Folder Explainer
Back to folderResearch Explainer · Flyvbjerg et al. (2026)
IT projects often hit budget, but their overruns defy conventional forecasting
Across 11,011 projects, IT had the fattest cost-overrun tail and the only Pareto alpha point estimate at or below 1. The danger is not an ordinary bad average, but a class of risk for which mean-based forecasts can fail outright.
Published February 2026
α = 0.92 median Pareto tail estimate for IT, the only point estimate in the extreme-risk category
453% mean overrun among IT projects that exceeded budget by more than 50%
40.86% of IT projects exceeded budget, a low frequency masking an unusually destructive tail
11,011 projects across 23 types, including 5,360 IT projects
A quiet median hides a violent tail
Across 5,360 IT projects, the mean actual-to-estimated cost ratio was 1.73, while the median was 1.00. Only 40.86% ran over budget, yet 18.26% exceeded budget by more than 50%. Among that latter group, the mean ratio was 5.53, equivalent to a 453% overrun and the highest of all 23 project types.
That is the paper's barbell pattern: many IT projects land on or below budget, while a minority run spectacularly far past it. A conventional average blends those two worlds into one reassuring number. The problem is not how often IT misses, but what happens when it does.
| Project type | Projects | Over budget | More than 50% over | Mean ratio in >50% tail |
|---|---|---|---|---|
| IT | 5,360 | 40.86% | 18.26% | 5.53 |
| Nuclear storage | 25 | 92.00% | 52.00% | 5.27 |
| Roads | 2,086 | 53.84% | 9.97% | 2.01 |
| Mining | 886 | 49.44% | 16.93% | 2.29 |
| Rail | 372 | 72.58% | 27.15% | 2.22 |
| Pipelines | 437 | 55.38% | 9.61% | 2.05 |
IT alone crosses into extreme cost-tail risk
Flyvbjerg et al. (2026), Table D2. Exact bootstrapped median Pareto alpha estimates for all 23 project types. Lower alpha means a fatter cost-overrun tail; red marks IT and blue marks the other types. Figure 3 instead plots empirical complementary cumulative distribution curves for IT, roads, mining, rail and pipelines. Those curve values are not printed, so they are not reconstructed here. Alpha is dimensionless.
The tail changes the mathematics
The authors fitted a Pareto 1 distribution to the upper tail of each project type. Its shape parameter, alpha, measures tail fatness: the lower the value, the more slowly the probability of extreme overruns falls. IT's bootstrapped median was 0.92, with a 95% confidence interval of 0.75 to 1.17. Nuclear storage came next at 1.047. The interval crossing 1 matters, so the distinctive claim rests on IT's point estimate rather than certainty about the population threshold.
Figure 3 makes the contrast visible through complementary cumulative distribution curves for the five largest tail samples. IT remains far above roads, mining, rail and pipelines as overruns grow. Under a fitted Pareto model, alpha at or below 1 implies an infinite population mean and variance. That does not mean any invoice is literally infinite. It means conventional mean-based prediction has no stable quantity to converge on.
The paper groups all 23 types into five risk bands. Only IT falls into the extreme band by point estimate; solar power sits at the other end with an alpha of 7.836. For IT, the average is not merely misleading. In the fitted population model, it does not exist.
| Risk category | Alpha range | Statistical consequence | Project types |
|---|---|---|---|
| Extreme | α ≤ 1 | Infinite mean and variance | IT |
| Very high | 1 < α ≤ 2 | Finite mean, infinite variance | Buildings, dams, defence, fossil thermal power, hydroelectric dams, nuclear power, nuclear storage, Olympics, rail |
| High | 2 < α ≤ 3 | Finite mean and variance, infinite skew and kurtosis | Aerospace, bridges, mining, pipelines, rail stations, roads, tunnels, water |
| Elevated | 3 < α ≤ 4 | Finite mean, variance and skew, infinite kurtosis | Oil and gas |
| Moderate | α > 4 | Finite mean, variance, skew and kurtosis | Energy transmission, nuclear decommissioning, solar power, wind power |
The comparison was designed to survive obvious objections
The dataset contains 11,011 projects across 126 countries and six continents, worth US$4.64 trillion in 2023 prices. The descriptive analysis used every project. Tail analysis began with the 5,596 projects whose actual cost exceeded the estimate, with the theoretical fits applied above selected tail cut-offs.
Cost overrun was actual divided by estimated real cost, with the estimate fixed at the final investment decision and actual cost measured at go-live. The authors compared Pareto and lognormal fits using quantile plots and three goodness-of-fit tests, then estimated alpha and its 95% confidence interval with a 500-iteration nonparametric bootstrap.
Sensitivity checks covered source, size, duration, completion year, classification and statistical method. No historical trend was detected, and neither duration nor estimated cost was significantly associated with overrun. Around 25% of candidate cost data was rejected for poor quality, while badly managed projects may be less likely to release records at all. The reported tail may therefore be the polite version.
| Data source | Projects |
|---|---|
| Owner accounts | 2,845 |
| Freedom of information requests | 2,653 |
| Public records | 4,141 |
| Academic studies | 1,372 |
| Total | 11,011 |
Six possible reasons IT is different
The paper begins with four explanations from prior research: immaturity, intangibility, goal ambiguity and stakeholder resistance. Each could amplify cost risk, and IT may combine all four more intensely than physical project types. The study does not measure them directly, so the data support the theory without proving its causal chain.
The cross-project pattern suggests two additions. The fattest-tailed types cluster around bespoke, tailor-made delivery, while modular solar, wind and transmission projects sit at the thin-tailed end. IT projects also averaged only 3.2 years against 6.9 years elsewhere, so short duration did not buy safety. The authors suggest that rushed, fast decisions may cancel the usual advantage of speed. That is a plausible diagnosis, not a causal result wearing a lab coat.
Four inherited explanations and two additions organise the paper's causal argument.
- ImmaturityIT is a younger discipline with less accumulated standardisation, regulation and costing experience.
- IntangibilitySoftware lacks physical milestones, remains unusually malleable and often hides integration trouble until work is under way.
- Goal ambiguityUnclear objectives feed requirements volatility, scope creep and escalation.
- Stakeholder resistanceIT changes workflows and power, giving affected users and outside actors reasons to obstruct implementation.
- BespokenessTailor-made systems multiply novelty and interdependence, while modular components repeat what has already worked.
- Fast thinkingShort cycles may compress planning and encourage biased decisions. Speed looks efficient until it starts feeding the tail.
What the evidence cannot yet settle
This is an observational comparison, so it cannot establish final causality. The proposed mechanisms were not directly measured. The analysis covers upfront capital cost through go-live, not lifecycle cost, and it does not separate IT subtypes. Schedule evidence was preliminary, while benefit data was too sparse for analysis.
Project-type samples also vary sharply: nuclear decommissioning had 16 projects, the Olympics 21 and nuclear storage 25. Some distribution fits were inconclusive or produced conflicting tests, and the fitted IT Pareto tail used 48 observations above its selected cut-off. Its 95% confidence interval also crosses the alpha-equals-1 boundary. A serious tail does not grant immunity from sampling uncertainty.
For practice, the paper argues against normal-distribution assumptions and casual reliance on mean forecasts. It favours larger reference classes, more deliberate decisions, and standardised modular systems built from smaller repeatable parts. Those remedies still need causal testing. The paper has found the tail. It has not yet found the hand pulling it.
THE PRACTICAL CONSEQUENCE
Treat IT cost forecasts as tail-risk decisions, not ordinary estimates with a little contingency added. Use large reference classes, preserve extreme outcomes in the data, and reduce bespoke interdependence through modular design. The sensible response is not a more confident average. It is a project design that gives the tail fewer places to hide.
Reference
Flyvbjerg, B., Budzier, A., Aaen, J., Keil, M., & Zottoli, M. (2026). The uniqueness of IT cost risk: A cross-group comparison of 23 project types. Project Management Journal, 57(1), 14-43. https://doi.org/10.1177/87569728251340590