Skip to content

Human Error Is a Symptom of Bad Design

Definition

Investigations that find a "human error" and stop there — blame, punish, retrain, repeat — treat error as a personal failing rather than as evidence about the system. Norman argues the investigation should continue past the human error using root-cause analysis (the "Five Whys"): if a system lets the same mistake happen to different competent people, or actively induces it, the error is a design defect, not a character flaw. "If the system lets you make the error, it is badly designed. And if the system induces you to make the error, then it is really badly designed."

In the Book

Chapter 5 makes the case through two paired examples. The 2010 crash of a US Air Force F-22, initially blamed on pilot error ("failure to recognize and initiate a timely dive recovery"), was reopened by the Department of Defense Inspector General, who asked why the pilot's possible unconsciousness from hypoxia wasn't treated as a contributing factor — Norman uses this to illustrate the "Five Whys" technique, tracing from proximate cause toward underlying cause instead of stopping at the first human found in the chain. The second example is Norman's own consulting engagement with an electric utility company, where trained workers were repeatedly electrocuted servicing high-voltage lines; every investigation blamed the workers (who agreed), but no one asked why the same error kept recurring across different individuals. Norman proposed procedural changes; years later he learned the company made none, and injuries continued — a culture where field workers saw themselves as infallible ("we do not make errors") made the real, systemic causes invisible. He also invokes James Reason's "Swiss cheese model," in which accidents require multiple simultaneous failures rather than one single cause, meaning root-cause analysis that stops at "found the guilty person" is analytically incomplete, not just uncharitable.

Why It Matters

This concept converts an emotionally satisfying but useless response — find and punish the individual — into a mandate to redesign the process or artifact that made the error possible or likely. It transfers directly to any domain where the same mistake recurs across different capable people: repeated data-entry errors, repeated compliance violations, repeated "operator error" incidents — the recurrence itself is diagnostic evidence that the fault lies upstream, in the system's design, and that punishing the latest person who tripped over it will not stop the next one from doing the same.