Home » ITSM
Category Archives: ITSM
Larger projects are NOT riskier
Is Complexity Theory Right that Bigger Is Riskier? Evidence from Information Technology
Ajazi, Nickelsen, Schmidt, Flyvbjerg & Christodoulou
Overview
Conventional project management wisdom assumes that larger IT projects are inherently more risky because they involve greater complexity, more stakeholders, and stronger interdependencies. This study challenges that assumption using one of the world’s largest empirical datasets of completed IT projects.
The authors analyzed 5,094 IT projects (cost performance) and 831 projects (schedule performance) from 64 countries, covering software development, ERP, BI, cybersecurity, and other IT initiatives. Their conclusion is striking:
Project size is not a reliable predictor of project risk. In fact, the smallest IT projects exhibit the highest cost risk, while schedule risk shows no consistent increase with project size.
Research Objectives
The study tested two widely accepted hypotheses:
- H1: Larger IT projects experience greater cost overruns.
- H2: Larger IT projects experience greater schedule overruns.
Project size was measured by the approved project budget at the Final Investment Decision (FID), while project risk was measured by:
- Cost overrun (Actual Cost / Estimated Cost)
- Schedule overrun (Actual Duration / Planned Duration)
Key Findings
1. Smaller Projects Are Not Safer
Contrary to conventional belief, very small projects demonstrate the highest average cost overruns.
| Project Size | Average Cost Overrun |
|---|---|
| Very Small | 192% |
| Small | 53% |
| Medium | 42% |
| Large | 42% |
| Very Large | 57% |
The statistical analysis found no evidence that increasing project size leads to higher cost risk. Instead, the smallest projects performed significantly worse than all other groups.
2. Schedule Overruns Do Not Increase with Project Size
The analysis of schedule performance also rejected the traditional assumption that larger projects are more likely to finish late.
| Project Size | Average Schedule Overrun | Projects with >50% Delay |
|---|---|---|
| Very Small | 37% | 20.4% |
| Small | 30% | 21.7% |
| Medium | 75% | 43.4% |
| Large | 67% | 44.0% |
| Very Large | 26% | 33.1% |
Although medium and large projects showed higher average delays, statistical testing found no consistent upward trend between project size and schedule risk. Very large projects actually demonstrated the lowest average schedule overrun.
3. IT Project Risk Has “Fat Tails”
A major contribution of the paper is confirming that IT project overruns follow fat-tailed (power-law) distributions.
This means that:
- extreme overruns are not rare exceptions;
- catastrophic outcomes occur much more frequently than predicted by traditional risk models;
- conventional approaches based on normal distributions systematically underestimate project risk.
Importantly, this characteristic applies to projects of every size, although it is strongest among the smallest projects.
Why Are Small Projects More Risky?
The authors suggest several explanations:
- Small projects often receive less executive attention and governance.
- Organizations frequently assign less experienced teams to smaller initiatives.
- Risk management processes are typically less rigorous for projects below predefined budget thresholds.
- Cognitive biases (such as the Dunning–Kruger Effect and Uniqueness Bias) contribute to underestimating project complexity and organizational capability.
Practical Implications
The findings challenge several common project management practices:
- Budget should not be used as the primary indicator of project risk.
- Small IT projects require the same level of governance and risk assessment as larger initiatives.
- Organizations should evaluate project risk based on team capability, organizational maturity, technical complexity, and uncertainty, rather than project size alone.
- Risk management frameworks should explicitly account for fat-tailed risks, recognizing that extreme overruns are an inherent characteristic of IT projects rather than statistical anomalies.
Conclusions
The study fundamentally challenges the long-standing assumption that “bigger means riskier” in IT project management. Instead, it demonstrates that all IT projects carry substantial risk, while small projects are often the most vulnerable to severe cost overruns.
For practitioners, the key lesson is clear: project governance should be driven by risk characteristics rather than budget size. Organizations that automatically devote greater oversight only to large projects may inadvertently overlook the projects most likely to fail.
Original article
ITIL5 Transformation module released
In mid-April, the latest ITIL5 update was released, including the “Transformation,” “AI Management,” and “Strategy” modules. I’ll begin with a brief overview of the “Transformation” module, which is a new addition to the ITIL module lineup. There were no direct equivalents in the previous version.
This module presents concepts for transforming an enterprise to provide digital services. It emphasizes a comprehensive, multidimensional approach that considers both external and internal enterprise factors, demand, technology, and much more.
The “Transformation” module presents templates for implementing management during transformation, supporting ongoing operations during transformation, managing major changes, supporting employees and stimulating transformation, and, of course, the role of AI.
The module offers standard tools, methods, and techniques, and, as usual, links them to ITIL domains (dimensions), practices, and guiding principles.
ITIL(r) 5 Product, Service, Experience modules released
Axelos/Peoplecert announced the official release of these 3 modules on March, 12th. All modules and appropriate exams are available now, focusing on synchronizing product and service lifecycle in Experienced value delivery.
Fig. 1 Combined Product and Service Value chain –

Operational model canvas –

Our Service Desk course received “The Highest Rated” status
AI module in IT Service management online course
Our course IT Service management has a new module now – AI in ITSM.
Learn which roles can AI play in ITSM – boring and generative. We discuss risks, achievements, challenges and advantages of applying AI for IT service management.
Join or Retake our course NOW!

AI applying for Service Desk
Our online course – Service operations and Service Desk – got a new module – AI in Service Desk.
Join our course here.

We’re DevOps accredited training provider!
We’re happy to announce that services gained again the prestigious Training Provider and Accredited trainer status.
Join our online courses and purchase individual consulting!


Challenges in moving to DevOps Culture
Axelos, famous for its ITIL(r) and PRINCE(r) frameworks, issued a series of publications on DevOps culture and DevOps engineering.
In this publication our authors discuss the presented 4 challenges/barriers on the organization’s road to DevOps culture.
“1. An organization’s structural barrier keeps DevOps teams from thriving:
Organizational structure barriers are easy to spot but difficult to change.These organizational structural barriers include the following:
a) the excessive layers of anxious middle management which stand between ideas and their execution,
b) pathologically siloed organizational structures with no history of or incentives to engage in collaboration, and
c) senior-level executives who are not able, willing, or skilled to lead digital disruption in the company.
2. Cultural habits an fears prevent individuals and teams from innovating: for 25% of global enterprise IT organizations, a change in culture is one of the top three challenges they are facing (Upskilling IT 2023). Culture refers to the organization’s informal patterns that signal to people which behaviors are right and which behaviors define you as difficult.
The challenges can be summarized as:
a) not bringing the right people into the organization or not keeping and developing them once there,
b) aversion to risk-taking and proposing innovative ideas, and existing habits of seeing past failures and successes inhibit change.
3· Existing processes, bureaucracy, and procedural hurdles challenge even motivated staff members and teams: existing complex processes hamper the ability to make changes as there are too many dependencies and constituencies to connect. For 15% of IT enterprise organizations, the lack of innovative operating models hampers their progress. Existing processes and procedures are important as they are useful in getting things done, but they also cause issues if there is too much emphasis on internal processes and procedures versus the focus on outcomes.
4· Technology trends will continue to drive challenges: although there are a variety of technology topics that are interesting, exciting and might provide a variety of benefits, technology challenges are unavoidable, but the continuous adoption of technology continues to increase the technical debt. For 31% of IT enterprise organizations, managing technical debt and/or avoiding technical debt is a significant challenge. “
Service Desk Predictors (Leading indicators)
Service desk predictors (or leading indicators) module is added to our Service Desk KPIs e-learning course. In this module you learn how to develop and measure subjective predictors which help us to predict ad solve issues before they happen, and thus reach high KPIs.

