[#6] ETTO Principle Ch.2-1|Why the Rational Human Model Fails to Explain the Field






Why the Rational Human Model Fails to Explain the Field | ETTO Principle Efficiency Thoroughness Ch.2-1


SAFETY MANAGEMENT · CHAPTER 2 · PART 1/5

Why the Rational Human Model Fails to Explain the Field

Chapter 2-1 · The Rational Human · Time to Think, and Time to Do

Chapter 2 begins with a classical assumption: people succeed when they
follow the rules, and when they fail, it is because they broke them.
Hollnagel argues this assumption is insufficient for real operations.
In particular, any rationality model that excludes time
constraints
misses the core of real-world decision-making.
Chapter 2-1 uses “The Rational Human” and “Time to Think, and Time to
Do” as its foundation to examine the gap between the normative model
and the operational model — through the lens of the
ETTO Principle: the efficiency-thoroughness trade-off.

ETTO Principle efficiency thoroughness trade-off — rational human model versus Time to Think vs Time to Do decision structure
The ETTO Principle: people are not ideal calculators — they are
operators trading off efficiency and thoroughness within a time window.
Failure is more often the product of trade-off pressure than of
insufficient capability.

1) The Appeal of Normative Rationality: Clear, Measurable, and
Easy to Assign Accountability

Classical decision-making theory has genuine strengths. It establishes
criteria for correct choices, enables identification of incorrect ones,
and provides a common language for comparing performance and failure.
From an organizational standpoint, this model is convenient: clear
standards make evaluation and accountability assignment
straightforward.

Within this framework, people are fundamentally rational agents. They
are expected to gather necessary information, compare alternatives, and
select the option that maximizes a given criterion. If failure occurs,
the default assumption is: the person failed to see the information
correctly, violated a rule, or made a calculation error.

The problem is that this model’s explanatory power is strongest under
ideal conditions. Real operations rarely provide a well-defined
alternative set, stable evaluation criteria, or adequate time.
The model is elegant — but in the field, it routinely oversimplifies
the conditions under which decisions are actually made.

2) The Three Assumptions of Homo Economicus: Perfect Information,
Unlimited Sensitivity, and Consistent Optimization

Hollnagel identifies three core assumptions underlying the rational
human model (homo economicus). First, the decision-maker must have
access to all possible alternatives and their outcomes — perfect
information. Second, the decision-maker must be able to detect even
marginal differences between alternatives — unbounded sensitivity.
Third, the decision-maker must rank alternatives against a consistent
criterion and optimize for it — rational maximization.

These conditions may hold reasonably well in controlled experimental
settings. But in operational environments, information arrives late or
distorted, alternatives continue changing up to the point of
execution, and evaluation criteria — safety, quality, cost, schedule —
conflict with one another. Decision-making in the field is less a
static calculation than a dynamic trade-off.

The issue is not that people are irrational. The issue is that the
model’s assumptions do not match operational reality. When failure is
interpreted against premises that diverge from reality, analysis
converges on correcting individuals — and system-level corrections
are deferred.

3) The Limits of “The Worker Broke the Rule”: The Gap Between
Required Action and Available Action

The normative model tells us clearly what people should do. But from
the ETTO Principle perspective, the more important question is: what
could this person actually do in that moment? Under conditions of
incomplete information and tight time windows, people prioritize
executable choices over theoretically optimal ones.

Ignoring this gap produces repetitive corrective actions: retraining,
attention campaigns, renewed emphasis on procedure compliance. These
measures are sometimes warranted — but when the execution conditions
(time windows, approval bottlenecks, information availability, tool
accessibility) go unaddressed, the same pressures produce the same
choices again.

The shift that Chapter 2 requires is therefore not a rejection of
rules — it is a reframing of interpretation. Rather than viewing
people only as “components that produce errors,” the ETTO perspective
views them as adaptive agents operating within constraints to keep
the system moving.

4) The Computer Metaphor and Bounded Rationality: Progress in
Explanation, but the Time Problem Remains

In the latter half of the twentieth century, cognitive science
expanded the view of humans as information-processing systems. This
contributed to refining the rationality model. Simultaneously,
evidence rapidly accumulated that actual human performance diverges
from ideal computation. Concepts such as heuristics, bounded
rationality, and memory limitations emerged from this recognition.

However, as Hollnagel observes, much of this discussion focused on
“mismatches between information load and processing capacity” without
placing sufficient emphasis on a more fundamental fact: all activity
occurs within time. Capability limitations were explained as stable
properties — but the more essential constraint may be the mismatch
between the available time window and what the task actually demands.

This is the bridge to the ETTO Principle. People do not fail because
they are too slow. They fail because they are simultaneously required
to be fast enough and accurate enough — and those two demands compete.
Failure is often the product of trade-off pressure, not of capability
deficit.

5) Time to Think vs. Time to Do: Decision-Making Is a Time
Competition, Not a Sequential Process

Standard decision-making models depict a sequential progression:
evaluation → selection → execution. The problem is that these stages
do not separate neatly in practice. In the field, execution begins
while evaluation is still in progress; new information arrives during
execution; and the selection criteria themselves shift as events
unfold.

By emphasizing the overlapping and iterative nature of these stages,
Hollnagel draws attention to a persistent mismatch: time required and
time available are not always equal. When the required time exceeds
the available time, organizations typically have two options:
extend the deadline (usually difficult) or compress some portion of
evaluation, selection, or execution to fit within it (usually the
operational reality).

This is precisely where the efficiency-thoroughness trade-off
activates. Think more, or act now? Secure greater certainty, or
accept uncertainty and proceed? The objective of safety management is
not to eliminate this dilemma — it is to explicitly manage which way
the trade-off should tilt under which conditions.

6) The Uncertainty of Time: Deadlines Are Fixed, but the Timing
of the Next Interruption Is Not

The difficulty in operational environments is not simply time
pressure. The deeper challenge is uncertainty about when the next
interruption will arrive. New alarms, external requests, and
reprioritization events force in-progress activities to be
interrupted, compressed, or deferred. A planned schedule is
continuously overlaid with unpredictable events.

This drives practitioners toward conservative behavior: “Finish it
now while I can.” “Clear the backlog before the next event hits.”
This strategy is useful for maintaining control under interruption —
but it simultaneously reduces review depth and promotes simplified
judgment calls.

From the ETTO Principle perspective, this is not irrational. It is a
rational adaptation to an interrupt-dense environment. The implication
is that improvement efforts should focus less on individual behavioral
tendencies and more on redesigning the interruption structure and
time architecture of the work itself.

7) Chapter 2-1 Summary: The Core Question Is Not “Who Was Wrong?”
but “What Trade-Off Was Forced?”

The central point of Chapter 2-1 is clear. The normative rationality
model provides useful criteria — but when it fails to account for
time constraints and dynamic environments, its explanatory power in
the field breaks down. People are not ideal calculators. They are
operators making trade-offs within time windows.

This reframing matters because it changes the corrective strategy.
When failure is viewed only as a rule violation, correction becomes
individual-focused. When failure is viewed as a time-trade-off
problem, correction becomes condition-design-focused. The ETTO
Principle is the framework that enables that design question.

Chapter 2-2 will take up ETTO redefined, the bird-feeder and
herbivore analogies, and the Roman military camp example — examining
how trade-offs function as situational adaptation strategies. The
progression moves from “why do trade-offs occur?” to “how do we
design trade-offs to our advantage?”

The diagnostic questions that EHS practitioners should bring directly
from this chapter are concrete. Do our incident investigation reports
explain failure together with the time structure it occurred in —
or do they extract the final action and analyze it in isolation?
In key operational reviews, do we ask not only “how accurate was the
decision?” but also “did the operator actually have the time to
achieve that accuracy?” When task interruptions spike during
operations, do we have pre-agreed criteria for how to simplify
decision rules without degrading safety margins?
If these questions cannot be answered, we are evaluating individual
judgment while systematically converting structural pressure into
individual accountability.

The practical starting point for applying Chapter 2 is revising the
incident reporting form. Adding mandatory fields for “time
availability,” “interruption density,” “steps deferred or omitted,”
and “feasibility of deadline renegotiation” creates the data
infrastructure for ETTO analysis. This data is not evidence for
blame — it is a map showing which work segments routinely erode the
minimum threshold of thoroughness. A map enables precise intervention;
precise intervention reduces the cost of repeatedly correcting the
same failure mode.

A structured incident checklist amplifies this effect. For each
significant event, capturing at minimum: (1) the number of concurrent
tasks active at the time, (2) the number of interruptions in the
preceding 30 minutes, (3) deferred verification items and their
stated reasons, (4) unresolved hazards remaining at task completion,
and (5) the assigned owner and scheduled time for follow-up
verification — prevents the chronic problem of outcomes being
preserved in the record while process context disappears. These five
data points are not instruments of surveillance. They are learning
data: predictors of which steps will fail first the next time the
same pressure configuration appears. ETTO analysis is not about
judging the past — it is about designing future trade-offs more safely.

A team-level operational experiment is also worth piloting.
Running the same task under two conditions — standard operations
and time-protected operations (interruption limits + maintained
verification floor) — and comparing quality variance, rework rate,
and decision fatigue converts the ETTO discussion from theory into
negotiable data. Small-scale operational A/B tests of this kind
generate the evidence needed to shift organizational conversation
from “should we care about time pressure?” to “here is what time
pressure specifically costs us.”

The objective is not to find a single correct answer. It is to
identify repeating patterns: which time conditions reliably produce
which decision quality outcomes. When those patterns become visible,
the conclusion that design precedes training follows naturally.

Those patterns also vary by team. Even within the same organization,
teams with different interruption structures develop different trade-off
profiles — and require different protective measures. The same job
title under different time-pressure configurations needs a different
design response.

Consider a concrete example. A customer-response team and an
equipment-inspection team may both use the word “urgent” — but their
actual time windows differ substantially. The former is required to
respond in minutes; the latter may derive far greater value from
accurate diagnosis than from rapid response. Applying a single
enterprise-wide response rule to both produces overtaxed speed in
one context and unnecessary over-verification in the other.
Properly applying the ETTO Principle means maintaining common
principles while mapping different protective mechanisms to work
contexts with structurally different time-pressure profiles.

Source:
Erik Hollnagel,
The ETTO Principle: Efficiency-Thoroughness Trade-Off (2009, Chapter 2)
Next: Chapter 2-2 — ETTO Redefined · Feed the Birds · The Value of Planning


읽고 끝내지 않는 현장 적용

이 글의 현장 적용 패키지

작업 전 5분 체크

브라우저에서 바로 확인하고 인쇄할 수 있습니다.

최근 검토일 2026.03.02 · 공식 근거는 본문 출처를 확인하세요. 편집·검증 안내 · 수정 제보