There is a point in most safety assessments where the...
Read MoreJames Reason's Swiss Cheese Model: The Most Important Safety Framework You Need to Know
The Model and Its Origins
In 1990, British psychologist James Reason published ‘Human Error’ — a book that introduced a framework for understanding accidents that has since become the most widely used model in aviation safety, healthcare, nuclear power, and industrial safety worldwide. The Swiss Cheese Model — named for the visual representation Reason used — describes how accidents occur in complex, defended systems.
The model is deceptively simple. Imagine a system with multiple layers of defence — procedures, training, equipment, redundancy, supervision. Each layer can be represented as a slice of Swiss cheese: mostly solid (protection) but with holes (weaknesses, gaps, failures). In normal operation, the holes in different layers do not align — a hazard penetrating one layer is stopped by the next. An accident occurs when the holes align — when a specific combination of failures in multiple layers creates an unobstructed path from a hazardous event to a catastrophic consequence.
This visual metaphor is powerful because it captures the fundamental insight of modern accident investigation: accidents are almost never caused by a single failure. They are caused by the simultaneous alignment of multiple smaller failures, each individually insufficient to produce the accident.
The Swiss Cheese Model’s most important insight is that the last person to touch the system before an accident — the ‘active failure’ — is usually surrounded by layers of ‘latent failures’ that made the active failure both more likely and less catchable. Fixing the person without fixing the latent conditions is not safety improvement.
Active Failures and Latent Conditions
Reason distinguished between two types of failure in his model. Active failures are the immediate, visible actions or omissions that contribute directly to an accident — the captain who begins the takeoff roll, the engineer who installs the wrong bolt, the crew who continues an unstabilised approach. These are the failures that investigations most easily identify and that blame most naturally attaches to.
Latent conditions are the pre-existing vulnerabilities in the system — the design flaws, the inadequate procedures, the time pressures, the organisational cultures, the regulatory gaps — that have been present for years before the accident and that shaped the environment in which the active failure occurred. Latent conditions are the holes in the deeper cheese slices. They are created by designers, managers, and regulators long before any specific accident.
The distinction matters for safety improvement. Addressing only active failures — disciplining the captain, retraining the engineer, requiring the crew to go around — does not close the holes in the deeper layers. The latent conditions remain. A different person will encounter them in different circumstances and produce a different active failure with the same underlying cause.
The Model in Aviation
The Swiss Cheese Model maps directly onto the structure of every major aviation accident investigation. Tenerife’s active failures — the captain’s departure without clearance, the radio transmission, the heterodyne squeal — rested on latent conditions including inadequate phraseology standards, no ground radar, no stop bars, and a training culture that made crew challenge impermissible.
The NTSB and AAIB use the model’s logic explicitly in their accident reports — tracing the ‘accident sequence’ back through multiple contributing factors to the systemic and organisational conditions that made the accident predictable. The goal is not to find the last person who touched the system, but to find all the holes that aligned.
Limitations and Evolution
The Swiss Cheese Model has been criticised for presenting a somewhat linear and passive view of system failure — as if defences simply have holes rather than actively interacting with each other. Researchers including Nancy Leveson (STAMP/STPA) and Erik Hollnagel (FRAM) have developed more dynamic frameworks that better represent the complex, emergent nature of modern sociotechnical systems.
These newer models are valuable — particularly for complex software-intensive systems like modern avionics. But the Swiss Cheese Model remains the most widely understood and operationally applicable safety framework available. Its language — active failures, latent conditions, defence layers, accident trajectories — is the shared vocabulary of aviation safety investigation worldwide.
Key Takeaway
The Swiss Cheese Model tells every aviation professional what accidents are not: they are not the product of a single person’s single error. They are the product of multiple aligned failures across multiple system layers — and the obligation is to find all the holes, close as many as possible, and ensure that those which remain do not align.
Related Content on Aviation Risk Lab
Human Factors: https://aviationrisklab.com/human-factors/
Safety Engineering: https://aviationrisklab.com/safety-engineering/
Systems Engineering: https://aviationrisklab.com/systems-engineering/
Case Study: Tenerife 1977: https://aviationrisklab.com/case-studies/tenerife-1977/
From Hazards to Risk: The Basics of Risk Understanding
If you spend any amount of time around safety engineering,...
Read MoreSafety in Design vs Operation: Where Risk Actually Lives
In aviation safety engineering, it’s easy to talk as if...
Read MoreHow Risk Is Assessed in Aviation (Step-by-Step)
Risk assessment is one of the core processes in aviation...
Read MoreSwiss Cheese Model Explained (With Aviation Examples)
The Swiss Cheese Model is one of the most widely...
Read MoreFunctional Hazard Assessment (FHA): Mapping Intent to Failure States
Mapping System Intent to Failure States Functional Hazard Assessment...
Read MoreWhy Aviation Accidents Happen (Human Error vs System Failure)
When an aviation accident occurs, the explanation often sounds familiar:...
Read MoreHow to Do a Functional Hazard Assessment (FHA) and a Fault Tree Analysis (FTA)
Where FHA and FTA sit in safety engineering Functional Hazard...
Read MoreWhat Does “Safe Enough” Actually Mean?
When people hear the word safety, they often think of...
Read MoreSoftware vs Hardware: Assurance Levels Explained
There was a time when most aviation safety discussions were...
Read MoreSafety Engineering Fundamentals: What Actually Keeps Complex Systems Safe
Safety engineering is often treated like a compliance exercise—fill out...
Read More