Summary
A strategic vision is not an acceptance specification. Collecting and checking passenger information before travel was a legitimate objective, but delivery required testable data, workflow, availability, integration and stakeholder obligations.
Requirements risk cannot simply be priced away. A fixed-price, milestone-led contract was poorly matched to high-level requirements, changing interfaces and dependencies on hundreds of carriers and public bodies.
Departmental and supplier accountability coexist. The public record identifies Home Office shortcomings in strategy, capability, governance and stakeholder management, while also preserving the Department's position that Raytheon missed milestones and failed contractual obligations.
Termination is a controlled programme, not a single notice. Evidence of default, contractual procedure, proportionality, asset transfer, service continuity and litigation exposure must be governed together.
The legal sequence must remain exact. The arbitral award, the High Court challenge and set-aside, and the £150 million settlement without admission of liability were distinct stages.
Operational evidence survives the contract. Passenger-data completeness, accuracy, matching, coverage, system performance and benefit measures remain essential after a supplier exit or programme reset.
The ambition was operationally important and institutionally demanding
The core idea behind e-Borders was straightforward to state. The United Kingdom wanted more information about people travelling to and from the country before they reached the physical border. Carriers would provide passenger, crew and service data. Systems would compare information with police, security and immigration watchlists and support decisions by border and law-enforcement organisations. Better advance information could help identify persons of interest while facilitating legitimate travel.
That statement, however, contains several different systems. It contains legal authority to require information, technical connections to hundreds of carriers, data definitions, message timing, identity matching, watchlist governance, analyst workflows, operational responses, security accreditation, service availability and mechanisms for correcting poor-quality data. It also involves multiple agencies whose priorities are not identical.
The 2008 parliamentary answer describing passenger-data requirements distinguished travel-document information from other passenger information and described the expectation that commercial carriers and vessel operators would submit passenger, service and crew data before journeys. That record demonstrates the breadth of the intended information supply. It does not prove that every route, carrier system, data field or operational use had been converted into a settled and technically feasible requirement.
Public-technology accountability begins by separating an outcome from a product. “Know who is coming and who has left” is an outcome. A product requirement says which messages arrive, from whom, at what point, in which format, with what error tolerance, and what happens when information is late or inconsistent. A service requirement defines throughput, availability, recovery time, security classification and support. An operational requirement defines which official sees an alert, how it is resolved and how false matches are handled.
This decomposition matters because a supplier can deliver software that conforms to an abstract description while users still cannot achieve the intended result. Conversely, a department can change an operational practice or legal rule in a way that makes a previously plausible design obsolete. Accountability must therefore preserve a chain from public outcome to business process, data contract, technical component, acceptance test and measurable benefit.
The chain also establishes ownership. Ministers own policy choices and public commitments. The Senior Responsible Owner owns the programme outcome and key trade-offs. Business owners define how capability changes work. Data owners define quality and lawful use. Commercial leaders construct incentives and remedies. Technical leaders judge feasibility and integration. Suppliers own the work and risks actually allocated to them. Carriers and partner agencies own agreed contributions. Blurring these roles turns every later dispute into a contest of narratives.
High-level requirements collided with a fixed commercial commitment
After planning, piloting and procurement, the Home Office entered a contract with Raytheon in November 2007. The National Audit Office later described a fixed-price arrangement in which payments were linked to milestones. The supplier was expected to develop a solution against high-level requirements within a demanding schedule. That structure attempted to transfer substantial delivery risk.
The NAO's e-Borders report page records the wider conclusion: the Department spent at least £830 million between 2003 and 2015 on e-Borders and successor programmes, developed valuable capabilities, but had not delivered the full vision. The number covers several programmes and periods. It should not be represented as a payment to Raytheon, a legal damages figure or proof that all expenditure lacked value.
The detailed NAO e-Borders and successor programmes report explains why the commercial model was fragile. The high-level requirements and Raytheon's proposed design were incorporated into the contract but attracted different interpretations. The report found that fixed price and deadline transferred risks that were not sufficiently defined or manageable, and that the criticality of the infrastructure meant the Department would require more control over the solution than the arrangement could comfortably support.
A fixed price is not inherently unsound. It works best when the buyer can define the deliverable, suppliers can estimate the work, dependencies can be controlled and acceptance can be decided objectively. It becomes hazardous when the buyer retains strong design influence but the contract assumes that design risk has moved, when interfaces change, or when external stakeholders determine whether deployment can proceed.
The central control is a requirements baseline with named uncertainty. Each requirement should have a source, owner, rationale, priority, dependency, test method and version. Open decisions should not hide inside apparently final prose. They should appear in a decision log with a due date, authority and consequence if unresolved.
High-level outcome requirements can coexist with iterative development, but they need discovery stages and commercial checkpoints. A design phase can establish carrier constraints, prototype data flows and produce an agreed architecture before the buyer authorises a broad build. Modular work packages can isolate risk and give both sides evidence about velocity and feasibility. A fixed commitment made before that evidence exists does not eliminate uncertainty; it determines where conflict over uncertainty will surface.
Acceptance criteria are especially important. Design approval can mean permission to proceed, confirmation that a document is complete, or agreement that a solution meets the contract. Those meanings are not interchangeable. A controlled acceptance record should state what was reviewed, which requirement version applied, which tests passed, which exceptions remain and whether approval changes risk ownership.
Change control had to distinguish clarification from new work
In a complex border system, change is inevitable. Threats evolve, legislation changes, carrier technology varies, agencies revise processes and new security constraints appear. The governance failure is not change itself. It is the inability to decide whether a request clarifies an existing obligation, corrects a supplier defect, changes the solution within allocated risk or adds new scope requiring time and money.
The September 2010 parliamentary record on contract specifications shows that Parliament asked about changes to scope, the location of the National Border Targeting Centre, security-clearance requirements and European data-protection implications. The ministerial answer maintained that termination followed consideration of the issues and supplier performance. A parliamentary answer is an official statement of the government's position, not an independent adjudication of which disputed change caused which delay.
The NAO later identified unresolved changes involving the targeting-centre location, interfaces with carriers and government agencies, less structured passenger information, robustness and disaster recovery. It reported disagreement about the clarity of the original requirements, the proposed solution and how new work should be priced. Those findings support shared causal analysis. They do not erase the supplier's delivery duties, and they do not make every supplier delay a departmental change.
A useful change record has two layers. The operational layer states why a change is needed, which users and risks it affects, what happens if it is deferred and how it will be tested. The commercial layer states contractual classification, cost, schedule effect, dependencies and authority. If the classification is disputed, the parties can preserve their positions while authorising bounded work, rather than allowing a legal disagreement to stop all engineering.
The programme also needs a requirements trace that survives change. When a data interface changes, leaders should be able to identify affected components, carrier onboarding, tests, security assurance, operational procedures and benefits. Without that trace, local changes accumulate into unmeasured programme drift.
Change budgets should be explicit. A programme may reserve money and schedule for predictable evolution without conceding that every request is payable. Thresholds can route small clarifications through delivery governance and strategic changes through investment and commercial review. Trend information—volume of requests, ageing disputes, repeated requirement families and rework—reveals whether the baseline is deteriorating.
The objective is not to win each classification argument. It is to prevent ambiguity from becoming a hidden queue of work whose cost, schedule and operational consequence emerge only during milestone acceptance or termination.
Carriers and agencies were part of the delivery system
e-Borders depended on data from air, maritime and rail operators and on use by multiple government organisations. A contract with one technology supplier could not compel every external party to change systems, provide complete messages, resolve data-quality errors or redesign operational processes on the programme's timetable.
The NAO described more than 600 stakeholders and found that the Department underestimated the importance of managing them. Ferry routes posed particular practical challenges, and some early feasibility work was not retained. Requirements and schedules that assume stakeholder participation without a verified commitment convert external dependency into hidden delivery risk.
Stakeholder management is not a communications plan added after technical design. It is part of architecture and scheduling. Each entity needs a defined data or service obligation, legal basis, onboarding route, test environment, support model, readiness criteria and escalation path. The programme must know which routes are covered, which messages are provided and where exceptions are material.
Carrier readiness should be represented as evidence, not percentage optimism. A route can be technically connected but send incomplete records. A carrier can pass a test but fail at production volumes. One voyage message does not prove that data arrived for every passenger. Measures must reflect the operational question being asked.
Agency participation requires equal discipline. Security, immigration, customs, police and border operations may use the same information differently. Their definition of a useful alert, permissible access, response time and false-positive tolerance may diverge. A common platform needs an agreed data model and governance that preserves lawful, role-specific use.
The consequence for commercial allocation is clear. A prime supplier can be responsible for interface software, onboarding support and reporting. It cannot fairly carry unlimited schedule risk for a carrier or agency the Department has not enabled or directed. The buyer, meanwhile, cannot cite an external dependency as a complete excuse if it failed to obtain commitments, stage deployment or adapt the plan.
A dependency register should therefore identify a named owner on both sides, evidence of commitment, latest feasible decision date, contingency and impact on each milestone. Senior governance should review the few dependencies capable of defeating an outcome, not merely a long list of routine actions.
Milestones needed proof of usable capability
Milestone payment can focus attention and protect public money, but only if a milestone represents verifiable progress. Document production, code completion, technical installation, user acceptance and operational capability are distinct states.
The Home Office's July 2010 statement cancelling the contract said critical parts were at least twelve months late, cited missed milestones and quality issues, maintained that the supplier had not complied with contractual obligations, and required a smooth handover. This is the Department's contemporaneous termination position. Later arbitration and court proceedings mean it must not be presented as the final legal resolution of all responsibility.
For a milestone to be accountable, its evidence pack should identify requirement versions, completed components, test data, defects, security status, dependency exceptions, user readiness and operational limitations. Sign-off should be split where necessary: technical acceptance does not automatically equal business acceptance, and business acceptance does not waive unresolved commercial claims unless the document says so.
The programme should also track leading indicators. Milestones are intermittent and can conceal deteriorating design quality, integration backlogs or unresolved decisions. Measures such as test pass rate, defect escape, interface readiness, requirement volatility, decision age and onboarding throughput give earlier warning.
The NAO found that the parties did not establish agreed acceptance criteria for design approval and that disputes arose quickly. It also described limited public evidence integration of subcontractor work and overlapping phases. These are programme-control findings, not a court's final allocation of contractual liability. They show why both the buyer and prime contractor need a common technical baseline.
Independent assurance can test whether a milestone is substantively meaningful. Assurance should examine evidence samples, not simply report whether the programme board has received a green status. Where evidence is incomplete, an amber acceptance with explicit conditions and retained payment may be more honest than either blanket rejection or unconditional approval.
Benefits must also attach to capability. Receiving more data is not itself the full benefit. The programme needs to know whether information is timely and accurate, whether alerts are usable, whether decisions improve, whether staff effort changes and whether legitimate passengers move efficiently. A milestone without an operational benefit hypothesis can complete while the public outcome remains distant.
Departmental capability was an accountability control
The buyer of a major technology programme cannot outsource understanding of its own business. It needs people who can translate policy into operations, challenge architecture, manage data, decide changes, assess commercial evidence and preserve institutional memory.
The NAO reported leadership turnover and gaps in programme capability. It also described a culture that did not always convey bad news clearly enough. Those conditions make it harder to maintain a stable requirements baseline, distinguish performance problems from buyer-caused change and make timely decisions.
Leadership continuity does not require one person to remain forever. It requires a durable operating record. Decision logs, architecture rationales, requirements history, commercial positions, test evidence and risk ownership should be intelligible to a successor. A handover based on presentations and memory is limited public evidence when a programme spans policy cycles and supplier disputes.
The Public Accounts Committee's 2016 summary of e-Borders and successor programmes emphasised continuing failure to deliver the full vision and the cost of programmes and settlement. Committee language is parliamentary scrutiny and should be attributed as such. It is valuable because it tests whether the Department converted earlier lessons into a credible plan.
The Committee's conclusions on commercial approach, leadership and delivery challenged the suitability of the fixed-price model for a programme whose requirements and environment were not stable. It also called for clearer plans, benefits and staff continuity. These recommendations point to an institutional control: the Department must be an intelligent owner even when suppliers perform much of the build.
An intelligent owner maintains a minimum internal capability. It can explain the target operating model, determine the authoritative requirement, understand the end-to-end architecture, assess data quality, interpret delivery evidence and forecast the operational effect of change. External expertise can supplement this team but should not become the only holder of knowledge needed to replace or challenge a supplier.
Capability also includes decision speed. A technically sophisticated department can still fail if approvals are fragmented and suppliers wait for direction. Governance should make authority visible: which forum decides policy, architecture, scope, commercial classification, acceptance, security and operational deployment, and how quickly each decision must be made.
Supplier performance and buyer conduct had to be analysed separately
Public debate often seeks one root cause. Complex delivery rarely supplies one. A disciplined account separates supplier performance, departmental programme management and environmental change, then examines interaction among them.
Supplier performance includes staffing, consortium integration, design quality, schedule management, defect correction, risk escalation and compliance with accepted obligations. Departmental conduct includes requirement quality, stakeholder commitments, approvals, change decisions, governance, resourcing and accurate reporting. Environmental change includes law, threats, security classification, passenger volumes and other programmes.
The NAO reported problems across these categories. It described Raytheon as ill-placed to manage the transferred risks and identified design and consortium integration issues. It also found the Department's commercial approach ill-conceived, its requirements too high-level, its stakeholder assumptions unrealistic and its programme management weak. Raytheon disputed aspects of the Department's account and attributed delays and costs to changes and dependencies.
That record does not demand false equivalence. Evidence may show one party responsible for a particular event. It demands event-level attribution. For each missed milestone, the record should state the required result, baseline date, actual evidence, dependencies, approved changes, notices, mitigation and causal assessment. Programme-wide labels are not a substitute.
The analysis should also distinguish entitlement from performance. A supplier may be entitled to payment for a customer change while still performing poorly elsewhere. A department may have legitimate grounds to reject a milestone while also having contributed to delay. Resolving one proposition does not decide the other.
This separation supports intervention before termination. A cure plan can define specific breaches, owner actions, stakeholder dependencies, evidence and deadlines. It can reserve rights without making recovery impossible. If the plan fails, the same evidence supports a more controlled exit.
No part of this institutional analysis implies wrongdoing by any named individual. The public sources concern programme structures, party positions, audit findings and legal procedures. They do not support personal allegations of dishonesty, corruption or criminality.
Termination required its own evidence architecture
Terminating a technology contract is not the opposite of delivery. It is a high-risk delivery phase. The public institution must protect operations, preserve evidence, control access, obtain assets and knowledge, manage staff and subcontractors, procure replacement services and comply with the contract's decision process.
The termination decision should begin with a clean record of grounds. It should map each alleged failure to a contractual obligation, notice, evidence and cure opportunity. It should distinguish historic breach, continuing breach, delay caused by dependencies and commercial disagreement. Legal advice, technical evidence and programme judgment should remain identifiable rather than blended into a single conclusion.
Decision-makers also need options. Continue under the existing contract, renegotiate, reduce scope, step in, terminate part, terminate for cause or terminate for convenience may have different costs and continuity consequences. An options paper should include realistic transition time, asset rights, data access, staff knowledge, supplier claims and the risk of operating legacy systems longer.
The Department publicly maintained that termination was the appropriate response. Its 2014 letter announcing the arbitral award said the government stood by the decision, while acknowledging the tribunal's concerns about contract management and the termination process. The same letter stated that the tribunal's ruling did not decide whether Raytheon had defaulted or whether termination was substantively justified. That boundary is essential.
A termination governance pack should preserve the contemporaneous record. It includes the authoritative contract and amendments, performance notices, meeting minutes, test evidence, correspondence, commercial claims, risk assessments, advice and decision approvals. Retention should be locked before relationships deteriorate further. Selective reconstruction after litigation begins weakens both accountability and defence.
The process also requires independence. People deeply involved in a disputed programme may supply evidence, but an exit board should test whether the grounds, procedure and transition plan are complete. Commercial, legal, technical, security, operational and finance perspectives must all be represented.
Procedural discipline is not bureaucracy that shields a poor supplier. It protects the public decision. A well-founded substantive concern can still generate avoidable liability if notices, consideration of evidence or contractual steps are defective. Conversely, procedural compliance cannot make a weak performance case strong. Both are needed.
The arbitral award was one stage, not the final public record
After the 2010 termination, Raytheon disputed its validity. The Home Office initiated arbitration. In August 2014 the tribunal issued an award that treated the termination as wrongful and made substantial monetary awards, including damages, disputed change notices and an amount for transferred assets, with interest.
Arbitration is a legal process, and the award had legal significance. But the Home Secretary's 2014 account expressly said the tribunal had not passed judgment on whether Raytheon defaulted or whether the substantive decision to terminate was justified. Instead, it focused on how the contract was managed and the termination decision and process.
The first High Court judgment, Secretary of State for the Home Department v Raytheon Systems Ltd [2014] EWHC 4375 (TCC), concerned a challenge under section 68 of the Arbitration Act 1996. The court found serious irregularity arising from failure to deal with issues put to the tribunal, causing substantial injustice. It was a review of the arbitral process under the statutory standard, not a trial producing a comprehensive final allocation of programme blame.
The later judgment, Secretary of State for the Home Department v Raytheon Systems Ltd [2015] EWHC 311 (TCC), addressed the remedy. The court set the award aside and contemplated a fresh tribunal, while granting permission to appeal. Setting aside removed the award's operative resolution; it did not automatically prove the Department's performance allegations or negate every Raytheon claim.
This sequence is often compressed into a misleading headline. “Raytheon won arbitration” omits the successful court challenge. “The Home Office won in court” can imply a merits determination the court did not make. An accurate record states what each decision decided, what it did not decide and what procedural step remained available.
The accountability lesson is that exit exposure cannot be measured only as expected damages. Legal process consumes leadership, records, expert evidence, continuity planning and public confidence. A programme should maintain a live dispute map showing claims, defences, evidence gaps, procedural milestones, asset positions, costs and settlement authority.
That map also helps Parliament and auditors. Confidentiality may limit disclosure during proceedings, but the institution can still preserve a controlled internal explanation and later provide a reconciled account when legal constraints permit.
The final settlement closed claims without admitting liability
In March 2015 the government and Raytheon reached a negotiated resolution. The Home Office letter announcing the settlement described a full and final payment of £150 million, covering the wider resolution and avoiding further litigation, interest and claims. It expressly said the settlement recognised no admission of liability by the government and that both parties genuinely held their positions.
A settlement is not the arbitral award. It is not the High Court judgment. It is not an admission that the original termination was right or wrong. It is a commercial and legal agreement reached after the award had been set aside and appeals and renewed proceedings remained possible.
The £150 million should therefore not be presented as a court-ordered penalty. Nor should the difference between the award and settlement be called a proven saving without stating the different components, legal posture and avoided future costs. The public record can explain the government's rationale without transforming negotiation into adjudication.
Settlement governance requires a comparison of expected pathways. Leaders should consider litigation probability, duration, legal and expert costs, management burden, interest, asset claims, operational dependencies, disclosure and precedent. The analysis should use ranges and show assumptions. It should also state which non-financial outcomes—release of claims, asset certainty, confidentiality or continued supplier relationships—are included.
Approval should identify who has authority to settle, how public-money rules are satisfied and what accounting treatment applies. After resolution, the institution should publish as much as legal obligations permit: total amount, broad scope, absence or presence of liability admission, status of assets and reason for concluding that settlement serves the public interest.
Lessons learned must remain independent of the legal compromise. A no-admission clause does not prevent a department from examining its requirements, governance and exit procedure. Equally, an internal lesson about poor control is not an admission of contractual liability. Keeping those functions separate makes institutional learning possible without rewriting the settlement.
Exit had to preserve live border operations and knowledge
The e-Borders capability could not simply stop when the prime contract ended. Passenger information was already being collected and checked, and border operations needed to continue. The Department had to secure live services, assets and data and procure or organise replacements.
The January 2011 parliamentary update on transition said the programme was securing existing live systems and assets, had novated the Semaphore contract, and was pursuing alternative providers. It also reported coverage of around 55% of passenger and crew movements at that time. These were government statements at a point in transition, not a later independent validation of service completeness or quality.
An exit inventory should cover software source and binaries, infrastructure, configurations, interfaces, security keys, test environments, licences, supplier contracts, data models, operational manuals, defect lists and named knowledge holders. Ownership and right-to-use are separate from physical possession. Every asset needs a legal status and an operational custodian.
Service continuity requires a transitional architecture. Which components remain live? Who supports incidents? How are vulnerabilities fixed? Which change requests are essential? What capacity and recovery targets apply? A new supplier cannot responsibly inherit a system described only by contract schedules and disputed milestone files.
Data continuity is equally important. The institution must preserve provenance, access controls, retention rules, matching logic and quality measures while systems change. A migration that loses error history or changes identifiers can make comparisons unreliable and undermine operational decisions.
Exit also creates lock-in risks. A public buyer may own assets but still depend on people who understand them, proprietary tools, third-party licences or a supplier's integration knowledge. Lock-in should be measured before award and throughout delivery. Documentation, open interfaces, escrow where appropriate, cross-training and test portability reduce the cost of changing supplier.
The goal is not to eliminate every dependency. Complex systems always have specialised components. It is to ensure that dependencies are visible, priced and governed, so a performance dispute does not become an operational hostage situation.
Successor programmes inherited the unresolved control problem
After termination, the Home Office commissioned successor initiatives, including the Border Systems Programme and later Digital Services at the Border. The names, scopes and delivery approaches changed, but the underlying need to collect, analyse and use border information remained.
The NAO's Digital Services at the Border report page describes the programme started in 2014 to replace legacy systems and improve frontline information. In 2019 the Department reset it after scope changes and poor performance, moving the target and reducing or reallocating parts of the scope. This later programme is not Raytheon's contractual responsibility. It is evidence that exit did not remove the underlying institutional delivery challenge.
The full 2020 NAO Digital Services at the Border audit found that the Department did not achieve value for money against its 2014–2019 plans, while also recording improved governance, leadership and delivery capability after reset. It identified continued legacy reliance, technical challenges, interdependencies and the need for performance requirements and stakeholder clarity.
That balanced finding matters. A reset can be rational when evidence shows the plan is not deliverable. It becomes weak accountability when scope, costs and benefits are rebased without a traceable explanation of what failed, what remains and how the new controls differ.
Every reset should publish a bridge between baselines. It should identify abandoned, deferred, transferred and newly added outcomes; sunk costs; reusable assets; legacy extension costs; revised benefits; and new evidence gates. Otherwise leaders can report the new plan as on track while the original public outcome disappears from view.
The Public Accounts Committee's 2021 Digital Services at the Border summary criticised repeated delay, cost and weak transparency and challenged the Department to show that systems could operate at required scale. This is later parliamentary scrutiny of the Department, not evidence about the merits of the 2007 contract dispute.
The recurring lesson is not that modular or agile methods guarantee success. They provide smaller decision points. Those points still require stable outcomes, capable product ownership, controlled architecture, user participation, honest status and measurable operational results.
Passenger-data quality was the enduring outcome test
A border-data programme cannot be assessed only by the volume of messages collected. It needs measures of coverage, receipt, completeness, accuracy, timeliness, coherence, duplicate handling and match quality. Each measure answers a different question.
The NAO found that the Department initially focused more on increasing data volume than on quality and only later developed limited quality measures. It also found gaps in management information about how checks and processes performed. These weaknesses affect both operational assurance and benefits evidence.
The Independent Chief Inspector's exit-checks inspection record examined what data the Home Office collected, where gaps remained and what it could achieve through analysis. Exit checks were delivered after the original contract period, so the inspection should not be used to attribute later data defects to Raytheon. It demonstrates the continuing need for usable evidence.
The Home Office's collection of exit-check statistics and guidance provides a public trail of evolving measures and methodological explanation. Statistical transparency matters because a high-level coverage figure may exclude routes or populations, and a voyage-level receipt measure may not show that every passenger record was received.
The later Developments in Exit Checks quality explanation explicitly distinguishes route coverage, voyage-level data receipt and newer quality metrics. It warns through definition that at least one message for a voyage does not mean information was received for every passenger or crew member.
An accountable dashboard should therefore use a data-quality ladder. Route readiness shows whether a connection exists. Receipt shows whether messages arrive. Record completeness shows required fields. Accuracy and coherence test whether fields agree with other trusted evidence. Timeliness shows whether information arrives early enough to act. Operational yield shows what useful decisions follow, while false positives and unresolved matches reveal cost and harm.
Targets need denominators, exclusions and confidence. A percentage without an eligible population or error process invites misinterpretation. Changes in definitions should be versioned, and historical comparisons should be restated or clearly marked.
These controls also protect travellers. Poor data can create missed threats, unnecessary intervention, delay or incorrect inferences about immigration compliance. Accountability is therefore not only financial. It covers the quality and proportionality of decisions made from public technology.
A durable control model joins requirements, delivery and exit
The e-Borders record suggests a practical control model for major public technology.
First, define an outcome hierarchy. Policy objectives lead to operating capabilities, user journeys, data obligations, service levels, components, tests and benefits. Every level has an owner. Open questions remain visible.
Second, choose the commercial model after uncertainty is assessed. Discovery, prototypes and staged commitments should reduce uncertainty before broad fixed obligations. Risk is allocated to the party able to control it, with external dependencies separately owned.
Third, make acceptance empirical. Milestones carry requirement versions, test results, defects, stakeholder readiness, security status and operational limits. Payment decisions and technical acceptance are connected but not silently conflated.
Fourth, govern change as a portfolio. Clarification, defect, allocated risk and new scope are classified with preserved positions. Time, cost and benefit effects are visible. Repeated disputes trigger baseline review.
Fifth, maintain an exit-ready architecture from the beginning. Asset rights, interfaces, documentation, data provenance, licences, knowledge transfer, service continuity and supplier substitution are current controls, not end-of-contract paperwork.
Sixth, treat termination as a programme. Grounds, procedure, options, evidence preservation, transition, asset transfer, litigation exposure and public explanation each have an owner and gate.
Seventh, keep legal statuses precise. An internal finding, a party allegation, an arbitral award, a court decision and a settlement answer different questions. Reports should never merge them for narrative convenience.
Eighth, measure the live public outcome. Data quality, system performance, user adoption, passenger impact, security usefulness, cost and benefit evidence must continue across supplier and programme boundaries.
What boards, Parliament and auditors should ask
A programme board should be able to answer which version of the outcome and requirements it is funding. It should know the ten highest-impact unresolved decisions, the external dependencies capable of defeating the next milestone and the evidence that users can operate the delivered capability.
The commercial authority should be able to explain why the contract form fits uncertainty. It should show how price, schedule, change, acceptance and termination interact, and which risks remain with the Department. It should not rely on a statement that risk was “transferred” when the buyer still controls critical decisions and stakeholders.
The data authority should publish definitions for coverage, receipt, completeness, accuracy and operational use. It should identify exclusions and data-quality error pathways. Security sensitivity may limit detail, but it does not remove the need for assurance.
The exit authority should maintain a transition inventory long before termination. It should know which assets are owned, which are usable, which licences constrain them, how services remain supported and how institutional knowledge will transfer.
Parliament and auditors should reconcile baselines. When a programme is reset, they should ask which original outcomes remain, which moved elsewhere, how costs are allocated and when benefits will be measured. A green rating against a reduced plan should not erase the original commitment.
Legal reviewers should test both substantive grounds and procedural integrity. They should preserve the distinction between a defensible termination decision and a flawed process, and between a successful challenge to an award and a final merits victory.
The public explanation should use reconciled numbers: supplier payments, programme expenditure, successor costs, legal costs, arbitral components, settlement and legacy extension costs. Each number needs a period and definition.
Institutional legitimacy depends on preserving distinctions
The e-Borders programme matters because border security technology combines secrecy, operational urgency, personal data, multiple agencies and major commercial commitments. That combination makes simple narratives attractive and dangerous.
The public record supports criticism of the Home Office's high-level requirements, commercial strategy, stakeholder management, programme capability, data culture and successor delivery. It also records the Department's performance concerns about Raytheon, including missed milestones and quality, and preserves supplier disagreement. Accountability requires both to remain visible.
The legal record must be stated in sequence. The Department terminated in 2010 and maintained that decision. An arbitral tribunal later made an award in Raytheon's favour. The Home Office challenged it. The High Court found serious irregularity and set the award aside, without producing a final allocation of blame for the programme. The parties settled for £150 million, with no admission of liability by the government.
The operational record continued beyond all those events. Live services and assets had to be secured. Legacy systems remained important. Successor programmes were reset. Passenger-data quality and benefits still needed proof.
That is why contract exit is a technology accountability test rather than merely a procurement dispute. A public institution must be able to change supplier without losing the service, the evidence or the ability to explain its own decisions. It must learn without converting lessons into admissions, defend itself without erasing departmental weaknesses, and scrutinise a supplier without implying personal misconduct.
The durable standard is a connected evidence chain: outcome, requirement, dependency, design, milestone, change, performance, decision, asset, data, legal status, transition and benefit. When that chain is maintained, disagreement can be resolved at the level of facts. When it is missing, every reset creates another story and every exit creates another accountability gap.

