Identical Error Paradox in Aviation Maintenance

Identical Error Paradox in Aviation Maintenance

Kevin Hayes and Nicolò Gariglio of Airbus UK presented at the Chartered Institute of Ergonomics & Human Factors (CIEHF) Ergonomics & Human Factors 2026 conference in April 2026 on the subject of identical maintenance errors on the same aircraft.  It however prompts reflection on wider maintenance human factors issues.

They explain that…

…a potential paradox was identified; that under certain circumstances a system can intentionally produce more errors in order to result in an overall safer outcome.

They note that:

Despite the employment of various strategies to prevent a catastrophic occurrence during the design stage…certain architectural choices can still be bypassed by Common Cause Failure (CCF) modes, where two systems fail in the same way for the same reason (Jones, 2012).

Maintenance errors are a potential CCF, even in a redundant system:

An example of this might be if a maintenance technician is installing two identical but independent flight control computers and makes the same installation mistake on both (such as cross connecting the input feeds)…

The phenomena of simultaneous incorrect maintenance gained attention after a serious incident to British Midland Boeing 737-400, G-OBMM on 23 February 1995. Subsequently UK CAA published Airworthiness Notice 72 on 16 March 1998 on Safety Critical Maintenance Tasks.  AN72 later became CAP562 Leaflet 11-21 and then Leaflet B-150.

Regulations on ‘identical errors’ (EASA) or ‘dual errors’ (FAA) have been issued with the implied intent…

…that they are trying to reduce the probability of an Aviation Maintenance Error (AME) from occurring on critical systems that could result in a Common Cause Failure mode and thus compromise safety.

This is very much in the vein of the Person Approach to human error rather than the Systems Approach (Reason, 2000).

That is a thought provoking contention as conventionally the process for how maintenance is planned and allocated would be seen as a systemic approach.  However, the authors observe that:

By its very nature, this strategy of having different people doing the same task on redundant systems can only be used as a mitigation against those AMEs that have causal factors relating primarily to the individual rather than those factors…such as environmental, process or design related factors (Hayes, 2024).

The authors use Rasmussen’s Skill-Rule-Knowledge framework (1986) to model a scenario where a twin engine aircraft has both of its engines re-installed simultaneously.

The SRK concept involves a spectrum of cognitive control.  Skill-based actions tend to be highly routine actions in familiar environment performed fairly automatically & rapidly. Rule-based ones require specific instructions to be followed.  When rules can’t cope with the unique or complex circumstances, slower, conscious knowledge-based activity is needed, until it’s possible to revert to rule or even skill-based activity.

In the selected maintenance scenario:

Because each engine acts as a redundant system for the other engine, this scenario falls into the category of “identical maintenance”.

…the objective of the analysis…is to determine what types of Human Error can be mitigated against by having separate engineers installing each of the engines. This is achieved through a comparison with what is likely to happen if the same engineer installed both engines.

They explain (our emphasis added) that…

…in aviation maintenance skill based errors are strongly linked to Performance Shaping Factors (PSFs) that are localised by time or space, such as fatigue resulting in memory lapses or equipment deficiencies resulting in physical slips (Hobbs and Williamson, 2002).

In contrast, rule-based errors and knowledge-based errors are more tightly coupled with PSFs that have a systematic influence across the cohort, regardless of when and where they are conducting the maintenance. For example, rule-based errors were found to be linked to inadequate procedures while knowledge-based errors were found to be linked to training (Hobbs and Williamson, 2002).

They do note that:

…engineers will be constantly switching between skill-based, rule-based and knowledge-based behaviours depending on the immediate context and requirements of the activity.

They observe (our emphasis added):

From this analysis it can be seen that the concept of “identical error” avoidance is not tightly coupled with skill-based or rule-based error mechanisms. In other words, having a second engineer involved does not substantively change the pre-conditions that led to the Maintenance Error occurring.

However, knowledge-based errors are more tightly coupled with the avoidance of “identical error”. By having a second engineer change the second engine, it can fundamentally change the framing of the decision making process and result in a different outcome to the one reached by the first engineer.

Of course in most cases, this sort of maintenance task should be sufficiently well defined to be able to rely upon the established rules.

As such, the use of an “identical maintenance” approach can be an effective mitigation against the total failure of redundant systems due to a knowledge-based Human Error CCF.

This finding, that different people with different knowledge will make different mistakes, will feel intuitively correct to the majority of people.

However, when this observation is analysed further it results in a finding that will seem counter intuitive, that the “identical maintenance” approach simultaneously results in both safer outcomes but also in more Human Error overall.

To illustrate this counter intuitive outcome, the authors go one step further in their paper, applying a simple Human Reliability Analysis (Swain and Guttman, 1983) to the hypothetical knowledge-based errors (noting the challenge establishing accurate Human Error Probabilities [HEPs], especially if there is no linkage between maintenance and safety databases) .  We won’t discuss that further here but its worth reading the author’s paper for more insight.

Practical Application of the Findings

The authors state that:

The important takeaway from this paper is less around whether the “identical error paradox” is a real effect or not, and more around how the aviation industry thinks about Maintenance Error, why these errors happen and what mitigations should be put in place to reduce the chances of such an error happening again.

They note there is little data on the effectiveness of error reduction techniques in use and ask…

  • Are we (as an industry) adequately addressing all of the factors that lead to Maintenance Errors?
  • Are our mitigations targeting the correct PSF’s?
  • Are we over emphasising or under emphasising the right strategies?

Airbus engaged with six major airlines (with a combined fleet of over 800 airliners), conducting 24 semi-structured online interviews.

One of the major findings was that airlines often struggled to mitigate against Maintenance Error reoccurring. The reasons for this often involved the misidentification of what the causal factors were that led to the Maintenance Error occurring and/or the inability to identify an appropriate mitigation that would both systemically address the primary causal factors and that was also within the ability of the organization to implement.

Repetition of similar Maintenance Errors, despite implementation of mitigations, was found to frustrate interviewees.  The interviewees generally considered that error reduction mitigations should result in “error free” maintenance, so any adverse event “was often perceived as a failing of the individual to adhere to the mitigations that the organization had already implemented”.

This shows a disconnect between the types of error being observed, the selection of an appropriate mitigation strategy and the expectations of the organization.

It also shows a lack of understanding of James Reason’s 12 Principles of Error Management, the first of which is that “Human error is both universal & inevitable: Human error is not a moral issue. Human fallibility can be moderated but it can never be eliminated”.

The chasing of “zero Maintenance Errors” is very much in the vein of Safety-I thinking (Hollnagel, 2014) but when an error occurs during an “identical maintenance” scenario then it is the perfect natural experiment (Petticrew et al, 2005) for understanding how to apply a Safety-II philosophy in the aviation maintenance domain.

They explain that (our emphasis added):

If an investigator can identify why two individuals with access to the same tooling, infrastructure and procedures can have two different outcomes then, it will allow the organization to identify why things normally go right, as well as why errors sometimes occur.

Additionally, such an analysis can show where the error sits on the Skill-Rule-Knowledge spectrum and whether the failure mode is tightly coupled with “identical maintenance”. This can enable the most appropriate means of mitigation to be selected for the error type (Hobbs and Williamson, 2002) and reduces the chance of a similar error happening again.

The authors state that:

Through having a deeper understanding of the reality of aircraft maintenance and why Maintenance Errors keep happening then it can help organizations to foster a better Just Culture in the organization.

We would interpret that as focusing more on the systemic causes of errors than on needlessly judging individual’s culpability.

Understanding that the correct mitigation is needed to address a given error type can change how leadership teams view Maintenance Error and the role of the individual.

They conclude that:

The “identical error paradox” remains an unproven hypothesis, but one that is useful as a lens for questioning the efficacy of mitigation strategies and whether they are truly addressing the mechanisms that are causing the error.

Such a questioning philosophy is important to regulators, aircraft operators and Maintenance Repair Organizations alike.

Our Safety Observations

Techniques to mitigate or capture errors will themselves always be subject to human error if they themselves depend on human action.  So, while they should reduce the probability of a defective aircraft flying, they are not a silver bullet to eliminate it.  So when errors occur they remain an opportunity to refine our maintenance processes.

Independent Inspections (‘II’) are another error mitigation that occasionally fail, and induce similar misdirected organisational frustrations.  In that case the original error is sometimes unhelpfully ignored to fixate on the failure of the II.

Being able to readily fuse opportunity data (from maintenance software tools) and error data (from SMS software) would help establish more accurate failure data and potentially help better target mitigations on tasks with the greatest probability of error.  This is not a trivial task but arguably underlines the inadequacy of some current maintenance safety metrics being tracked within organisations’ SMS.

Gathering accurate error data needs an effective reporting culture.  Notoriously when IIs find an error, the issue is usually fixed but not formally reported (perhaps a sign of a weak Just Culture, low level of organisational trust and associated reluctance to inform on a colleague).

This research also highlights the criticality of ‘rules’ (by which we primarily mean procedures, work instructions and maintenance data in this context) being correct and unambiguous for safety critical tasks.  They otherwise become a CCF in themselves, misdirecting multiple individual engineers.  While that should be self-evident, it begs the question of how well such rules are actually tested before being issued.  Often there is a assumption that if an error occurs that is neither skill or knowledge based, then a rule must have been broken (i.e. the rule-based ‘error’ is a ‘violation‘ and the individual’s motives should be considered).  In practice however a ‘rule’ may have been incorrect, inappropriate for the circumstances, ambiguous, badly explained/trained, contradicted by other rules, inaccessible, unavailable or unknown to the individual.

Safety Resources

See also Ten Facts About Human Failure and Best Maintenance Practices for Redundant Systems.  The latter recommends:

It notes that for ETOPS operations, these apply:

  • US 14 CFR Part 121 section 121.374, “Continuous airworthiness maintenance program (CAMP) for two-engine ETOPS – Limitations on dual maintenance.”
  • FAA AC 120-42, “MAINTENANCE REQUIREMENTS FOR TWO-ENGINE ETOPS AUTHORIZATION – Dual Maintenance” paragraph
  • EASA AMC 20-6 (AMJ 120-42/IL 20). “4. CONTINUING AIRWORTHINESS MANAGEMENT EXPOSITION” chapter.

EASA and UK regulations also require that operators establish procedures that prevent the risk of repeating errors on identical systems:

  • EASA Part-145: 145.A.48(c)(3) and its AMC1 145.A.48(c)(3) & GM1 145.A.48(c)(3)
  • UK CAA Part-145: 145.A.48(c) and its AMC 145.A.48(c) & GM 145.A.48(c)

You may also find these Aerossurance articles of interest:

Professionalism and Integrity in Aviation

 


Aerossurance has extensive air safety, airworthiness, maintenance human factors, aviation regulation and safety analysis experience.  For practical aviation advice you can trust, contact us at: enquiries@aerossurance.com

Scroll to Top