Protect the design through delivery.
The specification you paid for at L2 is a snapshot — a design that starts going out of date the moment delivery begins. L3 is the monthly retainer that stops that. We sit between your board and your implementation partner, protecting the design — and the benefits case the board signed for — against the drift every platform programme produces.
Governance. The layer most programmes never define.
It’s the sixth dimension of Commercial Lifecycle Architecture — the one that keeps the other five aligned through every technology, organisational and market change. It’s also the layer most exposed on almost every L1 audit we produce.
Architecture
The layer that holds it together
Who decides. How changes get approved. What gets measured.
Governance is what binds the design to what actually gets built. It decides what counts as a change, who has the authority to approve one, and how a benefit committed in the business case is tracked through to landing in the operating model.
Without it, the specification produced at L2 is a snapshot — a design that starts going out of date the moment delivery begins. With it, the specification is enforced through every change request, every partner trade-off, every board update.
The cost of leaving it unmanaged is measurable. Benefits-realisation studies from BCG, McKinsey and the UK National Audit Office converge on the same finding: realised benefits decay 15–30% within 18–24 months of go-live where ongoing architectural governance is absent. The decay is rarely visible quarter to quarter — it shows up as gradually eroding retention, NPS or unit economics that resist single-cause explanation at the board.
L3 is the engagement that installs that layer and runs it through delivery, until the design is operationally live.
How the L3 engagement actually works.
L3 is a monthly retainer that runs alongside your implementation programme. Four functions, performed continuously, so the design can’t drift unseen.
Change review
Every change request the implementation partner raises is checked against the L2 specification before sign-off. No silent variances.
Decision rights
The decision-rights matrix from L2 is put to work. Who can approve what — enforced by an independent party, not by the partner who benefits from the change.
Benefits tracking
The benefits case the programme was approved against is tracked stage by stage. Drift is named when it appears, not at the post-implementation review.
Board readout
A monthly executive update on the real state of the programme, in language the board can act on — independent of the partner’s own status report.
Governance isn’t project management.
The most common reason boards never buy governance is that they assume project management covers it. It doesn’t. Project management protects the schedule. Governance protects the design.
Protects schedule, scope, budget.
- Tracks status against the plan
- Manages the risks and issues log
- Owned by the implementation partner
- Reports on what the partner is delivering
- Doesn’t enforce the design
Protects the design, the benefits, the intent.
- Reviews changes against the L2 specification
- Tracks the business benefits stage by stage
- Owned by the board, run by Formalus
- Reports on the real state, independent of the partner
- Enforces the design through delivery
£8K–£15K per month. Tied to programme scale.
The retainer is set against the size and complexity of the implementation it governs — typically 1–2% of the monthly platform burn it’s protecting.
When L3 starts: usually at specification lock, the end of L2. It runs through build and stabilisation — most engagements last 9–18 months, ending when the design is operationally live, not when the platform is deployed. Those are different milestones.
Architecture before technology.
Build the software around the business, not the business around the software.
Discuss an L3 retainer →