Person in dark setting, thoughtful expression.
GCC REGION

KAIROS INSIGHT · Contract Risk Management  

The risk you transferred is still yours

Contract risk management and the hidden exposure inside every capital project agreement

This Insight Covers

  • What contract risk management governs is not whether a risk exists, but which party carries it and at what price.
  • Why transferring every risk to the contractor fails is that exposure exceeding a contractor’s capacity to absorb it returns to the employer.
  • How sound allocation is decided is by testing which party can control, foresee, and bear each risk at the lowest cost.
  • When the employer’s hidden exposure is created is at contract formation, not on the day the risk event finally arrives on site.
  • Who pays for mispriced risk is the employer, through the tender price, through claims, or through a contractor that cannot perform.

~13 min read

Every capital project agreement carries exposure that the employer does not believe it holds. The contract says otherwise. It names the contractor as the party responsible for ground conditions, for design adequacy, for weather, for delay, for whatever else the drafting has pushed across the line. The employer reads those clauses and concludes the risk has left the building. It has not. Contract risk management is the discipline of understanding where exposure actually sits once the agreement is tested by events, and the answer is rarely the one written on the page.

Contract Risk Management
The risk you transferred is still yours 4

This matters because risk allocation is often treated as a drafting exercise rather than a commercial one. A clause that assigns a risk to the contractor is easy to write and costs nothing at the time of writing. Whether that assignment holds is a separate question, decided by whether the contractor can actually control the risk, price it accurately, and absorb it when it materialises. Effective contract risk management is the analysis that connects the wording to that reality. Where the two diverge, the employer has bought protection that will not be there when it is needed.

Across the GCC, the default answer to this problem has become the lump-sum EPC agreement, in which the contractor takes single-point responsibility for design, procurement, and construction at a fixed price, and with it the great majority of project risk. The appeal to an employer is obvious. One counterparty, one price, one date, and an apparently clean transfer of exposure to someone else’s balance sheet. On the right project, with the right preparation, that structure works well. Applied as a reflex to every programme regardless of its characteristics, it does the opposite of what the employer intends, and contract risk management is the discipline that distinguishes the two cases.

The uncomfortable conclusion, and the one that experienced practitioners reach eventually, is that an employer cannot reduce its exposure simply by writing it away. Risk can be allocated, priced, and managed. It cannot be abolished by contract. Contract risk management done properly is the work of putting each exposure where it will be carried most cheaply and most competently, which is a different exercise from putting all of it as far from the employer as the drafting will reach.

A contract does not remove risk from a project. It decides who is holding it when the risk arrives, and how much everyone pays for that decision.

01  ·  Contract risk

Contract risk management decides who carries exposure, not whether it exists

The starting point is a fact that contract drafting tends to obscure. The total quantum of risk on a capital programme is set by the project itself: its ground, its design maturity, its complexity, its schedule, its regulatory environment. Nothing in the agreement changes that quantum, and contract risk management begins with accepting it. What the agreement changes is its distribution. Contract risk management is therefore an exercise in distribution, and the measure of a good outcome is not how much risk the employer has shed but how efficiently the total has been placed.

Efficiency here has a precise meaning. A risk held by the party that can see it coming, act to prevent it, and absorb it cheaply when it occurs costs the project very little. The same risk held by a party that can do none of those things costs the project a great deal, because it will be priced with a heavy contingency, mismanaged when it materialises, or both. Two contracts can allocate identical risks to different parties and produce materially different total costs. That difference is what contract risk management exists to capture.

This reframes what an employer should be buying. The objective of contract risk management is not the largest possible transfer but the lowest total cost of risk, counting the contingency built into the price, the claims that allocation will provoke, and the exposure the employer retains whether it acknowledges it or not. Employers rarely measure that total, which is why the reflex to transfer everything survives so comfortably. A programme that measured it would find that contract risk management pays for itself long before the first variation is issued.

02  ·  Sound allocation

Sound allocation follows capability rather than bargaining power

There is a well-established framework for making these decisions, and it has nothing to do with who has the stronger negotiating position. The FIDIC Golden Principles set out that the Particular Conditions of a contract must not disturb the balance of risk and reward established in the General Conditions, and they ground that requirement in the Abrahamson principles as refined by Nael Bunni: risk should sit with the party best able to control it, best able to foresee it, best able to bear it, and the party that most benefits or suffers when it eventuates.

FIDIC is explicit that fair and balanced allocation is what keeps the contract price moderate and disputes rare. Those four tests are the analytical core of contract risk management, and they are capability tests rather than power tests.

Applying them changes real decisions. Ground conditions on a site the employer has owned and investigated for years fail the foresight test when transferred to a contractor given six weeks to tender. Regulatory approval risk fails the control test when the counterparty holding it has no standing with the authority granting the approval. Employer-caused delay fails every test at once, which contract risk management should catch before the clause is written.

The Kairos insight on project risk management argues that risk which is properly identified and assigned to an owner who can act on it becomes manageable, while risk assigned to a party with no ability to influence it simply waits to become a cost. Contract risk management applies that logic at the point where the assignment is legally fixed.

03  ·  The lump-sum

The lump-sum EPC reflex pushes risk past the point where it can be absorbed

The EPC lump-sum model is not the problem. Its indiscriminate use is. FIDIC’s own guidance on the Silver Book, the form drafted precisely for EPC and turnkey delivery, warns that it is not suitable where tenderers have insufficient time or information to scrutinise the employer’s requirements, carry out their design work, and complete proper risk assessment and estimating.

Selecting that form in those circumstances is treated as a departure from the principles the contract is built on. This is a description of a great many fast-track GCC programmes, where tender periods are compressed, employer’s requirements are still evolving, and the contractor is asked to fix a price against a scope nobody has finished defining.

What happens next is predictable to anyone who has watched it. The contractor cannot price the unknown accurately, so it does one of two things. It loads the tender with contingency, and the employer pays for risk that may never materialise. Or, under competitive pressure, it prices thin, wins the work, and then manages its exposure through the claims process for the next three years.

Neither outcome delivers what the employer wanted when it decided to transfer everything. Contract risk management is what interrupts that sequence, by asking before award whether the transfer being contemplated is one the market can actually price.

The model deserves a fair hearing. Single-point responsibility has real value where an employer lacks the capability to coordinate multiple interfaces, where the scope is well defined before tender, and where the contractor has time and information enough to price what it is taking on.

Under those conditions the EPC structure transfers risk to a party that can truly manage it, and the premium the employer pays is money well spent. The failure is not the structure but its application to programmes that meet none of those conditions, and disciplined contract risk management is what tells the two situations apart.

Risk pushed onto a party that cannot carry it does not stay there. It waits, and it comes back to the employer with interest.

04  ·  Excessive transfer returns

Excessive transfer returns to the employer as price, claims, or failure

Contract Risk Management op 2
The risk you transferred is still yours 5

The economics of over-transfer are documented rather than theoretical. The World Bank’s guidance on allocating risk in infrastructure projects states that each risk should go to the party best able to control its likelihood, best able to control its impact, or able to absorb it at the lowest cost, and it is direct that applying these principles does not mean transferring the maximum possible risk to the private party.

It notes that the more risk is transferred, the higher the premium the counterparty requires and the harder the project becomes to finance. Most tellingly for employers, it observes that where losses exceed what the private party can bear, that party can walk away, and the remaining risk sits with the public sponsor who was responsible all along.

That last mechanism is the hidden exposure of the title. An employer that transfers risk beyond a contractor’s capacity to absorb it has not moved the risk. It has converted a manageable project risk into a counterparty risk, which is worse, because it now arrives suddenly, at the least convenient moment, and with a distressed contractor attached.

A contractor in financial trouble slows down, staffs the job thinly, claims aggressively, and in the worst case leaves the site. The employer then holds the original risk plus the cost of replacement, re-procurement, and delay. The Kairos insight on margins in project risk management makes the point that contractor margin is not the employer’s enemy but part of the employer’s risk buffer, and that squeezing it to nothing removes the shock absorber the programme depends on.

05  ·  Amended standard forms

Amended standard forms turn balanced contracts into unbalanced ones

The mechanism by which this happens in the region is usually amendment rather than form selection. An employer adopts a recognised standard form, which carries a considered balance of risk, and then rewrites the Particular Conditions until that balance is gone. Time bars are shortened. Entitlements to extension of time are narrowed or deleted.

Unforeseeable conditions are reassigned without any contract risk management assessment of what that reassignment will cost. Each amendment looks small in isolation, and each is defensible on its own terms. The cumulative effect is a contract that no longer behaves the way the form was designed to behave, and the employer is frequently unaware of how far the aggregate has shifted.

This is where contract risk management earns its place at the drafting table rather than after signature. Someone has to hold the cumulative view: not whether each amendment is individually justifiable, but what the amended contract as a whole does to pricing, to claim exposure, and to the incentives of the party being asked to sign it. That assessment is rarely performed.

Legal review tests enforceability, commercial review tests price, and the question of whether the risk position is coherent falls between them. Contract risk management is the function that closes that gap.

06  ·  Disciplined contract risk management

What disciplined contract risk management looks like on a GCC capital programme

In practice, strong contract risk management has a recognisable shape. It begins before the form of contract is chosen, with an honest assessment of design maturity, site knowledge, and schedule pressure, because those three factors determine which delivery model can work. It produces an explicit risk allocation matrix that names each significant exposure and the party assigned to it, tested against capability rather than preference.

It prices retained risk deliberately, so the employer knows what it is carrying instead of discovering it later. And it revisits the allocation before signature, when the accumulated amendments can still be assessed as a whole.

None of this amounts to a softer deal for the contractor, which is the objection employers usually raise. An employer practising rigorous contract risk management may well transfer more risk in some areas than a conventional lump-sum package does, because it has identified exposures the contractor is demonstrably better placed to manage and has priced them accordingly.

What changes is that each transfer is now a contract risk management decision supported by analysis rather than a reflex applied across the board. The employer ends up with a lower total cost of risk, which is the only number that matters, rather than the largest apparent transfer.

Conclusion: Exposure follows capability, not wording

The instinct to transfer everything comes from a reasonable place. An employer facing a multi-billion-dirham commitment wants certainty, and a fixed price with a single responsible counterparty looks like certainty. The difficulty is that certainty purchased this way is conditional on the counterparty remaining able to honour it, and that condition weakens with every risk added beyond what the contractor can control or absorb. At some point the employer stops buying protection and starts buying a claim, or a distressed contractor, or an abandoned site, and contract risk management is what marks that boundary.

Contract risk management is how an employer finds that point before crossing it. The exposure hidden in a capital project agreement is not the risk the contract mentions. It is the risk the contract assigns to someone who was never in a position to carry it, and which therefore never left the employer at all.

WORK WITH KAIROS

If your programme is in distress, we can help.

Kairos provides contract risk management for complex capital programmes across the GCC, covering delivery model selection, risk allocation matrices tested against capability, review of amended standard forms, and the pricing of retained employer risk. We help owners see the exposure their agreements actually create, before it is fixed by signature. To discuss how disciplined contract risk management can reduce the total cost of risk on your programme.