Folder Explainer

Back to folder
GPT-5.6 Sol · Sync

Research Explainer · Flyvbjerg et al. (2026)

IT projects often hit budget, but their overruns defy conventional forecasting

Across 11,011 projects, IT had the fattest cost-overrun tail and the only Pareto alpha point estimate at or below 1. The danger is not an ordinary bad average, but a class of risk for which mean-based forecasts can fail outright.

Published February 2026

α = 0.92 median Pareto tail estimate for IT, the only point estimate in the extreme-risk category

453% mean overrun among IT projects that exceeded budget by more than 50%

40.86% of IT projects exceeded budget, a low frequency masking an unusually destructive tail

11,011 projects across 23 types, including 5,360 IT projects

Across 5,360 IT projects, the mean actual-to-estimated cost ratio was 1.73, while the median was 1.00. Only 40.86% ran over budget, yet 18.26% exceeded budget by more than 50%. Among that latter group, the mean ratio was 5.53, equivalent to a 453% overrun and the highest of all 23 project types.

That is the paper's barbell pattern: many IT projects land on or below budget, while a minority run spectacularly far past it. A conventional average blends those two worlds into one reassuring number. The problem is not how often IT misses, but what happens when it does.

Project typeProjectsOver budgetMore than 50% overMean ratio in >50% tail
IT5,36040.86%18.26%5.53
Nuclear storage2592.00%52.00%5.27
Roads2,08653.84%9.97%2.01
Mining88649.44%16.93%2.29
Rail37272.58%27.15%2.22
Pipelines43755.38%9.61%2.05
Flyvbjerg et al. (2026), Table 2. IT and selected comparators. The final column is the mean actual-to-estimated cost ratio among projects more than 50% over budget.

IT alone crosses into extreme cost-tail risk

Flyvbjerg et al. (2026), Table D2. Exact bootstrapped median Pareto alpha estimates for all 23 project types. Lower alpha means a fatter cost-overrun tail; red marks IT and blue marks the other types. Figure 3 instead plots empirical complementary cumulative distribution curves for IT, roads, mining, rail and pipelines. Those curve values are not printed, so they are not reconstructed here. Alpha is dimensionless.

Log-log chart of complementary cumulative distribution functions for five project types. Each curve shows the probability that a project's cost overrun exceeds a given size. IT's curve sits highest and extends furthest right, meaning very large overruns are far more common for IT than for roads, rail, mining or pipelines.
How to read it: each curve shows the share of projects (y-axis) whose cost overrun is at least the size on the x-axis — the '1 − F(x)' of the paper, on log scales. The flatter and further right a curve runs, the more often that project type produces monster overruns. IT's curve stays far above roads, rail, mining and pipelines: extreme IT overruns keep happening at sizes where other project types have essentially stopped.

The authors fitted a Pareto 1 distribution to the upper tail of each project type. Its shape parameter, alpha, measures tail fatness: the lower the value, the more slowly the probability of extreme overruns falls. IT's bootstrapped median was 0.92, with a 95% confidence interval of 0.75 to 1.17. Nuclear storage came next at 1.047. The interval crossing 1 matters, so the distinctive claim rests on IT's point estimate rather than certainty about the population threshold.

Figure 3 makes the contrast visible through complementary cumulative distribution curves for the five largest tail samples. IT remains far above roads, mining, rail and pipelines as overruns grow. Under a fitted Pareto model, alpha at or below 1 implies an infinite population mean and variance. That does not mean any invoice is literally infinite. It means conventional mean-based prediction has no stable quantity to converge on.

The paper groups all 23 types into five risk bands. Only IT falls into the extreme band by point estimate; solar power sits at the other end with an alpha of 7.836. For IT, the average is not merely misleading. In the fitted population model, it does not exist.

Risk categoryAlpha rangeStatistical consequenceProject types
Extremeα ≤ 1Infinite mean and varianceIT
Very high1 < α ≤ 2Finite mean, infinite varianceBuildings, dams, defence, fossil thermal power, hydroelectric dams, nuclear power, nuclear storage, Olympics, rail
High2 < α ≤ 3Finite mean and variance, infinite skew and kurtosisAerospace, bridges, mining, pipelines, rail stations, roads, tunnels, water
Elevated3 < α ≤ 4Finite mean, variance and skew, infinite kurtosisOil and gas
Moderateα > 4Finite mean, variance, skew and kurtosisEnergy transmission, nuclear decommissioning, solar power, wind power
Flyvbjerg et al. (2026), Tables 3 and 4. Statistical consequences of the five Pareto alpha risk bands.

The dataset contains 11,011 projects across 126 countries and six continents, worth US$4.64 trillion in 2023 prices. The descriptive analysis used every project. Tail analysis began with the 5,596 projects whose actual cost exceeded the estimate, with the theoretical fits applied above selected tail cut-offs.

Cost overrun was actual divided by estimated real cost, with the estimate fixed at the final investment decision and actual cost measured at go-live. The authors compared Pareto and lognormal fits using quantile plots and three goodness-of-fit tests, then estimated alpha and its 95% confidence interval with a 500-iteration nonparametric bootstrap.

Sensitivity checks covered source, size, duration, completion year, classification and statistical method. No historical trend was detected, and neither duration nor estimated cost was significantly associated with overrun. Around 25% of candidate cost data was rejected for poor quality, while badly managed projects may be less likely to release records at all. The reported tail may therefore be the polite version.

Data sourceProjects
Owner accounts2,845
Freedom of information requests2,653
Public records4,141
Academic studies1,372
Total11,011
Flyvbjerg et al. (2026), Appendix B. Included projects by data source.

The paper begins with four explanations from prior research: immaturity, intangibility, goal ambiguity and stakeholder resistance. Each could amplify cost risk, and IT may combine all four more intensely than physical project types. The study does not measure them directly, so the data support the theory without proving its causal chain.

The cross-project pattern suggests two additions. The fattest-tailed types cluster around bespoke, tailor-made delivery, while modular solar, wind and transmission projects sit at the thin-tailed end. IT projects also averaged only 3.2 years against 6.9 years elsewhere, so short duration did not buy safety. The authors suggest that rushed, fast decisions may cancel the usual advantage of speed. That is a plausible diagnosis, not a causal result wearing a lab coat.

Four inherited explanations and two additions organise the paper's causal argument.

  • ImmaturityIT is a younger discipline with less accumulated standardisation, regulation and costing experience.
  • IntangibilitySoftware lacks physical milestones, remains unusually malleable and often hides integration trouble until work is under way.
  • Goal ambiguityUnclear objectives feed requirements volatility, scope creep and escalation.
  • Stakeholder resistanceIT changes workflows and power, giving affected users and outside actors reasons to obstruct implementation.
  • BespokenessTailor-made systems multiply novelty and interdependence, while modular components repeat what has already worked.
  • Fast thinkingShort cycles may compress planning and encourage biased decisions. Speed looks efficient until it starts feeding the tail.

This is an observational comparison, so it cannot establish final causality. The proposed mechanisms were not directly measured. The analysis covers upfront capital cost through go-live, not lifecycle cost, and it does not separate IT subtypes. Schedule evidence was preliminary, while benefit data was too sparse for analysis.

Project-type samples also vary sharply: nuclear decommissioning had 16 projects, the Olympics 21 and nuclear storage 25. Some distribution fits were inconclusive or produced conflicting tests, and the fitted IT Pareto tail used 48 observations above its selected cut-off. Its 95% confidence interval also crosses the alpha-equals-1 boundary. A serious tail does not grant immunity from sampling uncertainty.

For practice, the paper argues against normal-distribution assumptions and casual reliance on mean forecasts. It favours larger reference classes, more deliberate decisions, and standardised modular systems built from smaller repeatable parts. Those remedies still need causal testing. The paper has found the tail. It has not yet found the hand pulling it.

THE PRACTICAL CONSEQUENCE

Treat IT cost forecasts as tail-risk decisions, not ordinary estimates with a little contingency added. Use large reference classes, preserve extreme outcomes in the data, and reduce bespoke interdependence through modular design. The sensible response is not a more confident average. It is a project design that gives the tail fewer places to hide.

Reference

Flyvbjerg, B., Budzier, A., Aaen, J., Keil, M., & Zottoli, M. (2026). The uniqueness of IT cost risk: A cross-group comparison of 23 project types. Project Management Journal, 57(1), 14-43. https://doi.org/10.1177/87569728251340590

We use analytics cookies to understand site usage and improve the service. We do not use marketing cookies.