−58%
Inspection time
14
Service journeys live
100%
Audit pass
240k
Monthly declarations
Client
Leading Middle East Customs Authority
Sector
Government
Duration
9 months
Team
22 specialists
01 · The challenge

Problem

Cargo inspection ran across 5 ageing systems with paper checklists at the dockside. Inspection time averaged 4.5 hours per consignment. Audit teams flagged decision-trail gaps annually.

02 · How we delivered

Solution

Unified Mendix workflow with mobile-first inspector app, AI-assisted risk pre-screening, and a regulator-grade decision trail. Strangler-fig migration of 5 legacy systems with parallel run.

03 · Outcome

Impact

Inspection time fell 58%. 14 service journeys live in 9 months. 100% audit pass. 240,000 declarations per month on the new platform with zero manual reconciliation.

How we delivered

Programme phases.

Five phases. One accountable team. Every phase had a named decision point and a measurable outcome.

Discovery & alignment

2–3 weeks

Workshops with the Leading Middle East Customs Authority executive team, baseline metrics, target outcome tree, programme governance set up.

Design & architecture

4–6 weeks

Reference architecture, security blueprint, joint squad model agreed. Data model and integration contracts published.

Build & live-parallel

Q2 onwards

Vertical slice built and run live-parallel against the existing system. Continuous integration, daily deploys, weekly business demos.

Cutover & scale

Mid-programme

Phased cutover, audit-aligned reconciliation, scaling out of squads, capability transfer to Leading Middle East Customs Authority teams.

Run & continuous improve

Steady state

Managed run with named SLOs, quarterly value reviews, and a 15% optimisation budget reserved for improvement work.

Engineering view

Architecture overview.

Foundations

Cloud landing zone, identity, network, security baseline. Data fabric with lineage-by-default. Audit-grade observability stack from day one.

Application & integration

Domain-aligned microservices behind a published API surface. Event-driven core with CDC into the data fabric. Live-parallel capability built in, not bolted on.

Trust & governance

RBAC, audit logs, lineage, policy-as-code. Model risk records for every production model. Compliance posture on the executive dashboard, not in a quarterly slide.

Built on

Technology stack.

Production-grade choices, defended by track record. The stack is one engineering decision among many — but a load-bearing one.

Mendix Azure Postgres Microsoft Entra Camunda OpenSearch
Trust by design

Governance & assurance.

01

Programme assurance

Independent assurance reviews at each phase gate. Findings tracked in a single risk register with named owners and remediation deadlines.

02

Security & data

ISO 27001, SOC 2 Type II controls applied throughout. Data lineage captured by default; sensitive data tokenised at the edge.

03

NESA / sovereign cloud

Deployment aligned to national cybersecurity authority controls. Sovereign cloud where data residency requires it.

04

Accessibility & inclusion

WCAG-AA on every citizen-facing journey. Arabic-first design with parallel English; user-research panels include accessibility users.

Inspectors prefer the new platform. That is rare for a system replacement.

D Director of Operations · Leading Middle East Customs Authority

What we learnt

Three things we would do again.

  1. 01

    9 months from kickoff to first regulated outcome — squad density and decision velocity matter more than headcount.

  2. 02

    Joint squads with Leading Middle East Customs Authority engineers stayed in place after go-live. Ownership did not transfer in a hand-off — it grew in place.

  3. 03

    Live-parallel for a meaningful window before cutover bought us trust. The cutover itself was a flag flip, not a war room.

Book the partner

Want a programme like this one?

Tell us your sector and your timeline. A senior partner with sector experience will respond within one business day.