Introduction. Four bodies of work describe how organisations fail. Normal accident theory (Perrow) classifies systems by interactive complexity (unplanned, non-linear interactions) and coupling (how tightly one step follows another); where both are high, accidents are consequences of system properties rather than pathologies, and the organisational requirements are contradictory, because complexity demands decentralised discretion and coupling demands centralised control. Perrow explicitly judges contingency management — decentralised in normal times, centralised under challenge — infeasible. The disaster-incubation model (Turner) shows, from British public inquiries, that disasters are preceded by a period in which discrepant events accumulate unnoticed or are misread because they conflict with prevailing beliefs; the disaster is the collapse of those beliefs. Vaughan’s Challenger study shows normalisation of deviance: evidence of O-ring damage was incrementally reclassified as acceptable by engineers following NASA’s own rules, aided by structural secrecy. High-reliability organising (Weick and Sutcliffe; the Berkeley group of La Porte, Roberts and Rochlin) claims that some organisations — carriers, nuclear plants, air traffic control — sustain both autonomy and tight coordination through mindful practices, which normal accident theory says cannot be done. Reason’s Swiss-cheese model and Leveson’s control-theoretic STAMP are the engineering counterparts.
Important authors. Charles Perrow (1925–2019), Yale, organisational sociologist. Barry Turner (1937–1995), Exeter; Nick Pidgeon (Cardiff) co-authored the second edition. Diane Vaughan (Columbia). Karl Weick (Michigan) and Kathleen Sutcliffe (Johns Hopkins). Todd La Porte, Karlene Roberts and Gene Rochlin (Berkeley) formed the original HRO group; Scott Sagan (Stanford) tested HRO against NAT on nuclear-weapons safety. James Reason (Manchester) and Nancy Leveson (MIT) represent the safety-science side.
Importance for cybernetics and the VSM. Perrow is the best-defined empirical disagreement with the VSM in the whole critique series. Beer claims a structure that reconciles autonomy and cohesion: System One autonomy in normal operation, algedonic escalation and System Three intervention under challenge. That is contingency management, and Perrow considered it and rejected it on accident evidence. The VSM literature does not engage him. Turner and Vaughan supply pathologies the VSM cannot name — incubation (failures accumulating below any monitored boundary) and normalisation of deviance (the threshold an algedonic signal fires against is itself corrupted) — and HRO is the one tradition that claims Beer’s design is feasible, without having been asked. Leveson’s STAMP is a control-theoretic accident model the VSM community could have produced and did not.
Importance for the article. §3.3 cites Perrow (1984) for the infeasibility of the arrangement the VSM prescribes where complexity and coupling are both high, and adds normalisation of deviance (Vaughan†) and incubation (Turner†) to the pathology list; §10.5’s candidate table sets “autonomy in normal operation with escalation under challenge is a viable design” against normal accident theory and high-reliability organising, discriminated by an adversarial receipt on cases in the complex-and-tightly-coupled quadrant. Perrow is Tier A; Turner, Vaughan and Weick are Tier C, and Weick and Sutcliffe is absent from v02’s references although HRO is named in the table. The imports are Applying new lenses (C5 §VI, “Perrow is the decisive challenge”) and VSM vs Complexity Science (C6 §2), which adds a third party: Siggelkow and Levinthal’s alternation result answers Perrow by sequence rather than balance and treats fixity as the pathology. A reviewer will press on whether Perrow’s “infeasible” is a finding or a judgement (a judgement, argued from cases), whether any VSM application sits in that quadrant, and how the three-way disagreement is staged; Sagan (1993) is the existing HRO–NAT adjudication to name.
Sources in the reading list.
- chapter 3 for the complexity–coupling matrix and the passage on centralisation and decentralisation; the source of the infeasibility judgement.
- the incubation model; Tier C, verify the passage.
- the chapters on the acceptable-risk reclassifications for normalisation of deviance; Tier C.
- the five principles of mindful organising, as the HRO side of the §10.5 receipt; Tier C and not yet in v02’s references.
Other important sources and authors.
- La Porte, T. R., & Consolini, P. M. (1991). Working in practice but not in theory: Theoretical challenges of “high-reliability organizations”. Journal of Public Administration Research and Theory, 1(1), 19–48 — the HRO programme’s founding statement.
- Sagan, S. D. (1993). The Limits of Safety: Organizations, Accidents, and Nuclear Weapons. Princeton University Press — the explicit HRO-versus-NAT test on one class of cases; the template for the §10.5 adversarial receipt.
- Rijpma, J. A. (1997). Complexity, tight-coupling and reliability: Connecting normal accidents theory and high reliability theory. Journal of Contingencies and Crisis Management, 5(1), 15–23 — the reconciliation attempt, and the reasons it is incomplete.
- Reason, J. (1997). Managing the Risks of Organizational Accidents. Ashgate — latent conditions and defences in depth; the safety-science pathology vocabulary.
- Turner, B. A., & Pidgeon, N. F. (1997). Man-Made Disasters (2nd ed.). Butterworth-Heinemann — the revised incubation model with the safety-culture literature added.
- Leveson, N. G. (2012). Engineering a Safer World: Systems Thinking Applied to Safety. MIT Press — accidents as control failures in a hierarchy of feedback loops; the closest existing cybernetic accident model, built without the VSM.
