A Good Response Does Not Erase a Preventable Failure
Every organisation appreciates a good recovery story.
Something goes wrong, the team responds, the immediate problem is contained and, a few weeks later, a polished incident review explains:
- what happened;
- how the team responded;
- what was learned; and
- what will change as a result.
These reviews can be genuinely valuable. They support organisational learning, encourage transparency and help prevent the same incident from happening again.
However, they can also create a dangerous sense of closure.
A strong response after an incident is evidence that an organisation performed well under pressure.
It is not evidence that the incident could not—or should not—have been prevented.
“We responded well” and “we managed the risk well” are not the same claim.
The Story Organisations Tell Themselves
Post-incident reviews and blameless investigations represent an important improvement on the traditional approach of identifying an individual to blame and then moving on.
A well-run review can help employees speak openly about:
- failed controls;
- missed warning signs;
- unclear responsibilities;
- system limitations;
- workload pressures; and
- decisions that made sense at the time but contributed to the outcome.
The problem is not the review itself.
The problem arises when the quality of the response becomes the organisation’s main measure of success.
Restoring operations quickly, supporting affected people and implementing immediate corrective actions are all important.
However, these actions do not answer the harder questions:
- Why was the hazard present in the first place?
- Were warning signs raised and ignored?
- Had the organisation previously accepted similar failures?
- Were resources, staffing or time pressures weakening existing controls?
- Could the incident reasonably have been prevented?
A team may perform exceptionally during a crisis while the broader organisation has failed to manage the conditions that created it.
Both things can be true at the same time.
What the Boeing 737 MAX Shows Us
The Boeing 737 MAX provides a confronting example of the difference between responding to an incident and addressing the organisational conditions behind it.
Lion Air Flight 610 crashed in October 2018. Less than five months later, Ethiopian Airlines Flight 302 also crashed.
The two crashes resulted in the deaths of 346 people.
Subsequent investigations identified significant problems involving the design and certification of the aircraft, the Maneuvering Characteristics Augmentation System, known as MCAS, pilot information and training, regulatory oversight and Boeing’s broader safety culture.
The aircraft was grounded worldwide after the second crash, and extensive technical and regulatory changes followed.
However, the later response could not undo the earlier decisions and missed opportunities that contributed to the two disasters. A United States congressional investigation subsequently described serious failures in the aircraft’s development and certification and raised concerns about Boeing’s safety culture and the adequacy of regulatory oversight. (transportation.house.gov)
The lesson became relevant again on 5 January 2024, when a mid-exit door plug separated from an Alaska Airlines Boeing 737 MAX 9 shortly after take-off.
The aircraft returned safely, although one flight attendant and seven passengers sustained minor injuries.
In its 2025 findings, the United States National Transportation Safety Board concluded that Boeing had failed to provide adequate training, guidance and oversight to factory workers. It also found that Boeing’s safety management system had not proactively identified and managed relevant risks during the two years before the incident. (NTSB)
The NTSB determined that the four bolts required to secure the door plug were missing before the accident flight. The investigation also identified failures in documentation, production processes and regulatory oversight. (NTSB)
This does not mean that Boeing made no safety improvements following the earlier crashes.
It demonstrates something more important:
Corrective actions after one failure do not automatically address the organisational conditions capable of producing the next one.
The Swiss Cheese Model
Psychologist James Reason’s Swiss cheese model provides a useful way to understand how organisational incidents occur.
The model represents an organisation’s defences as several layers.
Each layer may contain weaknesses or “holes”, such as:
- an incomplete procedure;
- inadequate training;
- a missed inspection;
- poor communication;
- insufficient supervision;
- equipment failure;
- workload pressure; or
- an ineffective reporting system.
An incident occurs when weaknesses across multiple layers align and allow the hazard to pass through every available defence.
The model is sometimes interpreted as suggesting that incidents are simply the result of unfortunate circumstances.
However, weaknesses across different layers are often connected.
The same organisational pressures may affect multiple controls at once. For example:
- cost reduction may affect staffing, maintenance and training;
- production pressure may discourage reporting and increase shortcuts;
- unclear accountability may weaken supervision and incident escalation;
- a punitive culture may prevent employees from raising concerns; and
- repeated success despite known deviations may create misplaced confidence.
Patching one hole after an incident will not necessarily strengthen every other layer.
If the organisation replaces a piece of equipment but leaves the workload, culture and decision-making pressures unchanged, it may have addressed the immediate cause without addressing the underlying risk.
Recovery and Prevention Require Separate Accountability
A strong incident response deserves recognition.
The employees who protect others, restore operations, identify the immediate cause and communicate honestly are demonstrating valuable behaviours.
However, praise for the response should not close the examination of what happened before the incident.
Organisations should maintain two separate lines of accountability.
The first considers the response:
- Was the incident contained effectively?
- Were affected people supported?
- Were regulators and stakeholders notified?
- Was accurate information communicated?
- Were immediate corrective actions implemented?
The second considers prevention:
- Was the hazard reasonably foreseeable?
- Had similar concerns been raised before?
- Were existing controls adequate and properly maintained?
- Did the organisation act on previous reports, near misses or audit findings?
- Were commercial or operational pressures influencing safety decisions?
- Could earlier action have prevented the incident?
An organisation can perform well against the first set of questions and poorly against the second.
One does not cancel out the other.
The Warning Signs Usually Appear Earlier
Serious incidents rarely emerge without any prior indication.
The warning signs may include:
- repeated minor failures;
- recurring defects;
- unresolved audit findings;
- overdue maintenance;
- employee complaints;
- near misses;
- temporary controls that have become permanent;
- high employee turnover;
- recurring staffing shortages; or
- risk reports that are regularly closed without meaningful action.
Individually, these issues may appear manageable.
Together, they may indicate that the organisation’s controls are gradually weakening.
A good post-incident investigation should therefore look beyond the immediate sequence of events and examine the history surrounding the failure.
The question should not only be:
“What caused this incident?”
It should also be:
“What allowed these conditions to remain in place?”
A Practical Test for Leaders
Following an incident, leaders should ask:
If the same warning signs had existed six months earlier, would our systems have identified and addressed them?
If the answer is no, the corrective action may have treated the incident’s symptoms without addressing the underlying weakness.
Leaders should also consider:
- Would employees feel safe raising the concern?
- Would the issue receive sufficient attention before someone was injured?
- Would operational pressure override the proposed control?
- Would the risk be escalated to someone with authority to act?
- Would the organisation fund preventative action without first experiencing a serious consequence?
- Are we learning from near misses with the same urgency as actual incidents?
The next incident may not present in exactly the same way as the last.
It may pass through a different weakness created by the same underlying culture or operational pressure.
How Capture Culture Can Help
A meaningful incident review should do more than explain what happened.
It should help the organisation understand why its systems allowed the risk to develop, remain or become accepted.
At Capture Culture, we support organisations with:
- independent workplace investigations;
- WHS incident and near-miss investigations;
- root-cause and systems analysis;
- safety culture reviews;
- risk and control assessments;
- corrective action planning;
- governance and accountability reviews; and
- practical support implementing sustainable improvements.
Responding well to an incident matters.
Preventing the incident from being necessary matters more.
The strongest organisations do not use recovery as proof that their systems are working.
They use the incident as an opportunity to test whether those systems were working before anyone needed to recover at all.
Further Reading
James Reason, Human Error (Cambridge University Press, 1990).
United States House Committee on Transportation and Infrastructure, The Design, Development and Certification of the Boeing 737 MAX (2020).
John Allspaw’s work on blameless post-incident reviews and organisational learning.