Last updated October 2026
Give four competent risk managers the same project, the same risks and exactly the same luck. Let each of them work the way they were trained, and let Trevor work the way he always has. Then add up the bills.
The company and the people are invented. The risks, the probabilities and every number below come from a simulation model you can download at the end and run yourself. We ran the project 10,000 times, and in every one of those runs all five faced the identical draw of events. When their results differ, the only cause is how they worked.
Qualitative risk analysis scores each risk’s likelihood and impact on ordinal scales, such as 1 to 5, and ranks the risks, usually on a heat map. Quantitative risk analysis estimates the risks in money and time, combines them in a model, usually by Monte Carlo simulation, and gives the probability of each possible outcome. Only the quantitative kind can add risks together or put a value on a decision.
That is the textbook answer. The rest of this article is what the difference looks like on an actual project.
A family mustard maker is building a new filling line. It costs €10m and takes twelve months, with a planned finish at the end of September. The date that matters is a different one: the line has to be commissioned by 31 October, or the factory misses the Christmas season, and the Christmas season is worth €1.5m of contribution. Every month of delay costs another €120,000 in site costs.
Five kinds of risk sit on the project:
The fifth row only bites when the second one does, and that turns out to matter a great deal.
Before anyone gets graded, it is worth being fair to the heat map, because there are good reasons it is everywhere.
These are real advantages, and anything proposed as a replacement has to be cheap enough and quick enough to compete with them. The question this project asks is narrower: when it comes to the decisions that change the cost, does the method help?
Brian runs a textbook register on a 5×5 matrix. His likelihood bands run from rare (under 5%) to almost certain (over 70%); his impact bands from insignificant (under €50,000) to severe (over €5m). Scores of 1 to 4 are green, 5 to 12 amber, 15 and above red.1
His register scores the project like this:
There is no red anywhere, on a project with nearly a one-in-five chance of losing Christmas.
Brian manages his top ten. The filler and the fire take the first two places. The other eight go to rows that scored 4, picked from the forty rows that scored 4, in the order someone typed them in. Everything is marked monitor, and it is monitored carefully.
Three things are invisible from where Brian sits:
The story year. We picked one of the 10,000 simulated years to tell as a story: the filler fails, the snags run high (25 of the 39 bite), there is no fire, and scope creep is about average. Every risk that bit that year was on Brian’s register. The filler fails its acceptance test on site, at commissioning. The fix costs €1.48m and takes four months, and the line is commissioned in mid-February. Christmas is gone.
Brian’s project costs €14.06m, €4.06m over budget. He predicted everything and prevented nothing.
Sandra uses the company’s standard contingency: add 10% to the budget and six weeks to the schedule. The policy goes back to a memo nobody can find, written possibly for a different factory. Her budget is €11m.
Two things go wrong, and the policy causes both.
First, the six weeks. A planned finish of 30 September plus six weeks is 11 November, which is already past the date the season needs. The policy adds weeks. It doesn’t look at what the dates mean.
Second, the money gets spent. Money that is visibly available tends to find uses, so we assumed that half of Sandra’s €1m disappears into things the project would otherwise have done without: a better control panel, a nicer mezzanine.2 Then the snags and the scope creep take their share, and when the filler fails in October there is nothing left to absorb it.
The story year costs Sandra €14.56m: €3.56m over her padded budget, and €0.5m more than Brian, who had no contingency at all. A flat percentage is the same size whatever the project contains. On a simple job it is too much. On this one it was too little, and it was spent before it was needed.
If you want to size a contingency from the risks instead of from a percentage, our cost contingency article walks through it.
Quentin starts from a register very like Brian’s. The difference is what he does with it. In a workshop he gets ranges instead of colours for each risk (how likely, how much, how long) and puts them into a Monte Carlo model: a spreadsheet that replays the project thousands of times, with each risk happening or not according to its probability.
The workshop is where the season comes up for the first time. Someone from production mentions, almost in passing, that if the line isn’t running by November they might as well not bother until January. Nobody had written that down, because a date doesn’t look like a risk. Once it is in the model, the filler stops being one amber row among forty-odd and becomes the thing that drives most of the downside.
Quentin makes four decisions nobody else makes:
The board wants a number. “Ten point nine,” he says, and watches everyone write down ten.
The story year. The filler fails, just as it did for everyone else, but it fails in June at the supplier’s works. The fix costs €0.45m and the line is commissioned at the end of October, about four weeks late and just inside the season. Quentin’s project costs €11.31m.
That is more than his own P80. He said there was a one-in-five chance of going over €10.91m, and this was one of those years. His worst meeting of the year is the one in which he is right.
Petra transfers risk. She buys the full package: property cover, plus delay-in-start-up cover that pays for lost time. It costs €700,000.
In the story year there is no fire, so the property cover pays nothing. The delay cover pays nothing either, because a machine failing its acceptance test is excluded under clause 14.3(b) as “a quality matter”.4 Petra’s project costs €14.76m, the most expensive of the five, and she has to explain to the board that not having a fire was the good outcome.
Across the 10,000 years, the fire happens in 1.1% of them. The package’s expected payout in our model is about €90,000 a year, against a €700,000 premium. The cover stops where the exclusions start, and the exclusions are written around the insurer’s exposure, not yours. That is why Quentin bought cover for the one risk that could sink the company and carried the rest himself.
Trevor keeps no register, builds no model and puts nothing in writing. With nobody asking whether each new nozzle is worth it, scope creep runs at twice the rate, and problems found late cost 30% more to fix.5
His project costs €14.69m. Since he never wrote down an expectation, he never missed one, and he is promoted in the spring.
The same filler failed in all five universes. What differed was when it was found, and what was left to absorb it when it was.
One year is an anecdote, and we picked a year in which the filler failed. So we replayed all 10,000 years:
(P50 and P95 are the costs with a 50% and a 95% chance of not being exceeded.)
And now the uncomfortable number. Brian is cheaper than Quentin in 81% of years.
In the 84% of years when the filler works, Quentin’s test and premium buy nothing anyone can see, and Brian comes out ahead 96% of the time. In the 16% of years when the filler fails, Quentin comes out ahead every single time, by €2.8m on average. On the average of all years Quentin is cheaper by about €380,000, and his bad years are small: his P95 is €11.31m, and Brian’s is €14.23m.
This is why Brian still has a job. Judged one year at a time, the quantitative approach looks like overhead four years out of five, and the board is right about each of those years. The fifth year pays for all of them, and it is the one that decides whether the company still makes mustard at Christmas.
The most expensive single item in the story year was €1.5m of lost Christmas. It appears on nobody’s register, because it only exists when the filler and the calendar meet. There are three structural reasons the qualitative methods missed it, and being more careful would not have fixed any of them.
Sandra’s percentage and Petra’s premium have the same blind spot, one level up: neither looks at which risks it is meant to cover.
It is good enough when no decision depends on the answer. That covers screening a long list down to the risks worth modelling, recording who owns what, and running the conversation that produces the list in the first place. Quentin’s model started from a register, and it would have been worse without one.
It stops being enough as soon as someone asks how much, which option or how likely. That means setting a budget or a contingency, deciding whether a test or an insurance policy is worth its price, or asking whether a deadline will hold. Those questions have answers in money and time, and a method that doesn’t work in money and time cannot give them.
The workbook contains the whole project: the register, all five side by side reading the same random draws, and a switch that replays the story year exactly as told here. It runs in Excel with ModelRisk:
Download the Four Risk Managers workbook (.xlsx). It is free and needs no registration. No ModelRisk yet? Start the free 15-day trial and run all 10,000 years yourself.
If you want the method in more depth: Monte Carlo simulation explained, what information is worth (the arithmetic behind Quentin’s test), and a cost contingency worked example. If your register lives in a database rather than a spreadsheet, Pelican keeps it quantitative.
Is semi-quantitative risk analysis a good compromise? It keeps the main problem. Semi-quantitative methods turn the bands into numbers and multiply them, but a likelihood of 3 times an impact of 4 is still a rank, not an amount of money, so the scores still can’t be added or compared with the cost of a response. Estimating each risk as a range in money and time takes about the same workshop and gives numbers you can use.
Do you need historical data for quantitative risk analysis? No. Most project risk models run on expert estimates given as ranges, for example a minimum, most likely and maximum cost, or a 10th and 90th percentile. Quentin’s inputs came from the same workshop that produced Brian’s scores. Data improves the ranges where it exists, but its absence is not a reason to fall back on colours.
Can you do quantitative risk analysis in Excel? Yes. A Monte Carlo add-in such as ModelRisk turns an ordinary spreadsheet into a model that replays thousands of scenarios and reports the distribution of outcomes. The workbook with this article is an example: every calculation is visible in the cells, and the plain-Excel sheet shows what the same model does without the add-in, one scenario at a time.
Try ModelRisk free for 15 days, or request a demo.
1. Brian’s bands are one common layout; yours may differ. Try your own organisation’s bands on the four rows. A rare catastrophe tends to land in amber or green, because its low likelihood drags the score down, and the snags will be green on almost any scale. ↑
2. This is one of three behavioural assumptions in the model, and all three are on the workbook’s Inputs sheet. Set Sandra’s factor to zero and she becomes Brian with €1m of false comfort: the same cost, and a bigger number in the budget. ↑
3. In decision-analysis terms this is the value of the information the test provides: learning early whether the filler works, while a fix is still cheap. The model runs Quentin’s project with and without the test in the same 10,000 years and compares the averages. The EVPI and EVII article explains the idea. ↑
4. Clause 14.3(b) is invented for this story. Read the exclusions before you buy the cover. ↑
5. The other two behavioural assumptions. Both are on the Inputs sheet if you think we have been unfair to Trevor. ↑
Put your register in money and time, and let the model say which response is worth its price. ModelRisk runs your Excel model thousands of times with proper distributions and dependencies, and a fully functional 15-day trial is free.