Qualitative vs Quantitative Risk Analysis, Simulated | Vose

Four risk managers, Trevor and a mustard factory: qualitative vs quantitative risk analysis in one project

One project, the same luck, 10,000 simulated years

Last updated October 2026

Give four competent risk managers the same project, the same risks and exactly the same luck. Let each of them work the way they were trained, and let Trevor work the way he always has. Then add up the bills.

The company and the people are invented. The risks, the probabilities and every number below come from a simulation model you can download at the end and run yourself. We ran the project 10,000 times, and in every one of those runs all five faced the identical draw of events. When their results differ, the only cause is how they worked.

What is the difference between qualitative and quantitative risk analysis?

Qualitative risk analysis scores each risk’s likelihood and impact on ordinal scales, such as 1 to 5, and ranks the risks, usually on a heat map. Quantitative risk analysis estimates the risks in money and time, combines them in a model, usually by Monte Carlo simulation, and gives the probability of each possible outcome. Only the quantitative kind can add risks together or put a value on a decision.

That is the textbook answer. The rest of this article is what the difference looks like on an actual project.

The project

A family mustard maker is building a new filling line. It costs €10m and takes twelve months, with a planned finish at the end of September. The date that matters is a different one: the line has to be commissioned by 31 October, or the factory misses the Christmas season, and the Christmas season is worth €1.5m of contribution. Every month of delay costs another €120,000 in site costs.

Five kinds of risk sit on the project:

RiskWhat could happenHow we modelled it
Installation snags39 small items, each of which may or may not biteEach has a 50% chance; about €15,000 each if it does, plus a little schedule friction
The fillerThe bespoke filling machine fails its acceptance test on site15% chance; about €1.5m to fix and about 4 months’ delay
Fire during hot worksWelding sets the building alight1% chance; about €8m of damage
Scope creepMarketing asks for one more nozzle, most months50% chance each month; €10,000 to €50,000 each time
The seasonA slip past 31 October loses Christmas€1.5m, if the finish date passes the gate

The fifth row only bites when the second one does, and that turns out to matter a great deal.

Why do most organisations use qualitative risk analysis?

Before anyone gets graded, it is worth being fair to the heat map, because there are good reasons it is everywhere.

  • It needs almost no information. A likelihood band and an impact band per risk, and you are done.
  • It can be done in a single workshop, by people with no training in probability.
  • Everyone reads red, amber and green the same way, and managers expect to see them.
  • Frameworks, templates and audit checklists ask for exactly this output.
  • It is a quick way to turn a long, messy list into a short one.

These are real advantages, and anything proposed as a replacement has to be cheap enough and quick enough to compete with them. The question this project asks is narrower: when it comes to the decisions that change the cost, does the method help?

Brian: what does a heat map make of this project?

Brian runs a textbook register on a 5×5 matrix. His likelihood bands run from rare (under 5%) to almost certain (over 70%); his impact bands from insignificant (under €50,000) to severe (over €5m). Scores of 1 to 4 are green, 5 to 12 amber, 15 and above red.1

His register scores the project like this:

Register rowLikelihoodImpactScoreColour
Filler fails acceptance3 (15%)4 (€1.5m)12Amber
Fire during hot works1 (1%)5 (€8m)5Amber
Each of the 39 snags (rows 23 to 61)4 (50%)1 (€15,000)4Green
Scope creep4 (50% a month)1 (€30,000 a time)4Green

There is no red anywhere, on a project with nearly a one-in-five chance of losing Christmas.

Brian manages his top ten. The filler and the fire take the first two places. The other eight go to rows that scored 4, picked from the forty rows that scored 4, in the order someone typed them in. Everything is marked monitor, and it is monitored carefully.

Three things are invisible from where Brian sits:

  • The snags, added up. Each green row is trivial. Together they are expected to cost 39 × 50% × €15,000 = €292,500. The fire, which outscores every one of them, is expected to cost 1% × €8m = €80,000. The green rows are worth more than three and a half times the amber one. Colours cannot be added, so the register has no way of saying so.
  • The season. It has no row of its own. It is the filler row meeting a date, and a register records risks one at a time.
  • What to do about the filler. Scored 12 and monitored, it gets watched until it happens.

The story year. We picked one of the 10,000 simulated years to tell as a story: the filler fails, the snags run high (25 of the 39 bite), there is no fire, and scope creep is about average. Every risk that bit that year was on Brian’s register. The filler fails its acceptance test on site, at commissioning. The fix costs €1.48m and takes four months, and the line is commissioned in mid-February. Christmas is gone.

Brian’s project costs €14.06m, €4.06m over budget. He predicted everything and prevented nothing.

Sandra: is a fixed contingency percentage enough?

Sandra uses the company’s standard contingency: add 10% to the budget and six weeks to the schedule. The policy goes back to a memo nobody can find, written possibly for a different factory. Her budget is €11m.

Two things go wrong, and the policy causes both.

First, the six weeks. A planned finish of 30 September plus six weeks is 11 November, which is already past the date the season needs. The policy adds weeks. It doesn’t look at what the dates mean.

Second, the money gets spent. Money that is visibly available tends to find uses, so we assumed that half of Sandra’s €1m disappears into things the project would otherwise have done without: a better control panel, a nicer mezzanine.2 Then the snags and the scope creep take their share, and when the filler fails in October there is nothing left to absorb it.

The story year costs Sandra €14.56m: €3.56m over her padded budget, and €0.5m more than Brian, who had no contingency at all. A flat percentage is the same size whatever the project contains. On a simple job it is too much. On this one it was too little, and it was spent before it was needed.

If you want to size a contingency from the risks instead of from a percentage, our cost contingency article walks through it.

Quentin: what does quantitative risk analysis change?

Quentin starts from a register very like Brian’s. The difference is what he does with it. In a workshop he gets ranges instead of colours for each risk (how likely, how much, how long) and puts them into a Monte Carlo model: a spreadsheet that replays the project thousands of times, with each risk happening or not according to its probability.

The workshop is where the season comes up for the first time. Someone from production mentions, almost in passing, that if the line isn’t running by November they might as well not bother until January. Nobody had written that down, because a date doesn’t look like a risk. Once it is in the model, the filler stops being one amber row among forty-odd and becomes the thing that drives most of the downside.

Quentin makes four decisions nobody else makes:

  1. He tests the filler at the supplier’s works, before it ships, for €120,000. A failure found at the works costs about 30% as much to fix and half a month instead of four. The model values that test at €462,000 of expected saving, 3.9 times its price.3
  2. He re-sequences commissioning so that seasonal production can start a month later than planned if it has to.
  3. He insures the fire, and only the fire, for €90,000, with a €250,000 deductible. The fire is the only risk the company could not absorb on its own.
  4. He asks for a budget at the P80, the figure the model says has an 80% chance of not being exceeded: €10.91m.

The board wants a number. “Ten point nine,” he says, and watches everyone write down ten.

The story year. The filler fails, just as it did for everyone else, but it fails in June at the supplier’s works. The fix costs €0.45m and the line is commissioned at the end of October, about four weeks late and just inside the season. Quentin’s project costs €11.31m.

That is more than his own P80. He said there was a one-in-five chance of going over €10.91m, and this was one of those years. His worst meeting of the year is the one in which he is right.

Petra: can’t you just insure the risk?

Petra transfers risk. She buys the full package: property cover, plus delay-in-start-up cover that pays for lost time. It costs €700,000.

In the story year there is no fire, so the property cover pays nothing. The delay cover pays nothing either, because a machine failing its acceptance test is excluded under clause 14.3(b) as “a quality matter”.4 Petra’s project costs €14.76m, the most expensive of the five, and she has to explain to the board that not having a fire was the good outcome.

Across the 10,000 years, the fire happens in 1.1% of them. The package’s expected payout in our model is about €90,000 a year, against a €700,000 premium. The cover stops where the exclusions start, and the exclusions are written around the insurer’s exposure, not yours. That is why Quentin bought cover for the one risk that could sink the company and carried the rest himself.

Trevor: what happens if you do nothing?

Trevor keeps no register, builds no model and puts nothing in writing. With nobody asking whether each new nozzle is worth it, scope creep runs at twice the rate, and problems found late cost 30% more to fix.5

His project costs €14.69m. Since he never wrote down an expectation, he never missed one, and he is promoted in the spring.

What happened in the story year?

Risk managerTotal costOver the €10m budgetDelayChristmas season
Quentin (quantitative model)€11.31m+€1.31m1.0 monthKept
Brian (heat map, top ten)€14.06m+€4.06m4.5 monthsLost
Sandra (+10% and +6 weeks)€14.56m+€4.56m4.5 monthsLost
Trevor (no register)€14.69m+€4.69m4.5 monthsLost
Petra (insure everything)€14.76m+€4.76m4.5 monthsLost

Bar chart of total cost in the story year against a 10 million euro budget: Quentin 11.31 million, Brian 14.06 million, Sandra 14.56 million, Trevor 14.69 million, Petra 14.76 million.

The same filler failed in all five universes. What differed was when it was found, and what was left to absorb it when it was.

Did Quentin just get lucky?

One year is an anecdote, and we picked a year in which the filler failed. So we replayed all 10,000 years:

Risk managerMean costP50P80P95Chance of losing Christmas
Quentin€10.82m€10.75m€10.91m€11.31m0.2%
Brian€11.20m€10.54m€10.77m€14.23m18.4%
Trevor€11.47m€10.74m€11.05m€14.93m18.4%
Sandra€11.70m€11.04m€11.27m€14.73m18.4%
Petra€11.81m€11.24m€11.43m€14.85m18.4%

(P50 and P95 are the costs with a 50% and a 95% chance of not being exceeded.)

And now the uncomfortable number. Brian is cheaper than Quentin in 81% of years.

In the 84% of years when the filler works, Quentin’s test and premium buy nothing anyone can see, and Brian comes out ahead 96% of the time. In the 16% of years when the filler fails, Quentin comes out ahead every single time, by €2.8m on average. On the average of all years Quentin is cheaper by about €380,000, and his bad years are small: his P95 is €11.31m, and Brian’s is €14.23m.

Two histograms of total cost over 10,000 simulated years. Brian: mean 11.20 million euros, P80 10.77 million, P95 14.23 million, with a second hump between about 13.5 and 14.5 million from the years the filler fails. Quentin: mean 10.82 million, P80 10.91 million, P95 11.31 million, and no second hump.

This is why Brian still has a job. Judged one year at a time, the quantitative approach looks like overhead four years out of five, and the board is right about each of those years. The fifth year pays for all of them, and it is the one that decides whether the company still makes mustard at Christmas.

Why can’t a qualitative method see the risk that costs the most?

The most expensive single item in the story year was €1.5m of lost Christmas. It appears on nobody’s register, because it only exists when the filler and the calendar meet. There are three structural reasons the qualitative methods missed it, and being more careful would not have fixed any of them.

  • Scores can’t be added. Thirty-nine green rows worth €292,500 lose to one amber row worth €80,000, because there is no arithmetic that sums colours.
  • Registers treat risks one at a time. Interactions between rows (a failure and a deadline, a delay and a price rise) have no row of their own.
  • A colour doesn’t price a decision. Nothing on Brian’s heat map tells you that a €120,000 test is worth €462,000. That needs the risk in money, and the alternatives compared.

Sandra’s percentage and Petra’s premium have the same blind spot, one level up: neither looks at which risks it is meant to cover.

When is qualitative risk analysis good enough?

It is good enough when no decision depends on the answer. That covers screening a long list down to the risks worth modelling, recording who owns what, and running the conversation that produces the list in the first place. Quentin’s model started from a register, and it would have been worse without one.

It stops being enough as soon as someone asks how much, which option or how likely. That means setting a budget or a contingency, deciding whether a test or an insurance policy is worth its price, or asking whether a deadline will hold. Those questions have answers in money and time, and a method that doesn’t work in money and time cannot give them.

Try it yourself

The workbook contains the whole project: the register, all five side by side reading the same random draws, and a switch that replays the story year exactly as told here. It runs in Excel with ModelRisk:

  • Dashboard: run one simulation of 10,000 years and read off each manager’s mean, P50, P80 and P95, their chance of losing Christmas, how often Brian beats Quentin, and the value of Quentin’s test.
  • Inputs: every assumption in one place. Make the filler more reliable, cut the season’s value, give Sandra a smaller Parkinson factor, and see who wins.
  • Model: the 39 snags, 12 months of scope creep, the filler and the fire, each with its live draw, then the five universes calculated line by line.
  • Without ModelRisk: the same model in plain Excel. Press F9 for one year at a time.

Download the Four Risk Managers workbook (.xlsx). It is free and needs no registration. No ModelRisk yet? Start the free 15-day trial and run all 10,000 years yourself.

If you want the method in more depth: Monte Carlo simulation explained, what information is worth (the arithmetic behind Quentin’s test), and a cost contingency worked example. If your register lives in a database rather than a spreadsheet, Pelican keeps it quantitative.

Frequently asked questions

Is semi-quantitative risk analysis a good compromise?
It keeps the main problem. Semi-quantitative methods turn the bands into numbers and multiply them, but a likelihood of 3 times an impact of 4 is still a rank, not an amount of money, so the scores still can’t be added or compared with the cost of a response. Estimating each risk as a range in money and time takes about the same workshop and gives numbers you can use.

Do you need historical data for quantitative risk analysis?
No. Most project risk models run on expert estimates given as ranges, for example a minimum, most likely and maximum cost, or a 10th and 90th percentile. Quentin’s inputs came from the same workshop that produced Brian’s scores. Data improves the ranges where it exists, but its absence is not a reason to fall back on colours.

Can you do quantitative risk analysis in Excel?
Yes. A Monte Carlo add-in such as ModelRisk turns an ordinary spreadsheet into a model that replays thousands of scenarios and reports the distribution of outcomes. The workbook with this article is an example: every calculation is visible in the cells, and the plain-Excel sheet shows what the same model does without the add-in, one scenario at a time.

Try ModelRisk free for 15 days, or request a demo.

Notes

1. Brian’s bands are one common layout; yours may differ. Try your own organisation’s bands on the four rows. A rare catastrophe tends to land in amber or green, because its low likelihood drags the score down, and the snags will be green on almost any scale. ↑

2. This is one of three behavioural assumptions in the model, and all three are on the workbook’s Inputs sheet. Set Sandra’s factor to zero and she becomes Brian with €1m of false comfort: the same cost, and a bigger number in the budget. ↑

3. In decision-analysis terms this is the value of the information the test provides: learning early whether the filler works, while a fix is still cheap. The model runs Quentin’s project with and without the test in the same 10,000 years and compares the averages. The EVPI and EVII article explains the idea. ↑

4. Clause 14.3(b) is invented for this story. Read the exclusions before you buy the cover. ↑

5. The other two behavioural assumptions. Both are on the Inputs sheet if you think we have been unfair to Trevor. ↑

ModelRisk logo

ModelRisk

Adding risk and uncertainty to your Excel model

Put your register in money and time, and let the model say which response is worth its price. ModelRisk runs your Excel model thousands of times with proper distributions and dependencies, and a fully functional 15-day trial is free.