The “Swiss-Cheese” Model (Professor James Reason)

The Swiss Cheese Model Professor James Reason

The “Swiss-Cheese” Model, developed by Professor James Reason, illustrates that accidents involve successive breaches of multiple system defenses. These breaches can be triggered by a number of enabling factors such as equipment failures or operational errors. Since the Swiss-Cheese Model contends that complex systems are extremely well defended by layers of defenses, single-point failures are rarely consequential in such systems. Breaches in safety defenses can be a delayed consequence of decisions made at the highest levels of the system, which may remain dormant until their effects or damaging potential are activated by specific operational circumstances. Under such specific circumstances, human failures or active failures at the operational level act to breach the system’s inherent safety defenses.

The Reason Model proposes that ALL accidents include a combination of both active and latent conditions.

Active failures are actions or inactions, including errors and violations, which have an immediate adverse effect. They are generally viewed, with the benefit of hindsight, as unsafe acts. Active failures are generally associated with front-line personnel and may result in a harmful outcome.

Latent conditions are those that exist well before a consequence is experienced. The consequences of latent conditions may remain dormant for a long time. Initially, these latent conditions are not perceived as harmful but will become evident once the system’s defenses have been breached. These conditions are generally created by people far removed in time and space from the event. Latent conditions in the system may include those created by

  • a lack of safety culture,
  • poor equipment or procedural design,
  • conflicting organizational goals,
  • defective organizational systems or management decisions

The perspective underlying the organizational accident aims to identify and mitigate these latent conditions on a system-wide basis rather than through localized efforts to minimize active failures by individuals.

This image illustrates that various defenses are built into a safety management system to protect against fluctuations in human performance or decisions at all system levels. While these defenses act to protect against the risks, breaches that penetrate all defensive barriers may potentially result in a catastrophic situation. Additionally, Reason’s Model represents how latent conditions are present within the system BEFORE the accident and can manifest through local triggering factors.

 

The Swiss Cheese Model Professor James Reason

The notion of the organizational accident underlying Reason’s Model can be best understood through a building-block approach consisting of five (5) blocks.

The top block represents the organizational processes. These are activities over which any organization has a reasonable degree of direct control. Typical examples include:

  • policy-making,
  • planning,
  • communication,
  • allocation of resources, and
  • supervision

Unquestionably, the two (2) FUNDAMENTAL organizational processes regarding safety are allocation of resources and communication. Downsides or deficiencies in these organizational processes are the breeding grounds for a dual pathway towards failure.

The Organizational Accident Professor James Reason

 

One pathway is the latent conditions pathway. Examples of latent conditions may include deficiencies in

  • equipment design,
  • incomplete/incorrect standard operating procedures and
  • training deficiencies

In generic terms, latent conditions can be grouped into two large clusters. One cluster is inadequate hazard identification and risk management, whereby the risks and consequences of hazards are not kept under control but roam freely in the system to become active through operational triggers eventually.

The second cluster is known as the NORMALIZATION OF DEVIANCE, a notion that simply put, is indicative of operational contexts where the exception becomes the rule. The allocation of resources in this case is flawed to the extreme. As a consequence of the lack of resources, the only way that operational personnel who are directly
responsible for the actual performance of the production activities can successfully achieve these activities by adopting shortcuts that involve ROUTINE violation of the rules and procedures.

Latent conditions have the potential to breach system defenses. Typically, defenses in aviation can be grouped under three large headings: technology, training, and regulations. Defenses are usually the last safety net to contain latent conditions, as well as the consequences of lapses in human performance. Most, if not all, mitigation strategies against the risks of the consequences of hazards are based upon the strengthening of existing defenses or the development of new ones.

The other pathway originating from organizational processes is the workplace conditions pathway.  Workplace conditions are factors that directly influence the efficiency of people in aviation workplaces. Workplace conditions are largely intuitive in that all those with operational experience have experienced them to varying degrees, including

  • workforce stability
  • qualifications and experience
  • morale
  • management credibility, and
  • traditional ergonomics factors such as
    • lighting
    • heating and cooling

Less-than-optimum workplace conditions foster active failures by operational personnel. Active failures can be considered as either errors or violations.

James Reason Human Failure Model Flowchart 2023

 

The difference between errors and violations is the MOTIVATIONAL COMPONENT.

  • A person trying to do the best possible to accomplish a task, following the rules and procedures as per the training received, but failing to meet the objective of the task at hand commits an error.
  • While accomplishing a task, a person willingly deviates from rules, procedures, or training received commits a violation.

Thus, the fundamental difference between errors and violations is INTENT.

From the perspective of the organizational accident, safety endeavors should monitor organizational processes to identify latent conditions and thus reinforce defenses.

Safety endeavors should also improve workplace conditions to contain active failures because it is the combination of all these factors that produces safety breakdowns.

 

A practical drift from baseline performance to operational performance is foreseeable in any system, no matter how careful and well-thought-out its design planning may have been. Some of the reasons for the practical drift may include:

  • technology that does not always operate as predicted
  • procedures that cannot be executed as planned under certain operational conditions
  • regulations that are not applicable within certain contextual limitations
  • introduction of changes to the system, including the addition of new components
  • the interaction with other systems

The fact remains, however, that, despite all the system’s shortcomings leading to the drift, people operating inside the practical drift make the system work on a daily basis, applying local adaptations (or workarounds) and personal strategies “beyond what the book says.” As explained in the image below, capturing and analyzing the information on what takes place within the practical drift holds CONSIDERABLE LEARNING POTENTIAL about successful safety adaptations and, therefore, for the control and mitigation of risks. The closer to the beginning of the practical drift that the information can be systematically captured, the greater the number of hazards and safety risks that can be predicted and addressed, leading to formal interventions for re-design of or improvements to the system. However, the unchecked proliferation of local adaptations and personal strategies may lead the practical drift to depart too far from the expected baseline performance to the extent that an incident or an accident becomes a greater possibility.

The Practical Drift Scott Snook

 

Sources:

Organizational Accidents Revisited, James Reason, 2016

MANAGING THE RISKS OF ORGANIZATIONAL ACCIDENTS, James Reason, 1997

Doc 9859, AN/474, IACO, 2013

Friendly Fire, Scott Snook, 2000

Scroll to Top