Project Management›Project Risk Management›Algorithms for Decision Making›Chapter 3
3Part I · Probabilistic Reasoning
Parameter Learning
Where do the numbers come from? Calibrating a risk model from data — and blending thin project history with expert judgement without fooling yourself.
A network with the wrong numbers is a confident way to be wrong. Parameter learning is how you fill the tables from evidence rather than from optimism.
Chapters 1 and 2 assumed the conditional probability tables were already populated. In reality someone has to choose those numbers, and the choice is consequential: the same structure can give sober or reckless advice depending on the parameters inside it. Parameter learning is the principled way to set them — from data where you have it, and from disciplined judgement where you don’t.
1The obvious method, and its sharp edge
Maximum likelihood estimation chooses the parameters that make the data you actually observed as probable as possible. For a risk table this reduces to something intuitive: use the observed frequencies. If 3 of your last 20 similar packages had a design change, the estimate is 3/20. It is simple, unbiased in the large-sample limit, and exactly what a base-rate table is.
Its sharp edge is small samples — which is nearly all project risk data. If none of your last five projects hit a particular failure, maximum likelihood assigns it probability zero: not “rare”, but impossible. One dramatic near-miss then looks like a miracle the model insists cannot occur. Estimating rare, high-consequence events from a handful of observations is precisely where this method misleads most.
2Bayesian estimation: start from a belief, update with data
The Bayesian approach treats the parameters themselves as uncertain. You begin with a prior — your belief before seeing this project’s data — and update it into a posterior as evidence arrives. For probabilities this is clean: a Beta (or, for multi-outcome tables, a Dirichlet) prior updates simply by adding your observed counts to a set of pseudocounts that encode the prior. Those pseudocounts behave exactly like imagined prior observations.
Two properties make this the right default for risk work. With abundant data, the prior washes out and the Bayesian estimate converges to the maximum-likelihood one — you lose nothing. With scarce data, the prior stabilises the estimate, and crucially a sensible prior never assigns a genuine hazard a flat zero. You get graceful behaviour across the whole range from “no data” to “lots”.
3Pseudocounts are expert judgement, made honest
Good risk practitioners already blend history with judgement — they just do it in their heads, invisibly. Pseudocounts make that blend explicit and defensible: “our prior is equivalent to having seen this fail twice in fifty comparable jobs” is a claim a reviewer can interrogate and a data trail can eventually overrule. It is the difference between an auditable assumption and a gut feel wearing a number.
Maximum likelihood trusts only this project’s data; Bayesian estimation blends it with prior knowledge and lets the data win as it accumulates. For the thin, lopsided datasets typical of project risk, the blend is not a nicety — it is what stops the model from declaring rare disasters impossible.
4When the record has gaps
Project data is not only sparse but incomplete — a field left blank, an outcome never recorded. The expectation–maximization approach handles this by alternating: estimate the missing pieces using the current model, then re-fit the parameters as if those estimates were real, and repeat until it settles. It lets you learn from imperfect records instead of discarding every row with a hole in it.
Anchor your risk numbers in data wherever you have it, but state your priors openly and carry them where you don’t. Never let a small sample talk you into a probability of zero for something that can plainly happen. Write your assumptions as pseudocounts — “as if we’d seen n cases” — so that experience can override them as your portfolio grows. A model that learns is a model that gets less wrong every project.
Handbook application: from concept to controlled practice
Purpose. This expanded section turns the original page into a practical handbook. It preserves the supplied material and adds a repeatable way to apply, check and review Parameter Learning. It does not replace a contract, legislation, a controlled standard, competent engineering judgement or specialist advice.
The operating aim is to convert the subject into a governed decision, owned work, usable evidence and a reviewable outcome. Read the original explanation first, then use the workflow and checks below to convert knowledge into evidence.
Use Parameter Learning as a decision instrument rather than an administrative form. The subject terms—parameter, learning, risk, bayesian, estimation—need an explicit connection to the project objective, business value and stakeholder commitments. Before completing the artefact, write one sentence stating who will use it, what decision it supports and when that decision is required.
Apply a disciplined information model. Separate facts supported by evidence, forecasts derived from a method, assumptions awaiting validation, constraints that limit choice, risks that may occur, issues that already exist and actions assigned to people. Each material entry should have an owner, date, status and next review point. Where probability or impact scores are used, define the scale so different reviewers interpret it consistently.
A baseline is useful only when changes are visible. Give the artefact an identifier, version, approval state and effective date. Define which changes require reapproval, how superseded versions are retained and where supporting evidence is stored. During reviews, focus on exceptions, decisions and trends rather than reading every field aloud. Record the decision and rationale, not merely that a meeting occurred.
Close the loop beyond delivery. Confirm acceptance criteria, unresolved items, transferred responsibilities and operational ownership. Where benefits are expected, identify the outcome measure, baseline, target, observation period and owner who remains accountable after the project team disbands. Lessons should describe the condition, consequence and reusable action; a generic statement such as “communicate better” cannot improve the next project.
Step-by-step operating method
- Clarify the decision. Name the outcome, sponsor, affected stakeholders and decision that this work must enable.
- Set boundaries. Record scope, assumptions, constraints, dependencies, tolerances and escalation conditions.
- Plan the evidence. Define deliverables, measures, owners, due dates and acceptance criteria before execution.
- Control delivery. Compare actual performance with the baseline, assess changes and manage risks and issues explicitly.
- Close the loop. Confirm acceptance, transfer ownership, capture lessons and track benefits beyond handover.
Completion and governance protocol
Start with a short drafting workshop involving the accountable owner and the people who hold the evidence. Complete high-consequence fields first: objective, scope, owner, baseline, acceptance, dependencies and escalation. Mark unknowns as assumptions or actions rather than hiding them behind vague prose. Circulate a review draft, resolve conflicting interpretations, baseline the approved version and place the next review date in an owned schedule.
| Information type | Minimum useful content | Review test |
|---|---|---|
| Outcome | Observable change and intended recipient | Not merely a deliverable or activity |
| Measure | Definition, baseline, target, frequency and source | Two reviewers would calculate it the same way |
| Ownership | One accountable role plus contributors and approver | Authority matches responsibility |
| Uncertainty | Assumption, risk or issue with response and trigger | Status reflects current reality |
| Control | Version, approval, review date and change rule | Current baseline is identifiable |
Common failure modes and recovery actions
1. Watch for
Producing a document with no named decision or accountable owner.
Recovery: Return to the governing definition or requirement and restate the decision in one sentence.
2. Watch for
Mixing risks, current issues, assumptions and actions in one unstructured list.
Recovery: Separate evidence from assumption, assign an owner and set a date for validation.
3. Watch for
Measuring activity or output while leaving the intended outcome undefined.
Recovery: Run a small counterexample, boundary test, pilot or independent check before proceeding.
4. Watch for
Accepting changes without evaluating effects on value, scope, schedule, cost and risk.
Recovery: Record the consequence, decision and rationale, then update the controlled baseline.
5. Watch for
Closing the project at delivery even though benefit ownership has not transferred.
Recovery: Escalate when the issue affects safety, compliance, acceptance, material value or an agreed tolerance.
Review checklist
- Which decision or commitment does this artefact support?
- Who owns each action, risk, acceptance and post-project benefit?
- What is the baseline and what variance triggers escalation?
- Where is the evidence that the result was accepted and transferred?
- Are mandatory requirements distinguished from recommendations and illustrative values?
- Are sources, assumptions, units, dates and versions recorded closely enough to reproduce the decision?
- Have safety, legal, ethical, stakeholder and operational consequences been considered at the appropriate level?
- Is there a named owner and a trigger for review, escalation, change or retirement?
Questions for deeper application
What is the most important distinction a practitioner must preserve when applying Parameter Learning?
Answer with a fact or cited source where available. Where evidence is incomplete, record the assumption, consequence, responsible owner and next validation action.
Which assumption about parameter would change the result most if it proved false?
Answer with a fact or cited source where available. Where evidence is incomplete, record the assumption, consequence, responsible owner and next validation action.
What evidence would allow an independent reviewer to reproduce or challenge the conclusion?
Answer with a fact or cited source where available. Where evidence is incomplete, record the assumption, consequence, responsible owner and next validation action.
Which boundary, exception or failure case has not yet been tested?
Answer with a fact or cited source where available. Where evidence is incomplete, record the assumption, consequence, responsible owner and next validation action.
What must be handed over, monitored or reviewed after the immediate work is complete?
Answer with a fact or cited source where available. Where evidence is incomplete, record the assumption, consequence, responsible owner and next validation action.
Authoritative references and use notes
The sources below were selected as institutional or primary guidance for the broader practice. They support the handbook method; they do not imply that every statement or clause in a source applies to every project. Confirm the current edition, jurisdiction, contract and application before treating any requirement as mandatory.
- Risk Management in Portfolios, Programs, and Projects: A Practice Guide — Project Management Institute. Used for risk practices across portfolios, programs and projects. Accessed 2026-08-13.
- ISO 31000 family — Risk management — International Organization for Standardization. Used for principles and guidance for enterprise risk management. Accessed 2026-08-13.
