Skip to content

Swiss-Cheese Barrier Review

Structured review — instantiates Layered Defense Gap Decorrelation

Walks one hazard through the whole defensive stack at a table, asking layer by layer where the same scenario could slip through — the fast first screen for aligned holes.

Before anyone can argue about whether a system's defenses are enough, someone has to trace how a single hazard would actually travel through them. Swiss-Cheese Barrier Review is the lightweight, prospective tabletop exercise that does exactly that: pick one credible harm, name the ordered layers that are supposed to stop it, and walk the hazard through the stack slice by slice, asking at each layer "under the same conditions that let it reach here, could it also pass through this one?" Its whole reason for existing is the alignment question — not "does each layer exist?" but "could the weak spots in these layers line up into one open path?" The review is done from imagination, before any incident, on a whiteboard rather than the floor; it produces the first shared picture of the hazard path, the serial layer map, and a rough read on where the holes plausibly coincide. It is coarse and fast on purpose — a screen, not a survey.

Example

A regional passenger-rail operator convenes a two-hour review of one scenario: a train passing a signal at danger and reaching an occupied section of track. Around the table sit a signaller, a driver-standards manager, a maintenance lead, and a safety analyst. They list the serial layers meant to prevent it — the driver's own vigilance, the AWS audible warning in the cab, the TPWS train-stop grids at the signal, the signaller's route-setting interlocking, and the block-section spacing that buys stopping distance. Then they walk the hazard through, one slice at a time. Vigilance fails on a tired driver at the end of a shift. The AWS warning is present, but the review notes drivers routinely cancel it by reflex. TPWS covers the signal — but only at approach speeds below a threshold that a late brake application can exceed. The interlocking is solid. The block spacing is generous on this stretch but tight at one junction.

The output is not a fix and not a numbered risk — it is a picture the room did not have an hour earlier: for a fatigued driver over-speeding at the tight junction, four of the five layers have a hole in the same scenario, and only the interlocking is clearly independent. That single observation is what tells them where a deeper look is warranted — and it is the review's entire job to surface it.

How it works

The distinguishing move is that the review reasons across layers about one scenario, not down a checklist of controls:

  • Anchor on the harm, work backward. Start from the unacceptable outcome and name the credible trajectory to it. A layer only has meaning relative to the path it is supposed to block.
  • Order the layers as a series. Lay them out in the sequence the hazard would meet them, because the question is whether one scenario can clear the whole line, not whether the average control is healthy.
  • Ask the alignment question at each slice. For the same triggering conditions, is there a plausible hole here? Known weak spots are used as-is; the review does not stop to build a durable hole census.
  • Read the coincidence, not the count. Flag where holes plausibly line up for one scenario — that pattern, not the number of layers, is the finding.

Tuning parameters

  • Scenario breadth — one tightly specified trajectory versus a family of variants. Narrow keeps the review sharp; broad risks turning it into a generic controls debate.
  • Layer granularity — how finely the stack is sliced. Finer slicing exposes handoff gaps but lengthens the walk and invites false precision.
  • Room composition — who is in the room. Each absent layer-owner is a blind spot; too many voices stalls the walk.
  • Optimism discipline — how hard the facilitator pushes on "but does it really hold?" More adversarial framing finds more holes and costs more goodwill.
  • Follow-through trigger — what level of apparent alignment escalates the scenario to a quantitative or field mechanism versus closing it at the table.

When it helps, and when it misleads

Its strength is speed and framing: in an afternoon it converts "we have five layers" into "here is the one scenario where four of them are porous at once," and it does so cheaply enough to run on many hazards. It is the natural entry point to the whole archetype, and it directly attacks the layer-counting fallacy — the comfort of many slices when the holes sit in the same place.[n1] Its central failure mode is that a tabletop walk trades on the room's imagination: holes nobody in the room knows about stay invisible, and an optimistic group will wave a hazard past a layer that would not really hold. The classic misuse is treating the review's clean pass as assurance — "we walked it, we're fine" — when all it ever produces is a hypothesis about alignment. The guarding discipline is to treat every apparent pass as unverified and route any scenario with plausible aligned holes to a field walk or an independence test rather than closing it at the whiteboard.

How it implements the components

Swiss-Cheese Barrier Review fills the framing components — the ones a first-pass tabletop screen can produce:

  • hazard_path_inventory — its opening step names the credible trajectory from trigger to harm that the rest of the walk hangs on.
  • defense_layer_map — it orders the serial layers meant to intercept that trajectory, which is what makes "pass through all of them" a well-posed question.
  • gap_alignment_matrix — its signature move is the qualitative alignment read: for one scenario, which layers have a coincident hole.

It does NOT maintain the durable per-barrier hole census (layer_gap_catalog) — that is the Barrier Gap Walkthrough, which replaces hypothesized holes with observed ones — nor does it store real trajectories (near_miss_path_repository); reconstructing paths hazards actually took is the Near-Miss Trajectory Review. This review works forward from imagination; those work from the floor and from history.

Editorial Notes

Form Classification

Form family: Assessment, Review & Assurance

Rationale: Swiss-Cheese Barrier Review operates as a bounded evaluation of existing evidence or work that produces a finding or disposition because it walks one hazard through the whole defensive stack at a table, asking layer by layer where the same scenario could slip through — the fast first screen for aligned holes.

Independent corroboration: The frozen evidence defines Swiss-Cheese Barrier Review as 'Walks one hazard through the whole defensive stack at a table, asking layer by layer where the same scenario could slip through — the fast first screen for aligned holes', so its operative form is Assessment, Review & Assurance.

Nearest alternative: Analysis, Modeling & Optimization — Swiss-Cheese Barrier Review includes features of an analytical, modeling, inference, comparison, or optimization procedure that derives insight or a solution, but its defining operation is a bounded evaluation of existing evidence or work that produces a finding or disposition.

Review outcome: Independent reviewer agreement; medium confidence.

Origin Attribution

Primary origin: Medicine & Healthcare

Origin pattern: Cross-disciplinary synthesis

Present-day reach: Universal

Rationale: The Swiss-cheese model arose in accident and patient-safety analysis of imperfect defensive layers.

Related originating lineages:

  • Disaster Management & Risk Reduction — Preparedness reviews layer prevention, detection, and response.
  • Engineering & Design — Barrier engineering examines independent failure modes.
  • Psychology — Experimental, clinical, and behavioral psychology supplies a parallel or contributing lineage for the mechanism's defining operation: walks one hazard through the whole defensive stack at a table, asking layer by layer where the same scenario could slip through — the fast first screen for aligned holes.
  • Security Studies & Intelligence Analysis — Security engineering, threat analysis, and intelligence practice supplies a parallel or contributing lineage for the mechanism's defining operation: walks one hazard through the whole defensive stack at a table, asking layer by layer where the same scenario could slip through — the fast first screen for aligned holes.

Review resolution: The blind reviewers agree that medicine_healthcare is the primary origin and differ only on alternate origin disagreement, origin mode disagreement, domain reach disagreement, encyclopedia synthesis disagreement. I preserve every independently explained alternate from both records rather than imposing a numeric cap. I retain cross_disciplinary_synthesis because the combined evidence shows material contributions from several lineages. The broader reach of universal records portability separately from historical provenance; encyclopedia_synthesis=true preserves the affirmative synthesis judgment where either reviewer identified one.

Encyclopedia synthesis: The exact catalogued form synthesizes established practice rather than reproducing a single standard historical label.

Review outcome: Reconciled after independent review; high confidence.

Notes

[n1] The Swiss cheese model of accident causation (James Reason) pictures each defensive layer as a slice with holes, and holds that a loss occurs only when holes in successive slices momentarily align into a trajectory. The model is the source of this mechanism's name and of the archetype's "layer-counting fallacy" — more slices help only if their holes move independently.