BernhardSchieber

Swiss Cheese Model: Investigate the Defenses Around the Error

Communication · Executive Insight Brief · 349

Find the defenses that let the error through

The Swiss Cheese Model directs incident analysis toward layered defenses and latent conditions instead of allowing the nearest unsafe act to become the whole causal story

Premise

A serious failure rarely requires only one thing to go wrong. High-risk systems rely on multiple defenses because people, procedures, technology, and organizations are fallible. James Reason’s Swiss Cheese Model represents those defenses as imperfect layers whose weaknesses can align long enough for a hazard trajectory to pass through.

For executives, the model changes the first question after an incident. “Who made the error?” is too narrow to explain why that act became consequential. The investigation must also examine information, alarms, staffing, maintenance, handoffs, incentives, supervision, technical barriers, and recovery mechanisms that were expected to stop or absorb the failure.

The essential model

Reason’s Human Error (1990) already distinguished active failures near the event from deeper latent conditions and presented organizational accident models. The literal Swiss-cheese image emerged later through continuing development. Historical reconstruction by Justin Larouzee and Jean-Christophe Le Coze identifies John Wreathall’s defense-in-depth influence and attributes the cheese analogy to Rob Lee in the early 1990s; Reason’s 2000 BMJ article then made a simplified representation especially visible in health care.

Each slice is a defense or safeguard—technical, procedural, administrative, human, or organizational. Holes are conditions under which a defense fails, and they can move with workload, maintenance, staffing, incentives, or operating state. The slices are not management levels; they are interruption points along a hazard pathway. Safety depends on what each layer contributes and on whether several layers share the same vulnerability.

Swiss Cheese Model — Find the defenses that let the error through. Executive Insight Brief 349 by Bernhard Schieber.

Why this matters

Consider an illustrative hospital where concentrated medication is stored near a common formulation, an electronic order contains an ambiguous abbreviation, the barcode scanner is offline, the ward is short-staffed, and a nurse bypasses an independent double-check during an emergency. Each weakness affects a different defense. Harm occurs because those conditions align during the same administration episode rather than because one weakness alone guarantees the outcome.

The investigation should therefore map expected defenses before assigning blame: what should have prevented initiation, detected deviation, stopped progression, and supported recovery? It should also test common-mode dependencies, because several apparent layers may rely on the same data source, staffing level, supervisor, vendor, or incentive. If redesign later reduces events, that result cannot establish that use of the model caused the improvement.

Risks and limits

The memorable graphic suppresses complexity. Real systems are dynamic, defenses interact, adaptations can both protect and endanger, and causal paths need not be linear. Investigators can also reason backward from an accident and label every upstream imperfection a “hole,” producing hindsight certainty. Reason himself warned against pushing remote latent explanations too far.

The model does not assign causal weights, accident probabilities, or a rule for how far upstream to search. Human Error and later Swiss-cheese formulations were conceptual and case-informed, not a founding controlled experiment with one participant N or effect size. The diagram is a heuristic for barrier analysis, not a complete ontology of failure.

Executive takeaway

Use the model to widen prevention architecture, not to abolish accountability. Separate disciplinary questions from causal questions, map the defenses that should have interrupted the hazard, identify which conditions weakened them, and look for dependencies that make several layers fail together. The nearest unsafe act may still matter, but it should not become the whole explanation when the system gave that act a path to harm.

Key questions

  • Which defenses were expected to prevent, detect, stop, or recover from this hazard before the final unsafe act?
  • What active failure occurred, and which latent conditions shaped the situation in which it became consequential?
  • Which apparently separate defenses depend on the same staffing, data source, vendor, supervisor, or incentive?
  • Which barrier change has a clear owner and verification criterion rather than merely adding another layer to the diagram?

Selected sources

  • Reason, J. (1990). Human Error. Cambridge University Press.
  • Reason, J. (2000). Human error: Models and management. BMJ, 320(7237), 768-770.
  • Larouzee, J., & Le Coze, J.-C. (2020). Good and bad reasons: The Swiss cheese model and its critics. Safety Science, 126, 104660.
Brief 0Axiom 0: Communication is EverythingRead the axiom →
What these mean

Editorial orientation · Family

Model

In this series, Model names the editorial family primarily used to understand and explain communication: theories, frameworks, effects, traditions, principles and other conceptual resources. It is an umbrella for a route into the field, not a claim that every included object is a predictive model.

Editorial orientation · Category

Theories & Explanatory Models

Explains how or why a communication process works by relating mechanisms, conditions or variables. Its value is an account that can guide inquiry into what produces an outcome, rather than a name for the outcome alone.

All Communication briefs · Knowledge