Digital transformation done right (Bermuda)

Published: 5 Jun 2025
Type: Insight

As any specialised tech lawyer or technology consultant will tell you, digital transformation projects are not for the faint of heart.

The more innovative and untested the technology solutions are, and the more those solutions will radically transform your business, the higher the risk is of project failure.

Over the last ten years, there have been hundreds of news reports of failed digital transformation projects. There are now so many documented failures, no organisation can say they haven’t been warned.

The May 16 article in The Economist, titled “Why so many IT projects go so horribly wrong” is no exception.

Citing research published by an Oxford professor, the article points out that IT projects have unique risk management challenges.

That research discloses that the mean cost overrun for 20 per cent of all IT projects is 450 per cent, and that those risks exist because “IT projects reach deep into organisations, which means tech neophytes often call the shots”.

The neophyte risk rings true because very few IT executives will oversee more than just a few critical transformative projects in their entire career.

The many documented failures of transformative projects are exactly why a 36-page chapter of my 2021 book concerning IT project best practices is titled “Why Technology Projects Fail: Lessons Learned”, and why the next chapter in the book is titled “Dear IT Executive: Let’s Put The Lessons Learned Into Practice”.

Considering that there are so many digital transformation projects now being either considered or under way in Bermuda, including some highly innovative AI projects, The Economist’s article was a good reminder to flag a few common pitfalls to reduce project risk.

The most serious risk of digital transformation failure is not that project problems will cause project abandonment.

The real project risk to be managed is that the project will not achieve its organisation’s definition of transformative success, including: being on time; being on budget; materially achieving the desired operational functionality; ensuring mechanisms of performance verification; ensuring responsive and effective performance remediation; and achieving acceptable standards of security and operational resiliency.

One of the most common and serious mistakes that contributes to digital transformation failure arises when the proposed business innovations, including the desired operational outcomes, are not well defined as performance specifications, service levels and key performance indicators.

That mistake often occurs when transformative projects do not “separate design from build”, as separate and distinct phases of project implementation.

Practically speaking, organisations must first have a clear understanding of the house they want to build before they can select the technology that is best suited to deliver those innovative outcomes.

Since all digital transformation projects involve the procurement of either (or both) technology goods or services, it is essential that organisations manage risk with focused contracts that contain:

  • Terms for the commercial allocation of risk that are consistent with industry accepted commercial norms and practices. Off-the-shelf vendor contracts very rarely meet those criteria
  • Covenants concerning the vendor’s project expertise, experience, qualified personnel and professional qualifications that reflect the findings of rigorous vendor due diligence
  • A detailed technology solution definition so that both parties understand the required functionality of the procured solution
  • Provisions that separate business innovative process design services from all technology build services to permit key performance indicators and “value for money” verification
  • Provisions to ensure ongoing performance monitoring and verification, including effective service remediation
  • Day-to-day dispute or misunderstanding resolution mechanisms
  • Adequate technology support, update, enhancement, new release and maintenance provisions
  • Solution specifications to ensure enterprise interoperability, connectivity and compatibility, especially where digital solutions meet legacy systems
  • Terms to satisfy the organisation’s legal and regulatory requirements for cybersecurity, privacy, operational resilience and business continuity, outsourcing risk management and governance compliance

In fact, given the large number of publications about digital transformation, including essential AI contract terms and conditions, the abject failure of organisations to contractually consider all of those risk management issues may constitute some degree of malfeasance or misconduct by those who are managing those projects.

As I suggest in my 2021 book, digital transformation projects are like icebergs: only 10 per cent of the project risk is visible to inexperienced executives and the other 90 per cent of project risk, which can sink any digital transformation project, lurks below the surface.

Remember my book’s chapter nine title: “Dear IT Executive: Let’s Put The Lessons Learned Into Practice”.

First Published in The Royal Gazette, Legally Speaking column, June 2025

Share
More publications
Appleby-Website-Private-Client-and-Trusts-Practice-1905px-x-1400px
15 Apr 2026

Purpose trusts: Bermuda’s answer to modern asset structuring

Purpose trusts represent a notable development in modern trust law, particularly within offshore financial jurisdictions such as Bermuda. Unlike traditional private trusts, which are established for the benefit of identifiable beneficiaries, purpose trusts are created to achieve specific objectives or purposes. Historically, common law jurisdictions were reluctant to recognise such arrangements due to the absence of beneficiaries capable of enforcing the trust. However, legislative reforms in Bermuda have significantly expanded the scope of trust law by expressly validating noncharitable purpose trusts. Through the enactment of the Trusts (Special Provisions) Act 1989 (‘the 1989 Act’), Bermuda introduced a statutory framework that allows trusts to exist for defined purposes, provided certain legal requirements are satisfied. This innovation has made Bermuda a leading jurisdiction for the establishment of purpose trusts, particularly in the fields of international finance, corporate structuring and private wealth management. This article examines the legal foundations of purpose trusts under Bermuda law, focusing on their historical development, statutory framework, requirements for validity, enforcement mechanisms and practical applications.

Website-Code-Bermuda-1
10 Apr 2026

Bermuda Regulatory Update – Economic Substance Amendment Act 2026

On 31 March 2026, the Economic Substance Amendment Act 2026 and the Economic Substance Amendment Regulations 2026 (together, the “2026 Amendments”) came into force, enacting changes to the Economic Substance Act 2018 (“ES Act”) and Economic Substance Regulations 2018.

ICLG Fintech 21 cover
10 Apr 2026

Digital asset developments and Bermuda’s regulatory readiness

While frightening to some, “finance bros” and “tech bros” are now wearing the same gilets as traditional finance products and structures are being infused with digital asset adaptation.

Appleby-Website-Insurance-and-Reinsurance
1 Apr 2026

Q1’26 Suggests Cat Bond Issuance Could Reach $20bn Again, Private ILS & Sidecar Surge to Continue

It’s been an exceptionally busy start to the year for the catastrophe bond sector, with Q1’26 officially becoming the second highest Q1 on record in terms of total catastrophe bond issuance, which indicates that 2026 could end up reaching the $20 billion+ milestone once again, Brad Adderley, Managing Partner at law firm Appleby has said.

Trust Disputes
27 Mar 2026

Privy Council decision in X Trusts – redefining the role of the protector

On 19 March 2026, the Judicial Committee of the Privy Council (JCPC) delivered its long-awaited judgment regarding the role of a fiduciary protector in the administration of a trust (A and 6 others (Appellants) v C and 13 others (Respondents) [2026] UKPC 11, on appeal from the Court of Appeal of Bermuda). The decision of the JCPC was unanimous, with the judgment being given by Lords Briggs and Richards.

Appleby-Website-Insurance-and-Reinsurance
26 Mar 2026

Latin American risks and the Bermuda market

Bermuda’s decades-long efforts to welcome Latin American risks to the island’s re/insurance market have borne fruit in the form of the many LatAm captive insurers that have become domiciled here.

Appleby-Website-Insurance-and-Reinsurance
24 Mar 2026

Navigating Bermuda’s New Recovery Planning Requirements: A Roadmap for Commercial Insurers

On 20 March 2026, the Bermuda Monetary Authority (BMA) issued an updated Guidance Note for Recovery Planning Requirements (Guidance Note). The Guidance Note assists Bermuda commercial insurers’ compliance with the obligations set out in the Insurance (Prudential Standards) (Recovery Plan) Rules 2024 (Rules), which became operative on 1 May 2025.

Appleby-Website-Private-Client-and-Trusts-Practice-1905px-x-1400px
13 Mar 2026

A will trust can keep a home in the family

In Bermuda, a family homestead represents more than financial value; it embodies ancestral heritage and housing security.

Appleby-Website-Employment-and-Immigration
12 Mar 2026

Privacy at Work: What PIPA Means for Bermuda Employers

The Personal Information Protection Act 2016 (PIPA), which came into force on 1 January 2025, represents Bermuda’s first comprehensive date protection regime. The legislation regulates the collection, use, disclosure and storage of personal information with the objective of protecting individuals’ privacy while allowing organisations to use data in a responsible and transparent manner. PIPA applies broadly to organisations operating in Bermuda, including employers. As a result, the employment relationship is one of the contexts in which the practical impact of PIPA is the most significant. Employers routinely process large volumes of personal information relating to employees and job applicants, and PIPA imposes obligations that affect recruitment, workplace monitoring, record-keeping, and disciplinary processes.