/ insights
The State Cannot See Itself
British government doesn't have a technology problem. It has a comprehension problem — it cannot understand or reconcile its own data — and the cost of that, paid by the taxpayer department by department, runs to the low tens of billions a year.
Before you read
By Aaron Gammon · Founder, Inferrex · June 2026
This is a piece of thinking, not a product pitch. It draws on 18 years selling data protection, automation, and enterprise software into government and large organisations; on what I now build for a living — a comprehension layer for business data; and increasingly on my own experience as a company director, and a patient, trying to deal with the state.
The argument is uncomfortable and parts of it are my interpretation rather than settled fact. Where I'm reading intent rather than reporting it, I say so. Where a point is my own first-hand observation rather than a published figure, I say that too. Every statistic that carries weight is sourced inline. The headline cost figure later in this piece is explicitly illustrative and built from numbers measured on different bases — I show my working and refuse to pretend it's a single audited total.
If you think I've got something wrong, that's the most useful thing you could tell me. The whole thesis is that understanding improves when someone shows you what you couldn't see from where you stand.
Part 1 — Let me start with my own week
I run a company. That means dealing with HMRC and Companies House constantly — personal tax, corporation tax, VAT, PAYE, statutory filings. And every time I sit down to do something that should take five minutes, I lose the first ten working out how to log in.
I have a Government Gateway ID. I also have a GOV.UK One Login. Some services want one; some want the other; some show me both options on the same screen and let me pick wrong. Companies House moved to One Login in October 2025 and made it mandatory (Pearson McKinsey). HMRC, as I write this, still runs primarily on Government Gateway and won't even begin migrating existing users until the end of 2027 (AllinAccountancy, Feb 2026). So for a multi-year window I am required, by design, to maintain two identities for the same government and guess which one each service speaks. The advisers handling this professionally report the predictable result: email mismatches between HMRC, Companies House and One Login accounts, and shared logins that can't be migrated at all (Plan A).
Then there's the DVLA, which in 2026 will still write me a letter. Not an email, not a portal notification — a letter, posted, that I wait for and post something back to. I'm not an edge case: 31% of DVLA driver transactions were still done fully or partially on paper, and the agency's own processes were, in the NAO's words, "designed around staff being on site" with IT "not designed for remote working" (NAO, 2023). Paper applications run 6 to 10 weeks; medical licences up to a year (BBC; Transport Forum, 2025). The absurdity compounds across organisations: Epilepsy Action notes that some people must first be refused a driving licence — a paper decision — before a council will issue a disabled bus pass (Epilepsy Action). One paper rejection, gating another paper application, across two bodies that can't see each other.
None of this is me being disorganised. It's the system working exactly as built.
The self-inflicted bill
Here's the part that should make every taxpayer wince. The login chaos isn't an accident of history that government is gracefully cleaning up. Government built it. By the time anyone counted, HMRC's own ecosystem had grown to roughly 191 different ways to set up an account and 44 different sign-in methods (Jupps Accountants, 2025). Forty-four. For one tax authority.
So now the state is spending £305m on GOV.UK One Login to consolidate the mess it spent two decades creating (Jupps Accountants, 2025). And here's the part that makes it worse than a simple cleanup bill: it still isn't fixed. I'm writing this mid-migration, still holding two identities, still guessing which service wants which — and the rollout doesn't even finish until the end of 2027. The £305m is being spent and the mess persists, simultaneously, for years.
That is the entire pattern in miniature, and it's the pattern to hold onto for the rest of this piece: government fragments its own data and access, lives with the inefficiency for years, then pays a fortune to bolt a single layer on top of the fragmentation it created — and is still mid-fix long after the money starts flowing. The £305m isn't the cost of progress. It's the cost of never having had a shared layer in the first place — the bill for incomprehension, itemised, and still running.
And One Login is the good version of this story, because at least it's an attempt at a shared layer. Most of government hasn't got that far.
Now scale that down to one MP's software bill
If you want the same disease at its most absurdly granular, look at how individual MPs buy software. There is no central procurement function purchasing tools on their behalf — IPSA confirms each MP is "legally responsible for all money claimed and for managing their budgets," with their own office-costs budget and their published expenses to show for it (IPSA). So 650 MPs each go shopping alone.
The results, from published expense data, are exactly what you'd expect when nobody is comparing notes: a QR-code generator billed at over £200 when Chrome makes them for free; a SurveyMonkey subscription when Parliament already provides Microsoft 365 with Forms built in; casework software that every single MP needs but that nobody has thought to negotiate a single bulk deal on. Take one MP's stack at roughly £2,000 a year, multiply across 650, and you're illustratively looking at on the order of £1.3m a year — with nobody negotiating volume, nobody checking whether the thing is already free, and nobody whose job it is to say "we already have that." (Those line items and that extrapolation are my own reading of published data, offered as illustration, not an audited total — but the structural point, that there is no central procurement function, is simply how the system is built.)
It's a rounding error against the headline numbers. But it's the same error: fragmentation by default, no shared layer, no one comparing notes — just at a scale small enough to see the whole thing in one glance.
Part 2 — The thesis, stated plainly
We talk about government IT failure as if it were a series of unlucky projects. It isn't. It's the visible surface of a single, structural condition: the British state cannot see itself. It cannot reliably tell that the citizen in one department's system is the same citizen in another's. It cannot gather consistent data about its own costs. It cannot reconcile what it knows across the silos it has accumulated over four decades of bolt-on digitisation.
Everything else — the scrapped programmes, the supplier lock-in, the legacy bill, the fraud losses, the digital ID scramble, the two logins and the letter from Swansea — is a downstream symptom of that one thing. Integration was never really the problem. Integration is a comprehension problem. Government isn't short of data about you; it's drowning in it. What it lacks is a shared, governed layer that sits above every system, understands what each field means, reconciles which source is authoritative, records where every value came from, and lets every system communicate through it — without forcing anyone to migrate or rename anything.
The rest of this piece does four things: counts what the incomprehension costs; shows that it isn't only between departments but inside each major service; explains why the structure guarantees it repeats; and sets out the fix.
Part 3 — The bill for not understanding itself
Start with the denominator. The UK public sector spends over £26bn a year on digital technology, according to the government's own State of Digital Government Review (GOV.UK, Jan 2025). That review makes three admissions that frame everything else: 28% of central government systems are legacy and the figure is rising; 47% of services still rely on non-digital methods like phone and paper; and that £26bn is roughly 30% below what comparable peers spend (DataCenterDynamics, 2025). This is not a state lavishing money on gold-plated technology. It's a state underspending and still wasting an enormous share of what it spends. The fix is not "spend more." It's "spend the existing money on systems that understand each other, instead of on maintaining and bridging systems that can't."
Here is what the incomprehension costs, in honestly-separate piles. Read them as a landscape, not a sum.
Keeping the dead alive (recurring). Roughly half the core government IT budget — about £2.3bn a year — goes on maintaining legacy systems, some over 30 years old (BBC, citing Cabinet Office), at three to four times the cost of modern alternatives (DataCenterDynamics, 2025). At department level, DWP and NHS England spend as much as 75–80% of their tech budgets just keeping the lights on (DataCenterDynamics, 2025). HMRC is the clean case: three of its eight costliest digital programmes in 2023-24 were remediation of legacy systems, with whole-life costs up 60% to 390% (The Register, 2025).
The productivity that never happens (recurring). Running one-in-four systems on obsolete technology carries an opportunity cost put at around £45bn in foregone savings (PDMS, citing NAO) — the modernisation and automation that can't happen because the systems can't be joined up.
Renting humans to bridge the gaps (recurring). Because the data won't reconcile itself and the in-house skills aren't there — digital staff are about 4.5% of the civil service against an 8–12% industry norm (The Register, 2023) — government rents people to bridge the gaps by hand. Consultancy spend rose roughly 75% between 2019 and 2023 (British Progress), and consultant fees have been put at around £14.5bn a year, at roughly three times the cost of a civil servant (TechMonitor, 2025). That is inefficiency hiring inefficiency.
Money out the door through the gaps (recurring). Fraud and error thrive in the spaces between departments that can't cross-check each other. The Public Sector Fraud Authority estimated public spending lost up to £58.8bn to fraud and error in 2020-21 alone (The Stack, citing NAO, 2025); DWP's accounts have been qualified for 37 consecutive years, with £9.5bn overpaid in 2024-25 (PAC, Feb 2026). The NAO's own conclusion is that breaking down inter-departmental data silos is critical to tackling it — and the government's response was to legislate the power to compel banks to share data (PAC, Feb 2026). When you have to pass a law to make your data join up, the real failure is that it was never designed to join up.
The graveyard of cancelled and ballooning programmes (one-off, historic). The pattern is always the same — a minister announces it, billions are committed, contracts go to the usual suspects, a reshuffle arrives, priorities change, and the thing is binned or bloated beyond recognition:
- NPfIT, the NHS national records programme — dismantled in 2011 having cost an estimated £10bn–£12.7bn for benefits later valued at around £2.6bn; still the largest failed civilian IT programme in the world (IEEE Spectrum).
- Universal Credit — its administration cost was first estimated at £2.2bn; the whole-life programme cost was put at £15.8bn by the Major Projects Authority in 2015, after the programme was "reset" and millions in IT development was written off (Computer Weekly, 2015). (Those two figures aren't measuring the same thing — one is admin, one is whole-life — but the trajectory, and the scrapped IT inside it, is the point.)
- The Emergency Services Network — around £3.1bn over budget (49%) and seven years late, and may never work as first intended (UK Campaign4Change).
- The MoD's Defence Information Infrastructure — the Ministry told Parliament it would cost £2.3bn while internally knowing the figure was at least £5.8bn, and the PAC later estimated £7.1bn (Wikipedia / PAC). Read that again: the department gave Parliament a number it knew to be less than half the real one.
- E-Borders — over £340m spent before cancellation, then £150m in settlement and £35m in legal costs fighting the supplier it cancelled on, with at least £830m sunk across the programme and its successors (NAO).
- C-NOMIS, a system meant to track offenders across the whole justice chain, trebled from £234m to £690m — and, tellingly, costs weren't monitored for three years partly because the responsible owner "did not have relevant project experience or training" (Silicon UK, citing PAC).
- FireControl — £469m wasted on regional control centres, some left empty. And the Post Office Horizon scandal — ~£600m on software so flawed it produced 700+ wrongful convictions and a compensation bill heading toward £1bn, destroying lives along the way.
One tally of these decades of disasters puts state IT-related failures at around £40bn (UK Campaign4Change). The NAO's auditor general called the broader failure to modernise "inexcusably wasteful," noting after 25 years of strategies a "consistent pattern of underperformance" — and that a third of contracts awarded by large government departments in 2021-22 weren't even subject to competition (IT Pro, citing NAO, 2024).
The order-of-magnitude figure — and why I won't pretend it's precise
Can these be added up? Not cleanly, and I won't pretend otherwise. The £45bn is an opportunity cost, not cash. The £58.8bn is a single exceptional pandemic year and includes losses that aren't purely a data problem. The graveyard is decades of one-offs, not an annual rate. Stacking them into one shiny number would be exactly the unprovenanced number-mashing I spend my working life arguing against.
But the order of magnitude is unavoidable, and worth stating as an illustration rather than an audit:
Illustrative, not audited. On a conservative recurring-annual basis — legacy maintenance (~£2.3bn), the consultancy premium driven by skills and integration gaps (a large share of ~£14.5bn), and the avoidable slice of fraud and error enabled by un-joined data (a fraction of figures reaching tens of billions) — the recurring annual waste attributable to government not comprehending its own data sits comfortably in the low tens of billions of pounds a year, with a multi-decade pile of cancelled-programme write-offs of around £40bn on top. Set against 37.4 million income-tax payers (HMRC, via UK Decline), even a conservative £10–20bn of recurring annual waste is £270–£535 per taxpayer, every year — for systems the government itself admits it underspends on and increasingly can't understand.
Disagree with the arithmetic and you're disagreeing with sourced public figures, not with me. But whether the honest recurring number is £10bn or £25bn, the conclusion doesn't move: the single largest controllable cost in government technology is not the technology. It's the incomprehension.
Part 4 — It isn't only between departments. It's inside each one.
When they dug the Channel Tunnel, the British and French teams bored toward each other from opposite coasts and met within a few centimetres — because both worked to one shared survey, one agreed specification, one common reference. Had each used its own datum, you'd have two expensive half-tunnels pointing at each other under the seabed, never connecting. All that effort, no tunnel.
That is how Britain has built the technology behind its biggest public services. Each part dug toward a shared goal using its own spec — and the halves never meet. And it's worth seeing that this happens not just between departments but inside each major service that the public thinks of as a single system.
The NHS: one body, hundreds of records
Here's the small, true thing that opened my eyes. People I trust who've worked inside the system — my mother-in-law was a Sister at Portsmouth's QA hospital, and I've put the same question to paramedics — describe a reality where a patient moved between hospitals routinely has equipment swapped and information re-gathered at the boundary, because the receiving site can't simply pick up where the last left off. I hit a version of it myself moving from NHS to private care for heart investigations: the work didn't travel with me cleanly; it largely started again.
Treat that as the illustrative, first-hand observation it is — and then look at whether it generalises. It does, overwhelmingly. Around 33% of hospital trusts still cannot electronically access patient data held outside their own walls (Netguru). A national study found that on roughly 11 million occasions — about 9.1% of patient interactions — a patient presented to a hospital using a different record system than their previous one, with "minimal coordination of health record systems between the hospitals that most commonly share the care of patients" (BMJ Open / PMC). More than 70% of trusts still run on a mix of paper and partial digital records, and the NHS spends around £230m a year on records management — three-quarters on paper storage alone (Civica).
The NHS doesn't lack data; it's trapped in incompatible silos, each procured separately and never specced to meet. "We have the systems," as one analysis put it. "What we lack is the integration that makes them useful" (PublicTechnology). And it won't fix itself: trusts procure independently, and vendors resist true interoperability and charge premium fees to integrate, because the gaps are a revenue stream (Zühlke). Giving high-performing trusts more autonomy over their IT risks worsening the fragmentation "without mandatory interoperability standards enforced at the national level" (Zühlke). When people say the NHS is on its knees, this is a large, invisible part of why — the daily friction tax of a hundred systems that can't read each other. Multiply my mother-in-law's small example by every ward, every handover, every year. That is the number.
Criminal justice: a chain whose links don't connect
Now a system that is, by definition, a sequence — police to prosecutors to courts to prisons to probation. A case is meant to flow down that chain, each link building on the last. The Ministry of Justice has admitted the problem in its own words: justice data is "held in large, disparate systems owned by different agencies — such as police forces, prosecutors, courts, prisons and probation services," which "makes it hard to share, and means staff may not have all the information when they need it" (MoJ Digital blog). Its own proposed fix — share data "from one definitive place, rather than passing it back and forth between multiple systems" — is an admission that today it doesn't.
The structural root is the absence of a shared reference: without a single identifier for a person or case, it becomes "nearly impossible to track individuals as cases move through the system from arrest to resolution" (Governing), with each link recording "different data points, tracking different metrics, performing different analyses" (Recidiviz). This is the tunnel failure with consequences measured in more than money: cases delayed, decisions made on partial information, people held or released against an incomplete picture.
Local government: 300 councils, 300 datums
The pattern repeats again at scale. Roughly 70% of public sector organisations say their data landscape is not well co-ordinated, interoperable, or able to provide a unified source of truth (techUK); 41% of council executives name legacy technology as the single biggest barrier to change (SysGroup, citing the LGA Almanac). From inside the sector: councils struggle to use their own data because "the varying platforms and systems used by different service areas hamper interoperability," and when one needs data from another body — say NHS patient data — "the problem is compounded by an endemic lack of standardisation. Each government organisation operates under its own security requirements, technology stack and data standards" (Manchester Digital). Every organisation its own datum; no shared survey; the tunnels don't meet.
The same fragmentation surfaces wherever you look — defence programmes wrestling with decades of incompatible legacy platforms, education data scattered across schools, trusts and agencies that don't reconcile. I won't claim precise figures I haven't verified in those two, so I'll put it no more strongly than this: this is not an NHS problem or a justice problem. It is the default condition of a state that has never specced its implementations to meet.
Part 5 — Why it never gets fixed: the structure guarantees it
Why doesn't this get solved? Because the structure that procures, builds, and staffs government technology actively prevents the long, patient comprehension work it would require.
Tenure versus timeline. The Infrastructure and Projects Authority puts the average ICT project at 8.5 years, and ICT carries the highest proportion of "red" (undeliverable) ratings of any category — about one in six (PublicTechnology, 2025). Against that, when Simon McDonald left the Foreign Office in 2020 he had worked, in five years as Permanent Secretary, for 22 junior ministers, four Foreign Secretaries and three Prime Ministers (civilservant.org.uk). A reshuffle resets the sponsorship of a programme that needs the better part of a decade to land. Britain has long been, in an LSE/Oxford study's phrase, a world leader in cancelling or producing non-functioning government IT (Prospect).
Capability versus dependency. Digital staff are about 4.5% of the civil service against an 8–12% norm (The Register, 2023), and the route to the most senior posts is almost sealed off from outside experience: across permanent secretaries, private and non-profit work accounts for only about 3% of total career experience (Institute for Government) — while around 20% of senior civil servants change role in a single year (civilservant.org.uk). Insular at the top, unstable in the middle. The PAC's verdict on the result: services "capable of only piecemeal and incremental change" (The Register, 2023).
Procurement versus access. The G-Cloud framework was built to break "the oligopoly of large suppliers" and let smaller, cheaper firms sell to the state. Around 90% of its suppliers are SMEs (Stotles, 2025) — yet roughly 65% of spend over five years went to large enterprises, the top 10 took about 75% since late 2024, and 75–80% of SME suppliers made no sales at all in a representative year (Stotles, 2025; Advice Cloud). The door opened; the route didn't. Smaller vendors still mostly reach buyers through large integrators and resellers who add margin and a services wrap — intermediation the taxpayer funds on top of the product.
Consequence versus its absence. And underneath all of it sits the thing that lets the pattern repeat forever: nobody carries the cost of getting it wrong. The C-NOMIS overrun ran unmonitored for three years partly because the person in charge lacked relevant project experience — and the system carried on regardless. The MoD told Parliament a number it knew was less than half the truth. In the private sector, if I sold a client a platform that tripled in cost and delivered nothing, I'd lose the account, my reputation, and my job — that afternoon. In government, you get rotated to another department and someone else inherits the mess. The minister who announced the programme has moved on; the officials who delivered it were there before and will be there after; and the structure offers no one whose job it is to say "we already have that," "that's ten times what it should cost," or "this isn't going to work." The decision-makers rotate, the delivery layer is permanent and largely shielded from market consequence, and the newcomers thrown into it often don't yet know which questions to ask. Politicians come and go. The structure stays. And nothing is ever anyone's fault.
This isn't a party point — it's true under every colour of government, because it's a structural condition, not a political one. Each of these failures is the same disease in a different organ. None of the incentives rewards the unglamorous, multi-year work of making the state's data comprehensible to itself. So that work never gets done — and the inefficiency renews every year.
Part 6 — The missing stable core
Here's the part that turns a cost analysis into a thesis. Every cost above is a symptom. The disease is that government has no stable core — no durable, governed layer of shared understanding that survives the people who happen to be in charge this year.
Think about how a well-run business actually works. A new CEO arrives with their own style, priorities, and pet projects. But the core of the business — what it sells, how it books revenue, who its customers are, the single source of truth about its own operations — stays stable. New leadership is additive: it builds on the core, redirects emphasis, opens new lines. What new leadership does not get to do is rip out the company's understanding of its own customers and rebuild it from scratch every time there's a change at the top. A leader who tried that — who destabilised the foundation rather than building on it — wouldn't last. The organisation's immune system would reject them, because the core is what keeps the business alive between leaders.
Government has this exactly backwards. The core — the data, the systems, the shared understanding of who citizens are and what the state knows — is the unstable layer, perpetually re-litigated, re-platformed, and re-procured. Meanwhile the people, who should be the changeable layer, turn over on a cycle far shorter than the systems they're meant to steward. The foundation shifts with every election and reshuffle; the people meant to hold it steady are gone before the project they sponsored is finished. No wonder the programmes get cancelled — they're foundations being poured by people who'll have moved on before the concrete sets, on ground the next arrival will dig up to pour their own.
That inversion is the whole problem. In a healthy organisation, the core is stable and leadership is additive. In government, leadership is the only constant and the core is what keeps getting rebuilt.
Part 7 — The fix: spec the join, not the systems
The lesson of the Channel Tunnel isn't "build one tunnel from one end." It's "let both teams dig from their own ends, with their own equipment and expertise — but bind them to one shared survey, so they meet." And the lesson of NPfIT is the equal and opposite warning: don't try to replace every local system with one giant central one, because that ignores how much works locally and how much a single mega-programme can lose. Replacement fails; pure autonomy fails. Both miss the same middle path.
That middle path is a comprehension layer: not a mega-system that replaces what every department, trust, force, and council already runs, but a shared, governed layer that sits above them and does four things, permanently, regardless of who's in office:
- Understands what each system's data means — reconciling that HMRC's taxpayer, DWP's claimant, the NHS's patient, Companies House's director, and DVLA's licence-holder can be facets of one person — without forcing any of them to rip out what works.
- Reconciles which source is authoritative for which fact, so the state has one answer to "what do we know about this person or business," not twelve conflicting ones.
- Tracks provenance — where every value came from, when it changed, which system is trusted for it — so the answer is auditable, not "the system says so."
- Persists across political cycles, because it's infrastructure, not policy. Ministers set priorities on top of it. They don't get to dig it up.
This is what I mean by a lingua franca for public-sector data — and it's the same principle behind what I build at Inferrex, which is why I see this pattern everywhere I look. A lingua franca doesn't abolish local languages; it sits above them and translates, getting richer as each new one joins. Aramaic, Latin, English: none won by decree. They won because the cost of not speaking the shared language became isolation, and adoption became inevitable through usefulness. A government data layer wins the same way — department by department, because using it beats not using it — or it doesn't win at all. But it has to be a binding shared reference, not a voluntary one, because, as the NHS evidence shows plainly, voluntary compliance yields predictably poor results (Zühlke) when vendors profit from the gaps and every part is free to dig to its own datum.
A layer like this is reshuffle-proof by design. A new minister can build a hundred new services on top of it without touching it — additive, exactly as new leadership should be. What they can't do is destabilise the core every four years. That's not a constraint on democratic control; it's what makes democratic control cheap, because each new administration inherits a state that already understands itself instead of one it has to teach from scratch.
The warning in the current plan
Every department is now being pointed at AI as the efficiency answer. But AI doesn't repair incomprehension — it industrialises it. Feed a model the same fragmented, unreconciled, unprovenanced data from systems that can't see each other, and you get the same wrong answers, faster and more confidently, trusted more because "the AI said so." The comprehension layer has to come first. Build the stable core — reconciled, authoritative, with lineage attached — and AI becomes genuinely transformative on top of it. Skip that order and you've spent the AI budget automating the £40bn mistake.
Part 8 — The bill we keep choosing to pay
You cannot shortcut comprehension. You can keep the dead systems alive, rent the consultants, write off the cancelled programmes, pass the law that forces the banks to share, spend £305m bolting a single login onto the sprawl, and ask 60 million people to introduce themselves again. Each is a payment on a debt that never reduces — because none of them builds the one thing that would make the debt disappear: a stable core that understands what the state already knows, and survives the people who pass through it.
So I'll end where I started: my own week. Two logins for one government. A letter from Swansea in 2026. Four facets of one taxpayer that no system reconciles. £305m to consolidate a login estate that should never have sprawled to 44 sign-in methods. 650 MPs each buying the same software alone. A patient's history that starts again at every boundary. A case file that can't flow cleanly from police to court to prison. Forty billion pounds of failed programmes, a department that told Parliament half the real number, and not one person who lost their job for any of it. None of it is a story about bad people, or even bad technology. It's a story about a state that never built the layer that would let it comprehend itself — and has chosen, for forty years, to keep paying the bill for the absence rather than build the thing that would end it.
The taxpayer isn't paying for technology. They're paying, in the low tens of billions a year, for a government that cannot see itself.
This is professional observation built on sourced public data and 18 years in the sector. The headline cost figure is explicitly illustrative and order-of-magnitude, built from individually-sourced figures on different measurement bases that should not be treated as a single audited total — the Universal Credit figures in particular mix an administration estimate with a whole-life programme cost, and are presented as a trajectory, not a like-for-like. The MP software figures and the ~£1.3m extrapolation are my own reading of published expense data, offered as illustration; the structural point (no central procurement function) is not in question. The digital ID and NHS equipment examples that informed this thinking are flagged in-text as interpretation and first-hand observation respectively, not as measured statistics; references to defence and education are deliberately qualified because I have not verified precise figures there. Tell me where it's wrong — that's how the argument gets closer to the truth.
Aaron Gammon — Founder, Inferrex · aaron.gammon@inferrex.com
Source Appendix
Sources are grouped by the part of the essay they support, in order of appearance. Where a figure originates with an official body (the NAO, PAC, IPA, a parliamentary committee, or a government department) but is quoted here via a secondary report, both are noted so the primary source can be traced. "Primary" denotes an official/government/peer-reviewed source; "Secondary" denotes journalism or industry analysis reporting on it.
Part 1 — The citizen and business experience (DVLA, Government Gateway / One Login, MPs)
- Pearson McKinsey — GOV.UK One Login: what directors and businesses need to know (Companies House One Login mandatory from Oct 2025). Secondary. https://www.pearsonmckinsey.co.uk/the-new-gov-uk-one-login-what-directors-and-businesses-need-to-know/
- AllinAccountancy (Feb 2026) — Government Gateway replaced by GOV.UK One Login (HMRC existing-user migration not beginning until end of 2027). Secondary. https://www.allinaccountancy.co.uk/post/government-gateway-replaced-by-gov-uk-one-login
- Plan A — GOV.UK One Login: what it means for businesses and directors (email mismatches; shared logins that can't be migrated). Secondary. https://www.plan-a.co.uk/gov-uk-one-login-what-it-means-for-businesses-directors-and-how-to-prepare-now/
- NAO (2023) — Investigation into the management of backlogs in driving licence applications (31% of DVLA transactions on paper; processes "designed around staff being on site"). Primary. https://www.nao.org.uk/reports/investigation-into-the-management-of-backlogs-in-driving-licence-applications/
- BBC News — DVLA: Apology over continuing driving licence renewal delays (paper applications 6–10 weeks). Secondary. https://feeds.bbci.co.uk/news/uk-wales-58266532
- Transport Forum (2025) — driver discussion of medical-licence waits up to a year. Secondary / anecdotal corroboration. https://www.transportforum.com/viewtopic.php?t=28551
- Epilepsy Action — Inquiry into DVLA finds significant delays for driving licence applicants (licence refusal required before a council bus pass). Secondary. https://www.epilepsy.org.uk/news/driving-licence-delays
- Jupps Accountants (2025) — HMRC replacing Government Gateway accounts with One Login (≈191 account setup routes / 44 sign-in methods; £305m One Login spend). Secondary, reporting figures from HMRC/GDS. https://www.juppsaccountants.co.uk/2025/03/13/%F0%9F%94%B9-hmrc-replacing-government-gateway-accounts-with-one-login-%F0%9F%94%B9/
- IPSA — A guide to MPs' business costs (each MP legally responsible for their own claims; no central procurement function; published per-MP expense data). Primary. https://www.theipsa.org.uk/a-guide-to-mps-business-costs
Part 3 — The bill: total spend, legacy, productivity, consultancy, fraud, cancelled programmes
- GOV.UK (Jan 2025) — State of Digital Government Review (£26bn annual digital spend; 28% legacy; 47% of services still non-digital). Primary. https://www.gov.uk/government/publications/state-of-digital-government-review/state-of-digital-government-review
- DataCenterDynamics (2025) — 28% of UK central gov't IT still considered "legacy" (legacy 3–4× modern cost; DWP/NHSE 75–80% on upkeep; spend ~30% below peers). Secondary, reporting the State of Digital Government Review. https://www.datacenterdynamics.com/en/news/report-finds-28-of-uks-central-govt-it-still-considered-legacy/
- BBC News — Keeping old computers going costs government £2.3bn a year (£2.3bn of £4.7bn IT budget on legacy; Cabinet Office Organising for Digital Delivery). Secondary, reporting Cabinet Office. https://feeds.bbci.co.uk/news/uk-politics-58085316
- The Register (2025) — Legacy systems running UK's tax collector (HMRC legacy remediation whole-life costs up 60–390%; IT "a significant risk"). Secondary, reporting NAO. https://www.theregister.com/2025/02/10/legacy_costs_hmrc/
- PDMS — How legacy systems are holding back UK public services (£45bn foregone productivity). Secondary, citing NAO. https://www.pdms.com/latest/how-legacy-systems-are-holding-back-uk-public-services/
- The Register (2023) — UK government hurt by delays in legacy tech upgrades, skills shortages (DDaT ≈4.5% of civil service vs 8–12% norm; PAC "piecemeal and incremental change"). Secondary, reporting PAC. https://www.theregister.com/2023/09/13/uk_government_efficiency_held_back/
- British Progress — Recruiting and retaining civil service technologists (consultancy spend +≈75% 2019–23; ≈70% on specialist gaps). Secondary. https://britishprogress.org/uk-day-one/recruiting-and-retaining-civil-service-technologists/
- TechMonitor (2025) — Legacy technology costs UK public sector £45bn annually (consultant fees ≈£14.5bn/yr; ≈3× a civil servant). Secondary, quoting the Technology Secretary. https://www.techmonitor.ai/government-computing/legacy-technology-costs-uk-public-sector-45bn-annually/
- The Stack (2025) — UK government fraud crisis (up to £58.8bn fraud and error 2020-21; NAO on data silos). Secondary, reporting NAO/PSFA. https://www.thestack.technology/uk-government-fraud-data-silos-nao/
- PAC (Feb 2026) — Tackling fraud and error in benefit expenditure 2024-25 (DWP accounts qualified 37 years; £9.5bn overpaid; new powers compelling banks to share data). Primary. https://publications.parliament.uk/pa/cm5901/cmselect/cmpubacc/1231/report.html
- IEEE Spectrum — NPfIT Dismantled (NHS national records programme; £10–12.7bn). Secondary, reporting Dept of Health / MPA. https://spectrum.ieee.org/npfit-dismantled-uk-government-announces-end-of-its-127-billion-national-electronic-health-record-program
- Computer Weekly (2015) — Universal Credit costs leap to £15.8bn (whole-life programme cost per MPA; admin estimate originally £2.2bn). Secondary, reporting Major Projects Authority. https://www.computerweekly.com/news/4500248772/Universal-Credit-costs-leap-by-more-than-20-to-158bn
- UK Campaign4Change — 43 years of state IT project disasters (Emergency Services Network £3.1bn over / 49% / 7 yrs late; FireControl £469m; Post Office Horizon; ≈£40bn cumulative). Secondary aggregation; individual figures traceable to NAO/PAC. https://ukcampaign4change.com/2022/01/27/43-years-of-state-it-project-disasters-and-theyre-still-happening/
- Wikipedia / PAC — Defence Information Infrastructure (MoD told Parliament £2.3bn while knowing ≥£5.8bn; PAC estimate £7.1bn). Secondary summary of Public Accounts Committee findings; primary PAC report at publications.parliament.uk/pa/cm200809/cmselect/cmpubacc/100/. https://en.wikipedia.org/wiki/Defence_Information_Infrastructure
- NAO — Home Office: e-borders and successor programmes (£340m+ on programme; £150m settlement; £35m legal; ≥£830m across successors). Primary. https://www.nao.org.uk/reports/home-office-e-borders-and-successor-programmes/
- Silicon UK — Prison IT System Branded "A Shambles" (C-NOMIS £234m → £690m; owner lacked project experience). Secondary, quoting PAC. https://www.silicon.co.uk/e-regulation/prison-it-system-branded-a-shambles-2320
- IT Pro (2024) — UK government IT spending is "inexcusably wasteful" (NAO auditor general Gareth Davies; a third of large-department contracts 2021-22 not subject to competition). Secondary, quoting NAO. https://www.itpro.com/business/digital-transformation/uk-government-it-spending-is-inexcusably-wasteful-as-millions-lost-maintaining-outdated-systems
- HMRC, via UK Decline — UK Failed Projects Database (37.4m income-tax payers, used for the per-taxpayer calculation). Secondary presentation of HMRC 2024-25 income-tax-payer statistics. https://ukdecline.co.uk/failed-projects
Part 4 — Within-sector interoperability (NHS, criminal justice, local government)
- Netguru — Why Healthcare Interoperability Still Fails (≈33% of trusts can't access outside patient data). Secondary, citing NHS digital-maturity data. https://www.netguru.com/blog/healthcare-interoperability-uks-emr-systems
- BMJ Open / PMC — Improving data sharing between acute hospitals in England (≈11m occasions / 9.1% of interactions on a different record system; minimal coordination between hospitals sharing care). Primary (peer-reviewed). https://www.ncbi.nlm.nih.gov/pmc/articles/PMC7008454/
- Civica — One Patient, Many Systems (70%+ of trusts part-paper; ≈£230m/yr records management, three-quarters on paper storage; five systems / five logins). Secondary. https://www.civica.com/en-gb/insights/one-patient-many-systems/
- PublicTechnology — Interoperability in NHS cancer care ("We have the systems. What we lack is the integration that makes them useful"). Secondary. https://www.publictechnology.net/2025/04/23/partner/interoperability-in-nhs-cancer-care-fixing-the-digital-disconnect/
- Zühlke — Why NHS transformation depends on interoperability (trusts procure independently; vendors resist interoperability and charge premium fees; autonomy risks more fragmentation; voluntary compliance fails). Secondary. https://www.zuehlke.com/en/insights/digital-foundations-why-nhs-transformation-depends-on-interoperability
- MoJ Digital blog — Opening up data in the criminal justice system (justice data in "large, disparate systems owned by different agencies… staff may not have all the information"). Primary (government department). https://mojdigital.blog.gov.uk/2015/12/01/opening-up-data-in-the-criminal-justice-system/
- Governing — Bridging the Data Gap in Criminal Justice (no unique identifier; impossible to track individuals arrest-to-resolution). Secondary; illustrative of the general pattern. https://www.governing.com/policy/bridging-the-data-gap-in-criminal-justice
- Recidiviz — Unleashing Public Data Creates a Smarter Criminal Justice System (each part records different data points, tracks different metrics). Secondary; illustrative of the general pattern. https://www.recidiviz.org/updates/unleashing-public-data-creates-a-smarter-criminal-justice-system
- techUK — Devolution, local government reorganisation and the future of local services (70% of public sector orgs say data not co-ordinated/interoperable/single source of truth). Secondary (industry body). https://www.techuk.org/resource/devolution-local-government-reorganisation-and-the-future-of-local-services.html
- SysGroup — The Infrastructure Problem at the Heart of UK Council Cyber Risk (41% of council execs name legacy as biggest barrier, citing the LGA Digitalisation Almanac). Secondary, citing LGA. https://www.sysgroup.com/insights/the-infrastructure-problem-at-the-heart-of-uk-council-cyber-risk/
- Manchester Digital — Four digital, data and technology challenges slowing local government ("Each government organisation operates under its own security requirements, technology stack and data standards"). Secondary. https://www.manchesterdigital.com/post/made-tech/four-digital-data-and-technology-challenges-slowing-local-government-evolution
Part 5 — Structure: tenure, skills, procurement, accountability
- PublicTechnology (2025) — Major projects: £26bn ICT category has highest proportion of red ratings (8.5-yr average ICT delivery; ≈1 in 6 rated red). Secondary, reporting the IPA Annual Report. https://www.publictechnology.net/2025/01/17/education-and-skills/major-projects-26bn-ict-category-has-highest-proportion-of-red-risk-ratings/
- civilservant.org.uk — Permanent Secretaries (Simon McDonald: 22 junior ministers, 4 Foreign Secretaries, 3 PMs in 5 years). Secondary reference site, citing public record. https://www.civilservant.org.uk/information-dismissal-permanent_secretaries.html
- Prospect — Public sector IT failures (LSE/Oxford Dunleavy/Margetts study: Britain a world leader in cancelled/non-functioning government IT). Secondary, reporting academic research. https://www.prospectmagazine.co.uk/essays/56986/public-sector-it-failures
- Institute for Government — How permanent secretaries reach the top (private/non-profit ≈3% of total career experience). Primary (research institute). https://www.instituteforgovernment.org.uk/article/comment/how-permanent-secretaries-reach-top
- civilservant.org.uk — Senior Civil Service pay (≈20% of senior civil servants changed role in 2023-24; SSRB on "excessive churn"). Secondary reference site, citing the Senior Salaries Review Body. https://www.civilservant.org.uk/information-pay-scs.html
- Stotles (2025) — From 14 to 15: the G-Cloud supplier playbook (≈90% of suppliers SMEs; ≈65% of 5-yr spend to large enterprises; top 10 ≈75% since Nov 2024). Secondary analysis of CCS spend data. https://www.stotles.com/resource/report/from-14-to-15-the-g-cloud-supplier-playbook
- Advice Cloud — G-Cloud & DOS FY 2022/23 review (75–80% of SME suppliers made no sales in a representative year). Secondary analysis of CCS spend data. https://advice-cloud.co.uk/knowledge-hub/g-cloud-dos-fy-2022-2023-review/
A note on source tiers
The load-bearing claims — total digital spend, legacy proportion, fraud and error, the project failures, contract competition, ICT delivery timelines — rest on primary sources: the NAO, the Public Accounts Committee, the Infrastructure and Projects Authority, the State of Digital Government Review, IPSA, a peer-reviewed BMJ study, and government departments' own statements. Secondary sources (journalism and industry analysis) are used where they report those primary findings clearly, and are labelled as such above so the original can be traced. The two US-based criminal-justice references (Governing, Recidiviz) are included only to illustrate that the fragmentation pattern is structural and not unique to the UK; the UK-specific claim in that section rests on the Ministry of Justice's own words (source 33). Anecdotal and illustrative material — the DVLA forum post, the MP expense line items, the NHS equipment observation — is identified as such in the text and is not relied upon for any quantitative claim.

