
A CIO's framework for turning board vision into an executable, funded, defensible technology roadmap.
Boards do not reject IT roadmaps because the technology is wrong. They reject them because the roadmap reads as a shopping list instead of a business case: no baseline, no sequencing logic, no stated risk of inaction, and no way to tell in ninety days whether it is working. This playbook rebuilds the roadmap as a governance artefact — capability baseline, prioritised gaps, funded increments, and a one-page report the board can hold you to.
Score the current estate across infrastructure, applications, data, security, and delivery — evidence-based, not aspirational.
Growth, margin, risk, and compliance drivers converted into the capabilities they actually require.
The single section most roadmaps omit, and the one that most reliably unlocks funding.
Foundational work first — identity, network, data quality — then the initiatives that depend on it.
Capex/opex shape, run-rate impact, contingency, and the multi-year view finance needs to plan against.
Treating security and compliance as roadmap workstreams with owners, not as a slide at the back.
What to report, at what granularity, and how to raise a variance before it becomes a surprise.
How to change the roadmap in public — the discipline that separates a living plan from an abandoned one.
“A roadmap without a stated cost of inaction is a wish list. A roadmap with one is a business case.”
“Boards do not fund technology. They fund outcomes with a defensible path and a named owner.”
“If your first eighteen months contain no foundational work, your roadmap will be re-written by an incident.”