Mission Intelligence Systems
Risk · Attention

Ordering Work by Risk-Adjusted Value

Do first whatever most changes the decisions still ahead of you.

Almost every programme sequences its work by value: what stakeholders want most, what demonstrates progress, what the sponsor asked about last. It is an understandable rule and it reliably leaves the expensive unknowns until the point where nothing cheap can be done about them.

Published

Key Takeaways

Research foundation

The formal basis for resolving uncertainty in order of what it changes is Howard's information value theory (1966), applied to software requirements and architecture decisions by Letier, Stefan and Barr (2014) and to risk-based requirements reasoning by Feather and Cornford (2003). The sequencing instinct itself predates the quantification: Boehm's spiral model (1988) is explicitly risk-driven. Cox (2008) establishes why an ordinal risk ranking cannot carry this decision on its own. One honest note carried through the article: information value theory ranks by how much an observation changes the optimal decision, not by raw variance, and those are not the same ordering. The Four A's are the executive lens applied to that evidence.

There is a moment on most capital programmes where someone says, reasonably, that the team should start with the parts people can see. The portal before the data migration. The station finishes before the utility relocation. It feels like momentum, and it produces a period where everything reported is green while every genuinely hard question remains unanswered.

Then the hard question arrives, and it arrives after the money is committed.

What is wrong with sequencing by value?

Nothing, as far as it goes. The problem is that value and uncertainty are different axes, and most prioritization sessions only have one of them on the wall.

Value estimates are conditional on the plan holding. They describe what a piece of work is worth if it goes roughly as expected. The items that threaten that condition are usually the ones with the weakest value narrative: a geotechnical investigation demonstrates nothing to a stakeholder, a legacy data migration has no demo, an environmental permit produces no visible artifact. Rank by value and those items sink, every time, without anyone deciding to deprioritize them.

Flyvbjerg's work on public infrastructure documents the downstream shape of that pattern: systematic and persistent cost underestimation across hundreds of projects, at a scale that ordinary estimating error does not explain. Kahneman and Tversky supplied the mechanism decades earlier, describing how inside-view planning produces forecasts anchored to the intended path rather than to the distribution of outcomes. A value-ordered sequence is an inside-view instrument. It assumes the path.

What should you order by instead?

Here is where the popular version of this idea goes wrong, and it is worth being precise because the imprecise version is what gets people into trouble.

The common formulation is tackle the biggest risks first, usually operationalized by reading the top bars off a tornado diagram. That is close, and it is not right. The formal criterion, established by Howard in 1966, is the expected value of information: an observation is worth making to the extent that it changes what you would optimally do. An uncertainty can be enormous and still be worth nothing to resolve early, if the answer would not change a single decision. Conversely a modest uncertainty that flips a commitment is worth resolving immediately.

So the sequencing question has two parts, not one. First, how large is the uncertainty. Second, and more important, would resolving it change what we do. Letier, Stefan and Barr applied exactly this reasoning to prioritizing software requirements and architecture decisions, and Feather and Cornford built a quantitative risk-based method for reasoning about requirements on the same logic.

In practice this produces three buckets from the top of a sensitivity ranking:

Why does a tornado diagram not answer this by itself?

Because it ranks inputs by how much they move the outcome, which is a statement about the model rather than about your options. It tells you where the variance lives. It does not tell you whether you can do anything about it this quarter, or whether knowing the answer would alter a commitment.

There is a further caution worth carrying. Cox showed formally that ordinal risk rankings have limited resolution and can, under specifiable conditions, invert the true quantitative ordering, particularly where probability and consequence are negatively correlated. A ranking is a starting point for a conversation about sequence, not an output you can schedule against directly. That argument is made in full in Are Risk Matrices Valid.

Is this just risk-driven development renamed?

It is the same instinct, and saying so is a strength rather than an admission. Boehm set it out in 1988. The spiral model, in his words, “creates a risk-driven approach to the software process rather than a primarily document-driven or code-driven process,” and it deliberately “defer[s] detailed elaboration of low-risk software elements and avoid[s] unnecessary breakage in their design until the high-risk elements of the design are stabilized.” He added that once risks are evaluated, “the next step is determined by the relative remaining risks.” That is this article's thesis, written thirty-eight years ago, for software.

What has changed is not the principle but the instrument. Boehm's teams assessed relative remaining risk by judgment. A programme running a quantified cost and schedule model can put a number on it, test the ordering, and re-derive the sequence as the distribution moves. The idea is old. Pointing it at a simulation is not.

What does this look like on a capital programme?

The translation is more literal than people expect. Take the drivers accounting for most of the modelled variance. Filter them through the resolvable and decision-changing tests. What survives becomes the near-term work, ahead of items with a better value story.

The sponsor conversation is the hard part, because the honest version of it is: for the next two cycles you will see less visible progress than you would have, and in exchange the number that goes to the board afterwards will be defensible. That trade is easy to describe and unpleasant to sit through, which is why it usually needs to be agreed before the sequence is set rather than defended afterwards.

The payoff is measurable, and it is the same mechanism described in What P80 Means. Resolving a high variance item removes its spread from the model. The distribution narrows, the percentile pulls toward the baseline, and the contingency arithmetic changes in your favour. De-risking first is not merely prudent, it is the thing that lets you hand money back.

Why is this an Attention problem?

Because sequencing is the purest expression of what an organization is actually paying attention to, and the default is always the visible.

No leadership team decides to defer its hardest unknowns. It happens because the prioritization ritual only asks one question, because the items that would surface are the ones nobody can demo, and because the person who would raise them is often the person with the least standing in the room. The register may well contain every one of those risks, correctly rated. Nothing in the process brings them to the moment where sequence is decided, which is the same failure described in The Risk Register Nobody Reads, applied to the calendar instead of the document.

ISO 31000:2018 puts the underlying obligation plainly in stating that risk management should be based on the best available information. A sequence chosen without reference to the model is not using the best available information, however good the model is.

Evidence matrix

ClaimEvidence tierSource
An observation is worth making to the extent it changes the optimal decisionPeer reviewed, foundationalHoward (1966), IEEE Transactions on Systems Science and Cybernetics 2(1)
Value of information can prioritize real design and requirements decisionsPeer reviewedLetier, Stefan & Barr (2014), ICSE; Feather & Cornford (2003), Requirements Engineering 8(4)
Deferring low-risk elaboration until high-risk elements stabilize is established practicePeer reviewed, foundationalBoehm (1988), Computer 21(5); Boehm (1991), IEEE Software 8(1)
Ordinal rankings cannot be scheduled against directlyPeer reviewedCox (2008), Risk Analysis 28(2)
Inside-view planning systematically underestimates cost and durationPeer reviewedFlyvbjerg (2006); Kahneman & Tversky (1977)
Sequence reveals what the organization is actually attending toFour A's interpretationBuilders Build, Attention

What to do with this

At the next prioritization session, add one column to whatever board you already use, and label it: what decision does this change, and when. Anything that cannot answer it is not a de-risking activity, whatever its rating says. Then take the top drivers off the model and place them explicitly, in front of the sponsor, against the items they are displacing. Making the displacement visible is what turns this from a technique into a decision.

References

  1. Howard, Ronald A. “Information Value Theory.” IEEE Transactions on Systems Science and Cybernetics, vol. 2, no. 1, 1966, pp. 22–26. doi.org/10.1109/TSSC.1966.300074. Establishes that the value of an observation derives from how much it changes the optimal decision, not from the size of the uncertainty.
  2. Letier, Emmanuel, David Stefan, and Earl T. Barr. “Uncertainty, Risk, and Information Value in Software Requirements and Architecture.” Proceedings of the 36th International Conference on Software Engineering (ICSE 2014), ACM, 2014, pp. 883–894. doi.org/10.1145/2568225.2568239.
  3. Feather, Martin S., and Steven L. Cornford. “Quantitative Risk-Based Requirements Reasoning.” Requirements Engineering, vol. 8, no. 4, 2003, pp. 248–265. doi.org/10.1007/s00766-002-0160-y.
  4. Boehm, Barry W. “A Spiral Model of Software Development and Enhancement.” Computer, vol. 21, no. 5, 1988, pp. 61–72. doi.org/10.1109/2.59. Source of the risk-driven sequencing argument quoted above.
  5. Boehm, Barry W. “Software Risk Management: Principles and Practices.” IEEE Software, vol. 8, no. 1, 1991, pp. 32–41. doi.org/10.1109/52.62930.
  6. Cox, Louis Anthony (Tony), Jr. “What's Wrong with Risk Matrices?” Risk Analysis, vol. 28, no. 2, 2008, pp. 497–512. doi.org/10.1111/j.1539-6924.2008.01030.x.
  7. Flyvbjerg, Bent. “From Nobel Prize to Project Management: Getting Risks Right.” Project Management Journal, vol. 37, no. 3, 2006, pp. 5–15. doi.org/10.1177/875697280603700302.
  8. Flyvbjerg, Bent, Mette K. Skamris Holm, and Søren L. Buhl. “Underestimating Costs in Public Works Projects: Error or Lie?” Journal of the American Planning Association, vol. 68, no. 3, 2002, pp. 279–295. doi.org/10.1080/01944360208976273.
  9. Kahneman, Daniel, and Amos Tversky. Intuitive Prediction: Biases and Corrective Procedures. Technical Report PTR-1042-77-6, Decision Research, June 1977. DTIC accession ADA047747. apps.dtic.mil.
  10. International Organization for Standardization. Risk Management: Guidelines. ISO 31000:2018, Clause 4(f), best available information. iso.org/standard/65694.html.
DF

About the Author

Dan Flynn

Creator of The Four A's of Organizational Readiness™ · Enterprise Transformation Executive · Author, Builders Build

Dan Flynn has spent thirty years inside federal, defense, and commercial organizations: diagnosing the invisible conditions that determine whether capable people produce extraordinary results. He is the creator of The Four A's of Organizational Readiness™ framework, has reached more than 11,000 professionals across corporate, civic, and national security contexts, and took a federal data platform from one release every six months to seventy-two every two weeks by changing organizational conditions: not people.

His book, Builders Build: The Four A’s of Organizational Readiness™, is forthcoming.