A payments switch replaced in nine cutovers
Nobody would sign off a single weekend, and they were right not to.
The program
| Sector | Banking and insurance |
|---|---|
| System age | 22 years |
| Daily volume | Tens of millions of authorisations |
| Scope | Switch replacement, nine phased cutovers |
| Duration | 16 months |
| Status | Complete. Old switch retired |
A payments switch is the least forgiving thing to replace, because it fails in a way customers notice within seconds and a regulator notices within hours. The client had a plan for a single weekend. It was a good plan and everybody who read it believed it, which is a different thing from it being safe.
What made a single window impossible was not the volume. It was that a rollback from a completed migration would itself have taken most of the window, so the decision to abort would have had to be made before there was enough evidence to make it. A plan in which the go/no-go arrives before the information is not a plan; it is a coin toss with a runbook attached.
So we split the traffic instead. Nine windows, each carrying one class of transaction, each small enough that the rollback was uninteresting — twenty minutes, rehearsed, with the old path still warm. The first was the hardest and took four rehearsals. By the fourth the client's own team was running it and we were watching from the back of the room.
The ninth window was the easiest thing anybody did all year. By then there was almost nothing left on the old switch, everybody in the room had done it eight times, and the interesting decisions had all been made months earlier.
By the fourth window the client’s own team was running it and we were watching. That is the point at which a program stops being ours.
>
— Yusuf Bramwell, Principal, Migration and Cutover

The old switch, dark
Nine windows later the old switch was taken out of service, the changeover panel set to one side, and a monthly line item that had been running for twenty-two years stopped.