EPR Delivery10 min readApril 2026Jonah Aburrow‑Jones

Big bang or phased? Choosing an EPR cutover you can defend

The cutover decision is made too early, for the wrong reasons, and rarely written down honestly. It isn’t a question of ambition — it’s risk allocation. Here’s a clearer way to choose, and to defend the choice to a board.

Ask a programme why it chose a big‑bang cutover and you’ll often get an answer that’s really about something else: a vendor’s preferred model, a date the board already announced, a fear of running two systems, or simply that the last place someone worked did it that way. The cutover strategy is one of the highest‑consequence decisions in the whole programme, and it’s routinely made early, for the wrong reasons, and never written down honestly.

So let’s write it down honestly. Big bang or phased is not a matter of taste, and it isn’t a moral question about ambition. It’s a risk‑allocation decision, and it can be reasoned about.

What each approach really trades

A big‑bang cutover switches the organisation — or a whole site — to the new record at a single moment. Its virtue is coherence: one source of truth from day one, no lingering interfaces between old and new, no half‑digital limbo where staff work across two systems and neither is trusted. Its cost is concentration of risk. Everything that can go wrong goes wrong at once, in a compressed window, with no fallback that doesn’t mean reverting the whole thing.

A phased approach — by module, by service, or by site — spreads that risk across time. You learn from each phase, you contain the blast radius of any single failure, and you give the organisation room to absorb change. The price is duration and interface complexity: for the length of the transition you are running two worlds, building and maintaining the bridges between them, and asking staff to hold both models in their heads. That in‑between state has its own clinical‑safety risks, and they’re easy to underestimate because they’re diffuse rather than dramatic.

Big bang concentrates risk into one window you can prepare intensely for. Phased spreads it across a transition you have to live in.

The questions that actually decide it

Rather than starting from the answer, start from the organisation. A handful of questions do the real work.

How coupled are your services? A single acute hospital where every service touches every other is a poor candidate for a clean phased split — the interfaces you’d have to build between “live” and “not yet” services may be more dangerous than a well‑drilled big bang. A federation of loosely coupled sites is the opposite.

Can you actually run two systems safely? Phased assumes you can operate old and new in parallel without harming patients in the seams. Sometimes you can. Sometimes the interfaces required are so complex, or the dual‑running so confusing at the bedside, that the “safer” phased option is quietly the more dangerous one.

How much change can the workforce absorb, and how often? Phased spreads change but also prolongs it — change fatigue is real, and a two‑year drip of disruption can be harder on morale than one intense, well‑supported week.

What’s your appetite and capacity for a command‑centre go‑live? Big bang lives or dies on preparation: floor‑walking, a command centre, rehearsed fallback, and the resourcing to flood support into the first fortnight. If you can’t resource that properly, big bang’s central advantage evaporates.

What does your data and estate readiness allow? A phased cutover can buy time to get foundations right in sequence. A big bang demands they all be right at once.

Defending the decision to a board

Whichever way you go, the board deserves the honest version — not the one that makes the recommender look brave. A defensible cutover paper does three things.

It states the risk it is accepting, explicitly. Big bang: “we are concentrating risk into a single window, and here is exactly how we are preparing for it, and here is our fallback.” Phased: “we are accepting a prolonged transition with interface and dual‑running risk, and here is how we contain it.” A paper that pretends its chosen option has no downside is not an analysis; it’s advocacy.

It shows the readiness gates, and commits to not going through them until they’re met. The most dangerous phrase in any cutover is “we’ll be ready by then.” Readiness is demonstrated, not asserted — through workflow simulation, data reconciliation, and dress rehearsals with real users before anyone commits to the date.

It names the fallback and proves it works. A big‑bang plan without a rehearsed, credible fallback is a bet, not a plan. Boards can approve risk; they should not be asked to approve a bet dressed as a plan.

The right answer isn’t big bang or phased. It’s the one whose risks you’ve named out loud, prepared for honestly, and can still defend when the date gets tight.

A word on the pressure to decide early

The cutover model tends to get locked in during procurement, because vendors have preferences and business cases want certainty. Resist that. The cutover decision depends on things you often don’t fully know at procurement — the true state of your data, the coupling of your services, the readiness of your estate. Keep the option open as long as you responsibly can, gather the evidence that actually bears on it, and make the call when you can defend it rather than when the schedule template demands a tick in a box.

Done well, this decision barely gets mentioned afterwards, because nothing went badly wrong. Done badly, it becomes the thing the inquiry is about. The difference is rarely the model chosen. It’s whether the choice was reasoned, evidenced, and honest about the risk it took on.

Written by Jonah Aburrow‑Jones, Founder of Undine Digital. If this raised a question about your own programme, start a conversation — or read more of our insights.

Put it to work

Map your Waterline.

A one‑week diagnostic across foundations, operations and experience — clarity on where your programme actually stands.

Book a discovery call