The reorganisation was announced in October. Four directorates became three, the data team moved out of IT into a function called Information and Insight, two roles went and three were created. The intranet A to Z was updated inside a fortnight.
By April the new structure was being asked what the old one had been asked: who owns this, why it broke at the handover, why it was found so late, and why nobody had the whole picture.
Three owners in six years
In 2019 third-party access sat with the security team. The security team wrote a policy.
In 2021 it moved to a vendor risk function under procurement. Vendor risk built a questionnaire.
In 2023 vendor risk was folded into Data and Trust. Data and Trust commissioned a dashboard.
The policy, the questionnaire and the dashboard are all current. All three have owners. All three are reviewed.
Third-party access touches the joiner and leaver process, the contract register, four identity systems, the people who approve exceptions at month end, and whoever happens to notice that an account is still open. The security team held the joiner and leaver process and the identity systems. Vendor risk held the contract register. Data and Trust holds the dashboard.
In each of those three years the same thing turned up, a supplier account still open after the contract ended.
Divided into three parts
Resilience was one team until 2021, when a reorganisation divided it: infrastructure took the platforms, operations took the runbooks, business continuity took the plans. Each of the three tests its part twice a year.
The dependency between the payments platform and the notification service has never been tested, because it sits in none of the three parts.
In November the payments platform failed over correctly. Nobody could tell customers, because the notification service had gone with it.
Forty-one workstreams and a completion report
Data protection readiness was a programme. It ran for two years, delivered forty-one workstreams and closed in 2019 with a completion report.
The record of processing activities the programme produced has not been updated since it closed. Answering the audit committee takes about a fortnight, and starts by asking three teams what they hold.
The question it was set up to answer, whether the organisation can say what personal data it holds and why, comes back twice a year. It is answered by whoever is free that week.
The reorganisation after next
A fourth reorganisation is scheduled for next year. Third-party access will be given its fourth owner.
Reorganisations change who answers the door. They do not change who keeps knocking.
There is an index built on concern, asking what, where, when, who, how and which. It is called Metier.
Departments describe where people sit. Projects describe what people are doing. Technologies describe what people are using. Concerns describe what keeps coming back.