Industry: Construction and Infrastructure Product: ModelRisk Application: Risk Register Quantification on a $2B Metro Project
A $2B underground metro project carried a risk register with 38 named events — ranging from "TBM cutter-head obstruction" (40% likelihood, $4–18M impact) to "archaeological discovery requiring rerouting" (5% likelihood, $30–95M impact). The deterministic risk roll-up summed the expected values to a $70M risk-weighted exposure. The Monte Carlo aggregation said the probability of total risk impact exceeding the $100M contingency was 17%, and the 99% VaR was $171M — 1.7× the booked contingency and nearly 2.5× the deterministic exposure the project had reserved against.
The difference is not because the deterministic sum was arithmetically wrong. It is because expected value is the wrong number to fund against.
The heat map is the familiar likelihood-versus-impact register view — but here each cell is the expected dollar exposure (probability × mean impact) contributed by the risks that fall in it, not a subjective red/amber/green rating. The dense band of moderate-probability, moderate-impact risks is where most expected value lives; the sparse high-impact / low-probability cells in the top-left are where the tail lives. The two require different funding logic, and the rest of this analysis quantifies both.
Every line in a project risk register is implicitly a compound distribution: a probability of occurrence multiplied by an impact distribution. Adding them up correctly requires Monte Carlo aggregation, not arithmetic on the means. The 38 risks were rebuilt as:
Treating the risks as independent under-states the aggregate P99 only modestly here — about 2% ($168M vs $171M) — because the register is large and the correlated pairs are a minority of it. But the dependency bites locally: where two risks share a root cause, the joint tail is far heavier than independence predicts, and that joint tail is exactly what overruns a tunnelling contingency. The aggregate number hides it; the pairwise view (below) does not.
The Pareto view showed that 7 risks accounted for 78% of expected impact — but the tail of the aggregate distribution was dominated by a different set: the four risks with low probability and very high impact (ground collapse, archaeological discovery, contractor insolvency, force-majeure event). These never made it to the top of the expected-value ranking, but they owned the 99th percentile.
50,000 trials of the 38-risk register, with the calibrated copula on the five correlated pairs, produced a sharply right-skewed distribution.
The $100M contingency reserve sat at the P83 — meaning a 17% chance that the aggregate impact would breach the contingency. Pushing the contingency to P95 required $133M; pushing to P99 required $171M. The board's risk appetite — a 5% probability of breaching — demanded $133M, not $100M. The gap to the booked contingency was $33M at the board's own stated appetite, and it was visible only after Monte Carlo aggregation.
A risk register added up line-by-line implicitly assumes the risks are independent. The most consequential dependency in this project is between the TBM cutter-head obstruction and the ground-condition surprise — they share a root cause (the same uncertain geology), so they tend to fire together, and when they do, both fire large. The scatter below plots the two risks' per-trial impacts against each other.
The mass in the upper-right quadrant — both geotechnical risks severe in the same simulated project — is the joint tail. A sum-of-independent-risks model lands there with probability 0.56%; the copula-aware model lands there 0.72% of the time — roughly 30% more often — because the geology that triggers one triggers the other. The gap looks small in percentage points, but it is concentrated entirely in the most expensive corner of the distribution: that upper-right quadrant is exactly the scenario that overruns a tunnelling contingency, and it is invisible to a deterministic register.
The biggest driver of P99 was the TBM obstruction risk (40% probability, $4–18M impact, Poisson multiplicity averaging 1.5 events). The single-event tail of the archaeological-discovery risk was second. Third was the calibrated correlation between TBM and ground-condition risks — though, as the aggregate showed, the register-wide effect of correlation is small; its leverage on P99 comes almost entirely through this one geotechnical pair.
The bottom of the tornado was illuminating: risks that the project team had spent hours debating in workshops — supplier insolvency, IT-system failure, key-personnel turnover — moved the answer by less than $4M. The Monte Carlo redirected workshop time away from these and toward the four risks that owned the P99: TBM obstruction, ground condition, archaeological discovery, and labour productivity loss.
The project team had been arguing about whether to insure or self-insure each risk based on its expected value. Monte Carlo reframed the question:
After applying these decisions — transferring the four tail risks and halving the modelled correlation on the retained pairs — the re-simulated P99 dropped from $171M to $131M and the P95 from $133M to $107M. The contingency was right-sized at $110M (the retained P95), and roughly $40M of P99 capital was released for use elsewhere on the programme.
A risk register is not a list of numbers to add up. It is a portfolio of distributions to convolve — and the convolution lives in the tail, which the average never sees.