| Vose Software

Industry: Aerospace
Product: Tamara
Application: Aircraft design risk assessment


The Plan Promised First Aircraft in Mid-2032. The Simulation Gives That Date a 6% Chance

A next-generation commercial-aircraft programme was scheduled the orthodox way: eleven major development activities — concept through certification and production ramp — each with a most-likely duration, chained through the network and read off the end. The number that came back was 2,320 working days (about six and a half years), a clean mid-2032 first-article delivery the manufacturer took to its board and its launch customer. On its own terms the date was defensible. It was simply the answer to the one question a clean-sheet aircraft schedule should never be asked — what happens if every activity lands exactly on its most-likely duration, the engine arrives on time, the composite cures first pass, and nothing fails on the rig?

Rebuild the same programme in Tamara, Vose Software's Monte Carlo project risk tool, with each activity carrying a Beta-PERT duration and six discrete risk events layered on top, and the single date dissolves into a distribution: P50 February 2033, P90 October 2033, and a probability of delivering by the mid-2032 plan of just 6%. The S-curve below is the whole argument — the deterministic plan sits at the very foot of the curve.

Stochastic S-curve of programme completion date versus the deterministic plan

The gap between the deterministic plan and the P80 finish is 425 days — roughly 14 months. That gap is the programme's true schedule contingency, and it was invisible to the deterministic roll-up.

Why a single critical-path date fails

A bar-chart critical path adds most-likely durations along one assumed-longest chain. Two effects break it on a programme like this. First, development durations are right-skewed — flight test or certification can finish a little early but overrun badly — so the mean simulated finish is 2,593 days against the 2,320-day plan. Second, with parallel chains (wing fabrication, avionics and supplier qualification all run off detail design), whichever chain is longest in a given iteration drives the finish, so the programme inherits the worst of several paths rather than the average of one.

Where the duration risk actually lives

Tamara reports each activity's cruciality — the rank-correlation between its duration and the programme finish — turning the simulation into a prioritised action list.

Schedule tornado ranking activities by correlation with the finish date

The flight-test campaign dominates (cruciality 0.53), ahead of certification (0.47) and detail design (0.35). This is what directs contingency budget, de-risking effort and management attention: a week of certainty bought on the flight-test and certification back end is worth more than a week anywhere else on the programme.

The tornado answers how much each activity moves the finish; a second view answers which activities are reliably on the critical path to begin with — and the two questions have different answers:

Criticality scatter of each activity by critical-path frequency and impact on the finish date

Plotting criticality index (how often an activity is on the critical path) against cruciality (how much its variability moves the finish) separates two facts a bar chart conflates. First-article delivery, production ramp-up and certification each sit on the critical path in 100% of iterations — always critical — yet only certification also rises on the cruciality axis. The flight-test campaign, by contrast, leads on impact without being critical every single time. The upper-right region — high on both axes — is where contingency and de-risking belong: flight test and certification, not the always-critical but low-variability delivery tail.

The discrete risks that drive the tail

Six discrete events were modelled as Bernoulli risks — each may or may not occur, but if it does it adds delay and cost. Ranked by expected schedule impact (probability × delay):

Pareto of discrete risk events by expected schedule impact

A handful of events — engine-supplier delivery slip (4.8 weeks expected), software-certification slip (3.9), composite cure-cycle defects (3.5) and a flutter/structural redesign (3.3) — carry roughly 80% of the expected discrete-event delay. Once the ranking is visible, the risk-response budget writes itself.

Schedule risk is cost risk

Every day beyond the deterministic plan carries programme-burn and escalation overhead, so the schedule distribution drives the cost distribution. Tamara let the team price two mitigations together — a long-term engine-supply contract (the single largest discrete risk) and a flight-test de-risking package — and compare before/after on the same axis:

Programme cost distribution before and after mitigation against the budget

Without mitigation the cost distribution runs to a mean of $5.79B and a P90 of $6.50B, with a 22% probability of breaching the $6.2B budget. The mitigation package cuts the P80 finish by roughly two months and, because schedule drives cost, takes the budget-overrun probability from 22% to 14% — it buys a higher probability of finishing on-budget, which is exactly what the board is signing up to.

What Tamara changed

  • The external commitment moved from the deterministic mid-2032 date to a risk-informed P80, ending the rolling-promise cycle with the launch customer before it started.
  • A 14-month schedule contingency was quantified and funded, rather than discovered one slipped milestone at a time.
  • De-risking effort was directed at the flight-test and certification back end — the highest-cruciality activities (0.53 and 0.47) — and at the engine supplier, the largest discrete risk.
  • A mitigation package was approved on its tail-clipping effect, cutting budget-overrun probability from 22% to 14%.

Tamara Functionality Used

  • Monte Carlo schedule simulation over the full activity network, with Beta-PERT durations and parallel-path logic.
  • Discrete risk-event modelling (Bernoulli occurrence × Triangular impact) layered onto task durations and costs.
  • Criticality and cruciality analysis plotting how often an activity is critical against how much its variability moves the programme finish, so the two are never confused.
  • Cumulative S-curve for communicating schedule uncertainty to executives and the launch customer.
  • Integrated cost–schedule modelling linking finish-date overruns to programme-overhead cost, so mitigations are priced on their joint effect.
  • Scenario comparison quantifying the engine-supply contract and flight-test de-risking mitigations' before/after impact on the P80 finish and the budget-overrun probability.

A clean-sheet aircraft schedule is not a date; it is a distribution with a body the programme can plan against and a tail it cannot afford to ignore. Tamara is what turns "when does the first aircraft fly?" into a probability the manufacturer, the board and the launch customer can all sign.