Three Lessons from the OIOS Digital Transformation Evaluation for the AI Era

The 2026 OIOS evaluation shows that a central challenge of digital transformation in the United Nations Secretariat is institutional, not only technological. For the AI era, the three priorities are one shared direction, reusable and sustainable digital foundations, and measurement tied to mandate outcomes rather than tool usage.

Three Lessons from the OIOS Digital Transformation Evaluation for the AI Era

Published 2026-09-18 · By Shahzad Asghar

The 2026 OIOS evaluation shows that a central challenge of digital transformation in the United Nations Secretariat is institutional, not only technological. For the AI era, the three priorities are one shared direction, reusable and sustainable digital foundations, and measurement tied to mandate outcomes rather than tool usage.

The United Nations has no shortage of digital activity. The harder question is whether that activity adds up to institutional transformation.

The May 2026 evaluation by the Office of Internal Oversight Services gives a useful answer. It found important progress across the United Nations Secretariat. It also exposed a familiar pattern in large organizations: useful solutions exist, committed people are pushing change forward and leadership support is visible, yet strategy, architecture, funding, measurement, user involvement and organizational ownership remain uneven.

That matters even more as organizations move from conventional digital systems into generative AI, AI assistants and increasingly autonomous workflows.

Here are three lessons I take from the evaluation.

What the OIOS digital transformation evaluation covered

The OIOS Inspection and Evaluation Division report, *Evaluation of Digital Transformation in the United Nations Secretariat* (IED-25-016), was issued on 11 May 2026. It assessed digital transformation activity from 1 January 2020 through 30 June 2025 across 41 Secretariat entities. Peacekeeping missions were excluded because a separate evaluation was planned.

The evidence base was unusually broad:

  • 41 Secretariat entities were included.
  • 2,259 staff responded to the survey.
  • 37 entities reported 1,217 digital initiatives.
  • OIOS conducted 11 senior leadership interviews and 57 business process owner interviews.
  • Twenty-eight initiatives across 23 entities received in-depth review.
  • Six group discussions involved 106 participants.

The evaluation therefore provides more than a snapshot of technology deployment. It shows how a large international institution organizes, funds, governs and measures digital change.

The findings at a glance

OIOS findingEvidence reportedAI-era implication
Strategic direction was fragmentedFour of 38 assessed entities had a specific digital transformation strategy or roadmap; 23 submitted no relevant strategy documentAn AI use-case list cannot substitute for an institutional operating model
Shared foundations were limited22% of submitted initiatives used joint technology platforms and 26% used shared digital infrastructureCommon AI services should be reused across mission-specific applications
Funding was uncertain54% of surveyed staff disagreed that digital transformation funding was sufficientAI services need lifecycle funding for models, data, hosting, assurance and support
User involvement was uneven36% agreed that user needs were considered during designAI cannot repair a process that was designed without its users
Accessibility was not systematicFive of 28 initiatives reviewed in depth included accessibility featuresAccessibility and inclusion must be requirements, not post-launch additions
Benefits were difficult to demonstrateMost non-OICT initiatives lacked systematic performance and benefit measurementAI must be measured against operational and mandate outcomes, not query volume

Lesson 1: Digital transformation needs one institutional direction

One of the strongest findings in the report is surprisingly basic.

The Secretariat had significant commitment to a digital agenda, but it did not have one common definition or framework for digital transformation. Staff interpreted the subject differently, and only a small number of entities had an explicit strategy or roadmap.

Only four of the 38 entities assessed had developed a specific digital transformation strategy or roadmap. Others relied on ICT strategies, data strategies, UN 2.0 plans or innovation strategies, while 23 submitted no relevant strategy document.

This distinction matters.

Buying technology is not digital transformation.

Moving a paper form online is useful, but it does not necessarily change how an organization works.

Building a dashboard does not necessarily improve a decision.

Adding an AI assistant does not automatically change programme delivery.

The starting point should therefore not be, "What technology should we deploy?"

The better questions are:

  • What organizational problem are we solving?
  • Which mandate result should improve?
  • Which process needs to change?
  • Who owns that process?
  • What data is required?
  • How will systems exchange that data?
  • How will we know that the change produced a better result?

This is also where the division of responsibility between business functions and IT becomes important.

Business owners should own the outcome, process change, requirements, adoption and benefits.

IT should own or govern architecture, integration, cybersecurity, platforms, technical standards, data interfaces and service sustainability.

Senior management should own prioritization, funding and accountability.

Digital transformation fails when it becomes an IT workplan with occasional consultation from business units. It also fails when individual business units buy technology independently without regard for architecture, security, data and long-term support.

The OIOS report points toward the same institutional response. It calls for a common definition, clear strategic direction at entity level, stronger ICT project-management arrangements and an organization-wide performance measurement system. My broader digital transformation strategy for humanitarian organizations sets out how those responsibilities can work as one operating model.

The AI implication

AI makes this issue more serious.

Traditional system fragmentation creates duplicate databases and applications. AI fragmentation can create duplicate models, separate knowledge stores, inconsistent prompts, uncontrolled access to organizational information, separate vendor contracts and conflicting answers to the same institutional question.

An organization entering the AI era therefore needs more than an AI use-case list. It needs a common operating model covering business ownership, approved AI services, data access, identity, cybersecurity, human oversight, model risk, information classification, procurement, monitoring and accountability.

Without that foundation, organizations can move very quickly while still moving in different directions. This is why AI governance in the United Nations must connect policy to architecture and operational decision rights.

Lesson 2: Design for reuse, interoperability and sustainable operations

The OIOS evaluation found 1,217 digital initiatives across 37 entities. They ranged from SharePoint sites and dashboards to AI-enabled applications, natural-language processing, forecasting systems and other advanced technologies.

That number demonstrates activity.

It does not demonstrate institutional maturity.

OIOS found that many solutions were highly customized, operated independently and had limited interoperability. Approximately 22% used joint technology platforms and 26% relied on shared digital infrastructure. Even where teams knew similar systems existed elsewhere, they frequently proceeded independently.

The result is familiar to anyone who has managed a large IT portfolio:

  • Several teams solve the same problem.
  • Each project has its own funding.
  • Each system has its own data model.
  • Each solution has its own vendor or technology stack.
  • Integration comes later, if at all.
  • Maintenance becomes somebody else's problem.

The report also identifies the funding problem behind this pattern. Fifty-four per cent of surveyed staff disagreed that financial resources for digital transformation were sufficient. Many solutions depended on extra-budgetary or redirected funding, creating uncertainty around licensing, data, hosting and maintenance after project funding ended.

This suggests a different way to manage a digital portfolio.

Before approving a new solution, an organization should ask:

  • Does this capability already exist elsewhere?
  • Can an existing platform be reused?
  • Can an API provide the required service?
  • Can one shared component serve several departments or field operations?
  • Does the solution comply with enterprise architecture?
  • Who pays for year three, not just year one?
  • Who owns support after the original project team moves on?
  • Can another office deploy the same solution without rebuilding it?

These questions are less visible than launching a new application, but they determine whether digital investments survive.

The AI implication

Departments may face pressure to build their own chatbot, document assistant, knowledge-search system or AI agent.

That model will become expensive very quickly.

A more sustainable approach is to establish common AI services where appropriate. These may include approved model access, identity and access management, common API gateways, retrieval services, search infrastructure, audit logging, security controls, evaluation methods and usage monitoring.

Business units can then build mission-specific applications on common institutional services.

The principle is simple: reuse the platform and differentiate through the business process, approved data and user experience.

Common services must not become uncontrolled central access to every dataset. Access control, information classification and purpose limitation still follow the data. The AI security and assurance framework explains why exposure usually sits in data paths, permissions and agent authority rather than in the model alone.

Lesson 3: Measure mandate outcomes, not the number of tools

The OIOS report identifies perhaps the most important management weakness.

Most digital initiatives outside the Office of Information and Communications Technology lacked systematic methods for measuring benefits. Many depended on page views, logins, Google Analytics or informal user feedback. Those measures were rarely connected to organizational performance or user outcomes.

This creates a serious management problem.

A system can have thousands of users and still fail to improve the underlying process.

A dashboard can have hundreds of views and still have no influence on decisions.

A high-volume AI assistant can still give poor answers.

Usage is evidence of activity. It is not evidence of value.

The report shows that staff perceived significant benefits from digital tools. Among respondents who reported results from integrating digital tools into work processes, 89% cited time savings, 54% reported more seamless collaboration, 50% identified improved data-driven decision-making and 42% reported cost savings.

Those are useful signals. Organizations should now move from perceived benefits toward systematic benefit measurement.

From usage measures to outcome measures

Measurement levelExampleManagement question
Process outcomeProcessing time reduced from ten days to threeDid the workflow become materially faster?
Service outcomePercentage of requests resolved at first contactDid users receive a better service?
Programme outcomeDecision time reduced during an emergency responseDid the change improve mandate delivery?
Financial outcomeCost per completed transaction before and after implementationDid total operating cost change?
User outcomeCompletion rate, error rate, accessibility and satisfactionCould intended users complete the task successfully?
Risk outcomeSecurity, privacy or compliance exceptionsDid institutional exposure increase or decrease?
Adoption outcomeIntended users regularly following the new processDid behavior change, or was only a tool deployed?

AI requires additional measures:

  • Accuracy and unsupported-answer rate
  • Human correction and escalation rates
  • Cost per completed task
  • Response time and service availability
  • Access-control violations and sensitive-information exposure
  • Performance across languages and user groups
  • Percentage of AI recommendations accepted, changed or rejected by accountable staff

Most importantly, organizations should measure whether AI improves the underlying programme or operational result.

The report also found weaknesses on the user side. Only 36% of surveyed respondents agreed that user needs were considered during solution design. Accessibility was also inconsistent: only five of the 28 initiatives reviewed in depth included accessibility features.

AI will not correct a poorly designed process. In some cases, it will make that process faster without making it better.

The management lesson is therefore to put users, process owners and measurable outcomes into the design process from the beginning. A structured AI use-case intake form can help establish the owner, affected users, decision consequences, data requirements and success measures before development starts.

What the OIOS report is really telling leaders

The report does not describe a technology problem.

It describes an institutional management problem.

The Secretariat has people willing to experiment. It has hundreds of digital initiatives, visible leadership interest and growing digital skills. OIOS found more than 400 entity-delivered training sessions and more than 100 Secretariat-wide courses, although capability remained uneven.

The next stage requires stronger institutional mechanisms around that activity:

  • A clear strategy
  • Business ownership
  • Enterprise architecture
  • Shared platforms
  • Predictable financing
  • User involvement and accessibility
  • Digital and AI competencies
  • Cybersecurity and responsible AI controls
  • Portfolio governance
  • Outcome measurement

The report's opportunities for improvement point in the same direction. They call for clearer strategic direction, organizational skills assessment, sustained leadership support, a central repository of digital solutions, systematic user feedback, stronger ICT project-management arrangements and an organization-wide performance measurement system.

The AI era does not make those lessons obsolete.

It makes them more urgent.

Generative AI can reduce the cost and time required to produce new digital solutions. Organizations will soon face more applications, more experimentation and more technology choices, not fewer.

The organizations that manage this well will not necessarily be those with the most AI pilots. They will be those that can decide what should be built, what should be shared, what should be stopped, who is accountable, how risk is managed and whether the investment is producing measurable results.

That is the point where digital transformation becomes institutional change rather than a collection of technology projects.

What leaders should do now

  1. Establish one definition of digital transformation tied to mandate outcomes.
  2. Require every initiative to name a business owner, technical owner and accountable executive.
  3. Review the portfolio for duplicate capabilities before approving new AI tools.
  4. Define common services for identity, model access, retrieval, logging, evaluation and security.
  5. Fund the complete service lifecycle, including data, hosting, assurance, maintenance and exit.
  6. Involve intended users and accessibility specialists before architecture and procurement decisions become fixed.
  7. Measure process, service, programme, financial, user and risk outcomes from an agreed baseline.

Frequently asked questions

What was the 2026 OIOS digital transformation evaluation?

It was an evaluation by the United Nations Office of Internal Oversight Services of digital transformation across 41 UN Secretariat entities. It examined activity from January 2020 through June 2025 using a staff survey, document review, information on 1,217 initiatives, interviews and group discussions.

What were the main findings of the OIOS evaluation?

OIOS found extensive digital activity and perceived operational benefits, but uneven strategic direction, fragmented solutions, limited interoperability, uncertain funding, inconsistent user involvement, weak accessibility and limited outcome measurement.

Why does the OIOS evaluation matter for AI adoption?

AI can increase the speed and number of digital initiatives without resolving fragmented ownership, architecture, data, funding or accountability. The evaluation's management lessons therefore become more important as entities introduce AI assistants, retrieval systems and autonomous workflows.

Who should own digital transformation in a UN entity?

Executive leadership should own prioritization and accountability, business leaders should own process outcomes and benefits, and IT and digital leaders should govern architecture, platforms, integration, cybersecurity and sustainable operations. No single function can deliver institutional transformation alone.

How should organizations measure AI-enabled transformation?

They should measure the operational or mandate outcome first, then track AI-specific quality and risk measures such as unsupported answers, human corrections, escalations, cost per completed task, language performance and access-control violations.

What is the difference between digital activity and digital transformation?

Digital activity produces tools, dashboards, online forms and pilots. Digital transformation changes an operating process, its ownership, information flows, decisions and measurable results. A large number of tools can coexist with limited institutional transformation.

What should UN leaders do after the OIOS digital transformation evaluation?

Leaders should set one definition of transformation linked to mandate outcomes, assign an accountable executive and business owner to every initiative, reuse common services before funding new tools, protect lifecycle funding, involve users and accessibility specialists early, and measure operational, user and risk outcomes from a baseline. For AI, those controls must also cover approved model access, data permissions, evaluation, logging and human accountability.

Primary source

Office of Internal Oversight Services, *Evaluation of Digital Transformation in the United Nations Secretariat*, report IED-25-016, 11 May 2026.

Key evidence locations in the report: scope and methodology on pages 3-4; strategic direction on pages 5-6; interoperability, funding and accessibility on pages 17-19; benefit measurement on page 20; and opportunities for improvement on page 22.

Written by Shahzad Asghar — Head of Data and Digital Solutions at UN-ESCWA, with 20+ years building AI and data systems across UNHCR, UNICEF, and UNOCHA. His team built UNHCR’s first global IVR appointment system, serving 700,000+ refugees. He created the Last-Mile AI Framework. Read more about this UN AI expert

← All articles