How much contingency?
Estimating uncertainty and risk events are different things and get modelled separately. The answer is a figure that covers you a stated share of the time — not an expected value no outcome ever equals.
What contingency actually covers you
Estimating uncertainty and discrete risk events are different things, modelled separately — because adding an expected value to the estimate produces a number no outcome ever equals.
Cost items — uncertainty around the estimate
These will cost roughly what you think. Give the range.
Risk events — things that either happen or do not
Each has a probability and a cost if it occurs. One-sided: they can only make things worse.
Where the final cost lands
Contingency, by how covered you want to be
Which risks drive the number
How the simulation works
Each run samples every cost item from a triangular distribution over your low/likely/high, then tests each risk event against its probability and adds a sampled cost when it fires. Ten thousand runs give a distribution of final cost.
The two sources of variance are kept apart deliberately. Estimating uncertainty is roughly symmetric and always present. Risk events are discrete and one-sided. Blending them into a single padded estimate hides which is which, and they call for completely different responses.
Contingency is a gap to a confidence level, not a percentage of the estimate. A flat 10% is a number chosen by convention; P80 minus the point estimate is a number chosen by your actual exposure.
Why the expected value is the wrong contingency
The standard shortcut is to multiply each risk's probability by its cost and add the results. A 20% chance of a 100k problem contributes 20k to the contingency.
No outcome ever equals that. The problem either happens, costing 100k, or it does not, costing nothing. A 20k contingency is wrong in both worlds — too much in one and nowhere near enough in the other.
What a simulation gives you instead is a figure that covers you a stated proportion of the time. That is a different kind of number and it is the one you can actually defend in a funding conversation.
The point estimate is not the middle
Sum the likely costs and you get a number that is beaten less than half the time, because risk events only push one way. The gap between your point estimate and the median is the amount of optimism built into the estimate before any risk has been considered.
That gap is usually a surprise the first time a team measures it.
Which risks are worth managing
The simulation ranks events by their average contribution across all runs, which is a better guide than either probability or cost alone. A 5% chance of a catastrophic cost and a 60% chance of a nuisance can contribute similarly, and they need entirely different responses.
Managing the top two or three is usually most of the available benefit. Managing all fifteen is how risk registers become paperwork.
Correlation, again
Risk events here fire independently. Real ones cluster: the supplier who fails is the same supplier whose delay pushes the schedule, and a market shift moves several line items at once. Independent sampling understates the tail, so treat the P80 as a floor rather than a ceiling.