Knowledge / Maintenance and reliability
Maintenance error: task design, interfaces and error-tolerant checks
Reduce assembly and restoration errors through usable task information, compatible interfaces, interruption control and checks that can find the specific mistake.
On this page
Experienced maintainers can make slips, omit steps or act on an incorrect understanding of a task. A reliable maintenance system anticipates those possibilities in the equipment, information and work sequence. The objective is to make the correct action easier, make dangerous combinations harder and create a realistic chance of detecting errors before service is restored. Blame alone does not redesign an error-prone task.
Distinguish doing the wrong action from choosing the wrong plan
A slip can occur when the intended action is correct but the wrong connector is selected. An omission can leave a step undone after interruption. A knowledge or reasoning mistake can produce a consistently executed but unsuitable plan. These mechanisms need different controls: better identification, progress tracking or clearer technical information and decision support.
HSE’s maintenance-error guidance notes that trained and motivated technicians can still make errors and identifies reassembly, replacement specification, settings and restoration as recurring concerns. Its emphasis on maintainability and task design is useful beyond the process industries. Treat “human error” as the beginning of the explanation: identify the conditions that made the action likely and difficult to recover.
Make identity and orientation hard to confuse
Similar connectors, symmetrical parts and ambiguous labels can permit a wrong assembly that looks complete. Where engineering change is appropriate, keyed interfaces, distinct connection geometry and visible orientation marks can reduce the opportunity. A label should match the actual equipment identifier and remain readable in the access position, lighting and contamination expected during the task.
Error resistance needs evaluation of the whole system. A connector adapter can defeat intentional keying; a replacement part revision can reverse a familiar orientation cue. Colour alone may be unreliable under poor light or for users with colour-vision differences. Use more than one suitable identifying feature, and verify that new markings agree with drawings and procedures. A clear wrong label can create more confidence than no label.
Keep units and specifications visible at the action
An original dimensional example shows the consequence of a unit mismatch. A hypothetical instruction says 80 N·m, but a tool is mistakenly set to 80 lbf·ft. Using 1 lbf·ft = 1.355817948 N·m, the applied setting is about 108.47 N·m, 35.6% higher than intended. The example is not a torque recommendation for any fastener.
A correct numeric value copied without its unit is incomplete information. The task should also preserve the applicable component, thread condition, lubrication state, sequence and tool requirements from the approved specification. A second person checking only that the display reads “80” would miss the unit error. Design the check around the actual specification and tool state, not a familiar number or a tick box.
Design the procedure for use in the work environment
A technically correct procedure can be difficult to use if it hides critical conditions in dense paragraphs, separates warnings from the relevant step or assumes an access position the ship does not provide. Place the required identity, tools, acceptance criteria and hold points where the worker needs them. Distinguish steps that can be done in parallel from those requiring a verified sequence.
The FAA maintenance human-factors programme treats equipment, procedures, jobs and organizational conditions as part of human performance. Its aviation context is not a marine regulatory requirement. The transferable principle is to test task information with actual users and realistic conditions. Ask a competent maintainer to walk through the task and identify ambiguities before the document is treated as evidence that the work is straightforward.
Control interruption and incomplete assembly
An interruption breaks the link between the worker’s memory and the physical task state. Provide a reliable way to mark the last verified completed step and the next action, especially when identical fasteners or multiple similar connections are involved. A component placed loosely in position can look installed; a verbal “nearly finished” gives the next worker little usable evidence.
Before a handover, identify open boundaries, temporary connections, removed parts, tools, settings and checks not yet completed. The receiving person should reconcile the written state with the physical state through the applicable safe process. Restarting from an arbitrary remembered point can skip a critical step; repeating a step blindly can also be harmful. The method should make both omission and unintended repetition detectable.
Choose checks that can actually detect the error
A checker needs access to the relevant feature and an independent basis for deciding whether it is correct. Verifying a hidden seal’s orientation after the housing is closed may be impossible without reopening it, so the check belongs before closure. A later successful no-load run may not reveal the wrong seal material or an omitted locking feature.
Independence can be weakened by shared assumptions, the same wrong drawing or a leading statement such as “I fitted it correctly, just sign here.” Specify the feature to inspect, the reference and the acceptance condition. Separate completion evidence from attendance. Two signatures on a form do not establish two independent technical observations. Apply the degree of checking required by consequence and the approved work process.
Manage fatigue through the work system
Fatigue can reduce attention and make recovery from interruptions harder, but a generic fatigue label does not explain every maintenance error. Examine actual scheduling, workload, sleep opportunity, environment and task demands. Protect demanding or consequence-sensitive steps from avoidable time pressure and interruptions, and provide a credible route for reporting inability to perform safely.
IMO’s Guidelines on fatigue discuss company, ship and environmental factors and include maintainability and workspace design. The point is broader than recording hours: available rest and actual restorative sleep are not identical. Maintenance schedules can also disturb other crew members’ rest. Coordinate work so that one team’s repair programme does not quietly degrade the readiness of another.
Make restoration visible and resist common mistakes
At the end of work, temporary states must be reconciled: manual selectors, isolated supplies, forced signals, temporary blanks and inhibited protections. Grouping restoration evidence by system function can reveal an overlooked dependency. The operator receiving the equipment needs to know the demonstrated configuration and any authorized remaining limitation.
Error-tolerant design can include visible status, captive components, appropriate interlocks or a sequence that makes an unsafe state apparent. Such changes need engineering assessment because an interlock can introduce another failure mode or obstruct a legitimate maintenance activity. The aim is not to add obstacles indiscriminately, but to prevent the specific credible mistake while preserving safe access, isolation and recovery.
Learn from recoveries and near misses
A wrong part caught before installation is useful evidence about procurement, identification and checking. Record how the error became possible and how it was detected, without treating successful recovery as proof that no improvement is needed. The same recovery may fail next time under different workload or access conditions.
Review whether actions changed the task: clearer information, corrected labels, improved access or a better hold point. Verify the change with realistic use and retain feedback from maintainers. A reduction in reported errors is not automatically success if reporting has become punitive or burdensome. The desired outcome is fewer error opportunities and stronger detection and recovery, demonstrated through work quality and functional performance.
Sources
- Maintenance error · HSE · Source check date: 2026-10-06
- Human Factors in Aviation Maintenance · Federal Aviation Administration · Source check date: 2026-10-06
- Guidelines on fatigue, MSC.1/Circ.1598 · IMO · Source check date: 2026-10-06