← BlogSimulation

When can a reactor simulation be trusted?

Verification, validation and uncertainty quantification explained, with the role of international benchmarks and the graded approach to evidence.

5 min read
Photo: Oak Ridge National Laboratory, CC BY 2.0

A reactor simulation can inform a design decision when its evidence fits the question being asked. Analysts assess that evidence through verification, validation and uncertainty quantification, often shortened to VVUQ.

What does it mean to trust a simulation?

A trustworthy simulation is one whose results are accurate enough for a stated purpose, with that accuracy demonstrated and quantified. The definition has three parts. First, the purpose must be clear, because a result can be adequate for comparing early design options and inadequate for setting a safety limit. Second, the accuracy must be demonstrated by evidence, gathered in a structured way. Third, the remaining uncertainty must be estimated and reported alongside the result.

Engineers organise this evidence around three activities, often described together as VVUQ: verification, validation and uncertainty quantification.

VerificationAre the equations solvedcorrectly?ValidationDo the results matchreal measurements?UncertaintyHow large is theremaining error band?DecisionIs the evidence enoughfor this use?VerificationAre the equations solvedcorrectly?ValidationDo the results match realmeasurements?UncertaintyHow large is the remaining errorband?DecisionIs the evidence enough for thisuse?

What is verification?

Verification answers the question: are the equations being solved correctly? It concerns mathematics and software, independent of physical reality. Verification has two branches.

Code verification checks that the software implements its intended equations and algorithms correctly. A powerful technique is the method of manufactured solutions: the analyst chooses an exact mathematical solution, derives the source terms that would produce it, feeds those sources to the code and checks that the code recovers the chosen solution. As the computational mesh is refined, the error should shrink at the rate predicted by the numerical method. Matching that rate is strong evidence that the implementation is correct. Comparisons with analytical solutions of simplified problems, and regression tests that confirm results stay stable as software evolves, complete the picture.

Solution verification estimates the numerical error in a specific calculation. In deterministic codes, this means refining the mesh, time step or angular resolution and observing convergence. In Monte Carlo neutron transport codes, results carry a statistical uncertainty that shrinks with the square root of the number of simulated particles, and analysts confirm that the fission source has converged before collecting results.

What is validation?

Validation answers a different question: are the right equations being solved? It compares simulation results with measurements from the physical world, under conditions relevant to the intended application.

Validation evidence is usually organised as a hierarchy:

  • Separate-effects tests isolate one phenomenon, such as heat transfer in a heated tube or neutron absorption in a sample, under well-controlled conditions.
  • Component and integral tests combine several phenomena in a representative system, such as a scaled loop that reproduces a loss-of-coolant transient.
  • Plant data from operating reactors, such as measured power distributions and critical boron concentrations, test the full combination of physics at full scale.

Each level adds realism and complexity. Agreement with one experiment supports the model under that experiment's conditions; extending confidence to new conditions requires evidence that spans the range of interest. Measurements themselves carry uncertainty from instruments, material composition, geometry and operating history, and a meaningful comparison accounts for experimental uncertainty as well as computational uncertainty.

What is uncertainty quantification?

Uncertainty quantification estimates how much a result could vary given everything that is imperfectly known. Sources of uncertainty fall into several groups:

  • Input data. Nuclear cross-sections, material properties, dimensions and boundary conditions all carry measured uncertainties. Evaluated nuclear data libraries supply covariance matrices that describe these uncertainties and their correlations.
  • Model form. Every model simplifies reality, for example through correlations for heat transfer or turbulence.
  • Numerical error. Estimated through solution verification.

Analysts distinguish aleatory uncertainty, which reflects genuine randomness such as manufacturing variation, from epistemic uncertainty, which reflects incomplete knowledge and can shrink with better data.

Two families of methods propagate input uncertainty to results. Sampling methods run the simulation many times with inputs drawn from their probability distributions and examine the spread of outputs. Sensitivity methods compute how strongly each output depends on each input, then combine those sensitivities with the input covariances. Sensitivity results also show which inputs dominate the uncertainty, which guides where better measurements would be most valuable.

How do international benchmarks help?

The OECD Nuclear Energy Agency (NEA) organises international benchmark exercises across neutronics, thermal hydraulics, fuel performance and coupled multiphysics. In a typical exercise, organisers specify a problem in detail: geometry, materials and conditions, often based on a real experiment or plant. Participating organisations solve it with their own codes and submit results, which are compared with measured reference data or with each other.

These exercises serve several purposes. They reveal differences in assumptions, numerical methods and nuclear data choices. They provide shared, well-documented test cases for code developers. And they build a collective understanding of how well current methods perform for a class of problems.

The NEA also maintains evaluated experimental databases. The International Criticality Safety Benchmark Evaluation Project and the International Reactor Physics Experiment Evaluation Project collect carefully documented experiments with assessed uncertainties, which serve as reference points for validating neutronics codes and nuclear data. Recent NEA work extends benchmarking to novel multiphysics tools and advanced reactor concepts, where operating experience is limited.

How does uncertainty travel through coupled calculations?

Modern reactor analysis increasingly couples several physics fields, and uncertainty travels between them.

Nuclear dataSet reactionprobabilitiesPowerDistribution follows thereaction ratesTemperatureFuel and coolant respondto powerFeedbackDensity and Dopplereffects change theneutronicsEach change feeds back into the neutronicsNuclear dataSet reaction probabilitiesPowerDistribution follows thereaction ratesTemperatureFuel and coolant respond topowerFeedbackDensity and Doppler effectschange the neutronics

Uncertainty in nuclear data affects reaction rates and hence the power distribution. The power distribution sets fuel and coolant temperatures. Temperature changes alter material densities, Doppler broadening of resonances and moderator properties, which in turn alter the neutron behaviour. A thermal-hydraulic result therefore inherits uncertainty from its own models and from the neutronics upstream of it.

Coupled uncertainty analysis treats the linked calculation as a single system and propagates uncertainty through every coupling. The NEA's benchmark for uncertainty analysis in modelling of light-water reactors was organised around exactly this idea, moving step by step from cell physics to lattice, core and transient calculations.

What should a simulation report contain?

A useful simulation report allows a reader to judge the evidence behind its numbers. It identifies:

  • the code and version used, and the nuclear and material data libraries;
  • the model geometry, input data and key assumptions;
  • convergence checks and estimated numerical error;
  • the validation cases relevant to the application, and how closely they match its conditions;
  • uncertainty estimates for the reported quantities;
  • which outputs have been compared with measurements, and the range of conditions those comparisons cover.

Keeping a complete record of inputs and versions also makes results reproducible, which allows independent reviewers to repeat and check the work.

How much evidence is enough?

The required level of evidence scales with the consequences of a decision, an idea often called a graded approach.

  • Early design screening compares many options quickly. Approximate models with moderate uncertainty are adequate when the aim is to rank designs and discard weak ones.
  • Experiment planning needs enough accuracy to choose meaningful test conditions and instrumentation.
  • Licensing analysis sets safety limits and demonstrates margins, and calls for comprehensive verification, validation across the full operating range, rigorous uncertainty analysis and independent regulatory review.
The level of evidence should match the decision being made.