Change management for financial services: a 3-level governance model

Change management for financial services: a 3-level governance model

On 1 July 2025, APRA’s Prudential Standard CPS 230 came into force, and with it, a requirement most financial services change functions still have not absorbed: boards must now oversee operational risk arising from their own institution’s change activity, as a standing governance responsibility, not a project-level concern raised only when something has already gone wrong. It is one of the first times a regulator has said explicitly, in a binding prudential standard, that a poorly sequenced portfolio of change is a board-level risk in its own right, and it is one instance of a pattern now playing out in board rooms well beyond Australia, from London to Toronto to Singapore.

CPS 230 did not invent this problem. It named it. And it forces a question most financial services change functions have never had to answer cleanly: at which level of the organisation, exactly, is the volume and sequencing of change actually governed, and does the board see the performance and benefit impact of that portfolio, or only a status summary of individual projects.

Most change management for financial services content treats regulatory pressure as one more generic source of “change volume” to manage. It is not generic. It is a structural governance question that plays out differently at three distinct levels, the frontline teams absorbing change day to day, the business unit coordinating it across them, and the enterprise and board reviewing what it is doing to performance and value. This article sets out a working governance model across those three levels, and shows why regulators well beyond Australia are now converging on the same demand.

Why this is now a board-level governance question

CPS 230 is not an isolated Australian requirement. Over the past three years, financial services regulators across several major markets have independently converged on treating change-related operational risk as a governance obligation, not a delivery detail. A few examples make the pattern clear.

  • Australia: alongside CPS 230’s operational risk requirement, the Financial Accountability Regime requires banks (from March 2024) and insurers and superannuation trustees (from March 2025) to name accountable persons against specific responsibilities, backed by formal accountability statements.
  • The United Kingdom: in April 2023, the Bank of England’s Prudential Regulation Authority personally fined TSB Bank’s former Chief Information Officer for breaching the PRA’s Senior Manager Conduct Rules, following a 2018 core banking migration that locked out 5.2 million customers and eventually cost the bank £48.65 million in combined FCA and PRA fines. The regulators were explicit that the failure was not the migration itself, migrations fail regularly, but that no one had both the authority and the full picture needed to stop it going ahead once the warning signs were there.
  • Canada: the Office of the Superintendent of Financial Institutions’ Guideline E-21, finalised in August 2024, explicitly lists change management alongside business continuity and crisis management as a named component of operational risk and resilience that federally regulated institutions must govern.
  • Singapore: the Monetary Authority of Singapore’s Guidelines on Individual Accountability and Conduct require financial institutions to clearly identify the senior managers responsible for each core function and hold them accountable for the conduct of the business under their purview.
  • The European Union: the Digital Operational Resilience Act, in force since January 2025 across roughly 22,000 financial entities, ties ICT and change-related operational resilience directly to internal governance obligations, with penalties reaching €1 million for individual senior managers.

None of these regimes were written with change management in mind specifically. All of them arrive at the same practical requirement: a financial services change portfolio needs real governance at every level where a decision about sequencing, capacity or risk actually gets made, not a single dashboard the board glances at once a quarter. If you already have a strong grip on the different categories of transformation running through your organisation, our companion piece on the eight core types of financial services transformation is the right place to map what is actually in your portfolio before applying the governance model below.

A governance model for change portfolios: operations, business unit, enterprise

Most financial services change functions have governance on paper, a steering committee here, a change advisory board there, but it rarely maps cleanly onto the three levels where decisions about change risk and value actually get made. Here is a model that does, built around a single artefact each level contributes to and draws from: a risk-in-change register, a live record of what change is landing where, how much capacity it is consuming, and what operational, consumer-outcome or performance risk it is creating, that exists as one shared view rather than three disconnected reporting lines.

Operations level: the source of real signal

The operations level, claims processing teams, contact centre agents, branch tellers, loan servicing staff, is where change load is actually experienced, not where it is reported from a spreadsheet. This is the frontline delivering the customer interaction every disclosure and prudential regime ultimately cares about. This level should surface three specific things upward:

  • Real capacity data, not estimated capacity. How many hours per week is this team realistically able to absorb in new process, system or product change, given its existing operational workload, not a generic FTE assumption inherited from a project template.
  • Early psychosocial and readiness signals. Frontline supervisors are the first people to see when concentrated change load is producing disengagement, error rates, or attrition risk, well before it shows up in a portfolio dashboard.
  • First-hand evidence from the customer interaction itself. Where a change affects a customer-facing product or process, frontline staff are the ones who can confirm whether customers actually understand what changed, not just whether a disclosure document was technically issued.

The failure mode at this level is not incompetence. It is that most portfolio governance never asks operations teams for this information in a structured, recurring way, so it only surfaces informally, if at all, until it becomes an incident.

Business unit level: the sequencing function

This is the divisional or business-unit layer, retail banking, claims, wealth advice, coordinating operations teams underneath it, and it is the level TSB’s case shows was structurally missing: someone with a live, cross-initiative view who can see that two individually “green” projects are about to land on the same operations team in the same fortnight, one driven by a hard regulatory deadline and one entirely discretionary.

This level should own:

  • Cross-referencing regulatory deadlines against operational capacity data, not managing regulatory and discretionary change as separate, uncoordinated streams reporting into different committees.
  • The sequencing and trade-off recommendation, deciding, with evidence, which discretionary initiative slows down when a mandatory obligation is added to a team’s load, rather than leaving that decision to whichever project manager escalates loudest.
  • Genuine change conflict detection across the business unit’s initiatives, treating overlapping change on the same team as a standing risk to monitor, not a coincidence discovered after go-live.
  • Aligning frontline readiness and engagement data with the customer communication plan, rather than letting the two run on separate tracks. A business unit that knows its contact centre team is stretched thin two weeks out from a major product change should be the same function deciding when and how customers hear about that change, because a rushed or poorly staffed customer response is exactly when a communications gap turns into a complaint, an escalation, or a DDO and Consumer Duty evidence problem.

Without a real system of record spanning every initiative, not a folder of individual project plans, this function is guesswork dressed up as governance. This is precisely the gap a dedicated change portfolio platform is built to close.

Enterprise and board level: performance and portfolio benefit impact

The board and executive committee should not be reviewing individual project statuses, and their interest in this governance model is not primarily who is personally accountable for what. It is performance: what is the change portfolio, taken as a whole, doing to operational performance, customer outcomes and the benefits the organisation committed to when it funded each initiative. This level should own three things:

  • A portfolio-wide performance and benefit-impact view, showing where concurrent change is degrading operational metrics, error rates, service levels, adoption, or customer satisfaction, against the benefit case that justified the investment in the first place, not a status roll-up of red, amber and green.
  • The change capacity ceiling, set as an explicit decision: how much combined regulatory-mandated and discretionary change the organisation can absorb in a given period without measurably eroding performance, informed by what the business unit and operations levels are reporting, not set once a year and forgotten.
  • The trade-off decision when capacity and benefit realisation conflict, deferring or resequencing discretionary transformation when the evidence shows it is putting delivery of committed benefits, or day-to-day performance, at risk. TSB’s board found this out only after the fact; CPS 230 and its international equivalents now expect boards to be asking the question before it happens.

If your board only ever sees a portfolio-wide status summary with no visibility of the performance and benefit impact underneath it, you do not yet have this layer, regardless of how many steering committees exist beneath it.

Customer disclosure obligations are now a change design constraint

Two regimes change what “ready to launch” means for any customer-facing financial services change. Under ASIC’s Design and Distribution Obligations, issuers and distributors must define a target market and take reasonable steps to keep distribution within it on an ongoing basis, not through a one-off disclosure document; ASIC has already secured an $8 million penalty against Firstmac and issued more than 80 preliminary stop orders for DDO contraventions. In the UK, the FCA’s Consumer Duty, in force since July 2023, goes further still, requiring firms to evidence good outcomes across products, price, consumer understanding and consumer support, with an annual board-level assessment of whether they achieved this.

The practical effect is that the customer communications and monitoring plan, historically a downstream deliverable finished once “the real work” was done, is now itself a compliance artefact that has to be designed before a change goes live, not written up afterwards. For any financial services group operating across more than one of these regimes, and most larger insurers and wealth managers do, a single change rolled out on one timeline needs two distinct evidence trails, not one disclosure pack adapted after the fact, because DDO and Consumer Duty ask genuinely different questions of the same change.

Inside the governance model, this obligation sits at the intersection of the operations and business unit levels, and it fails when it is treated as belonging to neither. Three things need to move earlier in the change lifecycle to close that gap:

  • Target market and product governance checks belong inside the change design phase, reviewed alongside scope and timeline, not bolted on as a compliance sign-off after design is locked.
  • Frontline readiness and engagement data has to be read alongside the customer communication plan, not separately. If operations-level signals show a team is already stretched, that is a reason to reconsider the timing or intensity of the customer-facing message going out at the same time, not just a resourcing footnote for the business unit to manage quietly.
  • Consumer-facing changes need enough lead time built into sequencing to construct the outcomes evidence base regulators expect, which the business unit level can only protect if it has visibility of the deadline early, not discover it competing with an unrelated regulatory-mandated change for the same launch window.
  • Overlapping customer segments need to be visible at portfolio level, because a segment absorbing three separate product changes in one quarter is a consumer-understanding risk even where each change individually cleared its own DDO or Consumer Duty review in isolation.

Two risk domains most governance models still bolt on instead of owning

AI as its own governance lane

APRA’s April 2026 letter to industry, following targeted engagement with large banks, insurers and superannuation trustees, found that “AI governance, risk management and assurance are struggling to keep pace” with adoption, with specific gaps in identity and access management, patch management and testing of AI-generated code. The governance model above answers this directly: an AI-enabled change, a new underwriting model, an AI-assisted advice tool, needs its own line in the enterprise-level performance and benefit-impact view and its own capacity and risk data at the operations and business unit levels, not a place inside the general “technology change” category where AI-specific risk gets diluted into a bucket it does not fit.

Badly managed change as a named operational and legal hazard

Canada’s OSFI Guideline E-21 is unusual among the regimes above in naming change management explicitly as a component of operational risk and resilience regulators expect institutions to govern, not folding it into generic technology or project risk. Australia’s Safe Work Australia Model Code of Practice on psychosocial hazards reaches a parallel conclusion from the workplace health and safety side, naming badly managed change, alongside high job demands and low role clarity, as a specific hazard organisations have a legal duty to identify and control. Read together, these two regimes from two different regulatory traditions are saying the same thing: change load concentration on a team is not a soft people-risk footnote. It belongs in the operations and business unit levels of the governance model as a tracked risk, on the same footing as a system outage or a compliance breach.

For financial services specifically, this hazard concentrates in exactly the operations and frontline teams carrying the heaviest regulatory-mandated load, claims, contact centre, lending operations, the same teams disclosure and prudential regimes place under the most scrutiny. A governance model that tracks capacity and readiness at the operations level is therefore not a parallel wellbeing initiative sitting alongside risk management. It is the same data serving both obligations at once, which is precisely why it belongs in the risk-in-change register rather than a separate HR dashboard nobody in risk or compliance ever sees.

What this looks like in practice

Take a claims operations team absorbing three concurrent changes: a mandatory process update to meet a new disclosure deadline, a core system upgrade, and a discretionary efficiency initiative the business case was signed off eighteen months ago. Under most current governance arrangements, each of these reports green individually, three separate project managers, three separate steering committees, no shared view of the team underneath them. Under the three-level model, operations would have flagged the combined load against real team capacity weeks earlier; the business unit would have used that signal to recommend deferring the discretionary initiative and to hold back the customer communication until the team had capacity to handle the resulting enquiries well, since the disclosure deadline is fixed and the system upgrade is nearly complete; and the enterprise level would have seen the benefit-realisation and performance trade-off explicitly, on the record, rather than discovering it once the team’s error rate, complaint volume or attrition spikes. That is the exact sequence of missing decisions TSB’s post-mortem points to, replayed at a smaller, everyday scale.

A governance model is only as good as the data feeding it. In practice, the financial services change functions doing this well share four disciplined habits.

  • They maintain a rolling, not point-in-time, change readiness assessment at the operations level, because readiness collected once at project kickoff is stale within weeks in a fast-moving regulatory environment.
  • They give the board a single portfolio-level view of performance and benefit impact, where regulatory deadlines, capacity and consumer-facing change intersect, rather than a stack of individual project RAG statuses that hide exactly the kind of overlap TSB’s failure exposed.
  • They treat the organisational structure question, centralised, federated or hybrid change governance, as a deliberate design choice rather than an accident of history; if this decision has not been made explicitly in your organisation, our guide to choosing the right enterprise change management structure is a useful next step.
  • They tie change delivery to sustained benefit realisation, not milestone completion, so the enterprise level’s capacity-ceiling decisions are informed by what previous change actually protected or delivered, not just what it shipped on time.

None of this is achievable through steering-committee reporting alone. It requires a system of record spanning the whole portfolio that can answer, for any team, at any level, “what is landing here, from every source, this quarter, and what is it doing to performance,” as a standing question rather than a special request pulled together after something has already gone wrong. This is the specific gap a change intelligence platform like Change Compass is built to close for financial services portfolios: giving each governance level, operations, business unit and enterprise, the same live view of change load, sequencing, readiness and benefit impact, rather than three disconnected versions of the truth.

Where governance actually has to start

TSB’s board found out only after the fact what its change portfolio was doing to operational performance and customer outcomes. That is the test worth applying to your own portfolio today: can your board see, right now, the performance and benefit impact of everything landing on your frontline teams this quarter, not just a status roll-up of individual projects. If the answer is no, that is where your governance model needs to start, at whichever of the three levels, operations, business unit or enterprise, currently has the least visibility, before the next regulatory deadline forces you to find out the hard way.

Frequently asked questions

What does governance at the operations, business unit and enterprise level mean for change management? It means splitting change portfolio governance into three distinct levels: operations teams who surface real capacity, readiness and customer-interaction data, a business unit layer that sequences change and aligns frontline readiness with customer communication, and an enterprise or board level that reviews the performance and benefit impact of the whole portfolio and sets the capacity ceiling. Most financial services change functions have committees at each level but rarely this clean a division of what each one actually owns.

Why do financial services regulators increasingly treat change-related operational risk as a board-level issue? Regimes such as Australia’s CPS 230, Canada’s OSFI Guideline E-21, the EU’s DORA and the UK’s Senior Managers regime were all designed to close a gap regulators saw repeatedly: institutional failures where no one at the right level had both the visibility and the authority to prevent them. Some of these regimes go further and require a named accountable individual, but the underlying demand in every case is board-level oversight of the risk change activity creates, not just after-the-fact accountability.

How is change management treated as an operational risk under regimes like CPS 230 and OSFI Guideline E-21? Both regimes require boards to oversee operational risk arising from an institution’s own change activity, not just external threats. OSFI’s Guideline E-21 goes further by explicitly naming change management as a component institutions must govern, alongside business continuity and crisis management, rather than treating it as a generic project management concern.

Why do design and distribution obligations affect how a change is rolled out, not just how it is communicated? DDO and the FCA’s Consumer Duty both require ongoing evidence that a product or service change is reaching its intended market and delivering good customer outcomes, not a one-off disclosure at launch. This means the monitoring and evidence plan has to be designed into the change itself before go-live, rather than treated as a communications task completed afterwards.

Is AI-enabled change different from other technology change in a governance model? Yes. Regulators including APRA have found that AI governance, risk management and assurance are not keeping pace with the speed of AI adoption in financial services. This means AI-enabled change needs its own line in the enterprise-level performance view and its own risk data at the operations and business unit levels, rather than being managed inside a general technology change category where AI-specific risks are easy to miss.

Why should frontline readiness data be linked to customer communication planning? If a frontline team is already stretched by concentrated change load, that is directly relevant to when and how a customer-facing message about that change should go out, because an under-resourced team is more likely to produce inconsistent answers, longer wait times or missed follow-up when customers respond. Treating readiness and customer communication as two separate workstreams is a common reason DDO and Consumer Duty evidence gaps appear even when each team believes it delivered its part correctly.

References

Why change management maturity matters: how to build it systematically

Why change management maturity matters: how to build it systematically

Change management maturity is the degree to which an organisation has institutionalised change capability so it is repeatable, consistent and improving over time, rather than dependent on individual practitioners or isolated programmes. A mature change function has a defined methodology applied across initiatives, embedded practitioners across business units, governance that connects change activity to portfolio decisions, measurement infrastructure that tracks adoption and benefit realisation, and leaders who model the behaviour change required of others. Maturity matters because it is the difference between an organisation that succeeds at change because of who is in role, and one that succeeds because of how it operates.

Most organisations approach change maturity the same way they approach most capability gaps: they send people on training courses, roll out a methodology, and distribute a set of templates. It is a reasonable instinct. But after working with organisations across industries and geographies, a consistent pattern emerges that challenges this assumption. The teams that made the biggest leaps in change maturity were not the ones with the most comprehensive training programmes or the most elaborately designed toolkits. They were the ones who first learned to see the change happening around them.

That distinction matters enormously. Visibility and measurement do something that training alone rarely achieves: they create intrinsic motivation. When a business leader can look at a dashboard and see that their team is absorbing seven concurrent initiatives, the conversation about change management stops being abstract. It becomes urgent, personal, and practical. And organisations that reach that point of urgency tend to improve their change capability faster than any classroom intervention could achieve.

This article makes the case that building genuine change management maturity requires three things working in concert: meaningful visibility of change across the organisation, robust governance structures that bring discipline to how change is planned and sequenced, and a portfolio-level view that treats change capacity as a finite resource to be managed. Training has a role, but it is further down the list than most organisations assume.

The training-and-templates assumption

Ask a senior HR or transformation leader how their organisation is building change capability, and the answer is usually some version of the same story. A cohort of change practitioners has been trained in a recognised methodology, perhaps Prosci’s ADKAR model or Kotter’s eight-step framework. A standard set of templates has been created and made available on an intranet. Sponsor briefings are scheduled. A change network has been formed.

These are not bad things. But they share a common limitation: they treat change management as a skill to be acquired by specialists, rather than as a discipline to be embedded across the business. The result is that change management remains something that happens to business teams rather than something they actively participate in. Leaders nod along to change plans prepared by dedicated practitioners, but rarely feel enough ownership of the data to ask hard questions or push back on the change load being placed on their people.

Prosci’s research across more than 2,600 organisations reveals the cost of this gap. Projects with excellent change management are 88% likely to meet or exceed their objectives. Projects with poor change management: 13%. That is a nearly seven-fold difference in outcomes, driven largely by the quality of how the people side of change is managed. And yet the majority of organisations still treat the methodology as the destination, rather than as a starting point.

The deeper problem is that training programmes and templates are, by design, disconnected from real-time data. They equip people with frameworks for thinking about change. What they do not do is give business teams a clear, current picture of what is actually being asked of their people, how ready those people are for upcoming changes, or whether adoption is actually occurring once changes go live.

What actually accelerates change maturity

Visibility as the first catalyst

The most reliable accelerant for change maturity is the moment a business leader first sees their team’s change load visualised in a meaningful way. Not a list of projects. Not a status report. A genuine picture of cumulative change impact: how many initiatives are hitting which business units, in which timeframes, and what that means for the people doing the day-to-day work.

Something shifts when that visibility arrives. Leaders who previously treated change management as a compliance exercise start asking different questions. How does this new initiative land on top of what my team is already absorbing? Are we sequencing this sensibly? Who is most at risk of overload? What does our readiness data actually show? These are exactly the right questions, and they rarely get asked without data to prompt them.

This matters because sustainable change capability is built on habit and ownership, not on awareness. A business unit leader who has seen the visual representation of their team’s change load, and who has experienced the relief of better sequencing or the cost of poor planning, will prioritise change management in ways that no training course can instil. The motivation is intrinsic, grounded in something they have directly witnessed.

When business teams can see the data, behaviour shifts

The pattern repeats across organisations of different sizes and sectors. Business teams that engage regularly with change impact data, readiness assessments, and adoption tracking begin to mature much faster than teams where change management remains the exclusive domain of the change team. They start using the language. They ask for assessments before agreeing to new project timelines. They flag risks earlier, because the data gives them the language and the evidence to do so.

Readiness data is particularly powerful in this regard. When business leaders can see that their team’s readiness scores are lagging behind the go-live date of a major system change, the conversation about additional support shifts from a change practitioner’s recommendation to a business leader’s decision. That shift in ownership is the difference between change management as a service and change management as a capability.

Adoption metrics complete the picture. Tracking whether people are actually using new systems, following new processes, or behaving differently after a change goes live tells the organisation something that no impact assessment or readiness survey can: whether the change has truly landed. Mature change organisations do not close out initiatives when they go live. They close them out when adoption targets are met.

This is not simply a technology observation. It is a behavioural one. Data creates accountability. When change impact, readiness, and adoption are all visible, the full lifecycle of change becomes manageable rather than aspirational.

Why change maturity matters and how to build it systematically

What research tells us about mature change organisations

The performance gap is significant

The case for investing in change maturity is not just philosophical. The performance differential between mature and immature change organisations is measurable, and it is substantial.

Prosci’s maturity model research found that more than half of organisations (54%) operate at Level 1 or Level 2 on the five-level maturity scale, meaning change management is either absent, ad hoc, or applied only on isolated projects. Only 11% had reached Level 4 or Level 5, where change management is embedded into organisational standards and has become a genuine organisational competency. The gap between these groups is not marginal: at higher maturity levels, change management occurs across more initiatives, is applied more consistently, and produces significantly better outcomes in terms of benefits realisation and achievement of strategic goals.

McKinsey’s research reinforces this picture. Organisations with excellent change management practices are six times more likely to meet or exceed their performance expectations. The research also found that putting equal emphasis on performance and organisational health during transformations is what separates the 30% success rate from a 79% success rate.

More recently, Deloitte’s research on organisational agility found that organisations leading the way in agility are approximately twice as likely as their peers to report better financial results. Change maturity and organisational agility are not the same thing, but they are deeply connected: an organisation that has built genuine change capability can move faster, absorb more change with less disruption, and recover more quickly when things do not go to plan.

The ability to undergo more rapid change without burning out the workforce is precisely what high-maturity organisations develop. They are not necessarily running more changes. They are running changes better, sequencing them more carefully, tracking readiness more rigorously, and building the organisational muscle to do it repeatedly.

The saturation problem most organisations overlook

One of the most consistent findings in change management research is how severely most organisations underestimate the cumulative burden of change on their people. Prosci’s research found that more than 73% of respondents reported their organisations were near, at, or beyond the saturation point. Yet most change governance conversations focus on individual initiative delivery, not on the total change load being absorbed by any given team or role group.

Change saturation is not simply a question of too many changes happening at once. It is a question of whether the organisation has the structures to see the problem coming, and the authority to do something about it. Without visibility and governance, saturation is invisible until it becomes a crisis. By the time leaders notice the symptoms, including rising resistance, disengagement and initiative stalling, the damage is already done. Readiness scores that were adequate six months earlier have deteriorated. Adoption rates have plateaued. And the change team is firefighting rather than building capability.

The structural foundations of change maturity

Visibility alone is necessary but not sufficient. Organisations that sustain high levels of change maturity over time tend to have three structural elements in place that give their change capability a backbone.

Change governance

Change governance refers to the formal structures, decision rights, and accountability mechanisms that determine how change is planned, approved, and overseen at an organisational level. Without governance, change management remains advisory. Individual practitioners can produce excellent assessments and plans, but if there is no mechanism for those assessments to influence decisions about timelines, sequencing, resourcing, or priority, they sit in folders and gather dust.

Effective change governance typically includes:

  • An executive-level sponsor or committee with explicit accountability for the change portfolio
  • A defined escalation path for change conflicts and capacity constraints
  • Regular rhythms for reviewing the cumulative change load across business units
  • Clear criteria for what triggers a change impact assessment, a readiness review, or an adoption audit
  • Governance checkpoints that require adoption evidence before an initiative can be formally closed

Governance does not need to be bureaucratic. But it does need to be real. The organisations that build genuine change maturity are the ones where change governance carries actual weight in project and portfolio decisions.

Business change processes

Alongside governance structures, mature change organisations embed change management into their core business processes rather than treating it as a parallel activity. This means change impact assessment is a standard part of the project initiation process. It means change readiness data is a standing item on portfolio review agendas, not a one-time survey conducted in the final weeks before go-live. It means adoption measurement is built into the benefit realisation framework from the outset, not bolted on after the fact. And it means business unit leaders have a defined role in the change process, not just as recipients of communications but as active participants in planning, readiness tracking, and adoption accountability.

The practical effect of this integration is significant. When business change processes are built into how the organisation already works, change management becomes part of the operating rhythm rather than an add-on. The cognitive load on individual practitioners reduces. Consistency improves. And the organisation begins to build a shared vocabulary around change impact, readiness, and adoption that reaches well beyond the change team.

Change portfolio management as air traffic control

Perhaps the most critical structural element for organisations managing high volumes of concurrent change is the practice of change portfolio management, sometimes described using the air traffic control metaphor. Just as an air traffic control tower tracks all flights in the air and on the ground, managing runway capacity and issuing ground stops when necessary, an effective change portfolio function tracks all active and planned initiatives, assesses their cumulative impact on affected populations, monitors readiness and adoption status across the portfolio, and has the authority to sequence, defer, or prioritise accordingly.

Protiviti’s analysis of change saturation describes this function well: a change management centre of excellence operating like an air traffic control tower, monitoring what is planned, assessing capacity, and implementing “ground stops” on lower-priority projects when the organisation cannot absorb more change. Without this function, competing projects land on the same business units simultaneously, readiness is assumed rather than measured, and adoption rates become a post-project surprise rather than an in-flight metric.

The air traffic control metaphor is useful precisely because it frames change capacity as a finite resource. Runways have limits. So do people. An organisation that treats change capacity as effectively unlimited will consistently over-commit, under-deliver, and wonder why its change programmes keep stalling.

A practical roadmap for building change maturity

Building change maturity is not a linear process, but there is a practical sequence that tends to produce the fastest results. Organisations that skip directly to governance structures without first establishing data visibility often find that governance lacks teeth, because there is nothing concrete for it to act on. Conversely, organisations that invest in visualisation without governance tend to produce interesting data that does not translate into changed behaviour.

A sequenced approach looks like this:

  1. Start with change impact data. Before investing in methodology training or governance frameworks, get a clear picture of the change currently hitting your business. Which teams are most affected? What is the cumulative load across key role groups? This baseline is the foundation for everything that follows.
  2. Add readiness and adoption tracking. Impact data tells you what is coming. Readiness data tells you whether your people are prepared for it. Adoption data tells you whether it has actually taken hold. Building all three into your measurement framework early means you are managing the full change lifecycle, not just the delivery phase.
  3. Make the data visible to business leaders. Do not present change load, readiness, or adoption data only to the change team. Bring it into the room with general managers, operational leaders, and executives. The goal is to create the shared awareness that makes governance conversations real rather than theoretical.
  4. Establish lightweight governance. Once leaders can see the data, the case for governance is self-evident. Start with a simple portfolio review rhythm and clear decision rights for managing conflicts and sequencing. Governance does not need to be complex to be effective.
  5. Embed change into business processes. Identify two or three core business processes, such as project initiation, business case approval, or benefit realisation reviews, and integrate change impact assessment, readiness gates, and adoption milestones into them. This is where change management moves from advisory to mandatory.
  6. Build capability where it is needed most. Only at this point does targeted training become highly effective, because it is being delivered to people who already understand why it matters. Training disconnected from real change context rarely sticks. Training delivered to leaders who are already engaged with impact, readiness, and adoption data lands differently.
  7. Measure and improve. Use your baseline data to track maturity progress over time. Mature organisations treat change capability as a measured outcome, not an aspiration.

How digital tools support the journey

Building the kind of change visibility that accelerates maturity requires more than spreadsheets. Platforms like Change Compass are designed specifically to help organisations aggregate change impact data across initiatives, visualise the cumulative load on business units and role groups, and track readiness and adoption in a single portfolio view. When business leaders can see a real-time picture of what their teams are absorbing, how prepared they are, and whether previous changes have genuinely been adopted, the conversations about sequencing, prioritisation, and capacity shift from abstract to concrete. That shift, from gut feel to governed data, is often the turning point in an organisation’s maturity journey.

Where the journey actually starts

The organisations that build genuine change management maturity are not necessarily the ones with the most comprehensive training programmes or the most sophisticated methodologies. They are the ones that first make change visible across its full lifecycle, from impact through to readiness and adoption, then put governance structures in place to act on what they see, and then build the portfolio management discipline to treat change capacity as something to be managed deliberately rather than consumed carelessly.

The research is clear: mature change organisations outperform their peers significantly, can absorb more change with less disruption, and are far more likely to achieve the outcomes their transformation programmes set out to deliver. The path to that level of maturity is more practical than most organisations expect. It starts not with a training calendar, but with a dashboard.

To read more about Change Maturity check out our other article here.

Frequently asked questions

What is change management maturity? Change management maturity refers to how consistently and effectively an organisation applies change management principles, processes, and governance across its initiatives. Prosci’s five-level maturity model ranges from Level 1 (absent or ad hoc) to Level 5 (organisational competency), where change management is a strategic capability embedded across the enterprise. Mature organisations apply change management systematically across impact, readiness, and adoption, not just on high-profile projects and not just during the delivery phase.

How does change management maturity affect business performance? The performance evidence is significant. Prosci’s research shows that projects with excellent change management are nearly seven times more likely to meet their objectives than those with poor change management. McKinsey’s research found that organisations with strong change capabilities are six times more likely to outperform their peers. At an organisational level, greater maturity translates directly into higher transformation success rates, better adoption outcomes, and faster realisation of strategic benefits.

What is change portfolio management and why does it matter? Change portfolio management is the practice of tracking and coordinating all active and planned change initiatives across an organisation, assessing their cumulative impact on affected teams, monitoring readiness and adoption across the portfolio, and sequencing them to prevent saturation and conflict. It is sometimes described using the air traffic control metaphor: like managing runway capacity, it ensures initiatives land without collision. More than 73% of organisations are operating at or near change saturation, which makes portfolio management one of the highest-leverage investments a mature change function can make.

What is the difference between change readiness and change adoption? Readiness measures whether people have the awareness, knowledge, and capability to change before a go-live event. Adoption measures whether they are actually using new ways of working after it. Both matter, and both are frequently under-measured. Organisations that track only readiness often mistake pre-launch preparation for sustained behaviour change. Organisations that track only adoption often find that poor readiness caused the low adoption rates they are now scrambling to fix. Mature change organisations track both, sequentially and in relation to each other.

What is the fastest way to build change management maturity? Based on observed patterns and available research, the fastest path to maturity begins with making change visible to business leaders across its full lifecycle, covering impact, readiness, and adoption, rather than starting with training. When leaders can see concrete data on what their teams are absorbing and whether change is actually sticking, they develop an intrinsic motivation to manage it better. Governance structures and embedded business processes then give that motivation a formal channel. Targeted capability building is more effective once leaders already understand why it matters.

References