Who Owns It?
Twelve capabilities from a target operating model, each with a name against it. The question is not who is named — it is whether they can decide, fund it, and say no.
1. Integration platform. The platform lead sets standards, holds the budget and can refuse a non-conforming integration.
2. Customer data quality. The data governance council reviews it quarterly. The council has no budget and its decisions are recommendations.
3. API standards. Architecture publishes them; each product team decides whether to follow them; no one tracks conformance.
4. Identity and access management. Security owns the policy and IT operations owns the platform. Both agree the other decides the roadmap.
5. The reporting data model. It arrived with an acquisition. Nobody in the current structure has it in their objectives.
6. Cloud cost management. The FinOps lead has a mandate from the CFO, a budget and the authority to switch off untagged resources.
7. Third-party risk for technology vendors. Procurement runs onboarding; security assesses; neither owns ongoing monitoring.
8. Master data management. A programme director owns it for the duration of the programme. There is no operational owner after go-live.
9. The developer platform. The platform team owns it and reports to the CTO, who has agreed its roadmap and funding for the year.
10. Data retention. Legal sets the schedule and each business unit implements it. No one holds the list of systems in scope.
11. Technical debt in the payments stack. It is on the engineering manager's objectives. Their capacity is allocated by a product council they do not sit on.
12. Enterprise architecture standards. A chief architect owns them, sits on the investment board and can block funding for non-conforming proposals.
Educational. Operating model conventions vary; what transfers is the three-part test — can the named owner decide, can they fund it, and can they refuse a non-conforming request.