Risk Management in UK Megaprojects: What HS2, Crossrail and Edinburgh Trams Reveal About Where Control Actually Breaks Down
The Department for Transport now puts HS2 Phase One’s cost at somewhere between £87.7bn and £102.7bn — against an original approved budget of £36bn. The National Audit Office’s verdict on why wasn’t that HS2 lacked a risk register; it was that government “did not adequately manage risks to taxpayers’ money” and underestimated the project’s complexity from the outset. Crossrail and Edinburgh’s tram line failed for related but distinct reasons, documented in the same kind of public record: NAO reports, Committee of Public Accounts hearings, and — for Edinburgh — a statutory inquiry that ran longer than Chilcot.

None of these three programmes broke down for lack of paperwork. They broke down because risk ownership moved — through a contract signature, a design freeze, a reporting gap — without anyone making an explicit decision that it should, and nobody was tracking that drift until the cost showed up. What follows is the documented failure pattern across all three, a contract-level breakdown of where it happens under NEC4, and an operational tracking method — the Risk Transfer Ledger — built to catch it before it becomes a variance report.
Why UK Megaprojects Keep Running Into the Same Wall
“Megaproject” in UK infrastructure circles generally means a scheme with a capital value above roughly £1 billion, multi-year delivery, multiple contracting tiers, and public accountability through Parliament or a local authority. That last point matters more than the price tag. A private-sector project of similar scale answers to shareholders and lenders, who can walk away. A public megaproject answers to the NAO, the Infrastructure and Projects Authority (IPA), select committees, and ultimately voters — none of whom can easily cancel a half-built tunnel.
That accountability structure creates a specific and well-documented risk: optimism bias. HM Treasury’s Green Book has required departments to apply an optimism bias uplift to capital cost estimates since the early 2000s, precisely because analysis of past projects showed that initial estimates were systematically too low, not just randomly inaccurate. The uplift exists as a corrective, not a formality — and the pattern the Green Book was designed to correct for has continued to show up on the UK’s largest schemes even after the guidance was in place. On HS2, for example, the original estimate for main civil construction works came in far below what was eventually recorded, exceeding even the upper end of the Green Book’s suggested optimism bias range for civil engineering work.
A second structural factor is contractual risk allocation, and on recent UK infrastructure this almost always runs through the NEC4 Engineering and Construction Contract (ECC). Most Tier 1 packages on programmes like HS2 use NEC4 Option C (target cost with a pain/gain share), specifically because it’s meant to split risk between client and contractor rather than dumping it entirely on one side, as a fixed-price Option A/B contract would. Two mechanisms inside NEC4 do the day-to-day risk-tracking work the framework is built around:
- Early Warning Notices (EWNs) — a contractual duty on both client and contractor to flag anything that could increase cost, delay completion, or impair performance, as soon as either party becomes aware of it, followed by a joint risk reduction meeting. EWNs are meant to be the live, working version of the risk register — not a formality, but the mechanism that’s supposed to stop a known issue from silently turning into a claim.
- Compensation Events (CEs) — the formal process for adjusting price and programme when a defined event outside the contractor’s control occurs (a client instruction, a physical condition an experienced contractor couldn’t have foreseen, and so on). Every CE that gets raised late, or without a prior EWN, is a signal that the risk wasn’t tracked when it should have been — it’s evidence, not just administration.
Programmes also increasingly bring contractors in early through Early Contractor Involvement (ECI) arrangements, specifically to get constructability and risk input into the design before a target cost is fixed. HS2’s post-2020 shift toward restructured contractor risk allocation, and the NAO’s later call for HS2 Ltd to re-baseline quantified risk allowances for geotechnical and structural works before signing further major contracts, both sit squarely inside this EWN/CE/target-cost mechanic. Push too much risk onto the contractor under Option C and they price it into the target cost upfront, or bank it and recover it later through a wave of CEs once ground conditions or design changes appear. Push too little onto the contractor and the client absorbs shocks it never priced for. Getting that balance wrong, and not correcting it once EWNs and CEs start showing a pattern, is a recurring theme across the case studies below.
Case Studies: Three Different Failure Patterns, One Common Root
The table below draws on published NAO reports, the Committee of Public Accounts, and the statutory Edinburgh Tram Inquiry (the Hardie Inquiry). Figures are the latest publicly reported estimates as of these documents’ publication; megaproject costs are routinely revised, so treat any single number as a snapshot rather than a permanent fact.
| Project | Original approved budget | Latest reported cost / outcome | Time overrun | Documented root cause of risk failure |
|---|---|---|---|---|
| HS2 Phase One | £36bn (whole programme, 2015 prices, per NAO) | DfT estimate range of £87.7bn–£102.7bn for the reset programme (2026) | Original 2026 opening now expected between 2029–2033, Euston date unconfirmed | NAO found the government did not adequately manage risk to taxpayers’ money and underestimated the project’s complexity; contractor risk allocation later had to be restructured mid-programme |
| Crossrail / Elizabeth Line | £14.8bn | Increased to roughly £18.9bn+ across the extended programme, plus an added management reserve for “unknown unknowns” that hadn’t previously existed | Planned December 2018 opening slipped to May 2022, roughly 3.5 years late | A 2024 DfT/IPA lessons report found systems integration risk was managed on an individual basis rather than as an interconnected whole, which distorted the management information the board relied on |
| Edinburgh Trams (Line 1) | £375m (three-line network); £545m (reduced scope, agreed before construction) | Best estimate of £835.7m for a line roughly eight stops shorter than planned | Five years late (2009 target vs 2014 opening) | The Hardie Inquiry found the delivery body abandoned its own procurement strategy meant to keep risk out of the project, signed a major infrastructure contract before design was complete, and gave councillors business cases that misrepresented the actual risk allowance |
Three different sectors, three different delivery models, three different public bodies — and in each case, the documented failure sits upstream of construction itself. It’s in how risk was estimated, contractually allocated, or reported before the diggers ever moved.
Common Mistakes That Show Up Across These Records
Treating the risk register as a compliance document rather than a decision tool. A risk register that exists to satisfy a governance gate, rather than to actively change what the project team does next week, tends to list risks without forcing anyone to act on them. The Elizabeth Line lessons-learned report specifically flagged that risks were tracked individually rather than for their knock-on effects on each other — which is a register design failure, not a bad-luck failure.
Signing contracts before the design is stable. Edinburgh’s tram inquiry found that the delivery body departed from its own strategy of finishing design before signing the main infrastructure contract. Once a fixed-price-style contract is signed against an incomplete design, every subsequent design change becomes a commercial negotiation instead of an internal engineering decision — and the contractor holds the stronger hand in that negotiation.
Reporting risk allowance in a way that understates it to the people approving funding. This isn’t always deliberate deception; the Hardie Inquiry’s language about “misleading” business cases points to a mix of optimism bias and incomplete disclosure. Either way, the effect on the funding body is the same: approval is granted against a number that was never realistic.
Under-costing systems integration and testing relative to physical construction. Physical construction (tunnelling, civils, track-laying) tends to get disciplined cost and risk modelling because it’s familiar and quantity-driven. Software, signalling, and systems integration — the work that actually determines whether trains can run safely — has historically received less rigorous risk treatment on UK rail projects, and it shows up late, close to planned opening dates, when there’s no schedule float left to absorb it.
No standing contingency for genuine unknown-unknowns. Crossrail’s own team noted that earlier in the programme there was no management reserve set aside specifically for risks nobody had identified yet — as distinct from contingency for known, quantified risks. Adding one later, after cost pressure had already built up, is corrective rather than preventive.
An Original Framework: The Risk Transfer Ledger (RTL) Method
Most UK megaproject risk registers answer “what could go wrong?” They answer far less well “who currently owns this risk, and did that change without anyone deciding it should?” The Risk Transfer Ledger is built around that second question, because the case studies above show risk failures clustering at exactly the points where ownership shifted implicitly — a contract signature, a design freeze, an EWN that never got raised — rather than through a deliberate call by client or contractor.
RTL data fields (one row per material risk, reviewed at every EWN, CE, design freeze, and funding gate):
| Field | What it records | Escalation rule |
|---|---|---|
| Nominal owner | Who the NEC4 contract currently allocates this risk to — client, main contractor, named subcontractor, or shared under the target-cost pain/gain mechanism | — |
| Practical owner | Who actually controls the decisions needed to manage this risk down right now, based on design status and site control | If practical owner ≠nominal owner, log automatically as a standalone amber risk regardless of the underlying risk’s own score |
| Transfer trigger | The specific event that would move ownership (contract signature, design freeze, EWN raised, CE agreed, planning consent, testing milestone) and whether it has occurred | If a trigger event has occurred but the ownership fields haven’t been reviewed within 10 working days, escalate to red |
| EWN/CE cross-reference | Any Early Warning Notice or Compensation Event number linked to this risk | If a CE is raised with no prior linked EWN, flag for board-level review — this is the pattern that shows up repeatedly in post-project NAO findings |
| Contingency drawdown linkage | Which specific contingency or management reserve category this risk draws against | If a single risk category has drawn down more than 25% of its ring-fenced allowance ahead of programme, escalate to the funding body separately from routine cost reporting |
The distinguishing column is “practical owner.” A standard register records contractual responsibility; it rarely forces a periodic check on whether that party is still the right one to manage the risk, given how the project has actually moved on. On Edinburgh’s trams, the delivery body remained the nominal owner of design-related ground risk long after it had lost the practical ability to manage it, because the main infrastructure contract was signed before design was finished. An RTL review at that point would have logged the nominal/practical mismatch as its own red flag — independent of whether the risk had yet turned into a cost, and well before it reached inquiry.
Illustrative example (hypothetical, not a reported figure from any named project): if a programme carries a 150-person project controls and site supervision team through an unplanned six-month hold while an EWN-flagged ground condition is resolved, and that team’s fully loaded monthly cost runs in the region of £400,000, the pure overhead exposure before groundworks resume could be on the order of £2.4 million — before any knock-on delay cost to the main works contract. The exact figures will vary hugely by project; the point the RTL is built to catch is that this exposure sits against whichever risk category “unforeseen ground conditions” was ring-fenced under, and a 25%-drawdown escalation rule would have surfaced it as a funding-body conversation well before it became a £2.4m line item nobody flagged in advance.
Comparing Risk Management Approaches Used on UK Infrastructure Programmes
| Method | What it does | Strength | Main weakness | Best suited for |
|---|---|---|---|---|
| Traditional risk register (probability × impact) | Lists identified risks, scores likelihood and impact, assigns an owner | Simple, familiar to most project teams, easy to report to a board | Risks are often assessed independently, missing compounding effects; can become a static compliance artefact | Smaller programmes, early-stage projects, low contractual complexity |
| Reference Class Forecasting | Estimates cost/schedule by comparing the project to a database of similar completed projects, rather than building up from first principles | Directly counters optimism bias with outside-view data; underpins the Green Book’s optimism bias uplifts | Depends on having a genuinely comparable reference class, which is hard for one-off megaprojects | Business case and budget-setting stage, before detailed design exists |
| Quantitative Risk Analysis / Monte Carlo simulation | Models cost and schedule outcomes probabilistically across thousands of simulated scenarios to produce a confidence-banded estimate (e.g. P50, P80) | Gives decision-makers a realistic cost range instead of a single misleading number | Output quality depends entirely on the quality of the input risk data; can create false precision if inputs are weak | Funding approval gates, contingency-setting, major re-baselining |
| Risk Transfer Ledger (RTL) | Tracks nominal vs practical risk ownership and the triggers that shift it, alongside ring-fenced contingency per risk | Surfaces ownership drift before it becomes a cost overrun; keeps contingency traceable to specific risks | Requires disciplined, recurring review — it’s a governance habit, not a one-off document | Mid-to-late design and construction phases on multi-contractor programmes |
None of these replace the others. A well-run programme typically uses Reference Class Forecasting to set an honest budget at the outset, Quantitative Risk Analysis to set contingency at each funding gate, and something like the RTL method running continuously underneath both to catch the ownership drift that neither of the first two is designed to detect.
Step-by-Step Blueprint: Setting Up Risk Ownership Tracking on a Major Project
- Build the risk register the normal way first — identify risks by category (design, ground conditions, systems integration, third-party interfaces, commercial, planning/consent, supply chain), score likelihood and impact, and assign a nominal owner per the contract.
- Add the RTL’s four columns to your existing register rather than building a separate document. Practically, this is a spreadsheet or risk-management-software extension, not new software.
- Set a fixed review cadence tied to contract events, not just calendar dates — at minimum, whenever an Early Warning Notice is raised, a Compensation Event is agreed, a design freeze is reached, or a funding gate is passed. Under NEC4, EWNs and CEs already generate a paper trail; the RTL simply requires that trail to be cross-referenced against ownership, not just cost and time.
- At each review, explicitly ask “has the practical owner changed?” for every red and amber risk, independent of whether the risk score has changed. Log any mismatch between nominal and practical owner as its own tracked item with an assigned closure action — usually either a formal contract variation or a governance decision to knowingly accept the mismatch.
- Ring-fence contingency by risk category rather than pooling it entirely, and report drawdown against each category separately to the funding body. This makes it visible early if one category (systems integration is the recurring UK rail example) is consuming contingency disproportionately fast.
- Report ownership-drift findings to the board or funding body separately from cost and schedule status, even when there’s no cost impact yet. The point of the RTL is to give an early warning before the financial consequence shows up, and that only works if it’s reported before the number changes, not alongside it.
- Commission an independent gateway review (IPA-style) at major funding decision points, and specifically task the reviewer with checking the RTL’s ownership-drift log, not just the headline risk register.
- After project closure, feed the realised risk data back into your Reference Class Forecasting baseline for future programmes, so the next project’s initial budget estimate is calibrated against what actually happened here rather than what was originally assumed.
Who This Approach Will Not Work For
This framework assumes a multi-year programme with multiple contracting tiers, formal governance gates, and a client organisation with the capacity to run recurring risk reviews — the conditions that actually existed (and were mishandled) on HS2, Crossrail, and the Edinburgh Trams. It’s a poor fit for:
- Single-contractor, fixed-price projects with a short duration, where there’s limited opportunity for risk ownership to drift because there’s only one delivery period and one contract to begin with.
- Organisations without dedicated project controls resource. The RTL method only adds value if someone owns the recurring review; bolted onto a register nobody revisits, it becomes exactly the static compliance document it’s designed to avoid.
- Projects still at concept stage with no design or contract structure yet. There’s no meaningful “practical owner” to compare against a nominal one until a contract exists.
- Situations where the real problem is political, not technical. No risk tracking method fixes a project whose scope keeps changing because of shifting ministerial or council decisions; that’s a governance and mandate problem, and it shows up in the case studies above as much as any risk-scoring failure did.
Frequently Asked Questions
Why do UK megaprojects specifically seem to overrun more than similar projects in some other countries? There’s no single agreed answer, and the NAO itself has been cautious about over-generalising across sectors. Published analysis points to a mix of factors documented above — Green Book optimism bias persisting even with the uplift in place, contractual risk allocation disputes, and the unique accountability pressure of publicly funded schemes that can’t simply be cancelled once underway. Comparisons with other countries need to control for differing procurement models and reporting standards before drawing firm conclusions.
Does having a large contingency budget solve the risk management problem? No — contingency size doesn’t fix poor risk ownership tracking, it just delays the point at which the underlying problem becomes visible as a cost overrun. Crossrail’s programme included a management reserve for unknown unknowns, and still ran years late and billions over its original funding, because the reserve addressed the symptom (needing more money) rather than the cause (risks not being managed down by the party best placed to manage them).
Is the National Audit Office involved in every UK megaproject? The NAO scrutinises value for money on government spending generally and has published specific reports on HS2 and Crossrail because both are DfT/central-government-funded programmes. Locally funded projects like Edinburgh’s trams are instead subject to different oversight — in that case, a dedicated statutory public inquiry after the fact, rather than NAO reporting during delivery.
How is Reference Class Forecasting different from just being pessimistic about costs? Reference Class Forecasting isn’t about applying an arbitrary pessimistic adjustment — it’s about basing the estimate on the actual recorded outcomes of comparable past projects, rather than a bottom-up build from the current project’s own assumptions. The Green Book’s optimism bias uplifts are essentially a simplified, standardised application of this idea across UK government business cases.
Can a smaller project (say, £50–200 million) use any of this, or is it only relevant above £1 billion? The risk register, Quantitative Risk Analysis, and Reference Class Forecasting all scale down reasonably well. The Risk Transfer Ledger method scales down less cleanly, since it depends on there being enough contracting tiers and programme duration for ownership to meaningfully drift — on a short, single-contractor project there’s often nothing for it to catch that a normal register wouldn’t already show.
A Note on the Limits of This Analysis
This article draws on publicly available NAO reports, Committee of Public Accounts findings, and the published Edinburgh Tram Inquiry report. Megaproject cost figures are revised periodically as programmes continue, so treat the figures above as accurate to their publication date rather than as live numbers, and check the original NAO or inquiry documents directly before using specific figures in a formal business case, funding submission, or public statement. This is general informational analysis of documented public-sector project outcomes, not financial, legal, or investment advice, and it isn’t a substitute for a qualified quantity surveyor, project controls specialist, or legal adviser reviewing your specific contract and programme.
Where This Leaves Project Teams
The pattern across HS2, Crossrail, and Edinburgh’s trams isn’t that risk went unrecorded — in each case there were registers, business cases, and governance processes on paper. The failure was in how risk ownership was tracked and acted on as the project moved from business case to contract to construction, and in how honestly that risk was reported to the people approving the money. A risk register that scores probability and impact is necessary but not sufficient. Whether ownership of each risk still sits with whoever can actually manage it down — and whether contingency is traceable to the specific risks it’s meant to cover — are the questions that the published record on all three of these projects shows getting missed.
