| Vose Software

Industry: Pharmaceutical
Product: ModelRisk
Application: Enterprise Risk Mitigation (ERM)


Aggregating 12 enterprise risks into one number — and deciding which mitigations earn their keep

A typical pharmaceutical enterprise risk register lists between 10 and 30 named risks: API single-source disruptions, sterile-fill contamination events, Warning Letters, Phase III pivotal failures, generic at-risk launches, IPR losses on revenue assets, cold-chain excursions, ransomware outages, KOL controversies. Each risk gets a heatmap colour and a one-line treatment plan. The register is then summarized to the board as a single "high / medium / low" exposure rating. What the register cannot tell the board is the number that actually matters: what is the 95th-percentile total loss across the entire register in any given year, and how does that number change for each dollar of mitigation spending?

A specialty pharmaceutical company with a 12-risk enterprise register rebuilt its ERM analysis in ModelRisk as a fully aggregated stochastic model. Each risk is its own frequency-severity compound, the cross-risk dependence is modeled with a Gaussian copula (because regulatory and supply risks co-move, and commercial and IP risks co-move), and the aggregated annual loss is the metric the board now reviews quarterly.

That single aggregated loss distribution is the picture the heatmap never produced. The naïve sum-of-expected-losses the prior register reported lands at ~$269M; the simulation's mean is ~$351M, and the VaR 95% is ~$1,261M — nearly five times the register's headline number. The expected shortfall beyond VaR 95% (TVaR 95%) is ~$1,859M, the conditional average loss in a bad year and the metric the board now cares most about.

Enterprise annual loss — body, tail, and what the risk register misses

The dotted sum-of-expected-losses line sits materially below the simulation's mean and dramatically below the VaR 95%, and the TVaR 95% runs about 1.5× the VaR 95% because the tail above the 95th percentile is fat and dependence-amplified. The deterministic register would never have produced these numbers.

Each risk modeled the same way, dependence modeled separately

Per-risk model:

  • Annual occurrence — Bernoulli with risk-specific probability. The 12 probabilities span 5% (manufacturing-partner solvency) to 22% (cold-chain excursion above 50% of lot value), all calibrated against eight years of internal incident data plus industry benchmarks.
  • Conditional severity — LogNormal with risk-specific median and σ(log). Medians range from $40M (cold-chain excursion) to $480M (pivotal Phase III failure); σ(log) values 0.6–0.9. LogNormal is the right family for loss severities — bounded below by zero, right-skewed, and capable of producing the heavy tail that pharmaceutical enterprise losses actually exhibit.

Cross-risk dependence is the second-order layer the prior risk-register spreadsheet ignored entirely. Two correlations matter materially:

  • Regulatory ↔ Supply (ρ ≈ 0.35): a Warning Letter at one site is correlated with API disruption and sterile-fill incidents because they share root causes (deviation backlogs, training gaps, vendor changes).
  • Commercial ↔ IP (ρ ≈ 0.30): a successful IPR challenge correlates with generic at-risk launches and with downstream pricing-reform pressure.

These are modeled by a Gaussian copula: sample correlated Normals, push them through the standard-normal CDF to get correlated uniforms, then threshold each uniform against the per-risk Bernoulli probability. The same uniform also seeds the conditional severity draw, so the dependence travels into the severity layer as well, not just the occurrence layer.

Treatment-action ROI — which mitigations earn their keep

The substantive output of the model is the per-risk treatment ROI: how much expected loss the mitigation buys per dollar of mitigation cost.

Treatment-action ROI by risk — which mitigations earn their keep

Several findings landed immediately:

  • The IRA-expansion mitigation (a $3.5M state-level advocacy and channel-shift programme) tops the register at an ROI of ~6 — it attaches to a high-probability, high-severity commercial exposure, so even a modest fractional reduction buys a large amount of expected loss per dollar.
  • The IPR-loss treatment (~4.6 ROI) and the cold-chain excursion treatment (a $1.8M active-temperature shipper-fleet upgrade, ~3.7 ROI) round out the top three. The cold-chain case is the cleanest small-exposure win — the mitigation cuts both probability and severity sharply for a low absolute cost.
  • The Phase III failure "mitigation" (a $12M adaptive-design and biomarker-stratification programme) sits at the bottom of the ranking with an ROI near 0.3 — barely positive — because pivotal failure is largely a function of underlying biology, and the programme reduces severity (faster pivot to backup) more than probability. Its case has to be made on portfolio-construction grounds, not on direct ROI.
  • No treatment in the register is negative-ROI on this calibration, but the low-end cluster — Phase III, ransomware/IT, API single-source — earns its keep only thinly, and each is being re-examined to confirm the mitigation was scoped correctly rather than funded on reflex.

What drives the enterprise tail

A tornado decomposing the VaR 95% by parameter ranks where the next dollar of analytical effort should go:

Tornado: what drives the enterprise VaR 95%

Three parameters sit in a tight top cluster — safety-signal severity, IPR-loss severity, and Phase III failure probability all move the VaR 95% by roughly $115M–$126M of half-spread. The clinical exposures dominate the list: between them, safety-signal severity, Phase III failure probability, and the high-severity commercial/IP risks account for almost all of the tail's parameter sensitivity. This quantified the trade-off clinical operations had been arguing qualitatively — that reducing pivotal failure probability is among the highest-leverage interventions available — and refocused the team on biomarker-stratified Phase II readouts as gating criteria for pivotal initiation.

Where the dependence lives

The Gaussian copula structure is itself the picture that explains why the deterministic register understates the tail:

Cross-risk correlation (Gaussian copula structure)

The visible block-diagonal pattern is the supply-cluster and the commercial-cluster being themselves internally correlated, plus the regulatory↔supply and commercial↔IP cross-links. In a low-dependence world the central-limit theorem would shrink the relative tail of the aggregate; with dependence at this level, the aggregate's right tail is meaningfully heavier than the sum-of-tails the register implies.

What the model changed

  • IRA-advocacy and cold-chain shipper-fleet upgrades approved on first-pass ROI — the register's two strongest small-cost signals, both treatments the prior heatmap had ranked mid-list.
  • Low-ROI mitigations flagged for re-scoping — the Phase III, ransomware, and API single-source treatments, which the model showed earn their keep only thinly as currently specified.
  • Phase III biomarker-stratified Phase II gating instituted across pivotal-initiation governance, driven by pivotal-failure probability sitting in the tornado's top cluster.
  • Enterprise VaR 95% / TVaR 95% added to the board's quarterly risk report, replacing the previous high/medium/low heatmap as the lead exposure metric.

ModelRisk Functionality Used

  • Bernoulli occurrence × LogNormal severity per risk, composed into a per-risk annual-loss distribution.
  • Gaussian copula linking the 12 risks via a fitted correlation matrix, with the visible block structure (supply cluster, commercial cluster, regulatory↔supply cross-link, commercial↔IP cross-link) calibrated to internal incident-co-occurrence data.
  • Aggregation in-cell across 12 dependent random variables — 100,000 trials evaluated against the live risk register, so adding or re-parameterising a risk is a single-cell edit.
  • Per-risk treatment-ROI computation comparing expected-loss reduction against documented mitigation programme cost, ranked end-to-end for board prioritisation.
  • Tornado on VaR 95%, ranking the parameters that the tail is most sensitive to and directing the analytical-investment roadmap.
  • Cross-risk correlation heatmap as the board-level diagnostic for why the aggregate loss is heavier-tailed than the sum-of-parts.

An enterprise risk register that lists 12 risks is not an enterprise risk model — it is a list. Monte Carlo simulation in ModelRisk turns the list into a distribution, the distribution into a VaR, and the VaR into a defensible per-mitigation ROI, so the next dollar of risk spend lands where the tail of the aggregate is actually shrinking.