Industry: Pharmaceutical Product: ModelRisk Application: Enterprise Risk Mitigation (ERM)
A typical pharmaceutical enterprise risk register lists between 10 and 30 named risks: API single-source disruptions, sterile-fill contamination events, Warning Letters, Phase III pivotal failures, generic at-risk launches, IPR losses on revenue assets, cold-chain excursions, ransomware outages, KOL controversies. Each risk gets a heatmap colour and a one-line treatment plan. The register is then summarized to the board as a single "high / medium / low" exposure rating. What the register cannot tell the board is the number that actually matters: what is the 95th-percentile total loss across the entire register in any given year, and how does that number change for each dollar of mitigation spending?
A specialty pharmaceutical company with a 12-risk enterprise register rebuilt its ERM analysis in ModelRisk as a fully aggregated stochastic model. Each risk is its own frequency-severity compound, the cross-risk dependence is modeled with a Gaussian copula (because regulatory and supply risks co-move, and commercial and IP risks co-move), and the aggregated annual loss is the metric the board now reviews quarterly.
That single aggregated loss distribution is the picture the heatmap never produced. The naïve sum-of-expected-losses the prior register reported lands at ~$269M; the simulation's mean is ~$351M, and the VaR 95% is ~$1,261M — nearly five times the register's headline number. The expected shortfall beyond VaR 95% (TVaR 95%) is ~$1,859M, the conditional average loss in a bad year and the metric the board now cares most about.
The dotted sum-of-expected-losses line sits materially below the simulation's mean and dramatically below the VaR 95%, and the TVaR 95% runs about 1.5× the VaR 95% because the tail above the 95th percentile is fat and dependence-amplified. The deterministic register would never have produced these numbers.
Per-risk model:
Cross-risk dependence is the second-order layer the prior risk-register spreadsheet ignored entirely. Two correlations matter materially:
These are modeled by a Gaussian copula: sample correlated Normals, push them through the standard-normal CDF to get correlated uniforms, then threshold each uniform against the per-risk Bernoulli probability. The same uniform also seeds the conditional severity draw, so the dependence travels into the severity layer as well, not just the occurrence layer.
The substantive output of the model is the per-risk treatment ROI: how much expected loss the mitigation buys per dollar of mitigation cost.
Several findings landed immediately:
A tornado decomposing the VaR 95% by parameter ranks where the next dollar of analytical effort should go:
Three parameters sit in a tight top cluster — safety-signal severity, IPR-loss severity, and Phase III failure probability all move the VaR 95% by roughly $115M–$126M of half-spread. The clinical exposures dominate the list: between them, safety-signal severity, Phase III failure probability, and the high-severity commercial/IP risks account for almost all of the tail's parameter sensitivity. This quantified the trade-off clinical operations had been arguing qualitatively — that reducing pivotal failure probability is among the highest-leverage interventions available — and refocused the team on biomarker-stratified Phase II readouts as gating criteria for pivotal initiation.
The Gaussian copula structure is itself the picture that explains why the deterministic register understates the tail:
The visible block-diagonal pattern is the supply-cluster and the commercial-cluster being themselves internally correlated, plus the regulatory↔supply and commercial↔IP cross-links. In a low-dependence world the central-limit theorem would shrink the relative tail of the aggregate; with dependence at this level, the aggregate's right tail is meaningfully heavier than the sum-of-tails the register implies.
An enterprise risk register that lists 12 risks is not an enterprise risk model — it is a list. Monte Carlo simulation in ModelRisk turns the list into a distribution, the distribution into a VaR, and the VaR into a defensible per-mitigation ROI, so the next dollar of risk spend lands where the tail of the aggregate is actually shrinking.