practice

Spend Control Gate

also called Funding Gate, Investment Approval Control

Architecture governance applied at the point money is committed rather than at design review, so the conversation happens while the decision is still reversible and the centre has actual authority.

gdsgovernancefundingprocurementreversibility

Most architecture governance is applied to designs. Designs are cheap to change, which is why review boards can be effective and why they are also routinely ignored: a team that disagrees with a design review can proceed anyway, and frequently does.

The decisions that are genuinely hard to reverse are rarely design decisions. They are a six-year supplier contract, a platform licence, a managed-service commitment, a hiring plan for a technology the organisation does not have. A governance function that reviews designs and never sees the contract is governing the reversible decisions and missing the irreversible ones.

A spend control gate moves the review to the commitment. Above a threshold, money does not move without a conversation, and the conversation has criteria attached. The authority comes from the budget rather than from any claim to decide how teams build.

Why it matters

It supplies the thing standards documents lack: a moment of contact. A published standard has no point at which anyone must engage with it, so adherence is whatever each team chooses. A funding gate creates a specific time at which a specific person must answer questions, and it does so without requiring any authority over how teams build software — which matters in federated organisations where such authority does not exist.

It also lands where the money is. Architectural cost is dominated by commitments, not by code, and an organisation that reviews architecture without seeing procurement is reviewing the smaller number.

Implementation patterns

  • Set the threshold low enough to catch the decision early, before a procurement is committed rather than at signature, when nothing can change without breaking a negotiation.
  • Use a zero threshold for specific categories where the centre has a strong view and divergence is expensive — public-facing identity, payments, customer data platforms.
  • Publish criteria in advance. Without them the gate degenerates into negotiation and personal relationships. With them, teams prepare, and most of the value is obtained before the meeting.
  • Pair the gate with components. This is the half organisations skip: a control plus a standard plus nothing to use is a tax. The compliant path must be cheaper than the alternative, or the gate produces resentment and creative accounting.
  • Decide fast and publish the decision. A gate with a six-week queue is an obstacle whatever its criteria, and an unexplained refusal spends credibility the function will need later.
  • Design the exit condition when you introduce it. State what capability, distributed to teams, would make the gate unnecessary — otherwise it outlives its purpose and becomes the thing people describe as bureaucracy.

Industry example

From 2011 the UK's Government Digital Service operated exactly this arrangement: departmental digital spending above roughly £100,000 required central approval, with a zero threshold for some categories such as public-facing websites, alongside a published service standard, assessments, and common components for publishing, payments and notifications. Central government had no authority to direct departments' engineering, and the spend control supplied the influence that guidance could not.

The ending is as instructive as the mechanism. By 2026 the GDS-run controls had been retired in favour of departments owning their own approvals with a far higher pipeline threshold — the accumulated cost of the queue, and the judgement that local capability had matured, doing exactly what a well-designed exit condition should do.

Failure scenarios

  • The gate without the road. Approval required, no better alternative offered, so compliance costs more than non-compliance and teams find routes around the control.
  • Too late in the process. A control that bites at contract signature reviews a decision that has already been made, and the only available answers are yes and an expensive no.
  • Criteria invented in the room, so outcomes depend on who attends and the process is correctly perceived as arbitrary.
  • Queue growth. The control becomes the constraint on delivery, and the organisation's response is to raise the threshold until the gate catches nothing.
  • Scope blindness. The gate sees new spend and never the existing estate, so a large unreviewed legacy footprint accumulates behind a well-governed front door.
  • No exit. The control persists after departments or business units have built the capability it was compensating for, at which point it subtracts value from people who can now do better.

Trade-offs

The gate buys authority the function would not otherwise have, and pays in delivery friction and political capital. Each refusal spends credibility; a function that refuses often runs out and is then overruled on the one that mattered.

It also narrows what governance can see. Funding-point review is excellent for irreversible commitments and blind to everything that costs nothing to start, which in a cloud-era organisation is a great deal of architecture. It is a complement to engineering-level mechanisms, not a replacement for them.

When not to use it

Where the centre has no budget authority, which is most commercial organisations below the capital-approval line: imposing an approval gate without either money or a better alternative produces the routed-around review board in its purest form.

At small scale, the control point is the planning conversation that already happens weekly, and formalising it adds ceremony to something that works. And where a paved road already exists and is genuinely the cheapest path, the road is doing the governing — adding a gate in front of it taxes the behaviour you were trying to encourage.

Interview question

Q: You are the first enterprise architect in a group of six autonomous business units. You have no authority over their engineering. Where would you position your one point of influence, and what would you need to have built before using it?

What a strong answer covers: identifying the irreversible commitments — procurement, licensing, multi-year managed services — rather than design review as the place where authority is real; a threshold set early enough to change the outcome; published criteria so the gate is not negotiation; the components or reference implementations that must exist first, because a gate without an alternative is a tax; the credibility economics of refusals; and an explicit exit condition, with the GDS arc from 2011 to 2026 as evidence that the mechanism is for a period rather than forever.

Quick check

Quiz: Why does a spend control succeed where a published standard fails in a federated organisation? — The standard has no moment at which anyone must engage with it; the control creates one, at the point where commitment becomes irreversible, without requiring authority over how teams build.

Flashcard: What must accompany a funding gate for it to be governance rather than a tax? — Published criteria decided in advance, and common components that make the compliant answer the cheaper one; a gate with neither is an obstacle teams learn to route around.