| Vose Software

Industry: Agriculture and Food Supply Chain
Product: ModelRisk
Application: Food safety analysis


The Average Recall Year Costs $4.4M. The Median Costs $0.5M. Plan for Neither.

A food manufacturer's finance team carried a single line in its risk register for product recalls: an expected annual cost of roughly $4.4M. It was a defensible average — pathogen-contamination recalls are rare, perhaps one event per year, with each event costing a few million in product destruction, logistics, lost sales and litigation. But the average is a number that almost never happens. In 52% of simulated years there is no recall at all and the cost is $0; the median year costs $0.5M; and the same model shows a 3% chance of a year exceeding $25M and a 99% value-at-risk of $39M. The mean sits eight times above the median, dragged up by a tail the single figure cannot represent.

Recall losses are a textbook frequency-times-severity problem, and that structure is exactly what defeats a point estimate. The manufacturer rebuilt the exposure as a 200,000-trial Monte Carlo model in ModelRisk: an uncertain number of contamination events per year multiplied by a heavy-tailed cost per event. The result is not a tidier average — it is a loss distribution with a thin body and a long fat tail, which is the only honest shape for a catastrophe-style risk.

Annual recall-cost loss distribution with value-at-risk and tail

The distribution carries a mean of $4.4M but a 95% VaR of $19.8M, a 99% VaR of $39.4M, and an expected shortfall beyond the 99th percentile of $56.9M. The probability that a year's recall cost exceeds $10M is 14%. A reserve set at the mean would be exhausted by any single serious event; the model says the capital question is not "what is the expected loss?" but "how much tail do we choose to hold or insure?"

Why the mean is the wrong planning number

Two compounding sources of skew make recall cost a poor candidate for a point estimate.

First, event frequency is over-dispersed, not steady. The annual rate of recall-triggering events is itself uncertain — modelled as a Gamma-distributed rate feeding a Poisson count, the standard Negative-Binomial mixture for clustered rare events. A drifted sanitation regime or a compromised supplier raises the rate for every event that year, so events arrive in clusters rather than as independent draws around a fixed mean. This shared control-regime factor is what stops the annual total from collapsing toward a thin Normal the way a sum of independent risks would.

Distribution of recall-triggering events per year

The frequency picture alone overturns the "about one a year" intuition: 52% of years see zero events, a mean of 0.9, and a meaningful probability of two or more events stacking up in a bad year.

Second, severity is heavy-tailed. Each event's cost is modelled as a LogNormal with a $2.8M median but a $4.9M mean — a right-skewed shape where most events are manageable but a handful (a national recall, a litigated illness cluster) run past $40M. Multiply an over-dispersed count by a fat-tailed severity and the annual total inherits both skews. No single number can stand in for a distribution whose mean is eight times its median.

What testing and HACCP controls are worth

The manufacturer evaluated two control programs by their effect on the whole loss distribution, not just the average: routine pathogen testing, and a full HACCP-plus-supplier-audit regime. Each lowers the expected event rate and tightens the severity tail through faster containment.

Annual recall-loss CDFs under three control levels

The CDFs separate cleanly:

  • No enhanced controls — mean $4.3M, P99 $39M, P(loss > $10M) = 14%.
  • Routine pathogen testing — mean $2.2M, P99 $24M, P(loss > $10M) = 6%.
  • Full HACCP + supplier audit — mean $1.1M, P99 $15M, P(loss > $10M) = 2%.

Against program costs of about $0.45M/yr for testing and $1.3M/yr for full HACCP, the expected-loss savings are $2.1M and $3.2M per year — net positives of $1.7M and $1.9M annually. The stronger argument is in the tail: full HACCP nearly halves the 99% VaR, from $39M to $15M, which is the number that determines how much catastrophe reserve or insurance the business must carry.

What drives the tail

A reserve is sized off the tail, so the team ranked what moves the 99% VaR rather than the mean.

Tornado of drivers of the 99% recall-loss value-at-risk

The severity tail parameter and the severity median dominate, each swinging the 99% VaR by roughly $11M — more than the event rate's $6.6M half-spread. The implication is sharp: controls that reduce how often events happen lower the average, but controls that reduce how bad an event gets — rapid traceability, tighter recall scope, contained lot sizes — are what shrink the tail the reserve is built on.

What the model changed

  • The reserve was sized to the tail, not the mean. Recall provisioning moved off the $4.4M expected value and onto the $39M 99% VaR, with the residual tail above it transferred to insurance rather than self-funded.
  • HACCP was justified on tail reduction, not just average savings. The business case led with the 99% VaR falling from $39M to $15M under full HACCP — a far stronger argument than the $3.2M mean-loss saving alone.
  • Control investment was steered toward severity. Because the tornado put severity ahead of frequency in driving the 99% VaR, spending was weighted toward traceability and recall-scope containment over pure event-rate reduction.

ModelRisk Functionality Used

  • Gamma-Poisson (Negative-Binomial) frequency model capturing over-dispersed, clustered recall events with a shared control-regime factor, producing the 52%-zero, mean-0.9 annual event distribution.
  • LogNormal severity with a $2.8M median and $4.9M mean, composed with the frequency model into a 200,000-trial compound annual-loss distribution.
  • Value-at-risk and expected-shortfall readouts quantifying the mean $4.4M, 95% VaR $19.8M, 99% VaR $39.4M and ES99 $56.9M that the point estimate concealed.
  • Three-scenario control comparison translating routine testing and full HACCP into mean-loss and 99%-VaR reductions, netted against program cost.
  • Tornado on the 99% VaR identifying severity parameters (each ~$11M) as larger tail drivers than event frequency ($6.6M).

For a rare, catastrophic exposure like a recall, the expected value is the least useful number in the analysis; Monte Carlo replaces it with the shape of the tail, which is what the reserve, the insurance, and the control program are all actually paying for.