Avoiding normalization of deviance means treating every recurring workaround, unexplained anomaly, or missed control as evidence to investigate—not proof that the underlying risk is acceptable. The core discipline is simple: past success must not redefine the standard. NASA’s safety guidance expressly warns against using prior successful outcomes to redefine acceptable performance and calls for evidence-based assessment of probability and severity.^1
What it is
Normalization of deviance is the gradual process through which people depart from an agreed standard, experience no immediate disaster, and begin to regard the departure as normal practice. Over time, the workaround stops feeling like a deviation at all.^2
It rarely starts with recklessness. It often begins with a rational local response:
- “The approval takes too long; we will obtain it afterwards.”
- “The alarm always triggers; it is probably a false positive.”
- “We cannot fill that role this month; the team will cover it.”
- “The project is late, so we will skip the readiness review.”
- “The risk has been open for ages, but nothing has happened.”
The danger is the inference: nothing bad happened last time, therefore the risk is tolerable. That conclusion confuses luck, low frequency, or incomplete observation with demonstrated control effectiveness.

Design the countermeasures
Avoiding normalization of deviance means treating every recurring workaround, unexplained anomaly, or missed control as evidence to investigate—not proof that the underlying risk is acceptable. The core discipline is simple: past success must not redefine the standard. NASA’s safety guidance expressly warns against using prior successful outcomes to redefine acceptable performance and calls for evidence-based assessment of probability and severity.[1]
What it is
Normalization of deviance is the gradual process through which people depart from an agreed standard, experience no immediate disaster, and begin to regard the departure as normal practice. Over time, the workaround stops feeling like a deviation at all.[2][3]
It rarely starts with recklessness. It often begins with a rational local response:
- “The approval takes too long; we will obtain it afterwards.”
- “The alarm always triggers; it is probably a false positive.”
- “We cannot fill that role this month; the team will cover it.”
- “The project is late, so we will skip the readiness review.”
- “The risk has been open for ages, but nothing has happened.”
The danger is the inference: nothing bad happened last time, therefore the risk is tolerable. That conclusion confuses luck, low frequency, or incomplete observation with demonstrated control effectiveness.
Design the countermeasures
The strongest defences combine clear standards, visible operational evidence, independent challenge, and consequences for unresolved deviation.

NASA’s own guidance is especially useful as a concise design test: require the system to be proven safe and effective to an acceptable risk level, rather than requiring someone to prove it is unsafe; deliberately prevent groupthink; keep safety assurance independent; and balance schedule and operational tempo against a comprehensive risk assessment. The Columbia Accident Investigation Board similarly identified organisational barriers to critical-safety communication, suppressed professional disagreement, fragmented management, and informal decision routes that operated outside formal rules.[1][4]
Make it operational
A practical way to turn the principle into routine management is to create a Deviation Review Loop.
1. Detect: Capture every material deviation from a standard, control, tolerance, approval route, or expected result—including near misses and “successful” workarounds.
2. Classify: Separate one-off human error, necessary emergency action, authorised exception, recurring workaround, and systemic control failure. The distinction matters because recurring workarounds are often the earliest warning.
3. Assess: Ask four questions:
- What standard or control was bypassed?
- Why did normal work require the bypass?
- What could plausibly happen under worse conditions?
- What evidence shows the risk is, or is not, controlled?
4. Decide formally: Either restore compliance, redesign the process/control, resource the required fix, or formally accept the residual risk at the right authority level. Do not leave the workaround unofficial.
5. Verify: Test whether the action changed behaviour and outcomes. For example, if a change was intended to prevent a repeat incident, look for a sustained fall in recurrence rather than merely a closed action item.
6. Escalate recurrence: A second or third instance should automatically attract more senior review. Repetition is not reassurance; it is evidence that the system may be adapting around a weakness.
Leadership behaviours
Leaders determine whether deviations are surfaced or buried. The most valuable behaviours are:
- Ask, “What are we doing outside the stated process to get the work done?”
- Ask for the uncomfortable data: overdue high-risk actions, repeated exceptions, near misses, control-test failures, unresolved audit findings, and red performance trends.
- Separate the question “Did we meet the deadline?” from “Did we meet the operating standard safely and reliably?”
- Thank people who expose problems early, especially when doing so delays a decision or delivery milestone.
- Do not reward heroic recovery from chronic under-resourcing while ignoring the conditions that made the heroics necessary.
- Personally test whether dissent reached the final decision-maker—not merely whether a meeting occurred.
A just culture is important here: people need confidence that reporting an error, near miss, or unsafe shortcut will trigger learning and improvement rather than automatic punishment. That does not mean no accountability; it means distinguishing deliberate disregard from a reasonable response to a poorly designed, poorly resourced, or contradictory system. Open communication, prompt treatment of deviations, continuous learning, and leaders willing to challenge unsafe practices even when it delays production are all highlighted as key prevention measures.[5][6]
Use the E1–E3 model
The Universal Framework is well suited to diagnosing this risk because it prevents an organisation from mistaking a written policy for a working capability. The useful test is:
For example, a project may have a formal stage-gate procedure at E1. It reaches E2 only when governance forums receive meaningful schedule, cost, risk, and readiness information and can intervene. It reaches E3 only when records show gates actually stop, redirect, rescope, or defer unready initiatives—and delivery outcomes improve as a result.
That is the broader lesson: a process that exists but is routinely bypassed is not a mature control; it is evidence of a capability gap.
Sources
[1] The Cost of Silence: Normalization of Deviance and Groupthink https://sma.nasa.gov/docs/default-source/safety-messages/safetymessage-normalizationofdeviance-2014-11-03b.pdf?sfvrsn=4
[2] Normalization of Deviance Is Contrary to the Principles … https://pubmed.ncbi.nlm.nih.gov/36971528/
[3] A Qualitative Systematic Review on the Application of the … https://safetyinsights.org/2022/02/17/a-qualitative-systematic-review-on-the-application-of-the-normalisation-of-deviance-phenomenon-within-high-risk-industries/
[4] Columbia Accident Investigation Board Report Executive … https://www.nasa.gov/wp-content/uploads/2024/03/sept4-caib-report-executive-summary.pdf?emrc=f4843a
[5] When Cutting Corners Becomes the Norm: How Normalizing Deviance … https://www.army.mil/article/286745/when_cutting_corners_becomes_the_norm_how_normalizing_deviance_can_lead_to_disaster
[6] The normalization of deviance in healthcare delivery – PMC https://pmc.ncbi.nlm.nih.gov/articles/PMC2821100/
[7] NASA’s Understanding of Risk in Apollo and Shuttle https://ntrs.nasa.gov/api/citations/20190002249/downloads/20190002249.pdf
[8] [PDF] Lessons Learned from the Aerospace Industry https://ehss.energy.gov/deprep/archive/documents/PM031023_CAIB.pdf
[9] Safety Culture Threat: Normalization of Deviance https://www.cer-rec.gc.ca/en/safety-environment/safety-culture/safety-culture-learning-portal/safety-culture-threat-normalization-deviance.pdf
[10] SEDLAR, N., IRWIN, A., MARTIN, D. and ROBERTS, R. 2023. A qualitative systematic review on the application of the https://rgu-repository.worktribe.com/preview/1822740/SEDLAR%202022%20A%20qualitative%20systematic%20review%20(AAM).pdf
[11] Marie Yolande Djedje https://researchportal.lsbu.ac.uk/ws/portalfiles/portal/11522043/Exploring_Normalization_of_Deviance_and_Examining_Factors_that_Predict_Negative_Patient_Safety_Outcomes_the_Case_of_the_Ivory_Coast_1_.pdf
[12] A qualitative systematic review on the application of … https://rgu-repository.worktribe.com/OutputFile/1822740
[13] ASHRM Patient Safety Tip Sheet: Normalization of Deviance in …www.ashrm.org › system › files › media › file › 2021/02 › Normalization-… https://www.ashrm.org/system/files/media/file/2021/02/Normalization-of-Deviance-in-Healthcare.pdf
[14] [PDF] Columbia and Challenger: organizational failure at NASA https://josephhall.org/papers/nasa.pdf
