Andy Callan tracks Norton Rose Fulbright’s Service Design & Transition journey over recent years.
Norton Rose Fulbright’s EMEA ITSM function has transformed its Service Design & Transition (SD&T) practice. From a largely ad hoc position in 2022, SD&T reached defined maturity by late 2024 through stronger governance, documented processes and clearer ownership. The next target is Capability Maturity Model Integration (CMMi) Level 4 (Quantitatively Managed) by 2027.
This article describes the journey from reactive transition activity to a governed, repeatable and evidence-led SD&T model: the starting point, the vision, the improvements delivered, the benefits realised and the next phase of maturity.
SD&T Maturity Journey: 2022-2027

We were here: 2022 baseline maturity and challenges
In 2022, SD&T was at a low maturity level. Service Design was not formally embedded, and transition activity was often handled reactively or by exception, usually for larger projects only.
Governance was limited, with handover relying on legacy templates, informal processes and late ITSM engagement. Service expectations, Service Level Agreements (SLAs) and handover measures were not consistently defined, increasing the risk of releases proceeding without adequate operational readiness, post-go-live issues and disruption. Operational teams often absorbed late changes, unclear support requirements and avoidable rework, while project teams lacked a consistent view of readiness. This weakened stakeholder confidence because outcomes were less predictable and ownership was not always clear.
| 2022 Baseline | 2022–2024 Improvement Approach | 2024/25 Defined Practice |
| Low maturity / ad hoc SD&T activity was reactive, inconsistently applied and often engaged late in the project lifecycle, increasing the risk of blind releases and post-go-live issues. | Internal reviews and improvements implemented SD&T was embedded into PMO gates, with ITSM leadership sign-off, peer reviews and mock transition exercises improving readiness, validation and CSI. | Defined and repeatable By late 2024, SD&T had moved to a defined maturity position, with clearer ownership, documented processes, improved readiness controls and stronger evidence of operational benefit. |
The baseline created three clear risks:
- Meeting business needs: The broader ITSM transformation aimed to align IT services with NRF’s business and legal practice needs. Poorly managed service design or inconsistent transitions lead to disruptions in critical legal technology services, affecting client service quality
- Risk and efficiency: Ad hoc transitions carried higher risk of post-release incidents and inefficiencies. Without strong SD&T, time and resources were wasted on firefighting production issues that could have been prevented through better planning, testing, and standardisation
- Strategic growth and compliance: As NRF expands cloud and AI adoption, SD&T needs stronger governance to ensure new services are introduced in a controlled, supportable and compliant way.
In response, EMEA ITSM strengthened SD&T governance, Project Management Office (PMO) integration, process standardisation, Continual Service Improvement (CSI) and tooling. Earlier supplier engagement also reduced delays, duplication and escalation caused by unclear responsibilities, support arrangements and acceptance evidence.
Setting the vision, bringing stakeholders on the journey
Embedding SD&T into Project Delivery & Governance
The vision was to make SD&T a governed part of the project and service lifecycle rather than a late-stage handover. Embedding it into PMO gates brought ITSM leadership sign-off and earlier input from project, operational and supplier stakeholders, making expectations and concerns visible before go-live.
Acceptance into Service (AIS) checklists, Early Life Support (ELS) planning, peer reviews, mock transitions and standard playbooks tested readiness and improved consistency. Adopting the controls initially increased workload and accountability, but reduced uncertainty, late rework and firefighting while improving confidence at go-live.
The EMEA SD&T Operating Model

The model shows SD&T as the controlled route from strategy and design into live operation, supported by PMO governance, connected ITSM practices and knowledge throughout the lifecycle.
Delivering prioritised, incremental improvements
Improvement was delivered incrementally through regular stand-ups, focused priority sessions and checkpoint reviews. This kept work visible, aligned priorities and unblocked delivery issues early. The team replaced individual Excel trackers with a shared Azure DevOps Kanban board and standard transition checklist. Adopting a common way of working improved ownership, visibility and tracking across project gates and transition tasks, reducing duplicated effort and time spent chasing updates.
SD&T strengthened go-live control by making operational readiness visible and evidence-led. New or changed services are accepted into live operation only when agreed readiness actions are complete, tracked through Azure DevOps and reviewed with the relevant project, ITSM, supplier and operational stakeholders. Regular checkpoints provided a practical route to challenge gaps, agree ownership and resolve issues before they reached live support.
Using tooling, automation & AI where valuable
Tooling supported the shift, but the main gain came from better control and discipline. Azure DevOps gave teams a shared view of work, ownership and deadlines, while targeted automation and early AI use improved responsiveness in specific areas. Practical guidance, peer support and reinforcement of the governance helped embed adoption rather than relying on tooling alone.
Building backlog & CSI discipline
A formal CSI backlog created a clear pipeline, ownership and prioritisation route across documentation, readiness checks, service catalogue foundations and review routines. This improved up-front planning, transition quality and operational readiness.
Maturing the wider IT service ecosystem
Shared governance and standard ways of working improved the wider service ecosystem, giving the organisation more predictable launches and teams a clearer route to raise and resolve operational concerns.
SD&T owned and delivered several direct improvements, but wider maturity was strengthened by related ITSM practices. Change Enablement moved from Level 2 to Level 4, supported by stronger governance, testing and risk evaluation. Problem Management moved from Level 1 to 4, reflecting a more proactive approach to root-cause resolution.
Together, these improvements supported smoother transitions and fewer recurring issues. Service Level Management (SLM) and Supplier Relationship Management (SRM) also matured, clarifying service expectations, supplier accountability and launch documentation while reducing post-go-live support gaps.
Benefits and evidence of maturity
By late 2024, the improvement journey was validated through an independent maturity assessment. SD&T had moved from an unstructured baseline to a defined practice with clearer governance, documentation and operational control.
The key evidence points were:
- SD&T maturity: SD&T scored 2.7 out of 5, up from 0 in 2022, placing the practice at a defined maturity level
- Design-stage involvement: ITSM is now represented earlier in the project lifecycle, helping identify support needs and operational impacts before go-live
- Transition outcomes: Stronger Change Enablement supports more consistent outcomes, fewer incidents and less post-release disruption
- Backlog & CSI: A central CSI backlog improved prioritisation, tracking and visibility of improvement work
- Measures & client value: Key performance indicators [KPIs] provide a clearer view of transition effectiveness and support the aim of making change less disruptive for users
Delivery and confidence: Better readiness controls reduced production surprises, firefighting and early-life support issues. Clearer gates, evidence and ownership made delivery more predictable and improved stakeholder confidence.
Efficiency and ownership: Shared Azure DevOps tracking and closer alignment across SD&T, PMO, operational teams and suppliers improved visibility, follow-up and accountability. Guidance, peer support and clear expectations helped embed the controls in day-to-day delivery.
Continuing towards CMMI Level 4
Having reached defined maturity, the next phase focuses on measurement, proactive governance and better use of data to manage SD&T performance.
Key priorities moving forward include:
- Defined KPIs and thresholds for transition quality, readiness and post-go-live performance
- Stronger use of data to identify risks, trends and improvement opportunities
- Continued integration of SD&T governance across project, supplier and operational delivery
- Improved visibility of workforce capability and the supporting technology landscape
- Targeted automation and AI adoption where it delivers measurable operational value
- Regular maturity reviews to track progress towards CMMI Level 4.
NRF has moved SD&T from ad hoc delivery to a defined, repeatable model. Stronger measurement, governance, capability and technology insight will underpin the next step towards CMMI Level 4.
Lessons learned
The journey highlighted several practical lessons for organisations looking to mature Service Design & Transition:
- Engage ITSM early: Operational requirements are easier and cheaper to address during design than immediately before go-live
- Make readiness a shared responsibility: Successful transition depends on clear ownership across project, ITSM, operational and supplier teams
- Keep governance practical: Controls must be proportionate, easy to understand and embedded into existing project gates
- Focus on adoption, not just process: Guidance, peer support and regular reinforcement are essential to making new controls part of day-to-day delivery
- Use evidence to support decisions: Clear acceptance criteria, documented exceptions and visible ownership reduce ambiguity and improve go-live confidence
- Improve incrementally: Prioritised improvements delivered through a visible backlog are easier to sustain than attempting wholesale change
Where we hit resistance: The hardest part was not designing the process; it was changing when and how people engaged with it. ITSM was often involved too late, ownership became unclear between project, operational and supplier teams, and fragmented tracking made gaps difficult to see. There was also an understandable concern that additional governance would delay delivery. Progress came from embedding proportionate SD&T controls into existing project gates, assigning named owners and showing through live transitions that earlier readiness activity prevented late rework, support gaps and avoidable disruption.
What we would recommend: Before introducing new tooling or extensive measures, agree the minimum readiness standard, decision points, evidence required and who is accountable at each stage. Secure PMO, operational and supplier support early, use existing governance wherever possible and allow time for guidance and reinforcement. Start with a small number of practical controls, prove their value through real deliveries and improve them incrementally. Tooling, automation and advanced metrics should follow once the underlying process is understood, consistently applied and trusted.
Key improvements and outcome summary
The journey can be summarised as follows:
| Stage | Key Improvement | Outcome / Value Realised |
| We were here | Baseline maturity was low, with SD&T activity handled reactively and inconsistently. | The need for stronger governance, earlier operational input and more consistent transition controls was clearly established. |
| We set the vision | SD&T was repositioned as a governed part of the project and service lifecycle, not a late-stage handover activity. | Project, PMO, ITSM, operational and supplier teams aligned around shared readiness expectations, earlier engagement and clearer accountability. |
| We brought people on the journey | SD&T activity was embedded into PMO gates, with ITSM leadership sign-off, peer reviews and mock transition exercises. | Operational readiness became a shared responsibility. Training, guidance, peer reviews and practical checkpoints helped people adopt the controls, reducing late rework and strengthening confidence before go-live. |
| We delivered incremental improvements | DevOps-managed tracking, Kanban delivery, standard transition task lists and CSI backlog discipline replaced fragmented manual tracking. | Visibility, ownership, follow-up and predictability improved, reducing rework and supporting more consistent change outcomes. |
| We matured | SD&T moved from an unstructured baseline to a defined practice, supported by improvements in Change Enablement, Problem Management, SLM and SRM. | The maturity assessment confirmed stronger process robustness, clearer governance and improved operational control. |
| We continue to mature | The practice now has a clearer route towards CMMI Level 4, focused on metrics, governance, workforce capability, technology landscape visibility and targeted automation and AI adoption. | NRF is better placed to deliver supportable services, reduce transition risk and continue improving service quality at scale. |

Andy Callan
Andy Callan is EMEA IT Service Management Senior Manager, doing all things IT Governance for Norton Rose Fulbright LLP.