The Human Cost of Getting It Wrong · Issue 5 of 5
HSI Governance and Safety Culture: When Expertise Has No Authority to Stop the Line
The experts were never silent on Ajax. What was missing was a path from what they knew to what the programme did. Governance is the domain that decides all the others.
An HSI plan is a document; HSI authority is a function. Programmes fail on the human side when the people who understand the human have no standing to stop the line: the Defence Science and Technology Laboratory tracked 136 technical concerns on Ajax and the programme rolled on, and Australia’s Tiger pilots had to vote not to fly to force their own escalation. Governance that gives human-systems expertise real escalation rights is the domain that decides whether any of the other four can work.
What did the experts say about Ajax?
The Defence Science and Technology Laboratory tracked 136 technical concerns about Ajax. Only four of them were about noise and vibration. The experts were not silent. They raised concern after concern, and the programme rolled on regardless. That is the finding that should haunt anyone who runs a capability programme: not that nobody knew, but that plenty of people knew, said so, and it changed nothing.
Why did raising concerns change nothing?
The Sheldon Review laid out why. The relationship between the procurement organisation and its own scientific advisers was fractious. Defence Equipment and Support discouraged Dstl from taking concerns directly to the safety team. People worked in silos that inhibited the sharing, understanding and escalation of exactly the information that mattered. Over all of it sat an optimism bias toward the programme, a default assumption that it would come good. The Ministry of Defence later admitted a breach of its duty of care, and soldiers were medically discharged. The expertise existed. What did not exist was a path for that expertise to stop the programme. There is a world of difference between having concerns and having the authority to act on them.
What does the Tiger helicopter add to the story?
Australia’s Tiger reconnaissance helicopter tells the same story in a different uniform. It was bought as an off-the-shelf capability and turned into a developmental one, flown under special arrangements while it matured. In 2012, after three cockpit fume incidents, the pilots voted not to fly until their safety concerns were addressed. Think about what it takes for aircrew to collectively refuse: that is the human end of the chain doing the escalation the system should have done years earlier. Final operational capability was eventually declared in 2016, around seven years late, with nine caveats attached because key systems were still developmental or incompatible with the rest of the force. The warning signs were not subtle, and they were not decisive. The platform was retired well ahead of the structural life still in its airframes.
What is HSI authority, and how is it different from an HSI plan?
In Human Systems Integration this is the governance and safety-culture domain, and it is the one that quietly determines all the others. An HSI plan is a document. HSI authority is a function: an independent voice with the standing and the escalation rights to halt a programme when the human-systems evidence demands it. Most troubled programmes have the plan. What they lack is the authority. A functioning safety culture is a structure in which the person who sees the problem can reach the person who can stop the line, and is not discouraged from doing so; posters and values statements are not that structure. Get this wrong and every other domain is exposed, because there is no mechanism to convert what the experts know into what the programme does.
What do the five issues add up to?
Which brings the series together. Over five issues we have walked the same building from five doors. Health hazards: noise and vibration met with earplugs instead of redesign. Survivability: a contaminated internal atmosphere nobody certified. Human factors: platforms built for a body that does not exist. Workforce: crewing models that assumed endurance was free. And now governance: expertise that had no authority behind it. Ajax, the MRH90, Collins, Hawkei, Armidale, Tiger. Different services, different decades, different machines. The same five failures, and beneath them the same root: the human treated as an adaptive buffer at the end of the process rather than a design constraint at the start. This is a governance failure with a known solution, and it repeats by decision rather than by bad luck.
The solution is to build the human in deliberately, and to give the people who understand the human the authority to be heard. That is the work Optimised Human Performance does: independent Human Systems Integration reviews of capability programmes and high-risk operations, across all of these domains, with the standing to surface what the programme would rather not see while there is still time to fix it.
If any of this series has felt familiar, if you have watched concerns get raised and absorbed rather than acted on, that is the signal to look harder.
Frequently asked questions
What is the difference between an HSI plan and HSI authority?
A plan is a document describing how human-systems work will be done. Authority is a function: an independent voice with the standing and escalation rights to halt the programme when the human-systems evidence demands it. Troubled programmes usually have the plan and lack the authority.
What did the Sheldon Review find?
That the relationship between the procurement organisation and its scientific advisers was fractious, that concerns were discouraged from reaching the safety team directly, that silos inhibited escalation, and that an optimism bias sat over the programme. The Ministry of Defence later admitted a breach of its duty of care.
What are the five failure domains in this series?
Health hazards, survivability, human factors engineering, workforce and personnel, and governance and safety culture. Across Ajax, MRH90, Collins, Hawkei, Armidale and Tiger, the shared root is the human treated as an adaptive buffer at the end of the process rather than a design constraint at the start.
Three or more red flags means an unassessed exposure
The Seven HSI Red Flags checklist is one page. If you tick three or more, your programme or operation has a human systems exposure that has not been formally assessed. Optimised Human Performance conducts independent Human Systems Integration reviews built for exactly this question.
Download the Seven HSI Red Flags