Despite their huge diversity, each organizational accident has at least three common features: hazards, failed defences, and losses (damage to people, assets and the environment). Of these, the most promising for effective prevention are the failed defences. Defences, barriers, safeguards, and controls exist at many levels of the system and take a large variety of forms. But each defence serves one or more of the following functions:
• to create understanding and awareness of the local hazards;
• to give guidance on how to operate safely;
• to provide alarms and warnings when danger is imminent;
• to interpose barriers between the hazards and the potential losses;
• to restore the system to a safe state after an event;
• to contain and eliminate the hazards should they escape the barriers and controls;
• to provide the means of escape and rescue should the defences fail catastrophically.
These ‘defences-in-depth’ make complex technological systems, such as nuclear power plants and transport systems, largely proof against single failures, either human or technical. But no defence is perfect. Each one contains weaknesses, flaws and gaps, or is liable to absences. Bad events happen when these holes or weaknesses ‘line up’ to permit a trajectory of accident opportunity to bring hazards into damaging contact with people and/or assets. This concatenation of failures is represented diagrammatically by the Swiss cheese model – to be reconsidered later.
Source: Organizational Accidents Revisited, Reason, 2016
