| Vose Software

Industry: Project Management
Product: ModelRisk
Application: Budget Control


When the 10% Contingency Is Not Enough: Probabilistic Budget Control with ModelRisk

The PMI benchmark for civil infrastructure is a 10–30% cost overrun, and a 10% blanket contingency is what most contractors quote into bids. Yet a $200M highway build with that boilerplate buffer carries a 35–45% probability of breaching contract price — the deterministic estimate cannot see it, because the deterministic estimate is a single number on a distribution that has a long right tail. Budget control is not about getting the mean right. It is about knowing where the P80 sits and what is driving it there.

A road and bridge contractor in Southeast Asia rebuilt the budget for a 24-month, $200M expressway project in ModelRisk. The objective was specific: produce a P50 baseline that earned-value reports could be tracked against, a P80 commitment number that capital-allocation committees could approve, and a ranked list of drivers that pointed the next dollar of risk spend at the right component. The simulation, run for 100,000 trials, is shown below — and it is the chart that ended the argument about whether a 10% buffer was enough.

Total at-completion cost — 100,000 Monte Carlo trials

The deterministic spreadsheet — base $180M direct plus a flat 10% contingency — handed back $198M and called the bid comfortable. The mean of the simulated cost lands close to that, at about $197M, but the P90 sits at $226M and the empirical probability of breaching the $200M contract price is 42%, not the implied 0% of the deterministic plan. The rest of this study is about where that 42% comes from and what it costs to buy it down.

Where the budget actually lives

The bottom-up estimate assembled four direct-cost components and a discrete risk register. Distribution choices were defended against historical project data, not picked off a list.

  • Materials (cement, asphalt, structural steel) — LogNormal, mean $70M, sigma_log 0.22. Commodity prices are right-skewed; a Normal here permits negative prices and undersells the 2021-style spike tail.
  • LaborLogNormal, mean $60M, sigma_log 0.18. Hour-bank pressure and overtime cap the upside softly but never produce a negative wage bill.
  • Equipment rentalBeta-PERT (min $18M, mode $24M, max $32M). Bounded by fleet availability on both sides; PERT puts mass on the mode the way expert elicitation actually delivers it.
  • Subcontractor feesBeta-PERT (min $24M, mode $30M, max $42M), correlated to Materials at rho = 0.45 through a shared commodity-index latent. Independent draws would have understated the joint tail by roughly 18%.

The PMI risk register added four discrete events drawn each iteration as Bernoulli × impact: monsoon-season overrun (P = 0.55, mean impact $9M, LogNormal), steel-price shock (P = 0.25, mean $14M), permit re-issue (P = 0.12, Triangular $4–18M), and a geotechnical surprise (P = 0.18, Triangular $3–22M).

What the deterministic estimate hides

Reading the distribution back: the P50 sits at $196M and the P90 at $226M — a P50-to-P90 gap of about $31M, which is more than the entire 10% contingency on its own. The "10% buffer" only carries the bid to a P55, not a P80, and the 42% breach probability says the contingency was being priced like an inevitability, not an insurance policy.

What actually moves the number

Rank-correlation tornado against total-cost output points the risk team at the largest leverage:

Tornado — drivers of total-cost variance

Materials price dominates by a wide margin, at roughly ±$16M of half-spread — about half again as large as the next driver. Labor cost is second at ±$11M; the correlated subcontractor draw and the steel-price shock event are tied for third at ±$6M each. The monsoon-overrun event has the highest expected cost impact in the Pareto view below, but a lower spread effect because its occurrence probability of 55% means the simulation prices most of it into the baseline rather than the tail.

Risk-register events ranked by expected cost impact (Pareto)

The top three events — monsoon, steel shock, geotech — account for about 75% of the expected risk-event cost. That is where mitigation dollars should go first.

Repricing the contingency

Two mitigations were costed and rerun through the same simulation. A fixed-price steel forward contract at a 3% premium to spot eliminated the steel-shock event and tightened materials sigma from 0.22 to 0.14. A monsoon-aware schedule moved 60% of weather-exposed activities outside the rainy window. The combined cost of both mitigations was about $2.2M up-front.

Mitigated plan vs baseline — P(exceed $200M) collapses

The P90 moves down by roughly $14M and the probability of breaching the $200M contract price drops from 42% to about 27%. For a $2.2M cost-of-risk-treatment, that is a ratio the audit committee can approve in a single meeting — and it is a number that did not exist before the simulation.

What the model changed

  • The bid was repriced. The contractor proposed a $211M ceiling with a transparent shared-savings clause — covering its P75 rather than its P50 and giving the client a credible upper bound rather than a marketing one.
  • Contingency was reallocated. Instead of a flat 10% spread across all line items, 65% of the contingency was redirected to materials and subcontractor exposure, where the tornado said the spread actually was.
  • Earned-value baselines became defensible. SPI and CPI reports tracked against the P50 cost baseline; any drift past the P70 line triggered a formal stage-gate review.
  • Tail risk had a price. The audit committee approved the $2.2M mitigation package because it was framed as "buying 15 points of overrun probability," not as "spending money on caution."

ModelRisk functionality used

  • Beta-PERT and LogNormal cost components parameterised from historical line-item data, not a universal Triangular.
  • Gaussian copula coupling of Materials and Subcontractor draws at rho = 0.45 — independent draws under-priced the joint tail by 18%.
  • Discrete risk-event register with Bernoulli triggers and parameterised impact distributions, summed into the cost roll-up per iteration.
  • Rank-correlation tornado that ranked the eight largest drivers and identified that two correlated inputs carried half the variance.
  • Mitigation comparison rerun on the same 100,000 trial seed so that the P(overrun) drop was attributable to the mitigation, not Monte Carlo noise.
  • Pareto ranking of risk-register events by expected cost impact — the input that re-prioritised the mitigation budget.

A deterministic estimate forces a single number to do two incompatible jobs: it has to be the most likely cost and the commitment number. The Monte Carlo answer separates the two — P50 for what you expect, P80 for what you commit — and tells you, line by line, where the contingency really has to sit.