Simple Smooth Safe
The FAROL Method

Digital transformation of government ministries, built to be repeated.

Farol is Portuguese for lighthouse: one service, lit early, showing the way for everything that follows. The name doubles as the acronym of the five principles the method is held to. It is for ministries that need one service working and measured before they commit to a programme — and that intend to run the next one themselves.

Updated 13 August 2026

Ler esta página em português

The problem

Government digital programmes are procured in multi-year blocks and judged at the end. That is the whole problem in one line: a long horizon hides failure. A decision that was wrong in the first months does not surface until the money is spent, everything else has been built on top of it, and everyone who made it has moved on.

The large contract is the failure mode, not the safeguard. The NHS National Programme for IT was abandoned at a cost of roughly £10bn. Healthcare.gov was sunk by its systems integrator and then rescued by a team of under twenty people. Size buys the appearance of seriousness and very little else.

The other standard failure is building identity and infrastructure before any service a citizen actually wants. Kenya spent roughly US$100m on Huduma Namba, a national identity number that arrived ahead of the services that would have given people a reason to register; eCitizen, which led with services, is the counter-example. And a programme that survives both of those still tends to leave dependency rather than capability — the service runs, and it runs because the supplier is still there.

FAROL exists because all of this is documented, and it is built backwards from the record: what worked in Rwanda, Cape Verde, Togo and Estonia, and what failed in Kenya, the United Kingdom and Australia. Every rule in the method is charged to a programme that already learned it somewhere else, at someone else's expense.

Five principles, non-negotiable

Non-negotiable means something checkable here: any project choice that violates a principle is escalated to the sponsor together with an alternative. There are no silent exceptions.

The phase engine

  1. P0 · 3 weeks

    X-Ray

    Where is the money and the pain? Week one follows the money: revenue and cost by service, where the fees sit, where the leakage happens, where paper still rules. Week two follows the queue — volumes, waiting times, points of discretion, citizen pain. Week three prioritises and sells: one beacon service chosen, with the business case and the 90-day plan ready for signature.

    Exit gate: a business case signed by the Minister. No signature, no P1 — which is what stops months of interest without commitment.

  2. P1 · 90 days

    Beacon

    Can we deliver visible value? One service end to end — application, workflow, decision, payment, verifiable document — redesigned before it is coded, so every field, signature and stamp justifies itself or dies. The legal basis is a ministerial order rather than legislation: weeks instead of years. The dashboard is public from week four, and the service ships with an assisted channel, a counter and agent network that files on behalf of citizens without a smartphone.

    Exit gate: the target metrics are met — or the programme stops or pivots, publicly.

  3. P2 · 6–12 months

    Foundation

    Can the ministry sustain scale? A clean master registry of whatever the ministry actually is: people, licences, cases, assets. Minimum viable interoperability — a simple gateway, not a national platform. Pragmatic identity, using the civil registry, SIM registration or bank KYC rather than waiting for a national ID. A legal package that settles electronic acts and basic data protection, and an internal academy that trains the trainers.

    Exit gate: three services in production, operated exclusively by the ministry's own staff.

  4. P3 · Ongoing

    Factory

    Does the machine replicate itself? Service by service from the playbook, with a shared platform team alongside the service teams, and benchmarking across services and across ministries on the same standard metrics: time from application to delivery, cost per transaction, revenue collected against potential, digital transactions per month, and what citizens say about it.

    Exit gate: a pipeline prioritised and executed without the architect on site.

The gate at the end of P1 is a kill gate, and that is the point of it. The targets are set on day zero, in writing, and if they are missed on day 90 the programme stops or changes direction — publicly, with the numbers that say so. Almost nothing in this field is built so that it can be stopped by its own evidence, which is exactly what makes the evidence worth anything afterwards. If the targets are missed, the programme stops at no cost to the next phase.

The artefact library

Each phase produces documents rather than a deck. Twelve are indexed, and the status column is the honest part of the table.

ArtefactPhaseStatus
A1 Diagnostic CanvasP0Ready — published
A2 Service Prioritisation MatrixP0Ready — within the Canvas
A3 Draft Ministerial OrderP0To be drafted
A4 Business CaseP0Ready
A5 Service BlueprintP1Ready
A6 Public dashboard templateP1To be drafted
A7 Resistance Management PlanP1Ready
A8 Minister's Communication KitP1To be drafted
A9 Academy curriculumP2To be drafted
A10 Phase contract templateAllTo be drafted
A11 Compliance checklistAllTo be drafted
A12 Decision Log and Risk RegisterAllTo be drafted

An artefact enters the library only after it has been used on a real case. Four of them are written as documents today — A2 lives inside A1 — and the rest are not. Saying that here is cheaper than being found out later.

The diagnostic canvas is published in full, because the questions a ministry is asked in the first three weeks are the fastest way to judge whether any of this is serious. It prints to A4 and is meant to be filled in.

Field rules

Twelve rules are distilled from public programmes that worked and public programmes that did not, and each one is charged to the case that paid for it. Breaking a rule is escalated, exactly like breaking a principle. Six of the twelve:

Always an assisted channel

Every digital service launches with an agent or counter network that files on behalf of citizens with no smartphone and no digital literacy. Irembo in Rwanda and M-Pesa in Kenya won on exactly this; digital-only excludes the people a public service exists for, and the political backlash follows.

Service before identity

Citizens adopt when they can see what a service does for them. Kenya's Huduma Namba spent roughly US$100m on a national identity number ahead of the services that would have given anyone a reason to register; eCitizen led with services and did the opposite.

Once-only

The state never asks a citizen for data it already holds, so every form is checked against the existing registries before it is designed. This is the founding principle of Estonia's X-Road, and it is the cheapest rule on this list to adopt.

Automated decisions need a human appeal

No automated refusal or charge without a simple route to a person who can overturn it. Robodebt in Australia ran to roughly A$1.8bn in remediation and the Dutch Toeslagenaffaire ended with the government resigning: automating an unfair rule produces unfairness at industrial scale.

Large contracts fail, small teams rescue

Prefer small lots, replaceable suppliers, and state ownership of the data and the code. The NHS National Programme for IT was abandoned at roughly £10bn; Healthcare.gov was sunk by its integrator and rescued by a team of under twenty.

Operating cost settled before go-live

Who pays to run the service in year two — transaction revenue, the ministry's own budget, or a public-private partnership — is written into the business case before launch, not discovered after it. Donor-funded pilots that skip this die with the funding.

What makes it different

A gate that can stop it

The P1 targets are set on day zero and judged in public on day 90. Miss them and the programme stops or pivots, on the same dashboard that has been showing the numbers all along. A method that cannot be stopped by its own evidence is not producing evidence.

Ownership is the method, not the handover

Seconded ministry staff operate the service from day one, rather than receiving it in a transition phase at the end. The outside team becoming unnecessary is the success condition: an architect still indispensable to daily operations by the third case is a failure signal, not job security.

Built backwards from documented failure

Twelve field rules, each one charged to a programme that already succeeded or already failed somewhere else, at someone else's expense. The originality is not in the ideas. It is in refusing to pay for those lessons a second time.

What it is not

FAROL is not a procurement vehicle, and it is not a software licence with a diagnosis attached to it. It is also not a fit for a ministry with no capacity to own anything: if nobody inside can operate the service from day one, a cycle produces artefacts and no change. A ministry that wants a supplier to run its service permanently should buy that instead, and we would rather say so on the first call than in month six.

Why this is an asset

FAROL is written down and numbered. The phases have codes, the gates have criteria that can actually be failed, and the artefacts have an index with a status column that admits what is not written yet. Someone other than its author can pick it up and run a phase with it, which is the only test that means anything.

It is domain-independent. The artefacts do not change between a health ministry and a finance ministry; what is written in them does. A diagnostic canvas asks the same questions of a licence renewal as it does of a tax refund.

And it compounds. Every phase adds to the ledger of evidence, so a fourth case starts from everything the first three learned rather than from a blank page.

Which is what makes it licensable. The same sequence, the same artefacts and the same metrics in any ministry means results can be compared across ministries and across countries, and local teams can be trained to run it — rather than selling hours, over and over, always starting from zero.

The test

A method that exists only in someone's head is not an asset. It is a person. It cannot be taught, audited or transferred, and it walks out of the door when they do.

Talk to us

Write to info@simplesmoothsafe.com. Say which ministry or organisation you are writing about and which service is hurting — not what you would like to buy. You will get a direct answer, including “this is not a fit” when that is the honest one.

Email info@simplesmoothsafe.com