Overview

Why major infrastructure programmes are rich in risk knowledge, but still experience surprises

Most surprises on major infrastructure programmes are not unknown.

They are known early, discussed often, and documented somewhere.

They just don't always influence decisions while options are still open.

Across large infrastructure programmes, my experience has been that these environments are not short of capability or effort. Risk management is generally well-understood and consistently applied. Registers are maintained. Workshops are run. Quantification is performed. Yet, despite this, outcomes do not always reflect the level of insight available.

It is in how consistently that insight shapes decisions in environments that are complex, fast-moving, and constrained. That is why I find the known-unknown matrix discussed in the Institute of Risk Management (IRM) resources useful (Figure 1). Not as a classification tool, but as a lens on behaviour. What we treat as a fact. What we acknowledge as risk. What we leave unspoken. And what later presents itself as a surprise.

Figure 1. Boothroyd & Thompson, Fundamentals of Risk Management (IRM)

Facts, things that exist, but still carry uncertainty

Every programme operates with a set of "facts". Design is incomplete. Interfaces are evolving. Approvals are progressing. Procurement is underway. Testing and commissioning strategies are being refined.

In major infrastructure programmes, this often includes conditions such as:

Design maturity at contract award still evolving

Interfaces across contractors, suppliers and stakeholders not fully resolved

Regulatory approvals and permitting activities ongoing

Procurement of long-lead equipment underway

Operational or site-access constraints affecting delivery

These are not risks. They are current conditions.

The challenge is that activity can create a false sense of certainty. An approval feels under control because it is progressing. A design feels advanced because it has been issued.

A practical test I often use is this: if the same condition could plausibly reappear, repeat, or cascade into time or cost impact, it should remain visible as a risk. The label matters less than ensuring the response reflects the uncertainty.

Acknowledged risks, the ones we are comfortable recording

Major infrastructure programmes are generally strong at identifying recognised uncertainties. The familiar set appears consistently:

Planning, environmental, and regulatory approvals

Ground conditions and site constraints

Third-party interfaces and stakeholder dependencies

Procurement and supplier lead-times

Construction productivity and resource availability

Testing, commissioning, and system integration

These are known unknowns, we know what we don't know. They are captured, discussed, and often well-modelled.

Where programmes are still evolving is in consistently linking these risks to decision-making.

For instance:

Late design maturity is recognised, but procurement or delivery may still proceed at pace

Interface risks are visible, yet governance across packages can remain fragmented

Operational or site-access constraints are understood, but sequencing decisions do not always adjust early

Approval risks are tracked, but contingency and programme logic do not always reflect realistic pathways

Risk rarely disappears. It changes shape.

Risk processes can therefore become procedural. Risks are reviewed, rated, and reported, but decisions around sequencing, scope stability, contracting strategy, or assurance do not always shift at the same pace.

A practical question helps anchor this:

Moving from:

"Is the risk captured?"

to:

"What decision has changed because of it?"

Unacknowledged risks, visible but hard to hold

This is where the animal metaphors become useful.

These are risks that experienced practitioners recognise, but which are harder to sustain in open discussion because they are cross-cutting, sensitive, or require trade-offs that are not straightforward.

This is the domain of the White Rhino. Large, visible risks that are clearly moving toward the programme, yet are challenging to address early, often due to competing priorities or constraints rather than lack of awareness.

On major infrastructure programmes, these often include:

Scope continuing to evolve under stakeholder or political pressure

Optimism bias in early cost and schedule assumptions

Contingency levels that do not fully reflect risk exposure

Interface ownership across multiple delivery partners remaining unclear

Benefits becoming harder to realise as delivery complexity increases

Regulatory or operational approval pathways assumed to be linear, until late-stage evidence gaps emerge

Publicly announced target dates acting as strong delivery anchors

It is also where we encounter the Elephant in the Room, widely understood but not always explicitly articulated. And at times, the Ostrich, where attention shifts to immediate deliverables while deeper structural uncertainties remain in the background.

None of these reflect a lack of capability. They are a natural outcome of delivering large, publicly visible programmes within constraints of time, funding, governance, and stakeholder expectations.

The real risk is not that these issues exist.

It is that they do not stay visible long enough to influence decisions.

The result is that programmes can gradually shift from shaping outcomes to managing them, often with fewer options available.

A practical improvement I have seen work well is explicitly testing for "uncomfortable risks" in reviews, not just the well-formed ones.

Surprises are often aggregation, not mystery

True "unknown unknowns", things we don't know we don't know, do exist, but in my view, they are less common than we often assume.

What is frequently experienced as a "surprise" is the cumulative effect of many smaller, individually manageable issues interacting across interfaces, packages, and time.

For example:

Approval delays affect design finalisation.

Design changes trigger rework and affect procurement.

Procurement delays constrain site activities.

Site constraints compress construction windows.

Compressed construction windows increase pressure on testing and commissioning.

Each step is visible. The combined effect is not always.

Surprises are often not sudden. They are accumulated.

While true Black Swans do exist, many outcomes in major infrastructure programmes are better understood as a Black Jellyfish pattern. Not a single dramatic event, but a collective effect, semi-visible, lightly owned, and significant in combination.

This is where traditional risk registers can struggle, because they tend to treat risks discretely.

A practical enhancement is to periodically test scenarios across interfaces, not just individual risks.

Not:

"What is the impact of this risk?"

but:

"What happens if these three things move together?"

A note on quantification and maturity

On complex programmes, another pattern can emerge.

Risk managers are often highly valued for the quality of quantification. Quantitative Risk Analysis (QRA) is essential. It provides insight into uncertainty, interaction, and tail exposure.

However, if the conversation centres only on:

"How much could this cost?"

there is a risk of drifting toward acceptance rather than intervention.

A more powerful question is:

"What would prevent this risk from ever materialising?"

That question shifts the conversation from modelling exposure to shaping outcomes.

White Rhinos do not charge because they are well-modelled. They charge when decisions are delayed, interfaces remain unclear, approvals are assumed rather than secured, or sequencing is not adjusted.

Quantification supports decisions. Maturity is reflected in how consistently that insight is carried through into those decisions over time.

In complex environments with competing priorities, the link between what the analysis shows and how delivery is ultimately shaped can weaken. Maturity is reflected in how well that connection is maintained, ensuring that quantified insight continues to influence not just the initial decision, but how it is sustained in practice.

What the matrix changes in practice

The value of the matrix is not the diagram itself, but the discipline it encourages:

Protect the boundary between facts and risks.If uncertainty can repeat or cascade, keep it visible.

Make acknowledged risks decision-relevant.Ensure risk discussions are directly linked to key decisions.

Create space for unacknowledged risks.Strong environments allow difficult topics to remain visible.

Look for interaction, not just individual risks.Aggregation is often where impacts emerge.

Major infrastructure programmes demonstrate strong capability, commitment, and delivery experience.

The opportunity is not in knowing more about risk.

It is in consistently allowing that knowledge to shape decisions early enough to change outcomes.

Because most surprises are not truly unknown.

They are known.

They are discussed.

But they are not acted upon while there is still time.