Home / Library / Human Factors

Human Factors and the SHELL Model

Human FactorsPPL · CPL · ATPL8 min readUpdated Sep 2026
Definition

Human factors is the study of people in the aviation system: what they can and cannot do, and how they interact with equipment, procedures, their environment and each other. The SHELL model describes that system as a human at the centre, linked to software, hardware, environment and other people.

Human factors (HF) is the study of people as part of the aviation system. It asks what pilots, controllers, engineers and cabin crew can and cannot do, and how well the aircraft, procedures, working environment and organisation fit them. Its goal is not to blame people for errors but to design the system so that errors are less likely, easier to catch and less harmful.

The subject matters because people are both the strength and the weak point of the system. The crew is the most valuable and flexible component, able to cope with situations no designer foresaw, but human performance also has limits and varies from day to day. About 70 per cent of aviation accidents are commonly attributed to human error, a figure that has driven much of the work on training, procedures and automation. ICAO has required human factors knowledge for professional pilot licences since 1989, and EASA teaches it as Human Performance and Limitations. The FAA covers the same ground in its aeromedical and aeronautical decision-making material.

On this page
  1. What human factors is
  2. Human performance and limitations
  3. The SHELL model
  4. Liveware-hardware interface
  5. Liveware-software interface
  6. Liveware-environment interface
  7. Liveware-liveware interface
  8. ICAO human factors guidance
  9. Frequently asked questions

What human factors is

ICAO's first Human Factors Digest, published in 1989, describes the field as the study of people in their living and working situations. It covers their relationship with machines, procedures and the environment around them, and their relationships with other people. It gives the discipline twin objectives: safety and efficiency. Human factors draws on psychology, physiology, medicine and engineering, and applies them to the design of aircraft and procedures, to selection and training, and to the organisations in which people work.

Human factors is sometimes confused with human error. Error is one of its concerns, but the field looks further: at why an error was likely, what would have caught it, and how the design of equipment, documents and rosters affects performance long before anything goes wrong. The SHELL model described below, threat and error management, crew resource management and Reason's Swiss cheese model of accident causation are different lenses on the same problem.

Human performance and limitations

Human Performance and Limitations (HPL) is the part of human factors that every pilot studies for a licence. It covers:

At the centre of it all is the central nervous system (CNS), the brain and spinal cord. It is served by the peripheral nervous system, the sensory and motor nerves, and works alongside the autonomic nervous system, which controls involuntary functions such as heart rate, breathing and sweating and triggers the stress response. Nerve impulses travel electrochemically: electrically along the nerve cells and chemically across the synapses between them.

The CNS sets hard limits on performance. A simple reaction, such as pressing a button when a light comes on, takes about 0.2 seconds. Anything that needs a decision takes longer, because every choice loads a central decision-maker of limited capacity. Reflexes are faster because the signal loops through the spinal cord without waiting for the brain. Even on simple, repetitive tasks people typically make about one error in a hundred attempts. Practice improves this greatly, while stress, fatigue and low morale make it worse.

The SHELL model

The SHELL model is a conceptual model of the aviation system. It was first developed by Elwyn Edwards in 1972, and Frank Hawkins produced a modified diagram of it in 1975, the form now familiar from ICAO material, where it is written SHEL. Its name comes from the initials of its components:

Hawkins drew the components as blocks with irregular edges, fitted around the central Liveware block. The edges show that the components do not match automatically: each must be matched to the human, whose basic characteristics cannot be redesigned. Errors and accidents tend to arise at the interfaces, where a component does not fit the person using it. The model directs the investigator, designer or trainer to the interface to find the mismatch, rather than stopping at "pilot error".

Human factors at a glance: error types and what catches them, the SHELL model, threat and error management, and situational awareness. v1prep schematic.
Human factors at a glance: error types and what catches them, the SHELL model, threat and error management, and situational awareness. v1prep schematic.Illustration © v1prep
Interface Covers Typical mismatch Typical remedy
L-H Controls, displays, seats, switches Two similar switches confused Standardised layout, shape coding, guards
L-S Procedures, checklists, charts, software A checklist or chart misread SOPs, clear documents, standard symbology
L-E Noise, heat, vibration, light, time of day Fatigue or distraction from the environment Headsets, climate control, rostering rules
L-L Crew, cabin crew, ATC, engineers A concern not voiced or not heard CRM, briefings, standard phraseology

Liveware-hardware interface

The Liveware-hardware (L-H) interface is the relationship between people and the physical equipment they use, the traditional territory of ergonomics. It covers the design of seats to fit the body, controls that move in the expected direction and can be told apart by shape and position, and displays that can be read quickly and correctly. For an instrument, that means considering its position relative to the pilot, the design of its scale, its lighting and colour coding, the viewing angle, the time needed to take in the information and the risk of misreading it at a glance.

A classic mismatch comes from the UK Confidential Human Factors Incident Reporting Programme (CHIRP). On some Fokker F27s, the switches for water-methanol injection and pitot heat were in each other's positions compared with the rest of the fleet. A first officer selected water-methanol instead of pitot heat during the after-start checks, and the error came to light only when the captain heard the water-methanol cut in on take-off. Standardising the layout across the fleet removes that trap.

Automation adds a newer layer to the L-H interface, because the pilot must understand what the systems are doing as well as operate the controls. EASA describes its design philosophy for avionics and automation in three principles: the system should help detect crew errors, tolerate them without dangerous consequences, and support recovery from them.

Liveware-software interface

The Liveware-software (L-S) interface is the relationship between people and the non-physical parts of the system: procedures, checklists, manuals, charts, symbology and the logic of computer programs. Reading a checklist, interpreting an approach chart or programming a flight management system are all L-S tasks.

Mismatches arise when information is easy to misread or misinterpret: an ambiguous checklist layout, a cluttered chart, an abbreviation used in two senses, or a computer mode whose behaviour is not what the pilot expects. Errors here can also lie dormant. In the 1979 Air New Zealand DC-10 accident on Mount Erebus, an error in the navigation data entered on the ground went unnoticed until it took the aircraft towards the mountain in poor visibility.

Standard operating procedures (SOPs) are the main defence at this interface. When strictly followed they turn routine tasks into habits that need less attention, and they give both pilots the same expectations. Their limitation is that no set of procedures can cover every situation.

Liveware-environment interface

The Liveware-environment (L-E) interface is where the person meets the conditions in which the work is done. Inside the aircraft that means noise, vibration, temperature, humidity, lighting, cabin altitude and acceleration. Outside it means weather, terrain, darkness and time zones. In the wider sense used in ICAO material, it also includes the political, economic and organisational constraints under which the aviation system operates.

Much of the environment cannot be changed, so the system adapts the person to it or shields the person from it. Pressurisation, air conditioning, oxygen equipment, noise-attenuating headsets and sunglasses protect against the physical environment. Flight time limitations and fatigue management address the effect of duty hours and the body clock.

The red towers of a suspension bridge rising out of a thick white bank of fog lying over the water, with a hilly city beyond in pink evening light.
Fog lying over the Golden Gate at sunset, San Francisco. Weather belongs to the Environment in the SHELL model. It cannot be redesigned, so the rest of the system is matched to it through equipment, procedures, minima and training.Brocken Inaglory · CC BY-SA 3.0 · Wikimedia Commons

Liveware-liveware interface

The Liveware-liveware (L-L) interface is the relationship between the central person and the other people in the system: the other pilot, the cabin crew, controllers, engineers, dispatchers and management. It covers leadership, teamwork, communication, personality and the balance of authority on the flight deck. Hawkins observed that selection, training and checking can ensure that a pilot is able to perform well, but motivation decides whether the pilot actually does so.

Many accidents of the 1970s happened to serviceable aircraft whose crews failed to share what they knew, and crew resource management grew out of this interface. Briefings, standard phraseology, cross-checking and graded assertiveness are its practical tools.

Exam tip: reading a checklist or a chart is L-S; confusing two similar switches is L-H; noise, heat and time of day are L-E; captain and first officer, or pilot and controller, is L-L. SOPs reduce errors at the L-S interface.

ICAO human factors guidance

ICAO's human factors programme dates from the late 1980s. Amendment 159 to Annex 1, Personnel Licensing, which came into force on 16 November 1989, made human factors knowledge a requirement for professional pilot licences. ICAO then published a series of Human Factors Digests, beginning with Digest No. 1 on fundamental human factors concepts in 1989, which presented the SHELL model. Much of this material was later brought together in the Human Factors Training Manual (Doc 9683), first published in 1998.

The same thinking runs through later ICAO work on threat and error management, line operations safety audits and safety management systems. In Europe, Human Performance and Limitations is a theoretical knowledge subject for every pilot licence, and commercial operators must give their crews CRM training. In the United States, the FAA covers the subject in the aeromedical and decision-making chapters of its Pilot's Handbook of Aeronautical Knowledge and in its CRM advisory circular.

Frequently asked questions

What does SHELL stand for in aviation human factors?

SHELL stands for Software, Hardware, Environment and Liveware, with a second Liveware for the other people involved. Software means procedures, checklists, manuals, charts, symbology and computer programs. Hardware means the aircraft, its controls, displays and seats. Environment covers the conditions in and around the flight deck, and Liveware is the human. The model places one person at the centre and examines each interface with the other components.

Who created the SHELL model?

The concept was first developed by Elwyn Edwards in 1972. Frank Hawkins produced a modified diagram of it in 1975, a set of blocks around a central Liveware block, with irregular edges to show that the components must be matched to each other. ICAO adopted the model, which it writes SHEL, in its Human Factors Digests and training manual, and it remains part of the EASA Human Performance and Limitations syllabus.

Which SHELL interface is a pilot reading a checklist?

Liveware-Software. Checklists, procedures, manuals, charts, symbology and computer programs are all Software in the SHELL model, so the pilot's interaction with them is the L-S interface. Errors there come from misreading or misinterpreting information, and standard operating procedures and well-designed documents are the main defence. A pilot selecting the wrong one of two similar switches is instead a Liveware-Hardware problem.

What is the difference between human factors and human performance and limitations?

Human factors is the broad discipline that studies people within the aviation system, including design, procedures, training and organisation, with safety and efficiency as its goals. Human Performance and Limitations is the name of the EASA theoretical knowledge subject that teaches pilots the part of it they need, from aviation physiology and health to information processing, error, decision-making, stress, fatigue and crew cooperation.

Why did ICAO make human factors part of pilot licensing?

Accident studies showed that most accidents, typically quoted as around 70 per cent, are attributed to human error rather than purely technical failures. ICAO responded by making human factors knowledge a requirement for professional pilot licences through Amendment 159 to Annex 1, which came into force on 16 November 1989, and by publishing a series of Human Factors Digests to support training and design.

Test yourself on Human Factors and the SHELL Model

The v1prep banks cover this topic in Human Performance and Limitations (040), with a worked explanation for every answer. EASA ATPL, PPL, IR and CPL, the FAA written tests and A320/B737 type ratings.

Start practising →
16,000+ questions · EASA & FAA · Free to start

Sources and further reading

  1. ICAO Doc 9683, Human Factors Training Manual
  2. ICAO Annex 1, Personnel Licensing
  3. EASA Easy Access Rules for Aircrew (Regulation (EU) No 1178/2011)
  4. FAA Pilot's Handbook of Aeronautical Knowledge (FAA-H-8083-25C), Chapter 2, Aeronautical Decision-Making, and Chapter 17, Aeromedical Factors
  5. FAA Advisory Circular 120-51E, Crew Resource Management Training
  6. SKYbrary, Crew Resource Management (CRM)

Library articles are written for study and exam preparation. They do not replace your aircraft's approved documentation, your operator's procedures or the regulations themselves.