RUN vs BUILD IT spending allocation in non-IT primary businesses

2026-03-08 · cost-performance tools-infrastructure workforce-skills · medium · source → · wiki →
key claims
  1. Gartner's Run-Grow-Transform model and TBM Council's ATUM model define RUN identically as all costs sustaining existing IT operations at current service levels, differing only in calling the discretionary-enhancement middle tier "Grow" (Gartner) versus "Build" (TBM); for non-IT primary businesses the practical distinction is immaterial
  2. Industry benchmarks from Gartner-aligned secondary sources place the RUN ratio for non-IT primary businesses at approximately 65–70% of total IT spend, trending gradually toward 60% as digital transformation investment increases across 2019–2023
  3. Financial services organisations (banking, insurance) carry RUN ratios of 75–80% of total IT cost, driven by legacy system maintenance, mandatory regulatory compliance infrastructure, and risk management system sustainment requirements
  4. Manufacturing and retail sectors benchmark at 65–70% RUN, with BUILD allocations accelerating since 2020 due to e-commerce, supply chain digitisation, IoT, and smart manufacturing investments
  5. McKinsey's "flip the ratio" study found that FTE-based RUN ratios at financial services institutions were approximately 90% before transformation programmes — substantially higher than the cost-based 75–80% benchmark — because knowledge workers concentrate in operational support roles while large vendor and infrastructure costs inflate the apparent BUILD share
  6. Activity-based costing is the technically correct apportionment method for shared IT overhead (security, architecture, management, coaching): each team's total cost pool is split RUN/BUILD in proportion to measured activities, using time logs as the primary driver and manager-estimated ratios as an accepted fallback
  7. Software licence renewals, managed service BAU contracts, and cybersecurity operational spend are classified as RUN; initial licence acquisition, project-phase implementation fees, and new system deployments are BUILD; mandatory vendor-forced end-of-life migrations are classified as RUN based on purpose (operational continuity, not new capability)
  8. FTE time logging is the most defensible proxy measure for indirect cost allocation; ticket-type ratios (incident/service request = RUN; project delivery = BUILD) provide a secondary check; Flow Distribution from the Flow Framework provides a real-time team-level signal where product delivery is organised around value streams

Research Question

How do non-IT primary businesses (manufacturing, retail, finance) calculate and apportion IT spending between RUN (nondiscretionary operational sustainment) and BUILD (discretionary strategic enhancement) activities, using documented industry frameworks and real-world productionised examples with quantitative outcomes?

Findings

Executive Summary

Non-IT primary businesses (manufacturing, retail, finance) calculate the RUN vs BUILD IT spending split using a converged methodology centred on the TBM Council's ATUM taxonomy as the operational framework, with Gartner's Run-Grow-Transform model providing the benchmarking and communication layer. Typical benchmarks are 65–70% RUN by total IT cost for manufacturing and retail, 75–80% for financial services, and up to 90% by FTE-allocation at heavily legacy-burdened institutions. Activity-based costing is the correct technique for apportioning shared/indirect IT costs; FTE time logging is the primary proxy where ABC cannot be fully implemented. The primary quantified value of establishing this classification is not the ratio shift itself but the benchmarked optimisation it enables: National Grid achieved $47M in first-year IT savings using TBM-sourced benchmark data, and MassMutual eliminated $75M in application costs during a divestiture using TBM allocation data.

Key Findings

  1. Gartner's Run-Grow-Transform model and TBM Council's ATUM model define RUN identically as all costs sustaining existing IT operations at current service levels, differing only in calling the discretionary-enhancement middle tier "Grow" (Gartner) versus "Build" (TBM); for non-IT primary businesses the practical distinction is immaterial.
  2. Industry benchmarks from Gartner-aligned secondary sources place the RUN ratio for non-IT primary businesses at approximately 65–70% of total IT spend, trending gradually toward 60% as digital transformation investment increases across 2019–2023.
  3. Financial services organisations (banking, insurance) carry RUN ratios of 75–80% of total IT cost, driven by legacy system maintenance, mandatory regulatory compliance infrastructure, and risk management system sustainment requirements.
  4. Manufacturing and retail sectors benchmark at 65–70% RUN, with BUILD allocations accelerating since 2020 due to e-commerce, supply chain digitisation, IoT, and smart manufacturing investments.
  5. McKinsey's "flip the ratio" study found that FTE-based RUN ratios at financial services institutions were approximately 90% before transformation programmes — substantially higher than the cost-based 75–80% benchmark — because knowledge workers concentrate in operational support roles while large vendor and infrastructure costs inflate the apparent BUILD share.
  6. Activity-based costing is the technically correct apportionment method for shared IT overhead (security, architecture, management, coaching): each team's total cost pool is split RUN/BUILD in proportion to measured activities, using time logs as the primary driver and manager-estimated ratios as an accepted fallback.
  7. Software licence renewals, managed service BAU contracts, and cybersecurity operational spend are classified as RUN; initial licence acquisition, project-phase implementation fees, and new system deployments are BUILD; mandatory vendor-forced end-of-life migrations are classified as RUN based on purpose (operational continuity, not new capability).
  8. FTE time logging is the most defensible proxy measure for indirect cost allocation; ticket-type ratios (incident/service request = RUN; project delivery = BUILD) provide a secondary check; Flow Distribution from the Flow Framework provides a real-time team-level signal where product delivery is organised around value streams.
  9. National Grid (energy utility) implemented TBM using Apptio in 2018, initiated approximately 130 benchmark-driven optimisations across its application, network, cloud, and technical debt portfolios, and achieved $47M in annual IT savings in the first year, exceeding its target, toward a $100M three-year savings goal.
  10. MassMutual (insurance) implemented TBM consumption-driven cost allocation across 450+ applications and used the resulting data to eliminate $75M in costs during a major business divestiture, demonstrating the value of RUN/BUILD transparency beyond routine portfolio management.
  11. The critical unmodelled failure mode in RUN/BUILD classification is the multi-year RUN tail of BUILD investments: each BUILD project creates a permanent annual RUN cost increment that, if not modelled at approval time, systematically inflates the RUN ratio in future periods and crowds out further BUILD investment.
  12. No publicly available standard driver ratios for shared IT services (security, architecture, management) exist in the literature; organisations must establish their own ratios from time studies or annually reviewed manager estimates, documented as cost model assumptions.

Assumptions

Analysis

Three frameworks approach the same question from complementary angles. Gartner RGT provides the executive communication vocabulary and industry benchmarks. TBM ATUM provides the operational cost classification machinery, including the IT Tower hierarchy, activity-based allocation rules, and integration guidance for GL/CMDB/HR data. McKinsey's FTE-ratio method provides a workforce diagnostic that captures what cost-based measures obscure: the concentration of human effort in operational support.

The evidence resolves the central methodology question unambiguously: TBM ATUM is the most complete and most widely adopted framework for non-IT primary businesses. It has the largest published case study base, an active industry council maintaining the standard, and tooling support (Apptio, ServiceNow ITFM) that connects financial classification to operational data. For organisations without ITFM tooling, Gartner's simpler RGT model provides adequate structure for executive-level reporting and benchmarking, at the cost of precision in shared-cost apportionment.

The most significant tension in the evidence is between precision and practicality. ABC-based apportionment of shared IT costs is technically correct but requires time-study data, activity mapping, and cost driver maintenance. Organisations that cannot sustain this invest level use fixed management-estimated ratios — less accurate but operationally sustainable. The evidence from federal TBM adoption (Markonsolutions, US Army, OMB mandate) shows that even large organisations often start with simplified allocation models and mature toward ABC over time.

Risks, Gaps, and Uncertainties

Open Questions

  1. Detailed step-by-step calculation methodology for a non-IT primary business — what is the full process for apportioning a complete IT budget (including blended vendor contracts, partially allocated roles, and contested upgrade classifications) to RUN/BUILD/TRANSFORM? This directly unblocks 2026-03-07-run-build-it-allocation-implementation-how.
  2. Published ABC driver ratios for shared IT services — is there any Gartner, TBM Council, or consulting firm publication that provides empirical benchmarks for the RUN/BUILD split of security, enterprise architecture, management, and coaching teams?
  3. Multi-year RUN tail modelling — what are the standard financial modelling templates or TBM tools for projecting the ongoing RUN cost increment created by each approved BUILD investment at approval time?
  4. ITFM tooling comparison — what are the implementation cost, capability, and suitability profiles of Apptio, ServiceNow ITFM, Broadcom Clarity, and spreadsheet-based approaches for non-IT primary businesses of different scale?

sources


Connected items

Loading…

View full knowledge graph →