# Public Administration Ecosystem Reference Architecture (PAERA)

Developed by Aare Laponin, Ivar Tallo, and Margus Magi.


# 1. Introduction to PAERA

## 1.1 Objective

This document aims to guide public sector organizations and governments undergoing digital transformation. In such organizations, there are typically two groups of people: management with governance background and IT personnel who are familiar with the technical aspects of digitalization. Often, these groups have different vocabularies and varying understandings of the scope and objectives of digitalization, which can lead to tensions.

This document is constructed in an accessible manner to overcome the dichotomy of governance and IT way of thinking, so it could be used:

* By high-level people (governance) to understand the hidden dependencies in the building blocks in the whole ecosystem.
* By IT personnel to better comprehend objectives, scope and required sequencing of digitalisation programs.

This document outlines GovStack building blocks for implementing Enterprise Architecture practices in Digital Government (DG) and establishes a Reference Architecture for the target ecosystem.

This document aims to provide the reader with an understanding of:

* The value proposition of the GovStack approach, and how it helps with the adoption of digital transformation initiatives.
* How Building Blocks approach (also, GovStack approach) and Enterprise Architecture practices interact, and how they can be used for the needs of a specific government.
* What are the dependencies and potential conflicts when attempting to apply the GovStack approach for digital transformation.&#x20;

## 1.2 Motivation

It is crucial that all countries, particularly those with lower incomes, are given an equal opportunity to develop digitally. The digital revolution is currently offering opportunities that can be used to tackle the most urgent global issues within the framework of the United Nations' Sustainable Development Goals (SDGs). Information and Communications Technologies (ICTs) serve as reliable facilitators in this regard.

As technology continues to evolve, we often focus on the latest solutions and the potential for rapid progress, but we may overlook the critical underlying conditions required for success. Unfortunately, there are many obstacles that can prevent us from achieving our goals, such as improper sequencing of changes, poor change management practices, or inadequate sourcing strategies for digitalization.&#x20;

There are many reasons why our efforts may fail, and success requires navigating a narrow path.

The Public Administration Ecosystem Reference Architecture (PAERA) aims to provide coordinated, efficient, and equitable services by transcending those boundaries.

This Reference Architecture presents a comprehensive approach that combines IT processes with government business strategies, guided by principles of digital governance.&#x20;

In practice, the most significant reasons why governments adopt this approach are usually the need to ensure that business and technology are aligned and the need to manage complexity effectively.

Another important lesson that PAERA wants to convey to readers is that Change Management should be addressed at both the government and public administration levels in a coordinated manner. This is crucial to overcome typical challenges that are daily arising and negatively impacting modernization efforts.

## 1.3 GovStack Vision

The GovStack vision is to accelerate the digital transformation of government services. This will empower governments to build a more effective and cost-efficient public sector, taking ownership of their digital future.

GovStack is a platform that will help countries start their digital transformation journey by adopting, deploying, and scaling digital government services. PAERA explains how the GovStack Approach, which involves digital building blocks, can help governments easily create or modify their digital platforms, services, and applications.&#x20;

The GovStack approach simplifies solution architectures, reduces cost, and decreases the time-to-market of digitalization programs. It aims to build a common understanding and technical practice of using fundamental, reusable, and interoperable digital components applicable to any public administration. PAERA collectively refers to those as building blocks.&#x20;

The GovStack initiative is led by a community of subject matter experts and involves multiple stakeholders who develop concrete guidance for strengthening a government’s ability to deliver practical solutions.&#x20;

GovStack is a platform that analyses digital government experiences worldwide. It identifies the common successful approaches used in countries that lead the transformation of government services through digitalization. GovStack building blocks represent an empirical abstraction of these approaches, and the PAERA outlines the baseline of the GovStack building blocks framework.

GovStack has started to develop specifications for reusable building blocks. Even if building block specifications are standardized, situations in which they will be utilized are always unique. Here is where change management comes in as a high-level requirement to manage the processes. We highlight timelines and dependencies wherever possible to make it easier for individuals to determine the appropriate course of action in their unique digital journey.

GovStack will work with all different communities who develop software solutions that adhere to these specifications to ensure interoperability between different GovStack-compliant software products.&#x20;

Following the development of specifications, the collaboration will create a reference digital government service that will demonstrate the reuse of elements across sectors and services.

The design specifications and the resulting government reference platform will be available as “digital public goods” for the global community.

We believe that the GovStack building block approach, enterprise architecture practice, and adequate change management will make digital transformation in public administration sustainable and effective and benefit citizens, businesses, and all social and demographic groups.&#x20;

## 1.4 GovStack Origin

The GovStack initiative was launched in 2021 under the leadership of four partners:&#x20;

* International Telecommunication Union (ITU)&#x20;
* Republic of Estonia&#x20;
* Deutsche Gesellschaft für Internationale Zusammenarbeit (GIZ)&#x20;
* Digital Impact Alliance (DIAL)

<br>


# Scope of Document

This document provides an overview of the digital transformation of government services and is expected to be a key reference for practitioners.

* The first chapter is a traditional introduction where we aim to show how the document is set in context and the larger context of GovStack itself.&#x20;
* The second chapter is about the basic assumptions that have created the need for such a document.&#x20;
* The third chapter applies the GovStack approach to national-level digitization efforts. It describes how the GovStack building blocks make the most sense for national digital transformation.&#x20;
* The fourth chapter defines the reference architecture of a public sector organization from the digital transformation perspective.
* The fifth chapter provides guidelines for practitioners on using this reference architecture.

The document is expected to be a practical and helpful guide for planning national public administration modernization initiatives. The authors intend to incorporate more knowledge and practical case studies over time, so we are interested in readers' feedback.


# Abbreviations

<table data-header-hidden><thead><tr><th width="113"></th><th></th></tr></thead><tbody><tr><td>Code</td><td>Description</td></tr><tr><td>BB</td><td>Building Block</td></tr><tr><td>BO</td><td>Back Office</td></tr><tr><td>DPG</td><td>Digital Public Goods</td></tr><tr><td>DPI</td><td>Digital Public Infrastructure</td></tr><tr><td>EA</td><td>Enterprise Architecture</td></tr><tr><td>ERP</td><td>Enterprise Resource Planning</td></tr><tr><td>FO</td><td>Front Office</td></tr><tr><td>G2G</td><td>Government to Gevernment</td></tr><tr><td>GS</td><td>GovStack</td></tr><tr><td>KPI</td><td>Key Performance Indicator</td></tr><tr><td>MDA</td><td>Ministries, Departments and Agencies</td></tr><tr><td>PAERA</td><td>Public Administration Ecosystem Reference Architecture</td></tr><tr><td>PAO-CC</td><td>Public Administration Core Components</td></tr><tr><td>PAR</td><td>Public Administration Reform</td></tr><tr><td>PCI DSS</td><td>Payment Card Industry Data Security Standard</td></tr><tr><td>PDU</td><td>Policy Development Unit </td></tr><tr><td>RA</td><td>Regulatory agency who regulates specific functional area of economy</td></tr><tr><td>SDA</td><td>Service delivery authority, e.g. Police Department, Customs Department etc. </td></tr><tr><td>SLA</td><td>Service Level Agreements</td></tr><tr><td>WoG</td><td>Whole of Government</td></tr></tbody></table>


# 2. State of Digital Transformation

## 2.1 Problem statement

#### Internal factors

The history of digital transformation initiatives is marked by numerous large and ambitious projects that have failed despite being constructed and funded by well-intentioned donors, whether domestic or foreign. Projects often introduce foreign ideas to a given society, which the society needs to assimilate in meaningful ways. If successful, they would bring about the desired benefits. However, often, they fail because the local cultural environment clashes with the underlying ideas upon which the benefits have been built.

To avoid failure and unnecessary spending, a country must carefully select a suitable action plan based on the needs and capabilities of the target groups who will benefit from the developed products. It is natural to want to adopt the best practices from around the world and use new technologies to speed up progress towards a better future, but this can only be done under certain circumstances.

#### External factors

Software markets are typically effective in meeting the needs of the private sector. Thanks to globalization and trade liberalization, successful software products are quickly accessible to users worldwide. As the customer base grows, the quality of products also improves. However, public administration practices and working processes differ significantly from those of the private sector, making it challenging to cater to the needs of the public sector.

While user functional and non-functional requirements can be agreed upon easily across cultures, harmonizing legislation and administrative procedures is challenging. It is therefore fair to say that automating a specific function in the public sector of a given country is a one-time occurrence.&#x20;

A global ERP vendor may have hundreds of thousands of customers in the private sector. However, a vendor selling, for example, tax administration software can only target around 200 tax administrations worldwide, making it a less attractive market for vendors. For this reason, mature and fit-for-purpose public administration-specific solutions are not in high demand. Many vendors claim to have public administration solutions. Upon closer inspection, these solutions may not be effectively tailored to a specific public administration context.

#### Technology factors

People believe that once a new technology solution is implemented, the problem is solved. Tough reality of Digital Age is that at this moment life-cycle of the new asset just starts.&#x20;

To maintain a solution's functionality, it is necessary to regularly upgrade its security features, adjust its software to keep up with changing infrastructure, address user issues, and define and implement new requirements. However, these needs are often overlooked by management, resulting in irregular implementation of security patches and using shortcuts during changes.&#x20;

This leads to the emergence of new legacy systems that are difficult to manage. A new cycle of the COBOL-ization process begins, investments are not sustainable, and systems are too complex. Finally, development stops, and all effort goes into maintenance.

#### GovStack response

GovStack has a solution to the above challenges:

1. We analyse the best practices around the globe.
2. Findings are consolidated, and appropriate reusable Building Blocks specifications are designed.
3. We point out the important assumptions and dependencies along the planning and implementation processes.
4. Specifications of Building Blocks are disseminated to the software developers’ community.
5. We are actively engaging with solution providers, seeking products that can be candidates for implementation of Building Blocks specifications.
6. We closely monitor Building Blocks implementation practices and learn from them, further improving the GovStack proposition.

#### Outcome Architecture

GovStack is a digital transformation approach aimed at creating prosperity for people by converting technological advances of the last decades into new capabilities for everybody

<figure><img src="https://4055358096-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FpqnbDhX09tb5z7q4AWcQ%2Fuploads%2FGJMc9RfmDsc8PrU7QxGw%2FScreenshot%202024-05-29%20004408.png?alt=media&amp;token=1256d6f8-1c57-43ea-8f31-da78c2a94817" alt=""><figcaption><p>Figure 1 - Outcomes architecture of digital transforamtion</p></figcaption></figure>

The digital transformation of the public sector is expected to benefit society as a whole, the economy, and the government sector.

* Society: fostering communities’ relationships, new capabilities for individuals to participate and thrive in all dimensions of their life, enhancements of the overall well-being and happiness of the population, including considerations such as healthcare, education, and cultural enrichment.
* Economy: less bureaucratic barriers, financial inclusion, new local jobs, new knowledge-based industries, better regional and international trade conditions.
* Government sector: cost-efficiency, pro-active service delivery, better workplace culture.

Consider this model when setting objectives for digital transformation initiatives to ensure better sustainability of efforts.

## 2.2 GovStack Methodology

GovStack is an initiative that aims to gather best Digital Government practices from case studies worldwide. It also seeks to create a reference architecture of building blocks for a Digital Government reference model.&#x20;

GovStack provides a platform for vendors and developers to have open access to building blocks on the supply side and Digital Government personnel on the demand side. GovStack bridges the gap between governments seeking to transform their practices and the developers and vendors who offer the necessary building blocks for successful solutions.

The GovStack Methodology follows a building block approach that aligns with the SDG Digital Investment Framework's whole-of-government philosophy ([Source](https://www.itu.int/pub/D-STR-DIGITAL.02-2019))

<figure><img src="https://4055358096-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FpqnbDhX09tb5z7q4AWcQ%2Fuploads%2FyTCq8fTLmeXQheZq0BKf%2Fimage12.png?alt=media&amp;token=07c082b1-534a-4804-a34c-da1469e270c3" alt=""><figcaption><p>Figure 2 - GovStack methedology componenets</p></figcaption></figure>

To facilitate the activation of the methodology, GovStack has created this Public Administration Ecosystem Reference Architecture (PAERA) outlining the necessary framework for the public sector to approach digital transformation in a practical, effective, efficient, and sustainable way.

GS develops [GS Specs](https://workflow.govstack.global/development-6/) to define building block requirements, dependencies, and usage guidelines for implementing solutions using those building blocks.\
GS develops GS Playbook to provide recommendations to government CIOs for implementing best Digital Government practices for solution design and related activities.\
\
GS architects identify available open source or commercial components that align with specs API and place them to GS Sandbox for demonstrations and rapid prototyping sessions during discussions with countries’ solutions architects.

Components that pass tests against defined specs can be placed on GS Marketplace for countries to consider during their transformational journeys.

GS working groups develop training materials, which are available in GS Learn & Train for staff training during change management.

The GS Certification program streamlines the process of hiring competent solutions architects to design transformational initiatives in different countries. This program evaluates a candidate's previous experience, work in GS working groups, and performance in the certification exams. It helps to certify professionals who can effectively implement the GS approach in their respective countries.

The methodology focuses on modern digital government systems' end-to-end life cycle management, enabling sustainable investment and reliable public administration. It leverages proven practices from digitally advanced societies to prioritize interoperability, reuse, and sustainability, simplifying and accelerating public sector digital transformation using proven technology blocks and governance and change management practices.

GovStack Knowledge Base compiles knowledge from country use cases and research studies, and shares guides and publications on best practices for digital transformation.

## 2.3 Role of Enterprise Architecture

#### Key Concepts

In PAERA, we require a practical and straightforward definition of Enterprise Architecture (EA). Some Chscholars criticize popular EA approaches, claiming that they are purely philosophical and unrealistic and provide little practical advice. They argue that the term EA has been utilized as an umbrella term to refer to a single comprehensive description of an organization developed and used by stakeholders (Ibid).

Enterprise architecture can be defined as a collection of documents describing various aspects of an organization from an integrated business and IT perspective, intended to bridge the communication gap between business and IT stakeholders, facilitate information systems planning and thereby improve business and IT alignment (Source: Kotusev, Svyatoslav. The Practice of Enterprise Architecture: A Modern Approach to Business and IT Alignment (p. 19). SK Publishing. Second Edition 2021).

The blend of Enterprise Architecture practice with the building blocks approach offers multiple advantages, such as cost savings, speed, real economic return, and agility, combined with responsiveness, integration, and information exchange to achieve interoperability, adherence to common standards, and minimizing vendor lock-in.

The discipline of Enterprise Architecture provides visibility into an organization, its activities, and its systems. It considers four different points of view that are central to understanding an organization:&#x20;

* Business Architecture. In EA practice, we refer to business architecture when we think about customers and the services that an organization provides to them. However, there are more important and interesting aspects to business architecture than just customers and services, such as business processes, regulations, key performance indicators, etc.
* Application Architecture. When people use application software to accomplish some tasks, we can say that the business process of this task is supported by an application. When we describe an organisation's all applications, which are used by a variety of business processes, then we would define the organisation's application architecture.
* Data Architecture. Recently, an increasing number of people have realized that automating business processes and service delivery is important, as is analysing the data collected by their organization. By doing so, they can adjust their business strategy and activities to enhance their achievements. For doing data analysis, however, you should know your data. So, when you meaningfully document your data, in EA practice, we say you documented your data architecture.
* Technology Architecture describes all computing, networking, storage, etc. devices that enable an organisation to use digital services.&#x20;

The enterprise architecture practice also provides advice on how to track dependencies between different elements of your architectural layers, both horizontally (within the same layer) and vertically (across layers). Once you create such a layered description of your organization, you will be able to understand how your organization functions as a system.

There are building blocks for every EA layer:

* Within the Business Architecture, a building block is a set of specific recommendations for legal and organizational arrangements.
* Within the Application Architecture a building block is a separately deployable executable software component, described in a specification of the block’s interface (API), and objectives to be achieved using the capabilities of that component.
* Within the Data Architecture, a building block is a definition of the required registries and information repositories and a description of the business capabilities that those registries and repositories enable.
* With the Technology Architecture, a building block is defined as an implementational pattern recommended for delivering secure and scalable ICT infrastructure services.

Reference Architecture refers to the consolidation of previous experience in the domain of digitalisation in public administration. It involves creating templates that structure components of applications and technology to support specific business models presented in the public sector. These templates are used to speed up the development of solutions for Public Administration Organizations (PAOs) and to decrease the risk of design decisions.

For example, in \[Source: Kotusev, Svyatoslav. The Practice of Enterprise Architecture: A Modern Approach to Business and IT Alignment (p. 19). SK Publishing. Second Edition 2021] author provides the following practical visualisation of Reference Architecture in the context of the development of solutions:

<figure><img src="https://4055358096-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FpqnbDhX09tb5z7q4AWcQ%2Fuploads%2FhL5DA1Md6cuBXjyuR2Rf%2FScreenshot%202024-05-29%20005332.png?alt=media&amp;token=61df42e2-0ffc-468d-9873-74768be3b151" alt=""><figcaption><p>Figure 3 - Reference Architectures and Solution Enterprise Architectures <br>Source: Adapted from “IT Connect. Information technology tools and resources at the UW” (Univ. of Washington, 2020)</p></figcaption></figure>

Such re-use of existing solution experience will be enabled by continues update and development of PAERA in GovStack.

Utilizing EA practice, GovStack lays out a target reference architecture for national level, public administration level, and MDAs.

Finally, GovStack provides an implementation framework for the effective use of PAERA as defined in this document.

Metamodel of the reference architecture provided in the Annex 2.

#### Value proposition

Enterprise Architecture has traditionally been used as a tool to align business and technology domains. This is especially important during times of significant environmental changes, which often require new strategies.&#x20;

Today, technology has the potential to revolutionize the internal operations of public administration organizations. This presents an extraordinary new opportunity that we want to leverage.

The current reference architecture document aims to unlock technology's potential to transform the process of creating public value using architectural and solution building blocks. This transformation can occur rapidly, generating local employment opportunities and revolutionizing entire societies.

In defining the PAERA approach, we want to highlight a few important aspects of the EA value proposition.

First aspect. When a customer with specific business requirements collaborates with a capable developer, they can often come up with a solution that works. In such cases, they may not require the assistance of an architect or architectural document. However, it may not be immediately apparent how well the solution will address requirements that are invisible to the business customer, such as maintainability, scalability, security, and so on. This is when architectural requirements and reference architecture become helpful.

Second aspect. Once a software system is created, it requires regular maintenance, as well as version upgrades annually and technology upgrades at least every decade for as long as the organization exists. If the software is not receiving updates regularly, let’s say at least once per year, and its technology is not entirely renovated at least every 7-8 years, then such software becomes a dangerous legacy, which poses a significant operational risk for the organization. Utilizing Building Blocks supported by independent open-source vendors who actively develop their products will enable the public sector to avoid falling into such legacy traps.

Third aspect. Digitalization of the public sector should not be narrowly seen as the automation of existing business processes. Instead, it should involve the creation of new operating models, with public administration customers at the center.

#### Specific Objectives of the Document

The Reference Architecture:

1. Tries to define specific national infrastructure components, which are foundational for more effective digitalization.
2. Defines a taxonomy of government entities aiming to define set of specific building blocks required for different types of organisations.
3. Provides a practical framework of decisions to be made and implementation activities to be planned by a public administration organisation for effective digital transformation.&#x20;
4. Defines the context and boundaries of the public administration digital ecosystem.
5. Identifies key drivers of digital transformation in a typical public sector organisation.

## 2.4 What is Public Administration?

It is important to define the scope of the reference architecture. Here, we will provide a simplified view of the public sector and its organisational structure.

According to (A unitary state is a state governed as a single entity. There are no federal autonomous regions.), “Government units are unique kinds of legal entities established by political processes that have legislative, judicial, or executive authority over other institutional units within a given area. The principal economic functions of government units are to:

* Assume responsibility for the provision of goods and services to the community or individual households primarily on a nonmarket basis.
* Redistribute income and wealth by means of transfers.
* Engage primarily in nonmarket production.
* Finance their activities primarily out of taxation or other compulsory transfers.

A government unit may also finance a portion of its activities in a specific period by borrowing or by acquiring funds from sources other than compulsory transfers—for example, interest revenue, incidental sales of goods and services, or the rent of subsoil assets. All government units are part of the general government sector.”

From our perspective, the most crucial aspect of this definition is the funding from the public budget and the non-market nature of primary activities.\
Following is an example of how a unitary state defines its public sector (based on Digital Transformation and Public Services, Edited by Anthony Larsson and Robin Teigland, 2020 by Routledge).

<figure><img src="https://4055358096-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FpqnbDhX09tb5z7q4AWcQ%2Fuploads%2Fl6SS6wxcSR7xBOcXExUv%2FScreenshot%202024-05-29%20005746.png?alt=media&amp;token=c82d95ef-a04b-4334-babb-60a1477c786f" alt=""><figcaption><p>Figure 4 - Public sector units in a unitary system</p></figcaption></figure>

In a federal system, the Central Government represents the Federal Government, and an additional budgeting level will be added for federated states/counties. Local municipalities fall under specific states/counties, such as in the USA, Nigeria, India, etc. In this case, the diagram could be presented in the following way:

<br>

<figure><img src="https://4055358096-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FpqnbDhX09tb5z7q4AWcQ%2Fuploads%2FdAEQosT78DLndxNj8s1K%2FScreenshot%202024-05-29%20005849.png?alt=media&amp;token=91a07b19-aa73-4881-b76c-a3256d29b32f" alt=""><figcaption><p>Figure 5 - Federal country public administration</p></figcaption></figure>

In some countries, there are no state-provided social insurance schemes, which means there are no social insurance funds. However, in terms of digitalization, these differences are not important. At the end of the day, these are budget levels with pre-defined sets of responsibilities and revenue sources.&#x20;

In smaller countries, there will be fewer independent budgetary levels and units. In larger countries, there may be more budget levels, some shared revenue allocations from one budgetary level to another, and more budget units. Otherwise, there are not many differences between bigger and smaller countries when it comes to the required building blocks for digital transformation.

**Government sector** – includes public sector entities that are not considered market producers and are financed mainly by compulsory payments made by entities belonging to other sectors. In a typical small or medium-sized country, the government sector is divided into three sub-sectors: central government, local governments and social insurance funds.

**Other public sector** – public sector companies that produce goods and services with the participation of the state and other government sector members (e.g. utility companies, strategic resource processing, etc.) and Central Bank.

**Central government** – state institutions belonging to the sub-sector of the central government (government institution, state institution managed by a government institution, county court, administrative court and district court); constitutional institutions (the Chancellery of the Parliament, the Chancellery of the President of the Republic, the National Audit Office, the Chancellery of the Chancellor of Justice and the Supreme Court) and the institutions in their administrative area; legal entities of the central government (a public legal entity defined as a central government unit, a foundation established by the state and a company with state participation).

**Local government** – the right, ability and obligation of the democratically formed authorities of a self-governing unit - municipality or city - to independently organize and manage local life on the basis of laws and the legitimate needs and interests of the residents of the municipality or city and taking into account the peculiarities of the development of the municipality or city.

A public service institution, or public authority, is an institution financed from the budget of the state or local government unit, whose task is to exercise public authority.

**Managed institution** – state institutions financed from the state budget, whose main task is not to exercise executive state power, but on the basis of the law, state institutions managed by government institutions can exercise executive state power. State institutions managed by government agencies belong under a ministry's jurisdiction.

The current reference architecture is applicable mainly to non-market activity units.

## 2.5 What is Digital Government?

A couple of important concepts still need to be defined for the clarity of our further discussion.

The term “digitization” entails the conversion of non-digital material (such as images, video, and/or text, etc.) into a digital format (Digital Transformation and Public Services, Edited by Anthony Larsson and Robin Teigland, 2020 by Routledge).

The term "digitalization" refers to the process of adopting or increasing the use of digital/computer technology, including mobile applications. This technology is usually implemented to establish a communication infrastructure that connects various activities and processes of the actor (Ibid).

The term "digital transformation" encompasses strategic business changes driven by customer needs, requiring extensive organizational change and the adoption of digital technologies. It involves multiple projects and requires organizations to effectively manage change. Essentially, digital transformation makes organizational change a core competency as the goal is to become customer-driven from end to end (Ibid).

#### **Digital Governance Model**

Several prerequisites need to be addressed before transformative projects can be targeted to achieve ambitious digital transformation objectives. These prerequisites rely on data flows and have strict dependencies on various building blocks. Digital transformation teams in any country should be aware of these preconditions, as they need to be addressed before one can successfully implement specific building blocks.

We will express the idea of those preconditions through the following metaphor. We say that Digital Governance can be seen as a building as follows:

<figure><img src="https://4055358096-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FpqnbDhX09tb5z7q4AWcQ%2Fuploads%2Fp8NHqHgQ55VUL3swlRaQ%2FScreenshot%202024-05-29%20010249.png?alt=media&amp;token=5394e462-1ca7-4390-9bcd-36af4e494f5d" alt=""><figcaption><p>Figure 6 - Digital Governance Infrastructure Framework (Source: Ivar Tallo &#x26; Aare Lapõnin)</p></figcaption></figure>

While houses in different cultures can be quite different, the basic principles of their construction are similar. First, one needs to build the foundation. There are foundational cross-cutting issues of governance and policy — as well as legislative framework — that support the walls and pillars, which support the roof. Similarly, the framework is based on a causal sequence; one input causes other Digital Governance aspects to succeed. Such 'inputs' are called underlying conditions for Digital Governance.

From bottom to top level, we describe layers in the following way.

Digital Governance Infrastructure includes Foundation and National Level infrastructure.

#### **Foundation**

Foundation Frameworks, which consist of horizontal preconditions, meaning that they are applicable in any case.

1. **Legal frameworks** or applicable laws are necessary preconditions for different types of building blocks, and they are discussed later in Chapter 3. Technical solutions in the form of building blocks can usually only be implemented after there is a legal basis for them, and this usually goes outside the specific building blocks themselves.&#x20;
2. **Governance & Policy frameworks** are also necessary to coordinate digitization efforts. While it is possible to develop one or another application autonomously, this approach is not cost-effective from the general development point of view.

#### **National Level**

The Digital Infrastructure Pillars are essential technical conditions for achieving goals. Completing them before developing functional applications in ministries and departments is often impossible, but at least they should be somehow addressed before pursuing wide and ambitious modernization goals.

1. **Access** in terms of connectivity of offices and citizenry seems to be a self-evident precondition, but we have brought it out here. After all, there are still a lot of situations where otherwise good projects die mysteriously after being successfully executed because either the people do not have the possibility or the habit of using the internet, or offices don’t have internet access or have it in a very limited way, making it very hard to be part of the digital data flows.
2. **Digital Data**, or rather the need to digitize data has been rising in importance as we started to talk about digital government, but it is a topic of a rather large scope that needs to be addressed by a multitude of specific efforts, found in different building blocks of the GovStack. &#x20;
3. **Interoperability** is the ability of the government to exchange data inside and with the outside world and it requires a significant effort by any government to introduce. Different approaches to interoperability and its components are expressed in technical terms in the Enterprise Architecture framework, and introducing this requires any government a major effort and dedication, and support on the highest government levels. &#x20;
4. The **Digital Identity** pillar describes efforts to create common semantics for the information government is collecting and allowing us to construct transactions in the virtual world by citizens and businesses as well as giving a legal protection to these transactions where necessary.&#x20;

The governance and legal framework questions spanning different areas don't need to be explained separately. However, it is very important to provide examples of best practices and explain why they work.

#### **Pillars as Digital Infrastructure**

Pillars are crucial in constructing a strong foundation for a "digital house" and thus will be elaborated a bit more.

The first pillar, Access, is a fundamental requirement in today’s world and can take various forms, such as connectivity for offices and citizens. However, it may require specific attention based on the entities and regions, as something that may seem obvious in the country’s capital may not be the case just outside its boundaries. Without sufficient Access, other digitalization efforts are meaningless, as demonstrated by attempts to teach digital skills using traditional blackboards.

The second pillar or underlying condition is digital data. It is obvious but also a time-consuming and resource-hungry endeavour that cannot be resolved with just one straightforward project or GovStack building block. It requires both the overall framework development and the consideration of government-specific functions such as accounting for land, people, property, and activities.

The third pillar is interoperability. Once we have digital data, we need to be able to reuse it in different information systems to avoid repeating the same operations in various government departments. This requires planning for and introducing interoperability. Without interoperability, IT investments will be limited to simply automating existing processes, which will not bring any additional value to society. Value can only be created by redesigning old processes.

Finally, we need to be able to navigate the digital realm and prove our identity in the court of law, so we need a mature system for digital identity.

#### **Level of a Public Sector Organisation**

At the organizational level, successful digital transformation requires the presence of the following dynamic capabilities:

* **Management & Architecture** – The management of the organization understands the significance of digitalization and is capable of implementing the necessary change management to transition operations from paper-based processes to a completely digital operational environment. The IT personnel are capable of overseeing the overall architecture to ensure the sustainability of investments.
* **Digital Service Culture** – Transitioning from paper-based to digital service delivery requires a significant cultural shift within an organization. This shift is essential to ensure smooth adoption of new technologies and maximize the benefits of digital transformation. The organization should internally adapt to deliver services to customers in a fully digital manner, prioritizing customer satisfaction.
* **Data-driven Decisions** – An organization can make data-driven decisions when it can consolidate all available data, manage its quality and availability securely, and there is a management who is motivated to be data-driven on a daily basis.
* **Digital Co-creation** – Digital co-creation is a new concept. Traditionally, the government executed its mandates from behind tall walls of laws and professional public administration apparatus. In the digital era, a successful organization should be capable of sourcing digitalization initiatives within its local community of stakeholders and sharing the available data back to communities.

Also, we have to admit that successful digital transformation at the organizational level is nearly impossible without a mature Digital Governance Infrastructure.

#### **Public Reform & Governance**

There are many higher-level concepts that tend to attract decision-makers’ attention over the preconditions viewed as technical. Many donors and governments themselves view these higher levels of changes under the common umbrella of **Public Administration Reform (PAR)**.

However, as we already mentioned, constructing of a house, one does not start from the roof or windows. While the interest of decision-makers can be in providing various digital services or data-driven decisions (i.e., “doors” and “windows”), the reality is that one first needs to build the foundations and the “walls”.

### **Role of GovStack**

GovStack aims to ensure that partner countries are aware of the model of dependencies described above when approaching digitalisation initiatives.

## 2.6 Change management

#### **Continuous Process**

Change management deals with modernisation projects at organizational level. However, government-level concerns must also be addressed. These are often referred to as reforms arising from political debates. Digital Transformation – one of such reforms – should address the government's vision, policy statements, and legal changes.

The GovStack Approach can only be implemented within a systematic practice of Change Management both at government as well as organisational level:

* As foreseen in policies, national digital infrastructure capabilities are being planned and developed at central, regional, and municipal levels.&#x20;
* Organisational capabilities are planned and developed in MDAs at all levels of a country's public sector.
* There is a practice to support implementation of projects from legal and administrative perspectives.
* Development of government internal IT capabilities to manage sustainable delivery of software solutions for digital services.

#### **Quality Attributes of the Process**

GovStack emphasizes that digital transformation will create a new digital public infrastructure (DPI) for the upcoming digital era. It is crucial to ensure that while developing DPI, both the outcomes and the process are clearly defined, with a focus on reflecting public needs. To achieve this, the process must meet specific requirements, which can be illustrated as follows (Source: \[8]):

<figure><img src="https://4055358096-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FpqnbDhX09tb5z7q4AWcQ%2Fuploads%2FCnJr01538kecgtqpZu7V%2FScreenshot%202024-05-29%20010729.png?alt=media&amp;token=74c8c9a7-bf20-40fe-b168-821765a287f5" alt=""><figcaption><p>Figure 7 - Requirements for Digital transformation process (Source: [8]).</p></figcaption></figure>

**Purpose and Directionality**. In a "common good" framework, two critical capabilities are setting directionality and orchestrating the process. There is a growing trend of desiring more explicit directionality in building shared digital infrastructure. DPI is not neutral and shapes what can be built on top of it. Therefore, it is crucial to make the nature of directionality explicit and prioritise it.&#x20;

One case in which purpose and directionality are made explicit in DPI is India’s identity system, Aadhaar. To the Indian government, the main reason for establishing residents’ identity was to simplify the distribution of welfare benefits (including direct cash transfers, subsidised food, cooking gas and other benefits). The government feared that a substantial portion of those benefits was being wasted due to fraud and corruption. Building a system to identify an individual uniquely was paramount to prevent fraud and improve the targeting of social benefits. Directionality simplified scaling and KYC compliance for banking and telecommunications and prevented welfare benefit leakage.

In contrast to the Indian case, the digital identity system in Jamaica was not built with an explicit, primary purpose in mind. Initially, the Jamaican government declared an interest in building an ID system but did not link it to a primary policy purpose. This allowed others to imagine the ID’s purpose, fostering the distrust of civil society actors, who were suspicious of the government’s intentions. It was also a wasted opportunity, as the government did not focus on developing a programme or application that would benefit its citizens.

**Co-creation and participation**. The common good stresses collaboration, coordination, and co-investment among different entities. Co-creation and participation should be integral to the governance process. Institutional mechanisms should be established for collaboration around DPI. Participation around proprietary technologies is challenging.

A good example of successful co-creation is Brazil's Pix, a new instant payment scheme launched in November 2020 by Brazil's Central Bank. It allows citizens, companies, and government entities to transfer payments quickly and easily, even on non-business days. The team behind Pix understood the importance of involving society in the development process and breaking away from traditional practices of working in silos. This led to the creation of the Pix Forum, a collaborative governance practice that brought together more than 130 representatives from various societal groups, including banks, fintechs, civil society organizations, and small business associations. The team processed feedback from all participants, which was a challenging but necessary step towards the success of the project. The Pix Forum's co-creative process was instrumental in developing a solution that was user-centric and met the needs of society.

**Collective learning and knowledge-sharing**. Learning from each other's successes and failures and encouraging knowledge-sharing and collective intelligence is crucial for collective value creation. Institutionalized learning and knowledge accumulation can create long-term state capacities. Innovative institutional examples can facilitate collective learning.

One example is Bangladesh’s Aspire to Innovate (a2i) programme, whose goal is to ‘drive collaborative digital innovation for the public good. In practice, it serves as a think tank inside the government, focused on technology projects that are geared towards helping the country achieve the SDGs. The programme is an arrangement that allows the government to integrate inputs from, and collaborate with, civil society groups. More importantly, the model provides lessons to the DPG ecosystem in Bangladesh by demonstrating the capacities and talents needed to support the maintenance of digital public goods.&#x20;

Encourage collective learning with DPI by incentivizing open-source software and communities of code led by digital public goods enthusiasts. External contributors are key for effective learning. Here is a good example.

MOSIP is a solution that helps countries to implement open-source identity systems. It offers an open approach to contributors, which means that they can introduce new features or fix bugs, covering a spectrum of tasks, from requirements and design to coding, testing, and documentation. While some components are closely governed with limited room for external input, to avoid adopters bypassing the safety and do-no-harm mechanisms built into the technology, other components are more open to external contributions. This comprehensive approach strengthens the system, establishing clear pathways for contribution while adhering to submission and reporting guidelines.

**Access for all and reward-sharing**. Universal access and reward sharing are crucial to the concept of the 'common good' in policymaking. If an infrastructure benefits everyone, it must be accessible to all, and its benefits must be shared with society. Governments prioritize access and inclusion over market pricing and rent extraction. Physical infrastructure has been essential for social and economic development for 10,000 years. Digital access must be ensured through analogue means since waiting for universal internet access burdens citizens.&#x20;

A few countries have explored creative solutions to analogue access. In Bangladesh, DPI was expanded to include an additional ‘access layer’, which turns DPI into a “phygital” public infrastructure’ (Chowdhury 2023). The access layer encompasses physical locations and call centres, improving DPI’s accessibility for individuals with disabilities and those in underserved communities in remote rural areas. Bangladesh’s over 9000 digital centres (also known as one-stop shops), widely spread at an average of 4km from a person’s house, are run by young local entrepreneurs (a third of whom are women). These public-private partnerships guarantee that government services reach the grassroots level.&#x20;

The city of Barcelona has been working on implementing reward-sharing mechanisms for Data Privacy Impact. After Mayor Ada Colau was elected, the city's government established a "new data deal" agenda to encourage the use of corporate-controlled data for improving public services while also ensuring citizens have control over their data. The government also reviewed its procurement processes and regulations to ensure that the value extracted from data is not privatized but shared with the public instead. To achieve this goal, the city introduced "data sovereignty" clauses, which give the city the right to acquire data collected through or about public services and some private sector data that is associated with the public interest, such as geolocation and data from ride-mobility operators. This example demonstrates that procurement rules, in addition to regulations, can be powerful policy instruments for the common good.

**Transparency and accountability**. Public sector organisations leading or managing a DPI implementation need transparency and accountability to win trust. DPI’s decentralised architecture poses accountability challenges across government departments and levels of government. Although accountability is more challenging, DPI has the potential to improve transparency.

The more systems are integrated, the more digital footprints can be leveraged for transparency. One well-known example is Estonia’s e-health portal, which allows citizens to see who has accessed their data and when. The city of Barcelona, as mentioned previously, also worked on giving citizens more transparency about how private companies used their data.&#x20;

One of the ways these objectives were achieved was through using an open-source data-sharing infrastructure, enabling citizens to control their data as a common good and to share them on terms that are fair, transparent and accountable.&#x20;

Transparency alone cannot ensure accountability and trust. User-friendly data interaction is necessary to maintain trust and accountability, as the effect of transparency on trust can be neutral or negative if not operationalized properly.&#x20;

#### **Business & IT alignment**

The key to our approach is acknowledging the different viewpoints and communication styles of various stakeholders. We are often trained to see things from a specific perspective and communicate within our own professional groups.

For example, in the public sector, having a legal basis is a fundamental requirement for governance practitioners. However, for IT professionals, it is just one of the many conditions that need to be addressed. Additionally, the language used in IT systems is based on "0" and "1", "either" / "or", while top management tends to see a broader spectrum of options. It can be challenging to reconcile these different approaches, especially when both groups use the same terminology with different meanings.

Throughout this document, we provide relevant examples and warnings to help readers understand stakeholders, their motivations, and guidance to ensure the success of their digitization efforts.

<br>


# 3. National Level

## 3.1 Governance & Policy

### 3.1.1 Needs for Governance

Over the past three decades, there have been numerous attempts to integrate information and communications technologies (ICTs) into government operations and services, especially since the widespread availability of low-cost personal computers since the 1990s. This drive towards digitization of government has had many labels over the last three decades, from online government to paperless government to e-governance and m-government, to name just a few.&#x20;

Today, the use of new technologies in public administration is known as digital government. This refers to digitizing all government data and relying heavily on information infrastructure and digitalized information flows in all stages of almost any process. At the same time, a new term of “post-digital era” has come into use.

However, it is essential to distinguish between high-level digitalization strategies that outline general goals, and more tactical infrastructure-oriented digitization plans. Tactical digitization initiatives need to be situated within wider governance reform processes.&#x20;

Merely buying technology does not guarantee improved governance. To be able to transform services digitally in a useful and sustainable manner it is essential to be able to incorporate technology into daily administrative procedures and decision-making. Without these abilities, a digital development plan will not produce the anticipated outcomes or have a significant impact. Set of such capabilities we will also refer to also as a **digital culture**.

Creating digital public service delivery through a GovStack approach requires necessary foundational elements like governance frameworks, legal frameworks, and advanced technologies and software. However, developing a digital culture amongst people creating and using these systems is even more critical.&#x20;

If civil servants do not recognize the importance of utilizing data-driven insights, discussing the concept of smart government or evidence-based governance may be premature. It is necessary to have a basic level of technology adoption before building systems that leverage sophisticated AI-based solutions. Once people understand the value of the internet and data accessibility, it paves the way for further development without any roadblocks.

In situations where the necessary prerequisites are absent, it is essential to cultivate an environment that promotes the growth of digital culture. This cannot be achieved through high-level strategy papers alone, and instead requires civil servants to habitually use new technologies in meaningful ways. For instance, digitalized document management systems should be employed in the day-to-day activities of every given office in a country public sector.&#x20;

When faced with obstacles such as lack of internet access or delays in obtaining logins, it is critical to maintain internal momentum and demand for change rather than allow civil servants to revert to their previous habits of conducting business.

When thinking about governance, one needs to remember some general principles that have been proven over time:

1. There is the need for political leadership. Substantial changes in national and organisational levels need political support expressed through words and budget allocations.&#x20;
2. Changes start to happen when dedicated people and structures make them happen, they collect, keep, and develop the knowledge of digital developments. There is no single recipe for successful digitization drive, however, a dedicated agency with coordination role is an essential ingredient for successful effort.&#x20;
3. It is crucial to understand that governments should refrain from prioritizing building their solutions in-house by arguing that they know what is best for their situation. A government's primary responsibility is to lead. Civil servants should be intelligent purchasers, not IT specialists, except for a few individuals responsible for maintaining the overall data and software architecture.
4. One should also underline the positive role of high-level policies in ensuring the processes run smoothly and guiding the development of organizational-level solutions.
5. It is recommended that a country have an empowered CIO office that systematically develops a digital culture in the public sector.

### 3.1.2 Transforming Governance

Building digital government capabilities is a gradual, step-by-step process rather than a one-time project. The process of cultivating right governance, building legal framework, developing infrastructure and skills must be assessed and subsequently strengthened before attempting large-scale digitization or service delivery reforms.&#x20;

In a nutshell, governance-related issues that affect digitalization in a country can be identified by four distinct indicators:&#x20;

1. **Bad governance choices resulting in extreme centralization in the hope of effective use of qualified human resources** - The creation of services or even homepages for Ministries is sometimes outside the competency of any given Ministry. Instead, it is delegated to the Cabinet of Ministers responsible unit.
2. **Politics prevails over development logic**. It is quite understandable that politics has a different logic and calendar, and it has to be accommodated. However, there is a need for overall awareness of the meaning and lack of data in governance processes and what needs to be done to achieve this.&#x20;
3. **Prevalence of paper-based culture in offices** – public officials in some countries are used to working in the mess of paper trails that enables them to hide mistakes and provide avenues for corruption. Multiple interests always need to be navigated to have the GovStack building blocks meaningfully situated in the overall processes of digitalization.
4. **Security-centric approach** – In many countries, institutions focused on security have control over digitalization, and as a consequence, they often limit data sharing while imposing aspects of surveillance on systems that are meant to uphold participation and democratic decision-making.

These governance issues must be addressed to force digitization on MDA managers. That will lead to better adoption and success of a digital strategy.&#x20;

#### **Digital Culture**

The main goal of the digitalization strategy is to cultivate a digital culture. This involves creating a meaningful work environment incorporating IT development and everyday usage. By doing so, demand for digitization will grow organically, enabling centralized proposals to be implemented successfully and minimizing the risk of process failures.

Political will should drive practical actions that guide daily decisions and escalate unresolved issues. Maintaining political support for digitalization is important for the overall success of the project.

Various strategies and tactics exist for managing change, but the toughest challenge is making people aware of the importance of data. Simply stating that "data is crucial for decision-making" or “data is the new oil” is not sufficient. Instead, processes must be established that highlight the significance of data.&#x20;

Where there is a will, there is a way. Therefore, political will to support digital transformation is the most important aspect of the readiness assessment. We should not forget that oil in the ground becomes valuable only if there is an infrastructure in place to pump it out, refine, and sell it.

#### **Institutional Framework**

The most effective way to manage the technical aspects of digital government is through a whole-of-government approach with centralized coordination of decentralized key initiatives, considering political realities and regulatory frameworks. Various organizational solutions have proven effective, and the following is a brief overview of some of them.

<details>

<summary>Digitalization Ministry vs Digitalization Agency under the Cabinet of Ministers</summary>

Usually, the digitization drive has to emanate in the close proximity to the head of executive power, so the successful cases are Digitization Ministries as in this case they have representation in the form of their own minister. If digitalization is charged to be led by an agency, its power can be measured in its distance from the top executive and the closer, the more chance it has to influence the governance processes and get things done.  &#x20;

</details>

<details>

<summary>Digitalization Committee</summary>

To overcome the challenge of multidimensional nature of digitization, one of the working solutions, deployed often, are Digitization Committees, consisting of key Ministers. Such committees meet to decide the funding issues and make recommendations to the Cabinet or the Chief Executive. Usually, they are also initiating and approving new policies and larger digitization projects.

</details>

<details>

<summary>Digital officers in Ministries</summary>

Digital has become such a big part of the administration that it cannot be handled alone on the level of technical people in IT departments alone. The whole topic has to be coordinated on the political/decision making level and the best way to either everybody getting proficient understanding and using the principles of digital governance or as a minimum have somebody with this function to advise the office how to integrate the digitalization into the everyday administrative practices.&#x20;

</details>

#### **Transformation Strategy**

Conduct assessments to find gaps in legal frameworks, institutional capacity, infrastructure, and skills that need to be addressed.&#x20;

Start building a solid digital foundation by&#x20;

1. strengthening laws that allow for digital governance,&#x20;
2. improving IT infrastructure,&#x20;
3. establishing interoperability standards,&#x20;
4. governing data effectively, and&#x20;
5. enhancing cybersecurity.&#x20;

A digital transformation governance framework should have:

* strong leadership,&#x20;
* comprehensive strategies,&#x20;
* policies & standards, and&#x20;
* coordination mechanisms across the government.

### 3.1.3 Readiness Assessment

Successful implementation of digital transformation efforts requires joint identification and mitigation of risks while building new capabilities where feasible.&#x20;

It takes time to develop digital culture capabilities, which grow through a series of successes. Therefore, it's important to assess a country's level of digital transformation maturity.

When we examine the environment from a technical standpoint, there are clear indicators of low digitalization process maturity:&#x20;

1. Lack of sufficient connectivity.
2. Lack of integrated IT systems in government entities.
3. Lack of digital data.
4. Lack of a wider legal framework for digital processing.
5. Absence of digital payments (i.e., using a bank account or mobile money or CBDC or similar).
6. Absence of national authentication infrastructure and digital signature.
7. Lack of IT literate workforce that can support digital operations.

You should regularly conduct detailed assessments of these and many other indicators to obtain valuable insights for digital strategies and a practical approach to digital transformation.

The key is to recognize that building digital government infrastructure is a long-term, adaptive change process rather than a fixed end state. Regular assessment of maturity levels, gaps, and dependencies provides a crucial perspective. Building progressively from one capability level to the next sustains meaningful and lasting digital transformation.

## 3.2 Legal Framework

### **3.2.1 Principles**

Establishing digital governance requires adapting legal frameworks for digital data flows across public and private sectors to enable secure e-government and e-business.&#x20;

Foundational regulations organizing digital data flows and creating necessary preconditions for government action in digital service provision like e-signature laws, data protection, and cybersecurity standards provide validity, privacy, and security for online transactions and allow the protection of foundational governance principles in the court of law.

Laws and policies promoting user-friendly digital interfaces between citizens and government systems are needed for transparent and efficient e-services. Also, you have to recognize the primacy of electronic documents and transactions. However, the shift from paper documents to digital-only processing can be challenging. Enabling the primacy of digital records is a key issue that every country needs to address.

Carefully adapted laws aligned with overarching e-government goals are needed for societal digital transformation. Regulations should be flexible enough to accommodate emerging technologies and facilitate sustainable, future-proof digital governance.

Digital government regulations should also embed a few fundamental digital society principles to align governance with user needs and societal goals:&#x20;

* The '**once-only**' principle means citizens and businesses provide data only once to the government, enabled by interconnected databases and digital ID laws.&#x20;
* '**Digital by default**' makes online services the primary channel, facilitated by recognizing electronic transactions.&#x20;
* '**No legacy policy**' involves not digitizing legacy paperwork but reengineering processes for digital optimization as well as keeping systems and technology platforms up to date, thus enforcing security by design concept.&#x20;
* **Openness** and transparency principles require updated access to information and data protection laws.&#x20;
* **Privacy** regulations (e.g. GDPR) ensure confidentiality in digital systems.
* **Human rights in the Digital Era** for all population groups, as a fundamental starting point, ensuring that human rights apply online as they apply offline. This creates conditions for reducing abuse by the government, equitable distribution of benefits, and the realization of fundamental human rights in the digital era through the use of digital government without discrimination.

Overall, e-government legislation should institutionalize such principles to drive simplified, user-centric digital services focused on value creation rather than technology per se. Embedding principles in the legal framework creates obligations and incentives for administrators to apply them in practice. Regulatory guidelines can also recommend interpreting principles when implementing digital governance initiatives.

Also, focusing on general regulation and technology neutrality principles when implementing legal reforms is better than overly specializing in e-government legislation. This approach allows for a more integrated and innovative digital governance that prioritizes user needs over specific technologies. It also ensures the realization of human rights in the digital era for all individuals residing within the state's territory, including citizens, stateless persons, foreign nationals, refugees, and other categories of individuals.

### 3.2.2 Process

Here are key regulation process attributes to apply for developing good digital governance regulatory frameworks:

* Consultation - Consult relevant stakeholders like government agencies, the private sector, civil society groups, and citizens when drafting regulations.
* Transparency - Make the regulatory processes and decisions openly accessible and clearly communicated.
* Evidence-based - Develop regulations based on a rigorous assessment of available data, research and impact evaluations.
* Risk-based approach - Prioritize addressing real-world risks and challenges through regulations.
* Future-proofing - Build adaptability for regulations to accommodate emerging technologies and changing contexts.
* Technology neutrality - Focus regulations on desired objectives rather than specific technologies which keep changing.
* Accountability - Clearly define institutional mandates, roles and responsibilities for implementing regulations.
* Review mechanisms - Build systematic processes to periodically review, evaluate and update regulations.
* Proportionality - Balance regulatory costs and burden against expected public benefits.
* Outcome orientation - Structure regulations towards achieving real-world impacts and goals.
* Gradual building of Compliance - Support regulated entities in understanding and complying with regulations.

### **3.2.3 Roadmap**

The digital transformation process in government differs from that in the private sector, mainly due to the requirement for a legal basis for all government activities. While government policy documents can provide some guiding principles, it's crucial to establish them in legal text, which is the law.

There are several ways to approach this and clearly, only some of the laws are necessary for all the parts of GovStack components to be implemented successfully. For the ease of understanding, we have grouped them here in general topics. The ways the laws are drafted depends on a given country’s legal traditions; thus, it is impossible to list them by titles and provide ready-made texts. However, some of the laws that are expressing well debated technical solutions can be almost copied from best examples around the world and for some, similar countries can orient their own law drafting to the experience of others.&#x20;

In the sake of clarity, we have followed the necessary functions of government that wants to become digital in the groupings in the legal toolbox. The titles can vary and the content as well, but these functions should be offered legal basis for the overall success of digitalization.

Fundamental legal norms established in the forms of domestic and international law in the sphere of human rights in the digital era and human rights:

* Universal international legal treaties, principles, and customs concerning human rights and human rights in the digital era.
* Regional international legal treaties, principles, and customs concerning human rights and human rights in the digital era.
* National constitutional acts that enshrine basic human rights and human rights in the digital era (for example, in Estonia, access to the Internet is considered a human right), establishing basic rights to not only access the internet but also access to modern digital technologies of Industry 4.0 and their benefits.
* Federal constitutional laws that enshrine basic human rights and human rights in the digital era.
* Federal laws (including Codes, Foundations of Legislation, Laws on Ratification and Denunciation of International Treaties) that enshrine basic human rights and human rights in the digital era.
* Subordinate legislation: 1) Decrees of the head of state as provided by the Constitution or other fundamental national documents; 2) Government resolutions; 3) Departmental acts; 4) Acts of executive authorities of federal subjects.

1. Foundational laws enabling e-governance ( T. Kerikmäe (ed.), Regulating eTechnologies in the European Union, DOI 10.1007/978-3-319-08117-5\_3: e-Governance in Law and by Law, The Legal Framework of e-Governance by Katrin Nyman-Metcalf (as basis of)) and digital data flows:
   1. Legal framework recognizing electronic documents, signatures, and transactions as valid and binding, such as e-signature laws
   2. Laws enabling digital identification methods for individuals/businesses to securely interact with government online
   3. Legal recognition of electronic transactions, payments, billing and invoicing
2. Privacy, security, and risk management:
   1. Data protection and privacy laws regulating collection, storage, use and sharing of personal data, including in interconnected databases
   2. Cybersecurity laws setting standards for protection of government IT systems and data
   3. Intellectual property regulations for government data and digital services&#x20;
3. Openness, transparency, and access:
   1. Access to information/freedom of information laws facilitating proactive disclosure and access to government data and documents
   2. Regulations on use of emerging technologies like artificial intelligence, cloud computing, and blockchain in government
4. Institutional organization, standards, and oversight:
   1. Organizational and institutional mandates clarifying roles, responsibilities, and oversight for e-governance initiatives
   2. Interoperability frameworks and open standards to allow connectivity between government IT systems &#x20;
   3. Competition regulations adapted for e-government public-private partnerships
5. Digital service delivery:
   1. Administrative laws and procedures adapted for electronic administrative processes and digital service delivery
   2. Laws on digital archiving and records management for electronic documents and data
   3. Rules for electronic procurement, tendering and contracting&#x20;
   4. Laws facilitating electronic voting and other e-democracy initiatives, where applicable

## 3.3 Digital Infrastructure

### 3.3.1 Overview<br>

Digital transformation of the public sector should enable better user experience and reliable legal digital transactions. For secure and resilient delivery of public digital services, a certain level of Digital Government Infrastructure should already be in place (for details, see section 2.5 above):

<figure><img src="https://4055358096-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FpqnbDhX09tb5z7q4AWcQ%2Fuploads%2F9kzqUTe57fjPsj0tkzoh%2Fimage.png?alt=media&amp;token=cd8913e7-81e2-4622-9df5-384fc15b20d2" alt=""><figcaption><p>Figure 8 - Digital Governance Model (Source: Ivar Tallo &#x26; Aare Lapõnin)</p></figcaption></figure>

Digital Governance Infrastructure consists of a Foundation Framework Digital Infrastructure Pillars.

Foundation Framework contains:

* governance,&#x20;
* policy, and&#x20;
* legal components.

Four Digital Infrastructure Pillars such as

* Access
* Digital Data
* Interoperability
* Digital Identity

Following is description of required level of maturity for those components to enable digital transformation of public sector.

### 3.3.2 Principles & Policies

The digital governance policy should focus on to national coordination, capacity building, data and technology governance, iterative piloting, and stakeholder engagement for digital transformation.

#### General guidelines

Following are key recommendations from international for digital government policy frameworks:

* Develop a national digital or e-government strategy with vision, priorities, and implementation roadmap (EU, OECD, ADB, UNDP)
* Establish centralized coordination of digital government efforts (EU, OECD, WB)
* Develop policies and standards for digital services, data, shared platforms, interoperability, and cybersecurity (EU, OECD, WB)
* Institute governance frameworks specifying institutional roles and responsibilities (OECD, WB)
* Develop national laws or amend existing ones (including constitutions) to incorporate human rights in the digital era, such as access to the internet and Industry 4.0 technologies, as well as the benefits derived from such technologies, into digital or e-government strategies.
* Develop digital capabilities and skills within government (EU, OECD, WB)
* Pursue public-private partnerships and engagement with startup ecosystems (EU, OECD, WB)
* Develop guidelines for use of emerging technologies like AI in the public sector (OECD)
* Leverage digital technologies at all stages of policymaking (OECD)
* Undertake piloting and iteration in digital government innovations (UNDP, WB)
* Develop guidelines for digital procurement and platform business models (WB)
* Promote whole-of-government and government-as-a-platform approaches (EU, WB)
* Develop legislation for digital identity, data protection, cybersecurity etc. (EU, WB)
* Commit to principles of openness, transparency, and public participation (UNDP, OECD)
* Continuously evaluate policies and update based on latest trends and feedback (ADB)

#### Principles

Regulations and policies should adhere to the following principles:

1. Rule of law based on the priority of human rights and the SDG set by the United Nations. The rule of law is a fundamental governance concept that pertains to the idea that everyone, including individuals, institutions, and governments, is subject to the law and accountable under it. In modern terms, this means that a state should be governed by a system of international and domestic law rather than arbitrary decisions or whims of those in power. In this context, the law should be understood as a system of principles and norms aimed at realising human rights, particularly human rights in the digital era, shaping a human-centred state, eliminating barriers that may arise with new technologies and minimising state abuses. A modern digital state should be human-centric. Legal regulation of the digital environment related to human rights will ensure that technologies serve the benefit of every individual, enhance trust in digital service systems among the population, and minimise abuses (for example, excessive data collection, discrimination, and human rights violations). This will increase public engagement in state development and enhance trust in the system.
2. Whole of government - The principle refers to an approach in governance where all government agencies, departments, and ministries work collaboratively and cohesively towards achieving common goals and objectives. This approach recognises that many complex issues and challenges societies face require coordinated efforts across different sectors and levels of government. Systems and services should interoperate by design to deliver integrated services across agencies.
3. Digital by Default - Public services should be delivered digitally as preferred. Traditional channels remain available, but digital should be primary.
4. No-legacy - rethinking and redesigning processes from scratch to take full advantage of technology and be "digital native".
5. Once Only - Citizens and businesses should only have to provide information to the government once. Data should be reusable across agencies. Public organisations should share information proactively. Processes and decision-making should be transparent.
6. User-Centric Government - Services should be designed around user needs and experience. Governments should adopt an outside-in perspective.
7. Natural Digital Environment - Public administration should aim to deliver digital services directly to customers' natural digital environment.&#x20;
8. Public and Private Sector Co-creation – Public administration should engage the private sector in the process of co-creation of public sector digital services on a beneficial private sector basis.
9. Cross-Border by Default - Services should cater to citizens' needs regardless of location.
10. Intrinsic Security & Privacy - Security and privacy should be embedded into systems immediately, not as an afterthought.

#### Policies

Policies are a great way for the government to communicate their goals in a way that everyone can understand, as opposed to using legal language in legislation which can be difficult to comprehend.&#x20;

Policies introduce new concepts and provide context to help explain them. While there can be many different policies, there are a few that are essential for successful digitization efforts.&#x20;

<details>

<summary>Digitalization policy</summary>

Summarizing the dynamics of digitization drive of the government, the major responsibilities and expectations the government has vis-a-vis the initiative its entities toward digitization, what citizens, government and society at large can expect to be achieved if this direction is upheld. It also usually caters to access questions and formulates overall goals for other policies like once-only for services and creation of a digital data ecosystem.&#x20;

</details>

<details>

<summary>Policies</summary>

Policies are a great way for the government to communicate their goals in a way that everyone can understand, as opposed to using legal language in legislation which can be difficult to comprehend.&#x20;

Policies introduce new concepts and provide context to help explain them. While there can be many different policies, there are a few that are essential for successful digitization efforts.&#x20;

#### Digitalization policy

Summarizing the dynamics of digitization drive of the government, the major responsibilities and expectations the government has vis-a-vis the initiative its entities toward digitization, what citizens, government and society at large can expect to be achieved if this direction is upheld. It also usually caters to access questions and formulates overall goals for other policies like once-only for services and creation of a digital data ecosystem.&#x20;

#### Digital services policy&#x20;

The efforts of directing/doing all services from one office have shown not to work too well, the business processes are simply too different. However, there should be harmonization of efforts, so primary suggestions as user centricity or once only or multichannel approach, etc could be put forward and explained in that type of policy. &#x20;

#### Data Policy&#x20;

Data Policy’s prime purpose for the government is to move from analogue to digital mode of operation and to establish the primacy of digital data over paper-based records. For that to happen, there must be a shift to trust the data in government databases. Government has to establish the precise rules for the databases and registers, how they are created, who can run them on behalf of the government and how the data is collected and kept in the digital age. One of the hardest debates in any government is how different data is priced and who has the right to use it.&#x20;

#### Data protection policy

Data protection topic is treated differently in different cultures. However, the basic substantive principles as well as the way they are approached are quite similar. If there is no data protection legislation yet or if there is some 15-20 years old law, it would make sense first to articulate the current demands coming from digitalization drive as opposed to traditional treatment from the time when personal data protection was more concerned with potential government violations as opposed to current public-private interactions, private sector data protection issues, cross border data flows, and technical ways of addressing variety of data protection concerns and political concerns that come from the desire of the private companies to participate in large markets like the EU Common Market where there are strict data protection rules in force and these rules are applicable to all outside participants also. &#x20;

#### Cyber security policy

Cyber security has evolved over the last 15 years from a niche exercise into one of the most critical areas of digital activities. When any country is embracing digital journey seriously, there is a need for basic statements of intention on cyber security. It is necessary to situate the cyber security activities into the overall digitization effort and as stated above, find a logical timeline to deal with these issues. First, if digitalization is still in the initial stages, cyber security concerns can be kept in mind but no serious budgetary claims to this area should be honoured. Second, there is a need to situate the cyber security concerns in government structures correctly.&#x20;

There are usually three types of claims made by different participants to own these processes. First, there is the question of network protection issues that are typically addressed with CERT/CSIRT type of organizations whether private or public. Second, there are traditional issues of physical network protection and how to best accomplish this, whether and to what extent a government needs to use private networks or could they utilize public networks and protect only data belonging to the government. Third, there are concerns about critical information infrastructure protection. They appear when governments start to rely on their functions to the&#x20;

So traditionally there are three parties interested in taking lead: security organisations, defence organisations and digital/economy ministries. The cyber security policy needs to sort out how the given government wants to approach these topics.&#x20;

#### IT procurement policy

IT procurement needs are different from those of finite goods or services as there is constant technological development and procurement should support the development needs of the administration when formally the rules have to prevent different forms of corruption. The development of some IT elements, like interoperability platforms could take years. At the same time, IT developments are path dependent, I.e., if there is a choice of certain products, it is difficult to switch to alternative products and one has to be aware of the problems that these features cause in the overall development process and how to address them.

</details>

<details>

<summary>Digital services policy </summary>

The efforts of directing/doing all services from one office have shown not to work too well, the business processes are simply too different. However, there should be harmonization of efforts, so primary suggestions as user centricity or once only or multichannel approach, etc could be put forward and explained in that type of policy. &#x20;

</details>

### 3.3.3 Building Infrastructure

#### **Whole-of-Government**

The SDG Digital Investment Framework offers a comprehensive approach to help organizations break down silos from a technical perspective. This cross-government view allows for a methodical approach to making digital investments. The framework provides a compelling rationale for enterprise planning and funding reusable platforms, registries, workflows, and policies.&#x20;

This approach shifts traditional silo-based thinking and investments, enabling a citizen-centric and whole-of-government digital transformation. It's important to identify shared services, workflows, and data to meet the needs of multiple agencies and sectors, consolidating duplicated services and eliminating duplicate data through interoperability.

The working environment of government organizations differs significantly from that of private enterprises. In government agencies, decision-making is often guided by political considerations, complex hierarchical structures, and various relationships, unlike in private companies. Thus, resolving competency and responsibility issues is usually more critical than ensuring technological solutions are appropriately aligned. That is why the whole-of-government approach often encounters substantial opposition and challenges.

#### **Chicken-egg problem**

It takes time to implement the comprehensive set of preconditions. You may face the chicken-and-egg issue: why would someone invest in Digital ID, for example, when there are no digital services available? In ministries and departments, you cannot build personalized services without universal national digital identification capacity. What can be done about this?

It is therefore a good idea to use a two-tier approach:

* Target the foundational elements.&#x20;
* Make some quick wins that help demonstrate the benefits of the chosen path to both political leaders and the public.

The incremental building of capabilities and digital readiness allows for managing the complexities of digital transformation.

The pragmatic approach will first focus on improving connectivity, instituting IT management capacity, and nurturing digital culture within government organizations.&#x20;

Once the basic infrastructure is in place, introducing digital document and data management systems should catalyze the initial shift away from paper-based processes.&#x20;

With the initial foundation solidified, the next stage should involve:

* digitizing public sector back-office operations and transactions, i.e., pursuing quick-win projects early on to demonstrate tangible benefits and impact, building momentum for more significant initiatives (priority use cases).
* delivering omnichannel self-services focused on user needs, and&#x20;
* developing data management platforms to support decision-making processes, i.e., digitizing existing processes and transactions to enable digital delivery of high-volume citizen-government interactions. If most of the data is in traditional paper format, digitizing existing paper-based documents in use is necessary.&#x20;
* Develop basic national digital infrastructure standard services like digital ID, payments, and legal data registries.&#x20;

#### **Transforming Services**&#x20;

Use user-centered service design principles to transform public services around user needs for an integrated omnichannel experience.&#x20;

Build skills and culture for user-centric governance through extensive training programs, especially retraining public servants.&#x20;

When undertaking reforms, manage change through stakeholder engagement, communication, and participatory approaches.

**Manage Data**

Today, it is widely recognized that organizational data is an important asset. Data and information can provide insights into customers, quality, needs, and services, which can help organizations innovate and achieve their strategic goals. Despite this recognition, only a few organizations take steps to consolidate all available data and use it actively on a daily basis.

Deriving value from data requires intention, planning, coordination, and commitment. It requires data management. An organisation should establish data management, i.e., the development, execution, and supervision of plans, policies, programs, and practices that deliver, control, protect, and enhance the value of data and information assets through their lifecycles.

**Driving Adoption**

Build, test, and refine digital services using an agile, iterative approach based on continuous user feedback and data insights.&#x20;

Collaborate with the private sector and civil society via partnerships, hackathons, and open government data initiatives to drive co-creation and adoption.&#x20;

Review progress periodically, share lessons across government, and update strategies based on the latest trends.

#### **Sustaining Innovation**

Pursue a whole-of-government approach to digitalization for integrated services across agencies but allow flexibility for contexts of different departments.&#x20;

Institutionalise mechanisms for periodic reviews and incremental improvements in policies, regulations, and technologies.&#x20;

Share best practices across government and with other countries to sustain continuous innovation as technologies evolve.

Also, to some degree, "allow to fail" is important. You learn from failed projects. If you always fear failure, you will probably never do anything at all.

## 3.4 Foundational Pillars

### 3.4.1 Access

#### **Example of electricity**

William Gilbert's book, De Magnete, published in 1600, distinguished between the lodestone effect and static electricity produced by rubbing amber. He coined the word electricus, which led to the creation of the English words "electric" and "electricity." Only, during the late 19th century, notable individuals, such as Alexander Graham Bell, Thomas Edison, Nikola Tesla, and George Westinghouse, made significant contributions to electrical engineering, transforming electricity from a scientific curiosity into a crucial tool for modern life. Electric lighting became common only in the early 20th century.

It took 300 years to develop and make accessible an alternative to candles for people. We must ensure that digital services become available to everyone within a **much shorter period**.

Enabling nationwide access to digital services needs a holistic approach that simultaneously addresses infrastructure, education, policy, and societal requirements.

Here are the main components needed for that.

**Infrastructure**

Reliable electricity is a prerequisite for digital services. Therefore, improving the electrical grid and exploring renewable options like solar power can be crucial.

Invest in broadband infrastructure to provide high-speed internet access across urban, rural, and remote areas.&#x20;

Enhance mobile network coverage to include 4G/5G technologies to ensure widespread internet access. This could involve using satellite connections, mobile broadband, or other technologies suited to remote regions.

Affordability can be improved by providing subsidies or affordable plans for low-income households to access digital services and by offering incentives to internet service providers to extend services to less profitable areas.

#### **Education**

Digital literacy and education are crucial enablers for the digital transformation. To promote digital education and awareness, the following steps can be taken:

* Training Programs: National digital literacy programs can be implemented to educate people about the benefits of digital services.
* School Curriculum: The younger generation can be made digitally literate by integrating digital skills training into the school curriculum.&#x20;
* Awareness: To encourage adoption, run promotional campaigns and provide assistance and incentives for transition to digital platforms.
* Socio-economic barriers: identify and address inequality by reducing socio-economic disparities that may hinder access to digital services.&#x20;
* Internet Kiosks: set up community internet access points or digital kiosks in areas with low private home access.

**Policy**

It is crucial to build human capacity in ICTs through education, infrastructure development, and international internet bandwidth expansion.

To establish inclusive and transparent digital transformation governance, you need to:

1. Establish a centralised authority responsible for driving the digital governance agenda.
2. Engage with stakeholders (citizens, NGOs, and the private sector) to ensure digital services meet everyone's needs.

To build trust in digital services, enact strong data protection and privacy laws and establish robust cybersecurity frameworks to protect against cyber threats. Implement secure and verifiable digital identity systems that can be used to access public services.

Encourage collaboration between government, private sector, and non-profit organisations to expand digital services and stimulate investment in digital technologies and infrastructure.

Invest in research and development in the digital sector to foster innovation and support start-ups through incubators, grants, and mentorship programs. Across the globe a tech start-up ecosystem is expanding rapidly, attracting significant investment in sectors like FinTech, AgriTech, EdTech, and HealthTech. Diversification in services offered by start-ups contributes to economic development and innovation.

Develop KPIs and metrics to measure digital service uptake and impact. Implement feedback systems for continuous improvement.

#### **Social Requirements**

It is important to note that simply automating existing business processes may not provide any significant benefit to citizens or businesses. It may only result in some efficiency gains for the internal staff of public administration organisations. This can be seen as a good first step towards building the capacity to transform, but it is only a start.&#x20;

Eventually, the goal should be to achieve a real transformation of existing processes while keeping in mind the desired outcomes by fully redesigning internal processes and implementing the Once-Only and Digital-First principles.

Use design thinking to ensure digital services are easy for people of all digital skill levels. Additionally, one should adhere to accessibility standards to make our services usable for people with disabilities.

It is important to provide digital services in multiple languages to cater to diverse linguistic groups within the nation.

Promote mobile financial services and develop digital platforms for government services to encourage digital economic inclusion. Actively explore digital financial services to enhance financial access through mobile money and central bank digital currencies. Mobile money has played a significant role in financial inclusion by enabling accessible digital payments and transfers without the need for physical banks.

Enhancing digital infrastructure, technology adoption, and financial services can drive economic growth, structural transformation and prosperity.

Telemedicine services can extend healthcare access to remote areas. Digital services can provide farmers with information on markets, weather, and farming techniques. Targeted programs can encourage and support women and girls in using digital technologies to address the gender digital divide.

Collaborate with community leaders to increase digital adoption and address any cultural resistance.

### 3.4.2 Digital Data

#### **Data Management**

A country's digital transformation has a significant impact on governance, particularly on data management. We have a well-established system for handling paper-based documents and information, including the infrastructure for creation, dissemination, usage, and retention. This system is deeply ingrained in our societies and taught in schools, universities, companies, and the public. However, when we shift from paper to digital data, we need to create a similarly comprehensive and solid infrastructure that can handle digital information on a societal-wide level.

Specific policies required for data management in a country to facilitate digital transformation should at least include the following elements.

**Data privacy regulations**, such as the General Data Protection Regulation (GDPR) in Europe, play a crucial role in governing personal data collection, processing, and storage. These regulations ensure that individuals have control over their personal information and that organisations handle it responsibly. By implementing these laws, a country can ensure that anyone who processes data will comply with the legal requirements and foster trust with their customers.

Establishing **standards** and regulations for data security to protect against unauthorised access, breaches, and cyber-attacks. This may involve encryption protocols, authentication mechanisms, and regular security audits.

Data **localization** law sets rules on where data can be stored and processed, including requirements for data to be kept within national borders or specific regions to protect sensitive information.

**Open Data** policies promote transparency, collaboration, and economic growth by encouraging government agencies to make non-sensitive data available to the public for analysis, research, and innovation.

**Interoperability** standards and protocols will enable different systems and platforms to exchange data seamlessly. Interoperability facilitates integration, data sharing, and collaboration across various sectors and organisations.

Creating mechanisms for **sharing data** between public and private entities while ensuring privacy, security, and compliance with regulations can foster collaboration, innovation, and the development of new services and products. The should be no fees for sharing data amongst governmental agencies.&#x20;

Establishing frameworks for managing and governing data throughout **its** **lifecycle**, including policies for data quality, metadata management, access control, archiving, and compliance.

**Capacity building** initiatives to enhance the digital skills and data literacy of citizens, businesses, and government officials will ensure knowledge and expertise to manage and leverage data for digital transformation effectively. Investing in capacity building is a prerequisite for the success of data-driven projects.

**Incentivizing** data innovation by offering tax breaks, grants, or funding programs will encourage businesses and organisations to invest in data-driven innovation and technology adoption. Also, state agencies should enable depersonalised data in a sandbox to facilitate product development by start-ups.

Developing **ethical guidelines** and frameworks for responsible use of AI and data analytics to address bias, fairness, transparency, and accountability in decision-making processes.

Such policies and frameworks will enable digital transformation without jeopardising it through the risk of losing data (prioritizing the realization of human rights in the digital era in the context of AI design, development, implementation).

#### **State Registries**

State registries play a critical role in the governance, administration, and service delivery mechanisms of a country. They are centralized databases that maintain up-to-date records on various aspects such as population, businesses, property, vehicles, etc. Following are main reasons, why it should part of the national digital infrastructure enabling digital transformation.

**Authoritative Source of Information**: State registries serve as the official source for various types of data, ensuring that government agencies and departments have access to accurate and reliable information for decision-making, policy formulation, and governance.

**Efficient Service Delivery**: By having centralised registries, governments can streamline the delivery of public services. For example, a registry of citizens can expedite processes like issuing identification documents, voter registration, and providing social services, thereby enhancing the efficiency of government services.

**Improved Data Management**: Centralized registries enable better management and control of data, ensuring that information is consistently updated and maintained. This reduces duplication of data across different government entities and minimises inconsistencies.

**Enhanced Transparency and Accountability**: State registries contribute to greater transparency by providing a clear record of transactions, ownerships, and registrations. This is particularly important in areas like property registration, where clear records help prevent fraud and disputes over ownership.

**Facilitation of Legal and Regulatory Compliance**: Registries help ensure compliance with laws and regulations by maintaining records of registrations, licenses, and other legal documents. This is instrumental for business operations, vehicle registration, and real estate transactions.

**Support for Economic and Social Planning**: The data contained in state registries is invaluable for planning and research purposes. It allows governments to analyse trends, make informed decisions on infrastructure development, public service needs, and social programs, and monitor the effectiveness of policies.

**Public Health and Safety**: Registries for vaccinations, health records, or criminal records are vital for public health management and safety.

See list of most important state registries in the Appendix 3.

### 3.4.3 Interoperability

#### **Overall approach**

The public sector architecture follows a distributed model. This empowers government agencies to be independent yet integrated. Agencies can choose their systems and partners while benefiting from centralised governance and standards that enable efficient, secure, and scalable systems.&#x20;

Taking a whole-of-government approach that balances standardisation with flexibility will provide a digital ecosystem that serves citizens seamlessly while giving institutions autonomy.

The interoperability infrastructure should establish legal certainty and trust by enabling once-only data collection from citizens and strong data lineage across all systems. Cyber resilience is ensured through distributed security measures rather than having a single point of failure.

The interoperability platform for information exchange between systems should be fully decentralised implementing the following key aspects:

* Information exchange is always between the receiver and submitter without any centralized party in between.
* Organisational sovereignty of participating in information exchange members is not compromised retaining administrative responsibility to data owners and users.
* There is clear data lineage supported by PKI-based logins.
* There is cyber resilience supported by encryption and access rights management.
* It avoids a single point of failure through distributed data.

#### **Governance**

To achieve optimal efficiency and scalability of an interoperability platform that relies fully on distributed implementation, certain principles must be observed:

* Centralized oversight and coordination if interoperability requirements implementation across all governmental organisations.
* Standardization of security policies, software, and protocols for data exchange.
* Mandatory verification, testing, audit, and certification to ensure compliance.
* Governmental central agency should operate usage monitoring and permissions management; that should ensure legal certainty.

#### **Administrative procedures**

There should be a procedure that ensures the trust and interoperability of participants. The owner of the procedure should be the central governmental agency. The following aspects should be covered:&#x20;

1. Application – members should apply to Central Authority to join interoperability platform describe planned information system, data content and usage intent.
2. Verification - The authority verifies the application and ensures the planned system meets security and interoperability standards.
3. Agreement - An agreement is concluded between Authority and the information system owner outlining rights and obligations.
4. Installation - Authority provides standard interoperability member’s software and assists with configuration.
5. Testing - Extensive testing is done to validate correct functioning before moving to production.
6. Security Audits - Regular security audits are conducted by all participants.
7. Usage - The information system owner access data and share information with other systems based on principles and regulatory framework.

At an institutional level, decentralised interoperability platform empowers government agencies to be independent yet integrated. Agencies can choose their systems and partners while benefiting from centralized governance and standards that enable efficient, secure, and scalable interoperability.&#x20;

### 3.4.4 Digital Identity

Digital identity is a key enabler of secure and trusted digital services and transactions between governments, organizations, and individuals. At its core, digital ID provides authentication and digital signature capabilities that allow legal validity like handwritten signatures.

While approaches like self-sovereign identity or federated functional identity are around, they currently face adoption challenges due to legal uncertainties and technical complexities. For legally binding digital identity and signature solutions, a foundational ecosystem model is advisable.

The digital signature and identity ecosystem have layers:&#x20;

#### **Legal Framework**

It is needed to properly regulate and operate every aspect of the ID ecosystem. A comprehensive legal framework like eIDAS in the EU establishes standards for digital identity, electronic signatures, electronic seals, time stamps, and more. This provides the regulatory basis for digital ID ecosystems to ensure legal compliance. However, every government and situation may require slight adjustments to ensure success.

#### Identity Provider&#x20;

Identity provider(s) enroll and verify real-world identities into the digital system (civic registry). This can be government bodies or authorized private providers. Enrolling digital identities into the ecosystem requires in-person verification and the ID issuance process in many cases. In the case of fundamental ID, it should be issued, governed, and maintained by government authority or by a service provider appointed by authority. In ideal case the ID issuer should be the same authority that is responsible of issuance of passports, to ease the legal validity question of digital ID. Thus, here below is an example of civic registry, vital statistics, and identity management system overview, recommended by UN. The civic register with all its components will play a crucial role as a base information for the rest of the ID ecosystem layers.&#x20;

<figure><img src="https://4055358096-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FpqnbDhX09tb5z7q4AWcQ%2Fuploads%2FKIZ7a5jafI1kq95gTJ7l%2FScreenshot%202024-05-29%20014113.png?alt=media&amp;token=f6be4b45-4367-4ed0-bd40-5415a959e51c" alt=""><figcaption><p>Figure 9 CRVS platforms, Key Findings for Practitioners by UNICEF; graph developed by UN Legal Identity Expert Group (LIEG)</p></figcaption></figure>

#### Identity Token

The identity token is a cryptographic container that stores digital keys for authentication, digital signing, and encryption. It can be based on smart cards, mobile apps, SIM cards, etc. Having multiple tokens running in one ecosystem provides additional resilience for token failures and allows users to switch between solutions that are most suitable for their use case, thus providing flexibility. These tokens can be provided by private sector providers, and it is advisable to create a competitive market.

#### Certificate Authority

Trusted certificate authorities validate user identities and bind their identity to their cryptographic keys by issuing digital certificates. Multiple CAs can exist within the ecosystem as per the legal framework. This prevents vendor lock-in and will boost rollout.&#x20;

#### User Software&#x20;

Software tools enable integration with business workflows to allow digital signing, verification, and authentication. Opting for open standards and open-source software enables ease of adoption. Customizable solutions cater to specific needs.

All these layers are necessary for a comprehensive and proven digital ID ecosystem. Technically, there are multiple ways to address these aspects, but building blocks and open-source approaches are essential for government sovereignty and system sustainability.

Many governments struggle with digital ID and signature deployments due to low citizen participation. A recommended solution is to develop a "killer-service" that everyone needs and wants to use. Collaboration with the private sector for cross-domain use cases, such as using government-provided digital ID as an authentication method for banking services, enables legally binding client data in digital format while outsourcing authentication process risk management to the government. These types of solutions are win-win and can boost and ease the solutions take-up. &#x20;

<br>


# 4. Organisation Level

## 4.1 Overview

Digitization challenges at organization and government levels require separate treatment due to technical and political considerations.&#x20;

Although the term "Whole-of-Government" may seem reasonable, a GovStack approach recognizes that public sector modernization is not a single national project. Rather, it consists of hundreds or thousands of initiatives undertaken independently but in a planned manner across all levels of government. These initiatives are driven by public administration organizations, and their success depends on their capabilities. Therefore, we must approach digital transformation at the organizational level.

Digital transformation of the public sector on an organizational level depends on the availability of national digital infrastructure:

<figure><img src="https://4055358096-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FpqnbDhX09tb5z7q4AWcQ%2Fuploads%2FcsE8yzB7yc95gRUK1VbE%2Fimage.png?alt=media&amp;token=5758c363-a436-462c-9608-fb8f97b039cd" alt=""><figcaption><p>Figure 10 - Digital Governance Model (Source: Ivar Tallo &#x26; Aare Lapõnin)</p></figcaption></figure>

The Digital Governance model mentioned in section 2.5 highlights the need for a national digital infrastructure and a set of capabilities to support the digitalization of public services.

### 4.1.1 Public vs Private

Digitalization of the public sector requires significant change management of processes, skills, awareness, and legal basis, and must align with legal mandates and government-wide policies.

First, public sector operations differ from the private sector in terms of organizational needs and the requirement to strictly adhere to business rules that arise from legislation and administrative regulations.

When a private sector organization aims to transform a particular aspect of its operations, the first crucial step is to establish a clear business case and obtain the necessary resources for its implementation. Once these are in place, it becomes possible to make a reasonably accurate prediction of the timeline for completing the transformation.

In the public sector, implementing similar transformations may require approval at different levels of the organizational hierarchy. Legislative changes may be difficult to pass, budget allocation may be uncertain and take a lot of time due to rigid annual budgeting procedures.

In the public sector, digital transformation has wide-ranging implications that must be considered holistically as part of any reform that involves change management:

* Rules and regulations might need updating to enable digital options; and facilitate the realization of human rights in the digital domain, which in turn will increase users’ trust (citizens, stateless persons, and foreign nationals residing in the state) in the platforms.&#x20;
* Institutional roles may need realigning.&#x20;
* Staff skills and culture will need transitioning.
* Citizens expect seamless services but lack an understanding of government roles and responsibilities.

All these aspects should be considered and planned for a successful transformation.

### 4.1.2 Functional Similarities

Organizations in the public sector share basic functions but differ in their mandates. For example, registrar functions, document management, and case management are similar across all domains but can vary in detail.&#x20;

This similarity allows the use of common building blocks for different needs while aligning procedures in specific aspects. Similar administrative functions may have different procedures, so technical solutions must align with governance and legal frameworks.

A comprehensive study of service and system design must be conducted before any building block can be deployed.&#x20;

### 4.1.3 The Role of Legislator

Often, implementing a desired innovation is hindered by outdated or overly strict regulations. This highlights the importance of having effective policy and regulatory frameworks in place that can facilitate and encourage modernization and innovation. The qualitative aspect of a state digital transformation is linked to ensuring that the transition to a proactive, citizen-centered state incorporates human rights.

### 4.1.4 Horizontal Cooperation

Ministries and agencies today are quite independent and will remain such for the observable future. They are acting based on different legal acts, which might have different legal requirements for data processing and management.&#x20;

When changes affect multiple ministries, communication should go through the highest level of the chain of command, such as ministers or the Cabinet of Ministers. It would be beneficial if a central coordinating body for digitalization was situated near the centre of the government. Even if lower-level cooperation is possible through the legislative framework, it is still more time-consuming than activities within a single organization.

The whole-of-government strategy does not imply that the entire government is a single organization. Rather, the strategy and goals should encompass the whole of government. Innovation and deployment of solutions will still happen within specific organizations that have received a designated budget.

### 4.1.5 Digital Organisation

In traditional public administration, critical capabilities of digital transformation and digital service delivery are missing.&#x20;

Those capabilities should be presented in the following areas:&#x20;

* Management & Architecture
* Digital Services
* Data-driven decision-making
* Digital Co-creation

In the sections below, we describe the capabilities and maturity level required for the digital transformation of a public sector organization.

## 4.2 Management & Architecture

### 4.2.1 Management

Digital organisations differ from traditional public sector organisations and, as such, require different management practices for successful functioning. This does not necessarily mean that managers need to have a computer science degree or similar qualification, but rather that management practices should be adapted to consider the significant digital infrastructure present in the organisation. Process management, operational costs, and risks are also different in digital organisations, and therefore, staff skills need to be adjusted accordingly. Additionally, stakeholders in digital organisations are also distinct, and management practices should reflect this.

#### **Who decides?**

First among them is the widespread belief that digitalisation is a task for the IT department of a given organisation. Decision makers delegate the challenge to the technical department, whose primary task often is to take care of IT hardware, software, and connectivity and who administers the internal network if it already exists. These are all necessary tasks; however, the digitalisation challenge is about changing the business processes, which is a management-level task.&#x20;

Thus, a digitalisation project should be owned by the management. It is their business processes that would undergo change.&#x20;

#### **How are changes done?**

The next challenge is integrating a digitalisation project into the organisation's broader administrative framework. It is insufficient to provide funding for its implementation; there must be communications to departments responsible for legal issues, PR, HR, etc. IT departments are of a technical nature, and often, they are not accustomed to communicating with stakeholders. This can put the project under additional strain.&#x20;

It is crucial to analyse and address change management issues on an organizational level to identify and solve cross-cutting issues beyond the implementation of a technical solution and reduce inevitable tensions that arise with the adoption of new ways of doing business.&#x20;

In the context of such change management, it is essential to understand that while the private sector can align everything with the goals defined by leadership, government organizations must follow rules often reflected in laws that are not easily changeable, adoptable, or ignorable.

#### **How is communication done?**

There are clear steps that management should implement to advance change management on an organisation level. &#x20;

* Create a vision statement in human language, i.e. not just bullet points but what the goals are and how different users would benefit from the digital project that is planned to be implemented.
* Get approval from the top-level leadership, including whenever necessary on a political level.
* Create events to talk about it, preferably in a semi-formal environment that allows anyone to express their reactions because the pain points for implementation would come out of this.&#x20;
* Approach key middle-level managers separately to recruit them to be supporters of the project.
* Institute clear communication protocols between the digitalisation project and legal, HR and PR departments to avoid non-IT related misunderstandings during the implementation period.&#x20;
* When necessary, agree on training and awareness events.
* Map potential stakeholders outside the given organisation and seek to engage them in a similar fashion.

All these actions are the responsibility of the organization's management and not the IT department's area of expertise or responsibility.

#### **Chief Digitalisation Officer (CDO)**

In every public sector organization, there should be a Chief Digital Officer (CDO) who is part of the top management. The CDO should have a strong background in business and digital transformation to combine these practices and support strategic management toward more effective digitalization.

### 4.2.2 Architecture

An organisation in the digital age is not merely a social construct. It is, as before, a well-structured entity comprising of people, policies, and an internal culture. However, it is also a complex technological system that involves new operational methods and inherent risks. To manage such a techno system effectively, one must clearly understand its elements, roles, and dependencies.&#x20;

Knowledge gained from development projects alone does not suffice to comprehend an organisation's resulting technology landscape. Hence, it is crucial to practice systematic organisational architecture management to gain visibility.

Architecture is an abstract description of a system's entities and the relationship between those entities 13. Only if you have an up-to-date organisational architecture description can you plan maintenance costs, seek potential business process improvements, design service-level quality monitoring systems, etc.

## 4.3 Digital Services

Service delivery is done differently in digital organisations compared to traditional public service deliver

#### **Where is business value from digital?**

Governments worldwide are embarking on digital transformation journeys to enhance efficiency and service delivery. Yet, optimising government transactions goes beyond merely digitising documents and constructing IT systems.&#x20;

Digital transformation requires a comprehensive strategy that encompasses legislation, regulations, institutional agreements, workforce capabilities, and a shift in cultural mindset.&#x20;

* Business value from the transformation can be achieved only if the whole operating model is adequately adopted for the digital era.
* Early agreements and collaborations can speed up digitisation. Laws must support digital governance principles. Again, a phased roadmap is essential for successful implementation.

#### **Is it Digital-first?**

To streamline transformation, there is a pressing need to modernise overarching public procedural laws that define general rules for public administration, organisations, and officers. Instead of amending laws for each individual organisation and procedure, a holistic public procedural law can set the foundational principles vital for a digital public administration.

On the regulatory spectrum, digital data and documents should be accorded the same validity and protection as their paper counterparts. For instance, electronic signatures and documents should be legally equivalent to handwritten signatures and paper contracts. By updating laws to embody these digital equivalence principles, the pace of modernisation can be accelerated.

Uniform cybersecurity and data protection standards for government systems should be established.

#### **How do we get Digital Literacy?**

Promoting digital literacy among public officers and citizens is paramount in today's digital age. As governments and public institutions transition towards complete digitalisation, it's essential that both public officers and the general populace are well-equipped with the knowledge and skills to navigate this new digital landscape. Here are some training activities, with examples, that could be beneficial:

Digital Literacy Workshops for Public Officers

* Scenario-based Training: Use real-life scenarios to demonstrate the implications of complete digitalization. For instance, a simulation could show how a digital system might streamline the approval process for a public project, highlighting both the advantages and potential pitfalls.
* Hands-on Computer Training: Offer courses on essential software and tools that public officers might use in their daily tasks, from data analysis tools to project management software.
* Digital Etiquette Seminars: Educate officers on the dos and don'ts of digital communication, emphasizing the importance of clarity, brevity, and respect.
* Mindset Shift Sessions: Organize sessions focusing on digital transformation's benefits, addressing common fears and misconceptions. Explain the user-centric approach to service design and illustrate how it differs from the traditional officer-centric approach.
* Cyber Hygiene Seminars: Offer seminars on basic cybersecurity practices, such as how to recognize phishing emails, the importance of regular software updates, and the dangers of public Wi-Fi.
* Executive Digital Bootcamps: Organize intensive training sessions covering digitalization's strategic implications, ensuring that top-level decision-makers understand the broader impact on the organization.
* Cybersecurity Tabletop Exercise for Top Management: These exercises simulate cyber incidents in a controlled environment, allowing management to test response strategies and improve decision-making processes without the risk of real-world consequences.
* Human rights in digital era and the digital transformation of law Seminars: Train politicians and legislators in new knowledge areas of digital law transformation and governance; ensure that the strategic legal vision for a digital state is citizen-centered and takes into account the context of modern technologies (generative artificial intelligence, Industry 4.0, Web 3.0) and their impact on human rights.

#### Digital Literacy Workshops for Citizens

* Hands-on Sessions: Organize practical sessions where citizens can set up their digital profiles, learn to recognise secure websites and practice safe online behaviours. Additionally, the sessions can include workshops aimed at building trust in digital platforms. This will help ensure that citizens are aware of their digital rights and understand how the government is working to implement them.
* Digital ID organisation and Authentication Workshops: Use simple, relatable examples to explain concepts like digital tokens, two-factor authentication, biometric verification, and password management.

#### Change Management Programs

* Feedback and Discussion Forums: Create platforms where public officers and citizens can voice their concerns, ask questions, and provide feedback on the digital transition.
* Digital Champions: Identify and train enthusiastic individuals about digital transformation to act as role models and assist their peers in adapting to new technologies.
* Regular Updates and Communication: Ensure that all stakeholders are kept in the loop about upcoming changes, the reasons behind them, and the benefits they'll bring. Ensure that all stakeholders consider the priorities of implementing human rights in the digital era in new governance systems.

By implementing such training activities, governments can ensure a smoother transition to digital platforms, with a workforce and citizenry that are skilled, confident, and comfortable in the digital realm.&#x20;

The change management programs and training are instrumental in fostering this cultural metamorphosis.

## 4.4 Data-driven Decisions

Often, digital transformation is perceived as a project of implementing some technology. However, it is an activity which is enabling more efficient data management. So, the focus should be shifted from the technology to the question, what can we do with new data? That will help us adopt a data-driven approach to thinking and decision-making.

Adopting a data-driven decision-making approach involves integrating data usage into business processes at all levels of an organisation.&#x20;

Here's a step-by-step guide on how an organisation can start with data-driven thinking:

* Define clear objectives that align with the overall business strategy for effective data-driven decision-making.
* Develop a data strategy for crucial decision-making.
* Implement data governance policies and assign data management responsibility.
* Upgrade data infrastructure to handle various types and volumes of data. Use data warehousing, data lakes, and other relevant technologies.
* Collect and integrate relevant data from internal and external sources for a comprehensive view.
* Establish data quality standards and processes, and regularly clean and validate data for accuracy and reliability.
* Train employees to enhance data literacy and teach decision-makers how to use and interpret data.
* Deploy analytics tools that fit your needs and offer advanced capabilities.
* Define and track KPIs that align with objectives, and establish benchmarks for performance measurement.
* Encourage data-driven decision-making culture and reward contributors.
* Ensure leadership commitment to data-driven culture.
* Lead by example in data-driven decisions.

It is recommended to start with small, manageable projects to showcase the value of data-driven decision-making. By doing so, your organisation will learn from successful projects and improve your approach. Further on, iterate and improve continuously by evaluating data-driven processes, learning from successes and failures, and refining your approach.

By following these steps, organisations can gradually shift towards a more data-driven decision-making culture, leveraging insights to enhance efficiency, innovation, and overall business performance.

## 4.5 Digital Co-creation

The digital transformation of one organisation is more efficient and has a higher chance for success if it is done within the existing local digital ecosystem. Such an ecosystem should include experienced local developers, successful private digital companies, and existing national digital infrastructure. Like that, the engagement of the whole society in the public sector's digital transformation is vital.&#x20;

The following is the list of critical areas that directly impact the transformation's success.

#### **Budget**

Budget allocation to public sector organizations is done in parliament or similar institutions. Thus, the business value of digital transformation initiatives should be explained to the public. Without that, politicians will not be able to allocate resources.

Acquiring resources for a significant initiative usually involves obtaining funds from the annual state budget, which has a planning phase 9-10 months before the beginning of the next financial year. A solid business case must be prepared to apply for budget funds, and decision-makers must be convinced of the initiative's feasibility. This process can take 2-3 years before funds are received for the idea you got today. Also, financial rules often prevent transferring funds to the following year, causing potential delays and unspent budgets.

GovStack policy recommendations are:

* Multi-year budgeting with in-year transfer authority
* Dedicated budgets for enterprise-wide platforms
* Outcome-based budgeting models
* Exceptional models like "Digital First" funds
* Donor-based funded projects should have state budget commitment for long-term sustainability and maintenance.

#### **Procurement**

The public procurement process often hinders the selection of optimal technology vendors and solutions for digital systems.

The first obstacle is the lack of capacity to identify innovation areas and design feasible projects that can bring tangible results for citizens and businesses. The GovStack attempt to analyse best practices and materialise such practices into architectural building blocks will help overcome that.

The next issue is overly prescriptive contracts, and low-risk vendor choices lead to a lack of innovation.

GovStack policy recommendations are:

* Flexible procurement methods like pre-commercial procurement
* Outcomes-based requirement definitions
* Engaging innovative local SMEs/start-ups
* Joint procurement across agencies
* Project decoupling into smaller logical components and making project into a framework contract with multiple vendors

#### **IT Project**

Many digital government projects fail (20/80) to achieve expected benefits and are plagued by time/cost overruns. Key challenges are the lack of technical capabilities, poor risk management, and weak governance.

GovStack policy recommendations are:

* Start small and build organisational capacity iteratively.
* Robust project governance frameworks.
* Stage-gate models with agile iterations.
* Government-shared services for technical capabilities.
* Reusability and customizability to match business process.

Staffing should follow the definition of work processes: First, one should identify the needs for a process or activity and then hire people to execute that. One should not just “put people to organisational unit boxes”.

#### **Maintenance**&#x20;

When acquiring an IT system, the initial cost typically accounts for only 10% of the overall Total Cost of Ownership. Once the system is implemented, it becomes an asset that helps achieve business objectives and is integrated into the organisational digital infrastructure. That also increases complexity and creates dependencies. Therefore, it is important not only to allocate 15-20% of the initial cost for annual maintenance, but also plan for decommissioning the system after 5-7 years, when its technological fitness will degrade.

GovStack policy recommendations are:

* Central shared services for common applications
* Improve architecture management practices.
* Legacy modernization programs
* Develop business continuity programs and manage operational risks.

### 4.6 Organisational Taxonomy

During PAERA preparation, we analysed public administration organizations of several countries using EA techniques. We identified key business services and the required processes for those services. Additionally, we identified the applications needed to support the business processes. Complete information about the outcomes of this analysis is in Annex 1 in section A1.2 below.

An important observation from this analysis is that despite a seemingly large variety of organizational types in the public sector, it is possible to categorize them into three major types:

1. The Policy Development Unit is responsible for developing and implementing policies. A typical example is a different ministry.
2. The regulatory Agency is responsible for regulating specific sectors of the economy. A typical example here is Data Protection Authority, Business Licensing Authority, etc.
3. A state authority with a complex set of responsibilities and several performance outcome areas. We refer to such organisational type as a Service Delivery Authority. A typical example here is a tax department, police department, etc.&#x20;

We know that international government functions Classification COFOG identifies 10 government functions, which are further divided into 69 functions. For every function, there are several institutions on different levels of a public sector structure. Like that, there are hundreds and thousands of different institutions even in middle-sized countries. However, from the automation point of view all them can be generalised into 3 abovementioned types.

Following is a brief description of those types (for details see Annex 1 in section A1.2 below). To describe those organizational units, we use Business Canvas’s format.

&#x20;Policy Development Unit (PDU)

* Function: Responsible for policy analysis, development, and monitoring.
* Value Proposition: Policy development, legislation maintenance, stakeholder communication.
* Customer Interface: Engage with demographic groups, economic agents, NGOs, and international organizations.
* Strategic Partners: Parliament, government, media, industrial unions.
* Required Applications: Document Management, Content Management, Analytics, and other general office automation tools.

Regulatory Agency (RA)

* Function: Implementation and enforcement of regulations in specific functional area.
* Value Proposition: Policy implementation, license management, supervision of licensees.
* Customer Interface: Engage with economic agents and communities.
* Infrastructure: Compliance management, digital service delivery, risk management.
* Strategic Partners: Related MDAs, media, and industrial unions.
* Application Architecture by main business functions:
  * Forms & Procedures Design: User-friendly forms and automated workflows.
  * Application Capturing & Processing: Efficient application lifecycle management.
  * Payment & Refund Processing: Secure financial transactions.
  * Decision Management: Transparent decision-making processes.
  * Inspections Management: Efficient inspection scheduling and compliance tracking.
  * Legal Affairs & Litigation: Management of legal documents and cases.

Service Delivery Authority (SDA)

* Function: Complex service delivery with extensive customer interaction.
* Value Proposition: Policy enforcement, compliance monitoring, public awareness.
* Customer Interface: Engage with economic agents and communities.
* Infrastructure: Performance management, service delivery, IT management.
* Strategic Partners: Responsible PDU, related MDAs, media, industrial unions.
* Application Architecture by main business functions:
  * Registration & Profile Management: Secure user registration and profile management.
  * Customers & Users Management: Comprehensive user management and support.
  * Online Learning & Training: Interactive and accessible learning environment.
  * Customer Accounting: Efficient transaction and account management.
  * Compliance & Enforcement: Monitoring and enforcing compliance.
  * Data Management: Advanced data services for transformation and monitoring.

After creating application architectures for different types of organizations, we realized the following:

* PDU requires a general office automation environment, which is similar to what knowledge-based service providers in the private sector need.
* RA requires everything that PDU needs, plus a basic digital service delivery platform.
* SDA requires everything that RA needs, but at a more robust and industrialized level.

By integrating these architectures and identifying reusable components, we can create functional building blocks that accompany infrastructural building blocks. This integration can help public administration achieve greater efficiency, standardization, and service delivery responsiveness, benefiting citizens and stakeholders.

\
\
\ <br>


# 5. Implementation Framework

## 5.1 Capabilities Assessment

An organisation's ability to transform itself into a digital organisation cannot be achieved simply by command or by assigning a budget. It can only be acquired through the internalisation of successful implementation of modernisation projects and digitalisation initiatives. Therefore, it is essential to consider the organisation's maturity level when creating a roadmap for its transformation.&#x20;

A model of maturity levels shows a realistic and practical sequence of developing internal organisational capabilities:

<figure><img src="https://4055358096-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FpqnbDhX09tb5z7q4AWcQ%2Fuploads%2F6rroAIpZbkdyj1ClVAvt%2FScreenshot%202024-05-29%20015434.png?alt=media&amp;token=7601fd10-b9ee-4376-8509-a57adc02a604" alt=""><figcaption><p>Figure 21 - Organisation digital transformation capability model (Source: Aare Lapõnin)</p></figcaption></figure>

Our experience shows that organisations should start from the ground floor and gradually move from one level to another. Practically speaking, it is not possible to “skip” a level.

We explain this diagram by describing each step of the maturity levels diagram.

#### Ground floor

If an organisation has never implemented any automation project, we can say that it is on the ground floor.&#x20;

The ground floor, in terms of capabilities, means:

* The management did not plan for IT systems to deliver services or support activities.
* There is no organisational architecture document that describes the business, data, application, and technology used by an organisation.
* An organisation does not deliver digital services to external customers.
* Management is not using its operational data systematically to make decisions regarding strategic options for the organisation.
* The organisation has never procured IT system development and management services from a market.

Once you are on the ground floor, you should:

* Make sure there is connectivity for your organisation and your customers.
* Start with small projects, which should have a small budget and delivery timeline, at most 6-9 months.
* Prepare plans for how users will be trained to use the new system, what administrative procedures you need to support a new way of working, and how the latest IT system will be supported.
* Start cultivating a digital culture in an organisation (see 3.1.2 above for details on a digital culture).

Following important rules should be considered:

1. A New IT system is a liability, and you have to plan maintenance costs for the entire lifecycle of the planned solution.
2. There will be digital data, and you should have procedures for managing the lifecycle of the digital data.
3. There should be a unit in charge of digital transformation that is able to report and escalate to the management of the organisation.

It is important to note that if the staff has experience in digital transformation from other organisations but has yet to deliver any project as a team, then this organisation starts from the ground floor.

#### 1st Level – Trust of Data

An organisation achieved the 1st floor if the following is true:

1. Management: There are regular planning activities where management assesses and commits to proposals to invest in IT projects to improve operations. Management cultivates digital culture in the organisation.
2. Architecture: There is a process in an organisation to maintain documentation of business services, processes, data, applications, integrations, and technology components. This is known as the architecture management process, and it aligns the organisation’s business and IT staff.
3. Digital Services: The organisation is delivering digital services to external customers. For that, there is an IT development, maintenance, and ITIL-compliant IT service management capability. Also, the design and operation of digital service delivery is done as a collaborative effort between business process owners and IT.
4. Data-driven Decisions: The organisation consolidates all its data, including logs and monitoring metrics, in a reliable enterprise data warehouse (EDW). They use management dashboards and reports for operational and strategic decisions, and EDW is accessible through self-service analytics to all analysts in the organisation. For all data, metadata describes the semantics of available data. There is a data quality management process. The organisation trusts the quality of data. The organisation is in the process of learning to make decisions based on data.
5. Digital Co-creation: The organisation can procure different services from the market to ensure high-quality digital service delivery. There are channels for consultation with customers to receive feedback regarding the quality of digital service delivery.

Once you are on the 1st floor, you should:

* Continue with small projects, which should have a limited budget and delivery timeline, at most 12 months.
* Prepare plans for the complete digitalisation of all activities in the organisation. Often, such plans can be formulated as an organisation's IT strategy, and it should cover a 3-5 years time period.
* Establish a comprehensive enterprise architecture repository for detailed planning of modernisation initiatives.
* Introduce a dedicated Enterprise Architecture management team to ensure IT and business alignment.

#### 2nd Level – Process Management

An organisation achieved the 2nd floor when all indicators of the 1st floor are fully accomplished and additionally, the following is true:

1. Management: There are service level agreements (SLA) established for every business service, which is delivered to external customers. SLA levels are regularly reviewed by management, and in case of deviations, corrections are implemented. For every internal business process, there are key performance indicators (KPIs) established and regularly monitored by management. In case of deviations, corrective actions are implemented. There is a process of continuous analysis of changes in the internal and external organisational environment. The result of this analysis is proactively used for planning changes needed for improvements of quality services and efficiency of business processes. This process is known as strategic management, and it is fully aligned internally with IT management and externally with the budget cycle in the government. In the management of an organisation there is a dedicated top manager responsible for digital transformation of organisation.
2. Architecture: An organisation has the internal capability to plan for improvements in service delivery operations to achieve better efficiency. On the level of organisational architecture, there is a capability to trace all operational and IT risks and design adequate response plans for all such identified risks. There is a regular process of rationalisation of organisation application and technology landscape, eliminating or minimising existing technical debt.
3. Digital Services: All core and support processes are fully digitalised. All internal activities are digital-first by design. Full digital literacy is a mandatory skill requirement for all staff positions.
4. Data-driven Decisions: There is a mature process of development and usage of data products. Data architecture is designed based on current and long-term organisational requirements. Data architecture quality and reliability are the highest priority, and application architecture is aligned with data architecture, i.e., changes in application architecture do not change overall data architecture. The organisation relies entirely on digital data for all decisions, which is of high quality.
5. Digital Co-creation: Organisations prioritise integrating digital services with customers' natural digital environments for seamless information exchange.

Once you are on the 2nd floor, you should:

* Continue with small projects, which should have a limited budget, clear tangible objectives, and delivery timeline, at most 18-24 months.
* Plan for improvement of resilience of digital service delivery, including introducing a comprehensive and robust business continuity management process.
* Plan for better integration of business process owners with an architecture management process.
* Plan for better integration of product management with the architecture management process.
* Introduce program management discipline to manage long-term objectives systematically.
* Work to ensure that the procurement process is flexible enough to address complex tasks when the result is not possible to define precisely.

#### 3rd Level – Change Management

An organisation achieved the 3rd-floor maturity level when all indicators of the 2nd floor are fully accomplished, and additionally, the following is true:

1. Management: For all relevant policy changes, there is a capability to identify impact analysis and prepare a comprehensive change management plan, which is routinely executed by appropriate organisational units. The organisation can adopt frequent policy changes as required.
2. Architecture: An organisation can proactively plan for architecture, which supports the flexible and fast implementation of changes due to policy changes and changes in the external environment.
3. Digital Services: A mature business continuity management process ensures the resilience of digital service delivery.
4. Data-driven Decisions: The organisation can proactively support policy change requirements analysis.
5. Digital Co-creation: The organisation can ensure the sustainability of its IT systems by designing and implementing solutions using GovStack architectural building blocks.

Once you are on the 3rd floor, you should:

* Continue with small projects, which should have a limited budget, clear tangible objectives, and delivery timeline, at most 18-24 months, which are part of a program to achieve broader outcomes.
* Regularly review the external environment, international best practices, and technological advancements and update the organizational strategy to incorporate beneficial elements.

#### 4th Level – Compliance Management

An organisation achieved the 4th-floor maturity level when all indicators of the 3rd floor are fully accomplished, and additionally, the following is true:

1. Management: The organisation can proactively recommend policy changes to ensure improved outcomes in the mandated area.
2. Architecture: Architecture management is seamlessly integrated into the organisational strategic management process.
3. Digital Services: Adopting changes in digital service delivery is seamlessly integrated into the organisational strategic management process. Organisational digital platform is integrated part of national digital ecosystem.
4. Data-driven Decisions: The organisation proactively deliver data products to all internal and external stakeholders. There is an active feedback loop with all consumers of data products. Feedback is routinely used in product management.
5. Digital Co-creation: The organisation manages its organisational digital platform as a two-sided market open for providers of products and users of those products. There is a managed process of reviewing the quality of products and onboarding products with an accepted level of quality.

Upon reaching the 4th floor, it's important to continue regularly reviewing the external environment, international best practices, and technological advancements. Updating the organizational strategy with beneficial elements should be a continuous process.

## 5.2 Principles

The digital transformation roadmap of an organisation should adhere to principles which we introduced in section 3.2.2 above. In the following section, we elaborate on the implications of those principles for the digitalisation of an organisation. For every principle we outline:

* Motivation – An explanation of why we believe this principle is important for consideration during digital transformation.
* Rationale – Description.
* Implication – Description of what are the anticipated consequences of the application of the principle to digital transformation.

### Principle #1 - Rule of Law

#### **Motivation**

While individuals in the private sector may engage in any activity that are not prohibited by the law, public sector organisations can only perform activities that are strictly and directly prescribed by the law.

#### **Rationale**

That is something that helps with accountability and prevent society from becoming lawless. The principle of the Rule of Law is a foundational concept in governance that refers to the idea that everyone, including individuals, institutions, and governments, is subject to and accountable under the law. It signifies that the law should govern a nation rather than arbitrary decisions or the whims of individuals in positions of power.

#### **Implications**

The principle of the Rule of Law has significant implications for the digital transformation of a public sector organisation. Here are key implications:

1. Legal Compliance: In a digital transformation, a public sector organisation must ensure its activities, processes, and systems comply with relevant laws, regulations, and legal frameworks governing data protection, privacy, cybersecurity, and other digital-related issues, including the implementation of human rights in the digital era through digital governance systems.
2. Transparent and Accountable Governance: The Rule of Law requires transparency and accountability in governance processes. In a digital transformation, a public sector organisation must ensure transparency in adopting and implementing digital technologies, including procurement, data-sharing agreements, and algorithmic decision-making.
3. Protection of Individual Rights: The Rule of Law emphasizes the implementation of human rights in digital context and the protection of individual rights and freedoms. In the context of digital transformation, a public sector organisation must ensure that the rights of citizens, such as privacy rights and due process, are respected and protected in the design and implementation of digital services and systems. This involves conducting privacy impact assessments, implementing robust data protection measures, and providing mechanisms for individuals to exercise their rights.
4. Fair and Impartial Administration: A public sector organisation must ensure that digital transformation initiatives are administered fairly and impartially, without discrimination or bias. This includes providing equal access to digital services and resources and safeguarding against algorithmic bias and discrimination in automated decision-making systems.
5. Security and Trust: The Rule of Law requires a public sector organisation to uphold security and trust in digital systems and services. This involves implementing robust cybersecurity measures to protect against data breaches, cyber-attacks, and unauthorised access to sensitive information. It also requires establishing trust-building mechanisms, such as transparency about data practices and data security and integrity commitments.
6. Adherence to Ethical Standards: A public sector organisation must maintain ethical standards during digital transformation. Guidelines for emerging technologies such as AI, machine learning, and big data should promote fairness, transparency, accountability, and integrity.
7. The UN Sustainable Development Goals are directly linked to the Rule of Law and are a priority for countries in addressing global issues. The governance system should facilitate the implementation of the Sustainable Development Agenda, and digital governance can help distribute responsibilities to achieve specific SDGs and uphold human rights.&#x20;
8. The definition of human rights in the digital era encompasses fundamental opportunities for development, afforded to everyone by right of birth, codified in international and national law. The implementation of these rights aims to enable the use of social benefits through new technologies. It's important to differentiate between informational rights, rooted in the third industrial revolution (internet, computers), and digital rights that evolve under the fourth industrial revolution and digital globalization.

National strategies must consider human rights in the digital era, including those of children, within the changing digital landscape. This necessitates the development of relevant legislative acts, industry codes, techno-legal platforms, design standards, and action plans.

Additionally, the state should strive to implement human rights in the digital era of the entire population, which are divided into the following categories:

1. Rights to access the Internet, digital individualization tools, digital asset storage, and other digital technologies, protection of life, personal, biometric, biological, and other data.
2. Rights to access technologies (Industry 4.0) as digital guarantees for the realization of fundamental human rights. Rights to exercise personal, social, economic, political, and cultural rights based on new technologies without technological barriers.
3. Rights to manage public affairs (at the national level, and potentially in a system of global governance) through digital technology platforms.
4. Rights in the realm of ownership, use, and disposition of digital property (assets), conducting digital economic activities (transactions, digital deals, etc.), and to digital security systems.
5. The right to access social services based on digital technology platforms; equal access to opportunities offered by technologies, including access to education, employment, healthcare, and basic social services based on new technologies.
6. The right to access cultural values and education, etc.
7. The right to human-centered artificial intelligence. Priority to human interests, health, and quality of life in the context of the creation, use, implementation, and development of artificial intelligence.
8. The right to personal data protection, including the protection of genetic information and health data (for example, in the context of rapid progress in biotechnology, bioengineering, and telemedicine).

These categories underscore the importance of integrating digital rights into the legal framework to ensure equitable access to technology and its benefits across all sectors of society.

In the context of future Digital governance ecosystems development, it is crucial that they are citizen-centered. We view them as a means to implement human rights in the digital era through techno-legal platforms.

Techno-legal platforms are designed, regulated, and updatable digital products based on digital identity, aimed at realising human rights in digital era. These platforms ensure transparency, accountability, comprehensibility, and the efficiency of decisions based on technology, expanding everyone's opportunities to access social goods by integrating into specific life domains. This includes elements of big data, decentralisation, and transparency in decision-making, taking into account the achievements of the GovTech and CivTech sectors. These platforms may include mechanisms to protect personal data, ensure algorithmic decision-making transparency, and consider public interests.

The principle of techno-legal platforms operation is to align the corresponding digital human right with the techno-legal platform aimed at its implementation. This alignment allows for: first, the transformation of business processes in countries while reducing abuses in the development, implementation, and use of technologies in the public sphere (e.g., surveillance systems in public spaces not aimed at human rights realisation); second, placing technology management in a legal framework for long-term developmental perspectives; and third, addressing societal and individual needs in aspects of life quality, health, safety, and development expressed in human rights.

### Principle #2 - Whole of Government

#### **Motivation**

The public administration organisation is part of the national Digital Government Ecosystem. It should be fully interoperable with the rest of the ecosystem entirely using utilising benefits of available digital infrastructure.

#### **Rationale**

The principle refers to an approach in governance where all government agencies, departments, and ministries work collaboratively and cohesively towards achieving common goals and objectives. This approach recognises that many complex issues and challenges societies face require coordinated efforts across different sectors and levels of government.

Also, to digitize the public sector, organizations should use digital assets from others and provide their own. National infrastructure provides building blocks for the digitalization of any organization.

#### **Implications**

The principle of "Whole of Government" (WoG) has several implications for the digital transformation of a public sector organisation

1. Coordination and Collaboration: WoG implies that all government agencies collaborate closely in digital transformation efforts. This coordination ensures that digital initiatives are aligned with broader government goals, avoid duplication of efforts, and leverage the collective expertise and resources of different agencies.
2. Integrated Service Delivery: Digital transformation often involves delivering services to citizens in a seamless and integrated manner. By adopting a WoG approach, a public sector organisation should work together to streamline service delivery processes, eliminate silos, and provide citizens with a cohesive and user-friendly experience.
3. Data Sharing and Interoperability: WoG emphasizes the importance of data sharing and interoperability among government agencies. This means that data collected and maintained by different agencies should be easily accessible and interoperable, allowing for better data-driven decision-making, improved service delivery, and enhanced efficiency.
4. Holistic Policy Development: Digital transformation initiatives may require the development of new policies or regulations to govern the use of digital data and technologies. A WoG approach ensures that policy development is holistic, involving input from all relevant government agencies to address the complex and interconnected nature of digital issues.
5. Cybersecurity and Risk Management: Digital transformation introduces new cybersecurity risks and challenges that require a coordinated response across government agencies. A WoG approach enables agencies to collaborate on cybersecurity strategies, share threat intelligence, and coordinate incident response efforts to protect government systems and data from cyber threats.
6. Capacity Building and Skill Development: Digital transformation requires building the digital capabilities and skills of government employees. A WoG approach facilitates collaboration among agencies to develop training programs, share best practices, and build a skilled workforce capable of implementing and managing digital initiatives effectively.
7. Cross-Agency Innovation and Experimentation: WoG encourages innovation and experimentation by enabling government agencies to share ideas, resources, and lessons learned from digital transformation projects.
8. Public Engagement and Participation: Digital transformation initiatives should involve input and feedback from citizens and stakeholders to ensure that they meet the needs and expectations of the public.

### Principle #3 - Digital by Default

#### **Motivation**

The concept of digital transformation implies the shift towards a new era where paper-based communication might become obsolete, especially for upcoming generations. Therefore, it is important to ensure that all new processes and services are designed with a comprehensive digital user experience from the very beginning.

#### **Rationale**

In the context of digital transformation of a public sector organisation, the principle of "Digital by Default" refers to the strategic prioritization of digital channels and technologies as the primary means of delivering services, interacting with citizens, and conducting government operations.&#x20;

This principle advocates for cultivating digital culture and designing services and processes with a digital-first mindset, making digital channels the default option for accessing government services, information, and transactions.

#### **Implications**

The principle of "Digital by Default" has several implications for the digital transformation of a public sector organisation:

1. Service Delivery Transformation: Adopting a "Digital by Default" approach means that a public sector organisation prioritise delivering services digitally as the primary channel for interactions with citizens and businesses. This implies a fundamental shift in the service delivery model, moving away from traditional, paper-based processes towards digital, online, and mobile-friendly services.
2. Accessibility and Inclusivity: While embracing digital channels, a public sector organization must ensure that their digital services are accessible to all citizens, including those with disabilities or limited digital literacy. This requires designing user-friendly interfaces, providing alternative access options, and offering assistance and support to vulnerable or marginalized groups to ensure inclusivity.
3. Cost Savings and Efficiency: Digital by Default leads to significant cost savings and efficiency gains for a public sector organisation by reducing the need for manual processes, paperwork, and physical infrastructure. Automation, self-service options, and streamlined workflows help to optimise resource utilization and improve service delivery efficiency.
4. Data-Driven Decision Making: Digital channels generate vast amounts of data that can be analysed to gain insights into citizen behaviour, preferences, and needs. A public sector organization should leverage this data to inform decision-making, improve service design, and enhance the overall user experience.
5. Change Management and Stakeholder Engagement: Implementing Digital by Default initiatives requires organisational change and stakeholder buy-in. A public sector organization must engage with stakeholders, including employees, citizens, businesses, and policymakers, to communicate the benefits of digital transformation, address concerns, and foster support for the transition to digital service delivery.
6. Continuous Improvement and Iteration: Digital transformation is an ongoing process that requires continuous improvement and iteration. A public sector organization should embrace an agile and iterative approach to digital service delivery, incorporating feedback from users, monitoring performance metrics, and adapting strategies based on evolving needs and technological advancements.

### Principle #4 - No legacy software

#### **Motivation**

One of the main problems faced by digitally advanced countries around the world is the presence of legacy software systems. These systems are expensive to maintain and often offer no options for extension or updating. Therefore, new systems must be designed in a way that overcomes these issues.

#### **Rationale**

The principle of "No Legacy Software" in the context of digital transformation for a public sector organization refers to the strategic decision to minimize or eliminate the use of outdated or legacy software systems during the modernization process.&#x20;

This principle advocates for migrating away from legacy systems towards modern, scalable, and sustainable digital solutions.&#x20;

At large, software systems should be composed of reusable building blocks with viable support, which ensures at least every year new version update.

Lifecycle of software should have a clear end date and decommissioning costs should be planned and accrued from the time of acquisition.

#### Implications

1. Limited lifecycle: Every solution should have at most 5-7 years of lifecycle. At the end of the lifecycle, it should be replaced entirely.
2. Minimizing Dependence on Outdated Technology: A public sector organization should aim to reduce reliance on legacy software systems that may be outdated, unsupported, or incompatible with modern technologies. These legacy systems pose risks such as security vulnerabilities, compliance issues, and limited scalability, hindering the organization's ability to adapt to evolving needs and technological advancements.
3. Migration to Modern Platforms: The principle of No Legacy Software encourages organizations to migrate to modern software platforms and architectures that offer greater flexibility, scalability, and functionality.&#x20;
4. Enhancing Efficiency and Agility: By eliminating legacy software, a public sector organisation can streamline processes, improve operational efficiency, and enhance agility in responding to changing requirements and priorities.
5. Improving User Experience: Legacy software systems often lack user-friendly interfaces and may be cumbersome to use, leading to frustration among employees and stakeholders. Transitioning to modern software solutions with intuitive user interfaces and seamless user experiences enhances usability and satisfaction, driving higher adoption rates and productivity.
6. Reducing Maintenance and Support Costs: Maintaining and supporting legacy software systems is costly and resource-intensive, requiring ongoing investments in maintenance, upgrades, and technical support. Transitioning to modern software solutions with lower total cost of ownership (TCO) helps a public sector organization allocate resources more efficiently and focus on delivering value-added services and initiatives.

### Principle #5 - Once-Only

#### Motivation

Citizens and businesses should only have to provide information to the government once. Data should be reusable across agencies.

#### Rationale

The principle of "Once Only" in the context of the digital transformation of a public sector organisation refers to the concept of capturing and reusing information or data provided by citizens or businesses only once rather than repeatedly requesting the same information across multiple interactions or transactions and across different organisations within the public sector.

#### Implications

1. Data Sharing and Integration: The Once Only principle involves establishing mechanisms for sharing and integrating data across different government agencies and departments.&#x20;
2. Single Point of Entry: A public sector organisation implements digital platforms or portals that serve as a single point of entry for individuals and businesses to access government services, submit applications, and complete transactions in specific regulated functional areas.
3. Interoperability and Standardization: Adopting interoperability standards and data exchange protocols enables different government systems to communicate and share information seamlessly.
4. Consent and Privacy Protection: The Once Only principle emphasizes obtaining consent from individuals or businesses before sharing or reusing their data for other purposes unless such reuse is allowed explicitly by legislation.&#x20;
5. Efficiency and Cost Savings: By minimizing duplication of effort and data entry, the Once Only principle helps public sector organizations improve operational efficiency, reduce administrative costs, and optimize resource utilization.
6. Accuracy and Data Quality: Reusing data provided by individuals or businesses in previous interactions helps ensure the accuracy and quality of information used by government agencies.

### Principle #6 - Customer-centricity

#### Motivation

Services should be designed around user needs and experience. The government should adopt an outside-in perspective.

#### Rationale

The principle of "User-Centric Government" in the context of digital transformation for a public sector organization emphasizes designing and delivering services, policies, and processes to the needs, preferences, and experiences of users, such as citizens, businesses, and other stakeholders, at the forefront. It involves prioritizing user satisfaction, accessibility, and usability throughout the design and implementation of digital services and initiatives.

#### Implications

1. Understanding User Needs: User-centric government requires a public sector organisation to proactively gather insights into the needs, behaviours, and preferences of their users, i.e., conducting user research, surveys, and usability testing to understand the diverse needs and expectations of citizens, businesses, and other stakeholders.
2. Designing Intuitive Interfaces: A public sector organisation should prioritize designing digital interfaces and platforms that are intuitive, user-friendly, and accessible to a wide range of users, including those with disabilities or limited digital literacy, i.e., adopting principles of responsive design, clear navigation, intuitive workflows, etc.
3. Personalization: User-Centric Government involves tailoring services and content to the specific needs and preferences of individual users whenever possible. A public sector organisation should leverage data analytics and user profiling techniques to deliver personalized experiences, recommendations, and content that are relevant and meaningful to each user.
4. Empathetic Communication: A public sector organisation should provide clear and timely information, guidance, and support to users, addressing their concerns and needs with empathy and respect.
5. Feedback and Continuous Improvement: A public sector organisation actively solicit feedback from users and stakeholders to identify areas for improvement and enhance the user experience, i.e., gathering insights through feedback forms, user surveys, and social media channels, and using this input to iterate and improve digital services and processes over time.
6. Multi-Channel Engagement: User-Centric Government recognizes that users may have different preferences for how they interact with government. A public sector organisation should offer multiple channels for engagement, including online portals, mobile apps, phone support, and in-person services.

### Principle #7 - Natural Digital Environment

#### Motivation

Instead of doing its own portals a public sector organisation should seek for options to deliver digital services to people’s natural digital environments.

#### Rationale

The principle of "Natural Digital Environment" in the context of digital transformation for a public sector organisation refers to creating an ecosystem where digital technologies seamlessly integrate into the daily lives and activities of citizens, businesses, and government entities. It involves fostering an environment where digital solutions are intuitive, ubiquitous, and supportive of human activities, interactions, and workflows.

#### Implications

1. Seamless Integration of Digital Technologies: A public sector organisation strives to integrate digital technologies seamlessly into the daily lives and activities of users, making them an inherent and natural part of the environment. This involves embedding digital solutions into existing processes, systems, and infrastructures to enhance efficiency, accessibility, and usability.
2. Ubiquitous Access to Digital Services: The Natural Digital Environment principle ensures ubiquitous access to digital services and information across different devices, platforms, and locations.
3. Contextual Relevance and Personalization: A public sector organisation should leverage data and contextual information to deliver users personalised and relevant digital experiences, i.e., tailoring content, recommendations, and services based on user preferences, location, behaviour, and past interactions.
4. Integration with Physical Spaces and Infrastructures: A public sector organisation should leverage digital technologies to enhance physical spaces and infrastructures, creating smart environments that are connected, responsive, and adaptive, i.e., deploying sensors, IoT devices, and other technologies to collect data, monitor environments, and optimise resource usage in areas such as transportation, energy, and urban planning.

### Principle #8 - Public and Private Sector Co-creation

#### Motivation

The current phase of digital transformation should be viewed as a national economy and society transformation. Thus, public sector organisations should avoid mere automation of internal processes and actively seek to transform the value creation by engaging private sector stakeholders.

#### Rationale

Many public sector organisations still use internal processes designed with technology constraints from the 19th century. However, modern society's widespread internet and computer literacy have created a new platform for interaction between parties. To improve customer experience, the public sector must abandon their legacy processes and embrace these new platforms.

The principle of "Public and Private Sector Co-creation" in digital transformation for a public sector organisation refers to collaborative efforts between government entities and private sector organisations to jointly develop, implement, and improve digital solutions and initiatives.&#x20;

This principle emphasises partnership and collaboration between the public and private sectors to leverage their respective strengths, expertise, and resources in driving innovation, efficiency, and effectiveness in digital transformation efforts.

In the context of building a digital government ecosystem, an important aspect of public-private partnership is the interaction with stakeholders from the startup ecosystems of countries, which often utilize the latest technological advancements (generative AI, Web 3.0, Industry 4.0 in the redesign of state systems in a human-centered direction). This will allow the private sector of technology entrepreneurs to engage in initiating and developing Govtech, Legaltech, Civtech products jointly with the public sector. Such a pooling of resources will achieve sustainability, transparency, decentralization of the process and will increase economic efficiency and reduce the risk of duplicative actions in both sectors.

Therefore, it is worth paying attention to young startups that may already be trying to solve these problems, and allow them to undertake this work jointly with the public sector.

#### Implications

1. Shared Vision and Objectives: Public and private sector organisations align on common goals and objectives for digital transformation initiatives, fostering a shared vision for the desired outcomes and impact. This collaborative approach ensures that both parties are committed to driving positive change and delivering value to citizens, businesses, and society.
2. Complementary Expertise and Resources: Public and private sector organisations bring complementary expertise, capabilities, and resources. Public sector organisations offer domain knowledge, regulatory expertise, and a deep understanding of citizen needs and priorities. In contrast, private sector companies bring technical expertise, innovative solutions, and agile methodologies to the partnership.
3. Co-design and Co-development: Public and private sector organisations collaborate in co-designing digital solutions and initiatives, i.e., involving stakeholders from both sectors in the ideation, design, prototyping, and testing phases, ensuring that solutions meet the needs and expectations of end-users and stakeholders.
4. Joint Investment and Funding: Public and private sector organisations may share the financial investment and funding for digital transformation initiatives. This may involve public sector organisations providing funding, grants, or incentives to support private sector innovation and participation, while private sector companies contribute resources, expertise, and technology solutions.
5. Open Innovation and Knowledge Sharing: Public and private sector organisations embrace open innovation principles and knowledge-sharing practices to drive collaboration and mutual learning. This involves sharing best practices, lessons learned, and success stories from digital transformation initiatives and fostering a culture of innovation, experimentation, and continuous improvement.
6. Agile and Iterative Approach: Public and private sector organisations adopt an agile and iterative approach to co-creation, allowing for flexibility, adaptability, and responsiveness to changing requirements and priorities. This iterative process involves rapid prototyping, feedback loops, and incremental improvements, enabling solutions to evolve based on user feedback and real-world experiences.
7. Long-term Partnership and Sustainability: Public and private sector organisations foster long-term partnerships and collaborations to ensure the sustainability and scalability of digital transformation efforts. This involves establishing governance structures, communication channels, and performance metrics to monitor progress, evaluate outcomes, and drive continuous collaboration and improvement.

### Principle #9 - Cross-border by Default

#### Motivation

Services should cater to citizens' needs regardless of location.

#### Rationale

The principle of "Cross-border by Default" in the context of the digital transformation of a public sector organisation refers to the design and implementation of digital services and processes with a proactive approach to ensure they are inherently accessible and functional across national borders.&#x20;

This principle is particularly relevant within frameworks such as the European Union's digital single market, where interoperability and standardisation across member states are critical for the seamless delivery of services to citizens and businesses regardless of location. Also, it is equally relevant for GCC countries, African Union countries and other areas of regional cooperation.

#### Implications

1. Interoperability: Services are designed to work across different systems, administrations, and borders, using common standards and protocols.
2. Inclusion and Accessibility: Digital services should be accessible to all users, including those from different countries, and should cater to various languages and accessibility needs. This process involves the availability of digital services and the realisation of human rights in the digital era for the population residing within the state's territory (citizens, stateless persons, foreign nationals, refugees, and other categories of individuals).&#x20;
3. Standardization: Adopting widely accepted standards and practices facilitates the integration and compatibility of digital services across borders, i.e., data formats, security protocols, and communication standards.
4. Collaboration and Sharing: Encouraging the sharing of digital solutions, best practices, and resources between countries.
5. Legal and Regulatory Frameworks: Ensuring that digital services comply with the legal and regulatory requirements of all the jurisdictions they operate in.
6. Privacy and Security: Given the cross-border nature of services, robust measures to protect user data and ensure the security of digital services are paramount, i.e., adherence to international standards and practices for data protection and cybersecurity.

### Principle #10 - Intrinsic Security & Privacy

#### Motivation

Security and privacy should be embedded into systems immediately, not as an afterthought. This is sometimes referred to as “security and privacy by design”.

#### Rationale

The principle of "Intrinsic Security & Privacy" within the digital transformation of a public sector organisation emphasises that security and privacy considerations are integrated into the design and architecture of digital systems from the outset, rather than being added as an afterthought.&#x20;

This approach is foundational in building trust and ensuring protecting sensitive information and personal data managed by public sector entities.

#### Implications

1. Privacy by Design: This concept involves incorporating privacy into the initial design stages and throughout the lifecycle of any system, service, or process that handles personal data.
2. Security by Design: Similar to Privacy by Design, Security by Design requires that security measures are built into the infrastructure and processes of digital services from the beginning.
3. Data Minimization: Only collecting data that is directly relevant and necessary to accomplish a specified purpose.
4. End-to-end Encryption: Encrypting data at its origin and decrypting it only at its final destination without decryption at intermediate points ensures the confidentiality and integrity of the data while in transit.
5. Regular Security and Privacy Assessments: Conduct ongoing evaluations of security and privacy practices to ensure they are up-to-date with current threats and regulations, i.e., vulnerability assessments, penetration testing, and compliance audits.
6. User Control and Transparency: Providing users with clear information about how their data is used and ensuring they have control over it, i.e., mechanisms for consent, data access, correction, and deletion.
7. Compliance with Laws and Regulations: Adhering to all relevant privacy and security laws and regulations.
8. Employee Training and Awareness: Ensuring that all personnel involved in the design, development, and maintenance of digital services are trained in best practices for privacy and security.

## 5.3 Digital Public Infrastructure Assessment

The digital transformation of a public administration organisation can significantly benefit from reusable national digital infrastructure components. For instance, all self-service portals nationwide should identify users and verify their authority to perform specific roles. This means that identification and authorisation services should be established once and utilised by all self-service portals. Numerous other components or building blocks exist that any organisation building a digital services delivery platform should reuse.

Realistic understanding of status of national digital infrastructure is important input for building digital transformation roadmap of an organisation.&#x20;

National Digital Infrastructure Assessment should provide information about following aspects:

* What are approved principles and policies, to which organisation should adhere?
* What is national digital transformation governance framework?
* What is national digital transformation legal framework?
* How extensively does the national legal framework incorporate human rights in the digital era and SDG?
* What is national digital access infrastructure status?
* What is national digital data management infrastructure status?
* What is national interoperability infrastructure status?
* What is national digital identity infrastructure status?
* What kind architectural building blocks are readily available? See list of building blocks in the Annex 1.

GovStack has a tool for quick assessment of those aspects of the National Digital Infrastructure Assessment.

## 5.4 Organisational Assessment & Roadmap

In section 5.1, we have described five organisation maturity levels related to the set of processes and capabilities available in the organisation to support digital transformation.&#x20;

Before one starts developing a roadmap for digital transformation, we recommend assessing capabilities to understand the possible level of complexity of the project and what can be tackled by the organisation.

Conducting an organisational maturity assessment to define a public administration's readiness for digital transformation involves evaluating various dimensions of the organisation's operations, culture, technology infrastructure, and capabilities. This process helps to identify the current state of digital maturity, pinpoint areas for improvement, and guide strategic planning for digital transformation.&#x20;

Here’s a structured approach to conducting such an assessment.

### 1. Define Assessment Criteria and Dimensions

Start by defining the criteria and dimensions critical for digital transformation in your public administration context. We recommend using the dimensions, which are described in section 4:

* Management & Architecture
* Digital service delivery
* Data-driven decisions
* Digital co-creation

### 2. Develop Assessment Tools

Create or adapt assessment tools that can accurately measure the organisation’s status across the defined dimensions. Tools might include:

* Surveys and Questionnaires: To gather input from staff at all levels on their perceptions of digital maturity, challenges, and opportunities.
* Interviews and Focus Groups: To collect qualitative insights from key stakeholders, including leadership, IT staff, and end-users of digital services.
* Document Review: To assess existing strategies, policies, and plans related to digital transformation.
* Technology Audits: To evaluate the current IT infrastructure, software applications, and data management practices.

We recommend using the GovStack assessment tool, which already has a predefined set of questions and assessment methodology.

### 3. Conduct the Assessment

Implement the assessment tools across the organisation, ensuring broad and representative participation. Collect data systematically and ensure confidentiality where necessary to encourage honest and constructive feedback.

### 4. Analyse the Results

Compile and analyse the data to identify strengths, weaknesses, opportunities, and threats related to digital transformation. Use the findings to score the organisation’s maturity level for each dimension.

### 5. Develop Recommendations

Based on the analysis, develop specific, actionable recommendations for each dimension to move the organisation towards higher levels of digital maturity. Recommendations should be prioritised based on their impact on service delivery, operational efficiency, and strategic goals.

We recommend using:

1. Reference models from section 4.6 to see the potential architecture needed for your organisation.
2. The organisation maturity model is in section 5.1 to plan organisational capacity development.
3. Principles from section 5.2 to plan for target capabilities.
4. Outcomes from digital infrastructure assessment as per section 5.3.

### 6. Create an Action Plan

Translate recommendations into a comprehensive action plan that outlines initiatives, responsible parties, timelines, required resources, and performance metrics. The plan should be aligned with the organisation's overall strategic objectives and include short-term wins and long-term strategies.

### 7. Implement, Monitor, and Review

Begin implementing the action plan, monitoring progress regularly against the established metrics. Maintaining flexibility to adjust strategies based on emerging trends, technological advances, and stakeholder feedback is essential.

### 8. Continuous Improvement

Digital transformation is an ongoing process. Regularly revisit the maturity assessment, perhaps annually, to reflect on progress, reassess maturity levels, and identify new areas for improvement.

## 5.6 Sourcing Strategy

The optimal sourcing strategy for a digital transformation initiative in a public administration organisation balances cost, quality, innovation, risk management, and alignment with strategic goals. It involves determining the best mix of in-house capabilities and external services (such as cloud services, software providers, and consulting firms) to achieve the digital transformation objectives.&#x20;

The strategy should consider immediate needs, long-term sustainability, and adaptability to change. The following is a non-exhaustive list of recommended considerations.

1. Internal Capabilities: To achieve digital transformation goals, you must assess internal capabilities and needs. This means evaluating the current IT infrastructure, software solutions, and staff skills, and identifying gaps and strengths. Additionally, you must define future requirements, such as needed capabilities, technologies, and services, to create a roadmap for implementation.
2. Define Sourcing Objectives:
   1. The sourcing strategy should aim to improve service delivery, increase efficiency, or enhance cybersecurity.
   2. The sourcing strategy should aim for a cost-effective mix of sourcing options without compromising quality or strategic objectives.
   3. The strategy should be flexible and scalable. It should allow the organization to adjust solutions based on demand and adapt to emerging technologies.&#x20;
3. Evaluate Sourcing Options: When considering the development of software and change management, there are different approaches that can be taken:

   1. Examine what can realistically be created and maintained by internal teams based on their skills and workload.&#x20;
   2. If there are capabilities that are not available in-house, consider outsourcing options such as software development, cloud services, data analytics, or cybersecurity.&#x20;
   3. Explore the possibility of strategic partnerships with technology firms, government agencies, academic institutions, or NGOs (for example, GovStack) to leverage their expertise and resources.&#x20;

   Typically, a combination of in-house development, outsourcing, and partnerships provides the most flexibility and efficiency.
4. To manage risks associated with outsourcing, develop a Risk Management Framework. Identify potential risks and develop strategies to mitigate them. Implement governance and performance monitoring by setting up clear structures to manage relationships with providers and monitor their performance against agreed-upon metrics and standards.
5. Get all stakeholders to support the sourcing strategy. Use change management to manage concerns and ensure a smooth transition.
6. The sourcing strategy should be regularly reviewed and adapted to keep up with technological advancements and organisational goals.

## 5.7 Recommended Roadmap

### 5.7.1 Overview

If a country is in the initial phase of digital transformation and there is a will to follow the GovStack approach, then the logic for sequencing steps would be as follows:

<figure><img src="https://4055358096-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FpqnbDhX09tb5z7q4AWcQ%2Fuploads%2FXwEGuirX4IzhOsIWCgW6%2FScreenshot%202024-05-29%20020710.png?alt=media&amp;token=5a3db750-b97c-4973-85f1-0838c7a693a6" alt=""><figcaption><p>Figure 22 - Suggested phasing for implementation of BBs</p></figcaption></figure>

All components on this diagram are explained in section 4.6 above. With different colour we highlight recommended phases of the implementation:

* **1st phase** – Inception with focus on introduction to GS methodology and planning.
* **2nd phase** will focus on identification of High Priority use cases with subsequent rapid prototyping and fast-track implementation to show the value of BB-based development.
* **3rd phase** should start with first wave of industrial digitalisation of the highest priority functional areas in a country.
* **4th phase** should complete full digitalisation of all governmental services in a country.

General logic of the sequencing of activities is following:

* There is always should be visible for citizens and business positive impact.
* All mandatory internal prerequisites should be in place before any governmental service can be introduced to external customers to mitigate risks. &#x20;

Below is the description of the suggested high-level roadmap in terms of activities and outcomes.

### 5.7.2 Inception Phase

The Inception Phase activities and impact can be depicted in the following way:

<figure><img src="https://4055358096-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FpqnbDhX09tb5z7q4AWcQ%2Fuploads%2FNHsQLWjtEkk2bHV45v0C%2Fimage22.png?alt=media&amp;token=f3f89ed2-47c0-49e0-95d6-e64f2d4341ee" alt=""><figcaption><p>Figure 23 - First Phase activities &#x26; value (Source: Aare Lapõnin)</p></figcaption></figure>

#### Activities

* Activity 1.1: In the initial phase of digital transformation planning, the country's central IT organisation should objectively assess national digital capabilities. This will provide a basis for realistic change planning.  Based on the assessment outcome, the legal and governance framework should be adjusted. Create a centralised Change Management team to monitor the progress of the implementation of the GS approach.
* Activity 1.2: It is crucial to promote the use of BB-based approach for automation among a wide range of government officials. GovStack provides Deep Dive sessions for this purpose, which allow senior staff from the country's MDAs to gain first-hand experience of digital transformation in digitised countries. During these sessions, it is essential to select high-priority use cases that can be quickly implemented using the GovStack approach to demonstrate its validity to country officials and the public.
* Activity 1.3: It is crucial that a country's Ministries, Departments, and Agencies (MDAs) are not left to struggle with data centres, servers, networks, and related technologies. The recommended approach is for the country's central IT organisation to establish a governmental cloud that can seamlessly host all solutions from all MDAs.
* Activity 1.4: The Identity, Payment, and No-code/Low-code Development building blocks should be implemented to support subsequent rapid high-priority use cases implementation.

#### Building Blocks

During the inception phase following BBs should be adopted:

* Identity BB – it enables personalised and legally binding transactions.
* Payment BB – often transaction is associated with a fee; it should be possible pay it in online, that will enable fully digital transactions.
* No-code/Low-code Development – this will enable rapid prototyping and fast-track delivery of production-ready solutions. As far as GovStack highest priority is really working service as soon as possible, this component is the highest priority.

#### Value & Impact

For Citizens & Businesses:

* Enabling of cashless, fully online remote service delivery &#x20;

For Government:

* Acquiring Ground Floor capabilities, i.e. understanding of digital initiatives life-cycle, essential risk management, sourcing skills&#x20;
* Basic understanding of GS Approach

### 5.7.3 High-priority Use Case Implementation

The High Priority Use Cases (HPUC) Phase activities and impact can be depicted in the following way:

<figure><img src="https://4055358096-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FpqnbDhX09tb5z7q4AWcQ%2Fuploads%2FPE7tDlKXytQSVSq7LxCD%2Fimage23.png?alt=media&amp;token=23dd29e4-44ea-429b-9b0d-57943f5c2f3b" alt=""><figcaption><p>Figure 24 - Second Phase activities &#x26; value  (Source: Aare Lapõnin)</p></figcaption></figure>

Activities

* Activity 2.1: If the country has not yet adopted a consolidated portal for citizens and businesses, the MyGov component should be implemented as a front-end for the high-priority use cases (HPUC).&#x20;
* Activity 2.2: The implementation of HPUCs should begin with the rapid prototyping of the overall solution, followed by the immediate engagement of a local system integrator, who can implement and roll out the target solution in just a few months.
* Activity 2.3: Besides implementing HPUCs, detailed GovStack methodology training should be done for all MDAs nationwide to ensure widespread awareness.

#### Building Blocks

During the inception phase, the following BBs should be adopted:

* The initial version of MyGov environment as a One-Stop Shop for individuals and businesses.
* To support the fast-track implementation, most infrastructural BBs should be implemented, i.e., at least an Information Mediator (IM), Registration, GIS, Workflow, Messaging, QR Code, E-signature, Adapters, and Consent should be adopted.

#### Value & Impact

For Citizens:

* There is s a One-Stop Shop for all digital transactions with the Government.
* Access to end-to-end digital experience.

For Businesses:

* Primary business life-cycle services are end-to-end digitalised and convenient.
* Regulatory information is accessible and trustworthy.

For Government:

* Acquiring 1st Level of capabilities, i.e., data can be trusted, and solid risk management is in place.
* There is first hands-on experience of fast-track delivery using BBs.

### 5.7.4 Initial Transformation

The Initial Transformation Phase activities and impact can be depicted in the following way:

<br>

<figure><img src="https://4055358096-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FpqnbDhX09tb5z7q4AWcQ%2Fuploads%2FPOaKdCw27qCOF4Zkn9TV%2Fimage24.png?alt=media&amp;token=67b9834e-0f90-4d7f-b0c4-d8f1e93f3f38" alt=""><figcaption><p>Figure 25 - Third Phase activities &#x26; value  (Source: Aare Lapõnin)</p></figcaption></figure>

#### Activities

GovStack approach enables the industrialisation of the country’s public sector digital transformation. First two phases prepared required prerequisites as initial awareness and internal organisational dynamic capabilities. Now the country can select priority functional areas of public administration and transform it.&#x20;

It is essential to synchronise activities in this phase with the overall legal and governance framework adjustments to ensure that the legislation supports all planned changes and that institutional changes are enabled.

* Activity 3.1: Implementation of a modern digital front-end, including a Digital Wallet and mobile app for all transactions with the public sector (MyGov), should be done.
* Activity 3.2: All main state registries (as indicated in Annex 3) should be digitalised.
* Activity 3.3: Automation for all MDAs in the selected areas should be accomplished.

The duration of this phase should be time-boxed and should not exceed 2-3 years.

#### Building Blocks

During this phase all GovStack infrastructural BBs should be adopted and used for solutions.

#### Value & Impact

For Citizens:

* All services are end-to-end, digitalised, and convenient.
* There is remarkably less bureaucracy.

For Businesses:

* All services are end-to-end, digitalised, and convenient.
* There is remarkably less bureaucracy.

For Government:

* Acquiring 2nd Level of capabilities, i.e., architecture is managed, and digital service delivery is based on the ITIL framework.
* There is a capacity for fast-track delivery in priority areas.

### 5.7.5 Mass-scale Transformation.

The country acquired enough capabilities during the previous 3 phases to leap-frog to the Digital Era.

At that point, the legal and governance framework should be fully adjusted. All horizontal systems should be in place to support smooth transformation.

The Mass-scaled Transformation Phase activities and impact can be depicted in the following way:

<figure><img src="https://4055358096-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FpqnbDhX09tb5z7q4AWcQ%2Fuploads%2FOV0XsF2p2bAh7cvHPn2V%2Fimage25.png?alt=media&amp;token=a85f2f9e-53f9-42d9-a069-b62c1d67c637" alt=""><figcaption><p>Figure 25 - Fourth Phase activities &#x26; value  (Source: Aare Lapõnin)</p></figcaption></figure>

Activities

* Activity 4.1: A Comprehensive National Digital Transformation Roadmap for the digital transformation of the whole public sector should be prepared.
* Activity 4.2: Complete digitalisation of public sector should be implemented using fast-track delivery factory.

#### Building Blocks

During this phase all GovStack BBs should be adopted and used for solutions.

#### Value & Impact

For Citizens:

* Social and health care services are widely available.
* Education services are equally available across the country

For Businesses:

* There are new jobs and export opportunities in the IT industry.
* Banking sector efficiency is very high.
* Telco sales are growing.
* Agriculture efficiency is growing fast.

For Government:

* Acquiring 3rd Level of capabilities, i.e., data-driven decisions and digital co-creation.
* All governmental solutions are open-sourced.
* Very high efficiency of operations


# 6. Annex 1 – Digital Infrastructure

## A1.1 Reference Model – National Level

In the reference model for the national level of digital governance ecosystem we present a list of main components, which should be presented in the target architecture.

### A1.1.1 Foundation

1\. Digital Forms of Law and Compliance Systems consist of provisions and norms that regulate digital transactions and promote the implementation and protection of human rights in the digital era within digital government systems. These rights encompass a wide range of digital freedoms and responsibilities, including:&#x20;

* The right to access the Internet, digital identification tools, digital asset storage, and other digital technologies; the protection of life and personal, biometric, and biological data.&#x20;
* The right to participate in the management of societal affairs, whether at the state level or potentially within future systems of global governance, through digital technological platforms.&#x20;
* Rights related to the ownership, use, and management of digital property and assets, as well as the conduct of digital economic activities such as transactions and digital deals, and access to systems of digital security.&#x20;
* Access to social services provided through digital technological platforms.&#x20;
* Rights to access cultural values and educational resources digitally. These facets underscore the broad scope of human rights in the digital era, highlighting their crucial role in contemporary and future societal structures.

2\. E-Governance Frameworks: Strategies and policies that guide the implementation and evolution of digital services.

### A1.1.2 Access Pillar

1\. High-Speed Connectivity: Reliable and fast internet access is the backbone of digital services, ensuring that all citizens can connect to government platforms.

2\. Accessibility Features: Ensuring that digital services are usable by all citizens, including those with disabilities.

3\. Cybersecurity Framework: Robust security protocols and infrastructure to protect sensitive data and ensure privacy and trust in digital transactions.

### A1.1.3 Data Pillar

1\. Data Centres and Cloud Services: Efficient and secure data storage and processing capabilities that allow for scalability and resilience of digital services.

2\. Monitoring and Analytics Tools: Systems to analyse service delivery and usage patterns, leading to informed decision-making and service improvements.

3\. Data protection institutional infrastructure.

### A1.1.4 Interoperability Pillar

Interoperable Platform: An ecosystem that facilitates data exchange and integrated services across different government departments. The following components should be part of the ecosystem.

1. API Management Tools: These tools are used to create, publish, and manage APIs, which are sets of protocols for building and interacting with software applications. They help in securing, scaling, and monitoring API traffic.
2. Identity and Access Management (IAM): This component ensures that the right organisations can access the right resources at the right times and for the right reasons.
3. Data Format and Transformation Services: These services convert data from one format to another so that different systems can understand and use the information without manual intervention
4. Registry/Repository Services: Central directories where metadata, services, and components are catalogued and can be queried or invoked. They help in service discovery and management.
5. Security Services: This includes encryption, digital signatures, secure data transmission protocols, and other cybersecurity measures to ensure data integrity and confidentiality.
6. Monitoring and Logging Services: These services track the health and usage of the interoperability platform, recording data on transactions, performance, and potential security incidents.
7. Business Rules Management: A system for defining, deploying, monitoring, and maintaining the complex decision logic used by system processes.
8. Workflow and Business Process Management (BPM): Tools that allow for the design, execution, and automation of business processes involving multiple interconnected systems.
9. Master Data Management (MDM): Software that ensures the uniformity, accuracy, stewardship, semantic consistency, and accountability of the enterprise's official shared master data assets.
10. Service Orchestration: The middleware that coordinates and combines services, resources, and data into complex business processes across the interoperability platform.

### A1.1.5 Identity Pillar

Digital Identity and Authentication: Secure and accessible means for citizens to verify their identities online to access various services.

A national identity ecosystem is a framework that enables the trusted establishment, use, and interoperability of digital identities. It should have following components.

1. Identity Management Systems (IdMS): These systems manage the lifecycle of digital identities, including creation, maintenance, and deletion, i.e., registration, de-registration, identity proofing, and credential management.
2. Authentication Services: These services verify users' identities when they log in or access services. They may support various mechanisms such as PKI-based authentication, biometrics, one-time passwords (OTPs), security tokens, and multi-factor authentication (MFA), etc.
3. Authorization Services: Once authentication is verified, these services determine what resources or services the user can access based on their identity, roles, and policies.
4. Credential Management: This involves the issuance, renewal, revocation, and management of digital credentials that assert identity attributes, such as digital certificates.
5. Public Key Infrastructure (PKI): PKI is a framework that creates, manages, distributes, uses, stores, and revokes digital certificates and manages public-key encryption, enabling secure electronic transfer of information.
6. Federated Identity Management: This enables users to access multiple applications and services with one set of credentials. It includes Identity Federation Hub, a centralised service connecting various identity providers and service providers to facilitate cross-domain authentication and authorisation.
7. Single Sign-On (SSO): A user authentication process that allows a user to access multiple applications with one set of login credentials.
8. Civil Registry Integration: Software components that integrate with civil registry databases to ensure that identity data is consistent with official government records. This also includes biometric systems integration, which uses physical characteristics (fingerprints, facial recognition, iris scans, etc.) to identify individuals uniquely.
9. User Self-Service Interfaces that allow users to manage their profiles, reset passwords, and update personal information.
10. Audit and Compliance Reporting Tools: Systems to monitor and report on identity-related activities, ensuring compliance with legal and regulatory requirements.
11. Privacy Management Tools: Software to manage and enforce policies related to the privacy of personal identity information.
12. Consent Management Platforms: Systems that manage user consent for data sharing and processing, which are vital for complying with privacy laws and regulations.

### A1.2 Reference Model – Organisational Level

#### A1.2.1 Taxonomy Overview

The COFOG Governmental Functions classification identifies 10 government functions, which are further divided into 69 functions. These can be carried out by hundreds or even thousands of public administration organizations at the federal, state, and local municipality levels. Each organization may have multiple performance outcome areas requiring digital transformation.

However, upon detailed analysis, it was found that the differences in those areas primarily lie in the data, whereas the required automation components are not that dissimilar.

#### **Public Sector Organisational Taxonomy**

Currently, we see that public sector intervention into the economy and society can be viewed as following main types of organisational architectures:

<table data-header-hidden><thead><tr><th width="107"></th><th></th><th></th></tr></thead><tbody><tr><td>ID</td><td>Type</td><td>Touchpoints with customers</td></tr><tr><td>1.</td><td>Policy development unit is making analysis, develop policies and monitor policies efficiency. Typical example of such a unit is a line ministry.</td><td><ul><li>Informal communication with stakeholders in society</li><li>Formal communication to prepare legislation.</li></ul><p><br></p></td></tr><tr><td>2. </td><td>Regulatory agency is responsible for specific area in society, which requires regulations and policies enforcement. For example, data protection authority, business registration, licensing etc.</td><td><ul><li>Formal communication with applicants and decision-making process regarding licenses &#x26; permissions</li><li>For one individual or company there are not many interactions: issuing license/permission, suspension and/or ending of license/permission.</li><li>Informal conflict resolution</li></ul><p><br></p></td></tr><tr><td>3.</td><td>Service delivery authority, which is not only involved in regulatory activities but also applies specialised methods to ensure enforcement of legal regulations. Examples: Police Department, Tax Department, Customs, Treasury, etc.</td><td><ul><li>Formal onboarding of customers</li><li>Most of the time recurrent service delivery</li><li>Solid training process to build awareness amongst external customers and skills for employees</li></ul></td></tr></tbody></table>

#### **Ecosystem**

In addition to the above three main types of public sector organisation there are several important elements in the public administration ecosystem:

* State registries. A state register is an official record-keeping system maintained by a government entity in which vital information is stored and managed. This can include records on individuals, such as births, marriages, and deaths; legal documents like property deeds and business licenses; or more specific registers like those for motor vehicles or professional credentials. State registers serve as a reliable source of legal documentation and are used to ensure public administration processes are accurate and effective.
* Government internal organisations, which are providing support services to other government organisations. We call systems in such organisations as Horizontal Systems.&#x20;

PAERA facilitates an outward-looking approach to the public sector digital transformation, which puts the citizen’s ability to utilise digital services is in the centre of our attention. Hereunder PAERA introduces the concept of Natural Digital Environment and Sectoral Ecosystems.

The following describes the architectural building blocks that make up those architectures.

### A1.2.2 - 1st type: Policy Development Unit

#### **Business Model**

The Policy Development Unit (PDU) is the most basic bureaucratic organisational unit. The digital platform in this unit should support all main bureaucratic organisational activities. Digital support for such a basic unit should have at least two areas.&#x20;

1. Direct support for specific function policy development and
2. Generic organisation management service (for example, HR, finance, etc.)

Examples: ministries, chancelleries of constitutional institutions (like the President, Prime Minister, etc.).

For the PDU type of organisation, a generalised business model can be described in the following way:

<figure><img src="https://4055358096-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FpqnbDhX09tb5z7q4AWcQ%2Fuploads%2FdEFjkiaTmU5Mn5Xlh8Oq%2Fimage26.jpg?alt=media&amp;token=0cd20ffd-c685-4d09-8914-abb78bd5178f" alt=""><figcaption><p>Figure 11 - PDU Business Model Canvas</p></figcaption></figure>

The following are details for the business model for PDU:

<table data-header-hidden><thead><tr><th width="175"></th><th width="260"></th><th></th></tr></thead><tbody><tr><td>Pillar</td><td>Component</td><td>Description</td></tr><tr><td>Product</td><td>Value proposition</td><td><p>1. Policy Development</p><ul><li>Responsible for specific functional area, i.e., defence, health, social care etc.</li><li>Develop and maintain legislation to regulate the area of responsibility.</li><li>Communicate with stakeholders explaining policies and identifying issues and needs.</li></ul><p><br></p><p>2. Supervision of policy implementation</p><ul><li>Set up KPI-s and needed reporting.</li><li>Staffing of managers</li></ul><p><br></p><p>3. Research</p><p><br><br></p></td></tr><tr><td>Customer interface</td><td>Customer Segment</td><td><ul><li>Population demographic groups</li><li>Economic agents</li><li>Non-profit organisations</li><li>Communities of interests and locations</li><li>Foreign investors</li><li>International organisations</li></ul><p><br></p></td></tr><tr><td></td><td><p></p><p><br>Communication</p></td><td><p></p><ul><li>n-person meetings with stakeholders</li><li>Media analysis</li><li>Insource of research from external professionals</li><li>Formal communication within the legislation development process with internal government stakeholders, i.e., other ministries, government, parliament etc.</li><li>Social media</li></ul></td></tr><tr><td></td><td><p>Customer Relationships</p><p><br></p></td><td><p></p><ul><li>Setup permanent relationships with industrial unions and NGO-s in the relevant functional area for economy or society</li><li>Setup close relations with media to be capable to build awareness campaigns for relevant society groups and economy agents.</li></ul></td></tr><tr><td>Infrastructure Management</td><td>Value Configuration</td><td><p>Group 1. Specific public administration capabilities:</p><ul><li>Policy development</li><li>Legislation development</li><li>Policy implementation monitoring</li><li>Processing of requests from stakeholders</li><li>Making decisions and delivering answers</li><li>Managed entities supervision</li><li>Coordination with EU and international stakeholders</li><li>Research</li></ul><p><br></p><p>Group 2. Policy development support activities:</p><ul><li>Documents management</li><li>Data gathering, data management and analytics.</li><li>Knowledge Management</li><li>Web Content Management</li><li>Process Management</li><li>Project Management </li><li>Teams Collaboration</li><li>Surveys Management</li><li>Engagement with stakeholders through social media</li></ul><p><br></p><p>Group 3. Generic organisation support capabilities:</p><ul><li>HR management, including structure management, job descriptions, hiring, etc.</li><li>Risk management</li><li>Budget, Finance, Procurement &#x26; Accounting</li><li>Strategic Management</li></ul><p><br></p></td></tr><tr><td></td><td><p></p><p><br>Staff and Resources</p></td><td><p></p><ul><li>Functional area expertise</li><li>Legal experts</li><li>Institutional building expertise</li></ul></td></tr><tr><td></td><td><p>Strategic Partners</p><p><br></p></td><td><p></p><ul><li>Parliament</li><li>Government</li><li>Ministries</li><li>Media</li><li>Industrial unions</li><li>Public</li></ul></td></tr><tr><td>Financial Aspects</td><td>Cost Structure</td><td><p>Main cost components:</p><ul><li>Staff salary</li><li>Office space</li><li>IT systems</li><li>Utilities</li></ul><p><br></p></td></tr><tr><td></td><td><p>Income Structure</p><p><br></p></td><td>Appropriate governmental-level Budget</td></tr></tbody></table>

#### **PDU Application Architecture Outline**

The following application architecture is needed to digitalise PDU activities:

<figure><img src="https://4055358096-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FpqnbDhX09tb5z7q4AWcQ%2Fuploads%2Fe5hKwghUSfLsIqkLkQnK%2Fimage27.png?alt=media&amp;token=850cceab-9730-444d-a196-db76ffaa98be" alt=""><figcaption><p>Figure 12 - Reference Application Architecture for PDU Activities</p></figcaption></figure>

Here, we have three main areas of application architecture:

* **Channels** zone – implements secure omni-channel access capabilities for all external customers and stakeholders. This should be well standardised and use standard national digital infrastructure building blocks for security services like authentication, authorisation, digital signature, etc.
* **Infrastructure** – standard component to enable modern data-driven processing, including data collection from many different sources, data consolidation into analytical data sets, visualisation, etc. This zone should be fully standardised and ideally part of a governmental cloud.
* Public Administration **Core Services** automation support zone – implements application software components to support the activities of the PDU staff. Following is a description of those components for the core services support..

The Policy Development Unit (a ministry) is primarily responsible for formulating, analysing, and implementing policies in different functional areas. Such a unit requires a suite of software components that facilitate research, collaboration, data analysis, and stakeholder engagement.

1. Document Management Systems (DMS): These systems are crucial for creating, storing, managing, and tracking documents and revisions. A DMS helps maintain an organized repository of policy drafts, official documents, legal texts, and related materials, ensuring that the latest versions are always accessible.
2. Collaboration and Communication Tools: Software that enables effective communication and collaboration among team members, stakeholders, and other departments is essential. This includes email, instant messaging apps, video conferencing tools, and platforms that support collaborative document editing and sharing.
3. Data Analysis and Visualization Tools: Policy development relies heavily on data to inform decisions. Tools that can analyse large datasets, perform statistical analysis, and visualise data trends are critical. These tools help understand complex information, identify patterns, and present data in an easily digestible format for decision-makers.
4. Project Management Software: This software helps plan, execute, and monitor policy development projects. It can track progress, manage tasks, allocate resources, and keep timelines, ensuring policy initiatives progress as planned.
5. Stakeholder Engagement Platforms: Engaging with stakeholders is a key part of policy development. Platforms facilitating surveys, feedback collection, public consultations, and forums can help gather insights, concerns, and suggestions from the public, industry experts, and other relevant parties.
6. Content Management Systems (CMS): For policy units that publish reports, guidelines, or any public-facing documents, a CMS is vital. It allows for the easy creation, management, and publication of content on websites or intranets, ensuring that information is accessible to relevant audiences.
7. Legislative Tracking Software: This software helps monitor legislation and regulatory changes that could impact policy areas. It can track bills, regulations, and other legislative documents across various stages, providing alerts and updates relevant to the unit’s focus areas. Also, it integrates the PDU with national legislation drafting activities.
8. Research and Reference Management Software: Tools that assist in organising research materials, references, and bibliographies are essential for policy development. They facilitate the management of digital libraries, streamline the citation process, and support literature reviews.
9. Case Management: A case management system can be adapted to manage relationships and interactions with stakeholders, experts, and other external parties involved in policy consultation and feedback processes. Also, it provides visibility over performance and service delivery quality, providing capabilities to manage SLAs and KPIs.
10. Secure File Sharing and Storage Solutions: Given the sensitive nature of policy work, secure platforms for storing and sharing documents are necessary. These solutions protect sensitive information through encryption, access controls, and audit trails.&#x20;
11. Risk Management and Compliance Software: This software helps identify, assess, and mitigate risks associated with policy proposals. It also ensures policies comply with existing laws and regulations, minimising legal and operational risks.
12. HR, Budget, and Accounting: all public administration organisations have standard corporate services implementation for budgeting operations and accounting of personnel, salary and resources.

By integrating these software components, a Policy Development Unit can enhance its efficiency, effectiveness, and responsiveness in policymaking.

These tools support the complex tasks of analysing data, managing projects, engaging with stakeholders, and ultimately developing policies that are well-informed, timely, and relevant.

**NOTE**: This set of components is required in all types of public administration organisation. We will refer to this set of building blocks as **Public Administration Organisation Core** **Components** (PAO-CC).

### A1.2.3 - 2nd type: Regulatory Agency

#### **Business Model**

The Regulatory Agency (RA) is responsible for the implementation of regulatory policies in some functional areas. They are accountable to PDU, which is in charge for the policy development in their functional area.

For the RA type of organisation, a generalised business model can be described in the following way:

<figure><img src="https://4055358096-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FpqnbDhX09tb5z7q4AWcQ%2Fuploads%2FJeEj0KXlnkXradsOzB8G%2Fimage28.jpg?alt=media&amp;token=63dcbf04-3e0b-4751-8be4-dec7ed8222e8" alt=""><figcaption><p>Figure 13 - RA business model canvas</p></figcaption></figure>

Examples: Financial Service Authority, Commercial Register, Trade Licenses, Data Protection Authority, etc.

The following are details for the business model for RA:

<br>

<table data-header-hidden><thead><tr><th width="138"></th><th width="280"></th><th></th></tr></thead><tbody><tr><td>Pillar</td><td>Component</td><td>Description</td></tr><tr><td>Product</td><td>Value proposition</td><td><p>1. Policy Implementation regarding specific regulated governance functional area</p><ul><li>Detailed requirements formulation.</li><li>Design of application forms and procedures for application of license/permission.</li><li>Review and assessment of an application for license/permission.</li><li>Fee collection.</li><li>Issuing of licenses/permissions.</li><li>Register of license/permission management.</li></ul><p><br></p><p>2. Supervision of licensees</p><ul><li>Set up required regular reporting framework.</li><li>Collection of regular reports</li><li>Risk management</li><li>Intervention in case of high risk</li><li>Resolution of issues with non-compliant licensees</li></ul><p><br></p><p>3. Awareness campaigns to stakeholders and communities</p><p><br></p></td></tr><tr><td>Customer interface</td><td>Customer Segment</td><td><ul><li>Economic agents</li><li>Communities of interests and locations</li><li>Local &#x26; Foreign investors</li></ul><p><br></p></td></tr><tr><td></td><td>Communication</td><td><p></p><ul><li>Formal communication with Policy Development body to whom RA is accountable.</li><li>Formal communication with other relevant government stakeholders, i.e., other MDA-s, government, parliament etc.</li><li>Formal and informal communication with applicants and licensed agents</li><li>Awareness campaigns in traditional and social media</li><li>In-person training events</li><li>Training content delivery in digital channels</li><li>In-person meetings with stakeholders</li></ul></td></tr><tr><td></td><td><p>Customer Relationships</p><p><br></p></td><td><ul><li>Setup permanent relationships with industrial unions in the relevant functional area of economy or society</li><li>Setup close relations with media to be capable to build awareness campaigns for relevant society groups and economy agents.</li></ul></td></tr><tr><td>Infrastructure Management</td><td>Value Configuration</td><td><p>RA must have all Group 2 and 3 capabilities, which are listed for PDU in the section 4.2.1. </p><p><br></p><p>Group 4. In additional to that, there should be following specific public administration capabilities:</p><ul><li>Compliance management framework design</li><li>Digital service delivery</li><li>Regulated area risk management</li><li>Operational risk management</li><li>Business continuity management</li><li>Internal staff training regarding service delivery.</li><li>Design and delivery of training content to licensees and potential applicants.</li><li>Reporting to appropriate PDU</li></ul><p><br></p></td></tr><tr><td></td><td><p>Staff and Resources</p><p><br></p></td><td><p></p><ul><li>Functional area expertise</li><li>Risk management</li><li>Compliance management</li></ul></td></tr><tr><td></td><td><p>Strategic Partners</p><p><br></p></td><td><p></p><ul><li>Responsible PDU</li><li>Related (horizontally) MDA-s</li><li>Media</li><li>Industrial unions</li><li>Public</li></ul></td></tr><tr><td>Financial Aspects</td><td>Cost Structure</td><td><p>Main cost components:</p><ul><li>Staff salary</li><li>Office space</li><li>IT systems management</li><li>Utilities</li></ul><p><br></p></td></tr><tr><td></td><td><p>Income Structure</p><p><br></p></td><td>Appropriate level government Budget</td></tr></tbody></table>

#### RA Application Architecture Outline

The following application architecture is needed to digitalise regulatory agency (RA) activities:

<figure><img src="https://4055358096-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FpqnbDhX09tb5z7q4AWcQ%2Fuploads%2FBKMbR8B7IqY00p5GWhE8%2Fimage29.png?alt=media&amp;token=b5ba2c21-8fb0-4de3-8cf6-edc9bf385e35" alt=""><figcaption><p>Figure 14 - RA application architecture reference model</p></figcaption></figure>

It includes all components from the PDU model, i.e. Channel zone, Infrastructure zone and Public Administration Core Components (PAO-CC). In addition, there are BBs for digital service delivery.

**1. Forms & Procedures Design**

Implementing forms and procedures design in a public administration regulatory agency requires software that supports creating, managing, and optimising digital forms and workflows.&#x20;

The software should enable the organisation to design user-friendly forms, automate processes, and manage data efficiently:

* Intuitive Form Builder: A drag-and-drop interface that allows non-technical users to create and design forms quickly. This should include the ability to add various field types (e.g., text, dropdowns, checkboxes), validation rules, and conditional logic to show or hide fields based on user inputs.
* Workflow Design: Tools to define and automate business processes and workflows associated with forms.
* Integration Capabilities: Integrating with other systems and databases is crucial for automating data entry and retrieval, ensuring that form data can flow seamlessly between systems. This includes PAO-CC, such as Case Management, ERP, document management systems, and payment gateway.
* Data Validation and Verification: Features to validate form inputs in real-time to ensure data accuracy and completeness. This might include checking for valid email addresses and required fields and integrating with external databases for verification.
* Customisable Templates: A library of pre-built form templates that can be customized to suit different services and processes.
* Mobile Responsiveness: Forms should be accessible and easy to complete on any device, including smartphones and tablets.
* Multilingual Support: Features to create and manage forms in multiple languages, catering to a diverse population and ensuring inclusivity in service delivery.
* Feedback Mechanisms: Incorporating feedback forms or surveys to collect user feedback on the form-filling experience and the efficiency of the service delivery process.
* Version Control: Keeping track of changes made to forms and procedures over time, allowing for the rollback to previous versions if needed.

**2. Application Capturing & Processing**

Implementing application forms capturing and processing workflows in a regulatory agency involves managing the entire lifecycle of applications, from submission to final decision.&#x20;

The software supporting these workflows must facilitate efficient, accurate, and user-friendly processes both for the applicants and the administrative staff:

* Automated Workflow Management: The ability to define, automate, and manage workflows associated with the application process, i.e., routing applications for review and approval, assigning tasks to specific staff members, setting deadlines, and automating notifications and reminders.
* Electronic Signatures and Document Uploads: Features that allow applicants to sign documents and securely upload necessary supporting documents electronically.
* Role-Based Access Control: The ability to define access levels for different users, ensuring that staff and applicants can only access information and functionalities relevant to their role in the application process.
* Reporting and Analytics: Tools to track and analyse application data, monitor workflow efficiency, and generate reports, including support for identification bottlenecks, tracking processing times, and improving service delivery.
* Communication Tools: Integrated communication tools for sending automated emails or messages to applicants regarding the status of their application, requests for additional information, and final decisions.
* Scalability: The software should be scalable to handle varying volumes of applications and adaptable to process changes or the introduction of new services.

**3. Payment & Refund processing**

Implementing payment and refund processing workflows involves handling financial transactions securely and complying with regulations.&#x20;

The software supporting these workflows must facilitate efficient and accurate processing, provide a good user experience, and ensure the highest levels of security and compliance:

* Secure Payment Gateway Integration: Integration with secure and reliable payment gateways to process various forms of payment, including credit/debit cards, bank transfers, mobile money and digital wallets. The software should support multiple payment methods to accommodate the preferences of all users.
* PCI DSS Compliance: Adherence to the Payment Card Industry Data Security Standard (PCI DSS) and other relevant security standards to protect cardholder data during transactions.
* Flexible Refund Processing: The ability to process refunds efficiently, allowing for full or partial refunds directly through the platform. This should include automated workflows for approving and processing refund requests.
* Real-Time Transaction Processing: Capability to process payments and refunds in real-time, providing immediate feedback to users about the status of their transactions.
* Fraud Detection and Prevention: Security features to detect and prevent fraudulent transactions, including encryption, secure authentication, risk-based analysis, and monitoring of suspicious activities.
* Multi-Currency Support: The ability to process payments in multiple currencies is essential for organisations serving an international audience (e.g., foreign investors).
* Financial Reporting and Analytics: Tools for generating detailed financial reports and analytics, providing insights into payment volumes, refund rates, revenue, and other key financial metrics.
* Automated Receipt Generation: Automatic generation and sending of receipts for payments and refunds to users via email or available for download, providing proof of transactions.
* Audit Trails: Comprehensive logging of all transactions, including payments and refunds, to create an audit trail for compliance, dispute resolution, and financial auditing purposes.
* Integration with Financial System: Seamless integration with the organisation's financial system to automate the reconciliation process and ensure accurate financial records.
* Customer Support Tools: Integration with customer support tools to assist users with payment-related inquiries and issues, including refunds, transaction disputes, and technical problems.

**4. Decision Management**

Implementing Decision Management workflows in a public administration regulatory authority requires support for making, recording, and communicating decisions related to regulations, compliance, and enforcement actions.&#x20;

This requires software that supports complex decision-making processes and ensures transparency. POA-CC components support such functionality. It only requires the configuration of specific workflows and document templates.&#x20;

The following specific aspects, however, should be added:

* Notification and Communication Systems: Automated notifications and communication features to inform relevant parties about decisions, updates, or required actions. This could include email alerts, SMS notifications, or in-platform messages.
* Regulatory Compliance Management: Tools to ensure all decisions comply with applicable laws, regulations, and standards. This may include checklists, compliance tracking, and integration with legal databases.
* Integration with Public Access Portal: A portal for stakeholders and the public to access information on decisions, regulations, and compliance requirements.
* Customisable Dashboards: These provide an overview of decision-making activities, status updates, and key performance indicators (KPIs).
* 14\. Decision Modelling and Analytics: Tools for modelling decision processes and analysing decision outcomes. This can help identify patterns, predict impacts, and optimise decision-making strategies.

**5. Inspections Management**

Implementing inspection management workflows in a regulatory authority involves coordinating and tracking a wide range of activities, from scheduling inspections to recording outcomes and enforcing compliance.

POA-CC components support such functionality. It only requires the configuration of specific workflows and document templates.&#x20;

The following specific aspects, however, should be added:

* Scheduling and Calendar Integration: Tools for scheduling inspections, including calendar integration that allows for easy assignment of inspectors and visibility into their schedules.&#x20;
* Mobile Access and Offline Capability: Mobile applications or web access enable inspectors to access and input data in the field, even without an internet connection. Once a connection is re-established, the data should sync with the central system.
* Checklist and Form Customization: The ability to create, customise, and update inspection checklists and forms. This should include support for various types of data entry, such as text, checkboxes, dropdown lists, and photo uploads.
* Geolocation Services: Geolocation services are integrated to help plan routes, verify inspection locations, and log the location of an inspection for accountability and efficiency.
* Compliance Tracking and Enforcement: Tools to track compliance status, record violations, and manage enforcement actions such as fines, warnings, or follow-up inspections.
* Communication Tools: Integrated communication tools to facilitate direct communication between inspectors, regulated entities, and other stakeholders.&#x20;

**6. Legal Affairs & Litigation**

Implementing Legal Affairs & Litigation workflows in a public administration regulatory authority involves managing various legal documents, cases, and processes efficiently and effectively.&#x20;

The software supporting these workflows must be capable of handling complex legal operations, ensuring compliance, and facilitating collaboration among legal teams, other departments, and external parties.

Mostly POA-CC components support such functionality. It requires the configuration of specific workflows and document templates. The following specific aspects, however, should be added:

* Calendar and Deadline Tracking: Integration with calendars to track important dates, deadlines, hearings, and meetings. Automated reminders can help ensure that no critical dates are missed.
* Legal Research Tools: Access to legal databases and research tools within the platform to support legal analysis, precedent research, and case preparation.
* Security and Compliance: High-level security features to protect sensitive legal information, including encryption, access controls, and compliance with relevant legal and regulatory standards.
* Litigation Support: Features that support litigation activities, including evidence management, discovery process management, and integration with court filing systems.
* Financial Management: Integration with financial systems for managing legal budgets, expenses, invoicing, and cost recovery.
* Knowledge Management: A centralized repository for storing and sharing legal knowledge, such as memos, legal opinions, and guidelines, to support decision-making and ensure consistency.
* E-Discovery and Evidence Management: Tools for managing the collection, processing, review, and production of electronic documents as part of the discovery process.
* Complaint and Dispute Resolution Management: Mechanisms to track and manage complaints, disputes, and non-litigation cases, including mediation and arbitration processes.

### A1.2.4 - 3rd type: Service Delivery Authority

#### Business Model

The Service Delivery Authority (SDA) is the most complex governmental organizational unit. The digital platform in this unit should support not only internal processes automation, but also intensive communication with external customers. Examples: Customs, Tax Authority, Police Department, etc.

Digital support for such a unit may have many areas, including the following:&#x20;

1. Support for strategic management and planning
2. Support for customer experience management and service delivery framework design
3. Core value chain automation systems, including G2B, G2C, and G2G integration with external customers.
4. Support for extensive data management
5. Generic organization management service (for example, HR, finance, etc.)

For the SDA type of organization, a generalized business model can be described in the following way:

<figure><img src="https://4055358096-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FpqnbDhX09tb5z7q4AWcQ%2Fuploads%2FkvREAXDVWfcR3Ao5PsCQ%2Fimage1.jpg?alt=media&amp;token=342efa5d-3e25-46e0-ba25-0f126d5df46d" alt=""><figcaption><p>Figure 15 - SDA business model canvas</p></figcaption></figure>

The following are details for the business model for RA:

<table data-header-hidden><thead><tr><th width="95"></th><th></th><th></th></tr></thead><tbody><tr><td>Pillar</td><td>Component</td><td>Description</td></tr><tr><td>Product</td><td>Value proposition</td><td><p>1. Policy Implementation regarding specific regulated governance functional area</p><ul><li>Detailed compliance requirements formulation.</li><li>Design of forms and procedures for policy requirements implementation in the regulated functional area.</li><li>Enforcement of requirements for agents in the regulated area.</li></ul><p>2. Supervision and enforcement of compliance in regulated area</p><ul><li>Regular data gathering</li><li>Risk management</li><li>Intervention in case of high risk</li><li>Resolution of issues with non-compliant licensees</li></ul><p><br></p><p>3. Awareness campaigns to external customers, stakeholders, and communities.</p><p><br></p><p>4. Gathering feedback from customers and stakeholders and adjusting the service delivery framework accordingly.</p><p><br></p></td></tr><tr><td>Customer interface</td><td>Customer Segment</td><td><ul><li>Economic agents</li><li>Communities of interests and locations</li><li>Local &#x26; Foreign investors</li></ul><p><br></p></td></tr><tr><td></td><td><p></p><p><br>Communication</p></td><td><p></p><ul><li>Formal communication with Policy Development body to whom SDA is accountable.</li><li>Formal communication with other relevant government stakeholders, i.e., other MDA-s, government, parliament etc.</li><li>Formal and informal communication with agents in regulated area</li><li>Awareness campaigns in traditional and social media</li><li>In-person training events</li><li>Training content delivery in digital channels</li><li>In-person meetings with stakeholders</li></ul></td></tr><tr><td></td><td><p></p><p>Customer Relationships<br></p></td><td><p></p><ul><li>Setup permanent relationships with industrial unions in the relevant functional area of economy or society</li><li>Setup close relations with media to be capable to build awareness campaigns for relevant society groups and economy agents.</li></ul></td></tr><tr><td>Infrastructure Management</td><td>Value Configuration</td><td><p>SDA must have all Group 2 and 3 capabilities, which are listed for PDU in the section 4.2.1. </p><p><br></p><p>Also, SDA must have Group 4 capabilities, which are listed for RA in the section 4.3.1. </p><p><br></p><p>Group 5. In additional to that, there should be following specific public administration capabilities:</p><ul><li>Performance management (for internal staff)</li><li>Service Management (SLA-based quality assurance for external customers)</li><li>Enterprise Architecture management </li><li>IT Planning and strategic management</li><li>IT Security management</li></ul><p><br><br></p></td></tr><tr><td></td><td><p></p><p>Staff and Resources<br></p></td><td><p></p><ul><li>Functional area expertise</li><li>Compliance management</li><li>Risk management</li><li>Business continuity management</li><li>Digital service delivery</li></ul></td></tr><tr><td></td><td><p></p><p><br>Strategic Partners</p></td><td><p></p><ul><li>Responsible PDU</li><li>Related (horizontally) MDA-s</li><li>Media</li><li>Industrial unions</li><li>IT provider</li><li>Customers’ IT development community</li><li>Public</li></ul></td></tr><tr><td>Financial Aspects</td><td>Cost Structure</td><td><p>Main cost components:</p><ul><li>Staff salary</li><li>Office space</li><li>IT systems management, including Digital Service management, EA management and Operational risk and business Continuity management.</li><li>Utilities</li></ul><p><br></p></td></tr><tr><td></td><td><p>Income Structure</p><p><br></p></td><td>Appropriate level of Government Budget</td></tr></tbody></table>

### SDA Application Architecture Outline

The following application architecture is needed to digitalise SDA activities:

<figure><img src="https://4055358096-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FpqnbDhX09tb5z7q4AWcQ%2Fuploads%2FWiCO4MXjViUyfPee7loh%2Fimage2.png?alt=media&amp;token=6f31a66a-cf29-4e3e-bb2b-f5a8e3139606" alt=""><figcaption><p>Figure 16 - SDA application architecture reference model</p></figcaption></figure>

It includes all the Regulatory Agency model components, i.e., Channel zone, Infrastructure zone, Public Administration Core Components (PAO-CC) and Regulatory Supervision & Compliance Monitoring components. In addition, there are BBs for digital service delivery for a massive number of transactions:

1. Registration & Profile Management
2. Customers & Users Management
3. Online Learning & Training
4. Customer Accounting
5. Compliance & Enforcement
6. Data Management

To a certain level, this functionality is also presented in the regulatory agency (RA) model. However, those components must be scaled up to the next level for service delivery in the context of massive transactions. For example, those functional components for RA can be implemented using low-code/no-code platforms. For SDA, this implementation requires custom development. to ensure performance and availability during workload peaks for millions of concurrent transactions.

**1. Registration & Profile Management**

Implementing Registration & Profile Management in a service delivery organisation involves managing business and/or citizen information securely and efficiently while ensuring easy access and interaction for users.&#x20;

The software supporting these functions must be robust, user-friendly, and secure, facilitating the management of personal and financial information.

* Customer Registration, Authentication and Authorisation: A secure and straightforward process for users to register and associate with profiles of legal entities on behalf of which they are acting. This should include very strong security authentication to ensure legally binding transactions, non-repudiation, and personalisation of service delivery.
* Privacy Controls and Consent Management: Tools for users to control their privacy settings and manage consents for how their information is used and shared, in compliance with data protection regulations.
* Communication Preferences Management: The ability for users to set and manage their communication preferences, including the types of notifications they wish to receive and through what channels (email, SMS, etc.).
* Personalised Dashboard: A personalised dashboard that gives customers an overview of their profile status, pending actions, recent transactions, and other relevant information.
* Multilingual Support: Support for multiple languages to accommodate the diverse population the organisation serves.

**2. Customers & Users Managemen**

Implementing Customer & Users Management in a public administration service delivery organisation requires a comprehensive set of software features to effectively manage the information and interactions of individuals and businesses.&#x20;

* Centralised User Database: A robust database to store and manage comprehensive profiles of customers, including personal information, contact details, transaction history, and compliance status.
* Secure Registration and Authentication: A secure process for new and existing users to act on behalf of legal entities.
* Account Recovery and Support: Robust mechanisms for account recovery in case of lost passwords or compromised accounts, including customer support features for assisting users with account management issues.
* Role-Based Access Control (RBAC): The ability to define roles and permissions for different types of users (e.g., individuals, business representatives, tax advisors) to control access to sensitive information and functionalities based on their role.
* Audit Trails and Activity Logs: Comprehensive logging of all user activities within their profile for security and compliance purposes, ensuring that any unauthorised access or changes can be traced and investigated.
* Customer Support and Ticketing System: A built-in support system to manage user inquiries and issues, including a ticketing system for efficiently tracking and resolving support requests.
* Analytics and User Behaviour Tracking: Tools to analyse user behaviour, service usage patterns, and satisfaction levels to inform service improvements and policy decisions.
* Bulk Operations and Communications: Features to manage bulk operations, such as mass updates or communications, to handle large user bases efficiently.
* Accessibility Features: Ensuring that the system is accessible to all users, including those with disabilities, following web accessibility standards.

**3. Online Learning & Training**

Implementing Online Learning & Training within a service delivery organisation requires comprehensive software features to create a compelling, engaging, and accessible learning environment. Support should be provided for the delivery of training materials, facilitate interactive learning, and enable tracking and assessment of learner progress.

To a limited extent, POA-CC components support some of the required functionalities. It requires the configuration of specific workflows and templates, and the following specific aspects should be added:

* Course Catalogue and Enrolment: An online catalogue of available courses with detailed descriptions, prerequisites, and enrolment options. Users should be able to easily browse, search, and enrol in courses.
* Learning Pathways: The ability to create structured learning pathways or curriculums that guide learners through courses or modules based on their roles, learning goals, or skill levels.
* Interactive Learning Tools: Features such as quizzes, interactive simulations, discussion forums, and live webinars to engage learners actively and support various learning styles.
* Assessment and Testing: Tools to create and administer tests and quizzes, including multiple-choice questions, essays, and practical tasks, with automatic grading where applicable.
* Certification and Badging: The ability to issue certificates or digital badges upon course completion or mastery of specific skills, providing recognition of learners’ achievements.
* Progress Tracking and Reporting: Dashboards and reporting tools for learners and administrators to track progress, completion rates, assessment scores, and other metrics to monitor learning outcomes.
* Instructor Tools and Resources: Tools for instructors to create and manage content, interact with learners, provide feedback, and monitor class or course progress.
* Feedback and Evaluation: Mechanisms for collecting feedback from learners about courses, instructors, and the overall learning experience to inform continuous improvement.

**4. Customer Accounting**

Implementing Customer Accounting in a service delivery organisation requires a robust set of software features that can handle complex transactions, ensure compliance with laws, and provide a user-friendly interface for customers and administrators.

* Reports Filing and Processing: Features to support the submission of regular reports (for example, tax returns in a revenue authority or financial reporting in a business registry or statistical department) with pre-validation of data to reduce errors.
* Payment Processing Integration: Integration with payment gateways to facilitate payments and refunds, supporting various payment methods (credit/debit cards, bank transfers, digital wallets) and providing real-time transaction processing.
* Account Management: Tools for customers to manage their accounts, including viewing account transactions.
* Automated Calculations: Automated calculation features to pre-fill forms for customers.
* Customer Support and Inquiry Management: Integrated customer support features, including a ticketing system for managing customer inquiries and issues, FAQs, and live chat support.
* Integration with Other Government Systems: Capabilities to integrate with other government databases and systems for data verification and compliance checks and to provide a holistic view of customer obligations and entitlements.

**5. Compliance & Enforcement**

Implementing Compliance & Enforcement in a service delivery organisation requires components to support activities to monitor, detect, and act upon compliance issues efficiently.

To some extent, POA-CC components support the required functionalities. It involves the configuration of specific workflows and templates, and the following particular aspects should be added:

* Regulatory Database: A centralised database that contains all relevant laws, regulations, and compliance requirements, which can be easily updated as new legislation is passed or existing laws are amended.
* Automated Compliance Monitoring: Tools automatically monitor transactions, filings, and other regulated activities for potential compliance violations, using predefined rules and algorithms to identify anomalies and red flags.
* Advanced Specialised Risk Assessment Tools: Features that enable the assessment of compliance risks associated with specific entities, sectors, or activities, allowing for targeted enforcement and monitoring efforts based on risk profiles.
* Audit and Inspection Workflows: Workflow automation for planning, scheduling, and conducting audits and inspections, including checklists, reporting templates, and tools for auditors and inspectors to record findings and recommendations.
* Financial Analysis Tools: Advanced tools for analysing financial transactions, patterns, and records to detect signs of non-compliance, fraud, or other illicit activities.
* Penalty and Sanction Processing: Features for calculating, issuing, and tracking penalties and sanctions for compliance violations, including payment processing and appeals management.
* Stakeholder Communication: A secure channel for communicating with regulated entities, legal representatives, and other stakeholders, providing access to case information, document submission, and status updates.
* Whistle-blower and Complaint Submission: Secure and anonymous channels for whistle-blowers and the public to report suspected violations, including tips, complaints, and submission of supporting evidence, which could also serve as an automated evaluation and feedback mechanism.

**6. Data Management**

The Data Management component should contain at least the following building blocks:

* Data Format and Transformation Services: These services convert data from one format to another so that different systems can understand and use the information without manual intervention.
* Monitoring and Logging Services: These services track the health and usage of the service delivery platform, recording data on transactions, performance, and potential security incidents.
* Business Rules Management: A system for defining, deploying, monitoring, and maintaining the complex decision logic system processes use.
* Workflow and Business Process Management are tools that allow for the design, execution, and automation of business processes involving multiple interconnected systems.
* Master Data Management (MDM) is software that ensures the uniformity, accuracy, stewardship, semantic consistency, and accountability of the enterprise's official shared master data assets.
* Data Warehousing and Analytics: Systems that collect, store, and allow for analysing large volumes of data to inform decision-making and service improvements.
* Risk and Fraud Detection Systems: Analytical tools to identify suspicious activities and potential fraud

### A1.2.5 State Registries

One additional type of system is a state registry. For example, a business registry registers companies. In many countries, there are population registries to record the birth and death of individuals, along with all other important personal lifecycle events. The digitalization of such agencies requires two building blocks:

* Registration BB
* Digital Registry BB

Registration BB: Registration is a process through which an applicant gets information recorded in a registry and receives a credential as proof of registration, in exchange for providing information, with or without money. The information provided by the applicant consists of data and/or credentials issued by public or private entities. Money is provided to pay for one or more registration fees/costs. A registration involves at least two parties:

* applicant who wants to register (something or somebody);
* authorized representative of a registry in charge of registering the data and issuing the credential.

One registration may involve more than two parties, as one or more third parties can be requested to assert/confirm the information provided by the applicant (a notary, a family member, a witness, another public entity, or a non-human entity such as a database); or a third party can be requested to receive the payment made by the applicant (a bank, a cashier, an online payment service).&#x20;

The registry or registries where the information is written can also be considered as a third party.

Digital Registry BB: The Digital Registries Building Block provides services to other Building Blocks and to external systems, to store and manage data/claims on any entity (persons, places, and things) in forms of uniquely identiﬁable records in a database.

For example, these records could contain health and medical information, ownership of property, vehicles, money, qualiﬁcations, birth/expiry of people and entities, land surveys, manufacturing information of vehicles and equipment, banking, and commercial transactions, etc. Given the diversity of such information, this Building Block provides services useful to abstract the structure, linkages, and grouping of information into various records and collections such as ﬁnancial, legal, medical, social, educational, commercial, etc., as needed.

The Digital Registry BB provides the capability to capture, store, search, distribute, and present data with zero or minimal need for software development. It also maintains and reports logs of all operations on database schemas and data. It contains various functional components and data resources to abstract away all the details and complexity and to expose capabilities as service-APIs to external Building Blocks/applications.

#### A1.2.6 Government Horizontal Systems

One additional type of system is an internal governmental system, where the provider and consumer are both public administration organisations (so-called G2G type). A non-exhaustive list of such G2G systems:

1. Procurement
2. HR management
3. Budget
4. Contracts
5. Invoices
6. Payments
7. Accounting
8. E-Cabinet
9. Legislation Drafting
10. Repository of Laws
11. Service Delivery Platforms: User-centric platforms offering digital government services, including websites and mobile applications.
12. Citizen Engagement Platforms: These are channels for citizens to provide feedback, participate in policymaking, and engage with the government.
13. Open Data Initiatives: Making government data available to the public to increase transparency and enable innovation.
14. Emergency and Disaster Response Systems: Digital infrastructure to provide timely information and services during emergencies.

In most cases, this functionality should be implemented only once in a country and used by all public administration organisations from a **Shared Services Centre**.

The current version of this document does not cover the specifics of those systems.

### A1.2.7 Natural Digital Environments

The concept of a natural digital environment refers to the fact that in a digital society and digital economy, eventually, everyone should have a specialised digital environment that is used for everything. Following is a description of possible options, which can be envisioned with our today’s understanding of technology and needs.

#### Digital Walle

We used to classify stakeholders of digital services as “citizens, businesses, NGOs, etc.”. However, everyone should appreciate the fact that even when we talk about businesses and other organisations, there are people who are behind transactions. Like that, we can state that an individual’s Digital Wallet is a first and foremost Natural Digital Environment of the Digital Era.

A Digital Wallet has two main elements: security features and personal information. Security features include encryption, authentication protocols, and biometric verification. Personal information includes foundational identity, functional identities, addresses, contact information, and other relevant data to streamline online transactions.

A Digital Wallet can also be seen as a virtual payment tool that stores money and facilitates transactions using payment methods such as electronic money, credit/debit cards, bank accounts, or digital currency. It also maintains a transaction history for users.

Also, a digital wallet can store a variety of retail business information, such as digital tickets, coupons, boarding passes, event tickets, discount codes, and loyalty rewards. This provides users with a convenient way to access and manage these items in one place. To ensure a satisfactory user experience, a digital wallet should have a user-friendly interface that simplifies the process of making payments, transferring funds, getting access and managing different transactions.

A Digital Wallet can be integrated with MyGov functionality, allowing citizens to connect a government digital channel directly to their personal wallet.

Digital wallets are also a good way to overcome the difficulties in regions where Internet access or cross boarder data flows are difficult to achieve.

#### MyGov

First of all, MyGov is a mobile application that provides citizens and residents with essential public information and enables them to execute any public sector transaction, such as submitting tax returns, applying for and receiving driver's licenses, etc.

MyGov is also a unified governmental portal, which provides centralised services and provides links to decentralised services.

It is a brand for a network of walk-in counters that provide digital access to people without personal devices through self-service kiosks and service clerks.

Like that, MyGov provides access to digital government services for all without any discrimination.

#### Organisation ERP

Previously, ERP stood for Enterprise Resource Planning solution. Today, it refers to an integrated IT system used to provide digital resources to different organisational roles to achieve business objectives. In this context, it would be ideal for the public sector to facilitate direct integration between Digital Government services and ERP systems of various businesses and organisations in a country.

### A1.2.8 Public Ecosystems

The public sector organisations described above—policy development units, regulatory agencies, and service delivery authorities—are present in all main functional areas of the digital economy and society. They develop and implement policies, regulate market activities, and deliver services to citizens and businesses.

Simplified model of the public sector ecosystem can be depicted in the following way:

<figure><img src="https://4055358096-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FpqnbDhX09tb5z7q4AWcQ%2Fuploads%2FagLTKqdOfGcHd5BihjeZ%2Fimage3.png?alt=media&amp;token=b945b69b-87b5-4160-bda7-5cd036e7a04f" alt=""><figcaption><p>Figure 17 - Simplified model of public administration ecosystem</p></figcaption></figure>

There are the following main functional areas:

* **Finance**. The sector includes public finance (i.e. treasury, budget planning and execution, revenue management, customs, national accounting, central bank, and statistics) and private sector financial organisations (banking, securities, investment banks, non-bank financial institutions, pension funds, fintech companies, credit rating agencies, etc.)
* **Internal security**. In a country's internal security sector, organisations are responsible for maintaining public order, combating crime, and ensuring citizens' safety. These include the Ministry of Internal Affairs, law enforcement agencies, intelligence services, border control, civil defence, cybersecurity agencies, counterterrorism units, judicial and correctional institutions, customs and excise, and regulatory bodies.
* **Education**. A country's education sector includes various organisations, such as Ministries, educational institutions, teacher training institutions, research institutions, and non-state actors. These organisations work together to provide high-quality educational services and promote human capital development. Different state programs for Education Development aim to improve the quality of education services.
* **Social care**. In a country's social care sector, public health institutions, NGOs, educational institutions, social work organisations, government agencies, and civil society organisations collaborate to provide social services, promote health education, deliver healthcare services, and support vulnerable communities. They work together to address social challenges and enhance the social care sector.
* **Health care**. A country's healthcare sector includes several types of organisations that provide medical care and services to the population, such as government agencies, public and private hospitals and healthcare facilities, medical schools, medical research institutions, healthcare professional associations, healthcare insurance companies, and non-governmental organisations (NGOs).
* **Construction**. A country's construction sector involves various organisations that handle different aspects of the construction process. These include construction companies, architecture firms, engineering companies, contractors and subcontractors, material suppliers, regulatory bodies, real estate developers, project management firms, surveying firms, consultancy firms, and legal services. Range of projects from residential buildings to commercial developments and infrastructure projects.
* **Agriculture**. Various organisations work together in the agricultural sector to form the industry's backbone, i.e., farms, cooperatives, research institutions, governmental agencies, NGOs, equipment manufacturers, agrochemical companies, seed and genetic companies, food processing companies, and agricultural extension services.
* **Utilities**. In a country's utility sector, organisations are involved in essential services such as electricity production and distribution, water supply and sanitation, natural gas supply, renewable energy, telecommunications, waste management, and relevant regulatory bodies.
* **Mobility**. In the mobility sector, various organisations play essential roles in the transportation and movement of people and goods. These include public transportation providers, ride-sharing companies, taxi services, logistics and freight companies, bicycle and scooter-sharing services, regulatory agencies, vehicle manufacturers and dealerships, infrastructure development firms, and technology and innovation firms.

From the public administration standpoint, those are main sectors of Digital Economy and Society. According to national priorities, the government's digital transformation should focus on the main public administration sectors.

Within those ecosystems public sector organisations are interacting with different players from private sector.&#x20;

For example, here is healthcare reference architecture developed by Oliver Kipf:

<figure><img src="https://4055358096-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FpqnbDhX09tb5z7q4AWcQ%2Fuploads%2FaAc6JTzBaqPapnAOgHUA%2Fimage4.png?alt=media&amp;token=c6542617-fd05-4c76-a975-646f885a0c53" alt=""><figcaption><p>Figure 18 - A healthcare reference architecture (Source: Oliver Kipf)</p></figcaption></figure>

In this diagram, governmental regulatory authority is part of a more complex information exchange ecosystem.

There is another example of an ecosystem in the Construction area:

<figure><img src="https://4055358096-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FpqnbDhX09tb5z7q4AWcQ%2Fuploads%2FH79okLMHGdNI5hw1uEac%2Fimage5.png?alt=media&amp;token=5cdf17cc-7620-4bb9-85eb-4cc9f64ba543" alt=""><figcaption><p>Figure 19 - Construction ecosystem (Source: Jüri Ross)</p></figcaption></figure>

This example is from Estonia. It shows how different players exchange information during the construction project's progress.

It is essential to understand that public and private sector entities should be able to communicate with each other from their natural digital environments. In the Digital Era, **portals are no longer necessary**.&#x20;

Instead, businesses with their own ERP solutions should be able to communicate with the public sector directly from within their ERP systems. Similarly, citizens with a Digital Wallet and the MyGov mobile app should be able to perform all necessary tasks through those channels. Public sector entities should also be able to proactively push information and services to stakeholders' natural digital environments.

The current version of the document does not cover the specifics of those ecosystems. However, the GovStack team is committed to continuing the analysis to identify reusable components and practices to streamline building such a comprehensive Digital Society and Economy ecosystem.

In many countries, the defence sector is also important, but it has intentionally been omitted from the scope of GovStack's reference architecture.<br>

### A1.2.9 Summary

Now we can summarise our current understanding regarding required building blocks (BB) for the public administration. Overall architecture can be depicted in the following way:

<figure><img src="https://4055358096-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FpqnbDhX09tb5z7q4AWcQ%2Fuploads%2Fo55i06MN1hCVuUBAyTtO%2Fimage6.png?alt=media&amp;token=d7cb256b-25cb-47ab-89d5-4570a4765551" alt=""><figcaption><p>Figure 20 - Overall list of required BBs</p></figcaption></figure>

Here we are categorizing building blocks into the following main groups:

* **Back Office** (BO) building blocks (BBs) are used to build public administration solutions strictly for internal use by public administration officers.
  * The BO **infrastructure** BBs are modular building blocks that are not specific to the function of the organisation that uses them and these building blocks are deployed once for a particular country and then reused by everyone. For instance, the Identity BB is installed once and is intended to be re-used by everyone.
  * The BO **functional** BBs are specific for business activities or when they are generic (like Content Management), they should be configured in a specific way for every organisation. That means, that knowledge of internals of those BBs and capability to configure them should be presented in many organisations in a country.
* **Front Office** (FO) building blocks are meant for use by external public sector stakeholders and customers.
* In **Ecosystems**, public sector organisations participate using the back-office or the front-office BBs.

All infrastructural BBs are currently already defined in the GovStack specifications Knowledge Base section.

All functional building blocks at a high level have been defined in sections 4.6.2 - 4.6.3 above.

The building blocks of the Front Office at a high level are defined in section 4.6.7 above.

The Ecosystem concept is defined in the section 4.6.8 above.&#x20;

## A1.3 Building Blocks

Public administration organizations can benefit from digital transformation by reusing standardized architectural building blocks from the national digital infrastructure. These blocks are essential components that can be utilized in various digital projects to ensure consistency, reliability, and security.&#x20;

GovStack offers some common architectural blocks as national digital infrastructure that public administrations can utilize to improve their efficiency, interoperability, and service delivery.

1. Digital Identity Systems: A foundational component for enabling secure and convenient access to digital services. Public administrations can integrate national digital ID systems to authenticate users and enable electronic signatures, ensuring transactions are both secure and legally binding.
2. Data Exchange Layers: Such as APIs (Application Programming Interfaces) and standardised data exchange formats, facilitate seamless communication and data sharing between different government systems and services. Public administrations can ensure interoperability and easy integration of services by adopting national data exchange standards.
3. Payment Gateways: Standardized digital payment systems can be reused to facilitate transactions for various public services. This enables a uniform, secure, and efficient mechanism for collecting fees, taxes, and other payments from citizens and businesses.
4. Security Infrastructure: Including encryption protocols, cybersecurity frameworks, and threat detection systems that can be adopted to protect sensitive information and digital services from cyber threats. Utilizing national security infrastructure helps maintain high standards of data protection and trust.
5. Cloud Infrastructure: Government cloud platforms offer scalable and flexible computing resources. Public administrations can leverage these for hosting services and applications, benefiting from economies of scale and reducing the need for extensive individual investments in IT infrastructure.
6. Geospatial Services: National geospatial data and services provide detailed geographic information that can be used for planning, infrastructure development, environmental management, and emergency response. Integrating these services can enhance the quality and relevance of public services.
7. Registry Services: Centralized registries (such as citizen, business, property, and vehicle registries) are crucial for maintaining authoritative sources of information. By reusing these registries, public administrations can streamline processes, reduce duplication, and improve accuracy.
8. Open Data Platforms: By utilizing national open data initiatives, administrations can access a wealth of non-sensitive information for analysis, policy-making, and service improvement. This promotes transparency, innovation, and data-driven decision-making.
9. Digital Service Platforms: Platforms that provide reusable components for building digital services, including templates, design systems, and development tools. These enable a consistent user experience across government services and reduce development time and costs.
10. Communication and Collaboration Tools: National infrastructure often includes secure communication channels and collaboration platforms that public sector employees can use to enhance productivity and teamwork.
11. Consent service: The Consent Building Block enables services for individuals to approve the use of their Personal Data by defining the principles, functions, and architecture of an information system. For organisations that process Personal Data​,​ it provides the ability to know the ​individual's will and legitimately process such Personal Data. The Consent Building Block is a process-oriented GovStack Building Block facilitating auditable bilateral agreements within a multi-agent environment that integrates with most other Building Blocks.
12. Messaging service: The Messaging Building Block is a secure communication channel for public administration service providers to communicate with their customers. It offers functionalities such as logging, backup, and security. Developers can use it to create communication components on top of different services, allowing them to pass messages with federated architecture. It supports various modalities such as email and SMS and helps connect with existing messaging service providers, making the adoption process less disruptive for end-users.
13. Workflow management service: Workflow Building Block automates and orchestrates business processes within and across Building Blocks. It maps and models business processes using open standards like BPMN. Deployed workflows are executed during runtime to orchestrate process flows from initiation to completion.
14. Scheduling service: The Scheduler Building Block coordinates time-driven activities within and between Building Blocks by sending alert messages based on a predetermined schedule. Each event has an ID, name, date, time, and duration and involves multiple resources. Subscribers can enrol to benefit from the activities. The Scheduler alerts specific resources and subscribers with messages to carry out respective activities. The Scheduler Building Block contains functionalities for planning, booking, tracking, triggering, notifying, and status reporting of multiple events. It has micro-services that orchestrate these functions through RESTful APIs.
15. Digital signature service: Digital Signature Building Block provides the necessary functionalities to bring handwritten signatures to the digital world. Handwritten signatures have served as a way to agree/witness a given document, yet, in today's digital world most documents are in digital form. The digital form varies between structured (XML, JSON) and unstructured documents (PDF, Word, Image, CSV, Spreadsheet). eSignatures can be added to digital documents similar to handwritten signatures, achieving the same functionality.

This list of building blocks by no means is final. It will be growing as GovStack will be supporting more and more transformational initiatives.

<br>


# 7. Annex 2 – Metamodel of Reference Architecture

## Methodology Baseline

To define the reference architecture of a public administration organisation (PAO) we adopted Open Group TOGAF framework:

<figure><img src="https://4055358096-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FpqnbDhX09tb5z7q4AWcQ%2Fuploads%2FkepujgU1pAHLnH8BAVq8%2Fimage7.png?alt=media&amp;token=69316e7d-dba5-4c2b-9819-9df7c25fd332" alt=""><figcaption><p>Figure 26 - Architecture description components in TOGAF (Source: OGM)</p></figcaption></figure>

Overall organisation architecture in TOGAF is defined by following layers

1. Business Architecture Layer,
2. Information Systems Architecture, including Data and Applications architectures and
3. Technology Architecture layer.

## Primary Viewpoints

The primary concern for the current document is to provide guidelines for structuring business and application target architecture during the planning of digital transformation.

To define business architecture, we are using the business model concept. In details business model is described in the \[1]. In \[3], the author provides the following short definition: “A business model is a conceptual tool containing a set of objects, concepts and their relationships with the objective to express the business logic of a specific firm. Therefore, we must consider which concepts and relationships allow a simplified description and representation of what value is provided to customers, how this is done and with which financial consequences”.

From an external perspective, a business model outlines how an organization conducts its operations. It encompasses the strategies and tactics employed by a company to achieve its goals \[1]. The following are main components of the business model:

<figure><img src="https://4055358096-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FpqnbDhX09tb5z7q4AWcQ%2Fuploads%2FODfmtCRfyg30t8rLxplZ%2Fimage8.png?alt=media&amp;token=88a360da-2f78-46ee-8f3c-6332a39906db" alt=""><figcaption><p>Figure 27 - Business model components. </p></figcaption></figure>

Like that, business architecture will be described using a business model and then will be connected to the application architecture via required application services.&#x20;

Following is a metamodel, which we are using to define PAO reference architectures:

<figure><img src="https://4055358096-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FpqnbDhX09tb5z7q4AWcQ%2Fuploads%2FXN6SGkJMF9Gu7e98lcS9%2Fimage9.jpg?alt=media&amp;token=727f0c73-d759-4bd9-871e-6f707aa14481" alt=""><figcaption><p>Figure 28 - Reference Architecture Metamodel</p></figcaption></figure>

### Customer

A person or organization that is served by a public administration organisation.

### Service

A defined performance of a person or organization that meets a customer's needs.

### Business process

Ordered series of work processes that are carried out within one organization with the aim of providing a (combination of) service (s) to a citizen, company or organization.

### Workflow

An ordered series of process steps (business activities) carried out within one organizational unit within an organization with the aim of making a specific contribution (performance) to a service. (Can be a supporting process).

### Application function

Related functionality offered by an application component. An application function offers support to one or more business activities.

### Application component

The actual software that delivers the application functionality.

For modelling, ArchiMate 3.1 is used. For every class of customer, main services are defined with reference to a business process implementing the service. Business processes may give internal workflows, which are supported by application architecture services.


# 8. Annex 3 – Main state registries

[Base registers](https://joinup.ec.europa.eu/collection/nifo-national-interoperability-framework-observatory/glossary/term/base-registries) should be established in a country to ensure feasibility of holistic approach toward secure and reliable digital government services:

* **Population Registry** or alternative reliable data source to enable Digital Identification. Contains key demographic and residency details of all citizens in the country.
* **Business Registry** to enable legally binding authorisation of users in context of legal entities for making legal transactions. Central database of all registered companies and legal entities operating in the country.
* **Cadastre/Land register** or similar alternative for assurance of property rights. Authoritative information on land parcels, property boundaries and ownership
* **Official Publications** – register and a system to publish laws and regulations for public access and awareness.
* **Securities Register** - Beneficial ownership information behind corporate entities to enable transparency.
* **Registry of economic activities**, licenses and permissions contains data on all requirements in any area of business activities, regulated in a country and reference to appropriate procedures and entities, who are in charge for regulations.
* **Vehicle Register** - Records details of all vehicles registered in the country.
* **Health Registers** - Databases of healthcare providers, facilities, treatments, diseases etc.
* **Social Insurance Register** - Citizen records related to pensions, unemployment benefits, healthcare coverage etc.
* **Education Register** - Details of educational institutions, students, qualifications awarded.
* **Criminal Register** - Records of crimes, convictions by courts and related law enforcement actions.
* **Procurement Register** - Data on government contracts, bids and awards.


# Public Administration Ecosystem Reference Architecture (PAERA)

Developed by Aare Laponin, Ivar Tallo, and Margus Magi..


# 1. Introduction to PAERA

## 1.1 Objective

This document aims to guide public sector organizations and governments undergoing digital transformation. In such organizations, there are typically two groups of people: management with governance background and IT personnel who are familiar with the technical aspects of digitalization. Often, these groups have different vocabularies and varying understandings of the scope and objectives of digitalization, which can lead to tensions.

This document is constructed in an accessible manner to overcome the dichotomy of governance and IT way of thinking, so it could be used:

* By high-level people (governance) to understand the hidden dependencies in the building blocks in the whole ecosystem.
* By IT personnel to better comprehend objectives, scope and required sequencing of digitalisation programs.

This document outlines GovStack building blocks for implementing Enterprise Architecture practices in Digital Government (DG) and establishes a Reference Architecture for the target ecosystem.

This document aims to provide the reader with an understanding of:

* The value proposition of the GovStack approach, and how it helps with the adoption of digital transformation initiatives.
* How Building Blocks approach (also, GovStack approach) and Enterprise Architecture practices interact, and how they can be used for the needs of a specific government.
* What are the dependencies and potential conflicts when attempting to apply the GovStack approach for digital transformation.

## 1.2 Motivation

It is crucial that all countries, particularly those with lower incomes, are given an equal opportunity to develop digitally. The digital revolution is currently offering opportunities that can be used to tackle the most urgent global issues within the framework of the United Nations' Sustainable Development Goals (SDGs). Information and Communications Technologies (ICTs) serve as reliable facilitators in this regard.

As technology continues to evolve, we often focus on the latest solutions and the potential for rapid progress, but we may overlook the critical underlying conditions required for success. Unfortunately, there are many obstacles that can prevent us from achieving our goals, such as improper sequencing of changes, poor change management practices, or inadequate sourcing strategies for digitalization.

There are many reasons why our efforts may fail, and success requires navigating a narrow path.

The Public Administration Ecosystem Reference Architecture (PAERA) aims to provide coordinated, efficient, and equitable services by transcending those boundaries.

This Reference Architecture presents a comprehensive approach that combines IT processes with government business strategies, guided by principles of digital governance.

In practice, the most significant reasons why governments adopt this approach are usually the need to ensure that business and technology are aligned and the need to manage complexity effectively.

Another important lesson that PAERA wants to convey to readers is that Change Management should be addressed at both the government and public administration levels in a coordinated manner. This is crucial to overcome typical challenges that are daily arising and negatively impacting modernization efforts.

## 1.3 GovStack Vision

The GovStack vision is to accelerate the digital transformation of government services. This will empower governments to build a more effective and cost-efficient public sector, taking ownership of their digital future.

GovStack is a platform that will help countries start their digital transformation journey by adopting, deploying, and scaling digital government services. PAERA explains how the GovStack Approach, which involves digital building blocks, can help governments easily create or modify their digital platforms, services, and applications.

The GovStack approach simplifies solution architectures, reduces cost, and decreases the time-to-market of digitalization programs. It aims to build a common understanding and technical practice of using fundamental, reusable, and interoperable digital components applicable to any public administration. PAERA collectively refers to those as building blocks.

The GovStack initiative is led by a community of subject matter experts and involves multiple stakeholders who develop concrete guidance for strengthening a government’s ability to deliver practical solutions.

GovStack is a platform that analyses digital government experiences worldwide. It identifies the common successful approaches used in countries that lead the transformation of government services through digitalization. GovStack building blocks represent an empirical abstraction of these approaches, and the PAERA outlines the baseline of the GovStack building blocks framework.

GovStack has started to develop specifications for reusable building blocks. Even if building block specifications are standardized, situations in which they will be utilized are always unique. Here is where change management comes in as a high-level requirement to manage the processes. We highlight timelines and dependencies wherever possible to make it easier for individuals to determine the appropriate course of action in their unique digital journey.

GovStack will work with all different communities who develop software solutions that adhere to these specifications to ensure interoperability between different GovStack-compliant software products.

Following the development of specifications, the collaboration will create a reference digital government service that will demonstrate the reuse of elements across sectors and services.

The design specifications and the resulting government reference platform will be available as “digital public goods” for the global community.

We believe that the GovStack building block approach, enterprise architecture practice, and adequate change management will make digital transformation in public administration sustainable and effective and benefit citizens, businesses, and all social and demographic groups.

## 1.4 GovStack Origin

The GovStack initiative was launched in 2021 under the leadership of four partners:

* International Telecommunication Union (ITU)
* Republic of Estonia
* Deutsche Gesellschaft für Internationale Zusammenarbeit (GIZ)
* Digital Impact Alliance (DIAL)

\\


# Scope of Document

This document provides an overview of the digital transformation of government services and is expected to be a key reference for practitioners.

* The first chapter is a traditional introduction where we aim to show how the document is set in context and the larger context of GovStack itself.
* The second chapter is about the basic assumptions that have created the need for such a document.
* The third chapter applies the GovStack approach to national-level digitization efforts. It describes how the GovStack building blocks make the most sense for national digital transformation.
* The fourth chapter defines the reference architecture of a public sector organization from the digital transformation perspective.
* The fifth chapter provides guidelines for practitioners on using this reference architecture.

The document is expected to be a practical and helpful guide for planning national public administration modernization initiatives. The authors intend to incorporate more knowledge and practical case studies over time, so we are interested in readers' feedback.


# Abbreviations

<table data-header-hidden><thead><tr><th width="113"></th><th></th></tr></thead><tbody><tr><td>Code</td><td>Description</td></tr><tr><td>BB</td><td>Building Block</td></tr><tr><td>BO</td><td>Back Office</td></tr><tr><td>DPG</td><td>Digital Public Goods</td></tr><tr><td>DPI</td><td>Digital Public Infrastructure</td></tr><tr><td>EA</td><td>Enterprise Architecture</td></tr><tr><td>ERP</td><td>Enterprise Resource Planning</td></tr><tr><td>FO</td><td>Front Office</td></tr><tr><td>G2G</td><td>Government to Gevernment</td></tr><tr><td>GS</td><td>GovStack</td></tr><tr><td>KPI</td><td>Key Performance Indicator</td></tr><tr><td>MDA</td><td>Ministries, Departments and Agencies</td></tr><tr><td>PAERA</td><td>Public Administration Ecosystem Reference Architecture</td></tr><tr><td>PAO-CC</td><td>Public Administration Core Components</td></tr><tr><td>PAR</td><td>Public Administration Reform</td></tr><tr><td>PCI DSS</td><td>Payment Card Industry Data Security Standard</td></tr><tr><td>PDU</td><td>Policy Development Unit</td></tr><tr><td>RA</td><td>Regulatory agency who regulates specific functional area of economy</td></tr><tr><td>SDA</td><td>Service delivery authority, e.g. Police Department, Customs Department etc.</td></tr><tr><td>SLA</td><td>Service Level Agreements</td></tr><tr><td>WoG</td><td>Whole of Government</td></tr></tbody></table>


# 2. State of Digital Transformation

## 2.1 Problem statement

#### Internal factors

The history of digital transformation initiatives is marked by numerous large and ambitious projects that have failed despite being constructed and funded by well-intentioned donors, whether domestic or foreign. Projects often introduce foreign ideas to a given society, which the society needs to assimilate in meaningful ways. If successful, they would bring about the desired benefits. However, often, they fail because the local cultural environment clashes with the underlying ideas upon which the benefits have been built.

To avoid failure and unnecessary spending, a country must carefully select a suitable action plan based on the needs and capabilities of the target groups who will benefit from the developed products. It is natural to want to adopt the best practices from around the world and use new technologies to speed up progress towards a better future, but this can only be done under certain circumstances.

#### External factors

Software markets are typically effective in meeting the needs of the private sector. Thanks to globalization and trade liberalization, successful software products are quickly accessible to users worldwide. As the customer base grows, the quality of products also improves. However, public administration practices and working processes differ significantly from those of the private sector, making it challenging to cater to the needs of the public sector.

While user functional and non-functional requirements can be agreed upon easily across cultures, harmonizing legislation and administrative procedures is challenging. It is therefore fair to say that automating a specific function in the public sector of a given country is a one-time occurrence.

A global ERP vendor may have hundreds of thousands of customers in the private sector. However, a vendor selling, for example, tax administration software can only target around 200 tax administrations worldwide, making it a less attractive market for vendors. For this reason, mature and fit-for-purpose public administration-specific solutions are not in high demand. Many vendors claim to have public administration solutions. Upon closer inspection, these solutions may not be effectively tailored to a specific public administration context.

#### Technology factors

People believe that once a new technology solution is implemented, the problem is solved. Tough reality of Digital Age is that at this moment life-cycle of the new asset just starts.

To maintain a solution's functionality, it is necessary to regularly upgrade its security features, adjust its software to keep up with changing infrastructure, address user issues, and define and implement new requirements. However, these needs are often overlooked by management, resulting in irregular implementation of security patches and using shortcuts during changes.

This leads to the emergence of new legacy systems that are difficult to manage. A new cycle of the COBOL-ization process begins, investments are not sustainable, and systems are too complex. Finally, development stops, and all effort goes into maintenance.

#### GovStack response

GovStack has a solution to the above challenges:

1. We analyse the best practices around the globe.
2. Findings are consolidated, and appropriate reusable Building Blocks specifications are designed.
3. We point out the important assumptions and dependencies along the planning and implementation processes.
4. Specifications of Building Blocks are disseminated to the software developers’ community.
5. We are actively engaging with solution providers, seeking products that can be candidates for implementation of Building Blocks specifications.
6. We closely monitor Building Blocks implementation practices and learn from them, further improving the GovStack proposition.

#### Outcome Architecture

GovStack is a digital transformation approach aimed at creating prosperity for people by converting technological advances of the last decades into new capabilities for everybody

<figure><img src="https://2983968174-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FWNaBkXRH5GkT1VCcv0BB%2Fuploads%2Fgit-blob-9ac55860a2b8918d99c2690e3b1dca0e5461a82f%2FScreenshot%202024-05-29%20004408.png?alt=media" alt=""><figcaption><p>Figure 1 - Outcomes architecture of digital transforamtion</p></figcaption></figure>

The digital transformation of the public sector is expected to benefit society as a whole, the economy, and the government sector.

* Society: fostering communities’ relationships, new capabilities for individuals to participate and thrive in all dimensions of their life, enhancements of the overall well-being and happiness of the population, including considerations such as healthcare, education, and cultural enrichment.
* Economy: less bureaucratic barriers, financial inclusion, new local jobs, new knowledge-based industries, better regional and international trade conditions.
* Government sector: cost-efficiency, pro-active service delivery, better workplace culture.

Consider this model when setting objectives for digital transformation initiatives to ensure better sustainability of efforts.

## 2.2 GovStack Methodology

GovStack is an initiative that aims to gather best Digital Government practices from case studies worldwide. It also seeks to create a reference architecture of building blocks for a Digital Government reference model.

GovStack provides a platform for vendors and developers to have open access to building blocks on the supply side and Digital Government personnel on the demand side. GovStack bridges the gap between governments seeking to transform their practices and the developers and vendors who offer the necessary building blocks for successful solutions.

The GovStack Methodology follows a building block approach that aligns with the SDG Digital Investment Framework's whole-of-government philosophy ([Source](https://www.itu.int/pub/D-STR-DIGITAL.02-2019))

<figure><img src="https://2983968174-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FWNaBkXRH5GkT1VCcv0BB%2Fuploads%2Fgit-blob-2bf2022f3477401784abdec0d0e6f98f008d4064%2Fimage12.png?alt=media" alt=""><figcaption><p>Figure 2 - GovStack methedology componenets</p></figcaption></figure>

To facilitate the activation of the methodology, GovStack has created this Public Administration Ecosystem Reference Architecture (PAERA) outlining the necessary framework for the public sector to approach digital transformation in a practical, effective, efficient, and sustainable way.

GS develops [GS Specs](https://workflow.govstack.global/development-6/) to define building block requirements, dependencies, and usage guidelines for implementing solutions using those building blocks.\
GS develops GS Playbook to provide recommendations to government CIOs for implementing best Digital Government practices for solution design and related activities.\
\
GS architects identify available open source or commercial components that align with specs API and place them to GS Sandbox for demonstrations and rapid prototyping sessions during discussions with countries’ solutions architects.

Components that pass tests against defined specs can be placed on GS Marketplace for countries to consider during their transformational journeys.

GS working groups develop training materials, which are available in GS Learn & Train for staff training during change management.

The GS Certification program streamlines the process of hiring competent solutions architects to design transformational initiatives in different countries. This program evaluates a candidate's previous experience, work in GS working groups, and performance in the certification exams. It helps to certify professionals who can effectively implement the GS approach in their respective countries.

The methodology focuses on modern digital government systems' end-to-end life cycle management, enabling sustainable investment and reliable public administration. It leverages proven practices from digitally advanced societies to prioritize interoperability, reuse, and sustainability, simplifying and accelerating public sector digital transformation using proven technology blocks and governance and change management practices.

GovStack Knowledge Base compiles knowledge from country use cases and research studies, and shares guides and publications on best practices for digital transformation.

## 2.3 Role of Enterprise Architecture

#### Key Concepts

In PAERA, we require a practical and straightforward definition of Enterprise Architecture (EA). Some Chscholars criticize popular EA approaches, claiming that they are purely philosophical and unrealistic and provide little practical advice. They argue that the term EA has been utilized as an umbrella term to refer to a single comprehensive description of an organization developed and used by stakeholders (Ibid).

Enterprise architecture can be defined as a collection of documents describing various aspects of an organization from an integrated business and IT perspective, intended to bridge the communication gap between business and IT stakeholders, facilitate information systems planning and thereby improve business and IT alignment (Source: Kotusev, Svyatoslav. The Practice of Enterprise Architecture: A Modern Approach to Business and IT Alignment (p. 19). SK Publishing. Second Edition 2021).

The blend of Enterprise Architecture practice with the building blocks approach offers multiple advantages, such as cost savings, speed, real economic return, and agility, combined with responsiveness, integration, and information exchange to achieve interoperability, adherence to common standards, and minimizing vendor lock-in.

The discipline of Enterprise Architecture provides visibility into an organization, its activities, and its systems. It considers four different points of view that are central to understanding an organization:

* Business Architecture. In EA practice, we refer to business architecture when we think about customers and the services that an organization provides to them. However, there are more important and interesting aspects to business architecture than just customers and services, such as business processes, regulations, key performance indicators, etc.
* Application Architecture. When people use application software to accomplish some tasks, we can say that the business process of this task is supported by an application. When we describe an organisation's all applications, which are used by a variety of business processes, then we would define the organisation's application architecture.
* Data Architecture. Recently, an increasing number of people have realized that automating business processes and service delivery is important, as is analysing the data collected by their organization. By doing so, they can adjust their business strategy and activities to enhance their achievements. For doing data analysis, however, you should know your data. So, when you meaningfully document your data, in EA practice, we say you documented your data architecture.
* Technology Architecture describes all computing, networking, storage, etc. devices that enable an organisation to use digital services.

The enterprise architecture practice also provides advice on how to track dependencies between different elements of your architectural layers, both horizontally (within the same layer) and vertically (across layers). Once you create such a layered description of your organization, you will be able to understand how your organization functions as a system.

There are building blocks for every EA layer:

* Within the Business Architecture, a building block is a set of specific recommendations for legal and organizational arrangements.
* Within the Application Architecture a building block is a separately deployable executable software component, described in a specification of the block’s interface (API), and objectives to be achieved using the capabilities of that component.
* Within the Data Architecture, a building block is a definition of the required registries and information repositories and a description of the business capabilities that those registries and repositories enable.
* With the Technology Architecture, a building block is defined as an implementational pattern recommended for delivering secure and scalable ICT infrastructure services.

Reference Architecture refers to the consolidation of previous experience in the domain of digitalisation in public administration. It involves creating templates that structure components of applications and technology to support specific business models presented in the public sector. These templates are used to speed up the development of solutions for Public Administration Organizations (PAOs) and to decrease the risk of design decisions.

For example, in \[Source: Kotusev, Svyatoslav. The Practice of Enterprise Architecture: A Modern Approach to Business and IT Alignment (p. 19). SK Publishing. Second Edition 2021] author provides the following practical visualisation of Reference Architecture in the context of the development of solutions:

<figure><img src="https://2983968174-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FWNaBkXRH5GkT1VCcv0BB%2Fuploads%2Fgit-blob-53a3c2d9aa5e979c1197ecc62bee60ace4ac3b0e%2FScreenshot%202024-05-29%20005332.png?alt=media" alt=""><figcaption><p>Figure 3 - Reference Architectures and Solution Enterprise Architectures<br>Source: Adapted from “IT Connect. Information technology tools and resources at the UW” (Univ. of Washington, 2020)</p></figcaption></figure>

Such re-use of existing solution experience will be enabled by continues update and development of PAERA in GovStack.

Utilizing EA practice, GovStack lays out a target reference architecture for national level, public administration level, and MDAs.

Finally, GovStack provides an implementation framework for the effective use of PAERA as defined in this document.

Metamodel of the reference architecture provided in the Annex 2.

#### Value proposition

Enterprise Architecture has traditionally been used as a tool to align business and technology domains. This is especially important during times of significant environmental changes, which often require new strategies.

Today, technology has the potential to revolutionize the internal operations of public administration organizations. This presents an extraordinary new opportunity that we want to leverage.

The current reference architecture document aims to unlock technology's potential to transform the process of creating public value using architectural and solution building blocks. This transformation can occur rapidly, generating local employment opportunities and revolutionizing entire societies.

In defining the PAERA approach, we want to highlight a few important aspects of the EA value proposition.

First aspect. When a customer with specific business requirements collaborates with a capable developer, they can often come up with a solution that works. In such cases, they may not require the assistance of an architect or architectural document. However, it may not be immediately apparent how well the solution will address requirements that are invisible to the business customer, such as maintainability, scalability, security, and so on. This is when architectural requirements and reference architecture become helpful.

Second aspect. Once a software system is created, it requires regular maintenance, as well as version upgrades annually and technology upgrades at least every decade for as long as the organization exists. If the software is not receiving updates regularly, let’s say at least once per year, and its technology is not entirely renovated at least every 7-8 years, then such software becomes a dangerous legacy, which poses a significant operational risk for the organization. Utilizing Building Blocks supported by independent open-source vendors who actively develop their products will enable the public sector to avoid falling into such legacy traps.

Third aspect. Digitalization of the public sector should not be narrowly seen as the automation of existing business processes. Instead, it should involve the creation of new operating models, with public administration customers at the center.

#### Specific Objectives of the Document

The Reference Architecture:

1. Tries to define specific national infrastructure components, which are foundational for more effective digitalization.
2. Defines a taxonomy of government entities aiming to define set of specific building blocks required for different types of organisations.
3. Provides a practical framework of decisions to be made and implementation activities to be planned by a public administration organisation for effective digital transformation.
4. Defines the context and boundaries of the public administration digital ecosystem.
5. Identifies key drivers of digital transformation in a typical public sector organisation.

## 2.4 What is Public Administration?

It is important to define the scope of the reference architecture. Here, we will provide a simplified view of the public sector and its organisational structure.

According to (A unitary state is a state governed as a single entity. There are no federal autonomous regions.), “Government units are unique kinds of legal entities established by political processes that have legislative, judicial, or executive authority over other institutional units within a given area. The principal economic functions of government units are to:

* Assume responsibility for the provision of goods and services to the community or individual households primarily on a nonmarket basis.
* Redistribute income and wealth by means of transfers.
* Engage primarily in nonmarket production.
* Finance their activities primarily out of taxation or other compulsory transfers.

A government unit may also finance a portion of its activities in a specific period by borrowing or by acquiring funds from sources other than compulsory transfers—for example, interest revenue, incidental sales of goods and services, or the rent of subsoil assets. All government units are part of the general government sector.”

From our perspective, the most crucial aspect of this definition is the funding from the public budget and the non-market nature of primary activities.\
Following is an example of how a unitary state defines its public sector (based on Digital Transformation and Public Services, Edited by Anthony Larsson and Robin Teigland, 2020 by Routledge).

<figure><img src="https://2983968174-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FWNaBkXRH5GkT1VCcv0BB%2Fuploads%2Fgit-blob-008748449c86a1de7771cb500c6f8af94f55638c%2FScreenshot%202024-05-29%20005746.png?alt=media" alt=""><figcaption><p>Figure 4 - Public sector units in a unitary system</p></figcaption></figure>

In a federal system, the Central Government represents the Federal Government, and an additional budgeting level will be added for federated states/counties. Local municipalities fall under specific states/counties, such as in the USA, Nigeria, India, etc. In this case, the diagram could be presented in the following way:

\\

<figure><img src="https://2983968174-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FWNaBkXRH5GkT1VCcv0BB%2Fuploads%2Fgit-blob-99bb9cb39af1984e8f8e0aa15b14d447d4d6bc58%2FScreenshot%202024-05-29%20005849.png?alt=media" alt=""><figcaption><p>Figure 5 - Federal country public administration</p></figcaption></figure>

In some countries, there are no state-provided social insurance schemes, which means there are no social insurance funds. However, in terms of digitalization, these differences are not important. At the end of the day, these are budget levels with pre-defined sets of responsibilities and revenue sources.

In smaller countries, there will be fewer independent budgetary levels and units. In larger countries, there may be more budget levels, some shared revenue allocations from one budgetary level to another, and more budget units. Otherwise, there are not many differences between bigger and smaller countries when it comes to the required building blocks for digital transformation.

**Government sector** – includes public sector entities that are not considered market producers and are financed mainly by compulsory payments made by entities belonging to other sectors. In a typical small or medium-sized country, the government sector is divided into three sub-sectors: central government, local governments and social insurance funds.

**Other public sector** – public sector companies that produce goods and services with the participation of the state and other government sector members (e.g. utility companies, strategic resource processing, etc.) and Central Bank.

**Central government** – state institutions belonging to the sub-sector of the central government (government institution, state institution managed by a government institution, county court, administrative court and district court); constitutional institutions (the Chancellery of the Parliament, the Chancellery of the President of the Republic, the National Audit Office, the Chancellery of the Chancellor of Justice and the Supreme Court) and the institutions in their administrative area; legal entities of the central government (a public legal entity defined as a central government unit, a foundation established by the state and a company with state participation).

**Local government** – the right, ability and obligation of the democratically formed authorities of a self-governing unit - municipality or city - to independently organize and manage local life on the basis of laws and the legitimate needs and interests of the residents of the municipality or city and taking into account the peculiarities of the development of the municipality or city.

A public service institution, or public authority, is an institution financed from the budget of the state or local government unit, whose task is to exercise public authority.

**Managed institution** – state institutions financed from the state budget, whose main task is not to exercise executive state power, but on the basis of the law, state institutions managed by government institutions can exercise executive state power. State institutions managed by government agencies belong under a ministry's jurisdiction.

The current reference architecture is applicable mainly to non-market activity units.

## 2.5 What is Digital Government?

A couple of important concepts still need to be defined for the clarity of our further discussion.

The term “digitization” entails the conversion of non-digital material (such as images, video, and/or text, etc.) into a digital format (Digital Transformation and Public Services, Edited by Anthony Larsson and Robin Teigland, 2020 by Routledge).

The term "digitalization" refers to the process of adopting or increasing the use of digital/computer technology, including mobile applications. This technology is usually implemented to establish a communication infrastructure that connects various activities and processes of the actor (Ibid).

The term "digital transformation" encompasses strategic business changes driven by customer needs, requiring extensive organizational change and the adoption of digital technologies. It involves multiple projects and requires organizations to effectively manage change. Essentially, digital transformation makes organizational change a core competency as the goal is to become customer-driven from end to end (Ibid).

#### **Digital Governance Model**

Several prerequisites need to be addressed before transformative projects can be targeted to achieve ambitious digital transformation objectives. These prerequisites rely on data flows and have strict dependencies on various building blocks. Digital transformation teams in any country should be aware of these preconditions, as they need to be addressed before one can successfully implement specific building blocks.

We will express the idea of those preconditions through the following metaphor. We say that Digital Governance can be seen as a building as follows:

<figure><img src="https://2983968174-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FWNaBkXRH5GkT1VCcv0BB%2Fuploads%2Fgit-blob-3caeabadc21b7e09c624e0c2a338c4396de1b56c%2FScreenshot%202024-05-29%20010249.png?alt=media" alt=""><figcaption><p>Figure 6 - Digital Governance Infrastructure Framework (Source: Ivar Tallo &#x26; Aare Lapõnin)</p></figcaption></figure>

While houses in different cultures can be quite different, the basic principles of their construction are similar. First, one needs to build the foundation. There are foundational cross-cutting issues of governance and policy — as well as legislative framework — that support the walls and pillars, which support the roof. Similarly, the framework is based on a causal sequence; one input causes other Digital Governance aspects to succeed. Such 'inputs' are called underlying conditions for Digital Governance.

From bottom to top level, we describe layers in the following way.

Digital Governance Infrastructure includes Foundation and National Level infrastructure.

#### **Foundation**

Foundation Frameworks, which consist of horizontal preconditions, meaning that they are applicable in any case.

1. **Legal frameworks** or applicable laws are necessary preconditions for different types of building blocks, and they are discussed later in Chapter 3. Technical solutions in the form of building blocks can usually only be implemented after there is a legal basis for them, and this usually goes outside the specific building blocks themselves.
2. **Governance & Policy frameworks** are also necessary to coordinate digitization efforts. While it is possible to develop one or another application autonomously, this approach is not cost-effective from the general development point of view.

#### **National Level**

The Digital Infrastructure Pillars are essential technical conditions for achieving goals. Completing them before developing functional applications in ministries and departments is often impossible, but at least they should be somehow addressed before pursuing wide and ambitious modernization goals.

1. **Access** in terms of connectivity of offices and citizenry seems to be a self-evident precondition, but we have brought it out here. After all, there are still a lot of situations where otherwise good projects die mysteriously after being successfully executed because either the people do not have the possibility or the habit of using the internet, or offices don’t have internet access or have it in a very limited way, making it very hard to be part of the digital data flows.
2. **Digital Data**, or rather the need to digitize data has been rising in importance as we started to talk about digital government, but it is a topic of a rather large scope that needs to be addressed by a multitude of specific efforts, found in different building blocks of the GovStack.
3. **Interoperability** is the ability of the government to exchange data inside and with the outside world and it requires a significant effort by any government to introduce. Different approaches to interoperability and its components are expressed in technical terms in the Enterprise Architecture framework, and introducing this requires any government a major effort and dedication, and support on the highest government levels.
4. The **Digital Identity** pillar describes efforts to create common semantics for the information government is collecting and allowing us to construct transactions in the virtual world by citizens and businesses as well as giving a legal protection to these transactions where necessary.

The governance and legal framework questions spanning different areas don't need to be explained separately. However, it is very important to provide examples of best practices and explain why they work.

#### **Pillars as Digital Infrastructure**

Pillars are crucial in constructing a strong foundation for a "digital house" and thus will be elaborated a bit more.

The first pillar, Access, is a fundamental requirement in today’s world and can take various forms, such as connectivity for offices and citizens. However, it may require specific attention based on the entities and regions, as something that may seem obvious in the country’s capital may not be the case just outside its boundaries. Without sufficient Access, other digitalization efforts are meaningless, as demonstrated by attempts to teach digital skills using traditional blackboards.

The second pillar or underlying condition is digital data. It is obvious but also a time-consuming and resource-hungry endeavour that cannot be resolved with just one straightforward project or GovStack building block. It requires both the overall framework development and the consideration of government-specific functions such as accounting for land, people, property, and activities.

The third pillar is interoperability. Once we have digital data, we need to be able to reuse it in different information systems to avoid repeating the same operations in various government departments. This requires planning for and introducing interoperability. Without interoperability, IT investments will be limited to simply automating existing processes, which will not bring any additional value to society. Value can only be created by redesigning old processes.

Finally, we need to be able to navigate the digital realm and prove our identity in the court of law, so we need a mature system for digital identity.

#### **Level of a Public Sector Organisation**

At the organizational level, successful digital transformation requires the presence of the following dynamic capabilities:

* **Management & Architecture** – The management of the organization understands the significance of digitalization and is capable of implementing the necessary change management to transition operations from paper-based processes to a completely digital operational environment. The IT personnel are capable of overseeing the overall architecture to ensure the sustainability of investments.
* **Digital Service Culture** – Transitioning from paper-based to digital service delivery requires a significant cultural shift within an organization. This shift is essential to ensure smooth adoption of new technologies and maximize the benefits of digital transformation. The organization should internally adapt to deliver services to customers in a fully digital manner, prioritizing customer satisfaction.
* **Data-driven Decisions** – An organization can make data-driven decisions when it can consolidate all available data, manage its quality and availability securely, and there is a management who is motivated to be data-driven on a daily basis.
* **Digital Co-creation** – Digital co-creation is a new concept. Traditionally, the government executed its mandates from behind tall walls of laws and professional public administration apparatus. In the digital era, a successful organization should be capable of sourcing digitalization initiatives within its local community of stakeholders and sharing the available data back to communities.

Also, we have to admit that successful digital transformation at the organizational level is nearly impossible without a mature Digital Governance Infrastructure.

#### **Public Reform & Governance**

There are many higher-level concepts that tend to attract decision-makers’ attention over the preconditions viewed as technical. Many donors and governments themselves view these higher levels of changes under the common umbrella of **Public Administration Reform (PAR)**.

However, as we already mentioned, constructing of a house, one does not start from the roof or windows. While the interest of decision-makers can be in providing various digital services or data-driven decisions (i.e., “doors” and “windows”), the reality is that one first needs to build the foundations and the “walls”.

### **Role of GovStack**

GovStack aims to ensure that partner countries are aware of the model of dependencies described above when approaching digitalisation initiatives.

## 2.6 Change management

#### **Continuous Process**

Change management deals with modernisation projects at organizational level. However, government-level concerns must also be addressed. These are often referred to as reforms arising from political debates. Digital Transformation – one of such reforms – should address the government's vision, policy statements, and legal changes.

The GovStack Approach can only be implemented within a systematic practice of Change Management both at government as well as organisational level:

* As foreseen in policies, national digital infrastructure capabilities are being planned and developed at central, regional, and municipal levels.
* Organisational capabilities are planned and developed in MDAs at all levels of a country's public sector.
* There is a practice to support implementation of projects from legal and administrative perspectives.
* Development of government internal IT capabilities to manage sustainable delivery of software solutions for digital services.

#### **Quality Attributes of the Process**

GovStack emphasizes that digital transformation will create a new digital public infrastructure (DPI) for the upcoming digital era. It is crucial to ensure that while developing DPI, both the outcomes and the process are clearly defined, with a focus on reflecting public needs. To achieve this, the process must meet specific requirements, which can be illustrated as follows (Source: \[8]):

<figure><img src="https://2983968174-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FWNaBkXRH5GkT1VCcv0BB%2Fuploads%2Fgit-blob-b46a26c2fcee3ef0ddb082a36bf050c061f436c0%2FScreenshot%202024-05-29%20010729.png?alt=media" alt=""><figcaption><p>Figure 7 - Requirements for Digital transformation process (Source: [8]).</p></figcaption></figure>

**Purpose and Directionality**. In a "common good" framework, two critical capabilities are setting directionality and orchestrating the process. There is a growing trend of desiring more explicit directionality in building shared digital infrastructure. DPI is not neutral and shapes what can be built on top of it. Therefore, it is crucial to make the nature of directionality explicit and prioritise it.

One case in which purpose and directionality are made explicit in DPI is India’s identity system, Aadhaar. To the Indian government, the main reason for establishing residents’ identity was to simplify the distribution of welfare benefits (including direct cash transfers, subsidised food, cooking gas and other benefits). The government feared that a substantial portion of those benefits was being wasted due to fraud and corruption. Building a system to identify an individual uniquely was paramount to prevent fraud and improve the targeting of social benefits. Directionality simplified scaling and KYC compliance for banking and telecommunications and prevented welfare benefit leakage.

In contrast to the Indian case, the digital identity system in Jamaica was not built with an explicit, primary purpose in mind. Initially, the Jamaican government declared an interest in building an ID system but did not link it to a primary policy purpose. This allowed others to imagine the ID’s purpose, fostering the distrust of civil society actors, who were suspicious of the government’s intentions. It was also a wasted opportunity, as the government did not focus on developing a programme or application that would benefit its citizens.

**Co-creation and participation**. The common good stresses collaboration, coordination, and co-investment among different entities. Co-creation and participation should be integral to the governance process. Institutional mechanisms should be established for collaboration around DPI. Participation around proprietary technologies is challenging.

A good example of successful co-creation is Brazil's Pix, a new instant payment scheme launched in November 2020 by Brazil's Central Bank. It allows citizens, companies, and government entities to transfer payments quickly and easily, even on non-business days. The team behind Pix understood the importance of involving society in the development process and breaking away from traditional practices of working in silos. This led to the creation of the Pix Forum, a collaborative governance practice that brought together more than 130 representatives from various societal groups, including banks, fintechs, civil society organizations, and small business associations. The team processed feedback from all participants, which was a challenging but necessary step towards the success of the project. The Pix Forum's co-creative process was instrumental in developing a solution that was user-centric and met the needs of society.

**Collective learning and knowledge-sharing**. Learning from each other's successes and failures and encouraging knowledge-sharing and collective intelligence is crucial for collective value creation. Institutionalized learning and knowledge accumulation can create long-term state capacities. Innovative institutional examples can facilitate collective learning.

One example is Bangladesh’s Aspire to Innovate (a2i) programme, whose goal is to ‘drive collaborative digital innovation for the public good. In practice, it serves as a think tank inside the government, focused on technology projects that are geared towards helping the country achieve the SDGs. The programme is an arrangement that allows the government to integrate inputs from, and collaborate with, civil society groups. More importantly, the model provides lessons to the DPG ecosystem in Bangladesh by demonstrating the capacities and talents needed to support the maintenance of digital public goods.

Encourage collective learning with DPI by incentivizing open-source software and communities of code led by digital public goods enthusiasts. External contributors are key for effective learning. Here is a good example.

MOSIP is a solution that helps countries to implement open-source identity systems. It offers an open approach to contributors, which means that they can introduce new features or fix bugs, covering a spectrum of tasks, from requirements and design to coding, testing, and documentation. While some components are closely governed with limited room for external input, to avoid adopters bypassing the safety and do-no-harm mechanisms built into the technology, other components are more open to external contributions. This comprehensive approach strengthens the system, establishing clear pathways for contribution while adhering to submission and reporting guidelines.

**Access for all and reward-sharing**. Universal access and reward sharing are crucial to the concept of the 'common good' in policymaking. If an infrastructure benefits everyone, it must be accessible to all, and its benefits must be shared with society. Governments prioritize access and inclusion over market pricing and rent extraction. Physical infrastructure has been essential for social and economic development for 10,000 years. Digital access must be ensured through analogue means since waiting for universal internet access burdens citizens.

A few countries have explored creative solutions to analogue access. In Bangladesh, DPI was expanded to include an additional ‘access layer’, which turns DPI into a “phygital” public infrastructure’ (Chowdhury 2023). The access layer encompasses physical locations and call centres, improving DPI’s accessibility for individuals with disabilities and those in underserved communities in remote rural areas. Bangladesh’s over 9000 digital centres (also known as one-stop shops), widely spread at an average of 4km from a person’s house, are run by young local entrepreneurs (a third of whom are women). These public-private partnerships guarantee that government services reach the grassroots level.

The city of Barcelona has been working on implementing reward-sharing mechanisms for Data Privacy Impact. After Mayor Ada Colau was elected, the city's government established a "new data deal" agenda to encourage the use of corporate-controlled data for improving public services while also ensuring citizens have control over their data. The government also reviewed its procurement processes and regulations to ensure that the value extracted from data is not privatized but shared with the public instead. To achieve this goal, the city introduced "data sovereignty" clauses, which give the city the right to acquire data collected through or about public services and some private sector data that is associated with the public interest, such as geolocation and data from ride-mobility operators. This example demonstrates that procurement rules, in addition to regulations, can be powerful policy instruments for the common good.

**Transparency and accountability**. Public sector organisations leading or managing a DPI implementation need transparency and accountability to win trust. DPI’s decentralised architecture poses accountability challenges across government departments and levels of government. Although accountability is more challenging, DPI has the potential to improve transparency.

The more systems are integrated, the more digital footprints can be leveraged for transparency. One well-known example is Estonia’s e-health portal, which allows citizens to see who has accessed their data and when. The city of Barcelona, as mentioned previously, also worked on giving citizens more transparency about how private companies used their data.

One of the ways these objectives were achieved was through using an open-source data-sharing infrastructure, enabling citizens to control their data as a common good and to share them on terms that are fair, transparent and accountable.

Transparency alone cannot ensure accountability and trust. User-friendly data interaction is necessary to maintain trust and accountability, as the effect of transparency on trust can be neutral or negative if not operationalized properly.

#### **Business & IT alignment**

The key to our approach is acknowledging the different viewpoints and communication styles of various stakeholders. We are often trained to see things from a specific perspective and communicate within our own professional groups.

For example, in the public sector, having a legal basis is a fundamental requirement for governance practitioners. However, for IT professionals, it is just one of the many conditions that need to be addressed. Additionally, the language used in IT systems is based on "0" and "1", "either" / "or", while top management tends to see a broader spectrum of options. It can be challenging to reconcile these different approaches, especially when both groups use the same terminology with different meanings.

Throughout this document, we provide relevant examples and warnings to help readers understand stakeholders, their motivations, and guidance to ensure the success of their digitization efforts.

\\


# 3. National Level

## 3.1 Governance & Policy

### 3.1.1 Needs for Governance

Over the past three decades, there have been numerous attempts to integrate information and communications technologies (ICTs) into government operations and services, especially since the widespread availability of low-cost personal computers since the 1990s. This drive towards digitization of government has had many labels over the last three decades, from online government to paperless government to e-governance and m-government, to name just a few.

Today, the use of new technologies in public administration is known as digital government. This refers to digitizing all government data and relying heavily on information infrastructure and digitalized information flows in all stages of almost any process. At the same time, a new term of “post-digital era” has come into use.

However, it is essential to distinguish between high-level digitalization strategies that outline general goals, and more tactical infrastructure-oriented digitization plans. Tactical digitization initiatives need to be situated within wider governance reform processes.

Merely buying technology does not guarantee improved governance. To be able to transform services digitally in a useful and sustainable manner it is essential to be able to incorporate technology into daily administrative procedures and decision-making. Without these abilities, a digital development plan will not produce the anticipated outcomes or have a significant impact. Set of such capabilities we will also refer to also as a **digital culture**.

Creating digital public service delivery through a GovStack approach requires necessary foundational elements like governance frameworks, legal frameworks, and advanced technologies and software. However, developing a digital culture amongst people creating and using these systems is even more critical.

If civil servants do not recognize the importance of utilizing data-driven insights, discussing the concept of smart government or evidence-based governance may be premature. It is necessary to have a basic level of technology adoption before building systems that leverage sophisticated AI-based solutions. Once people understand the value of the internet and data accessibility, it paves the way for further development without any roadblocks.

In situations where the necessary prerequisites are absent, it is essential to cultivate an environment that promotes the growth of digital culture. This cannot be achieved through high-level strategy papers alone, and instead requires civil servants to habitually use new technologies in meaningful ways. For instance, digitalized document management systems should be employed in the day-to-day activities of every given office in a country public sector.

When faced with obstacles such as lack of internet access or delays in obtaining logins, it is critical to maintain internal momentum and demand for change rather than allow civil servants to revert to their previous habits of conducting business.

When thinking about governance, one needs to remember some general principles that have been proven over time:

1. There is the need for political leadership. Substantial changes in national and organisational levels need political support expressed through words and budget allocations.
2. Changes start to happen when dedicated people and structures make them happen, they collect, keep, and develop the knowledge of digital developments. There is no single recipe for successful digitization drive, however, a dedicated agency with coordination role is an essential ingredient for successful effort.
3. It is crucial to understand that governments should refrain from prioritizing building their solutions in-house by arguing that they know what is best for their situation. A government's primary responsibility is to lead. Civil servants should be intelligent purchasers, not IT specialists, except for a few individuals responsible for maintaining the overall data and software architecture.
4. One should also underline the positive role of high-level policies in ensuring the processes run smoothly and guiding the development of organizational-level solutions.
5. It is recommended that a country have an empowered CIO office that systematically develops a digital culture in the public sector.

### 3.1.2 Transforming Governance

Building digital government capabilities is a gradual, step-by-step process rather than a one-time project. The process of cultivating right governance, building legal framework, developing infrastructure and skills must be assessed and subsequently strengthened before attempting large-scale digitization or service delivery reforms.

In a nutshell, governance-related issues that affect digitalization in a country can be identified by four distinct indicators:

1. **Bad governance choices resulting in extreme centralization in the hope of effective use of qualified human resources** - The creation of services or even homepages for Ministries is sometimes outside the competency of any given Ministry. Instead, it is delegated to the Cabinet of Ministers responsible unit.
2. **Politics prevails over development logic**. It is quite understandable that politics has a different logic and calendar, and it has to be accommodated. However, there is a need for overall awareness of the meaning and lack of data in governance processes and what needs to be done to achieve this.
3. **Prevalence of paper-based culture in offices** – public officials in some countries are used to working in the mess of paper trails that enables them to hide mistakes and provide avenues for corruption. Multiple interests always need to be navigated to have the GovStack building blocks meaningfully situated in the overall processes of digitalization.
4. **Security-centric approach** – In many countries, institutions focused on security have control over digitalization, and as a consequence, they often limit data sharing while imposing aspects of surveillance on systems that are meant to uphold participation and democratic decision-making.

These governance issues must be addressed to force digitization on MDA managers. That will lead to better adoption and success of a digital strategy.

#### **Digital Culture**

The main goal of the digitalization strategy is to cultivate a digital culture. This involves creating a meaningful work environment incorporating IT development and everyday usage. By doing so, demand for digitization will grow organically, enabling centralized proposals to be implemented successfully and minimizing the risk of process failures.

Political will should drive practical actions that guide daily decisions and escalate unresolved issues. Maintaining political support for digitalization is important for the overall success of the project.

Various strategies and tactics exist for managing change, but the toughest challenge is making people aware of the importance of data. Simply stating that "data is crucial for decision-making" or “data is the new oil” is not sufficient. Instead, processes must be established that highlight the significance of data.

Where there is a will, there is a way. Therefore, political will to support digital transformation is the most important aspect of the readiness assessment. We should not forget that oil in the ground becomes valuable only if there is an infrastructure in place to pump it out, refine, and sell it.

#### **Institutional Framework**

The most effective way to manage the technical aspects of digital government is through a whole-of-government approach with centralized coordination of decentralized key initiatives, considering political realities and regulatory frameworks. Various organizational solutions have proven effective, and the following is a brief overview of some of them.

<details>

<summary>Digitalization Ministry vs Digitalization Agency under the Cabinet of Ministers</summary>

Usually, the digitization drive has to emanate in the close proximity to the head of executive power, so the successful cases are Digitization Ministries as in this case they have representation in the form of their own minister. If digitalization is charged to be led by an agency, its power can be measured in its distance from the top executive and the closer, the more chance it has to influence the governance processes and get things done.

</details>

<details>

<summary>Digitalization Committee</summary>

To overcome the challenge of multidimensional nature of digitization, one of the working solutions, deployed often, are Digitization Committees, consisting of key Ministers. Such committees meet to decide the funding issues and make recommendations to the Cabinet or the Chief Executive. Usually, they are also initiating and approving new policies and larger digitization projects.

</details>

<details>

<summary>Digital officers in Ministries</summary>

Digital has become such a big part of the administration that it cannot be handled alone on the level of technical people in IT departments alone. The whole topic has to be coordinated on the political/decision making level and the best way to either everybody getting proficient understanding and using the principles of digital governance or as a minimum have somebody with this function to advise the office how to integrate the digitalization into the everyday administrative practices.

</details>

#### **Transformation Strategy**

Conduct assessments to find gaps in legal frameworks, institutional capacity, infrastructure, and skills that need to be addressed.

Start building a solid digital foundation by

1. strengthening laws that allow for digital governance,
2. improving IT infrastructure,
3. establishing interoperability standards,
4. governing data effectively, and
5. enhancing cybersecurity.

A digital transformation governance framework should have:

* strong leadership,
* comprehensive strategies,
* policies & standards, and
* coordination mechanisms across the government.

### 3.1.3 Readiness Assessment

Successful implementation of digital transformation efforts requires joint identification and mitigation of risks while building new capabilities where feasible.

It takes time to develop digital culture capabilities, which grow through a series of successes. Therefore, it's important to assess a country's level of digital transformation maturity.

When we examine the environment from a technical standpoint, there are clear indicators of low digitalization process maturity:

1. Lack of sufficient connectivity.
2. Lack of integrated IT systems in government entities.
3. Lack of digital data.
4. Lack of a wider legal framework for digital processing.
5. Absence of digital payments (i.e., using a bank account or mobile money or CBDC or similar).
6. Absence of national authentication infrastructure and digital signature.
7. Lack of IT literate workforce that can support digital operations.

You should regularly conduct detailed assessments of these and many other indicators to obtain valuable insights for digital strategies and a practical approach to digital transformation.

The key is to recognize that building digital government infrastructure is a long-term, adaptive change process rather than a fixed end state. Regular assessment of maturity levels, gaps, and dependencies provides a crucial perspective. Building progressively from one capability level to the next sustains meaningful and lasting digital transformation.

## 3.2 Legal Framework

### **3.2.1 Principles**

Establishing digital governance requires adapting legal frameworks for digital data flows across public and private sectors to enable secure e-government and e-business.

Foundational regulations organizing digital data flows and creating necessary preconditions for government action in digital service provision like e-signature laws, data protection, and cybersecurity standards provide validity, privacy, and security for online transactions and allow the protection of foundational governance principles in the court of law.

Laws and policies promoting user-friendly digital interfaces between citizens and government systems are needed for transparent and efficient e-services. Also, you have to recognize the primacy of electronic documents and transactions. However, the shift from paper documents to digital-only processing can be challenging. Enabling the primacy of digital records is a key issue that every country needs to address.

Carefully adapted laws aligned with overarching e-government goals are needed for societal digital transformation. Regulations should be flexible enough to accommodate emerging technologies and facilitate sustainable, future-proof digital governance.

Digital government regulations should also embed a few fundamental digital society principles to align governance with user needs and societal goals:

* The '**once-only**' principle means citizens and businesses provide data only once to the government, enabled by interconnected databases and digital ID laws.
* '**Digital by default**' makes online services the primary channel, facilitated by recognizing electronic transactions.
* '**No legacy policy**' involves not digitizing legacy paperwork but reengineering processes for digital optimization as well as keeping systems and technology platforms up to date, thus enforcing security by design concept.
* **Openness** and transparency principles require updated access to information and data protection laws.
* **Privacy** regulations (e.g. GDPR) ensure confidentiality in digital systems.
* **Human rights in the Digital Era** for all population groups, as a fundamental starting point, ensuring that human rights apply online as they apply offline. This creates conditions for reducing abuse by the government, equitable distribution of benefits, and the realization of fundamental human rights in the digital era through the use of digital government without discrimination.

Overall, e-government legislation should institutionalize such principles to drive simplified, user-centric digital services focused on value creation rather than technology per se. Embedding principles in the legal framework creates obligations and incentives for administrators to apply them in practice. Regulatory guidelines can also recommend interpreting principles when implementing digital governance initiatives.

Also, focusing on general regulation and technology neutrality principles when implementing legal reforms is better than overly specializing in e-government legislation. This approach allows for a more integrated and innovative digital governance that prioritizes user needs over specific technologies. It also ensures the realization of human rights in the digital era for all individuals residing within the state's territory, including citizens, stateless persons, foreign nationals, refugees, and other categories of individuals.

### 3.2.2 Process

Here are key regulation process attributes to apply for developing good digital governance regulatory frameworks:

* Consultation - Consult relevant stakeholders like government agencies, the private sector, civil society groups, and citizens when drafting regulations.
* Transparency - Make the regulatory processes and decisions openly accessible and clearly communicated.
* Evidence-based - Develop regulations based on a rigorous assessment of available data, research and impact evaluations.
* Risk-based approach - Prioritize addressing real-world risks and challenges through regulations.
* Future-proofing - Build adaptability for regulations to accommodate emerging technologies and changing contexts.
* Technology neutrality - Focus regulations on desired objectives rather than specific technologies which keep changing.
* Accountability - Clearly define institutional mandates, roles and responsibilities for implementing regulations.
* Review mechanisms - Build systematic processes to periodically review, evaluate and update regulations.
* Proportionality - Balance regulatory costs and burden against expected public benefits.
* Outcome orientation - Structure regulations towards achieving real-world impacts and goals.
* Gradual building of Compliance - Support regulated entities in understanding and complying with regulations.

### **3.2.3 Roadmap**

The digital transformation process in government differs from that in the private sector, mainly due to the requirement for a legal basis for all government activities. While government policy documents can provide some guiding principles, it's crucial to establish them in legal text, which is the law.

There are several ways to approach this and clearly, only some of the laws are necessary for all the parts of GovStack components to be implemented successfully. For the ease of understanding, we have grouped them here in general topics. The ways the laws are drafted depends on a given country’s legal traditions; thus, it is impossible to list them by titles and provide ready-made texts. However, some of the laws that are expressing well debated technical solutions can be almost copied from best examples around the world and for some, similar countries can orient their own law drafting to the experience of others.

In the sake of clarity, we have followed the necessary functions of government that wants to become digital in the groupings in the legal toolbox. The titles can vary and the content as well, but these functions should be offered legal basis for the overall success of digitalization.

Fundamental legal norms established in the forms of domestic and international law in the sphere of human rights in the digital era and human rights:

* Universal international legal treaties, principles, and customs concerning human rights and human rights in the digital era.
* Regional international legal treaties, principles, and customs concerning human rights and human rights in the digital era.
* National constitutional acts that enshrine basic human rights and human rights in the digital era (for example, in Estonia, access to the Internet is considered a human right), establishing basic rights to not only access the internet but also access to modern digital technologies of Industry 4.0 and their benefits.
* Federal constitutional laws that enshrine basic human rights and human rights in the digital era.
* Federal laws (including Codes, Foundations of Legislation, Laws on Ratification and Denunciation of International Treaties) that enshrine basic human rights and human rights in the digital era.
* Subordinate legislation: 1) Decrees of the head of state as provided by the Constitution or other fundamental national documents; 2) Government resolutions; 3) Departmental acts; 4) Acts of executive authorities of federal subjects.

1. Foundational laws enabling e-governance ( T. Kerikmäe (ed.), Regulating eTechnologies in the European Union, DOI 10.1007/978-3-319-08117-5\_3: e-Governance in Law and by Law, The Legal Framework of e-Governance by Katrin Nyman-Metcalf (as basis of)) and digital data flows:
   1. Legal framework recognizing electronic documents, signatures, and transactions as valid and binding, such as e-signature laws
   2. Laws enabling digital identification methods for individuals/businesses to securely interact with government online
   3. Legal recognition of electronic transactions, payments, billing and invoicing
2. Privacy, security, and risk management:
   1. Data protection and privacy laws regulating collection, storage, use and sharing of personal data, including in interconnected databases
   2. Cybersecurity laws setting standards for protection of government IT systems and data
   3. Intellectual property regulations for government data and digital services
3. Openness, transparency, and access:
   1. Access to information/freedom of information laws facilitating proactive disclosure and access to government data and documents
   2. Regulations on use of emerging technologies like artificial intelligence, cloud computing, and blockchain in government
4. Institutional organization, standards, and oversight:
   1. Organizational and institutional mandates clarifying roles, responsibilities, and oversight for e-governance initiatives
   2. Interoperability frameworks and open standards to allow connectivity between government IT systems
   3. Competition regulations adapted for e-government public-private partnerships
5. Digital service delivery:
   1. Administrative laws and procedures adapted for electronic administrative processes and digital service delivery
   2. Laws on digital archiving and records management for electronic documents and data
   3. Rules for electronic procurement, tendering and contracting
   4. Laws facilitating electronic voting and other e-democracy initiatives, where applicable

## 3.3 Digital Infrastructure

### 3.3.1 Overview

Digital transformation of the public sector should enable better user experience and reliable legal digital transactions. For secure and resilient delivery of public digital services, a certain level of Digital Government Infrastructure should already be in place (for details, see section 2.5 above):

<figure><img src="https://2983968174-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FWNaBkXRH5GkT1VCcv0BB%2Fuploads%2Fgit-blob-4f4b9e400d57761414251055b5cc462ca8298bcb%2Fimage.png?alt=media" alt=""><figcaption><p>Figure 8 - Digital Governance Model (Source: Ivar Tallo &#x26; Aare Lapõnin)</p></figcaption></figure>

Digital Governance Infrastructure consists of a Foundation Framework Digital Infrastructure Pillars.

Foundation Framework contains:

* governance,
* policy, and
* legal components.

Four Digital Infrastructure Pillars such as

* Access
* Digital Data
* Interoperability
* Digital Identity

Following is description of required level of maturity for those components to enable digital transformation of public sector.

### 3.3.2 Principles & Policies

The digital governance policy should focus on to national coordination, capacity building, data and technology governance, iterative piloting, and stakeholder engagement for digital transformation.

#### General guidelines

Following are key recommendations from international for digital government policy frameworks:

* Develop a national digital or e-government strategy with vision, priorities, and implementation roadmap (EU, OECD, ADB, UNDP)
* Establish centralized coordination of digital government efforts (EU, OECD, WB)
* Develop policies and standards for digital services, data, shared platforms, interoperability, and cybersecurity (EU, OECD, WB)
* Institute governance frameworks specifying institutional roles and responsibilities (OECD, WB)
* Develop national laws or amend existing ones (including constitutions) to incorporate human rights in the digital era, such as access to the internet and Industry 4.0 technologies, as well as the benefits derived from such technologies, into digital or e-government strategies.
* Develop digital capabilities and skills within government (EU, OECD, WB)
* Pursue public-private partnerships and engagement with startup ecosystems (EU, OECD, WB)
* Develop guidelines for use of emerging technologies like AI in the public sector (OECD)
* Leverage digital technologies at all stages of policymaking (OECD)
* Undertake piloting and iteration in digital government innovations (UNDP, WB)
* Develop guidelines for digital procurement and platform business models (WB)
* Promote whole-of-government and government-as-a-platform approaches (EU, WB)
* Develop legislation for digital identity, data protection, cybersecurity etc. (EU, WB)
* Commit to principles of openness, transparency, and public participation (UNDP, OECD)
* Continuously evaluate policies and update based on latest trends and feedback (ADB)

#### Principles

Regulations and policies should adhere to the following principles:

1. Rule of law based on the priority of human rights and the SDG set by the United Nations. The rule of law is a fundamental governance concept that pertains to the idea that everyone, including individuals, institutions, and governments, is subject to the law and accountable under it. In modern terms, this means that a state should be governed by a system of international and domestic law rather than arbitrary decisions or whims of those in power. In this context, the law should be understood as a system of principles and norms aimed at realising human rights, particularly human rights in the digital era, shaping a human-centred state, eliminating barriers that may arise with new technologies and minimising state abuses. A modern digital state should be human-centric. Legal regulation of the digital environment related to human rights will ensure that technologies serve the benefit of every individual, enhance trust in digital service systems among the population, and minimise abuses (for example, excessive data collection, discrimination, and human rights violations). This will increase public engagement in state development and enhance trust in the system.
2. Whole of government - The principle refers to an approach in governance where all government agencies, departments, and ministries work collaboratively and cohesively towards achieving common goals and objectives. This approach recognises that many complex issues and challenges societies face require coordinated efforts across different sectors and levels of government. Systems and services should interoperate by design to deliver integrated services across agencies.
3. Digital by Default - Public services should be delivered digitally as preferred. Traditional channels remain available, but digital should be primary.
4. No-legacy - rethinking and redesigning processes from scratch to take full advantage of technology and be "digital native".
5. Once Only - Citizens and businesses should only have to provide information to the government once. Data should be reusable across agencies. Public organisations should share information proactively. Processes and decision-making should be transparent.
6. User-Centric Government - Services should be designed around user needs and experience. Governments should adopt an outside-in perspective.
7. Natural Digital Environment - Public administration should aim to deliver digital services directly to customers' natural digital environment.
8. Public and Private Sector Co-creation – Public administration should engage the private sector in the process of co-creation of public sector digital services on a beneficial private sector basis.
9. Cross-Border by Default - Services should cater to citizens' needs regardless of location.
10. Intrinsic Security & Privacy - Security and privacy should be embedded into systems immediately, not as an afterthought.

#### Policies

Policies are a great way for the government to communicate their goals in a way that everyone can understand, as opposed to using legal language in legislation which can be difficult to comprehend.

Policies introduce new concepts and provide context to help explain them. While there can be many different policies, there are a few that are essential for successful digitization efforts.

<details>

<summary>Digitalization policy</summary>

Summarizing the dynamics of digitization drive of the government, the major responsibilities and expectations the government has vis-a-vis the initiative its entities toward digitization, what citizens, government and society at large can expect to be achieved if this direction is upheld. It also usually caters to access questions and formulates overall goals for other policies like once-only for services and creation of a digital data ecosystem.

</details>

<details>

<summary>Policies</summary>

Policies are a great way for the government to communicate their goals in a way that everyone can understand, as opposed to using legal language in legislation which can be difficult to comprehend.

Policies introduce new concepts and provide context to help explain them. While there can be many different policies, there are a few that are essential for successful digitization efforts.

**Digitalization policy**

Summarizing the dynamics of digitization drive of the government, the major responsibilities and expectations the government has vis-a-vis the initiative its entities toward digitization, what citizens, government and society at large can expect to be achieved if this direction is upheld. It also usually caters to access questions and formulates overall goals for other policies like once-only for services and creation of a digital data ecosystem.

**Digital services policy**

The efforts of directing/doing all services from one office have shown not to work too well, the business processes are simply too different. However, there should be harmonization of efforts, so primary suggestions as user centricity or once only or multichannel approach, etc could be put forward and explained in that type of policy.

**Data Policy**

Data Policy’s prime purpose for the government is to move from analogue to digital mode of operation and to establish the primacy of digital data over paper-based records. For that to happen, there must be a shift to trust the data in government databases. Government has to establish the precise rules for the databases and registers, how they are created, who can run them on behalf of the government and how the data is collected and kept in the digital age. One of the hardest debates in any government is how different data is priced and who has the right to use it.

**Data protection policy**

Data protection topic is treated differently in different cultures. However, the basic substantive principles as well as the way they are approached are quite similar. If there is no data protection legislation yet or if there is some 15-20 years old law, it would make sense first to articulate the current demands coming from digitalization drive as opposed to traditional treatment from the time when personal data protection was more concerned with potential government violations as opposed to current public-private interactions, private sector data protection issues, cross border data flows, and technical ways of addressing variety of data protection concerns and political concerns that come from the desire of the private companies to participate in large markets like the EU Common Market where there are strict data protection rules in force and these rules are applicable to all outside participants also.

**Cyber security policy**

Cyber security has evolved over the last 15 years from a niche exercise into one of the most critical areas of digital activities. When any country is embracing digital journey seriously, there is a need for basic statements of intention on cyber security. It is necessary to situate the cyber security activities into the overall digitization effort and as stated above, find a logical timeline to deal with these issues. First, if digitalization is still in the initial stages, cyber security concerns can be kept in mind but no serious budgetary claims to this area should be honoured. Second, there is a need to situate the cyber security concerns in government structures correctly.

There are usually three types of claims made by different participants to own these processes. First, there is the question of network protection issues that are typically addressed with CERT/CSIRT type of organizations whether private or public. Second, there are traditional issues of physical network protection and how to best accomplish this, whether and to what extent a government needs to use private networks or could they utilize public networks and protect only data belonging to the government. Third, there are concerns about critical information infrastructure protection. They appear when governments start to rely on their functions to the

So traditionally there are three parties interested in taking lead: security organisations, defence organisations and digital/economy ministries. The cyber security policy needs to sort out how the given government wants to approach these topics.

**IT procurement policy**

IT procurement needs are different from those of finite goods or services as there is constant technological development and procurement should support the development needs of the administration when formally the rules have to prevent different forms of corruption. The development of some IT elements, like interoperability platforms could take years. At the same time, IT developments are path dependent, I.e., if there is a choice of certain products, it is difficult to switch to alternative products and one has to be aware of the problems that these features cause in the overall development process and how to address them.

</details>

<details>

<summary>Digital services policy</summary>

The efforts of directing/doing all services from one office have shown not to work too well, the business processes are simply too different. However, there should be harmonization of efforts, so primary suggestions as user centricity or once only or multichannel approach, etc could be put forward and explained in that type of policy.

</details>

### 3.3.3 Building Infrastructure

#### **Whole-of-Government**

The SDG Digital Investment Framework offers a comprehensive approach to help organizations break down silos from a technical perspective. This cross-government view allows for a methodical approach to making digital investments. The framework provides a compelling rationale for enterprise planning and funding reusable platforms, registries, workflows, and policies.

This approach shifts traditional silo-based thinking and investments, enabling a citizen-centric and whole-of-government digital transformation. It's important to identify shared services, workflows, and data to meet the needs of multiple agencies and sectors, consolidating duplicated services and eliminating duplicate data through interoperability.

The working environment of government organizations differs significantly from that of private enterprises. In government agencies, decision-making is often guided by political considerations, complex hierarchical structures, and various relationships, unlike in private companies. Thus, resolving competency and responsibility issues is usually more critical than ensuring technological solutions are appropriately aligned. That is why the whole-of-government approach often encounters substantial opposition and challenges.

#### **Chicken-egg problem**

It takes time to implement the comprehensive set of preconditions. You may face the chicken-and-egg issue: why would someone invest in Digital ID, for example, when there are no digital services available? In ministries and departments, you cannot build personalized services without universal national digital identification capacity. What can be done about this?

It is therefore a good idea to use a two-tier approach:

* Target the foundational elements.
* Make some quick wins that help demonstrate the benefits of the chosen path to both political leaders and the public.

The incremental building of capabilities and digital readiness allows for managing the complexities of digital transformation.

The pragmatic approach will first focus on improving connectivity, instituting IT management capacity, and nurturing digital culture within government organizations.

Once the basic infrastructure is in place, introducing digital document and data management systems should catalyze the initial shift away from paper-based processes.

With the initial foundation solidified, the next stage should involve:

* digitizing public sector back-office operations and transactions, i.e., pursuing quick-win projects early on to demonstrate tangible benefits and impact, building momentum for more significant initiatives (priority use cases).
* delivering omnichannel self-services focused on user needs, and
* developing data management platforms to support decision-making processes, i.e., digitizing existing processes and transactions to enable digital delivery of high-volume citizen-government interactions. If most of the data is in traditional paper format, digitizing existing paper-based documents in use is necessary.
* Develop basic national digital infrastructure standard services like digital ID, payments, and legal data registries.

#### **Transforming Services**

Use user-centered service design principles to transform public services around user needs for an integrated omnichannel experience.

Build skills and culture for user-centric governance through extensive training programs, especially retraining public servants.

When undertaking reforms, manage change through stakeholder engagement, communication, and participatory approaches.

**Manage Data**

Today, it is widely recognized that organizational data is an important asset. Data and information can provide insights into customers, quality, needs, and services, which can help organizations innovate and achieve their strategic goals. Despite this recognition, only a few organizations take steps to consolidate all available data and use it actively on a daily basis.

Deriving value from data requires intention, planning, coordination, and commitment. It requires data management. An organisation should establish data management, i.e., the development, execution, and supervision of plans, policies, programs, and practices that deliver, control, protect, and enhance the value of data and information assets through their lifecycles.

**Driving Adoption**

Build, test, and refine digital services using an agile, iterative approach based on continuous user feedback and data insights.

Collaborate with the private sector and civil society via partnerships, hackathons, and open government data initiatives to drive co-creation and adoption.

Review progress periodically, share lessons across government, and update strategies based on the latest trends.

#### **Sustaining Innovation**

Pursue a whole-of-government approach to digitalization for integrated services across agencies but allow flexibility for contexts of different departments.

Institutionalise mechanisms for periodic reviews and incremental improvements in policies, regulations, and technologies.

Share best practices across government and with other countries to sustain continuous innovation as technologies evolve.

Also, to some degree, "allow to fail" is important. You learn from failed projects. If you always fear failure, you will probably never do anything at all.

## 3.4 Foundational Pillars

### 3.4.1 Access

#### **Example of electricity**

William Gilbert's book, De Magnete, published in 1600, distinguished between the lodestone effect and static electricity produced by rubbing amber. He coined the word electricus, which led to the creation of the English words "electric" and "electricity." Only, during the late 19th century, notable individuals, such as Alexander Graham Bell, Thomas Edison, Nikola Tesla, and George Westinghouse, made significant contributions to electrical engineering, transforming electricity from a scientific curiosity into a crucial tool for modern life. Electric lighting became common only in the early 20th century.

It took 300 years to develop and make accessible an alternative to candles for people. We must ensure that digital services become available to everyone within a **much shorter period**.

Enabling nationwide access to digital services needs a holistic approach that simultaneously addresses infrastructure, education, policy, and societal requirements.

Here are the main components needed for that.

**Infrastructure**

Reliable electricity is a prerequisite for digital services. Therefore, improving the electrical grid and exploring renewable options like solar power can be crucial.

Invest in broadband infrastructure to provide high-speed internet access across urban, rural, and remote areas.

Enhance mobile network coverage to include 4G/5G technologies to ensure widespread internet access. This could involve using satellite connections, mobile broadband, or other technologies suited to remote regions.

Affordability can be improved by providing subsidies or affordable plans for low-income households to access digital services and by offering incentives to internet service providers to extend services to less profitable areas.

#### **Education**

Digital literacy and education are crucial enablers for the digital transformation. To promote digital education and awareness, the following steps can be taken:

* Training Programs: National digital literacy programs can be implemented to educate people about the benefits of digital services.
* School Curriculum: The younger generation can be made digitally literate by integrating digital skills training into the school curriculum.
* Awareness: To encourage adoption, run promotional campaigns and provide assistance and incentives for transition to digital platforms.
* Socio-economic barriers: identify and address inequality by reducing socio-economic disparities that may hinder access to digital services.
* Internet Kiosks: set up community internet access points or digital kiosks in areas with low private home access.

**Policy**

It is crucial to build human capacity in ICTs through education, infrastructure development, and international internet bandwidth expansion.

To establish inclusive and transparent digital transformation governance, you need to:

1. Establish a centralised authority responsible for driving the digital governance agenda.
2. Engage with stakeholders (citizens, NGOs, and the private sector) to ensure digital services meet everyone's needs.

To build trust in digital services, enact strong data protection and privacy laws and establish robust cybersecurity frameworks to protect against cyber threats. Implement secure and verifiable digital identity systems that can be used to access public services.

Encourage collaboration between government, private sector, and non-profit organisations to expand digital services and stimulate investment in digital technologies and infrastructure.

Invest in research and development in the digital sector to foster innovation and support start-ups through incubators, grants, and mentorship programs. Across the globe a tech start-up ecosystem is expanding rapidly, attracting significant investment in sectors like FinTech, AgriTech, EdTech, and HealthTech. Diversification in services offered by start-ups contributes to economic development and innovation.

Develop KPIs and metrics to measure digital service uptake and impact. Implement feedback systems for continuous improvement.

#### **Social Requirements**

It is important to note that simply automating existing business processes may not provide any significant benefit to citizens or businesses. It may only result in some efficiency gains for the internal staff of public administration organisations. This can be seen as a good first step towards building the capacity to transform, but it is only a start.

Eventually, the goal should be to achieve a real transformation of existing processes while keeping in mind the desired outcomes by fully redesigning internal processes and implementing the Once-Only and Digital-First principles.

Use design thinking to ensure digital services are easy for people of all digital skill levels. Additionally, one should adhere to accessibility standards to make our services usable for people with disabilities.

It is important to provide digital services in multiple languages to cater to diverse linguistic groups within the nation.

Promote mobile financial services and develop digital platforms for government services to encourage digital economic inclusion. Actively explore digital financial services to enhance financial access through mobile money and central bank digital currencies. Mobile money has played a significant role in financial inclusion by enabling accessible digital payments and transfers without the need for physical banks.

Enhancing digital infrastructure, technology adoption, and financial services can drive economic growth, structural transformation and prosperity.

Telemedicine services can extend healthcare access to remote areas. Digital services can provide farmers with information on markets, weather, and farming techniques. Targeted programs can encourage and support women and girls in using digital technologies to address the gender digital divide.

Collaborate with community leaders to increase digital adoption and address any cultural resistance.

### 3.4.2 Digital Data

#### **Data Management**

A country's digital transformation has a significant impact on governance, particularly on data management. We have a well-established system for handling paper-based documents and information, including the infrastructure for creation, dissemination, usage, and retention. This system is deeply ingrained in our societies and taught in schools, universities, companies, and the public. However, when we shift from paper to digital data, we need to create a similarly comprehensive and solid infrastructure that can handle digital information on a societal-wide level.

Specific policies required for data management in a country to facilitate digital transformation should at least include the following elements.

**Data privacy regulations**, such as the General Data Protection Regulation (GDPR) in Europe, play a crucial role in governing personal data collection, processing, and storage. These regulations ensure that individuals have control over their personal information and that organisations handle it responsibly. By implementing these laws, a country can ensure that anyone who processes data will comply with the legal requirements and foster trust with their customers.

Establishing **standards** and regulations for data security to protect against unauthorised access, breaches, and cyber-attacks. This may involve encryption protocols, authentication mechanisms, and regular security audits.

Data **localization** law sets rules on where data can be stored and processed, including requirements for data to be kept within national borders or specific regions to protect sensitive information.

**Open Data** policies promote transparency, collaboration, and economic growth by encouraging government agencies to make non-sensitive data available to the public for analysis, research, and innovation.

**Interoperability** standards and protocols will enable different systems and platforms to exchange data seamlessly. Interoperability facilitates integration, data sharing, and collaboration across various sectors and organisations.

Creating mechanisms for **sharing data** between public and private entities while ensuring privacy, security, and compliance with regulations can foster collaboration, innovation, and the development of new services and products. The should be no fees for sharing data amongst governmental agencies.

Establishing frameworks for managing and governing data throughout **its** **lifecycle**, including policies for data quality, metadata management, access control, archiving, and compliance.

**Capacity building** initiatives to enhance the digital skills and data literacy of citizens, businesses, and government officials will ensure knowledge and expertise to manage and leverage data for digital transformation effectively. Investing in capacity building is a prerequisite for the success of data-driven projects.

**Incentivizing** data innovation by offering tax breaks, grants, or funding programs will encourage businesses and organisations to invest in data-driven innovation and technology adoption. Also, state agencies should enable depersonalised data in a sandbox to facilitate product development by start-ups.

Developing **ethical guidelines** and frameworks for responsible use of AI and data analytics to address bias, fairness, transparency, and accountability in decision-making processes.

Such policies and frameworks will enable digital transformation without jeopardising it through the risk of losing data (prioritizing the realization of human rights in the digital era in the context of AI design, development, implementation).

#### **State Registries**

State registries play a critical role in the governance, administration, and service delivery mechanisms of a country. They are centralized databases that maintain up-to-date records on various aspects such as population, businesses, property, vehicles, etc. Following are main reasons, why it should part of the national digital infrastructure enabling digital transformation.

**Authoritative Source of Information**: State registries serve as the official source for various types of data, ensuring that government agencies and departments have access to accurate and reliable information for decision-making, policy formulation, and governance.

**Efficient Service Delivery**: By having centralised registries, governments can streamline the delivery of public services. For example, a registry of citizens can expedite processes like issuing identification documents, voter registration, and providing social services, thereby enhancing the efficiency of government services.

**Improved Data Management**: Centralized registries enable better management and control of data, ensuring that information is consistently updated and maintained. This reduces duplication of data across different government entities and minimises inconsistencies.

**Enhanced Transparency and Accountability**: State registries contribute to greater transparency by providing a clear record of transactions, ownerships, and registrations. This is particularly important in areas like property registration, where clear records help prevent fraud and disputes over ownership.

**Facilitation of Legal and Regulatory Compliance**: Registries help ensure compliance with laws and regulations by maintaining records of registrations, licenses, and other legal documents. This is instrumental for business operations, vehicle registration, and real estate transactions.

**Support for Economic and Social Planning**: The data contained in state registries is invaluable for planning and research purposes. It allows governments to analyse trends, make informed decisions on infrastructure development, public service needs, and social programs, and monitor the effectiveness of policies.

**Public Health and Safety**: Registries for vaccinations, health records, or criminal records are vital for public health management and safety.

See list of most important state registries in the Appendix 3.

### 3.4.3 Interoperability

#### **Overall approach**

The public sector architecture follows a distributed model. This empowers government agencies to be independent yet integrated. Agencies can choose their systems and partners while benefiting from centralised governance and standards that enable efficient, secure, and scalable systems.

Taking a whole-of-government approach that balances standardisation with flexibility will provide a digital ecosystem that serves citizens seamlessly while giving institutions autonomy.

The interoperability infrastructure should establish legal certainty and trust by enabling once-only data collection from citizens and strong data lineage across all systems. Cyber resilience is ensured through distributed security measures rather than having a single point of failure.

The interoperability platform for information exchange between systems should be fully decentralised implementing the following key aspects:

* Information exchange is always between the receiver and submitter without any centralized party in between.
* Organisational sovereignty of participating in information exchange members is not compromised retaining administrative responsibility to data owners and users.
* There is clear data lineage supported by PKI-based logins.
* There is cyber resilience supported by encryption and access rights management.
* It avoids a single point of failure through distributed data.

#### **Governance**

To achieve optimal efficiency and scalability of an interoperability platform that relies fully on distributed implementation, certain principles must be observed:

* Centralized oversight and coordination if interoperability requirements implementation across all governmental organisations.
* Standardization of security policies, software, and protocols for data exchange.
* Mandatory verification, testing, audit, and certification to ensure compliance.
* Governmental central agency should operate usage monitoring and permissions management; that should ensure legal certainty.

#### **Administrative procedures**

There should be a procedure that ensures the trust and interoperability of participants. The owner of the procedure should be the central governmental agency. The following aspects should be covered:

1. Application – members should apply to Central Authority to join interoperability platform describe planned information system, data content and usage intent.
2. Verification - The authority verifies the application and ensures the planned system meets security and interoperability standards.
3. Agreement - An agreement is concluded between Authority and the information system owner outlining rights and obligations.
4. Installation - Authority provides standard interoperability member’s software and assists with configuration.
5. Testing - Extensive testing is done to validate correct functioning before moving to production.
6. Security Audits - Regular security audits are conducted by all participants.
7. Usage - The information system owner access data and share information with other systems based on principles and regulatory framework.

At an institutional level, decentralised interoperability platform empowers government agencies to be independent yet integrated. Agencies can choose their systems and partners while benefiting from centralized governance and standards that enable efficient, secure, and scalable interoperability.

### 3.4.4 Digital Identity

Digital identity is a key enabler of secure and trusted digital services and transactions between governments, organizations, and individuals. At its core, digital ID provides authentication and digital signature capabilities that allow legal validity like handwritten signatures.

While approaches like self-sovereign identity or federated functional identity are around, they currently face adoption challenges due to legal uncertainties and technical complexities. For legally binding digital identity and signature solutions, a foundational ecosystem model is advisable.

The digital signature and identity ecosystem have layers:

#### **Legal Framework**

It is needed to properly regulate and operate every aspect of the ID ecosystem. A comprehensive legal framework like eIDAS in the EU establishes standards for digital identity, electronic signatures, electronic seals, time stamps, and more. This provides the regulatory basis for digital ID ecosystems to ensure legal compliance. However, every government and situation may require slight adjustments to ensure success.

#### Identity Provider

Identity provider(s) enroll and verify real-world identities into the digital system (civic registry). This can be government bodies or authorized private providers. Enrolling digital identities into the ecosystem requires in-person verification and the ID issuance process in many cases. In the case of fundamental ID, it should be issued, governed, and maintained by government authority or by a service provider appointed by authority. In ideal case the ID issuer should be the same authority that is responsible of issuance of passports, to ease the legal validity question of digital ID. Thus, here below is an example of civic registry, vital statistics, and identity management system overview, recommended by UN. The civic register with all its components will play a crucial role as a base information for the rest of the ID ecosystem layers.

<figure><img src="https://2983968174-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FWNaBkXRH5GkT1VCcv0BB%2Fuploads%2Fgit-blob-66812be6805412b865f4e9238f53e2652df73963%2FScreenshot%202024-05-29%20014113.png?alt=media" alt=""><figcaption><p>Figure 9 CRVS platforms, Key Findings for Practitioners by UNICEF; graph developed by UN Legal Identity Expert Group (LIEG)</p></figcaption></figure>

#### Identity Token

The identity token is a cryptographic container that stores digital keys for authentication, digital signing, and encryption. It can be based on smart cards, mobile apps, SIM cards, etc. Having multiple tokens running in one ecosystem provides additional resilience for token failures and allows users to switch between solutions that are most suitable for their use case, thus providing flexibility. These tokens can be provided by private sector providers, and it is advisable to create a competitive market.

#### Certificate Authority

Trusted certificate authorities validate user identities and bind their identity to their cryptographic keys by issuing digital certificates. Multiple CAs can exist within the ecosystem as per the legal framework. This prevents vendor lock-in and will boost rollout.

#### User Software

Software tools enable integration with business workflows to allow digital signing, verification, and authentication. Opting for open standards and open-source software enables ease of adoption. Customizable solutions cater to specific needs.

All these layers are necessary for a comprehensive and proven digital ID ecosystem. Technically, there are multiple ways to address these aspects, but building blocks and open-source approaches are essential for government sovereignty and system sustainability.

Many governments struggle with digital ID and signature deployments due to low citizen participation. A recommended solution is to develop a "killer-service" that everyone needs and wants to use. Collaboration with the private sector for cross-domain use cases, such as using government-provided digital ID as an authentication method for banking services, enables legally binding client data in digital format while outsourcing authentication process risk management to the government. These types of solutions are win-win and can boost and ease the solutions take-up.

\\


# 4. Organisation Level

## 4.1 Overview

Digitization challenges at organization and government levels require separate treatment due to technical and political considerations.

Although the term "Whole-of-Government" may seem reasonable, a GovStack approach recognizes that public sector modernization is not a single national project. Rather, it consists of hundreds or thousands of initiatives undertaken independently but in a planned manner across all levels of government. These initiatives are driven by public administration organizations, and their success depends on their capabilities. Therefore, we must approach digital transformation at the organizational level.

Digital transformation of the public sector on an organizational level depends on the availability of national digital infrastructure:

<figure><img src="https://2983968174-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FWNaBkXRH5GkT1VCcv0BB%2Fuploads%2Fgit-blob-899ebe22b10b36e2f55738043412b418ab29314d%2Fimage%20(1).png?alt=media" alt=""><figcaption><p>Figure 10 - Digital Governance Model (Source: Ivar Tallo &#x26; Aare Lapõnin)</p></figcaption></figure>

The Digital Governance model mentioned in section 2.5 highlights the need for a national digital infrastructure and a set of capabilities to support the digitalization of public services.

### 4.1.1 Public vs Private

Digitalization of the public sector requires significant change management of processes, skills, awareness, and legal basis, and must align with legal mandates and government-wide policies.

First, public sector operations differ from the private sector in terms of organizational needs and the requirement to strictly adhere to business rules that arise from legislation and administrative regulations.

When a private sector organization aims to transform a particular aspect of its operations, the first crucial step is to establish a clear business case and obtain the necessary resources for its implementation. Once these are in place, it becomes possible to make a reasonably accurate prediction of the timeline for completing the transformation.

In the public sector, implementing similar transformations may require approval at different levels of the organizational hierarchy. Legislative changes may be difficult to pass, budget allocation may be uncertain and take a lot of time due to rigid annual budgeting procedures.

In the public sector, digital transformation has wide-ranging implications that must be considered holistically as part of any reform that involves change management:

* Rules and regulations might need updating to enable digital options; and facilitate the realization of human rights in the digital domain, which in turn will increase users’ trust (citizens, stateless persons, and foreign nationals residing in the state) in the platforms.
* Institutional roles may need realigning.
* Staff skills and culture will need transitioning.
* Citizens expect seamless services but lack an understanding of government roles and responsibilities.

All these aspects should be considered and planned for a successful transformation.

### 4.1.2 Functional Similarities

Organizations in the public sector share basic functions but differ in their mandates. For example, registrar functions, document management, and case management are similar across all domains but can vary in detail.

This similarity allows the use of common building blocks for different needs while aligning procedures in specific aspects. Similar administrative functions may have different procedures, so technical solutions must align with governance and legal frameworks.

A comprehensive study of service and system design must be conducted before any building block can be deployed.

### 4.1.3 The Role of Legislator

Often, implementing a desired innovation is hindered by outdated or overly strict regulations. This highlights the importance of having effective policy and regulatory frameworks in place that can facilitate and encourage modernization and innovation. The qualitative aspect of a state digital transformation is linked to ensuring that the transition to a proactive, citizen-centered state incorporates human rights.

### 4.1.4 Horizontal Cooperation

Ministries and agencies today are quite independent and will remain such for the observable future. They are acting based on different legal acts, which might have different legal requirements for data processing and management.

When changes affect multiple ministries, communication should go through the highest level of the chain of command, such as ministers or the Cabinet of Ministers. It would be beneficial if a central coordinating body for digitalization was situated near the centre of the government. Even if lower-level cooperation is possible through the legislative framework, it is still more time-consuming than activities within a single organization.

The whole-of-government strategy does not imply that the entire government is a single organization. Rather, the strategy and goals should encompass the whole of government. Innovation and deployment of solutions will still happen within specific organizations that have received a designated budget.

### 4.1.5 Digital Organisation

In traditional public administration, critical capabilities of digital transformation and digital service delivery are missing.

Those capabilities should be presented in the following areas:

* Management & Architecture
* Digital Services
* Data-driven decision-making
* Digital Co-creation

In the sections below, we describe the capabilities and maturity level required for the digital transformation of a public sector organization.

## 4.2 Management & Architecture

### 4.2.1 Management

Digital organisations differ from traditional public sector organisations and, as such, require different management practices for successful functioning. This does not necessarily mean that managers need to have a computer science degree or similar qualification, but rather that management practices should be adapted to consider the significant digital infrastructure present in the organisation. Process management, operational costs, and risks are also different in digital organisations, and therefore, staff skills need to be adjusted accordingly. Additionally, stakeholders in digital organisations are also distinct, and management practices should reflect this.

#### **Who decides?**

First among them is the widespread belief that digitalisation is a task for the IT department of a given organisation. Decision makers delegate the challenge to the technical department, whose primary task often is to take care of IT hardware, software, and connectivity and who administers the internal network if it already exists. These are all necessary tasks; however, the digitalisation challenge is about changing the business processes, which is a management-level task.

Thus, a digitalisation project should be owned by the management. It is their business processes that would undergo change.

#### **How are changes done?**

The next challenge is integrating a digitalisation project into the organisation's broader administrative framework. It is insufficient to provide funding for its implementation; there must be communications to departments responsible for legal issues, PR, HR, etc. IT departments are of a technical nature, and often, they are not accustomed to communicating with stakeholders. This can put the project under additional strain.

It is crucial to analyse and address change management issues on an organizational level to identify and solve cross-cutting issues beyond the implementation of a technical solution and reduce inevitable tensions that arise with the adoption of new ways of doing business.

In the context of such change management, it is essential to understand that while the private sector can align everything with the goals defined by leadership, government organizations must follow rules often reflected in laws that are not easily changeable, adoptable, or ignorable.

#### **How is communication done?**

There are clear steps that management should implement to advance change management on an organisation level.

* Create a vision statement in human language, i.e. not just bullet points but what the goals are and how different users would benefit from the digital project that is planned to be implemented.
* Get approval from the top-level leadership, including whenever necessary on a political level.
* Create events to talk about it, preferably in a semi-formal environment that allows anyone to express their reactions because the pain points for implementation would come out of this.
* Approach key middle-level managers separately to recruit them to be supporters of the project.
* Institute clear communication protocols between the digitalisation project and legal, HR and PR departments to avoid non-IT related misunderstandings during the implementation period.
* When necessary, agree on training and awareness events.
* Map potential stakeholders outside the given organisation and seek to engage them in a similar fashion.

All these actions are the responsibility of the organization's management and not the IT department's area of expertise or responsibility.

#### **Chief Digitalisation Officer (CDO)**

In every public sector organization, there should be a Chief Digital Officer (CDO) who is part of the top management. The CDO should have a strong background in business and digital transformation to combine these practices and support strategic management toward more effective digitalization.

### 4.2.2 Architecture

An organisation in the digital age is not merely a social construct. It is, as before, a well-structured entity comprising of people, policies, and an internal culture. However, it is also a complex technological system that involves new operational methods and inherent risks. To manage such a techno system effectively, one must clearly understand its elements, roles, and dependencies.

Knowledge gained from development projects alone does not suffice to comprehend an organisation's resulting technology landscape. Hence, it is crucial to practice systematic organisational architecture management to gain visibility.

Architecture is an abstract description of a system's entities and the relationship between those entities 13. Only if you have an up-to-date organisational architecture description can you plan maintenance costs, seek potential business process improvements, design service-level quality monitoring systems, etc.

## 4.3 Digital Services

Service delivery is done differently in digital organisations compared to traditional public service deliver

#### **Where is business value from digital?**

Governments worldwide are embarking on digital transformation journeys to enhance efficiency and service delivery. Yet, optimising government transactions goes beyond merely digitising documents and constructing IT systems.

Digital transformation requires a comprehensive strategy that encompasses legislation, regulations, institutional agreements, workforce capabilities, and a shift in cultural mindset.

* Business value from the transformation can be achieved only if the whole operating model is adequately adopted for the digital era.
* Early agreements and collaborations can speed up digitisation. Laws must support digital governance principles. Again, a phased roadmap is essential for successful implementation.

#### **Is it Digital-first?**

To streamline transformation, there is a pressing need to modernise overarching public procedural laws that define general rules for public administration, organisations, and officers. Instead of amending laws for each individual organisation and procedure, a holistic public procedural law can set the foundational principles vital for a digital public administration.

On the regulatory spectrum, digital data and documents should be accorded the same validity and protection as their paper counterparts. For instance, electronic signatures and documents should be legally equivalent to handwritten signatures and paper contracts. By updating laws to embody these digital equivalence principles, the pace of modernisation can be accelerated.

Uniform cybersecurity and data protection standards for government systems should be established.

#### **How do we get Digital Literacy?**

Promoting digital literacy among public officers and citizens is paramount in today's digital age. As governments and public institutions transition towards complete digitalisation, it's essential that both public officers and the general populace are well-equipped with the knowledge and skills to navigate this new digital landscape. Here are some training activities, with examples, that could be beneficial:

Digital Literacy Workshops for Public Officers

* Scenario-based Training: Use real-life scenarios to demonstrate the implications of complete digitalization. For instance, a simulation could show how a digital system might streamline the approval process for a public project, highlighting both the advantages and potential pitfalls.
* Hands-on Computer Training: Offer courses on essential software and tools that public officers might use in their daily tasks, from data analysis tools to project management software.
* Digital Etiquette Seminars: Educate officers on the dos and don'ts of digital communication, emphasizing the importance of clarity, brevity, and respect.
* Mindset Shift Sessions: Organize sessions focusing on digital transformation's benefits, addressing common fears and misconceptions. Explain the user-centric approach to service design and illustrate how it differs from the traditional officer-centric approach.
* Cyber Hygiene Seminars: Offer seminars on basic cybersecurity practices, such as how to recognize phishing emails, the importance of regular software updates, and the dangers of public Wi-Fi.
* Executive Digital Bootcamps: Organize intensive training sessions covering digitalization's strategic implications, ensuring that top-level decision-makers understand the broader impact on the organization.
* Cybersecurity Tabletop Exercise for Top Management: These exercises simulate cyber incidents in a controlled environment, allowing management to test response strategies and improve decision-making processes without the risk of real-world consequences.
* Human rights in digital era and the digital transformation of law Seminars: Train politicians and legislators in new knowledge areas of digital law transformation and governance; ensure that the strategic legal vision for a digital state is citizen-centered and takes into account the context of modern technologies (generative artificial intelligence, Industry 4.0, Web 3.0) and their impact on human rights.

#### Digital Literacy Workshops for Citizens

* Hands-on Sessions: Organize practical sessions where citizens can set up their digital profiles, learn to recognise secure websites and practice safe online behaviours. Additionally, the sessions can include workshops aimed at building trust in digital platforms. This will help ensure that citizens are aware of their digital rights and understand how the government is working to implement them.
* Digital ID organisation and Authentication Workshops: Use simple, relatable examples to explain concepts like digital tokens, two-factor authentication, biometric verification, and password management.

#### Change Management Programs

* Feedback and Discussion Forums: Create platforms where public officers and citizens can voice their concerns, ask questions, and provide feedback on the digital transition.
* Digital Champions: Identify and train enthusiastic individuals about digital transformation to act as role models and assist their peers in adapting to new technologies.
* Regular Updates and Communication: Ensure that all stakeholders are kept in the loop about upcoming changes, the reasons behind them, and the benefits they'll bring. Ensure that all stakeholders consider the priorities of implementing human rights in the digital era in new governance systems.

By implementing such training activities, governments can ensure a smoother transition to digital platforms, with a workforce and citizenry that are skilled, confident, and comfortable in the digital realm.

The change management programs and training are instrumental in fostering this cultural metamorphosis.

## 4.4 Data-driven Decisions

Often, digital transformation is perceived as a project of implementing some technology. However, it is an activity which is enabling more efficient data management. So, the focus should be shifted from the technology to the question, what can we do with new data? That will help us adopt a data-driven approach to thinking and decision-making.

Adopting a data-driven decision-making approach involves integrating data usage into business processes at all levels of an organisation.

Here's a step-by-step guide on how an organisation can start with data-driven thinking:

* Define clear objectives that align with the overall business strategy for effective data-driven decision-making.
* Develop a data strategy for crucial decision-making.
* Implement data governance policies and assign data management responsibility.
* Upgrade data infrastructure to handle various types and volumes of data. Use data warehousing, data lakes, and other relevant technologies.
* Collect and integrate relevant data from internal and external sources for a comprehensive view.
* Establish data quality standards and processes, and regularly clean and validate data for accuracy and reliability.
* Train employees to enhance data literacy and teach decision-makers how to use and interpret data.
* Deploy analytics tools that fit your needs and offer advanced capabilities.
* Define and track KPIs that align with objectives, and establish benchmarks for performance measurement.
* Encourage data-driven decision-making culture and reward contributors.
* Ensure leadership commitment to data-driven culture.
* Lead by example in data-driven decisions.

It is recommended to start with small, manageable projects to showcase the value of data-driven decision-making. By doing so, your organisation will learn from successful projects and improve your approach. Further on, iterate and improve continuously by evaluating data-driven processes, learning from successes and failures, and refining your approach.

By following these steps, organisations can gradually shift towards a more data-driven decision-making culture, leveraging insights to enhance efficiency, innovation, and overall business performance.

## 4.5 Digital Co-creation

The digital transformation of one organisation is more efficient and has a higher chance for success if it is done within the existing local digital ecosystem. Such an ecosystem should include experienced local developers, successful private digital companies, and existing national digital infrastructure. Like that, the engagement of the whole society in the public sector's digital transformation is vital.

The following is the list of critical areas that directly impact the transformation's success.

#### **Budget**

Budget allocation to public sector organizations is done in parliament or similar institutions. Thus, the business value of digital transformation initiatives should be explained to the public. Without that, politicians will not be able to allocate resources.

Acquiring resources for a significant initiative usually involves obtaining funds from the annual state budget, which has a planning phase 9-10 months before the beginning of the next financial year. A solid business case must be prepared to apply for budget funds, and decision-makers must be convinced of the initiative's feasibility. This process can take 2-3 years before funds are received for the idea you got today. Also, financial rules often prevent transferring funds to the following year, causing potential delays and unspent budgets.

GovStack policy recommendations are:

* Multi-year budgeting with in-year transfer authority
* Dedicated budgets for enterprise-wide platforms
* Outcome-based budgeting models
* Exceptional models like "Digital First" funds
* Donor-based funded projects should have state budget commitment for long-term sustainability and maintenance.

#### **Procurement**

The public procurement process often hinders the selection of optimal technology vendors and solutions for digital systems.

The first obstacle is the lack of capacity to identify innovation areas and design feasible projects that can bring tangible results for citizens and businesses. The GovStack attempt to analyse best practices and materialise such practices into architectural building blocks will help overcome that.

The next issue is overly prescriptive contracts, and low-risk vendor choices lead to a lack of innovation.

GovStack policy recommendations are:

* Flexible procurement methods like pre-commercial procurement
* Outcomes-based requirement definitions
* Engaging innovative local SMEs/start-ups
* Joint procurement across agencies
* Project decoupling into smaller logical components and making project into a framework contract with multiple vendors

#### **IT Project**

Many digital government projects fail (20/80) to achieve expected benefits and are plagued by time/cost overruns. Key challenges are the lack of technical capabilities, poor risk management, and weak governance.

GovStack policy recommendations are:

* Start small and build organisational capacity iteratively.
* Robust project governance frameworks.
* Stage-gate models with agile iterations.
* Government-shared services for technical capabilities.
* Reusability and customizability to match business process.

Staffing should follow the definition of work processes: First, one should identify the needs for a process or activity and then hire people to execute that. One should not just “put people to organisational unit boxes”.

#### **Maintenance**

When acquiring an IT system, the initial cost typically accounts for only 10% of the overall Total Cost of Ownership. Once the system is implemented, it becomes an asset that helps achieve business objectives and is integrated into the organisational digital infrastructure. That also increases complexity and creates dependencies. Therefore, it is important not only to allocate 15-20% of the initial cost for annual maintenance, but also plan for decommissioning the system after 5-7 years, when its technological fitness will degrade.

GovStack policy recommendations are:

* Central shared services for common applications
* Improve architecture management practices.
* Legacy modernization programs
* Develop business continuity programs and manage operational risks.

### 4.6 Organisational Taxonomy

During PAERA preparation, we analysed public administration organizations of several countries using EA techniques. We identified key business services and the required processes for those services. Additionally, we identified the applications needed to support the business processes. Complete information about the outcomes of this analysis is in Annex 1 in section A1.2 below.

An important observation from this analysis is that despite a seemingly large variety of organizational types in the public sector, it is possible to categorize them into three major types:

1. The Policy Development Unit is responsible for developing and implementing policies. A typical example is a different ministry.
2. The regulatory Agency is responsible for regulating specific sectors of the economy. A typical example here is Data Protection Authority, Business Licensing Authority, etc.
3. A state authority with a complex set of responsibilities and several performance outcome areas. We refer to such organisational type as a Service Delivery Authority. A typical example here is a tax department, police department, etc.

We know that international government functions Classification COFOG identifies 10 government functions, which are further divided into 69 functions. For every function, there are several institutions on different levels of a public sector structure. Like that, there are hundreds and thousands of different institutions even in middle-sized countries. However, from the automation point of view all them can be generalised into 3 abovementioned types.

Following is a brief description of those types (for details see Annex 1 in section A1.2 below). To describe those organizational units, we use Business Canvas’s format.

Policy Development Unit (PDU)

* Function: Responsible for policy analysis, development, and monitoring.
* Value Proposition: Policy development, legislation maintenance, stakeholder communication.
* Customer Interface: Engage with demographic groups, economic agents, NGOs, and international organizations.
* Strategic Partners: Parliament, government, media, industrial unions.
* Required Applications: Document Management, Content Management, Analytics, and other general office automation tools.

Regulatory Agency (RA)

* Function: Implementation and enforcement of regulations in specific functional area.
* Value Proposition: Policy implementation, license management, supervision of licensees.
* Customer Interface: Engage with economic agents and communities.
* Infrastructure: Compliance management, digital service delivery, risk management.
* Strategic Partners: Related MDAs, media, and industrial unions.
* Application Architecture by main business functions:
  * Forms & Procedures Design: User-friendly forms and automated workflows.
  * Application Capturing & Processing: Efficient application lifecycle management.
  * Payment & Refund Processing: Secure financial transactions.
  * Decision Management: Transparent decision-making processes.
  * Inspections Management: Efficient inspection scheduling and compliance tracking.
  * Legal Affairs & Litigation: Management of legal documents and cases.

Service Delivery Authority (SDA)

* Function: Complex service delivery with extensive customer interaction.
* Value Proposition: Policy enforcement, compliance monitoring, public awareness.
* Customer Interface: Engage with economic agents and communities.
* Infrastructure: Performance management, service delivery, IT management.
* Strategic Partners: Responsible PDU, related MDAs, media, industrial unions.
* Application Architecture by main business functions:
  * Registration & Profile Management: Secure user registration and profile management.
  * Customers & Users Management: Comprehensive user management and support.
  * Online Learning & Training: Interactive and accessible learning environment.
  * Customer Accounting: Efficient transaction and account management.
  * Compliance & Enforcement: Monitoring and enforcing compliance.
  * Data Management: Advanced data services for transformation and monitoring.

After creating application architectures for different types of organizations, we realized the following:

* PDU requires a general office automation environment, which is similar to what knowledge-based service providers in the private sector need.
* RA requires everything that PDU needs, plus a basic digital service delivery platform.
* SDA requires everything that RA needs, but at a more robust and industrialized level.

By integrating these architectures and identifying reusable components, we can create functional building blocks that accompany infrastructural building blocks. This integration can help public administration achieve greater efficiency, standardization, and service delivery responsiveness, benefiting citizens and stakeholders.

\
\
\
\\


# 5. Implementation Framework

## 5.1 Capabilities Assessment

An organisation's ability to transform itself into a digital organisation cannot be achieved simply by command or by assigning a budget. It can only be acquired through the internalisation of successful implementation of modernisation projects and digitalisation initiatives. Therefore, it is essential to consider the organisation's maturity level when creating a roadmap for its transformation.

A model of maturity levels shows a realistic and practical sequence of developing internal organisational capabilities:

<figure><img src="https://2983968174-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FWNaBkXRH5GkT1VCcv0BB%2Fuploads%2Fgit-blob-14847202aa7dd1600c61adff3402a58c52198026%2FScreenshot%202024-05-29%20015434.png?alt=media" alt=""><figcaption><p>Figure 21 - Organisation digital transformation capability model (Source: Aare Lapõnin)</p></figcaption></figure>

Our experience shows that organisations should start from the ground floor and gradually move from one level to another. Practically speaking, it is not possible to “skip” a level.

We explain this diagram by describing each step of the maturity levels diagram.

#### Ground floor

If an organisation has never implemented any automation project, we can say that it is on the ground floor.

The ground floor, in terms of capabilities, means:

* The management did not plan for IT systems to deliver services or support activities.
* There is no organisational architecture document that describes the business, data, application, and technology used by an organisation.
* An organisation does not deliver digital services to external customers.
* Management is not using its operational data systematically to make decisions regarding strategic options for the organisation.
* The organisation has never procured IT system development and management services from a market.

Once you are on the ground floor, you should:

* Make sure there is connectivity for your organisation and your customers.
* Start with small projects, which should have a small budget and delivery timeline, at most 6-9 months.
* Prepare plans for how users will be trained to use the new system, what administrative procedures you need to support a new way of working, and how the latest IT system will be supported.
* Start cultivating a digital culture in an organisation (see 3.1.2 above for details on a digital culture).

Following important rules should be considered:

1. A New IT system is a liability, and you have to plan maintenance costs for the entire lifecycle of the planned solution.
2. There will be digital data, and you should have procedures for managing the lifecycle of the digital data.
3. There should be a unit in charge of digital transformation that is able to report and escalate to the management of the organisation.

It is important to note that if the staff has experience in digital transformation from other organisations but has yet to deliver any project as a team, then this organisation starts from the ground floor.

#### 1st Level – Trust of Data

An organisation achieved the 1st floor if the following is true:

1. Management: There are regular planning activities where management assesses and commits to proposals to invest in IT projects to improve operations. Management cultivates digital culture in the organisation.
2. Architecture: There is a process in an organisation to maintain documentation of business services, processes, data, applications, integrations, and technology components. This is known as the architecture management process, and it aligns the organisation’s business and IT staff.
3. Digital Services: The organisation is delivering digital services to external customers. For that, there is an IT development, maintenance, and ITIL-compliant IT service management capability. Also, the design and operation of digital service delivery is done as a collaborative effort between business process owners and IT.
4. Data-driven Decisions: The organisation consolidates all its data, including logs and monitoring metrics, in a reliable enterprise data warehouse (EDW). They use management dashboards and reports for operational and strategic decisions, and EDW is accessible through self-service analytics to all analysts in the organisation. For all data, metadata describes the semantics of available data. There is a data quality management process. The organisation trusts the quality of data. The organisation is in the process of learning to make decisions based on data.
5. Digital Co-creation: The organisation can procure different services from the market to ensure high-quality digital service delivery. There are channels for consultation with customers to receive feedback regarding the quality of digital service delivery.

Once you are on the 1st floor, you should:

* Continue with small projects, which should have a limited budget and delivery timeline, at most 12 months.
* Prepare plans for the complete digitalisation of all activities in the organisation. Often, such plans can be formulated as an organisation's IT strategy, and it should cover a 3-5 years time period.
* Establish a comprehensive enterprise architecture repository for detailed planning of modernisation initiatives.
* Introduce a dedicated Enterprise Architecture management team to ensure IT and business alignment.

#### 2nd Level – Process Management

An organisation achieved the 2nd floor when all indicators of the 1st floor are fully accomplished and additionally, the following is true:

1. Management: There are service level agreements (SLA) established for every business service, which is delivered to external customers. SLA levels are regularly reviewed by management, and in case of deviations, corrections are implemented. For every internal business process, there are key performance indicators (KPIs) established and regularly monitored by management. In case of deviations, corrective actions are implemented. There is a process of continuous analysis of changes in the internal and external organisational environment. The result of this analysis is proactively used for planning changes needed for improvements of quality services and efficiency of business processes. This process is known as strategic management, and it is fully aligned internally with IT management and externally with the budget cycle in the government. In the management of an organisation there is a dedicated top manager responsible for digital transformation of organisation.
2. Architecture: An organisation has the internal capability to plan for improvements in service delivery operations to achieve better efficiency. On the level of organisational architecture, there is a capability to trace all operational and IT risks and design adequate response plans for all such identified risks. There is a regular process of rationalisation of organisation application and technology landscape, eliminating or minimising existing technical debt.
3. Digital Services: All core and support processes are fully digitalised. All internal activities are digital-first by design. Full digital literacy is a mandatory skill requirement for all staff positions.
4. Data-driven Decisions: There is a mature process of development and usage of data products. Data architecture is designed based on current and long-term organisational requirements. Data architecture quality and reliability are the highest priority, and application architecture is aligned with data architecture, i.e., changes in application architecture do not change overall data architecture. The organisation relies entirely on digital data for all decisions, which is of high quality.
5. Digital Co-creation: Organisations prioritise integrating digital services with customers' natural digital environments for seamless information exchange.

Once you are on the 2nd floor, you should:

* Continue with small projects, which should have a limited budget, clear tangible objectives, and delivery timeline, at most 18-24 months.
* Plan for improvement of resilience of digital service delivery, including introducing a comprehensive and robust business continuity management process.
* Plan for better integration of business process owners with an architecture management process.
* Plan for better integration of product management with the architecture management process.
* Introduce program management discipline to manage long-term objectives systematically.
* Work to ensure that the procurement process is flexible enough to address complex tasks when the result is not possible to define precisely.

#### 3rd Level – Change Management

An organisation achieved the 3rd-floor maturity level when all indicators of the 2nd floor are fully accomplished, and additionally, the following is true:

1. Management: For all relevant policy changes, there is a capability to identify impact analysis and prepare a comprehensive change management plan, which is routinely executed by appropriate organisational units. The organisation can adopt frequent policy changes as required.
2. Architecture: An organisation can proactively plan for architecture, which supports the flexible and fast implementation of changes due to policy changes and changes in the external environment.
3. Digital Services: A mature business continuity management process ensures the resilience of digital service delivery.
4. Data-driven Decisions: The organisation can proactively support policy change requirements analysis.
5. Digital Co-creation: The organisation can ensure the sustainability of its IT systems by designing and implementing solutions using GovStack architectural building blocks.

Once you are on the 3rd floor, you should:

* Continue with small projects, which should have a limited budget, clear tangible objectives, and delivery timeline, at most 18-24 months, which are part of a program to achieve broader outcomes.
* Regularly review the external environment, international best practices, and technological advancements and update the organizational strategy to incorporate beneficial elements.

#### 4th Level – Compliance Management

An organisation achieved the 4th-floor maturity level when all indicators of the 3rd floor are fully accomplished, and additionally, the following is true:

1. Management: The organisation can proactively recommend policy changes to ensure improved outcomes in the mandated area.
2. Architecture: Architecture management is seamlessly integrated into the organisational strategic management process.
3. Digital Services: Adopting changes in digital service delivery is seamlessly integrated into the organisational strategic management process. Organisational digital platform is integrated part of national digital ecosystem.
4. Data-driven Decisions: The organisation proactively deliver data products to all internal and external stakeholders. There is an active feedback loop with all consumers of data products. Feedback is routinely used in product management.
5. Digital Co-creation: The organisation manages its organisational digital platform as a two-sided market open for providers of products and users of those products. There is a managed process of reviewing the quality of products and onboarding products with an accepted level of quality.

Upon reaching the 4th floor, it's important to continue regularly reviewing the external environment, international best practices, and technological advancements. Updating the organizational strategy with beneficial elements should be a continuous process.

## 5.2 Principles

The digital transformation roadmap of an organisation should adhere to principles which we introduced in section 3.2.2 above. In the following section, we elaborate on the implications of those principles for the digitalisation of an organisation. For every principle we outline:

* Motivation – An explanation of why we believe this principle is important for consideration during digital transformation.
* Rationale – Description.
* Implication – Description of what are the anticipated consequences of the application of the principle to digital transformation.

### Principle #1 - Rule of Law

#### **Motivation**

While individuals in the private sector may engage in any activity that are not prohibited by the law, public sector organisations can only perform activities that are strictly and directly prescribed by the law.

#### **Rationale**

That is something that helps with accountability and prevent society from becoming lawless. The principle of the Rule of Law is a foundational concept in governance that refers to the idea that everyone, including individuals, institutions, and governments, is subject to and accountable under the law. It signifies that the law should govern a nation rather than arbitrary decisions or the whims of individuals in positions of power.

#### **Implications**

The principle of the Rule of Law has significant implications for the digital transformation of a public sector organisation. Here are key implications:

1. Legal Compliance: In a digital transformation, a public sector organisation must ensure its activities, processes, and systems comply with relevant laws, regulations, and legal frameworks governing data protection, privacy, cybersecurity, and other digital-related issues, including the implementation of human rights in the digital era through digital governance systems.
2. Transparent and Accountable Governance: The Rule of Law requires transparency and accountability in governance processes. In a digital transformation, a public sector organisation must ensure transparency in adopting and implementing digital technologies, including procurement, data-sharing agreements, and algorithmic decision-making.
3. Protection of Individual Rights: The Rule of Law emphasizes the implementation of human rights in digital context and the protection of individual rights and freedoms. In the context of digital transformation, a public sector organisation must ensure that the rights of citizens, such as privacy rights and due process, are respected and protected in the design and implementation of digital services and systems. This involves conducting privacy impact assessments, implementing robust data protection measures, and providing mechanisms for individuals to exercise their rights.
4. Fair and Impartial Administration: A public sector organisation must ensure that digital transformation initiatives are administered fairly and impartially, without discrimination or bias. This includes providing equal access to digital services and resources and safeguarding against algorithmic bias and discrimination in automated decision-making systems.
5. Security and Trust: The Rule of Law requires a public sector organisation to uphold security and trust in digital systems and services. This involves implementing robust cybersecurity measures to protect against data breaches, cyber-attacks, and unauthorised access to sensitive information. It also requires establishing trust-building mechanisms, such as transparency about data practices and data security and integrity commitments.
6. Adherence to Ethical Standards: A public sector organisation must maintain ethical standards during digital transformation. Guidelines for emerging technologies such as AI, machine learning, and big data should promote fairness, transparency, accountability, and integrity.
7. The UN Sustainable Development Goals are directly linked to the Rule of Law and are a priority for countries in addressing global issues. The governance system should facilitate the implementation of the Sustainable Development Agenda, and digital governance can help distribute responsibilities to achieve specific SDGs and uphold human rights.
8. The definition of human rights in the digital era encompasses fundamental opportunities for development, afforded to everyone by right of birth, codified in international and national law. The implementation of these rights aims to enable the use of social benefits through new technologies. It's important to differentiate between informational rights, rooted in the third industrial revolution (internet, computers), and digital rights that evolve under the fourth industrial revolution and digital globalization.

National strategies must consider human rights in the digital era, including those of children, within the changing digital landscape. This necessitates the development of relevant legislative acts, industry codes, techno-legal platforms, design standards, and action plans.

Additionally, the state should strive to implement human rights in the digital era of the entire population, which are divided into the following categories:

1. Rights to access the Internet, digital individualization tools, digital asset storage, and other digital technologies, protection of life, personal, biometric, biological, and other data.
2. Rights to access technologies (Industry 4.0) as digital guarantees for the realization of fundamental human rights. Rights to exercise personal, social, economic, political, and cultural rights based on new technologies without technological barriers.
3. Rights to manage public affairs (at the national level, and potentially in a system of global governance) through digital technology platforms.
4. Rights in the realm of ownership, use, and disposition of digital property (assets), conducting digital economic activities (transactions, digital deals, etc.), and to digital security systems.
5. The right to access social services based on digital technology platforms; equal access to opportunities offered by technologies, including access to education, employment, healthcare, and basic social services based on new technologies.
6. The right to access cultural values and education, etc.
7. The right to human-centered artificial intelligence. Priority to human interests, health, and quality of life in the context of the creation, use, implementation, and development of artificial intelligence.
8. The right to personal data protection, including the protection of genetic information and health data (for example, in the context of rapid progress in biotechnology, bioengineering, and telemedicine).

These categories underscore the importance of integrating digital rights into the legal framework to ensure equitable access to technology and its benefits across all sectors of society.

In the context of future Digital governance ecosystems development, it is crucial that they are citizen-centered. We view them as a means to implement human rights in the digital era through techno-legal platforms.

Techno-legal platforms are designed, regulated, and updatable digital products based on digital identity, aimed at realising human rights in digital era. These platforms ensure transparency, accountability, comprehensibility, and the efficiency of decisions based on technology, expanding everyone's opportunities to access social goods by integrating into specific life domains. This includes elements of big data, decentralisation, and transparency in decision-making, taking into account the achievements of the GovTech and CivTech sectors. These platforms may include mechanisms to protect personal data, ensure algorithmic decision-making transparency, and consider public interests.

The principle of techno-legal platforms operation is to align the corresponding digital human right with the techno-legal platform aimed at its implementation. This alignment allows for: first, the transformation of business processes in countries while reducing abuses in the development, implementation, and use of technologies in the public sphere (e.g., surveillance systems in public spaces not aimed at human rights realisation); second, placing technology management in a legal framework for long-term developmental perspectives; and third, addressing societal and individual needs in aspects of life quality, health, safety, and development expressed in human rights.

### Principle #2 - Whole of Government

#### **Motivation**

The public administration organisation is part of the national Digital Government Ecosystem. It should be fully interoperable with the rest of the ecosystem entirely using utilising benefits of available digital infrastructure.

#### **Rationale**

The principle refers to an approach in governance where all government agencies, departments, and ministries work collaboratively and cohesively towards achieving common goals and objectives. This approach recognises that many complex issues and challenges societies face require coordinated efforts across different sectors and levels of government.

Also, to digitize the public sector, organizations should use digital assets from others and provide their own. National infrastructure provides building blocks for the digitalization of any organization.

#### **Implications**

The principle of "Whole of Government" (WoG) has several implications for the digital transformation of a public sector organisation

1. Coordination and Collaboration: WoG implies that all government agencies collaborate closely in digital transformation efforts. This coordination ensures that digital initiatives are aligned with broader government goals, avoid duplication of efforts, and leverage the collective expertise and resources of different agencies.
2. Integrated Service Delivery: Digital transformation often involves delivering services to citizens in a seamless and integrated manner. By adopting a WoG approach, a public sector organisation should work together to streamline service delivery processes, eliminate silos, and provide citizens with a cohesive and user-friendly experience.
3. Data Sharing and Interoperability: WoG emphasizes the importance of data sharing and interoperability among government agencies. This means that data collected and maintained by different agencies should be easily accessible and interoperable, allowing for better data-driven decision-making, improved service delivery, and enhanced efficiency.
4. Holistic Policy Development: Digital transformation initiatives may require the development of new policies or regulations to govern the use of digital data and technologies. A WoG approach ensures that policy development is holistic, involving input from all relevant government agencies to address the complex and interconnected nature of digital issues.
5. Cybersecurity and Risk Management: Digital transformation introduces new cybersecurity risks and challenges that require a coordinated response across government agencies. A WoG approach enables agencies to collaborate on cybersecurity strategies, share threat intelligence, and coordinate incident response efforts to protect government systems and data from cyber threats.
6. Capacity Building and Skill Development: Digital transformation requires building the digital capabilities and skills of government employees. A WoG approach facilitates collaboration among agencies to develop training programs, share best practices, and build a skilled workforce capable of implementing and managing digital initiatives effectively.
7. Cross-Agency Innovation and Experimentation: WoG encourages innovation and experimentation by enabling government agencies to share ideas, resources, and lessons learned from digital transformation projects.
8. Public Engagement and Participation: Digital transformation initiatives should involve input and feedback from citizens and stakeholders to ensure that they meet the needs and expectations of the public.

### Principle #3 - Digital by Default

#### **Motivation**

The concept of digital transformation implies the shift towards a new era where paper-based communication might become obsolete, especially for upcoming generations. Therefore, it is important to ensure that all new processes and services are designed with a comprehensive digital user experience from the very beginning.

#### **Rationale**

In the context of digital transformation of a public sector organisation, the principle of "Digital by Default" refers to the strategic prioritization of digital channels and technologies as the primary means of delivering services, interacting with citizens, and conducting government operations.

This principle advocates for cultivating digital culture and designing services and processes with a digital-first mindset, making digital channels the default option for accessing government services, information, and transactions.

#### **Implications**

The principle of "Digital by Default" has several implications for the digital transformation of a public sector organisation:

1. Service Delivery Transformation: Adopting a "Digital by Default" approach means that a public sector organisation prioritise delivering services digitally as the primary channel for interactions with citizens and businesses. This implies a fundamental shift in the service delivery model, moving away from traditional, paper-based processes towards digital, online, and mobile-friendly services.
2. Accessibility and Inclusivity: While embracing digital channels, a public sector organization must ensure that their digital services are accessible to all citizens, including those with disabilities or limited digital literacy. This requires designing user-friendly interfaces, providing alternative access options, and offering assistance and support to vulnerable or marginalized groups to ensure inclusivity.
3. Cost Savings and Efficiency: Digital by Default leads to significant cost savings and efficiency gains for a public sector organisation by reducing the need for manual processes, paperwork, and physical infrastructure. Automation, self-service options, and streamlined workflows help to optimise resource utilization and improve service delivery efficiency.
4. Data-Driven Decision Making: Digital channels generate vast amounts of data that can be analysed to gain insights into citizen behaviour, preferences, and needs. A public sector organization should leverage this data to inform decision-making, improve service design, and enhance the overall user experience.
5. Change Management and Stakeholder Engagement: Implementing Digital by Default initiatives requires organisational change and stakeholder buy-in. A public sector organization must engage with stakeholders, including employees, citizens, businesses, and policymakers, to communicate the benefits of digital transformation, address concerns, and foster support for the transition to digital service delivery.
6. Continuous Improvement and Iteration: Digital transformation is an ongoing process that requires continuous improvement and iteration. A public sector organization should embrace an agile and iterative approach to digital service delivery, incorporating feedback from users, monitoring performance metrics, and adapting strategies based on evolving needs and technological advancements.

### Principle #4 - No legacy software

#### **Motivation**

One of the main problems faced by digitally advanced countries around the world is the presence of legacy software systems. These systems are expensive to maintain and often offer no options for extension or updating. Therefore, new systems must be designed in a way that overcomes these issues.

#### **Rationale**

The principle of "No Legacy Software" in the context of digital transformation for a public sector organization refers to the strategic decision to minimize or eliminate the use of outdated or legacy software systems during the modernization process.

This principle advocates for migrating away from legacy systems towards modern, scalable, and sustainable digital solutions.

At large, software systems should be composed of reusable building blocks with viable support, which ensures at least every year new version update.

Lifecycle of software should have a clear end date and decommissioning costs should be planned and accrued from the time of acquisition.

#### Implications

1. Limited lifecycle: Every solution should have at most 5-7 years of lifecycle. At the end of the lifecycle, it should be replaced entirely.
2. Minimizing Dependence on Outdated Technology: A public sector organization should aim to reduce reliance on legacy software systems that may be outdated, unsupported, or incompatible with modern technologies. These legacy systems pose risks such as security vulnerabilities, compliance issues, and limited scalability, hindering the organization's ability to adapt to evolving needs and technological advancements.
3. Migration to Modern Platforms: The principle of No Legacy Software encourages organizations to migrate to modern software platforms and architectures that offer greater flexibility, scalability, and functionality.
4. Enhancing Efficiency and Agility: By eliminating legacy software, a public sector organisation can streamline processes, improve operational efficiency, and enhance agility in responding to changing requirements and priorities.
5. Improving User Experience: Legacy software systems often lack user-friendly interfaces and may be cumbersome to use, leading to frustration among employees and stakeholders. Transitioning to modern software solutions with intuitive user interfaces and seamless user experiences enhances usability and satisfaction, driving higher adoption rates and productivity.
6. Reducing Maintenance and Support Costs: Maintaining and supporting legacy software systems is costly and resource-intensive, requiring ongoing investments in maintenance, upgrades, and technical support. Transitioning to modern software solutions with lower total cost of ownership (TCO) helps a public sector organization allocate resources more efficiently and focus on delivering value-added services and initiatives.

### Principle #5 - Once-Only

#### Motivation

Citizens and businesses should only have to provide information to the government once. Data should be reusable across agencies.

#### Rationale

The principle of "Once Only" in the context of the digital transformation of a public sector organisation refers to the concept of capturing and reusing information or data provided by citizens or businesses only once rather than repeatedly requesting the same information across multiple interactions or transactions and across different organisations within the public sector.

#### Implications

1. Data Sharing and Integration: The Once Only principle involves establishing mechanisms for sharing and integrating data across different government agencies and departments.
2. Single Point of Entry: A public sector organisation implements digital platforms or portals that serve as a single point of entry for individuals and businesses to access government services, submit applications, and complete transactions in specific regulated functional areas.
3. Interoperability and Standardization: Adopting interoperability standards and data exchange protocols enables different government systems to communicate and share information seamlessly.
4. Consent and Privacy Protection: The Once Only principle emphasizes obtaining consent from individuals or businesses before sharing or reusing their data for other purposes unless such reuse is allowed explicitly by legislation.
5. Efficiency and Cost Savings: By minimizing duplication of effort and data entry, the Once Only principle helps public sector organizations improve operational efficiency, reduce administrative costs, and optimize resource utilization.
6. Accuracy and Data Quality: Reusing data provided by individuals or businesses in previous interactions helps ensure the accuracy and quality of information used by government agencies.

### Principle #6 - Customer-centricity

#### Motivation

Services should be designed around user needs and experience. The government should adopt an outside-in perspective.

#### Rationale

The principle of "User-Centric Government" in the context of digital transformation for a public sector organization emphasizes designing and delivering services, policies, and processes to the needs, preferences, and experiences of users, such as citizens, businesses, and other stakeholders, at the forefront. It involves prioritizing user satisfaction, accessibility, and usability throughout the design and implementation of digital services and initiatives.

#### Implications

1. Understanding User Needs: User-centric government requires a public sector organisation to proactively gather insights into the needs, behaviours, and preferences of their users, i.e., conducting user research, surveys, and usability testing to understand the diverse needs and expectations of citizens, businesses, and other stakeholders.
2. Designing Intuitive Interfaces: A public sector organisation should prioritize designing digital interfaces and platforms that are intuitive, user-friendly, and accessible to a wide range of users, including those with disabilities or limited digital literacy, i.e., adopting principles of responsive design, clear navigation, intuitive workflows, etc.
3. Personalization: User-Centric Government involves tailoring services and content to the specific needs and preferences of individual users whenever possible. A public sector organisation should leverage data analytics and user profiling techniques to deliver personalized experiences, recommendations, and content that are relevant and meaningful to each user.
4. Empathetic Communication: A public sector organisation should provide clear and timely information, guidance, and support to users, addressing their concerns and needs with empathy and respect.
5. Feedback and Continuous Improvement: A public sector organisation actively solicit feedback from users and stakeholders to identify areas for improvement and enhance the user experience, i.e., gathering insights through feedback forms, user surveys, and social media channels, and using this input to iterate and improve digital services and processes over time.
6. Multi-Channel Engagement: User-Centric Government recognizes that users may have different preferences for how they interact with government. A public sector organisation should offer multiple channels for engagement, including online portals, mobile apps, phone support, and in-person services.

### Principle #7 - Natural Digital Environment

#### Motivation

Instead of doing its own portals a public sector organisation should seek for options to deliver digital services to people’s natural digital environments.

#### Rationale

The principle of "Natural Digital Environment" in the context of digital transformation for a public sector organisation refers to creating an ecosystem where digital technologies seamlessly integrate into the daily lives and activities of citizens, businesses, and government entities. It involves fostering an environment where digital solutions are intuitive, ubiquitous, and supportive of human activities, interactions, and workflows.

#### Implications

1. Seamless Integration of Digital Technologies: A public sector organisation strives to integrate digital technologies seamlessly into the daily lives and activities of users, making them an inherent and natural part of the environment. This involves embedding digital solutions into existing processes, systems, and infrastructures to enhance efficiency, accessibility, and usability.
2. Ubiquitous Access to Digital Services: The Natural Digital Environment principle ensures ubiquitous access to digital services and information across different devices, platforms, and locations.
3. Contextual Relevance and Personalization: A public sector organisation should leverage data and contextual information to deliver users personalised and relevant digital experiences, i.e., tailoring content, recommendations, and services based on user preferences, location, behaviour, and past interactions.
4. Integration with Physical Spaces and Infrastructures: A public sector organisation should leverage digital technologies to enhance physical spaces and infrastructures, creating smart environments that are connected, responsive, and adaptive, i.e., deploying sensors, IoT devices, and other technologies to collect data, monitor environments, and optimise resource usage in areas such as transportation, energy, and urban planning.

### Principle #8 - Public and Private Sector Co-creation

#### Motivation

The current phase of digital transformation should be viewed as a national economy and society transformation. Thus, public sector organisations should avoid mere automation of internal processes and actively seek to transform the value creation by engaging private sector stakeholders.

#### Rationale

Many public sector organisations still use internal processes designed with technology constraints from the 19th century. However, modern society's widespread internet and computer literacy have created a new platform for interaction between parties. To improve customer experience, the public sector must abandon their legacy processes and embrace these new platforms.

The principle of "Public and Private Sector Co-creation" in digital transformation for a public sector organisation refers to collaborative efforts between government entities and private sector organisations to jointly develop, implement, and improve digital solutions and initiatives.

This principle emphasises partnership and collaboration between the public and private sectors to leverage their respective strengths, expertise, and resources in driving innovation, efficiency, and effectiveness in digital transformation efforts.

In the context of building a digital government ecosystem, an important aspect of public-private partnership is the interaction with stakeholders from the startup ecosystems of countries, which often utilize the latest technological advancements (generative AI, Web 3.0, Industry 4.0 in the redesign of state systems in a human-centered direction). This will allow the private sector of technology entrepreneurs to engage in initiating and developing Govtech, Legaltech, Civtech products jointly with the public sector. Such a pooling of resources will achieve sustainability, transparency, decentralization of the process and will increase economic efficiency and reduce the risk of duplicative actions in both sectors.

Therefore, it is worth paying attention to young startups that may already be trying to solve these problems, and allow them to undertake this work jointly with the public sector.

#### Implications

1. Shared Vision and Objectives: Public and private sector organisations align on common goals and objectives for digital transformation initiatives, fostering a shared vision for the desired outcomes and impact. This collaborative approach ensures that both parties are committed to driving positive change and delivering value to citizens, businesses, and society.
2. Complementary Expertise and Resources: Public and private sector organisations bring complementary expertise, capabilities, and resources. Public sector organisations offer domain knowledge, regulatory expertise, and a deep understanding of citizen needs and priorities. In contrast, private sector companies bring technical expertise, innovative solutions, and agile methodologies to the partnership.
3. Co-design and Co-development: Public and private sector organisations collaborate in co-designing digital solutions and initiatives, i.e., involving stakeholders from both sectors in the ideation, design, prototyping, and testing phases, ensuring that solutions meet the needs and expectations of end-users and stakeholders.
4. Joint Investment and Funding: Public and private sector organisations may share the financial investment and funding for digital transformation initiatives. This may involve public sector organisations providing funding, grants, or incentives to support private sector innovation and participation, while private sector companies contribute resources, expertise, and technology solutions.
5. Open Innovation and Knowledge Sharing: Public and private sector organisations embrace open innovation principles and knowledge-sharing practices to drive collaboration and mutual learning. This involves sharing best practices, lessons learned, and success stories from digital transformation initiatives and fostering a culture of innovation, experimentation, and continuous improvement.
6. Agile and Iterative Approach: Public and private sector organisations adopt an agile and iterative approach to co-creation, allowing for flexibility, adaptability, and responsiveness to changing requirements and priorities. This iterative process involves rapid prototyping, feedback loops, and incremental improvements, enabling solutions to evolve based on user feedback and real-world experiences.
7. Long-term Partnership and Sustainability: Public and private sector organisations foster long-term partnerships and collaborations to ensure the sustainability and scalability of digital transformation efforts. This involves establishing governance structures, communication channels, and performance metrics to monitor progress, evaluate outcomes, and drive continuous collaboration and improvement.

### Principle #9 - Cross-border by Default

#### Motivation

Services should cater to citizens' needs regardless of location.

#### Rationale

The principle of "Cross-border by Default" in the context of the digital transformation of a public sector organisation refers to the design and implementation of digital services and processes with a proactive approach to ensure they are inherently accessible and functional across national borders.

This principle is particularly relevant within frameworks such as the European Union's digital single market, where interoperability and standardisation across member states are critical for the seamless delivery of services to citizens and businesses regardless of location. Also, it is equally relevant for GCC countries, African Union countries and other areas of regional cooperation.

#### Implications

1. Interoperability: Services are designed to work across different systems, administrations, and borders, using common standards and protocols.
2. Inclusion and Accessibility: Digital services should be accessible to all users, including those from different countries, and should cater to various languages and accessibility needs. This process involves the availability of digital services and the realisation of human rights in the digital era for the population residing within the state's territory (citizens, stateless persons, foreign nationals, refugees, and other categories of individuals).
3. Standardization: Adopting widely accepted standards and practices facilitates the integration and compatibility of digital services across borders, i.e., data formats, security protocols, and communication standards.
4. Collaboration and Sharing: Encouraging the sharing of digital solutions, best practices, and resources between countries.
5. Legal and Regulatory Frameworks: Ensuring that digital services comply with the legal and regulatory requirements of all the jurisdictions they operate in.
6. Privacy and Security: Given the cross-border nature of services, robust measures to protect user data and ensure the security of digital services are paramount, i.e., adherence to international standards and practices for data protection and cybersecurity.

### Principle #10 - Intrinsic Security & Privacy

#### Motivation

Security and privacy should be embedded into systems immediately, not as an afterthought. This is sometimes referred to as “security and privacy by design”.

#### Rationale

The principle of "Intrinsic Security & Privacy" within the digital transformation of a public sector organisation emphasises that security and privacy considerations are integrated into the design and architecture of digital systems from the outset, rather than being added as an afterthought.

This approach is foundational in building trust and ensuring protecting sensitive information and personal data managed by public sector entities.

#### Implications

1. Privacy by Design: This concept involves incorporating privacy into the initial design stages and throughout the lifecycle of any system, service, or process that handles personal data.
2. Security by Design: Similar to Privacy by Design, Security by Design requires that security measures are built into the infrastructure and processes of digital services from the beginning.
3. Data Minimization: Only collecting data that is directly relevant and necessary to accomplish a specified purpose.
4. End-to-end Encryption: Encrypting data at its origin and decrypting it only at its final destination without decryption at intermediate points ensures the confidentiality and integrity of the data while in transit.
5. Regular Security and Privacy Assessments: Conduct ongoing evaluations of security and privacy practices to ensure they are up-to-date with current threats and regulations, i.e., vulnerability assessments, penetration testing, and compliance audits.
6. User Control and Transparency: Providing users with clear information about how their data is used and ensuring they have control over it, i.e., mechanisms for consent, data access, correction, and deletion.
7. Compliance with Laws and Regulations: Adhering to all relevant privacy and security laws and regulations.
8. Employee Training and Awareness: Ensuring that all personnel involved in the design, development, and maintenance of digital services are trained in best practices for privacy and security.

## 5.3 Digital Public Infrastructure Assessment

The digital transformation of a public administration organisation can significantly benefit from reusable national digital infrastructure components. For instance, all self-service portals nationwide should identify users and verify their authority to perform specific roles. This means that identification and authorisation services should be established once and utilised by all self-service portals. Numerous other components or building blocks exist that any organisation building a digital services delivery platform should reuse.

Realistic understanding of status of national digital infrastructure is important input for building digital transformation roadmap of an organisation.

National Digital Infrastructure Assessment should provide information about following aspects:

* What are approved principles and policies, to which organisation should adhere?
* What is national digital transformation governance framework?
* What is national digital transformation legal framework?
* How extensively does the national legal framework incorporate human rights in the digital era and SDG?
* What is national digital access infrastructure status?
* What is national digital data management infrastructure status?
* What is national interoperability infrastructure status?
* What is national digital identity infrastructure status?
* What kind architectural building blocks are readily available? See list of building blocks in the Annex 1.

GovStack has a tool for quick assessment of those aspects of the National Digital Infrastructure Assessment.

## 5.4 Organisational Assessment & Roadmap

In section 5.1, we have described five organisation maturity levels related to the set of processes and capabilities available in the organisation to support digital transformation.

Before one starts developing a roadmap for digital transformation, we recommend assessing capabilities to understand the possible level of complexity of the project and what can be tackled by the organisation.

Conducting an organisational maturity assessment to define a public administration's readiness for digital transformation involves evaluating various dimensions of the organisation's operations, culture, technology infrastructure, and capabilities. This process helps to identify the current state of digital maturity, pinpoint areas for improvement, and guide strategic planning for digital transformation.

Here’s a structured approach to conducting such an assessment.

### 1. Define Assessment Criteria and Dimensions

Start by defining the criteria and dimensions critical for digital transformation in your public administration context. We recommend using the dimensions, which are described in section 4:

* Management & Architecture
* Digital service delivery
* Data-driven decisions
* Digital co-creation

### 2. Develop Assessment Tools

Create or adapt assessment tools that can accurately measure the organisation’s status across the defined dimensions. Tools might include:

* Surveys and Questionnaires: To gather input from staff at all levels on their perceptions of digital maturity, challenges, and opportunities.
* Interviews and Focus Groups: To collect qualitative insights from key stakeholders, including leadership, IT staff, and end-users of digital services.
* Document Review: To assess existing strategies, policies, and plans related to digital transformation.
* Technology Audits: To evaluate the current IT infrastructure, software applications, and data management practices.

We recommend using the GovStack assessment tool, which already has a predefined set of questions and assessment methodology.

### 3. Conduct the Assessment

Implement the assessment tools across the organisation, ensuring broad and representative participation. Collect data systematically and ensure confidentiality where necessary to encourage honest and constructive feedback.

### 4. Analyse the Results

Compile and analyse the data to identify strengths, weaknesses, opportunities, and threats related to digital transformation. Use the findings to score the organisation’s maturity level for each dimension.

### 5. Develop Recommendations

Based on the analysis, develop specific, actionable recommendations for each dimension to move the organisation towards higher levels of digital maturity. Recommendations should be prioritised based on their impact on service delivery, operational efficiency, and strategic goals.

We recommend using:

1. Reference models from section 4.6 to see the potential architecture needed for your organisation.
2. The organisation maturity model is in section 5.1 to plan organisational capacity development.
3. Principles from section 5.2 to plan for target capabilities.
4. Outcomes from digital infrastructure assessment as per section 5.3.

### 6. Create an Action Plan

Translate recommendations into a comprehensive action plan that outlines initiatives, responsible parties, timelines, required resources, and performance metrics. The plan should be aligned with the organisation's overall strategic objectives and include short-term wins and long-term strategies.

### 7. Implement, Monitor, and Review

Begin implementing the action plan, monitoring progress regularly against the established metrics. Maintaining flexibility to adjust strategies based on emerging trends, technological advances, and stakeholder feedback is essential.

### 8. Continuous Improvement

Digital transformation is an ongoing process. Regularly revisit the maturity assessment, perhaps annually, to reflect on progress, reassess maturity levels, and identify new areas for improvement.

## 5.6 Sourcing Strategy

The optimal sourcing strategy for a digital transformation initiative in a public administration organisation balances cost, quality, innovation, risk management, and alignment with strategic goals. It involves determining the best mix of in-house capabilities and external services (such as cloud services, software providers, and consulting firms) to achieve the digital transformation objectives.

The strategy should consider immediate needs, long-term sustainability, and adaptability to change. The following is a non-exhaustive list of recommended considerations.

1. Internal Capabilities: To achieve digital transformation goals, you must assess internal capabilities and needs. This means evaluating the current IT infrastructure, software solutions, and staff skills, and identifying gaps and strengths. Additionally, you must define future requirements, such as needed capabilities, technologies, and services, to create a roadmap for implementation.
2. Define Sourcing Objectives:
   1. The sourcing strategy should aim to improve service delivery, increase efficiency, or enhance cybersecurity.
   2. The sourcing strategy should aim for a cost-effective mix of sourcing options without compromising quality or strategic objectives.
   3. The strategy should be flexible and scalable. It should allow the organization to adjust solutions based on demand and adapt to emerging technologies.
3. Evaluate Sourcing Options: When considering the development of software and change management, there are different approaches that can be taken:

   1. Examine what can realistically be created and maintained by internal teams based on their skills and workload.
   2. If there are capabilities that are not available in-house, consider outsourcing options such as software development, cloud services, data analytics, or cybersecurity.
   3. Explore the possibility of strategic partnerships with technology firms, government agencies, academic institutions, or NGOs (for example, GovStack) to leverage their expertise and resources.

   Typically, a combination of in-house development, outsourcing, and partnerships provides the most flexibility and efficiency.
4. To manage risks associated with outsourcing, develop a Risk Management Framework. Identify potential risks and develop strategies to mitigate them. Implement governance and performance monitoring by setting up clear structures to manage relationships with providers and monitor their performance against agreed-upon metrics and standards.
5. Get all stakeholders to support the sourcing strategy. Use change management to manage concerns and ensure a smooth transition.
6. The sourcing strategy should be regularly reviewed and adapted to keep up with technological advancements and organisational goals.

## 5.7 Recommended Roadmap

### 5.7.1 Overview

If a country is in the initial phase of digital transformation and there is a will to follow the GovStack approach, then the logic for sequencing steps would be as follows:

<figure><img src="https://2983968174-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FWNaBkXRH5GkT1VCcv0BB%2Fuploads%2Fgit-blob-6d6579f5d93f4783972dfbfa4c6aa75f03ac1f17%2FScreenshot%202024-05-29%20020710.png?alt=media" alt=""><figcaption><p>Figure 22 - Suggested phasing for implementation of BBs</p></figcaption></figure>

All components on this diagram are explained in section 4.6 above. With different colour we highlight recommended phases of the implementation:

* **1st phase** – Inception with focus on introduction to GS methodology and planning.
* **2nd phase** will focus on identification of High Priority use cases with subsequent rapid prototyping and fast-track implementation to show the value of BB-based development.
* **3rd phase** should start with first wave of industrial digitalisation of the highest priority functional areas in a country.
* **4th phase** should complete full digitalisation of all governmental services in a country.

General logic of the sequencing of activities is following:

* There is always should be visible for citizens and business positive impact.
* All mandatory internal prerequisites should be in place before any governmental service can be introduced to external customers to mitigate risks.

Below is the description of the suggested high-level roadmap in terms of activities and outcomes.

### 5.7.2 Inception Phase

The Inception Phase activities and impact can be depicted in the following way:

<figure><img src="https://2983968174-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FWNaBkXRH5GkT1VCcv0BB%2Fuploads%2Fgit-blob-d951391c74d6a08c84939d121ef100fe4c7f2e49%2Fimage22.png?alt=media" alt=""><figcaption><p>Figure 23 - First Phase activities &#x26; value (Source: Aare Lapõnin)</p></figcaption></figure>

#### Activities

* Activity 1.1: In the initial phase of digital transformation planning, the country's central IT organisation should objectively assess national digital capabilities. This will provide a basis for realistic change planning. Based on the assessment outcome, the legal and governance framework should be adjusted. Create a centralised Change Management team to monitor the progress of the implementation of the GS approach.
* Activity 1.2: It is crucial to promote the use of BB-based approach for automation among a wide range of government officials. GovStack provides Deep Dive sessions for this purpose, which allow senior staff from the country's MDAs to gain first-hand experience of digital transformation in digitised countries. During these sessions, it is essential to select high-priority use cases that can be quickly implemented using the GovStack approach to demonstrate its validity to country officials and the public.
* Activity 1.3: It is crucial that a country's Ministries, Departments, and Agencies (MDAs) are not left to struggle with data centres, servers, networks, and related technologies. The recommended approach is for the country's central IT organisation to establish a governmental cloud that can seamlessly host all solutions from all MDAs.
* Activity 1.4: The Identity, Payment, and No-code/Low-code Development building blocks should be implemented to support subsequent rapid high-priority use cases implementation.

#### Building Blocks

During the inception phase following BBs should be adopted:

* Identity BB – it enables personalised and legally binding transactions.
* Payment BB – often transaction is associated with a fee; it should be possible pay it in online, that will enable fully digital transactions.
* No-code/Low-code Development – this will enable rapid prototyping and fast-track delivery of production-ready solutions. As far as GovStack highest priority is really working service as soon as possible, this component is the highest priority.

#### Value & Impact

For Citizens & Businesses:

* Enabling of cashless, fully online remote service delivery

For Government:

* Acquiring Ground Floor capabilities, i.e. understanding of digital initiatives life-cycle, essential risk management, sourcing skills
* Basic understanding of GS Approach

### 5.7.3 High-priority Use Case Implementation

The High Priority Use Cases (HPUC) Phase activities and impact can be depicted in the following way:

<figure><img src="https://2983968174-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FWNaBkXRH5GkT1VCcv0BB%2Fuploads%2Fgit-blob-f99ac9a9a8c5d234ddfb751215de96b7839e4668%2Fimage23.png?alt=media" alt=""><figcaption><p>Figure 24 - Second Phase activities &#x26; value (Source: Aare Lapõnin)</p></figcaption></figure>

Activities

* Activity 2.1: If the country has not yet adopted a consolidated portal for citizens and businesses, the MyGov component should be implemented as a front-end for the high-priority use cases (HPUC).
* Activity 2.2: The implementation of HPUCs should begin with the rapid prototyping of the overall solution, followed by the immediate engagement of a local system integrator, who can implement and roll out the target solution in just a few months.
* Activity 2.3: Besides implementing HPUCs, detailed GovStack methodology training should be done for all MDAs nationwide to ensure widespread awareness.

#### Building Blocks

During the inception phase, the following BBs should be adopted:

* The initial version of MyGov environment as a One-Stop Shop for individuals and businesses.
* To support the fast-track implementation, most infrastructural BBs should be implemented, i.e., at least an Information Mediator (IM), Registration, GIS, Workflow, Messaging, QR Code, E-signature, Adapters, and Consent should be adopted.

#### Value & Impact

For Citizens:

* There is s a One-Stop Shop for all digital transactions with the Government.
* Access to end-to-end digital experience.

For Businesses:

* Primary business life-cycle services are end-to-end digitalised and convenient.
* Regulatory information is accessible and trustworthy.

For Government:

* Acquiring 1st Level of capabilities, i.e., data can be trusted, and solid risk management is in place.
* There is first hands-on experience of fast-track delivery using BBs.

### 5.7.4 Initial Transformation

The Initial Transformation Phase activities and impact can be depicted in the following way:

\\

<figure><img src="https://2983968174-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FWNaBkXRH5GkT1VCcv0BB%2Fuploads%2Fgit-blob-8527461b45251ed96f9943e49bf859cf927ba7a6%2Fimage24.png?alt=media" alt=""><figcaption><p>Figure 25 - Third Phase activities &#x26; value (Source: Aare Lapõnin)</p></figcaption></figure>

#### Activities

GovStack approach enables the industrialisation of the country’s public sector digital transformation. First two phases prepared required prerequisites as initial awareness and internal organisational dynamic capabilities. Now the country can select priority functional areas of public administration and transform it.

It is essential to synchronise activities in this phase with the overall legal and governance framework adjustments to ensure that the legislation supports all planned changes and that institutional changes are enabled.

* Activity 3.1: Implementation of a modern digital front-end, including a Digital Wallet and mobile app for all transactions with the public sector (MyGov), should be done.
* Activity 3.2: All main state registries (as indicated in Annex 3) should be digitalised.
* Activity 3.3: Automation for all MDAs in the selected areas should be accomplished.

The duration of this phase should be time-boxed and should not exceed 2-3 years.

#### Building Blocks

During this phase all GovStack infrastructural BBs should be adopted and used for solutions.

#### Value & Impact

For Citizens:

* All services are end-to-end, digitalised, and convenient.
* There is remarkably less bureaucracy.

For Businesses:

* All services are end-to-end, digitalised, and convenient.
* There is remarkably less bureaucracy.

For Government:

* Acquiring 2nd Level of capabilities, i.e., architecture is managed, and digital service delivery is based on the ITIL framework.
* There is a capacity for fast-track delivery in priority areas.

### 5.7.5 Mass-scale Transformation.

The country acquired enough capabilities during the previous 3 phases to leap-frog to the Digital Era.

At that point, the legal and governance framework should be fully adjusted. All horizontal systems should be in place to support smooth transformation.

The Mass-scaled Transformation Phase activities and impact can be depicted in the following way:

<figure><img src="https://2983968174-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FWNaBkXRH5GkT1VCcv0BB%2Fuploads%2Fgit-blob-1ef9f7221223d12021220a9e0eb2c29a9dad8e5a%2Fimage25.png?alt=media" alt=""><figcaption><p>Figure 25 - Fourth Phase activities &#x26; value (Source: Aare Lapõnin)</p></figcaption></figure>

Activities

* Activity 4.1: A Comprehensive National Digital Transformation Roadmap for the digital transformation of the whole public sector should be prepared.
* Activity 4.2: Complete digitalisation of public sector should be implemented using fast-track delivery factory.

#### Building Blocks

During this phase all GovStack BBs should be adopted and used for solutions.

#### Value & Impact

For Citizens:

* Social and health care services are widely available.
* Education services are equally available across the country

For Businesses:

* There are new jobs and export opportunities in the IT industry.
* Banking sector efficiency is very high.
* Telco sales are growing.
* Agriculture efficiency is growing fast.

For Government:

* Acquiring 3rd Level of capabilities, i.e., data-driven decisions and digital co-creation.
* All governmental solutions are open-sourced.
* Very high efficiency of operations


# 6. Annex 1 – Digital Infrastructure

## A1.1 Reference Model – National Level

In the reference model for the national level of digital governance ecosystem we present a list of main components, which should be presented in the target architecture.

### A1.1.1 Foundation

1\. Digital Forms of Law and Compliance Systems consist of provisions and norms that regulate digital transactions and promote the implementation and protection of human rights in the digital era within digital government systems. These rights encompass a wide range of digital freedoms and responsibilities, including:

* The right to access the Internet, digital identification tools, digital asset storage, and other digital technologies; the protection of life and personal, biometric, and biological data.
* The right to participate in the management of societal affairs, whether at the state level or potentially within future systems of global governance, through digital technological platforms.
* Rights related to the ownership, use, and management of digital property and assets, as well as the conduct of digital economic activities such as transactions and digital deals, and access to systems of digital security.
* Access to social services provided through digital technological platforms.
* Rights to access cultural values and educational resources digitally. These facets underscore the broad scope of human rights in the digital era, highlighting their crucial role in contemporary and future societal structures.

2\. E-Governance Frameworks: Strategies and policies that guide the implementation and evolution of digital services.

### A1.1.2 Access Pillar

1\. High-Speed Connectivity: Reliable and fast internet access is the backbone of digital services, ensuring that all citizens can connect to government platforms.

2\. Accessibility Features: Ensuring that digital services are usable by all citizens, including those with disabilities.

3\. Cybersecurity Framework: Robust security protocols and infrastructure to protect sensitive data and ensure privacy and trust in digital transactions.

### A1.1.3 Data Pillar

1\. Data Centres and Cloud Services: Efficient and secure data storage and processing capabilities that allow for scalability and resilience of digital services.

2\. Monitoring and Analytics Tools: Systems to analyse service delivery and usage patterns, leading to informed decision-making and service improvements.

3\. Data protection institutional infrastructure.

### A1.1.4 Interoperability Pillar

Interoperable Platform: An ecosystem that facilitates data exchange and integrated services across different government departments. The following components should be part of the ecosystem.

1. API Management Tools: These tools are used to create, publish, and manage APIs, which are sets of protocols for building and interacting with software applications. They help in securing, scaling, and monitoring API traffic.
2. Identity and Access Management (IAM): This component ensures that the right organisations can access the right resources at the right times and for the right reasons.
3. Data Format and Transformation Services: These services convert data from one format to another so that different systems can understand and use the information without manual intervention
4. Registry/Repository Services: Central directories where metadata, services, and components are catalogued and can be queried or invoked. They help in service discovery and management.
5. Security Services: This includes encryption, digital signatures, secure data transmission protocols, and other cybersecurity measures to ensure data integrity and confidentiality.
6. Monitoring and Logging Services: These services track the health and usage of the interoperability platform, recording data on transactions, performance, and potential security incidents.
7. Business Rules Management: A system for defining, deploying, monitoring, and maintaining the complex decision logic used by system processes.
8. Workflow and Business Process Management (BPM): Tools that allow for the design, execution, and automation of business processes involving multiple interconnected systems.
9. Master Data Management (MDM): Software that ensures the uniformity, accuracy, stewardship, semantic consistency, and accountability of the enterprise's official shared master data assets.
10. Service Orchestration: The middleware that coordinates and combines services, resources, and data into complex business processes across the interoperability platform.

### A1.1.5 Identity Pillar

Digital Identity and Authentication: Secure and accessible means for citizens to verify their identities online to access various services.

A national identity ecosystem is a framework that enables the trusted establishment, use, and interoperability of digital identities. It should have following components.

1. Identity Management Systems (IdMS): These systems manage the lifecycle of digital identities, including creation, maintenance, and deletion, i.e., registration, de-registration, identity proofing, and credential management.
2. Authentication Services: These services verify users' identities when they log in or access services. They may support various mechanisms such as PKI-based authentication, biometrics, one-time passwords (OTPs), security tokens, and multi-factor authentication (MFA), etc.
3. Authorization Services: Once authentication is verified, these services determine what resources or services the user can access based on their identity, roles, and policies.
4. Credential Management: This involves the issuance, renewal, revocation, and management of digital credentials that assert identity attributes, such as digital certificates.
5. Public Key Infrastructure (PKI): PKI is a framework that creates, manages, distributes, uses, stores, and revokes digital certificates and manages public-key encryption, enabling secure electronic transfer of information.
6. Federated Identity Management: This enables users to access multiple applications and services with one set of credentials. It includes Identity Federation Hub, a centralised service connecting various identity providers and service providers to facilitate cross-domain authentication and authorisation.
7. Single Sign-On (SSO): A user authentication process that allows a user to access multiple applications with one set of login credentials.
8. Civil Registry Integration: Software components that integrate with civil registry databases to ensure that identity data is consistent with official government records. This also includes biometric systems integration, which uses physical characteristics (fingerprints, facial recognition, iris scans, etc.) to identify individuals uniquely.
9. User Self-Service Interfaces that allow users to manage their profiles, reset passwords, and update personal information.
10. Audit and Compliance Reporting Tools: Systems to monitor and report on identity-related activities, ensuring compliance with legal and regulatory requirements.
11. Privacy Management Tools: Software to manage and enforce policies related to the privacy of personal identity information.
12. Consent Management Platforms: Systems that manage user consent for data sharing and processing, which are vital for complying with privacy laws and regulations.

### A1.2 Reference Model – Organisational Level

#### A1.2.1 Taxonomy Overview

The COFOG Governmental Functions classification identifies 10 government functions, which are further divided into 69 functions. These can be carried out by hundreds or even thousands of public administration organizations at the federal, state, and local municipality levels. Each organization may have multiple performance outcome areas requiring digital transformation.

However, upon detailed analysis, it was found that the differences in those areas primarily lie in the data, whereas the required automation components are not that dissimilar.

#### **Public Sector Organisational Taxonomy**

Currently, we see that public sector intervention into the economy and society can be viewed as following main types of organisational architectures:

<table data-header-hidden><thead><tr><th width="107"></th><th></th><th></th></tr></thead><tbody><tr><td>ID</td><td>Type</td><td>Touchpoints with customers</td></tr><tr><td>1.</td><td>Policy development unit is making analysis, develop policies and monitor policies efficiency. Typical example of such a unit is a line ministry.</td><td><ul><li>Informal communication with stakeholders in society</li><li>Formal communication to prepare legislation.</li></ul><p><br></p></td></tr><tr><td>2.</td><td>Regulatory agency is responsible for specific area in society, which requires regulations and policies enforcement. For example, data protection authority, business registration, licensing etc.</td><td><ul><li>Formal communication with applicants and decision-making process regarding licenses &#x26; permissions</li><li>For one individual or company there are not many interactions: issuing license/permission, suspension and/or ending of license/permission.</li><li>Informal conflict resolution</li></ul><p><br></p></td></tr><tr><td>3.</td><td>Service delivery authority, which is not only involved in regulatory activities but also applies specialised methods to ensure enforcement of legal regulations. Examples: Police Department, Tax Department, Customs, Treasury, etc.</td><td><ul><li>Formal onboarding of customers</li><li>Most of the time recurrent service delivery</li><li>Solid training process to build awareness amongst external customers and skills for employees</li></ul></td></tr></tbody></table>

#### **Ecosystem**

In addition to the above three main types of public sector organisation there are several important elements in the public administration ecosystem:

* State registries. A state register is an official record-keeping system maintained by a government entity in which vital information is stored and managed. This can include records on individuals, such as births, marriages, and deaths; legal documents like property deeds and business licenses; or more specific registers like those for motor vehicles or professional credentials. State registers serve as a reliable source of legal documentation and are used to ensure public administration processes are accurate and effective.
* Government internal organisations, which are providing support services to other government organisations. We call systems in such organisations as Horizontal Systems.

PAERA facilitates an outward-looking approach to the public sector digital transformation, which puts the citizen’s ability to utilise digital services is in the centre of our attention. Hereunder PAERA introduces the concept of Natural Digital Environment and Sectoral Ecosystems.

The following describes the architectural building blocks that make up those architectures.

### A1.2.2 - 1st type: Policy Development Unit

#### **Business Model**

The Policy Development Unit (PDU) is the most basic bureaucratic organisational unit. The digital platform in this unit should support all main bureaucratic organisational activities. Digital support for such a basic unit should have at least two areas.

1. Direct support for specific function policy development and
2. Generic organisation management service (for example, HR, finance, etc.)

Examples: ministries, chancelleries of constitutional institutions (like the President, Prime Minister, etc.).

For the PDU type of organisation, a generalised business model can be described in the following way:

<figure><img src="https://2983968174-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FWNaBkXRH5GkT1VCcv0BB%2Fuploads%2Fgit-blob-2b911e20b5c80907033bd9f64d20d55b67f776e4%2Fimage26.jpg?alt=media" alt=""><figcaption><p>Figure 11 - PDU Business Model Canvas</p></figcaption></figure>

The following are details for the business model for PDU:

<table data-header-hidden><thead><tr><th width="175"></th><th width="260"></th><th></th></tr></thead><tbody><tr><td>Pillar</td><td>Component</td><td>Description</td></tr><tr><td>Product</td><td>Value proposition</td><td><p>1. Policy Development</p><ul><li>Responsible for specific functional area, i.e., defence, health, social care etc.</li><li>Develop and maintain legislation to regulate the area of responsibility.</li><li>Communicate with stakeholders explaining policies and identifying issues and needs.</li></ul><p><br></p><p>2. Supervision of policy implementation</p><ul><li>Set up KPI-s and needed reporting.</li><li>Staffing of managers</li></ul><p><br></p><p>3. Research</p><p><br><br></p></td></tr><tr><td>Customer interface</td><td>Customer Segment</td><td><ul><li>Population demographic groups</li><li>Economic agents</li><li>Non-profit organisations</li><li>Communities of interests and locations</li><li>Foreign investors</li><li>International organisations</li></ul><p><br></p></td></tr><tr><td></td><td><br>Communication</td><td><ul><li>n-person meetings with stakeholders</li><li>Media analysis</li><li>Insource of research from external professionals</li><li>Formal communication within the legislation development process with internal government stakeholders, i.e., other ministries, government, parliament etc.</li><li>Social media</li></ul></td></tr><tr><td></td><td><p>Customer Relationships</p><p><br></p></td><td><ul><li>Setup permanent relationships with industrial unions and NGO-s in the relevant functional area for economy or society</li><li>Setup close relations with media to be capable to build awareness campaigns for relevant society groups and economy agents.</li></ul></td></tr><tr><td>Infrastructure Management</td><td>Value Configuration</td><td><p>Group 1. Specific public administration capabilities:</p><ul><li>Policy development</li><li>Legislation development</li><li>Policy implementation monitoring</li><li>Processing of requests from stakeholders</li><li>Making decisions and delivering answers</li><li>Managed entities supervision</li><li>Coordination with EU and international stakeholders</li><li>Research</li></ul><p><br></p><p>Group 2. Policy development support activities:</p><ul><li>Documents management</li><li>Data gathering, data management and analytics.</li><li>Knowledge Management</li><li>Web Content Management</li><li>Process Management</li><li>Project Management</li><li>Teams Collaboration</li><li>Surveys Management</li><li>Engagement with stakeholders through social media</li></ul><p><br></p><p>Group 3. Generic organisation support capabilities:</p><ul><li>HR management, including structure management, job descriptions, hiring, etc.</li><li>Risk management</li><li>Budget, Finance, Procurement &#x26; Accounting</li><li>Strategic Management</li></ul><p><br></p></td></tr><tr><td></td><td><br>Staff and Resources</td><td><ul><li>Functional area expertise</li><li>Legal experts</li><li>Institutional building expertise</li></ul></td></tr><tr><td></td><td><p>Strategic Partners</p><p><br></p></td><td><ul><li>Parliament</li><li>Government</li><li>Ministries</li><li>Media</li><li>Industrial unions</li><li>Public</li></ul></td></tr><tr><td>Financial Aspects</td><td>Cost Structure</td><td><p>Main cost components:</p><ul><li>Staff salary</li><li>Office space</li><li>IT systems</li><li>Utilities</li></ul><p><br></p></td></tr><tr><td></td><td><p>Income Structure</p><p><br></p></td><td>Appropriate governmental-level Budget</td></tr></tbody></table>

#### **PDU Application Architecture Outline**

The following application architecture is needed to digitalise PDU activities:

<figure><img src="https://2983968174-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FWNaBkXRH5GkT1VCcv0BB%2Fuploads%2Fgit-blob-7b79d7e957bab4c7471cae8cd19d86c4e42a2ffa%2Fimage27.png?alt=media" alt=""><figcaption><p>Figure 12 - Reference Application Architecture for PDU Activities</p></figcaption></figure>

Here, we have three main areas of application architecture:

* **Channels** zone – implements secure omni-channel access capabilities for all external customers and stakeholders. This should be well standardised and use standard national digital infrastructure building blocks for security services like authentication, authorisation, digital signature, etc.
* **Infrastructure** – standard component to enable modern data-driven processing, including data collection from many different sources, data consolidation into analytical data sets, visualisation, etc. This zone should be fully standardised and ideally part of a governmental cloud.
* Public Administration **Core Services** automation support zone – implements application software components to support the activities of the PDU staff. Following is a description of those components for the core services support..

The Policy Development Unit (a ministry) is primarily responsible for formulating, analysing, and implementing policies in different functional areas. Such a unit requires a suite of software components that facilitate research, collaboration, data analysis, and stakeholder engagement.

1. Document Management Systems (DMS): These systems are crucial for creating, storing, managing, and tracking documents and revisions. A DMS helps maintain an organized repository of policy drafts, official documents, legal texts, and related materials, ensuring that the latest versions are always accessible.
2. Collaboration and Communication Tools: Software that enables effective communication and collaboration among team members, stakeholders, and other departments is essential. This includes email, instant messaging apps, video conferencing tools, and platforms that support collaborative document editing and sharing.
3. Data Analysis and Visualization Tools: Policy development relies heavily on data to inform decisions. Tools that can analyse large datasets, perform statistical analysis, and visualise data trends are critical. These tools help understand complex information, identify patterns, and present data in an easily digestible format for decision-makers.
4. Project Management Software: This software helps plan, execute, and monitor policy development projects. It can track progress, manage tasks, allocate resources, and keep timelines, ensuring policy initiatives progress as planned.
5. Stakeholder Engagement Platforms: Engaging with stakeholders is a key part of policy development. Platforms facilitating surveys, feedback collection, public consultations, and forums can help gather insights, concerns, and suggestions from the public, industry experts, and other relevant parties.
6. Content Management Systems (CMS): For policy units that publish reports, guidelines, or any public-facing documents, a CMS is vital. It allows for the easy creation, management, and publication of content on websites or intranets, ensuring that information is accessible to relevant audiences.
7. Legislative Tracking Software: This software helps monitor legislation and regulatory changes that could impact policy areas. It can track bills, regulations, and other legislative documents across various stages, providing alerts and updates relevant to the unit’s focus areas. Also, it integrates the PDU with national legislation drafting activities.
8. Research and Reference Management Software: Tools that assist in organising research materials, references, and bibliographies are essential for policy development. They facilitate the management of digital libraries, streamline the citation process, and support literature reviews.
9. Case Management: A case management system can be adapted to manage relationships and interactions with stakeholders, experts, and other external parties involved in policy consultation and feedback processes. Also, it provides visibility over performance and service delivery quality, providing capabilities to manage SLAs and KPIs.
10. Secure File Sharing and Storage Solutions: Given the sensitive nature of policy work, secure platforms for storing and sharing documents are necessary. These solutions protect sensitive information through encryption, access controls, and audit trails.
11. Risk Management and Compliance Software: This software helps identify, assess, and mitigate risks associated with policy proposals. It also ensures policies comply with existing laws and regulations, minimising legal and operational risks.
12. HR, Budget, and Accounting: all public administration organisations have standard corporate services implementation for budgeting operations and accounting of personnel, salary and resources.

By integrating these software components, a Policy Development Unit can enhance its efficiency, effectiveness, and responsiveness in policymaking.

These tools support the complex tasks of analysing data, managing projects, engaging with stakeholders, and ultimately developing policies that are well-informed, timely, and relevant.

**NOTE**: This set of components is required in all types of public administration organisation. We will refer to this set of building blocks as **Public Administration Organisation Core** **Components** (PAO-CC).

### A1.2.3 - 2nd type: Regulatory Agency

#### **Business Model**

The Regulatory Agency (RA) is responsible for the implementation of regulatory policies in some functional areas. They are accountable to PDU, which is in charge for the policy development in their functional area.

For the RA type of organisation, a generalised business model can be described in the following way:

<figure><img src="https://2983968174-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FWNaBkXRH5GkT1VCcv0BB%2Fuploads%2Fgit-blob-750d85ad26d8466e2276efb3d2343a041f238a0c%2Fimage28.jpg?alt=media" alt=""><figcaption><p>Figure 13 - RA business model canvas</p></figcaption></figure>

Examples: Financial Service Authority, Commercial Register, Trade Licenses, Data Protection Authority, etc.

The following are details for the business model for RA:

\\

<table data-header-hidden><thead><tr><th width="138"></th><th width="280"></th><th></th></tr></thead><tbody><tr><td>Pillar</td><td>Component</td><td>Description</td></tr><tr><td>Product</td><td>Value proposition</td><td><p>1. Policy Implementation regarding specific regulated governance functional area</p><ul><li>Detailed requirements formulation.</li><li>Design of application forms and procedures for application of license/permission.</li><li>Review and assessment of an application for license/permission.</li><li>Fee collection.</li><li>Issuing of licenses/permissions.</li><li>Register of license/permission management.</li></ul><p><br></p><p>2. Supervision of licensees</p><ul><li>Set up required regular reporting framework.</li><li>Collection of regular reports</li><li>Risk management</li><li>Intervention in case of high risk</li><li>Resolution of issues with non-compliant licensees</li></ul><p><br></p><p>3. Awareness campaigns to stakeholders and communities</p><p><br></p></td></tr><tr><td>Customer interface</td><td>Customer Segment</td><td><ul><li>Economic agents</li><li>Communities of interests and locations</li><li>Local &#x26; Foreign investors</li></ul><p><br></p></td></tr><tr><td></td><td>Communication</td><td><ul><li>Formal communication with Policy Development body to whom RA is accountable.</li><li>Formal communication with other relevant government stakeholders, i.e., other MDA-s, government, parliament etc.</li><li>Formal and informal communication with applicants and licensed agents</li><li>Awareness campaigns in traditional and social media</li><li>In-person training events</li><li>Training content delivery in digital channels</li><li>In-person meetings with stakeholders</li></ul></td></tr><tr><td></td><td><p>Customer Relationships</p><p><br></p></td><td><ul><li>Setup permanent relationships with industrial unions in the relevant functional area of economy or society</li><li>Setup close relations with media to be capable to build awareness campaigns for relevant society groups and economy agents.</li></ul></td></tr><tr><td>Infrastructure Management</td><td>Value Configuration</td><td><p>RA must have all Group 2 and 3 capabilities, which are listed for PDU in the section 4.2.1.</p><p><br></p><p>Group 4. In additional to that, there should be following specific public administration capabilities:</p><ul><li>Compliance management framework design</li><li>Digital service delivery</li><li>Regulated area risk management</li><li>Operational risk management</li><li>Business continuity management</li><li>Internal staff training regarding service delivery.</li><li>Design and delivery of training content to licensees and potential applicants.</li><li>Reporting to appropriate PDU</li></ul><p><br></p></td></tr><tr><td></td><td><p>Staff and Resources</p><p><br></p></td><td><ul><li>Functional area expertise</li><li>Risk management</li><li>Compliance management</li></ul></td></tr><tr><td></td><td><p>Strategic Partners</p><p><br></p></td><td><ul><li>Responsible PDU</li><li>Related (horizontally) MDA-s</li><li>Media</li><li>Industrial unions</li><li>Public</li></ul></td></tr><tr><td>Financial Aspects</td><td>Cost Structure</td><td><p>Main cost components:</p><ul><li>Staff salary</li><li>Office space</li><li>IT systems management</li><li>Utilities</li></ul><p><br></p></td></tr><tr><td></td><td><p>Income Structure</p><p><br></p></td><td>Appropriate level government Budget</td></tr></tbody></table>

#### RA Application Architecture Outline

The following application architecture is needed to digitalise regulatory agency (RA) activities:

<figure><img src="https://2983968174-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FWNaBkXRH5GkT1VCcv0BB%2Fuploads%2Fgit-blob-80cb21d45f742ec5c418e8ee51d2b62955bf878e%2Fimage29.png?alt=media" alt=""><figcaption><p>Figure 14 - RA application architecture reference model</p></figcaption></figure>

It includes all components from the PDU model, i.e. Channel zone, Infrastructure zone and Public Administration Core Components (PAO-CC). In addition, there are BBs for digital service delivery.

**1. Forms & Procedures Design**

Implementing forms and procedures design in a public administration regulatory agency requires software that supports creating, managing, and optimising digital forms and workflows.

The software should enable the organisation to design user-friendly forms, automate processes, and manage data efficiently:

* Intuitive Form Builder: A drag-and-drop interface that allows non-technical users to create and design forms quickly. This should include the ability to add various field types (e.g., text, dropdowns, checkboxes), validation rules, and conditional logic to show or hide fields based on user inputs.
* Workflow Design: Tools to define and automate business processes and workflows associated with forms.
* Integration Capabilities: Integrating with other systems and databases is crucial for automating data entry and retrieval, ensuring that form data can flow seamlessly between systems. This includes PAO-CC, such as Case Management, ERP, document management systems, and payment gateway.
* Data Validation and Verification: Features to validate form inputs in real-time to ensure data accuracy and completeness. This might include checking for valid email addresses and required fields and integrating with external databases for verification.
* Customisable Templates: A library of pre-built form templates that can be customized to suit different services and processes.
* Mobile Responsiveness: Forms should be accessible and easy to complete on any device, including smartphones and tablets.
* Multilingual Support: Features to create and manage forms in multiple languages, catering to a diverse population and ensuring inclusivity in service delivery.
* Feedback Mechanisms: Incorporating feedback forms or surveys to collect user feedback on the form-filling experience and the efficiency of the service delivery process.
* Version Control: Keeping track of changes made to forms and procedures over time, allowing for the rollback to previous versions if needed.

**2. Application Capturing & Processing**

Implementing application forms capturing and processing workflows in a regulatory agency involves managing the entire lifecycle of applications, from submission to final decision.

The software supporting these workflows must facilitate efficient, accurate, and user-friendly processes both for the applicants and the administrative staff:

* Automated Workflow Management: The ability to define, automate, and manage workflows associated with the application process, i.e., routing applications for review and approval, assigning tasks to specific staff members, setting deadlines, and automating notifications and reminders.
* Electronic Signatures and Document Uploads: Features that allow applicants to sign documents and securely upload necessary supporting documents electronically.
* Role-Based Access Control: The ability to define access levels for different users, ensuring that staff and applicants can only access information and functionalities relevant to their role in the application process.
* Reporting and Analytics: Tools to track and analyse application data, monitor workflow efficiency, and generate reports, including support for identification bottlenecks, tracking processing times, and improving service delivery.
* Communication Tools: Integrated communication tools for sending automated emails or messages to applicants regarding the status of their application, requests for additional information, and final decisions.
* Scalability: The software should be scalable to handle varying volumes of applications and adaptable to process changes or the introduction of new services.

**3. Payment & Refund processing**

Implementing payment and refund processing workflows involves handling financial transactions securely and complying with regulations.

The software supporting these workflows must facilitate efficient and accurate processing, provide a good user experience, and ensure the highest levels of security and compliance:

* Secure Payment Gateway Integration: Integration with secure and reliable payment gateways to process various forms of payment, including credit/debit cards, bank transfers, mobile money and digital wallets. The software should support multiple payment methods to accommodate the preferences of all users.
* PCI DSS Compliance: Adherence to the Payment Card Industry Data Security Standard (PCI DSS) and other relevant security standards to protect cardholder data during transactions.
* Flexible Refund Processing: The ability to process refunds efficiently, allowing for full or partial refunds directly through the platform. This should include automated workflows for approving and processing refund requests.
* Real-Time Transaction Processing: Capability to process payments and refunds in real-time, providing immediate feedback to users about the status of their transactions.
* Fraud Detection and Prevention: Security features to detect and prevent fraudulent transactions, including encryption, secure authentication, risk-based analysis, and monitoring of suspicious activities.
* Multi-Currency Support: The ability to process payments in multiple currencies is essential for organisations serving an international audience (e.g., foreign investors).
* Financial Reporting and Analytics: Tools for generating detailed financial reports and analytics, providing insights into payment volumes, refund rates, revenue, and other key financial metrics.
* Automated Receipt Generation: Automatic generation and sending of receipts for payments and refunds to users via email or available for download, providing proof of transactions.
* Audit Trails: Comprehensive logging of all transactions, including payments and refunds, to create an audit trail for compliance, dispute resolution, and financial auditing purposes.
* Integration with Financial System: Seamless integration with the organisation's financial system to automate the reconciliation process and ensure accurate financial records.
* Customer Support Tools: Integration with customer support tools to assist users with payment-related inquiries and issues, including refunds, transaction disputes, and technical problems.

**4. Decision Management**

Implementing Decision Management workflows in a public administration regulatory authority requires support for making, recording, and communicating decisions related to regulations, compliance, and enforcement actions.

This requires software that supports complex decision-making processes and ensures transparency. POA-CC components support such functionality. It only requires the configuration of specific workflows and document templates.

The following specific aspects, however, should be added:

* Notification and Communication Systems: Automated notifications and communication features to inform relevant parties about decisions, updates, or required actions. This could include email alerts, SMS notifications, or in-platform messages.
* Regulatory Compliance Management: Tools to ensure all decisions comply with applicable laws, regulations, and standards. This may include checklists, compliance tracking, and integration with legal databases.
* Integration with Public Access Portal: A portal for stakeholders and the public to access information on decisions, regulations, and compliance requirements.
* Customisable Dashboards: These provide an overview of decision-making activities, status updates, and key performance indicators (KPIs).
* 14\. Decision Modelling and Analytics: Tools for modelling decision processes and analysing decision outcomes. This can help identify patterns, predict impacts, and optimise decision-making strategies.

**5. Inspections Management**

Implementing inspection management workflows in a regulatory authority involves coordinating and tracking a wide range of activities, from scheduling inspections to recording outcomes and enforcing compliance.

POA-CC components support such functionality. It only requires the configuration of specific workflows and document templates.

The following specific aspects, however, should be added:

* Scheduling and Calendar Integration: Tools for scheduling inspections, including calendar integration that allows for easy assignment of inspectors and visibility into their schedules.
* Mobile Access and Offline Capability: Mobile applications or web access enable inspectors to access and input data in the field, even without an internet connection. Once a connection is re-established, the data should sync with the central system.
* Checklist and Form Customization: The ability to create, customise, and update inspection checklists and forms. This should include support for various types of data entry, such as text, checkboxes, dropdown lists, and photo uploads.
* Geolocation Services: Geolocation services are integrated to help plan routes, verify inspection locations, and log the location of an inspection for accountability and efficiency.
* Compliance Tracking and Enforcement: Tools to track compliance status, record violations, and manage enforcement actions such as fines, warnings, or follow-up inspections.
* Communication Tools: Integrated communication tools to facilitate direct communication between inspectors, regulated entities, and other stakeholders.

**6. Legal Affairs & Litigation**

Implementing Legal Affairs & Litigation workflows in a public administration regulatory authority involves managing various legal documents, cases, and processes efficiently and effectively.

The software supporting these workflows must be capable of handling complex legal operations, ensuring compliance, and facilitating collaboration among legal teams, other departments, and external parties.

Mostly POA-CC components support such functionality. It requires the configuration of specific workflows and document templates. The following specific aspects, however, should be added:

* Calendar and Deadline Tracking: Integration with calendars to track important dates, deadlines, hearings, and meetings. Automated reminders can help ensure that no critical dates are missed.
* Legal Research Tools: Access to legal databases and research tools within the platform to support legal analysis, precedent research, and case preparation.
* Security and Compliance: High-level security features to protect sensitive legal information, including encryption, access controls, and compliance with relevant legal and regulatory standards.
* Litigation Support: Features that support litigation activities, including evidence management, discovery process management, and integration with court filing systems.
* Financial Management: Integration with financial systems for managing legal budgets, expenses, invoicing, and cost recovery.
* Knowledge Management: A centralized repository for storing and sharing legal knowledge, such as memos, legal opinions, and guidelines, to support decision-making and ensure consistency.
* E-Discovery and Evidence Management: Tools for managing the collection, processing, review, and production of electronic documents as part of the discovery process.
* Complaint and Dispute Resolution Management: Mechanisms to track and manage complaints, disputes, and non-litigation cases, including mediation and arbitration processes.

### A1.2.4 - 3rd type: Service Delivery Authority

#### Business Model

The Service Delivery Authority (SDA) is the most complex governmental organizational unit. The digital platform in this unit should support not only internal processes automation, but also intensive communication with external customers. Examples: Customs, Tax Authority, Police Department, etc.

Digital support for such a unit may have many areas, including the following:

1. Support for strategic management and planning
2. Support for customer experience management and service delivery framework design
3. Core value chain automation systems, including G2B, G2C, and G2G integration with external customers.
4. Support for extensive data management
5. Generic organization management service (for example, HR, finance, etc.)

For the SDA type of organization, a generalized business model can be described in the following way:

<figure><img src="https://2983968174-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FWNaBkXRH5GkT1VCcv0BB%2Fuploads%2Fgit-blob-69bd7402d5da0e16b140d7539ffc434bc6cc4d66%2Fimage1.jpg?alt=media" alt=""><figcaption><p>Figure 15 - SDA business model canvas</p></figcaption></figure>

The following are details for the business model for RA:

<table data-header-hidden><thead><tr><th width="95"></th><th></th><th></th></tr></thead><tbody><tr><td>Pillar</td><td>Component</td><td>Description</td></tr><tr><td>Product</td><td>Value proposition</td><td><p>1. Policy Implementation regarding specific regulated governance functional area</p><ul><li>Detailed compliance requirements formulation.</li><li>Design of forms and procedures for policy requirements implementation in the regulated functional area.</li><li>Enforcement of requirements for agents in the regulated area.</li></ul><p>2. Supervision and enforcement of compliance in regulated area</p><ul><li>Regular data gathering</li><li>Risk management</li><li>Intervention in case of high risk</li><li>Resolution of issues with non-compliant licensees</li></ul><p><br></p><p>3. Awareness campaigns to external customers, stakeholders, and communities.</p><p><br></p><p>4. Gathering feedback from customers and stakeholders and adjusting the service delivery framework accordingly.</p><p><br></p></td></tr><tr><td>Customer interface</td><td>Customer Segment</td><td><ul><li>Economic agents</li><li>Communities of interests and locations</li><li>Local &#x26; Foreign investors</li></ul><p><br></p></td></tr><tr><td></td><td><br>Communication</td><td><ul><li>Formal communication with Policy Development body to whom SDA is accountable.</li><li>Formal communication with other relevant government stakeholders, i.e., other MDA-s, government, parliament etc.</li><li>Formal and informal communication with agents in regulated area</li><li>Awareness campaigns in traditional and social media</li><li>In-person training events</li><li>Training content delivery in digital channels</li><li>In-person meetings with stakeholders</li></ul></td></tr><tr><td></td><td>Customer Relationships<br></td><td><ul><li>Setup permanent relationships with industrial unions in the relevant functional area of economy or society</li><li>Setup close relations with media to be capable to build awareness campaigns for relevant society groups and economy agents.</li></ul></td></tr><tr><td>Infrastructure Management</td><td>Value Configuration</td><td><p>SDA must have all Group 2 and 3 capabilities, which are listed for PDU in the section 4.2.1.</p><p><br></p><p>Also, SDA must have Group 4 capabilities, which are listed for RA in the section 4.3.1.</p><p><br></p><p>Group 5. In additional to that, there should be following specific public administration capabilities:</p><ul><li>Performance management (for internal staff)</li><li>Service Management (SLA-based quality assurance for external customers)</li><li>Enterprise Architecture management</li><li>IT Planning and strategic management</li><li>IT Security management</li></ul><p><br><br></p></td></tr><tr><td></td><td>Staff and Resources<br></td><td><ul><li>Functional area expertise</li><li>Compliance management</li><li>Risk management</li><li>Business continuity management</li><li>Digital service delivery</li></ul></td></tr><tr><td></td><td><br>Strategic Partners</td><td><ul><li>Responsible PDU</li><li>Related (horizontally) MDA-s</li><li>Media</li><li>Industrial unions</li><li>IT provider</li><li>Customers’ IT development community</li><li>Public</li></ul></td></tr><tr><td>Financial Aspects</td><td>Cost Structure</td><td><p>Main cost components:</p><ul><li>Staff salary</li><li>Office space</li><li>IT systems management, including Digital Service management, EA management and Operational risk and business Continuity management.</li><li>Utilities</li></ul><p><br></p></td></tr><tr><td></td><td><p>Income Structure</p><p><br></p></td><td>Appropriate level of Government Budget</td></tr></tbody></table>

### SDA Application Architecture Outline

The following application architecture is needed to digitalise SDA activities:

<figure><img src="https://2983968174-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FWNaBkXRH5GkT1VCcv0BB%2Fuploads%2Fgit-blob-b9c966e576c9f14eacd623ebd423380f8000bfee%2Fimage2.png?alt=media" alt=""><figcaption><p>Figure 16 - SDA application architecture reference model</p></figcaption></figure>

It includes all the Regulatory Agency model components, i.e., Channel zone, Infrastructure zone, Public Administration Core Components (PAO-CC) and Regulatory Supervision & Compliance Monitoring components. In addition, there are BBs for digital service delivery for a massive number of transactions:

1. Registration & Profile Management
2. Customers & Users Management
3. Online Learning & Training
4. Customer Accounting
5. Compliance & Enforcement
6. Data Management

To a certain level, this functionality is also presented in the regulatory agency (RA) model. However, those components must be scaled up to the next level for service delivery in the context of massive transactions. For example, those functional components for RA can be implemented using low-code/no-code platforms. For SDA, this implementation requires custom development. to ensure performance and availability during workload peaks for millions of concurrent transactions.

**1. Registration & Profile Management**

Implementing Registration & Profile Management in a service delivery organisation involves managing business and/or citizen information securely and efficiently while ensuring easy access and interaction for users.

The software supporting these functions must be robust, user-friendly, and secure, facilitating the management of personal and financial information.

* Customer Registration, Authentication and Authorisation: A secure and straightforward process for users to register and associate with profiles of legal entities on behalf of which they are acting. This should include very strong security authentication to ensure legally binding transactions, non-repudiation, and personalisation of service delivery.
* Privacy Controls and Consent Management: Tools for users to control their privacy settings and manage consents for how their information is used and shared, in compliance with data protection regulations.
* Communication Preferences Management: The ability for users to set and manage their communication preferences, including the types of notifications they wish to receive and through what channels (email, SMS, etc.).
* Personalised Dashboard: A personalised dashboard that gives customers an overview of their profile status, pending actions, recent transactions, and other relevant information.
* Multilingual Support: Support for multiple languages to accommodate the diverse population the organisation serves.

**2. Customers & Users Managemen**

Implementing Customer & Users Management in a public administration service delivery organisation requires a comprehensive set of software features to effectively manage the information and interactions of individuals and businesses.

* Centralised User Database: A robust database to store and manage comprehensive profiles of customers, including personal information, contact details, transaction history, and compliance status.
* Secure Registration and Authentication: A secure process for new and existing users to act on behalf of legal entities.
* Account Recovery and Support: Robust mechanisms for account recovery in case of lost passwords or compromised accounts, including customer support features for assisting users with account management issues.
* Role-Based Access Control (RBAC): The ability to define roles and permissions for different types of users (e.g., individuals, business representatives, tax advisors) to control access to sensitive information and functionalities based on their role.
* Audit Trails and Activity Logs: Comprehensive logging of all user activities within their profile for security and compliance purposes, ensuring that any unauthorised access or changes can be traced and investigated.
* Customer Support and Ticketing System: A built-in support system to manage user inquiries and issues, including a ticketing system for efficiently tracking and resolving support requests.
* Analytics and User Behaviour Tracking: Tools to analyse user behaviour, service usage patterns, and satisfaction levels to inform service improvements and policy decisions.
* Bulk Operations and Communications: Features to manage bulk operations, such as mass updates or communications, to handle large user bases efficiently.
* Accessibility Features: Ensuring that the system is accessible to all users, including those with disabilities, following web accessibility standards.

**3. Online Learning & Training**

Implementing Online Learning & Training within a service delivery organisation requires comprehensive software features to create a compelling, engaging, and accessible learning environment. Support should be provided for the delivery of training materials, facilitate interactive learning, and enable tracking and assessment of learner progress.

To a limited extent, POA-CC components support some of the required functionalities. It requires the configuration of specific workflows and templates, and the following specific aspects should be added:

* Course Catalogue and Enrolment: An online catalogue of available courses with detailed descriptions, prerequisites, and enrolment options. Users should be able to easily browse, search, and enrol in courses.
* Learning Pathways: The ability to create structured learning pathways or curriculums that guide learners through courses or modules based on their roles, learning goals, or skill levels.
* Interactive Learning Tools: Features such as quizzes, interactive simulations, discussion forums, and live webinars to engage learners actively and support various learning styles.
* Assessment and Testing: Tools to create and administer tests and quizzes, including multiple-choice questions, essays, and practical tasks, with automatic grading where applicable.
* Certification and Badging: The ability to issue certificates or digital badges upon course completion or mastery of specific skills, providing recognition of learners’ achievements.
* Progress Tracking and Reporting: Dashboards and reporting tools for learners and administrators to track progress, completion rates, assessment scores, and other metrics to monitor learning outcomes.
* Instructor Tools and Resources: Tools for instructors to create and manage content, interact with learners, provide feedback, and monitor class or course progress.
* Feedback and Evaluation: Mechanisms for collecting feedback from learners about courses, instructors, and the overall learning experience to inform continuous improvement.

**4. Customer Accounting**

Implementing Customer Accounting in a service delivery organisation requires a robust set of software features that can handle complex transactions, ensure compliance with laws, and provide a user-friendly interface for customers and administrators.

* Reports Filing and Processing: Features to support the submission of regular reports (for example, tax returns in a revenue authority or financial reporting in a business registry or statistical department) with pre-validation of data to reduce errors.
* Payment Processing Integration: Integration with payment gateways to facilitate payments and refunds, supporting various payment methods (credit/debit cards, bank transfers, digital wallets) and providing real-time transaction processing.
* Account Management: Tools for customers to manage their accounts, including viewing account transactions.
* Automated Calculations: Automated calculation features to pre-fill forms for customers.
* Customer Support and Inquiry Management: Integrated customer support features, including a ticketing system for managing customer inquiries and issues, FAQs, and live chat support.
* Integration with Other Government Systems: Capabilities to integrate with other government databases and systems for data verification and compliance checks and to provide a holistic view of customer obligations and entitlements.

**5. Compliance & Enforcement**

Implementing Compliance & Enforcement in a service delivery organisation requires components to support activities to monitor, detect, and act upon compliance issues efficiently.

To some extent, POA-CC components support the required functionalities. It involves the configuration of specific workflows and templates, and the following particular aspects should be added:

* Regulatory Database: A centralised database that contains all relevant laws, regulations, and compliance requirements, which can be easily updated as new legislation is passed or existing laws are amended.
* Automated Compliance Monitoring: Tools automatically monitor transactions, filings, and other regulated activities for potential compliance violations, using predefined rules and algorithms to identify anomalies and red flags.
* Advanced Specialised Risk Assessment Tools: Features that enable the assessment of compliance risks associated with specific entities, sectors, or activities, allowing for targeted enforcement and monitoring efforts based on risk profiles.
* Audit and Inspection Workflows: Workflow automation for planning, scheduling, and conducting audits and inspections, including checklists, reporting templates, and tools for auditors and inspectors to record findings and recommendations.
* Financial Analysis Tools: Advanced tools for analysing financial transactions, patterns, and records to detect signs of non-compliance, fraud, or other illicit activities.
* Penalty and Sanction Processing: Features for calculating, issuing, and tracking penalties and sanctions for compliance violations, including payment processing and appeals management.
* Stakeholder Communication: A secure channel for communicating with regulated entities, legal representatives, and other stakeholders, providing access to case information, document submission, and status updates.
* Whistle-blower and Complaint Submission: Secure and anonymous channels for whistle-blowers and the public to report suspected violations, including tips, complaints, and submission of supporting evidence, which could also serve as an automated evaluation and feedback mechanism.

**6. Data Management**

The Data Management component should contain at least the following building blocks:

* Data Format and Transformation Services: These services convert data from one format to another so that different systems can understand and use the information without manual intervention.
* Monitoring and Logging Services: These services track the health and usage of the service delivery platform, recording data on transactions, performance, and potential security incidents.
* Business Rules Management: A system for defining, deploying, monitoring, and maintaining the complex decision logic system processes use.
* Workflow and Business Process Management are tools that allow for the design, execution, and automation of business processes involving multiple interconnected systems.
* Master Data Management (MDM) is software that ensures the uniformity, accuracy, stewardship, semantic consistency, and accountability of the enterprise's official shared master data assets.
* Data Warehousing and Analytics: Systems that collect, store, and allow for analysing large volumes of data to inform decision-making and service improvements.
* Risk and Fraud Detection Systems: Analytical tools to identify suspicious activities and potential fraud

### A1.2.5 State Registries

One additional type of system is a state registry. For example, a business registry registers companies. In many countries, there are population registries to record the birth and death of individuals, along with all other important personal lifecycle events. The digitalization of such agencies requires two building blocks:

* Registration BB
* Digital Registry BB

Registration BB: Registration is a process through which an applicant gets information recorded in a registry and receives a credential as proof of registration, in exchange for providing information, with or without money. The information provided by the applicant consists of data and/or credentials issued by public or private entities. Money is provided to pay for one or more registration fees/costs. A registration involves at least two parties:

* applicant who wants to register (something or somebody);
* authorized representative of a registry in charge of registering the data and issuing the credential.

One registration may involve more than two parties, as one or more third parties can be requested to assert/confirm the information provided by the applicant (a notary, a family member, a witness, another public entity, or a non-human entity such as a database); or a third party can be requested to receive the payment made by the applicant (a bank, a cashier, an online payment service).

The registry or registries where the information is written can also be considered as a third party.

Digital Registry BB: The Digital Registries Building Block provides services to other Building Blocks and to external systems, to store and manage data/claims on any entity (persons, places, and things) in forms of uniquely identiﬁable records in a database.

For example, these records could contain health and medical information, ownership of property, vehicles, money, qualiﬁcations, birth/expiry of people and entities, land surveys, manufacturing information of vehicles and equipment, banking, and commercial transactions, etc. Given the diversity of such information, this Building Block provides services useful to abstract the structure, linkages, and grouping of information into various records and collections such as ﬁnancial, legal, medical, social, educational, commercial, etc., as needed.

The Digital Registry BB provides the capability to capture, store, search, distribute, and present data with zero or minimal need for software development. It also maintains and reports logs of all operations on database schemas and data. It contains various functional components and data resources to abstract away all the details and complexity and to expose capabilities as service-APIs to external Building Blocks/applications.

#### A1.2.6 Government Horizontal Systems

One additional type of system is an internal governmental system, where the provider and consumer are both public administration organisations (so-called G2G type). A non-exhaustive list of such G2G systems:

1. Procurement
2. HR management
3. Budget
4. Contracts
5. Invoices
6. Payments
7. Accounting
8. E-Cabinet
9. Legislation Drafting
10. Repository of Laws
11. Service Delivery Platforms: User-centric platforms offering digital government services, including websites and mobile applications.
12. Citizen Engagement Platforms: These are channels for citizens to provide feedback, participate in policymaking, and engage with the government.
13. Open Data Initiatives: Making government data available to the public to increase transparency and enable innovation.
14. Emergency and Disaster Response Systems: Digital infrastructure to provide timely information and services during emergencies.

In most cases, this functionality should be implemented only once in a country and used by all public administration organisations from a **Shared Services Centre**.

The current version of this document does not cover the specifics of those systems.

### A1.2.7 Natural Digital Environments

The concept of a natural digital environment refers to the fact that in a digital society and digital economy, eventually, everyone should have a specialised digital environment that is used for everything. Following is a description of possible options, which can be envisioned with our today’s understanding of technology and needs.

#### Digital Walle

We used to classify stakeholders of digital services as “citizens, businesses, NGOs, etc.”. However, everyone should appreciate the fact that even when we talk about businesses and other organisations, there are people who are behind transactions. Like that, we can state that an individual’s Digital Wallet is a first and foremost Natural Digital Environment of the Digital Era.

A Digital Wallet has two main elements: security features and personal information. Security features include encryption, authentication protocols, and biometric verification. Personal information includes foundational identity, functional identities, addresses, contact information, and other relevant data to streamline online transactions.

A Digital Wallet can also be seen as a virtual payment tool that stores money and facilitates transactions using payment methods such as electronic money, credit/debit cards, bank accounts, or digital currency. It also maintains a transaction history for users.

Also, a digital wallet can store a variety of retail business information, such as digital tickets, coupons, boarding passes, event tickets, discount codes, and loyalty rewards. This provides users with a convenient way to access and manage these items in one place. To ensure a satisfactory user experience, a digital wallet should have a user-friendly interface that simplifies the process of making payments, transferring funds, getting access and managing different transactions.

A Digital Wallet can be integrated with MyGov functionality, allowing citizens to connect a government digital channel directly to their personal wallet.

Digital wallets are also a good way to overcome the difficulties in regions where Internet access or cross boarder data flows are difficult to achieve.

#### MyGov

First of all, MyGov is a mobile application that provides citizens and residents with essential public information and enables them to execute any public sector transaction, such as submitting tax returns, applying for and receiving driver's licenses, etc.

MyGov is also a unified governmental portal, which provides centralised services and provides links to decentralised services.

It is a brand for a network of walk-in counters that provide digital access to people without personal devices through self-service kiosks and service clerks.

Like that, MyGov provides access to digital government services for all without any discrimination.

#### Organisation ERP

Previously, ERP stood for Enterprise Resource Planning solution. Today, it refers to an integrated IT system used to provide digital resources to different organisational roles to achieve business objectives. In this context, it would be ideal for the public sector to facilitate direct integration between Digital Government services and ERP systems of various businesses and organisations in a country.

### A1.2.8 Public Ecosystems

The public sector organisations described above—policy development units, regulatory agencies, and service delivery authorities—are present in all main functional areas of the digital economy and society. They develop and implement policies, regulate market activities, and deliver services to citizens and businesses.

Simplified model of the public sector ecosystem can be depicted in the following way:

<figure><img src="https://2983968174-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FWNaBkXRH5GkT1VCcv0BB%2Fuploads%2Fgit-blob-f0471b75962a61c8be2cc1863a866f904f147369%2Fimage3.png?alt=media" alt=""><figcaption><p>Figure 17 - Simplified model of public administration ecosystem</p></figcaption></figure>

There are the following main functional areas:

* **Finance**. The sector includes public finance (i.e. treasury, budget planning and execution, revenue management, customs, national accounting, central bank, and statistics) and private sector financial organisations (banking, securities, investment banks, non-bank financial institutions, pension funds, fintech companies, credit rating agencies, etc.)
* **Internal security**. In a country's internal security sector, organisations are responsible for maintaining public order, combating crime, and ensuring citizens' safety. These include the Ministry of Internal Affairs, law enforcement agencies, intelligence services, border control, civil defence, cybersecurity agencies, counterterrorism units, judicial and correctional institutions, customs and excise, and regulatory bodies.
* **Education**. A country's education sector includes various organisations, such as Ministries, educational institutions, teacher training institutions, research institutions, and non-state actors. These organisations work together to provide high-quality educational services and promote human capital development. Different state programs for Education Development aim to improve the quality of education services.
* **Social care**. In a country's social care sector, public health institutions, NGOs, educational institutions, social work organisations, government agencies, and civil society organisations collaborate to provide social services, promote health education, deliver healthcare services, and support vulnerable communities. They work together to address social challenges and enhance the social care sector.
* **Health care**. A country's healthcare sector includes several types of organisations that provide medical care and services to the population, such as government agencies, public and private hospitals and healthcare facilities, medical schools, medical research institutions, healthcare professional associations, healthcare insurance companies, and non-governmental organisations (NGOs).
* **Construction**. A country's construction sector involves various organisations that handle different aspects of the construction process. These include construction companies, architecture firms, engineering companies, contractors and subcontractors, material suppliers, regulatory bodies, real estate developers, project management firms, surveying firms, consultancy firms, and legal services. Range of projects from residential buildings to commercial developments and infrastructure projects.
* **Agriculture**. Various organisations work together in the agricultural sector to form the industry's backbone, i.e., farms, cooperatives, research institutions, governmental agencies, NGOs, equipment manufacturers, agrochemical companies, seed and genetic companies, food processing companies, and agricultural extension services.
* **Utilities**. In a country's utility sector, organisations are involved in essential services such as electricity production and distribution, water supply and sanitation, natural gas supply, renewable energy, telecommunications, waste management, and relevant regulatory bodies.
* **Mobility**. In the mobility sector, various organisations play essential roles in the transportation and movement of people and goods. These include public transportation providers, ride-sharing companies, taxi services, logistics and freight companies, bicycle and scooter-sharing services, regulatory agencies, vehicle manufacturers and dealerships, infrastructure development firms, and technology and innovation firms.

From the public administration standpoint, those are main sectors of Digital Economy and Society. According to national priorities, the government's digital transformation should focus on the main public administration sectors.

Within those ecosystems public sector organisations are interacting with different players from private sector.

For example, here is healthcare reference architecture developed by Oliver Kipf:

<figure><img src="https://2983968174-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FWNaBkXRH5GkT1VCcv0BB%2Fuploads%2Fgit-blob-ff4575fbe22d25f6c32e3b4ab950e7a708a886ea%2Fimage4.png?alt=media" alt=""><figcaption><p>Figure 18 - A healthcare reference architecture (Source: Oliver Kipf)</p></figcaption></figure>

In this diagram, governmental regulatory authority is part of a more complex information exchange ecosystem.

There is another example of an ecosystem in the Construction area:

<figure><img src="https://2983968174-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FWNaBkXRH5GkT1VCcv0BB%2Fuploads%2Fgit-blob-4c4139da5fa7579460c262107afb314d581e0449%2Fimage5.png?alt=media" alt=""><figcaption><p>Figure 19 - Construction ecosystem (Source: Jüri Ross)</p></figcaption></figure>

This example is from Estonia. It shows how different players exchange information during the construction project's progress.

It is essential to understand that public and private sector entities should be able to communicate with each other from their natural digital environments. In the Digital Era, **portals are no longer necessary**.

Instead, businesses with their own ERP solutions should be able to communicate with the public sector directly from within their ERP systems. Similarly, citizens with a Digital Wallet and the MyGov mobile app should be able to perform all necessary tasks through those channels. Public sector entities should also be able to proactively push information and services to stakeholders' natural digital environments.

The current version of the document does not cover the specifics of those ecosystems. However, the GovStack team is committed to continuing the analysis to identify reusable components and practices to streamline building such a comprehensive Digital Society and Economy ecosystem.

In many countries, the defence sector is also important, but it has intentionally been omitted from the scope of GovStack's reference architecture.\\

### A1.2.9 Summary

Now we can summarise our current understanding regarding required building blocks (BB) for the public administration. Overall architecture can be depicted in the following way:

<figure><img src="https://2983968174-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FWNaBkXRH5GkT1VCcv0BB%2Fuploads%2Fgit-blob-a71d3c08b418c4f67dd570c59eaa618ab075c4bf%2Fimage6.png?alt=media" alt=""><figcaption><p>Figure 20 - Overall list of required BBs</p></figcaption></figure>

Here we are categorizing building blocks into the following main groups:

* **Back Office** (BO) building blocks (BBs) are used to build public administration solutions strictly for internal use by public administration officers.
  * The BO **infrastructure** BBs are modular building blocks that are not specific to the function of the organisation that uses them and these building blocks are deployed once for a particular country and then reused by everyone. For instance, the Identity BB is installed once and is intended to be re-used by everyone.
  * The BO **functional** BBs are specific for business activities or when they are generic (like Content Management), they should be configured in a specific way for every organisation. That means, that knowledge of internals of those BBs and capability to configure them should be presented in many organisations in a country.
* **Front Office** (FO) building blocks are meant for use by external public sector stakeholders and customers.
* In **Ecosystems**, public sector organisations participate using the back-office or the front-office BBs.

All infrastructural BBs are currently already defined in the GovStack specifications Knowledge Base section.

All functional building blocks at a high level have been defined in sections 4.6.2 - 4.6.3 above.

The building blocks of the Front Office at a high level are defined in section 4.6.7 above.

The Ecosystem concept is defined in the section 4.6.8 above.

## A1.3 Building Blocks

Public administration organizations can benefit from digital transformation by reusing standardized architectural building blocks from the national digital infrastructure. These blocks are essential components that can be utilized in various digital projects to ensure consistency, reliability, and security.

GovStack offers some common architectural blocks as national digital infrastructure that public administrations can utilize to improve their efficiency, interoperability, and service delivery.

1. Digital Identity Systems: A foundational component for enabling secure and convenient access to digital services. Public administrations can integrate national digital ID systems to authenticate users and enable electronic signatures, ensuring transactions are both secure and legally binding.
2. Data Exchange Layers: Such as APIs (Application Programming Interfaces) and standardised data exchange formats, facilitate seamless communication and data sharing between different government systems and services. Public administrations can ensure interoperability and easy integration of services by adopting national data exchange standards.
3. Payment Gateways: Standardized digital payment systems can be reused to facilitate transactions for various public services. This enables a uniform, secure, and efficient mechanism for collecting fees, taxes, and other payments from citizens and businesses.
4. Security Infrastructure: Including encryption protocols, cybersecurity frameworks, and threat detection systems that can be adopted to protect sensitive information and digital services from cyber threats. Utilizing national security infrastructure helps maintain high standards of data protection and trust.
5. Cloud Infrastructure: Government cloud platforms offer scalable and flexible computing resources. Public administrations can leverage these for hosting services and applications, benefiting from economies of scale and reducing the need for extensive individual investments in IT infrastructure.
6. Geospatial Services: National geospatial data and services provide detailed geographic information that can be used for planning, infrastructure development, environmental management, and emergency response. Integrating these services can enhance the quality and relevance of public services.
7. Registry Services: Centralized registries (such as citizen, business, property, and vehicle registries) are crucial for maintaining authoritative sources of information. By reusing these registries, public administrations can streamline processes, reduce duplication, and improve accuracy.
8. Open Data Platforms: By utilizing national open data initiatives, administrations can access a wealth of non-sensitive information for analysis, policy-making, and service improvement. This promotes transparency, innovation, and data-driven decision-making.
9. Digital Service Platforms: Platforms that provide reusable components for building digital services, including templates, design systems, and development tools. These enable a consistent user experience across government services and reduce development time and costs.
10. Communication and Collaboration Tools: National infrastructure often includes secure communication channels and collaboration platforms that public sector employees can use to enhance productivity and teamwork.
11. Consent service: The Consent Building Block enables services for individuals to approve the use of their Personal Data by defining the principles, functions, and architecture of an information system. For organisations that process Personal Data​,​ it provides the ability to know the ​individual's will and legitimately process such Personal Data. The Consent Building Block is a process-oriented GovStack Building Block facilitating auditable bilateral agreements within a multi-agent environment that integrates with most other Building Blocks.
12. Messaging service: The Messaging Building Block is a secure communication channel for public administration service providers to communicate with their customers. It offers functionalities such as logging, backup, and security. Developers can use it to create communication components on top of different services, allowing them to pass messages with federated architecture. It supports various modalities such as email and SMS and helps connect with existing messaging service providers, making the adoption process less disruptive for end-users.
13. Workflow management service: Workflow Building Block automates and orchestrates business processes within and across Building Blocks. It maps and models business processes using open standards like BPMN. Deployed workflows are executed during runtime to orchestrate process flows from initiation to completion.
14. Scheduling service: The Scheduler Building Block coordinates time-driven activities within and between Building Blocks by sending alert messages based on a predetermined schedule. Each event has an ID, name, date, time, and duration and involves multiple resources. Subscribers can enrol to benefit from the activities. The Scheduler alerts specific resources and subscribers with messages to carry out respective activities. The Scheduler Building Block contains functionalities for planning, booking, tracking, triggering, notifying, and status reporting of multiple events. It has micro-services that orchestrate these functions through RESTful APIs.
15. Digital signature service: Digital Signature Building Block provides the necessary functionalities to bring handwritten signatures to the digital world. Handwritten signatures have served as a way to agree/witness a given document, yet, in today's digital world most documents are in digital form. The digital form varies between structured (XML, JSON) and unstructured documents (PDF, Word, Image, CSV, Spreadsheet). eSignatures can be added to digital documents similar to handwritten signatures, achieving the same functionality.

This list of building blocks by no means is final. It will be growing as GovStack will be supporting more and more transformational initiatives.

\\


# 7. Annex 2 – Metamodel of Reference Architecture

## Methodology Baseline

To define the reference architecture of a public administration organisation (PAO) we adopted Open Group TOGAF framework:

<figure><img src="https://2983968174-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FWNaBkXRH5GkT1VCcv0BB%2Fuploads%2Fgit-blob-2dddac068f86bb8d20e5f5bf4fc25870422387c0%2Fimage7.png?alt=media" alt=""><figcaption><p>Figure 26 - Architecture description components in TOGAF (Source: OGM)</p></figcaption></figure>

Overall organisation architecture in TOGAF is defined by following layers

1. Business Architecture Layer,
2. Information Systems Architecture, including Data and Applications architectures and
3. Technology Architecture layer.

## Primary Viewpoints

The primary concern for the current document is to provide guidelines for structuring business and application target architecture during the planning of digital transformation.

To define business architecture, we are using the business model concept. In details business model is described in the \[1]. In \[3], the author provides the following short definition: “A business model is a conceptual tool containing a set of objects, concepts and their relationships with the objective to express the business logic of a specific firm. Therefore, we must consider which concepts and relationships allow a simplified description and representation of what value is provided to customers, how this is done and with which financial consequences”.

From an external perspective, a business model outlines how an organization conducts its operations. It encompasses the strategies and tactics employed by a company to achieve its goals \[1]. The following are main components of the business model:

<figure><img src="https://2983968174-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FWNaBkXRH5GkT1VCcv0BB%2Fuploads%2Fgit-blob-da0d032c7f5354446f5b47365f05e37122b83f5c%2Fimage8.png?alt=media" alt=""><figcaption><p>Figure 27 - Business model components.</p></figcaption></figure>

Like that, business architecture will be described using a business model and then will be connected to the application architecture via required application services.

Following is a metamodel, which we are using to define PAO reference architectures:

<figure><img src="https://2983968174-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FWNaBkXRH5GkT1VCcv0BB%2Fuploads%2Fgit-blob-bbf5b4670fd20ce01e4f6ab17750de3cc6b1db26%2Fimage9.jpg?alt=media" alt=""><figcaption><p>Figure 28 - Reference Architecture Metamodel</p></figcaption></figure>

### Customer

A person or organization that is served by a public administration organisation.

### Service

A defined performance of a person or organization that meets a customer's needs.

### Business process

Ordered series of work processes that are carried out within one organization with the aim of providing a (combination of) service (s) to a citizen, company or organization.

### Workflow

An ordered series of process steps (business activities) carried out within one organizational unit within an organization with the aim of making a specific contribution (performance) to a service. (Can be a supporting process).

### Application function

Related functionality offered by an application component. An application function offers support to one or more business activities.

### Application component

The actual software that delivers the application functionality.

For modelling, ArchiMate 3.1 is used. For every class of customer, main services are defined with reference to a business process implementing the service. Business processes may give internal workflows, which are supported by application architecture services.


# 8. Annex 3 – Main state registries

[Base registers](https://joinup.ec.europa.eu/collection/nifo-national-interoperability-framework-observatory/glossary/term/base-registries) should be established in a country to ensure feasibility of holistic approach toward secure and reliable digital government services:

* **Population Registry** or alternative reliable data source to enable Digital Identification. Contains key demographic and residency details of all citizens in the country.
* **Business Registry** to enable legally binding authorisation of users in context of legal entities for making legal transactions. Central database of all registered companies and legal entities operating in the country.
* **Cadastre/Land register** or similar alternative for assurance of property rights. Authoritative information on land parcels, property boundaries and ownership
* **Official Publications** – register and a system to publish laws and regulations for public access and awareness.
* **Securities Register** - Beneficial ownership information behind corporate entities to enable transparency.
* **Registry of economic activities**, licenses and permissions contains data on all requirements in any area of business activities, regulated in a country and reference to appropriate procedures and entities, who are in charge for regulations.
* **Vehicle Register** - Records details of all vehicles registered in the country.
* **Health Registers** - Databases of healthcare providers, facilities, treatments, diseases etc.
* **Social Insurance Register** - Citizen records related to pensions, unemployment benefits, healthcare coverage etc.
* **Education Register** - Details of educational institutions, students, qualifications awarded.
* **Criminal Register** - Records of crimes, convictions by courts and related law enforcement actions.
* **Procurement Register** - Data on government contracts, bids and awards.


