Why This Matters: When Ordinal Scales Are Not Enough
For most project risks, qualitative analysis using probability-impact matrices and ordinal severity rankings is sufficient to drive good decisions. You do not need to know that a vendor delay has a 63.7% probability to decide that it warrants a contingency plan. Knowing it is "Likely" is enough.
But there are decisions in project management where qualitative rankings break down — where the project manager must choose between competing alternatives with different cost structures, different risk profiles, and different payoff scenarios. Should we buy the land now or later? Should we develop in-house or outsource? Should we invest in a prototype or proceed directly to production? Should we select the low-cost/high-risk vendor or the high-cost/low-risk vendor?
These are risk-cost trade-off decisions, and they require tools that can quantify the economic value of different decision paths under uncertainty. The three primary tools for this purpose are decision tree analysis, expected value calculation, and PERT-based schedule risk analysis — supplemented by sensitivity analysis and simulation for complex scenarios.
What Are Quantitative Risk Tools?
The Quantitative Analysis Toolkit
| Tool | Purpose | When to Use |
|---|---|---|
| Decision Tree | Visualise branching decisions and risk outcomes | When choosing between alternatives with different cost/risk profiles |
| Expected Value (EV) | Calculate the probability-weighted average outcome of a decision | When comparing the economic value of competing decision paths |
| PERT Analysis | Estimate risk-based schedule durations using three-point estimates | When determining buffer sizes for risk-impacted tasks |
| Sensitivity Analysis | Assess how outcomes change when individual variables shift | When identifying which risks have the greatest influence on project outcomes |
| Monte Carlo Simulation | Model the combined effect of multiple risks on schedule/cost | When project complexity makes manual analysis infeasible |
This article focuses on the first three tools, which are directly applicable to practitioner-level risk decisions in defence and heavy engineering projects.
Decision Tree Analysis
The Architecture of a Decision Tree
A decision tree is a diagrammatic tool that maps out decisions, uncertainties, and outcomes in a branching structure that allows systematic comparison of alternative courses of action.
The tree has two types of nodes:
- Decision nodes (represented by a square) — points where the project manager must choose between options. Each option is an arrow extending from the node.
- Chance nodes (represented by a circle) — points of uncertainty where multiple outcomes are possible, each with an associated probability. The probabilities around each chance node must sum to 1.0. Key rules:
- The sum of all probabilities around each chance node must equal 1.0
- The states must represent all possible conditions (mutually exclusive and collectively exhaustive)
- Analysis proceeds from right to left — calculate expected values at the rightmost chance nodes first, then work backward to the decision node
Worked Example — the project manager Land Purchase Decision
The supplied project-risk guidance provides a classic decision tree example that illustrates the technique in a project procurement context.
Scenario: the project manager is a project manager whose company has submitted a proposal to install a telephone trunk line. The project manager has an option on 1,000 acres of right-of-way property at AUD 100/acre. The decision involves whether to buy the land now or wait until the contract is awarded. Known information:
- 60% chance the company will win the contract
- If the project manager buys now and the project is not selected, there is a 60% chance of selling at AUD 100/acre (original price) and a 40% chance of selling at AUD 90/acre
- If the project manager waits and the project is awarded, there is an 80% chance the land will still be AUD 100/acre and a 20% chance it will increase to AUD 120/acre
- Original proposal, based on AUD 100/acre, nets AUD 100,000 profit
Building the tree:
The decision has two options: "Buy Now" and "Buy Later." Each option faces the uncertainty of winning the contract, and then secondary uncertainties about land prices. Analysing "Buy Later" (top branch):
If the project manager waits, the first uncertainty is whether the company wins the contract (60% probability). If they win, the land purchase price is uncertain:
- 80% chance: AUD 100/acre → total cost = AUD 100,000
- 20% chance: AUD 120/acre → total cost = AUD 120,000
Expected land cost if they win:
Expected profit for "Buy Later":
Wait — let me recalculate this properly. The original proposal profits AUD 100,000 when land costs AUD 100,000. If land costs AUD 96,000 on average, the expected profit contribution from the land cost uncertainty when winning is:
Analysing "Buy Now" (bottom branch):
If the project manager buys now at AUD 100/acre (AUD 100,000 total):
- Win contract (60%): Profit = AUD 100,000
- Lose contract (40%): Must sell land
- 60% chance: sell at AUD 100/acre → break even on land
- 40% chance: sell at AUD 90/acre → lose AUD 10,000
Expected value of selling if contract lost:
Expected loss if contract lost = AUD 100,000 − AUD 96,000 = AUD 4,000
Expected profit for "Buy Now":
Decision: "Buy Now" has an expected value of AUD 58,400 versus "Buy Later" at AUD 57,600. The optimal decision is to buy now — the expected value is AUD 800 higher.
Decision Trees in Defence Procurement
In defence contexts, decision trees are valuable for evaluating procurement strategies under uncertainty. Consider:
Decision: Should a Tier-1 contractor develop a critical radar subsystem in-house or subcontract to a specialist firm?
| Branch | Probability | Outcome |
|---|---|---|
| In-house, success | 70% | On schedule, AUD 12M cost |
| In-house, technical failure | 30% | 9-month delay + AUD 18M cost |
| Subcontract, on-time delivery | 80% | On schedule, AUD 15M cost |
| Subcontract, late delivery | 20% | 4-month delay + AUD 17M cost |
On expected cost alone, in-house development wins (AUD 13.8M vs AUD 15.4M). But the decision is not purely about cost — the 30% chance of a 9-month delay in the in-house option has schedule consequences that may cascade to other subsystems. The decision tree makes these trade-offs explicit and quantifiable.
Expected Value
The Mathematics of Risk-Weighted Decisions
Expected value (EV) is the fundamental calculation underlying decision tree analysis. It provides the probability-weighted average outcome of a decision:
Where:
- = probability of outcome
- = value (profit, loss, or cost) of outcome
- = number of possible outcomes
Expected value is particularly useful for:
- Comparing decision alternatives (as in the decision tree examples above)
- Calculating the Risk Event Status or expected monetary value of a risk:
- Prioritising risks by economic exposure rather than ordinal severity rankings
Limitations of Expected Value
Expected value is an average — it tells you what you would expect on average across many repetitions of the same decision. For one-off project decisions, the EV may not capture the decision-maker's actual risk preference:
| Scenario | EV | Problem |
|---|---|---|
| 50% chance of AUD 200K profit, 50% chance of AUD 200K loss | EV = AUD 0 | A risk-averse PM would reject this gamble even though EV is neutral |
| 99% chance of AUD 10K profit, 1% chance of AUD 10M loss | EV = -AUD 90K | The catastrophic downside may be unacceptable regardless of high probability of profit |
In these cases, risk appetite and tolerance thresholds (covered in earlier articles in this series) must supplement the EV calculation. Expected value is a tool for analysis, not a substitute for judgement.
PERT Analysis for Risk-Based Scheduling
Three-Point Estimation
The Program Evaluation and Review Technique (PERT) uses three duration estimates to calculate a risk-adjusted expected duration for each task:
Where:
- = Optimistic duration — the best-case scenario if everything goes right
- = Most Likely duration — the normal-conditions estimate
- = Pessimistic duration — the worst-case scenario if the risk materialises
The standard deviation of the PERT estimate is:
And the variance:
PERT for Budget Risk
The supplied project-risk guidance notes that the PERT three-point estimation technique can be applied to dollars as well as time. This allows the project manager to calculate a risk-based budget estimate:
Where , , and are optimistic, most likely, and pessimistic cost estimates respectively. The difference between the expected budget and the pessimistic budget represents the cost contingency reserve.
Buffer Calculation from PERT
The connection between PERT analysis and the buffer management approach from the Risk Matrix article is direct:
These buffers are withheld by the project manager and deployed when risk triggers fire, aligning with the Theory of Constraints approach where project-level buffers replace task-level padding.
Worked Example — Radar Integration PERT
For the radar-CMS integration task on a defence programme:
| Estimate Type | Duration | Basis |
|---|---|---|
| Optimistic () | 12 weeks | Clean API documentation, full test environment available |
| Most Likely () | 18 weeks | Minor API gaps, partial test environment |
| Pessimistic () | 30 weeks | Major API rework, EMI issues, security clearance delays |
The baseline schedule shows 19 weeks for radar integration. The project manager holds an 11-week buffer reserve, deployable in increments as specific risk triggers activate.
Sensitivity Analysis
Identifying the Risks That Matter Most
Sensitivity analysis examines how the project outcome changes when individual risk variables are adjusted while holding all others constant. This identifies the key risk drivers — the variables whose uncertainty has the greatest influence on project success.
The output is typically visualised as a tornado diagram, which ranks variables by the width of their outcome range:
| Variable | Low Estimate Impact | High Estimate Impact | Range |
|---|---|---|---|
| Subcontractor delivery time | -AUD 50K (early) | +AUD 400K (late) | AUD 450K |
| Steel alloy unit price | -AUD 20K | +AUD 180K | AUD 200K |
| Labour productivity rate | +AUD 30K | +AUD 150K | AUD 120K |
| Equipment availability | AUD 0 | +AUD 80K | AUD 80K |
| Weather delays | AUD 0 | +AUD 60K | AUD 60K |
The tornado diagram tells the project manager where to focus risk management effort: subcontractor delivery time has by far the largest influence on project cost outcomes, making it the highest-priority risk for contingency planning and active monitoring.
Simulation — When Complexity Exceeds Manual Analysis
Monte Carlo Overview
When a project has many interacting risks — where the combined effect of simultaneous risk events cannot be calculated by adding individual impacts — Monte Carlo simulation models the overall distribution of possible outcomes.
The process involves:
- Define probability distributions for each uncertain variable (cost, duration, probability of occurrence)
- Randomly sample from each distribution simultaneously
- Calculate the project outcome (total cost, total duration) for that sample
- Repeat thousands of times to build a probability distribution of project outcomes
The output is a probability curve showing, for example, that there is a 50% confidence that the project will complete within 24 months, an 80% confidence within 27 months, and a 95% confidence within 31 months.
Monte Carlo is powerful but requires specialised tools (such as simulation software, simulation software, or schedule-risk software) and trained practitioners. It is typically reserved for:
- Large, complex programmes (>AUD 100M)
- Projects with significant schedule or cost uncertainty across many work packages
- Programmes where governance bodies require quantified confidence levels for cost and schedule forecasts
Common Pitfalls in Quantitative Risk Analysis
Pitfall 1 — Applying Quantitative Tools to Every Risk
Quantitative analysis is resource-intensive and adds value only for risks where the precision genuinely changes the decision. Applying decision tree analysis to a low-impact risk wastes analytical effort that would be better spent on improving qualitative identification and response planning.
Pitfall 2 — False Precision in Probability Estimates
Decision tree analysis is only as good as the probability estimates fed into it. If the probability of winning a contract is estimated at 60% based on gut feel rather than historical bid success data, the expected value calculation inherits that uncertainty. The output should be treated as indicative, not definitive.
Pitfall 3 — Ignoring Risk Appetite in EV Decisions
Expected value optimisation can lead to decisions that are mathematically optimal but organisationally unacceptable. A project with the highest EV but a 20% chance of catastrophic loss may be rejected by risk-averse stakeholders — and rightly so. EV must be interpreted through the lens of organisational risk appetite and tolerance thresholds.
Pitfall 4 — PERT Without Calibration
The PERT formula assumes a beta distribution, which may not match the actual distribution of durations for a given task. More importantly, the optimistic and pessimistic estimates are only as good as the experience and honesty of the estimators. Systematic optimism bias (common in project environments) will underestimate the pessimistic duration, leading to undersized buffers.
Key Takeaways
Quantitative tools supplement qualitative analysis for the small number of high-impact decisions where the choice between alternatives depends on economic trade-offs under uncertainty.
Decision trees map decisions and uncertainties in a branching structure that enables systematic comparison of alternatives using expected value.
Expected value provides a probability-weighted average outcome but must be interpreted through risk appetite — the mathematically optimal decision may be organisationally unacceptable.
PERT three-point estimation calculates risk-adjusted durations and budgets, directly producing the buffer reserves that the project manager deploys when risk triggers fire.
Sensitivity analysis identifies the key risk drivers — the variables with the greatest influence on project outcomes — so that management attention is focused where it matters most.
Monte Carlo simulation is reserved for large, complex programmes where the interaction of multiple risks makes manual analysis infeasible and governance frameworks require quantified confidence levels.
All quantitative tools are limited by the quality of their inputs. False precision in probability estimates, uncalibrated PERT ranges, and optimism bias in estimating all undermine the value of quantitative analysis.
