The mechanism is almost always the same and it is not dishonesty. Each vendor reports accurately on its own scope. Each report is green because each vendor is doing what its contract says. What nobody reports on is the space between the contracts, which is where the dependencies live, and a dependency with no owner is a dependency that will be discovered at integration.
Reporting drifts by increments rather than by lies. A milestone gets redefined slightly to reflect what was actually achievable. A risk moves from red to amber because it is being managed, which is true, without the underlying exposure changing. None of these is a misrepresentation and the cumulative effect is a status pack that describes a programme nobody would recognise from the inside.
The sponsor is usually the last to know, and structurally so. Bad news travels slowly upward because each layer reasonably hopes to have resolved it before it needs escalating. By the time the gap is undeniable, the options that were available six months earlier, rescope, resequence, renegotiate, have expired, and what remains is expensive.
Multi-vendor programmes concentrate all of this. Each vendor has commercial reasons to hold its position, a different reporting cadence, and a different definition of done. Without a single plan and a single dependency register, integration becomes the moment when four accurate accounts of progress turn out to be incompatible.
And there is a specific failure that is worth naming because it is so common: the programme where everyone senior privately knows the date will not hold, and nobody will say it, because the person who says it first owns the consequence. That is a governance failure rather than a delivery one, and it is fixable by giving the assessment to someone whose job is to make it.