← Federal Suite 05 · Governance & Financial

Program Governance Model

Download Word

Program Governance Model

BenefitConnect Portal Modernization — Task Order 3, HSS-IDIQ — Acme Federal Systems

VersionDateSummary
1.0May 18, 2026Initial governance model — structure, decision rights, escalation, CDRL gates
1.1May 2, 2026D-02 staffing correction incorporated as the framework's first applied precedent

1. Purpose & Governance Principles

This document establishes the decision-making authority, escalation paths, and accountability structure for the BenefitConnect Portal Modernization Task Order. It is distinct from the Task Order Charter: the Charter describes what the Task Order will deliver and why; this document defines who has the authority to decide, and how disputes or exceptions are resolved when the plan needs to change — including the staffing correction (RAIDD D-02) that already tested this framework once.

Five principles guide this governance model:

Transparency — decisions and their rationale are documented and visible, not made informally. The staffing correction is the clearest example: it's recorded as a formal RAIDD decision, not a quiet headcount change.
Accountability — every decision has a single accountable owner, even when multiple people are consulted.
Timely Decision-Making — defined escalation timeframes prevent CDRL, security, or staffing issues from stalling at the wrong authority level.
Proportionality — oversight scales with contractual and security impact; a minor schedule adjustment doesn't need CO attention, but a contract modification always does, no matter how small.
Single Source of Truth — this document is the authoritative reference for decision rights; where other documents (RAIDD Log, Contract Mod Log) summarize decision authority, this document is what they summarize from.

2. Governance Structure

Federal Task Order governance is built around a different backbone than a commercial program's: legal authority to bind the contract sits with exactly one person (the CO), no matter how senior anyone else in the room is. Commercial program governance usually concentrates authority in a single executive sponsor who can approve scope, budget, and schedule changes in one conversation; this Task Order deliberately splits that authority across four bodies instead.

BodyCompositionFunction
Contracting Officer (CO)A. ReyesSole legal authority to modify the contract — every Mod in the Contract Mod Log carries her signature. No other role, including the Sponsor, can bind the contract.
Contracting Officer's Representative (COR)M. WhitcombeDelegated day-to-day oversight: CDRL deliverable review/acceptance, QASP surveillance monitoring, primary government point of contact — but no authority to change contract terms herself.
Federal Business Owner / SponsorR. OseiOwns the mission outcome (a modernized, accessible benefits portal); informed on major decisions but doesn't sit in the day-to-day oversight chain.
Task Order PMC. Tyrrell, Acme Federal SystemsDay-to-day execution authority within delegated limits defined in Section 3; leads the full 35-person delivery team.

Delivery Team Leadership

NameRole
C. TyrrellTask Order PM
D. FerrisDeputy Task Order PM
K. LindqvistSolutions Architect / Tech Lead
T. AbernathyISSO (ATO Owner)

For the full 35-person reporting-line structure, including the flat Resource Registry, see the companion Organizational Chart.

3. Roles, Responsibilities & Decision Rights

Every decision on this Task Order falls into one of three authority tiers. The staffing correction (D-02) is a real, already-applied example of this tiering, not just a hypothetical: it stayed within the Task Order PM's own budget-neutral authority to reallocate roles, because it corrected an internal planning gap (a 7-person estimate with no developers) rather than changing the Task Order's Firm-Fixed-Price value or scope.

TierAuthorityDecisions Covered
Tier 1Task Order PM (informational only — no approval required)Task-level schedule adjustments with no CDRL-gate impact; staffing corrections within the approved FFP labor budget (the D-02 precedent); internal tooling or process adjustments
Tier 2COR (delegated from the CO)CDRL deliverable acceptance, rejection, or return-for-rework; QASP surveillance findings; day-to-day contractor coordination
Tier 3Contracting Officer (sole legal authority)Any contract modification — scope, cost, or schedule — no matter how small; Option Period exercise; funding changes

ATO/security authorization sits in a distinct, parallel chain rather than this tiering: the Authorizing Official, not the CO or COR, holds go/no-go authority over Authority to Operate, based on the ISSO's submitted security package (see Section 11).

Key Role Responsibilities

RoleKey Responsibilities
Task Order PMDay-to-day execution; Tier 1 decisions; prepares CDRLs for COR review; escalates per Section 4
Solutions Architect / Tech LeadTechnical architecture decisions; COR informed for anything touching security or 508 posture
ISSOOwns the ATO/RMF security package; submits to the Authorizing Official; escalates security findings per Section 4
Section 508 LeadOwns Section 508/VPAT conformance; coordinates the independent third-party audit required under Mod P00001
CORTier 2 decisions; CDRL acceptance; QASP surveillance; primary government point of contact
Contracting OfficerTier 3 decisions; sole authority to sign a Mod or exercise the Option Period

3.1 Governance-Process RACI Matrix

This matrix covers governance-process activities only — approving staffing corrections, accepting CDRLs, authorizing exceptions. It is deliberately narrower than, and complementary to, the delivery-execution RACI already defined in the RACI Matrix. The two matrices should never duplicate the same row.

Governance ActivityResponsibleAccountableConsultedInformed
Approve Tier 1 staffing correction (D-02 precedent)C. TyrrellC. TyrrellD. FerrisM. Whitcombe (COR)
Accept a CDRL deliverableC. TyrrellM. Whitcombe (COR)K. Lindqvist, T. Abernathy (as applicable)R. Osei
Approve a contract modificationC. Tyrrell (prepares)A. Reyes (CO)M. Whitcombe (COR)R. Osei
Accept high-scored risk (RAIDD ≥7)C. TyrrellA. Reyes (CO), where cost/schedule impact existsRisk OwnerR. Osei
Authorize an ATO conditional acceptance / POA&MT. AbernathyAuthorizing OfficialM. Whitcombe (COR)C. Tyrrell, R. Osei
Quarterly governance framework reviewC. TyrrellM. Whitcombe (COR)A. Reyes (CO)R. Osei

Also available as its own page: RACI Matrix.

4. Escalation Process

Escalation follows the same three-layer split as the governance structure above — an issue moves up through the contractor chain first, then crosses into the government chain only at the level actually authorized to resolve it. A delivery-level defect never reaches the CO; a genuine scope dispute never gets resolved by the COR alone, because she doesn't have that authority to give. Escalation is triggered automatically once a defined threshold is crossed — not left to individual judgment about whether something "feels" significant enough to raise.

TriggerThresholdEscalates ToTimeframe
Delivery-level issueAny internal schedule or technical blockerC. Tyrrell → D. Ferris / functional leadsSame business day
Government coordination issueAny item needing COR input or decisionC. Tyrrell → M. Whitcombe (COR)5 business days
Contractual dispute or scope disagreementAny disagreement the COR cannot resolve within her delegated authorityC. Tyrrell → M. Whitcombe → A. Reyes (CO) — formal, in writing10 business days
Security finding blocking ATOAny Critical/High finding from the pre-assessment or formal scanT. Abernathy → M. Whitcombe → Authorizing Official2 business days
Risk scoreRAIDD score ≥7 (High/High)M. Whitcombe (COR), visibility; A. Reyes (CO) if cost/schedule impact existsNext reporting cycle
Contract modification growthCumulative mod value exceeds 5% of FFP baseline in a single reporting periodA. Reyes (CO), notificationNext monthly status report

Standard escalation path: Delivery team → Task Order PM → Deputy PM / functional leads → COR → Contracting Officer / Authorizing Official (where contract or ATO authority is affected). Issues unresolved at the PM level within 5 business days (2 business days for ATO-blocking security findings) escalate automatically to the next tier.

5. Meeting Cadence & Reporting

CadenceForumPurpose
WeeklyDelivery Standup (C. Tyrrell, D. Ferris, functional leads)Internal, contractor-only — status & blockers
Bi-weeklyCOR Sync (C. Tyrrell, M. Whitcombe)CDRL status, open issues, upcoming deliverables
MonthlyStatus Report (CDRL A008)Formal written deliverable to the COR, per the agency-wide template established under Mod P00003
QuarterlyProgram Review (C. Tyrrell, M. Whitcombe, R. Osei)Mission-outcome and business-case check-in; doubles as the quarterly governance framework review (Section 13)

6. Contract Modification Governance

Every scope, cost, or schedule change on this Task Order — no matter how small — goes through a formal Mod, signed by the CO, before it takes effect. This Task Order processed 11 mods over its period of performance, from administrative corrections (P00003, P00009) to security-driven scope additions (P00004, P00006, P00008) to the formal Option Period exercise (P00010), for a net incremental value of +$4,154,000 above the $3,550,000 baseline — $4,040,000 of it from Mod P00011 alone. See the Contract Modification Log for the full list and the Contract Modification Detail page for each mod's full SF-30-style documentation.

7. CDRL Governance & Deliverable Acceptance

The 10-item CDRL schedule is the contract's formal deliverable spine — each item has a defined format, due date, and acceptance authority, tracked on the CDRL Schedule page. Acceptance authority sits with the COR for most items, with the ISSO added as a co-reviewer on the System Security Plan (A005) given its direct bearing on the ATO package.

ActivityAuthority
CDRL submission reviewC. Tyrrell prepares; M. Whitcombe (COR) reviews
CDRL formal acceptanceM. Whitcombe (COR), or Authorizing Official for the ATO Package (A007)
CDRL rejection / return for reworkM. Whitcombe (COR), with written rationale tied to the CDRL's acceptance criteria
CDRL format or template changeAdministrative Mod (the P00003 precedent for A008) — A. Reyes (CO)
Independent audit of a CDRL (508 Test Plan / VPAT)Independent third-party auditor added under Mod P00001, not contractor self-attestation

8. CDRL Gates & Approval Criteria

Several CDRLs function as hard gates — the Task Order cannot proceed past them on self-attestation alone.

Every gate below requires the specific go/no-go criteria in the table, not general progress: a CDRL that's "mostly done" is not an accepted CDRL.

Gate (CDRL)Go/No-Go CriteriaApproval
PMP + IMS Baseline (A001/A002)Baseline schedule and management approach accepted with no open COR commentsM. Whitcombe (COR)
Section 508 Test Plan (A004)Test methodology accepted; independent auditor named per Mod P00001M. Whitcombe (COR)
System Security Plan (A005)Security control baseline documented and accepted ahead of formal ATO submissionT. Abernathy (ISSO) + M. Whitcombe (COR)
Section 508 / VPAT Test Report (A006)Full conformance, independently verified — no open Critical findingsIndependent third-party auditor + COR
ATO Package (A007) — Milestone Gate 1Zero open Critical/High security findings, or an accepted POA&M for any Medium findingAgency Authorizing Official
Data Migration Plan & Validation (A009)Full field-level validation report accepted; no unresolved data-integrity exceptionsM. Whitcombe (COR)
Task Order Closeout (A010)All CDRLs accepted; final budget reconciled; CPARS input finalizedM. Whitcombe (COR) / A. Reyes (CO)

9. Independent Assurance

Performance Monitoring (Section 12) is self-reported: the Task Order PM and functional leads track and report status upward through the normal chain. Independent Assurance is a distinct, separate check — performed by someone outside the reporting chain being assessed.

ElementDetail
Who performs itAn independent third-party auditor, added under Mod P00001 specifically so Section 508/VPAT conformance is never contractor self-attestation
FrequencyAt CDRL A006 (508/VPAT Test Report) and any subsequent re-test cycle; QASP surveillance runs continuously between formal CDRLs
ScopeManual assistive-technology testing against the VPAT; spot-check of automated regression results added under Mod P00006
FindingsReported directly to the COR — not filtered through the Task Order PM
ATO equivalentThe Authorizing Official's security assessment is itself an independent check, separate from the ISSO's own self-reported security posture

10. Risk & Issue Governance

The RAIDD Log records what the risks and issues are; this section defines who has the authority to accept, fund, or escalate a response to them.

Risk ScoreAuthority
1–3 (Low)Task Order PM may accept and manage without further approval
4–6 (Medium)Task Order PM manages; reported to the COR in the next status cycle
7–9 (High)Requires COR visibility and, where cost or schedule impact exists, CO approval of the response plan (the R-01 ATO risk is the live example)

11. Compliance & Regulatory Oversight

Two compliance threads run in parallel to the delivery schedule rather than as a phase within it: the ATO/RMF security authorization (owned by T. Abernathy, approved by the Authorizing Official) and Section 508 accessibility conformance (owned by P. Duvall, independently audited per Mod P00001). Both are gating — the portal cannot go live without ATO, and cannot ship non-conformant UI past the independent 508 audit.

ATO / Section 508 Veto Authority
No Critical or High ATO security finding, and no Section 508 non-conformance flagged by the independent auditor, may be waived or overridden by schedule or budget pressure at the Task Order PM or COR level. Only the Authorizing Official (for ATO) or the independent auditor in consultation with the COR (for Section 508) may accept a documented exception via POA&M — and any such exception must be logged with rationale in the governance review record (Section 13).

See the ATO Package and Section 508/VPAT pages for the compliance detail behind this oversight.

12. Performance Monitoring

The COR monitors contractor performance against the compliance and delivery KPIs reported monthly via the Steering Deck:

Neither the COR's monitoring nor QASP surveillance gives the COR authority to change the contract — only to accept, reject, or flag a deliverable for CO attention, per Section 3.

13. Governance of This Framework

This document is owned by the Task Order PM and reviewed quarterly, with amendments to decision-rights tiers or escalation thresholds requiring COR concurrence and, where contractual terms are touched, a formal Mod; amendments to meeting cadence or reporting format may be approved by the Task Order PM alone.

VersionDateSummaryApproved By
1.0May 18, 2026Initial governance model establishedM. Whitcombe (COR)
1.1May 2, 2026D-02 staffing correction formally incorporated as the framework's first applied precedentC. Tyrrell

Note: version 1.1's effective date (May 2, 2026) predates version 1.0's formal document date (May 18, 2026) because the D-02 decision itself was made under the framework's principles before this document was formally finalized and dated — the precedent came first, the write-up caught up to it.

14. Approval

This governance model is approved for use across the BenefitConnect Portal Modernization Task Order.

 

R. Osei, Federal Business Owner / Sponsor
 

A. Reyes, Contracting Officer
 

M. Whitcombe, Contracting Officer's Representative
 

C. Tyrrell, Task Order PM