6.1 Schedule Risk Principles, Risk Drivers, and Three-Point Estimates

Key Takeaways

  • A deterministic CPM produces one result from one set of durations; a risk model samples uncertainty to produce a distribution of possible completion dates.

  • Three-point estimates must use clearly defined optimistic, most-likely, and pessimistic assumptions rather than arbitrary percentages around the baseline.

  • Classic PERT uses an expected duration of (O + 4M + P) divided by 6 and an approximate standard deviation of (P − O) divided by 6.

  • A risk driver combines a probability of occurrence, an impact distribution, and the activities affected if the risk occurs.

  • Model selection and contingency confidence must reflect data quality, decision purpose, risk tolerance, and documented assumptions.

Last updated: October 2026

6.1 Schedule Risk Principles, Risk Drivers, and Three-Point Estimates

A deterministic Critical Path Method (CPM) schedule calculates dates from one duration, one calendar, and one logic model for each activity. It is essential for coordination, but its single finish date is conditional: the date is true only if the modeled assumptions occur. A probabilistic schedule risk analysis repeatedly samples uncertain inputs and shows a range of completion outcomes.

AACE RP 57R-09 addresses integrated cost and schedule risk analysis using risk drivers and Monte Carlo simulation of a CPM model. It is guidance, not a universal standard, and it emphasizes choosing a degree of confidence appropriate to the decision. AACE RP 65R-11 is a different document: it concerns integrated expected-value methods. Do not cite RP 65R-11 as the title for Monte Carlo CPM simulation.

Two different things to model

InputMeaningExample treatment
Base-duration uncertaintyNormal variation even when no named event occursSample an activity duration range
Discrete risk eventAn event may occur or may not occurSample occurrence first, then sample impact if triggered
Common-cause risk driverOne risk affects several related activitiesApply one correlated driver to all mapped activities
Logic or calendar riskThe execution model itself may changeModel alternatives explicitly or analyze scenarios

Treating every risk as independent activity padding usually overstates some paths, understates common-cause effects, and hides the source of contingency. The model should preserve traceability from each material risk to its affected work.

Building three-point estimates

For an uncertain duration, define:

  • Optimistic (O): a credible short outcome under favorable but feasible conditions;
  • Most likely (M): the modal or most plausible outcome under the stated execution plan; and
  • Pessimistic (P): a credible long outcome under unfavorable but feasible conditions.

The labels do not automatically mean P1, P50, or P99. If the organization intends the endpoints to represent particular percentiles, it must say so. The team should document crew size, quantities, production rates, calendars, weather treatment, access assumptions, and whether named risk events are included. Otherwise, two experts can use the same three numbers while describing different uncertainties.

Classic PERT approximation

The traditional PERT approximation is:

Te=O+4M+P6T_e = \frac{O + 4M + P}{6}

σ≈P−O6\sigma \approx \frac{P - O}{6}

For O = 12, M = 18, and P = 36 working days, the expected duration is 20 days and the approximate standard deviation is 4 days. These are model outputs, not guarantees. The standard-deviation expression is a PERT approximation; it is not the standard deviation of every possible beta distribution sharing the same three inputs.

Triangular distribution

A triangular distribution uses minimum, mode, and maximum directly. Its mean is:

μ=O+M+P3\mu = \frac{O + M + P}{3}

It can be useful when a bounded range and a mode are all that can be defended. A beta-PERT form can place more weight near the mode. Neither distribution is automatically “correct” merely because data are scarce or abundant. Historical data may support an empirical distribution, while expert judgment may still support either triangular or beta-PERT after calibration.

Discrete risk drivers

Suppose an environmental permit has a 35% chance of causing delay. A traceable model can represent:

  1. a 35% occurrence probability;
  2. an impact distribution conditional on occurrence; and
  3. the activities and logic interfaces affected.

In iterations where the risk does not occur, its added impact is zero. In iterations where it occurs, the model samples the defined impact. If the event affects design, procurement, and field mobilization together, mapping a common driver preserves that dependence better than applying three unrelated random paddings.

Correlation and model quality

Correlated inputs matter. Weather may affect several civil activities during the same period; a late vendor drawing may affect fabrication and testing together. Ignoring correlation can produce an unrealistically narrow or otherwise distorted output distribution. Conversely, adding arbitrary correlation everywhere can overstate tail risk.

Before trusting the output, verify that the deterministic CPM is usable: logic is complete, calendars are intentional, constraints are justified, resource assumptions are understood, and the status date is correct. Simulation does not repair a defective network; it repeats that defect thousands of times.

Interpreting results

The output usually includes a completion-date distribution, percentile dates, criticality or schedule-sensitivity measures, and risk-driver rankings. These answer different questions. A P80 date is the date met or beaten in about 80% of modeled iterations, given the model assumptions. A high criticality index indicates frequent critical-path participation; high correlation indicates strong association with completion variation. Neither statistic by itself proves causation or prescribes a mitigation.

The practical discipline is to state assumptions, run sensitivity checks, and explain limitations. A risk model supports a decision; it does not convert uncertain inputs into certainty.

Test Your Knowledge

For O = 12 days, M = 18 days, and P = 36 days, what does the classic PERT approximation produce?

A

Expected duration 18 days and standard deviation 6 days

B

Expected duration 20 days and approximate standard deviation 4 days

C

Expected duration 22 days and variance 4 days

D

Expected duration 24 days and approximate standard deviation 12 days

Test Your Knowledge

How should a 35%-probability permit-delay event be represented in a traceable risk-driver model?

A

Increase every activity duration by 35%.

B

Always insert the maximum delay so the baseline is conservative.

C

Trigger the event in roughly 35% of iterations and sample its conditional impact only when triggered.

D

Ignore the event because CPM cannot represent uncertainty.

Test Your Knowledge

Which statement about three-point distribution selection is most defensible?

A

The choice should reflect the meaning of the inputs, available evidence, and sensitivity testing; no one distribution is universally required.

B

Triangular is mandatory whenever historical data are unavailable.

C

Beta-PERT is mandatory whenever historical data exist.

D

The deterministic duration must always equal the optimistic value.

Sections you finish are checked off in the contents.