Most of the causal work in a serious organisational accident is done long before, and far from, the moment of failure. This is James Reason’s central contribution: the distinction between active failures — the unsafe acts of people at the sharp end, whose effects are immediate — and latent conditions, the dormant weaknesses seeded upstream by decisions at the blunt end, which lie in the system for years until a combination of circumstances lets them through.

Active failures and latent conditions

Active failures are the errors and violations of operators — the pilot, the nurse, the control-room engineer — committed at the point where the system meets the world. Latent conditions are the consequences of decisions taken by designers, managers, policymakers and regulators: understaffing, poor interfaces, incompatible goals, gaps in defences, and cultural tolerances. They are not errors in the moment; they are resident weaknesses, and they are present in every complex system all the time.

The Swiss cheese model

Reason’s image is a stack of defensive layers — procedures, alarms, training, physical barriers, oversight — each with holes. Some holes are active failures, opened briefly; others are latent conditions, standing open for long periods. An accident occurs when, for a moment, the holes across every layer line up and an accident trajectory passes clean through. The practical implication is that defence-in-depth works by keeping the holes unlikely to align — and that safety is degraded quietly whenever latent holes are allowed to grow.

The pathogen metaphor

Reason described latent conditions as resident pathogens in the body of the system: always present, tolerated, doing no harm until circumstances allow them to combine into disease. The metaphor makes the key point — that asking only “who was at the controls?” is usually the wrong question. The operator’s active failure is frequently just the agent that lets a pre-existing, upstream pathology express itself. This is the same relocation of diagnosis, from person to architecture, that defines the cognitive-systems frame: latent conditions are, in cognitive terms, hazards the organisation committed to but never represented to itself.

How latent conditions accumulate

Because they originate in ordinary design trade-offs and resource decisions, latent conditions are a routine by-product of running an organisation, not a sign of exceptional failure. Two mechanisms in this archive do most of the accumulating: normalisation of deviance, which lets tolerances widen unremarked until a latent weakness is standing wide open, and tight coupling, which governs how readily aligned holes turn into a full breach once they line up. Unlike active failures, latent conditions can in principle be found and closed before any accident — which is the basis of proactive rather than reactive safety management.

The critical turn: emergence and resilience

The Swiss cheese model earned its influence by being clear and teachable, but its clarity is also its limit, and for genuinely complex systems the critique matters. Resilience engineering — Hollnagel’s Safety-II — argues that the model is too linear and componential: it pictures safety as the absence of failures in discrete layers, whereas in complex systems safety and failure both emerge from the same normal, everyday variability of work, not from broken parts. Leveson’s systems-theoretic approach (STAMP) reframes accidents as breakdowns of control and constraint across a whole sociotechnical system rather than as chains of component failures. For anyone coming from complexity, this is the more natural framing: latent conditions are a useful first cut, but the deeper phenomenon is emergent behaviour that no decomposition into layers and holes fully captures.

In this archive

Key sources

  • Reason, J. (1990). Human Error. Cambridge University Press.
  • Reason, J. (1997). Managing the Risks of Organizational Accidents. Ashgate.
  • Reason, J. (2000). Human error: models and management. BMJ, 320, 768–770.
  • Hollnagel, E. (2014). Safety-I and Safety-II: The Past and Future of Safety Management. Ashgate.
  • Leveson, N. G. (2011). Engineering a Safer World: Systems Thinking Applied to Safety. MIT Press.
  • Dekker, S. (2006). The Field Guide to Understanding ‘Human Error’. Ashgate.