Principle 04

Risk provisions: never in the baseline budget.

Covering a risk does not mean budgeting work you hope never to do. In Waterfall, a risk is costed like an estimate, its provision weighs on the forecast, and the baseline revision keeps provisions apart, as a reserve against which what risks actually cost is compared.

The trap: a project that eats its provisions

When risk provisions are blended into the budget, a risk that occurs is paid for out of them and nothing shows: the budget holds, the indices stay green, and the safety margin has gone. You find out at the next risk, when there is nothing left to absorb it. Waterfall therefore keeps three things clearly apart: what the risk would cost, what is set aside for it, and what it actually cost.

A risk is costed like an estimate

A risk is an uncertain event that, if it happens, will cost money and time. In Waterfall, it carries its own estimate: a cost structure with its tasks and lines, describing what would have to be done if it occurred. Its severity is not a score entered by guesswork; it is the total of that estimate. Qualifying a risk therefore requires having costed it, and that is deliberate.

A risk also carries a label, a description, a note on mitigation actions, and a probability of occurrence as a percentage. It is placed in a risk matrix with four probability levels and four severity levels, whose bounds are set in the reference data.

The provision: severity weighted by probability

As long as it is identified, the risk is represented in the project’s main structure by a provision line, whose amount equals its severity multiplied by its probability. This line uses a cost type of the provision kind, so the estimate breakdown shows provisions separately from labour and purchases. It is carried by the task the user designates, most often the phase the risk threatens.

The provision counts in the estimate and in the estimate to complete. It never enters the baseline budget. The baseline revision keeps the sum of its provision lines apart: this is the risk reserve.

Fictional example: building up the reserve

RiskSeverity (own estimate)ProbabilityProvision
A — Requalification of a component€200,00030%€60,000
B — Subcontractor delay€100,00020%€20,000
Baseline risk reserve€80,000

The estimate presented to the client includes this €80,000. The baseline budget does not: it measures only the planned work.

A reassessment at every review

The probability and state of each risk are reassessed at every periodic review. Each reassessment is dated and kept, with the probability, severity and state retained: the history shows how the view of a risk has evolved. The risk’s own estimate remains editable throughout the project, because a risk that occurs late does not cost what was expected two years earlier, and the schedule it will have to fit into has changed.

A risk is in one of three states:

  • identified: it carries a provision;
  • dismissed: it can no longer happen, and its provision stops weighing on the estimate; it can become identified again;
  • occurred: it is no longer a risk but a fact, and the transition is final.

The risk tracking grid is the register you go through in a review. It shows each risk with its probability, severity, provision, state and the date of its latest reassessment, coloured according to the matrix. It separates three totals: the provisions of identified risks, and the provisions that the baseline held for risks that have occurred and for dismissed risks, with the reserve alongside.

Occurrence: from risk to fact

When a risk occurs, the tasks and lines of its own estimate are merged into the main structure of the draft revision, like tasks added during execution. They carry a budgeted amount of zero and, as re-estimated amount, that of the risk’s own estimate. The provision line disappears.

Occurrence does not move the baseline: only a contract amendment does. The total of the risk’s own estimate at the time it is declared is frozen: this is the cost at occurrence.

Risk coverage

At every review, Waterfall sets the baseline risk reserve against what risks represent today: the provisions of risks still identified, plus the cost at occurrence of risks that have occurred. The signed difference is the coverage gap.

coverage gap = baseline reserve − (remaining provisions + costs at occurrence)

Example continued

Eighteen months later, risk A occurs. Its own estimate, revised before the declaration, comes to €240,000. Risk B is still identified, but its probability is lowered to 10%: its provision drops to €10,000.

Baseline risk reserve€80,000
Remaining provision (B, identified)€10,000
Cost at occurrence (A)€240,000
Coverage gap−€170,000

The negative gap says that risks cost more than what was reserved. The €240,000 enters the estimate to complete and the project manager’s estimate, and the cost performance index worsens accordingly. The baseline budget has not moved: the project cannot appear to be on budget by consuming its reserve.

Risks across the portfolio

The risk view of the portfolio totals the provisions of all projects, ranks the heaviest risks across all projects, fills the risk matrix with the number of risks per cell, and aggregates coverage: the baseline reserve against remaining provisions and the cost of risks that have occurred. The organisation thus sees what uncertainty it carries, and what has become of its provisions.

Join the project

Want to test Waterfall or contribute?

Waterfall is built in public. Testers, project managers, cost controllers, developers: every piece of feedback counts, from a remark on the specification to testing a screen.