8.1 Error Models: Reason's Swiss Cheese Model & The SHELL Model

Key Takeaways

  • James Reason's Swiss Cheese Model shows multiple layers of defence whose shifting holes must line up for an accident trajectory to pass through.
  • Active failures are unsafe acts at the sharp end with immediate effects, while latent conditions are dormant weaknesses created earlier by decisions, design, or organisation.
  • A technician's error is an unsafe act when made, but it usually lies dormant in the aircraft as a latent condition until vibration, thermal cycling, or pressurisation triggers it.
  • The SHELL model places the human (Liveware) at the centre, with interfaces to Software, Hardware, Environment, and other Liveware.
  • A mismatch at any SHELL interface invites error, so the surrounding elements should be designed to fit human capabilities and limits.
Last updated: September 2026

8.1 Error Models: Reason's Swiss Cheese Model & The SHELL Model

In high-reliability industries such as aviation maintenance, understanding how and why human errors occur requires moving beyond the primitive assumption that accidents stem from individual negligence. Historical accident investigations consistently reveal that failures emerge from the complex interaction of biological human limitations, physical engineering interfaces, procedural documentation, and organizational decisions. To analyze these systemic vulnerabilities, aviation regulatory bodies—including the International Civil Aviation Organization (ICAO) and the European Union Aviation Safety Agency (EASA)—rely on two foundational conceptual models: Professor James Reason's Swiss Cheese Model and the SHELL Model developed by Elwyn Edwards and Frank Hawkins.

The Systems Perspective on Human Error

Traditional approaches to accident investigation operated under the person approach, which focused almost exclusively on the unsafe acts of frontline workers (forgetfulness, inattention, carelessness, or poor motivation). The remediation under the person approach typically involved blaming, retraining, or disciplining the individual. Modern aviation safety under EASA Part-145 rejects this framework in favor of the system approach. The system approach recognizes that humans are inherently fallible and that errors are to be expected even in the most qualified, disciplined professionals. Rather than viewing errors as causes, the system approach treats human errors as consequences or symptoms of deeper systemic vulnerabilities embedded within technology, workplace design, and organizational culture.

James Reason's Swiss Cheese Model

Developed by British psychologist Professor James Reason (set out in Human Error, 1990, and later drawn as slices of Swiss cheese), the Swiss Cheese Model illustrates how complex sociotechnical systems defend against failure. In an ideal operational world, safety defenses are impenetrable barriers. In reality, modern commercial aviation relies on multiple successive layers of defences-in-depth, each designed to prevent, trap, or mitigate errors. These defensive layers encompass:

  1. Organizational and administrative policies: Corporate safety policies, safety management systems (SMS), adequate staffing, and fatigue risk management.
  2. Engineering and physical interlocks: Mistake-proofing (Poka-Yoke) geometry, keyed electrical connectors, asymmetric bolt patterns, and guard covers.
  3. Procedural and documentation controls: Current Aircraft Maintenance Manuals (AMM), task cards, engineering orders, and tool calibration tracking.
  4. Personnel qualifications and training: Basic licensing standards (EASA Part-66), type ratings, human factors recurrent training, and task-specific authorizations.
  5. Supervisory oversight and quality barriers: Independent dual inspections, duplicate sign-offs, non-destructive testing (NDT), and hangar quality audits.

In Reason's model, each defensive layer is represented as a slice of Swiss cheese. The holes in the slices represent weaknesses or deficiencies within that specific defense. Crucially, these holes are not static; they continually open, close, expand, and shift position across time as operational tempo, environmental stressors, staffing levels, and commercial pressures fluctuate.

An accident or catastrophic airworthiness failure occurs only when the holes across every defensive layer momentarily align in a straight path. This alignment allows a hazard trajectory—an uninterrupted sequence of breakdowns—to penetrate all safety barriers, escalating an uncorrected error into an operational catastrophe.

Active Failures vs. Latent Conditions

A critical contribution of Reason's model is the definitive distinction between two fundamentally different types of system vulnerabilities: active failures and latent conditions.

Active Failures

Active failures are unsafe acts (slips, lapses, mistakes, or procedural violations) committed by frontline operators who are in direct physical contact with the operational system. In aviation, active failures are typically associated with flight crews, air traffic controllers, or line maintenance technicians. Characteristics of active failures include:

  • Immediate impact: The adverse consequences manifest almost instantaneously (e.g., a pilot selecting gear up instead of flaps on rollout, or an air traffic controller clearing two aircraft onto the same runway).
  • Frontline execution: They occur at the sharp end of the system where humans interact directly with machines.
  • Symptomatic nature: They are frequently the final trigger in an accident chain, rather than the root cause.

Latent Conditions

Latent conditions (originally termed latent failures) are dormant vulnerabilities, procedural defects, or management decisions embedded within the organizational and physical architecture of the system long before an active event occurs. Characteristics of latent conditions include:

  • Delayed manifestation: They may lie dormant within an organization or airframe for days, weeks, months, or even years without causing harm.
  • Origin at the blunt end: They are created by decision-makers, designers, procedure writers, software programmers, line managers, and regulatory authorities.
  • Systemic precursors: They include inadequate shift staffing, uncalibrated tooling, ambiguous AMM illustrations, poor hangar lighting, excessive overtime rostering, and conflicting commercial schedules.

Maintenance Errors as Latent Traps

In Module 9, keep the perspective clear: a technician's error is an unsafe act at the moment it is made, but for flight operations it usually behaves as a latent condition. When a technician misroutes an aileron cable, pinches an actuator O-ring, or under-torques an engine oil line B-nut, the error does not immediately cause an accident in the hangar. The aircraft is signed off with a Certificate of Release to Service (CRS) and enters revenue service. The error remains entirely dormant until exposed to an operational catalyst—such as aerodynamic buffet, thermal cycling, or high cabin pressure differentials—at which point it manifests as an active in-flight emergency.

The SHELL Model (Edwards & Hawkins)

Originally developed by Elwyn Edwards in 1972 and modified into its renowned conceptual diagram by Frank H. Hawkins in 1975 (and updated in 1987), the SHELL Model is a systems framework adopted by ICAO (Doc 9683) to analyze human performance and human-machine integration.

The acronym SHELL represents five interrelated components:

  • S: Software (rules, procedures, manuals, checklists, computer software)
  • H: Hardware (airframe structure, engines, tools, ground support equipment, avionics)
  • E: Environment (physical surroundings: temperature, lighting, noise, weather)
  • L: Liveware (Central: the human operator at the core of the system)
  • L: Liveware (Peripheral: other human beings in the operational loop)
+-------------------------------------------------------------+
|                        SOFTWARE (S)                         |
|         (AMM, Task Cards, MEL, Procedures, Regs)            |
+------------------------------+------------------------------+
|         HARDWARE (H)         |       ENVIRONMENT (E)        |
|  (Aircraft, Tools, GSE,      |   (Noise, Temp, Lighting,    |
|       Test Benches)          |     Hangar Vibration)        |
|              +---------------+---------------+              |
|              |      CENTRAL LIVEWARE (L)     |              |
|              |  (Technician Capabilities &   |              |
|              |          Limitations)         |              |
|              +---------------+---------------+              |
+------------------------------+------------------------------+
|                    PERIPHERAL LIVEWARE (L)                  |
|    (Supervisors, Colleagues, Shift Handover, Flight Crew)   |
+-------------------------------------------------------------+

Central Liveware (The Core Human Element)

At the absolute center of the SHELL model sits the human technician: Central Liveware. Unlike mechanical hardware, the human cannot be redesigned or re-manufactured to custom specifications. Central Liveware is governed by fixed biological, physiological, and psychological constraints:

  • Physical limitations: Reach envelope, physical strength, anthropometric measurements, visual acuity, and color discrimination.
  • Physiological limitations: Circadian rhythm disruptions, fatigue, oxygen requirements, dehydration, and susceptibility to environmental temperature extremes.
  • Psychological limitations: Working memory capacity (7 ± 2 chunks of information), attentional bottlenecks, sensory processing limits, cognitive biases, and emotional stress.

The foundational premise of ergonomics and human factors is that the external elements of the SHELL system must be molded and adapted to fit the central Liveware—never the reverse.

The Four Operational SHELL Interfaces

System failure occurs when there is a mismatch or friction at the boundary between the central Liveware and the surrounding components:

  1. Liveware-Hardware (L-H): This interface represents the interaction between the human technician and the physical machine, airframe components, specialized test rigs, and hand tools. Common L-H mismatches in maintenance include awkward workspace geometry forcing unnatural postures, non-ergonomic safety wire pliers causing repetitive strain injury, unreadable dial displays on test sets, or identically shaped fluid lines that permit cross-connection.
  2. Liveware-Software (L-S): This interface encompasses the human's interaction with the non-physical elements of the maintenance environment: AMMs, Illustrated Parts Catalogs (IPC), Service Bulletins (SB), job cards, computer maintenance management systems (such as AMOS or SAP), and regulatory documents. Common L-S mismatches include ambiguous step-by-step instructions, poorly translated technical documentation, font sizes too small to read under low lighting, or complex digital interfaces that invite data-entry errors during sign-off.
  3. Liveware-Environment (L-E): This interface concerns the relationship between the human technician and the internal or external physical environment. Key environmental factors include extreme ramp temperatures (-20°C winter line maintenance versus +45°C summer tarmac heat), inadequate hangar illumination (<200 lux for detailed structural inspection), high ambient acoustic noise (>85 dBA from auxiliary power units or ground run-ups), and toxic chemical vapors (e.g., Skydrol hydraulic fluid or solvent degreasers). L-E mismatches impair sensory perception, accelerate physical fatigue, and induce cognitive tunneling.
  4. Liveware-Liveware (L-L): This interface governs interpersonal relationships, teamwork, leadership, and communication between individuals across the maintenance organization. It includes technician-to-technician handovers, mechanic-to-supervisor reporting, interactions with quality assurance inspectors, and coordination with flight crews. Common L-L mismatches involve steep authority gradients discouraging junior mechanics from speaking up, unstructured shift handovers resulting in omitted steps, and conflicting interpersonal communication styles.

Comparative Analysis: Active Failures vs. Latent Conditions across SHELL

FeatureActive FailuresLatent Conditions
Primary LocationAt the sharp end (hangar floor, flightline, cockpit)At the blunt end (management, design offices, regulatory bodies)
Time Frame to ConsequenceImmediate (seconds to minutes)Delayed (days, weeks, months, or years)
Primary ActorsLicensed engineers, certifying technicians, flight crewsMaintenance planners, corporate directors, procedure authors
DetectabilityHigh immediate feedback (alarms, operational failure)Low immediate feedback; silent and dormant within system
Maintenance ExampleFitting a lock pin into the wrong hole during the taskAn outdated task card revision or long-failed hangar lights
Mitigation FocusError-trapping barriers, dual sign-offs, independent checksSystem redesign, workload balancing, cultural reform, clear AMM text

Worked Maintenance Scenario: The Thrust Reverser Latent Trap

During a scheduled night C-check on a widebody commercial transport, a dual-engine fan cowl and thrust reverser inspection was assigned to a line maintenance team. The work took place between 02:00 and 04:30 during the physiological circadian trough (L-E factor).

To lock out the thrust reverser translating cowls for maintenance access, the technician was required to insert a physical ground safety lockout pin. The operator's computerized task card (L-S factor) referenced an outdated revision of the AMM that omitted a critical warning: on this engine variant, two distinct pin holes existed—one for the operational drive unit latch and one for a structural alignment jig.

Working in a hangar bay where the primary overhead bay lights were partially inoperative (L-E factor), the technician inserted the pin into the incorrect hole by tactile feel (L-H factor). Believing the cowl was locked out, the technician proceeded with the hydraulic line inspection. When the line supervisor arrived to perform a progress check, the supervisor was distracted by a phone call regarding an imminent aircraft departure delay (L-L factor) and signed off the lockout verification box without shining a flashlight directly into the latch mechanism.

The aircraft was released to service (CRS signed). The unlatched lockout pin was an active failure that instantly transformed into a latent condition. The aircraft operated 42 successful flight sectors over 14 days without incident. On sector 43, while descending through severe turbulence, aerodynamic buffeting caused the unpinned latch to migrate. The left thrust reverser translating cowl unlocked in flight, triggering an emergency cowl-open alert in the cockpit. The flight crew declared a Mayday, throttled back the engine to idle, and executed an immediate overweight landing.

This scenario demonstrates how dynamic holes across the Swiss cheese slices—ambiguous manuals (L-S), dim lighting (L-E), confusing pinhole geometry (L-H), and rushed supervisory sign-off (L-L)—aligned to release a dormant latent hazard into revenue flight.

Exam Pitfalls / Common Traps

  • Trap 1: Getting the perspective wrong. A technician who misroutes a cable commits an unsafe act, but the defect usually lies dormant until the aircraft flies, so exam questions describe it as a latent condition for flight operations. Choose answers that stress the delay between the maintenance act and its consequence.
  • Trap 2: Believing Central Liveware can be modified to eliminate error. Exam questions often propose "retraining the technician to eliminate biological error" as a correct engineering solution. In the SHELL framework, the central Liveware has fixed physiological and cognitive limitations. Safety is achieved by redesigning Hardware, Software, and Environment to accommodate those limits, not by demanding superhuman perfection from the technician.
  • Trap 3: Restricting 'Software' in SHELL to computer software. In aviation human factors, the "S" in SHELL includes all non-physical rules, manuals, checklists, standard operating procedures, and regulatory requirements—not merely computer code.
  • Trap 4: Viewing Swiss Cheese holes as static openings. Swiss cheese holes are constantly moving and changing size depending on operational tempo, staffing shortages, circadian rhythms, and commercial pressures. They are dynamic vulnerabilities, not permanent static defects.
Loading diagram...
Reason's Swiss Cheese Model and Latent Error Trajectory
Test Your Knowledge

In James Reason's Swiss Cheese Model, why do maintenance errors usually behave as latent conditions for flight operations?

A
B
C
D
Test Your Knowledge

In the SHELL model formulated by Edwards and Hawkins, which interface is compromised when a certifying engineer misinterprets an ambiguous step in an Aircraft Maintenance Manual?

A
B
C
D
Test Your Knowledge

According to human factors principles underlying the SHELL model, what is the primary method for resolving a mismatch between the human technician and the operational system?

A
B
C
D
Test Your Knowledge

What does the alignment of holes across multiple defensive layers represent in James Reason's Swiss Cheese Model?

A
B
C
D