Risk assessment is one of the core processes in aviation...
Read MoreHistory of CRM: 1979 to Today
Three Accidents That Built a Discipline
On 27 March 1977, the deadliest accident in aviation history occurred on a fog-bound runway in Tenerife.
Two Boeing 747s were positioned at Los Rodeos Airport after being diverted from their original destination. As congestion increased and visibility deteriorated, the operation became increasingly complex. Communication became more difficult, uncertainty increased, and time pressure began to influence decisions.
The captain of KLM 4805 began his takeoff roll without receiving clearance to depart.
The most significant aspect of the accident was not simply that a clearance was misunderstood. The information needed to prevent the accident existed inside the cockpit. The first officer and flight engineer had indications that something was wrong, but the cockpit environment did not provide an effective mechanism for converting their concerns into decisive action.
The captain was highly experienced. The crew was qualified. The aircraft was serviceable.
Yet the system failed.
Five hundred and eighty-three people died.
The Tenerife accident exposed a fundamental weakness in aviation operations at the time: technical competence alone was not enough. A cockpit was not just a place where individuals performed tasks. It was a complex team environment where communication, authority, and decision-making directly influenced safety.
Two years earlier, the crew of Eastern Air Lines Flight 401 had demonstrated another form of the same problem.
On 29 December 1972, Eastern Air Lines Flight 401 was operating a Lockheed L-1011 approaching Miami International Airport. During the approach, the crew noticed that the landing gear indicator light had failed to illuminate.
The crew began troubleshooting the issue.
The captain, first officer, and flight engineer became focused on diagnosing the landing gear problem while the aircraft continued flying on autopilot. Their attention narrowed around a technical issue, and nobody remained focused on the overall state of the aircraft.
The aircraft gradually descended into the Florida Everglades.
Four qualified crew members were present. The aircraft systems were functioning. The crew was actively engaged in solving a problem.
But nobody was flying the aircraft.
One hundred and one people died.
Eastern 401 became a defining example of how a team can lose situational awareness when attention becomes concentrated on a single problem. The accident was not caused by a lack of skill or effort. It occurred because the cockpit lacked an effective system for managing attention, workload, and shared awareness.
Then, in December 1978, United Air Lines Flight 173 revealed another variation of the same failure.
While approaching Portland, Oregon, the crew experienced a landing gear indication problem. The captain decided to enter a holding pattern while troubleshooting the issue.
The decision was understandable. A landing gear problem required careful assessment.
However, as the troubleshooting continued, fuel became the dominant threat. The first officer and flight engineer recognised the declining fuel state and communicated their concerns multiple times.
Their information was accurate.
Their warnings were factual.
But the communication was not strong enough to change the decision-making process.
The aircraft eventually ran out of fuel and crashed.
Ten people died.
Three Accidents. One Common Failure
These three accidents had different immediate causes.
Tenerife involved a runway collision.
Eastern 401 involved loss of situational awareness.
United 173 involved fuel exhaustion.
However, viewed through a system safety lens, they revealed the same underlying weakness.
Critical information existed, but the system failed to ensure that information influenced the final decision.
This was not simply a problem of individual human error.
It was a design problem.
The flight deck hierarchy was clear: the captain was responsible and had final authority. However, the aviation system had not yet developed effective methods for managing that authority.
The challenge was not removing the captain’s authority.
The challenge was ensuring that authority was supported by the knowledge and observations of the entire crew.
The accidents showed that safety-critical systems require more than competent individuals. They require structures that allow information to move freely, decisions to be challenged, and risks to be identified before they become irreversible.
The hierarchy of the cockpit was not the problem.
The uncontrolled authority gradient was.
Tenerife, Eastern 401, and United 173 were not isolated accidents. They were different expressions of the same systemic failure:
A flight deck culture without a reliable method for transforming crew knowledge into operational action.
The aviation industry needed a new approach.
That approach became Crew Resource Management.
The 1979 NASA Workshop and the Birth of CRM
In June 1979, NASA convened a workshop at Ames Research Center titled “Resource Management on the Flightdeck.”
The workshop represented a major change in aviation safety thinking.
Until this point, many safety improvements had focused on technical reliability, aircraft design, procedures, and pilot skills. These areas remained essential, but accident investigations increasingly showed that many failures occurred not because crews lacked technical knowledge, but because teams failed to work effectively together.
The workshop examined a critical question:
How could aviation design a cockpit environment where human performance limitations were recognised and managed?
The answer was Crew Resource Management (CRM).
Initially called Cockpit Resource Management, CRM introduced the idea that the cockpit should be treated as a team system rather than a collection of individuals.
It identified several critical behaviours:
- effective communication
- leadership and authority management
- decision-making
- situational awareness
- workload management
Importantly, CRM changed the way aviation viewed these capabilities.
They were no longer considered personality traits or “soft skills.”
They were safety-critical skills that could be trained, measured, and improved.
United Airlines, working with NASA researcher Robert Helmreich and influenced by the lessons from United 173, introduced the first formal CRM training programme in 1981.
The purpose was not to weaken command authority.
The purpose was to make command more effective.
The captain remained responsible for the aircraft.
But every crew member became responsible for contributing to safety.
Six Generations of CRM
CRM has continued to evolve since its introduction. Aviation safety researchers often describe this evolution through six generations, with each stage addressing limitations identified through operational experience.
First Generation CRM
The first generation focused on changing cockpit leadership styles.
The primary concern was the authority gradient between captains and junior crew members. Training encouraged captains to become more open to input and encouraged crew members to communicate concerns more confidently.
However, early CRM focused mainly on individual behaviour rather than the wider operational system.
Second Generation CRM
The second generation expanded CRM into practical operational skills.
Training began focusing on:
- structured communication
- decision-making
- briefing techniques
- situational awareness
- workload management
CRM moved from a discussion about leadership style into a framework for improving everyday flight operations.
Third Generation CRM
The third generation integrated CRM into recurrent training and simulator exercises.
CRM was no longer a standalone classroom topic. It became part of how pilots were trained and assessed.
Crew coordination, communication, and decision-making became recognised elements of professional competence.
Fourth Generation CRM
The fourth generation introduced evidence-based approaches such as Line Operations Safety Audit (LOSA).
Instead of only examining accidents, aviation began studying normal operations to understand how crews managed threats and errors during everyday flights.
This reflected a broader safety principle:
Understanding why operations succeed is as important as understanding why they fail.
Fifth Generation CRM
The fifth generation introduced Threat and Error Management (TEM).
TEM recognised that threats and errors are unavoidable in complex systems. The goal is not to eliminate human imperfection but to ensure that threats are identified, errors are detected, and consequences are controlled.
This aligned CRM with modern safety management principles.
Sixth Generation CRM
Modern CRM is evidence-based, organisation-wide, and integrated across aviation.
It extends beyond pilots to include:
- cabin crew
- maintenance personnel
- dispatchers
- air traffic controllers
- operational teams
CRM is no longer viewed as a pilot training course.
It is an operating philosophy for managing risk in a complex aviation system.
What CRM Has Achieved
The impact of CRM is difficult to measure in isolation because aviation safety improvements have resulted from many combined efforts, including better aircraft design, improved regulations, automation, and safety management systems.
However, CRM is widely recognised as one of the most significant human factors improvements in aviation history.
The value of CRM is most visible during situations where technical challenges combine with uncertainty and time pressure.
US Airways Flight 1549, where Captain Sullenberger and First Officer Skiles successfully managed a dual engine failure after bird strike, demonstrated the importance of communication, shared awareness, and disciplined decision-making.
United Airlines Flight 232 in 1989 provided another example. After a catastrophic engine failure destroyed critical flight controls, the crew worked with a deadheading instructor pilot to develop an improvised recovery strategy. The outcome was influenced not by one individual’s actions, but by effective teamwork under extreme conditions.
Modern aviation operates with a fundamentally different cockpit culture from the one that existed in 1977.
The captain remains in command.
But command no longer means operating alone.
Crew members are trained and expected to speak up, challenge decisions, identify threats, and ensure important information reaches the person responsible for making the final decision.
That cultural transformation did not happen naturally.
It was built through lessons written in tragedy.
Key Takeaway
CRM was not created to make pilots more polite.
It was created to make aviation safer by redesigning the way authority, communication, and decision-making function inside complex operational systems.
It remains one of aviation’s most important safety developments because it recognises a fundamental truth:
Even highly skilled professionals can fail when the system around them does not support effective teamwork.
CRM continues to evolve because aviation continues to evolve. The challenge is not only preventing individual mistakes — it is designing systems where teams can detect, manage, and recover from risk before failure occurs.
Related Content on Aviation Risk Lab
Human Factors Pillar Page: https://aviationrisklab.com/human-factors/
Case Study: Tenerife 1977: https://aviationrisklab.com/case-studies/tenerife-1977/
Case Study: United 173: https://aviationrisklab.com/case-studies/united-173/
Case Study: United 232: https://aviationrisklab.com/case-studies/united-232/
Crew Resource Management: https://aviationrisklab.com/crew-resource-management/
From Hazards to Risk: The Basics of Risk Understanding
If you spend any amount of time around safety engineering,...
Read MoreSafety Engineering Fundamentals: What Actually Keeps Complex Systems Safe
Safety engineering is often treated like a compliance exercise—fill out...
Read MoreFunctional Hazard Assessment (FHA): Mapping Intent to Failure States
Mapping System Intent to Failure States Functional Hazard Assessment...
Read MoreSafety in Design vs Operation: Where Risk Actually Lives
In aviation safety engineering, it’s easy to talk as if...
Read MoreWhat Does “Safe Enough” Actually Mean?
When people hear the word safety, they often think of...
Read MoreWhy Aviation Accidents Happen (Human Error vs System Failure)
When an aviation accident occurs, the explanation often sounds familiar:...
Read MoreMitigations Are Not Solutions
There is a point in most safety assessments where the...
Read MoreSwiss Cheese Model Explained (With Aviation Examples)
The Swiss Cheese Model is one of the most widely...
Read MoreHow to Do a Functional Hazard Assessment (FHA) and a Fault Tree Analysis (FTA)
Where FHA and FTA sit in safety engineering Functional Hazard...
Read MoreSoftware vs Hardware: Assurance Levels Explained
There was a time when most aviation safety discussions were...
Read More