Enterprise velocity

The go-live that sued its integrator

TL;DRNational Grid ran a big-bang SAP cutover in 2012 despite a known defect backlog; payroll broke, cleanup topped $585m, and the utility sued for roughly $1bn. Wipro settled for $75m. The lesson: a fixed-bid contract that pays on go-live, not on a working system, is architecture that prices in the incentive to ship broken.

Because the contract paid the integrator to reach go-live, not to be right. National Grid US ran a big-bang SAP cutover in November 2012 with a system its own testing had flagged as unready. Payroll broke for thousands, the monthly book-close stretched to 43 days, remediation ran past half a billion dollars, and the utility sued for roughly a billion. Wipro settled for $75m in 2018 — the tell that the downside was capped from the start.

What actually broke at National Grid?

National Grid US, a utility serving Massachusetts, New York and Rhode Island, hired Wipro as systems integrator around 2010 and paid roughly $140m to replace its legacy back-office systems with SAP. The program went live on 5 November 2012, in the middle of Hurricane Sandy and against a slip that would have cost tens of millions and a trip back to the rate commission. The new system miscalculated pay en masse: some staff were overpaid, some underpaid, some not paid at all. National Grid overpaid workers by about $8m it never clawed back and, per the case write-ups, owed a further $12m for short pays and bad deductions.

Financial reporting seized up with it. A book-close that used to take under a week now took 43 days. Stabilisation ran at about $30m a month, total outlay passed $300m, and a 2014 audit estimated the upgrade could reach $1bn. Later analysis put the cleanup alone at roughly $585m, more than 150% of the original implementation cost. In 2017 National Grid sued, alleging it had been fraudulently induced into the contract; in 2018 Wipro settled for $75m, with no admission of liability.

Why does a go-live end up suing its integrator?

Diagnose the incentive, not the engineers. On a fixed-bid program with payment milestones tied to cutover, the deliverable the integrator is actually paid for is the event of going live — not a system that computes payroll correctly on the Monday after. Once a fixed date and a fixed price are both set, every defect discovered late becomes a reason to push harder toward the date, never to move it. Testing that says "not ready" is arguing with a contract that says "get paid on go-live," and the contract usually wins.

That is why the defect backlog is so reliably known before cutover. Everyone can see the list; the incentives simply all point at shipping anyway. It is the same failure mode we picked apart in the 12-month purchase of a 6-week feature — procurement optimises the paperwork, not the outcome — and it is why your change advisory board can make releases riskier rather than safer when it funnels a year of accumulated change into one irreversible weekend. Big-bang is not a delivery method; it is a bet that you will not need to roll back the thing you cannot roll back.

What does a $75m settlement actually buy back?

Line the money up and the shape of the deal becomes obvious.

ItemAmount (approx.)
SI fee paid to the integrator$140m
Payroll overpaid, never recovered$8m
Owed for short pays and bad deductions$12m
Stabilisation run-rate$30m / month
Cleanup cost$585m
2014 audit program estimate$1bn
Recovered from integrator (2018 settlement)$75m

The settlement recovered roughly an eighth of the cleanup and well under a tenth of the billion-dollar program estimate. That gap is not an accident; it is the design. Liability caps, exclusions for consequential damages, and the ordinary economics of litigation mean a systems integrator's realistic worst case is a fraction of the client's realistic loss. Ship-and-settle is a rational strategy when the downside is bounded and the upside — getting paid for go-live — is not. The contract you signed is the architecture of that outcome, as surely as any diagram.

And it repeats. A few years later, one of America's largest brewers took the same shape to court: its SAP go-live shipped with eight critical and 47 high-severity defects on the record before cutover, thousands more surfaced in hypercare, and the company sued its integrator for $100m. Different industry, identical mechanics: a fixed commitment to a date, a big-bang cutover, and a defect list everyone had already read. This is not the median outcome — as we set out in 15.5 months is the median, not the horror story, most programs land undramatically — but when two of them on two continents fail the same way, the common cause is the incentive structure, not the luck.

Where does the fix actually live?

Not in a sharper indemnity clause. It lives in removing the incentive to ship broken before you sign anything: pay for a working system rather than a date, put the people who build on the hook for the Monday after, and replace the single irreversible weekend with small, reversible cutovers you can back out before payroll runs. That alignment is most of why we build these platforms in-house on one event bus instead of buying a fixed-bid big-bang — the incentives and the architecture turn out to be the same decision.

The National Grid docket closed in 2018, but the contract pattern that produced it is still the default on most eight-figure integration deals being signed this year. The utilities, CPGs and brewers writing those cheques are, mostly, buying the same three things: a date, a cap, and a backlog everyone has quietly agreed to ignore. The interesting question for the next few years is not whether big-bang go-lives keep failing — they will — but which enterprises stop paying integrators to hit a date and start paying teams to be right on the morning after it.

Frequently asked questions

Did National Grid go live against advice?

In effect, yes. The SAP system went live on 5 November 2012 while testing showed it was not ready, under deadline and cost pressure amid Hurricane Sandy. Payroll miscalculated for thousands and the monthly book-close stretched to 43 days. National Grid later alleged it had been fraudulently induced into the contract.

Why did Wipro only pay $75m when remediation cost far more?

Because liability caps, exclusions for consequential damages and litigation economics bound an integrator's downside well below the client's loss. National Grid's cleanup ran about $585m and a 2014 audit put the program near $1bn; the 2018 settlement recovered $75m, with no admission of liability by either party.

How do you avoid a go-live that ends in a lawsuit?

Remove the incentive to ship broken. Tie payment to a working system rather than a date, put the people who build on the hook for running the result, and replace one irreversible weekend with small, reversible cutovers you can roll back before payroll runs. Contract structure is the real architecture.

Stuck with exactly this?

BrewOS builds the full route-to-market stack for global brewers — order capture, stock, loyalty, returnables, delivery and analytics on one event bus, run by a team of ~20 engineers. Bring us the feature that’s been stuck the longest and we’ll show you how we’d ship it in days.

Book a 30-minute walkthrough