The Swiss Cheese Model: How Boards Can Spot Systemic Failures Before Disasters Happen
Every serious crisis inside a construction or infrastructure company arrives with the same peculiar quality: in hindsight, it looked obvious. A cost overrun that should have been flagged eighteen months earlier. A safety incident preceded by three near-misses that were each individually explained away. A compliance failure that had been technically avoidable at half a dozen different points along the way. Almost never does a serious organizational failure trace back to one bad decision by one bad actor. It traces back to a chain of small, individually forgivable gaps that happened to line up.
There is a model, developed decades ago by the psychologist James Reason to explain accidents in complex systems like aviation and healthcare, that captures this pattern more precisely than almost anything else in governance work. It is called the Swiss Cheese Model, and once a director understands it properly, it becomes almost impossible to look at a corporate crisis the same way again.
What the Swiss Cheese Model Actually Says
Picture a stack of slices of Swiss cheese, each one representing a layer of defense within an organization — a safety inspection, a compliance review, a financial audit, a design check, a contractor vetting process. Each layer exists specifically to catch problems before they cause harm. No single layer is expected to be perfect. Every slice has holes in it: gaps, oversights, moments where the defense doesn’t quite catch what it was designed to catch.
Under normal circumstances, this doesn’t matter. The holes in any one slice are covered by the solid parts of the slices behind it. The layered nature of the defenses is what keeps the system safe, even though no individual layer is flawless.
A disaster happens, in Reason’s model, only when the holes in multiple layers happen to align at the same moment — when a gap in the design review lines up with a gap in the site inspection, which lines up with a gap in the contractor’s own quality process, creating a straight, unobstructed path all the way through the system. No single layer failed catastrophically. Each one simply had its ordinary, expected imperfection, at the worst possible moment, in the worst possible place.
This is a profoundly different way of thinking about failure than the instinct most organizations default to, which is to look for the one layer that “should have caught it” and treat that layer’s failure as the root cause. The model insists on a harder, more honest question: which several layers all had a gap in the same place, and why did nobody notice the gaps were aligning until it was too late.
Why This Model Matters Specifically for Boards
Most boards, when reviewing a serious incident, instinctively reach for a single explanatory layer. A project cost overrun gets attributed to “poor site-level cost tracking.” A safety incident gets attributed to “a contractor safety lapse.” Each explanation is usually true, as far as it goes. But it is almost never the whole truth, and treating it as the whole truth leads a board to fix one slice of cheese while leaving the rest of the stack exactly as porous as it was before.
PRACTITIONER NOTE“Every post-mortem report I’ve ever written could have been titled ‘The Five Things That All Had to Go Wrong At Once.’ But by the time it reaches the board, someone has usually simplified it down to one villain, because one villain is easier to present and easier to fire.”
— a compliance officer who has investigated corporate failures for years
This simplification is comforting, but dangerous, because it leaves the other holes in place, waiting for the next unlucky alignment. A board that genuinely wants to prevent the next crisis has to resist the pull toward a single-cause narrative and ask instead: what are all the layers of defense in this organization, and where might their gaps be quietly lining up right now, without anyone noticing?
Translating the Model Into Plain Governance Language
It helps to translate Reason’s model directly into the language a board actually works with. In a typical infrastructure or construction company, the relevant “slices” of defense include:
Each layer has known, tolerated gaps — the ordinary imperfections of any real-world system run by real people under real constraints. The governance question is not “how do we make every layer perfect,” which is neither possible, nor past a certain point, cost-effective. The question is: how do we ensure the layers are genuinely independent of each other, so a gap in one is unlikely to align with a gap in another?
Where Boards Should Look for Aligning Gaps
Three patterns are worth watching for specifically.
Shared sources of information. If the site safety inspection, the project manager’s status report, and the compliance summary all trace back to the same site team’s self-reporting, these are not three independent layers — they are one layer, dressed up as three. A genuine defense-in-depth structure needs some layers drawing on independent sources: an external auditor rather than internal self-certification, a whistleblower channel that bypasses the chain of command, a board-commissioned site visit rather than a summarized report.
Shared commercial pressure. If a project is behind schedule and over budget, the temptation to compress or soften almost every layer of review rises simultaneously, because the same underlying pressure is pushing on all of them at once. This is precisely the condition under which holes are most likely to align, because the gaps are no longer random — they are being pulled toward the same weak point by the same force.
Organizational silence between departments. A design flaw a site engineer has quietly worked around, a subcontractor’s financial instability procurement has noticed but not escalated, a regulatory concern legal is tracking but hasn’t connected to an operational decision — these gaps often exist in full view of different people who simply never compare notes.
PRACTITIONER NOTE“In aviation, the near-misses that matter most are never the ones everyone already knows about. They’re the ones sitting in three different logbooks, each looking harmless on its own, that nobody has ever put next to each other.”
— a former air safety investigator who now consults on corporate risk
What Boards Can Do With This Framework
The most direct application at board level is to stop asking, after an incident, “which layer failed,” and start asking, before an incident, “which of our layers currently rely on the same source of information, the same team, or the same set of assumptions, such that a single failure could pass through several of them at once.”
This can be built into risk oversight structure. Rather than reviewing risk purely by category — financial, safety, compliance, reputational — a board can periodically ask which of its control layers are genuinely independent and which are quietly dependent on the same underlying source. It is also worth explicitly reviewing whether commercial pressure on a specific project is currently pushing on multiple layers of defense simultaneously; under this model, that moment deserves increased independent scrutiny, not less.
Finally, boards benefit from creating structured opportunities for cross-departmental information to surface before it aligns into a crisis — regular sessions where design, site operations, procurement, legal, and finance are each asked, without the filter of a single consolidated report, what risks they are individually aware of that they suspect nobody else has connected to their own.
A Closing Thought
The value of the Swiss Cheese Model for a board is not that it offers a new checklist. It is that it offers a new way of asking the question. Instead of “did our safety process fail,” it asks “which of our independent defenses had a gap in the same place at the same time, and why did none of the others catch it.” Instead of “who is responsible for this failure,” it asks “how many ordinary, tolerable imperfections had to align, unnoticed, for this to happen.”
That shift in framing changes how a board watches for a crisis before it happens — not by demanding perfection from any single layer, which no organization can deliver, but by insisting the layers remain genuinely independent, that pressure on one is treated as pressure on all, and that the small, quiet gaps different departments already know about are brought into the same room before they ever get the chance to line up.