The situation

A flight school does not run like an office. The day is built around aircraft, instructors and simulator slots, and those slots are the scarce resource. When a simulator is unavailable, the training hours booked against it do not move to tomorrow. They are gone, and the cost lands on students, instructors and the schedule.

Around that sits a regulated organization. Training records have to be produced on request, in a form that satisfies a civil-aviation regulator rather than an internal preference. Internal audit, enterprise risk management and SoX controls put their own demands on the same systems and the same evidence.

The third condition is the ordinary one that quietly decides everything. Demand for IT arrives from every department at once, all of it urgent to whoever raised it. A central IT office with no shared way to prioritize becomes both the bottleneck and the villain. Every department believes it is being deprioritized, none can see the other requests, and the argument escalates to whoever is most senior.

Four aircraft flying in close formation

The decision

Push the prioritization out. Keep the standards in.

The instinct in that seat is to centralize: one intake queue, one owner, IT decides. It fails predictably, because IT does not know which flight schedule matters more this month. A federated governance model went in instead. Departments own their priorities and are accountable for the trade-offs those priorities create. Standards, risk posture, architecture and control evidence stay central.

The second call was to refuse a big-bang replacement. A multi-year digital transformation was sequenced into deliverable pieces: Scrum where the work was project shaped, Kanban where it was service shaped. SAFe coordinated the portfolio above both, so departments could see one another’s queues.

Rejected: a single central intake queue with IT as arbiter, a replace-everything program, and governance that lived only as a document.

What was built

The federated model came first: who decides what, what stays local, what stays central, and what a department accepts when it moves its own request to the front. Paired with that came repeatable prioritization and accountability practices, so the answer to why something was not done this month was a visible trade-off, not an opinion.

Delivery ran on that. Scrum for project work, Kanban for service and operational flow, SAFe as the coordinating layer above the portfolio.

The supplier and procurement lifecycle covered flight simulators and business-critical technology end to end: specification, selection, contract, acceptance, maintenance regime, vendor relationship and renewal. Simulators are capital equipment with long lead times, and their maintenance windows collide with the training calendar. The lifecycle was planned against the schedule rather than the budget year.

Underneath all of it sat control evidence. Supporting internal audit, enterprise risk management and SoX controls means producing evidence on request and keeping it producible, which is a design constraint, not an afterthought.

How it was proven

Proof in that environment is not a dashboard. It is whether simulator availability held against the training schedule. Whether the portfolio delivered what departments had agreed to in the open. Whether internal audit received its evidence as routine work instead of as a fire drill. One more nobody writes down: whether prioritization arguments stopped needing the most senior person to settle them.

Civil-aviation compliance sets a harder standard than most corporate reporting. The question is not whether a policy exists. It is whether the record of what happened can be produced, intact, when someone external asks.

What it changed

Over more than 9 years, IT ran as a governed portfolio rather than a request queue. Departments prioritized their own demand inside a model they understood and could defend. The simulator estate ran on a managed lifecycle, from specification and acceptance through maintenance and renewal. Internal audit, enterprise risk management and SoX controls were supported as standing work, not as a periodic scramble.

The durable change is a habit. Building under auditors and aviation regulators for nearly a decade is why guardrails now arrive with the design instead of 6 months after it. The security and compliance case that later made enterprise AI adoption possible was written by someone used to being asked to prove what happened.

What I’d do differently

Write the decision rights down and re-ratify them every year. Federated governance decays back toward central control the moment the map lives in people’s heads. In any dispute, the fastest path is to ask the IT office to decide.

Treat SAFe as vocabulary rather than doctrine. What it delivered was a shared cadence and a portfolio view. The ceremonies that served neither should have been cut in the first year instead of tolerated out of method loyalty.

Publish the simulator lifecycle calendar earlier, and publish it widely. Lead times on that class of equipment punish late decisions harder than any software procurement. A maintenance window agreed in advance with the training schedule beats a faster approval process.

“Governance is not a document. It is what happens when two departments want the same week and nobody senior is in the room.”