Cross-Agency AI Coordination
Maria Delgado runs the analytics program at a mid-sized state Department of Labor. In March her team built a model that flags likely unemployment insurance fraud. It worked. Then she learned the state Department of Revenue had built a nearly identical model eight months earlier, on better data, under a vendor contract Maria could have ridden for free. Two teams, two budgets, two privacy reviews, and two sets of bias complaints waiting to happen. Her director's question was fair and it stung: why are we paying twice to solve the same problem?
That question is the whole subject of this lesson. As a program manager you rarely get to invent the perfect model from scratch. Your real leverage is coordination: borrowing what another agency already built, sharing what you build, and writing the agreements that make sharing legal and safe. Done well, cross-agency coordination is the cheapest performance gain available to you. Done badly, it is a series of polite meetings that produce nothing and a calendar full of standing invitations nobody can cancel.
Coordination is load-bearing, not optional
Government AI work rarely stays inside one agency. Veterans benefits decisions touch the veterans department, the social security administration and the tax authority. Border operations touch customs, immigration, transportation security, the state department and health agencies. Climate resilience work touches weather, emergency management, environmental, transport and agriculture bodies. Cyber defense touches the national cyber agency, the signals agency, the investigative agency and every organization's own security officer. An AI leader who tries to operate inside the boundary of a single agency is misreading the job.
The moment a system needs data from another agency, uses a vendor another agency also uses, or produces decisions that shape a citizen's dealings with a second agency, coordination becomes load-bearing. The pattern that separates agencies that cope from agencies that do not is timing. Those that invest in coordination infrastructure before they need it operate smoothly. Those that try to stand it up during an incident, a media story or an audit discover that the relationships, the agreements and the escalation paths all take longer to build than the crisis allows.
The three things agencies actually share
Coordination sounds abstract until you name the goods being moved. There are three, and they have very different rules. Getting the classification right in the first conversation determines which lawyer you need, which instrument you sign, and whether the exchange takes a week or three quarters. Most coordination that fails, fails because someone reached for the wrong instrument for the goods in question and then spent months discovering it.
Models. An algorithm or trained system another agency has already validated. The Revenue Department's fraud model is the example. Reusing a model can save six to twelve months and a six-figure vendor build. But a model trained on Revenue's taxpayers may behave differently on Labor's claimants, so you inherit their assumptions and their population, not just their code. Reuse is a head start on the build, never a substitute for your own validation.
Data. The fuel. Revenue's wage records would make Maria's model far more accurate. Data is also the hardest thing to share, because privacy law, the original collection purpose and the terms under which the public handed it over all travel with it. Most failed coordination dies here, and it usually dies late, after months of work on the assumption that the data would arrive.
Practices. The cheapest and most underrated: vendor evaluations, bias testing checklists, a privacy review template, a record of which prompts leaked sensitive information. Sharing a hard-won lesson costs nothing and carries almost no legal risk. Start here. If you cannot share the data yet, share the lesson today, because practices move at the speed of a phone call and data moves at the speed of a lawyer.
Why government coordination is genuinely hard
Private companies struggle to share across business units. Government has all of those problems plus three more that are baked into how agencies are funded and governed. Naming them explicitly is useful, because each one has a specific remedy and none of the three is solved by goodwill. Coordination that relies on two program managers liking each other survives exactly as long as both stay in post.
First, appropriations are siloed. Maria's budget is authorized for Labor's mission, and spending it to help Revenue raises legal questions about whether funds are being used for their appropriated purpose. The remedy is a written reimbursable arrangement rather than a handshake. Second, data was collected for a specific purpose. Wage data gathered to administer unemployment insurance cannot automatically be repurposed to train a model for another program, and privacy law plus program-specific statutes constrain the reuse. Third, nobody owns the seam between agencies, so coordination only happens when someone is explicitly tasked and resourced to make it happen.
Knowing the landscape before you need it
Federal AI leaders operate inside a standing set of coordination bodies, and knowing which one owns which question saves weeks. The chief information officer council, convened at the central budget office, coordinates technology policy across agencies and runs AI-focused working groups. A council of chief AI officers, established under OMB memorandum M-24-10, convenes those officers to share practice, coordinate use case inventories and feed recommendations upward. A science and technology council subcommittee coordinates federal AI research and development, including the national AI research resource pilot. A chief data officer council, established by evidence-based policymaking legislation, coordinates data governance including AI training data.
Alongside those sit the operational bodies. The federal acquisition service hosts the government-wide schedules and the cloud authorization program. The national cyber agency coordinates security incidents across civilian agencies, including AI-specific ones. The defense department's digital and AI office coordinates defense AI. The national standards institute maintains the AI risk management framework and its community of practice. A privacy council and state, local, tribal and territorial coordination bodies cover the remaining seams. Named councils are chartered, merged and renamed over time, so confirm the current roster rather than assuming this list is durable.
Each body has a charter, a meeting cadence, and either decision or recommendation authority. Have a named liaison in your agency for each one, even if the same person covers several. Participation is the cost of admission, and reading minutes without attending misses the working-group conversation where the actual work happens. Agencies that participate actively get vendor intelligence sooner, get an early read on guidance, and help shape standards they will later be measured against. Agencies that sit out are measured without their input, which is a worse position than disagreeing loudly.
Why participation pays, and what policy requires
Policy pushes in the same direction as self-interest. OMB memorandum M-24-10, issued in 2024, requires agencies to publish AI use case inventories and to coordinate with peer agencies where use cases overlap. The 2023 executive order on artificial intelligence directed agencies to coordinate on AI workforce, use case selection and risk management; treat that as historical context, since executive orders are revoked and replaced, and treat the underlying obligation as the durable part. Security incident coordination expectations have moved the same way, with agencies increasingly expected to share indicators and vulnerability intelligence rather than hold them.
The deeper argument is that coordination is how government AI learns. No single agency can see the whole vendor landscape, independently evaluate foundation models at the scale the technology now demands, or afford to repeat evaluation work that central bodies already perform. An AI officer who declines to participate in the interagency councils and framework working groups is making their agency poorer by refusing intelligence the public has already paid for. The standard interagency case studies, including a national passenger screening program, a health insurance exchange launch and a shared identity service, are studied precisely because their failures and recoveries were about coordination rather than about technology.
The mechanisms, from lightest to heaviest
Match the mechanism to the goods. Reaching for a formal agreement to swap a checklist wastes months, while relying on a verbal promise to move regulated data invites a breach and an inspector general finding. The list below runs from the lightest instrument to the heaviest, and the professional skill is picking the lightest one that is actually sufficient rather than the heaviest one that is definitely safe.
- Community of practice. A standing group of practitioners who trade lessons. No legal instrument needed. Best for sharing practices and warning each other off a vendor before the contract is signed.
- Memorandum of understanding. A written statement of shared intent and roles. Good for committing to collaborate, naming points of contact and setting expectations. It documents agreed commitments without creating contractual obligations, and it is not usually sufficient on its own to move regulated data or money.
- Interagency or reimbursable agreement. The instrument that lets one agency pay another or buy off a shared contract. This is how Maria could ride Revenue's vendor deal legally rather than running her own procurement.
- Data sharing or data use agreement. The specific, lawyer-reviewed document that authorizes data to cross the boundary, naming exactly which fields, for which purpose, with which protections, for how long, and what happens at the end.
- Shared service. A central provider runs the capability once for many agencies. Highest effort to stand up, lowest marginal cost per agency once it exists, and the only option that removes the duplication permanently rather than case by case.
The legal and financial instruments in detail
The architecture for interagency work is more flexible than most career staff realize. The Economy Act at 31 USC 1535 is the most common instrument. It allows one agency to order goods or services from another when the head of the ordering agency determines that the order is in the government's interest, that the services cannot be acquired as conveniently or cheaply by contracting commercially, and that the performing agency can reasonably deliver. Those are three separate determinations, all of them documented in writing with specific terms, and the middle one is where most orders get challenged.
Other financial routes exist. A franchise fund operating under government management reform legislation lets a service-providing agency deliver administrative and technology capabilities to others on a fee-for-service basis without the Economy Act's commercial-alternative test. Assisted acquisition services let an agency use another organization's contracting expertise instead of building its own. Electronic government legislation encourages shared services and is the statutory foundation for government-wide platforms such as the shared identity service that many agency systems now sit behind. Paperwork reduction requirements at 44 USC 3506 oblige agencies collecting similar information from the public to coordinate centrally, which makes that a mandatory path for AI systems that survey or query citizens.
Data sharing carries the heaviest legal freight. A system of records notice under the Privacy Act may need to be modified before the exchange is lawful. A computer matching agreement under 5 USC 552a(o) may be required where records are compared across programs. Agency-specific statutes impose their own constraints: tax information under 26 USC 6103, education records under the federal education privacy statute, health information under the federal health privacy rule. A team that assumes it can simply pull data across an agency boundary is headed for a Privacy Act complaint, and the assumption usually surfaces after the model has already been built.
The practical accelerant is a template library. Agencies that maintain cleared, previously negotiated versions of their agreements move dramatically faster than agencies that start from a blank page each time, because the negotiation shifts from drafting language to filling in fields. Build the library from the agreements you have already executed, get counsel to bless the templates once, and treat each new negotiation as an opportunity to improve them rather than as an isolated event.
The sequence that makes data sharing work
Data sharing is where interagency AI coordination earns its keep and also where it most often fails, so the order of operations matters more than the speed. The right sequence is: identify the specific data elements you need, rather than requesting a table; determine the statutory and regulatory basis for the exchange; execute the necessary agreements, which may include a records notice, a matching agreement, a memorandum and a data use agreement; implement technical safeguards proportionate to the sensitivity of the data; and establish monitoring so that compliance is continuous rather than asserted once at signing.
Notice what that sequence rules out. It rules out building the model first and papering the data flow afterwards, which is the most common failure and the hardest to unwind, because by then a program has a working demonstration and a sunk cost arguing against the lawyer. It also rules out the vague request. An ask for a partner agency's dataset invites a slow no, while an ask for six named fields for one stated purpose with a retention limit invites a negotiation. Specificity is not bureaucratic caution here. It is the thing that makes the answer yes.
Joint vendor management
When the same vendor serves multiple agencies, coordination produces leverage no single agency can achieve alone. Vendor performance feedback shared through interagency councils lets agencies compare notes before a contract is signed and pool intelligence about performance problems afterwards. Cloud authorization leveraging lets an agency inheriting an existing authorization avoid repeating the full authority to operate process, which is one of the largest single time savings available in government technology. A government-wide schedule for AI acquisition, which the source for this lesson dates to 2024, consolidates common purchases and offers a standard contractual baseline to build on.
When a shared vendor has a performance failure or a security incident, a coordinated response among affected agencies produces a unified message that is much harder to ignore than agency-by-agency complaints arriving separately over six weeks. The supporting discipline is an interagency working group: named representatives from each agency, a written charter, a documented decision process and a recurring cadence. Avoid the ad hoc pattern in which coordination happens only when something breaks, because that pattern is slow, conflict-prone, and tends to reward the agency that shouts loudest rather than the one with the strongest mission case.
When an incident crosses agency lines
An AI incident that spans agencies is the moment coordination either pays for itself or visibly does not exist. The national cyber agency coordinates incidents across civilian agencies, and that role now extends to AI-specific incidents. An AI officer whose agency experiences an incident touching a shared vendor or shared data should notify that coordinating body within the 72-hour window many agencies now require, participate in joint root cause analysis, and contribute to a public after-action account where that is appropriate. Confirm your own agency's actual reporting deadline, which may be considerably shorter than 72 hours for major incidents.
The instinct to contain an incident internally is understandable and usually wrong when the incident is not internal. Keeping quiet about a vendor failure that affects three other agencies compounds the incident, because those agencies continue operating an affected system while you investigate, and it costs credibility that you will need at the next coordination table. The reputational calculation that feels protective in the first hour is nearly always the wrong one by the second week.
Build it yourself or consume a shared service
The strategic move over the next few years is consuming shared services rather than building bespoke. A central platform spreads the cost of security accreditation, monitoring and compliance across every tenant. When a government-wide platform has already cleared a security authorization, a new agency can stand on that work instead of repeating a one to two year accreditation. The trade-off is less customization and a dependence on the provider's roadmap. As a rule: build only what is core to your specific mission, and consume everything that is common infrastructure.
Concrete examples of the positive case are easy to find. Central AI advisory bodies offer model evaluation and pilot design support that small agencies could never fund alone. Shared evaluation of foundation models spares every agency from repeating the same tests. Defense shared inference and training infrastructure avoids duplicating capital-intensive capability across components. A shared identity service means individual agency systems do not each build their own. The discipline is to evaluate the shared service fairly against building your own, document the trade-off, and, when you choose the shared service, design your agency-specific pieces to integrate cleanly rather than to fight it.
Coordinating below the federal level
Federal AI systems often touch state and local operations, particularly in health, education, law enforcement and emergency management, where the federal role is to fund and set rules while the delivery happens somewhere else entirely. Federal engagement programs for state, local, tribal and territorial partners exist for exactly this seam, as does the long-standing coordination between emergency management agencies at each level. A federal team designing a system that state or local staff will actually operate should engage those partners during design, not at rollout.
Three things need explicit attention in that relationship. Document the federal-state data relationship, including who holds what and under whose authority. Plan for the different privacy and public records regimes that apply at each level, since a record protected federally may be disclosable under a state sunshine law. And budget for the fact that this is slow work. It is also the only route by which a federally sponsored AI system delivers value at the point where a citizen actually meets government.
A coordination playbook you can run
Before launching any AI build, Maria now runs the scan below. It takes about a week and routinely saves quarters. The order matters: the first two steps are free, the third determines the cost of everything that follows, and skipping the fourth is what turns a promising collaboration into a legal problem discovered at the worst possible moment.
- Search first. Check published government AI use case inventories and ask your peers directly. Is someone already solving this? Agencies publish inventories specifically so that you can find them.
- Classify the goods. Are you moving a model, data or a practice? This single decision determines everything downstream, including which instrument and which reviewer you need.
- Pick the lightest sufficient mechanism. Practice means a community of practice. Money or a shared contract means an interagency agreement. Data means a data sharing agreement and the review chain that comes with it.
- Loop in counsel and privacy early. If data crosses the line, your privacy officer and your lawyers are on the critical path. Engage them in week one, not week ten.
- Name a single accountable owner on each side. Coordination without named owners is a meeting series with a distribution list.
- Write down the protections. Purpose limits, retention, security controls and end-of-life handling. Vague agreements fail audits and are unenforceable in the moment they matter.
- Validate the borrowed asset on your own population. A model that is fair on Revenue's taxpayers may be biased on Labor's claimants. Re-test before you trust it, and write down what you tested.
A reusable coordination decision record
Use this template to document each coordination opportunity as you evaluate it. It becomes your audit trail, your handoff document when the program manager changes, and the evidence you need when an oversight body asks why you did or did not reuse something that already existed elsewhere in government.
| Field | What to capture | Example |
|---|---|---|
| Opportunity | What you want to share or reuse | Reuse Revenue's fraud detection model |
| Goods type | Model, data or practice | Model, plus practice: their vendor evaluation |
| Partner & owner | Agency and named accountable person | Dept. of Revenue, J. Okafor, Analytics Lead |
| Legal basis | Authority that permits the exchange | Interagency agreement; data use agreement for wage fields |
| Mechanism | Lightest sufficient instrument | Agreement to ride vendor contract; community of practice for lessons |
| Protections | Purpose limit, retention, controls | Wage data: fraud detection only, 18 month retention, encrypted |
| Revalidation | How you confirm fitness for your use | Bias test on Labor claimant sample before go-live |
| Est. savings | Time and dollars avoided | About 8 months and about $240K vendor build avoided |
Maria filled out one row for the fraud model. The estimated savings cell, eight months and roughly a quarter of a million dollars, was what turned her director's frustration into a standing instruction to coordinate by default on every future build. The record also did something less obvious: it made the decision reviewable. When an auditor later asked why Labor had not simply built its own, the answer was a document rather than a memory.
Anti-Patterns
- The parallel silo. Each agency builds its own version of a capability that would be more efficiently shared. The federal identity landscape before a shared login service is the canonical case: every agency ran its own identity management at enormous aggregate cost and poor experience for the public. The remedy is to evaluate shared services seriously and document the trade-off rather than defaulting to build-your-own.
- The undocumented handshake. Agencies share data or coordinate on a vendor based on personal relationships without formal agreements. It works until a lawsuit, a public records request or a personnel change surfaces the informality, and the missing records notice or agreement becomes a legal problem. The remedy is template-based agreement workflows and a named interagency program manager who tracks the paperwork.
- The abandoned working group. A coordination body is chartered, meets enthusiastically for two months and slides into irrelevance, leaving a calendar invitation nobody can cancel. Working groups need clear charters, time-bounded deliverables and an escalation path when participation flags. The counter-example is a working group that produced visible guidance quickly and then closed.
- The escalation race. A shared vendor underperforms and each affected agency rushes to file its own complaint rather than coordinating. Sequential, separate complaints are easy for a vendor to absorb. A coordinated notice from several agencies at once is not, and the joint work builds the relationships you will need next time.
- The federal-only bubble. A federal team designs a system that state and local partners will actually execute, without involving those partners in design. The result briefs beautifully in the capital and fails at the counter. The remedy is early engagement through the established state and local coordination channels.
- The excluded inspector general. An oversight office is kept outside an interagency initiative and later issues a finding that could have been avoided by a conversation in month two. Bringing inspectors general in early is a sign of confident program management rather than a concession, and the interagency council of inspectors general exists as a route to do it.
- Borrowing without revalidating. Adopting another agency's model because it was already validated, then deploying it on a different population without testing. The other agency's validation is evidence about their claimants, not yours. Inheriting a model means inheriting its assumptions, and a fairness result does not transfer across populations by itself.
- Coordination as a meeting series. A recurring interagency call with no named owner on either side, no decision log and no deliverable. It generates a comforting sense of collaboration and produces nothing, and it is the most common form coordination takes precisely because it is the least uncomfortable.
Practice Prompts
- Run the search step for real. Take an AI project your organization is about to start. Spend two hours checking published use case inventories and calling two peer agencies. What did you find, and what would it have cost to find it out after the contract was signed?
- Classify three exchanges. Identify three things your organization currently shares or wants to share with another agency. Label each as a model, data or a practice, then name the lightest sufficient instrument for each. Which one is currently being handled with the wrong instrument?
- Draft the specific ask. Rewrite a vague data request as a named list of fields, a single stated purpose, a retention period and a set of protections. Would your counterpart's privacy officer be able to say yes to the rewritten version without escalating?
- Complete one decision record. Fill in every field of the coordination decision record for a real opportunity, including the legal basis and the revalidation plan. Which field did you have to guess at, and who owns the answer?
- Test the incident path. Assume a vendor your agency shares with two others has a security incident this afternoon. Who do you call, in what order, and what is your agency's actual reporting deadline? If you cannot answer in under a minute, that is the finding.
- Build one template. Take an agreement your agency has already executed and turn it into a cleared template with the fields marked. Get counsel to bless it once. Then measure how long the next negotiation takes compared with the last one.
Reflection
Think about the last capability your organization built from scratch. Would a phone call to a peer agency have changed the plan, and what stopped that call from happening? Consider which of the three goods your organization shares most easily and which it never shares at all, and whether that pattern reflects genuine legal constraint or simply the absence of an instrument nobody has drafted. Ask who in your agency currently owns the seam between you and your most important partner, and whether that person knows they own it. And if an inspector general asked next quarter why you had not reused something that already existed elsewhere in government, would your answer be a document or a memory?
Glossary
- Economy Act order. An interagency order under 31 USC 1535 in which one agency buys goods or services from another, subject to written determinations about government interest, comparative cost and the performing agency's capacity.
- Memorandum of understanding. A written statement of shared intent, roles and points of contact between agencies. It documents commitments without creating contractual obligations and rarely suffices on its own to move money or regulated data.
- Interagency or reimbursable agreement. The instrument that permits one agency to pay another for work performed, or to buy through a contract another agency has already competed.
- System of records notice. The published notice describing a set of records about individuals maintained by an agency, the purposes for which they are used, and the disclosures permitted. Sharing outside those terms may require the notice to be modified first.
- Computer matching agreement. The agreement required under 5 USC 552a(o) when records about individuals are compared across programs or agencies for specified purposes.
- Franchise fund. A revolving fund that allows one agency to provide administrative or technology services to others on a fee-for-service basis rather than through appropriated transfers.
- Authorization leveraging. The practice by which one agency inherits an existing cloud security authorization instead of repeating the full assessment, converting a multi-month process into a review.
- Shared service. A capability operated once centrally and consumed by many agencies, spreading the cost of accreditation, monitoring and compliance across every tenant.
- Coordinated cure notice. A performance notice issued jointly by several agencies affected by the same vendor failure, rather than separately and sequentially.
- SLTT coordination. Engagement with state, local, tribal and territorial partners who often operate the systems federal programs fund, and who work under different privacy and public records regimes.
Related Lessons
The organizational form that usually anchors this work is covered in Building AI Centers of Excellence, and Shared Services and Infrastructure Models goes deeper on the consume-versus-build decision. Cross-Agency Governance Coordination and Multi-Level Government AI Governance address the governance layer above the instruments described here, while Data Governance for AI and Privacy Impact Assessments for AI Systems cover the reviews that sit on the critical path of every data exchange. AI Use Case Inventory and Documentation (OMB M-24-10) is the search step's source material, Managing AI Vendor Performance and Third-Party AI Risk Management cover the shared-vendor problem in depth, and Data Infrastructure for Enterprise AI describes what you are actually plugging into once the agreements are signed. Bias Detection and Mitigation at Scale covers the revalidation you owe any model you borrow.
Closing
Coordination is unglamorous and it is the highest-leverage thing on your list. Nobody is promoted for the model they did not build, which is exactly why duplicated capability is so common and so expensive across government. The counterweight is process: search before you build, classify the goods before you pick an instrument, pick the lightest instrument that is actually sufficient, and document the decision so that the next person and the next auditor can both follow it.
Start with practices, because they are free and legally uncomplicated, and use the relationships they build to make the harder data conversations possible later. Maintain your template library so that the second agreement is faster than the first. And revalidate everything you borrow, because the one thing coordination cannot transfer is the population your model will actually meet. Maria's second model was somebody else's, and it was the best decision her program made that year.
Key Takeaways
- Coordination is your cheapest performance gain. Reusing a validated model or riding a shared contract can save quarters and six figures compared with building alone, and the search that finds them takes about a week.
- Name the goods first. Models, data and practices have different rules. Practices are nearly free to share, data is the hardest, and misclassifying the exchange is how coordination quietly fails.
- Match the mechanism to the goods. A community of practice moves lessons, an interagency or reimbursable agreement moves money and shared contracts, and a data use agreement plus its review chain is required to move regulated data.
- Government's hard parts are structural. Siloed appropriations, purpose-limited data and an unowned seam between agencies mean coordination needs an explicitly tasked owner, a written instrument and early legal engagement.
- Be specific when you ask for data. Named fields, one stated purpose, a retention limit and defined protections invite a negotiation. A request for a dataset invites a slow no.
- Coordinate before the incident, not during it. Relationships, agreements and escalation paths all take longer to build than a crisis allows, and an incident touching a shared vendor is not an internal matter.
- Consume shared services, build only what is core. Standing on an already-accredited platform spares a one to two year authorization, at the cost of customization and roadmap dependence. Document the trade-off either way.
- Revalidate anything you borrow. Another agency's fairness and accuracy results are evidence about their population. Re-test on yours before you trust it, and write down what you tested.
- Document every opportunity. A one-row decision record naming the legal basis, protections, revalidation plan and estimated savings is your audit trail and your business case in one document.
Frequently Asked Questions
Where do I even start looking for what already exists? Start with published AI use case inventories, which agencies maintain in part so that other agencies can find them, then call two peers directly. The inventory tells you what exists; the phone call tells you whether it worked, what it cost and what they would do differently. Budget about a week for the whole scan. Compared with a duplicated build, that is the cheapest week in the project.
Can we just sign a memorandum of understanding and start sharing data? Usually not. A memorandum documents intent, roles and contacts, which is genuinely useful, but moving regulated data typically also requires the underlying legal basis to be established: the applicable records notice may need to be modified, a matching agreement may be required where records are compared across programs, and program-specific statutes for tax, education or health information impose their own conditions. Treat the memorandum as the frame and the data agreement as the substance.
Our partner agency's lawyers are slower than ours. How do we speed this up? Be more specific and ask for less. Vague requests generate legal work because counsel has to imagine every use you might make of the data. A request naming six fields, one purpose, a retention period and the protections you will apply is a much smaller question. Beyond that, the durable fix is a template library on both sides, so the conversation starts from cleared language rather than a blank page.
How much can we rely on another agency's validation of a model? As evidence, not as clearance. Their testing tells you the model behaved acceptably on their population under their conditions, which is genuinely valuable information and a real head start. It does not tell you how it behaves on your claimants, your data quality or your edge cases. Plan and budget for revalidation on your own population before go-live, and document what you tested so that the next agency to borrow it inherits more than you did.
Is a shared service always the right answer? No, and the discipline is to run the comparison honestly rather than to default either way. Shared services spread accreditation, monitoring and compliance costs across tenants and remove duplication permanently, at the price of customization and a dependence on someone else's roadmap. Build what is genuinely core to your mission, consume what is common infrastructure, and document the trade-off so the decision can be revisited when either the mission or the service changes.
Who is responsible when a shared vendor fails? Each agency remains accountable for its own systems and its own public, which is precisely why coordination matters. Practically, that means agreeing in advance who convenes the affected agencies, who speaks to the vendor, what gets reported centrally and on what deadline, and how a joint notice is issued if one is needed. Working that out during a live incident is possible but expensive, and the cost is usually paid in credibility with the agencies you will need next time.
Skill.re