Why a quantified cost still doesn’t get approved
You have done the hard part. You have quantified the cost of your legacy estate. You know the direct maintenance cost, incident exposure, delayed initiatives and talent drag. You have built a defensible estimate of the cost of doing nothing.
And the legacy modernisation business case still stalled.
That is not unusual. A quantified cost is only one part of the decision. An audit or risk committee also needs to understand whether the exposure is material, how it aligns with the firm’s risk appetite and operational resilience obligations and whether the proposed remediation can be delivered under effective governance.
This article is for regulated financial services firms that have already completed the cost model. If you have not yet quantified the exposure, start with the calculation. This article begins with the completed number and explains how to turn it into a business case the board can approve.
Why legacy technology has become a board-level issue
Technology risk was once treated primarily as an IT concern. In regulated financial services, it is now a governance, operational resilience and business continuity issue.
For listed firms within scope of the 2024 UK Corporate Governance Code, the Code applies to financial years beginning on or after 1 January 2025. Provision 29 applies to financial years beginning on or after 1 January 2026. It requires boards to declare on the effectiveness of material internal controls, including financial, operational, reporting and compliance controls.
Not every financial services firm falls formally within the scope of the Code. However, the direction of travel is clear. Material technology weaknesses require visible ownership, supporting evidence and a governed remediation plan. A quantified cost, without that governance context, is only part of the business case.
The practical implication is that the business case is no longer being read by one CFO with a calculator. It may be challenged by executives, non-executive directors, audit, risk, compliance and internal assurance. Each group needs evidence that the exposure is credible, the remediation is proportionate and the delivery risk is controlled.
The regulatory backdrop. Where FCA and PRA obligations bite
Operational resilience has changed what boards need to see
The transition period under the FCA’s PS21/3 operational resilience rules ended on 31 March 2025. Firms in scope should already have identified and tested their important business services, set impact tolerances and made the investments needed to remain within them. The FCA is now publishing supervisory observations based on firms’ implementation.
The FCA has also finalised new operational incident and material third-party reporting rules, which come into force on 18 March 2027. In-scope firms will need to maintain and submit an annual register of material third-party arrangements alongside the relevant operational incident reporting requirements.
The important point for boards is not that another regulatory deadline is approaching. It is that firms must be able to demonstrate continuous control over the systems, suppliers and dependencies that support important business services. That is exactly the context in which a legacy modernisation business case will be assessed.
Why ‘tech debt raises your capital requirement’ is the wrong claim
Do not claim that unresolved legacy risk automatically increases the firm’s regulatory capital requirement. From 1 January 2027, the PRA’s Basel 3.1 standardised approach is due to apply an Internal Loss Multiplier of 1. That removes the simple mechanical link between a firm’s historical operational losses and its Pillar 1 operational risk capital calculation.
That does not make legacy risk irrelevant to capital or supervision. Operational weaknesses and loss experience may still inform supervisory judgement and Pillar 2 assessments. The point is narrower. Avoid presenting a direct Pillar 1 capital increase as an automatic consequence of unresolved legacy technology risk. An overstated claim gives the committee a reason to question the credibility of the rest of the business case.
Use board language, not accounting claims
A quantified exposure still needs to be translated into language the audit and risk committee already uses. The objective is not to change the underlying analysis, but to present it in a way that supports informed board-level decision-making.
Impairment and contingent liability can be useful analogies. An under-performing technology asset may no longer deliver the value originally expected from it. Likewise, an unresolved technology weakness may represent a probable future cost whose timing or final amount remains uncertain. One board adviser has used these comparisons to help finance leaders frame unfunded technology work.
These are communication tools, not proposed accounting treatments. A legacy modernisation business case should not claim that legacy technology is formally recognised as an impaired asset or contingent liability unless the firm’s Finance and Audit functions determine that the relevant accounting criteria have been met.
Used carefully, these analogies change the conversation. The request is no longer simply that the CTO needs funding. It is that the organisation has a measurable operational exposure, constrained technology assets and an unfunded remediation obligation that requires a governed response.
Building the board pack. A governance-ready structure
A governance-ready board pack connects the quantified exposure to the evidence the committee needs to approve, oversee and monitor remediation. Each component should demonstrate not only why investment is required, but also how delivery will be governed and how progress will be measured after approval.
| Board-pack component | What it must demonstrate | Evidence to include |
|---|---|---|
| Quantified exposure | The cost range is repeatable, material and jointly owned. | Finance-approved assumptions, source data, low/base/high range and cost-of-delay view. |
| Risk and resilience | The exposure affects defined services, controls or risk appetite. | Risk register, important-business-service mapping, impact tolerances and scenario-test findings. |
| Regulatory relevance | The case reflects the firm’s current obligations, not a generic compliance claim. | Operational resilience self-assessment, applicable FCA/PRA rules and third-party dependencies. |
| Remediation roadmap | The firm can reduce exposure in controlled stages. | Named owners, milestones, decision gates, dependencies, exit criteria and rollback options. |
| Benefits and assurance | Progress and value can be independently measured after approval. | Outcome KPIs, control testing, reporting cadence, benefit owners and independent assurance points. |
This is the approach Catapult CX uses for legacy modernisation programmes. Rather than beginning with a single big-bang replacement, it starts with phased assessment, prototyping, Minimum Viable Replacement and controlled delivery. That gives the committee clear milestones, decision gates and measurable checkpoints against which progress and risk can be monitored throughout the programme.
Related reading: How to decide whether to modernise or replace once the case is approved.
Governance in practice. A UK financial services case study
Aldermore Bank needed to replace a legacy digital banking platform that was difficult to scale, slow to change and increasingly out of step with customer expectations. The programme also had to meet FCA, GDPR and Data Protection Act requirements throughout delivery.
Catapult CX used Minimum Viable Replacement to protect continuity, cloud infrastructure provisioned through Infrastructure as Code and DevSecOps practices embedded from the start. Private beta testing and controlled release reduced the risk of moving from the legacy platform.
The resulting platform went live with no major incidents. Business Savings NPS increased from 46.5 to 65.8 and peaked at 70.3. Process changes saved 91 hours per month, while self-service features saved a further 130 hours per month. These outcomes gave the business evidence of both controlled delivery and measurable value.
Read the full Aldermore case study.
Get the number approved, not just calculated
Calculating the cost of legacy technology and securing approval for remediation are two different disciplines. The first quantifies the exposure. The second demonstrates that the exposure is material, the proposed response is proportionate and the remediation programme can be delivered under effective governance.
A strong legacy modernisation business case is therefore co-owned. Technology provides the quantified model and delivery evidence. Finance validates the assumptions and expected benefits. Risk, Compliance and Operational Resilience connect the case to the firm’s existing obligations and approved risk appetite. The board receives one coherent decision supported by shared evidence, rather than several competing narratives.
If you would like an independent review before your business case goes to the board, audit committee or risk committee, Catapult CX can assess the roadmap, governance approach and supporting evidence to identify any gaps before approval.
Talk to Catapult CX about your legacy modernisation approach
FAQs
Why can a well-calculated legacy modernisation business case still be rejected?
Because the calculation alone does not demonstrate that the exposure is material, aligned with the firm’s risk appetite or supported by a credible remediation plan. Audit and risk committees also need clear ownership, governance, evidence and a way to monitor delivery after approval.
What should a legacy modernisation business case include?
A board-ready legacy modernisation business case should include a quantified exposure, supporting assumptions, links to operational resilience and risk appetite, a phased remediation roadmap, named owners, governance checkpoints, expected benefits and a reporting framework to measure progress after approval.
What does the FCA currently require around legacy technology and operational resilience?
The FCA does not prescribe a specific legacy modernisation programme. Firms in scope must be able to remain within impact tolerances for important business services and continue making the investments needed to do so. New operational incident and material third-party reporting rules come into force on 18 March 2027.
Does legacy tech debt automatically increase a bank’s regulatory capital requirement?
No. From 1 January 2027, the PRA’s Basel 3.1 operational risk approach is due to use an Internal Loss Multiplier of 1, so historical operational losses will not mechanically increase Pillar 1 operational risk capital. Legacy weaknesses can still influence supervisory judgement and Pillar 2 assessment.
How do you quantify the cost of legacy technology?
A legacy technology cost model typically combines direct costs, such as maintenance and support, with indirect costs including operational incidents, delayed change, technical debt, productivity losses, security exposure, regulatory risk and the opportunity cost of slower delivery.
What evidence should the audit or risk committee expect?
A defensible cost range, clear links to risk appetite and operational resilience, a phased remediation roadmap, named owners, measurable outcomes and a reporting cadence that allows the committee to monitor whether the organisation’s exposure is reducing over time.
Who should own the legacy modernisation business case?
It should be co-owned. Technology builds the cost model and remediation roadmap. Finance validates the assumptions and expected benefits. Risk, Compliance and Operational Resilience connect the case to the firm’s control framework, regulatory obligations and approved risk appetite.
What is a governance-ready board pack?
A governance-ready board pack connects the quantified exposure to the evidence needed for approval and ongoing oversight. It should include the cost model, risk and resilience evidence, regulatory context, a phased remediation roadmap, governance checkpoints and measurable outcomes so the board can monitor delivery after approval.