Case Study
IT Governance
02
Operationalizing IT Governance
Empowering a Federal Aerospace Agency to Autonomously Manage a Multi-Billion Dollar IT Portfolio
Executive Summary
A prominent Federal Aerospace Agency needed to operationalize a nascent IT Governance and Capital Planning and Investment Control (CPIC) framework to manage a complex, multi-billion-dollar IT portfolio. Serving as the primary IT Governance and CPIC Subject Matter Expert, we bridged the gap between high-level strategy and tactical execution, modernizing manual data collection into automated, criteria-driven workflows. The engagement successfully produced a federated governance model, empowering the agency’s Center to autonomously govern its 250 IT investments, meet strict FITARA mandates, and integrate seamlessly with the annual PPBE lifecycle.
Client Profile
Client Type:
Aerospace & Scientific Center
Mission Domain:
Enterprise IT Governance, CPIC, and Financial Systems
The Challenge
The Center possessed a foundational IT governance framework on paper, but it had not been stress-tested or fully operationalized to drive executive decision-making. With a multi-billion-dollar portfolio spanning 250 investments—including five Major IT investments across three Centers—the Center needed to synthesize its CPIC processes with day-to-day IT Governance and Strategic Sourcing.
A significant hurdle was the heavy reliance on cumbersome, manual Excel spreadsheets to collect IT investment data during the annual Planning, Programming, Budgeting, and Execution (PPBE) kick-off. The customer required a sustainable, transparent, and modernized system to evaluate, prioritize, and justify future IT investments while ensuring strict regulatory compliance.
The Approach
Stepping in to evolve the program from analytical support to full program management, our embedded expert architected a comprehensive roadmap to shift the organization from a theoretical framework to active, transparent governance.
Criteria Development:
Established formalized CIO IT Investment Criteria to consistently evaluate and prioritize which IT investments would receive funding in future years.
Stakeholder Alignment:
Developed formal Charters and Roles & Responsibilities documentation for each governing board to ensure clear accountability and demonstrate the value of their participation.
Cultural Readiness:
Orchestrated a highly structured schedule of strategic "roadshows" and kick-off meetings. This proactive change management prepared the broader IT community for the massive data collection and reporting exercises required for CPIC compliance.
Solution & Execution
The execution focused on connecting daily operations—such as overseeing SAP IT purchase approvals and C-SCRA requests—with overarching strategic goals to ensure continuous alignment and modernize legacy processes.
Modernizing Data Collection:
Created the agency’s first centralized "Reviewed and Approved Vendors" list, implementing rigorous tracking and recording mechanisms.
Operational
Rhythm:
Built comprehensive internal resource libraries, training modules, and intranet sites to educate stakeholders and integrate C-SCRM into the agency's daily operations.
Executive
Facilitation:
Conducted high-level briefings for the CIO and Cybersecurity Director, presenting complex supply chain vulnerabilities, SCRA findings, and actionable mitigation strategies.
Cross-Functional Synthesis:
Integrated the CPIC lifecycle directly into IT Governance and Strategic Sourcing workflows to instill discipline, transparency, and accountability across the enterprise portfolio.
Outcomes & Impact
By fully operationalizing the governance framework and modernizing data collection, we delivered massive strategic value and localized control to the Center over its future IT infrastructure:
Massive Cost Avoidance:
Streamlined Decision-Making:
The automated PPBE survey dynamically filters the 250 investments against the CIO's criteria,
instantly identifying which projects require Center-level governance versus those cleared for decentralized execution, drastically reducing administrative bottlenecks.
Federated Governance Achieved:
Successfully implemented
a federated model that incorporated input from local Directors,
enabling them to directly influence and evolve the Center's future IT infrastructure both strategically and operationally.
Operational Autonomy:
Empowered the Center to become one of the few within the overarching enterprise with the maturity and authority to govern its own IT spend,
significantly reducing its reliance on broader Agency enterprise services for projects and programs.
Regulatory Compliance & Financial Readiness:
Fully aligned the multi-billion-dollar portfolio with FITARA mandates
and the stringent requirements of the annual PPBE budget exercise, ensuring defensible, audit-ready financial reporting.
Key Differentiators
Strategic to Tactical Bridge:
Demonstrated the unique capability to not only design high-level CPIC strategies but also operationalize them into daily IT operations, procurement workflows, and supply chain risk assessments.
Process
Modernization:
The ability to identify legacy bottlenecks (like manual Excel data calls) and engineer automated, criteria-driven solutions that save time and improve data integrity.
Change Management Expertise:
Successfully navigated complex IT environments and varied stakeholder priorities to drive the adoption of new, rigorous governance models across 250 distinct investments.
Scalable
Leadership:
Showcased a seamless transition from providing foundational project support to executing full-scale program management over a highly visible, multi-billion-dollar federal IT portfolio.
See more of our Case studies
Ready to work
with us?
Every engagement starts with a conversation. The right partner should make complex work feel clearer, not heavier. At Qoral, we take the time to understand your goals, constraints, risks, and operating environment before recommending a path forward. Reach out to start a conversation about where you are, what you need, and how we can support your next step. Whether you need strategic guidance, compliance support, or a trusted partner for IT initiatives, Qoral is here to help.

