Swiss Cheese Model is accidents occur when multiple layers of defenses fail simultaneously. It sits in the Cognition dimension (COG) of the Human Behavior Taxonomy™ as element HBT-COG-0653, within the Systems family. The core principle: accidents occur when multiple layers of defenses fail simultaneously. In incentive terms, it matters because it changes the payoff people perceive before they choose — which means it can be designed for, or exploited.
Scientific Definition
Accidents occur when multiple layers of defenses fail simultaneously.
Plain-English Definition
Accidents occur when multiple layers of defenses fail simultaneously.
Feynman Explanation
Every layer has holes. Catastrophe finds the alignment.
Core Principle
Accidents occur when multiple layers of defenses fail simultaneously.
Mechanisms
Pending editorial review.
Accidents occur when multiple layers of defenses fail simultaneously.
Pending editorial review.
Pending editorial review.
Pending editorial review.
Pending editorial review.
Risk management is about layers, not single controls.
Inputs (Triggers)
Pending editorial review.
Outputs (Behaviors)
Pending editorial review.
Behavioral Signature
Every layer has holes. Catastrophe finds the alignment.
Examples
- A plane crash requires several safeguards to fail at once.
- Risk management is about layers, not single controls.
Pending editorial review.
Original analysis from The Incentives Lab — how this element behaves inside real payoff structures.
Why this element matters to incentive design
Most organizations meet this element as a personnel problem. It is not one. The mechanism underneath it is straightforward: accidents occur when multiple layers of defenses fail simultaneously. You can recognize it in the field by its signature: every layer has holes. Catastrophe finds the alignment. Every element in the Cognition dimension changes the perceived payoff of an action before the action happens, which is exactly where incentive design has leverage.
How it gets exploited
Left undesigned, risk management is about layers, not single controls. It is amplified whenever risk management is about layers, not single controls. Inside organizations that shows up as risk management is about layers, not single controls. The pattern is the same one Goodhart's Law describes: the measurable proxy attracts the effort, and the purpose behind it quietly loses funding.
How the Lab designs around it
The redesign move is to add independent layers and monitor near-misses. Design against it the way you would design against a known failure mode — assume it will appear, and price the exploit before someone finds it.
Famous Experiments
Pending editorial review.
Design Principles
- Add independent layers and monitor near-misses.
Measurement Approaches
Pending editorial review.
Evidence
Pending editorial review.
Pending editorial review.
The Perverse Incentive Lens™
How this behavior is exploited — and how to redesign around it.
- Add independent layers and monitor near-misses.
Pending editorial review.
Pending editorial review.
Interactive Mini Network
Click any neighbor to re-center the graph and follow the threads of connection.
Knowledge Graph Neighbors
Auto-linked to the rest of the Human Behavior Taxonomy by family, domain, dimension, and shared keywords.
Combining substances to create a new material stronger than its parts.
A single constraint limits the throughput of an entire system.
A system's throughput is constrained by its single slowest step.
Small visible disorders signal that bigger ones will be tolerated.
Adding manpower to a late software project makes it later.
Adding people to a late project makes it later.
A substance that speeds up a reaction without being consumed.
Nonlinear systems are highly sensitive to initial conditions.
Inputs combine under conditions to produce new outputs — sometimes irreversibly.
Software architecture mirrors org structure.
Working together has a cost that scales with the number of people.
The threshold at which a system becomes self-sustaining.
Where Swiss Cheese Model is cited in the corpus
Essays, field guides, and diagnostics from The Incentives Lab that apply this element.
- EssayGoodhart's Law in the Real World
How measurable proxies capture judgment.
- EssayThe Perverse Incentives Hiding in Your KPIs
Cognitive shortcuts turned into scorecards.
- EssayAI Agents Inherit Your Incentives
How this element propagates into automated systems.
- CourseIncentives 101
The free ten-part primer on reading a payoff structure.
- ReferenceThe incentive glossary
Definitions for every mental model, bias, and fallacy in the corpus.
- ReferenceThe Periodic Table of Human Behavior
The full 1,267-element map this page belongs to.
Questions about Swiss Cheese Model
- What is Swiss Cheese Model?
- Swiss Cheese Model is accidents occur when multiple layers of defenses fail simultaneously. It sits in the Cognition dimension (COG) of the Human Behavior Taxonomy™ as element HBT-COG-0653, within the Systems family. The core principle: accidents occur when multiple layers of defenses fail simultaneously. In incentive terms, it matters because it changes the payoff people perceive before they choose — which means it can be designed for, or exploited.
- What is an example of Swiss Cheese Model?
- Risk management is about layers, not single controls. The Incentives Lab catalogs everyday, organizational, and historical instances of this element on its Human Behavior Taxonomy™ page (HBT-COG-0653).
- How is Swiss Cheese Model exploited?
- Risk management is about layers, not single controls.
- How do you design around Swiss Cheese Model?
- Add independent layers and monitor near-misses.
- Which behavioral dimension does Swiss Cheese Model belong to?
- Swiss Cheese Model is classified in the Cognition dimension (COG) of the Human Behavior Taxonomy™, family "Systems", class "Mental Model". Its permanent identifier is HBT-COG-0653 and its evidence grade is B.