Sanjay K Mohindroo
When IT accepts every business request, priorities blur and value suffers. A five-gate framework for better technology investment decisions.
After nearly three decades in enterprise IT, I have learned to be wary of one sentence that sounds wonderfully collaborative:
“IT will make it happen.”
It wins applause in the meeting. Six months later, it can leave the organisation with too many priorities, too much technology, diluted accountability, and very little clarity about what actually created value.
The conventional wisdom says IT must be an enabler. The modern CIO, we are told, should remove friction, support every business initiative, move faster, and never become the dreaded “Department of No.”
I think that advice has been taken too far.
When IT says yes to everything, it is not enabling the business. It is avoiding a decision the business needs to make.
And eventually, the business pays for it.
The Real Cost of an IT “Yes”
A request arrives from sales for a new customer platform.
Operations want workflow automation.
Finance wants better analytics.
HR wants another employee system.
A business unit has found an AI tool it wants deployed immediately.
Another team wants a custom application because the enterprise platform does not work exactly the way it would prefer.
Individually, almost every request can sound reasonable.
That is precisely the problem.
The question is rarely whether an initiative has some value. Most do. The real question is whether it creates more value than the alternatives competing for the same capital, management attention, technical capacity, and organisational change bandwidth.
That question cannot be answered by IT alone.
Yet organisations routinely behave as though it can.
A business sponsor makes a request. IT estimates it. Funding is somehow found. The project enters the portfolio.
Then another one enters.
And another.
Soon, the organisation has fifty “priority” initiatives, each with an executive sponsor and a compelling presentation explaining why it cannot wait.
At that point, priority has lost its meaning.
This is not an IT capacity problem. It is a management discipline problem.
Why Saying Yes Creates IT Portfolio Risk
For years, CIOs were encouraged to become more customer-centric. That was correct.
But internal customer service has sometimes been confused with internal order-taking.
They are not the same thing.
A good technology organisation listens carefully to the business. It understands urgency. It solves problems. It makes experimentation easier.
But it also protects the enterprise from fragmented investment, duplicated capability, unmanaged risk, and projects whose business case disappears the moment somebody asks who owns the outcome.
The strongest CIOs I have worked with and observed understand something important:
Their job is not to maximise the number of business requests IT fulfils. Their job is to maximise the business value created from technology investment.
Those are very different objectives.
One rewards activity.
The other demands choices.
Every IT Yes Has an Opportunity Cost
Boards understand this instinctively when discussing acquisitions, factories, markets, and capital expenditure.
Every investment competes with another investment.
Technology should be treated no differently.
If an organisation commits people and capital to Initiative A, those resources are no longer available for Initiative B.
Yet this opportunity cost is strangely absent from many technology discussions.
The conversation becomes:
“Can IT do this?”
That is the wrong question.
Given enough money, time, vendors, and people, IT can do an extraordinary number of things.
The better question is:
“Should this be one of the things we choose to do now?”
That changes the conversation completely.
It moves technology demand away from functionality and toward enterprise value.
It also forces one uncomfortable but necessary question:
If this becomes a priority, what stops being a priority?
If the answer is “nothing,” management has probably not prioritised anything at all.
The Hidden Cost of Unlimited IT Demand
The damage from excessive yeses is not limited to the IT budget.
It appears in at least five places.
First, strategic focus gets diluted.
The enterprise starts funding many reasonable ideas instead of a few important ones.
Second, delivery slows down.
More projects mean more dependencies, more governance, more vendor coordination, and more executive attention spread across competing programmes.
Third, complexity compounds.
A new platform or application may solve one department's immediate problem while creating additional integration, data, security, licensing, and support obligations for the enterprise.
The initial business case rarely prices that complexity correctly.
Fourth, accountability becomes blurred.
IT delivers the system, but the promised productivity improvement, revenue increase, cost reduction, or customer adoption never materialises.
Who owns the shortfall?
Too often, nobody.
Finally, important work gets crowded out by urgent work.
Cyber resilience, architecture simplification, technical debt, data quality, core platform renewal, and infrastructure modernisation are easy to defer because they rarely arrive with a business executive demanding action by Friday.
Until something breaks.
Then they suddenly become board matters.
The Five Gates Before IT Says Yes
I believe every material technology initiative should pass five simple gates before it receives a meaningful commitment of enterprise resources.
Not a fifty-slide business case.
Five questions.
1. What business outcome will change?
Start with the outcome, not the technology.
Not:
“We need an AI platform.”
Not:
“We need a new CRM.”
Ask:
What measurable business result should be different if we make this investment?
Revenue?
Cost?
Cycle time?
Customer retention?
Working capital?
Regulatory exposure?
Operational resilience?
If management cannot describe the result in business terms, the initiative is not ready.
There should also be a baseline. “Improve productivity” is not enough.
Improve it from what, to what, and by when?
2. Do the economics justify the investment?
Technology projects have visible costs and invisible costs.
Licences and implementation fees are visible.
Management time, process redesign, training, integration, security, data preparation, support, and future upgrades frequently receive less attention.
Then there is opportunity cost.
What could those same resources accomplish elsewhere?
A strong business case therefore asks not merely whether an initiative generates value.
It asks whether it is one of the best available uses of scarce enterprise resources.
That is a much higher bar.
3. Who owns the business outcome?
Every major technology investment needs a named business owner.
Not merely a sponsor who appears at steering committee meetings.
An executive who is accountable for the outcome.
If a new sales platform is supposed to increase conversion, sales leadership owns conversion.
If automation is supposed to reduce processing costs, operations owns the reduction.
IT should be accountable for technology delivery, resilience, security, and agreed service outcomes.
It should not become the default owner of benefits that depend on business behaviour.
Technology can enable change.
It cannot force a business unit to adopt it.
4. What new risk are we accepting?
Every technology investment changes the organisation's risk profile.
It may reduce one risk while creating another.
A cloud platform may increase agility while changing concentration risk.
An AI deployment may increase productivity while introducing data, decision, regulatory, or reputational exposure.
A new application may solve an immediate business problem while adding another dependency the enterprise must support for years.
Boards should ask a simple question:
What risk exists after this decision that did not exist before it?
The purpose is not to stop innovation.
It is to ensure enthusiasm does not temporarily suspend judgement.
5. What are we willing to stop?
This is the gate most organisations avoid.
It is also the most important.
Every major new priority should force a portfolio conversation.
What will we stop?
What will we delay?
What funding moves?
What leadership attention changes?
Without an explicit trade-off, portfolios expand until everything moves slowly.
A serious strategy is not a list of things an organisation wants.
It is a list of choices.
#ITGovernance is therefore less about controlling technology and more about forcing clarity about those choices.
The Board Should Not Approve Technology Shopping Lists
Another mistake is taking technology portfolios to boards as collections of programmes.
ERP transformation.
Cloud migration.
AI programme.
Data platform.
Cybersecurity upgrade.
Customer experience platform.
Those labels describe technology activity.
They do not describe why shareholders should care.
Boards should instead see the technology portfolio mapped to enterprise outcomes.
Which investments protect revenue?
Which lower structural cost?
Which create growth options?
Which address material risk?
Which simplify the operating model?
Which are mandatory?
And which are experiments that deserve limited capital until they prove themselves?
This framing makes one uncomfortable category visible: projects that consume substantial resources but have weak strategic justification.
That visibility is useful.
“But Won't Saying No Slow Innovation?”
This is the obvious counter-argument.
If every idea goes through governance, don't we risk becoming bureaucratic?
Yes, if governance is badly designed.
But that is not an argument for unlimited yeses.
It is an argument for different levels of commitment.
Small, reversible experiments should be easy.
A business team wanting to test an idea with limited cost, controlled data, and bounded risk should not need a six-month approval cycle.
Experiment quickly.
Learn cheaply.
Stop unsuccessful ideas without drama.
But an experiment becoming an enterprise commitment is a different decision.
That is when the five gates matter.
The distinction is important:
Speed should increase when decisions are reversible. Scrutiny should increase when commitments become expensive, difficult to reverse, or strategically consequential.
That is not bureaucracy.
It is sensible capital discipline.
Saying No Is Sometimes the Most Business-Friendly Answer
There is a reason executives dislike hearing “no” from IT.
Historically, some technology organisations earned a reputation for protecting their own convenience rather than enabling the enterprise.
That needed to change.
But the correction should not turn CIOs into order takers.
A mature technology leader sometimes needs to say:
“Yes, but not now.”
“Yes, if we stop something else.”
“Yes, provided the business owns the outcome.”
“Yes, as a limited experiment first.”
Or simply:
“No. The enterprise already has a capability that solves this problem.”
That is not obstruction.
That is leadership.
The most useful CIO in the boardroom is not the person who promises to make every request happen.
It is the person who helps leadership understand which technology decisions are worth making.
What CEOs Should Ask Their CIOs
A CEO does not need to become a technologist to improve technology decision-making.
Ask five questions at the next portfolio review:
1. Which three technology investments matter most to our strategy, and why?
2. What measurable business outcome does each one have?
3. Which executive owns each outcome?
4. What have we deliberately stopped or delayed to fund these priorities?
5. Which projects would we cancel today if we had to rebuild the portfolio from zero?
The fifth question is particularly revealing.
Legacy priorities have a habit of surviving because stopping them requires a decision, while continuing them requires only inertia.
IT Demand Is Ultimately a Leadership Question
Technology portfolios do not become overloaded because businesses have too many ideas.
Ideas are supposed to be abundant.
They become overloaded because organisations lack the discipline to choose among them.
That distinction matters.
The CIO can bring transparency.
Finance can expose economics.
Risk teams can challenge exposure.
The board can demand evidence.
But enterprise leadership must ultimately decide what matters most.
IT saying “yes” should therefore never end the conversation.
It should mean:
Yes, this deserves scarce enterprise capital ahead of the alternatives.
That is a much more consequential statement.
And it should be treated as one.
After three decades around enterprise technology, I remain convinced that one of the most valuable services IT can provide is not faster agreement.
It is better decision-making.
Where has your organisation drawn the line between enabling business demand and simply accepting too much of it?
Subscribe to TechnologyTrends, or add your perspective in the comments, for more on cutting through the hype to what actually matters in IT.