A few more words on human error: an illustrative example

On the evening of 6 March 1987, the Herald of Free Enterprise, one of three Spirit-class ferries operated by Townsend Thoresen, left Zeebrugge fully loaded and bound for Dover. Just over twenty minutes later, shortly after passing the harbour’s outer mole, she capsized, eventually claiming the lives of 193 passengers and crew.

The immediate cause could hardly have been more prosaic—or more merciless. The crew had failed to close the enormous bow doors through which vehicles entered and left the car deck. Once the ship cleared the harbour and began gaining speed, vast quantities of water poured onto the deck. Within minutes, the ferry was lying on her side. Only the shallow water and a fortunate sandbank prevented her from disappearing completely beneath the surface.

There was little dispute about the immediate cause: the bow doors had been left open. Identifying who was responsible, however, turned out to be a much more complicated exercise—one that would ultimately lead to important changes in maritime safety and, more broadly, to the way human error is understood.

The first suspect appeared rather quickly.

Closing the bow doors before departure was the responsibility of the assistant bosun, Mark Stanley. Shortly before sailing, Stanley went down to his cabin for a short break. He fell asleep and was still asleep when the ship dropped her moorings.

So the investigation was clearly dealing with human error, and the human in question seemed obvious: Stanley had overslept an important duty.

Case closed?

Happily, the investigators did not stop there.

They discovered that this was not the first time something remarkably similar had happened. In 1983, another ferry belonging to the same company—the Pride of Free Enterprise—had sailed with its doors open after another assistant bosun had fallen asleep. On that occasion the mistake was noticed in time and disaster was avoided. There had, in fact, been several previous occasions on which company vessels had gone to sea with bow or stern doors open.

At that point, blaming one sleepy junior crew member began to look less satisfactory. Passenger ferries should not be capable of sinking simply because one tired person fails to wake up at the right moment.

There is another detail worth remembering about Stanley. After the capsize, despite being injured, he returned to help rescue passengers trapped inside the vessel until cold and blood loss forced him to stop. The man whose mistake helped trigger the disaster was also capable, minutes later, of considerable courage.

Human beings are inconveniently complicated like that.

So the investigation moved one step further up the chain of command, to Stanley’s superior: Chief Officer Leslie Sabel.

Sabel had responsibility for ensuring that the bow doors were closed. He had been on the vehicle deck, but left shortly before departure without actually seeing them shut.

Surely that qualified as serious negligence and a clear failure of duty?

It did. But again, the answer was not quite complete.

Another set of company instructions could require the same officer to be on the bridge before departure while his loading duties still kept him on the vehicle deck. The inquiry itself recognised that this created a conflict between his responsibilities. At the same time, officers were under considerable pressure to get the ferries away promptly once loading was finished.

Most of the time, of course, everything worked. The officer left the deck, somebody closed the doors, and the ship sailed safely. Nothing terrible happened.

And repetition has a remarkable ability to make an unsafe practice feel perfectly normal.

So responsibility moved another step upwards.

The captain was ultimately responsible for the safe departure of the vessel. Surely it was his duty to recognise the dangerous situation and stop the ship before it left harbour.

Sadly, not this time.

The captain could not see the bow doors from the bridge. Nor was there any indicator or other visual cue telling him whether they were open or closed.

There was something else too.

Townsend Thoresen’s standing orders effectively operated on a system of negative reporting: if nobody reported a deficiency, the Master could assume that the vessel was ready for sea.

And that was exactly what he did.

The inquiry still found the captain negligent. But it also noted that other masters were using essentially the same defective system, and that previous incidents involving open doors had not been communicated adequately to them.

So the investigation moved further again—to the people who had designed and managed that system.

Why should a safety-critical operation rely on the principle that “no news means everything is safe”? Why wasn’t there a simple “DOOR OPEN” light on the bridge? The problem hardly called for cutting-edge technology.

And why had no effective lesson been learned from earlier incidents?

The lessons certainly had opportunities to be learned.

As early as 1985, one of the company’s captains had specifically proposed fitting indicator lights on the bridge so that officers could see whether the bow doors were closed. The suggestion was circulated within management, but dismissed. One response even questioned whether an indicator was really necessary when someone was already being paid to close the doors.

The inquiry later concluded that, had the proposal received proper consideration, the disaster might well have been prevented.

By now, the picture looked very different from the one we started with.

Stanley had made a mistake. Sabel had failed in his responsibilities. The captain had departed without knowing for certain that the vessel was secured. Procedures had allowed conflicting duties and unsafe assumptions to become routine. Management had received warning signs and opportunities for improvement but had failed to act on them.

None of those discoveries made the previous failures disappear. They simply showed that stopping at any one of them would have produced an incomplete explanation.

The official inquiry ultimately reached much the same conclusion. Having examined the actions of the crew, it found itself led inexorably further up the organisation, eventually describing the company as suffering, “from top to bottom”, from a “disease of sloppiness”.

The subsequent criminal proceedings revealed another interesting problem.

Company managers were prosecuted for gross negligence manslaughter, and the operating company itself was charged with corporate manslaughter. The prosecution ultimately failed. At the time, English law struggled to deal with exactly this kind of distributed organisational responsibility: to convict a company, the prosecution effectively needed to identify a sufficiently senior individual whose personal gross negligence could be treated as the negligence of the company itself.

The evidence pointed towards failures spread throughout an organisation, while the law was still searching for one sufficiently important human being to pin them on.

The Herald of Free Enterprise teaches many lessons, but perhaps one of the most important is about the way we think about human fallibility.

Human beings make mistakes. We become tired. We lose concentration. We overlook things, make poor judgements, misunderstand instructions and occasionally behave negligently. These weaknesses are as inseparable from us as the better aspects of human nature—kindness, courage, compassion, self-sacrifice and love.

Accepting our fallibility, studying it and designing the way we live and work around it will take us towards a safer world far more effectively than treating every mistake as an opportunity for blame or humiliation.

That does not mean removing personal responsibility. Stanley was responsible for failing to close the doors. Sabel was responsible for leaving without ensuring that they were closed. The captain carried his own responsibility, and management carried theirs.

Understanding why somebody made a mistake does not make the mistake disappear.

But neither should identifying one mistake bring the investigation to an end.

Thanks to investigators who resisted the temptation to stop when they reached an easy answer—and then resisted it again when they reached the next one—the Herald of Free Enterprise became an important case in the development of maritime safety and in our understanding of organisational failure.

Would any of that have happened if the inquiry had assigned one hundred percent of the blame to the sleeping assistant bosun?

A few words on human error

It is widely assumed that between 70% and 90% of serious accidents across all industries can be attributed to human error. While this is probably about right—you can’t argue with statistics—few people understand what kind of error lies behind that incredible number.

Upon hearing the words ‘human error’, most people think of the person or people directly involved in the accident—the ‘operator’. Was it a road traffic collision? Probably the driver who misjudged the situation. An aeroplane crash? The pilot pulled too hard on the controls. An explosion at a power plant? Must have been some young and clumsy shift operator.

While any of these may, of course, be the case, reality is rarely that straightforward. Many industries—particularly high-risk ones such as aviation, traffic management, construction and nuclear energy—have long been interested in reducing their accident rates. They have worked hard to introduce safety controls that reduce the chance of human error, or at least make its consequences more manageable. Did you know, for example, that the white swirl painted on an aircraft engine is not just a funny bit of styling, but is there to help ground crews see that the engine is running when they may not be able to hear it at a busy airport?

Those efforts have paid off. Commercial aviation, for example, has become one of the safest methods of transport available to human beings, with air travel around 170 times safer per mile than travelling by car, and orders of magnitude safer than walking. In 2023, the industry could boast zero fatalities, despite air traffic reaching a record-breaking 32 million flights.

This increase in safety has had a curious side effect, though. While the proportion of accidents attributed to human error has remained somewhere around that 70–90% mark—of a much smaller number of accidents—the source of human error has propagated well up the chain of command.

A modern human error, particularly in a high-risk industry, is rarely just an operator error. Everything possible has been done to reduce the chances of basic ‘human fallibility’ errors. Most of the improvement in safety records has been achieved not by carefully selecting only responsible, prudent, well-disciplined and positive people for safety-critical positions (there are only so many of us 😉), but by designing systems in such a way that their susceptibility to human fallibility is low—and their tolerance of it is high.

It is highly unlikely that a poorly qualified, exhausted or drunk pilot will make it into the cockpit—and even if one somehow does, there is another qualified pilot sitting right beside them. It is next to impossible for an unqualified person to enter the control room of a nuclear power plant, just as it is impossible to gain that qualification without rigorous training and having your knowledge verified by a diligent examiner. Critical jobs are rarely assigned to a single person without some form of supervision, checking or independent control.

Today, traditional operator failings—fatigue, drink-driving, lack of discipline, negligence, poor training and the like—rarely become the sole root cause of a high-severity accident. Multiple things usually have to go wrong at the same time.

More importantly, alongside increased attention to system resilience, there has also been a qualitative shift in the way we think about human behaviour and workplace failures. Gone are the days of imposing unrealistic expectations on frontline workers and then simply blaming them when they fail to cope. Today, the UK Health and Safety Executive puts the following statement at the heart of its approach:

“Human failure is normal and predictable. It can be identified and managed.”

That is why modern ‘human errors’ are often quite different from what we instinctively imagine them to be. They are no longer solely operator errors. They can be failures to recognise a flaw in the system design that leaves a task beyond the operator’s reasonable capabilities. They can be failures of management to anticipate honest mistakes and mitigate their consequences. They can be failures by executives to keep up with modern working practices and adopt them within their organisations.

None of this means that the operator is now implicitly cleared of all responsibility. Negligence, lack of focus and deliberate violations of rules cannot—and should not—be tolerated. But the operator no longer carries the entire burden of responsibility for an accident and the damage it causes. They remain accountable within the scope of their responsibilities, their abilities, and the balance between the two.

Responsibility for deficiencies in that balance—and for a system’s inability to protect itself against annoying but entirely predictable human slip-ups—belongs to the system and to the people who designed, organised and managed it.

And that is, without doubt, a good thing.