Another reason that I observed is that large organizations are extremely afraid of mistakes regardless of expected loss. Such companies appoint gatekeepers, and those gatekeepers are by nature risk averse. The gatekeepers will simply reject any idea by default, unless there is a well-proven precedent. As a result, anything moves slowly.
Also true. In the meantime, wanting to use Guava 33 instead of Guava 27 will get rejected immediately. Using Spark instead of AWS Batch is an absolute no no. I guess what qualifies as risk is also highly asymmetrical.