1 / 30100%
Module 2
Errors, Complex Systems, and Analyzing Data
a. Operators and Complex System
There have been extraordinary changes in the machines that affect our daily lives.
The equipment has become more complex, more sophisticated and more automated,
while becoming more central to our activities. In commercial aviation, for example, two
pilots were needed to fly the first commercially successful air transport aircraft, the
Douglas DC-3, an aircraft that was designed over 80 years ago. The DC-3 could carry
about 20 passengers at a speed of about 200 miles an hour over several hundred miles.
Today, two pilots are also needed to operate a passenger-carrying aircraft, the Airbus A-
380, but this aircraft transports over 500 passengers, several thousand miles, at speeds in
excess of 500 miles an hour. Although the acquisition and operating costs of the A-380
are many times those of its predecessor, the per-seat operating costs are lower. This has
helped to make air transportation affordable to many more people than in the DC-3'era.
Yet, there is a price that is paid for these technological advances. While the cost
of travel has gone down substantially since the DC-3 era because modern aircraft
transport more people at lower cost than previously, more people are also exposed to the
consequences of operator errors than was true of the earlier era. Accidents that occurred a
century ago, such as ship fires, exposed relatively fewer people to risk whereas today
thousands have been lost in single events, such as the 1987 sinking of a ferry in the
Philippines, or in the 1984 chemical accident in Bhopal, India.
People work with machines routinely and when they do they are machine
operators. Whether operating lawn mowers, automobiles, tablets, or power saws, people
use machines to perform tasks that they either cannot do themselves, or can perform more
quickly, accurately, or economically with the machines. Together the operator and the
machine form a system in which each is a critical and essential system component.
Complex systems, which employ machines that require multiple operators with
extensive training, support our way of life. They provide clean water and sewage
treatment, electrical power, and facilitate global finance, to name but a few. These
systems, considerably more sophisticated than, say a person operating a lawn mower,
have become so integral to our daily activities that in the event they fail whole economies
can be threatened. However, as Perrow (1999) notes, the complexity of such systems has
increased inordinately.
As our dependence on systems increases, more is asked of them, and with their
increasing technical capabilities we have witnessed increased complexity. Complex
systems are more than merely operators and equipment working together, they are
entities that typically perform numerous tasks of considerable import to both companies
and individuals.
Although complex systems need not necessarily be high-risk systems, that is,
systems in which the consequences of failure can be catastrophic, many authors apply the
terms interchangeably. Systems that are sufficiently complex are often high-risk systems,
if for no other reason than because so many people depend on them and thus interruptions
from service can dramatically affect our lives. Nonetheless, while the focus of this book
is on complex systems, the methodology to investigate human error described can be
readily applied to simple systems as well—even to the system in which one person
operates a lawn mower.
Operators interact with and control complex systems, and consequently play a
central role in system safety. Despite the diversity of skills they need, equipment used,
and settings in which they operate, one term can be used to describe them. While some
have used terms such as “actor,” “technician,” “pilot,” “controller,” and “worker,” the
term operator will be used presently. In reference to maintenance activities, the terms
technician and inspector will be used, as appropriate.
Whether it is a financial, air transport, or electrical generating system, operators
essentially perform two functions: they monitor the system and they control its
operations. To do so, they obtain information from the system and its operating
environment, using their knowledge and experience, with the information, to understand
the system state. Based on their understanding of the system, they modify operations, as
needed, according to operational phase and the system-related information they perceive.
Because of the potential severity of the consequences of error in complex systems,
operators are expected to be skilled and qualified. They are the first line of defense in
trying to limit the effects of system anomalies from becoming catastrophic. However,
operators sometimes precipitate rather than prevent system incidents or accidents.
The changes that have taken place over time in the complexity of these systems
have fundamentally altered the relationship between operators and the machines they
control. Once directly controlling the machines, operators now largely supervise their
operations. These tasks are typically performed at a higher cognitive and a lower physical
level than was true of operators of earlier times who largely controlled the machines
manually.
Charles Perrow (1999) suggests that complex systems have changed to the extent
that “interactive complexity” and “tight coupling” have made “normal accidents”
inevitable. That is, as systems have become more efficient, powerful, and diverse in the
tasks they perform, the consequences of system failures have grown. In response,
designers have increased the number of defenses against system malfunctions and
operator errors, thus increasing internal system complexity. At the same time, systems
have become tightly coupled, so that processes occur in strict, time-dependent sequences,
with little tolerance for variability. Should a component or subsystem experience even a
minor failure, little or no “slack” would be available within the system, and the entire
process could be impacted. The combination of increased complexity and tight coupling
has created system states that neither designers nor operators had anticipated.
It seems difficult to accept that fundamental characteristics of complex systems
have made catastrophic accidents “normal.” Perrow, however, has greatly influenced how
incidents and accidents in complex systems are considered by focusing not on the
operator as the cause of an accident or incident but on the system itself and its design.
James Reason (1990, 1997), the British human factors researcher, expanded on
Perrow’s theory by focusing on the manner in which system operation as well as system
design can lead to errors. He suggests that two kinds of accidents occur in complex
systems: one results from the actions of people, which he terms “individual accidents,”
and the other “organizational accidents,” which results largely from the actions of
companies and their managers.
Vicente (1999) elaborates on the work of Reason and Perrow and identifies
elements of what he refers to as “sociotechnical systems,” which have increased the
demands on system operators. These include the social needs and different perspectives
of team members that often operate complex systems, the increasing distance among
operators and between operators and equipment, the dynamic nature of systems,
increasing system automation, and uncertain data. By escalating the demands on
operators, each element has increased the pressure on them to perform without error.
Human fallibilities being what they are, there will always be a possibility that an
operator will commit an error, and that the consequences of even “minor” errors will
present a threat to the safety of complex systems. Some, such as Senders and Moray
(1991), Hollnagel (1993), and Reason (1997), suggest that the impossibility of
eliminating operator error should be recognized, by focusing not on error but instead on
minimizing the consequences of errors.
b. Human Error
Most errors are insignificant and quickly forgotten. The relatively minor
consequences of most human errors justify the relative inattention we pay them. Some
circumstances even call for errors, such as when learning new skills. Children who learn
to ride bicycles are expected to make numerous errors initially, but fewer errors as they
become more proficient, until they reach the point of riding without error. Designers and
training professionals, recognizing the value of errors in learning environments, have
developed system simulators that enable operators to be trained in operating systems in
realistic environments, free of the consequences of error.
People require feedback after they have erred; without it, they may not even
realize that they have committed errors. Someone who forgets to deposit money into a
checking account may continue to write checks without recognizing that the account
lacks sufficient funds. That person would not likely be considered to be committing an
error each time he or she wrote a check. Rather, most would consider the person to have
committed only one error—the initial failure to deposit funds into the account.
It should be apparent that the nature of errors and the interpretation and
determination of their significance are largely contextual. Turning a crank the wrong way
to close an automobile window is a minor error that would probably be quickly forgotten.
On the other hand, turning a knob in the control room of a nuclear power plant in the
wrong direction can lead to a nuclear accident. Both errors are similar—relatively simple
acts of rotating a control in the wrong direction—yet under certain conditions an
otherwise minor error can cause catastrophic consequences. What ultimately
differentiates errors are their contexts and the relative severity of their consequences.
c. Theories of Error
Modern error theory suggests that in complex systems, operator errors are the
logical consequences of antecedents or precursors that had been present in the systems.
Theorists have not always considered system antecedents to play as large a role in error
causation as is considered today. Freud and his students believe that error is a product of
the unconscious drives of the person. Those who erred are considered less effective and
possibly more deficient than those who do not, an interpretation that has had wide
influence on theories of error and on subsequent research. For example, the concept of
“accident proneness,” influenced by Freud’s view of error, attributed to certain people a
greater likelihood of committing errors than to others because of their personal traits.
However, studies have found serious methodological deficiencies in the initial studies
upon which much of the later assumptions about error proneness had been based. For
example, the failure to control the rates of exposure to risk minimized the applicability of
conclusions derived. Lawton and Parker conclude, “…it proved impossible to produce an
overall stable profile of the accident-prone individual or to determine whether someone
had an accident-prone personality”. The application of Freud’s theories (he used multiple
theories to explain human behavior) outside of clinical settings has largely fallen into
disfavor as both behavioral and cognitive psychological theories have gained increasing
acceptance. Unlike Freud, error theorists since his day consider the setting in which
errors are committed when examining error to be far more important than the
characteristics of the person committing the error.
Heinrich was among the first to systematically study accident causation in
industrial settings. He suggested that incidents and accidents can be prevented by
breaking the causal link in the sequence or chain of events that led up to them. Focusing
on occupational injuries, that is jobrelated injuries, he suggested that accidents result
from a sequence of events involving people’s interactions with machines. One step leads
to others in a fixed and logical order, much as a falling domino causes subsequent
standing dominoes to fall, ultimately leading to an incident or accident. Heinrich
suggested that incidents and accidents form a triangle or pyramid of frequency, with non-
injury incidents, which occur the least often, located at the bottom of the pyramid,
incidents with minor injuries, which occur more often than non-injury incidents, at the
middle of the pyramid, and accidents with serious injuries, which occur the least often, at
the top of the pyramid.
To Heinrich, two critical underlying factors leading to accidents were personal or
mechanical hazards resulting from carelessness and poorly designed or improperly
maintained equipment. Carelessness and other “faults” were, to Heinrich, the result of
environmental influences, that is, the environment in which people were raised, or traits
that they inherited. Heinrich’s work, with its systematic study of accident causation, had
considerable influence on our view of accident causation. Coury, Ellingstad, and Kolly
wrote that as a result of Heinrich’s work, many have come to view accident causation as
a series of links in a chain, to be prevented by breaking the link or sequence of events.
Norman studied both cognitive and motor errors and differentiated between two
types of errors: slips and mistakes. Slips are action errors or errors of execution that are
triggered by schemas, a person’s organized knowledge, memories, and experiences. Slips
can result from errors in the formation of intents to act, faulty triggering of schemas, or
mental images of phenomena, among other factors. He categorized six types of slips,
exemplified by such relatively minor errors as striking the wrong key on a computer
keyboard, pouring coffee into the cereal bowl instead of the cup adjacent to the bowl, and
speaking a word other than the one intended.
Mistakes are errors of thought in which a person’s cognitive activities lead to
actions or decisions that are contrary to what was intended. To Norman, slips are errors
that logically result from the combination of environmental triggers and schemas.
Applying the lessons of slips to design, such as standardizing the direction of rotation of
window cranks in automobiles, would, to Norman, reduce the number of environmental
triggers and therefore reduce the likelihood of slips.
Jens Rasmussen, a Danish researcher, expanded the cognitive aspects of error that
Norman and others described, by defining three levels of operator performance and three
types of associated errors: skill-, knowledge-, and rule-based. Skill-based performance,
the simplest of the three, relies on skills that a person acquires overtime and stores in
memory. Skill-based performance errors are similar to Norman’s slips in that they are
largely errors of execution. With rule-based performance, more advanced than skill-
based, operators apply rules to situations that are similar to those that they have
encountered through experience and training. Rule-based performance errors result from
the inability to recognize or understand the situations or circumstances encountered. This
can occur when the information necessary to understand the situation is unavailable, or
the operator applies the wrong rule to unfamiliar circumstances.
Rasmussen maintains that the highest level of performance is knowledgebased.
Rather than applying simple motor tasks or rules to situations that are similar to those
previously encountered, the operator applies previously learned information, or
information obtained through previous experience, to novel situations to analyze or solve
problems associated with those situations. Knowledge-based performance errors result
primarily from shortcomings in operator knowledge or limitations in his or her ability to
apply existing knowledge to new situations.
James Reason enlarged the focus of earlier definitions of errors and further
distinguished among basic error types. He defines slips as others have—relatively minor
errors of execution, but he also identifies an additional type of error, a lapse, which he
characterizes as primarily a memory error. A lapse is less observable than a slip and
occurs when a person becomes distracted when about to perform a task, or omits a step
when attempting to complete the task.
Reason also distinguishes between mistakes and violations. Both are errors of
intent—mistakes result from inappropriate intentions or incorrect diagnoses of situations,
violations are actions that are deliberately nonstandard or contrary to procedures. Reason
does not necessarily consider violations to be negative. Operators often develop
violations to accomplish tasks in ways they believe would be more efficient than those
accomplished by following procedures that designers and managers developed. By
contrast, Reason considers a deliberate act, intended to undermine the safety of the
system, to be sabotage. Reason’s categorization of errors corresponds to Rasmussen’s
performance-based errors. Slips and lapses are action errors that involve skillbased
performance while mistakes involve either rule- or knowledge-based performance.
Reason, however, added to previous error theories by addressing the role of
designers and company managers in operator errors, that is, those who function at the
higher levels of system operations, at what he labels the “blunt end” of a system. Those at
the blunt end commit what he terms “latent errors” referred to as “latent conditions”
within a system. Operators, located at the “sharp end” of a system, commit what he calls
“active errors,” errors that directly lead to accidents. Operators’ active errors are
influenced, Reason argues, by latent errors that those at the blunt end have committed,
errors that lie hidden within the system. Although active errors lead to consequences that
are almost immediately recognized, the consequences of latent errors may go unnoticed
for some time, becoming manifest only when a combination of factors weaken system
defenses against active errors. Designers and managers place internal defenses in systems
to prevent errors from leading to incidents and accidents in recognition of the potential
fallibility of human performance. However, should the defenses fail when an operator
commits an error, catastrophic consequences could occur.
Reason illustrates how company-related defenses and resident pathogens affect
safety by pointing to slices of Swiss cheese that are lined up against each other.
Unforeseen system deficiencies, such as questionable managerial and design decisions,
precede managers’ actions. These lead to “psychological precursors” among operators
such as reactions to stress or to other aspects of the “human condition,” and to unsafe
acts. These represent the holes in the Swiss cheese whereas the solid parts of the cheese
slices represent company defenses against the hazards of unsafe acts. If the Swiss cheese
slices were placed one against the other, the holes or deficiencies would be unlikely to
line up in sequence.
To Reason, even though managerial and design errors are unlikely to lead directly
to accidents and incidents, an examination of human error should assess the actions and
decisions of managers and designers at the blunt end at least as much, if not more, than
the actions of the system operators at the sharp end. His description of the role of both
design and company-related or managerial antecedents of error has greatly influenced our
understanding of error, largely because of its simplicity, rationality, and ease of
understanding. Further, his approach to developing a model to explain error causation
was also influential. For example, the International Civil Aviation Organization (ICAO)
has formally adopted Reason’s model of error for its member states to facilitate their
understanding of human factors issues and aviation safety.
Researchers generally agree on the meaning of an error. To Senders and Moray, it
is “something [that] has been done which was not intended by the actor, not desired by a
set of rules or an external observer, or that led the task or system outside its acceptable
limits”. Reason (1990) sees an error as “a generic term to encompass all those occasions
in which a planned sequence of mental or physical activities fails to achieve its intended
outcome, and when these failures cannot be attributed to the intervention of some chance
agency”. Woods, Johannesen, Cook, and Sarter (1994) define error as “a specific variety
of human performance that is so clearly and significantly substandard and flawed when
viewed in retrospect that there is no doubt that it should have been viewed by the
practitioner as substandard at the time the act was committed or omitted”.
Hollnagel (1993) believes that the term “human error” is too simplistic and that
“erroneous action” should be used in its place. An erroneous action, he explains, “is an
action which fails to produce the expected result and which therefore leads to an
unwanted consequence”. He argues that one should not make judgments regarding the
cause of the event. The term erroneous action, unlike error, implies no judgment and
accounts for the context in which the action occurs.
Despite some disagreement in defining error, most researchers agree on the
fundamental aspects of error, seeing it as the result of something that people do or intend
to do that leads to outcomes different from what they had expected. Therefore, to be
consistent with these views, error will be defined in this book as an action or decision that
results in one or more unintended negative outcomes. Errors that occur in learning or
training environments, where they are expected, tolerated, and used to enhance and
enlarge a person’s repertoire of skills and knowledge, will not be considered further.
For our purposes even though researchers have described multiple types of errors,
insofar as accident or incident investigations are concerned, only two types of errors are
important, action errors and decision errors. In an action error, an operator does
something wrong, such as shuts a system down that should have continued in operation,
or does something contrary to what had been called for by company procedures. Decision
errors refer to incorrect decisions that operators make, such as misinterpreting weather
information and proceeding into an area of adverse weather. In general, errors related to
equipment control design antecedents tend to be action errors. Errors that call for
interpretation, such as navigation or understanding the meaning of multiple alarms, tend
to be decision errors.
Senders and Moray (1991) developed an error taxonomy based largely on the
work of Rasmussen, Reason, and others, to better understand errors and the
circumstances in which people commit errors. Their taxonomy suggests that error results
from one or more of the following factors, operating alone or together, the person’s
“information-processing system” or cognitive processes; environmental effects; pressures
on and biases of the individual; and the individual’s mental, emotional, and attentional
states. This taxonomy describes errors in terms of four levels; “phenomenological” or
observable manifestations of error, cognitive processes, goal-directed behaviors, and
external factors, such as environmental distractions or equipment design factors.
Shappell and Wiegmann (1997, 2001) propose a taxonomy to apply to the
investigation of human error in aircraft accidents, a model that has since been embraced
and applied by such U.S. agencies as the U.S. Coast Guard, in the investigation of marine
accidents. Expanding on Reason’s work, their taxonomy differentiates among operations
that are influenced by unsafe supervision, unsafe conditions, and unsafe acts. Unsafe acts
include various error categories, while unsafe conditions include both behavioral and
physiological states and conditions. Unsafe supervision, which distinguishes between
unsafe supervisory actions that are unforeseen and those that are foreseen, incorporates
elements that Reason would likely term latent errors or latent conditions.
Sutcliffe and Rugg (1998) propose a taxonomy based on Hollnagel’s (1993), that
distinguishes between error phenotypes (the manifestation of errors) and genotypes (their
underlying causes). They group the operational descriptions of errors into six categories
and divide causal factors into three groups: cognitive, social and company-related, and
equipment or tool design. O’Hare (2000) proposed a taxonomy, referred to as the “Wheel
of Misfortune,” to serve as a link between researchers in human error and accident
investigators seeking to apply research findings to incidents or accidents. As with
Reason, he delineates company-related defenses that could allow operator error to affect
system operations unchecked.
d. Incidents, Accidents, and Investigations
Loimer and Guarnieri (1996), in a review of accident history, described how the
meaning of term has changed over the years. Aristotle, for example, used accidents to
refer to nonessential or extrinsic characteristics of people and things. Thus, someone
could have accidental qualities, for example, one leg, and still retain human
characteristics. About the fourteenth century, the English began to use a more modern
understanding of the term, closer to that of contemporary times, that is, “to happen by
chance; a misfortune; an event that happens without foresight or expectation, a usage
initially found in Chaucer in 1374. As the industrial revolution developed in the late
eighteenth century, injuries of workers in the textile, railroad, and mining industries
began to emerge. These were new types of accidents that occurred among workers who
were operating what were then complex systems, but of course system operations
required considerably more muscular effort than is true today, with little design and
training consideration directed to worker safety. Loimer and Guarnieri noted that accident
attribution began to change around that time as well, from being considered the result of
divine influence that had been common in the middle ages to that of worker causation, for
example, carelessness, of the industrial revolution.
Coury et'al. (2010) wrote that World War II brought about considerable
complexity in systems such as aircraft used in the war effort. System complexity was also
influenced by the rapid development of and the need to quickly utilize these systems,
which called for hastily training people to operate them, factors that contributed to high
rates of training accidents. In attempting to understand the reasons for the accident rates,
researchers focused on operator error from the perspective of factors related to the design
of the system controls and displays, rather than on the operator himself or herself, a focus
that led to research to better understand how machine design can lead to error.
Today, researchers devote considerable attention to examining on the job injuries,
especially in such industries as petrochemical processing and mining (e.g., Flin, Mearns,
O’Connor, and Bryden, 2000). But the nature of accident causation is typically different
in worker injury accidents than it is in process accidents. In the former, accident
causation is largely considered the result of flaws in control design, training, or worker
attention. In the latter, the type that is the focus of this book, causation is generally
attributed to flaws in the system itself, which can include design, training, and worker
attention but typically involves elements of the entire system. Certainly, the
consequences of the two are different as well. Occupational accident consequences
primarily affect system operators while process accidents may affect the workers or
operators, but as often affect those uninvolved in system operations, such as passengers
in transportation accidents, or residents near a nuclear generating station that sustained a
radiation leak.
Senders and Moray (1991), focusing on process accidents, term an accident “a
manifestation of the consequence of an expression of an error”. Others suggest that
accidents are events that are accompanied by injury to persons or damage to property. In
this way, even minor injuries can change the categorization of an incident, typically
involving an occurrence of more minor consequences, to that of an accident, an
occurrence with often major or severe consequences. Those consequences can be injuries
to persons, damage to property, and or pollution of the air, water, or land environment.
Perrow (1999) distinguished between accidents and incidents largely by the extent of the
damage to property and injuries to persons. He considers incidents to be events that
damage parts of the system, and accidents events that damage subsystems or the system
as a whole, resulting in the immediate shutdown of the system. Although a system
accident may start with a component failure, it is primarily distinguished by the
occurrence of multiple failures interacting in unanticipated ways. Catastrophic system
accidents may bring injury or death to bystanders uninvolved with the system, or even to
those not yet born. For example, accidents in nuclear generating stations can lead to birth
defects and fertility difficulties among those exposed to radiation released in the accident.
Whether an event is classified as an incident or an accident can have considerable
influence on data analysis, research, as well as on civil or criminal proceedings.
Therefore, much attention has been devoted to the classification of accidents. Loimer and
Guarnieri (1996) describe the historic tradition, dating to the middle ages, of accident
causation being attributed to acts of god as compared to acts of people. Today, they note,
any accident that is caused, directly or indirectly, by natural causes “without human
intervention” is considered to be “an act of god.” In this respect, the March 11, 2011,
accident at the Fukushima Daiichi nuclear power plant, which occurred in the aftermath
of a magnitude 9 earthquake and subsequent tsunami, may be considered an act of god,
despite the fact that the direct cause of the nuclear accident was the flooding of the diesel
generators that provided electric power for emergency water cooling to the nuclear core.
Water from the tsunami entered and contaminated the generators, which had been placed
at ground level, thereby making them susceptible to flooding given the reactor’s
proximity to the sea. For our purposes, even though the flooding was a naturally caused
event, the placement of the generators adjacent to the sea was not, and thus investigators
would still want to examine the system shortcomings that allowed the tsunami to result in
a nuclear accident.
ICAO also precisely defines injury and death associated with an accident. Injuries
include broken bones other than fingers, toes, or noses, or any of the following:
hospitalization for at least 48 hours within 7 days of the event, severe lacerations, internal
organ damage, second- or third-degree burns over 5% or more of the body, or exposure to
infectious substances or injurious radiation. A fatal injury is defined as a death from
accident-related injuries that occurred within 30 days of the accident. An incident is an
event that is less serious than an accident.
Coury et'al. (2010) reviewed the history of accident investigations in complex
systems, focusing on transportation accident investigations, and noted how the evolution
of accident investigation matched the corresponding evolution in technology. As
technology became more reliable, investigations focused less on hardware and more on
the role of those who operate the systems. Although companies often investigated the
accidents of systems they owned and operated, governments also played a role in the
investigations, often initially in the role of coroners’ inquests. Eventually, investigations
went beyond identifying the accident cause as operator error, or pilot error in the case of
aviation, to focus on the nature of the interaction between the operator and the system
being operated. Coury et'al. (2010) note that with the advent of World War II, human
factors emerged as a major element of accident invstigations. “No longer was it
acceptable,” they note, “to merely identify the type of pilot error; now the design of the
system and its contribution to the error must also be considered”.
Rasmussen, Pejtersen, and Goodstein (1994) contend that investigators examine
system events according to a variety of viewpoints. These include a common sense one,
and those of the scientist, reliability analyst, therapist, attorney, and designer,
respectively. Each influences what Rasmussen et'al. (1994) refer to as an investigation’s
“stopping point,” that is, the point at which the investigator believes that the objectives of
the investigation have been met. For example, an investigator with a common sense
perspective stops the investigation when satisfied that the explanation of the event is
reasonable and familiar. The scientist concludes the investigation when the mechanisms
linking the error antecedent to the operator who committed the error are known, and the
attorney concludes the investigation when the one responsible for the event, usually
someone directly involved in the operation who can be punished for his or her actions or
decisions, is identified. The objective advocated in this book is based on the suggestions
of Rasmussen et'al. (1994). Investigators should conduct investigations to learn what
caused an incident or accident by establishing a link between antecedent and error, so that
changes can be implemented to prevent future occurrences.
Dekker (2015) identified four purposes of accident investigations,
epistemological, that is, establishing what happened; preventive, identifying pathways to
avoidance; moral, tracing the transgressions that were committed and reinforcing moral
and regulatory boundaries; and existential, finding an explanation for the suffering that
occurred. These purposes affect the conduct of accident investigations. For example, the
existential and moral needs Dekker identified, and the public policy implications Le Coze
(2013) described, are addressed by the direct role of governments in investigations.
Relying on government rather than industry to conduct such investigations, for example,
satisfies the public need for answers to what happened, and the need for reassurance that
action will be taken to address the shortcomings that led to the accident. Stoop and
Dekker (2012), focusing on aviation accident investigations, also note the evolution of
investigations as technology has advanced, to where today we accept failure as “normal,”
where resilient 30 Investigating Human Error systems can allocate scarce safety
resources as needed in response to different system states.
Accident investigations, where investigators identify the factors that led to an
accident, analyze how those factors played a role in the circumstances in which the
accident occurred, and ultimately suggest ways to prevent their recurrence, call for data
collection and analysis skills. Unlike empirical research, which is overseen through peer
review, theory testing, and/or experimental replication, major accident investigations are
typically subject to governmental or corporate review. In addition, investigations face
time pressures that can be considerable. Unless the investigations can be conducted
quickly, the findings of the investigation could have little significance in terms of risk
mitigation and public need.
Further, analytical rules of accident investigations tend to be legalistic, using
logical consistency and the preponderance of evidence. Based on the facts gathered,
investigators develop a logical explanation of the events that led to an accident. This
generally results in identifying errors on the part of individual operators or operator teams
(including maintenance personnel), failures of some mechanical component or system, a
failure that may have been the result of an operator error, and/or errors in actions,
inactions and/ or shortcomings in decisions of organizational managers. Although some
investigative agencies shy away from identifying operator errors, the practice is still
commonplace among such investigative agencies as the United States National
Transportation Safety Board, the British Air Accidents Investigation Branch and the
Marine Accidents Investigation Branch, and the French Bureau d’Enquêtes et d’Analyses
pour la sécurité de l’aviation civile, when investigators believe that this is warranted.
These aspects of investigations affect the way in which investigations are conducted, by
emphasizing the investigators’ ability to complete the investigation in a timely manner
(i.e., “getting the job done”), while simultaneously following rigorous rules of logic.
e. From Antecedent to Error to Accident
Several assumptions about operator error in complex systems form the foundation
of the investigative approach of this book. Although the first two assumptions may seem
rather obvious, some assume the contrary, that by adding steps and operators to a task the
chances of error decrease. In fact, with certain exceptions, the opposite is true. As a task
becomes more complex and more people are needed to perform it, opportunities for error
increase. In addition, operators are rational in that they want to avoid accidents and
operate systems accordingly. Those who mean to cause accidents in effect intend
criminal acts, which call for a different investigative approach than that used in this book.
It should be noted, however, that on occasion criminal acts have been initially
investigated as accidents, until evidence of operator planning to make the event appear to
be an accident emerged (e.g., National Transportation Safety Board, 2002).
Systems that people design, manage, and operate, are not immune to the effects of
error. Because people are not perfect, designers and managers cannot design and oversee
a perfect system and operators cannot ensure errorfree performance. Operators of any
system, irrespective of its complexity, purpose, or application, commit errors.
Researchers have proposed different accident causation and investigation models,
to explain how error affects operator performance in investigations. Some, like Leveson’s
(2004) systems-theoretic accident model and processes (STAMP) model, seek to
integrate accident causation analysis with hazard analysis and accident prevention
strategies. Others, like Shappell and Wiegmann’s human factors analysis and
classification system (HFACS) model (1997, 2001), which is directly based on Reason’s
model of error causation (1990, 1997), have been widely used to analyze the role of
human factors in accident causation (e.g., Li and Harris, 2005; Schröder-Hinrichs,
Baldauf, and Ghirxi, 2011).
However, models, largely because they are directly based on theory, may be
difficult to apply in actual investigations. Accidents are unique events and investigators
must be prepared to identify data to be collected and analyzed according to the needs of
the investigation, rather than of particular theories.
Neville Moray (1994, 2000), a British human factors researcher, contends that
error in complex systems results from elements that form the systems and to investigate
system errors, one must examine the pertinent elements. He outlines these features with
concentric squares that show the equipment as a core component of the system.
To be useful for those investigating accidents, models must be practical and if not
investigators will have difficulty applying them to investigations. Models should also be
simple by avoiding complexity in explaining error or accident causation. For optimum
benefit, models should also be practical, while still adhering to research findings on error
causation. This text will eschew models in favor of a method that, based in the theories of
both Moray (1994, 2000) and Reason (1990, 1997), is designed to facilitate the task of
data identification, collection, and analysis for those investigating the role of human error
in accident and incident investigations. Because errors are unintended, one assumes that
operators want to operate systems correctly. Using Moray’s (1994, 2000) model, with
that of Reason (1990, 1997), their errors are considered to reflect system influences on
their performance. That is, the operators wanted to perform well but did not because of
shortcomings within the system.
I refer to these characteristics as precursors or antecedents to error. As Reason
argues, antecedents may be hidden within systems, such as in equipment design,
procedures, and training, where they remain unrecognized but can still degrade system
operators’ performance. The mechanisms by which each antecedent or precursor exerts
its influence varies with the context and nature of both the system element and the
antecedent itself. For example, an antecedent may distract an operator during a critical
task, hinder his or her ability to obtain critical information, or limit his or her ability to
recall or apply the proper procedure. The focus of the accident investigator therefore
should be to identify those shortcomings within the system that led to the accident.
Investigators identify the presence of an antecedent in two ways, by identifying an
action, situation, or factor that influenced the operator’s performance during the event,
and more importantly, by obtaining evidence demonstrating that the operator’s
performance was affected by the antecedent.
Antecedents in complex systems contribute to errors through unrecognized or
unacted upon shortcomings in the system. While complex systems are composed of a
multitude of components, the elements of the system in this book are general, derived
from the antecedents identified in both Moray (1994, 2000) and Reason’s (1990) models.
They can be considered latent errors or latent conditions within the system as well as
system shortcomings, inadequacies, in sum, any other system action or decision that
adversely influenced an operator’s performance.
The errors that led to accidents and incidents, whether committed by operators or
system managers, are either action errors, that is, someone did something wrong, or
decision errors, that is, someone made a decision that proved to be erroneous. Further,
because in accident causation failure to take an action or make a decision may be as
critical to the cause of the accident as taking the wrong action or making a decision that
proved to be erroneous, errors of omission should be considered as well as errors of
commission.
Keep in mind though, that the steps to be conducted in identifying both
antecedents and errors, and relating them to the accident or incident, are ongoing through
the investigation. That is, when identifying errors and searching for their antecedents,
investigators should always keep in mind the role antecedents may play in the critical
error or errors that led to the event under investigation.
f. Investigative Methodology
Accident investigation methodology and the scientific method have similar
objectives, to explain observed phenomena or events by using formal methods of data
collection and analysis. The objectives of scientific research correspond to those of
accident investigations, “[the] systematic, controlled, empirical, and critical investigation
of hypothetical propositions about the presumed relations among natural phenomena”
(Kerlinger, 1973, p. 11). Although control groups are not used in accident investigations
and the process is not empirical, accident investigators apply a systematic and critical
methodology to study the relationships between antecedents and errors, and the
relationships among those errors, to determine the extent of the relationships, if any,
between those errors and the incidents and accidents that the errors may have caused.
Investigators collect and analyze data after the fact, that is, after an accident has
occurred, using a method that is similar to “ex post facto” research designs. Here,
investigators work backward after the event has occurred and the data have been
collected, to identify and explain the nature of the variables that led to the event. Ex post
facto analytical techniques allow investigators to effectively explain the nature of the
relationships underlying the data and apply them well beyond the immediate
circumstances of the event under investigation. Well-conducted investigation analyses
fall within Vicente’s (1997) observation that, “science…encompass(es) naturalistic
observation, qualitative description and categorization, inductive leaps of faith, and
axioms that can never be empirically tested”.
However, researchers have recognized that this method, although providing
critical insights into event causation, can lead to analytical inaccuracy. Because data are
gathered after the fact, researchers and investigators can select from and apply a favored
explanation to account for the obtained results, rather than be compelled to accept the
explanation that the data offer from experimental design techniques developed before the
fact (e.g., Kerlinger, 1973). Dekker (2002, p. 374) and others refer to this as hindsight
bias, a tendency in accident investigations to lead investigators to, as he writes, make
“tangled histories” of what operators were dealing with at the time of an accident “by
cherry-picking and re-grouping evidence” to fit their view of what transpired in the
accident. However, knowledge of an operator’s error and the accident that occurred as a
result need not necessarily lead to highsight bias. In fact, investigators as a matter of
course recognize that their job calls on them to explain errors from the perspective of the
person who committed them, because doing so allows a proper analysis to be conducted
of the system flaw that led to the error.
Nonetheless, error investigators compensate for this potential limitation because
they typically obtain data on many measures, data that had been continuously collected
throughout the event, unlike researchers who generally collect data on only a few
parameters, often only at selected intervals, and under highly controlled conditions.
Further, investigators examine real world behavior under conditions that could not
reasonably be examined in controlled settings. Thus, by collecting considerable data
about an event, subjecting the data to objective and systematic analysis, and by being
sensitive to the possibility of hindsight bias, investigators can avoid allowing hindsight
bias to affect their analyses.
Although the investigative process is systematic, it is still affected by the skills
and experience of the particular investigator. For this and other reasons, some have shied
away from definitive identifications of accident “causes there is no absolute cause” of an
accident because imprecision is an inherent part of error investigations. Absolute
certainty in establishing the errors leading to an event is an impossibility.
Yet, differences in the results of incident and accident investigations between
organizations that determine a cause and those that do not suggests little difference
between them. Whether an organization determines a probable cause or not appears to
make little difference to the quality of the investigation or its proposed recommendations.
Irrespective of a requirement to develop a cause to an event, the key focus for
investigators should be on conducting a thorough and systematic investigation in order to
reduce future opportunities for error. Doing so will result in effective investigations,
regardless of the nature of the “cause” or “findings” that are determined. As Klein et'al.
(2014) note, “regardless of which causes are invoked, an explanation has to adopt a
format or argument structure for characterizing these causes”.
A hypothetical accident illustrates the process. Assume that a train failed to stop
at a stop signal (also referred to as an “aspect”) and struck another train that had been
standing on the same track. The locomotive engineer had an unobstructed view of the
signal.
The engineer claimed that he observed a stop signal and applied the brakes, but
the brakes failed. If he is correct, investigators will have to identify a mechanical
malfunction as the cause of the accident, otherwise they would unfairly fault an operator
who performed well, and worse from a safety consideration, fail to address hazards that
led to the accident in the first place. However, before they could accept the engineer’s
explanation as the most likely cause of the accident, investigators would have to test and
accept the viability of several possible conclusions that are necessary to accept a failed
brakes explanation.
Thus, investigators are faced with only two possible alternatives to the cause of
the accident, assuming that signals, track, and other train systems were not involved.
Either the engineer failed to properly apply the brakes, or he applied them correctly but a
mechanical malfunction prevented the brakes from stopping the train. To determine
which of these conclusions is supported, investigators would need to collect a variety of
system data. If the data supported these conclusions, they could be reasonably confident
that defective brakes caused the accident. If not, other explanations would need to be
proposed, and the data reexamined and reanalyzed. The data would either support or
refute the proposed explanations.
During an investigation, it is likely that investigators will collect different types of
data of varying quality. Before analyzing the data, they evaluate the collected data to
assess their value in the investigation. Not all data are of equal value and some types of
data should be given more consideration than other types.
g. Assessing the Quality of the Data
Some of the data that investigators collect will pertain to the investigation
objective while other data may not; some data sources will be complete and others not.
Including incomplete data and data that do not address the antecedents of error in the
analysis will lead to an analysis that contributes little to understanding the origin of the
particular errors, or worse, is incorrect. Determining the quality of data is critical because
the effectiveness of an investigation largely depends on the quality of the data that
investigators collect. “Garbage in-garbage out” applies to the analysis of error in
incidents and accidents as it does to other types of analysis. Two standards of quality are
used to assess data value, internal consistency and sequential consistency.
Anderson and Twining (1991), describing legal analysis, believe that internally
consistent data should converge into one conclusion. Converging data, they argue, even if
derived from different sources and collected at different times, support the same
conclusion. For example, if an operator’s performance history reveals deficiencies and
those deficiencies are similar to characteristics of the operator’s performance at the time
of the occurrence, the data converge. In that instance, one could reasonably conclude that
the operator’s performance during the event was consistent with his performance in
previous, similar circumstances and not an aberration. In complex systems, internally
consistent data converge by depicting different aspects of the same event similarly, at the
same points in time. If they do not, the data will not be internally consistent.
If the brakes had been defective and investigators determined that the defect
caused the accident, internally consistent data should reveal the effects of the defect
among a variety of types of data. All data, except those pertaining to the brakes and those
independent of the sequence of antecedents and errors/flaws leading to the event, should
be consistent. However, if the data showed defects in other components that could have
altered the sequence of occurrences, or if the brakes were found to have been defect free,
the data would be inconsistent and the discrepancy would need to be resolved.
Inconsistencies could be caused by deficiencies either in the data or in the
proposed theory or explanation of the cause of the event. Deficiencies in the equipment-
related data could result from flaws in the recording devices, measuring instruments, or,
with eyewitnesses, in their perceptions and recall of the event. Inconsistencies in
operator-related data could be caused by any of several factors that will be discussed
shortly. Otherwise, inconsistent data indicate the need to revise the theory or explanation
of the cause of the accident, to reexamine the data, or to collect additional data.
Likely sources of inconsistent data. Inconsistencies among the data, though rare,
are most often found among eyewitness accounts and operator-related information.
Substantial differences among eyewitness accounts are infrequent, but, as investigators
found in the explosion of the Boeing 747 off the coast of Long Island, occur occasionally
(National Transportation Safety Board, 2000a).
Several factors may explain differences in operator-related information. For one,
people interact differently with operators than they do with others, based on their
relationships with them. Colleagues, acquaintances, and supervisors have different
perceptions of the operator than would his or her family members, and these perceptions
will affect the information they give interviewers
Investigators can safely discard inconsistent data, if the inconsistency is not a
result of deficiencies in the way the data were collected and if it can be safely attributed
to factors related to investigation shortcomings or to the event itself. Investigators of the
1999 collapse of logs being prepared for a bonfire at Texas A & M University that
resulted in 12 deaths, discarded numerous eyewitness reports that were not supported by
the physical evidence, or were otherwise irrelevant (Packer Engineering, 2000; Special
Commission, 2000).
Because the physical evidence contradicted many of the eyewitness accounts, and
because the inconsistencies between the eyewitnesses reports and the other data did not
result from factors related to the event or investigation shortcomings, investigators could
confidently discard the inconsistent eyewitness data without affecting the quality of the
subsequent analysis and the strength of the findings and conclusions.
Investigative data should consistently match the sequence of occurrences and the
period of time in which they occurred. The sequential relationships between antecedents
and errors are invariant; antecedents will always precede errors and errors will always
precede the event.
In the railroad accident example used earlier, if a signal commands a stop,
locomotive event recorders would be expected to show, in order, power reduction first
and then brake application, corresponding to the order of the expected operator actions.
The data should also match the passage of time corresponding to the occurrence, in the
actual period in which the train approached the signal and struck the standing train.
Regardless of the rate at which actions occur and system state changes, the two should
correspond. Specific operator actions must still occur in certain orders and within specific
periods of time, after certain events have taken place. Further, specific operator actions
should precipitate specific equipment responses. Sequentially inconsistent data may be
the result of inaccurate data recorders, defective measuring devices, or deficiencies
within the data. If the inconsistencies cannot be resolved satisfactorily, investigators may
need to collect additional data, or reexamine the data selection and collection methods to
resolve the inconsistencies.
h. Data Value
Data vary in their value and contribution to the investigation. Depending on the
event and the data, investigators may rely on some data to understand what happened and
why and ignore other data. The greater the reliability, accuracy, and objectivity of the
data, the greater their value to, and influence upon, the analysis. Reliable and objective
data from different sources should describe the same phenomenon the same way, albeit
from different perspectives, regardless of their sources.
In general, “hard” data, data obtained directly by the system, contribute
substantially to the investigation because of their high reliability, objectivity, and
accuracy. By contrast, the value of “soft data,” such as eyewitness accounts and interview
data, is less because the data can change as a function of the person collecting the data,
the time of day the data are obtained, and the skill of the interviewer or person collecting
the data, among other factors.
Anderson and Twining (1991), referring to legal analyses, consider a statement
relevant if it tends to make the hypothesis to be proven more likely to be supported than
would otherwise be the case. Data that can help explain conclusions regarding the cause
of the event, the critical errors, and the antecedents to the errors, are analogous to data
that can support the hypothesis and are considered relevant to the investigation.
Most investigators routinely gather data that may not necessarily relate to their
investigations but are needed to rule out potential explanations or factors. If it is
determined that an operator did not commit an error, one can exclude data from the
analysis that pertains to the operator’s performance history without degrading the quality
of the analysis or the investigation, unless the data relate to other critical issues. On the
other hand, if operator error is believed to have led to the incident, almost all data
concerning the operator would be considered relevant and therefore would be included in
the analysis.
Data relevance can change as more is learned about an event. For example, an
initial focus on potential training deficiencies makes information pertinent to the
development, implementation, and conduct of the training relevant to the investigation. If
the data suggest that equipment design factors rather than training affected operator
performance, operator training-related data would be less relevant.
The more data obtained about a particular aspect of the system, the more
confidence one can have in the value of the data and their contribution to the analysis.
For example, in some systems, multiple recorders capture a variety of operator
performance parameters, documenting the operator’s spoken words and any related
sounds. These provide a considerable amount of data that describe, both directly and
indirectly, what the operator did before and during the event.
If there are little data available, other measures that can approximate the
parameters of interest should be sought. If no data directly describe aspects of operator
performance, investigators may need to learn about operator actions from other sources,
such as from system recorders. If there are insufficient data available to allow inferences
about the parameters of interest, conclusions regarding the data of interest will have little
factual support.
i. Identifying the Errors
After the data have been examined and evaluated, one can begin to propose
relationships among antecedents, errors, and the causes of the event. To begin developing
the critical relationships, first establish the sequence of actions and occurrences in the
event. The sequence will determine the order of actions and decisions, and facilitate the
task of identifying the critical relationships.
Establish the sequence of occurrences in the event by working backward from the
event itself until the errors that led to the event, and the antecedents to those errors, are
reached—what Rasmussen, Pejtersen, and Goodstein (1994) refer to as the “stopping
point.” Regardless of the event, whether an airplane accident, chemical refinery
explosion, or vessel grounding, stop collecting data and analyzing the data at the point at
which the sequence of occurrences that led to the incident or accident begins.
Using the railroad accident discussed earlier, the sequence of occurrences begins
with the collision. Working backward from the event, occurrences earlier in the sequence
would likely include the engineer’s brake application and power reduction, and progress
to company brake maintenance practices, going as far back as brake manufacture and
locomotive assembly.
The sequence of occurrences includes major system elements. In this illustration,
these would include the operator, the railroad, the regulator, and the brake system.
However, a few issues should be ruled out early in the investigation. Data pertinent to
those issues need to be collected to determine the role of each element in the event.
For example, if it is learned that the locomotive engineer did not apply the brakes
properly, then operator actions would be a focus of the investigation'and'investigators
would need to identify potential antecedents to those actions. Other issues to be
investigated would likely include the railroad’s training and oversight of its operators,
and the regulator’s oversight of the railroad. Although each accident is unique with its
own set of occurrences, the critical facts, in this instance the collision, the record of
inspections of the'brakes and their manufacture, would not be in dispute. A list of an
initial sequence of'occurrences of the hypothetical railroad accident is illustrated below.
After examining the data, assessing their relative value, and establishing the
sequential order of occurrences, investigators can exclude from the analysis several
additional factors that would no longer be considered relevant to the accident. For
example, if tested and found to have been in acceptable condition at the time of the event,
factors related to the signal system may now be considered irrelevant.
j. Assessing the Relationship of Antecedents to Errors
After identifying the errors, the antecedents of those errors must be determined.
The process is largely inferential, based on investigative logic regarding the relationship
between the two. The evidence consists of the nature of the error, and information from
written documentation, interviews, system recorders, equipment, and other sources. A
relationship between antecedent and error must be logical and unambiguous.
Investigators must establish that the antecedent, either by itself or with others, influenced
the operator’s performance so that he or she committed an error. To identify the
antecedent, one should ask a counterfactual question, would the operator have committed
the error if this (and other) antecedent(s) had not preceded it? If the answer is no, one
could be confident that the antecedent led to the error. Counterfactual questions are
central to analyzing error data in investigations.
Assume that insufficient operator experience is one of several antecedents that
affected the performance of an operator, and the operator misinterpreted system-related
data as a result. A relationship between experience in operating a system and the error of
misinterpreting data is logical; a more experienced operator is less likely to commit the
same error than a less experienced one. This conclusion is supported by research findings
and the determinations of previous accident investigations. This relationship between
antecedent and error is clear and unambiguous, reached only after the necessary facts
have been obtained and analyzed.
The logic used to establish a relationship between antecedents and errors is
analogous to multiple regression analysis, a statistical technique used to determine the
relationship between one or more predictor variables and a single variable (e.g., Harris,
1975). Economists, for example, employ multiple regression analysis to predict the
combined effects of changes in variables such as the prime interest rate, unemployment,
and government spending, or changes in an outcome variable such as inflation rate.
The stronger the relationship between the predictor or influencing variables and
the outcome variable, the higher the correlation between the two sets of variables. In
relationships that have high positive correlations (say 0.60 or higher since correlations of
plus or minus one are the limits of correlational strength), changes in the predictor
variables are associated with corresponding changes in the outcome variables. As the
value of predictor variables increases or decreases, the value of the outcome variable
similarly increases or decreases. If the correlations are negative, predictor variable
changes in one direction would be associated with outcome variable changes in the
opposite direction. As the predictor variables increase or decrease in value, the outcome
variable loses or gains value in the opposite direction.
Multiple regression analyses also describe another facet of these relationships that
can be stated statistically; when the correlation between the two sets of variables is high
the predictor variables account for much of the total variance in changes in the outcome
variable. That is, the higher the correlation between the two, the more that changes in the
predictor variables—and not some other variable or the effects of chance—are associated
with changes in the outcome variable. The lower the correlation, the less that changes in
the outcome variable can be attributed to changes in the predictor variables. In that case,
changes in the outcome variable will more likely be associated with variables that had not
been considered in the analysis.
In investigations of error, the predictor variables correspond to the antecedents
and the outcome variable to the critical error. Investigators assess the relationship
between one or more antecedents and the operator’s error in the circumstances that
prevailed at the time of the accident. The stronger the relationship between the
antecedents and errors, the more the antecedents would account for “variance” about the
errors, and the more the error can be attributed to those antecedents, and not to other
variables or antecedents not yet recognized.
To determine with confidence that a proposed error has contributed to the cause
of the event, ask a counterfactual question; would the accident have occurred if this error
had not been committed? If the answer is no, the accident would not have occurred, one
can be confident that the error caused or contributed to the cause of the accident.
Using the train collision illustration, assume that (1) the brake defect resulted
from a maintenance error and (2) the defect was sufficiently conspicuous that inspectors
should have noticed it during routine inspections, but they did not. In addition to the
errors of those involved in the brake maintenance, the investigation would also examine
the inspectors’ errors and consider them contributory to the accident. In this accident, if
neither error had been committed, the accident would not have occurred. Both errors are
needed for the accident to occur, and each can be considered to have led to the accident.
If the maintenance error has been identified, the list of relevant occurrences to be retained
can be further narrowed, with a concomitant expansion of the list of those excluded, as
illustrated below. This list includes the accident itself, the errors that directly led to it, as
well as the antecedents that may have allowed the errors to occur.
k. Multiple Antecedents
In complex systems, multiple antecedents often influence operator performance.
Multiple antecedents can affect performance cumulatively, by increasing the influence of
each to bring a greater total influence on operator performance than would otherwise be
the case, and they can interact with each other to differentially affect performance.
Investigators should search for the presence of multiple antecedents, even if one
antecedent appears to adequately explain the error.
Multiple antecedents can increase each antecedent’s influence on operator
performance so that their cumulative total influence is greater than would otherwise be
true. For example, individual antecedents of fatigue can cumulatively influence
performance beyond that of individual antecedents, as investigators found in a 1998
accident involving a commercial bus. The bus'driver fell asleep while at the controls, and
the bus ran off the road and struck a parked truck as a result (National Transportation
Safety Board,'2000b).
Investigators identified three antecedents of the driver’s fatigue. Individually,
each may have been insufficient to have caused him to fall asleep while operating the
vehicle, but combined, their effects were substantial. Toxicological analysis of a
specimen from the driver’s body revealed the presence an over-the-counter sedating
antihistamine that he had consumed earlier to treat a sinus condition. He had also worked
at night for several consecutive days before the accident, after having maintained a
daytime awake/ nighttime asleep pattern, a schedule change that had disrupted his sleep
patterns and caused a sleep deficit. Further, the accident occurred at 4:05 a.m., a time
when he would ordinarily have been in his deepest phase of sleep. Those who stay awake
at that time are especially prone to the effects of fatigue. Combined, the effects of the
sedating antihistamine, disruptive schedule, and time of day were sufficiently powerful
that the driver was unable to stay awake.
Interacting antecedents can differentially affect operator performance. That is,
two or more antecedents together will affect performance differently than the antecedents
would have if acting on their own. To illustrate, assume that the control rooms of two
electrical power generating stations, designed 5 years apart, are identical in all respects
except that one employs “older” analog gauges and the other “newer” digital displays to
present system information. The same information is shown in both, and in both
generating station operators have received identical training and use identical procedures.
Further, in a certain nonroutine situation, the displays present information that
requires the operators to respond. Only one of two responses is possible for that situation,
either correct or incorrect. With no interaction, differences in operator response would be
affected either by their experience or by the display type, or there would be little or no
difference in their responses. Inexperienced operators might respond erroneously while
experienced ones would not, or operators working with the “newer” displays could
respond correctly though the others not. Alternatively, with no interaction all four groups
could perform correctly or all could commit errors, in which case the effects of either
operator experience or display type would lead to performance that is independent of the
other. An interaction occurs when experience and display type interact to differentially
affect operator performance. Operators committing the greatest number of errors could be
the inexperienced ones who worked with the “older” displays. Alternatively, experienced
operators working with the “newer” technology could commit the greatest number of
errors, and the inexperienced operators working with analog displays, the fewest.
Students also viewed