Back to Blog

Project risk budgeting contingency: how to stop guessing and start calculating

RC

Risk Companion

August 25, 2026
9 min read

Key Takeaways

  • A contingency figure derived from expected monetary value calculations is defensible to a board because it traces directly to specific identified risks with named owners and assessed probabilities. A percentage applied without a risk register behind it contains no information about the actual exposure on your project.
  • Known unknowns belong in contingency reserve, which the project manager controls and which should trace directly to specific risks in the register. Unknown unknowns belong in management reserve, a separate buffer held by senior leadership for events the project team could not have anticipated, governed at a higher level and requiring escalation to access.
  • Contingency percentages should reduce as project maturity increases. Around 20 percent is appropriate at feasibility stage and 10 to 15 percent at detailed engineering, because uncertainty genuinely reduces as scope, design, and procurement become clearer. The operative word is 'appropriate', not 'standard'.
  • Large capital projects routinely overrun their budgets by significant margins, and the most common cause is optimism bias at the planning stage, where political pressure produces a budget that was never realistic. The risks were real, the contingency was not sized to cover them.
  • Running a Monte Carlo simulation across your risk register produces a probability distribution of cost outcomes, including P50, P85, and P90 figures. That distribution gives you a contingency recommendation with a confidence level behind it and a clear answer when a board asks where the figure came from.

Large capital projects routinely overrun their budgets by enormous margins, and the explanation is rarely bad site management or unexpected weather. The root cause is almost always the same: insufficient contingency planning at the outset, shaped by optimism bias and political pressure to present a budget the client or board will approve.

Project risk budgeting contingency is a structured response to the specific risks sitting in your register, calculated from the evidence you have and traceable back to individual risk assessments. Adding a percentage at the end when the estimate feels thin is a different thing entirely.

The gap between a defensible contingency and an optimistic guess is almost always the quality of the risk thinking behind it.

Why contingency budgets so often fail before the project starts

The estimating team builds a cost model, someone senior asks what contingency to add, and a figure between 10 and 15 percent arrives through a combination of habit, industry convention, and the desire not to lose the bid or the board approval.

That percentage can be a reasonable order-of-magnitude check when you have very little project definition to work with. The problem is when it becomes the answer, with no risk register behind it to validate whether the figure is appropriate.

A blanket percentage applied to a EUR 50 million project budget gives you no indication of whether your contingency of EUR 6 million is appropriate for the risks you have actually identified, or whether it leaves you exposed on the ones you have missed.

Optimism bias compounds the problem, because project teams are structurally incentivised to present lean budgets. A realistic contingency calculation that produces EUR 12 million on a EUR 50 million project is politically difficult to defend, so it quietly becomes EUR 6 million. By the time the risks materialise, the contingency is exhausted before the project is finished.

Known unknowns and unknown unknowns: the distinction that changes everything

Every project operates with two categories of uncertainty, and mixing them up in the budget creates real problems.

Known unknowns are risks you have identified, assessed, and registered. Their timing and precise cost are uncertain, but their existence is acknowledged and their exposure is estimated.

A supply chain delay on a key component, a planning permission that might take longer than the programme allows, a subcontractor with a thin track record in this type of work: these risks have owners, probability assessments, and impact estimates, and they belong in the contingency reserve.

Unknown unknowns are things you genuinely could not have anticipated at the time of planning: a new regulation that changes technical requirements mid-project, a geopolitical event that closes a critical supply route, or the financial collapse of a key supplier. These events are outside the project team's normal sphere of foresight and they belong in management reserve, a separate budget buffer held by senior management and governed at a higher level than the project manager's authority.

The distinction matters for governance as much as for calculation. The project manager has authority to draw on contingency reserve to address known risks as they materialise, while management reserve requires an escalation and a decision at a higher level. Conflating the two means your project manager is either sitting on money that should have been in the reserve, or spending money that was never theirs to allocate.

A well-structured project budget keeps these three layers clearly separated: the base estimate, the contingency reserve for identified risks, and the management reserve for residual uncertainty. The UK HM Treasury Green Book, the government's standard guidance on appraisal and evaluation for public spending decisions, is clear on this principle: contingency provision should reflect measured risk on an expected likelihood basis, with optimism bias adjustments grounded in empirical data from comparable projects. A contingency is a structured response to the specific risk profile of this project at this stage, with the percentage reducing as project definition improves.

How contingency percentages should move with project maturity

One of the more useful contributions of cost engineering practice is the recognition that contingency should reduce as project definition improves, because uncertainty genuinely decreases as scope, design, and procurement become clearer.

A rough order of magnitude at feasibility stage might reasonably carry a contingency of around 20 percent, reflecting the breadth of unknowns at that point. By the time detailed engineering is complete and major contracts are placed, 10 to 15 percent is a more appropriate range, because you have eliminated a large portion of the uncertainty that existed earlier. The operative word is 'appropriate', not 'standard'.

A project with a well-populated risk register, good historical data on similar scopes, and experienced subcontractors might support a contingency at the lower end of the range at detailed engineering, while a project with novel technology, limited comparable data, and a volatile supply chain might need significantly more. The percentage is an input to a judgement, and the judgement is what the risk register is for.

What changes this from a rule of thumb into a real calculation is the quality of the risk assessment sitting underneath it. A register with thirty identified risks, probability assessments, financial impact estimates, and named owners gives you something to calculate from. A register with twelve vague entries and no scores gives you decoration, and the contingency figure it produces is as unreliable as the register behind it.

From risk register to contingency reserve: the calculation that matters

Expected monetary value is the simplest bridge between a risk register and a contingency number. For each identified risk, you multiply the probability of occurrence by the estimated financial impact, then sum those figures across your register. The result is a baseline contingency figure derived from actual risk assessments, with a clear line of sight back to the register.

Consider a construction project with five significant identified risks. A ground condition risk with a 30 percent probability and a EUR 400.000 cost impact if it occurs contributes EUR 120.000 to the expected monetary value. A planning delay risk with a 40 percent probability and a EUR 250.000 cost impact contributes EUR 100.000. A procurement risk at 20 percent probability with a EUR 600.000 impact contributes EUR 120.000. Two smaller risks add another EUR 60.000 between them. Your expected monetary value across those five risks is EUR 400.000, which gives you a contingency figure you can stand behind in a board conversation, because it traces directly to specific identified risks with named owners and assessed probabilities.

The limitation of a simple expected monetary value calculation is that it treats each risk independently and produces a single point estimate, when in reality risks can correlate, impacts can be skewed, and the distribution of outcomes matters as much as the central figure.

This is where Monte Carlo simulation adds real value. Instead of treating each risk as a single probability-times-impact calculation, you assign a range to each impact using a triangular distribution, a minimum, most likely, and maximum, and run thousands of simulated scenarios.

The output is a probability distribution of total cost outcomes. From that distribution you can read a P50 figure (the outcome with a 50 percent probability of not being exceeded), a P85, and a P90.

A board asking where the contingency figure came from can be told it represents the P85 outcome from a Monte Carlo simulation across forty-seven identified risks. That is a very different conversation from "we added 12 percent."

Risk Companion supports this directly. Risk assessments in the platform can be entered as triangular distributions, and the Monte Carlo simulation runs across the full register to produce those percentile outputs.

You are not working from a spreadsheet where someone has typed a formula into a cell and hoped for the best. The contingency figure comes from the risk register, which means every change to a risk assessment updates the analysis. If a risk owner closes a measure and lowers the probability on a significant risk, the contingency calculation reflects that immediately.

Why the risk register is the budget document nobody uses

On many projects, the risk register and the contingency budget are maintained by different people, updated on different cycles, and reviewed in different meetings.

The register is a risk management document and the budget is a finance document. They reference each other in theory and ignore each other in practice.

This disconnect is where budget overruns are born. A risk that has been assessed at EUR 300.000 impact and 35 percent probability might not survive the translation into the finance model. Someone converts it to "contingency for supply chain issues: EUR 80.000" and moves on. By the time the risk materialises at EUR 290.000, the EUR 80.000 looks like a rounding error.

The solution is a better connection between the two documents, and that connection already exists when the risk register contains the financial impact estimates, the probability assessments, and the Monte Carlo output.

When the risk register contains the financial impact estimates, the probability assessments, and the Monte Carlo output, it is already the contingency budget, and the finance model is reading two views of the same underlying data.

That connection also disciplines the risk register itself. When people know the register feeds the contingency calculation, vague entries with no probability and no impact estimate become a problem.

"Regulatory changes may affect project delivery" is not a risk assessment. It is a placeholder.

A register that feeds the budget forces specificity: which regulation, what probability, what financial impact under which scenarios.

What a defensible contingency actually looks like

A defensible project risk budgeting contingency has four characteristics.

It is traceable. Every euro in the contingency reserve maps to at least one identified risk in the register, with a named owner, a probability, and an impact estimate.

It reflects estimate maturity. The percentage acknowledges how much project definition exists at the point of calculation and adjusts accordingly, with higher contingency at early stages and lower contingency as scope and design become clearer.

It separates known from unknown. Contingency reserve and management reserve are distinct line items with distinct governance, with the project manager authorised to draw on the first and escalation required before the second can be accessed.

It updates as the project progresses. Risk assessments change, measures close risks, and new risks emerge. The contingency is a live number that the risk register keeps current, reflecting the actual state of the project at each review point.

Industry percentages of 10 to 15 percent give you a useful reference point, and a calculation grounded in your actual risk register tells you whether that reference point is too conservative or dangerously thin for the specific project in front of you.

The destination is a number with a probability distribution behind it, derived from the specific risks on this project, and presented with enough transparency that someone asking "where did that figure come from?" gets a real answer.

If you want to see the P85 Monte Carlo output and the EMV breakdown for your own project's risks, start a free 14-day trial of Risk Companion.

Ready to improve your risk management?

See how Risk Companion can help you implement these best practices with powerful, easy-to-use tools. Sign up and we'll prepare a demo project tailored to your company.

Risk assessments
AI assistance
Bowtie models
Simulations

Frequently Asked Questions

Project risk budgeting contingency is a financial allowance within a project budget set aside to cover the cost impact of identified risks if they materialise. A well-structured contingency reserve is derived from the risk register through expected monetary value calculations or probabilistic analysis, and is traceable to specific identified risks rather than based on a generic percentage of total project cost.