the £26 billion. The explanation for the gap is unit cost, and the review states it plainly: a contractor averages £182,000 a year where a permanent employee averages £61,000.

Look at what that structure does to a legacy programme. The knowledge of how a thirty-year-old system behaves under load lives with people whose contracts end. The organisation buying the replacement cannot describe the thing being replaced without asking the supplier who maintains it. Every published recommendation about becoming an intelligent customer runs into that arithmetic, and pay is why the arithmetic holds: the review found central government cyber specialists earning 35% less than private sector peers and civil service chief information security officers about 40% less.

The other constraint is the annual budget

The National Audit Office reported that in March 2024 departments had no fully funded plans to remediate 53% of government’s legacy IT assets, 120 systems out of at least 228, and that 63 were red-rated for the likelihood and impact of operational and security risk. Of the £2.6 billion announced for cyber at the 2021 Spending Review, £1.3 billion was allocated to departments for cyber security and legacy remediation. By January 2023 departments had funded the most urgent priorities but risked missing their targets under financial pressure, and some subsequently cut the scope of improvement programmes to pay for other things.

Government also estimated it spent nearly half of its £4.7 billion IT expenditure in 2019 keeping legacy systems running. Money spent on continuity is money not spent on removing the need for it, and the loop closes each April.

The programme ratings say the same thing from a different angle

Only 9% of major technology programmes in government are assessed as green for delivery confidence, and technology programmes are 60% more likely than others to be assessed as red. Those figures also come from the January 2025 review.

The temptation is to read that as evidence that digital delivery is uniquely hard. A more defensible reading is that technology programmes are the ones that make an organisation’s existing dysfunction visible on a schedule. A policy programme can absorb a decade of accumulated exceptions in guidance. A system has to encode them, which means somebody has to write them down and someone senior has to agree they are correct. That is where these programmes stop, and it is not a technical stop.

Two further findings from the same review point the same way. Only 8% of AI projects were showing measurable benefits, and only 16% showed forecast costs. Meanwhile 123 outages were recorded in NHS England alone during 2024, and a quarter of survey respondents reported suffering critical outages. A programme portfolio can be rated on its plans. An outage is not a plan, and an estate producing that many of them is telling you about its operating conditions rather than its ambitions.

There is also a measurement problem that flatters everyone. Delivery confidence ratings assess whether a programme will deliver what its business case said, not whether the business case described something worth doing. A programme can be rated green all the way to installing a system that nobody afterwards uses, without the rating ever having been wrong.

What is genuinely digital’s fault

Two things, and it is worth being fair about them.

The sector has an established habit of promising savings from a pilot and delivering costs at scale, and the AI figures quoted above are what that habit looks like when someone finally counts. A discipline that can forecast the cost of only one project in six is not in a position to lecture anyone about business cases.

And the profession has been slow to make itself legible to the people who hold the budgets. Only around 20% of senior civil servants have verified themselves as digitally upskilled, and only four central departments have a digital leader on their executive committee. Some of that is a recruitment failure by government. Some of it is a communication failure by a profession that has preferred its own vocabulary.

The implication

If digital were the constraint, eleven strategies and £26 billion a year would have moved the position further than they have. The constraint is a set of rules about how public money may be committed across years, a pay framework that cannot hold the people who understand the estate, and a contracting model in which the supplier knows more about the system than the buyer does.

None of that is fixed by another strategy, and all of it is fixed by things that are dull, slow and within the gift of the Treasury. Which is an unsatisfying conclusion, and it is the one the audit record supports.

A test for the next strategy

There will be a twelfth. When it arrives, there is a quick way to tell whether it is different in kind from the eleven before it, and it has nothing to do with what technologies it mentions.

Look for whether it commits money across more than one financial year to systems that are not being replaced. Look for whether it changes a pay band. Look for whether it names the person who can stop a department procuring something incompatible, and says what happens if they are ignored. A strategy that does none of those is a description of an ambition, and the record shows what happens to those.

For public sector technology generally, and for the buying question in particular, the detail is in what the Procurement Act changed for suppliers.

Sources

  1. Committee of Public Accounts, Digital transformation in government: addressing the barriers to efficiency, HC 1229, 13 September 2023 publications.parliament.uk
  2. National Audit Office, Government cyber resilience, HC 546, 29 January 2025 nao.org.uk
  3. DSIT and GDS, State of digital government review, 21 January 2025 gov.uk