Aviation reports roughly 0.003 fatalities per billion passenger-kilometres. Manufacturing still debates whether 3.4 defects per million opportunities is acceptable. The gap is not talent. The gap is system design.
On 27 March 1977, two Boeing 747s collided on the runway at Tenerife's Los Rodeos Airport. 583 people died. The investigation did not fire the pilot. It asked what system allowed the failure, and the answers rebuilt commercial aviation into the safest transport mode in history.
Every principle developed in response is directly applicable to a production floor running IATF 16949 or AS9100. The mechanisms differ; the discipline does not. Here are the lessons most plants have not implemented.
Standardisation Without Exception
Before Tenerife, checklists existed but senior captains treated them as optional. After Tenerife, checklists became mandatory regardless of rank. A 20,000-hour captain follows the same procedure as a first-day first officer.
Walk onto any shop floor and watch the setup process. The most experienced operator likely works from memory while the new hire struggles with a document the veteran has never opened. Experience is treated as a substitute for the standard rather than the ability to execute it.
Aviation learned that experience makes you better at executing the standard; it does not exempt you from it. Manufacturing work instructions should be designed like cockpit checklists: short, critical, interruptible, and revised after every near-miss. If the most senior person on your floor is not following the documented standard work, the standard does not exist.
Audit your current work instructions against this test. Are they written for the steps that cause failure, or for every obvious action? Can they be paused and resumed? When did you last update them based on a near-miss or an internal 8D finding? Most plants will find the answer is never.
Authority at the Point of Execution
In 1978, United Airlines Flight 173 ran out of fuel over Portland, Oregon. The captain fixated on a landing-gear indicator light. The first officer and flight engineer both knew fuel was critically low, but neither spoke forcefully enough to override the captain's authority. The crash killed ten people.

United's response was Crew Resource Management (CRM): a framework that trains every team member to speak up and trains leaders to listen. The cockpit moved from a dictatorship to a crew system. The person closest to the problem gained the authority to name it.
In manufacturing, when a machine operator sees that material looks wrong, do they stop the line? Or do they assume someone upstream already checked it? When a quality technician flags a deviation, does production override them because the customer needs the shipment today?
I have audited plants where operators stop the line without asking permission. Those plants have the lowest cost of poor quality. The average plant flags the issue and waits for a supervisor. The worst plants stay silent because the last person who spoke up was told to make it work.
Authority to stop the line
What most teams do
- Operator flags the issue to a supervisor and waits
- Production pressures quality to release the shipment
- Speaking up is informally discouraged by schedule pressure
- Decisions are made one or two levels above the problem
What works
- Operator stops the line without asking permission
- Quality holds are respected without override
- Near-misses are reported voluntarily and formally analysed
- The person closest to the defect makes the first call
Lessons Are Data, Not Secrets
Every commercial aircraft carries two black boxes: a flight data recorder and a cockpit voice recorder. Their purpose is not to assign blame. It is to ensure no crash happens for the same reason twice. Findings are published. Recommendations become mandatory across the entire industry.
Manufacturing hides corrective action reports behind confidentiality agreements. The 8D is filed and forgotten. The same failure repeats at a different plant within the same company because nobody shared the lesson.
I worked with an automotive supplier that had three plants. Plant A documented a catastrophic welding failure in 2019. The root cause was found. The corrective action was effective. In 2021, Plant B, running the same process on the same equipment, had the identical failure. Nobody had transferred the learning.
In aviation, the NTSB would have published the findings and the FAA would have issued an Airworthiness Directive. Every operator running that equipment would have been forced to comply. Your nonconformance reports, customer complaints, and audit findings are your black boxes. If they are filed in a system nobody queries, you are satisfying auditors and wasting the data.
Just Culture: The Discipline That Replaces Blame
Professor James Reason, the cognitive psychologist who shaped modern safety science, distinguished between three types of behaviour. Honest human error gets a response that consoles the person and fixes the system. At-risk drift gets coaching and removal of the incentive to drift. Reckless disregard gets disciplinary action.
The genius of Just Culture is that it does not blame people for being human. It recognises that errors will occur and designs controls to catch them. It punishes only wilful recklessness.
Most factories either punish honesty or reward indifference. Neither leads to quality.
Most manufacturing plants operate in one of two modes. Blame culture triggers a witch hunt after every defect; someone is written up while the systemic cause goes unaddressed because everyone protects themselves. No-blame culture excuses everything as human error; no one is accountable and the systemic cause goes unaddressed because no one is motivated to find it.
Just Culture is the middle path. It creates the environment where people report errors and near-misses freely because honest mistakes will not be punished. If voluntary near-miss reporting on your floor is rare, the culture is broken. Fix it before you try to fix the process.
Redundancy as Insurance, Not Waste
Commercial aircraft have multiple engines, multiple hydraulic systems, and multiple flight computers. Not because any single system is unreliable, but because the consequence of total failure is catastrophic.
Manufacturing treats redundancy as waste. The question is always: why do we need two inspection points? Why do we need both automated and manual checks? Why do we need a secondary containment when the primary control should be sufficient?
Intelligent redundancy for critical controls
- Primary controlThe standard process parameter or mistake-proofing device that prevents the defect.
- Detection controlAutomated or operator inspection that catches the defect if the primary control fails.
- ContainmentSecondary barrier preventing escape to the customer if detection misses it.
- Systemic reviewPFMEA and control plan update triggered when any upstream layer fails.
The primary control will fail. Not because it is bad, but because everything fails eventually. Aviation designs for that inevitability. Manufacturing pretends it will not happen.
Intelligent redundancy means backup controls at points where the consequence of failure justifies the cost of duplication. The PFMEA in your drawer already identifies those points. It lists the severity, occurrence, and detection ratings for every potential failure mode. If a single control failure at Severity 9 or 10 reaches the customer without a barrier, you decided the risk was acceptable. Re-examine that decision.
Training Before the Crisis
Pilot training does not happen in the air. It happens in simulators. Crews practice engine failures at takeoff, cabin depressurisation, and dual hydraulic failures. They practice until the response is automatic, then return every six months to practice again.
In manufacturing, training on a new process happens once, perhaps twice, followed by a written test. Nobody simulates a quality emergency. The first time the team confronts a critical defect escape is the moment the customer calls.
Simulator training in aviation costs hundreds of dollars per hour. A single accident costs hundreds of millions. The math is not complicated. Your equivalents are mock recalls, tabletop exercises, and planned emergency drills.
Pick your three worst-case quality scenarios. Walk the team through them under time pressure. Watch where communication breaks down, where the documentation fails, and where authority is unclear. Fix the gaps before the real event arrives. The no-go decision matters only if the team has rehearsed what a no-go situation looks like.
