When Abnormal Becomes Normal - What Australian Workplaces Can Learn from the Space Shuttle Columbia Disaster
- Safety Jon
- 5 days ago
- 10 min read

On 16 Jan 03, Space Shuttle Columbia launched from Kennedy Space Center in Florida, USA on mission STS-107. Approximately 82 seconds after launch, a section of insulating foam separated from the shuttle’s external fuel tank and struck the reinforced carbon-carbon panels protecting the leading edge of its left wing.
The foam strike was captured by launch cameras, but the available imagery did not show the extent of the damage. Columbia continued into orbit, where its seven-member crew completed a 16-day scientific research mission while engineers and managers on the ground considered whether the impact posed a threat to the shuttle.
Some engineers sought higher-resolution imagery that may have helped determine whether the wing had been seriously damaged. That imagery was not obtained, and NASA ultimately proceeded on the basis that the foam strike was not expected to compromise Columbia’s safe return.
On 01 Feb 03, Columbia began its descent through the atmosphere. Superheated gases entered through the damaged section of the left wing and progressively destroyed its internal structure. Temperature and pressure sensors began failing, flight controllers lost data from the landing gear and hydraulic systems, and the shuttle became increasingly difficult to control.
Communication with Columbia was lost as it travelled over Texas. The shuttle broke apart approximately 16 minutes before its scheduled landing, killing commander Rick Husband, pilot William McCool, payload commander Michael Anderson, mission specialists Kalpana Chawla, David Brown and Laurel Clark, and payload specialist Ilan Ramon.
The physical cause was a foam strike, but the Columbia Accident Investigation Board found that NASA’s organisational culture and structure were as significant to the accident as the physical damage. Columbia was not lost because NASA lacked technical expertise, procedures, risk assessments or safety personnel. It was lost because the organisation became accustomed to abnormal performance, constrained the flow of contrary information and failed to treat uncertainty as a reason for further action.
That finding should concern any Australian organisation tempted to believe that sophisticated systems, qualified people and an impressive safety framework make it immune from catastrophic failure. NASA had all of those things, right up until the point that they failed to protect seven people.
The foam strike was not an unknown hazard
External tank foam had been shed during previous shuttle launches. NASA’s investigation found that foam loss occurred on more than 80 per cent of the missions for which imagery was sufficient to confirm or rule it out, while several earlier missions had sustained observable damage.
Because those missions returned safely, foam shedding gradually came to be treated as a turnaround maintenance issue rather than a threat to flight safety. The absence of a previous catastrophe became informal evidence that the condition was acceptable.
NASA had effectively converted an unresolved control failure into an operational norm. The hazard remained, but repeated survival reduced its organisational significance.
NASA now uses Columbia as a case study in both normalisation of deviance and organisational silence. A condition that was not supposed to occur became accepted because the organisation experienced it repeatedly without suffering the worst possible consequence.
This pattern is readily recognisable in Australian workplaces. A forklift repeatedly enters a pedestrian area without striking anyone, a machine interlock is occasionally bypassed without injury, a driver completes overloaded journeys without losing control, or workers continue accessing an unprotected edge without falling.
Each favourable outcome can make the activity feel safer. In reality, the exposure remains and the organisation has merely become less responsive to it.
From left, the foam-shedding and impact locations, the recorded strike against Columbia’s left wing, and experimental testing of reinforced carbon-carbon material after the accident. Images: NASA.
Previous success is not proof of safety
Columbia demonstrates the danger of outcome bias, where the quality of a decision or condition is judged by what happened rather than by the exposure that existed.
Previous shuttle missions had returned safely despite foam shedding, so those successful outcomes became informal evidence that foam loss was tolerable.
A worker surviving an uncontrolled fall risk does not prove that the work method was safe. A truck completing repeated journeys with inadequate load restraint does not validate the loading system, and a forklift missing a pedestrian by half a metre does not demonstrate effective traffic management.
A favourable outcome may simply mean that the uncontrolled variables happened to fall in the organisation’s favour. Luck has an excellent record in poorly managed operations, but it remains difficult to list as a critical control with a straight face.
Repeated abnormal events should therefore increase organisational concern, not gradually reduce it. Each recurrence is additional evidence that the relevant control is unreliable, even when no injury, damage or operational interruption results.
Uncertainty was treated as reassurance
NASA engineers attempted to determine what damage the foam strike may have caused, but they did not have sufficiently clear imagery of Columbia’s left wing. The available modelling tool was also being used outside the conditions for which it had been designed, leaving substantial uncertainty around the damage assessment.
Engineers sought high-resolution external imagery that may have helped establish the condition of the wing. Those requests moved through several channels, but NASA management did not obtain the imagery.
The investigation found that assumptions and uncertainties within the engineering analysis were not fully presented to the Mission Evaluation Room or Mission Management Team. Possible damage to the reinforced carbon-carbon wing panels was not meaningfully addressed in the relevant briefings, despite engineers and managers knowing that the foam could have struck them.
In practice, the decision had shifted from asking whether NASA could demonstrate that Columbia was safe to re-enter, to asking whether engineers could prove that Columbia was unsafe. That reversal matters because high-consequence operations should not require absolute proof of danger before further investigation is authorised.
An absence of information is not evidence of an absence of damage. When the possible consequence is catastrophic, uncertainty is itself an exposure requiring inspection, containment, suspension, additional technical analysis or contingency planning.
Australian workplaces make the same error when unknowns are converted into low likelihood ratings without supporting evidence. A risk assessment cannot honestly rate an event as unlikely merely because the organisation lacks inspection results, exposure data, maintenance history or a competent engineering opinion.
That is not risk analysis. It is administrative wishful thinking wearing a matrix.
The authority gradient restricted the flow of risk information
The Columbia investigation found leadership and communication failures that made it difficult for engineers to raise concerns or understand how decisions were being made. Management did not actively engage with the foam-strike analysis, while some engineers felt unable to take their concerns directly to senior mission managers.
Management also appeared more concerned with identifying who had requested external imagery and whether the request had followed the correct channels than with evaluating the technical merits of the request. At the same time, some management decisions relied upon informal advice and discussions outside the organisation’s formal decision rules.
This created procedural asymmetry. Engineers seeking additional evidence were expected to establish a mandatory operational need through formal channels, while managers retained considerable freedom to reject or redirect concerns through informal processes.
An escalation process does not exist merely because it appears in a procedure. It exists only when a worker, engineer, HSR, supervisor or specialist can use it without being blocked by hierarchy, professionally punished for challenging a preferred decision, or required to provide certainty that the available evidence cannot support.
The same principle applies to a WHS function. A safety adviser sitting in a meeting without access to technical information, protected escalation rights or the organisational standing to challenge a decision is not an effective control, it is a spectator with a position description.
Schedule pressure did not need to be spoken aloud
The Board identified schedule pressure, resource constraints and fluctuating organisational priorities as contributing conditions. NASA was working towards an ambitious International Space Station schedule, while unresolved technical anomalies, maintenance, recertification and program demands competed for limited resources and management attention.
Schedule pressure does not need to appear as a direct instruction to disregard safety. It operates through which work receives funding, which defects are repeatedly deferred, how uncertainty is characterised and whether raising a concern is treated as supporting or obstructing delivery.
When successful delivery becomes the dominant organisational narrative, contrary technical information acquires an additional burden. The person raising the concern must overcome both the uncertainty within the evidence and the institution’s desire to continue.
Australian organisations should recognise the same pressure in production targets, delivery windows, shutdown durations, project milestones, vehicle schedules and contractual penalties. The relevant question is not whether a manager explicitly directed someone to work unsafely, but whether the organisation’s priorities made the safer decision unnecessarily difficult to make.
Critical controls must be verified, not merely listed
NASA knew that Columbia’s thermal protection system was essential to surviving re-entry. The organisation nevertheless lacked reliable means to prevent dangerous foam shedding, obtain adequate imagery of the affected area, inspect the wing in orbit or undertake a proven emergency repair.
A critical control is not verified by confirming that a procedure, design standard, inspection schedule or risk register entry exists. Verification must establish whether the control is present, capable, functioning and effective under the conditions that actually exist.
For an Australian transport business, this may mean physically verifying load restraint, fatigue controls, braking systems or separation during loading. In manufacturing or warehousing, it may involve testing isolation integrity, guarding, interlocks, pedestrian exclusion, emergency stops or fire protection systems.
The relevant question is not whether the control appears in a document. It is whether the control would prevent or mitigate the material event if challenged today.
Recurring deviations should also be reported as control failures rather than buried within general incident statistics. An executive dashboard showing zero lost-time injuries can remain green while plant defects, workarounds, near misses and failed critical controls steadily accumulate underneath it.
Independent technical authority matters
The Board concluded that NASA required robust and independent technical authority, supported by an independent safety assurance function with influence across the organisation. Technical requirements, waivers and safety decisions could not remain subordinate to the same management structure responsible for cost, schedule and program delivery.
The industrial equivalent is a competent person with defined decision rights who cannot be overruled solely by the manager accountable for production, schedule or cost. Depending on the work, that authority may sit with an engineer, maintenance specialist, WHS professional, occupational hygienist, load restraint specialist or material-risk owner.
Independence requires more than a separate reporting line. The person must have access to relevant information, sufficient competence, protected escalation and the authority to require further evidence or stop work where a critical uncertainty remains unresolved.
Organisations should also document unresolved professional disagreement rather than allowing consensus to dissolve accountability. A critical decision record should identify what is known, what remains uncertain, who challenged the decision, who accepted the residual exposure and the evidence upon which that acceptance was based.
Recovery capability is part of the control system
Some NASA personnel questioned the value of obtaining better imagery because they believed little could be done if catastrophic damage was discovered. That assumption reduced the perceived operational value of confirming the wing’s actual condition.
The Board later examined possible repair and rescue scenarios. An improvised repair would have been extremely hazardous, while an accelerated rescue mission involving Atlantis was considered technically possible under favourable conditions if the damage had been identified sufficiently early, although success was far from assured.
The point is not that rescue would certainly have succeeded. The point is that the assumption that information had no operational value was incorrect.
Accurate information allows an organisation to develop contingencies, change the work method, seek external assistance, warn exposed people and make decisions based on the actual condition. Inspection is not pointless merely because recovery may be difficult.
High-consequence systems therefore require the capacity to detect and respond when prevention fails. Emergency isolation, secondary containment, shutdown arrangements, rescue equipment, competent external support and recovery plans should be designed before the event, not invented while the event is unfolding.
The Australian WHS governance lesson
Under the model WHS laws adopted across most Australian jurisdictions, a person conducting a business or undertaking has a primary duty to ensure, so far as is reasonably practicable, the health and safety of workers and other people affected by the work. Officers must exercise due diligence to ensure the organisation complies with its duties, including acquiring WHS knowledge, understanding operational hazards and risks, providing appropriate resources and verifying that risk-control processes are actually being used.
Victoria retains the Occupational Health and Safety Act 2004 rather than the model WHS Act, but the operational lesson remains the same. Employers must provide and maintain a working environment that is safe and without risks to health so far as is reasonably practicable, while consultation must involve an actual exchange of information with affected employees and HSRs.
Safe Work Australia confirms that officer due diligence requires active steps to ensure organisational compliance. Receiving a dashboard showing that nobody has recently been injured is not sufficient evidence that recurring deviations, failed controls and unresolved technical concerns are being identified and addressed.
Consultation is similarly ineffective when workers are invited to comment but decision-makers have already settled upon the outcome. Under the model WHS laws, consultation with workers and other duty holders is a legal requirement, not a ceremonial step added after the operational decision has been made.
Boards and executive teams should be receiving information about recurring deviations, overdue corrective actions, failed critical controls, rejected escalation requests and unresolved technical assumptions. They should also know whether those matters have been independently assessed and whether the organisation can safely recover when its primary controls fail.
What Australian workplaces should take from Columbia
Columbia demonstrates how a technically capable organisation can become increasingly vulnerable while continuing to believe that it is managing risk. Previous success softened the meaning of abnormal events, uncertainty was interpreted in favour of continuation, dissent struggled to reach decision-makers and program pressure competed with technical caution.
The foam strike initiated the physical failure, but the organisational system prevented NASA from treating the uncertainty as a threat while there was still time to act. That lesson applies to any Australian workplace where repeated deviations are being accepted because the organisation has not yet paid the full price for them.
A control does not become effective because the organisation has survived its failure before. When abnormal performance starts being described as normal work, the warning has already arrived.
NASA's Columbia: Her Continued Mission documentary video includes a documentary covering reconstruction, learning from debris, recovery and changes to NASA's operating approach.






