| Vose Software

Industry: Utilities
Product: Tamara
Application: Regulatory compliance risks


80% Confidence Costs 363 Days of Contingency Beyond the Plan

A multi-region utility had to bring an existing generation and transmission fleet into line with new environmental and safety rules — a compliance-upgrade programme of assessment, retrofit design, emissions-control construction and safety upgrades, every phase gated by an external approval milestone: an environmental impact statement, air and water permits, and a final safety certification. Those gates sit on the critical chain — work cannot proceed until the regulator signs — so each is a place the schedule can simply stall, and none is under the utility's direct control. A gated programme is, in the end, a single decision: how much schedule buffer do we commit to? The orthodox plan ducked that decision, chaining most-likely durations for twelve activities into a 1,295-day, December 2029 compliance date committed to the regulator on the assumption that every approval clears first time.

Rebuild the same network in Tamara, Vose Software's Monte Carlo project risk tool, with each activity carrying a Beta-PERT duration — the regulator gates given wide, heavy-tailed ranges — and seven discrete approval-and-rework risks layered on top, and the buffer decision can be read straight off the 60,000-iteration simulation. The contingency ladder below is that decision in one chart: each rung is a confidence level, and its bar is the days of buffer beyond the 1,295-day deterministic plan that the level demands.

Contingency ladder showing schedule buffer required at each confidence level

The ladder is the planning conversation made concrete. P50 needs +252 days (an August 2030 compliance date); P80 needs +363 days (December 2030); and chasing P95 costs +473 days (April 2031). The steepening steps show how expensive the last increments of certainty are — and how indefensible the published December 2029 date is: only 2% of runs beat it.

Why a single critical-path date fails

A deterministic schedule adds most-likely durations along one chain. Two things break it here. First, the approval gates are right-skewed — a regulator can sign a little early, but a rejection or appeal adds many months — so the mean simulated finish is 1,551 days against the 1,295-day plan, with a P50 of August 2030 and a P90 of February 2031. Second, the programme is a long serial chain through three gates, and each gate's variability stacks on every activity downstream, so delays accumulate rather than average out. The contingency the ladder quantifies is the direct consequence of both effects.

Where the schedule risk actually lives — and it is the gates

On a gated programme the right driver question is not "what moves the date?" but "what is always on the path?" Tamara's criticality index — the fraction of runs in which each activity lands on the critical path — answers it, and the answer is unambiguous.

Schedule tornado ranking activities by criticality index

The serial gated spine is unavoidable: the environmental impact study, EIS approval, retrofit construction and the safety-certification gate all sit on the critical path in 100% of runs — alongside compliance retrofit design, testing and the final sign-off, every one of them at 100%. The gates are not slack between work packages — they are the work that determines the finish, which is why pre-application engagement to make the gates predictable is the highest-leverage move available.

How much each gate stretches the schedule

The same simulation places every activity in time as a band, not a bar. The whiskers span each activity's P10-to-P90 finish, and at the regulator gates they fan out badly.

Stochastic Gantt showing each activity P50 bar with P10 to P90 finish spread

EIS approval finishes at a P50 of 419 days with a 192-day spread (333–525). Permit approval reaches a P50 of 908 days, a 279-day spread (778–1,057). And the safety-certification gate carries a 328-day spread (P50 1,496, range 1,340–1,667) — the single widest source of finish uncertainty in the programme. The whiskers never narrow downstream, because the serial chain inherits the full spread of every approval before it.

Schedule risk is cost risk

Every day beyond the deterministic plan carries continued-non-compliance carry and programme overhead (~$0.07M/day), so cost and schedule overrun together. Tamara renders the two as a joint density: finish date against total cost, with the 1,295-day plan and the $115M budget as quadrant lines.

Joint density of programme cost versus compliance date with plan and budget quadrant lines

The cost distribution runs a mean of $107M and a P90 of $122M, with a 24% probability of breaching the $115M budget, and 24% of all runs fall in the late-AND-over-budget quadrant. The upward tilt is the non-compliance carry: the runs that stall at a gate are the same runs that blow the budget, which is exactly why making the gates predictable is the cheapest way to protect both the date and the cost.

The discrete risks that drive the tail

Beyond continuous duration uncertainty, seven discrete events were modelled as Bernoulli risks — each may or may not occur, but if it does it adds delay and cost. Ranking them by expected schedule impact (probability × delay) gives a clean Pareto:

Pareto of discrete risk events by expected schedule impact

Five of the seven events carry ~80% of the expected discrete-event delay — an EIS rejection and resubmission (5.3 weeks expected), a permit condition or appeal (4.6), a control-equipment supply delay (3.6), a rule change mid-programme (3.6) and retrofit rework or scope growth (2.7). Every one of the top three is a regulatory event, confirming the tornado and the joint density: this is an approval-risk programme before it is a construction-risk programme.

What Tamara changed

  • The buffer decision was made explicit, turning "we hope to be compliant by December 2029" into a contingency table — +252 days for P50, +363 for P80, +473 for P95 — the board can actually commit to.
  • Risk-reduction effort was directed onto the regulator gates — on the critical path in 100% of runs and the widest single source of finish spread — through pre-application engagement, rather than onto construction the utility already controls.
  • Cost and schedule were managed as one coupled risk, with a 24% budget-breach probability shown to live in the same gate-stall runs as the schedule overrun.
  • The discrete-risk budget was aimed at approval events, the top three of which are regulatory and carry most of the expected delay.

Tamara Functionality Used

  • Monte Carlo schedule simulation over the full gated activity network, with Beta-PERT durations and wide, heavy-tailed approval gates.
  • Contingency-ladder analysis converting each confidence level into the days of buffer beyond the deterministic plan, as a decision table.
  • Criticality-index analysis identifying the activities — here the regulator gates — that sit on the critical path in every run.
  • Stochastic Gantt quantifying the P10–P90 finish spread each gate injects into the schedule.
  • Integrated cost–schedule modelling rendered as a joint density, linking compliance-date overruns to non-compliance carry so the coupled tail is visible.
  • Discrete risk-event modelling (Bernoulli occurrence × Triangular impact), including EIS rejection, appeals and rule-change risks.

A compliance date is not a milestone the utility sets; on a gated programme it is a distribution shaped largely by approvals it does not control. Tamara turns "when are we compliant?" into a buffer the board can commit to — and shows that the cheapest way to pull the date in is to make the regulator gates predictable, not to push harder on the construction.