Swiss Cheese Model Explained: 4 Layers Leaders Must Test After an Incident
A practical explainer for EHS leaders who need to trace how design, planning, organizational, and frontline gaps aligned before an incident.
Key takeaways
- 01The Swiss Cheese Model explains how weaknesses in several defensive layers can align before harm occurs.
- 02Investigations should test design, work planning, organizational decisions, and frontline conditions with evidence.
- 03A list of weaknesses is not enough; the causal narrative must show how the gaps connected and which barrier could have interrupted the chain.
- 04Operator actions matter, but stronger prevention depends on repairing the conditions that made the action consequential.
- 05Every corrective action should name the layer it strengthens, its owner, its due date, and the field evidence that will verify it.
An incident rarely begins with one careless act. More often, several protections contain small weaknesses at the same time, and the weaknesses line up when work becomes urgent. The Swiss Cheese Model gives leaders a practical way to examine that alignment without reducing the investigation to operator error.
The Swiss Cheese Model is James Reason's explanation that accidents occur when weaknesses in multiple defensive layers align. Each layer can block a hazard, but each also contains gaps created by design, decisions, supervision, maintenance, or frontline conditions. The model helps an investigation trace how those gaps became connected.
What does the Swiss Cheese Model explain?
James Reason introduced the model to show why complex systems cannot be understood by looking only at the final action before harm. A worker may open a valve, enter an area, or bypass a guard, yet the investigation still needs to ask which conditions made that action possible, likely, or difficult to challenge.
The slices represent defenses. Their holes represent weaknesses that change over time. A procedure may be technically correct but difficult to use. A supervisor may be expected to stop unsafe work while production rewards uninterrupted output. A critical alarm may exist, although nobody has verified whether it is available during the shift in which it matters.
The model is not a substitute for evidence. It is a map for asking better questions about evidence, especially when the first explanation sounds complete too quickly.
Layer 1: Design and engineering controls
The first layer should make the hazardous outcome harder to create. Examples include fixed guards, interlocks, separation distances, ventilation, automatic shutdowns, engineered access, and equipment that removes the need for a person to work inside the exposure zone.
After an incident, leaders should test whether the design matched the real task. A guard that blocks maintenance access may be removed repeatedly. An interlock that causes nuisance trips may be defeated. A ventilation system may meet its design specification while failing to control exposure at the worker's breathing zone. These are design questions, even when the visible event occurred at the point of use.
Evidence should include drawings, change records, inspection results, alarm histories, maintenance work orders, and photographs from the scene. If the control depended on a workaround, the workaround belongs in the design discussion rather than being treated as a private behavioral choice.
Layer 2: Procedures and work planning
The second layer translates the hazard analysis into a sequence that people can execute under actual operating conditions. It includes permits, job safety analyses, isolation steps, rescue arrangements, pre-job briefs, operating limits, and escalation rules.
A procedure can fail without being absent. It may assume stable staffing, clean equipment, daylight, enough time, or a supervisor who is physically present. When those assumptions are not true, the document remains compliant on paper while the work moves through an unprotected gap.
Investigators should compare the written process with the sequence that workers actually followed. Check what was known before the job, which step created delay, where the plan changed, and whether the change had a defined approval path. The goal is not to excuse a deviation. The goal is to understand whether the system made the safe path usable.
Layer 3: Supervision and organizational decisions
The third layer concerns the decisions that shape the work before the crew arrives. Staffing, production targets, contractor interfaces, maintenance priorities, training time, shutdown duration, and escalation authority all influence whether the lower layers remain available.
Leaders should ask what the organization rewarded in the weeks before the incident. If a team was praised for recovering schedule, closing permits quickly, or avoiding downtime, those signals may have changed the practical meaning of the written rules. A formal stop-work statement has little force when the person who uses it expects a penalty for delaying output.
Useful evidence includes shift plans, overtime records, staffing levels, backlog reports, supervisor messages, production decisions, contractor meeting notes, and prior safety concerns. These records can reveal whether the incident was an isolated surprise or the visible result of a decision pattern that had already become normal.
Layer 4: Frontline conditions and actions
The fourth layer is closest to the event. It includes the conditions, perceptions, choices, and adaptations present when the task was performed. This layer matters, but it should be examined in context rather than treated as the complete explanation.
Interview the people who performed and supervised the work before writing the conclusion. Ask what they saw, what they expected to happen, what changed, which control they believed was active, and what they thought would happen if they stopped. Their answers can identify missing information, conflicting signals, equipment defects, unclear ownership, or a control that existed only in the investigation file.
James Reason's contribution is especially useful here because it separates the immediate action from the conditions that shaped it. That distinction keeps corrective action focused on stronger barriers instead of producing a warning memo that leaves the same alignment intact.
How do you test whether the layers aligned?
Build a timeline that places each defense beside the conditions surrounding the task. For every layer, record what should have happened, what actually happened, what evidence supports the difference, and who had authority to close the gap.
| Layer | Test question | Evidence to review |
|---|---|---|
| Design | Could the hazard be prevented or physically constrained? | Drawings, interlocks, alarms, maintenance records |
| Planning | Could the safe sequence be executed under the real conditions? | Permits, task plans, changes, pre-job records |
| Organization | Did decisions preserve time, staffing, authority, and attention? | Schedules, targets, staffing, escalations |
| Frontline | What did the people closest to the work know and perceive? | Interviews, statements, scene evidence, communications |
The alignment is credible only when the evidence shows how one gap connected to another. A list of four weaknesses is not yet a causal explanation. The investigation needs to show the chain, including which barrier could have interrupted it and why that barrier was unavailable.
Swiss Cheese Model versus operator blame
Operator blame starts with the last visible action and stops there. The Swiss Cheese Model starts at the same action, then works backward through the conditions that made the action consequential. This does not remove personal responsibility or technical standards. It improves the quality of responsibility by distinguishing a mistake, a deliberate violation, a design trap, and a management decision.
In more than 250 cultural transformation projects supported by Andreza Araujo, the practical question is whether the organization changed the routine that allowed the risk to persist. A disciplinary response may be appropriate in some cases, but it cannot replace barrier verification when the same exposure remains available to the next person.
When should leaders use the model?
Use the model after serious incidents, high-potential near misses, repeated deviations, and failures involving several teams or contractors. It is also useful before a major change when leaders need to test whether the existing defenses can survive a new operating condition.
Do not use it as a decorative diagram in the final report. Use it to assign stronger actions, such as redesigning an access point, changing a permit sequence, giving a supervisor real escalation authority, or verifying that a critical control works during the task rather than during an office review.
The model earns its place when it changes what the organization will inspect, fund, schedule, and verify next. If the only output is a reminder to be more careful, the layers have not been repaired.
What should an investigation produce?
A useful investigation should leave leaders with a defensible causal narrative, a small number of barrier-strengthening actions, named owners, due dates, and evidence criteria. Each action should state which layer it strengthens and what would prove that the change worked in the field.
Andreza Araujo's book Safety Culture: From Theory to Practice frames safety culture as something leaders can observe in decisions, routines, and responses to risk information. That perspective fits the Swiss Cheese Model because the quality of a defense is visible in its use under pressure, not only in its wording.
For organizations that need to turn incident learning into stronger field controls, Andreza Araujo and ACS Global Ventures provide practical support for safety culture and critical-risk work.
Frequently asked questions
What is the Swiss Cheese Model in safety?
What are the four layers in the Swiss Cheese Model?
Does the Swiss Cheese Model remove operator accountability?
How do you use the Swiss Cheese Model after an incident?
When should leaders use the Swiss Cheese Model?
About the author
Andreza Araújo
Safety Culture Expert | Senior EHS Executive
Andreza Araújo is a safety culture expert and senior EHS executive with more than 25 years of experience in environment, health and safety. She is a Civil Engineer and Occupational Safety Engineer from Unicamp, holds a Master's degree in Environmental Diplomacy from the University of Geneva, and completed sustainability studies at IMD Switzerland. Andreza has served in Global Head of EHS roles in Fortune 500 environments, leading cultural transformation programs across multinational operations. She has represented Brazil as a speaker at the United Nations in Paris and has spoken at the International Labour Organization in Turin. She is the author of more than 16 books on safety culture in Portuguese, Spanish, English and German. Her work has earned more than 10 EHS awards, including two recognitions from Indra Nooyi, former PepsiCo CEO.
- Civil & Safety Engineer (Unicamp)
- M.A. Environmental Diplomacy (University of Geneva)
- Sustainability Cert (IMD Switzerland)
- People Management & Coaching (Ohio University)
- UN Paris speaker representative for Brazil
- ILO Turin speaker
- LinkedIn Top Voice
- Indra Nooyi PepsiCo CEO recognition (2x)
Documentaries
Watch Andreza's documentaries
Three productions on safety culture, organizational failure and the human lessons behind major disasters.
Podcasts
Listen to Andreza's podcasts
She hosts three shows on safety leadership, EHS and organizational culture, in English and Portuguese.