Guidance on managing commercial risk, supplier relationships and contract decisions during local government reorganisation (LGR) for councils that are aggregating, disaggregating or doing both.

Why commercial risk increases during LGR

Commercial decisions are one of the highest-risk areas during LGR. Reorganisation creates several pressures at once. These can include:

  • contract renewal cycles that rarely align with vesting dates, or create additional pressures on the shadow authority when they do
  • complex decision-making, with governance arrangements still evolving
  • procurement and legal teams working under significant capacity constraints
  • supplier responses varying depending on whether a council is aggregating or disaggregating, with suppliers seeking to protect their position through licensing, contract terms or pricing changes
  • uncertainty increasing supplier leverage during negotiations
  • time pressure encouraging risk-averse decisions that can limit future flexibility
  • the need to maintain business continuity and resilience throughout commercial transitions
  • increased cyber security risk during periods of change to systems and suppliers

At the same time, councils often rely on a small number of shared suppliers across multiple authorities. A supplier’s ability to meet the needs of all their customers during LGR can be a significant risk.

Decisions made during the shadow period can shape the technology estate of the new council for many years. The objective is not to eliminate risk, but to:

  • avoid unnecessary lock-in
  • maintain future flexibility
  • maintain an appropriate cyber security posture
  • avoid work that doesn’t create value for the new councils

We’re mostly using the same suppliers across councils, and that’s something we need to recognise early. If several authorities are going through reorganisation at the same time, those suppliers are going to be working with all of us simultaneously. It would really help if there was a way of bringing councils and suppliers together to talk about how systems might be merged or separated. Otherwise, every council ends up trying to solve the same problem independently.

Council Head of Transformation

Approval thresholds during the shadow period

Once the legal order to establish the new council is made, predecessor councils may be limited in the value of commercial commitments they can make without involving the shadow authority.

Digital, data and cyber leaders should:

  • agree decision-making authority and thresholds between predecessor councils and the shadow authority early in the shadow period
  • keep a record of decisions that approach the threshold so they can be reviewed if challenged
  • plan for shadow authority involvement where a contract renewal would exceed the threshold
  • be alert to suppliers proposing bundled services or multi-year commitments that could push routine decisions over the threshold

How contracts transfer to the new council

Contracts can move to the new councils through a small number of mechanisms, in increasing order of complexity:

  • simple transfer to a single successor
  • tri-party transfer to multiple successors
  • host arrangements, where one council delivers a service on behalf of others
  • novation, where a contract is renegotiated with the supplier’s agreement
  • disaggregation, where the contract is split across multiple successors

The first three options are statutory rights on vesting day under Section 16 of the Local Government and Public Involvement in Health Act 2007 and the 2008 Transfer Regulations. Novation and disaggregation depend on the terms of the contract provisions and need supplier agreement.

Hosted and tri-party arrangements should be governed through an Inter-Authority Agreement (IAA). This should clearly set out:

  • roles and responsibilities
  • governance and escalation arrangements
  • financial arrangements
  • dispute resolution processes

The IAA should also define responsibility for:

  • patching and vulnerability management
  • security scanning
  • access management
  • security monitoring
  • incident response leadership
  • emergency remediation costs during transition

Poorly defined IAAs are a recognised source of risk in previous reorganisations.

Digital, data and cyber leaders should work with procurement and legal to agree which transfer mechanism applies to each major contract well before vesting day, particularly where hosted IT services, shared identity services or jointly licensed software are involved.

Start with a complete contract baseline

Before making commercial decisions, councils need a clear and shared understanding of existing contracts. Many councils report that this information is not centrally available at the start of LGR.

Create a consolidated view of contracts across all participating councils. This baseline should include:

  • supplier name
  • service or system provided
  • contract start and end dates
  • notice periods and break clauses
  • contract value and licence commitments
  • procurement route used
  • hosting arrangements
  • integration dependencies
  • data ownership and export rights
  • data residency and hosting location, particularly for systems handling personal data
  • assignment, novation and change-of-control terms, so suppliers cannot use the formation of the new authority to renegotiate without challenge
  • the contract owner, decision-maker, business stakeholder and named contract manager
  • the legacy council that owns the contract
  • cyber assurance status, including:
    • whether the supplier has completed a security questionnaire
    • relevant assurance is held by the supplier
    • key supply-chain risks
    • incident notification and escalation arrangements
  • software version, as councils using different versions of the same product can complicate convergence
  • access method and network dependencies where users sit on different networks or infrastructure

This information helps councils identify:

  • contracts approaching renewal
  • systems critical for day one operations
  • opportunities for convergence
  • areas where supplier lock-in risk may exist
  • the complexity of transitioning to a new solution

Where possible, build this view jointly across digital, procurement and finance teams.

Treat this as a forward-looking pipeline as well as a baseline. Understanding activity over the next 12, 18 and 24 months, and beyond vesting day, lets councils smooth demand, avoid contract clustering expiries and plan post-vesting capacity. Councils that have been through LGR describe this as one of the valuable commercial preparations you can make.

Consideration for disaggregation

Where a shared system will continue to support more than one new council, capture the impact on licensing terms, costs and access. Suppliers often respond by increasing per-council charges.

Identify contracts that need to be split or novated, and the order in which changes need to happen to avoid service interruption.

Pay particular attention to how security responsibilities, access controls and monitoring will be managed.

The playbook should really start with contracts. What we need to know first is when they start, when they end, what the notice periods are, who the suppliers are, how much we’re paying and what procurement route was used. Once you have that information you have a baseline for the conversation about where to start. Without that visibility, it’s very hard to make sensible decisions about consolidation.

Council Head of Digital and IT

Using our contract mapping and commercial risk scoring template

We have created a workbook to help you build a shared view of supplier contracts and prioritise commercial risks during LGR.

Download the contract mapping and commercial risk scoring template

Prioritise high-risk contracts

Not all contracts need immediate attention. Focus your efforts first on contracts that:

  • expire within 12 to 24 months of vesting
  • underpin statutory services
  • involve long-term licensing commitments
  • have limited break clauses
  • hold large volumes of operational data
  • have high transition complexity, whether technical, data-related or organisational
  • present elevated cyber security or resilience risk

Common examples of high-risk contracts

  • Finance and enterprise resource planning (ERP) systems
  • Revenues and benefits systems
  • Adult and children’s social care platforms
  • Identity platforms and Microsoft 365 tenants
  • Telephony and contact centre solutions
  • The main council website and digital content platforms
  • Network and hosting services
  • Major outsourcing arrangements

These contracts often have the greatest operational impact and migration complexity.

Recognising common commercial failure patterns

Several commercial patterns regularly emerge during LGR. Understanding them early can help you avoid repeating them. Each pattern also has a counterpoint that is worth understanding.

Engage strategic suppliers early

Supplier engagement should begin early in the LGR process. Many councils rely on a shared group of core technology suppliers, and those suppliers may be supporting multiple LGR programmes at the same time.

Early conversations can help councils:

  • understand supplier delivery capacity
  • identify potential migration, replication or separation approaches
  • understand the licensing implications of consolidating or separating
  • explore options for contract modification
  • identify potential cost implications early

Early engagement also reduces the likelihood of rushed renewals close to vesting day. It should involve both commercial and technical stakeholders.

Councils should also feel confident in challenging suppliers where appropriate. Supporting LGR is a new experience for many suppliers. A strong collaborative relationship that allows assumptions to be tested and approaches refined is more likely to deliver better outcomes than purely transactional engagement.

There are minimum expectations for security schedules, assurance evidence, subcontractor flow-down, contractual incident notification and the council’s right to obtain assurance or audit evidence proportionate to risk. Read more about this guidance on the NCSC website, which includes Cyber Assessment Framework supply chain material and wider supply chain security guidance.

Smaller IT suppliers may not be familiar with councils’ statutory transfer powers under Section 16 of the Local Government and Public Involvement in Health Act 2007 Act. Clear and early communication about how contracts will transfer can help reduce supplier uncertainty and avoid unnecessary pressure to renegotiate contracts.

Sometimes when we engage with suppliers, they ask us what we want to do and the honest answer is that we don’t know yet. We just know that systems need to be consolidated or separated as part of reorganisation. What would help is suppliers coming to the table with their experience of how they’ve supported other councils through similar changes. That kind of shared learning could save everyone a lot of time and cost.

Council Senior Manager of Digital, Innovation and Customer Experience

Consider collective supplier engagement

Where several councils are undergoing LGR at the same time, suppliers may be working with multiple programmes simultaneously. In some cases, coordinated engagement across councils can reduce duplication and improve outcomes.

Examples include:

  • supplier roundtables
  • sector user groups
  • shared discussions on migration, replication or separation approaches
  • engagement facilitated by sector bodies or central government

Coordinated engagement can help suppliers better understand sector needs and encourage more consistent approaches across councils.

Microsoft tenancy and other enterprise licence events

Enterprise licence consolidation is one of the most common commercial topics in LGR. Microsoft 365 tenancy decisions are a common example. Councils may need to decide to:

  • consolidate multiple tenancies into one
  • run multiple tenancies for a period
  • split a single tenancy across more than one new council during disaggregation

Similar decisions apply to other major SaaS platforms and enterprise agreements.

These decisions involve commercial, technical and cyber considerations. Address the following early:

  • the total cost of the consolidated or separated state, and the cost of getting there
  • the delivery timeline, including how long parallel running will be needed
  • identity and access implications, particularly during transition
  • the scope and approach for data migration, including whether all data needs to migrate or whether some can be archived (see the ‘Plan for exit and migration’ section in this resource)
  • supplier support capacity and the order in which suppliers are likely to support tenancy migrations across different councils
  • identity, access, monitoring and data handling risks (review the NCSC guidance)

Two patterns specific to IT licensing regularly emerge during LGR:

  1. councils choosing to run critical systems in parallel for a transitional period rather than consolidating on vesting day, such as temporarily running multiple payroll, where contract timelines do not align and forced consolidation would create unacceptable risk
  2. suppliers being unwilling to support hosted licensing arrangements between councils because they view them as a form of licence resale, while being more open to discussions about scale-related benefits, such as volume discounts or rebates

Access our cyber readiness resource for the security implications of identity and tenancy decisions during LGR.

Use a structured commercial risk assessment

Contracts vary significantly in flexibility and migration complexity. A simple risk scoring approach can help you prioritise effort.

Link commercial prioritisation to the Cyber Assessment Framework (CAF) for local government. Use your council’s identified essential services and critical systems to determine which contracts require early review, enhanced assurance and senior escalation.

Learn more

Assessment factors

The commercial risk scoring tool included in our workbook scores contracts against these factors automatically and prioritises contracts requiring early review.

Download the contract mapping and commercial risk scoring template

Procurement Act 2023 and flexible procurement approaches

The Procurement Act 2023 gives councils more flexibility in how procurement procedures are designed. The competitive flexible procedure allows contracting authorities to design procurement processes that better reflect market conditions and service complexity.

This can support:

  • outcome-based requirements
  • structured supplier dialogue, including constructive challenge to test assumptions and refine approaches
  • evaluation of flexibility and exit options

Where new procurements are needed, councils should consider how contract structures enable future change rather than restricting it. Engage procurement and legal colleagues early to ensure procurement approaches remain compliant.

Plan for exit and migration

Exit planning is often overlooked during contract negotiation. Councils should understand:

  • how data will be extracted
  • the format data will be provided in
  • how long data extraction will take
  • any costs associated with exit

Migration and decommissioning costs can be significant, so should be considered early in the planning process. Where possible, contracts should include provisions that support future portability and migration.

You rarely need to migrate everything

Where historic data is archived rather than migrated, councils should still treat the archive as part of the authority’s cyber and information governance risk remit.

Archives should have:

  • clear ownership
  • access controls
  • encryption where appropriate
  • audit logging
  • retention and deletion arrangements
  • tested backup and recovery processes

Councils should also understand how archived data will be searched and retrieved for statutory, legal, safeguarding or operational purposes.

Our disaggregating services and data resource has guidance on how data can be archived rather than migrated during LGR.

Maintain clear commercial governance

Commercial decisions during LGR should be supported by clear governance. Councils should define:

  • who has authority to sign contracts during the shadow period and the value thresholds that apply
  • thresholds for commercial escalation, recognising that cyber-critical renewals or bundled changes may warrant escalation even when they appear routine or fall below a spending threshold because they can affect the new council’s control environment
  • how contract risk decisions are documented
  • how digital, procurement, finance, legal and information governance teams work together
  • how business continuity, resilience and cyber security are protected through every commercial decision

Risk-averse decisions are common during LGR. Where short-term solutions limit long-term flexibility, those trade-offs should be clearly understood and documented. The objective is informed risk, not the avoidance of risk.

The organisation plans intensively for day one. Procurement teams must plan for days two to 365.

Sharon Simpson, Assistant Director for Commissioning and Procurement, Westmorland and Furness Council