UK audits reveal core banking project risks
Two UK National Audit Office reports on major banking infrastructure projects highlight the unpredictable nature of IT cost overruns, which follow a power

Two UK National Audit Office reports, published a month apart in late 2025, provide a stark lesson for institutions procuring core banking technology. The audits reveal the extreme and unpredictable financial risks inherent in major system overhauls, challenging reliance on vendor statistics for planning.
In November 2025, the NAO reported on National Savings and Investments' business transformation programme. The initiative aimed to replace an outsourcing arrangement with Atos that began in 1999. Total costs with Atos are now estimated at £3 billion, representing a £1.3 billion overrun from the 2020 starting figure. A subsequent contract awarded to Sopra Steria in June 2023 was cancelled during the 2024-25 period. As of October 2025, the programme lacked a complete agreed plan and had no defined end date. The auditor placed responsibility on the buyer, stating NS&I underestimated the project's scale and overestimated its own delivery capability, despite warnings about internal skills and the complexity of disentangling a highly integrated system.
The shape of a successful outcome
A second NAO report in December 2025 examined the Bank of England's renewal of its Real-Time Gross Settlement (RTGS) system, which processes around £790 billion daily. The system launched in April 2025 at a cost of £431 million, nine years after its initial announcement. The project underwent four major replans. Causes for delays included a technology platform change and an external shock when the European Central Bank altered its own timetable, pushing the launch back by approximately 18 months. In contrast to the NS&I audit, the NAO deemed this programme value for money and an example of good practice in digital transformation. This report illustrates what a successful outcome looks like after rigorous external scrutiny.
The non-existent average overrun
The disparity between these two outcomes aligns with broader evidence on IT project performance. Research by Flyvbjerg and colleagues in the Journal of Management Information Systems in 2022 studied 5,392 IT projects completed between 2002 and 2014. They measured cost overrun as actual cost divided by estimated cost. Their central finding was powerful. Overruns and underruns occurred with roughly equal frequency, and the median project came in exactly on budget at a ratio of 1.0. The researchers concluded that overruns follow a power law distribution. In their own words, "the average cost overrun for IT projects does not exist and cannot be calculated."
This statistical reality changes how a buyer should approach risk management. If most programmes failed, purchasing assurance would be logical. They do not. Instead, a small proportion of projects go catastrophically wrong. The distribution has no usable middle, and it is impossible to predict in advance which category a specific project will fall into. The recommended protection is not assurance but portability.
Building contractual protection
Two key contractual clauses can establish this portability. The first mandates that the discovery phase must produce a durable artefact that survives the vendor relationship. This deliverable must serve a dual purpose. It must be a document acceptable to regulators and a functional list of service gaps ready for implementation, ensuring work can continue if the supplier is changed.
The second clause imposes a strict ceiling on the consulting engagement duration itself. The source argues that three months is sufficient. A prolonged consulting phase often results in recommendations that are obsolete or impractical upon delivery.
The internal political barrier
There is a separate, non-technical reason why sound recommendations often fail. A paper containing external advice that lands on a board member's desk is typically delegated to the technical director. If that director was not consulted during the paper's development, he may reasonably question whether the authors plan to implement their own suggestions. That question, according to the source, is a dead end. You will not break through that internal dynamic.





