When an aviation accident occurs, the explanation often sounds familiar:...
Read MoreNormalisation of Deviation: How Unsafe Practices Become Normal Before They Become Fatal
The Concept
In 1996, sociologist Diane Vaughan published ‘The Challenger Launch Decision’ — a study of how NASA decided to launch the Space Shuttle Challenger on 28 January 1986 despite documented concerns about the O-ring performance at low temperatures. Her central finding was that the decision was not the product of incompetence, negligence, or corporate malfeasance. It was the product of a process she called normalisation of deviation: the gradual, incremental acceptance of a departure from designed standards as normal, because each previous departure had not produced a catastrophic consequence.
The O-rings had shown distress on previous flights. The distress had been documented. The documentation had been assessed. Each time, the vehicle had survived. Each survival reinforced the belief that the distress was within acceptable limits — even as the limits were being redefined by each new data point. By the time of the Challenger launch, what had begun as an unacceptable anomaly had become an expected operational condition.
Vaughan’s framework applies with equal force to Aloha Airlines 243 (corrosion normalised), Alaska Airlines 261 (maintenance interval extensions normalised), Colgan Air 3407 (pilot commuting fatigue normalised), and the Boeing 737 MAX certification (MCAS severity assessment normalised). Normalisation of deviation is one of the most common root causes in major aviation accidents — and one of the most difficult to detect because, by definition, it looks normal.
Normalisation of deviation does not happen dramatically. It happens incrementally, invisibly, through a series of decisions each of which appears reasonable given the organisation’s recent experience. It is detected only in retrospect — usually after the deviation has produced its consequence.
How It Develops
Normalisation of deviation typically follows a predictable pattern. A deviation from a design standard occurs — a component performs slightly below specification, a procedure is abbreviated, a maintenance interval is extended. The system survives. The deviation is documented.
The next time the same deviation occurs, it is assessed against the organisation’s recent experience rather than against the original design standard. ‘This happened before and we were fine’ becomes the risk assessment criterion. The deviation is accepted at a slightly higher level. The system survives again.
Over time, the accumulation of accepted deviations moves the organisation’s operational practice progressively further from its design basis — while the organisation continues to believe it is operating within safe limits. The design limit has not moved. The practice has. And the gap between them has grown to the point where the next increment is the one that reaches the catastrophic threshold.
Detection and Prevention
Detecting normalisation of deviation requires comparing current practice against the original standard — not against recent practice. This is the function of safety audits and independent safety oversight: to provide a reference point external to the organisation’s own recent experience.
Safety Management Systems that include trend analysis of maintenance findings, safety reports, and operational deviations — comparing trend lines against baseline standards rather than against the previous period — are structurally better at detecting normalisation than systems that only assess current performance against recent history.
The most powerful cultural intervention is naming the mechanism: an organisation whose people know what normalisation of deviation is, and can recognise it in their own practice, has a meaningful defence against it. Vaughan’s concept was developed from one accident. Its application across the accident record has made it one of aviation safety’s most important analytical tools.
Key Takeaway
Normalisation of deviation is the safety drift mechanism — the process by which organisations move progressively away from their safety baseline, one accepted deviation at a time. It cannot be detected by looking at recent performance. It can only be detected by comparing current practice against the original standard.
Related Content on Aviation Risk Lab
Human Factors: https://aviationrisklab.com/human-factors/
Safety Engineering: https://aviationrisklab.com/safety-engineering/
Case Study: Columbia: https://aviationrisklab.com/case-studies/columbia-accident/
Case Study: Aloha 243: https://aviationrisklab.com/case-studies/aloha-243/
Case Study: Alaska 261: https://aviationrisklab.com/case-studies/alaska-261/
Mitigations Are Not Solutions
There is a point in most safety assessments where the...
Read MoreFrom Hazards to Risk: The Basics of Risk Understanding
If you spend any amount of time around safety engineering,...
Read MoreSwiss Cheese Model Explained (With Aviation Examples)
The Swiss Cheese Model is one of the most widely...
Read MoreSoftware vs Hardware: Assurance Levels Explained
There was a time when most aviation safety discussions were...
Read MoreHow to Do a Functional Hazard Assessment (FHA) and a Fault Tree Analysis (FTA)
Where FHA and FTA sit in safety engineering Functional Hazard...
Read MoreSafety in Design vs Operation: Where Risk Actually Lives
In aviation safety engineering, it’s easy to talk as if...
Read MoreFunctional Hazard Assessment (FHA): Mapping Intent to Failure States
Mapping System Intent to Failure States Functional Hazard Assessment...
Read MoreWhat Does “Safe Enough” Actually Mean?
When people hear the word safety, they often think of...
Read MoreSafety Engineering Fundamentals: What Actually Keeps Complex Systems Safe
Safety engineering is often treated like a compliance exercise—fill out...
Read MoreHow Risk Is Assessed in Aviation (Step-by-Step)
Risk assessment is one of the core processes in aviation...
Read More