The Control Existed. The Evidence Didn't.
Two New Zealand public sector organisations published, in the same week, two documents that describe the same architectural failure from opposite ends.
On Monday 21 September 2026, at 3:02pm, the Ministry of Business, Innovation and Employment released a rapid stocktake of seventy active technology initiatives. Its own internal assurance function examined it, and Maven Consulting reviewed that examination independently. Thirty-one of those seventy meet MBIE's threshold for formal governance. Projects cross it at anticipated capital or operating costs above $250,000, the point where a steering group, a business case and a benefits register stop being optional. Of the thirty-one, fifteen are rated green, six amber, nine red, and one has been shut down. MBIE's own release states plainly that it "has the frameworks, governance structures, controls and processes expected of a large public sector organisation managing major technology investments."
The review MBIE commissioned adds that qualifier. It is dated 28 August 2026, published on the same page as the release. Its executive summary opens differently: "The review found that MBIE has most of the frameworks, governance structures, controls, and processes expected of a large public sector organisation managing major technology investments." The same paragraph continues: "However, these arrangements are not consistently applied across the organisation, reducing their effectiveness and limiting confidence that risks, delivery performance, and benefits are being actively managed and challenged throughout the investment lifecycle." Maven Consulting's own independent assurance report, delivered a month earlier, is blunter still, concluding that "in practice much important detail that is needed to support better decision-making is missing."
The release carries forward the reassuring half of its own review's finding, and leaves out the qualifying half. That is not concealment: the review sits on MBIE's own website, one click from the release itself. The gap between the two sentences is real. This chapter is about it. A large organisation can hold every framework it is expected to hold, and still be unable to say, with confidence, whether those frameworks are applied the same way twice. Having the document that describes the control is not the same fact as having evidence the control fired.
MBIE's own internal assurance function examined the seventy initiatives first. Maven Consulting, a party with no stake in the portfolio looking good, examined the examiners second. A first-party review is useful. But it is Maven's independent pass, not MBIE's own, that lets anyone outside MBIE trust the "not consistently applied" sentence over the "has the frameworks" one. The stocktake earns its own credibility from the same mechanism the release's headline claim quietly skips.
RNZ's own reporting supplies the sentence that names the actual risk, quoting MBIE's review directly: "Inconsistencies in reporting, financial transparency, benefits management, portfolio classification and governance visibility reduce confidence in the extent to which emerging delivery concerns are consistently identified, escalated, understood and acted upon." That finding is about whether MBIE's governance would actually catch a problem escalating, before it became public. A steering group that meets on schedule and a steering group that would notice a red flag in time are two different claims. Only the review, not the release, was willing to separate them.
The day after MBIE's release, issued together with it on 23 September, the Privacy Commissioner put both Health New Zealand and Manage My Health on notice under section 123 of the Privacy Act 2020. The notices cite a failure, at the time of a December 2025 breach, to meet the security requirements of rule 5 of the Health Information Privacy Code 2020. An earlier compliance notice to Manage My Health, dated 28 August 2026, came first. Both concern the same event: a cyber security breach affecting the MMH patient portal, in which most of the affected patients were based in Northland.
The Commissioner's own Phase 1 inquiry, delivered 27 May 2026, is precise about where Health NZ's governance broke down. Health NZ "had an active project steering group, with senior leadership," the inquiry found. But that group "did not include direct privacy or security representation" of the kind necessary "for a project of this novelty, complexity and scale." The steering group was not absent. It was missing one specific competency, and nobody on it was positioned to ask the question a privacy or security specialist would have asked as a matter of course.
What Health NZ did instead, the inquiry found, was rely on the vendor's own word. The project team "relied too much on the security and privacy of information provided by Manage My Health, rather than taking a more independent view," while MMH itself showed "deficiencies in the company's data leak protection settings and in its ability to detect incidents and take action to intervene." A structure existed. What it produced, when it mattered, was trust in a vendor's self-assessment rather than an independent check of it.
Put the two documents side by side and the shape is identical, at two different altitudes. MBIE's frameworks exist; its own review finds reduced confidence that escalation actually works in practice. Health NZ's steering group existed; it lacked the specific expertise, and the independent check, that would have told it whether MMH's own assurances were true. The missing element was never a structure. In both, it was a source of evidence about performance that did not come from the party being assessed. That party is MBIE judging its own portfolio, or Health NZ judging its contracted vendor.
Chapter 27 of this book, "Governance Without Architecture Is Incomplete," argued that a security manager who cannot restate a governance requirement as a design constraint has a policy, not a control. This week's chapter carries that argument one level up, from a requirement to the evidence that the requirement was met. This book also argued, last week, that a board asking for a policy attestation is asking the wrong question: an attestation proves a document exists, not that anyone followed it under pressure. MBIE and Health NZ are that argument's first public sector portfolio test. Neither organisation had the artefact it calls for, sitting ready when a reviewer or a regulator went looking. What each has produced instead, this week, is a version of the missing evidence, assembled after the fact, by somebody other than the party whose performance it measures.
MBIE's own release is most interesting exactly where it declines to claim full confidence. Of the eighteen initiatives that needed targeted improvements to their controls, all but one are now rated Effective overall. The exception, In-Person Enrolment, remains rated Partially Effective, and MBIE says why: its close links to the Biometric Capability Update project "limit the extent to which it can be assessed independently and with full confidence." That sentence is MBIE applying, to one initiative, exactly the standard this chapter argues both organisations were missing everywhere else. The one place MBIE will not claim full confidence is the one place it cannot get an independent check. That is the stocktake working as intended, at the point where its own logic runs out.
MBIE's second fix is a transparency commitment rather than a rating: "We will report publicly at least quarterly, with more detail on technology investments costing over $5 million across their lifetime." That is a new baseline, dated to this release rather than a restatement of existing policy. It converts what has so far been an internal assurance exercise into something the public, and future reviewers, can check against without waiting for the next stocktake. The result is a governance pack designed to be read by somebody who was not in the room when it was written.
Health NZ's fix arrives by statute rather than by choice. The compliance notices set dated obligations: Health NZ must comply by 29 January 2027, Manage My Health by 31 August 2027. Health NZ's notice requires, among other things, a steering group with privacy and security expertise, privacy impact assessments and an independent assessment of its providers against the Health Information Safety Framework. It also requires audit and incident-reporting rights written into its contracts. Each of those four requirements answers a different half of the same architectural gap. The steering group expertise requirement answers who is positioned to ask the hard question at the table where the decision is made. The privacy impact assessments answer when the question gets asked, before data starts flowing rather than after a breach. The independent Health Information Safety Framework assessment answers who checks the answer. It is explicitly not the vendor checking itself. The contract audit and incident-reporting rights answer whether the checking party can actually reach the evidence, because a right to ask a question is not the same as a right to see the answer.
The Office of the Privacy Commissioner frames the intended effect plainly. The notices exist to make sure Manage My Health and Health NZ are demonstrably, not just declaratively, treating patient data securely. Where MBIE has chosen to commit to public reporting, the Commissioner is compelling Health NZ to build the independent check into its next contract, rather than take the next vendor's word for it.
An earlier chapter in this book argued that governance without architectural translation is not enforceable: a security manager who cannot restate a governance requirement as a design constraint has a policy, not a control. MBIE's and Health NZ's fixes are that argument made concrete at portfolio and contract scale. MBIE is building the check into its own reporting cadence, rather than leaving it to the next internal review to notice. The Commissioner is building it into Health NZ's contracts, rather than into a steering group's judgement about which vendor to trust. In both cases the fix takes the same shape: build the assurance path into the design, not onto the organisation chart.
Picture the version of this an enterprise architect at a New Zealand Crown agency is living through right now. Her governance pack for a new patient-facing digital service, delivered through a third-party vendor, is complete. It holds a steering group with the chief information officer and two general managers, a signed data-sharing agreement, and a vendor security questionnaire the vendor filled in and returned. A board member new to the role, a career auditor, asks one question: who checked that the vendor's answers on the questionnaire are true, and how?
She has an answer for every other question in the pack. She does not have one for that. The vendor is reputable and the questionnaire is thorough, but nobody on her steering group has the specific expertise to test a vendor's claim about its own security posture independently, so nobody has. Her governance structure has a place for every decision except the one that would tell the board whether the vendor's self-reported assurances hold up.
She does not cancel the project. She adds a line to the paper: an independent assessment of the vendor, before data starts flowing, with the cost and the timeline stated honestly. It is the first time in three governance packs that she has asked for evidence rather than for a policy.
If you run, sponsor or sit on a steering group for a system that touches a vendor's data, MBIE's and Health NZ's fixes translate into four questions. Put them on your own governance pack before a reviewer or a regulator puts them there for you. First, at the point the steering group is formed, name who on it has the specific expertise to test a vendor's security or privacy claim, not just receive it. If nobody does, that is a staffing gap to close, not a risk to accept silently. Second, schedule the independent check into the design from the outset, on a fixed date, rather than leaving it as something that only happens if an incident forces it. Third, decide in advance what "independent" means for your programme: a distinct assurance function inside your own organisation, on MBIE's model, or a contracted third party, on Health NZ's. Write the answer into the governance terms of reference before the first steering meeting, not after. Fourth, treat audit and incident-reporting rights as an architecture decision rather than a legal afterthought. Without a contractual right to reach the evidence, there is no mechanism for the independent check to happen at all, however well-intentioned the questionnaire.
There is a simple test for whether any of this is real rather than aspirational. It is the same test MBIE's own stocktake passes and a bare vendor questionnaire fails. Can somebody who was not in the room when the answer was written reach the evidence and check it themselves? A steering group minute that records "the vendor confirmed compliance" fails the test. A dated independent assessment report, filed somewhere a future reviewer or regulator can actually open it, passes. The difference costs almost nothing to design in at the start of a programme and, on the evidence of this week alone, costs a great deal to retrofit under a compliance notice.
MBIE and Health NZ did not have that evidence ready when a reviewer and a regulator each asked for it, by different routes, in the same week. Both are now building it, one through public reporting, the other through statute.
The open-source world settled a close relative of this question in 2024. XZ Utils, a compression library inside nearly every Linux distribution, turned out to carry a hidden backdoor built over roughly two years of trusted contribution. Every formal review the project had passed it. What caught it was one engineer's curiosity about a fraction of a second's extra delay in a routine login, a check nobody had designed the process to require. A contributor's standing, like a vendor's completed questionnaire, is evidence of a relationship, not evidence of security. The gap between the two only shows up when someone with no stake in a reassuring answer goes looking. Open reference architectures and open identity tooling carry, by construction, more of exactly the ingredient MBIE and Health NZ were each missing: eyes that have no reason to prefer the comfortable finding.
The same principle sits underneath the frameworks that now govern critical infrastructure: the European Union's NIS2 Directive requires many operators of essential services to have their security risk-management measures independently audited rather than merely self-declared. That is a structural answer to the failure mode traced through MBIE and Health NZ: a self-assessment is not evidence, however sincerely it is completed. The United States Cybersecurity and Infrastructure Security Agency and New Zealand's own National Cyber Security Centre both play comparable roles for their respective critical infrastructure sectors. Both coordinate and, where their mandate allows, verify rather than only collect attestations. None of the three make the vendor's word sufficient alone. An enterprise architecture that treats independent verification as a design constraint, not a compliance afterthought triggered by a breach, is applying the same discipline these frameworks apply to national infrastructure. It is doing so at the scale of one programme.
Before your own board pack goes out, ask the question that is simpler than either organisation's fix. If a new director asked who checked your vendor's answers, and how, would you have anything to show them beyond the questionnaire itself?
If your programme needs an independent architecture assurance review before its next gate, message me and I will send the scope and the fixed fee.
The views expressed in this article are entirely my own, informed by more than 30 years of professional experience in architecture, security, and technology leadership in New Zealand. I write as director of Te Pono Limited; the views are personal and do not represent the position of any client, any government agency, or the New Zealand government. My commentary on legislation and policy is analytical, drawing on publicly available sources and my professional expertise in architecture, security, and AI governance, and it is politically neutral.
Andreas Hamberger is a New Zealand leader in Architecture & Security and Associate Member of the Institute of Directors. Zero Trust Architecture for the Agentic Enterprise is the first book in The Hamberger Report series, providing practitioners with deployable patterns and configurations for securing AI-driven systems. Through Te Pono he provides independent architecture assurance reviews and AI verification audits to boards and programmes; contact andreas@thehambergerreport.com for the scope and fixed fee.
This article was produced with AI assistance under my direction. Research, drafting and images pass through a pipeline I built and govern: automated gates for source verification, forbidden language and political neutrality, and my own review before anything is published. The tools include Claude, Gemini and Openart. The frameworks, arguments and editorial judgements are mine and are the same discipline I apply to the AI systems I audit for clients. AI accelerated the work; the thinking, and the responsibility for it, are mine.
[1] Ministry of Business, Innovation and Employment. "MBIE Strengthens Oversight of Technology Investments" (media release, republished via Scoop). 21 September 2026. https://www.scoop.co.nz/stories/BU2609/S00248/mbie-strengthens-oversight-of-technology-investments.htm
[2] RNZ. "Stocktake of IT Projects at MBIE Finds Some Deficiencies in Controls." 21 September 2026. https://www.rnz.co.nz/news/business/1518488/stocktake-of-it-projects-at-mbie-finds-some-deficiencies-in-controls
[3] Ministry of Business, Innovation and Employment. "Strengthening MBIE's Technology Investment Project Systems and Processes." 28 August 2026. https://www.mbie.govt.nz/dmsdocument/32559-strengthening-mbies-technology-investment-project-systems-and-processes-pdf
[4] Maven Consulting. "Stocktake of MBIE Technology Projects Report: Independent Quality Assurance." 20 July 2026. https://www.mbie.govt.nz/dmsdocument/32557-stocktake-of-mbie-technology-projects-report-independent-quality-assurance-maven-pdf
[5] Office of the Privacy Commissioner. "Executive Summary, Manage My Health Inquiry, Phase One." 27 May 2026. https://www.privacy.org.nz/focus-areas/manage-my-health-inquiry/executive-summary-manage-my-health-phase-one/
[6] RNZ. "Privacy Commissioner Puts Manage My Health, Health NZ on Notice After Data Breach." 23 September 2026. https://www.rnz.co.nz/news/health/1530878/privacy-commissioner-puts-manage-my-health-health-nz-on-notice-after-data-breach
[7] Office of the Privacy Commissioner. "Privacy Commissioner Issues Compliance Notices to Manage My Health and Health NZ." 23 September 2026. https://www.privacy.org.nz/tuhono-connect/statements-media-releases/privacy-commissioner-issues-compliance-notices-to-manage-my-health-and-health-nz/
[8] Office of the Privacy Commissioner. "Privacy Commissioner Finds Manage My Health and Health New Zealand Breached Privacy Act: 91 Percent of Affected Patients Based in Northland." 23 September 2026. https://www.privacy.org.nz/tuhono-connect/statements-media-releases/privacy-commissioner-finds-manage-my-health-and-health-new-zealand-breached-privacy-act-91-percent-of-affected-patients-based-in-northland/

