top of page

An Uncomfortable Truth

Lessons from NASA, BP, and Global Brand Withheld


Safety is not defined by the absence of incidents. It is defined by an organization's capacity to identify risk, understand its potential consequences, and mitigate it before it causes harm.


A safety record tells leaders what has happened. Organizational capacity determines whether the company can find and address what could happen next.


Todd Conklin, who served as a senior advisor for organizational and safety culture at Los Alamos National Laboratory, one of the world’s most complex, high-consequence operating environments, offers, in my opinion, the best definition of safety. It is the one we use at Guidant Power: “Safety is the presence of capacity.”


For executive leaders, the implication is direct and uncomfortable. Low injury rates, experienced teams, mature safety programs, and years without a serious event can all exist in the same organization that is blind to a critical hazard.


None of those indicators prove the organization can recognize a hidden risk, understand its true consequence, and act in time to prevent a catastrophic event.

History has repeatedly shown the gap between appearing safe and being safe.


Texas City Had Strong Safety Results.. Until It Did Not

Before the 2005 explosion at BP's Texas City refinery, one of the deadliest U.S. refinery accidents, the facility appeared to have reported improving safety performance based on injury-rate metrics.

They were looking in the rear view mirror.

The injury rate measured personal safety events such as slips, trips, falls, and recordable injuries. It did not measure whether the organization could identify and control the process hazards capable of producing a catastrophic event.

On March 23, 2005, an explosion at the refinery killed 15 people and injured 180. 

The lesson is not that injury rates are unimportant. The lesson is that they are incomplete.

Texas City had safety programs. It had professional leaders. It had improving injury statistics. What it lacked was sufficient organizational capacity to identify and mitigate conditions that could lead to a catastrophic event.

Its safety record described the past. It did not reveal the risk already present in the plant. NASA Mistook Prior Success for Proof of Safety


NASA provides two more examples.


NASA and its contractors knew before the Challenger launch that O-ring erosion and blow-by had occurred during earlier shuttle flights. Those conditions were not expected by the original design and were not fully understood.


But the earlier missions had succeeded.


Instead of treating the O-ring damage as evidence that a critical system required correction, the organization gradually accepted it as an allowable flight condition. 


Challenger was lost on January 28, 1986, killing all seven crew members.


Seventeen years later, NASA repeated a similar pattern with Columbia.


Foam had separated from shuttle external tanks during previous missions without causing the loss of a spacecraft. NASA gradually came to treat foam strikes as an accepted maintenance issue rather than a threat to the shuttle and its crew.


During Columbia's launch, a piece of foam struck the leading edge of the left wing. NASA later reported that managers had been reassured because foam strikes had occurred on previous missions without causing a catastrophe. 


Columbia broke apart during reentry on February 1, 2003, killing all seven crew members.


The Columbia Accident Investigation Board found that NASA's management practices were as much a cause of the accident as the foam that struck the wing. The board identified communication failures, schedule pressure, weakened safety oversight, and an organizational culture that did not consistently identify, analyze, and control hazards.


NASA did not lack intelligent people. It did not lack technical expertise. It did not lack information.


It lacked sufficient organizational capacity to convert warning signs into effective action.


The successful flights before Challenger and Columbia were not evidence that the known conditions were safe. They were opportunities to discover and mitigate risk before the consequences became irreversible.


The Same Conditions Exist Inside Great Companies

Texas City, Challenger, and Columbia were highly visible catastrophes. It is easy to study them afterward and believe the warning signs should have been obvious.

They rarely are.

Hidden risks often exist within sophisticated, well-run organizations. The systems continue operating. Production continues. Employees follow the procedures they have been given. No incident forces anyone to question whether the underlying assumptions are correct.

We saw this while working with a well-known consumer brand that sets a global standard for electrical safety.

The facility had dedicated safety personnel, an established compliance program, an arc flash study, and labels on its electrical equipment. From the outside, it appeared that the hazard had been evaluated and the employees were properly protected.

When we inspected the switchgear, we found that the main breaker's protective relay had been installed but never been programmed.  This is the image.



The labels throughout the facility indicated incident energy of approximately five calories per square centimeter, an amount easily protected by light PPE. Because the assumed relay settings were not programmed, the actual exposure exceeded 100 calories per square centimeter. That's approximately like being hit by a military flamethrower at point-blank range.


Employees were making life-critical decisions based on those labels. They believed their protective equipment was appropriate for the hazard. They believed the protective device would operate as assumed.


None of that was true.


The company had completed the visible elements of an electrical safety program. It had a study, labels, procedures, and safety personnel. What it lacked was the organizational capacity to verify that the study, protective-device settings, labels, and actual field conditions agreed.


The unprogrammed relay was the technical problem. The larger problem was that the organization had incorrectly installed a new breaker and did not know it. 


Nothing had happened, so the system appeared to be working.


The absence of an incident was not evidence that the risk was controlled. It was the reason the risk remained hidden.


Capacity Requires More Than Activity


Many companies perform electrical safety activities.


They conduct infrared inspections. They complete arc flash studies. They install labels. They hire contractors. They train employees. They test some equipment and correct some deficiencies.


Those activities are important, but activity alone is not organizational capacity.


Capacity is the ability to connect those activities into a system that consistently finds risk and produces action.


A capable organization can do five things.


See the risk: It can determine the actual condition of its electrical infrastructure through inspection, testing, accurate documentation, field verification, and qualified expertise.


Understand the risk: It can distinguish a routine maintenance issue from a condition that could seriously injure an employee, destroy equipment, or interrupt operations.


Act on the risk: It assigns responsibility, establishes priorities, provides resources, and follows findings through correction.


Verify the response: It confirms that the corrective action solved the problem and that studies, settings, labels, procedures, and field conditions now agree.


Learn from the finding: It asks where else the same condition may exist and changes the system that allowed the risk to remain hidden.


An IR inspection report sitting in a file does not create safety.


An arc flash label based on incorrect assumptions does not create safety.


An arc flash recommendation that is never acted upon does not create safety.


Safety comes from the organization's capacity to turn information into action.


Our Job Is in Our Name


At Guidant Power, we believe our job is in our name. Our team is here to be a trusted guide on your electrical journey.


We help companies identify hidden conditions, understand their significance, establish practical priorities, and follow risks through correction. Our engineering, inspection, maintenance, and training services support that larger purpose.


We know that safety is not defined by what has not happened but is demonstrated by your capacity to find risk and act before it does. 


So when you work with us, the objective is not simply to complete more safety activities. The goal is to strengthen your organization's capacity to identify and mitigate electrical risks before they harm your people, reduce productivity, and damage your brand.

 


bottom of page