Swiss Cheese and the Board

,

A few months ago, working through a risk register entry for a risk I’ll leave unnamed, I found myself counting the layers and arriving at the usual three – first-line operational control, second-line risk function review, third-line internal audit assurance – and then noticing (with a small chill) that all three layers were ultimately staffed by people who reported through the same manager. My mental picture of the risk was correct: there were three lines. But this picture was also misleading: the holes in those three lines were, for any failure originating with that manager, almost certainly aligned.

This mental image was an instance of one of the most reproduced models in safety literature: James Reason’s “Swiss cheese” depiction of organisational accidents, first published in 1990. Reason’s model imagines a series of slices of cheese, each representing a defensive layer between a hazard and a consequence. Each slice has holes: gaps in the layer’s effectiveness, which move around as conditions change. An accident occurs when, for a moment, the holes line up and a trajectory of failure passes cleanly through every layer.

The power of the model is that it explains why accidents in well-defended systems are usually surprising even with hindsight. No single layer was missing; no single person was negligent… The holes simply lined up.

The three-lines-of-defence framework now embedded in every Australian (and international) governance handbook is, in effect, a Swiss cheese model with three named slices. It works, when it works, for the same reason Reason’s model works: the layers are independent, and the probability of all three failing simultaneously is therefore the product of three small probabilities, which is a much smaller number.

The catch is that independence is the property the diagram assumes rather than the property it tests. In practice, the holes in different layers are often correlated – the same person, the same system, the same assumption, or the same time pressure that produces a hole in one layer produces a hole in the next. When that happens, the layers are not statistically independent, the protective arithmetic collapses, and what was sold to the Board as three lines is in fact one line with two echoes.

In engineering, we ensure protective layers are truly independent by designing all aspects of their protection separate from other protective layers protecting the same risk. But this can be difficult to achieve in an organisational sense. For example, when a management report, the audit committee pack, and the regulator return all draw from the same general accounts extract, an error in the extract flows through three “layers” of review without ever being seen as an error. Each reviewer is checking the presentation; nobody is checking the source. The Board sees three sets of eyes; but the data actually has had only one.

A CFO who prepares the accounts, attends the audit committee, signs the representation letter to the auditor, and is the principal contact for the regulator is (for the purposes of the financial reporting control framework) a single point through which every layer passes. This is not a hypothetical: it is the modal arrangement at many smaller organisations, and it is almost never surfaced on a control map.

When the budget, the strategic plan, and the risk register all assume that funding source X will continue at current levels, the entire planning framework will fail in the same direction if X does not. Three documents; one assumption. And when the IT access control, the audit log, and the backup are all components of the same system, a compromise of that system defeats all three controls in a single stroke. This is the lesson of every major ransomware incident of the last five years, and it remains under-internalised in boardroom cyber discussions.

And finally. when all three layers operate in the final week of the month, a busy month-end could produce correlated failures across what looked like independent controls. A reviewer who skipped the cash reconciliation deep-dive is the same reviewer who skipped the accruals deep-dive, because the reviewer is one person under one set of pressures.

The remedy here would be not to redesign the control framework (that’s management’s job, not the Board’s). The Board’s job is to interrogate the framework with a slightly different question: not “how many layers do we have?”, but rather “what would have to be true for all of these layers to fail at once?”. If the answer is a single name, a single system, a single assumption, or a single moment in the calendar, the organisation’s Swiss cheese layers are not as independent at protecting from risk and/or consequence as the diagram suggests.

The complementary question, drawn again from engineering, is to ask what the common-mode failure is – the single underlying event that defeats multiple nominally redundant systems. The textbook example is the flood that takes out both the primary and the backup power supply at a nuclear power plant, because the backup is in the same flood-prone basement. The governance translation: what single event, decision, or omission could defeat every control we currently rely on for this risk..? Neither question is difficult. Neither is the question the standard three-lines diagram prompts you to ask. The diagram invites you to count layers. Swiss cheese, properly read, invites you to look at the holes.

I should say that perfectly independent layers are an idealisation. Real organisations have shared people, shared systems, and shared deadlines, because they are organisations and not abstract risk models. The point is not that correlated controls are a failure of governance; the point is that they should be recognised as correlated, so that a Board’s confidence in the overall framework is calibrated to what the framework actually provides rather than to what its risk management system appears to promise.

Reason’s original paper was, in the end, an argument for humility. The accidents he studied were not the result of negligent individuals or missing layers. They were the result of layers that everyone had believed were independent, and that turned out, on the day, not to be. A Board that asks where its holes might line up is doing the work that the a three layers diagram alone cannot do.

About Me

I’m Sebastian; an engineer, GAICD, commercial advisor and father who is passionate about contributing my commercial, legal and engineering acumen to purpose-driven organisations that create meaningful, sustainable change in the community.

Recent Articles