Systems Thinking

mental-model

When the same failure recurs across many people, look for the shared conditions producing it. Changing one system component can prevent more harm than demanding flawless performance from every individual.

A million nurses can be careful and competent, yet even a tiny error rate will still produce deaths if they all must use the same defective pump keyboard. The unsettling question is not why every nurse cannot be perfect, but why one company has not removed the shared trap.

E1

Move upstream to the shared constraint

Individual performance varies, but large numbers make rare mistakes inevitable. When a system repeatedly exposes many people to the same confusing interface or hazardous condition, that common component converts ordinary human fallibility into a recurring failure pattern. Blaming each operator treats every incident as separate; changing the shared design alters the odds for everyone at once. This is why human error should often begin the investigation rather than end it.

E1

Not every pattern has one master switch

Systems thinking earns its leverage only when failures share a cause that can actually be changed. If incidents arise from different conditions—or if the proposed redesign merely moves risk elsewhere—an upstream intervention may not solve them. The model also does not erase individual responsibility; it asks whether correcting individuals alone can prevent recurrence.

E1

Count recurrence before assigning blame

Tomorrow, take one repeated failure and list who encountered it, what condition they shared, and who controls that condition. If many different people stumble at the same point, propose one change to that shared component—such as altering the interface—instead of another reminder to be careful.

E1

Episodes that teach this