HPSAI Transformation
Three-system WHPS private AI foundation Three on-premises systems stand inside one estate boundary and run models locally. From that foundation a governed path leads to member service, controlled release, and product outcomes. On-premises WHPS estate Programme-reported Local model runtime 3 systems Private AI Member service Governed release Product outcomes
WHPS private AI foundation Three-system count and 2024 timing are programme-reported. Geometry explains the transformation path; it is not installation evidence or a configuration diagram.

01Foundation2024

Private AI became physical.

Three on-premises NVIDIA DGX systems established a protected place to run AI. What the programme learned running it became the WHPS AI SDLC.

On-premises NVIDIA DGXWHPS foundation · 2024

02Operating proof2025

Infrastructure earned its value in member service.

Contact Center AI moved the programme from private compute to a production member-service position. The documented target architecture keeps a person responsible for the customer-facing decision.

Documented target operating architecture

  1. 01Approved channelVoice or authenticated service entry
  2. 02Intent + contextConversation state and allowed service context
  3. 03Retrieve + inferBounded execution inside the protected runtime
  4. 04Response controlPrivacy, confidence, policy, and fail-closed checks
  5. 05Human serviceAnswer, escalation, documentation, and quality review
3.6M
Member interactions in the late-2025 production stack
99.99%
Uptime stated for that production stack
Five call types
Handled on the current service path
Harness-tested target
Sandbox tests exercise fail-closed routes; this is not production activation

Technology ecosystem Wipro · NVIDIA · Cisco · Google Cloud

Source boundary: the January 2026 strategic business case states the late-2025 production stack, interaction count, and uptime. Specific workload, open-enrollment, and call-type milestones come from that business case and are not independently validated here. The detailed control path is documented target architecture; the fail-closed line is sandbox-harness evidence.

03Delivery system2025–26

The operating lesson became the WHPS AI SDLC.

Agents execute bounded work in scoped workspaces. Humans own the gates. Every release carries tests, provenance, disposition, and a named release decision with the product.

Intent enters once. An independently verified product, evidence package, and named human release decision leave together.

7
Canonical lifecycle phases
13
Security and compliance gates
1
Named human release authority
  1. 01Define / Classify
  2. 02Decompose / Plan
  3. 03Architect / Secure
  4. 04Build / Integrate
  5. 05Validate / Test
  6. 06Package Evidence
  7. 07Release / Operate

The WHPS AI SDLC is a documented, model-agnostic operating standard. MarketLink demonstrates the controlled delivery path; one product does not imply universal adoption across every initiative.

04Verification control planeWhile work is happening

Observability tells you what happened. A control plane determines what is allowed to happen.

Governance sets the rules; the control plane enforces them.

A verifier is a named, independently-owned check with a defined trigger, defined scope, authority to block, and a recorded disposition.

  1. Before generationPreventive

    The agent cannot.

    Prevents the action
  2. During generationInline

    Checked while working, not after.

    Blocks and returns correction
  3. Before releaseGate

    Nothing ships unverified.

    Withholds release
  4. After releaseContinuous

    The last line, not the control.

    Observes only

Zero-trust independenceNo agent verifies its own output. Verification uses a different model lineage or deterministic tool, bridged through segregation of duties.

Fusion ruleAlgorithmic and agentic verification operate together—never either/or.

The control plane is the documented WHPS operating standard. Its verifier register distinguishes controls in force today from controls the standard still requires.

05Regulated proofMarketLink

A production-ready product. A release gate still correctly held.

MarketLink connects CMS Enhanced Direct Enrollment requirements to backlog, control gates, test cases, and evidence references. The implementation and traceability spine exist; evidence capture and independent approval remain open.

  1. 01RequirementCMS EDE production-entry obligation
  2. 02BacklogAcceptance criteria and implementation scope
  3. 03Control gateOne of thirteen release controls
  4. 04TestCMS UAT and product verification
  5. 05ArtifactCurrent evidence reference
  6. 06DispositionNamed review and release decision
21 / 21
Traceability rows mapped
22
CMS EDE API modules
0
Export-ready cases
1
Review candidate
11
Pending captures
1
Source-pending case

Coverage is not completion. MarketLink is production-ready and not yet in production. No external certification claim until the audit cycle completes.

06Portfolio outcomesProducts in motion

The delivery system is landing in products, not prototypes.

The portfolio carries live capability, active modernization, regulated proof, testing, and named dependencies at the same time. Mixed status is visible rather than averaged away.

Portfolio context Four products · different evidence standing Operating proof · modernization · regulated evidence · active testing

01 · Regulated enrollment

MarketLink

  1. Entry
  2. Consent
  3. CMS Hub
  4. 834

Production-ready. CMS APIs were exercised successfully in CMS UAT; the audit cycle and evidence package remain open.

Current proof
21 / 21 traceability rows mapped.
Next decision
Close the export-ready evidence gate.

02 · Member service

Contact Center AI

  1. Channel
  2. Context
  3. Local inference
  4. Human

The late-2025 production stack established the operating path. Claims, quality, and after-call work expand only as their named dependencies close.

Current proof
Business-case-reported production position.
Next decision
Sequence platform and service expansion.

03 · Group administration

GroupLink Portal

  1. Portal
  2. Services
  3. CDC
  4. DB2

Client live with shared payments integrated. Bidirectional IBM Change Data Capture deployment is underway while DB2 remains authoritative.

Current work
Harden coexistence and accumulate parity evidence.
Next decision
Cut over only when domain evidence supports it.

04 · Reconciliation operations

ReconLink

  1. Recon Buddy
  2. Testing
  3. Ops tuning
  4. Acceptance

Recon Buddy phase one is live; phase two remains in testing and defect correction. Platform modernization is in testing with weekly Operations tuning.

Current work
Continue Buddy defect correction and the platform Operations-tuning loop.
Boundary
Test-round accuracy is not a production-performance claim.

Additional operating proof remains visible in the portfolio: ICHRA Phase 1 was delivered inside the existing ServiceLink Portal; the image-to-text converter is operational. SQL Talk is in business testing.

07Modernization contextEstate · economics · exit

The legacy estate defines the economics—but not the transformation thesis.

Modernization and AI transformation run in parallel. The protected foundation and operating products prove the delivery capability; the starting estate explains where that capability must go next.

Estate baseline

A functional estate that prices change in months.

$55.0M
Annual run rate · $1.28 PMPM
9.55M
In-scope LOC in a 22M LOC environment
6,628
MIPS · vendor-operated mainframe
140h/wk
Batch plus 168h OLTP

Baseline: January 2026 strategic business case and April 10, 2026 mainframe migration assessment kickoff. COBOL, JCL, and DB2 skills are concentrated in a diminishing talent pool; the managed-services contract runs to 2030.

Dual-track bet

Modernize the platform and infuse AI across delivery—at the same time.

Modernization economics

A 52% run-rate reduction target, recognized only on retirement.

The business case moves the estate from $55.0M to a $26.5M target annual run rate—$1.28 to $0.60 per member per month. Savings count only when workloads are verifiably retired, not when code is migrated.

Current run rate$55.0M
Mainframe decommission−$18.5M
Ensono exit path−$8.0M
AI and operations efficiency−$14.0M
Cloud and AI run cost+$12.0M
Target run rate$26.5M
$4.5M
Phase-one foundation ask
$11.5M
Total programme
14 months
Payback target
$28.5M
Annual savings by FY30 · modelled

Source basis: WHPS AI Transformation strategic business case, January 2026. All figures are modeled targets in that business case, not realized savings.

Exit doctrine

The last constraint is a dependency, not an application.

A proposed five-play doctrine for engineering the mainframe out from under live platforms—sequenced on evidence, not on calendar. Self-perform the application build the programme has already proven; use vendor capability only where it closes a real gap.

  1. Extract the business rules
  2. Flip data sovereignty domain by domain
  3. Decompose the batch estate by job class
  4. Carve out payment processing last with penny-level reconciliation
  5. Gate every cutover on dual-run parity evidence

08Agent-ready futureGoverned service contracts

Local inference stayed inside the estate. A governed model lifecycle comes next.

The January 2026 business case records local large language model inference inside the WHPS estate; the documented architecture adds a model gateway. Training or fine-tuning becomes an operating claim only after the model inventory, data lineage, evaluation, and release evidence exist.

Target model operating loop Adapt only when evidence justifies it.

The durable asset is the governed operating record around the model—not an unsupported claim of model ownership.

  1. 01Capture task tracesService events, agent edits, QA decisions, exceptions, and citations.
  2. 02Curate protected dataDe-identify, classify, label, balance, and validate approved examples.
  3. 03Choose the model pathRetrieve, configure, or—when approved—train or fine-tune a task model on private compute.
  4. 04Evaluate independentlyAccuracy, grounding, privacy, bias, latency, cost, and rollback behavior.
  5. 05Register and releaseVersion, lineage, runtime boundary, named human approval, observation, and revoke path.
Current proof
Business-case-reported local LLM inference.
Documented standard
Model gateway, registry, evaluation, human release, and revoke controls.
Still to evidence
Approved model inventory, runtime configuration, training or fine-tuning standing, dataset lineage, and evaluation baselines.
Model estate ledger The operating record required before scale.
Runtime boundary
Local inference is reported in the January business case; the reviewed configuration record remains to be published.
Partially evidenced
Model identity + license
Approved model, version, origin, license, and accountable owner.
Next proof
Retrieval lineage
Approved sources, data classification, citation behavior, retention, and revocation path.
Documented standard
Adaptation standing
Explicit decision on retrieval, configuration, training, or fine-tuning—supported by data and authorization evidence.
No operational claim
Evaluation + rollback
Baseline, substitution test, risk thresholds, independent disposition, rollback trigger, and observed result.
Evidence required
Release authority
Named human owner, approval standing, review cadence, and authority to hold or revoke the model path.
Decision required
Authorization sequence

Three decisions turn the model estate into a governable operating record.

Approve the record, the independent baseline, and the standing for any adaptation path before scale.

  1. 01
    Publish the model inventory

    Register model identity, version, origin, license, accountable owner, runtime boundary, approved retrieval sources, and revoke path.

  2. 02
    Establish the independent evaluation baseline

    Set task-level accuracy, grounding, privacy, bias, latency, cost, substitution, and rollback thresholds with a separately owned disposition.

  3. 03
    Decide adaptation standing

    Record whether retrieval, configuration, training, or fine-tuning is authorized at all—and the protected data, evidence, human release, and review cadence any approved path requires.

Decision boundary: approving this sequence closes an operating-record gap. It does not claim that operational training or fine-tuning is in place.

The current frontier is agent-assisted. The model operating loop and agent-ready services describe the target architecture, not a current training pipeline or autonomous authority.

09Leadership agendaWHPS decisions now

The next wave is a set of decisions—not another generic roadmap.

WHPS has the foundation, operating proof, delivery method, and product evidence. Leadership now determines where the operating contract becomes binding and which outcome moves next.

  1. Decision 01Close the MarketLink evidence gate.

    Finish current capture, complete the independent audit cycle, and bind CMS submittal and controlled cutover to an export-ready package.

  2. Decision 02Sequence the Contact Center AI expansion.

    Resolve the call-centre platform direction, complete Claims Operations testing, and sequence the October quality and transcription discovery outcomes without presenting targets as completed releases.

  3. Decision 03Set GroupLink coexistence exit criteria.

    Name the parity evidence required for each data-sovereignty flip while IBM CDC deploys and DB2 remains authoritative.

  4. Decision 04Convert ReconLink testing into a release decision.

    Close test and tuning work, obtain business acceptance, and set timing only when the evidence supports it.

  5. Decision 05Approve the first modernization wave on retirement economics.

    Confirm scope and investment against the programme business case; recognize savings only as dependencies and workloads verifiably leave the estate.

  6. Decision 06Make independent verification binding as the portfolio scales.

    Name verifier ownership and standing, retain human release authority, and expose agent actions only through governed service contracts.

The transformation compounds only when each decision has an owner, evidence obligation, control boundary, and next move.