Dr. Sidney Dekker (Ph.D. in Cognitive Systems Engineering) states there are basically two (2) ways of looking at human error. In this article, I share with you, the first view, which could be called “the bad apple theory“. It maintains that:
- Complex systems would be fine, were it not for the erratic behavior of some unreliable people (bad apples) in it;
- Human errors cause accidents: humans are the dominant contributor to more than two-thirds of them;
- Failures come as unpleasant surprises. They are unexpected and do not belong in the system. Failures are introduced to the system only through the inherent unreliability of people
| The OLD view of human error | The NEW view of human error |
|
|
From his Bad Apples Theory
“Each debate about error reveals two (2) possibilities. Error is either the result of a bad apple, where disastrous outcomes could have been avoided if somebody had paid a bit more attention or made a little more effort. In this view, we wonder how we can cope with the unreliability of the human element in our systems.”
Or errors are the inevitable by-product of people doing the best they can in systems that themselves contain multiple subtle vulnerabilities; systems where risks and safety threats are not always the same; systems whose conditions shift and change over time. These systems themselves are inherent contradictions between operational efficiency on the one hand and safety on the other. In this view, errors are symptoms of trouble deeper inside a system. Like debates about human error, investigations into human error mishaps face the choice. The choice between the bad apple theory in one of its many versions, or what has become known as the new view of human error.
The ultimate goal of an investigation is to learn from failure. The road towards learning—the road taken by most investigations—is paved with intentions to follow the new view. Investigators intend to find the systemic vulnerabilities behind individual errors. They want to address the error-producing conditions that, if left in place, will repeat the same basic pattern of failure. In practice, however, investigations often return disguised versions of the bad apple theory—in both findings and recommendations. They sort through the rubble of a mishap to:
- Find evidence for erratic, wrong or inappropriate behavior;
- Bring to light people’s bad decisions; inaccurate assessments; deviations from written guidance;
- Single out particularly ill-performing practitioners
Investigations often end up concluding how front-line operators failed to notice certain data, or did not adhere to procedures that appeared relevant after the fact. They recommend the demotion or retraining of particular individuals; the tightening of procedures or oversight. The reasons for regression into the bad apple theory are many.
For example:
- Resource constraints on investigations. Findings may need to be produced in a few months time, and money is limited;
- Reactions to failure, which make it difficult not to be judgmental about seemingly bad performance;
- The hindsight bias, which confuses our reality with the one that surrounded the people we investigate;
- Political distaste of deeper probing into sources of failure, which may de facto limit access to certain data or discourage certain kinds
of recommendations; - Limited human factors knowledge on part of investigators. While wanting to probe the deeper sources behind human errors, investigators may not really know where or how to look.
To protect safe systems from the vagaries of human behavior, recommendations typically propose to:
- Tighten procedures and close regulatory gaps. This reduces the bandwidth in which people operate. It leaves less room for error.
- Introduce more technology to monitor or replace human work. If machines do the work, then humans can no longer make errors
doing it. And if machines monitor human work, they can snuff out any erratic human behavior. - Make sure that defective practitioners (the bad apples) do not contribute to system breakdown again. Put them on “administrative
leave”; demote them to a lower status; educate or pressure them to behave better next time; instill some fear in them and their peers by taking them to court or reprimanding them.
In this view of human error, investigations can safely conclude with the label “human error”—by whatever name (for example: ignoring a warning light, violating a procedure). Such a conclusion and its implications supposedly get to the causes of system failure.

