← AI Transformation Suite Master Planning Document

Program Management Plan (PMP) — Version 1.0

Download Word

Project Catalyst — $99,000,000 AI Transformation Program, ACME Highland Health. This Program Management Plan is the master operational document governing how the program will be executed, monitored, controlled, and closed across 36.5 months (Aug 2026–Aug 2029). It integrates all PMBOK subsidiary management plans plus AI-specific governance, model risk, data privacy, and regulatory compliance plans unique to enterprise AI deployment in regulated healthcare. Approved by Executive Steering Board; updates require formal change control.

Table of Contents

Part I — Program Integration & Management Approach
  1. Introduction & Document Purpose
  2. Program Overview & Strategic Context
  3. Management Approach & Delivery Methodology
  4. Phase Structure & Gate Process
Part II — Subsidiary Management Plans (PMBOK Knowledge Areas)
  1. Scope Management Plan
  2. Requirements Management Plan
  3. Schedule Management Plan
  4. Cost Management Plan
  5. Quality Management Plan
  6. Resource Management Plan
  7. Communications Management Plan
  8. Risk Management Plan
  9. Procurement & Vendor Management Plan
  10. Stakeholder Engagement Plan
Part III — AI-Specific Management Plans
  1. AI Governance & Model Risk Management Plan
  2. Data Governance & Privacy Management Plan
  3. Regulatory Compliance Management Plan
Part IV — Governance & Decision Authority
  1. Governance Structure & Decision Rights
  2. Meeting Cadence & Reporting Framework
  3. Escalation Framework
Part V — Program Execution & Control
  1. Change Management & Configuration Control
  2. Performance Measurement & Earned Value
  3. Benefits Realization Management
  4. Knowledge Transfer & Transition Planning
Part VI — Baselines, Assumptions & Reference
  1. Assumptions, Constraints & Dependencies
  2. Baselines Summary
  3. Process Improvement & Lessons Learned
  4. Document Control & Approvals
  5. Appendices & Cross-References
Part I — Program Integration & Management Approach

1. Introduction & Document Purpose

This Program Management Plan (PMP) is the single authoritative document governing how Project Catalyst will be planned, executed, monitored, controlled, and closed. It integrates all subsidiary management plans — scope, schedule, cost, quality, resource, communications, risk, procurement, and stakeholder — plus three plans unique to enterprise AI deployment in regulated healthcare: AI Governance & Model Risk, Data Governance & Privacy, and Regulatory Compliance. Together, these plans constitute the operational blueprint for a 262-person, $99 million, 36.5-month program.

This PMP operates under the authority of the Program Charter (approved August 3, 2026) and the Program Governance Model. It is reviewed at every phase gate and updated through the formal change control process defined in Section 21. No section of this plan may be modified without Executive Steering Board approval and a corresponding entry in the Change Control Log.

1.1 Intended Audience

1.2 Related Documents

DocumentRelationship to This PMP
Program CharterAuthorizing document; defines scope, budget, and executive authority. This PMP operationalizes the Charter.
Program Governance ModelDefines decision rights, board composition, and phase-gate sign-off process. Referenced throughout this PMP.
RAIDD LogSystem of record for risks, assumptions, issues, dependencies, and decisions. This PMP defines how each category is managed.
Resource PlanComplete 262-person named roster. This PMP Section 10 defines staffing management procedures.
Organization ChartComplete reporting structure. This PMP Section 10 defines reporting and matrix coordination procedures.
RACI MatrixResponsibility assignments for 14 key activities. This PMP defines the process behind each RACI entry.
Change Control LogRecords all formal changes to baselines. This PMP Section 21 defines the change control process.
Communications PlanDetailed communication matrix. This PMP Section 11 summarizes; full detail in the standalone artifact.
AI Governance & JAD CharterDefines JAD session structure and AI CoE mandate. Referenced in Sections 6, 15, and 17.
SOW-01, SOW-02, SOW-03Contractual scope and fee schedules for Years 1, 2, 3 respectively. Referenced in Section 8.

2. Program Overview & Strategic Context

Project Catalyst is a three-year enterprise AI transformation program for ACME Highland Health, a national health insurer with approximately 4 million members. The program delivers production AI capabilities across three business requirement documents (BRDs), supported by two cross-cutting workstreams, under a governance-first strategy that embeds responsible AI practices from Day 1 rather than retrofitting compliance post-deployment.

2.1 Strategic Drivers

Two converging forces make this program necessary and time-bound:

2.2 Program Scope Summary

WorkstreamTypeScopeTimeline
BRD-01: Claims & Prior Auth AIDeliveryAgentic prior-auth automation with mandatory human review of adverse determinationsYear 1 (Aug 2026–Sep 2027)
BRD-02: Member & Provider UX AIDeliveryConversational AI for member self-service and call-center support with escalation-to-human protocolsYear 2 (Oct 2027–Dec 2028)
BRD-03: Underwriting & Risk AIDeliveryPredictive risk-scoring with mandatory fairness/disparate-impact testing before any model influences pricingYear 2 (Oct 2027–Dec 2028)
AI Governance & CoECross-cuttingHub-and-spoke governance, NIST AI RMF + ISO/IEC 42001 alignment, enterprise AI standards, shadow-AI preventionYears 1–3
Data & Cloud AI PlatformCross-cuttingShared hyperscaler cloud platform, MLOps pipelines, data governance, FinOps controlsYears 1–3

2.3 Objectives & Success Criteria

  1. Governance: Zero Critical or High security findings from first production release onward. No model reaches production without clean Independent Model Validation sign-off.
  2. Model Quality: Every production model passes accuracy, fairness, explainability, and security validation. Override/escalation protocols documented and tested for every model type.
  3. Schedule: All three BRDs delivered to production by August 2029 within the phase-gate structure. Schedule changes formalized through change control; no unauthorized acceleration or compression of validation gates.
  4. Budget: Deliver within the $99M authorization. Contingency reserve ($9.0M) used only through formal Executive Steering Board approval with documented root cause.
  5. Benefits Realization: Measurable operational outcomes (PA cycle time reduction, call-center handle-time reduction, underwriting consistency improvement) benchmarked at Phase 0 and tracked against actuals through Year 3 closeout.
  6. Sustainability: AI Governance & CoE, Independent Model Validation, and data privacy functions transitioned to permanent ACME operations at program closeout — governance does not end when consulting ends.

2.4 Key Milestones

MilestoneTarget DateGate Owner
Program Kickoff17 Aug 2026Program Director
Phase 0 Gate: Foundation & Readiness06 Nov 2026Executive Steering Board
BRD-01 Requirements Sign-off (JAD Complete)18 Dec 2026AI Governance Board
Phase 1 Gate: Design Approved28 Feb 2027All 3 Boards
Data & Cloud Platform Foundation Go-Live31 Mar 2027EARB
Phase 2 Gate: Build & Testing30 Jun 2027All 3 Boards
BRD-01 Pilot Go-Live15 Jul 2027AI Governance Board
Phase 3 Gate: Production Readiness31 Aug 2027All 3 Boards
BRD-01 Full Production Scale30 Sep 2027Executive Steering Board
Year 2 Kickoff (BRD-02/03)01 Oct 2027Program Director
BRD-02 Production Go-Live30 Sep 2028All 3 Boards
BRD-03 Production Go-Live31 Dec 2028All 3 Boards
Year 3: Optimization & SustainJan–Aug 2029Program Director
Program Closeout & Transition Complete29 Aug 2029Executive Steering Board

3. Management Approach & Delivery Methodology

Project Catalyst uses a hybrid delivery methodology that combines phase-gated governance (waterfall structure for program-level oversight, phase gates, and regulatory sign-offs) with agile execution within each BRD delivery workstream (sprint-based development, continuous integration, iterative model training). This is not a concession; it is deliberate: regulated healthcare AI requires documented phase gates for audit and compliance, while the AI/ML development work itself requires the iterative feedback loops that only agile execution provides.

3.1 Program-Level Governance (Phase-Gated)

3.2 BRD-Level Execution (Agile/Sprint-Based)

3.3 Integration Points Between Governance and Agile

The hybrid model's critical integration points are where sprint-level work must pause for governance review:

4. Phase Structure & Gate Process

4.1 Phase Definitions

PhaseDurationPurposeKey DeliverablesGate Criteria
Phase 0
Foundation
12 weeks
(Aug–Nov 2026)
Assess readiness, stand up governance, select vendors, mobilize teamAI Readiness Assessment, CoE Charter, Governance Framework v1, Platform vendor BAA, Team onboardingAll readiness criteria met; governance framework approved; platform vendor signed; Phase 1 resource plan confirmed
Phase 1
Requirements & Design
12 weeks
(Nov 2026–Feb 2027)
Complete JAD series, lock requirements, approve architectureBRD requirements document (signed), Target architecture, Model validation criteria, Security threat modelRequirements signed by all JAD attendees; architecture approved by EARB; model validation protocol set
Phase 2
Build & Test
16 weeks
(Feb–Jun 2027)
Build platform, develop models, execute testingPlatform Foundation live, BRD-01 model development complete, UAT environment ready, Sprint velocity stabilizedPlatform operational; model build >80% complete; UAT environment provisioned; quality metrics on track
Phase 3
Pilot & Pre-Production
8 weeks
(Jun–Aug 2027)
Controlled pilot, model validation, production readinessPilot Go-Live with controlled user group, Pilot UAT (>95% pass rate), Model Validation Report (clean), Production readiness assessmentPilot UAT passed; model validation clean (zero Critical, zero uncorrected High); production readiness approved
Phase 4
Production Scale
4 weeks
(Sep 2027)
Full-scale production deployment, benefits tracking setupBRD-01 full production live, Benefits tracking baseline, Year 2 scope approved, Hypercare plan activatedProduction stable for 2+ weeks; benefits baseline established; Year 2 BRD-02/03 scope approved

4.2 Phase-Gate Sign-Off Procedure

This procedure is mandatory and invariant across all phase gates:

  1. T minus 7 business days — Package Submission: Program Director submits the phase-gate package to all three board chairs. Package contents: executive summary (2 pages), deliverable completion matrix (with evidence), risk assessment update (RAIDD Log delta since last gate), resource plan for next phase, budget forecast vs. actual, quality metrics summary. Package is uploaded to the project portal and notification sent to all board members.
  2. T minus 5 to T minus 1 — Board Review: Each board reviews the package independently. Board chairs submit written questions or concerns to Program Director no later than T minus 2. Program Director responds in writing before the gate meeting; responses are appended to the gate package for the record.
  3. Gate Day — Gate Meeting: 2-hour meeting with all three boards present (minimum quorum: chair + 1 additional member from each board). Program Director presents the package (30 min), followed by Q&A (45 min), followed by board deliberation (30 min). Each board votes independently: Approve, Approve with Conditions, or Reject.
  4. T plus 1 — Sign-Off Record: PMO Lead documents the gate decision in the Phase-Gate Record: deliverables accepted (enumerated list), risks re-assessed (updated RAIDD Log entries), next-phase budget approved (amount), next-phase team leads confirmed (names). Record is archived in the project portal as an immutable document. Distribution to all 25 team leads within 24 hours.
Gate Rejection Protocol: If any board votes Reject, the phase gate is not passed. Program Director has 5 business days to produce a remediation plan addressing the board's specific objections. Remediation plan is reviewed at a reconvened gate meeting (1 hour). If the rejection is sustained, escalation to Executive Sponsor. In the program's history, no gate rejection has occurred, but the protocol exists because governance without enforcement is theater.
Part II — Subsidiary Management Plans (PMBOK Knowledge Areas)

5. Scope Management Plan

Scope is defined through the five-workstream structure in Section 2.2 and controlled through the WBS (to be published in the Multi-Year WBS Console). The scope baseline is the set of deliverables committed at Charter sign-off, refined through JAD sessions (Phase 0/1), and locked at the Phase 1 gate for each BRD.

5.1 Scope Definition

5.2 Scope Validation

5.3 Scope Control

6. Requirements Management Plan

Requirements are distinct from scope: scope defines what the program delivers; requirements define the specific functional, non-functional, and regulatory conditions those deliverables must satisfy.

6.1 Requirements Gathering

6.2 Requirements Prioritization

6.3 Requirements Traceability

6.4 Requirements Change After Baseline

7. Schedule Management Plan

The schedule baseline spans 36.5 months from Kickoff (17 Aug 2026) to Closeout (29 Aug 2029), organized into the five-phase structure defined in Section 4.1, with Year 2 and Year 3 phases following the same gate rhythm.

7.1 Schedule Development

7.2 Schedule Contingency

7.3 Schedule Performance Monitoring

8. Cost Management Plan

8.1 Budget Baseline

Cost CategoryAmount% of Total
Internal FTE Labor$19,600,00019.8%
Onshore Consultant Labor$27,400,00027.7%
Offshore Consultant Labor$14,200,00014.3%
Cloud & AI Platform Infrastructure$26,900,00027.2%
Tooling (Governance, Compliance, Testing)$1,900,0001.9%
Contingency Reserve$9,000,0009.1%
TOTAL$99,000,000100%

8.2 SOW Fee Schedule

SOWPeriodTotal Fee% of Total
SOW-01 (Year 1: Foundation & Flagship)Aug 2026 – Sep 2027$27,720,00028%
SOW-02 (Year 2: Expansion)Oct 2027 – Dec 2028$41,580,00042%
SOW-03 (Year 3: Optimization & Sustain)Jan 2029 – Aug 2029$29,700,00030%
TOTAL$99,000,000100%

8.3 Cost Tracking & Variance Management

8.4 Contingency Reserve Management

The $9.0M contingency reserve (approximately 10% of total budget) is governed by the following rules:

9. Quality Management Plan

9.1 Quality Philosophy

Quality on this program has two distinct dimensions: software quality (does the system work as designed?) and model quality (does the AI model produce accurate, fair, explainable, and safe outputs?). Both dimensions require different testing approaches, different competencies, and different sign-off authorities. This plan addresses both.

9.2 Software Quality Standards

9.3 AI Model Quality Standards

Blocking Gate: No AI model advances to production without passing all five model validation criteria below. This is not advisory — Independent Model Validation (P. Okafor) has formal blocking authority. See Section 15 for the full AI Governance & Model Risk Management Plan.
  1. Accuracy Testing: Model performance evaluated against a ground-truth benchmark dataset. Accuracy threshold set per model type during Phase 1 (e.g., PA decision accuracy ≥ 92% on benchmark; member chatbot factual accuracy ≥ 97% on policy questions).
  2. Fairness / Disparate-Impact Testing: Model outputs tested for disparate impact across demographic groups (age, gender, geography, plan type). Threshold: no demographic group's approval/denial rate deviates >5% from the population mean without documented clinical justification.
  3. Explainability Review: Model outputs must be interpretable — for every PA decision, the system must produce a human-readable explanation of the factors that drove the decision. Black-box models without explainability are rejected.
  4. Security Testing (Model-Specific): Adversarial input testing (prompt injection, data poisoning, model inversion), data exfiltration resistance, and output sanitization. Conducted by Cybersecurity team in coordination with Model Validation.
  5. Regulatory Compliance Check: Override/escalation protocols verified (mandatory human review for adverse PA determinations), audit logging confirmed (every model decision traceable), and regulatory anchors validated (CMS-0057-F alignment for BRD-01, NAIC model bulletin alignment for BRD-03).

9.4 Quality Metrics & KPIs

MetricTargetMeasurement FrequencyOwner
Code Coverage≥ 80%Per commit (automated)BRD Lead
Sprint Defect Escape Rate< 5% of storiesPer sprintQA Lead (V. Müller)
UAT Test Case Pass Rate≥ 95% before productionPer UAT cycleOperational Testing Manager
Model Validation Defect CountZero Critical, Zero uncorrected HighPer model validation cycleP. Okafor
P95 API Latency≤ 2 secondsContinuous (monitoring)Platform Lead (W. Kumar)
Security Scan FindingsZero Critical, Zero High at releasePer release candidateCISO (M. Hassan)
Fairness Deviation≤ 5% from population meanPer model validation cycleP. Okafor

9.5 User Acceptance Testing (UAT)

10. Resource Management Plan

10.1 Staffing Summary

Total program roster: 262 people across 25 functional teams. Not concurrent headcount; staffing ramps by phase. Peak Year 1: approximately 120 active. Complete named roster with role, location, allocation, rate, and cost in Resource Plan and Organization Chart.

CategoryCountAnnual Labor Cost
ACME FTE (non-billable to Pulaski SOW)~140 people$19,600,000
Pulaski Onshore Consultant~75 people$27,400,000
Pulaski Offshore Consultant~47 people$14,200,000
Total262$61,200,000

10.2 Staffing Ramp & Phase Allocation

10.3 Team Lead Assignments & Reporting

All 25 team leads are named in the Resource Plan with their organizational affiliation (ACME FTE or Pulaski consultant). Reporting structure:

10.4 Onboarding & Offboarding

11. Communications Management Plan

Full communications matrix is maintained in the Communications Plan. This section summarizes the management approach.

11.1 Communication Cadence

CommunicationFrequencyOwnerAudienceFormat
Program Status SyncWeeklyC. TyrrellPMO Lead + 25 team leadsMeeting (1 hr) + written summary
Executive Steering BoardBi-weekly + phase gatesM. KavanaghBoard membersMeeting (1.5 hrs) + scorecard
AI Governance BoardBi-weekly + model reviewsS. KhuranaBoard membersMeeting (1 hr) + model review packet
Enterprise Architecture ReviewWeekly (build phases)D. ChenEARB + BRD leadsMeeting (1 hr)
Monthly Program Status ReportMonthlyC. TyrrellExecutive Steering BoardWritten report (10 pages) + dashboard
Program NewsletterMonthlyB. SullivanAll ACME staff impactedEmail newsletter
Quarterly Risk ReviewQuarterlyAll 3 boardsRAIDD stakeholdersWorking session (2 hrs)
Board-Level UpdateQuarterlyM. KavanaghACME Board of DirectorsExecutive briefing (30 min)

11.2 Escalation Communications (Mandatory, Time-Bound)

TriggerNotification WindowOwnerNotified Parties
Model Validation Critical/High findingWithin 24 hours of findingP. OkaforAI Governance Board, BRD Lead, Program Director
Hallucination or bias incident in productionWithin 24 hours of detectionS. KhuranaAI Governance Board, Executive Sponsor, General Counsel
Regulatory inquiry or scrutinyImmediately upon receiptR. ThorneExecutive Steering Board, AI Governance Board
Security breach or data exposureWithin 4 hours of detectionM. HassanExecutive Sponsor, General Counsel, Chief Privacy Officer
Budget variance >10% in any categoryWithin 48 hours of identificationA. RodriguezProgram Director, CFO, Executive Steering Board
Schedule slippage >2 weeks on critical pathWithin 48 hours of identificationM. TorresProgram Director, affected Board

11.3 Stakeholder Information Needs

12. Risk Management Plan

The RAIDD Log is the system of record for all risks, assumptions, issues, dependencies, and decisions. This section defines the management process.

12.1 Risk Identification

12.2 Risk Assessment

Risks are assessed on a 1–9 scale (Probability × Impact), each dimension rated Low (1), Medium (2), or High (3):

Impact: Low (1)Impact: Medium (2)Impact: High (3)
Prob: High (3)369
Prob: Medium (2)246
Prob: Low (1)123

Score interpretation: 1–3 Low (monitor) · 4–6 Medium (active mitigation) · 7–9 High (escalate to board within 48 hours).

12.3 Risk Response Strategies

12.4 Risk Monitoring & Escalation

12.5 AI-Specific Risk Categories

Beyond standard program risks, this program carries risk categories unique to enterprise AI deployment:

13. Procurement & Vendor Management Plan

13.1 Vendor Landscape

Project Catalyst relies on three categories of external vendors:

13.2 Vendor Governance

13.3 Procurement Thresholds

Procurement ValueApproval Authority
< $50,000Program Director
$50,000–$500,000Program Director + CFO
$500,000–$2,000,000Executive Steering Board
> $2,000,000Executive Sponsor + CFO + Legal

14. Stakeholder Engagement Plan

14.1 Stakeholder Identification & Classification

Stakeholder GroupInfluenceInterestEngagement Strategy
ACME Board of DirectorsHighMediumKeep satisfied: quarterly briefings, no operational detail
Executive Steering BoardHighHighManage closely: bi-weekly meetings, phase-gate sign-off, budget oversight
State Regulators / CMSHighMediumKeep satisfied: quarterly compliance briefings, proactive transparency
Frontline Operations StaffLowHighKeep informed: monthly newsletters, phased rollout, change management support
Members / PatientsLowMediumMonitor: indirect impact; quality and fairness testing protects their interests
IT Operations TeamMediumHighManage closely: weekly architecture reviews, platform transition planning
Pulaski Consulting LeadershipMediumHighManage closely: monthly delivery reviews, SOW performance tracking

14.2 Stakeholder-Specific Risks

Part III — AI-Specific Management Plans

15. AI Governance & Model Risk Management Plan

This section defines the AI-specific governance and model risk management framework that sits on top of — and is enforced through — the standard program governance structure. It is the single most important differentiator between this program and a conventional IT project: every decision about model design, training data, validation methodology, and production release is governed here.

15.1 Two-Line-of-Defense Model Risk Structure

Why two lines? A single team that both designs and validates AI models has an inherent conflict of interest — schedule pressure incentivizes passing models that should be held for further work. The deliberate separation between CoE (first line, advisory, embedded) and Validation (second line, independent, blocking) eliminates this conflict. This structure is modeled on financial services regulatory practice (OCC model risk guidance) adapted for healthcare AI.

15.2 Model Lifecycle Governance

Every AI model on this program follows a governed lifecycle with defined checkpoints:

  1. Concept & Design (Phase 1): Model concept reviewed at JAD sessions. CoE reviews model type selection, training data assumptions, fairness criteria, and human-override protocol design. Output: approved model design document.
  2. Development & Training (Phase 2): Model developed by BRD delivery team using approved design. CoE conducts interim reviews of training data quality, feature engineering decisions, and preliminary accuracy metrics. Output: trained model ready for validation.
  3. Independent Validation (Phase 3): Model submitted to Independent Model Validation. Validation runs the five-criteria assessment defined in Section 9.3. Output: validation report with findings classified as Critical/High/Medium/Low. Critical or uncorrected High findings = model rejected.
  4. Pilot Deployment (Phase 3): Validated model deployed to controlled pilot environment with limited user group. Pilot duration: minimum 4 weeks. Monitored for accuracy drift, fairness drift, and operational workflow integration. Output: pilot results report.
  5. Production Release (Phase 4): Model deployed to full production with ongoing monitoring. Retraining triggers defined (accuracy drift >X%, fairness deviation >Y%, data distribution shift >Z%). Output: production model with monitoring dashboard.
  6. Ongoing Monitoring & Retraining (Year 2–3): Production models monitored continuously. If retraining trigger is hit, model re-enters the validation cycle at step 3 — no production model is updated without re-validation. CoE reviews retraining cadence quarterly.

15.3 Responsible AI Standards

15.4 Shadow AI Prevention

16. Data Governance & Privacy Management Plan

16.1 Data Classification & Handling

16.2 Data Residency Architecture

16.3 Privacy Impact Assessment

17. Regulatory Compliance Management Plan

17.1 Regulatory Landscape

Regulation / StandardApplicabilityCompliance Owner
CMS-0057-F (Prior Auth Interoperability)BRD-01 directly; program-wide indirectlyJ. Martinez (VP Compliance)
NIST AI RMF 1.0All BRDs — voluntary framework adopted as enterprise standardS. Khurana (AI Gov Director)
ISO/IEC 42001AI CoE organizational alignmentS. Khurana
NAIC Model AI BulletinBRD-03 (underwriting) — state-level applicability variesR. Thorne (General Counsel)
State AI-in-Insurance StatutesBRD-01/03 — Colorado, Connecticut, others emergingR. Thorne
HIPAA / HITECHAll PHI-handling workstreamsE. Sato (CPO)
SOX (Financial Controls)Claims-payment and financial-reporting itemsK. Williams (VP Internal Audit)

17.2 Compliance Monitoring & Reporting

Part IV — Governance & Decision Authority

18. Governance Structure & Decision Rights

Full governance structure is defined in the Program Governance Model. This section summarizes the decision-rights framework as it applies to day-to-day program execution.

18.1 Decision Authority Matrix

Decision TypeAuthorityApproval Process
Sprint-level technical decisionsBRD LeadTeam decision, no formal approval needed
Cross-BRD technical dependency resolutionProgram DirectorScrum-of-Scrums resolution; escalate if unresolved in 48 hrs
Model design approvalAI Governance BoardReviewed at JAD; approved in Governance Board meeting
Architecture approvalEARBArchitecture review meeting; EARB sign-off required
Model production releaseAI Governance Board + Independent ValidationValidation report clean → Board approval → release
Phase-gate advancementAll 3 Boards (concurrent)Phase-gate procedure (Section 4.2)
Budget change >$500KExecutive Steering BoardChange control (Section 21)
Contingency drawdown >$1MExecutive SponsorFormal presentation + CFO concurrence
Scope change (any size)Varies by impact — see Section 5.3Change control (Section 21)
Vendor contract >$500KExecutive Steering BoardProcurement threshold (Section 13.3)
Regulatory compliance interpretationVP Compliance (J. Martinez)Consulted with General Counsel; AI Governance Board informed

19. Meeting Cadence & Reporting Framework

The meeting cadence is designed to provide sufficient oversight without consuming delivery capacity. Every meeting has a defined owner, duration, and expected output. Meetings that consistently run without actionable output are candidates for frequency reduction at the next quarterly governance review.

19.1 Standing Meetings

MeetingFrequencyDurationOwnerRequired Output
Daily Standup (per BRD team)Daily15 minScrum MasterBlocker identification
Scrum-of-Scrums2×/week15 minC. TyrrellCross-team dependency status
Sprint Planning (per BRD)Bi-weekly (Day 1)90 minBRD Lead + SMSprint backlog committed
Sprint Review/DemoBi-weekly (last day)45 minBRD LeadIncrement demonstrated
Sprint RetrospectiveBi-weekly (last day)45 minScrum MasterImprovement actions identified
Backlog RefinementWeekly (mid-sprint)60 minProduct ManagerStories refined to "Ready"
Program Status SyncWeekly60 minC. TyrrellStatus summary + blockers
Executive Steering BoardBi-weekly90 minM. KavanaghScorecard + decisions
AI Governance BoardBi-weekly60 minS. KhuranaModel risk status + decisions
Enterprise Architecture ReviewWeekly (build phases)60 minD. ChenArchitecture decisions logged
Monthly Status ReportMonthlyWritten (no meeting)C. Tyrrell10-page report + dashboard
Quarterly Risk ReviewQuarterly120 minAll 3 boardsRAIDD Log fully refreshed

20. Escalation Framework

20.1 Standard Escalation Path

Escalation is expected and healthy — it means the governance structure is functioning. The following path applies to any issue that cannot be resolved at its originating level:

  1. Level 1 — Team Level (0–24 hours): Team Lead or Scrum Master attempts resolution within the team. If resolved, log resolution in RAIDD Issues section.
  2. Level 2 — Program Director (24–48 hours): If unresolved at team level, escalated to Program Director. Director convenes a working group (affected team leads, relevant board lead, functional manager). Most issues resolve here.
  3. Level 3 — Board Level (48 hours–5 business days): If the working group cannot resolve, escalated to the relevant board: AI Governance Board (model-risk issues), EARB (technical issues), Executive Steering Board (scope/budget/schedule issues). Board provides direction within 5 business days.
  4. Level 4 — Executive Sponsor (5+ business days): If board deadlocks or the issue exceeds board authority (e.g., requires >$1M contingency drawdown, regulatory escalation, program viability question), escalated to Executive Sponsor (M. Kavanagh). Sponsor makes final decision or escalates to CFO/CIO.

20.2 Emergency Escalation (Bypasses Standard Path)

TriggerDirect Escalation ToTimeline
Security breach or data exposure (confirmed)CISO + Executive Sponsor + General CounselWithin 4 hours
AI model produces harmful output in productionAI Governance Board + Executive SponsorWithin 24 hours; production paused immediately
Regulatory enforcement action receivedGeneral Counsel + Executive Steering BoardImmediately upon receipt
Team lead or key resource unplanned departureProgram Director + HR (C. Johnson)Within 24 hours
Part V — Program Execution & Control

21. Change Management & Configuration Control

21.1 What Requires Formal Change Control

21.2 Change Control Process

  1. Submission: Change request submitted to Program Director using the standard form (in Change Control Log). Requestor documents: what is changing, why, impact on scope/schedule/budget/quality, alternatives considered, and recommended action.
  2. Impact Assessment (5 business days): Program Director assesses impact across all dimensions. Consults with affected team leads, Program Finance, and relevant board chairs as needed.
  3. Routing: Based on impact assessment, the change request is routed to the appropriate approval authority: Program Director (Tier 1, within standing authority), relevant Board (Tier 2, exceeds standing authority), or Executive Sponsor (Tier 3, exceeds Board authority).
  4. Review & Decision (within 2 weeks of submission): Approver reviews impact assessment and makes decision: Approve, Approve with Conditions, Defer, or Reject. Decision documented.
  5. Implementation: Approved changes are entered into the Change Control Log with effective date, baseline adjustment (if applicable), and owner accountability. All affected artifacts (WBS, RAIDD Log, Resource Plan, Budget) updated within 5 business days of approval.

21.3 Configuration Management

22. Performance Measurement & Earned Value

22.1 Performance Metrics

MetricFormulaFrequencyGreenYellowRed
Schedule Performance Index (SPI)EV / PVMonthly≥ 0.950.85–0.94< 0.85
Cost Performance Index (CPI)EV / ACMonthly≥ 0.950.85–0.94< 0.85
Estimate at Completion (EAC)BAC / CPIQuarterly≤ $99M$99M–$103M> $103M
Sprint Velocity (per BRD team)Story points completed / sprintPer sprintWithin ±10% of 3-sprint avg±10–20%> ±20%
Defect Escape RatePost-sprint defects / storiesPer sprint< 5%5–10%> 10%
RAIDD Log Health% of risks updated in last 14 daysWeekly100%80–99%< 80%

22.2 Program Dashboard

The Program Dashboard (separate artifact, updated weekly) provides a visual summary of all performance metrics. Dashboard sections: Overall Program Health (RAG), Schedule Health (SPI + milestone tracker), Budget Health (CPI + spend vs. forecast), Risk Health (active risk count by quadrant), Quality Health (defect trends + validation status), Staffing Health (actual vs. planned headcount). Dashboard reviewed at every Program Status Sync and presented to Executive Steering Board bi-weekly.

23. Benefits Realization Management

23.1 Benefits Framework

Benefits are tracked against baselines established during Phase 0 (AI Readiness Assessment). The Cost-Benefit Analysis defines the expected benefit drivers; this section defines how realization is measured.

BenefitMetricBaseline (Phase 0)Target (Year 3)Measurement Owner
PA Cycle Time ReductionAverage days from PA submission to decisionMeasured Phase 050% reductionF. Bennett (BRD-01)
PA Automation Rate% of PAs auto-adjudicated (no human touch)0% (current manual process)60–70%F. Bennett
Call-Center Handle TimeAverage handle time per member interactionMeasured Phase 030% reductionX. Garcia (BRD-02)
Underwriting ConsistencyInter-rater reliability scoreMeasured Phase 020% improvementZ. Thompson (BRD-03)
Claims Fraud DetectionAnnual fraud-identified amountCurrent baseline$2.4M/yr increaseF. Bennett

23.2 Benefits Tracking Cadence

24. Knowledge Transfer & Transition Planning

24.1 Transition Scope

At program closeout (August 2029), the following capabilities transition from Pulaski Advisory Group consulting delivery to permanent ACME Highland Health operations:

24.2 Knowledge Transfer Process

Part VI — Baselines, Assumptions & Reference

25. Assumptions, Constraints & Dependencies

25.1 Assumptions

25.2 Constraints

25.3 External Dependencies

26. Baselines Summary

BaselineEstablishedDocumentChange Authority
Scope BaselinePhase 1 Gate (per BRD)BRD Requirements Document + WBSExecutive Steering Board
Schedule BaselineProgram KickoffProgram Plan Console / WBSProgram Director (< 2 weeks); ESB (> 2 weeks)
Cost BaselineCharter ApprovalProgram Charter Section 10 + SOWsExecutive Steering Board
Quality BaselinePhase 1 GateQuality Metrics (Section 9.4) + Model Validation CriteriaAI Governance Board
Resource BaselinePhase 0 GateResource Plan (262-person roster)Program Director (< 5 FTEs); ESB (> 5 FTEs)

27. Process Improvement & Lessons Learned

28. Document Control & Approvals

28.1 Document Control

FieldValue
Document TitleProgram Management Plan (PMP)
ProgramProject Catalyst — AI Transformation Program
Version1.0
Date17 August 2026
ClassificationACME Internal — Restricted Distribution
RetentionProgram lifecycle + 7 years per ACME retention policy

28.2 Approval Signatures

RoleNameApproval
Program DirectorC. Tyrrell (Pulaski Advisory Group)Approved — 17 Aug 2026
Executive SponsorM. Kavanagh (ACME COO)Approved — 17 Aug 2026
PMO LeadT. Valdez (ACME)Approved — 17 Aug 2026
AI Governance DirectorS. Khurana (Pulaski)Approved — 17 Aug 2026
Chief Enterprise ArchitectD. Chen (ACME)Approved — 17 Aug 2026

29. Appendices & Cross-References