[#5] ETTO Principle Ch.1-4|Why Success and Failure Share the Same Root






Why Success and Failure Share the Same Root | ETTO Principle Efficiency Thoroughness Ch.1-4


SAFETY MANAGEMENT · CHAPTER 1 · PART 4/4

Why Success and Failure Share the Same Root

Chapter 1-4 · The ETTO Principle in Practice · Changing Views

Part 4 closes Chapter 1. The central task here is moving the
ETTO Principle — the efficiency-thoroughness trade-off
out of theory and into operational practice. Hollnagel does not use ETTO
solely to explain failure after the fact. Instead, by establishing that
success and failure emerge from the same performance mechanism,
he argues for a fundamental shift: from incident-investigation-driven
safety management to operationally-designed safety management. This part
covers “The ETTO Principle in Practice,” “Changing Views,” and
“A Note on Terminology” — translated into applied EHS criteria, not
just summary.

ETTO Principle efficiency thoroughness trade-off — success and failure emerging from the same performance mechanism
The ETTO Principle: success and failure are not separate worlds.
The same efficiency-thoroughness trade-off that enables daily performance
becomes a failure pathway when conditions change.

1) ETTO in Practice: Trade-Offs Are Not Exceptions — They Are the
Default Mode of Operations

The ETTO Principle does not describe a crisis phenomenon. It describes
the default mechanism of everyday operations. Every decision made on
the floor — processing speed, inspection depth, documentation
completeness, verification rigor — involves a real-time trade-off
between efficiency and thoroughness. The problem is not that trade-offs
exist, but that organizations rarely track which direction they are
systematically drifting.

The drivers of trade-offs are straightforward in practice: time is
constrained, unplanned work interrupts regularly, and production
pressure is constant. Compound that with workforce turnover, skill-level
variation, system updates, and audit cycles, and maintaining a uniform
level of thoroughness becomes increasingly difficult over time.

The first step in ETTO-based operations is therefore not to prohibit
trade-offs, but to make them visible. Which procedures are actually
being abbreviated? Which verification steps are routinely skipped?
How are deviation approval frequency and lead time changing?
Without data surfacing these patterns, unmanaged trade-offs
accumulate silently into systematic bias.

The practical method is simple. In monthly safety reviews, stop
looking only at incident counts. Add these questions: “Which
verification step was most frequently abbreviated this month?” “What
deviation justification appeared most often?” “Which work was
completed fastest but had the highest rework rate?” Embedding these
questions into a fixed review format keeps trade-off patterns visible
and on record.

2) Six Pressures That Drive Trade-Offs: Attributing Them to
Individuals Eliminates the Corrective Action

Translating Chapter 1’s operational context into applied EHS terms,
the pressures that produce trade-offs fall into six categories:

  • Production pressure and schedule compression — time-constrained or time-uncertain work conditions
  • Least-effort heuristics — the natural tendency to accomplish tasks with minimum expenditure of resources
  • Resource conservation — preserving capacity for anticipated contingencies
  • Organizational and social pressure — expectations from supervisors, peers, and subordinates
  • Priority misalignment — conflict between formally stated priorities and what is actually rewarded in practice
  • Individual variation — differences in habit, experience level, risk tolerance, and work style

What matters is that these pressures are not independent. When
schedule pressure intensifies, approval-step bypasses increase.
When bypasses are repeated without consequence, informal norms form:
“this is how we actually do it.” Once informal norms are established,
new workers learn them as standard practice.

This is why attributing incidents to individual decisions produces
shallow corrective actions. The worker is the last actor in a chain;
the conditions of their decision were created by the system. Applying
the ETTO Principle in practice means moving past “who took that
action” to “what combination of pressures made that action appear
rational in context.”

Even the sequencing of incident investigation interviews matters.
Before asking “Why didn’t you follow the procedure?”, establish
the operational context first: “What was the time pressure at that
point?” “Where did the information break down?” “Were alternative
courses of action actually available?” Reordering the questions
reduces individual defensiveness and yields more accurate data
on system-level contributing factors.

3) Success and Failure Are Not Separate Worlds: The Same Strategy
Reverses Under Different Conditions

Hollnagel’s most important insight is this: success and failure do
not result from different mechanisms. They result from the same
performance principle expressing itself under different conditions.
The rapid adjustments, shortcuts, workarounds, and experience-based
judgments that routinely produce good outcomes are the same behaviors
that, under certain conditions, become failure pathways.

This reframing matters because it changes where learning is directed.
The traditional model looks for causes only in failure events.
The ETTO model looks for the same behavioral patterns in successful
events as well. The question is not only “what was different on the
day of the incident?” but also “what adjustments were being repeated
consistently on incident-free days?”

In practice, this requires integrating near-miss data with normal
operations data. Alongside formal incident and near-miss reports,
organizations need to systematically capture variance patterns during
routine work: schedule compressions, abbreviated procedures,
management-of-change bypasses, handover omissions. Only then can
failures be interpreted on a continuum with everyday operations —
rather than isolated as discrete anomalies.

4) The ETTO Principle Is Not a Root-Cause Theory — It Is a Predictive
Behavioral Framework

The ETTO Principle does not identify the definitive root cause of any
specific event. Hollnagel proposes ETTO as both an explanatory and a
predictive framework: a tool for understanding which direction people
and organizations are likely to trade off under given constraints —
and for managing those outcomes proactively.

The practical difference is significant. Root-cause-focused approaches
are strong at post-event response but weak at pre-event design. The
ETTO approach, by contrast, is designed to track the direction of
trade-off drift in current operations and identify intervention points
before an incident occurs.

Leadership questions must shift accordingly. Rather than stopping
at “Who violated the procedure?”, the right questions are:
“Why were the operational conditions structured in a way that made
following the procedure difficult?” and “Which performance metrics
are currently rewarding unsafe speed or encouraging risk tolerance?”
Without this shift in questioning, ETTO remains a reporting
framework rather than an operational one.

More specifically, leadership must design the timing of intervention.
Rather than one-off directives after an event, establishing a
quarterly cycle to review trade-off indicators and recalibrate
acceptable baselines allows organizations to correct drift before it
accumulates into an incident. The ETTO Principle only generates
durable results when embedded in a recurring management loop —
not treated as a declaration.

5) System Boundaries and Terminology: The ETTO Principle Follows
Functional Flow, Not Structural Boundaries

The terminology section closing Chapter 1 is brief but operationally
significant. When Hollnagel refers to “the system,” he does not mean
a collection of equipment. He means a socio-technical system: an
integrated configuration of social elements (people, roles,
decision-making structures) and technical elements (tools, procedures,
interfaces) that collectively achieve a defined objective.

Critically, system boundaries in ETTO analysis are not defined by
physical perimeters. ETTO uses functional boundaries: “how far does
mutual dependency extend for the purpose in question?” Without this
perspective, significant contributing factors are classified as
“external” and excluded from the analysis scope.

For example, a field incident may functionally involve schedule
policy, staffing decisions, supply chain delays, and approval
authority structures — even if those factors appear organizationally
remote from the event location. If they are functionally linked,
they are internal variables for analysis purposes. Only by drawing
a wide enough functional boundary can ETTO drift be traced from
its origin point to its amplification point.

This principle must be distinguished from diffusing accountability.
Expanding the analysis scope does not obscure responsibility — it
extends responsibility from the last executor to the system designer.
The clearer the functional boundary, the more specific the corrective
action becomes at each organizational level, and the less likely the
analysis is to collapse into unproductive “field error” or
“management failure” framing.

6) Operational Application Framework: What to Prioritize When
Implementing the ETTO Principle

The most common failure mode when introducing ETTO is stopping at
awareness training. Training is necessary but insufficient — without
structural change, behavior reverts. A minimum of four elements must
be designed simultaneously from the outset:

  • KPI framework — simultaneous tracking of efficiency and thoroughness through both leading and lagging indicators
  • Decision documentation — forms requiring both an efficiency rationale and a thoroughness rationale for every significant decision
  • Operational mode protocol — defined criteria for transitioning between normal operations and heightened-vigilance mode
  • After-action review (AAR) — a structured meta-review examining where trade-offs exceeded acceptable bounds and why

On the metrics side, lagging indicators alone are insufficient.
Beyond incident rates and severity costs, organizations need leading
indicators: inspection step skip rate, deviation approval frequency,
approval cycle time, rework rate, and shift handover omission rate.
Leading indicators reveal the trajectory toward failure — not just
the arrival at it.

Finally, standardize the leadership response sequence for incidents.
The first response is conditions review — not individual
accountability. The second is identification of recurring pressures.
The third is recalibration of trade-off rules. When this sequence
is consistently applied, the organization moves from a punitive
reaction model to a learning-by-design model.

One additional practice significantly improves durability: within
two to four weeks following an intervention, conduct a field
verification to confirm that the corrective conditions are actually
being applied. A corrective action memo alone cannot confirm
execution quality. Without a follow-up loop, ETTO improvements
remain on paper rather than in practice.

7) Chapter 1 Conclusion: The ETTO Principle Moves Safety Management
from Post-Incident Analysis to Pre-Incident Design

The message running through all of Chapter 1 is straightforward.
People and organizations inherently operate by trading off efficiency
and thoroughness — and those trade-offs produce most of their
successes. Simultaneously, the same trade-offs, when conditions shift,
can produce failure. Failure is therefore not an abnormal event.
It is the shadow of normal operations.

This perspective reframes the core questions of EHS management.
Before asking “What additional procedure should we add?”, ask first:
“Do workers actually have the time and resources to choose thoroughness
when it matters?” “Are our KPIs rewarding dangerous speed?” and
“Are deviations being managed as exceptions, or have they solidified
into standard practice?”

In summary, the ETTO Principle is not another theory that simplifies
failure causation. It is an operational framework for understanding
success and failure along a single continuum — and for intentionally
managing the direction of trade-off drift. Chapter 2 extends this
framework into broader questions of decision-making and rationality,
examining how ETTO rules form at the individual, team, and
organizational levels.

One line to anchor Chapter 1 in practice: “To reduce incidents,
stop trying to control people more tightly — start designing the
conditions under which people make better trade-offs.”
That
principle makes every subsequent chapter of the ETTO Principle
coherent and applicable.

Source:
Erik Hollnagel,
The ETTO Principle: Efficiency-Thoroughness Trade-Off (2009, Chapter 1)
Next: Chapter 2 — From Rationality to ETTOing


읽고 끝내지 않는 현장 적용

이 글의 현장 적용 패키지

작업 전 5분 체크

브라우저에서 바로 확인하고 인쇄할 수 있습니다.

최근 검토일 2026.02.27 · 공식 근거는 본문 출처를 확인하세요. 편집·검증 안내 · 수정 제보