The Detection Trap

Analysis·Giovanni Leonardi·September 2026·11 min read

Researched by an agentic pipeline · reviewed and gated by the author

The governance problem that matters is not whether you know a programme is failing. It is whether you can do anything about it.

The Arithmetic That Forced the Experiment

Every programme governance body eventually confronts a version of the same arithmetic. At March 2026, the UK government’s central oversight body — approximately 200 staff within the National Infrastructure and Service Transformation Authority — was responsible for 189 programmes worth £924 billion in whole-life cost. Of those, 18% were rated Red and 58% Amber. Red-rated projects had increased from 23 to 34 in two years, the portfolio’s cost had grown from £834 billion to £924 billion, and the National Audit Office had concluded that after three reorganisations of the oversight body since 2011, it remained “difficult to tell whether performance is improving” [S7].

The government responded not with another reorganisation but with an architectural redesign. From April 2026, the centrally monitored portfolio was cut from 189 projects to approximately 81. An AI-powered Early Warning System was deployed to predict which retained projects would deteriorate before formal assessments changed. And a new mega-project classification, covering three programmes exceeding £10 billion, introduced five governance innovations that the broader portfolio does not receive.

This is a deliberate experiment in whether concentrated predictive oversight produces better outcomes than comprehensive periodic review. The experiment matters beyond Whitehall because the tension it exposes is structural: every organisation managing a programme portfolio larger than its oversight capacity can serve must decide how to allocate governance intensity, and most make that decision by default rather than by design. The UK has made it by design — and the architecture reveals a problem that the reform itself does not resolve.

What the Reform Actually Does

Three reforms took effect simultaneously, each addressing a different segment of the portfolio.

Portfolio concentration reduced the Government Major Projects Portfolio to programmes that support a top government priority, exceed £1 billion in whole-life cost, and benefit from central scrutiny [S2]. Approximately 110 programmes were transferred to departmental assurance. The stated logic is bandwidth reallocation: concentrate expert capacity where it produces the greatest return.

Predictive assurance added a new instrument. The Early Warning System analyses existing GMPP performance data — cost tracking, schedule milestones, risk assessments, benefits forecasts, resource allocation, and delivery confidence ratings — to identify programmes at risk of deteriorating to Red status before formal assessments change. NISTA describes it as having “already proved helpful in forecasting the future health of GMPP projects,” though no methodology, accuracy data, or specific intervention outcomes have been published [S1]. The system functions, as independent analysis has noted, as “an additional diagnostic tool rather than a replacement for Gateway reviews, business-case scrutiny, commercial assurance, technical assessment or experienced project leadership” [S9].

Mega-project governance created a formal classification for programmes exceeding £10 billion in whole-life cost and spanning multiple parliamentary cycles. Three projects received initial designation: HS2, Sizewell C, and Dreadnought, collectively representing over £160 billion. The classification carries five specific governance innovations: Strategy and Delivery Plans laid before Parliament as Command Papers; streamlined bespoke decision-making; staged incremental funding with feasibility studies at the outset; fixed capital envelopes with multi-year flexibility; and automatic pay flexibility for specialist roles [S3].

The three-tier architecture is coherent as design: differentiated governance for mega-scale complexity, concentrated central oversight for nationally significant programmes, and devolved assurance for the remainder. The question is whether the architecture’s central assumption holds.

The Detection Hypothesis

The reform rests on an implicit hypothesis: that the principal constraint on programme governance is detection — the ability to identify deterioration early enough to intervene. The AI Early Warning System embodies this hypothesis directly. Portfolio concentration supports it indirectly, by arguing that deeper scrutiny of fewer programmes will detect problems that shallow scrutiny of many cannot.

The hypothesis has an appealing logic. If the oversight system could have identified those 34 Red-rated programmes earlier — before they crossed the threshold — intervention might have changed their trajectories. Predictive analytics, applied across the existing data, might catch the patterns that periodic human review overlooks.

But the hypothesis breaks against the evidence in the government’s own reporting. The 18% Red-rated figure at March 2026 does not indicate a detection failure. Those projects were already identified as Red under existing assessment methods [S1]. The problem was not that no one knew they were in trouble. The problem was that knowing did not produce intervention that changed their trajectory. Red-rated projects increased from 23 to 34 over two years — not because the assessment system failed to detect deterioration, but because the organisational capacity to respond to what the assessment system detected was insufficient [S1, S8].

This is the distinction that matters. Detection identifies the problem. Intervention changes the outcome. They are different organisational capabilities, and improving one does not necessarily improve the other. The AI Early Warning System may well provide earlier warning. The question is what happens after the warning arrives.

The Intervention Gap

The binding constraint on programme delivery is the organisational and political capacity to change the trajectory of a deteriorating programme — to replace leadership, restructure delivery models, reduce scope, or stop work entirely when the evidence demands it. Detection systems, whether human review panels, delivery confidence assessments, or AI-powered prediction, can identify deterioration. What they cannot do is compel the decisions that reverse it.

The Matrix shared services programme illustrates the gap with uncomfortable specificity. A £4.3 billion cross-departmental programme, it was found by the Public Accounts Committee to have no single accountable person, governance fragmented across at least three boards, and departments — including HM Treasury — refusing formal commitment to the strategy they were supposed to implement [S6]. The programme’s problems were not hidden. They were extensively documented. What was absent was not visibility but the authority and institutional mechanism to enforce accountability across departmental boundaries.

The Integrated Data Service tells the same story from a different angle: £240 million spent before closure in March 2026, assessed as Red by NISTA itself, sharing the same characteristics of ambitious cross-government coordination paired with unclear governance and unachieved benefits [S6]. Detection was not the failure. The system detected the problem clearly. The intervention capacity to change the programme’s trajectory did not match.

Australia’s experience with the Gateway Review Process sharpens the point further. The most systematically audited assurance framework in comparable government, it produced a counterintuitive result: when detection became consequential, the institutional response was to undermine the detection system itself. Green ratings doubled to over 60% after methodology changes, while red ratings fell to zero. Nearly half of all reviews were deferred at agency request, and thirteen projects repeated Gates to obtain improved ratings [S11]. The framework detected less over time because the institutional cost of detection — escalation, scrutiny, intervention — exceeded the institutional tolerance for it.

This is not a uniquely governmental dynamic. Any organisation whose assurance framework produces consequences that the delivery system resists will experience a version of the same pressure: to manage the rating rather than the programme.

The Devolution Risk

Portfolio concentration’s structural weakness lies not in the 81 programmes retained under central oversight but in the approximately 110 transferred to departmental assurance. The government’s own evidence shows that departmental assurance capability is deeply uneven — ranging from departments with well-developed portfolio approaches to departments that cannot establish a single accountable person for a multi-billion-pound programme.

The Public Accounts Committee identified the risk directly, noting that excluded programmes “will still fall under the previous approach to governance and decision-making, which was not working effectively” [S4]. The Lower Thames Crossing, the New Hospitals Programme, and major digital transformation initiatives all sit outside the enhanced governance tier, despite complexity that would seem to warrant it [S5].

Scotland’s experience with its Technology Assurance Framework provides a parallel data point. Forty-five major digital projects reviewed in 2025-26 generated 345 recommendations across the same six recurring themes: resource requirements, procurement, planning, contract management, governance, and communications [S10]. The recurrence across review cycles suggests that assurance frameworks identify problems without producing structural improvement — precisely the pattern that concentrated oversight was supposed to break.

The critical design question for any organisation considering portfolio concentration is whether the governance architecture for the devolved tier matches the complexity of the programmes assigned to it. The UK’s reform assumes that departmental capability, supplemented by data sharing and access to NISTA’s tools, will be sufficient. The assumption has not been tested, and the available evidence does not support it uniformly.

The Mega-Project Exception

The most substantive governance innovations in the reform are paradoxically the ones that address the narrowest slice of the portfolio. The mega-project framework’s five instruments tackle documented root causes of mega-project failure — not detection shortcomings.

Staged incremental funding with feasibility studies at the outset confronts the commitment problem: the pattern in which political approval locks in cost and schedule assumptions before the programme’s complexity is understood. HS2’s cost escalation from £20.5 billion in 2012 to £66 billion by 2024 is the canonical case [S3]. Fixed capital envelopes with multi-year flexibility address the annual budget cycle’s distortion of multi-decade programmes — a structural constraint that no amount of assurance review can resolve. Pay flexibility for specialist roles acknowledges that programme capability is not a general-purpose resource that can be allocated by headcount.

These instruments draw explicitly on the 2012 London Olympics governance model — dedicated delivery authority, specialist-recruited leadership, tiered contingency, and clear accountability — and are designed against a documented record: the Office for Value for Money found that every UK mega-project since 1980 has been over budget and the majority delivered late [S3].

The framework’s limitation is scope. Three projects, however large, do not constitute a governance architecture for the portfolio. And the programmes excluded from the classification — including nationally significant infrastructure below the £10 billion threshold — face the kind of complexity that differentiated governance was specifically designed to address.

The Enterprise Pattern

The structural tension that the UK reform exposes operates wherever a programme portfolio exceeds the governance capacity available to oversee it. Three forces are in play, and they do not resolve easily.

Central bandwidth is finite. A governance body, whether a government oversight authority or a corporate portfolio management office, can provide meaningful scrutiny to a limited number of programmes. Beyond that limit, scrutiny becomes procedural rather than substantive — a review schedule rather than a governance instrument.

Devolved capability is uneven. Portfolio concentration works as a governance strategy only when the delivery organisations responsible for devolved programmes have sufficient assurance capability of their own. Where capability is weak, concentration does not reallocate governance intensity — it withdraws it.

Predictive technology extends detection reach without adding intervention capacity. The appeal is self-evident: identify deterioration before it becomes visible to periodic human review. The risk is that detection is mistaken for governance — that the ability to predict a programme’s trajectory is treated as equivalent to the ability to change it.

The UK’s reform assumes that these three forces can be resolved simultaneously. The honest assessment, at this early stage, is that the resolution depends on whether departmental assurance capability can carry the load that portfolio concentration assigns to it, and on whether detection that arrives earlier — through the AI Early Warning System or through deeper scrutiny of the retained portfolio — translates into intervention that changes outcomes. Neither condition can be assumed.

The practical test for programme leaders is direct. Examine the last several programmes in your own portfolio that were identified as deteriorating. In each case, ask: was the problem that the governance system did not see the deterioration? Or was the problem that seeing the deterioration did not produce the decisions — about leadership, scope, structure, or continuation — that would have changed the trajectory?

If the answer is the latter, and in most mature governance systems it is, then the investment that matters is not in detection. It is in the authority structures, escalation mechanisms, decision rights, and institutional willingness that translate what the governance system already sees into action that changes what happens next.

The governance problem that matters is not whether you know a programme is failing. It is whether you can do anything about it.

Sources

  1. NISTA — NISTA Major Projects Annual Report 2025-26 — July 2026 — https://www.gov.uk/government/publications/nista-major-projects-annual-report-2025-26/nista-major-projects-annual-report-2025-26
  2. GOV.UK — Government refocuses major projects to boost delivery of national priorities — April 2026 — https://www.gov.uk/government/news/government-refocuses-major-projects-to-boost-delivery-of-national-priorities
  3. Office for Value for Money — Mega projects slide pack — 2026 — https://assets.publishing.service.gov.uk/media/69eb2ecd9ca985145673b930/Mega_projects_slide_pack_-_publication__2026_correction_.pdf
  4. Public Accounts Committee — Governance and decision-making on major projects — 2026 — https://publications.parliament.uk/pa/cm5901/cmselect/cmpubacc/642/report.html
  5. Public Accounts Committee — Critical programmes slip through net of new governance plans — 2026 — https://committees.parliament.uk/committee/127/public-accounts-committee/news/209194/critical-programmes-slip-through-net-of-new-governance-plans-for-govt-megaprojects/
  6. Public Accounts Committee — Government shared services — 2026 — https://publications.parliament.uk/pa/cm5902/cmselect/cmpubacc/85/report.html
  7. National Audit Office — Delivering major projects in government — 2024 — https://www.nao.org.uk/briefings/delivering-major-projects-in-government-a-briefing-for-the-committee-of-public-accounts/
  8. Infrastructure and Projects Authority — Annual Report 2023-24 — 2024 — https://www.gov.uk/government/publications/infrastructure-and-projects-authority-annual-report-2023-24/infrastructure-and-projects-authority-annual-report-2023-24-html
  9. Construction Magazine — £924bn Government Projects Portfolio Puts AI and Delivery Risk Under New Scrutiny — July 2026 — https://www.constructionmagazine.uk/2026/07/nista-government-projects-ai-delivery-risk.html
  10. Scottish Government — Technology Assurance Framework 2025-26 — June 2026 — https://blogs.gov.scot/digital/2026/06/24/technology-assurance-framework-what-we-learned-from-major-digital-project-reviews-in-2025-26/
  11. Australian National Audit Office — Administration of the Gateway Review Process — https://www.anao.gov.au/work/performance-audit/administration-the-gateway-review-process