Mega Information Technology (IT) projects in government are known for high failure rates. Common issues range from budget overruns, missed deadlines, to systems that ultimately are not used by end-users. This emphasizes the importance of comprehensive risk management from the initiation phase.
Risks in IT projects are not limited to technical issues such as server downtime or software bugs. The biggest risks are actually non-technical, such as user resistance (resistance to change), leadership changes (political risk), and regulatory changes mid-project.
The implementation of standard risk management frameworks, such as ISO 31000 or COBIT 2019, is highly recommended. Every large-scale IT project must undergo an independent feasibility study and the development of proactive risk mitigation, rather than being merely reactive when a crisis occurs.
IT audits also serve as an objective control tool. Engaging an independent third party to conduct reviews at crucial stages will ensure the project remains on track and produces a return on investment (ROI) in the form of higher quality services for the people.