Human Error and Accident Causation
Human error is an action, decision or omission that departs from what was intended or required, when the departure cannot be put down to chance. In aviation it is studied through error types, the levels of behaviour at which errors occur, and models that show how active failures and latent conditions combine into accidents.
Pilots are selected, trained, checked and supported by procedures, yet they still make errors, because error is part of normal human performance rather than a mark of incompetence. About 70 % of aviation accidents are commonly attributed to human error, a figure that has driven the spread of automation. The modern approach to safety no longer stops at who made the error. It asks why the error was made, why the defences did not catch it, and what in the system can be changed.
This article covers the models examined in the EASA Human Performance and Limitations syllabus and used in threat and error management and safety management systems: the types of error and violation, Rasmussen's skill, rule and knowledge levels, the error chain, and James Reason's Swiss cheese model of active failures and latent conditions.
Human error and human reliability
Human error is an action or decision, or a failure to act, that departs from what was intended or required, when the departure cannot be put down to chance. Errors have internal causes, such as mistaken perception, misinterpretation, preconceived assumptions, faulty memory, fatigue and lack of practice, and external causes, such as stressors, poor ergonomics, economic pressure and the social environment.
Human reliability is the other side of the same coin: the probability that a person performs a task correctly. Studies of simple, repetitive tasks show a baseline error rate of about once in 100 attempts, and the rate rises quickly with stress, fatigue and low morale. Practice can improve reliability by orders of magnitude but never to perfection; Frank Hawkins suggested that one error in 1,000 might be "pretty good" in most circumstances. A system that depends on a human never making an error will therefore fail.
Errors of omission and commission
The simplest classification looks at the act itself. An error of omission is leaving out something that should have been done: a checklist item skipped, a frequency not changed, a call not made. Omissions are typical of well-practised, highly automatic tasks such as reading a checklist, and are strongly associated with unexpected interruptions, which break the practised sequence.
An error of commission is doing something incorrectly, or doing something that should not have been done. EASA texts describe a particular form, the response error. A pilot who expects a stimulus and has prepared a response may, under pressure, trigger that response on an unexpected stimulus: a pilot primed for an engine shutdown drill shuts down an engine at the noise of a falling tray. Preparing decisions in advance remains the best guard against time pressure; the defence against the response error is to confirm the stimulus before acting on it.
Slips, lapses, mistakes and violations
Following Reason, unsafe acts are classified by what failed:
| Type | What failed | Example | Main defences |
|---|---|---|---|
| Slip | Attention in execution: right intention, wrong action | Selecting the landing light instead of the adjacent fuel pump switch | Look-and-touch, standard layouts, checklists |
| Lapse | Memory: a planned step is forgotten | A fuel tank change missed after an interruption | Checklists, flows, protected critical phases |
| Mistake | Planning: the action matched the intention, but the intention was wrong | A route planned through cloud after misreading an icing forecast | Knowledge, briefing, cross-checking, a second opinion |
| Violation | Choice: a deliberate departure from a rule or procedure | Skipping a required mass and balance calculation because it "always works out" | Workable SOPs, supervision, safety culture |
Some textbooks call mistakes "faults" and lapses "omissions". The classification depends on the intention, not on the outcome: a slip with serious consequences is still a slip. Slips and lapses are failures of execution within a sound plan, typical of routine, highly practised tasks. Mistakes are errors of intention, where the knowledge or the assessment behind the plan was faulty.
Violations differ in kind because the departure is deliberate, even though harm is not intended; the difference from slips and lapses is intent. Routine violations are habitual shortcuts that have become the local norm, persisting because they usually work and save effort. Situational violations arise when circumstances make compliance difficult, for example time pressure, unworkable procedures or missing equipment. Exceptional violations are rare, one-off departures in unusual circumstances. A deliberate act meant to cause harm is sabotage and lies outside the error taxonomy. Because a peer group that does not comply soon overrides an instruction to an individual, violations are countered at organisational level, through workable procedures, supervision and safety culture, rather than by better technique.

Rasmussen's skill, rule and knowledge model
Jens Rasmussen's SRK model describes three levels at which people control their actions. It is well suited to explaining how pilots learn and why errors change with experience.
- Skill-based behaviour runs on stored routines, or motor programmes, learned by practice and repetition and carried out without conscious thought. Its errors are action slips and environmental capture. Skill-based errors occur only in experienced people, since a novice has to think about every action, and they become more likely when the pilot is preoccupied, tired or relaxed by easy conditions.
- Rule-based behaviour applies a learned procedure, such as an engine fire drill or an instrument approach. Unlike a skill it always needs a conscious decision to start. It is generally robust, and standard procedures let each crew member monitor the others. Its most common error is one of commission after an initial misidentification of the problem: an aural warning prompts a depressurisation drill when the real fault is a propeller overspeed.
- Knowledge-based behaviour is needed when no procedure has been learned. The pilot must evaluate the information and design a plan from knowledge and experience. It is slow and effortful, and the error rate rises sharply. Its errors come from incomplete or inaccurate mental models, overconfidence, loss of situational awareness, confirmation bias and frequency bias (see cognitive biases). Recognising that one has been forced to this level is itself a cue to slow the situation down: climb, hold, delay the decision and use every source of help.
The Kegworth accident of 8 January 1989 shows how the levels interact. After a fan blade failed in the left engine of a British Midland Boeing 737-400, the crew shut down the healthy right engine. The UK AAIB found that the combination of heavy vibration, noise, shuddering and a smell of fire was outside the crew's training and experience, which in SRK terms is the territory of knowledge-based behaviour, and that they reacted prematurely, before assimilating the engine instruments. The commander later explained his choice with reasoning about the air conditioning that held for types he had flown before but not for the 737-400, although the AAIB thought it more likely that he had accepted the first officer's assessment. When they throttled back the right engine, the noise and shuddering from the damaged engine ceased, which persuaded them they had chosen correctly. On the approach the damaged engine lost power, and 47 passengers died.
Environmental capture
Environmental capture is a skill-based error in which a familiar environment triggers a well-practised action that is not intended on this occasion. A pilot who always carries out an action at a certain point of a familiar circuit or route may carry it out automatically on a day when it is not required. A closely related slip catches pilots who move between types with different layouts, when a habit formed on one type captures the hand on the other.
Because the captured action feels entirely normal, the pilot rarely notices it. The defences are deliberate attention at the points where habits are triggered, a look-and-touch check on "obvious" actions, checklists that confirm the result rather than the habit, and standardised layouts across a fleet (see flight deck design).
The error chain
Accident investigations rarely find one catastrophic blunder. More often they find an error chain: a sequence of small errors and adverse conditions, each survivable on its own, that link together. A late start, a missed weather update, a fuel state accepted as "probably enough" and a distraction on the approach can combine into an accident. The practical value of the model is that breaking any one link stops the sequence, so recovery is possible at every stage rather than only at the start.
CRM training teaches the warning signs that a chain is forming: ambiguity, fixation, complacency, distraction, confusion, unresolved discrepancies, departures from SOPs and communication failures. Three or four minor things going wrong at once is itself the warning, whatever each one is on its own. Behind the chain lies Murphy's law, in the form human factors texts quote: if a system can be operated incorrectly, sooner or later it will be.
Reason's Swiss cheese model
James Reason's Swiss cheese model pictures the defences of an organisation as slices of cheese stacked one behind another: organisational decisions, supervision, the preconditions in the workplace, and the unsafe acts of the people at the front line, with the barriers provided by procedures and equipment. Each slice has holes, weaknesses that vary continuously in position and size. Usually a hole in one slice is covered by the next. An accident happens when the holes momentarily line up and a hazard passes through every defence.

The model underlies both threat and error management and safety management systems. It shifts attention from the last person to touch the aircraft to the whole system: the pilot's error is often the last hole to open, not the first.
Latent conditions and active failures
Reason distinguishes two kinds of hole. Active failures are errors and violations committed at the human-system interface, on the flight deck, in the cabin or at the ATC console, and their effect is immediate. Action slips and environmental capture are typical.
Latent conditions, called latent failures in older texts, result from decisions taken away from the front line by designers, manufacturers and senior management. They can lie dormant for a long time before combining with other factors, sometimes with sudden and disastrous results. Examples are a rostering practice that routinely follows a late finish with an early start, an unworkable procedure, a poorly designed control, rushed or incomplete preparation, and a navigation database error; exam questions cite the 1979 Mount Erebus accident as their example of the last (see controlled flight into terrain). Latent conditions are worth hunting because, unlike individual slips, they can be removed permanently rather than merely trained against. Threat and error management calls the ones a crew meets on the day latent threats.
Investigators also separate causal (causative) factors from contributory factors. A causal factor is a link in the accident chain which, if removed, would have stopped the accident. A contributory factor did not by itself cause the accident, but had it been eliminated or absent the accident would have been less likely, or its consequences less severe; ICAO Annex 13 defines contributing factors in these terms. Annex 13 investigations determine causes and contributing factors (see accident and incident investigation); at Kegworth the AAIB stated one cause and five factors that contributed to the crew's incorrect response.
System tolerance
System tolerance describes how a system copes with an error. A protected system keeps working when one element fails, as a wall still stands when a single brick is removed. A vulnerable system collapses when one error affects the whole. Good design and good procedures aim for the first: duplicated crew and systems, cross-monitoring, checklists and SOPs, and warning systems such as GPWS and ACAS. EASA's design philosophy for future avionics and automation puts the same idea into three principles: detectability (the system detects crew errors), tolerance (it tolerates them without dangerous consequences) and recoverability (it supports recovery).
The human side of tolerance is a just culture, in which unintentional errors are not punished while reckless behaviour and deliberate, unjustifiable risks are. NASA's confidential Aviation Safety Reporting System, set up in 1976, and the UK's CHIRP showed that the information needed to find latent conditions arrives only when reporters are not threatened with punitive action (see safety culture and occurrence reporting).
Exam tip: active failures act immediately at the front line; latent conditions come from designers and managers and lie dormant. Removing a causal factor would have prevented the accident. A protected system survives a single error, a vulnerable one does not, and Murphy's law says that a system that can be operated incorrectly eventually will be.
Frequently asked questions
What is the difference between a slip, a lapse and a mistake?
A slip is an action carried out wrongly although the intention was right, such as selecting the switch next to the one intended. A lapse is a planned step that is forgotten, often after an interruption. A mistake is an action carried out exactly as intended when the intention itself was wrong, for example a route planned through cloud after misreading an icing forecast. Slips and lapses are failures of execution; mistakes are failures of planning.
What is James Reason's Swiss cheese model?
The Swiss cheese model pictures an organisation's defences as slices of cheese stacked in a row, from organisational decisions and supervision through workplace conditions to the unsafe acts of front-line staff. Each slice has holes, weaknesses that move and change size continuously. Normally one slice covers the holes in another, but when the holes momentarily line up a hazard passes through every defence and an accident results.
What is the difference between active failures and latent conditions?
Active failures are errors and violations committed at the human-system interface, on the flight deck, in the cabin or at an ATC console, and they have an immediate effect. Latent conditions, also called latent failures, come from decisions by designers, manufacturers and managers. They lie dormant, sometimes for years, until they combine with other factors. Examples are poor rostering, unworkable procedures and database errors. Unlike slips, latent conditions can be removed permanently.
What is Rasmussen's SRK model?
Jens Rasmussen's model describes three levels of behaviour. Skill-based behaviour runs on stored motor programmes without conscious thought; its errors are action slips and environmental capture, and they occur only in experienced people. Rule-based behaviour applies a learned procedure, such as a fire drill, and its typical error is choosing the wrong procedure. Knowledge-based behaviour is needed when no procedure exists; it is slow and effortful and has the highest error rate.
What is a routine violation in aviation?
A routine violation is a habitual departure from a rule that has become the local norm, such as not reading a checklist from the card because nobody in the company does on a short sector. Routine violations persist because they usually work and save effort. Situational violations are driven by the circumstances, such as time pressure or missing equipment. Both are deliberate, which separates them from errors, and both are best tackled at organisational level.
What is environmental capture?
Environmental capture is a skill-based error in which a familiar environment triggers a well-practised action that is not intended on that occasion. A pilot who always performs an action at a certain point of a familiar circuit or route may do it automatically on a day when it is not required. Because the action feels normal it is rarely noticed. Deliberate attention at trigger points and checklists that confirm the result are the defences.
Test yourself on Human Error and Accident Causation
The v1prep banks cover this topic in Human Performance and Limitations (040), with a worked explanation for every answer. EASA ATPL, PPL, IR and CPL, the FAA written tests and A320/B737 type ratings.
Start practising →Sources and further reading
- ICAO Doc 9683, Human Factors Training Manual
- EASA, Explanatory Note to ED Decision 2018/001/R, Part-FCL theoretical knowledge learning objectives (040 Human Performance and Limitations)
- FAA Advisory Circular 120-51E, Crew Resource Management Training
- FAA Pilot's Handbook of Aeronautical Knowledge (FAA-H-8083-25), Chapter 2, Aeronautical Decision-Making
- AAIB, Aircraft Accident Report 4/90, Boeing 737-400 G-OBME near Kegworth, Leicestershire, 8 January 1989
- ICAO Annex 13, Aircraft Accident and Incident Investigation (ICAO Store)
- UK Health and Safety Executive, Managing human failures, overview
Library articles are written for study and exam preparation. They do not replace your aircraft's approved documentation, your operator's procedures or the regulations themselves.