Why This Matters: The Numbers That Drive Decisions
When a UK defence programme board decides whether to approve a £2.3 billion contract, a central question must be answered: What is the probability that this programme will be delivered within budget and on schedule? The answer does not come from a risk register filled with qualitative assessments of "High" and "Medium." It comes from quantitative risk analysis — specifically, Monte Carlo simulation models that produce probability distributions showing the range of possible cost and schedule outcomes.
Quantitative risk analysis (QRA) is the engine that converts qualitative risk information into decision-grade intelligence. It transforms subjective probability and impact assessments into statistical distributions, models the cumulative effect of multiple interacting risks on project outcomes, and produces confidence levels that enable risk-based decision-making on contingency, pricing, milestone setting, and programme viability.
Yet QRA is also the area where project risk management is most vulnerable to the production of impressive-looking but fundamentally misleading outputs. As an experienced risk practitioner warned using the term coined by early practitioners: GIGO — Garbage In, Gospel Out. People get blinded by the science, the mathematics, and the graphs, and lose sight of what the analysis actually means.
The Evolution of Quantitative Tools
The Mainframe Era (1975–1985)
An early practitioner account of quantitative risk analysis illustrates the technological constraints that shaped the discipline's development. In 1977, an early specialist risk consultancy used schedule-risk software, a simulation programme developed by a university research group, running on a time-shared computer in a remote computing centre. Data was input on punched cards and transmitted via a 300-baud modem. Computing was expensive, limiting risk analysis to high-capital, high-exposure ventures.
Despite these constraints, the early practitioners built sophisticated models incorporating time, existence, and resource uncertainty. They modelled weather effects, complex pipe-laying scenarios, repeating tasks, and plant breakdowns. The analytical ambition was remarkable; it was the technology that imposed limits, not the methodology.
The Desktop Revolution (1985–2000)
The arrival of personal computers in the early 1980s transformed QRA accessibility. Monte Carlo simulation add-ins for spreadsheets (simulation software, simulation software) and critical path method tools (schedule-risk software evolving into schedule-risk software, which became schedule-risk software) brought quantitative analysis within reach of individual practitioners rather than specialist bureaus.
Project-risk guidance wrote his first risk register programme using legacy database software. By the late 1980s, his company had developed integrated cost-schedule risk analysis with stochastic branches, dependency groups, probabilistic resource-levelling, and alternative calendars — features that remain at the leading edge of practice today.
Modern Integrated Tools (2000–Present)
Today's tools are cheap, fast, and reliable. A Monte Carlo simulation that once required hours of mainframe time runs in seconds on a laptop. Software packages integrate directly with project scheduling tools (scheduling software, scheduling software), enabling risk-adjusted schedules and cost estimates to be produced and updated routinely.
| Era | Representative Tools | Typical Capability |
|---|---|---|
| 1975–1985 | schedule-risk software (mainframe) | Schedule simulation; limited distributions |
| 1985–1995 | risk-analysis software, early schedule-risk software | PC-based cost and schedule simulation |
| 1995–2005 | simulation software, simulation software, schedule-risk software | Integrated simulation with scheduling tools |
| 2005–present | schedule-risk software, specialist schedule-risk software, risk-analysis software | Full integration with P6/MSP; real-time updating |
Core Quantitative Techniques
Monte Carlo Simulation
Monte Carlo simulation is the workhorse of quantitative risk analysis. The technique works by replacing single-point estimates for uncertain variables (activity durations, cost elements, risk event probabilities) with probability distributions, then running thousands of iterations of the project model. Each iteration randomly samples values from each distribution, calculates the project outcome, and records the result. The aggregate of all iterations produces a probability distribution of the overall project outcome.
The output — typically displayed as an S-curve (cumulative probability distribution) — answers questions such as:
- What is the P50 (50th percentile) cost? This is the expected cost — there is a 50% probability of being at or below this value.
- What is the P80 cost? This is the cost at which there is an 80% probability of delivery — a common threshold for management reserve calculation.
- What is the probability of achieving the current budget? If the budget sits at the P35, there is only a 35% chance of delivery within budget — an unacceptable risk exposure.
Three-Point Estimation
The foundation of any Monte Carlo model is the estimation of uncertainty ranges for each variable. Three-point estimation provides the minimum, most likely, and maximum values that define the shape of each distribution:
| Parameter | Symbol | Meaning | Estimation Guidance |
|---|---|---|---|
| Minimum | Plausible best case — achievable if everything goes well | P10 — 10% probability of being below this value | |
| Most Likely | Expected outcome under normal conditions | The mode of the distribution | |
| Maximum | Plausible worst case — outcome if significant problems occur | P90 — 90% probability of being below this value |
These three points define a triangular distribution (the most commonly used in project risk analysis) or a PERT-Beta distribution (which places more weight on the most likely value):
Schedule Risk Analysis
Schedule risk analysis applies Monte Carlo simulation to the project network schedule rather than to individual cost elements. Each activity's duration is replaced with a three-point estimate, and risk events are linked to specific activities or groups of activities (either extending their duration, introducing new activities, or changing the network logic).
The output shows the probability distribution of achieving each project milestone, enabling risk-based milestone setting. If the current contracted delivery date sits at the P30, the schedule has only a 30% probability of achievement — a finding that should trigger immediate corrective action.
Sensitivity Analysis
Sensitivity analysis identifies which uncertain variables have the greatest influence on the overall project outcome. The most common output is a tornado diagram — a horizontal bar chart showing the correlation between each input variable and the output, ranked from highest to lowest influence.
Sensitivity analysis answers the critical question: Where should we focus our risk management effort? If three activities drive 60% of the schedule variance, those activities deserve the most intensive risk mitigation — regardless of whether their individual risk register entries are rated "High" or "Medium."
The GIGO Problem: When Tools Mislead
Garbage In, Gospel Out
Practitioner guidance warning about GIGO reflects a persistent challenge. The mathematical sophistication of Monte Carlo simulation can create an illusion of precision that masks fundamental weaknesses in the underlying inputs. A simulation running 10,000 iterations produces outputs to multiple decimal places — but if the input distributions are based on uninformed guesses, anchored estimates, or politically constrained ranges, the precision is entirely spurious.
Common input problems include:
Symmetric ranges when reality is asymmetric. Many estimators provide symmetric three-point estimates (e.g., 10–15–20 weeks) because they are easier to think about. But project activity durations are almost always positively skewed — there are more ways for things to go wrong than to go right. An honest estimate might be 10–14–25 weeks. Unrealistically narrow ranges. Estimators often provide ranges that are too narrow, particularly for novel or complex activities. A range of 12–15–18 weeks for a first-of-class combat system integration suggests either deep expertise in a highly predictable activity or (more likely) a failure to acknowledge the true extent of uncertainty. Ignoring correlations. If the project is using the same scarce workforce across multiple activities, delays in one will cause delays in others — but standard Monte Carlo models typically assume independence between activity durations unless correlations are explicitly modelled. Ignoring correlations systematically underestimates overall project risk. Omitting risk events. A schedule risk model that includes duration uncertainty on activities but does not include discrete risk events (e.g., "Supplier X fails to deliver on time — probability 25%, impact 8 weeks") will underestimate overall risk. Conversely, a model that includes risk events but not baseline duration uncertainty will also underestimate — because it assumes the base plan is certain, which it never is.
The Interpretation Challenge
Even with high-quality inputs, QRA outputs can be misinterpreted. Common misinterpretations include:
Treating P50 as "the answer." The P50 is the expected value — there is a 50% chance of being above it and 50% below. Using P50 as a project commitment guarantees that half of all projects will overrun. Commitment figures should typically be set at P80 or higher, depending on the organisation's risk appetite. Confusing precision with accuracy. An output of "AUD 247.3 million at P80" implies a level of precision that the underlying estimates do not support. The appropriate communication might be "approximately AUD 250 million at the 80th percentile."Ignoring the shape of the distribution. A project with a P50 of AUD 200M and a P90 of AUD 210M has a very different risk profile from one with a P50 of AUD 200M and a P90 of AUD 350M, even though their expected costs are identical. The shape of the distribution — particularly the length and weight of the tail — matters enormously for decision-making.
The Relationship Between Qualitative and Quantitative Analysis
A persistent tension in project risk management practice is the relationship between qualitative assessment (risk registers, P-I matrices) and quantitative analysis (Monte Carlo simulation). In the early days, as project-risk guidance noted, quantitative analysis was "done separately in isolation from the qualitative assessment recorded in risk registers." Modern best practice recognises the importance of aligning both.
The optimal relationship is sequential and complementary:
Qualitative assessment provides the initial identification, screening, and prioritisation of risks. It enables rapid evaluation of a large number of risks and focuses attention on those that warrant deeper analysis. Quantitative analysis then models the cumulative effect of the high-priority risks (and baseline estimation uncertainty) on overall project outcomes. It provides the probability distributions, confidence levels, and sensitivity rankings that support major decisions.
Neither can substitute for the other. A qualitative-only approach cannot model cumulative effects or produce confidence levels. A quantitative-only approach cannot capture the rich contextual information in risk descriptions, the nuances of response strategies, or the political and organisational dimensions of risk.
The Earned Value Connection
The professional risk working group and the Earned Value Management (EVM) SIG collaborated to produce guidance on integrating the deterministic framework of EVM with the probabilistic emphasis of risk management. As practitioner guidance noted, "If properly understood, such techniques can really help inform decision-making."
The integration works in both directions. Risk analysis informs EVM by providing risk-adjusted estimates for Estimate at Completion (EAC), enabling the EAC to reflect not just current performance trends but also the effect of unrealised risks. EVM informs risk analysis by providing actual performance data (CPI, SPI) that can be used to update risk model inputs, replacing initial estimates with observed values as the project progresses.
The risk-adjusted EAC can be expressed as:
Where the expected value of remaining risks is derived from the Monte Carlo model's output for the remaining project scope.
Pitfalls: When Quantitative Analysis Goes Wrong
Running the model before building the foundation. Monte Carlo simulation requires a well-structured project schedule or cost estimate as its starting point. Running a simulation on a schedule with missing logic, summary-level activities, or unrealistic constraints produces meaningless outputs. Using default distributions without thought. Many tools default to triangular distributions, but not all uncertainties are best represented by triangles. Uniform distributions may be appropriate when the estimator has no basis for favouring any value within the range. Log-normal distributions may better represent cost uncertainties with long right tails. Presenting outputs without context. An S-curve without explanation is a picture, not a decision support tool. Effective QRA communication includes: what the model includes and excludes, the key assumptions and their sensitivity, the confidence level at the current budget/schedule, and the specific decisions the analysis supports. Treating the model as truth. As practitioner guidance observed, risk analysis should be understood as decision support, not prediction. The value lies not in the specific P80 figure but in the insight it provides about where risk is concentrated, how sensitive the outcome is to key assumptions, and what the effect of different response strategies might be. Failing to update. A quantitative model built at programme start and never updated is an archaeological artefact. As risks materialise, are mitigated, or expire, and as actual performance data becomes available, the model should be updated to reflect current reality.
Key Takeaways
1. Quantitative risk analysis — principally Monte Carlo simulation — transforms qualitative risk information into probability distributions that support major project decisions on contingency, pricing, milestone setting, and programme viability. 2. The evolution from mainframe bureaus to desktop tools has made QRA accessible to individual practitioners, but accessibility does not guarantee quality. The GIGO principle — Garbage In, Gospel Out — remains the discipline's most persistent challenge. 3. Three-point estimation is the foundation of QRA. The quality of the analysis depends entirely on the quality of these estimates, which must reflect genuine uncertainty ranges (typically asymmetric) rather than comfortable, narrow, symmetric guesses. 4. Qualitative and quantitative analysis are complementary, not competing approaches. Qualitative assessment screens and prioritises; quantitative analysis models cumulative effects and produces confidence levels. Neither can substitute for the other. 5. The purpose of QRA is decision support, not prediction. The value lies in understanding where risk is concentrated, how sensitive outcomes are to key assumptions, and what the effect of different response strategies might be — not in generating spuriously precise point estimates.
