Who holds the keys? The knowledge trap behind major technology contract failures
When a public sector department or agency signs a major technology contract, attention fixes on money and timelines. The more consequential transaction is quieter and rarely measured: the transfer of knowledge and, with it, power. Every large IT project moves expertise from the buyer to the seller. The vendor learns the client’s operations in intimate detail, while the client slowly loses the ability to run, question or replace the system on its own. Recent failures in the United Kingdom and across Australia show what happens when that imbalance is left to grow unchecked.
A contract is also a transfer of knowledge
It is easy to fall into the trap of reading an IT procurement as the purchase of software. It is better understood as an exchange of understanding. At the outset, the government department or agency holds deep knowledge of its own processes and the vendor holds deep knowledge of its product.
A well-managed project moves just enough in each direction for the system to work. A poorly managed one lets the flow run only one way: the vendor accumulates knowledge of the agency’s payroll rules, funding models and legacy quirks, while the agency’s own understanding drains away as experienced staff retire, documentation lapses and daily operations disappear into a black box only the vendor can open. At that point the buyer has quietly handed over the keys.
The customisation trap
Birmingham City Council (BCC), the largest local authority in the United Kingdom, which commands a gross budget more than double that of Australia’s largest council Brisbane City Council despite serving a similarly sized population of residents, learned this the hard way. In 2019, it set out to replace an aging finance and human resources platform with Oracle Cloud, a modern Enterprise Resource Planning (ERP) suite: the kind of software that runs core functions such as finance, procurement and payroll. The budget was roughly £19 million (AU$37 million) and the system was meant to be live by 2020. Modern Software-as-a-Service (SaaS) products are built around standard, preconfigured processes, and the discipline they demand is that the organisation adapts its workflows to the software. Birmingham did the opposite: it requested thousands of modifications so the new system would mirror its old bespoke ways of working. Every standard update then broke those customisations, costs climbed past £38 million (AU$73 million) and kept rising, and by the April 2022 launch the council could not reliably reconcile its own bank accounts.
By 2023 the projected repair bill topped £100 million (AU$193 million), the council issued a notice amounting to effective bankruptcy, and local services were gutted. The technical failure had a governance root: BCC lacked the internal expertise to challenge the design, so it leaned on outside consultants and demanded a level of complexity it could not itself manage. The more it customised, the more captive it became.
When the customer cannot walk away
One important Australian case predates Birmingham but carries the same signature. In 2007, the State of Queensland engaged IBM under a fixed price contract of about $6.19 million to replace Queensland Health's payroll system. When the system went live in March 2010, despite known defects and incomplete testing, close to 78,000 staff were underpaid, overpaid or not paid at all, and more than 35,000 payroll errors followed. The build had been heavily customised, with more than a thousand changes in one component and over fifteen hundred in another, which left it fragile and expensive to maintain. The estimated eventual cost reached about $1.2 billion, with $1.01 billion spent on business-as-usual operational expenses to manually process and run the fragile system, $220.5 million dedicated to remediating and fixing its thousands of technical defects, and $25 million allocated to planning for its eventual replacement, and a commission of inquiry later ranked the episode among the worst failures of public administration the country had seen.
The most instructive detail is not the price. By the time the failure was undeniable, senior officials believed the state had become reliant on the vendor to finish the job, and that removing it risked the collapse of the entire payroll. Litigation was avoided in part for fear the vendor would stop work, the state had already limited its ability to recover damages, and a later lawsuit failed. Knowledge and leverage had shifted so far that the customer could neither run the system nor abandon it. The vendor was eventually barred from Queensland government work, but by then the money and the leverage were gone.
The pattern was not confined to one agency. In 2016 the Australian Bureau of Statistics (ABS) ran the national census online under a contract with the same supplier. When the site collapsed on census night the outage added roughly $24 million in costs and ended in a confidential settlement. A different project, but the same theme: an agency dependent on a supplier it was not equipped to second guess.
The incumbency trap
A Victorian Government experience shows how the imbalance can persist for decades. In 2005, the state signed a contract worth about $944 million with a consortium known as Kamco to build myki, a bespoke smartcard system for public transport that it hoped would rank among the best in the world. Costs grew to roughly $1.5 billion over the life of the system, and the Victorian Auditor-General's Office (VAGO) found that the original scope and contract had been loosely defined and overly ambitious, with weak governance from the outset.
The more revealing detail came later. When the operating contract was put to tender again in 2016, the state handed it back to the same incumbent, a choice the auditor called a missed chance to apply the lessons of the first failure. Only in 2023, switching to a standard product from a new supplier, did Victoria finally break the pattern. Deep familiarity with a captive customer is itself a form of power.
Asymmetry is structural, not accidental
It is tempting to treat these as tales of individual villains, but the sharper reading is structural. A vendor need not act in bad faith to benefit from the imbalance, because the arrangement itself produces it. That dependence takes several familiar forms: bespoke customisation that cannot be lifted and moved elsewhere; proprietary data formats and configurations that only the vendor fully understands; a change process in which every modification becomes a billable event; and the sunk cost instinct that makes walking away feel more reckless the more has already been spent. Each of these converts the customer’s early enthusiasm into later dependence.
Where a vendor does behave improperly, as the Queensland inquiry found had happened during the tender, asymmetry tips over into exploitation.
Rebalancing the ledger
None of this argues against buying from capable vendors; it argues for keeping the keys. Agencies that fare better tend to retain an internal capability, sometimes called a smart client function that can specify requirements, interrogate designs and hold the supplier to account rather than outsourcing judgement wholesale. They resist the customisation trap and adopt standard configurations, changing their own processes to fit proven software rather than bending the software to fit them. They insist on owning their data in portable formats, and they write documented exit rights, configuration handover and knowledge transfer obligations into the contract from the beginning. They treat independent assurance and candid reporting as essential rather than optional, so that warnings reach decision makers before a launch rather than after. They never sign away liability simply to keep a struggling supplier at the desk.
The uncomfortable truth running through the Birmingham, Queensland and Victorian examples — and every comparable failure — is that the balance of power in a technology contract is settled long before anything goes wrong. It is decided by who understands the system, who owns the data, and who can still function if the relationship ends. Those questions belong at the start of a procurement, not in the wreckage. The agencies that ask them keep hold of the keys. The ones that do not eventually discover the keys were never really theirs.
Why the APS needs to be picky with AI
'AI everywhere' is the wrong strategy for the APS: here's what to do instead.
Digital ID must prove more than who we are
Digital ID may make it simpler to identify an individual but the question is whether it will...
Why sovereign AI matters now
Sovereign AI doesn't mean stepping back from the global technology ecosystem, but engaging...
