Sample Report · Enterprise Architecture

Application Portfolio Review — Sample

A worked example of reviewing every system an organisation runs — cost against value, duplication nobody had counted, the systems with no owner, and a disposition for each.

Markdown. No sign-up, no email.

This is an illustrative example. The organisation and figures are invented to show the shape of a review that leads to decisions. Copy the structure; count your own systems.

Every application receives one of four dispositions. A review that ends without one per system is an inventory, and an inventory changes nothing.


Application portfolio review — 2026#

Organisation~900 staff, 4 countries
Applications found147
Applications on the previous list89
Annual application spend£4.1M
MethodFinance records, network traffic, directory sign-ins, interviews

1. The count#

Fifty-eight systems were not on any list. They were found in the expense ledger, in sign-in logs and by asking departments what they use.

How it was foundCount
Already on the register89
Expense records — bought on a card31
Sign-in logs — free tier, no cost trail14
Named in interviews only9
Network traffic to an unknown service4

The 14 free-tier systems are worth noting. They cost nothing, so no finance control saw them, and four hold customer personal data.

2. Disposition#

SystemsAnnual cost
Invest — strategic, growing18£1.6M
Maintain — fit for purpose, stable61£1.4M
Replace — no longer adequate, or unsupported24£0.8M
Retire — duplicate, unused, or superseded44£0.3M

Forty-four systems can be retired, and they are only 7% of the spend. That is the usual shape: the count is dramatic and the saving is modest. The value of retiring them is the integrations, the access reviews, the vendor assessments and the attack surface that go with them — not the licence fees.

3. Duplication#

CapabilitySystemsAnnual costNote
Customer relationship management4£410kOne per region, no shared data
File sharing5£96kThree unsanctioned
Project tracking6£71kOne per department
Expense management2£54kAn acquisition, never merged
Video conferencing3£88kTwo are free tiers
Customer support ticketing3£120kSales, service and technical each have one

Four CRM systems is the finding with the largest consequence. Not because of the £410k, but because "how many customers do we have" cannot currently be answered. Each system holds a different subset, the definitions differ, and reconciliation is a monthly manual exercise for two people.

Six project tracking systems is a governance finding rather than a technology one: six departments each bought independently, each purchase was small enough to avoid review, and no step in the process asked whether one already existed.

4. Ownership#

Systems
Named business owner and technical owner71
Business owner only38
Technical owner only16
Neither22

Of the 22 with no owner, 9 are in daily use. Nobody is responsible for their contracts, their access reviews, their upgrades or their data.

One of the nine processes payroll variations.

5. Support and currency#

Systems
Current version, supported92
Supported, behind31
Out of vendor support19
Vendor no longer trading5

The five orphaned systems have no route to a fix. One is the warehouse label printing system, which stops shipping when it fails. It has failed twice, and both times recovery depended on one person who has since retired and was contacted informally.

That is not a technology risk. It is a business continuity risk with a technology cause, and it is reported as such.

6. Integration#

Count
Documented integrations61
Actually found148
Point-to-point121
Via the integration platform27
File drops or scheduled exports34
With a named owner44

The organisation believed it had 61 integrations and has 148. The 34 file-based ones are the most fragile — a scheduled export into a folder that another system reads, with no monitoring, no error handling, and no owner. Three have failed silently in the last year, one for six weeks.

7. Concentration#

SupplierSystemsAnnual spendExit time, estimated
Supplier A14£1.2M18 months
Supplier B9£680k12 months
Supplier C6£410k9 months

Supplier A carries 29% of application spend and supports three capabilities including the system of record for customer data. No exit plan exists and the contract auto-renews with 90 days' notice, which is the number that matters: exit takes an estimated 18 months, and the decision window is 90 days.

8. Recommendations#

PriorityAction
1Assign owners to the 22 unowned systems, starting with the 9 in daily use
2Warehouse label printing — supplier gone, single point of failure, recovery depends on a retired employee. Replace or contract support.
3Diarise the Supplier A notice date and start an exit assessment. 90 days against 18 months.
4Retire the 44, in three waves, checking integrations before each
5Consolidate CRM. Not for the £410k — so that the customer count has an answer.
6Bring the 34 file-based integrations under monitoring, then convert the worst
7Purchasing gate: any software purchase names the capability it serves and what already serves it

Recommendation 7 prevents recurrence. Without it, the 44 retired systems are replaced by 44 new ones over the next four years by exactly the same mechanism.


Notes on using this format#

Find the systems, do not ask for them. Fifty-eight of 147 were absent from the register, and they were found in expense records and sign-in logs rather than by asking.

Give every system a disposition. Four categories, one per system, no exceptions. An inventory without dispositions produces a document; dispositions produce a plan.

Report duplication by capability, not by system count. "Four CRMs" is a fact. "We cannot say how many customers we have" is the consequence, and it is what makes the case.

Put exit time next to notice period. Eighteen months against 90 days is the single most actionable line in this review.

Back to Enterprise Architecture