← Stage-Gate NPD Suite Operational Readiness & Cutover

Operations Readiness & Cutover Plan — Version 1.0

Download Word
Program timeline · status 16 Oct 2026Read the full story →
Harborline
Aug 2025
Cancelled
Gate 0
Feb 2026
Go
Stage 1
Business case
Gate 1
Apr 2026
Recycled
Gate 1
Jun 2026
Go w/ conditions
Stage 2
Development
You are here
Gate 2
Apr 2027
Gate 3
Oct 2027
Gate 4
Feb 2028
Launch
Mar 2028
Gate 5
Sep 2028

Lighthouse Financial Services Company — This plan governs the transition of the Beacon Index Advantage from a program deliverable into a product the company sells, administers and is contractually bound by. It is deliberately not written as an inventory of things to have ready. It is written around the one structural fact that separates an annuity cutover from a software cutover: a release can be rolled back and an in-force contract cannot. The point of no return is not go-live. It is the first policy issued — and it arrives some time after launch, unannounced, when a producer somewhere submits an application that clears suitability review. Everything before it is reversible and is planned that way. Everything after it is permanent and is planned that way. Rollback does not fail at cutover. It expires.

Status at the date of this version. Program is in Stage 2 — Development, week 17 of 40. Launch is 06 March 2028. Gate 4 (Launch Readiness) sits 11 days before it, and Gate 4 is what releases Stage 4 funding of $4,330,000 — including the vendor package that staffs hypercare. Operations is a 7-person team; the platform team is 10. Status date 16 October 2026. Three readiness criteria in §9 cannot close before Gate 4 by construction, and this plan says so rather than showing them amber.

Contents

  1. Purpose, Scope & the Point of No Return
  2. What Actually Changes at Launch
  3. The Day-One Operating Model — and Why It Is Not the Steady State
  4. New Business Processing & the Suitability Review Constraint
  5. Policyholder Services, Correspondence & the Free-Look Window
  6. Platform Cutover — Sequence, Environments & Data
  7. The Rollback Question, and When It Expires
  8. Hypercare — Structure, Staffing and Unreleased Funding
  9. Readiness Criteria and the 11-Day Window
  10. Dependencies Operations Does Not Own
  11. Risks, Issues & Register Linkage
  12. Governance, Ownership & Document Control

1. Purpose, Scope & the Point of No Return

This plan covers the operational readiness of Lighthouse Financial Services Company to sell, issue and administer the Beacon Index Advantage, and the cutover activity that moves the platform configuration into production. It covers new business intake, suitability review, policy issue, funding, policyholder services, correspondence, reconciliation and the hypercare period that follows launch.

1.1 The organizing distinction

Cutover plans in most industries are built on an assumption so ordinary it is rarely stated: if the thing goes wrong, you put back what was there before. That assumption is available here right up until it isn't. Configuration can be reverted. Rate tables can be reloaded. Interfaces can be disabled. A sales portal can be closed. None of that is difficult and all of it is planned in §6.

What cannot be reverted is a contract. The moment an application is accepted and a policy is issued, a person owns a financial instrument this company is obliged to honor for decades. There is no release note that undoes it. This produces a plan with two halves that obey different rules:

PhaseGoverning questionFailure response
Before first issueCan we still stop? Stop. Revert. The cost is schedule and credibility, both survivable.
After first issueCan we still serve the people who bought it? Forward-only. Remediate in place. Every option now involves policyholders.
The point of no return is not on the schedule, and that is the problem. Launch day is a date. First policy issued is an event, and it depends on producer behavior nobody controls. It could be launch morning. It could be nine days later. A cutover plan that treats go-live as the irreversible moment is measuring the wrong thing — and a plan that assumes a comfortable gap is assuming the one variable it has least claim on. §7 defines what the program does about a boundary it cannot schedule.

1.2 What this plan does not cover

2. What Actually Changes at Launch

A useful readiness plan starts by being honest about how much is genuinely new, because readiness effort should concentrate where the novelty is. Lighthouse Financial Services Company already administers annuity business. The platform already exists. Most of what happens on launch day is a variation of what the operation does every day. Treating all of it as new dilutes attention away from the parts that actually are.

Operational areaDegree of changeReadiness implication
Application intake and imagingMinimal Existing workflow, new product code. Configuration check, not retraining.
Suitability reviewSubstantial New product, new crediting mechanics, and a volume assumption the current staffing was never sized against. See §4.
Policy issue and contract assemblyModerate New forms, and the forms are not approved yet (I-05). Cannot be finalized upstream of filing.
Premium funding and 1035 exchangesMinimal Existing process. Exchange volume may rise; that is a capacity question, not a design question.
Index crediting administrationSubstantial Genuinely new mechanics. First crediting cycle falls well after launch, which makes it easy to under-prepare and impossible to fix late.
Illustrations and in-force quotingModerate Governed by the filed methodology, not the specification. Operations cannot resolve a discrepancy locally.
Correspondence and confirmationsModerate New templates, state-variable content, and free-look language that has to be right the first time.
Valuation and reserve reportingModerate First cycle is the proof. Nothing before it is evidence.
The two substantial items are not the two loudest items. Launch attention naturally goes to policy issue, because that is the visible moment. But issue is a moderate change to an existing process, while suitability review and index crediting administration are the areas where this product genuinely differs from what the operation already does. Readiness effort is allocated accordingly, and §9 reflects that rather than distributing criteria evenly for the look of balance.

3. The Day-One Operating Model — and Why It Is Not the Steady State

Operations is a 7-person team spanning new business and policyholder services, against a program labor envelope of $856,800 across 10,200 hours. That team is sized for the program, not for the product's eventual in-force block.

3.1 Why a headcount is the wrong answer

The obvious readiness question — "how many people do we need on day one?" — has no honest answer, because day one volume is unknown and the plan's own volume assumption is contested. The Distribution plan reports written Year One commitments below target and field coverage at four wholesalers against six planned (I-06). Staffing to the target risks paying for capacity that never arrives; staffing to the shortfall risks failing the producers who do sell.

So the day-one model is defined by triggers rather than headcount. The operation opens at its current size and expands on observed volume, with the expansion pre-authorized so that it does not require a fresh approval cycle at the moment it is needed.

TriggerObserved conditionPre-authorized response
T1Applications sustained above plan for 10 working days Extend intake hours; second reviewer cross-trained and released from project work.
T2Suitability review queue exceeds 2 working days at any point Escalate to the trained backup reviewer; notify Distribution that turnaround is degrading before producers discover it.
T3Issue-to-funding cycle exceeds the service standard for 5 consecutive days Daily stand-up moves to twice daily; hypercare vendor engaged on throughput, not defects.
T4Any single crediting strategy exceeds 60% of new premium Notify the hedging desk same day. This is R-12 surfacing operationally, and Operations sees it first.
T4 is in this plan because Operations is the earliest detector of a hedging problem. Sales concentration in one crediting strategy (R-12) reaches the Investments desk through reporting, which lags. It reaches new business processing in the application stack, which does not. Putting the trigger here costs nothing and buys days.

3.2 Named day-one ownership

FunctionOwnerRole
Overall operational readiness and the go / no-go operations inputL. Marchand Director, Annuity Operations
New business intake, issue and fundingK. BeauchampNew Business Manager
Policyholder services, correspondence and free-look handlingR. Underwood Policyholder Services Manager
Suitability reviewS. CarrenoSuitability Review Analyst
Procedures and training curriculumN. JessupTraining & Procedures Analyst
Process design and exception pathsT. HaddadiProcess Design Analyst
Readiness evidence, dress rehearsals and criteria trackingD. Fairbairn Operations Readiness Analyst
Platform cutover executionV. SandovalPlatform Delivery Lead
Release and environment controlR. AchterbergRelease & Environment Engineer
Interface and downstream integrationL. NavarreteIntegration Engineer

4. New Business Processing & the Suitability Review Constraint

Every fixed indexed annuity sale is subject to suitability review under the NAIC Suitability in Annuity Transactions Model Regulation (#275) as adopted in each state. The reviewer must form a judgment that the recommendation was in the consumer's best interest given their financial situation, objectives and needs. This is a licensed judgment task. It cannot be batched, it cannot be meaningfully automated, and it cannot be deferred: an unreviewed application is an unissued policy.

4.1 The arithmetic nobody put in a business case

The Year One premium target is $185,000,000 at an average case size of $118,000, which implies roughly 1,568 policies — about 131 per month, or on the order of 6 suitability reviews per working day at a steady rate.

The suitability rate above is a planning rate, not a locked figure: it assumes roughly 21 working days a month and an even arrival pattern, and annuity sales are not evenly distributed — they cluster at month end and quarter end. The peak is what matters, and the peak is higher than the average by a margin this program has not measured.

4.2 One analyst

The roster carries one Suitability Review Analyst. That is a correct establishment for a program team and an obviously insufficient one for a product operating at the Year One target. The gap is not a criticism of the staffing decision — program teams are not operating teams — but it becomes a launch problem at the exact moment the program hands over, which is precisely when program staffing dissolves.

This is the readiness item most likely to be discovered late. Suitability review capacity does not fail visibly. It degrades: the queue lengthens, turnaround slips from hours to days, producers notice before management does, and the first formal signal is a distribution complaint rather than an operational metric. By then the relationship damage with the four wholesalers carrying the whole field (I-06) is already done. OR-3 is therefore written as a capacity confirmation with a named escalation path, not as a training sign-off.

4.3 What closing OR-3 requires

  1. A documented peak-load assumption, not an average, with the month-end clustering stated.
  2. At least two additional staff trained and assessed to perform suitability review, drawn from existing licensed personnel, and named.
  3. A queue-depth measure visible daily from day one, with the T2 trigger in §3.1 attached to it.
  4. An agreed turnaround standard published to Distribution, so that degradation is a breach of a stated commitment rather than a matter of opinion.
  5. Written confirmation of who performs review if the named analyst is unavailable for a week.

5. Policyholder Services, Correspondence & the Free-Look Window

Policyholder services carries lower novelty than new business but higher consequence for error, because its output is a document a policyholder keeps. Confirmation statements, contract assembly and free-look disclosure are state-variable and must reflect the filed forms exactly.

5.1 The free-look period is the only rollback the company does not control

Every state mandates a free-look period during which a purchaser may rescind the contract and receive a return of premium, with the length and the return basis set by state law and the filed form. It is worth stating plainly what this means against §1: after the point of no return, the only remaining reversal belongs to the customer, not to the company.

Operationally this creates three obligations that are easy to under-prepare because they arrive weeks after the excitement of launch:

OR-9 covers this and is written to require a proven end-to-end rescission, including the money movement, rather than a procedure document describing one.

5.2 First index crediting cycle

The first crediting cycle falls a full contract year after the earliest issues, which places it outside the hypercare period and outside most people's attention. It is nonetheless the first moment the product's defining mechanic is exercised in production against real policyholder money. OR-7 requires the reconciliation and control set to be proven before launch, on the reasoning that a control designed a year after go-live is a control designed by whoever is left.

6. Platform Cutover — Sequence, Environments & Data

Cutover is executed by the 10-person platform team under V. Sandoval, with release and environment control held by R. Achterberg. The sequence below runs backward from launch, so that a change to the launch date moves every anchor rather than leaving the plan quietly out of step.

PointActivity and intent
T-90
07 Dec 2027
Operational readiness baseline frozen
Procedures, training curriculum and the day-one operating model are complete in draft. Anything not written by this point will not be trained by launch.
T-45
21 Jan 2028
Operations dress rehearsal #1
End-to-end: application intake, suitability review, issue, funding, confirmation. Run against the release candidate in a production-like environment with real staff, not a script.
T-21
14 Feb 2028
Operations dress rehearsal #2 — exception paths
Deliberately fails the happy path. Rejected suitability, incomplete application, wrong premium, free-look rescission, and every Severity-2 workaround accepted to date.
T-11
24 Feb 2028
Gate 4 — Launch Readiness decision
The gate that releases Stage 4 funding ($4,330,000), including the vendor hypercare package. 11 days before launch.
T-4
02 Mar 2028
Production cutover window opens
Configuration promoted, interfaces enabled, rate tables loaded and independently verified against the filed methodology. Still fully reversible at this point.
T-1
05 Mar 2028
Go / no-go call and final reversibility check
The last moment at which backing out costs nothing but embarrassment. Named decider, pre-committed criteria, documented answer.
T-0
06 Mar 2028
Launch — new business opens
Product available for sale. Reversible until the first application is accepted.
PONR
event-driven
First policy issued — point of no return
An in-force contract exists. From here the plan is a forward-only plan; see §7.

6.1 Rate table verification is a compliance step wearing an IT step's clothing

Loading rate tables looks like configuration. It is not: the values loaded must reconcile to the filed methodology, and where the configuration and the filing disagree, the filing governs. This is the same rule the Master Test & Validation Strategy applies to illustration validation, and it has the same consequence — a mismatch discovered at cutover cannot be resolved by changing the system, because the system is not the authority. Verification at T-4 is therefore performed against the filing, by a second person, with the result recorded.

6.2 Environments and the dress rehearsal standard

Both operational dress rehearsals (T-45 and T-21) run against the release candidate in a production-like environment, staffed by the people who will actually do the work. The second is deliberately structured around failure: rejected suitability, incomplete applications, mismatched premium, free-look rescission, and every Severity-2 workaround accepted to date (§9.2). A rehearsal that only exercises the happy path proves the least interesting third of the operation.

7. The Rollback Question, and When It Expires

Most cutover plans contain a rollback section that describes how to restore the previous state. This one contains a rollback section that describes how long that option exists.

WindowRollback available?Mechanism
T-4 to T-1Yes — complete Revert configuration, disable interfaces, restore prior release. No external party affected.
T-0 to first application acceptedYes — costly Close new business, withdraw sales authorization, notify distribution. Reputational cost with producers, no policyholder impact.
After first policy issuedNo Forward-only. Remediate in production. Any contract already issued stands.

7.1 What the program does about a boundary it cannot schedule

Because first issue is an event rather than a date, the plan cannot place the point of no return on a calendar. It can do three things instead, and does:

  1. Make the boundary visible in real time. The first issued policy is reported immediately to the launch decision-maker and the program manager — not in a daily summary. Everyone should know the hour at which the option to stop ended.
  2. Hold the highest-consequence checks before T-0, not after. Any verification whose failure would justify stopping must complete before new business opens, because the window in which stopping is cheap may be very short. Rate table verification, form correctness and the hedging confirmation in §10 are all pre-T-0 by design.
  3. Pre-decide the forward-only response. §7.2 sets out what happens if a material defect is found after first issue, so that the decision is made now rather than under pressure by people who will be tempted to minimize it.

7.2 Pre-committed response to a material defect found after first issue

8. Hypercare — Structure, Staffing and Unreleased Funding

Hypercare is the elevated-support period immediately following launch, during which defects are triaged faster, staffing is heavier, and the operation runs with direct access to the people who built the platform. It is where the residual risk of the entire program concentrates.

8.1 The funding problem, stated plainly

Hypercare is delivered in part by Cordelane under work package WP-3 — Stage 4 cutover, hypercare and handover, valued at $410,000, or 9% of the $4,330,000 Stage 4 tranche. Consistent with the program's gate-authorized contracting model, WP-3 is not released. It releases at Gate 4, which is 11 days before launch.

The vendor that runs hypercare is not under contract for hypercare during any of the readiness period. This is a direct and intended consequence of gate-authorized funding, and the Vendor Management Plan explains why the program contracts this way — a gated program cannot commit to scope a future gate may decline to fund. The discipline is correct. The operational consequence is still real: for the entire readiness window, the people expected to stabilize the launch have no contractual obligation to prepare for it, and 11 days is not enough time to mobilize a team that has not been paying attention. The mitigation is not to release funding early. It is to require, as a Gate 4 entry condition, that Cordelane has named the hypercare personnel and that those individuals have attended both dress rehearsals under WP-2. That places the preparation inside a work package that is released, at no additional cost, and it is the only version of this problem the program can solve without breaking its own funding model.

8.2 Hypercare structure

PeriodPostureStanding arrangements
Launch dayCommand All named owners available. Hourly checkpoint. Direct line from new business to platform team, no ticket queue.
Week 1Elevated Twice-daily checkpoint. Defect triage within the working day. First-issue notification per §7.1.
Weeks 2–4Elevated, tapering Daily checkpoint. Trigger set from §3.1 active. Weekly report to the Gate Review Board.
Weeks 5–8Transitional Twice weekly. Handover documentation being signed off progressively, not at the end.
ExitSteady state Formal acceptance by the receiving operational managers, evidenced against the day-one model in §3.2. Gate 5 draws on this evidence.

8.3 The handover is a decision, not a date

Handover completes when the receiving managers accept the operation, not when the calendar reaches week eight. Acceptance is withheld if defect volume is still elevated, if any §3.1 trigger is active, or if the suitability queue standard from §4.3 is not being met. Writing this down before launch matters, because the pressure at week eight will run entirely one way — program teams want to close, vendors want to demobilize, and nobody in the room is paid to keep it open.

9. Readiness Criteria and the 11-Day Window

The nine criteria below are Operations' evidence into the Gate 4 launch decision. They do not replace the Launch Readiness Criteria, which owns the go / no-go framework and its no-go conditions; these are the operational inputs that document feeds on.

IDCriterionOwnerStatus at this version
OR-1Day-one operating model documented and accepted by the receiving managersL. MarchandDraft complete
OR-2New business staff trained and assessed on the product, not just the platformN. JessupBlocked on form approval
OR-3Suitability review capacity and escalation path confirmed against projected volumeS. CarrenoOpen — see §4.3
OR-4Two operational dress rehearsals completed, exceptions includedD. FairbairnScheduled
OR-5Every accepted Severity-2 workaround has a named owner, a written procedure and a staffing allocationD. FairbairnOpen — see §9.2
OR-6Platform cutover rehearsed end-to-end in a production-like environmentV. SandovalNot started
OR-7Reconciliation and daily controls proven, including the first valuation cycleR. UnderwoodNot started
OR-8Hypercare staffing confirmed and under contractL. MarchandCannot close before Gate 4
OR-9Free-look and rescission handling proven, including premium return timingK. BeauchampNot started

9.1 Three of these cannot close before Gate 4, by construction

OR-2 is blocked on form approval (I-05) and cannot complete until forms clear. OR-8 cannot close until the vendor package releases, which is Gate 4 itself. OR-3 depends on staffing decisions that follow the Gate 4 funding release. Showing these as amber would imply they are progressing slowly. They are not progressing slowly; they are structurally sequenced after the gate that assesses them, and the honest presentation of a criterion that cannot close yet is to say so.

The 11-day window is the real finding of this section. Gate 4 releases the funding, confirms the vendor, and assesses the readiness of criteria that depend on that funding and that vendor — 11 days before the product goes on sale. There is no version of this sequence in which a Gate 4 finding can be remediated before launch. Which means Gate 4 is not really a readiness assessment; it is a launch-or-defer decision wearing a readiness assessment's clothing, and the Gate Review Board should be told that plainly in advance rather than discovering it in the room.

9.2 The workaround rule quietly assigns work to Operations

The Master Test & Validation Strategy and the Launch Readiness Criteria both state that a Severity-2 defect may proceed to launch where its workaround is documented, staffed and accepted. That rule is sound, and the middle word is the one this plan cares about. Staffed means somebody performs a manual step that the system was supposed to perform — and that somebody is almost always Operations.

Each accepted Severity-2 workaround therefore creates an operational liability that was created by a testing decision, costed in no budget, and inherited by a team of 7. Individually they are trivial. Collectively they are how a launch arrives with an operation quietly running on manual effort that nobody planned and nobody removes. OR-5 requires every accepted workaround to carry a named owner, a written procedure and an explicit staffing allocation before Gate 4, and the second dress rehearsal (T-21) exercises them as a set rather than individually — because the risk is cumulative load, and load is invisible one workaround at a time.

10. Dependencies Operations Does Not Own

Three readiness dependencies sit outside this plan's control and can each independently prevent launch. Naming them here is not an attempt to transfer accountability; it is so that Operations' readiness reporting is not read as a complete picture of launch readiness when it is not.

DependencyOwnerWhy Operations cannot proceed without it
Hedging capability (R-05, GC-05, DEP-06)M. Delacroix New business cannot open on a product the company cannot hedge. Documented ISDA capability is a pre-T-0 confirmation in §7.1, not a post-launch workstream.
Contract form approval (I-05)Legal & Compliance Forms govern contract assembly, correspondence and free-look disclosure. Training and template build cannot finalize ahead of them, which is what blocks OR-2.
Producer certification volumeR. Castellanos Determines actual day-one load and therefore which §3.1 triggers fire. Operations plans the response, not the volume.

11. Risks, Issues & Register Linkage

Entries below are held in the program RAIDD log and the Gate Conditions Register; they are reproduced here only where they bear directly on operational readiness. The register is authoritative for status.

IDDescriptionOwnerStatusOperational reading
R-05Hedging readiness (ISDA, derivatives ops, daily rebalance) lags launchM. DelacroixElevated — score 20Operations cannot open new business on a product the company cannot hedge. This is the largest single threat to the launch date and Operations does not own it.
DEP-06Second ISDA counterparty — documentation not begunM. DelacroixAt riskFeeds R-05 and GC-05. Until executed, hedging operations run single-counterparty, which is a concentration the Investments desk has not accepted for steady state.
GC-05Present a hedging readiness plan with ISDA execution milestones at Gate 2M. DelacroixOpen conditionThe condition is a Gate 2 obligation, but its subject matter is a Gate 4 readiness dependency. Operations should read the Gate 2 answer as a launch signal.
I-05GLWB contract form language returned twice by outside counselLegal & ComplianceOpen issueUpstream of everything here. Training on an unapproved form is training that may have to be repeated, so OR-2 cannot close until forms clear.
I-06Plan assumed 6 field wholesalers; Distribution can commit 4R. CastellanosOpen issueReduces the probability of hitting projected volume, which cuts both ways: it lowers day-one operational load and raises the risk of staffing to a volume that never arrives.
R-12Post-launch sales concentrate in one crediting strategyM. DelacroixScore 9An operational tell as much as a hedging one: the first hundred policies will show it, and Operations sees them before the hedging desk does.

12. Governance, Ownership & Document Control

12.1 Reporting and decision rights

12.2 Related documents

12.3 Version control

VersionDateChange
1.016 Oct 2026Initial plan issued. Establishes the point-of-no-return model, the trigger-based day-one operating model, the suitability capacity finding (OR-3), the WP-3 hypercare funding sequence, and the workaround-liability finding (OR-5).

Prepared by the Program Management Office, Lighthouse Financial Services Company. Owning executive: L. Marchand, Director, Annuity Operations. Platform cutover lead: V. Sandoval. Status date 16 October 2026.