Human Performance & Work Design
Designing work so people can do it correctly: task and procedure design, interfaces, workload, fatigue, recognition of error-likely situations, defences in depth, and learning from what nearly happened. Human error is an outcome, not a cause. Treating it as a cause ends the investigation exactly where the useful information starts — in the conditions that made the error likely and will make it likely again for the next person.
What an explainer is not
A topic explainer is SPEQ’s synthesis of what a practice involves, cited to the standards that govern it. It does not reproduce their text, and it does not determine which of them apply to your product or process.
[ POSITION IN THE FRAMEWORK ]
7 DIMENSIONS · 21 LINKSHuman error is a symptom with a design cause: the same mistake recurring across different people is evidence about the work, not about them, and retraining the individual guarantees the next one.
06 · QUALITY MATURITY — HUMAN PERFORMANCE & WORK DESIGN, REACTIVE TO ADAPTIVE
Human error is a root cause. The investigation ends at the person and the action is retraining.
Investigations look for contributing factors and note workload or unclear procedures, without those observations changing anything.
Error-provoking conditions are identified as findings in their own right, and the corrective action changes the work rather than the worker.
Recurring error patterns are analysed across investigations, so the design problem visible only in aggregate is found.
Work is designed so the correct action is the easy one — layout, sequence, interlocks, forcing functions — and procedures carry only what design cannot.
SPEQ’s shared five-stage progression, labelled synthesis — not the FDA QMM rating scale. Where does your organization sit? Score your quality system →
07 · REGULATORY & EVIDENCE
GOVERNING STANDARDS · 4
Derived from the 4 standards SPEQ maps to this subject, across 3 regulatory bodies: FDA, ICH, IEC.
RECORDS & OBJECTIVE EVIDENCE
- Investigations that identify error-provoking conditions rather than stopping at the individual
- Corrective actions that changed equipment, layout, sequence or interface
- Cross-investigation analysis of recurring error types
- Task or workload assessments where these were contributing factors
- Evidence that procedures were simplified rather than extended after an error
COMMON INSPECTION FINDINGS
- Human error recorded as a root cause with no examination of what made it likely
- The same error recurring across different individuals with the same corrective action each time
- Procedures lengthened after every incident until they cannot be followed as written
- Workload or shift factors noted in investigations and never acted on
- Design changes rejected as too expensive with the recurring error accepted instead
Error-likely situations are predictable
Errors are not randomly distributed. They cluster around identifiable conditions: time pressure, interruption, similar-looking materials or screens, unfamiliar tasks, first or last operation of a shift, concurrent activities, and steps requiring the operator to remember something rather than read it. These conditions can be identified in advance by walking a task and looking for them.
That makes error reduction a design activity with a specific target. Removing an interruption, differentiating two similar labels, replacing a remembered step with a prompted one — each addresses a condition rather than exhorting a person. And unlike training, the improvement persists when the individual changes.
Defences in depth, and the ones that are not real
Regulated processes are built with layered defences, and layers vary enormously in strength. Design that makes the error impossible is strongest; a physical or system barrier is next; independent verification is weaker; a procedural step is weaker still; and a warning or a reminder is the weakest of all. Investigations that add a procedural step as a corrective action have added the second-weakest available defence.
Independent verification deserves particular scrutiny because it is trusted more than it earns. Second-person checks decay quickly toward confirmation, especially where the checker is under the same time pressure and expects to find nothing. A check that has never found anything in two years is not evidence of a good process — it is evidence that nobody is looking.
Procedures written for the work as it is
A procedure describing an idealised version of the task creates a permanent gap between what is written and what is done. People bridge it, the bridging becomes standard practice, and it is undocumented — which surfaces as a finding when an inspector watches the task performed and compares it to the procedure.
Closing that gap requires writing procedures with the people who perform the work and observing the task as actually done. Where the documented and actual methods differ, the useful question is which one is right: sometimes the practice is a workaround to be corrected, and often it is an adaptation to a real constraint the procedure did not anticipate. Both answers are useful; assuming the first is how the gap persists.
SPEQ interpretation — near misses are free information nobody collects
A near miss is an error that was caught before it had a consequence. It carries most of the diagnostic value of an actual event and none of the cost, and almost no regulated organisation collects them systematically — because the deviation system is triggered by consequence, and a near miss has none.
Collecting them requires a route that is not the deviation system and a culture in which raising one is safe, which is the same Just Culture condition that determines whether anything else gets reported. Organisations that manage it get a stream of information about where their defences are being tested, months before one of those tests succeeds.
FREQUENTLY ASKED
Why is "human error" not a root cause?
Because it names the outcome rather than the condition that produced it. The useful information is in what made the error likely — time pressure, interruption, similar-looking materials, a remembered rather than prompted step — and those conditions will produce the same error for the next person unless they are addressed.
Which defences are strongest?
In order: design that makes the error impossible, a physical or system barrier, independent verification, a procedural step, and a warning. Investigations that add a procedural step have chosen the second-weakest option available, which is why the same deviation often recurs after a corrective action that looked reasonable.
How reliable is second-person verification?
Less than it is trusted to be. Checks decay toward confirmation, particularly where the checker is under the same time pressure and expects to find nothing. A verification step that has never found anything in two years is evidence that nobody is looking, not that the process is sound.
What should you do when practice differs from the procedure?
Ask which one is right. Sometimes the practice is a workaround to correct; often it is an adaptation to a real constraint the procedure never anticipated. Assuming the first without looking is how the gap between written and actual method persists until an inspector observes the task.