BlueFlash
teach preview

Man and Machine — Page 292, Lesson 484

Man and Machine — Page 292, Lesson 484BlueFlash
I want to walk you through a key concept in aviation safety: the difference between active and latent failures, and how we design systems to be error-tolerant. Let's start with the big picture. When we look at failures in modern technological systems like aircraft, the human contribution can be divided into two types: Active Failures and Latent Failures. The distinction between them comes down to two things: who made the error, and how long those errors take to appear. Active failures — also called active errors — are committed at what we call the human-system interface. That means right where the operator meets the machine: in the cockpit, in the cabin, or at the Air Traffic Controller's desk. These errors have an immediate effect. You've already come across some examples in earlier chapters — things like an Action Slip, or Environmental Capture. The key point is that the person at the sharp end makes the mistake, and the consequence happens right away. Latent errors, or latent failures, are a different beast. These are normally the results of decisions taken by people far removed from the immediate operation — designers, manufacturers, and senior management. Their actions or decisions lie dormant, sometimes for a very long time, and then suddenly produce disastrous results. Let me give you a classic example: the Mount Erebus crash. An aircraft database contained an unnoticed waypoint error of just 2 degrees West. That small error, introduced during design or data preparation, was enough to cause the aircraft to hit a mountain in poor visibility. Rushed or incomplete preparation is another example of latent failure. The person who makes the error never sees the consequence; the pilot who flies into the mountain never made the error. Now, this brings us to a fundamental truth in aviation: Sod's Law. It states: If something can go wrong, it will. A specific version of this is Murphy's Law, which states: If a system can be operated incorrectly, sooner or later it will be. That's not pessimism — it's a design requirement. Because of this, aviation systems — whether they are aircraft, organizational structures, or procedures — must be error-tolerant. What does that mean? It means the system is designed so that no single error has serious implications for the overall safety or conduct of the system. An example: an automatic system that prevents an aircraft from moving outside its flight envelope, regardless of what orders the pilot enters through the controls. The pilot can make a mistake, but the system won't let that mistake cause a loss of control. This leads to the concept of protected and vulnerable systems. Systems must be designed to contain their own intrinsic protection. A system is considered vulnerable if one error is allowed to affect the whole system. Think of a wall made of bricks. In a protected system, if you take one brick out, the main structure still stands. In a vulnerable system, removing that one brick causes the whole wall to collapse — its entire function is affected. I want you to look at Figure 14.7, which illustrates this concept perfectly. Finally, we have design-induced errors. These are errors made by aircrew as a direct result of poor or faulty design of any part of the aircraft. The philosophy that underpins all future EASA design efforts — especially in avionics and automation — is based on three principles: Detectability, Tolerance, and Recoverability. Systems will be expected to detect errors made by aircrew, tolerate them, and, as far as is possible, recover from those errors. That's the standard we're building toward.

This is one saved preview. Continue from this exact book or paper with BlueFlash voice AI.

Continue in BlueFlash