Industry: Utilities Product: Tamara Application: Regulatory compliance risks
A multi-region utility had to bring an existing generation and transmission fleet into line with new environmental and safety rules — a compliance-upgrade programme of assessment, retrofit design, emissions-control construction and safety upgrades, every phase gated by an external approval milestone: an environmental impact statement, air and water permits, and a final safety certification. Those gates sit on the critical chain — work cannot proceed until the regulator signs — so each is a place the schedule can simply stall, and none is under the utility's direct control. A gated programme is, in the end, a single decision: how much schedule buffer do we commit to? The orthodox plan ducked that decision, chaining most-likely durations for twelve activities into a 1,295-day, December 2029 compliance date committed to the regulator on the assumption that every approval clears first time.
Rebuild the same network in Tamara, Vose Software's Monte Carlo project risk tool, with each activity carrying a Beta-PERT duration — the regulator gates given wide, heavy-tailed ranges — and seven discrete approval-and-rework risks layered on top, and the buffer decision can be read straight off the 60,000-iteration simulation. The contingency ladder below is that decision in one chart: each rung is a confidence level, and its bar is the days of buffer beyond the 1,295-day deterministic plan that the level demands.
The ladder is the planning conversation made concrete. P50 needs +252 days (an August 2030 compliance date); P80 needs +363 days (December 2030); and chasing P95 costs +473 days (April 2031). The steepening steps show how expensive the last increments of certainty are — and how indefensible the published December 2029 date is: only 2% of runs beat it.
A deterministic schedule adds most-likely durations along one chain. Two things break it here. First, the approval gates are right-skewed — a regulator can sign a little early, but a rejection or appeal adds many months — so the mean simulated finish is 1,551 days against the 1,295-day plan, with a P50 of August 2030 and a P90 of February 2031. Second, the programme is a long serial chain through three gates, and each gate's variability stacks on every activity downstream, so delays accumulate rather than average out. The contingency the ladder quantifies is the direct consequence of both effects.
On a gated programme the right driver question is not "what moves the date?" but "what is always on the path?" Tamara's criticality index — the fraction of runs in which each activity lands on the critical path — answers it, and the answer is unambiguous.
The serial gated spine is unavoidable: the environmental impact study, EIS approval, retrofit construction and the safety-certification gate all sit on the critical path in 100% of runs — alongside compliance retrofit design, testing and the final sign-off, every one of them at 100%. The gates are not slack between work packages — they are the work that determines the finish, which is why pre-application engagement to make the gates predictable is the highest-leverage move available.
The same simulation places every activity in time as a band, not a bar. The whiskers span each activity's P10-to-P90 finish, and at the regulator gates they fan out badly.
EIS approval finishes at a P50 of 419 days with a 192-day spread (333–525). Permit approval reaches a P50 of 908 days, a 279-day spread (778–1,057). And the safety-certification gate carries a 328-day spread (P50 1,496, range 1,340–1,667) — the single widest source of finish uncertainty in the programme. The whiskers never narrow downstream, because the serial chain inherits the full spread of every approval before it.
Every day beyond the deterministic plan carries continued-non-compliance carry and programme overhead (~$0.07M/day), so cost and schedule overrun together. Tamara renders the two as a joint density: finish date against total cost, with the 1,295-day plan and the $115M budget as quadrant lines.
The cost distribution runs a mean of $107M and a P90 of $122M, with a 24% probability of breaching the $115M budget, and 24% of all runs fall in the late-AND-over-budget quadrant. The upward tilt is the non-compliance carry: the runs that stall at a gate are the same runs that blow the budget, which is exactly why making the gates predictable is the cheapest way to protect both the date and the cost.
Beyond continuous duration uncertainty, seven discrete events were modelled as Bernoulli risks — each may or may not occur, but if it does it adds delay and cost. Ranking them by expected schedule impact (probability × delay) gives a clean Pareto:
Five of the seven events carry ~80% of the expected discrete-event delay — an EIS rejection and resubmission (5.3 weeks expected), a permit condition or appeal (4.6), a control-equipment supply delay (3.6), a rule change mid-programme (3.6) and retrofit rework or scope growth (2.7). Every one of the top three is a regulatory event, confirming the tornado and the joint density: this is an approval-risk programme before it is a construction-risk programme.
A compliance date is not a milestone the utility sets; on a gated programme it is a distribution shaped largely by approvals it does not control. Tamara turns "when are we compliant?" into a buffer the board can commit to — and shows that the cheapest way to pull the date in is to make the regulator gates predictable, not to push harder on the construction.