Home / Library / Human Factors

Threat and Error Management (TEM)

Human FactorsPPL · CPL · ATPL9 min readUpdated Sep 2026
Definition

Threat and error management (TEM) is a safety framework that describes flight operations in terms of threats, crew errors and undesired aircraft states, together with the countermeasures crews use to anticipate threats, trap errors and recover from undesired states before safety margins are lost.

Threat and error management (TEM) is a way of describing, and managing, the safety of a flight. It sorts everything that can erode safety margins into three components: threats that arise outside the flight crew, errors the crew make themselves, and the undesired aircraft state (UAS) that can result when either is mismanaged. The crew's task is to anticipate threats, catch errors early and recover from any undesired state before it turns into an incident or accident.

TEM grew out of airline line audits in the 1990s and now runs through ICAO guidance, the EASA theoretical knowledge syllabus and airline training worldwide. It is closely tied to crew resource management: CRM supplies the communication, monitoring and decision-making skills, and TEM gives them an operational target by saying what those skills are defending against. Exam questions test the definitions and classifications below almost word for word.

On this page
  1. Origins of the TEM framework
  2. The TEM framework
  3. Types of threat
  4. Environmental and organisational threats
  5. Errors in TEM
  6. Undesired aircraft states
  7. Countermeasures
  8. TEM in training and audits
  9. Frequently asked questions

Origins of the TEM framework

The model was developed by the University of Texas at Austin Human Factors Research Project, led by Robert Helmreich with James Klinect and John Wilhelm. In 1994 Delta Air Lines, which had introduced a new CRM course, asked whether its lessons were actually being used on the line. The university and the airline developed a method of observing normal scheduled flights from the jump seat, the forerunner of the Line Operations Safety Audit (LOSA). At first the observers mostly rated CRM behaviour. From 1997, work with Continental Airlines widened the method to record the threats crews met and the errors they made, and how both were handled. That coding scheme became the TEM model.

ICAO took the model up through its Flight Safety and Human Factors Programme. Its Human Factors Training Manual (Doc 9683) covers TEM training, Annex 1 defines threats and errors, and the training procedures in PANS-TRG (Doc 9868) treat pilot competencies as countermeasures to threats, errors and undesired aircraft states. TEM is often described as the sixth generation of CRM, following a fifth generation that had already shifted the emphasis from avoiding error to managing it.

The TEM framework

The three components are defined as follows:

Component Meaning Examples
Threat An event or error that occurs beyond the influence of the flight crew, increases operational complexity and must be managed to keep the margin of safety Thunderstorms on the route, a late runway change, a system malfunction, a dispatcher's load sheet mistake
Error An action or inaction by the flight crew that leads to a deviation from organisational or flight crew intentions or expectations A wrong altitude set in the flight control unit, a missed checklist item, a misheard clearance
Undesired aircraft state A crew-induced deviation in aircraft position or speed, misapplication of the flight controls, or incorrect system configuration that reduces the margin of safety An unstable approach, taxiing towards the wrong runway, a wrong flap setting for take-off

Two points of the definitions matter in practice. First, threats and errors are a normal part of every flight; TEM does not assume they can be eliminated, only that they must be managed. Second, a mistake made by someone else, such as a controller or a maintenance engineer, is a threat to the flight crew, not a crew error.

The components form a chain. A threat that is not managed can induce an error; an error that is not trapped can produce an undesired aircraft state; and a state that is not recovered can end in an incident or accident. Each link corresponds to one of the three defences of error management: avoid (manage the threat), trap (catch the error) and mitigate (recover the aircraft). The model is deliberately neutral about blame. It records what happened and how well it was managed, not whose fault it was.

Types of threat

ICAO classifies threats by how predictable they are.

Exam tip: an unexpected runway change on final is a threat. If the crew then set up the new approach incorrectly, that is an error. If the aircraft ends up high and fast on the new final, that is an undesired aircraft state.

Environmental and organisational threats

Threats are also grouped by where they come from. Environmental threats arise from the environment in which the flight takes place. Some can be planned for and some appear without warning, but all have to be managed by the crew in real time. Organisational threats originate in the aviation organisation and can, in principle, be removed or reduced at source. They are usually latent in nature, so the crew is often the last line of defence against them.

Environmental threats Organisational threats
Weather: thunderstorms, turbulence, icing, wind shear, crosswind, low visibility Operational pressure: delays, late arrivals, aircraft changes
ATC: traffic congestion, runway changes, non-standard phraseology, controller errors Aircraft: malfunctions, automation anomalies, items deferred under the MEL
Airport: contaminated or short runways, works in progress, complex taxiways, poor signage Cabin: cabin crew errors, cabin events, interruptions
Terrain: high ground, lack of visual references Maintenance and ground handling: maintenance errors, ground crew errors, de-icing
Dispatch and documentation: load sheet, flight plan, manual and chart errors
An aircraft being de-iced at Copenhagen Airport.
De-icing at Copenhagen. Winter weather is a typical anticipated environmental threat, and the delays it causes can add the organisational threat of time pressure.My another account at English Wikipedia · CC0 · Wikimedia Commons

Errors in TEM

An error in TEM is always a flight crew action or inaction. Errors are grouped by the kind of activity in which they occur:

Error type Covers Examples
Aircraft handling errors Manual flying, automation, systems and radios, ground navigation Wrong autopilot mode, wrong frequency tuned, turning onto the wrong taxiway
Procedural errors SOPs, checklists, callouts, briefings, documentation Checklist item missed, callout omitted, wrong figure entered in the load sheet or flight plan
Communication errors Crew to external parties, pilot to pilot Readback error, misheard clearance, a misunderstanding between the two pilots

The classification describes what went wrong, not why. It is therefore different from James Reason's split into slips, lapses and mistakes, which depends on the person's intention, and from Rasmussen's skill, rule and knowledge levels of behaviour (see human error). An error that is detected and corrected quickly is said to be trapped and has no consequence. One that is not may lead to a further error or to an undesired aircraft state. TEM teaches that error detection and response matter as much as error avoidance, because even the best crews make errors.

Exam tip: EASA questions pair the three TEM components with threats, errors and undesired aircraft states, and the three error types with aircraft handling, procedural and communication. Distractors borrow Reason's slips, lapses and mistakes or Rasmussen's skill, rule and knowledge.

Undesired aircraft states

An undesired aircraft state is the last point in the chain at which the outcome is still under the crew's control. ICAO groups UAS into three categories:

The key lesson is a change of priority. Once a UAS exists, the crew must stop concentrating on the error that caused it and concentrate on recovering the aircraft. The classic example is the approach that is high and fast at the stabilisation gate: the right response is a go-around, not a debate about why the descent was started late (see stabilised approach).

An event such as an engine failure is not in itself a UAS, because it was not caused by the crew; it is a threat. A UAS is crew-induced by definition, although it may follow from a threat that was poorly managed.

Countermeasures

TEM countermeasures are what crews use to manage threats, errors and states. They come in two families.

Systemic-based countermeasures, often called the hard resources, are built into the aircraft and the operation: ACAS, GPWS and TAWS, standard operating procedures, checklists, briefings and training. Individual and team countermeasures, the human resources, are the skills, knowledge and attitudes developed chiefly by CRM training. The best results come from combining the two: a checklist traps errors only if the crew runs it with attention, and an alert protects only if the crew responds to it.

ICAO divides the individual and team countermeasures by phase:

Category Purpose Typical behaviours
Planning Managing anticipated and unexpected threats Thorough, interactive briefings; plans and decisions stated aloud; roles and workload assigned; contingencies prepared in advance
Execution Detecting and responding to errors Monitoring and cross-checking; managing workload so the critical tasks are protected; managing automation, including stepping down a level when it misbehaves
Review Managing the changing conditions of a flight Re-evaluating and modifying plans; asking questions; speaking up when something does not look right
Human factors at a glance, including threats, errors and undesired aircraft states and the three defences of avoid, trap and mitigate. v1prep schematic.
Human factors at a glance, including threats, errors and undesired aircraft states and the three defences of avoid, trap and mitigate. v1prep schematic.Illustration © v1prep

A good threat briefing is short and specific. Rather than reciting the approach chart, the crew names the two or three things most likely to catch them out on this particular flight, agrees what each pilot will watch for and decides in advance what will trigger a go-around or a diversion. The same habit extends to single-pilot flying, where the pilot names the threats aloud and sets personal limits before departure.

TEM in training and audits

The LOSA method is the main source of TEM data. ICAO describes it in Doc 9803 and lists ten operating characteristics, among them peer observations of normal flights from the jump seat, anonymous, confidential and non-punitive data collection, voluntary crew participation, trusted and trained observers, joint management and pilot union sponsorship, an observation form based on TEM, a secure data repository, data verification roundtables, improvement targets derived from the data, and feedback of the results to the workforce. If a crew declines to be observed, the observer simply takes another flight. The findings show an airline where its threats, errors and undesired states cluster and whether its procedures work as intended.

In Europe, TEM is part of licensing as well as operator training. EASA ED Decision 2018/001/R, published in February 2018 and often called the 2020 syllabus, introduced TEM into the learning objectives for the theoretical knowledge examinations. It also expects exercises during theory training to apply TEM, preferably in scenario form. In commercial air transport, TEM is normally delivered through the CRM training required by ORO.FC.115 and ORO.FC.215, whose elements AMC1 ORO.FC.220 requires to be integrated into all appropriate phases of operator conversion training.

In the United States, TEM reaches pilots mainly through CRM training for Part 121 crews under 14 CFR 121.404, with guidance in Advisory Circular 120-51E, and through LOSA, which AC 120-90 (2006) describes for voluntary use by operators. The FAA presents TEM as a framework for applying CRM skills on the line.

Note: the difference matters for students. EASA examines TEM directly in the theoretical knowledge papers, including Human Performance and Limitations (040), whereas FAA knowledge tests treat it within CRM, aeronautical decision-making and risk management.

Competency-based and evidence-based training take the idea further. PANS-TRG treats each pilot competency, such as communication, situation awareness, workload management and flight path management, as a countermeasure in its own right, so that TEM becomes the lens through which training scenarios are designed and crew performance is assessed. See also situational awareness and decision making.

Frequently asked questions

What is threat and error management in aviation?

Threat and error management (TEM) is a framework that describes a flight in terms of threats that arise outside the crew, errors the crew make, and undesired aircraft states that follow when either is mismanaged. Crews are trained to anticipate and brief threats, to detect and correct errors through monitoring and cross-checking, and to recover promptly from an undesired state, for example by going around from an unstable approach.

What are the three types of threat in TEM?

By predictability, threats are anticipated, unexpected or latent. Anticipated threats, such as forecast thunderstorms or a congested airport, can be foreseen and briefed. Unexpected threats, such as a system malfunction or a late runway change, arise without warning. Latent threats, such as poor equipment design, visual illusions or tight turnaround schedules, are not obvious to crews on the day and are usually found only by safety analysis.

What is an undesired aircraft state?

An undesired aircraft state (UAS) is a crew-induced deviation in the aircraft's position or speed, a misapplication of the flight controls, or an incorrect system configuration that reduces the margin of safety. ICAO groups them as aircraft handling, ground navigation and incorrect configuration states. A UAS is still recoverable, which is why the crew must switch from fixing the error to recovering the aircraft.

What is the difference between a threat and an error in TEM?

A threat originates outside the flight crew's influence and increases the complexity of the flight, such as weather, terrain, a technical fault or a controller's mistake. An error is an action or inaction by the flight crew themselves that departs from their own or their organisation's intentions or expectations, such as a wrong altitude selection or a missed checklist item. Errors made by others count as threats to the crew.

What is a LOSA in aviation?

A Line Operations Safety Audit (LOSA) is a programme in which trained peer observers ride on the jump seat of normal scheduled flights and record the threats the crew meet, the errors they make and how both are managed. Participation is voluntary and the data are anonymous, confidential and non-punitive. ICAO describes LOSA in Doc 9803 and the FAA in Advisory Circular 120-90.

Test yourself on Threat and Error Management (TEM)

The v1prep banks cover this topic in Human Performance and Limitations (040), with a worked explanation for every answer. EASA ATPL, PPL, IR and CPL, the FAA written tests and A320/B737 type ratings.

Start practising →
16,000+ questions · EASA & FAA · Free to start

Sources and further reading

  1. D. Maurino, Threat and Error Management (TEM), Canadian Aviation Safety Seminar, 2005
  2. ICAO Doc 9803, Line Operations Safety Audit (LOSA)
  3. ICAO Doc 9683, Human Factors Training Manual
  4. FAA Advisory Circular 120-90, Line Operations Safety Audits
  5. FAA, Line Operations Safety Assessments, History
  6. FAA Advisory Circular 120-51E, Crew Resource Management Training
  7. EASA, Explanatory Note to ED Decision 2018/001/R, Part-FCL theoretical knowledge learning objectives
  8. Transport Canada, Aviation Safety Letter 4/2023, Introduction to Threat and Error Management

Library articles are written for study and exam preparation. They do not replace your aircraft's approved documentation, your operator's procedures or the regulations themselves.