In every quality system I have audited, the loudest risks are rarely the most dangerous ones. They are simply the most recent.
A catastrophic customer rejection last month dominates the risk register. A chronic 2% scrap rate that has been stable for three years is accepted as background noise. The organisation is not managing risk; it is managing memory.
This is the availability heuristic at work. It is a cognitive bias where people judge the frequency and severity of an event by how easily examples come to mind. Recent, vivid, or emotionally charged failures crowd out older, statistical realities. In automotive and aerospace manufacturing, where failure modes are complex and the cost of quality is high, this bias routinely distorts resource allocation, CAPA prioritisation, and audit readiness.
The consequence is measurable: high-effort, low-impact corrective actions that feel productive but do not move the needle on overall equipment effectiveness (OEE), cost of poor quality (COPQ), or first-time yield (FTY).
What the Availability Heuristic Looks Like on the Shop Floor
You can spot memory-driven quality management by looking at where engineering and inspection hours are actually spent. The symptoms are structural.
After a major 8D investigation, organisations routinely over-apply the containment action. A single defective lot triggers 100% sorting on a process that has historically run at a Cpk of 2.5. The sorting becomes permanent. Nobody runs the data to prove the containment is still necessary, because the memory of the failure is too vivid to turn it off.
Conversely, the actual systemic threats—worn tooling on a legacy press, an uncalibrated gauge used informally on the line, a single-source supplier with deteriorating delivery performance—remain unaddressed. They lack a dramatic recent failure to anchor them in the management's attention.
Memory-Driven vs Data-Driven Quality Management
Memory-driven response
- Adds 100% inspection after a single high-profile escape
- Prioritises the customer complaint from last Tuesday over a chronic internal scrap rate
- Expands the PFMEA based on the most recent audit finding
- Allocates engineering hours to the problem people argued about most
Data-driven response
- Validates statistical risk via Cpk, PPM, and OEE before escalating containment
- Ranks CAPA by total COPQ and recurrence frequency across 12 months
- Updates the PFMEA based on rolling defect data and FMEA severity rankings
- Allocates resources based on quantified impact on first-time yield
The Cost of Fighting the Last War
I have audited plants where the entire quality function was oriented around the previous year's major customer audit. The team could recite the findings verbatim. The corrective actions were immaculately documented. Yet when I asked for the Cpk on a critical aerospace characteristic, the data was six months out of date.
This is resource diversion by cognitive bias. When management attention is captured by an available memory—usually a dramatic failure or a penalising audit—the organisation redirects engineering hours, measurement system analysis (MSA) studies, and floor inspections toward that single point of failure.
The systemic risk does not disappear. It compounds. Slow degradation in a stamping die, gradual drift in a welding fixture, or creeping variation in an injection moulding cycle goes unnoticed until it triggers a failure far larger than the one the team was busy preventing.

Structural Defences: Building an Evidence Hierarchy
You cannot train people out of the availability heuristic. It is a fundamental feature of human cognition. What you can do is build management systems that force decisions to be grounded in structural evidence rather than memory or intuition.
The defence against cognitive bias in quality is data architecture. When a Layered Process Audit (LPA) finding requires escalation, or when a PFMEA needs updating, the decision must trigger a query against actual production data, not a discussion about what happened last month.
Evidence-Based Escalation Trigger
- 01Event occursDefect, audit finding, or customer complaint triggers standard initial containment.
- 02Data pullQuality engineer queries 12-month rolling PPM, Cpk, and OEE for the affected process and family.
- 03Statistical triageCompare the event against historical baselines. Is this an anomaly or a trend?
- 04Risk-weighted actionCalibrate the CAPA response to the statistical threat level, not the emotional impact of the event.
This requires that your data is actually retrievable. If determining whether a defect is a one-off or a trend takes three days of manual spreadsheet mining, your team will default to the availability heuristic. Speed of access to data is a quality function.
Correcting the Risk Register
Your PFMEA and your risk register are the primary documents where the availability heuristic does damage. When a cross-functional team sits down to update a PFMEA, the severity, occurrence, and detection rankings they assign are heavily influenced by recent events.
An occurrence ranking of 4 might be assigned because everyone remembers the defect from last month, even if the historical PPM data suggests a ranking of 2. A failure mode that has not occurred in two years gets downgraded, regardless of whether the process controls that prevented it are still in place.
The fix is mandatory data anchoring. Before a PFMEA review, pull the rolling 12-month data for every failure mode listed. Anchor the occurrence ranking to the actual defect rate. This strips the emotional memory out of the equation and forces the team to confront the statistical reality of the process.
A risk register built on memory is a history book. A risk register built on data is a control plan.
The same principle applies to supplier risk management. The supplier that shipped a nonconforming lot last week gets a corrective action request and heightened scrutiny. The supplier with a steadily declining delivery performance and zero PPM data reported gets ignored. The first problem is visible; the second is structural.
Audit Readiness vs Process Control
AS9100 and IATF 16949 auditors are not immune to the availability heuristic either. If a major nonconformity was found in calibration during the previous audit, you can guarantee the next auditor will spend extra time reviewing calibration records. Plants often over-prepare for this specific line of questioning.
This is rational behaviour to pass an audit, but it is poor quality management. Preparing for the last audit means you are hardening the specific control that already failed, while potentially ignoring the control that is quietly degrading and will fail next.
The solution is a balanced audit preparation protocol that relies on internal audit data, not external audit history. Your internal audit programme—particularly if it uses VDA 6.3 methodology—should be surfacing the actual weak points in your system. If your internal audits are finding different issues than your external auditor found, your internal audit programme is either too weak or improperly scoped.
Key Indicators That Override Memory
From Reaction to Rhythm
Implementing Routing Verification KPIs at a major aerospace manufacturer taught me that the key to killing reactive management is rhythm. When verification happens at a fixed, predictable cadence, and the data is published where everyone can see it, the availability heuristic loses its grip on the operation.
Weekly scrap reviews, monthly Cpk trend analyses, and quarterly PFMEA validation against actual field returns—these regular rhythms force the organisation to look at the entire process, not just the last failure. The data becomes the shared memory of the organisation, replacing individual recollections with statistical fact.
Quality directors must actively police the gap between what the organisation remembers and what the data shows. When a manager proposes a new inspection station because of a recent escape, ask for the PPM trend. When an engineer wants to deprioritise a corrective action, ask for the recurrence data. Make the availability heuristic the explicit enemy of sound quality decisions, and build the systems that prove it.
