Pattern/Operations and Risk/No. 0679
Normalization of Deviance
Normalization of deviance is the process by which departures from standards become normal after repeated use without visible harm. Sociologist Diane Vaughan named it in her study of NASA’s Challenger decisions, showing how past success can replace evidence of safety.
- Evidence
- Well established
- Read
- 6 min
- Links
- 11 connections
01You've seen this when…
- in life
Your tire-pressure warning light comes on. After three weeks of uneventful driving, you stop noticing it when you start the car.
- at work
Operators bypass a machine guard to clear jams faster. Nobody gets hurt, and the next hire learns the bypass as part of the job.
- out in the world
A transit agency repeatedly postpones track inspections to keep trains running. With no derailments, another postponement becomes a scheduling decision rather than a safety exception.
02The idea
At first, a departure from normal practice needs an explanation. Someone approves an exception, records a concern or promises a repair. After several uneventful repetitions, the explanation gets shorter. Eventually, nobody asks for one.
Normalization of deviance is the process by which departures from expected standards become accepted as normal. The departure might be a skipped check, a disabled safeguard or equipment behaving outside its intended limits. Each apparently successful repetition makes the next one easier to accept.
The crucial shift is from we have tolerated this before to this is acceptable. An absence of visible harm starts doing the work that testing, inspection or a sound technical explanation should do.
Deviance here does not necessarily mean deliberate misconduct. People may investigate anomalies, follow approval procedures and sincerely believe their decisions are reasonable. The danger is that the standard of acceptable risk moves without evidence strong enough to justify the move.
Unlike habituation, which means responding less to a repeated stimulus, this process can change an organization’s shared judgment about what is safe.
03Why it happens
- A safe outcome looks like proof of a safe process. If the equipment ran yesterday, keeping it running today feels justified. But a weakness may need an unusual combination of conditions to cause harm. This is outcome bias: judging the decision by how it turned out.
- The benefit arrives before the cost. Skipping a check saves twenty minutes immediately. The possible accident remains distant and uncertain. Schedule pressure makes the immediate gain especially persuasive.
- Each exception becomes a precedent. A decision made under one set of conditions gets reused under another. Yesterday’s temporary workaround becomes today’s operating procedure, even if the original limits no longer apply.
- New people inherit the practice, not its history. A newcomer sees experienced colleagues using the shortcut. They may never learn that it began as an emergency exception or depended on a safeguard that has since disappeared.
- Approval can hide unresolved uncertainty. Once a review labels a concern acceptable, later teams may treat that label as evidence rather than revisit the reasoning behind it.
These choices often make sense to the people making them under their immediate constraints. That local rationality helps explain why the pattern can develop without anyone intending to weaken safety.
04A worked example
Before the Challenger disaster, shuttle missions had shown erosion of O-rings in solid rocket booster joints and, in some cases, evidence of hot gas getting past the primary seal. The flights returned safely. Engineers studied the damage and developed explanations for why the joints retained adequate protection. Repeated launches proceeded despite unresolved concerns.
On January 28, 1986, Challenger launched in unusually cold conditions. Some contractor engineers had opposed launching in the cold; contractor management reversed an initial recommendation to delay. A joint seal in the right booster failed, and all seven crew members died.
What it looks like A series of reviewed technical judgments supported by previous flights that survived similar anomalies.
What’s actually going on Evidence that the seals were not performing as intended had become part of the accepted flight history. Successful returns helped support continued acceptance of the problem, although they did not establish safety under the conditions of the next launch. Diane Vaughan’s account emphasizes this developing organizational process, not simply a last-minute decision to ignore danger.
What would have helped Treating recurring seal damage as an unresolved challenge to the safety case; requiring evidence relevant to the proposed launch conditions; and preserving a clear route for technical objections to trigger independent review. The safety case needed an explanation of why the system would remain safe in the cold, beyond the record of earlier success.
05How to spot it
06What to do about it
- Give exceptions an owner and an end date. Record what changed, why it was allowed, which conditions make it acceptable and when normal operation must resume. Review repeated exceptions together, not as unrelated requests.
- Ask what would show the practice is unsafe. Use a falsification test: identify evidence that would overturn the current safety judgment. If no conceivable result would stop the practice, the review is not doing much reviewing.
- Track degraded safeguards, not just accidents. Repeated alarms, overdue inspections and disabled protections can reveal trouble while the injury count stays at zero. These are leading indicators, though each still needs interpretation.
- Compare actual work with the written process. Observe a shift or walk through a task with the people doing it. The gap between work as imagined and work as done may reveal both unsafe shortcuts and impractical rules.
- Make raising a concern useful and safe. Give staff a route to pause work or request independent review without punishment. Psychological safety helps concerns surface; authority and resources are needed to resolve them.
- Fix the pressure that produces the workaround. Repair the equipment, redesign the task or adjust the schedule. Demanding compliance while leaving an impossible workload unchanged often drives deviations out of sight.
07When it isn’t normalization of deviance
A departure from a rule can be safe. Procedures can be outdated, poorly designed or unsuitable for an unexpected situation. Workers sometimes find a safer method.
The distinction is how the new practice earns acceptance. A deliberate change supported by relevant testing, explicit limits and monitoring differs from a workaround accepted mainly because nothing bad has happened yet.
Technical evidence is needed to judge whether a tolerated anomaly predicts disaster. Drift into failure is a broader account of how systems gradually become vulnerable; normalization of deviance describes one way their judgments and standards can change along the way.
08Roots
After Challenger, sociologist Diane Vaughan looked beyond the dramatic disagreement on the eve of launch. She traced NASA’s longer history through flight histories, technical reports, review records and interviews. She wanted to understand how capable people could come to regard a troubled component as acceptable to fly.
Vaughan’s account challenged the simple story of managers knowingly trading lives for a deadline. She traced how technical interpretations shaped successive decisions and how organizational routines and production pressures influenced those choices. O-ring damage was investigated and explained, yet repeated acceptance gradually changed what counted as normal. Her 1996 book, The Challenger Launch Decision: Risky Technology, Culture, and Deviance at NASA, named the process normalization of deviance.
The term traveled into aviation safety discussions and found the same use in healthcare and industrial operations: it explained something that a warning against carelessness missed. A system can become less safe through ordinary reviews conducted by conscientious people. Ask who broke a rule and how a departure came to stop looking like a departure.
09How solid is this?
The pattern is well documented in accident investigations and organizational research, especially Vaughan’s Challenger analysis. The evidence is mainly historical and qualitative; whether a particular deviation is dangerous still requires separate technical evidence.
10Connections
- Often confused with Habituation, Drift into Failure
- Countered by Falsification Test, Psychological Safety, High-Reliability Organization
- Can lead toLatent Conditions
- Can follow from Outcome Bias
- See alsoLocal Rationality, Work-as-Imagined vs. Work-as-Done, Leading vs. Lagging Indicator, Swiss Cheese Model
+ 1 more in the list
11Origin and sources
Sociologist Diane Vaughan named and developed the concept in The Challenger Launch Decision (1996), through her analysis of NASA’s acceptance of recurring technical anomalies before the Challenger disaster.
- [1]Vaughan, D. (1996). The Challenger Launch Decision: Risky Technology, Culture, and Deviance at NASA. University of Chicago Press.
- [2]Presidential Commission on the Space Shuttle Challenger Accident. (1986). Report of the Presidential Commission on the Space Shuttle Challenger Accident. U.S. Government Printing Office.
- [3]Vaughan, D. (1999). The Dark Side of Organizations: Mistake, Misconduct, and Disaster. Annual Review of Sociology, 25, 271–305.
Suggest an edit· Updated 2026-10-02