Governance & methodology

Analysis that earns trust under review.

Business cases. Gateway reviews. Assurance. Audit. Board papers. CRAFT is built for work that faces scrutiny, so every rating, assumption and number can be opened up and explained with confidence.

Risk information quality

Well-written risks are the foundation of everything.

Every review, rating and simulation is only as good as the risk statements underneath it. CRAFT builds that quality in from the first entry, structuring every risk as cause, event and consequence:

Cause The switchgear supplier runs a single qualified fabrication line

Event HV switchgear delivery slips past the energisation window

Consequence Commissioning pushes into the next shutdown, carrying 11 weeks of standby cost

Written like this, every risk has an owner who knows what they own, a consequence you can price, a cause your team can treat, and something concrete for the workshop to work with. The structure keeps the quality consistent whether a risk is drafted by AI or written by hand.

If your organisation runs a risk information repository, CRAFT is the natural front end to it. Repositories excel at storing, tracking and reporting what you give them; CRAFT makes sure what you give them is clear, structured and decision-ready. The thinking happens in CRAFT; the record lives wherever your governance framework says it should.

Better-written risks lift everything downstream: sharper workshops, cleaner priorities, and a contingency you can stand behind.

Where the lines sit

AI drafts. Your team decides. The engine calculates.

Three jobs with three different owners, and the boundaries between them don't move. This clear ownership is what gives your analysis its credibility under review.

AI drafts

Structure, not judgement

It turns project context and workshop inputs into risk candidates using the categories you configured. It can also draft commentary after a simulation, again as a draft for your review.

Your team decides

Every line, accepted

Risk acceptance, ratings, treatment decisions and methodology stay with the professionals in the room, applied through your matrices and your categories.

The engine calculates

It does the arithmetic

P50, P90, contingency and sensitivity come from a seeded Monte Carlo run over your inputs. CRAFT stores the seed with your project, so a rerun on the same inputs and engine version returns the same result.

AI never sets a risk ID, changes a rating or moves a number.

Cost methodology

How CRAFT produces the number

CRAFT models two sources of cost uncertainty and combines them in a single simulation. The detail is here for anyone who needs to interrogate the method.

Base estimate uncertainty

Your cost breakdown structure carries a range for every item: best case, most likely and worst case. Rather than forcing you to invent three numbers for every line, CRAFT offers estimate confidence profiles. Choose the profile that describes the line and CRAFT derives the range from your base cost. Where you already know the spread, choose User Defined and enter the three values directly.

Each item is sampled from a triangular distribution across that range.

Contingent risks

Each contingent risk carries a probability of occurrence and a cost impact range. In every iteration CRAFT tests independently whether the risk occurs and, when it does, samples its impact from the low, most-likely and high values.

CRAFT excludes risks classified as inherent from the contingent-risk total. Represent inherent or base-estimate uncertainty in the relevant CBS ranges or confidence profiles so it is not double-counted as a separate event.

Correlation

Cost items rarely move independently. When labour markets tighten, several packages feel it at once. Ignoring that understates exposure at the top end, which is where contingency decisions are made.

CRAFT supports standard correlation across six common driver groups:

  • Market and economic conditions
  • Labour market and productivity
  • Site and environmental conditions
  • Regulatory environments
  • Procurement and contract complexities
  • Technology and commissioning complexity

Assign each CBS item to a driver group and CRAFT applies a considered correlation structure between them, so items sharing a driver tend to move together. Correlation is optional and applies to base-cost uncertainty; contingent risks are always sampled independently.

The simulation

Each iteration samples every CBS item and tests every contingent risk, producing one possible total project cost. Across the run you get a distribution rather than a single figure. Rather than fixing the iteration count up front, CRAFT keeps going until the answer stops moving: it works through 5,000, 20,000, 80,000 and up to 320,000 iterations, stopping once the contingency estimate is precise enough.

You set how precise. The target is expressed against the contingency figure itself, anywhere from ±2% to ±7%, and CRAFT reports the sampling precision it reached alongside the result. That figure describes how tightly the simulation has pinned down its own estimate. It says nothing about whether your cost inputs are right.

CRAFT stores the random seed with the project, and writes it into your Excel and JSON exports. With the same inputs, seed and simulation-engine version, a rerun produces the same result, supporting review and audit of the analysis.

Reading the results
  • The percentile curve shows cost against confidence across the simulated distribution. CRAFT reports P5, P10, P50 and P90 as standard reference points.
  • The distribution shows how often simulated totals land in each cost band, with the cumulative probability curve over the top. Switch between it and the percentile curve; both mark P50 and P90.
  • Contingency is reported as the difference between P90 and P50: the additional allowance between the median simulated outcome and the high-confidence P90 outcome.
  • Sensitivity ranks sampled CBS lines and contingent risks by their Spearman rank correlation with total simulated cost, showing which inputs have the strongest relationship with the result.

Methodology

Your framework. Not ours.

Nobody wants to explain to their assurance team why the risk method changed because of a software purchase. CRAFT applies the approach your organisation already defends.

Rating matrices you configure

Anything from 3×3 to 6×6, set up to match your framework.

  • Current and residual assessed independently
  • The profile in use is recorded against the project
  • Save it once, reuse it across every project

Risk categories you control

Organisation-neutral out of the box, replaceable with your own taxonomy.

  • Applied consistently through identification and reporting
  • Recorded against the project so there's no ambiguity later
  • AI drafting is constrained to the approved set

Complexity as context, not a score

Eight dimensions, assessed before anyone starts listing risks.

  • Dimension scores and drivers stay visible
  • Red-flag conditions can override the calculated level
  • Feeds straight into risk identification

Quantification you can interrogate

Simulation over inputs you control, not judgement layered on a single-point estimate.

  • The full percentile curve, not two headline numbers
  • Sensitivity analysis names the risks doing the damage
  • Base-cost uncertainty and contingent risks modelled together

Your data

The project stays yours.

CRAFT is local-first on purpose. Moving your project anywhere is something you do deliberately, not something that happens by default.

Where your project data lives

CRAFT runs in your browser and stores your project data locally on your own device. You can save and reopen projects as .prs files. Project data is not stored on PRS servers, which means PRS cannot access, recover or delete your projects for you. If your subscription ends, you will no longer be able to open or edit projects in CRAFT, but your .prs files remain on your device in a readable format.

Security and data handling
  • Project data. CRAFT does not maintain a server-side project database. Your working projects remain in your browser and in .prs files you control.
  • Hosting. CRAFT application hosting is primarily in Microsoft Azure Australia East. Microsoft identity, AI and Paddle services may process data in other locations as explained in the privacy policy.
  • Identity. Customer sign-in uses Microsoft Entra External ID.
  • Payments. Checkout and payment processing are handled by Paddle as merchant of record. PRS does not store full card numbers.
  • In transit. Customer traffic to CRAFT is encrypted in transit using HTTPS/TLS.
  • Service credentials. Service secrets are stored in Azure Key Vault and accessed through restricted identities and platform controls.
  • AI processing. Only the information needed for an AI-assisted request is transmitted, and only when you choose to use that feature.
  • Account records. Subscription and entitlement records are operational data kept separately from browser-local project data.

Full detail is in the privacy policy.

Portable project files

Projects save to portable, versioned .prs files. Move one between machines or hand it to a colleague under whatever version control you already use.

No server-side project database

There's no central store of customer project data. When you use an AI-assisted feature, only what that request needs goes to the protected CRAFT service.

Exports built for the pack

Risk-register workbooks, Canvas workbooks, cost results and a consolidated CRAFT workbook, plus JSON. Generated from the project's current state.

Evaluating CRAFT for an organisation?

Governance alignment, deployment, access, support. Let's work out whether it fits before anyone commits to anything.