Technology
85% of tech investments survive. Most never deliver their case.
Technology risk assessment isn't about predicting failure—it's about surfacing the hidden vulnerabilities that turn expensive bets into stranded costs. Learn the two foundational practices that separate organizations that know their real risks from those discovering them mid-implementation.
Most technology investments fail not because the technology is broken but because organizations lack visibility into three core risks: whether the organization is actually ready to adopt the solution, whether critical dependencies expose the firm to vendor or architectural single points of failure, and whether the investment aligns with evolving business strategy. Disciplined technology risk assessment embeds risk identification into investment decisions upfront rather than discovering problems during implementation or after go-live.
What good looks like
| Metric | Minimum | Strong | World-class |
|---|---|---|---|
| Portfolio Alignment to Business StrategyThe percentage of active IT investments that directly support documented business strategic objectives and priorities. | 65-75% | 75-88% | 88-95% |
| IT Investment Value Realization RateThe percentage of planned business benefits from completed IT projects that are realized within 12 months post-deployment. | 55-70% | 70-82% | 82-92% |
| Portfolio Risk Mitigation CoverageThe percentage of identified IT portfolio risks that have documented mitigation strategies or contingency plans in place. | 60-72% | 72-85% | 85-96% |
World-class organizations realize 82-92% of projected technology investment value, compared to 55-70% at minimum performance levels. The gap reflects not better technology selection but better risk mitigation: they surface adoption barriers before deployment (through readiness assessment), identify vendor and architectural vulnerabilities before commitment, and maintain portfolio alignment to strategy through continuous monitoring. Portfolio Risk Mitigation Coverage shows this starkly—world-class firms have identified and mitigated risks for 85-96% of their portfolio, while minimum performers cover only 60-72%. That 25-point spread is the difference between discovering problems during implementation versus preventing them before you sign the contract.
Industry-Specific Benchmarks
These ranges are cross-industry. The figures differ materially by sector and company size.
Find benchmarks for your industry →Why the gap exists
The separation between organizations realizing 70% of technology value and those realizing 82%+ is not in their ability to pick better vendors or technologies. It is in their discipline to identify risks before money is spent. Organizations in the middle tier (70-82% realization) typically conduct some form of risk review—a governance gate, a technology assessment, a vendor due diligence conversation. But these reviews are often point-in-time activities, conducted in isolation from organizational readiness planning, and disconnected from ongoing portfolio monitoring. They ask "Is this a good technology?" but not "Are we ready to use it?" or "Does this create dependencies we should worry about?" World-class performers answer all three questions systematically, and they do it before commitment, not after.
The second gap is accountability. Middle-tier organizations often conduct risk reviews but lack clarity on who owns the risk if it materializes, whether it was explicitly accepted or simply overlooked, and what monitoring should occur post-implementation. This creates a situation where risks get documented in a spreadsheet, filed away, and then resurface during implementation as a surprise rather than a managed commitment. World-class organizations assign explicit risk ownership to named executives, tie risk acceptance to funding decisions, and embed continuous monitoring into portfolio governance cycles rather than treating risk assessment as a one-time gating event.
A third difference: middle performers assess risk in silos. Technology risk is reviewed by IT, organizational readiness is a change management concern, and vendor viability is a procurement issue. World-class performers integrate these three domains into a single assessment that asks whether the investment is technically sound, organizationally feasible, and strategically durable. This integration reduces the number of surprises and ensures that risk mitigation spending (training budget, vendor contingency, phased rollout approach) is sized to the actual risk profile rather than allocated according to historical practice.
What leading organizations do
Embed Risk Identification Into Investment Decisions
Technology risk assessment begins with distributed ownership rather than a centralized risk team. The business unit sponsoring an investment owns the strategic risk—whether the technology actually addresses the problem it claims to solve. IT owns technical and architectural risk—whether the solution creates dangerous concentrations of dependency or increases technical debt. The vendor management function owns concentration risk—whether the solution locks the firm into a vendor facing financial stress or strategic distraction. Finance owns cost and realization risk. Rather than a post-hoc review that asks "what could go wrong?", this model embeds risk identification into the investment decision itself, so risks are surfaced before commitment and their mitigation is baked into the funding decision and implementation plan.
The mechanism is straightforward but requires discipline: every material technology investment goes through a structured risk identification process that forces these stakeholders to surface concerns before the contract is signed. Not in a generic risk register, but in concrete terms: which systems will depend on this technology, what happens if the vendor is acquired, what skills gaps will the organization face, what process changes are required, what happens if adoption runs six months behind plan. Once risks are explicit, the investment decision becomes a risk acceptance decision—your finance team and sponsoring business leader have agreed to accept these specific risks in exchange for expected value, and they have approved mitigation spending to reduce those risks to acceptable levels.
Organizations that mature this practice see the difference during implementation. Rather than discovering mid-project that your team lacks the skills to operate the new system, or that business process change was more complex than anticipated, or that integration with a legacy system is creating architectural problems, these issues are already known, already planned for, and already budgeted. That difference is what separates a 70% value realization rate from an 85% rate.
Leading Practice Report
Full detail: IT Risk & Compliance Management
The full report covers:
- Expected benefits
- Core principles
- Key success factors
- Key metrics
- Risks and mitigations
- Implementation roadmap
Assess Organizational Readiness Before Implementation
Technology implementations fail when organizations treat adoption as something that will happen automatically once the technology is deployed. A sophisticated piece of software handed to an unprepared organization will underperform. The same solution given to an organization with strong change management, relevant skills, and clear process redesign will deliver expected value. Organizational Technology Readiness Assessment identifies adoption barriers before they derail implementation—skills gaps, process misalignment, leadership readiness, user motivation—and allows investment sponsors to make a realistic decision about feasibility and timeline.
A readiness assessment operates in three dimensions. First: capability readiness. Does the organization have the skills required to operate and optimize the solution? If not, when will training need to occur, and what does that cost? Second: process readiness. Which current business processes will need to change, and how much organizational change is that? Is the sponsoring business leader prepared to redesign those processes, or will the technology simply automate existing inefficiency? Third: adoption readiness. Do users understand why this change is happening, do they believe it will improve their work, and is leadership visibly committed to the transition? When these dimensions are weak, implementations stall, users resist, and benefits that looked solid on paper never materialize.
Organizations that assess readiness upfront make three different decisions than those that do not. First, they stage implementations to match organizational absorption capacity rather than trying to deploy everything at once. Second, they size change management spending to match adoption risk—if readiness is low, they invest more in training, communication, and user support before and after go-live. Third, they delay investments that would require capabilities the organization is not yet ready to absorb, deferring them until readiness improves. This is why organizations that conduct readiness assessments typically realize benefits faster and with less friction than those that begin with a technology-first approach.
Leading Practice Report
Full detail: Organizational Technology Readiness & Change Adoption Planning
Benefits, core principles, success factors, metrics, risks and the implementation roadmap.
Get the full report →Industry context
Technology risk assessment matters across all sectors, but the nature of the risk varies with operational structure. Organizations in regulated industries—financial services, healthcare, critical infrastructure—face compounded risk: a technology failure is not just an efficiency loss but a regulatory event and a reputational crisis. Their technology investments carry compliance risk alongside operational risk, and their boards expect explicit risk acceptance and mitigation planning. For these organizations, structured risk assessment is often not optional but mandated by audit and compliance functions.
Organizations with distributed technology decisions—multi-unit companies, franchises, holding companies—face a different problem: business units make independent technology choices that create redundant systems, vendor concentration at the corporate level, and architectural fragmentation that creates operational risk during mergers or acquisitions. Risk assessment for these organizations must be decentralized (unit leaders own their decision) but coordinated (corporate governance sets guard rails and identifies concentration risk). Organizations with legacy-heavy portfolios face technical debt risk that younger companies do not—their investments often target modernization or decommissioning, and the risk is not whether the new technology works but whether the organization can afford the parallel-running costs and change management burden of migrating off old systems. In all cases, the three core vulnerabilities remain the same: adoption risk, vendor/dependency risk, and strategy misalignment.
Where to start
- Identify your top 10 technology investments by budget or business criticality. For each, document what organizational readiness was assessed before implementation. If the answer is 'none' or 'informal conversation', that gap is your risk.
- List the technology platforms that, if unavailable, would disrupt critical business processes. Identify the single point of failure for each—the vendor, the person, the system that cannot be easily replaced. Assign ownership for each vulnerability.
- In your next investment approval cycle, require sponsors to explicitly name the three risks they are most concerned about (adoption, vendor, or dependency), describe how each will be mitigated, and confirm that mitigation spending is included in the investment budget.
Ask Kepler Research: How should we structure governance to ensure technology risk assessment happens before investment, not after implementation?
Start free with Ask Kepler →Advanced and emerging approaches
Advanced & Emerging Practices
Emerging practices are included with Ask Kepler Pro and Max.
Unlock these practices →