Why accidents are chains rather than events, what a safety system does that a careful individual cannot, and the specific habits that break the chain early.
Learn
Accidents do not have a cause
Read any accident report and the striking thing is how much had to go right — in the sense of lining up — for it to happen. Almost never is there a single failure that made the outcome inevitable. There is a sequence, typically of five to seven events, each individually survivable.
The Gimli Glider needed a conversion error, a failed indication system and a fuelling procedure that did not catch either. United 173 needed a burnt-out bulb, a captain absorbed in it, a crew who raised the fuel state indirectly, and an airline culture in which that was normal. Tenerife needed fog, a diversion, a congested apron, a non-standard instruction, a simultaneous radio transmission and an authority gradient.
This is why the useful question after an accident is not what caused it. It is: at how many points could this have been stopped, and why was it not stopped at each of them.
The same question is the useful one before a flight, which is what makes this more than an analytical framework. If an accident requires several things to align, then a flight in which two of them have already aligned is a flight that has less margin than it looks.
Explore
The Swiss cheese model
James Reason’s model, published in 1990 and now the standard framework across safety-critical industries, pictures an organisation’s defences as a series of slices of Swiss cheese standing in a row.
Each slice is a layer of protection: regulation, training, procedures, checklists, equipment, supervision, the crew themselves. Each has holes, because no defence is perfect. The holes move, as circumstances change.
An accident occurs when the holes in every slice line up at the same moment, allowing a hazard to pass through all of them. Most of the time they do not align, and the near-misses this produces are invisible — nothing happened, so nobody investigates.
The model’s important contribution is the distinction between active failures and latent conditions. An active failure is the unsafe act at the sharp end: the pilot who descended below minimums. A latent condition is the hole that was already there — the procedure that made it easy, the display that was ambiguous, the training that never covered it, the schedule that made everybody tired.
Blaming the active failure feels satisfying and prevents nothing, because the next person will meet the same latent conditions. This is why modern accident investigation spends most of its effort on the organisation and comparatively little on the individual.
Quick check
Learn
What actually kills people
Published safety studies are consistent on the ordering. In general aviation the largest category of fatal accidents is loss of control in flight — most often a stall or a spin, and most often at low altitude where recovery is not possible.
The specific circumstances repeat. The base-to-final turn, where a pilot overshoots the centreline and tightens the turn with rudder rather than going around, is a recurring scenario, and chapter four explains exactly why: the load factor in the turn raises the stall speed, and the uncoordinated input means one wing stalls first.
The engine failure after takeoff is another, and its version of the mistake is the attempted turn back to the runway from an altitude that does not permit it.
Controlled flight into terrain — a serviceable aircraft flown into the ground — was for decades a leading cause in commercial aviation. It has been reduced dramatically, and the reduction is a good example of a technical fix working: ground proximity warning systems, and later terrain awareness systems that compare position against a terrain database and warn well in advance, made a category of accident largely go away.
Mid-air collision is comparatively rare but concentrated: near airports, in good weather, in the airspace where everybody is looking at the runway rather than at each other.
And weather-related loss of control — continued VFR flight into instrument conditions — remains among the most reliably fatal categories, with a fatality rate far higher than most other accident types.
Apply
Assessing a flight before you are in it
The most widely taught framework for pre-flight risk assessment divides the flight into four areas, under the acronym PAVE.
Pilot: your own currency, experience in this aircraft and in these conditions, and the IMSAFE self-assessment from the previous chapter. Not whether you are legal — whether you are ready.
Aircraft: its airworthiness, its equipment relative to the flight you are planning, its performance at today’s weight and density altitude, and its fuel.
enVironment: weather, terrain, airspace, the airports involved, the time of day, and what the light will be doing when you arrive.
External pressures: everything that is pushing you to go. A commitment at the other end, passengers who have taken a day off, a rental booking, the cost of another night, the fact that you said you would.
The last one is listed last and is the one that does the damage. The first three are things a pilot can assess reasonably objectively. External pressure is the thing that makes a pilot assess them optimistically, and the value of writing it down is that it becomes visible as a factor rather than operating as a mood.
A flight with several yellows
- Pilot
- 3 weeks since last flight
- Aircraft
- Unfamiliar type, 4 hours on it
- Environment
- Arrival 30 min after sunset
- Environment
- Crosswind 12 kt at destination
- External
- Passengers with a morning commitment
Nothing here disqualifies the flight and no single row would give anybody pause. The point of writing them in a column is that five acceptable items are visible as a pattern in a way that five separate judgements are not. This is the whole mechanism of a written risk assessment.
Learn
The reason aviation knows so much about its own mistakes
Aviation has safety data that most industries do not, and the reason is a deliberate decision made decades ago: the people who make errors are the only reliable source of information about how errors happen, and they will not report them if reporting is punished.
The Aviation Safety Reporting System, run by NASA rather than by the regulator, accepts confidential reports from anybody in the system — pilots, controllers, cabin crew, mechanics, dispatchers. NASA de-identifies them, analyses them for patterns, and publishes the findings. It has collected well over a million reports.
A report also provides limited protection. Filing within ten days of an incident can waive a certificate suspension for an unintentional violation, provided the violation was not deliberate and did not involve a criminal offence or an accident. It is a narrow protection, deliberately: it covers the honest mistake and does not cover recklessness.
That boundary is what a just culture is. Error is reported and analysed; deliberate violation is not excused. Cultures that punish error get silence and learn nothing. Cultures that excuse everything lose the ability to hold anybody to a standard. The line between them has to be drawn explicitly, and drawing it is the hardest part of running a safety programme.
Go deeperWhat a Safety Management System actually consists of
A Safety Management System is the formalisation of everything in this chapter into an organisational process, and it has four components.
Safety policy: a stated commitment from the top of the organisation, with named accountabilities. This exists because safety programmes that are not owned by somebody with budget authority do not survive contact with commercial pressure.
Safety risk management: a process for identifying hazards, assessing the risk each presents in terms of likelihood and severity, and putting mitigations in place. This is the PAVE assessment done at organisational scale and written down.
Safety assurance: measuring whether the mitigations actually work. This is the component most often skipped, and its absence is what produces organisations with excellent safety documentation and poor safety.
Safety promotion: training, communication and the culture work that makes people use the system. A reporting system nobody trusts collects nothing.
The reason this matters to an individual pilot is that it is the same loop at a different scale. Identify what could go wrong, decide what to do about it, check afterwards whether it worked, and tell somebody what you learned.
Quick check
Apply
Breaking the chain, in practice
Everything in this course reduces to a small number of habits, and they are worth stating plainly at the end of it.
Decide in advance. Personal minimums, a duty day limit, a fuel reserve you will not go below, a decision point on the runway, a gate at which an approach must be stable. Every one of these is a decision made by a rested person who has nowhere to be, standing in for a decision that would otherwise be made by a tired person under pressure.
Notice accumulation. One yellow item is a normal flight. Three is a different flight, and the difficulty is that nobody is counting unless somebody writes them down.
Say the number. Whether to another crew member, to a controller, or to yourself — a fact has to be answered in a way that a feeling does not.
Keep the option that costs least. Fuel, altitude, daylight and runway are all the same commodity: they are decision time, they can only be acquired before you need them, and every one of them is bought on the ground.
And report. The single most valuable thing an individual pilot contributes to aviation safety is not flying carefully. It is telling the system what nearly happened, so that the hole in the slice can be found by somebody other than the next person to fall through it.
Explain it
Read by ATLAS
Aviation is remarkably safe, yet the people flying the aircraft are no more careful than people in other professions. Explain how that is possible.
Write it the way you would explain it to someone in the year below you. There is no score and no limit on attempts.
Mission scenario
Six small decisions
You are a private pilot with 310 hours and an instrument rating you earned fourteen months ago. You have flown 4 hours in the last 90 days, none of it in actual instrument conditions.
You are flying three friends from a weekend away back home — 230 nautical miles in a Piper Saratoga you have flown for two years. They all have work in the morning; one has a flight to catch at 07:00.
It is Sunday, 16:15. Sunset is at 17:52. The weather along the route is broken cloud at 3,000 with 6 miles visibility, forecast to lower after dark.
This mission is about noticing links as they form, rather than about any single decision.
Decisions stand. You will not be able to change one once it is made — fly the mission again if you want to try a different route.
Decision 01
Preflight. Your risk assessment: three weeks since your last flight, 4 hours in 90 days, no recent actual instrument time, arrival after dark, weather forecast to lower, three passengers with morning commitments.
The aircraft is airworthy and fully fuelled. The flight is legal in every respect — you are instrument current on paper, having done an approach check ride eleven months ago and six approaches in a simulator last month.
How do you read the assessment?
Chapter complete
What you now understand
- You can explain why an accident is a chain rather than an event, and why the useful question is where it could have been broken rather than what caused it.
- You can describe the Swiss cheese model and distinguish an active failure from a latent condition — and say why fixing only the active failure prevents nothing.
- You know the accident categories that dominate the statistics, why loss of control leads in general aviation, and how controlled flight into terrain was largely engineered away.
- You can run a structured pre-flight risk assessment, and you know why external pressure is the item that distorts the other three.
- You understand what a just culture is, why confidential reporting produces data that punishment cannot, and where the line between error and violation is drawn.