🇮🇪Ireland
16°C Partly Cloudy · Dublin
Live Updates
--:--:-- IST
Writer Login
Latest
Ireland Has the Capital and the Lessons: Digital Project Management Is How They Become Delivery Dunbar Pharma Brings First Plant-Derived Dronabinol API to UK Market Through IPS Pharma Leveraging Priya Life Science as a Data Tracker: The Ultimate Use Case & Career Guide The €100K Reality Check: Why a Six-Figure Pharma Salary in Ireland Feels Different Than in Switzerland or Germany Ireland's €93.8 Billion Non-EU Pharma Export Engine: Trade Data, Destination Markets, and Economic Impact The Pharmacist's Role: How Community Pharmacies in Ireland and the UK Are Adapting as Patients Bypass High-Street Stores for Direct Delivery GLP-1 Therapeutics and Clinical Research Updates: Brain Reward Mapping, Oral Small Molecules, and Triple-Agonist Horizons Rinn Pharma & Biopharma Joins NordicPharmaTrain Network to Accelerate European Research & Advanced Manufacturing Ireland Has the Capital and the Lessons: Digital Project Management Is How They Become Delivery Dunbar Pharma Brings First Plant-Derived Dronabinol API to UK Market Through IPS Pharma Leveraging Priya Life Science as a Data Tracker: The Ultimate Use Case & Career Guide The €100K Reality Check: Why a Six-Figure Pharma Salary in Ireland Feels Different Than in Switzerland or Germany Ireland's €93.8 Billion Non-EU Pharma Export Engine: Trade Data, Destination Markets, and Economic Impact The Pharmacist's Role: How Community Pharmacies in Ireland and the UK Are Adapting as Patients Bypass High-Street Stores for Direct Delivery GLP-1 Therapeutics and Clinical Research Updates: Brain Reward Mapping, Oral Small Molecules, and Triple-Agonist Horizons Rinn Pharma & Biopharma Joins NordicPharmaTrain Network to Accelerate European Research & Advanced Manufacturing
Industry

AI Will Not Rescue Ireland's Over-Budget Health IT Projects. Pharma-Grade Governance Might.

Sreepriya Prasannan
Sreepriya Prasannan
Sreepriya Prasannan
Reviewed for editorial accuracy Sreepriya Prasannan — Founder & Editor · MSc Digital Transformation of Life Sciences
Our standards
Speed:
AI Will Not Rescue Ireland's Over-Budget Health IT Projects. Pharma-Grade Governance Might.

Key Takeaways

  • Ireland is about to run the largest digital project in the history of the health service: a National Electronic Health Record that the HSE has estimated at 1.5 to 2 billion euro across six regions over seven to eight years. Procurement was approved by Government on 5 February 2026.
  • The State's record on health IT is the reason to worry. PPARS grew from a 9.1 million euro estimate to 195 million euro before it was suspended. The 2021 Conti attack sat undetected on HSE systems for 57 days, with roughly 30,000 Windows 7 machines and no Chief Information Security Officer in post.
  • None of those failures were technology failures. The Comptroller and Auditor General and PwC both traced them to governance: no fixed budget linked to deliverables, weak sponsor authority, ignored warnings and an estate that evolved rather than being designed.
  • AI planning and monitoring tools inherit the baseline they are given. A forecast built on an optimistic scope produces an optimistic forecast faster. The Infrastructure Guidelines already require a full risk assessment and an explicit adjustment for remaining optimism bias; the gap is in enforcement, not in tooling.
  • Irish pharma and MedTech sites already run computerised systems under GAMP 5, EU Annex 11 and the FDA's 2025 Computer Software Assurance guidance. That discipline (user requirements, risk-based validation, change control, audit trails and a named accountable owner) is the transferable asset the public sector needs, and the people who practise it are in Ireland today.

Every consulting firm in Dublin is selling artificial intelligence to the health service this year. Predictive scheduling, generative documentation, AI-assisted project controls, dashboards that promise to see cost overruns before they happen. The pitch lands well because the client has a genuine problem: the HSE is entering the most expensive digital programme it has ever attempted, and its track record on large IT projects is poor. But the pitch also contains a quiet fallacy. Irish health IT projects have not gone wrong because managers lacked information. They have gone wrong because the governance around them was too weak to act on the information they had. Adding a smarter dashboard to a weak governance structure produces a well-informed failure.

This article makes a different argument. The discipline the public sector needs already exists in Ireland, in the pharmaceutical and medical-device plants that sit within an hour of most hospitals. Those sites run validated computerised systems under regulatory frameworks that force exactly the behaviours PAC and the Comptroller and Auditor General keep asking for. The talent and the method are here. The question is whether the State will use them.

The money and the scrutiny

On 5 February 2026 the Minister for Health announced Government approval for the HSE to begin the procurement phase for the National Electronic Health Record, following completion of a Preliminary Business Case and independent external assurance under the State's Infrastructure Guidelines. The Department of Health described it as the largest digital transformation project in the history of the health service. In October 2024 the HSE's Chief Technology and Transformation Officer told a Dublin conference that the first regional deployment alone would exceed 200 million euro in capital spend and that the full programme was expected to cost between 1.5 and 2 billion euro over seven to eight years across the six Health Regions, starting with Dublin and North East.

That sits inside a wider Digital for Care 2030 framework: the HSE Health App with more than 200,000 downloads and 122,000 registered users, the Maternal and Newborn Clinical Management System live in five maternity hospitals, a National Shared Care Record scaling through 2026, and virtual wards. Each of those is a multi-vendor integration programme in its own right.

The scrutiny is proportionate to the money. The National Children's Hospital, originally costed at under one billion euro and now expected to reach roughly 2.24 billion euro including commissioning, has become the Public Accounts Committee's permanent case study in how a major project escapes its budget. In April 2026 the committee heard that legal fees alone had reached 5.3 million euro and that the hospital would not treat patients before 2027. A Big Four partner advising the HSE on the EHR knows precisely what an appearance before that committee looks like, and knows that the words "we had an AI dashboard" would be no defence.

Why Irish health IT projects blow out

Ireland does not need international literature to understand cost overruns in health technology. It has two domestic case files, and both were investigated in detail by the State's own auditor.

PPARS: no budget, no accountable owner

The Personnel, Payroll and Related Systems project began in 1997 as a 9.1 million euro human-resources and payroll system for the health boards. By the time the HSE suspended it in October 2005, the projected cost had reached 195 million euro, and the system was live for only a fraction of the workforce. The Comptroller and Auditor General's December 2005 report did not find a technology defect. It found that there was no definitive overall budget extending over the life of the project which linked money to deliverables, that project management lacked adequate authority, that board attendance was inconsistent and personnel changed frequently, and that 57 million euro had gone to consultants, of which 38.5 million euro went to a single firm. The report also found no evidence that the system would ever cost less than the manual processes it was replacing.

Every one of those findings describes a governance gap. Scope grew because nobody with authority was required to say no. Cost grew because no baseline tied spend to delivery. The consultants delivered what they were asked to deliver, which is the point: an external advisor cannot supply the client with a sponsor.

The 2021 cyberattack: warnings that nobody owned

On 18 March 2021 an HSE employee opened a malicious Excel attachment. The Conti ransomware was not deployed until 14 May, a gap of 57 days during which, according to PwC's independent post-incident review, antivirus software flagged Cobalt Strike and Mimikatz activity on 31 March but was set to monitor mode, hospital servers and domain controllers were compromised between 7 and 10 May, and a security provider emailed about unhandled threats across more than 16 systems the day before encryption. PwC found roughly 30,000 Windows 7 workstations past end of life, no Chief Information Security Officer and no security operations centre, and described an IT estate that had evolved rather than been designed for resilience. The Comptroller and Auditor General put the direct response cost at 58 million euro in 2021 and estimated that almost 657 million euro over seven years would be needed to bring security up to standard.

Again, the failure was not the absence of information. Alerts were generated. They were not owned by anyone with the authority and the obligation to act.

ProjectOriginal estimateOutcomeRoot cause identified by the auditor or reviewer
PPARS (HSE payroll and HR)9.1 million euro (1997)195 million euro projected; suspended October 2005No lifetime budget linked to deliverables; weak project authority; inconsistent board oversight (C&AG, 2005)
HSE Conti ransomware responseNot applicable58 million euro response cost in 2021; 657 million euro over seven years to remediateLow security maturity; no CISO; alerts ignored for 57 days; legacy estate (PwC, 2021; C&AG, 2022)
National Children's HospitalUnder 1 billion euroAbout 2.24 billion euro including commissioning; opening now expected 2027Scope and design changes, contract disputes, optimistic early estimates (PAC hearings 2019 to 2026)
National Electronic Health Record1.5 to 2 billion euro (HSE estimate, 2024)Procurement approved February 2026; first region Dublin and North EastNot yet known. This is the project the lessons are for.

The AI illusion

AI project-control tools do three things well. They forecast schedule and cost from historical performance, they surface anomalies in large data sets faster than a human can, and they draft the reporting that consumes so much of a programme office's week. All three are useful. None of them addresses the two failure modes above.

First, a forecasting model is only as honest as its baseline. If the approved business case carries an optimistic scope and a schedule that assumes six health regions will behave identically, the model will project confidently from that assumption. The output looks rigorous because it is numerical. It is the same optimism bias with a better user interface. The Infrastructure Guidelines, which replaced the Public Spending Code in December 2023, already require that the final business case include a full risk assessment and consideration of remaining optimism bias. That requirement is a human judgement about how wrong the estimate is likely to be. No vendor tool performs it.

Second, anomaly detection without ownership is the cyberattack story again. The HSE had monitoring in 2021. What it lacked was a named person whose job it was to act on the alert and who had the authority to stop clinical systems if necessary. An AI layer that generates more alerts into the same structure produces more ignored alerts.

Third, and this is the part senior partners at the Big Four already know, AI tooling changes the client's perception of risk. A programme that has "AI-enabled controls" in its governance pack feels safer to a steering committee than one that does not. That feeling is exactly the moment at which scope discipline slips.

What pharma already does that public bodies do not

There is a sector in Ireland that has been forced, by law, to solve the governance problem for computerised systems. Every pharmaceutical, biologics and medical-device manufacturer operating under EU GMP Annex 11, the FDA's 21 CFR Part 11 and the ISPE GAMP 5 framework (second edition, 2022) must demonstrate that any system affecting product quality or patient safety is specified, risk-assessed, tested in proportion to that risk, changed only under documented control, and owned by a named process owner and a named system owner. In September 2025 the FDA finalised its Computer Software Assurance guidance, which pushes the industry further toward critical thinking and risk-based assurance rather than paperwork for its own sake. HPRA inspectors and FDA investigators audit against these expectations on Irish sites every year.

The comparison with typical public-sector IT delivery is uncomfortable.

Governance elementRegulated life-science site (GAMP 5, Annex 11, CSA)Typical large public IT programme
RequirementsApproved User Requirements Specification before purchase; every requirement traceable to a testRequirements evolve through procurement and delivery; traceability often reconstructed later
RiskDocumented risk assessment per function drives how much testing is done; high-risk functions get the most scrutinyRisk register maintained; rarely determines the depth of assurance on individual functions
Change controlNo change without impact assessment, approval and re-verification; scope creep is a compliance findingChange requests approved by steering committees under delivery pressure; cumulative impact seldom re-baselined
OwnershipNamed process owner and system owner accountable to inspectors by nameSenior Responsible Owner role exists on paper; turnover and shared accountability dilute it
Audit trailWho changed what, when and why is a regulatory requirement for the life of the systemDecision records exist but are dispersed across vendors, minutes and email
Supplier assessmentVendor audited before selection; vendor evidence reused only where verifiedProcurement scoring; limited technical audit of the supplier's own quality system

None of this is exotic. It is Tuesday afternoon for a validation engineer in Ringaskiddy, Grange Castle or Westport. The reason it works is not the documentation. It is that the framework makes one person accountable for each decision, forces the risk conversation to happen before money is spent, and treats an unapproved change as a failure rather than as agility.

The sceptical project leader

The skill set the EHR programme, and the consultancies advising it, actually need is therefore not fluency with AI dashboards. It is the willingness and the standing to challenge a client. In practice that means four things.

  • Reference-class forecasting before the model. Before any predictive tool is switched on, the baseline should be corrected against how comparable EHR deployments in comparable health systems actually performed on cost and time. The Infrastructure Guidelines ask for this adjustment for optimism bias. The leader's job is to insist it is done honestly, and to put the adjusted number in front of the steering committee even when the unadjusted one is more welcome.
  • Stage gates with real kill authority. The Guidelines define three decision gates and route major projects through the Major Projects Advisory Group at 200 million euro and above. Gates only work if the sponsor can and will stop a project at one. A gate that has never once returned a project for rework is a ceremony.
  • Change control that re-baselines. Every approved scope change on a multi-region programme should trigger a fresh forecast, in the way a validated system requires re-verification after a change. The AI tool is useful here, provided the change is forced through it rather than around it.
  • Named ownership of alerts. The lesson of 2021 is that monitoring without an owner is theatre. Each class of programme risk, whether cyber, clinical safety, vendor performance or budget, needs one accountable individual whose obligation to escalate is written down.

Those are auditor's instincts and validation engineer's instincts. They are, not coincidentally, the instincts of the people who sit on the other side of the table at an Oireachtas committee.

What this means for consulting firms and public bodies

For the Big Four and the wider advisory market, the commercial implication is direct. The firms that win and keep the HSE's trust on the EHR will be the ones whose delivery leads can say no to the client and document why. Hiring for that profile means looking beyond generalist project managers toward people who have run validated systems under regulatory inspection: computerised-system validation leads, quality and compliance managers, and regulatory-affairs professionals who have written the change-control procedure rather than read about it. Ireland has thousands of them. Many are non-EU nationals on Critical Skills permits, which is one more reason the sector should care how the State treats them.

For the HSE and the Department of Health, the implication is that the EHR's governance model should borrow explicitly from the regulated industry next door: a URS-style requirements baseline agreed before shortlisting is complete, a risk-proportionate assurance plan for each clinical function, a change-control board with the authority to refuse, and a published audit trail of major decisions. HPRA already knows how to inspect against those things. There is no reason a public digital programme could not be held to the same standard.

AI will make the EHR programme's reporting faster and its forecasts more granular. It will not make anyone braver. The projects on the PAC's list did not fail for lack of data. They failed because the structure around them let optimistic assumptions survive contact with evidence. Fixing that is a human job, and the humans who already do it work in Irish pharma.

Frequently Asked Questions

How much will Ireland's National Electronic Health Record cost?

The HSE has publicly estimated between 1.5 and 2 billion euro for the full programme across six Health Regions over seven to eight years, with the first regional deployment in Dublin and North East expected to exceed 200 million euro in capital spend. Government approved the move to procurement on 5 February 2026 after external assurance under the Infrastructure Guidelines.

What is optimism bias in public projects?

It is the systematic tendency of project sponsors and estimators to understate costs and timelines and overstate benefits. Ireland's Infrastructure Guidelines require the final business case for a major project to include a full risk assessment and an explicit consideration of remaining optimism bias, which in practice means adjusting estimates against the real outcomes of comparable projects.

What is GAMP 5 and why is it relevant to public health IT?

GAMP 5 is the ISPE's good-practice framework for validating computerised systems in regulated life-science manufacturing. Its second edition (2022) and the FDA's 2025 Computer Software Assurance guidance emphasise risk-based, critical-thinking assurance with named ownership and controlled change. Those are precisely the governance elements that Irish auditors found missing in PPARS and in the run-up to the 2021 cyberattack.

Did the 2021 HSE cyberattack happen because of old technology?

Old technology contributed: PwC found around 30,000 Windows 7 machines past end of life. But the review's central findings were organisational: no Chief Information Security Officer, no security operations centre, and alerts generated over 57 days that were not acted on. Better tooling would not have helped without someone accountable for responding.

Can AI project-management tools reduce cost overruns?

They can improve forecasting and surface anomalies earlier, but only if the baseline they are fed has been corrected for optimism bias and if the programme has a governance structure that acts on what the tool reports. Without those two conditions, AI produces faster, more confident versions of the same errors.

Sources: Department of Health press release, 5 February 2026 (Government approval to commence EHR procurement); Pulse+IT report of HSE CTTO remarks, October 2024 (EHR cost and timeline estimates); Comptroller and Auditor General special report on PPARS, December 2005, as reported by The Irish Times; PwC, Conti cyber attack on the HSE: Independent Post Incident Review, December 2021, as reported by Krebs on Security; Comptroller and Auditor General, Financial impact of cyber security attack, September 2022, as reported by RTÉ; Public Accounts Committee hearings on the National Children's Hospital, April 2026, as reported by RTÉ; Department of Public Expenditure, NDP Delivery and Reform, Infrastructure Guidelines, December 2023; FDA, Computer Software Assurance for Production and Quality System Software, final guidance, September 2025; ISPE GAMP 5 second edition, 2022. This article is editorial analysis.

About the Author
Sreepriya Prasannan

Sreepriya Prasannan

Writer at Priya Life Science · Industry

Sreepriya Prasannan is the Founder and Editor of Priya Life Science, Ireland's independent pharma, biotech and MedTech platform. She holds an MSc in Digital Transformation (Life Science) from Griffith College Dublin, with a background in QA, GMP and production operations. Shortlisted for STEM Graduate of the Year at the Business Post Women in STEM Awards 2026 and a Top 14 finalist in the HSE Spark Ignite 2026 innovation programme, she writes on regulatory trends, GMP compliance and careers across the Irish and European life sciences.

Discussion
No comments yet. Be the first to share your thoughts!
Leave a Comment