Advice its author has to deliver.
IT strategy, enterprise and solution architecture, vendor and sourcing decisions, operating-model design, technology due diligence and regulatory readiness — written by a firm that expects to build what it recommends and to be measured against the case it made. A recommendation you can only admire is a report. A recommendation you can execute, with the author still in the room, is a plan.

Che cos’è questa disciplina
- A strategy written for execution. Every recommendation names the system it touches, the team that owns it, the sequence it belongs in and the evidence that will show it worked, so the board is approving a programme and not a direction of travel.
- Architecture as a decision record. Target state, transition states, the integration points between them and the trade-offs taken at each one are written down, argued and signed, so the organisation can still explain in five years why the estate looks the way it does.
- Independent on sourcing. When the right answer is a product you already own, a supplier we do not resell or a team you should hire rather than contract, that is the recommendation. Our delivery practices compete for the work on the same terms as anyone else, and the strategy is priced and paid for on its own.
- Written against the regulation you actually face. The revised Swiss FADP, the GDPR, Jordan's Personal Data Protection Law, the EU AI Act, DORA and FINMA's outsourcing expectations are read as obligations with owners and deadlines inside your programme, not appended as a compliance chapter.
Che cosa non è
- A slide deck that leaves with the consultants. Recommendations arrive with the architecture, the sequencing, the sourcing options and the risk register that a delivery team would need on its first day, because a delivery team may be ours and will hold us to every line.
- A vendor's reference architecture with your logo on the cover. The target state starts from your estate, your contracts, your regulator and your people, and a platform earns a place in it by fitting the case, never by having a partnership programme.
- Transformation theatre. A programme office that reports green until the go-live slips is a governance failure, and this practice designs the governance to surface bad news early enough to act on it, with the authority to stop work when the case no longer holds.
- Finished at the steering committee. The case the board approved is the yardstick for the programme that follows, and the practice stays accountable for measuring the result against it — whoever ends up building.
Competenze
- IT strategy and investment portfolio
- A statement of where technology money goes and why, tied to the operating plan, with each initiative carrying an owner, a case, a sequence and a kill condition, and reviewed at board level on a fixed cadence.
- Enterprise architecture
- Current state, target state and the transition states between them, across applications, data, integration, infrastructure and identity, maintained as a living register rather than a one-off diagram.
- Solution architecture and technical design
- The design of a specific system or programme — components, interfaces, data flows, failure modes, non-functional requirements and the build-or-buy call for each part — written so an engineering team can start from it without a discovery of its own.
- Vendor and sourcing decisions
- Requirements, evaluation criteria, the shortlist, structured demonstrations on your data, reference calls, contract and exit-term review, and a recommendation that may be a supplier, a product you already hold or an internal team.
- Core-system modernisation strategy
- How to replace or re-platform the systems the business cannot stop running: strangler patterns, parallel running, data migration sequencing, cut-over criteria and the governance that decides when to proceed and when to hold.
- Cloud, sovereign and on-premises strategy
- Where each workload should run and why, given data residency, regulatory supervision, latency, cost and the skills you have, with a landing-zone design for the chosen footprint, including national and private clouds.
- Operating-model and organisation design
- Which capabilities the organisation must own, which it can source, how teams are formed around products or platforms, how architecture and security decisions are made, and how the model changes as the programme lands.
- Data and AI governance
- Ownership, classification, lineage, retention and access for data; inventory, risk classification, human oversight and documentation for AI systems, mapped to the EU AI Act, the revised Swiss FADP and Jordan's Personal Data Protection Law.
- Regulatory readiness and data residency
- A gap assessment against DORA, FINMA's outsourcing expectations, the GDPR and the national digital-transformation policy your programme sits under, turned into a remediation plan with owners, evidence and a review date for each obligation.
- Technology due diligence
- For acquirers, investors and boards: architecture, code and infrastructure quality, security posture, key-person and licensing risk, technical debt priced as remediation effort, and the questions to put to management before signing.
- Programme and transformation governance
- Steering structure, decision rights, stage gates, benefit tracking and risk escalation designed so that the case approved by the board remains the instrument the programme is run and judged by.
- Board and executive advisory
- Standing counsel to the chief executive, the chief information officer and the board on technology decisions as they arise, in the register a board reads and with the evidence a non-executive can question.
Come consegniamo
Five phases, each closed by a gate your executive sponsor signs. In consulting the Build phase is the transformation programme itself and the Prove phase is its measurement against the case the board approved, so the same numbers that justified the work are the ones used to judge it.
- 01Discover
- Read the estate, the contracts, the regulatory obligations and the operating plan; interview the people who run and depend on each system; establish the baseline the case will be measured from.
- Varco: Current-state architecture, obligation register and baseline measures accepted by the executive sponsor, the chief information officer and the compliance function.
- 02Define
- Write the target architecture, the transition states, the sourcing recommendations, the operating model and the investment case, with the risks, dependencies and kill conditions for each initiative.
- Varco: Strategy, architecture and case approved by the board or its delegated committee; sourcing recommendations recorded with the alternatives considered and the reasons for rejecting them.
- 03Build
- Run the transformation programme against the approved case: stage gates, architecture governance, vendor management and benefit tracking, with the delivery team — ours, yours or a third party's — held to the design.
- Varco: Each stage gate passed on evidence: architecture conformance, security and regulatory sign-off, benefit tracking on schedule, and the sponsor's decision to proceed recorded.
- 04Prove
- Measure the landed programme against the baseline and the case: the operating cost, the cycle times, the risk position and the obligations now met, reported in the same terms the board approved.
- Varco: Benefit realisation report accepted by the sponsor and audit; variances explained and either corrected or written into the case as revisions the board has seen.
- 05Operate
- Keep the architecture register, the obligation register and the investment portfolio current as the estate, the regulation and the business change, through standing advisory or a scheduled review.
- Varco: Quarterly architecture and portfolio review with the executive team; annual re-assessment of regulatory obligations and sourcing contracts approaching renewal.
Che cosa ricevete
| Deliverable | Forma | Che cos’è |
|---|---|---|
| Technology strategy | Board document | Where technology investment goes and why, in the register a board reads, with the case, the sequence and the kill condition for each initiative. |
| Architecture register | Living record | Current, target and transition architectures with every significant decision, its alternatives and its rationale, maintained as the estate changes. |
| Sourcing recommendation | Document and evidence | Requirements, evaluation results, contract and exit-term review, and the recommendation with the options rejected and the reasons. |
| Operating-model design | Document | Capabilities owned and sourced, team structure, decision rights for architecture and security, and the transition plan from the model you have. |
| Obligation register | Register and remediation plan | Every regulatory obligation that touches the programme, its owner, the evidence required and the date it will be met. |
| Programme governance | Charter and cadence | Steering structure, stage gates, benefit tracking and escalation rules, written to keep the approved case as the instrument of control. |
| Due-diligence report | Document | For acquisitions and investments: findings by severity, remediation effort, deal-relevant risks and the questions for management. |
| Benefit realisation report | Document | The landed programme measured against the baseline and the case, with variances explained, for the board and for audit. |
Dove conta
- Servizi finanziariDistintivo, dove Altuon guidaCore-system and outsourcing decisions under FINMA expectations and DORA, where the architecture register is also the supervisory evidence.
- Pubblica amministrazioneDistintivo, dove Altuon guidaNational digital-transformation programmes on sovereign infrastructure, with sourcing that builds domestic capability rather than dependence.
- AssicurazioniDistintivo, dove Altuon guidaPolicy administration and claims platform modernisation where the regulator, the actuaries and the distribution channel all constrain the sequence.
- SanitàCentraleScheduling, records and integration strategy for hospital networks where downtime is a clinical event and residency is a legal one.
- Farmaceutica e scienze della vitaCentraleValidated-system strategy, data governance and AI readiness in an environment where every change carries a documentation obligation.
- TelecomunicazioniCentraleOperating-model and platform decisions for operators whose systems estate has outgrown the organisation that runs it.
- Energia e utilityCentraleOperational-technology and IT convergence, with the security and resilience obligations that come with critical infrastructure.
- Manifattura e industriaDi supportoEnterprise resource planning and plant-system strategy for groups consolidating estates acquired over decades.
Incarichi rappresentativi
- Schema di incaricoA sovereign AI programme for a government ministryArabic-first models on national infrastructure, a governance framework a minister can sign, and citizen services moved onto it one at a time.JordanPubblica amministrazione
- Schema di incaricoReplacing a hospital network's scheduling core without stopping the clinicsA twenty-year-old scheduling system migrated site by site behind a compatibility layer, with HIPAA controls designed in and no clinic closed for a cut-over.United StatesSanità
Prospettive collegate
- Ingegneria9 settembre 2026Migrating legacy core systems without stopping the businessThe big-bang cut-over is how core migrations fail. The alternative is slower, less dramatic and works: a compatibility layer, one consumer at a time, and a rollback path that is rehearsed rather than hoped for.
- Acquisti9 settembre 2026Procurement's questions about AI vendors, answeredWho owns the model weights? Where is the training data? What happens to our prompts? Can we leave? The questions procurement teams ask AI vendors are the right ones. Here are the answers a serious firm should be able to give, and the ones that should end the conversation.
Le domande degli acquisti
How independent are your recommendations from vendors, and from your own delivery practices?
Altuon holds no resale agreements and takes no referral fees from technology vendors, and the proposal for any consulting engagement states this in writing. Where a recommendation favours a product or supplier, the evaluation that produced it is a deliverable you keep, with the alternatives and the reasons they were rejected. Our own engineering and AI practices are treated as one option among the sourcing candidates: they compete on the same criteria, their proposal is reviewed by the same panel, and the consulting team that wrote the strategy does not score them. A recommendation to buy elsewhere, or to build with your own people, is a complete and successful outcome of the engagement.
How is the consulting work priced, and is it separate from delivery?
Separately, always. The strategy, architecture or due-diligence engagement is scoped, priced and invoiced on its own, and it is complete when its gates are signed, whether or not any delivery follows and whoever does it. If you later engage Altuon to build, that is a second agreement with its own scope, its own commercial terms and its own acceptance criteria. Nothing in the consulting fee is contingent on delivery work being awarded, and no delivery discount is offered in exchange for a favourable recommendation. The two agreements can be terminated independently.
How are strategy documents and the information behind them kept confidential?
Under a mutual confidentiality agreement signed before the Discover phase begins, covering everything we read, hear and produce. Working papers are held in an engagement workspace in the region you specify — Switzerland, the European Union, Jordan or the United States — with access limited to the named team, and they are returned or destroyed at close on your instruction with written confirmation. Strategy documents are never used as references, case studies or sales material without your written consent, and the sub-processor list for the engagement names every tool that could hold your material.
How is the risk of a transformation programme governed?
Through the case itself. The board approves a case with a baseline, expected benefits, a sequence and explicit kill conditions for each initiative. The programme is then run through stage gates that require evidence — architecture conformance, security and regulatory sign-off, benefit tracking on schedule — before work proceeds. The steering group holds the authority to pause or stop an initiative whose case no longer holds, and the escalation rules oblige the programme to report a threatened gate before it is missed, not after. Risk is tracked in a register the sponsor sees at every steering meeting, with owners and responses, and the register is part of what audit receives.
What does the board see, and how often?
A short report in the board's own register at each scheduled meeting, and an exception report between meetings if a gate is threatened or a kill condition is approaching. The regular report covers progress against the approved sequence, benefits tracked against the baseline, the top risks and the decisions the board is being asked to take. Non-executive directors can request the underlying evidence for any line, and a member of the engagement team attends to answer questions directly. The same report format is used from Discover through Operate, so the board is never asked to learn a new way of reading the programme.
What happens if we choose another firm, or our own team, to build?
The engagement has done its job. Every deliverable is written for a delivery team that has not met us: the architecture register, the transition states, the sourcing evidence, the operating model and the governance charter are yours on payment and complete enough to start from. We hand over to the chosen team in a structured session, remain available for clarification on agreed terms, and — if you wish — continue in the Prove phase to measure the landed programme against the case, which is often more useful when the builder and the assessor are not the same firm.
Can the strategy account for on-premises, sovereign and residency constraints?
It must, and it does from the first phase. Residency and supervision requirements under the revised Swiss FADP, the GDPR, Jordan's Personal Data Protection Law, DORA and FINMA's outsourcing expectations are captured in the obligation register during Discover and shape the target architecture rather than filtering it afterwards. Where the answer is on-premises infrastructure or a national cloud, the strategy states what that footprint costs, which products and skills fit it and which do not, and how the organisation will operate it. Where a hosted service is acceptable, the residency, audit and exit terms it must carry are written into the sourcing recommendation.
Let us read your estate.
The Discover phase begins with your systems, your contracts and your obligations, and ends with a baseline you can measure a programme against. Request a proposal, or book a briefing for the board members who will be asked to approve the case.
