Pattern/Operations and Risk/No. 1009
Swiss Cheese Model
The Swiss Cheese Model is James Reason’s framework for explaining how accidents occur when gaps in several defenses align. In safety science, it links active failures and latent conditions, showing how flaws in a protective system can let a hazard pass through.
- Evidence
- Useful, modest evidence
- Read
- 6 min
- Links
- 10 connections
01You've seen this when…
- in life
A scam message reaches your inbox. You enter your password on the linked page, then approve the login prompt you assume belongs to you.
- at work
An invoice with changed bank details passes through a rushed payment review and a second approver who checks only the amount. The transfer goes to the wrong account.
- out in the world
A hospital’s prescribing screen accepts an excessive dose. The pharmacist misses it during a busy shift, and the bedside check confirms the patient’s identity without checking whether the dose makes sense.
02The idea
After an accident, attention usually lands on the last person who could have stopped it. The nurse gave the medication. The operator pressed the button. The reviewer approved the transfer. But a serious failure often requires several protections to fail together.
James Reason pictured those protections as slices of Swiss cheese. Each slice represents a defense. Some defenses are built into equipment design. Others take the form of automatic warnings and reviews, or procedures and recovery measures. Each has holes where it cannot reliably stop a hazard. An accident becomes possible when the holes create a path through the defenses.
Some holes come from active failures: mistakes or unsafe actions close to the work. Others come from latent conditions: confusing interfaces, understaffing, weak maintenance, or management decisions whose consequences remain hidden until circumstances expose them.
The holes change with circumstances. A check that works on a quiet morning may fail during a night shift with three urgent demands. The model shifts attention from the final mistake to the whole protective system: what should have caught it, and what caused those defenses to fail?
03Why it happens
- Every safeguard has limits. A warning detects only certain conditions. A checklist depends on someone using it. A reviewer can miss what they do not understand. A defense’s reliability determines how much protection it provides.
- One weakness can affect several defenses. Two reviewers may trust the same incorrect record. A power failure may disable both the primary system and its backup. This is common-cause failure, and it makes apparently separate layers less independent than they look.
- Weaknesses accumulate quietly. Maintenance slips, staffing gets tighter, and exceptions become routine. If nothing bad happens immediately, the changes can look harmless. That is one route into drift into failure.
- Pressure exposes gaps at the same time. A surge in demand can exhaust staff as it shortens reviews and delays repairs. In tightly coupled systems, a problem can also move faster than people can detect and contain it.
In the model, one organizational condition can undermine multiple protections on its own.
04A worked example
On January 16, 2003, insulation foam broke away from the space shuttle Columbia’s external tank during launch and struck its left wing. On February 1, Columbia broke apart during reentry, killing all seven crew members.
What it looks like A catastrophic physical accident caused by a piece of foam damaging the wing.
What’s actually going on The Columbia Accident Investigation Board found that organizational causes mattered alongside the physical damage. Foam had fallen from the external tank on earlier missions without destroying a shuttle. That history helped turn an unresolved hazard into an accepted feature of operations, an example of normalization of deviance. During Columbia’s flight, engineers sought better imagery to assess possible damage, but those efforts did not produce the needed images. Damage assessments and management decisions failed to resolve the uncertainty about the wing’s condition.
In Swiss-cheese terms, the initiating impact was one part of the failure. Protection against a known launch hazard proved inadequate, as did the investigation of suspected damage and the channels for bringing technical concerns into decisions.
What would have helped Resolving the known foam-shedding hazard before launch, establishing a clear route for obtaining diagnostic imagery, and giving independent technical concerns more authority in mission decisions. These address different weaknesses. Whether one additional check would have saved this crew remains unproven.
05How to spot it
06What to do about it
- Trace one hazard through the actual defenses. Follow a wrong payment, unsafe dose, or equipment failure from its origin to possible harm. Compare each defense’s actual behavior with the protection described in the procedure.
- Look for shared weaknesses. Ask whether the backup uses the same power supply, data source, software, or assumptions as the primary protection. A second signature adds little if it repeats the first person’s check.
- Prevent errors where possible. A connector that cannot fit the wrong socket is stronger protection than a reminder to be careful. Use error prevention to reduce dependence on attention and memory.
- Investigate catches as well as losses. When someone stops a problem at the last moment, examine why earlier protections missed it. Back up praise for vigilance by preserving the conditions that enabled the catch.
- Make concerns actionable. Give people a clear way to pause work, escalate uncertainty, and obtain expert review. This is part of building a high-reliability organization.
- Check that improvements work under pressure. Test the safeguards during realistic workload, outages, and staff absences. Adding another form can leave protection unchanged while increasing workload.
07Where it doesn’t explain enough
The Swiss Cheese Model is a way to organize an investigation, not a calculation of accident probability. Separate evidence must establish whether five drawn slices represent independent defenses and whether an identified hole caused the outcome.
The picture can also make a complicated system look too linear. Failures involve feedback, interacting teams, changing conditions, and several possible paths to harm. Fault tree analysis can help specify combinations of failures when an investigation needs more detail than a loose diagram provides.
It is often confused with defense in depth. Defense in depth is a design strategy: build multiple protections. The Swiss Cheese Model explains how imperfect protections can still allow an accident.
Finally, a systems explanation keeps individual responsibility in view. It also asks what responsibility belongs elsewhere and what changes would prevent a repeat.
08Roots
At the University of Manchester, psychologist James Reason studied the mistakes people make while doing ordinary tasks. Industrial disasters made the stakes much larger. A lapse in a control room could have consequences far beyond the person making it, yet focusing on that person left much of the disaster unexplained.
In his 1990 book Human Error, Reason developed an account of organizational accidents that connected frontline actions with conditions created further upstream. Decisions about design, maintenance, staffing, and management could remain dormant for years before combining with a local mistake. The person nearest the accident was often encountering weaknesses they had not created.
The familiar cheese imagery developed through his later work. Its memorable detail was that every protective slice had holes that could change position and size. In 2000, Reason presented the model in a BMJ article contrasting person-focused and system-focused approaches to error. It found a receptive audience in healthcare, where several defenses already operated as a drug moved from prescribing through dispensing to administration. From aviation and industrial safety, the picture became a common language for discussing how competent people can work inside unsafe arrangements.
09How solid is this?
An influential framework for organizing accident evidence and examining safeguards. Investigations support the importance of interacting technical and organizational failures. The diagram’s use as a formula for predicting accident rates remains unvalidated.
10Connections
- Often confused with Defense in Depth
- Countered by Error Prevention
- IncludesCommon-Cause Failure, Latent Conditions
- See also Five Whys, Tight Coupling, Drift into Failure, Fault Tree Analysis, Normalization of Deviance, High-Reliability Organization
11Origin and sources
James Reason developed the organizational-accident framework in Human Error (1990). The familiar Swiss-cheese presentation appeared in later work and reached a broad healthcare audience through his BMJ article (2000).
- [1]Reason, J. (1990). Human Error. Cambridge University Press.
- [2]Reason, J. (1997). Managing the Risks of Organizational Accidents. Ashgate.
- [3]Reason, J. (2000). Human error: models and management. BMJ, 320(7237), 768–770.
- [4]Columbia Accident Investigation Board (2003). Columbia Accident Investigation Board Report, Volume I.
Suggest an edit· Updated 2026-10-02