Industry: Aerospace Product: Tamara Application: Aircraft design risk assessment
A next-generation commercial-aircraft programme was scheduled the orthodox way: eleven major development activities — concept through certification and production ramp — each with a most-likely duration, chained through the network and read off the end. The number that came back was 2,320 working days (about six and a half years), a clean mid-2032 first-article delivery the manufacturer took to its board and its launch customer. On its own terms the date was defensible. It was simply the answer to the one question a clean-sheet aircraft schedule should never be asked — what happens if every activity lands exactly on its most-likely duration, the engine arrives on time, the composite cures first pass, and nothing fails on the rig?
Rebuild the same programme in Tamara, Vose Software's Monte Carlo project risk tool, with each activity carrying a Beta-PERT duration and six discrete risk events layered on top, and the single date dissolves into a distribution: P50 February 2033, P90 October 2033, and a probability of delivering by the mid-2032 plan of just 6%. The S-curve below is the whole argument — the deterministic plan sits at the very foot of the curve.
The gap between the deterministic plan and the P80 finish is 425 days — roughly 14 months. That gap is the programme's true schedule contingency, and it was invisible to the deterministic roll-up.
A bar-chart critical path adds most-likely durations along one assumed-longest chain. Two effects break it on a programme like this. First, development durations are right-skewed — flight test or certification can finish a little early but overrun badly — so the mean simulated finish is 2,593 days against the 2,320-day plan. Second, with parallel chains (wing fabrication, avionics and supplier qualification all run off detail design), whichever chain is longest in a given iteration drives the finish, so the programme inherits the worst of several paths rather than the average of one.
Tamara reports each activity's cruciality — the rank-correlation between its duration and the programme finish — turning the simulation into a prioritised action list.
The flight-test campaign dominates (cruciality 0.53), ahead of certification (0.47) and detail design (0.35). This is what directs contingency budget, de-risking effort and management attention: a week of certainty bought on the flight-test and certification back end is worth more than a week anywhere else on the programme.
The tornado answers how much each activity moves the finish; a second view answers which activities are reliably on the critical path to begin with — and the two questions have different answers:
Plotting criticality index (how often an activity is on the critical path) against cruciality (how much its variability moves the finish) separates two facts a bar chart conflates. First-article delivery, production ramp-up and certification each sit on the critical path in 100% of iterations — always critical — yet only certification also rises on the cruciality axis. The flight-test campaign, by contrast, leads on impact without being critical every single time. The upper-right region — high on both axes — is where contingency and de-risking belong: flight test and certification, not the always-critical but low-variability delivery tail.
Six discrete events were modelled as Bernoulli risks — each may or may not occur, but if it does it adds delay and cost. Ranked by expected schedule impact (probability × delay):
A handful of events — engine-supplier delivery slip (4.8 weeks expected), software-certification slip (3.9), composite cure-cycle defects (3.5) and a flutter/structural redesign (3.3) — carry roughly 80% of the expected discrete-event delay. Once the ranking is visible, the risk-response budget writes itself.
Every day beyond the deterministic plan carries programme-burn and escalation overhead, so the schedule distribution drives the cost distribution. Tamara let the team price two mitigations together — a long-term engine-supply contract (the single largest discrete risk) and a flight-test de-risking package — and compare before/after on the same axis:
Without mitigation the cost distribution runs to a mean of $5.79B and a P90 of $6.50B, with a 22% probability of breaching the $6.2B budget. The mitigation package cuts the P80 finish by roughly two months and, because schedule drives cost, takes the budget-overrun probability from 22% to 14% — it buys a higher probability of finishing on-budget, which is exactly what the board is signing up to.
A clean-sheet aircraft schedule is not a date; it is a distribution with a body the programme can plan against and a tail it cannot afford to ignore. Tamara is what turns "when does the first aircraft fly?" into a probability the manufacturer, the board and the launch customer can all sign.