Project Controls in the AI EraRisk management, Monte Carlo and change control · Lesson 14 of 22
Quantitative risk analysis and Monte Carlo simulation
Video lecture
Quantitative risk analysis and Monte Carlo simulation
The narrated lecture is in production
Every chapter is scripted and ready. Browse the chapters and read the full transcript now — the video will appear here when it’s published.
Chapters
Transcript of the narration, chapter by chapter.
0:00 One date, or a range with confidence?
A deterministic schedule says: finish on the thirtieth of June. It sounds precise. It's also almost certainly wrong, because every duration and every cost in that plan is uncertain, and some risks will happen and others won't. The real question isn't 'when will we finish?' It's 'how confident are we of finishing by any given date?' In this lecture you'll learn how Monte Carlo simulation answers that question, how to build a sound model with three-point estimates, discrete risks and correlation, and how to read the results: P50, P80, the probability of meeting the plan, tornado charts and criticality. By the end you'll be able to interpret a quantitative risk analysis and translate it into three statements a board can act on.
0:53 Why it matters
Why does this matter? Because when you run a proper analysis, it's very common to find the deterministic plan sits at a low confidence level. The plan isn't the most likely outcome. It's an optimistic one. Quantitative risk analysis makes that visible and lets leaders choose a confidence level deliberately. An organisation with a low appetite for risk might fund to P80. Another might accept P50 with specific mitigations. Either can be a sound choice, as long as it's made knowingly. It also replaces habit with evidence in sizing contingency. Instead of 'we always add ten per cent', you can say 'reaching eighty per cent confidence requires this much time and this much money, driven by these three risks'.
1:45 The concept: rolling the dice thousands of times
Here's how it works. Imagine rolling dice for every uncertain activity, recalculating the whole schedule, writing down the finish date, and doing it again. Thousands of times. That's Monte Carlo. First, start from a sound model: a logic-linked schedule for schedule risk, a cost model tied to the WBS for cost risk. Poor logic gives meaningless results. Second, define ranges: minimum, most likely and maximum for key activities or cost items. Third, choose distributions. Triangular and PERT are common; PERT puts more weight on the most likely value. Fourth, add discrete risks from the register, each with a probability of occurring and an impact range, mapped to activities. Fifth, model correlation: related items tend to move together, and ignoring that narrows the range unrealistically. Then the software samples everything thousands of times and gives you a distribution of outcomes.
2:45 Reading the results
Now reading the results. P50 means half the simulated outcomes finish at or before this value. P80 means eighty per cent do. Neither is a guarantee; P80 still leaves a one in five chance of doing worse. The probability of meeting the plan tells you the share of outcomes at or below the deterministic date or cost. The tornado, or sensitivity, chart ranks which inputs drive the most variation, and that's where your mitigation effort should go. And the criticality index shows how often each activity appeared on the critical path across all the iterations. An activity that's critical in sixty per cent of runs deserves attention, even if it isn't on the deterministic critical path at all.
3:36 Worked example one: merge bias
Here's a simple example that shows why Monte Carlo sees things a deterministic schedule can't. You have three independent workstreams running in parallel, and commissioning can't start until all three are finished. Suppose each workstream, on its own, has a fifty per cent chance of finishing on time. What's the chance commissioning starts on time? It's not fifty per cent. All three must be on time. So it's a half, times a half, times a half. Twelve and a half per cent. That's merge bias. Wherever parallel paths converge, the merge point is less likely to be on time than any single path feeding it. The critical path method can't show this. Monte Carlo can. It's one reason projects with many parallel streams slip more than people expect.
4:32 Worked example two: Manchester hospital extension
Now the realistic example from the lesson. A fictional hospital extension in Manchester. Deterministic finish: week seventy. Base cost: twenty-four million pounds. After modelling ranges and twelve discrete risks, the results are sobering. The chance of meeting the plan is about fifteen per cent for time and twenty per cent for cost. P50 is week seventy-five and twenty-five point three million. P80 is week eighty and twenty-six point four million. The top drivers: the risk of discovering asbestos, productivity on building services, and discharging planning conditions. So the contingency needed to reach P80 cost is twenty-six point four minus twenty-four. Two point four million pounds. Now the board can choose its confidence level knowingly, and target mitigation at the three drivers, instead of discovering the gap in eighteen months' time.
5:29 Watch me do it: a Monte Carlo in a few lines
Let me show you the core idea in a Jupyter notebook, so it stops being a black box. I import NumPy and create a random generator with a fixed seed, so results are reproducible. For each of three activities, I draw ten thousand durations from a triangular distribution: minimum, most likely, maximum. Then I add a discrete risk: thirty per cent chance of happening, and if it happens, it adds between ten and twenty days. For a simple chain, the finish is the sum; for parallel paths, I take the maximum, which is exactly how merge bias appears. Then P50 and P80 are just the fiftieth and eightieth percentiles of the results. The full notebook, with correlation, a tornado and criticality, is in the hands-on lab lesson that follows. Dedicated schedule risk tools, such as Safran Risk or Deltek Acumen Risk, do this on full schedules, and Excel add-ins such as @RISK do it on spreadsheet models.
6:37 Good practice and common mistakes
Good practice, briefly. The schedule passes quality checks before you simulate. Ranges come from structured interviews and historical data, with evidence, not a blanket plus or minus ten per cent on everything. Discrete risks come from the register and aren't double-counted in activity ranges. Correlation is considered. Time-dependent costs, like site overheads and equipment hire, are linked to duration so schedule risk flows into cost risk; otherwise cost contingency is usually underestimated. And results are re-run at key decisions. The mistakes are the mirror image: simulating a schedule with missing logic, identical percentage ranges everywhere, treating P80 as a guarantee, and presenting a histogram without explaining what drives it.
7:24 Recap and try this now
Let's recap. Monte Carlo simulation samples every uncertain input thousands of times to give you a distribution of outcomes, not a single date. Build it on a sound schedule, with evidenced ranges, discrete risks from the register and sensible correlation. Read P50, P80, the probability of meeting the plan, the tornado and the criticality index. AI can help calibrate ranges from historical actual-versus-plan data and draft result narratives, but the analyst owns the assumptions. When you present, translate the results into three statements: the probability of meeting the current plan, the time and money needed to reach the organisation's chosen confidence level, and the top three drivers with the actions that would narrow the range. Your try-this-now: list the five most uncertain activities or cost items on a project you know, with minimum, most likely and maximum values and the evidence behind each.
Why a single number is not enough
A deterministic schedule says "finish on 30 June". But every duration and cost is uncertain, and risks may or may not occur. Quantitative risk analysis (QRA) models that uncertainty to produce a range of outcomes with confidence levels, so leaders can make informed decisions about contingency and commitments.
How Monte Carlo simulation works
- Start from a sound model. A logic-linked schedule (for schedule risk) and/or a cost model tied to the WBS (for cost risk). Poor logic produces meaningless results.
- Define uncertainty ranges. For key activities or cost items, estimate minimum, most likely and maximum (three-point estimates).
- Choose distributions. Triangular and PERT (beta) distributions are common for three-point data; PERT gives more weight to the most likely value.
- Add discrete risks. Risk events with a probability of occurring and an impact range, mapped to activities or cost lines.
- Model correlation. Related items tend to move together (e.g., all concrete activities affected by the same productivity issue). Ignoring correlation narrows the range unrealistically.
- Iterate. The software samples every uncertain input thousands of times, recalculating the finish date and total cost each time.
- Analyse results. The output is a distribution: histogram and cumulative S-curve of possible outcomes.
Reading the results
- P50: 50% of simulated outcomes are at or below this value.
- P80: 80% of outcomes at or below this value; often used for contingency setting or funding in organisations with lower risk appetite.
- Deterministic probability: the percentage of outcomes at or below the plan. It is common to find the deterministic plan sits at a low confidence level, which is a sign of optimistic planning.
- Sensitivity / tornado chart: which inputs drive the most variation.
- Criticality index: how often each activity appears on the critical path across iterations.
Worked example
Illustrative. A fictional hospital extension in Manchester has a deterministic finish of week 70 and base cost of £24.0M. After modelling ranges and 12 discrete risks:
| Measure | Schedule | Cost |
|---|---|---|
| Deterministic plan | Week 70 | £24.0M |
| Probability of meeting plan | ~15% | ~20% |
| P50 | Week 75 | £25.3M |
| P80 | Week 80 | £26.4M |
| Top drivers | Asbestos discovery risk, MEP productivity, planning condition discharge | Same, plus escalation of MEP packages |
Contingency to reach P80 cost = £26.4M − £24.0M = £2.4M. The board can now choose its confidence level knowingly instead of discovering the gap later.
Merge bias
Where several parallel paths converge (e.g., three workstreams all needed before commissioning), the probability of the merge point finishing on time is lower than for any single path, because all must be on time. Deterministic CPM cannot show this; Monte Carlo can. This is one reason projects with many parallel streams slip more than people expect.
Integrated cost and schedule risk
Time-dependent costs (site overheads, equipment hire, supervision) grow when the schedule slips. Integrated models link these costs to duration so that schedule risk flows into cost risk. Otherwise cost contingency is typically underestimated.
Good practice checklist
- Schedule passes quality checks before simulation.
- Ranges come from structured interviews, with evidence, not a blanket ±10%.
- Discrete risks come from the register and are not double-counted with ranges.
- Correlation is considered.
- Results are presented as ranges with drivers and recommended actions.
- The model is re-run at key decision points and after major changes.
Common mistakes
- Running Monte Carlo on a schedule with missing logic.
- Using identical percentage ranges on every activity.
- Treating P80 as a guarantee.
- Double counting a risk in both an activity range and a discrete event.
- Presenting a histogram without explaining what drives it.
AI and QRA
AI can help calibrate ranges from historical actual-vs-plan data, identify likely correlations and draft result narratives. The analyst remains accountable for model assumptions, which must be documented and reviewable.
Communicating results to leadership
Leaders rarely want histograms. Translate results into three statements: the probability of meeting the current plan, the time and cost needed to reach the organisation's chosen confidence level, and the top three drivers with the actions that would narrow the range. Then record the decision taken, for example funding to P80 or accepting a lower confidence with specific mitigations.
Hands-on: a Monte Carlo in plain Excel
No add-in is needed to understand the mechanics. For a triangular distribution with minimum a, most likely c and maximum b, the inverse-CDF sample from a uniform U = RAND() is:
F_c =(c-a)/(b-a)
Sample =IF(U<F_c, a+SQRT(U*(b-a)*(c-a)), b-SQRT((1-U)*(b-a)*(b-c)))- Put one iteration per row (for example 5,000 rows), one uncertain activity per column, each using its own
RAND(). - Add a discrete risk column:
=IF(RAND()<0.3, 10+RAND()*10, 0)for a 30% risk adding 10–20 days. - Finish = sum for a chain;
MAX()of path totals where paths merge. P50 =PERCENTILE.INC(Finish, 0.5),P80 =PERCENTILE.INC(Finish, 0.8), plan confidence=COUNTIF(Finish,"<="&Plan)/COUNT(Finish).- Press F9 to re-sample; results should move only slightly with 5,000+ iterations.
Commercial add-ins and schedule risk tools (for example Safran Risk and Deltek Acumen Risk for schedules, or @RISK for Excel models) run the same logic at scale, handle correlation and produce tornado and criticality outputs. Check each vendor's current documentation for features and licensing.
Hands-on: the core in Python
import numpy as np
rng = np.random.default_rng(42)
N = 10_000
# three parallel paths feeding commissioning (days: min, most likely, max)
path_a = rng.triangular(40, 45, 60, N)
path_b = rng.triangular(35, 42, 55, N)
path_c = rng.triangular(38, 44, 58, N)
risk = np.where(rng.random(N) < 0.30, rng.uniform(10, 20, N), 0.0) # 30% risk on path B
commissioning = rng.triangular(8, 10, 14, N)
finish = np.maximum.reduce([path_a, path_b + risk, path_c]) + commissioning
plan = 45 + 10 # deterministic: longest most-likely path + commissioning
print(f"Plan confidence {np.mean(finish <= plan):.0%}")
print(f"P50 {np.percentile(finish, 50):.1f} days, P80 {np.percentile(finish, 80):.1f} days")Run it and note how low the plan confidence is: that is merge bias plus skewed ranges at work.
How to measure success
- Plan confidence, P50 and P80 reported at each major decision, with top drivers.
- Ranges documented with evidence; risks traceable to the register.
- Post-project comparison of actual outcomes with the forecast distributions to calibrate future ranges.
Key takeaways
- Monte Carlo samples uncertain durations, costs and risk events thousands of times to produce outcome distributions.
- P50 and P80 express confidence levels; the deterministic plan often has low confidence.
- Merge bias and correlation make realistic ranges wider than intuition suggests.
- Garbage in, garbage out: schedule quality, evidenced ranges and no double counting are essential.
Check your understanding
Quick questions to lock in the lesson. They don’t count towards your certificate.
Put it into practice
List the five most uncertain activities or cost items on a project you know. For each, write min / most likely / max values and the evidence behind them.
Enrol for free to save your progress
Reading is always free. Enrol to keep your place, take the final assessment and earn a verifiable certificate.