From Risk Register to Quantified Model
Most registers cannot be simulated, and the reason is not technical.
There are fifty entries in the register and somebody now wants a P80. It sounds like an import problem. It is not. Most register entries are not statements about anything a model can consume, and discovering that is the first genuinely useful output of trying.
Published
Key Takeaways
- A register lists events with ratings. A model needs quantities attached to specific activities or cost items. The translation is mostly rewriting rather than importing, and the rewriting is where the real risk conversation happens.
- Two kinds of uncertainty need separating: inherent variability that occurs regardless, modelled by ranging, and discrete events that either occur or do not, modelled with a probability and an impact. A register built only from events misses the first entirely.
- Correlation matters more than the choice of distribution. Analysis of 216 buildings found omitting it distorts results more than distribution shape does, and ignoring it yields a distribution that is too narrow and a contingency that is too small.
Research foundation
The distinction between event risk and broader uncertainty is established by Ward and Chapman (2003). The correlation finding is Wall (1997), supported by Touran and colleagues on correlated random variables in construction simulation. Method guidance for the risk driver approach is AACE Recommended Practice 57R-09 and Hulett's Integrated Cost-Schedule Risk Analysis. One honest limitation is stated in the text: no peer-reviewed source addresses double counting between ranged uncertainty and discrete events, so that guidance is practice-based rather than published. The Four A's are the executive lens applied to this material.
The first attempt usually fails in a specific and instructive way. Someone exports the register, opens the modelling tool, and finds that a large share of the entries cannot be attached to anything. “Stakeholder resistance.” “Insufficient resources.” “Scope creep.” Each is a real concern and none of them is a quantity.
Why will most registers not simulate?
Because a register is written to be reviewed and a model is written to be computed, and those are different jobs.
A model needs three things for each item: a quantity, an attachment point, and a shape. What is the impact in days or dollars, which activity or cost item does it land on, and what is the range or the probability. A typical register entry supplies a description, a likelihood word, an impact word and an owner. None of those four is an input.
This is where the work becomes valuable rather than annoying. Forcing an entry to name its attachment point reveals that nobody had thought about where the consequence would actually land. Forcing a quantity surfaces disagreement that the shared vocabulary had been concealing, which is the argument in Why 'Likely' Is Not a Probability.
What are the two kinds of uncertainty?
Inherent uncertainty
Variability present whatever else happens. Productivity will not exactly match the assumption, quantities move as design matures, a thirty-day activity is genuinely a twenty-five to forty-five day activity. This is modelled by ranging the estimate or the durations, and on a well-run project it is usually the larger contributor.
It is also usually absent from the register, because a register is a list of things that might go wrong and ordinary variability does not feel like a risk. Ward and Chapman made exactly this argument in proposing that project risk management be reframed as uncertainty management: an event-based framing overlooks variability and ambiguity, which are not events and so never get logged.
Discrete risk events
Things that either happen or do not. The permit is refused. The long-lead item slips. These carry a probability and an impact and attach to specific activities or items. This is the category a register is actually built for, and the modelling approach, including the risk driver method where one risk can affect several activities at once, is set out in AACE Recommended Practice 57R-09 and in Hulett's treatment of integrated cost and schedule risk.
Where does double counting come from?
From modelling the same uncertainty twice under two names, and it is the most common reason these models overstate contingency.
The classic version: an activity is given a duration range wide enough to accommodate a possible supplier delay, and a discrete risk event for that same delay is also attached to the same activity. Both are defensible individually. Together they charge the project twice. The subtler version is a base estimate that already contains buried contingency with modelled uncertainty layered on top, which is precisely why FTA requires a stripped and adjusted base before its model runs.
I should be straight about the evidence. This failure mode is well known to practitioners and I could find no peer-reviewed study addressing it. The guidance lives in the AACE recommended practices and in Hulett's book rather than in the journal literature, so treat it as experienced practice rather than a published finding.
Why does correlation matter more than people think?
Because independence is the default assumption in most tools and it is almost always wrong.
Cost and schedule elements on a real project move together. The same labour market drives several trades. The same design immaturity affects several packages. The same weather season affects everything outdoors. A model that samples them independently produces a distribution that is too narrow, because offsetting highs and lows cancel in a way reality does not permit. Too narrow means the tail is understated, and the tail is where contingency comes from.
Wall analysed cost data from 216 office buildings and found that omitting correlation distorts risk results more than the choice of input distribution does, which is striking given how much practitioner argument is spent on distribution shape. Touran and Wiser had earlier set out a technique for Monte Carlo simulation with correlated random variables, and Touran and Lerdwuthirong followed with rank correlations in construction cost simulation.
The practical implication is unglamorous. An hour spent agreeing which cost groups move together is worth more than an afternoon arguing about triangular versus PERT.
Why is this an Adaptability problem?
Because the translation forces the organization to say things it has been comfortable not saying, and that is a learning capability rather than an analytical one.
Quantifying a register converts vague collective anxiety into specific, attributable numbers. “Stakeholder resistance” becomes an estimate of how many weeks a particular approval could slip and who believes it. That is more useful and more uncomfortable. Organizations that cannot hold the discomfort resolve it by keeping the register qualitative, which preserves the appearance of risk management while removing anything that could be tested against outcomes.
The tell is a quantification exercise that stalls at the estimating step and is never restarted. The obstacle is rarely the mathematics. It is that someone would have to put a number next to a colleague's work, and nothing in the organization has made that a normal thing to do.
Evidence matrix
| Claim | Evidence tier | Source |
|---|---|---|
| Event-based registers systematically miss variability and ambiguity | Peer reviewed | Ward & Chapman (2003), IJPM 21(2) |
| Omitting correlation distorts results more than distribution choice | Peer reviewed, empirical | Wall (1997), Construction Management and Economics 15(3) |
| Correlated random variables require explicit technique | Peer reviewed | Touran & Wiser (1992); Touran & Lerdwuthirong (1997), JCEM |
| Risk drivers can affect multiple activities simultaneously | Method guidance | AACE RP 57R-09 (2019); Hulett (2011) |
| Double counting between ranges and events | Practice, not published evidence | No peer-reviewed source located |
| The blocking step is social, not mathematical | Four A's interpretation | Builders Build, Adaptability |
What to do with this
Take the top ten entries in your register and try to write, for each, the activity or cost item it lands on and the impact in days or dollars. The ones you cannot complete are not badly written risks. They are places where the organization has not yet decided what it believes, and that list is more valuable than the model you were trying to build.
References
- Ward, Stephen, and Chris Chapman. “Transforming Project Risk Management into Project Uncertainty Management.” International Journal of Project Management, vol. 21, no. 2, 2003, pp. 97–105. doi.org/10.1016/S0263-7863(01)00080-1.
- Wall, D. M. “Distributions and Correlations in Monte Carlo Simulation.” Construction Management and Economics, vol. 15, no. 3, 1997, pp. 241–258. doi.org/10.1080/014461997372980. Finds omitting correlation distorts results more than the choice of distribution, from 216 office buildings.
- Touran, Ali, and Edward P. Wiser. “Monte Carlo Technique with Correlated Random Variables.” Journal of Construction Engineering and Management, vol. 118, no. 2, 1992, pp. 258–272. doi.org/10.1061/(ASCE)0733-9364(1992)118:2(258).
- Touran, Ali, and Suphot Lerdwuthirong. “Rank Correlations in Simulating Construction Costs.” Journal of Construction Engineering and Management, vol. 123, no. 3, 1997, pp. 297–301. doi.org/10.1061/(ASCE)0733-9364(1997)123:3(297).
- Hulett, David T. Integrated Cost-Schedule Risk Analysis. Gower Publishing, 2011. ISBN 978-0-566-09166-7. Reissued by Routledge. The standard practitioner treatment of the risk driver method.
- AACE International. Recommended Practice No. 57R-09: Integrated Cost and Schedule Risk Analysis Using Risk Drivers and Monte Carlo Simulation of a CPM Model. Issued 9 July 2019, editorial revision 25 October 2022. Cited for scope and applicability; available to AACE members.
- Cox, Louis Anthony (Tony), Jr. “What's Wrong with Risk Matrices?” Risk Analysis, vol. 28, no. 2, 2008, pp. 497–512. doi.org/10.1111/j.1539-6924.2008.01030.x. Why the register's own ratings cannot be aggregated.
- Federal Transit Administration. Oversight Procedure 40: Risk and Contingency Review. U.S. Department of Transportation, October 2023. transit.dot.gov. The stripped and adjusted baseline as the control against double counting.
- International Organization for Standardization. Risk Management: Guidelines. ISO 31000:2018, Clause 4(f). iso.org/standard/65694.html.
About the Author
Dan Flynn
Creator of The Four A's of Organizational Readiness™ · Enterprise Transformation Executive · Author, Builders Build
Dan Flynn has spent thirty years inside federal, defense, and commercial organizations: diagnosing the invisible conditions that determine whether capable people produce extraordinary results. He is the creator of The Four A's of Organizational Readiness™ framework, has reached more than 11,000 professionals across corporate, civic, and national security contexts, and took a federal data platform from one release every six months to seventy-two every two weeks by changing organizational conditions: not people.
His book, Builders Build: The Four A’s of Organizational Readiness™, is forthcoming.
