Abstract
Several techniques have been proposed to prioritize risks identified in projects. In academia and business, the most standard use is the probability-impact matrix, also known as the risk matrix. Although widespread, this tool has specific limitations, as demonstrated in numerous studies. This article introduces a quantitative method based on Monte Carlo simulation to enhance project risk prioritization. Our proposed method quantifies the impact of each risk on both duration and total cost objectives, enabling us to determine each risk’s relative importance based on these values. In contrast to previous work, this paper proposes a methodology that integrates the effects of risk interactions and the structure of the project-defining network. We conducted two simulation studies, which are detailed in this article. The first study uses fictitious projects to examine the influence of project network structure on the effectiveness of the risk matrix, compared with our proposed methodology. In the second study, we apply our method to two distinct real-world projects and compare these findings with results from simulations of fictitious projects. The conclusions indicate that the traditional risk matrix method produces results that diverge from those generated by our proposed approach, which quantifies impacts. Moreover, it was observed that the risk matrix provides more reliable results when a project’s structure approximates a serial configuration. However, its accuracy in risk prioritization declines for projects with a more parallel structure.
Similar content being viewed by others
1 Introduction
Risk management is crucial for anticipating, addressing, and mitigating potential issues that may impact a project’s success, thereby playing a vital role in achieving project objectives effectively and efficiently (Afzal et al., 2021; Ale et al., 2015; Qazi et al., 2021). In any project, risks might arise from various sources, such as changes in scope, budget constraints, schedule delays, or unforeseen technical problems. Identifying and managing these risks from the outset minimizes their impact and ensures that the project progresses as planned (Thamhain, 2013).
Risk management is one of the most critical knowledge areas in project management (Kendrick, 2009). This area involves identifying and assessing risks and developing strategies to respond effectively. Taking a proactive approach to risk management enables project teams to anticipate and prepare for potential challenges, rather than reacting to problems as they arise (Kaliprasad, 2006). This preparedness and responsiveness are critical for keeping the project on track and meeting the stated objectives.
There are numerous standards and methodologies in project management, and they all attach much importance to risk management. For example, one main chapter of the PMBOK (Project Management Body of Knowledge) (Project Management Institute, 2017, 2021) focuses on risk management, emphasizing its importance within the overall project management framework. Similarly, methodologies such as PM2 (European Commission, 2023) and frameworks such as RINCE2 (Axelos, 2023) incorporate risk management as an essential practice. These methodologies provide specific tools and techniques to identify, assess, and mitigate risks, helping project teams maintain proper control and direction.
Risk management encompasses several vital processes, including identification, assessment, risk response planning, and risk monitoring and control (International Organization for Standardization, 2012). Risk identification involves recognizing all the possible events that might affect the project, whether positive or negative. Once identified, these risks must be assessed to determine their likelihood and potential impact on the project. This assessment uses both qualitative and quantitative techniques.
A qualitative risk assessment prioritizes risks based on their likelihood of occurrence and potential impact. According to the Project Management Body of Knowledge (PMBOK), risk prioritization involves assessing and ranking identified risks in a project based on their probability of occurrence and the potential impact if they materialize (Project Management Institute, 2017). This assessment enables project managers to concentrate their resources and efforts on the most significant risks that may impact project objectives.
Beyond ease of use, prioritization methods should connect local activity risks to project-level outcomes through the project network, since serial/parallel structure and slack mediate how disturbances propagate. This motivates comparing qualitative matrices with quantitative, network-aware approaches.
Risk matrices are widely recognized as tools for assessing and ranking risks across various fields and sectors (Krisper, 2021; Li et al., 2018; Monat & Doremus, 2020; Qazi & Simsekler, 2021; Qazi et al., 2021). Today, they are so common that they are universally accepted and employed without question, along with their benefits and drawbacks. Risk matrices use the likelihood and potential impact of risks to inform decisions about prioritizing identified risks (Proto et al., 2023). Risk matrix methods (PxI) prioritize risks based on their likelihood and impact. Hence, those risks with higher risk level values will receive priority in resource allocation over those with lower assessment scores.
However, the probability-impact matrix has severe limitations (Ball & Watt, 2013; Cox, 2008; Cox et al., 2005; Duijm, 2015; Goerlandt & Reniers, 2016; Levine, 2012; Vatanpour et al., 2015). The primary criticism of this methodology is that it overlooks the complex interrelationships among various risks and does not use precise estimates of probability and impact levels. Consequently, many academics and practitioners are reluctant to use risk matrices (Acebes et al., 2024a, 2024b, 2024c; Qazi et al., 2021). These limitations suggest the need for quantitative formulations that avoid ordinal arithmetic and explicitly account for network propagation of risk effects on duration and cost.
Therefore, alternative proposals for using the risk matrix to prioritize project risks are emerging. Some are based on simple modifications of the original matrix, while others use quantitative techniques for prioritization. Of the latter, it is worth highlighting the proposals of Krisper (2021) and Qazi et al. (2021), which call for incorporating probability distributions into the definition of probability and impact for calculating quantitative prioritization indicators. Furthermore, in line with the work of Creemers et al. (2014), Acebes et al., (2024a, 2024b, 2024c) propose a novel risk-driven quantitative approach to prioritize risks, known as Quantitative Risk Prioritization (QRP). In this approach, the identified risks are embedded in the project model and analyzed using Monte Carlo simulation to quantify their impact on total duration and total cost, resulting in a prioritized list of risks.
This paper builds directly on Acebes et al., (2024a, 2024b, 2024c) and introduces a substantive advance identifying individual risk contributions. Whereas the earlier method assessed each risk by adding it to a risk-free baseline “one at a time”, the methodology we propose in this paper is network-conditional: we simulate the project with all identified risks active and, for each risk, run a counterfactual in which that single risk is disabled. Comparing the baseline (all risks) with the minus-risk scenario isolates the marginal impact of that risk, while conditioning on the concurrent presence of the others and on the project network's structure (e.g., whether the affected activity lies on a serial path or a parallel branch with slack). This design integrates both the specific activities concerned and the propagation implied by the precedence relations, providing a more faithful measure of how risks influence the project objectives.
In addition, when a risk can affect both duration and cost, we evaluate it holistically as a single risk rather than splitting it into separate “duration” and “cost” risks. This unified treatment allows the cost impact to reflect both channels, the risk’s direct effect on cost parameters, and its indirect effect via time (e.g., variable costs that accrue with longer activity durations). In contrast, the schedule impact remains driven by where the risk acts in the network and the available slack. The result is a pair of coherent rankings (duration-based and cost-based) derived from the same underlying risk, avoiding the artificial fragmentation present in the previous methodology.
To isolate structural effects, we adopt standard baseline assumptions (unlimited resources; independent risks beyond precedence coupling). These choices keep the focus on the methodological contrast (P × I vs QRP) and the role of network structure. By making the prioritization logic explicit and network-conditional, the proposed framework defines a reproducible decision rule that can be embedded in project risk decision-support environments, independently of whether the underlying computations are performed manually or automatically. With these substantial modifications to the initial proposal and being aware of the limitations of the probability-impact matrix in terms of the results that it offers for risk prioritization, the following research question arises: Does the project’s network typology (degree of serial/parallel structure) affect the alignment between P × I rankings and QRP’s network-conditional rankings?
A comprehensive double-simulation study addressed this question, incorporating enhancements to the risk prioritization methodology. The first simulation phase involved a series of fictitious projects with diverse network typologies, ranging from sequential, series-type configurations to parallel structures. This approach aimed to evaluate the degree of alignment between the responses generated by the risk matrix and the QRP approach across the full spectrum of possible network typologies. In the second phase, we applied the methodology to two real-world projects, each exhibiting distinct typologies, and subsequently prioritized the identified risks. This second simulation is expected to facilitate comparison of results from both methodologies (QRP and risk matrix) and to verify that the outcomes obtained in this simulation—using real projects with different structural typologies—are consistent with those derived from the initial simulation, which used fictitious projects. We emphasize that artificial projects provide internal validity and control, whereas the two real projects serve as concise external plausibility checks that the controlled patterns do not contradict practice.
In practice, there is no observable ground truth for the exact ordering of risks in a project. Different (and defensible) modelling choices, including network structure, probability/impact distributions, dependence assumptions, and other risk appetites, inevitably lead to different orderings. Consequently, our goal is not to assert absolute accuracy. Instead, we target consistency under stated assumptions: given an explicit model and a percentile level α, QRP yields reproducible rankings based on the marginal contribution of each risk to project duration and cost. Our evaluation is therefore comparative, focusing on robustness across controlled scenarios and agreement with baseline methods, rather than a validation against a non-existent ground truth.
The remainder of this article is organized as follows: Sect. 2 reviews the literature by addressing the problem posed using the risk matrix. We then present the methodology in Sect. 3 by discussing the proposed changes. In Sect. 4, we conduct simulation exercises: the first uses fictitious projects, and the second uses an actual project. Then, in Sect. 5, we comment on and discuss the results. Finally, in Sect. 6, we present the conclusions of our work.
2 Risk assessment matrix
A central problem in project risk management is deciding which risks to address first to protect the schedule and profitability under resource constraints (Chapman & Ward, 2011). Given that the sources of risk are numerous and heterogeneous, and that it is often impossible to make accurate estimates, prioritisation is essential, but not trivial. Practitioners value approaches that are transparent, easy to apply, and defensible, even when data are sparse. This demand explains the enduring appeal of probability–impact (P × I) matrices as a screening device to guide resource allocation across sectors. Beyond project management, their use extends to industrial operations, occupational health and safety, process industries (oil & gas/chemical), healthcare, and finance (Baybutt, 2018; Goerlandt & Reniers, 2016; Levine, 2012; Proto et al., 2023; Talbot, 2014; Thomas et al., 2014).
P × I matrices, codified in standards (International Organization for Standardization, 2018, 2019), provide simple, communicable categorizations of likelihood and impact and require limited expertise for implementation (Duijm, 2015; Kaya et al., 2019; Krisper, 2021; Li et al., 2018). Their graphical form (two axes discretized into levels whose combinations yield color-coded ratings) facilitates rapid triage (Ale et al., 2015; Baybutt, 2018; Creemers et al., 2014; Hubbard, 2009; Hulett, 2009). However, a substantial body of research has identified structural limitations: subjective and sometimes ambiguous scales; ordinal arithmetic being used as though interval; coarse resolution that induces ties; limited ability to represent joint or compounding effects; and weak compatibility with downstream quantitative analysis (Ale et al., 2015; Cox, 2008; Cox et al., 2005; Duijm, 2015; Elmonstri, 2014; Hubbard, 2009; Krisper, 2021; Levine, 2012; Monat & Doremus, 2020; Ni et al., 2010; Qazi & Dikmen, 2021; Qazi & Simsekler, 2021; Talbot, 2014; Taroun, 2014; Vatanpour et al., 2015). Proposed refinements, such as logarithmic axes, finer levels, or color rules aligned with quantitative definitions, ameliorate presentation but do not change the fundamentally categorical nature of the method (Akcay, 2021; Aven, 2017; Baybutt, 2018; Bolbot et al., 2022; Duijm, 2015; Goerlandt & Reniers, 2016; Kengpol & Tuammee, 2016; Levine, 2012; Monat & Doremus, 2020; Proto et al., 2023; Ruan et al., 2015).
Consequently, the literature has explored quantitative alternatives that either complement or substitute the matrix. One line replaces categories with continuous scales or adopts multi-criteria aggregation (e.g., TOPSIS) to enhance discrimination and reduce subjectivity (Duijm, 2015; Koulinas et al., 2021). Another uses expected values (probability × impact per event, then summation) to obtain a single metric (Haimes, 1993); while transparent, this approach can be misleading for tail risks. In project scheduling, Monte Carlo simulation is widely used to propagate activity-level uncertainty to project-level duration and cost, producing probabilistic outputs that support risk-based decisions (Aven, 2010; Creemers et al., 2014; Naderpour et al., 2019).
Within quantitative prioritization, Qazi and co-authors integrate risk attitude, uncertainty, and dependence to prioritize risks by expected utility under Monte Carlo sampling (Qazi & Dikmen, 2021; Qazi & Simsekler, 2021; Qazi et al., 2021). Krisper (2021 likewise advocates using fully quantitative value ranges, ratio scales, and probability distributions to avoid ordinal pitfalls. These contributions enhance the information content of prioritization; however, in practice, their operationalization depends on how risk effects propagate through the project network (a dimension that not all formulations explicitly model). Unlike multi-criteria decision-making techniques such as AHP, which rely on subjective weighting and static aggregation (Ishizaka & Labib, 2011; Tavana et al., 2023), QRP is a simulation-based, network-conditional framework that quantifies how risks propagate through precedence-constrained project networks.
Against this backdrop, Acebes et al., (2024a, 2024b, 2024c) introduced a risk-driven approach that embeds identified risks in the project model and ranks them based on their simulated impact on total duration and total cost. That formulation estimates a risk’s contribution by adding each risk to a risk-free baseline. While clearly structured, the “add-one” design limits conditioning on concurrent risks and may only partially reflect the network structure (e.g., serial vs. parallel paths, slack), which mediates how local disturbances affect project objectives.
This article presents a network-aware refinement of quantitative risk prioritization. Methodologically, we shift from an “add-one” to a “knock-one-out” design: the baseline simulation runs with all identified risks active, and for each risk, we simulate a counterfactual where that single risk is disabled; marginal impacts are measured as the differences in chosen percentiles of total duration/cost between these scenarios. This makes prioritization explicitly conditional on (i) where the risk acts in the network and (ii) the simultaneous presence of other risks. Substantively, when a risk can affect both time and cost, we treat it as one entity and report two coherent rankings, schedule (ΔTr(α)) and cost (ΔCr(α)), so the cost impact reflects direct cost parameters and indirect effects via time (e.g., variable cost rates). In contrast, the time impact captures the dynamics of the critical path. In this way, our formulation positions itself as a quantitative, network-conditional alternative to P × I and as a methodological advance over prior QRP variants, better aligning prioritization with the mechanisms by which risks propagate through project structures.
The following section formalizes this network-conditional QRP and details the simulation design used for comparison.
3 ‘Quantitative risk prioritization’ approach-QRP
The proposed approach for obtaining a prioritized list of identified project risks is based on Monte Carlo simulation. This approach offers quantitative prioritization based on the potential impact of each identified risk on the project’s overall duration and cost objectives.
The simplified flowchart in Fig. 1 provides an overview of the QRP, structured into four main phases. The first phase, ‘Identification’, focuses on recognizing the risks that may influence the project. This phase aligns with the initial processes outlined in several well-established risk management standards and methodologies (Axelos, 2023; European Commission, 2023; International Organization for Standardization, 2012; Project Management Institute, 2017; Simon et al., 1997). The second phase, ‘Estimation’, forecasts the probability and impact of each identified risk. According to the referenced standards and methodologies, this activity is integrated into the broader risk assessment process and can be particularly associated with qualitative risk analysis.
Quantitative Risk Assessment flow chart
Subsequently, a Monte Carlo simulation is employed, a widely recognized tool in quantitative risk analyses. In the final stage, risks are quantified, and a prioritized list of the identified risks is generated. The following sections provide a detailed explanation of the steps involved in this innovative approach.
3.1 Identification phase
The ‘Identification’ phase is a crucial component of any risk management process, as the quality of the results obtained in this stage significantly influences the overall success of the outcomes. The effectiveness of all the subsequent phases is directly tied to the accuracy and thoroughness achieved in this initial phase. To ensure thorough risk identification, information can be gathered through workshops and interviews with subject-matter experts (AACE, 2011; Van et al., 2019). Additionally, risks can be identified, and the information in the risk register can be enriched by referencing similar projects, drawing on lessons learned from other projects within the organization, consulting expert judgments, and utilizing any information provided by suppliers and subcontractors, among other sources (Cagliano et al., 2015; Hillson, 2014).
To formally define the identified risks, let \(R=\{1, 2,\dots ,m\}\), where Ri corresponds to each identified risk (Eq. 1), and m is an integer.
This first phase concludes by incorporating each identified risk into a risk register, enabling us to proceed to the next steps.
3.2 Estimation phase
The second phase of our procedure is dedicated to modelling the previously identified risks. This involves estimating the probability of occurrence for each risk and its potential impact if it materializes. Once these estimates are established, a distribution function is assigned to capture the critical characteristics of probability and impact.
In a qualitative risk analysis, the probability and impact matrix is applied in a standardized manner, serving as a valuable tool for evaluating and prioritizing risks based on their significance or overall value (European Commission, 2023; International Organization for Standardization, 2018, 2019; Project Management Institute, 2017). The matrix relies on input values, specifically the probability of occurrence and the potential impact each risk may have on the project’s objectives.
Typically, the risk matrix axes, corresponding to probability and impact, are divided into five levels, each with a semantic value: VL (Very Low), L (Low), M (Medium), H (High), and VH (Very High). Each identified risk is assigned a semantic value for probability and impact to calculate its risk level, based on the corresponding cell in the risk matrix, using the estimated input values. Each cell in the matrix is associated with a pre-established risk value, which is then used to compare the relative importance of the evaluated risks.
Our proposed model is designed to be versatile and is not limited solely to epistemic risks, unlike traditional risk matrices. Our methodology enables the modelling of each identified risk according to its specific nature, distinguishing among three possible risk types: stochastic, aleatoric, and epistemic. We deliberately omit the ontological risk because, by definition, it represents a risk type that cannot be identified (Alleman et al., 2018; Curto et al., 2022; Hillson, 2014).
Stochastic, or event risks, are events with well-defined consequences (Hillson, 2020). For these risks, both the probability of occurrence and the impact conditional on occurrence can be specified ex ante. Following standard practice, occurrence is modelled with a Bernoulli distribution (1 = occurs; 0 = does not) (Curto et al., 2022; Kwon & Kang, 2019; Vose, 2008), a representation widely used in risk analyses (Allahi et al., 2017). Independent of the occurrence model, the impact magnitude (on duration and/or cost) is represented by a severity distribution selected by the project’s Experts Committee; depending on context, this may be triangular, uniform, or a deterministic value when the effect on an activity is constant. This specification is consistent with standard Monte Carlo practice and integrates naturally with the project network and the QRP procedure.
Risk may also exhibit aleatoric uncertainty, particularly concerning its probability of occurrence and impact, which can fluctuate within a specific range due to inherent variability. This aleatoric uncertainty type can be effectively modelled using a probability distribution function (PDF), as with an activity’s uncertainty (Acebes et al., 2014, 2015). As the risk management or project management team gains a better understanding of the project and collects more information about the risk, the choice of the PDF (e.g., normal, triangular, beta) and its parameters becomes more accurate and better aligned with reality.
Finally, epistemic uncertainty arises from a lack of knowledge and represents uncertainty for which we do not have complete information(Alleman et al., 2018; Damnjanovic & Reinschmidt, 2020). Unlike a qualitative risk analysis, which uses a risk matrix to assign semantic values to probability and impact, our approach models this uncertainty using a PDF. In this case, we assume that the probability of risk occurrence falls within an equiprobable range of values, and we use a ‘uniform’ distribution to characterize uncertainty when knowledge is limited or unavailable (Curto et al., 2022; Eldosouky et al., 2014; Helton et al., 2006; Vanhoucke, 2018; Vose, 2008).
As the outcome of this phase, we establish the model and the parameters that define the probability (P) and impact (I) distribution functions for each risk identified in the preceding phase (Eq. 2). The probability of occurrence of each risk is formally defined as \(P=\{{P}_{m}|m\in Z\}\), where Pi represents the probability of occurrence of risk Ri. Similarly, \(I=\{{I}_{m}|m\in Z\}\), where Ii denotes the impact of risk Ri, should it occur.
This second phase concludes by integrating the probability and impact data for each risk identified in the risk register (Table 1).
The probability of occurrence of each identified risk is estimated and modelled using a PDF and the associated parameters. For instance, in a triangular distribution, the parameters include the maximum, most likely, and minimum values; in a normal distribution, the parameters include the expected value and standard deviation. If a risk materializes, it may impact only the duration of a specific activity, only the cost associated with that activity, or both the planned duration and cost. In each scenario, the distribution function for the impact of risk (on duration, cost, or both) is estimated, along with its characteristic parameters.
Up to this point, we have followed the standard approach in the literature by identifying risks and estimating the probability and potential impact of each occurrence. However, rather than using these results for traditional risk prioritization through a risk matrix, we will prioritize the risks based on a quantitative analysis of each risk’s impact. This marks the beginning of our innovative approach and the core contribution of this article.
3.3 Simulation scenarios and quantiles (Monte Carlo)
We quantify each identified risk’s marginal impact by comparing two simulation scenarios: a baseline with all risks active and, for each risk r, a counterfactual in which that risk is disabled. Repeating this operation for all risks yields risk-specific marginal effects that we will use for prioritization. This construction naturally captures interactions mediated by the project network, because the baseline always runs with all risks present, and each counterfactual removes exactly one risk while keeping the remaining risks unchanged. We implement the simulations with MCSimulRisk, a Matlab-based teaching/research tool developed at INSISOC (University of Valladolid) for Monte Carlo risk analysis in project management (Acebes et al., 2024a, 2024b, 2024c; Acebes, Curto, González-Varona, et al., 2024). MCSimulRisk integrates the risk set with the activity network, efficiently returning duration and cost statistics and percentiles. It is used in research and teaching within the INSISOC Project Risk Management (PRM) framework.
For clarity, the following list compiles the symbols used in Sects. 3.3, 3.4 with brief definitions. This notation is used consistently in the equations and steps that follow.
3.3.1 Symbols
-
\(T, C\): total project Duration and Cost (random variables).
-
\(\alpha\): percentile level (e.g., P80, P90).
-
\({Q}_{T}^{(\cdot )}(\alpha ) , {Q}_{C}^{(\cdot )}(\alpha )\): α-quantiles of T and C under the scenario indicated by the superscript.
-
\(\theta\): model configuration (project network + all risk parameters).
-
\({\theta }^{(-r)}\): as θ but with risk r disabled (probability and impact set to zero).
-
\({\Delta T}_{r}(\alpha ), { \Delta C}_{r}(\alpha )\): marginal impacts of risk r on the α-quantiles of duration and cost.
-
\({\rho}_{QRP}(r), { \rho }_{P\times I}(r)\): Ranking position of risk r under QRP and under the P × I matrix, respectively (1 = highest priority).
-
\({\Delta}_{r} = {\rho}_{QRP}(r) - {\rho}_{P\times I}(r)\): Difference in ranking position (QRP–P × I) for risk r; negative = higher priority under QRP.
-
\(SP\): Structural indicator of network parallelism/serialization (lower = more parallel; higher → 1 = more serial). SP \(\in \left[\text{0,1}\right]\)
-
\(N\): Number of Monte Carlo replications.
With the notation in place, we now describe the simulation workflow. The method compares a baseline scenario (where all risks are active) with a counterfactual in which one risk is disabled, repeating this comparison for each identified risk. Steps 1 and 2 below outline the process.
-
Step 1 Baseline (all risks active). Simulate the model \(\uptheta\) with \(\text{N}\) replications and estimate (Eq. 3):
$${Q}_{T}^{(all)}(\alpha ) , {Q}_{C}^{(all)}(\alpha )$$(3)
These are the α-quantiles of total duration and cost when all identified risks are present in the model.
-
Step 2 Counterfactual per risk. For each risk r ∈ {1,…,m}, define \({\theta }^{(-r)}\) by setting its probability and impact to zero, rerun the Monte Carlo simulation, and estimate (Eq. 4):
$${Q}_{T}^{(-r)}(\alpha ) , {Q}_{C}^{(-r)}(\alpha )$$(4)
This captures what would happen to the α-quantiles if risk r did not occur, holding everything else constant.
3.4 Marginal impacts, prioritization, and reporting
To align the analysis with the decision maker’s risk appetite, we summarize simulation outcomes at a chosen percentile α of the total Duration and Cost distributions (e.g., P80, P90, P95). Using percentiles is standard in risk measurement because, like Value at Risk (VaR) in finance, it focuses on the upper tail of outcomes relevant for conservative planning. (Caron, 2013; Caron et al., 2007). The choice of α is policy-driven rather than prescriptive: higher α (e.g., P95) reflects greater aversion to adverse outcomes, while lower α (e.g., P80) reflects a more neutral stance. In practice, α is selected by the project manager or sponsor to match decision thresholds and contract or governance requirements (Chen & Peng, 2018; Gatti et al., 2007; Giot & Laurent, 2003; Joukar & Nahmens, 2016; Kuester et al., 2006).
With α fixed, we compare two scenarios for each risk r: the baseline with all risks active and the counterfactual where risk r is disabled. Let \({Q}_{T}^{(\cdot )}(\alpha )\) and \({Q}_{C}^{(\cdot )}(\alpha )\) denote the α-quantiles of total Duration T and total Cost C under the scenario indicated by the superscript. We define the marginal effects (Eq. 5):
which measures the extent to which risk r contributes to the α-level of the project’s duration and cost, respectively. We then produce two independent rankings: duration-based, ordering risks by \({\Delta T}_{r}(\alpha )\) (descending), and cost-based, ordering by \({\Delta C}_{r}(\alpha )\) (descending). Ties are handled with the same competition rule as in the P × I analysis (equal values receive the same integer rank; subsequent ranks skip accordingly).
As good practice, we will report the selected α, the number of replications N, and present duration- and cost-based results separately (rank heatmaps and QRP–P × I rank-difference tables/plots), ensuring transparency and reproducibility.
4 Computational experiments
This section outlines the computational experiments conducted in this study. Two experiments are performed following the methodological approach advocated by Vanhoucke (2023).
In the first computational experiment, conducted on artificial projects, Sect. 4.1.1 presents a single-instance structural sweep across eleven SP levels in [0,1] (one instance per level), and Sect. 4.1.2 reports a multi-instance analysis of three representative structures (SP = 0.2, 0.5, 0.8) with five independent instances each (15 simulations in total). This experimental design allows us to assess the behavior of the proposed prioritization method under controlled network structures and to examine how network typology affects the alignment between P × I and QRP rankings.
The second experiment, presented in Sect. 4.2, involves simulations based on empirical data from two real projects with distinct network structures. As discussed by Vanhoucke (2023), empirical project data often exhibit idiosyncratic and heterogeneous characteristics that limit their suitability for statistical generalization. Accordingly, the role of real projects in this study is not statistical generalization but external plausibility: artificial networks ensure internal validity and experimental control, while a limited number of empirical cases serves to verify that the controlled patterns do not contradict observed project behavior.
The results from this simulation are used to validate our research. The findings from both computational experiments are discussed in the subsequent sections. The inferential weight of our study rests on the artificial-project experiments (Sect. 4.1), which ensure internal validity and control. The empirical examples (Sect. 4.2 and the Appendix) are included as external plausibility checks, offering concise triangulation with practice.
4.1 Artificial projects
In this subsection, we analyze artificial projects under controlled conditions to compare P × I with QRP across network structures. The subsection has two parts. First (Sect. 4.1.1), we define the activity network and the risk set (probabilities and impacts), and run a single-instance structural sweep over eleven distinct SP levels in [0, 1] (one project per level) to map how both approaches behave along the structural spectrum. Second (Sect. 4.1.2), we perform a multi-instance analysis at three representative structures (s/p = 0.2, 0.5, 0.8), generating five independent instances per structure (15 simulations in total) to assess between-instance variability and the stability of the P × I–QRP comparison. Throughout, we apply the same competition tie rule to both methods and report results using a rank heatmap (15 simulations) and an increment-by-SP summary (Δr = ρQRP − ρP × I), which tracks how QRP–P × I priority differences evolve from more parallel to more serial networks. Ties are handled according to the competition ranking rule (1, 2, 2, 4,…): equal values share the same rank, and the next rank is skipped.
4.1.1 Single-instance sweep across network structures (SP ∈ [0,1])
In the first computational experiment, we utilize the RANGEN project network generator (Demeulemeester et al., 2003; Vanhoucke et al., 2008) to generate a set of project networks with diverse topological structures. These networks range from configurations closely resembling a fully serial setup to those approaching a parallel topology. To quantify the network structure, we use the series–parallel (SP) indicator, where lower SP values indicate parallel-type projects, while higher SP values (approaching 1) indicate a predominantly serial topology (Colin & Vanhoucke, 2015; Martens & Vanhoucke, 2017).
We select 11 projects with SP ∈ {0.05, 0.10, 0.20, …, 0.80, 0.90, 0.95} (N = 30 activities per project). This selection encompasses projects with nearly entirely parallel topologies (SP = 0.05) to those with an almost serial configuration (SP = 0.95).
Parameter estimation: In the simulation exercise, each of the 11 projects is assigned consistent duration and cost values, including fixed and variable costs for its respective activities. The only differentiating factor among these projects is the network structure, represented by the SP value, which dictates the sequence of activities within each project network. All computational experiments assume unlimited resources (no resource arcs or capacity calendars). This isolates the network-structure effect (captured by SP) on risk prioritization without confounding it with resource-induced sequencing.
The duration of activities is modelled using a triangular distribution function with assigned values for the minimum (m), most likely (\(\widehat{{d}_{i}}\)), and maximum (M) durations. Although other distribution functions, such as lognormal (Ballesteros-Pérez et al., 2019; Curto et al., 2022; Vaseghi et al., 2024), normal (Acebes et al., 2014, 2015), or beta (Hoseini et al., 2020), can be considered, we select the triangular distribution for its widespread recognition in the literature (AACE—American Association of Cost Engineering, 2011; Eldosouky et al., 2014; Mohamed et al., 2020; Ünsal-Altuncan & Vanhoucke, 2024). This choice is standard and elicitation-friendly for artificial/benchmark projects, capturing plausible skewness with minimal parameters when no real calibration data are available. Alternative families such as beta or lognormal are also reasonable in domain-specific settings (e.g., detailed construction datasets). However, exploring distributional alternatives is beyond the scope of this paper: our goal is to isolate the methodological comparison between P × I and QRP and the structural effect of SP. Holding the family fixed avoids conflating distributional sensitivity with the core comparison.
For each project activity, the most probable value (\(\widehat{{d}_{i}}\)) is randomly assigned. To calculate the maximum and minimum values, we apply a ‘low variability’ approach (Ünsal-Altuncan & Vanhoucke, 2024), where the maximum value is set at \(M=1.4\cdot \widehat{{d}_{i}}\), and the minimum value at \(m=0.8\cdot \widehat{{d}_{i}}\). We adopt a “low-variability” calibration with \(m=0.8\cdot \widehat{{d}_{i}}\) and \(M=1.4\cdot \widehat{{d}_{i}}\), to avoid excessive spread while allowing skew.
Regarding the cost of activities (\({c}_{i}^{t}\)), we account for both fixed costs (\({c}_{i}^{f}\)), which are independent of activity duration and variable costs (\({c}_{i}^{v}\)) that represent the cost per unit of time for activity i. The total cost is, thus, computed as follows (Eq. 6):
where \({d}_{i}\) is the actual duration of activity i during simulation (Ünsal-Altuncan & Vanhoucke, 2024).
The variable cost per time unit for each activity (\({c}_{i}^{v}\)) is assigned as a constant value, selected randomly from a range of [0, 500] per activity. In contrast, the fixed cost (\({c}_{i}^{f}\)) is determined using a uniform distribution function with narrow variability that ranges from €10 to €90 (Ünsal-Altuncan & Vanhoucke, 2024).
Table 2 presents the detailed definition of project activities, including the parameters for each activity’s duration and costs (fixed and variable).
Risk definition: Following the establishment of 11 distinct simulation projects—each consisting of 30 activities with uniform durations and costs, differing only in their network structure—we identify project risks. These risks consistently affect the same activities across all projects, despite variations in SP structures. We estimate the probability values, duration, and cost impacts of each identified risk. This information is then compiled into the risk register, as detailed in Table 3.
A total of twelve distinct risks have been identified. Of these, seven risks impact the respective activities’ duration and cost objectives, while three affect only the duration objective, and two influence only the cost objective. Additionally, two specific risks, Re and Rf, are identified as potentially impacting the same activity (Activity 21). In the artificial project experiments, we assume statistical independence between risks (beyond the coupling already induced by precedence), to isolate the methodological contrast (P × I vs. QRP) and the structural effect of SP.
The estimation of probability and impact values is based on a comprehensive, systematic project analysis rather than arbitrary judgments. Table 4 illustrates the classification of various semantic levels of assessment for likelihood and impact (Very Low, Low, Medium, High, and Very High), along with the corresponding percentage ranges assigned to each level, as recommended by Curto et al. (2022) and Project Management Institute (2017).
Each of the 11 projects chosen for simulation contains an identical number of activities, with consistent activity characteristics across all projects. The only differentiating factor among these projects lies in the sequencing of activities, which results in varied SP indicators. Consequently, total project duration differs, with longer durations anticipated for projects with higher SP indicator values (serial projects) and shorter durations for those with lower SP values (parallel projects). However, the structure of the project network does not affect the total project cost, as it is simply the sum of all activities’ costs, regardless of the project’s structure.
The objective is for all simulated projects to encounter the same set of risks, each with identical probability and impact assessments, and for these risks to consistently affect the same project activities. We utilize uniform distribution functions to model these risks in the Monte Carlo simulation, which is particularly well-suited for representing epistemic uncertainty (Eldosouky et al., 2014; Vose, 2008). The minimum and maximum values for these uniform distribution functions, corresponding to each impact value in duration and cost, are determined by applying the percentage ranges specified in Table 4 to the planned project duration and cost values.
Risk prioritization: After selecting the projects for simulation and identifying and modelling the associated risks, we prioritize them to determine their significance and the level of attention required from the project manager. As an initial step, we conduct a qualitative risk assessment using a probability and impact matrix, following established literature and standard project management methodologies (see Sect. 2: Risk Assessment Matrix). To facilitate this assessment, a risk matrix (Fig. 2) is used to evaluate risks based on probability (Very Low, Low, Medium, etc.) and impact (Very Low, Low, Medium, etc.). The intersection of these values within the matrix identifies a specific cell, whose value is then used to rank risks and determine their relative priority.
Probability – impact matrix
Following the initial assessment, we prioritize quantitative risk using the proposed Quantitative Risk Prioritization (QRP) approach. This method considers the probability of each risk, its impact assessment, and the project network’s structure. By applying QRP, we produce two distinct prioritization lists: one indicating the impact of each risk on the project’s total duration, and the other on its total cost. To obtain these results, we employ a Monte Carlo simulation, facilitated by the educational software tool ‘MCSimulRisk’ (Acebes et al., 2023, 2024a, 2024b, 2024c).
Given the stochastic nature of Monte Carlo simulation results, selecting a percentile that aligns with our risk appetite when interpreting the outcomes is essential. This percentile reflects the level of risk the organization is prepared to accept. We adopt the P90 percentile for this analysis to reflect our risk-averse stance. This choice is common in risk-averse assessments and mirrors percentile-based practices in VaR-style analyses.
Figure 3 displays the prioritized list of risks based on their impact on the total duration objective derived from the risk matrix and QRP methods. Each cell in the figure indicates the risk priority ranking according to the respective method. For the QRP method, these risks are further categorized by the SP indicator of the simulated network. Columns are color-coded on a gradient scale, where red represents the highest-priority risk (value 1), and green indicates the lowest-priority risk. Intermediate colors correspond to risks with values between these extremes, facilitating a clear visual representation of relative risk priorities. The number within each cell denotes the priority ranking of each identified risk. When two risks share the same number in a cell, they have identical priority because they have been evaluated equivalently.
Risk priorities for total duration: P × I vs QRP across SP (0.05–0.95). (1 = highest priority)
Compared to a qualitative P–I matrix, which naturally induces ties when risks share the same categorical levels, QRP offers higher resolution by quantifying the marginal impact of each risk. We emphasize that this resolution is model-conditional. Accordingly, we accompany the rankings with an increment plot by the structural indicator s/p, showing how QRP–P × I priority differences evolve across s/p (Fig. 4).
QRP–P × I rank differences in duration across SP. Δr < 0 means higher priority under QRP. α = P90
To connect the heatmap with a numerical summary, Fig. 4 presents the rank differences between QRP and P × I for each risk across the entire set of SP levels (0.05, 0.1, …, 0.95). For risk r at a given SP value, we compute Δr = ρQRP(r) − ρP×I(r) (with 1 = highest priority). Thus, Δr < 0 indicates higher priority under QRP (smaller rank) relative to P × I, and Δr > 0 indicates lower priority under QRP. These values will be used in the subsequent line plot to visualize how the differences evolve as the network structure changes.
Figure 5 illustrates variations in risk-priority rankings by comparing the probability-impact matrix (risk matrix) results with those derived from each simulated project, distinguished by different SP indicator values. Each colored line in the graph represents a specific identified risk (Ra, Rb, …). The horizontal axis displays the different SP indicator values (0.05, 0.1, 0.5, …), while the vertical axis shows the difference in ranking positions for each risk between the two methods.
Plot of duration rank differences (QRP− P × I) across SP 0.05–0.95. Lines below 0= higher priority under QRP; α = P90
For instance, risk Ra, represented by the red line, is ranked fourth according to the risk matrix method. In the simulated project with an SP indicator of 0.05 (the first position on the horizontal axis), risk Ra is ranked first due to its significant impact on the project’s total duration. This results in a ranking difference of −3 positions for an SP value of 0.05. Conversely, for an SP indicator of 0.5, the ranking difference between the methods is + 5 positions.
The ‘MCSimulRisk’ application additionally provides insights into the impact on the project’s total cost objective. Figure 6 displays the hierarchical ranking of risks based on the different methods employed in this study. The first column reflects the risk prioritization determined by the probability-impact matrix method. In contrast, the subsequent columns present prioritized risk lists derived from applying the QRP method, with rankings tailored to each simulated project's SP indicator.
Risk priorities for total cost: P × I vs QRP across SP (1 = highest priority)
Similarly, differences in the significance of each risk can be organized and visually represented by comparing the results obtained from the risk matrix methodology with those from the QRP method for each simulated SP indicator. Figure 7 illustrates these differences by highlighting the impact of each risk on the project’s total cost.
Plot of cost rank differences (QRP − P × I) across SP 0.05–0.95. Lines below 0= higher priority under QRP; α = P90
Up to this point, we have analyzed artificial projects in two ways: (i) a single-instance sweep across network structures with s/p values from 0.05 to 0.95, and (ii) a multi-instance analysis at three representative structures (SP = 0.2, 0.5, 0.8). To complement these aggregate results with a concrete case, we now present one illustrative example showing a project configuration generated with RANGEN and the corresponding QRP outputs from MCSimulRisk (marginal impacts and rankings for duration and cost).
Then, we present an illustrative instance from the first simulation set (SP ∈ {0.05, …, 0.95}) with SP = 0.3, generated using RANGEN. Table 5 reports the precedence list: for each activity, the number of successors and the set of successor activities are shown. Activities 1 and 32 are dummy start/finish nodes; thus, the project comprises 30 real activities (2–31). This representation makes the network structure used in the simulations explicit.
Figure 8 shows the corresponding MCSimulRisk output for the same instance. For each risk r, the table reports (i) its marginal impact on total duration (Duration_Diff≡ΔTr(α)) and the associated ranking (Ranking_Dur, with 1 = highest priority), and (ii) its marginal impact on total cost (Cost_Diff≡ΔCr(α)) and the corresponding ranking (Ranking_Cost). Impacts are computed at the selected percentile α (see Sect. 3.4), and ties follow the same competition rule used for P × I. This example illustrates the method's workflow and the two independent prioritizations (duration and cost) used in the comparative analysis.
MCSimulRisk output for the SP = 0.3 instance: Duration_Diff (ΔTr(α)) and Cost_Diff (ΔCr(α)) per risk, with Ranking_Dur and Ranking_Cost (1 = highest priority). Values computed at percentile α = 90
4.1.2 Multi-instance analysis at representative SP levels (0.2, 0.5, 0.8)
This subsection tests the stability of the P × I–QRP comparison at a fixed structure. For each representative level s/p ∈ {0.2, 0.5, 0.8}, we generate five independent instances and examine whether the priority differences Δr = ρQRP(r) − ρP×I(r) exhibit consistent patterns across instances. This complements 4.1.1 (the single-instance structural sweep) by checking that, for a given SP, the behavior observed there is replicable and coherent across multiple realizations of the same network structure.
As in Sect. 4.1.1, we assume unlimited resource capacities and statistical independence between risks (except for precedence-induced coupling) to isolate network-structure effects. In addition, we utilize the RANGEN project-network generator (Demeulemeester et al., 2003; Vanhoucke et al., 2008) to create five independent instances for each of the three representative structures defined by the SP indicator: SP = 0.2 (parallel), SP = 0.5 (intermediate), and SP = 0.8 (serial). Instances are produced with identical calibration and distinct random seeds, so observed differences reflect within-structure (between-instance) variability rather than changes in model setup. While not exhaustive, these three levels span the structural spectrum in a manner that is standard in the literature; hence, the patterns we document at 0.2, 0.5, and 0.8 are indicative of (and broadly consistent with) behavior across the wider SP ∈ [0, 1] range.
In all artificial-project simulations, the activity-level parameterization and risk mapping are held constant across projects: base durations (and their distributional parameters), fixed and variable costs, and the set of identified risks (including their probability/impact parameters and the specific activities they affect) are defined exactly as in Sect. 4.1.1. The only element that varies across projects is the precedence structure generated by RANGEN. Consequently, even among instances with the same SP level, precedence relations differ while preserving the targeted structural indicator. This design controls for parameters and risk mapping so that any systematic change in the P × I–QRP comparison can be attributed to network structure (as captured by SP), rather than to changes in activity/risk parameterization.
After defining the activities and the risk set, we summarize the prioritization outcomes in the rank heatmap shown in Fig. 9. Each row corresponds to a risk (Ra-Rl). The leftmost column (“P × I – Rank_Dur”) reports the qualitative ranks obtained with the probability–impact matrix described in Sect. 4.1.1, using the risk matrix shown in Fig. 2. The remaining columns are grouped by network structure and display the QRP ranks for the five independent instances at each level: SP = 0.2, 0.5, and 0.8 (labelled a–e). Ranks are integers (1 = highest priority), and ties follow the same competition rule for both methods. Color shading encodes rank (warmer = higher priority, cooler = lower). A detailed reading of these results is provided in Sect. 5.
Risk priorities for total duration: P × I vs QRP across SP = 0.2, 0.5, 0.8 (a–e; 1 = highest priority)
We summarize the comparison between methods in Fig. 10, which reports the difference in ranking for each risk between QRP and P × I. For risk r and each instance (a–e) at a given structural level, we compute Δr = ρQRP(r) − ρP×I(r). The rows list the risks, and the columns are grouped by SP level (0.2, 0.5, 0.8), with five instances per level. Negative values indicate that QRP assigns a higher priority (a smaller rank number) than P × I, whereas positive values indicate a lower priority under QRP.
QRP–P × I rank differences in duration by risk and instance (a–e) at SP = 0.2, 0.5, 0.8. Negative = higher priority under QRP
Building on the previous figure, Fig. 11 provides a graphical view of the rank differences Δr = ρQRP(r) − ρP×I(r). Plotting Δr for each instance (a–e) and SP level (SP = 0.2,0.5,0.8) facilitates a visual assessment of how both prioritization methods behave across network structures. Values below zero indicate higher priority under QRP (smaller rank), whereas values above zero indicate lower priority under QRP relative to P × I. TBuilding on the previous
ognition across risks and structures.
Plot of duration rank differences (QRP − P × I) by risk and instance (a–e) at SP = 0.2, 0.5, 0.8. Lines below 0= higher priority under QRP
Having presented the results for project duration, we now report the cost-oriented prioritization. As in the duration analysis, risks are prioritized independently for the cost objective. For QRP, we calculate the marginal impact of each risk on cost at a given percentile (α) and rank the risks accordingly. For P × I, we use the same probability and cost-impact scales defined in Sect. 4.1.1 (see Fig. 2) and apply the same competition tie-breaking rule: risks with identical P × I scores are assigned the same rank. All activity-level parameters and the risk-to-activity mapping remain identical to those used for duration; only the precedence structure varies across instances and SP levels, as described in Sect. 4.1.
We present the cost results using the same trio of displays:
-
a rank heatmap juxtaposing P × I (left) with QRP ranks for the five instances at each SP ∈ {0.2,0.5,0.8} (Fig. 12);
-
a numeric table of rank differences Δr = ρQRP(r) − ρP×I(r) for cost (Fig. 13); and
-
an instance-by-SP line plot of these differences (a–e) that facilitates visual pattern recognition across structures (Fig. 14).
Risk priorities in total cost: P × I vs QRP across SP = 0.2, 0.5, 0.8 (a–e; 1 = highest priority)
QRP–P × I rank differences in cost by risk and instance (a–e) at SP = 0.2, 0.5, 0.8. Negative = higher priority under QRP
Plot of cost rank differences (QRP− P × I) by risk and instance (a–e) at SP = 0.2, 0.5, 0.8. Lines below 0= higher priority under QRP
As before, negative values indicate higher priority under QRP (smaller rank), while positive values indicate lower priority under QRP relative to P × I.
4.2 Empirical projects
We implement the proposed QRP approach using actual project data in a second simulation exercise to validate our research. The project selected for this analysis is sourced from the Empirical Project Data Database, ‘DSLIB’ (Dynamic Scheduling LIBrary) (Batselier & Vanhoucke, 2015; Vanhoucke, 2023; Vanhoucke et al., 2016), which provides extensive scheduling data, risk analysis inputs for Monte Carlo simulations, and project control metrics, including Earned Value Management (EVM) and Earned Schedule (ES). In this study, we concentrate on two specific projects: the ‘C2019–21_Tanglewood’ project, which features a predominantly parallel network structure, and the ‘C2019–19_Transitional House’ project, whose network structure closely aligns with a serial configuration.
The role of this section is illustrative rather than inferential. In line with Vanhoucke (2023), we use these real cases as ecological plausibility checks to verify that the controlled patterns observed in the artificial-project analysis do not contradict behavior in less structured environments.
4.2.1 ‘C2019–21_Tanglewood’ project
Initially, we used the project ‘C2019–21_Tanglewood’ to conduct a comparative analysis of risk-prioritization methodologies, explicitly contrasting the risk matrix approach with the QRP methodology.
Parameter estimation: The chosen project involves the installation and commissioning of a photovoltaic solar park, comprising 31 activities. The duration of each activity is modelled using a triangular distribution function, with a minimum value of \(m=0.8\cdot \widehat{{d}_{i}}\) and a maximum value of \(M=1.2\cdot \widehat{{d}_{i}}\) (refer to the project details in ‘C2019–21_Tanglewood.xlsx’ at https://www.projectmanagement.ugent.be/research/data). The variable cost (\({c}_{i}^{v}\)) represents the cost of the required resources, while the fixed cost for each activity is set at zero (\({c}_{i}^{f}=0\)) (Eq. 7).
Table 6 presents the project activities, along with their respective parameters for duration, cost, and precedence.
Project ‘C2019–21_Tanglewood’ is scheduled to be completed in 671 days, with a total planned cost of €13,812,918.75. The project’s SP indicator is 0.47, indicating an intermediate structure that balances serial and parallel configurations. Figure 15 displays the Gantt chart for the actual project, showing each activity’s planned duration and sequencing.
Gantt chart of the actual ‘C2019–21_Tanglewood’ project
Risk definition The research team convened and, through brainstorming sessions, reached consensus on the risks that could affect the project. Table 7 presents the identified risks, including their identification codes (Risk ID), the specific project activities affected, and qualitative estimates of the probability of occurrence and the impact of each risk on duration and cost.
The project team identified 12 risks: seven with potential impacts on the duration and cost objectives of the corresponding activities, three affecting only the duration objective, and two explicitly impacting the project’s cost.
The semantic assessment of each risk’s probability and impact parameters is based on the data provided in Table 8. By referencing the project’s planned duration and total cost, the research team establishes defined ranges for both probability and impact (in terms of duration and cost). These ranges enable the conversion of the numerical values in Table 7 into corresponding semantic categories (VL, L, M, H, VH).
Risk prioritization A comprehensive list of prioritized risks was generated by applying the proposed QRP approach. In parallel, another list of risks was developed using the conventional probability-impact matrix method, allowing for a comparative analysis of the results from both methods. The probability-impact matrix shown in Fig. 2 was used to prioritize risks under the risk matrix method. Semantic values were assigned to the probability and impact estimates for each identified risk using the matrix in Table 7; these semantic values serve as inputs for the risk matrix, yielding the resulting risk values.
For the QRP analysis, the identified risks (Table 7) were integrated into the project model and simulated using MCSimulRisk at a 90% confidence level (P90) to reflect a conservative risk appetite. The software reports, for each risk r, the marginal impact on total duration (Duration_Diff, ΔT(α)) and on total cost (Cost_Diff, ΔCr(α)), together with the associated rankings (Ranking_Dur, Ranking_Cost; 1 = highest priority). The numeric output (Fig. 16) shows that a small set of risks (e.g., Rh, Rd, Rf) dominate the duration ranking. At the same time, cost is driven by a different profile (with Ra at the top and several duration-neutral risks remaining low in cost). Conversely, risks like Rb exhibit negligible cost impact despite non-zero duration effects, illustrating how QRP separates the time and cost channels.
QRP results from MCSimulRisk (‘C2019–21_Tanglewood’ project, P90): per-risk impacts on total duration and cost with the resulting rankings (1 = highest priority)
Building on the numeric QRP output in Fig. 16, which reports per-risk impacts and rankings (e.g., Rh and Rd dominate duration, whereas Ra leads cost, while Rk/Rl show negligible time effects), Fig. 17 contrasts these rankings with the P × I results for the same risks and objectives.
Duration and cost rankings: P × I vs. QRP (‘C2019–21_Tanglewood’ project). Right column shows Δr = ρQRP − ρP×I (1 = highest priority; Δr < 0⇒ higher priority under QRP; α = P90)
The figure above illustrates risk prioritization based on its impact on the project’s duration and cost objectives. Initially, risks are ranked using the traditional risk matrix for each purpose. Subsequently, the prioritization outcomes derived from the proposed QRP approach are presented. Furthermore, a column illustrates the discrepancy in ranking positions between the two methods for each identified risk. P × I yields one fixed order based solely on probability–impact categories; QRP, in contrast, conditions on network placement and propagation to time and cost. The contrasts are informative: risks such as Ra or Rc appear less critical for duration under QRP because they act on parallel branches with slack, whereas Rk/Rl remain low in duration simply because their modelled effect is purely cost. Thus, even in this single real project, QRP provides a network-aware prioritization that can legitimately diverge from P × I when path structure and the nature of each risk’s channel (time vs. cost) modulate marginal impacts.
4.2.2 C2019–19_Transitional House’ project
The next project selected for analysis is titled ‘C2019–19_Transitional House’ and is also sourced from the Empirical Project Data Database, ‘DSLIB’ (Dynamic Scheduling LIBrary) (Batselier & Vanhoucke, 2015; Vanhoucke, 2023; Vanhoucke et al., 2016). This project involves the construction of a traditional house and comprises 25 activities. Unlike the previously discussed example, this project’s network structure is predominantly serial, as inferred from its Gantt chart (Fig. 18). Additionally, the project’s series/parallel indicator, SP = 0.75, approaches 1, indicating a nearly fully serial structure.
Gantt chart of the actual ‘C2019–19 Transitional house’ project
The appendix to this article provides a detailed definition of the project activities, including their duration, cost, and precedence relationships. Activity durations are modelled using a triangular distribution function based on the values specified in the project definition. The cost structure for each activity consists of a fixed cost component independent of the activity’s duration and a variable cost component directly influenced by the activity’s duration, as shown in Table 8. Based on all planning data for the ‘C2019–19_Transitional House’ project, the planned duration is 130 days, with an estimated total cost of €240,840.00.
Through a series of brainstorming sessions, the research team identified 14 distinct risks, each with a detailed description in the Appendix. Of these risks, nine have a combined impact on both the duration and cost objectives, three affect only the duration objective, and two affect the cost objective. During the risk identification process, the team assigned a probability of occurrence and an estimated impact on the duration and cost objectives to each risk (see Table 10).
To conduct the risk assessment using the probability-impact matrix, the risk matrix depicted in Fig. 2 is utilized. The research team developed specific scales for this project to assign a semantic value (VL, L, M, H, VH) to both probability and impact for each identified risk, as outlined in Table 11 (see Appendix).
For the ‘Transitional House project’ (SP = 0.75), Fig. 19 reports the QRP numerical output from MCSimulRisk at the selected percentile. The most significant duration impacts are produced by Rf and Rj (Ranking_Dur = 1 and 2, respectively), followed by Rc and Re; several risks have negligible or zero effect on time (e.g., Rm, Rn, Rk). In terms of cost, the leading contributors are Rf and Rj, with Re and Rm also prominent (Ranking_Cost = 1–4), whereas Rk, Rn, and Ri rank at the bottom of the list. This table provides the quantitative basis for the prioritization used in the following figure.
Duration and connection
Figure 20then contrasts this QRP ranking with the single P × I ranking for the same risks. As in the previous case, P × I yields a single fixed order based solely on probability–impact categories, whereas QRP conditions on where each risk acts within the network and on how effects propagate over time and across costs. The observed differences are meaningful; for example, risks that accumulate variable costs through time (e.g., Rf, Rj) rise in the cost list under QRP. In contrast, risks with minimal time effect (e.g., Rk, Rm, Rn) remain low in the duration ordering. Taken together, the real case corroborates the artificial experiments: because QRP conditions on the network and on time–cost propagation, its priorities can reasonably differ from those of P × I.
Duration and cost rankings: P × I vs. QRP (‘C2019–19 Transitional house’ project). Right column shows Δr = ρQRP − ρP×I (1 = highest priority; Δr < 0⇒ higher priority under QRP; α = P90)
5 Results and Discussion
This section reports and discusses the results of the computational study. Section 5.1 analyses how the proposed Quantitative Risk Prioritisation (QRP) method behaves relative to the traditional probability–impact (P × I) matrix as project network structure varies, using both controlled artificial networks and real projects. Section 5.2 then focuses on a methodological comparison within the QRP framework, contrasting the add-one and knock-one-out experimental designs to isolate the effect of the baseline used to compute marginal risk contributions.
5.1 Network-conditional behaviour of QRP relative to the P × I matrix
Section 5.1 analyses the outcomes of the computational study related to the comparison between QRP and the P × I matrix. We report results from two experiments with artificial projects: (i) a single-instance sweep across network structures with SP ∈ [0.05, 0.95], and (ii) a multi-instance analysis at SP ∈ {0.2, 0.5, 0.8} (five instances per level). We then use real projects as out-of-sample empirical checks. The artificial experiments evaluate the behavior and stability of the proposed Quantitative Risk Prioritization (QRP) relative to the P × I matrix under controlled precedence structures; the empirical analysis verifies that these patterns remain consistent in less structured, real-world settings. Throughout, SP denotes the serial–parallel index (higher values indicate a greater proportion of serial networks). To compare methods, we use the rank gap (Eq. 8)
with ties handled via average ranks.
Under the P × I matrix, rankings are invariant across networks and instances because prioritization depends only on each risk’s estimated probability and impact; the project network plays no role in this process. This invariance is visible in the P × I columns of the SP sweep (Figs. 3, 6) and in the leftmost columns of the multi-instance panels (Figs. 9, 12), where the same ordering appears irrespective of SP or instance (ties arise whenever multiple risks share the same categorical levels).
By contrast, QRP rankings are influenced by network structure and instance-specific precedence. As SP moves from more parallel to more serial configurations, and across the a–e instances at fixed SP, the ordering changes because marginal impacts are computed on total project duration and cost conditional on precedence relations. The resulting method-to-method gaps for duration (Figs. 5, 11) are more pronounced in parallel/intermediate structures and attenuate as the network becomes serial, consistent with the mechanism we investigate.
These findings directly address the research question of whether network structure affects agreement between P × I and QRP. For the duration objective, the evidence indicates that disagreement widens in more parallel networks (low SP) and narrows as the network becomes more serial (high SP), as shown in Figs. 3, 5. In parallel configurations (SP ≈ 0), the precedence-insensitive P × I ranking frequently diverges from QRP because QRP conditions on the location of the risk within the network.
For instance, risks that appear high priority under P × I (e.g., Rj) can lose priority under QRP when they affect activities on non-critical, slack-bearing parallel paths. Conversely, risks ranked low by P × I can move up under QRP when the affected (or propagating) activity lies on the critical path, resulting in a larger impact on the total project duration. In sum, QRP’s network-aware prioritization upgrades risks whose placement amplifies system-level effects, while downgrading those buffered by path slack, relative to P × I. Under serial network structures (SP close to 1), path slack is minimal and most perturbations propagate to total duration; accordingly, the P × I and QRP rank orders converge, with only minor deviations at high SP visible in Fig. 5, and at SP = 0.8 in Fig. 11. In the latter case, an occasional discrepancy (e.g., risk Rj) can arise because the affected activity lies on a residual parallel branch within the project network.
This pattern follows directly from the mechanism. In parallel networks, many risks are borne by slack-bearing paths, so their realization rarely changes the total duration; QRP therefore downweights them relative to risks on controlling (critical) paths, whereas P × I does not encode this structural conditioning. As the network becomes serial, almost any delay propagates to completion, the structure-induced filter disappears, and P × I’s qualitative screening converges toward QRP’s network-conditional ranking.
Turning to the cost objective, it is essential to recognize cost–schedule coupling. We decompose the risk-induced change in total cost as (Eq. 9)
where ct denotes the unit time cost and ΔT the change in project duration.
Because P × I (cost) typically captures only ΔCdirect, it tends to overvalue risks with significant immediate expenses but negligible temporal effects, and to miss risks whose costs arise mainly through time. In contrast, QRP incorporates both channels by computing marginal contributions on the network. This explains why average discrepancies are smaller for cost than for duration, while also clarifying the extreme cases in which the methods diverge sharply when time-dependent costs are material.
Figures 7 (SP sweep) and 14 (instances at SP = 0.2, 0.5, and 0.8) show that the QRP–P × I rank gaps for cost are broadly stable across SP: they exhibit slight oscillation and, on average, the magnitude of disagreement is similar across network structures. Two exceptions are noteworthy. First, risks Rk and Rl are ranked high by P × I but low by QRP. These risks contribute almost exclusively through direct cost (ΔCdirect), with negligible schedule effects (ΔT ≈ 0). Because QRP aggregates both channels per Eq. (9), other risks with nontrivial time-dependent cost (ct·ΔT) outrank them. Second, Rh shows the opposite pattern: it is low under P × I. However, it moves up under QRP because the affected activity has a large unit time cost ct, so even modest duration changes translate into sizable cost impacts. QRP captures these impacts, whereas P × I does not.
The empirical evidence is consistent with the controlled experiments. In the first real project (SP = 0.47), which is neither purely serial nor purely parallel, we observe substantial rank discrepancies between P × I and QRP for both objectives (Fig. 17). Several risks shift markedly when moving from P × I to QRP. A salient example concerns Rh under the duration objective: it moves up under QRP because the affected activity lies on (or feeds into) the critical path, so its impact propagates to total duration. In the second real project (SP = 0.75), whose structure is predominantly serial, agreement is generally tighter; however, there is an outlier with a ten-position gap under the cost objective (Fig. 21), which arises because P × I captures only direct cost, whereas QRP also accounts for time-dependent cost ct⋅ΔT induced by extensions of critical activities. These observations reinforce the structural interpretation advanced above.
In summary, for predominantly serial projects, the P × I matrix is a reasonable screening tool and broadly aligns with QRP’s network-conditional ranking. For parallel or intermediate structures, its reliability diminishes, and QRP offers a more dependable prioritization (especially when time-dependent costs are material). Dependence among risks can further modify marginal contributions (e.g., through co-occurrence along shared routes). Although the baseline analysis assumes independence for clarity, QRP readily accommodates joint sampling (e.g., via correlation matrices or copula-based generators). A systematic assessment of the interaction between SP and dependence is left for future research.
5.2 Add-one versus knock-one-out designs in quantitative risk prioritisation
Acebes et al., (2024a, 2024b, 2024c) introduced a quantitative risk prioritisation framework in which individual risk contributions were estimated using an add-one design. Under that formulation, risks are incorporated into an otherwise risk-free project one at a time, and their marginal impact is computed relative to a baseline without risks. This design yields a transparent estimate of each risk’s isolated effect and is appropriate when the aim is to quantify absolute impacts under simplified conditions.
In contrast, the present paper adopts a knock-one-out design, in which all identified risks are jointly incorporated into the project model and individual contributions are obtained by removing each risk in turn. The baseline is therefore the fully risk-exposed project, and marginal contributions are evaluated conditional on the coexistence of all other risks. The change in experimental design is deliberate and reflects a different managerial question: rather than assessing how severe a risk would be in isolation, the knock-one-out approach measures how much each risk contributes to overall project exposure when multiple sources of uncertainty are simultaneously present.
To isolate the effect of the design choice, we reapply both approaches to the same project and risk set analysed in Acebes et al., (2024a, 2024b, 2024c), keeping the project network, risk characterisation, simulation settings, and percentile level fixed. The resulting comparison is summarised in Table 9, which reports the risk ranking under each design for the duration objective and the corresponding rank shift.
We define the rank difference for each risk i as (Eq. 10):
where \({\text{Rank}}_{i}^{\text{AO}}\) denotes the position under the add-one design and \({\text{Rank}}_{i}^{\text{KOO}}\) denotes the position under the knock-one-out design (lower ranks indicate higher priority). Under this definition, negative values of \(\Delta {\text{Rank}}_{i}\) indicate that a risk moves up in priority under the knock-one-out design, whereas positive values indicate a loss of priority. Table 9, therefore, allows a direct inspection of (i) each risk’s position under the two designs and (ii) the direction and magnitude of the induced reordering.
Table 9 shows that applying the two designs to the same project and risk set leads to materially different prioritization outcomes. Several risks experience multi-position shifts, including rank reversals, despite an identical network structure and simulation settings. These discrepancies arise because marginal impacts are evaluated at different baselines. Under the add-one design, impacts are measured relative to a benign reference state (no other risks present), which can overstate the apparent importance of risks affecting slack-bearing or non-controlling paths when considered in isolation. Under the knock-one-out design, the contribution of a given risk is assessed against a project already exposed to the remaining risks; risks buffered by slack or dominated by other perturbations tend to exhibit smaller conditional contributions to total duration and may therefore be downweighted. Conversely, risks whose effects propagate through critical or near-critical activities can gain priority under knock-one-out because their removal produces a noticeable reduction in overall exposure.
Importantly, these differences should not be interpreted as numerical artefacts. In precedence-constrained networks, the mapping from local perturbations to project-level performance is non-linear, and marginal contributions are baseline-dependent. When multiple risks coexist, the contribution of one risk can depend on whether other risks have activated or constrained the same structural elements of the network (e.g., critical paths or near-critical branches). By conditioning on the complete risk profile, the knock-one-out design captures this baseline dependence explicitly, whereas the add-one design abstracts from it.
From a methodological standpoint, the two designs address complementary analytical purposes. The add-one approach is well-suited for early-stage assessments aimed at understanding isolated effects and for communication in settings where interactions are intentionally suppressed. The knock-one-out approach is more appropriate when the objective is to prioritize mitigation actions under concurrent uncertainty, where decisions naturally frame themselves in terms of marginal reductions in the exposure of a risk-laden project. Such a scenario is the setting targeted by the present study.
For conciseness, Table 9 reports the comparison for the duration objective only. Unlike the earlier formulation in Acebes et al., (2024a, 2024b, 2024c), the present study adopts a unified risk representation in which a single risk event may simultaneously affect activity durations and project costs, and both effects are assessed coherently within the proposed QRP framework. As a result, the add-one versus knock-one-out contrast is most transparently illustrated through duration-based prioritization. At the same time, cost effects are analysed within the integrated framework introduced in Sect. 5.1.
6 Conclusion
Our findings indicate that QRP provides a consistent and transparent prioritization of project risks under the modelled assumptions (project network, probability/impact distributions, dependence settings, and risk appetite α). Because the method relies on an explicit definition of marginal risk contributions and their propagation through the project network, it remains applicable in automated decision-support settings while preserving transparency and interpretability for project managers. We do not claim absolute precision, since a project’s “true” risk ordering is inherently unobservable. Instead, we demonstrate robust comparative behaviour and meaningful agreement with baseline approaches across controlled scenarios, while explicitly stating the modelling assumptions underlying the rankings.
This approach offers advantages over traditional qualitative methods, such as the probability-impact (risk) matrix. The proposed methodology enables us to quantify the marginal impact of each risk on the project, capturing its influence on cost, even when a risk is initially identified as affecting only the project duration. Furthermore, our method incorporates the project network's structure into the impact assessment, accounting for whether a risk affects activities on the critical path or those with sufficient slack. This allows for a more consistent reflection under the modelled assumptions of the risk’s influence on the final project objectives.
We conduct two distinct simulation exercises to evaluate the effectiveness of the risk matrix in comparison to our proposed methodology. The first exercise utilizes fictitious projects with various network structures, from nearly serial to nearly parallel configurations. By applying both the risk matrix and our proposed method to these simulations, we find that, for parallel project structures, the risk matrix produces results that differ significantly from those generated by our methodology. In contrast, for serial structures, the results are more consistent between the two methods, showing no substantial discrepancies.
In the second exercise, we apply our methodology to two real-world projects to validate the findings from the simulations involving fictitious projects. Although actual projects typically involve more complex, less structured data, the simulation results confirm that the outcomes of the two methods diverge considerably. This discrepancy underscores the impact of the project network typology on the assessment results.
Our conclusive evidence derives from artificial-project experiments, in which structural drivers are controlled. The real projects provide external plausibility checks, concise triangulation consistent with Vanhoucke’s guidance, confirming that the controlled patterns are coherent with practice.
Looking ahead, several modest extensions could enrich the analysis without altering its core focus. Although MCSimulRisk supports risk–risk dependence, we modeled risks independently. Examining how positive or negative correlations shape prioritization, notably when the P × I matrix lacks a native treatment of dependence, would add nuance. Likewise, a distributional sensitivity check (e.g., beta or lognormal fits derived from empirical data) could complement the triangular baseline. Finally, our experiments abstracted from resource constraints to isolate network effects; carrying the comparison into (S)RCPSP settings would test robustness when capacity limits introduce additional sequencing.
Data availability
Data will be made available on request.Data availability can be accessed through the external portal.
References
AACE - American Association of Cost Engineering. (2011). Integrated cost and schedule risk analysis using Monte Carlo simulation of a CPM model. In AACE International Recommended Practice No. 57R-09.
Acebes, F., Curto, D., De Antón, J., & Villafáñez, F. (2024a). Análisis cuantitativo de riesgos utilizando “MCSimulRisk” como herramienta didáctica. Dirección y Organización, 82, 87–99. https://doi.org/10.37610/dyo.v0i82.662
Acebes, F., Curto, D., González-Varona, J. M., & Pajares, J. (2024). Monte Carlo simulation for project risk prioritisation. In Lecture Notes on Data Engineering and Communications Technologies. Springer Nature Switzerland. https://doi.org/10.1007/978-3-031-57996-7_78
Acebes, F., De Antón, J., Villafáñez, F., & Poza, D. (2023). A matlab-based educational tool for quantitative risk analysis. In IoT and Data Science in Engineering Management (Vol. 160). Springer International Publishing. https://doi.org/10.1007/978-3-031-27915-7_8
Acebes, F., González-Varona, J. M., López-Paredes, A., & Pajares, J. (2024c). Beyond probability-impact matrices in project risk management: A quantitative methodology for risk prioritisation. Humanities and Social Sciences Communications. https://doi.org/10.1057/s41599-024-03180-5
Acebes, F., Pajares, J., Galán, J. M., & López-Paredes, A. (2014). A new approach for project control under uncertainty. Going back to the basics. International Journal of Project Management, 32(3), 423–434. https://doi.org/10.1016/j.ijproman.2013.08.003
Acebes, F., Pereda, M., Poza, D., Pajares, J., & Galán, J. M. (2015). Stochastic earned value analysis using Monte Carlo simulation and statistical learning techniques. International Journal of Project Management, 33(7), 1597–1609. https://doi.org/10.1016/j.ijproman.2015.06.012
Afzal, F., Yunfei, S., Nazir, M., & Bhatti, S. M. (2021). A review of artificial intelligence based risk assessment methods for capturing complexity-risk interdependencies: Cost overrun in construction projects. International Journal of Managing Projects in Business, 14(2), 300–328. https://doi.org/10.1108/IJMPB-02-2019-0047
Akcay, E. C. (2021). Prioritization of risk events in PPP wind power projects using integrated FMEA and Monte Carlo simulation. Journal of Construction Engineering, Management & Innovation, 4(2), 80–91. https://doi.org/10.31462/jcemi.2021.02080091
Ale, B., Burnap, P., & Slater, D. (2015). On the origin of PCDS - (Probability consequence diagrams). Safety Science, 72, 229–239. https://doi.org/10.1016/j.ssci.2014.09.003
Allahi, F., Cassettari, L., & Mosca, M. (2017). Stochastic risk analysis and cost contingency allocation approach for construction projects applying Monte Carlo simulation. World Congress on Engineering. WCE 2017, July.
Alleman, G. B., Coonce, T. J., & Price, R. A. (2018). What is risk? The Measurable News, 01(1), 25–34.
Aven, T. (2010). On the need for restricting the probabilistic analysis in risk assessments to variability: Perspective. Risk Analysis, 30(3), 354–360. https://doi.org/10.1111/j.1539-6924.2009.01314.x
Aven, T. (2017). Improving risk characterisations in practical situations by highlighting knowledge aspects, with applications to risk matrices. Reliability Engineering and System Safety, 167, 42–48. https://doi.org/10.1016/j.ress.2017.05.006
Axelos. (2023). Managing Successful Projects with PRINCE2® 7th ed. (AXELOS Limited, Ed.; 7th Ed). TSO (The Stationery Office).
Ball, D. J., & Watt, J. (2013). Further thoughts on the utility of risk matrices. Risk Analysis, 33(11), 2068–2078. https://doi.org/10.1111/risa.12057
Ballesteros-Pérez, P., Cerezo-Narváez, A., Otero-Mateo, M., Pastor-Fernández, A., & Vanhoucke, M. (2019). Performance comparison of activity sensitivity metrics in schedule risk analysis. Automation in Construction, 106, 102906. https://doi.org/10.1016/j.autcon.2019.102906
Batselier, J., & Vanhoucke, M. (2015). Construction and evaluation framework for a real-life project database. International Journal of Project Management, 33(3), 697–710.
Baybutt, P. (2018). Guidelines for designing risk matrices. Process Safety Progress, 37(1), 49–55. https://doi.org/10.1002/prs.11905
Bolbot, V., Theotokatos, G., McCloskey, J., Vassalos, D., Boulougouris, E., & Twomey, B. (2022). A methodology to define risk matrices – Application to inland water ways autonomous ships. International Journal of Naval Architecture and Ocean Engineering, 14, 100457. https://doi.org/10.1016/j.ijnaoe.2022.100457
Cagliano, A. C., Grimaldi, S., & Rafele, C. (2015). Choosing project risk management techniques. A theoretical framework. Journal of Risk Research, 18(2), 232–248. https://doi.org/10.1080/13669877.2014.896398
Caron, F. (2013). Quantitative analysis of project risks. In Managing the Continuum: Certainty, Uncertainty, Unpredictability in Large Engineering Projects (pp. 75–80). Springer, Milano. https://doi.org/10.1007/978-88-470-5244-4_14
Caron, F., Fumagalli, M., & Rigamonti, A. (2007). Engineering and contracting projects: A value at risk based approach to portfolio balancing. International Journal of Project Management, 25(6), 569–578. https://doi.org/10.1016/j.ijproman.2007.01.016
Chapman, C. B., & Ward, S. (2011). How to Manage Project Opportunity and Risk. Wiley.
Chen, P.-H., & Peng, T.-T. (2018). Value-at-Risk model analysis of Taiwanese high-tech facility construction. Journal of Management in Engineering. https://doi.org/10.1061/(asce)me.1943-5479.0000585
Colin, J., & Vanhoucke, M. (2015). A multivariate approach to statistical project control using earned value management. .https://doi.org/10.1016/j.dss.2015.08.002
Cox, L. A. (2008). What’s wrong with risk matrices? Risk Analysis, 28(2), 497–512. https://doi.org/10.1111/j.1539-6924.2008.01030.x
Cox, L. A., Babayev, D., & Huber, W. (2005). Some limitations of qualitative risk rating systems. Risk Analysis, 25(3), 651–662. https://doi.org/10.1111/j.1539-6924.2005.00615.x
Creemers, S., Demeulemeester, E., & Van de Vonder, S. (2014). A new approach for quantitative risk analysis. Annals of Operations Research, 213(1), 27–65. https://doi.org/10.1007/s10479-013-1355-y
Curto, D., Acebes, F., González-Varona, J. M., & Poza, D. (2022). Impact of aleatoric, stochastic and epistemic uncertainties on project cost contingency reserves. International Journal of Production Economics, 253, 108626. https://doi.org/10.1016/j.ijpe.2022.108626
Damnjanovic, I., & Reinschmidt, K. F. (2020). Data Analytics for Engineering and Construction Project Risk Management. Springer International Publishing.
Demeulemeester, E., Vanhoucke, M., & Herroelen, W. (2003). RanGen: A random networkgenerator for activity-on-the-node networks. Journal of Scheduling, 6(1), 17–38. https://doi.org/10.1023/A:1022283403119
Duijm, N. J. (2015). Recommendations on the use and design of risk matrices. Safety Science, 76, 21–31. https://doi.org/10.1016/j.ssci.2015.02.014
Eldosouky, I. A., Ibrahim, A. H., & Mohammed, H. E. D. (2014). Management of construction cost contingency covering upside and downside risks. Alexandria Engineering Journal, 53(4), 863–881. https://doi.org/10.1016/j.aej.2014.09.008
Elmonstri, M. (2014). Review of the strengths and weaknesses of risk matrices. Journal of Risk Analysis and Crisis Response, 4(1), 49.
European Commission. (2023). Project Management Methodology. Guide 3.1 (European Union, Ed.). Publications Office of the European Union.
Gatti, S., Rigamonti, A., Saita, F., & Senati, M. (2007). Measuring value-at-risk in project finance transactions. European Financial Management, 13(1), 135–158. https://doi.org/10.1111/j.1468-036X.2006.00288.x
Giot, P., & Laurent, S. (2003). Market risk in commodity markets: A VaR approach. Energy Economics, 25, 435–457. https://doi.org/10.1016/S0140-9883(03)00052-5
Goerlandt, F., & Reniers, G. (2016). On the assessment of uncertainty in risk diagrams. Safety Science, 84, 67–77. https://doi.org/10.1016/j.ssci.2015.12.001
Haimes, Y. Y. (1993). Risk of extreme events and the fallacy of expected value. Control and Cybernetics, 22(4), 7–31. https://doi.org/10.1002/9780470422489.ch8
Helton, J. C., Johnson, J. D., Oberkampf, W. L., & Sallaberry, C. J. (2006). Sensitivity analysis in conjunction with evidence theory representations of epistemic uncertainty. Reliability Engineering and System Safety, 91(10–11), 1414–1434. https://doi.org/10.1016/j.ress.2005.11.055
Hillson, D. (2014). How to manage the risks you didn’t know you were taking. PMI® Global Congress, 1–8.
Hillson, D. (2020). Capturing upside risk: Finding and managing opportunities in projects. In Capturing Upside Risk (1st ed.). Taylor & Francis.
Hoseini, E., van Veen, P., Bosch-Rekveldt, M., & Hertogh, M. (2020). Cost performance and cost contingency during project execution: Comparing client and contractor perspectives. Journal of Management in Engineering, 36(4), 05020006. https://doi.org/10.1061/(asce)me.1943-5479.0000772
Hubbard, D. W. (2009). The Failure of Risk Management: Why It’s Broken and How to Fix it. Wiley.
Hulett, D. T. (2009). Practical schedule risk analysis. Gower Publishing Limited.
International Organization for Standardization. (2012). ISO 21500:2012 Guidance on project management. BSI Standards Publication, 48.
International Organization for Standardization. (2018). ISO 31000 :2018 Risk management – Guidelines (Vol. 2).
International Organization for Standardization. (2019). ISO/IEC 31010:2019 Risk management - Risk assessment techniques.
Ishizaka, A., & Labib, A. (2011). Review of the main developments in the analytic hierarchy process. Expert Systems with Applications, 38(11), 14336–14345. https://doi.org/10.1016/j.eswa.2011.04.143
Joukar, A., & Nahmens, I. (2016). Estimation of the escalation factor in construction projects using value at risk. Construction Research Congress , 2351–2359. https://doi.org/10.1061/9780784479827.234
Kaliprasad, M. (2006). Proactive risk management. Cost Engineering, 48(12), 26–36.
Kaya, G. K., Ward, J., & Clarkson, J. (2019). A review of risk matrices used in acute hospitals in England. Risk Analysis, 39(5), 1060–1070. https://doi.org/10.1111/risa.13221
Kendrick, T. (2009). Identifying and managing project risk: essential tools for failure-proofing your project (Second Ed). AMACOM American Management Association.
Kengpol, A., & Tuammee, S. (2016). The development of a decision support framework for a quantitative risk assessment in multimodal green logistics: An empirical study. International Journal of Production Research, 54(4), 1020–1038. https://doi.org/10.1080/00207543.2015.1041570
Koulinas, G. K., Demesouka, O. E., Sidas, K. A., & Koulouriotis, D. E. (2021). A topsis—risk matrix and Monte Carlo expert system for risk assessment in engineering projects. Sustainability, 13(20), 1–14. https://doi.org/10.3390/su132011277
Krisper, M. (2021). Problems with Risk Matrices Using Ordinal Scales. https://doi.org/10.48550/arXiv.2103.05440
Kuester, K., Mittnik, S., & Paolella, M. S. (2006). Value-at-risk prediction: A comparison of alternative strategies. Journal of Financial Econometrics, 4(1), 53–89. https://doi.org/10.1093/jjfinec/nbj002
Kwon, H., & Kang, C. W. (2019). Improving project budget estimation accuracy and precision by analyzing reserves for both identified and unidentified risks. Project Management Journal, 50(1), 86–100. https://doi.org/10.1177/8756972818810963
Levine, E. S. (2012). Improving risk matrices: The advantages of logarithmically scaled axes. Journal of Risk Research, 15(2), 209–222. https://doi.org/10.1080/13669877.2011.634514
Li, J., Bao, C., & Wu, D. (2018). How to design rating schemes of risk matrices: A sequential updating approach. Risk Analysis, 38(1), 99–117. https://doi.org/10.1111/risa.12810
Martens, A., & Vanhoucke, M. (2017). A buffer control method for top-down project control. European Journal of Operational Research, 262(1), 274–286.
Mohamed, E., Seresht, N. G., Hague, S., & Abourizk, S. M. (2020). Simulation-based approach for risk assessment in onshore wind farm construction projects. 2020 Asia-Pacific International Symposium on Advanced Reliability and Maintenance Modeling, APARM 2020. https://doi.org/10.1109/APARM49247.2020.9209516
Monat, J. P., & Doremus, S. (2020). An improved alternative to heat map risk matrices for project risk prioritization. Journal of Modern Project Management, 7(4), 214–228. https://doi.org/10.19255/JMPM02210
Naderpour, H., Kheyroddin, A., & Mortazavi, S. (2019). Risk assessment in bridge construction projects in Iran using Monte Carlo simulation technique. Practice Periodical on Structural Design and Construction, 24(4), 1–11. https://doi.org/10.1061/(asce)sc.1943-5576.0000450
Ni, H., Chen, A., & Chen, N. (2010). Some extensions on risk matrix approach. Safety Science, 48(10), 1269–1278. https://doi.org/10.1016/j.ssci.2010.04.005
Project Management Institute. (2017). A guide to the project management body of knowledge: PMBoK(R) guide. Sixth Edition (6th ed.). Project Management Institute Inc.
Proto, R., Recchia, G., Dryhurst, S., & Freeman, A. L. J. (2023). Do colored cells in risk matrices affect decision-making and risk perception? Insights from randomized controlled studies. Risk Analysis. https://doi.org/10.1111/risa.14091
Qazi, A., & Dikmen, I. (2021). From risk matrices to risk networks in construction projects. IEEE Transactions on Engineering Management, 68(5), 1449–1460. https://doi.org/10.1109/TEM.2019.2907787
Qazi, A., & Simsekler, M. C. E. (2021). Risk assessment of construction projects using Monte Carlo simulation. International Journal of Managing Projects in Business, 14(5), 1202–1218. https://doi.org/10.1108/IJMPB-03-2020-0097
Qazi, A., Shamayleh, A., El-Sayegh, S., & Formaneck, S. (2021). Prioritizing risks in sustainable construction projects using a risk matrix-based Monte Carlo Simulation approach. Sustainable Cities and Society, 65, 102576. https://doi.org/10.1016/j.scs.2020.102576
Ruan, X., Yin, Z., & Frangopol, D. M. (2015). Risk matrix integrating risk attitudes based on utility theory. Risk Analysis, 35(8), 1437–1447. https://doi.org/10.1111/risa.12400
Simon, P., Hillson, D., & Newland, K. (1997). PRAM Project risk analysis and management guide. P. Simon, D. Hillson, & K. Newland (Eds.). Association for Project Management.
Talbot, J. (2014). What’s right with risk matrices? An great tool for risk managers... 31000risk. https://31000risk.wordpress.com/article/what-s-right-with-risk-matrices-3dksezemjiq54-4/.
Taroun, A. (2014). Towards a better modelling and assessment of construction risk: Insights from a literature review. International Journal of Project Management, 32(1), 101–115. https://doi.org/10.1016/j.ijproman.2013.03.004
Tavana, M., Soltanifar, M., & Santos-Arteaga, F. J. (2023). Analytical hierarchy process: Revolution and evolution. Annals of Operations Research, 326(2), 879–907. https://doi.org/10.1007/s10479-021-04432-2
Thamhain, H. (2013). Managing risks in complex projects. Project Management Journal, 44(2), 20–35. https://doi.org/10.1002/pmj.2132
Thomas, P., Bratvold, R. B., & Bickel, J. E. (2014). The risk of using risk matrices. SPE Economics and Management, 6(2), 56–66. https://doi.org/10.2118/166269-pa
Ünsal-Altuncan, I., & Vanhoucke, M. (2024). A hybrid forecasting model to predict the duration and cost performance of projects with Bayesian Networks. European Journal of Operational Research, 315(2), 511–527. https://doi.org/10.1016/j.ejor.2023.12.029
Van, S. Q., Le-Hoai, L., & Dang, C. N. (2019). Predicting implementation cost contingencies for residential construction projects in flood-prone areas. International Journal of Managing Projects in Business, 12(4), 1097–1119. https://doi.org/10.1108/IJMPB-04-2018-0071
Vanhoucke, M., Coelho, J., Debels, D., Maenhout, B., & Tavares, L. V. (2008). An evaluation of the adequacy of project network generators with systematically sampled networks. European Journal of Operational Research, 187(2), 511–524. https://doi.org/10.1016/j.ejor.2007.03.032
Vanhoucke, M. (2018). The data-driven project manager: A statistical battle against project obstacles. In The Data-Driven Project Manager: A Statistical Battle Against Project Obstacles. https://doi.org/10.1007/978-1-4842-3498-3
Vanhoucke, M. (2023). The illusion of control. Project Data, Computer Algorithms and Human Intuition for Project Management and Control. Springer Nature. https://doi.org/10.1007/978-3-031-31785-9
Vanhoucke, M., Coelho, J., & Batselier, J. (2016). An overview of project data for integrated project management and control. The Journal of Modern Project Management, 3(2), 6–21.
Vaseghi, F., Martens, A., & Vanhoucke, M. (2024). Analysis of the impact of corrective actions for stochastic project networks. European Journal of Operational Research, 316, 503–518. https://doi.org/10.1016/j.ejor.2024.02.040
Vatanpour, S., Hrudey, S. E., & Dinu, I. (2015). Can public health risk assessment using risk matrices be misleading? International Journal of Environmental Research and Public Health, 12(8), 9575–9588. https://doi.org/10.3390/ijerph120809575
Vose, D. (2008). Risk analysis: a quantitative guide (3rd ed.). Wiley.
Funding
Open access funding provided by FEDER European Funds and the Junta de Castilla y León under the Research and Innovation Strategy for Smart Specialization (RIS3) of Castilla y León 2021-2027. Consejería de Educación, Junta de Castilla y León, VA042G24, Fernando Acebes.
Author information
Authors and Affiliations
Corresponding author
Ethics declarations
Conflict of interest
The authors declare that they have no known competing financial interests or personal relationships that could have influenced the work reported in this paper.
Additional information
Publisher's Note
Springer Nature remains neutral with regard to jurisdictional claims in published maps and institutional affiliations.
Appendix
Appendix
This Appendix presents the numerical and graphical results derived from the simulation conducted on the empirical project ‘C2019–19 Transitional House.’ With an SP index of 0.75, this project exhibits a structure that approaches a serial configuration. Table 10 provides a comprehensive list of activities and their respective predecessor activities for this project. In addition to defining each activity, the table details the duration and the fixed and variable costs associated with it. Based on these data, the project’s expected duration is 130 days and the anticipated cost is €240,840.00.
Table 11 outlines the risks incorporated into the simulation of the ‘Transition House C2019–19’ project. This table includes a definition of each risk, the specific activity it affects, and a semantic estimate of the probability of occurrence and the potential impact, including duration and cost.
The alignment between the numerical impact values for duration and cost and the semantic assessment of probability and impact parameters is derived from the data presented in Table 12.
Below, we present a series of graphs generated from the simulation of the ‘Transition House C2019–19’ project, incorporating the identified risks. Figure
Scatter diagram of the project ‘C2019–19 Transitional house’ including identified risks
Distribution function and cumulative distribution of the project ‘C2019–19 Transitional house’, including identified risks
22 shows the scatter diagram from the simulation, where each point in the quadrant represents the end state (duration-cost) of a simulated project scenario.
Figure
Distribution function and cumulative distribution of the project ‘C2019–19 Transitional house’, including identified risks
23 presents the probability and cumulative distribution functions for the total duration of the ‘C2019–19 Transitional House’ project, incorporating the identified risks.
Similarly, Fig.
Schedule Sensitivity Index (SSI) of the project ‘C2019–19 Transitional house’, including identified risks
24 displays the probability distribution and cumulative distribution functions for the total cost of the ‘Transition House C2019–19' project, incorporating the identified risks. Both graphs illustrate the impact of the risks on the project’s objectives—duration in Fig. 23 and cost in Fig. 24.
Finally, Fig. 20 illustrates the Schedule Sensitivity Index (SSI) for the activities of the ‘C2019–19 Transitional House’ project, considering the identified risks in its calculation.
Rights and permissions
Open Access This article is licensed under a Creative Commons Attribution 4.0 International License, which permits use, sharing, adaptation, distribution and reproduction in any medium or format, as long as you give appropriate credit to the original author(s) and the source, provide a link to the Creative Commons licence, and indicate if changes were made. The images or other third party material in this article are included in the article's Creative Commons licence, unless indicated otherwise in a credit line to the material. If material is not included in the article's Creative Commons licence and your intended use is not permitted by statutory regulation or exceeds the permitted use, you will need to obtain permission directly from the copyright holder. To view a copy of this licence, visit http://creativecommons.org/licenses/by/4.0/.
About this article
Cite this article
Acebes, F., González-Varona, J.M., López-Paredes, A. et al. Quantitative risk prioritization. A new risk-based approach to prioritize project risks. Ann Oper Res (2026). https://doi.org/10.1007/s10479-026-07252-4
Received:
Accepted:
Published:
Version of record:
DOI: https://doi.org/10.1007/s10479-026-07252-4
























