## Use of Technology in Tax Administrations 1: Developing an Information Technology Strategic Plan (ITSP)

## Source details

**Canonical URL:** [Use of Technology in Tax Administrations 1: Developing an Information Technology Strategic Plan (ITSP)](https://www.imf.org/-/media/files/publications/tnm/2017/tnm1701.pdf)

## Other formats

- [Markdown version](/-/media/files/publications/tnm/2017/tnm1701.pdf.md)
- [Structured JSON version](/-/media/files/publications/tnm/2017/tnm1701.pdf.json)

---

### Purpose, scope, and audience
- Technical Guidance Note 1 of 3 addressing IT themes relevant to tax administrations.
- Focus: developing an ITSP for developing country tax administrations that are largely manual or have legacy/outdated IT systems.
- Intended audience: tax administrations with no technology or limited/outdated technology (Category 1 and Category 2); may also interest more advanced administrations.
- Exclusions: does not address other business systems (payroll, finance, document, and asset management systems).
- Related notes: selecting an IT system for core tax administration functions (note two) and implementation of a commercial-off-the-shelf (COTS) system (note three).

### Key questions addressed
- What questions and issues must be considered when developing an IT strategy?
- What is the link between the IT strategy and the organizational strategic plan?
- What functionality should the IT strategy aim for?
- What is an ITSP, why is it important and when should it be developed?
- Who should be involved in developing the strategy and in what roles?
- Should an ITSP address Risk Management issues?

### Rationale: importance of IT
- IT is central to handling increasing taxpayers, larger information volumes, transparency, efficiency, and responsiveness.
- Traditional manual means are inadequate; effective IT use is required.
- IT investment forms a significant part of administrations’ budgets and must be carefully managed.
- Note focused on administrations in early stages of IT adoption; Appendix 1 summarizes typical stages of technology introduction.

### Key decision issues when developing an IT strategy
- Define a "future state" vision to identify gaps between current and desired operations.
- Core decision questions and considerations:
  - What does the administration want from new technology?
  - What does the tax administration actually need?
    - Core needs: registration, processing, payment and accounting, plus audit targeting and debt collection.
    - Readiness for e-services: e-filing, e-payments, data sharing, self-help portals.
    - Community IT skills, electricity supply, internet and mobile coverage.
  - Affordability:
    - Basic core systems with hardware and communications networks will start at more than USD$10 million, even for a small administration.
  - Provider choice:
    - Shift from custom-built systems to COTS systems that can be configured and implemented progressively.
  - Timing:
    - Excluding procurement, a target of three years is reasonable; a two-year timespan can be achieved in ideal situations but is not typical.
  - Organizational readiness:
    - Technology introduction impacts staff, taxpayers, tax professionals, government, and business processes; develop a change management strategy early.
  - Other considerations:
    - Physical environment, day-to-day support, ongoing maintenance and license costs, security requirements, IT organization for management and planning.

### Link between IT strategy and organizational strategic plan
- Organizational strategic plans typically cover 3-5 years and set corporate outcomes.
- IT strategy must have a clear "line of sight" to corporate outcomes and link to other operational plans (e.g., compliance plan, operations plan).
- Illustrative planning hierarchy: Strategic Plan → Information Systems Strategic Plan → National annual plans / Corporate Plan / Compliance Improvement Strategy → Sub-national plans.

### Recommended functionality and sequencing
- Core system ("heart" of administration): integrated suite supporting Taxpayer Registration, Returns Processing, Taxpayer and Revenue Accounting, Payment Processing.
- Sub-systems/modules to consider:
  - electronic filing;
  - case management and workflow for debt collection and audit;
  - analytical capability for audit selection;
  - individualized taxpayer service;
  - revenue forecasting.
- Build incrementally on the core; introduce enhancements only when the administration and environment are ready (avoid mandating e-filing if internet access is lacking).
- Assess initiatives on cost/benefit for taxpayers and the administration.

### What is an ITSP: definition and typical coverage
- An ITSP sets out how IT will be used to achieve corporate outcomes; it addresses process modernization and organizational change as well as technical matters.
- Describes IT needs in "from – to" terms.
- Typical ITSP coverage includes:
  - management and governance arrangements;
  - hardware, software, technical platform and environment;
  - cost projections for capital and expense;
  - human capital management;
  - vendor/supplier management;
  - risk management;
  - change management;
  - stakeholder management and communications;
  - information management;
  - security provision and management;
  - other enterprise IT environment considerations (distribution of capability, accommodation, etc.).
- ITSP may include guiding principles for IT decision-making (see Appendix 2 examples).
- Inventories of software, hardware, communications standards are commonly placed in appendices or separate documents.

### Variations by administration maturity
- Less experienced administrations:
  - High-level objectives (e.g., establish core systems for registration, processing, accounting).
  - Emphasis on forming an IT organization, governance and management arrangements.
  - Identification of physical barriers (connectivity, internet availability).
  - Use high-level statements for communication and funding approvals; develop detailed plans later for procurement.
- More advanced administrations:
  - Greater definition of ambitions (e.g., integrating disparate systems, wider self-service options).
  - ITSP may focus on implementing an integrated suite or specific enhancements.

### Common ITSP contents (Box 1)
- Aims, objectives, and scope and relation to Corporate strategies.
- Governance and management arrangements for the IT organization.
- Description of overall organizational IT needs and dependencies.
- Current and future state descriptions with a transition approach (From – To statements).
- Business model for IT provision (In-house; outsourced; combined approach) and rationale.
- Resource requirements summary:
  - staffing (skills and numbers);
  - budgets both capital and expense;
  - summary of key projects;
  - timing (aligned to key reforms, capacity and funding).
- Assessment of internal capabilities and needs.
- External dependencies affecting IT (overall government rules and strategies).
- Risk Management approach.

### Implementation planning and major initiatives
- If ITSP identifies significant changes (e.g., replacement or establishment of core processing system(s)), include a separate transition approach and plan for the initiative.
- Common practice: engage an experienced IT executive to assist constructing a detailed ITSP; business desire frames requirements while IT technical capability designs the solution.

### Tailoring the ITSP to maturity and purpose (Section 2 highlights)
- ITSP must address particular issues faced by the administration; not "one size fits all."
- Inexperienced administrations:
  - Focus on availability of skilled IT staff in-country and pay/retention challenges.
  - May need to outsource IT development and maintenance; sourcing strategies are critical.
- More advanced administrations:
  - Focus on IT sourcing strategies, whether to build or buy an integrated system, or move systems to the next level.
- Role of the ITSP:
  - Reference point for operational plans and centerpiece for raising funds (through capital investment plans).
  - Public document intended for stakeholder access; common practice is a summary-style document for external engagement and a detailed ITSP for procurement and implementation guidance.

### Planning horizon and refresh
- ITSP looks forward for a period of three to five years, refreshed annually to maintain a rolling three to five year horizon.
- Annual refresh aligns ITSP with organizational strategy, business environment, and technology trends.
- Annual process accounts for unforeseen changes (government policies, delays in IT implementation), and new IT developments.
- Major projects (e.g., core system replacement) may need a longer planning horizon.

### Roles and stakeholders
- Strong leadership required; CIO10 and CTO11 (alternatively IT Director) should work closely with:
  - administration executive bodies;
  - information managers;
  - business owners;
  - budget and legal sections;
  - other user groups (e.g., staff associations).
- Infrastructure providers12 must be consulted to ensure technical proposals can be met.
- External organizations (Ministry of Finance/Treasury and information exchangers13) should be included.
- Participation of external bodies (accounting professionals, chambers of commerce, taxpayer groups) helps identify future IT needs and impacts.

### Risk management in the ITSP
- ITSP should address risks to availability, integrity, and confidentiality of infrastructure, business continuity, and data holdings.
- Cover security, disaster recovery, backup, and restore policies.
- Recommended risk policy/regime example: ISO27000 series.
- Risk management steps:
  1. identify risks;
  2. assess risks;
  3. mitigate risks;
  4. develop response plans; and
  5. review risk management procedures.
- Due to confidential nature, detailed risk identification, assessment, and treatment should be in a separate document from the ITSP.

### Stages in a typical technology reform program (Appendix I)
- Progression of taxpayer-facing technology capabilities:
  - Informational: one-way interaction for self-assessment compliance and transparency.
  - Education: supply tax laws, regulations, rulings, forms, guides, annual reports.
  - Traceability: allow taxpayers to follow status of interactions (refunds, audits).
  - Transactional: two-way interactions for obligations and core processes.
  - Submission of information: e-registration, e-filing, e-third-party information, e-accounting.
  - Interaction with third parties: e-payment, e-procurement.
  - Services to compliance: third-party disclosures, crosschecks, pre-populated returns.
  - Interoperability: real-time data gathering via IT interfaces.
  - Tax determination from accounting systems: common data definitions and rules across entities.
  - E-tax audit and e-crosscheck: automate enforcement processes.
  - E-invoicing: align tax and commercial transaction platforms.
  - Single window across government entities: streamline citizen-government interactions.
- Successful progression depends on capacity to manage compliance and harness enabling technology.

### Example IT guiding principles (Appendix II)
- Business requirements drive IT; business process owners must review processes before IT enablement.
- IT projects are prioritized and coordinated via IT governance.
- Understand total cost (implementation and ongoing support) before deciding.
- Balance risk of new technology against potential benefits.
- IT decisions should maximize benefit to the revenue system.
- IT investments are corporate assets and must be managed accordingly.
- Ensure appropriate system security and treat information as an asset.
- Aim for “one version of the truth” (collect once, access many times).
- Design systems for reuse; minimize overlapping technologies/products.
- Anticipate and maintain responsiveness to end users.
- Address disaster recovery in every IT solution implementation plan.
- Hardware/OS should operate within one version of the latest released software.
- Prefer commercially developed package software when possible over bespoke builds.

### Sample ITSP template and organizational content (Appendix III and IV highlights)
- Sections commonly included:
  - Aims and objectives; Scope.
  - Governance and management arrangements.
  - Organizational IT needs and dependencies.
  - Current and future state descriptions.
  - Business model (in-house, outsourced, combined) and rationale.
  - Resource requirements summary:
    - Staffing (skills and numbers).
    - Budgets (capital and expense).
    - Summary of key projects.
    - Timeframes (aligned to key reforms, capacity, and funding).
  - Internal capabilities and capability gaps.
  - External dependencies (government rules, country infrastructure, business IT capacity).
  - Risk management approach.
- Detailed ITSP examples include: IT vision/objectives, current and future portfolios, “make versus buy” decision, IT organization, IT infrastructure, security, business continuity/disaster recovery, implementation considerations, indicative delivery plan and preliminary schedule, costing, and review mechanisms.

*Source: Technical Notes and Manuals 17/01 — Use of Technology in Tax Administrations 1: Developing an Information Technology Strategic Plan (ITSP), Margaret Cotton and Gregory Dark, Fiscal Affairs Department, INTERNATIONAL MONETARY FUND*

### Section 1

### Use of Technology in Tax Administrations 1: Developing an Information Technology Strategic Plan (ITSP)

### Purpose and scope
- This Technical Guidance Note is the first of three addressing information technology themes and issues relevant to tax administrations.
- Focus: developing an Information Technology Strategic Plan (ITSP) for developing country tax administrations that are largely manual or have legacy IT systems that are outdated.
- Intended audience: tax administrations with no technology or limited/outdated technology (Category 1 and Category 2); may also interest more advanced administrations.
- Exclusions: does not address other business systems (e.g., payroll, finance, document, and asset management systems).
- Related notes in the series cover: selecting an IT system for core tax administration functions (note two) and implementation of a commercial-off-the-shelf (COTS) system (note three).

### Key questions the TNM addresses
- What questions and issues must be considered when developing an IT strategy?
- What is the link between the IT strategy and the organizational strategic plan?
- What functionality should the IT strategy aim for?
- What is an ITSP, why is it important and when should it be developed?
- Who should be involved in developing the strategy and in what roles?
- Should an ITSP address Risk Management issues?

### Rationale: importance of IT for revenue administration
- IT is central to effective tax administration to handle increasing taxpayers, larger volumes of information, transparency, efficiency, and responsiveness.
- Traditional manual means are inadequate; effective IT use is required.
- Investment in IT now forms a significant part of administrations’ budgets and must be carefully managed.
- The note is focused on administrations in early stages of IT adoption; Appendix 1 summarizes typical stages of technology introduction.

### Issues and decision questions for developing an IT strategy
- Define a "future state" vision to identify gaps between current and desired operations.
- Key decision questions:
  - What does the administration want from new technology?
  - What does the tax administration actually need?
    - Core needs may be registration, processing, payment and accounting, plus functions like audit targeting and debt collection.
    - Consider readiness of business and government environment for e-services (e-filing, e-payments, data sharing, self-help portals).
    - Assess community IT skills, electricity supply, internet and mobile coverage.
  - Can the IT system be afforded, and who will pay?
    - Basic core systems with hardware and communications networks will start at more than USD$10 million, even for a small administration.
  - Who will provide the IT system?
    - Shift from custom-built systems to Commercial-Off-The-Shelf (COTS) systems that can be configured and implemented progressively.
  - How long will procurement and implementation take?
    - Excluding procurement, a target of three years is reasonable; a two-year timespan can be achieved in ideal situations but is not typical.
  - Can the administration use a new system effectively?
    - Technology introduction impacts staff, taxpayers, tax professionals, government, and business processes; a change management strategy should be developed early.
  - What else is involved?
    - Physical environment, day-to-day support, ongoing maintenance and license costs, security requirements, IT organization for management and planning.

### Link between IT strategy and organizational strategic plan
- Organizational strategic plans usually cover 3-5 years and set corporate outcomes.
- IT strategy must have a clear "line of sight" to corporate outcomes and link to other operational plans (e.g., compliance plan, operations plan).
- Planning document hierarchy (illustrative): Strategic Plan → Information Systems Strategic Plan → National annual plans / Corporate Plan / Compliance Improvement Strategy → Sub-national plans.

### Recommended functionality and sequencing
- Core system ("heart" of administration): integrated suite supporting Taxpayer Registration, Returns Processing, Taxpayer and Revenue Accounting, Payment Processing.
- Sub-systems/modules: electronic filing, case management and workflow for debt collection and audit, analytical capability for audit selection, individualized taxpayer service, revenue forecasting.
- Build incrementally on the core; introduce enhancements only when the administration and environment are ready (e.g., don’t mandate e-filing if internet access is lacking).
- Assess initiatives on cost/benefit for taxpayers and the administration.

### What is an ITSP: definition, purpose, and typical coverage
- An ITSP sets out how IT will be used to achieve corporate outcomes; it is not purely technical and addresses process modernization and organizational change.
- Describes IT needs in "from – to" terms (examples provided in text).
- Typical ITSP coverage includes:
  - management and governance arrangements;
  - hardware, software, technical platform and environment;
  - cost projections for capital and expense;
  - human capital management;
  - vendor/supplier management;
  - risk management;
  - change management;
  - stakeholder management and communications;
  - information management;
  - security provision and management;
  - other enterprise IT environment considerations (distribution of capability, accommodation, etc.).
- The ITSP may include guiding principles for IT decision-making; Appendix 2 contains example guiding principles.
- Inventories of software, hardware, communications standards are commonly in appendices or separate documents.

### Variations in ITSP detail by administration maturity
- Less experienced administrations:
  - High-level objectives (e.g., establish core systems for registration, processing, accounting).
  - Emphasis on forming an IT organization, governance and management arrangements.
  - Identification of physical barriers (connectivity, internet availability).
  - Use high-level statements for communication and funding approvals; develop detailed plans later for procurement.
- More advanced administrations:
  - Greater definition of ambitions (e.g., integrating disparate systems, wider self-service options).
  - ITSP may focus on implementing an integrated suite or specific enhancements.

### Common contents of an ITSP (Box 1 summary)
- The aims, objectives, and scope of the strategy and relation to Corporate strategies.
- Governance and management arrangements for the IT organization.
- Description of overall organizational IT needs and dependencies.
- Current and future state descriptions with a transition approach (From – To statements).
- Description of the business model for IT provision (In-house; outsourced; combined approach) and rationale.
- Resource requirements summary:
  - staffing (skills and numbers);
  - budgets both capital and expense;
  - summary of key projects;
  - timing (aligned to key reforms, capacity and funding).
- Assessment of internal capabilities and needs.
- External dependencies affecting IT (e.g., overall government rules and strategies).
- Risk Management approach.

### Implementation planning and major initiatives
- If the ITSP identifies significant changes (e.g., replacement or establishment of the core processing system(s)), the ITSP should additionally describe the initiative and provide a separate transition approach and plan.
- It is common to engage an experienced IT executive to assist in constructing a detailed ITSP; business desire frames requirements while IT technical capability is essential to design.

*Source: Technical Notes and Manuals 17/01 — Use of Technology in Tax Administrations 1: Developing an Information Technology Strategic Plan (ITSP), Margaret Cotton and Gregory Dark, Fiscal Affairs Department, INTERNATIONAL MONETARY FUND*

### Section 2

### Section 2 — IT Strategy Planning and Supporting Materials

### Tailoring the IT Strategic Plan (ITSP) to maturity and purpose
- ITSP contents must be framed to address the particular issues an administration faces rather than being a “one size fits all” document.
- Inexperienced administrations:
  - Need to focus on the availability of skilled IT staff in their country.
  - Must consider whether it is possible to create an IT organization within the administration due to issues such as pay disparities between the public and private sectors.
  - May have little option but to outsource IT development and maintenance; sourcing strategies are a key discussion point.
- More advanced administrations:
  - May focus on IT sourcing strategies, how to move systems to the next level, or whether to build or buy an integrated system.
- Role of the ITSP:
  - Serves as a reference point for operational plans and the centerpiece for raising funds for implementation (through a capital investment plan where present).
  - Provides the rationale for any proposed investment.
  - Is intended to be a public document; all stakeholders should have ready access and it should be “pitched” accordingly.
  - Common practice: promote a summary-style document as the first level of interaction, from which the detailed document can be accessed if desired.
  - The summary ITSP may be used for communications seeking funding and general stakeholder engagement.
  - The more detailed ITSP is used for procurement and to guide development of the preferred system.

### Planning horizon and refresh process
- The ITSP looks forward for a period of three to five years, but is refreshed annually in line with the organizational strategy, so an administration always has a three to five year horizon for decision-making.
- Annual refresh ensures continual alignment with the business strategy, business environment, and technology trends.
- The annual process takes into account unforeseen changes (e.g., government policies, delays in IT implementation), and new IT developments.
- For major projects such as replacement of core systems, an even longer planning horizon may be needed.

### Who should be involved and roles
- Creating an IT strategy requires strong leadership; where existing, the Chief Information Officer (CIO)10 and Chief Technology Officer (CTO)11 (alternatively the IT Director) need to work closely with:
  - the administration executive bodies,
  - information managers,
  - business owners,
  - budget and legal sections,
  - other user groups such as staff associations within the organization.
- Infrastructure providers12 must be part of consultations to ensure technical proposals can be met.
- Closely associated external organizations such as the Ministry of Finance or Treasury should be included in consultations, as will the wider network of agencies/information exchangers.13
- Participation of external bodies such as accounting professionals, chambers of commerce, and taxpayer groups can improve understanding of future needs requiring IT solutions and impacts on their internal systems (e.g., e-filing systems, information exchange, payroll tax).

### Should the ITSP address risk management?
- It is important that an ITSP addresses risks to the organization relating to technology, including threats to physical infrastructure, business continuity, and data holdings, summarized as pertaining to: availability, integrity, and confidentiality.
- Issues to cover: security, disaster recovery, backup, and restore policies.
- Recommended risk management policy/regime: e.g., International Organization for Standardization (ISO)27000 series.
- The risk management process essentially follows these five steps:
  1. identify risks;
  2. assess risks;
  3. mitigate risks;
  4. develop response plans; and
  5. review risk management procedures.
- Due to its extremely confidential nature, detailed identification, assessment, and treatment program of risks should be compiled in a document separate from the ITSP.

### Stages in a typical tax administration technology reform program (Appendix I)
- Information technology is changing taxpayer interactions and enabling modernization to digital interactions (e-registration, e-filing, e-payment, e-invoicing, e-accounting, self-help portals).
- Tax administrations should adopt new technologies systematically to support business direction and compliance initiatives, aiming to maximize taxpayer compliance and minimize compliance costs.
- Identified stages and sub-stages:
  - Informational: discrete one-way interaction to enable self-assessment compliance and greater transparency.
  - Education: provide all tax-related information—laws, regulations, ruling, forms, guides, annual reports, etc.
  - Traceability: allow taxpayers to follow the status of interactions with tax administrations—e.g., refund claims and audits.
  - Transactional: two-way interactions for taxpayers to meet obligations and the administration to perform core processes; some discrete, others in real-time.
  - Submission of information: e.g., e-registration, e-filing, e-third-party information, e-accounting, etc.
  - Interaction with third parties: e-payment, e-procurement, etc.
  - Services to compliance: third-party information disclosure, crosschecks, pre-populated tax returns, etc.
  - Interoperability: IT interfaces enabling interactive real-time data gathering, taxpayers’ compliance, and RDs’ core operations.
  - Tax determination from accounting systems: step beyond pre-populated returns that may allow optional tax returns—requires common data definitions and rules across entities.
  - E-tax audit and e-crosscheck: automating enforcement processes to make them more transparent.
  - E-invoicing: aligning tax and commercial transaction platforms, including sales/purchases activity.
  - Single window across government entities: streamlining the relationship with citizens.
- Successful progression relies on the tax administration’s capacity to manage taxpayers’ compliance and harness enabling technology.

### Example IT guiding principles (Appendix II)
- The business requirements drive IT and are key to the future of the IT environment.
- Each business process is owned by the business and must be reviewed for appropriateness and performance before considering IT enablement or further automation.
- All projects involving IT resources are prioritized and coordinated via an IT governance process.
- The total cost of an IT solution, both implementation and ongoing support needs, is understood before a final decision is made.
- The risk of adopting new technology is balanced against the potential benefits of the new innovative technology.
- IT decisions provide maximum benefit to the revenue system as a whole.
- IT investments are recognized as corporate assets and are managed and maintained accordingly.
- Appropriate system security is in place so that information and systems are protected from unauthorized use and disclosure.
- Information is recognized as an asset and must be managed accordingly.
- As much as possible there should be “one version of the truth,” e.g., collect data once but access it many times and through multiple avenues.
- IT systems are designed and implemented allowing for possible reuse by other business processes.
- The number of different technologies and products providing the same or similar service is minimized.
- Appropriate responsiveness to end users is anticipated and maintained.
- Every IT solution has disaster recovery addressed as part of the implementation plan.
- Hardware and operating systems operate in an environment where the software is only one version behind the latest released one.
- Commercially developed package software should be purchased whenever possible, rather than building specific software products just for the tax administration.

### Sample ITSP template and organizational content (Appendix III and IV highlights)
- Aims and objectives: describe the aims and objectives of the IT strategy and how it relates to corporate strategies.
- Scope: describe what the IT Strategy will and will not cover.
- Governance and management arrangements: describe internal IT structure and governance framework/process for IT issues.
- Organizational IT needs and dependencies: describe what the tax administration needs from IT systems and what is needed for success.
- Current and future states: describe current state of IT (staff, hardware, software, policies, management and governance, and risks) and the desired future state.
- Business model: describe in-house, outsourced, or combined approach and rationale (availability, affordability, staff remuneration retention issues, etc.).
- Resource requirements summary:
  - Staffing (skills and numbers).
  - Budgets both (capital and expense).
  - Summary of key projects.
  - Timeframes (aligned to key reforms, capacity, and funding).
- Internal capabilities and needs: existing internal capability and capability needed in the new IT environment.
- External dependencies: overall government rules and strategies, country infrastructure, community and business IT capacity, etc.
- Risk management approach: describe the risks and measures to address them.
- Example detailed ITSP and anonymized examples include structured sections for: IT vision/objectives, current and future portfolios, “make versus buy” decision, IT organization, IT infrastructure, security, business continuity/disaster recovery, implementation considerations, indicative delivery plan and preliminary schedule, costing, and review mechanisms.

*Source: tnm1701 - Section 2*

---


_Source: https://www.imf.org/-/media/files/publications/tnm/2017/tnm1701.pdf_
