The CIO Track: Nine Decisions, In The Order They Arrive
A sequenced path through enterprise AI, cloud, licensing, security, architecture and IT finance, built for someone who has to decide rather than implement. Each module ends with a question to take into a meeting and a number to demand.
This is not a course in the sense the word usually implies. There is no instructor, no schedule, no credential and nothing to enrol in. It is a route through material we have already published, in an order that matches how the decisions actually arrive, with something to do at each stage.
We say that plainly because "CIO Academy" normally means recorded lectures and a certificate, and a certificate from a supplier is worth what you would expect. What is here is different in one specific way: every module ends with a question you can ask in a real meeting and a number you can demand. Not a quiz. If a module does not change what you ask for on Monday, it has failed and you should skip it.
Who this is for#
Someone accountable for the decision rather than the implementation. You do not need to configure anything. You do need to be able to tell when an answer you are being given is not an answer, and that is mostly what this teaches.
It assumes you are time-poor and sceptical, which are the two most reliable traits of people who have held the job for a while.
How to use it#
Take the modules in order the first time. They are sequenced by dependency, not by importance — module 2 is more urgent than module 1 for most organisations, and it is second because it needs the vocabulary from the first.
Read the material, then do the exercise, then take the question into an actual meeting. The last step is the one that converts this into anything. Reading four modules in an evening produces recognition, which is the feeling that you would know this if you saw it again. It disappears the moment a vendor is confident at you.
Module 1 — What AI readiness actually measures#
Most readiness assessments measure enthusiasm. The useful ones measure whether a decision can be made and executed: who owns the data, who signs off a model going live, and what happens when it is wrong.
Read: AI readiness · Enterprise AI Report
Do: Run the AI Maturity Assessment. Maturity is set by your weakest dimension, not your average, because that is where work stops.
Ask in the meeting: "Who is the named individual accountable for a model going to production?" A role title is an acceptable answer. "The committee" is not — accountability that is shared is absent at the moment it is needed.
Demand this number: How many AI systems are in production today. If the answer requires a survey, that is the finding.
Module 2 — Why AI pilots do not become systems#
The most expensive pattern in enterprise AI is a portfolio of pilots that each work and none of which ship. The blockers are consistently reported as data access, ownership and integration — organisational problems that another pilot will not solve.
Read: AI agent adoption
Do: List every AI pilot running. For each, name who owns the production budget. If the answer is the innovation team, it is not going to production, whatever the demo showed.
Ask in the meeting: "What would have to be true for this pilot to run for a year without the team that built it?"
Demand this number: Your own pilot-to-production rate over the last two years. Compare it to the 88% failure figure in the research before deciding whether you are the exception.
Module 3 — Licensing, where the money quietly goes#
Licensing is the largest controllable line in most IT budgets and the one least often examined, because it is tedious and the rules are deliberately intricate. It is also where a single metric change can move a number more than a year of efficiency work.
Read: Licence optimisation · Oracle
Do: Run the Licence Compliance Calculator against your own counts.
Ask in the meeting: "Which of our metrics scale with headcount rather than usage?" A per-employee metric is a tax on a successful year, and reducing deployment saves nothing against it.
Demand this number: Total licence cost modelled at your three-year headcount plan, not today's. The gap between those two figures is usually the entire conversation.
Module 4 — Non-production, DR and the audit you have not had#
Entitlement breaks quietly in the environments nobody tracks: cloned for a project, never decommissioned, running production data in UAT. None of it is malicious and all of it is billable.
Read: Licence optimisation, the non-production and DR sections specifically.
Do: Ask for an inventory of non-production environments with an owner and a decommission date against each.
Ask in the meeting: "What happens to our DR entitlement if we power the site on for a test?" Get the answer in writing from the vendor, naming your topology. A verbal assurance from an account manager is not a defence.
Demand this number: How many non-production environments exist. If nobody can answer without a discovery scan, the exposure is unmanaged rather than accepted.
Module 5 — Cloud, and the business case nobody revisits#
The migration business case is written once and never checked. Cost decouples from workload, and by the time anyone notices, the person who owned the case has moved on.
Read: Cloud adoption · Cloud knowledge centre
Do: Ask for cost per unit of work — per transaction, per customer — over 24 months, rather than total spend.
Ask in the meeting: "What would it cost to move this workload back, and who has priced it?" Repatriation has stopped being an admission of failure and become an ordinary option.
Demand this number: Cost per unit of work, 24-month trend. If only total spend exists, that absence is the finding.
Module 6 — Security, where the entry vector moved#
Vulnerability exploitation has overtaken stolen credentials as the top way in. That inverts the usual prioritisation, where identity gets the budget and patching gets a monthly window.
Read: Cybersecurity readiness
Ask in the meeting: "What is our patch SLA for internet-facing systems, separately from the general estate?" And: "Which administrative accounts are exempt from MFA?" Partial coverage of an authentication control is defeated by finding the gap, and the gap is discoverable.
Demand this number: Actual days from disclosure to full deployment for the last three critical vulnerabilities affecting you. Not the target — the measured figure.
Module 7 — Governance, residency and the dates already in force#
Regulatory obligation is usually discovered during a customer's procurement review rather than during a compliance programme, which is the most expensive possible order.
Read: AI policy · Data residency · UAE · Saudi Arabia
Do: Check the CIO Brief for obligations already in force.
Ask in the meeting: "Is our residency commitment contracted or technically enforced, and what physically prevents a write to another region?" Most buyers accept the first believing they bought the second.
Demand this number: How many of your AI systems have an EU-facing surface, and how many carry the required disclosure. The second number is usually smaller.
Module 8 — Buying, and where leverage actually comes from#
Leverage at renewal is a function of when you start, not how well you negotiate. A priced alternative nine months out is leverage; the same work three months out tells the vendor you cannot move, and they know before you do.
Read: Vendor Selection Scorecard — the criteria, the cost lines missing from proposals, and the negotiation levers.
Do: Score a live selection and stress-test it. If the winner flips when one weight moves, the decision rests on your weighting rather than your evidence.
Ask in the meeting: "What is the notice deadline on our three largest contracts?" It falls months before the renewal date, and missing it renews the term at the vendor's number with no conversation.
Demand this number: The renewal uplift cap, in writing. It is the highest-value clause obtainable during competition and close to impossible afterwards.
Module 9 — Architecture, and knowing what you actually run#
Every module above assumes you can answer questions about your own estate. Most organisations cannot, and the discovery is the work.
Read: Enterprise architecture · Technology Radar
Do: Run Red Team My Enterprise and take the findings with the cheapest verification steps first.
Ask in the meeting: "Which systems can only one person operate?" A single-operator system is an outage with a notice period attached.
Demand this number: The count of components running past their support date, with a named owner and a dated decision against each: upgrade, isolate, or accept in writing.
What this deliberately does not include#
No certificate. We are not an accrediting body, and a certificate issued by a supplier to its own prospects is marketing with a border around it. If you want a credential, the certifications guide covers ones that carry weight in a hiring market.
No vendor rankings. We do not score named products. We have not run them, and an invented comparative score would be worthless to you and indefensible for us — the same position our benchmark takes.
No predictions. Nothing here forecasts your outcome. Where we cite a figure, it is measured and linked; where we have no base rate, the material says so rather than implying one.
If you only do one module#
Module 3. Licensing is the largest controllable line in most IT budgets, the least examined, and the one where a single question in a single meeting has moved a seven-figure number. It is also the module where you will most quickly find out whether your organisation can answer questions about itself.
What else is coming for The CIO Track
Guide Ready
The path, and how to work through it.
Worked Example Not yet
Done once, in full.
Checklist Not yet
Check your own work.
Template Not yet
A starting file.
FAQ Not yet
The questions learners ask.