Thirty-three people died because the people who saw the danger could not get the person with the authority to listen.

On the morning of 1 October 2015, the SS El Faro, a 790-foot cargo ship carrying 391 containers and 294 trailers, sailed from Jacksonville, Florida, bound for San Juan, Puerto Rico. Hurricane Joaquin was developing in the Atlantic, and the ship’s route would take it close to the storm’s projected path. The captain, Michael Davidson, an experienced mariner with decades of service, assessed the available weather data and decided to proceed on a course that he believed would take the ship safely past the hurricane.

He was wrong.

In the early hours of 1 October, El Faro sailed into the teeth of a rapidly intensifying Category 4 hurricane. By approximately 7:39 a.m. on the morning of 1 October, the ship had lost propulsion, taken on a severe list, and was foundering.

All 33 crew members, five officers and 28 other crew, were killed.

The El Faro sinking was the worst American maritime disaster in over three decades. But what makes it relevant far beyond the shipping industry, and what makes it genuinely important for anyone who thinks about how organisations function under pressure, is what the voyage data recorder revealed about the dynamics on the bridge in the hours before the ship went down. Because it turned out that the people who could see the danger coming were not silent.

They spoke.

They raised concerns.

They offered alternative courses.

But it was not enough. The hierarchy held. The captain’s authority was not effectively challenged. And 33 people died.

This is an article about that failure, and about the pattern it shares with some of the most studied disasters in modern history. It is also, inevitably, an article about psychological safety, about authority gradients, about the normalisation of deviance, and about what it actually costs when organisations fail to create conditions in which critical information can travel upwards.

We want to be clear from the outset: we are writing about real people who lost their lives, and about decisions made under extreme pressure by professionals doing difficult work. The purpose is not to assign blame from the comfort of a desk. It is to understand the systemic conditions that made these outcomes more likely, and to ask what organisations in every sector can learn from them. This is a story we often tell in workshops, and we think it’s an important one.

What the Voyage Data Recorder Revealed

The El Faro’s voyage data recorder (VDR) was recovered from the ocean floor in August 2016, at a depth of approximately 15,000 feet. If you search online, you can find the transcripts of these recordings.

The National Transportation Safety Board’s subsequent investigation, published in 2017, drew extensively on the 26 hours of audio it contained. The recordings are, by any measure, harrowing. They capture a crew watching a hurricane bear down on them, growing increasingly alarmed, and attempting to communicate their concerns to a captain who remained committed to his chosen course.

The NTSB report documented multiple instances in which officers on the bridge expressed concern about the ship’s route. The second mate and third mate both raised the intensifying hurricane and suggested course alterations that would have taken the ship further from the storm’s path. The chief mate expressed reservations about the weather routing. These were not vague murmurs of discomfort. They were professional assessments, offered by qualified officers, based on the weather information available to them. And in each case, Captain Davidson either dismissed the concerns, reframed the situation as less dangerous than his officers believed, or asserted his own assessment of the weather with a confidence that effectively closed the conversation.

What the VDR recordings reveal is not a crew that was silent. It is a crew that spoke up and was not heard, or, more precisely, a crew that spoke up in ways that were insufficient to overcome the authority gradient between them and their captain. The officers used indirect language. They hinted. They raised concerns and then deferred when those concerns were dismissed. They did not, at any point that the recordings capture, directly state that they believed the captain’s decision was dangerous and that the ship should change course. Whether this was because they lacked the confidence, because the organisational culture did not support such direct challenge, because maritime hierarchy made it unthinkable, or because of some combination of all three, the effect was the same. Critical safety information did not travel from the people who had it to the person who needed to act on it.

The NTSB concluded that the captain’s decision to continue on his planned route was the probable cause of the sinking, and noted that the organisational culture at TOTE Maritime, the ship’s operator, did not adequately support crew members in challenging captain’s decisions. This finding, buried in the technical language of an accident investigation report, is one of the most consequential observations in the entire document. It locates the failure not merely in one individual’s decision-making but in the system that made it so difficult for anyone to effectively challenge that decision.

The Authority Gradient Problem

The concept of authority gradient describes the actual and perceived difference in authority between members of a hierarchical team. A steep authority gradient means there is a large gap between the leader’s authority and the rest of the team’s; a shallow one means the gap is smaller and more easily bridged. The steeper the gradient, the harder it is for information, concerns, and dissent to travel upwards. This is similar to “power distance”.

Authority gradients exist in every hierarchical organisation, and they are not inherently problematic. Hierarchies exist for good reasons: someone needs to make decisions, coordinate action, and be accountable. The problem arises when the gradient becomes so steep that it functions as a one-way valve, allowing information and instructions to flow downwards but blocking critical information from flowing upwards. When that happens, the person at the top of the hierarchy is making decisions with incomplete information, and the people below who possess the missing information are unable or unwilling to supply it.

On the El Faro, the authority gradient was steep. Merchant shipping has a long and deeply embedded tradition of captain’s authority, the legal and cultural principle that the master of the vessel has ultimate responsibility and ultimate decision-making power. This principle exists for good operational reasons: in a crisis at sea, someone must be able to make decisions quickly and without committee deliberation. But the same principle that enables decisive action in an emergency can, when combined with a culture that discourages challenge, prevent the very information that would avert the emergency from reaching the decision-maker.

The El Faro’s officers did not storm onto the bridge and demand a course change. They raised concerns obliquely. Their language in the transcripts stands out for its hesitancy.  They offered information and then waited for the captain to act on it. When he did not, they subsided. This is a pattern that will be instantly recognisable to anyone who has worked in a hierarchical organisation. The subordinate who raises a concern, is brushed off, and concludes that they have “done their bit” by raising it. The team member who flags a risk and then, when the leader dismisses it, assumes the leader must know something they do not. The junior professional who defers to seniority not because they agree but because the social cost of sustained disagreement feels too high. In a meeting room, this pattern costs organisations good ideas and honest feedback. On a ship sailing into a hurricane, it costs lives.

Tenerife: When a Legend’s Authority Becomes Unquestionable

The El Faro disaster finds its most direct parallel in the Tenerife airport disaster of 27 March 1977, which remains the deadliest accident in aviation history. On that day, two Boeing 747s, one operated by KLM and the other by Pan Am, collided on the runway at Los Rodeos Airport in Tenerife, Canary Islands, killing 583 people.

The circumstances were complex, involving fog, congested airport conditions, and communication failures with the control tower. But at the heart of the disaster was a decision by the KLM captain, Jacob Veldhuyzen van Zanten, to begin his takeoff roll without having received explicit clearance from air traffic control. Van Zanten was not merely any captain. He was KLM’s chief flying instructor, one of the airline’s most senior and respected pilots, the face of KLM’s safety programme. His authority, both formal and reputational, was enormous.

The KLM flight engineer, sensing that something was wrong, questioned whether the Pan Am aircraft had cleared the runway. The co-pilot had attempted to confirm clearance. But van Zanten, apparently convinced that clearance had been given or was imminent, advanced the throttles and began the takeoff. The flight engineer’s concern, expressed once and then not pursued when van Zanten responded with certainty, was the last opportunity to prevent the disaster. It was not enough to overcome the authority gradient.

The investigation into Tenerife was a watershed moment for aviation safety. It forced the industry to confront a deeply uncomfortable truth: that the veneration of captain’s authority, far from being a safety asset, could become a safety hazard when it prevented other crew members from effectively challenging a captain’s errors. The result was the development of Crew Resource Management (CRM), a training approach that would fundamentally transform how aviation thinks about hierarchy, communication, and team dynamics in the cockpit.

The Shuttle Disasters: When Engineers Cannot Reach Decision-Makers

If the El Faro and Tenerife illustrate the authority gradient within small teams, the Space Shuttle disasters of 1986 and 2003 illustrate how the same dynamics operate at the organisational level, with additional layers of bureaucratic complexity, political pressure, and what sociologist Diane Vaughan called the normalisation of deviance.

On 28 January 1986, the Space Shuttle Challenger broke apart 73 seconds after launch, killing all seven crew members. The immediate cause was the failure of an O-ring seal in one of the solid rocket boosters, a failure caused by the cold temperatures at launch. What the subsequent Rogers Commission investigation revealed was that engineers at Morton Thiokol, the contractor that manufactured the boosters, had explicitly warned that the O-rings might not seal properly at the low temperatures forecast for launch day. They recommended against launching.

What happened next is one of the most studied sequences in the history of organisational failure. NASA managers pushed back on the engineers’ recommendation, questioning their data and their conclusions. Morton Thiokol’s own management, under pressure from their client, overruled their engineers and reversed the no-launch recommendation. The engineers who had raised the concern were not in the room for the final decision. Their professional judgement, based on data and engineering analysis, was overridden by managers whose considerations included schedule pressure, political expectations, and the organisational desire not to be the ones who called off a launch.

Vaughan’s landmark study of the Challenger disaster, published as The Challenger Launch Decision in 1996, introduced the concept of normalisation of deviance to describe what had happened. The O-ring erosion was not a new problem. It had been observed on previous flights. Each time it occurred without catastrophic consequences, it was gradually reclassified from an anomaly requiring investigation to an accepted risk within the system’s normal operating parameters. The boundary of acceptable risk shifted incrementally, each small deviation justified by the fact that the previous deviation had not resulted in disaster. By the time of the Challenger launch, the O-ring issue had been normalised to the point where it was no longer treated as the urgent safety concern the engineers knew it to be.

Seventeen years later, the pattern repeated with devastating precision. On 1 February 2003, the Space Shuttle Columbia disintegrated during re-entry, killing all seven crew members. The cause was damage to the thermal protection system on the shuttle’s wing, caused by a piece of insulating foam that had struck it during launch. Engineers at NASA had observed the foam strike and had requested satellite imagery to assess the extent of the damage. Their requests were not acted upon. The damage was assessed, without adequate imaging, as unlikely to pose a safety threat. The shuttle was cleared for re-entry. The engineers were right. The managers were wrong. Seven people died.

The Columbia Accident Investigation Board’s report drew explicit parallels with the Challenger disaster, noting that NASA had failed to learn the organisational lessons of the earlier catastrophe. The Board found that the same cultural dynamics that had contributed to the Challenger disaster, hierarchy that suppressed dissent, schedule pressure that overrode safety concerns, and a management structure that insulated decision-makers from the engineers who had the most relevant technical knowledge, were present and operating in 2003. The foam strikes, like the O-ring erosion before them, had been normalised. They had occurred on previous flights without catastrophic consequences, and each occurrence made the next one seem less alarming.

The Common Patterns: What These Disasters Share

These four disasters, spanning different industries, different decades, and different continents, share a set of structural and psychological features that are worth naming explicitly. They are not identical cases, and the differences matter. But the common threads are striking, and they point towards failures that are systemic rather than individual.

Steep authority gradients that blocked upward information flow. In each case, people with critical safety information were unable to get that information to the person or people with the authority to act on it. On the El Faro, officers could not overcome the captain’s certainty. At Tenerife, a flight engineer could not override one of his airline’s most senior captains. At NASA, engineers could not penetrate the layers of management that separated them from the launch decision. The hierarchy was not merely a formal structure; it was a psychological barrier that determined what could be said, to whom, and with what force.

Normalisation of deviance. In the shuttle cases particularly, and to some degree on the El Faro (where TOTE Maritime’s practice of routing ships close to tropical weather systems had become routine), past success had recalibrated the perception of risk. Because previous deviations from safety standards had not resulted in disaster, the deviations were gradually accepted as normal. Vaughan’s concept captures something profound about how organisations drift towards catastrophe: not through a single dramatic failure but through an accumulation of small, individually rational decisions to accept slightly more risk than before.

Groupthink and the suppression of dissent. Irving Janis’s concept of groupthink, the tendency for cohesive groups to converge on a shared view and suppress information that contradicts it, is visible in all four cases. In each disaster, there was a prevailing view (the captain’s course is safe, the takeoff is cleared, the O-rings will hold, the foam strike is not significant) and a dissenting view that was either directly overruled or indirectly smothered. The groups did not set out to suppress dissent. But the combination of hierarchy, time pressure, and a desire for consensus created conditions in which dissent was structurally disadvantaged.

Indirect communication in the face of authority. This is perhaps the most painful commonality. In each case, the dissenters did not remain entirely silent. They spoke. But they spoke indirectly, tentatively, in language calibrated to avoid direct confrontation with authority. The El Faro officers hinted at course changes rather than demanding them. The KLM flight engineer questioned once and then subsided. The Thiokol engineers presented data and then were overridden. The Columbia engineers requested imagery and then were denied. At no point in any of these cases did anyone say, in plain language, “This decision will kill people and I am refusing to proceed.” The social and professional cost of that kind of direct challenge was, in each case, perceived as too high. And the cost of not making it was immeasurably higher.

Connecting to the Research: Psychological Safety, Swiss Cheese, and High Reliability

These disasters are not merely cautionary tales. They are empirical data points that connect to some of the most important theoretical frameworks in organisational safety and team dynamics.

Amy Edmondson’s research on psychological safety, first published in 1999 and synthesised in The Fearless Organization (2019), provides the most direct theoretical lens. Edmondson defines psychological safety as a shared belief that the team is safe for interpersonal risk-taking, that people will not be punished, humiliated, or marginalised for speaking up, admitting mistakes, asking questions, or challenging the status quo. What the El Faro, Tenerife, Challenger, and Columbia all demonstrate is the catastrophic consequence of its absence. In each case, interpersonal risk-taking, specifically the risk of directly challenging a superior’s judgement, was perceived as too costly. Not because the dissenters were weak or cowardly, but because the organisational culture had not created conditions in which that kind of challenge was safe, expected, and supported.

Edmondson’s framework makes an important distinction that is relevant here: psychological safety is not about being nice or avoiding conflict. It is about creating conditions in which people can engage in the kinds of candid, sometimes uncomfortable communication that complex, high-stakes work demands. A psychologically safe cockpit is not one in which the first officer never disagrees with the captain. It is one in which the first officer can say, clearly and directly, “Captain, I believe this course of action is dangerous and we need to change it,” and be heard. A psychologically safe engineering review is not one in which everyone agrees. It is one in which the junior engineer can challenge the programme manager’s assessment without career consequences.

James Reason’s Swiss cheese model of organisational accidents, articulated in Human Error (1990), provides a complementary framework. Reason argued that major accidents are never the result of a single failure. They occur when multiple layers of defence, each with their own imperfections (the “holes” in the Swiss cheese), align in a way that allows a hazard to pass through all of them simultaneously. On the El Faro, the layers of defence included weather forecasting, the captain’s route planning, the officers’ ability to challenge that planning, the shipping company’s safety culture, and the regulatory framework governing vessel operations. Each of these layers had holes. The weather data was available but not fully utilised. The captain’s judgement was flawed but unchallenged. The officers raised concerns but not forcefully enough. The company’s culture did not support effective challenge. When all of these holes aligned, the ship sailed into a hurricane and was lost.

What Reason’s model illuminates is that the absence of psychological safety is not merely a failure of team dynamics. It is a failure of one of the critical defensive layers that stands between normal operations and catastrophe. When people cannot speak up, one of the Swiss cheese layers has been removed entirely. The system has fewer defences, and the probability that the remaining holes will align increases significantly.

The concept of high reliability organisations (HROs), developed by Karl Weick and Kathleen Sutcliffe in Managing the Unexpected (2007), offers a positive model of what these organisations could have been. HROs, organisations that operate in high-risk environments but maintain remarkably low failure rates (nuclear aircraft carriers, air traffic control systems, certain nuclear power plants), share a set of characteristics that directly address the failures visible in these disasters. They are preoccupied with failure rather than success, attending to weak signals of trouble rather than celebrating good outcomes. They are reluctant to simplify, resisting the temptation to dismiss anomalies or reduce complex situations to comfortable narratives. They are sensitive to operations, maintaining close attention to the front line rather than managing from abstraction. They defer to expertise, allowing the person with the most relevant knowledge, regardless of rank, to influence decisions. And they are committed to resilience, investing in the capacity to detect, contain, and recover from errors before they cascade.

The principle of deference to expertise is particularly relevant. In an HRO, the authority gradient is deliberately flattened when it comes to safety-critical information. The most junior person on the team, if they possess the most relevant knowledge about a specific hazard, is expected to speak up and is expected to be heard. This is not a natural state for hierarchical organisations. It requires deliberate design, sustained cultural investment, and leadership that consistently models the behaviour it expects.

Crew Resource Management: Aviation’s Response

If there is a redemptive thread in this story, it runs through the aviation industry’s response to the Tenerife disaster and the subsequent decades of research and practice that produced Crew Resource Management. CRM, first developed in the late 1970s and refined through multiple generations of training, represents the most systematic attempt by any industry to address the authority gradient problem and create conditions for effective upward communication in hierarchical teams.

Robert Helmreich, whose research at the University of Texas from the 1980s onwards was instrumental in developing and evaluating CRM programmes, documented both the promise and the limitations of this approach. Early CRM training focused on interpersonal skills, communication, and leadership. Later generations incorporated threat and error management, the recognition that errors are inevitable and that the goal is to trap and manage them before they cascade. Helmreich’s research (2000) showed that CRM training could measurably improve crew communication, reduce the frequency of errors, and increase the likelihood that errors would be caught and corrected. It also showed that CRM was not a magic solution: some pilots resisted the training, some organisational cultures undermined it, and the authority gradient, though reduced, was not eliminated.

The core principles of CRM are worth stating, because they have implications far beyond aviation. In fact, we’ve sometimes used CRM as a basis for training in corporate environments about how to speak up and challenge effectively.

  • First, anyone on the team has both the right and the responsibility to speak up about safety concerns, regardless of rank.
  • Second, communication should be clear, direct, and assertive, not wrapped in the kind of indirect, face-saving language that characterised the El Faro bridge (and many other catastrophies).
  • Third, leaders should actively invite input from team members and respond to it constructively.
  • Fourth, the team should develop shared mental models of the situation, ensuring that everyone is working from the same understanding of the risks and the plan.
  • Fifth, decision-making should be a structured process that explicitly incorporates dissenting views rather than relying on the captain’s unilateral judgement.

CRM has been widely credited with contributing to the dramatic improvement in commercial aviation safety over the past four decades. It has also been adapted for use in healthcare, nuclear power, and other high-risk industries. Its adoption by the maritime industry was slower and less comprehensive, a fact that the El Faro disaster brought into painful relief. The NTSB’s investigation noted that while bridge resource management (the maritime equivalent of CRM) existed in principle, it was not effectively embedded in the culture aboard the El Faro or within TOTE Maritime’s operations.

What Organisations Can Learn

It would be comfortable to read these disasters as exceptional events, confined to high-risk industries with unusual operational pressures. It would also be wrong. The dynamics that contributed to the loss of the El Faro, the collision at Tenerife, and the destruction of two space shuttles operate in every hierarchical organisation, every day. They operate in quieter registers and with less dramatic consequences, but they operate nonetheless.

Every time a junior team member stays silent in a meeting because the last person who challenged the director’s thinking was publicly dismissed, the authority gradient is doing its work. Every time an employee notices a problem and decides it is “not their place” to raise it, the hierarchy is functioning as a one-way valve. Every time a warning sign is dismissed because “we’ve always done it this way and it’s been fine,” deviance is being normalised. Every time a team converges on a decision without genuinely interrogating it because the leader’s preference is already clear, groupthink is in operation. The scale is different. The mechanism is identical.

The research points towards several practical principles for any organisation that takes these lessons seriously. First, leaders must actively and visibly invite dissent, not as a one-time declaration but as a sustained practice. This means asking questions that genuinely invite challenge (“What am I missing?” “What could go wrong?” “Who disagrees?”), and then responding to the answers with curiosity rather than defensiveness. The leader who asks for honest feedback and then punishes the person who provides it has not merely failed to build psychological safety. They have actively demolished it, and they have taught everyone watching that speaking up is dangerous.

Second, organisations must create structural mechanisms for upward communication that do not rely on individual courage alone. Pre-mortem exercises, anonymous reporting systems, structured devil’s advocacy, and formalised challenge protocols all serve to reduce the social cost of dissent. The point is not to undermine authority but to ensure that authority is exercised with the benefit of all available information, including the information that is most uncomfortable to hear.

Third, organisations must pay attention to the language of dissent. One of the most consistent findings across these disasters is that concerns were raised indirectly, using hedging language, conditional phrasing, and face-saving formulations that allowed the authority figure to dismiss them without fully engaging. CRM training addressed this explicitly, teaching crew members to use structured assertion techniques that escalate from stating the concern, to offering an alternative, to insisting if the concern is not addressed. Organisations outside aviation can learn from this: if you want people to speak up effectively, you may need to teach them how, and you certainly need to create conditions in which direct language is welcomed rather than penalised.

Fourth, and perhaps most fundamentally, leaders must understand that their authority creates a gravitational field that distorts the communication around them. The more senior you are, the less likely people are to tell you what they really think, and the more likely they are to tell you what they think you want to hear. This is not because your team is dishonest. It is because hierarchy exerts a psychological force that is remarkably consistent across cultures, industries, and individuals. Counteracting that force requires deliberate, sustained effort, and it requires leaders who are genuinely willing to hear things that challenge their judgement. Not leaders who say they are open to feedback, but leaders whose behaviour consistently demonstrates it.

A Note on Complexity and Respect

We want to close the analytical portion of this article with a note of honesty about what we do and do not know. These disasters were complex events with multiple contributing factors. Reducing any of them to a single cause, whether that cause is “the captain was wrong” or “the culture lacked psychological safety,” is a distortion that we have tried to avoid, though the constraints of any written account make some simplification inevitable. We write about these disasters not to judge any individual decisions, but to understand the conditions that shaped those decisions and to share lessons that may prevent future catastrophies.

Learning More

To go deeper, explore these resources on people-shift.com:

The People Shift View

At PeopleShift, we tell the El Faro story often. The story is disastrous, relatable and powerful. And the transcripts bring the humanity of it all to life in an immediate and emotional way. We don’t need to say more here. 

Sources and Feedback

National Transportation Safety Board. (2017). Sinking of US Cargo Vessel SS El Faro, Atlantic Ocean, Near Crooked Island, Bahamas, October 1, 2015. Marine Accident Report NTSB/MAR-17/01. Washington, DC: NTSB.

Edmondson, A. C. (1999). Psychological safety and learning behavior in work teams. Administrative Science Quarterly, 44(2), 350–383.

Edmondson, A. C. (2019). The Fearless Organization: Creating Psychological Safety in the Workplace for Learning, Innovation, and Growth. Wiley.

Reason, J. (1990). Human Error. Cambridge University Press.

Vaughan, D. (1996). The Challenger Launch Decision: Risky Technology, Culture, and Deviance at NASA. University of Chicago Press.

Weick, K. E., & Sutcliffe, K. M. (2007). Managing the Unexpected: Resilient Performance in an Age of Uncertainty (2nd ed.). Jossey-Bass.

Helmreich, R. L. (2000). On error management: Lessons from aviation. British Medical Journal, 320(7237), 781–785.

We’re a small organisation who know we make mistakes and want to improve them. Please contact us with any feedback you have on this post. We’ll usually reply within 72 hours.