Why a Three-Year Horizon (and Why Most Pharma IT Plans Fail)

The three-year strategic plan sits in an awkward middle. It is longer than the annual budget cycle, so it must survive shifting priorities, launches, acquisitions, and reorganizations. It is shorter than the ten- or fifteen-year enterprise vision, so it cannot hide behind aspirational abstractions. Done well, it is the document that translates the CEO’s strategy into what IT will actually build, buy, retire, and staff — with enough specificity to guide portfolio decisions and enough flexibility to absorb the unexpected.

Done poorly, and this is the more common outcome, the three-year plan becomes a slide deck rewritten every year, a wishlist of technology investments dressed up in strategic language, or an unreadable enterprise architecture artifact that no business leader ever consults. McKinsey’s Digital Quotient work found that fewer than 30% of pharma companies can track digital spending across most business units — a symptom of exactly this failure mode.3 If you cannot see where money is going, you cannot plan where it should go next.

The four failure modes we see most often

FAILURE MODE 1

The Wishlist

A list of every technology the function would like to buy, with no ranking, no dependencies, no capacity model, and no linkage to business outcomes. Survives one budget cycle at best.

FAILURE MODE 2

The Architecture Poster

A beautiful reference architecture with layers, patterns, and platform names. No sequencing, no capability owners, no accountability model. Business leaders nod and forget.

FAILURE MODE 3

The AI Strategy

Ninety percent generative AI, ten percent everything else. Confuses a technology trend for a strategic plan. Ignores the run-the-business work that actually makes AI possible.

FAILURE MODE 4

The Vendor Brochure

Structured around the CIO’s top three vendors. Reads like a customer reference. Cannot survive a vendor change or a shift in commercial priorities.

A credible three-year plan has to do six things at once: read the environment, describe the starting position, describe the destination, sequence the work, resource the work, and measure the work. The rest of this article walks each one in order, with templates and frameworks a pharma IT leader can adapt to their own environment.

Phase 1: Environmental Scan

Every strategic plan begins by looking outward. In pharma IT, the environmental scan has three components: industry and technology trends, regulatory drivers, and competitor benchmarking. Skip any one and the plan reads as internally-focused, which is what leadership teams distrust most.

1.1 Industry and technology trends

The 2026 pharma IT context is defined by four converging forces. First, AI is shifting from analysis to action; IQVIA’s 2026 outlook flags this shift as the year agentic AI moves from generating insights to executing intelligent tasks across pharmacovigilance, clinical trial finance, and R&D operations.5 Second, the platform consolidation trend continues, with Veeva unifying its Development Cloud and Commercial Cloud on the same Vault platform and Salesforce expanding its Life Sciences Cloud footprint.6 Third, cloud saturation is now near-total: an estimated 83% of pharma companies leverage cloud in some form, and 40% report all operations already cloud-enabled.7 Fourth, Gartner’s 2026 strategic technology trends center on AI-native development platforms, multiagent systems, and confidential computing — themes any pharma IT plan will need to address, even if it does not adopt them all.8

$444B Forecast worldwide healthcare and life sciences IT spending by 20292
70% Of pharma AI pilots stall before enterprise scale4
27/100 Pharma’s Digital Quotient score, behind banking (32) and insurance (31)3

1.2 Regulatory drivers

Regulatory expectations are quietly reshaping the pharma IT roadmap. FDA’s final Computer Software Assurance guidance, issued September 2025 and updated February 2026, formally endorses a risk-based, activity-based approach to validation that can reduce validation cycle times by 30-60% for organizations that adopt it well.910 The 21 CFR Part 820 alignment with ISO 13485 took effect in February 2026, changing quality system expectations for combination products and device-adjacent software.9 EMA’s Reflection Paper on AI in the medicinal product lifecycle and the emerging Annex 22 discussions signal that AI governance is moving from voluntary practice to inspection-ready expectation. Any three-year plan must explicitly account for CSV-to-CSA transition, AI governance, and Part 11 modernization — not as compliance overhead but as investment cases in their own right.

1.3 Competitor benchmarking

Competitor benchmarking is the phase most often skipped or done badly. The temptation is to compare features and platforms; the discipline is to compare capabilities and outcomes. Public case examples worth studying include AstraZeneca’s IGNITE technology strategy, which frames its transformation around four pillars (accelerating discovery and design, transforming business operations, empowering patients, and enabling colleagues), and the ISPE Pharma 4.0 operating model, which structures maturity around digital, cultural, IT/OT integration, and data integrity dimensions.11 Deloitte’s 2025 life sciences outlook found that roughly 60% of executives named generative AI or broader digital transformation as the trend they were watching most closely — useful context for board conversations, less useful as a portfolio decision input.12

The SD perspective on benchmarking: Do not benchmark features (Veeva vs. Salesforce, Databricks vs. Snowflake). Benchmark outcomes and operating models. How long does it take a competitor to launch a clinical study? Onboard a new market? Validate a new automation? Those comparisons drive strategic conversations. Feature comparisons drive procurement conversations.

Phase 2: Current-State Assessment

The current-state assessment is the part of the strategic plan that no one enjoys, which is why most pharma IT plans skip it or reduce it to a page of platitudes. Do not skip it. A three-year plan without a rigorous current-state baseline is a wishlist. The assessment has three components: portfolio, capabilities, and gaps. Below is a working methodology.

2.1 Portfolio assessment

The application portfolio in a mid-to-large pharma typically contains 400-1,200 applications across R&D, clinical, regulatory, quality, manufacturing, supply chain, commercial, medical, and G&A. The assessment should score each application on business value (how critical it is to a strategic outcome), technical fit (how well it is running today), total cost of ownership (license plus operate plus validate), and strategic disposition (invest, tolerate, migrate, retire).

Portfolio assessment scoring rubric

Dimension 1 – Low 3 – Medium 5 – High
Business value Peripheral; used by fewer than 10 users; no strategic linkage Supports a defined process; would be missed if unavailable Directly enables a strategic pillar or regulated process; downtime is a business event
Technical fit End-of-life vendor, unsupported version, high defect rate, manual workarounds Supported version, moderate technical debt, acceptable performance Current version, cloud-native or roadmap-aligned, low incident volume
TCO (annual) >$500K per active user or per validated function $50K-$500K per active user or per validated function <$50K per active user or per validated function
Compliance posture Open audit findings, missing periodic review, CSV gaps Current on periodic review, CSA plan in progress Fully CSA-aligned, clean inspection history, automated evidence

The portfolio’s output is a two-by-two matrix: business value on one axis, technical fit on the other. High-value / low-fit applications are the modernization candidates. Low-value / low-fit applications are retirement candidates. Low-value / high-fit applications are the tolerate-and-observe quadrant. High-value / high-fit applications are your platforms — protect and extend them.

2.2 Capabilities assessment

The capability assessment is where TOGAF’s Architecture Capability Maturity Model earns its place. Score each IT capability across five levels — Initial, Under Development, Defined, Managed, and Measured (some frameworks use six levels; five is enough for a practical three-year plan).13 The domains to score depend on your organization, but a workable pharma IT set is: enterprise architecture, data and analytics, cybersecurity, cloud and infrastructure, application delivery, quality and validation, product management, service management, vendor and sourcing, and digital workplace.

Working definition of the five levels:

1. Initial: Ad hoc, hero-dependent, no documented practices.

2. Under Development: Practices exist in pockets but are not consistent.

3. Defined: Documented, adopted enterprise-wide, but not yet measured.

4. Managed: Instrumented with KPIs, reviewed on a cadence, improved by exception.

5. Measured: Optimizing continuously against outcome metrics, benchmarked externally.

2.3 Gap analysis

The gap analysis is straightforward once portfolio and capability scores are honest: for each strategic capability, what is the delta between current-state and target-state, and what is required to close it? The gaps typically fall into four buckets — technology (a system does not exist or is wrong), data (data does not exist, is not integrated, or is not trusted), process (the process is broken independent of the technology), and people (the skill or accountability does not exist). Most pharma IT plans over-index on technology gaps and under-invest in the other three. That is the pattern to break.

The most common current-state mistake: The assessment identifies gaps but not root causes. “We do not have a modern data platform” is not a root cause; it is a symptom. The root cause might be a governance model that has never adjudicated business ownership of master data, or a funding model that punishes cross-functional platform investment. A strategic plan that treats symptoms as gaps ends up rebuilding the same fractured landscape on newer technology.

Phase 3: Future-State Vision and Strategic Pillars

The future-state vision is where most strategic plans become unreadable. The trap is trying to describe every capability, every platform, and every process change in a single document. The discipline is to describe the destination in two artifacts: a short narrative vision (one to two paragraphs a business leader will actually read) and a set of strategic pillars (typically four to six) that translate the vision into decision criteria.

3.1 The narrative vision

A strong pharma IT vision is written in the language of business outcomes, not technology. It answers: three years from now, what will be true about how our organization discovers, develops, launches, and delivers medicines that is not true today, and what role will IT have played in making that so? Example structure: “By 2029, [Company] will operate as a data-connected, AI-enabled life sciences organization where clinical, quality, and commercial teams work from a shared source of truth, decisions that once took weeks now take hours, and every new capability we build meets a common set of governance, security, and validation standards. IT’s role in this future is to be the strategic partner our functional leaders come to first — not last.”

3.2 The strategic pillars

Four to six pillars is the sweet spot. Fewer than four and the pillars are too abstract to guide investment; more than six and no one can remember them. The pillars we see working in pharma today center on foundations, data and AI, portfolio modernization, ways of working, cyber and compliance, and colleague experience. The exact wording matters less than the discipline of using the pillars as the mandatory decision frame for every portfolio choice.

PILLAR 1

Foundational Platforms and Cloud

Modernize the core hybrid cloud footprint, retire technical debt, and establish a common set of platform services (identity, integration, observability, secrets, cost management) that every application team consumes rather than rebuilds.

PILLAR 2

Data and AI as Enterprise Assets

Establish authoritative sources for HCP, HCO, product, patient, and study master data. Build a governed data platform (mesh, fabric, or hybrid) that treats data as a product. Embed AI governance and MLOps as a shared capability, not a project.

PILLAR 3

Portfolio Modernization

Rationalize the application landscape: consolidate where the platform strategy justifies it (Veeva, Salesforce, ServiceNow, Workday), retire what no longer earns its keep, and adopt CSA to accelerate validated change on the systems that remain.

PILLAR 4

Ways of Working

Shift from project to product operating model where the business case supports it, adopt bimodal delivery to preserve regulated stability while enabling rapid experimentation, and rebuild capacity around persistent product teams rather than temporary project pools.

PILLAR 5

Cyber, Compliance, and Trust

Modernize identity, adopt zero-trust patterns, close the CSV-to-CSA transition, mature third-party risk management, and build a compliance evidence model that is inspection-ready without heroic quarter-end effort.

PILLAR 6

Colleague and Customer Experience

Treat the internal user as a customer. Modernize the digital workplace, rationalize the tool sprawl, and instrument colleague experience alongside customer experience so both are visible to leadership.

Phase 4: The Three-Year Execution Roadmap

The roadmap is where the plan either becomes a document leaders return to or a slide deck no one opens twice. The critical discipline is that each of the three years plays a distinct role: Year 1 is execution, Year 2 is directional, and Year 3 is aspirational. Being explicit about that spectrum protects the plan from the classic pathology of promising everything in Year 1 and losing credibility by Q2.

Year 1: The Execution Year

Year 1 must be granular enough that a portfolio manager could build a delivery plan from it and specific enough that a CFO could tie every commitment to a funding line. It is defended in detail. Typical Year 1 content: two to four “foundation” investments that de-risk everything after (identity modernization, integration platform, cloud landing zones, data platform baseline), two to four “early wins” that generate visible business outcomes within three quarters, and one or two “retirements” that free capacity and reduce run cost.

1

Stabilize and instrument

Get the portfolio inventory, cost transparency, and capability baseline current within the first ninety days. You cannot execute a plan you cannot measure.

2

Land the foundations

Cloud landing zones, identity, integration platform, and data platform baseline. These are the investments that everything else depends on. They rarely deliver visible outcomes, so leadership commitment is at its most fragile here.

3

Deliver two or three early wins

Pick outcomes that a functional leader will publicly claim. AI in medical information response drafting, MLR content acceleration, or clinical study startup automation are common candidates. Deliver small, deliver quickly, and instrument.

4

Retire visibly

Choose two or three retirements you can complete inside the first year and communicate the savings. Retirements are how you fund the next wave.

Year 2: The Directional Year

Year 2 is the year of pattern replication. If Year 1 built the foundations and delivered two or three early wins, Year 2 replicates those patterns across the enterprise. It is described with less granularity than Year 1 (portfolio managers do not build detailed plans this far out, and pretending otherwise wastes calories), but it is more specific than Year 3. Typical Year 2 content: scale successful Year 1 pilots to enterprise deployment, complete the platform consolidation trajectory (e.g., finish the Vault CRM migration, complete ServiceNow ITSM adoption), and open the second wave of AI use cases across R&D, quality, and manufacturing.

Year 3: The Aspirational Year

Year 3 is the horizon year. It is not defended in detail because it will change; the intent is to set direction and give the organization something to prepare for. Typical Year 3 content: agentic AI across major workflows, autonomous quality operations, real-time regulatory reporting, cross-functional patient data platforms, and the operating-model changes (product organizations, persistent teams, funding by capability rather than project) that the earlier years have made possible. Say the aspirational things here so that the Year 1 and Year 2 investments make sense; do not commit to delivery dates.

The rule of thumb we use: Year 1 has quarters. Year 2 has halves. Year 3 has themes. If your Year 3 has quarters and dates, you have written an aspirational plan that will be publicly wrong within eighteen months. If your Year 1 has themes and no dates, you have not planned.

4.1 Sample three-year roadmap

Pillar Year 1 (Execute) Year 2 (Direct) Year 3 (Aspire)
Foundations Cloud landing zones live in three regions; identity and integration platform baselined All new workloads on landing zones; legacy identity retired; observability at 90% coverage Platform-as-service model mature; self-service developer platform for regulated workloads
Data and AI Master data domains defined; data platform MVP; AI governance framework live Two or three data products in production; MLOps mature; agentic AI in one or two workflows Cross-functional patient and product data platform; agentic AI across R&D, quality, commercial
Portfolio Modernization Application inventory and disposition complete; five retirements delivered; CSA pilot Second wave of retirements; platform consolidation major milestones; CSA at scale Portfolio at target composition; validated change cycle times reduced by 40-60%
Ways of Working Product model pilot in two domains; bimodal delivery framework live Product model across regulated and non-regulated domains; funding-by-capability pilot Product operating model at scale; capability-based funding model
Cyber, Compliance, Trust Zero-trust roadmap in flight; TPRM overhaul; CSA policy adopted Zero-trust at 70% of critical assets; automated compliance evidence Inspection-ready-by-default; AI governance integrated with quality management
Experience Digital workplace refresh; colleague XP baseline instrumented Persona-based workspace; tool rationalization saves 15% Colleague XP equal to consumer standard; internal net promoter above +40

Phase 5: Resource, Governance, and Operating Model

A strategic plan without a resource model is a fiction. A resource model without a governance model is a budget request. The two have to be built together, and both have to be visible in the same document, or the plan will not survive the first serious portfolio conversation.

5.1 The resource model

The resource model has three components: financial, human, and vendor. The financial view should show total investment across the three years by pillar, with a clear split between run-the-business (RTB), grow-the-business (GTB), and transform-the-business (TTB). A common healthy mix in mature pharma IT is roughly 55-65% RTB, 20-25% GTB, and 15-20% TTB — but the healthy mix depends on your starting position. If you are underinvested in modernization, TTB may need to be 25-30% for the first two years to reset.

The human view should show FTE and contractor demand by pillar and by capability domain, with a plan for where new capability will come from (internal build, hire, acquire, partner). The vendor view should identify the top ten to fifteen strategic vendor relationships, the total spend with each, the concentration risk, and the transition plan for any vendor that will not survive the three years.

5.2 The governance model

Governance is the mechanism that turns a plan into decisions. A working pharma IT governance model has four layers.

Layer Body Decisions Cadence
Strategic Digital Council (CEO, CFO, business heads, CIO, CDIO) Multi-year investment envelope; approves strategic pillars; resolves cross-function conflict Quarterly
Portfolio Portfolio Review Board (CIO, function heads or delegates, PMO, EA, security) Prioritizes and sequences the investment portfolio; approves large investments; kills faltering initiatives Monthly
Architecture Architecture Review Board (EA, domain architects, security, quality) Enforces reference architecture; approves platform-level decisions; adjudicates variance Bi-weekly
Delivery Product / Program Reviews (product owner, delivery lead, stakeholders) Prioritization inside each product or program; scope, capacity, dependencies Weekly or fortnightly

McKinsey’s assessment work has long observed that having a clear governance structure helps digital-mature companies exert proper oversight over digital spending, and that high performers align organizational structure with digital priorities — often by setting up a center of excellence for digital or appointing a chief digital officer.3 The specific structure matters less than the discipline of running it consistently.

5.3 The operating model

Operating model choices sit alongside governance. The three that matter most for a pharma IT three-year plan are bimodal versus unified delivery, project versus product, and centralized versus federated. Bimodal IT — running Mode 1 predictable, regulated delivery alongside Mode 2 agile, experimental delivery — remains particularly well-suited to pharma given the mix of validated GxP systems and rapidly evolving analytics and AI workloads.14 The trap is treating bimodal as a permanent structural divide rather than a portfolio-level choice.

The product operating model is the more consequential shift. It moves accountability from project delivery (short-lived, scoped, funded per initiative) to product management (long-lived, outcome-owned, funded per capability). It is a strong fit for platforms and shared capabilities but is often over-applied to work that would be better run as a project. A pragmatic three-year plan usually adopts product for platforms and data domains, retains project structure for major regulated implementations, and articulates the criteria for each.

Phase 6: The KPI Framework

The KPI framework is the piece that fewest pharma IT strategic plans get right. The two common failure modes are trying to measure everything (producing a scorecard no one reads) and measuring only outputs (velocity, tickets, releases) without linking to outcomes. A working framework has four categories: business outcomes, delivery outcomes, run outcomes, and risk outcomes. Keep the total number of enterprise-level KPIs to twelve to sixteen; anything more is a dashboard, not a strategy.

KPIs, OKRs, and Balanced Scorecards are complementary, not competing: KPIs track continuous health. OKRs set aspirational, time-boxed goals. Balanced scorecards align across financial, customer, process, and learning perspectives. Most mature pharma IT functions use KPIs as the operational instrument, OKRs as the strategic goal-setting instrument, and a balanced-scorecard structure as the reporting frame to leadership.15

Four KPI categories

Category Example KPIs Owner
Business outcomes Time-to-market for defined launches; cycle time from data lock to submission; MLR turnaround; medical inquiry response time Business function head; IT partners
Delivery outcomes % of portfolio delivered on committed scope and quality; time from ideation to production for AI use cases; validated release cycle time (post-CSA) PMO / product leadership
Run outcomes Availability of tier-1 systems; MTTR; unit cost per user or per validated function; cloud cost variance Operations / service management
Risk outcomes Open critical audit findings; % of critical systems with current CSA package; identity coverage; third-party risk score; AI governance policy compliance Security / quality / compliance

The Pilot-to-Scale Prioritization Framework

The single most common failure mode in pharma IT strategic plans is the assumption that scaling is a linear extension of piloting. It is not. Roughly 70% of pharma AI pilots stall between successful proof-of-value and enterprise deployment — sometimes because the technology never worked at scale, more often because the organization never designed for scale in the first place.4 A three-year plan needs an explicit framework for how a pilot earns the right to scale.

The five-stage pilot-to-scale gate

1

Discovery (weeks 1-4): worth pursuing?

Business hypothesis, data readiness check, feasibility, and rough sizing. Kill or continue in four weeks. Discovery is deliberately cheap because it is designed to say no.

2

Pilot (months 2-6): does it work?

Small user group, controlled scope, live data. Measure against specific hypotheses. Success criteria set at gate entry, not adjusted mid-flight.

3

Scale-readiness (months 5-8): can the organization absorb it?

This is the gate most pilots fail. Data pipelines that worked for one team fracture at scale. Governance was never designed. Compliance evidence was never built. If the answer is no, do not scale — remediate and re-gate.

4

Scale (months 8-15): controlled expansion

Move to the second, third, fourth user population. Instrument adoption, value realization, and drift. Preserve the option to stop scaling if the pattern breaks.

5

Steady state (months 15+): productize

Transition to product management, embed in the operating model, retire the special-purpose scaffolding, and add the capability to run-the-business metrics.

Prioritization inside the pilot funnel

Not every candidate deserves a pilot slot. A pragmatic scoring model rates each candidate on four axes: strategic fit (does it advance a pillar?), business value (measurable outcome at scale?), feasibility (data ready, technology ready?), and organizational readiness (business owner accountable, adoption plan credible?). Score each 1-5, weight to your context, and hold the funnel to five to ten active pilots at a time. Anything more is a signal that governance has failed.16

The pilot purgatory pattern: A pharma with fifty pilots running has fifty pilots and no scale. The organizational bandwidth for change is not fifty pilots wide. Concentrated attention and disciplined kill decisions are the difference between a portfolio that generates value and one that generates PowerPoint.

The Strategic Plan Document: A Template Outline

Below is a working template outline for the three-year strategic plan document itself. It is intentionally opinionated. Adapt it to your organizational style, but resist the temptation to add sections that do not clearly earn their place. The document is a communication instrument first and a planning artifact second; if functional leaders cannot navigate it in twenty minutes, it will not shape decisions.

Section 1 — Executive Summary (2 pages)

The bottom line on a page. What is the destination, what does it cost, what changes in the operating model, and what does leadership need to decide? A second page for the visual: three-year roadmap picture on one side, resource envelope on the other.

Section 2 — Environmental Scan (4-6 pages)

Industry trends, regulatory drivers, technology shifts, competitor benchmarking. Written in the language of business consequence, not technology tourism.

Section 3 — Current-State Assessment (6-8 pages)

Portfolio composition, capability maturity, gap analysis, root causes. Include the assessment methodology in an appendix, not the body.

Section 4 — Future-State Vision and Strategic Pillars (4-5 pages)

Narrative vision (1 page), pillars (1 page each with intent, scope, success measures). This is the anchor for every subsequent portfolio conversation.

Section 5 — Three-Year Roadmap (5-6 pages)

Year 1 in detail (with quarters), Year 2 in direction (with halves), Year 3 in aspiration (with themes). Reference the pillar structure throughout.

Section 6 — Resource and Operating Model (4-5 pages)

Financial envelope by pillar and year, RTB/GTB/TTB split, FTE and vendor model, operating-model choices (product vs. project, bimodal, centralized vs. federated).

Section 7 — Governance and Ways of Working (2-3 pages)

The four governance layers, the cadence, the decision rights. Enough that a new leader can read the section and know how decisions get made.

Section 8 — KPI Framework (2 pages)

The twelve to sixteen enterprise-level KPIs, categorized (business, delivery, run, risk), with owners and baselines. Anything more granular belongs in operational dashboards, not the strategic plan.

Section 9 — Risk, Assumptions, and Dependencies (2 pages)

Explicitly enumerate the top ten risks to plan achievement (funding stability, executive turnover, regulatory shift, M&A, cybersecurity, talent, vendor concentration, etc.) with a mitigation position for each. This is the section that gives the plan credibility with the audit committee.

Appendices

Assessment methodology, portfolio inventory, glossary, and the pilot-to-scale scoring model. Keep the main body readable; put the working artifacts in appendices.

Conclusion

A three-year IT strategic plan is not a document. It is an operating discipline made visible on paper. The best plans are the ones that get quoted in portfolio meetings twelve months after publication, that give a new hire a map of what matters and why, and that survive the inevitable disruption — acquisition, restructuring, new CEO, new regulatory pressure — by being clear about which commitments are structural and which are directional. The framework in this article is not the only way to structure a plan; it is a working scaffold that has held up across pharma IT functions of very different sizes and maturities.

Sakara Digital works with pharma and biotech organizations building this kind of multi-year IT and digital plan — from the initial environmental scan and portfolio assessment through the KPI framework and governance cadence. If you are heading into a strategic planning cycle and want an independent perspective on where to start, what to defend in detail, and what to leave directional, we are happy to have that conversation.