Article
How a Warning Becomes Wallpaper
Early risk signals rarely fail loudly. They get explained away one at a time, this instance was a fluke, that one was an outlier, until a pattern that would have been obvious viewed together has been rationalized, individually and reasonably each time, into background noise nobody is watching anymor
- Published
- July 21, 2026
- Updated
- August 19, 2026
- Reading time
- 9 min

The Global Signal
On January 28, 1986, the Space Shuttle Challenger broke apart 73 seconds after launch, killing all seven crew members, due to the failure of an O-ring seal in one of the solid rocket boosters in unusually cold launch-morning temperatures. The Rogers Commission, the presidential commission that investigated the disaster, found that engineers at contractor Morton Thiokol had documented O-ring erosion and blow-by on prior shuttle flights for years before the accident, and had raised concerns about launching in cold temperatures the night before the flight, concerns that were ultimately overruled in the final launch decision (Rogers Commission Report, 1986). Sociologist Diane Vaughan's subsequent study of the decision, "The Challenger Launch Decision" (1996), coined the term "normalization of deviance" to describe how each prior instance of O-ring erosion, technically a deviation from the design specification, had been reviewed, explained, and accepted as within an expanding definition of acceptable risk, so that by the night before the final launch, a genuinely dangerous pattern had been absorbed into what counted as normal.
No single review of any one flight's O-ring data was dishonest or obviously wrong. Each review, taken alone, reached a defensible conclusion. The pattern only became visible in hindsight, once someone looked at the flights together instead of one at a time.
The pattern only became visible in hindsight, once someone looked at the flights together instead of one at a time.
What changes when patterns are reviewed, not just incidents
Reviewing each incident individually, however competently, cannot detect a pattern accumulating across the full series.
A standing, separate review comparing this period's accepted explanation against prior periods' catches a quietly widening risk before an individual review ever could.
Why the Visible Metric Misleads
A quarterly or per-incident review answers a narrow question well, what explains this specific instance, and that narrow framing is exactly what prevents it from answering a different, more important question: does this instance belong to a worsening pattern across time. The more revealing practice is not better individual incident reviews, which were often genuinely competent on their own terms in Challenger's case, but a separate, standing review that looks specifically for whether prior "acceptable" explanations are recurring and whether the range being called acceptable has quietly widened. The Rogers Commission found that Morton Thiokol's own engineers had, in effect, already updated their internal sense of acceptable O-ring erosion multiple times before the fatal flight, each update reasonable given the immediate data, cumulatively dangerous given the full series.
The Leadership Move
The right move is not to demand zero deviations or treat every minor anomaly as a crisis. It is to build a standing review, separate from routine incident-by-incident analysis, whose specific job is to ask whether this quarter's "acceptable" explanation matches or exceeds prior "acceptable" explanations, flagging when the accepted range itself is quietly expanding.
- Ownership
The team closest to an incident, engineering, quality, or frontline operations, typically owns explaining that specific instance well. A separate function, risk, safety, or an independent review body, needs to own comparing the accumulating series of explanations against each other, since the team explaining instance number twelve is rarely positioned to notice that instances one through eleven quietly redefined what counts as acceptable.
- Tradeoff
A standing pattern review that looks across incidents, rather than at each one individually, costs real time and will sometimes flag a pattern that turns out to be genuinely benign. The alternative, Challenger's case shows starkly, is a pattern that only becomes visible after the worst possible outcome has already occurred.
- Human consequence
The seven Challenger crew members were served by an organization in which every individual review of prior O-ring problems was defensible on its own terms, and none of those reviews, taken alone, was positioned to see that the accepted range of risk had been expanding flight after flight.
Implication for Operators
Any organization that reviews risk incidents one at a time, however competently, should assume that a genuine pattern can accumulate invisibly across those reviews, because no single review is built to compare itself against the full series. The practical shift is establishing a standing, separate review whose explicit purpose is checking whether this period's accepted explanation matches or exceeds prior periods', not simply reviewing each new incident on its own merits.
Challenger's O-ring problem was documented, discussed, and individually explained for years before the disaster. The organization was not blind to the existence of the risk. It was blind to the fact that each reasonable explanation was quietly widening what counted as acceptable, and no standing mechanism existed to compare this flight's explanation against the accumulating series that came before it.
The decision blindness here is not a hidden risk. It is a risk explained competently, one instance at a time, until the explanations themselves became the pattern nobody was watching for.
How often does your organization review incidents together to see whether the explanations themselves are becoming a pattern?
FAQ
Was the Challenger disaster a failure of the engineers who reviewed O-ring data?
The Rogers Commission's findings and Diane Vaughan's subsequent study describe a more structural failure: engineers raised concerns the night before launch that were overruled, and prior individual reviews of O-ring erosion were each defensible given the data available at the time. The deeper failure was the absence of a standing mechanism comparing those reviews against each other across the full series of flights.
What does "normalization of deviance" actually mean?
Diane Vaughan's term, from her 1996 study of the Challenger decision, describes how a deviation from a design specification, if reviewed and explained enough times without consequence, gradually becomes redefined as acceptable, so the organization's own sense of "normal" quietly shifts to include what was originally a warning sign.
How can an organization tell if it is normalizing deviance?
Ask whether anyone is comparing this period's "acceptable" explanation against prior periods' explanations for the same category of issue, specifically checking whether the accepted range has grown. If no one holds that comparison as an explicit, standing responsibility, the organization has no defense against the pattern Challenger's case illustrates.
Is reviewing every incident individually still valuable?
Yes, and Challenger's individual incident reviews were often technically competent. The point is not to replace incident-by-incident review but to add a separate, standing review whose job is comparing the accumulating series, which individual reviews are not designed to do.
Who should own the standing pattern review?
A function independent from the team explaining individual incidents, typically risk, safety, or an audit-style function reporting outside the operational chain being reviewed, so the comparison is not performed by the same people whose prior explanations are being checked.
Related intelligence
Article
Steering From Lagging Indicators
Strategic choices are routinely built on the most recent quarter's or year's results, indicators that are, by construction, a record of conditions that have already changed by the time they are reported. Leadership can steer confidently, using genuinely accurate numbers, toward a destination defined
Article
Automating a Decision Nobody Had Actually Made
Organizations frequently automate a workflow, a trading rule, a routing decision, a pricing exception, before anyone has explicitly decided what that workflow should optimize for, what should happen at its edges, or who owns the exceptions it will inevitably produce. Automation does not remove a dec
Article
Governance as a Way Not to Decide
A review committee, a steering group, or a multi-stage sign-off chain can look like careful oversight while actually functioning as a way to defer an uncomfortable decision indefinitely, because each additional review step looks rigorous and simultaneously postpones the moment someone has to actuall