Cutover is a measured threshold, not a date
The features are not the hard part of this programme. Replacing a system that has run the business for two decades is. It holds rules nobody has written down, and the business has shaped itself around its behaviour, including its limitations.
Illustrative schedule from the version one definition. Timings assume access and answers are in hand before the clock starts.
One number nobody can reconcile
Once a desk finds one number it cannot reconcile, it stops believing every other number, and the parallel run becomes permanent. This is why the reconciliation harness exists before the desk is asked to trust anything, and why migration is not a late step.
- Open voyages migrate as live records with their contracts, costs, events and accruals, reconciled voyage by voyage.
- Counterparties are deduplicated and resolved to legal identifiers, which is usually the first place the old data disagrees with itself.
- Undocumented rules are surfaced and written down, which for most firms is the single most valuable by-product of a replacement.
Variance between the two systems on the same voyages, by week
Five stages, each with a gate that can stop it
Deliberately slow at the front and fast at the back. Everything that can be learned about the data is learned before anything depends on it.
Extract and profile
Pull the full historical record out of the current system and profile it honestly. This produces the first genuinely new fact of the programme, which is what the record actually contains.
Gate A written profile of coverage, completeness and comparability, accepted by both sides before any model work is scoped.
Rebuild the rules
The calculations are re-implemented from the contracts rather than from the legacy code, then tested against historical outcomes the old system already produced.
Gate Laytime, hire and voyage result reproduce a sample of closed voyages to an agreed tolerance, with every difference explained.
Parallel run
A small number of real voyages run in both systems at once, from fixture to close. Traders and operators keep working as they do today. The comparison is the deliverable.
Gate Daily reconciliation, with the variance trending to zero and the remaining differences understood rather than tolerated.
Cut over
One workflow at a time moves across. Post-fixture and claims first, because the return is evidenced fastest and the blast radius is smallest. Trading last.
Gate Each workflow runs for an agreed period with no fallback and no unexplained variance before the next one moves.
Decommission
The old system becomes read-only, then an archive. It is switched off when nothing has read from it for a defined period, rather than on a date.
Gate A full financial period closed entirely in the new system, reconciled, and signed off by finance.
Rollback, honestly stated
Until the last stage the old system remains operable and the position can be reconstructed in it. That is the point of the parallel run and the staged cutover, and it is what makes the programme reversible at every step except the final one.
Four phases, four decisions
Each phase ends in a decision that can stop or reshape the programme, and none of them depends on a promise made before the data was seen.
- 1
Prove the data
Extract and profile the historical record. Capture the baselines. Rebuild and test the core calculations against closed voyages. No new workflow ships.
Ends with An honest written answer on what the history supports, and a baseline nobody can argue with later.
- 2
Land the operator desk
Port calls, events, disbursement control, laytime, claims, time bars and the early arrival ledger. The smallest blast radius and the fastest evidenced return.
Ends with Claims served from the new system inside the bar, with the pack assembled automatically.
- 3
Land the trade desk
Signal capture, estimates, negotiation, fixture, chain comparison and handover. The spine closes and one cargo runs end to end.
Ends with A voyage result that finance accepts without a spreadsheet in the middle.
- 4
Cut over and extend
Workflow by workflow cutover, decommissioning, then the second layer: quote guidance if the gate passed, contract portfolio, position book.
Ends with A full period closed in the new system, and the old one read-only.
Why the operator desk goes first
It is counter-intuitive, because the trading desk sponsors the work. Post-fixture is where the return can be proved in weeks rather than quarters, where a mistake costs a query rather than a fixture, and where the event and document foundation gets built that the trading layer will later depend on. The trade desk is worth waiting a phase for.
Against a baseline captured first
A number that has no before is not evidence. It is decoration.
| Measure | What it tells you | Baseline needed first | Honest caveat |
|---|---|---|---|
| Claims lost to time bar | The clearest and least arguable return in the system. The target is zero. | Value of claims that expired unserved over the last two years. | Split it by account, because a bar missed on a claim held for the owning entity is a liability rather than a return foregone. |
| Demurrage realisation rate | Of the demurrage calculated as due, how much is actually collected. | Calculated against collected, by counterparty, over a full year. | Improvement is partly commercial rather than systemic, so attribution needs care. |
| Estimate to actual variance | Whether the estimates are getting better, and specifically where they are systematically wrong. | Dispersion, not only the mean. A desk wrong by plus and minus alternately has a mean of zero and no control. | Needs a full cycle of voyages before the trend means anything. |
| Chain mismatches caught | Term mismatches surfaced before fixing rather than discovered at claim. | Count of historical cases where a pass-through failed. | Avoided losses are harder to evidence than recovered ones. Count the catches, describe the exposure. |
| Time gained and where it went | Predicted against realised early arrival hours, and how much of the gain was then spent stationary. | Sampled reconstruction of arrival against baseline on recent voyages. | Measured against the raw warranty it will overstate, and an owner will say so. |
| Manual touches removed | Whether the desk's day actually changed, measured in work removed rather than clicks saved. | Observed time on circular processing, estimate preparation and document chasing. | Only credible if measured with the people doing the work, rather than inferred from system logs. |
Stated plainly
A concept paper that carries no risk section is not describing a real programme.
History falls short
The record may hold fixtures without the losing side of the negotiation, or terms recorded inconsistently enough that comparison is not defensible.
How it is handled The readiness gate runs in phase one, before anything is promised on it. Version one does not depend on the engine, so a disappointing answer reshapes version two rather than derailing the programme.
Adoption fails
Traders abandon anything that adds a step between reading a circular and sending an offer. Operators abandon anything that adds a screen to a day they are already behind on.
How it is handled The first thing built is the thing that removes work. The system reads the inbox rather than asking anyone to leave it, and adoption is measured as work removed rather than as logins.
Parallel run persists
Two systems running side by side becomes the permanent state, doubling the work and eroding confidence in both.
How it is handled Each workflow has a defined period after which either it cuts over or the reason it cannot is escalated as a programme decision. Indefinite parallel running is treated as a failure.
Hidden rules surface
The current system encodes commercial conventions nobody has written down, and they appear one at a time, each as a reconciliation break.
How it is handled This is expected. Phase two rebuilds calculations from the contracts and tests against historical output specifically to flush these out early, and every one found is written down.
A system that carries one cargo from a broker email to a closed claim. A trader prices and fixes inside it. An operator runs the voyage to completion inside it. The claim is served inside the time bar from evidence the system assembled, and the voyage result agrees with finance without a spreadsheet in the middle. It has been proved on real voyages running in parallel.
A replacement. The legacy system still runs the book at week six and should. The position layer, the portfolio, quote guidance and the compliance cycle are version two, sequenced behind the layer they depend on rather than deferred out of caution. One voyage, end to end, correct. Then twenty. Then the book.
