The cutover checklist

The list we tape to the wall the week a workload changes homes. Twenty-two items, each one purchased with somebody's bad weekend.

Pixel drawing of a checklist sheet with a large tick beside it

Cutovers fail on paper first. The regulatory record's most expensive example remains TSB's 2018 core banking migration, which locked customers out for weeks and ended in a £48.65m fine: a cutover run before its checklist was true. Ours is below. It is not clever. Every line was purchased with a bad weekend, some of them ours.

Before the window:

  1. The rollback is rehearsed, not written. Someone has actually run it, this month, and it took the time the plan says.
  2. Success is defined as numbers: which checks, which thresholds, decided by whom. "Looks good" is not a gate.
  3. The no-go person is named. One human owns the abort call, and it is nobody whose bonus depends on go.
  4. Freeze scope is written: what may change in the old system during the window (usually: nothing) and who enforces it.
  5. Data reconciliation ran against production-size data, twice, clean. Not the staging subset. The whole ugly thing.
  6. Every external party (payment processor, EDI partner, that one vendor) has a phone number that answered a test call.
  7. DNS TTLs were dropped days ago, not hours.
  8. The comms templates exist for all three outcomes: went fine, went long, went back.

During:

  1. One channel, one log, timestamps on everything. The incident that starts mid-cutover is solved by this log.
  2. Checkpoints with go/no-go times, agreed in advance. Past the point of no return is a place you enter on purpose, announced, never discover.
  3. Nobody improvises fixes on the new estate mid-window. Improvisations are how a cutover becomes an incident with two crime scenes.

After, and this is where checklists usually go quiet:

  1. The old system goes read-only, not off. It gets its decommission date separately, weeks later, after the ledgers agree.
  2. Reconciliation runs daily for the first cycle: a full business cycle, including month-end. Most divergence hides in the batch calendar, not the request path.
  3. The checklist itself gets thirty minutes of honesty: what did we hit that wasn't on it? Add it. The list is the asset; the cutover was just this quarter's test of it.

Two rules govern all twenty-two lines. Boring is the goal: a cutover that makes a good story was a bad cutover. And the window is the wrong place to discover facts: every discovery belongs in the rehearsal, which is why we run old and new in parallel long before anyone touches DNS on a Saturday night.

Print it. Tape it up. Argue with it in daylight, not at 2 a.m.