• Our new ticketing site is now live! Using either this or the original site (both powered by TrainSplit) helps support the running of the forum with every ticket purchase! Find out more and ask any questions/give us feedback in this thread!

Question - what is the "swiss cheesiest" accident report?

Lockwood

Established Member
Joined
4 Apr 2013
Messages
1,249
I'm looking to lead a session on human factors in a non-rail setting. I have a few domain-relevant scenarios in mind.

Some of the training I got a few years ago followed an incident from some air accident that had terrible Customer Relationship Management (CRM).

I don't remember much of it - CRM was the module of the training day I was looking forward to the most, but it was late in the day and on a long Teams session because they cancelled face to face training due to lockdown.

I was thinking of using a similar idea, taking a long incident from a different domain to discuss (to avoid focusing on the "I would never have made that mistake" trap).
I've seen several incident reports that have some good examples of the Swiss cheese model.

Are there any reports that people could suggest for this? I'm looking for something where lots of things lined up "perfectly", and is not a load of extreme technical nuance that outsiders would not understand. And ideally non fatal.


Very odd request, I know.
 
Last edited by a moderator:
Sponsor Post - registered members do not see these adverts; click here to register, or click here to log in
R

RailUK Forums

Horizon22

Established Member
Associate Staff
Jobs & Careers
Joined
8 Sep 2019
Messages
11,035
Location
London
Most fatal incident investigations have an element of the "swiss cheese model" in them whereby multiple things have aligned (or gone wrong) in such a way which would not individually have led to disaster and loss of life but in turn each of them combined led to a fatal incident.

I know you are not looking for fatal incidents, but there will be quite a few RAIB reports which didn't lead to fatalities but certainly lots of things went wrong. Lewisham train strandings during Beast from the East perhaps in 2018? All the routes were locked in such a way that blocked up a huge chunk of South East London. The issue being missed originally by controllers, the train struggling to take power, a failure to declare it as failed, the lack of the route being de-iced - exactly because there was an emergency timetable - a sudden change in the weather to freezing rain, a gradual loss of power, on board trains with no toilets, communication failures etc.
 

Purple Train

Established Member
Joined
16 Jul 2022
Messages
2,487
Location
Exile or exile
The recent near miss at Bookham Tunnel springs to mind as one that was less serious but had an extraordinary stack of Swiss cheese slices. The report can be found here and as per custom here is the summary:
At around 11:42 on 29 April 2025, a passenger train was involved in a near miss with a team of three track workers walking through Bookham Tunnel, on the approach to Bookham station in Surrey. The train was travelling at 33 mph (53 km/h) as it passed the team. The track workers either moved to refuges inside the tunnel or stood against the tunnel wall as the train passed them. RAIB’s investigation found that the track workers were walking in a different location to that which had been blocked to trains and that neither the track workers, nor the signaller who had granted the line blockage, had realised this. This happened because the safe work pack, which formally detailed the safety arrangements for the task, incorrectly contained line blockage arrangements for the nearby Mickleham Tunnel, and not the tunnel around which the team was working. The error in the safe work pack had been introduced during the planning stage for the work and went unnoticed, despite the pack being checked multiple times during various stages of the safe work process.
I'm not sure if that one's too technical.

One that definitely isn't too technical but may not be a thick enough stack for you is the portable ramp incident at Norwood Junction. The report can be found here and here is the summary:
At around 09:52 on Tuesday 1 July 2025, a London Overground passenger train departed from Norwood Junction station with a portable access ramp attached. The ramp collided with the end-of-platform barrier and fell beside the track. No injuries were caused, although a member of station staff and a passenger needed to take action to avoid the ramp as it travelled down the platform. The portable access ramp was damaged beyond repair, and minor damage was caused to the train as a result of the accident. RAIB’s investigation found that a portable access ramp being attached at a doorway did not prevent the train’s doors from closing or from traction power being taken, because the ramp was of the incorrect type. Platform staff were unaware that the ramp they were using was of the incorrect type for the train involved. The correct ramp had not been available since September 2021 and none of the station checks in the period up to the accident had identified this. The train driver departed from Norwood Junction station with the ramp still attached as they believed it was safe to dispatch the train. The driver’s safety checks during dispatch were ineffective. Although some other factors may have been present, this was probably because the driver was distracted as they were making a mobile phone call at the time the train departed.

I suppose both of these go to show how far modern safety practices have come. These were two relatively benign incidents (although no doubt shocking and stressful for those involved) with a lot of varied factors. Talerddig was very similar, although sadly more serious. I think the railway has come so far in terms of safety that naturally we expect there to be a lot of Swiss cheese involved. In the wake of the Elstow crash, I think that came to the fore somewhat: we aren't used to "simple" accidents happening on the railway.

I will have a look through the RAIB archives and see if there are any more impressive stacks of Swiss cheese, but these are the two recent incidents which came to mind first. The Lewisham train strandings are a good example as well.
------------
EDIT:

I've just remembered an early RAIB report that may fit your criteria, although again it might be too technical. This was an incident where the door of a Class 222 came open just north of Kettering and the train ran for five minutes with the door open, due to two separate faults with the door system, one of which was the fact that a 2mm piece of dirt had been incorporated into the lock on manufacture. The train wasn't stopped immediately because the Train Management System software confused the driver into thinking that there was a fault with the passcom.

The report can be found here, and I have attached below the RAIB summary. Their diagram of the "Swiss cheese" factors can be found on page 42 of the report.
At 11:34 hrs on Saturday 10 June 2006, a passenger on train 1D17, the 10:30 hrs London St Pancras to Sheffield service, reported to on-board staff that an exterior door was open, in the first class portion, while the train was moving. The train was formed of a class 222 Meridian unit, number 222 009. The door opened just north of Kettering. The train was finally brought to a stand at Desborough summit, 5 miles 79 chains north of Kettering station, Figure 1. As intended by the design, when the door opened, the train’s brake applied automatically. However, the driver initially overrode this as, to him, the indications in the cab were ambiguous and he was uncertain what had happened. When the driver realised that the train was ‘in danger’, he made a controlled brake application to stop at the next signal. The train travelled for about five minutes with the door open before the driver braked the train to a stand.

Apologies for the long and wordy post, but I love an excuse to have a good trawl through minor RAIB reports and this is an excellent one!
 
Last edited:

Beebman

Member
Joined
17 Feb 2011
Messages
970
Location
Twyford
The Bexley derailment of 1997 has to be a candidate when wagons carrying spoil from railway track renewal work came off a viaduct injuring 4 people on the ground. A BBC News report from the time is still online: http://news.bbc.co.uk/1/hi/uk/294114.stm

It lists the various different causes from the HSE report as follows:

The report found:
  • South East Infrastructure Maintenance Company had identified the bridge timbers as needing urgent repair, but had not arranged for repairs to be made

  • Railtrack knew about the unsafe condition of the track, but took no action to remedy it

  • Southern Track Renewals Company Ltd failed to make adequate arrangements to ensure wagons were not overloaded

  • The training of the driver of the train was inadequate and no reassessment of his training had been made by train company Connex South Central

  • The arrangements for inspection, maintenance and calibration of the locomotive speedometers were inadequate
 

Iskra

Established Member
Joined
11 Jun 2014
Messages
10,741
Location
West Riding
I'm looking to lead a session on human factors in a non-rail setting. I have a few domain-relevant scenarios in mind.

Some of the training I got a few years ago followed an incident from some air accident that had terrible CRM. I don't remember much of it - CRM was the module of the training day I was looking forward to the most, but it was late in the day and on a long Teams session because they cancelled face to face training due to lockdown.

I was thinking of using a similar idea, taking a long incident from a different domain to discuss (to avoid focusing on the "I would never have made that mistake" trap).
I've seen several incident reports that have some good examples of the Swiss cheese model.

Are there any reports that people could suggest for this? I'm looking for something where lots of things lined up "perfectly", and is not a load of extreme technical nuance that outsiders would not understand. And ideally non fatal.


Very odd request, I know.
I’m assuming the air accident was the Tenerife one, I’ve covered that in a similar setting.
 

SuspectUsual

Established Member
Joined
11 Jul 2018
Messages
6,850
I’m assuming the air accident was the Tenerife one, I’ve covered that in a similar setting.

The windscreen bolts one with the flight from Birmingham (can't remember the aircraft type) is a good example as well, I've been on courses that used it
 

Lockwood

Established Member
Joined
4 Apr 2013
Messages
1,249
Thanks for the pointers, I will have a look at those. Bookham might be a good one to use, as I will be delivering the session in Surrey


I’m assuming the air accident was the Tenerife one, I’ve covered that in a similar setting.

I honestly can't remember which air accident it was, I think it was a Middle Eastern airline with the "I am captain, I know best, you do what I tell you". I think there were a couple of incidents maybe from there as one of the other people on the call wouldn't stop going on about how they wouldn't fly with that airline then (totally missing the point).


Since my original post has been flagged as not being very clear, what I am intending on doing is a session to a medical audience about human factors. I want a scenario that is different from a medication error or an unsafe discharge - those are good, but can descend into "I would never do that.". Having a scenario that is able to demonstrate a perfect storm of external factors in a world that is alien to the room can help focus on the concept rather than the detail.
 

Swedenorer

Member
Joined
28 Sep 2025
Messages
342
Location
Hants
If you want one about human factors the number of swiss-cheesed human errors - from initial planning to disaster - at Abermule in 1921 which combined to defeat a safety system expressly designed to prevent the kind of accident that occurred is quite striking. Everyone here made some kind of simple error.

This might be particularly interesting for your purpose as a similar chain of events was pretty well repeated at Romney Sands in 2019

It's always struck me that when you boil all these things down they usually amount to not doing simple things correctly.
 
Last edited:

D1537

Established Member
Joined
11 Jul 2019
Messages
2,100
Location
North Yorkshire
A fairly recent one with no injuries but a quite incredible sequence of events leading up to it was the Bletchley ECS derailment:
I came here to mention this one. A ridiculous amount of lined-up holes in that particular cheese. And of course only a minor accident with no injuries so a good one to use.
 

Tetchytyke

Veteran Member
Joined
12 Sep 2013
Messages
17,657
Location
Isle of Man
For non-fatal, the recent AAIB report into the Ryanair plane with low fuel might work. Plenty of Swiss chase factors: bad weather, more bad weather, poor communication.
 

Purple Train

Established Member
Joined
16 Jul 2022
Messages
2,487
Location
Exile or exile
What does CRM mean, please?
Crew Resource Management - essentially the aviation principle that all the cockpit crew contribute equally to the safe running of the aircraft and that there is no distinction of rank that might result in a situation where the captain does something unsafe but the first officer goes "they're the captain, I can't contradict them". (Not an aviation expert but that's my understanding, please correct me if I'm wrong.)
 

norbitonflyer

Established Member
Joined
24 Mar 2020
Messages
5,842
Location
SW London
There's this one , Glasgow Queen Street, early hours of Christmas Eve 1977. Runaway locomotive. Reports of faulty brakes failed to be passed on between the dozen or so drivers who had operated it in the previous 36 hours, along with maintenance staff, as the defect book was missing and the fault was only apparent when the loco was running light.


It had run a partially fitted freight from perth to Gragemounth and back, where the fault first became apparent, but because of a lack of other vailable locomotives it then rtook a passenger train to Edinburgh, and another to Inverness. It then ran light from Inverness to Dalwhinnie to take over a failed train, during whuich the fauklt mainfested itself again, before taking that train on to Mossend, light again from Mossend to Motherwell and back to Mossend, where it took over the Fort William portion of the sleeper to the top of Eastfield loop, where another locomotive was attached at the other end to take the train down Cowlairs bank into Queen Street. Running light again, it followed the train down the bank into Queen Street where it hit the train at over 40mph. The train crew and four passengers in the train required hospital treatement - the small number of serious injuries probably thanks to the fact that most of the passengers in the vehicle that took the full force of the collision would have been in bed. (and as a 1st class sleeper no-one could even fall very far)


paragraph 89 lists the errors made, some of them more than once
 
Last edited:

Bill57p9

Member
Joined
1 Dec 2019
Messages
907
Location
Ayrshire
I deliver a lecture to engineering students based on the 2002 Uberlingen mid air collision as one with a massive portion of Swiss Cheese human factors.
It doesn't meet your preference for non-fatal though.

Feel free to message me directly if you would like to set a call and I will happily share what I have.
 

62484GlenLyon

Member
Joined
30 May 2021
Messages
301
Location
Royston
Purple Train - Thank you for the CRM definition. I have heard the aviation version about questioning the captain expressed in very colourful terms that are not suitable for this forum!
 

waverley47

Member
Joined
17 Apr 2015
Messages
866
Honestly, it's a bit parochial, but the August 2019 power outages that triggered a meltdown of Thameslink. Simultaneous lightning strikes in the north see 200 miles apart, a 33 second frequency drop down to 49Hz, a catastrophic hardware and software issue, the trains trying to restart themselves three times and then bricking themselves until a Siemens engineer could come and get them.

Fourteen thousand minutes of delays in an afternoon from two lightning strikes, even though the grid fixed itself within 33 seconds, was genuinely incredible to watch.
 

100andthirty

Member
Joined
5 Mar 2012
Messages
606
Location
Milton Keynes
Another aspect of the August 2019 incident was that Siemens had intoroduced a modification that led to the train sutdown and technicial re-boot. Without the modification, the trains would have re-started when the power supply restarted.

This leads to another issue when developing a Swiss Cheese model. My comment above is based on main event, so to speak, was the a service inteeruption on GTR where the power supply was the cause, but the consequences were much more severe bcause of the software modification
 

King Lazy

Member
Joined
24 Apr 2019
Messages
159
I get that you’re on a rail forum so probably looking for rail reports but….

I spend a lot of time looking at incident reports from various industries. One I find interesting is the Windscale fire.

IMO this has every hallmark of the more famous Chernobyl disaster. I believe a big lesson from Windscale is that (despite being from 1957) it highlights that we can make the same mistakes as what we may perceive as inferior political and safety regimes. We often like to describe our industries as World Class but IMO Chernobyl was a carbon copy of Windscale.

Windscale had political pressure from
the highest levels, possibly even including selling the entire project to the public as something other than what the powers that be actually wanted (working towards clean cheap energy rather than a H-Bomb to stay at the top table with our American allies).

Pressures at design stage and arguments over exactly what safety measures should be in place (Cockcroft’s folly filters).

The technology wasn’t fully understood by anyone at the time, particularly the behaviour of the graphite. Attempts to solve problems caused by this knowledge gap led to more extreme attempts at mitigation being required on each occasion (Wigner releases) and ultimately led to the fire which was deemed so unlikely it hadn’t been planned for.

Safety measures were reduced in response to political pressure (cooling fins on fuel rods were cut because the government wanted plutonium produced faster to stay in the nuclear arms race).

Assumptions were made regarding instrument readings (Thermocouple temperatures were dismissed as being due to faulty instrumentation).

The fire therefore wasn’t noticed for some time.

Once diagnosed the fire itself seemed unplanned for and firefighting relied on spontaneous ideas rather than set procedures as no procedures actually existed for what was regarded as almost an impossible happening.

Eventually one of the ideas worked. If it hadn’t the operators would likely have been left without any plan.

As said I think it is very similar to Chernobyl. I suspect using a very famous example like Chernobyl would lose audience interest as everyone has preconceived ideas of what they think they know happened at that one especially after the TV show.

Using Windscale and Chernobyl alongside could engage the audience once they see the parallels and realise that our democratic institutions and technological excellence led to almost exactly the same set of failures as the communist Soviets.

This sort of pressure can be enacted at local or company levels leading to incidents.

(I typed this from memory of the reports. So apologies if I’ve misremembered some of the facts).

Even The Wikipedia page for the Windscale fire is very comprehensive and a great read.
 
Last edited:

norbitonflyer

Established Member
Joined
24 Mar 2020
Messages
5,842
Location
SW London
Would Apollo 13 count?

The investigation concluded that the chain of events went something like this (of course there was little physical evidence as the Service Module had been badly damaged by the explosiomn, and then burnt up in the Earth's atmosphere on re-entry, so it had to be pieced together from records of what had happened during the prepartations for launch, and tests of similar components to those in the ill fated module)
So, it went somethimng like this
- Starting with a dropped liquid oxygen tank, damaging a drain valve
- so after a test the contents could't be drained off, and had to be boiled off instead
- the heaters were fed with the wrong voltage - they were only supposed to be used in flight, using the on board 28volt supply, but the shore supply was 65 volts,
- the high voltage caused the thermostat controlling the heater to fail
- temperature sensors that couldn't register the extreme temperatures being reached. The gauge only went up to 29C, a little above the temperatre the thermostats were set to. - Beacuse of the failure of the thermostat, the heaters kept running and tenperatures reached an estimated 540C
- This damaged the insulation, exposing the wiring.

After which it was inevitable that the first time the stirring system was energised, a spark from the exposed wires would cause the remaining insulation to react explosievly with the oxygen in the tank.
 

Lockwood

Established Member
Joined
4 Apr 2013
Messages
1,249
Ooooo, some more good ideas. Windscale might be interesting, especially as a progressive disclosure story.

Nuclear plant, famous incident, attempts to silence what is going on, then a rug pull that we are talking about the UK.

I wanted non fatal because I didn't want to open up the can of worms of discussing some of the biggest tragedies in the group, and wanted to avoid any questions from the group about one of the jobs I had many years ago. I'll speak to some of them about it - not all of them.



This has certainly given me a lot of stuff to think about, some might be too technical, but I should be able to use something


And there has been a lot of push from the aviation community into healthcare. There was an incident many years ago where a surgeon left something inside a patient. Patient's husband was a pilot, and ends up asking "we have checklists. Why don't you?". Surgery now has checklists. Critical care transfers have pre-launch and midway checklists.


Thanks again
 

Top