top of page
Search

Beyond Static - contemporary risk management

  • Rob Cornish
  • Apr 30, 2025
  • 3 min read

Updated: Aug 3



Most organizations and projects manage risk with a familiar tool: a risk register, listing identified risks scored on a simple grid of likelihood and impact, typically color-coded red, yellow, and green. If you’ve ever sat through one of these workshops, it feels rigorous, produces a tidy document, a defensible paper trail, and a fleeting sense that risk has been accounted for. It is also, in today's world, a substantially inadequate way to actually understand and make informed decisions about risk - and the gap between what static risk registers promise and what they deliver has become one of the more expensive blind spots in modern project and financial management. This is particularly the case as we watch in real time a world that is anything but static - one that is contending with issues such as AI, climate volatility and conflict and displacement - all of which seem to be contributing to a faster pace of change and an increased complexity of the environment we are all operating within.


The core problem is that static risk assessment methodologies force continuous, uncertain phenomena into discrete categories that don't actually exist in reality. A risk scored as "medium likelihood, high impact" tells you almost nothing useful: is that a 20% chance of a cost overrun, or a 45% chance? Is the impact $50,000 or $5 million? The categorical label flattens a distribution of possible outcomes into a single point on a grid, discarding exactly the information needed to make a genuinely informed decision. Worse, static registers typically evaluate each risk in isolation, as though a schedule delay, a cost overrun, and a supply disruption exist independently of one another - when in reality, project risks are correlated and often compound: a single upstream delay cascades into cost overruns, resource conflicts, and quality shortcuts simultaneously, in ways a risk-by-risk checklist structurally cannot represent.


Probabilistic risk models and simulation-based approaches - Monte Carlo simulation chief among them - solve both problems directly. Rather than assigning a single point estimate to a risk's likelihood and impact, a probabilistic model represents each uncertain variable as a distribution: a range of possible outcomes with associated probabilities, reflecting the genuine uncertainty in, say, a construction task's duration or a material cost's volatility. Running that model thousands of times, each iteration sampling different values from those distributions, produces not a single predicted outcome but a full distribution of possible project outcomes - a genuine answer to the question "what's the probability this project finishes on budget," rather than a categorical guess dressed up as an assessment. Because the simulation can model correlations between variables explicitly, it also captures the compounding effects that static registers miss entirely: what happens to total project risk when a schedule delay and a cost overrun are likely to occur together, rather than independently.


This distinction has direct financial consequences. A project team relying on a static risk register typically builds a single contingency figure into its budget, usually a flat percentage applied uniformly regardless of the actual shape of the underlying uncertainty. A team running probabilistic simulation can instead identify the actual confidence level associated with any given contingency figure - a P50 estimate meaning the budget has a fifty percent chance of being sufficient, a P80 estimate meaning an eighty percent chance - and make a deliberate, informed choice about how much risk tolerance the organization is willing to accept, rather than defaulting to a round number inherited from convention.


This is not intended as a criticism of historical efforts to manage risk, but rather to highlight the good news - those technological advances, both AI-based and otherwise, make Probabilistic Risk Assessment (PRA) genuinely accessible for organizations or projects of any size, and the cost of implementation has never been more reasonable. PRA most effectively and practically runs as a simple add-in to spreadsheets, and while the old adage relating to the quality of data-in, data-out still applies, adoption of the underlying PRA process forces key stakeholders into a discussion that is commensurate with the modern challenges they are facing.  While risk assessment is only one of the stages of an effective risk management process, adopting a dynamic risk management policy framework serves to fundamentally align process with reality, which can only improve the probability of achieving the outcomes we are looking for.

 
 
 

Comments


Commenting on this post isn't available anymore. Contact the site owner for more info.
bottom of page