Swiss Cheese Model
Serious failures can occur when weaknesses in several layers of defense line up, allowing a hazard that any one safeguard should have caught to pass through all of them.
What Is It?
Psychologist James Reason developed the underlying active-failure and latent-condition systems model in his 1990 book Human Error, working from research into major industrial and medical accidents, and elaborated the now-familiar layered-defense picture in later work, including Managing the Risks of Organizational Accidents (1997). He pictured an organization’s defenses against failure as a stack of slices, each slice a different layer of protection, training, procedure, oversight, physical safeguards, and each slice riddled with holes representing that layer’s weaknesses. In practice, no single layer is ever complete, every safeguard has gaps. Most of the time this doesn’t matter, because the holes in one layer sit behind solid parts of the next layer, and a problem that slips through one gap gets caught by another layer positioned differently. A serious failure often becomes possible when weaknesses across multiple layers line up in a way that leaves an uninterrupted path to failure, some of these weaknesses are transient, others are latent conditions that can sit dormant in the system for a long time before an active failure exposes them. Reason distinguished active failures, the specific unsafe act that happens right before an incident, from these latent conditions, and argued that focusing on the last active failure alone, the person who made the final mistake, usually misses the more instructive story: which latent conditions had to already be sitting there, unnoticed, for that final act to turn into an actual failure.
Why Does It Matter?
Organizations investigating a serious failure often gravitate toward a single cause, and often toward a single person, because a single cause makes for a satisfying, closed story. The Swiss Cheese Model pushes against that instinct: it asks what conditions had to already be present, understaffing, an unclear handoff, a skipped review that had quietly become routine, before the final visible mistake could turn into an actual incident rather than a near miss that got caught by the next layer. This reframes prevention as well. Adding one more rule in response to a single failure treats that failure as the whole story, when the more durable response is usually asking which of several independent layers should have caught the problem, and why none of them did on this particular occasion.
It also explains why the same mistake can happen many times without incident and then suddenly cause a serious failure. The same active error can occur repeatedly without producing the same outcome, because the consequence depends on the state of the defenses around it at that particular moment. What was a near miss yesterday can become an incident tomorrow if the other layers fail to intercept it.
What Changes Once You See It?
You start asking, after any serious failure, not just “what did this person do wrong” but “which of our other layers should have caught this, and why didn’t any of them,” treating the final visible mistake as one link in a longer chain rather than the whole explanation.
You start treating a near miss, a failure that almost happened but got caught by some other layer, as valuable information about a hole that exists, rather than as a non-event with nothing to learn from, since the same hole may not get caught next time.
You also get more skeptical of any single safeguard, however well designed, and more interested in whether your important processes actually have several genuinely independent layers of protection or whether they quietly rely on one layer doing all the work while the others exist mostly on paper. The more defenses share assumptions, information sources, or failure modes, the less protection their apparent multiplicity actually provides.
You stop designing critical processes around the assumption that the first line of defense will always work, and start expecting individual layers to fail occasionally, making sure an ordinary error still has somewhere else to be caught.
Common Misunderstandings
- It isn’t a claim that individual mistakes don’t matter or shouldn’t be examined. The final active failure is a real and necessary part of the story, the model’s point is that it’s rarely the complete story, and that the latent conditions behind it usually deserve equal attention.
- It isn’t the same as Normalization of Deviance, though the two frequently appear together. Normalization of Deviance describes a standard itself eroding through repeated tolerance of small deviations, the Swiss Cheese Model describes how a failure gets through a system of layered defenses at a specific moment, and normalized deviance is one common way a layer’s hole gets larger over time.
- It doesn’t mean more layers are automatically safer. Layers that aren’t genuinely independent, that share the same blind spot, the same assumption, the same single point of failure, can all have their holes line up together far more easily than truly independent layers would.
- It isn’t a tool for assigning blame more fairly to more people. It’s a tool for finding and closing systemic gaps, using it to spread blame across everyone involved in every layer misses the point as much as blaming only the last person does.
Diagnostic Question
Which of our other layers of defense should have caught this before it became a real problem, and why didn’t any of them?
Explore Further
Field Notes
- None yet.
Related Field Guide
Origin
James Reason developed the underlying active-failure and latent-condition systems model in Human Error (1990) and elaborated the now-familiar layered-defense picture in later work, including Managing the Risks of Organizational Accidents (1997). The resulting “Swiss Cheese Model” became one of the most widely used representations of accident causation in safety science.