Boeing 737 MAX: How Production Pressure Outran Safety Governance
The Boeing 737 MAX crashes were not only a technical failure. They exposed a governance problem in which commercial urgency, delegated authority, incomplete challenge, and insufficient visibility of safety-critical decisions allowed risk to move faster than leadership oversight.

Key takeaways
- 01The Boeing 737 MAX case was a governance failure as well as a technical failure, because safety-critical decisions were not visible enough to the leaders accountable for the outcome.
- 02Production pressure becomes a safety hazard when schedule, cost, and market commitments can override unresolved technical questions without a clear escalation decision.
- 03Delegating engineering work does not delegate executive accountability for the assumptions, evidence, and residual risk attached to that work.
- 04A safety governance system needs challenge routes that can stop a release, expose uncertainty, and preserve dissent in the record.
- 05Leaders can apply the case by auditing decision ownership, change assumptions, evidence quality, and escalation latency before a high-consequence release.
Two Boeing 737 MAX crashes in 2018 and 2019 killed 346 people. The official investigations did not describe a single careless act that explained the loss. They exposed a decision system in which technical assumptions, delegated authority, commercial urgency, and weak challenge routes interacted until a safety-critical risk became difficult to see from the top.
This case matters to every senior safety leader who approves a design change, production ramp, temporary deviation, or new digital control. The lesson is not that leaders must personally perform every technical review. The lesson is that they must make the important decisions visible, challengeable, and owned before production pressure turns uncertainty into an operational fact.
Initial scenario: a market deadline changed the risk conversation
The 737 MAX was developed in a competitive commercial environment in which Boeing needed an aircraft that could respond to airline demand while preserving as much commonality as possible with earlier 737 models. The business objective was understandable. The safety question was whether the design and certification assumptions created new hazards that deserved a different level of leadership attention.
The U.S. House Committee on Transportation and Infrastructure, in its September 2020 final report, documented how production and market pressures shaped decisions around the aircraft. That does not mean that every employee ignored safety. It means the system made speed, continuity, and cost highly visible while important technical concerns were not always elevated with the same force.
That distinction is central to safety leadership. A company can have competent engineers, formal gates, and a strong safety statement while still allowing the business plan to define what counts as an acceptable delay. The risk grows when the person closest to the concern has no reliable path to make the concern consequential.
Decision: a design assumption became an accountability problem
The Maneuvering Characteristics Augmentation System, known as MCAS, was introduced to address handling characteristics associated with the aircraft configuration. The technical decision was not automatically unsafe because it used software. The governance problem emerged when the safety significance of the system, its activation logic, the information available to pilots, and the consequences of a faulty sensor were not treated as one visible executive decision.
The Joint Authorities Technical Review published in 2019 identified shortcomings in the assumptions, documentation, and certification process surrounding the aircraft. Its findings show why a safety-critical design decision cannot remain divided into small work packages that no senior owner sees as a complete risk picture.
Delegation is necessary in complex organizations, but delegation does not transfer accountability. A director may delegate analysis to engineering, certification, or a supplier while retaining responsibility for whether the organization has enough evidence to release the risk. If that boundary is unclear, a local approval can become a global exposure.
Execution: production pressure narrowed the challenge route
Once a program is under commercial pressure, the operating system starts rewarding closure. Open questions become schedule threats, additional training becomes a cost, and a request for independent review can look like an obstacle to delivery. The danger is subtle because the organization may still describe every step as controlled.
The House Committee report described communication failures, conflicts of interest, and a certification relationship that weakened independent visibility. Those findings are more useful than a simple story about bad culture because they show the mechanisms through which pressure changes behavior. People do not need to be indifferent to safety for a system to make silence easier than escalation.
The practical test for a safety leader is whether a technical specialist can record uncertainty without having to convert it into a fully proven failure before it receives attention. When the standard for escalation is certainty, the system discovers risk only after the consequence has already become visible.
Measured result: two crashes exposed the cost of invisible risk
Lion Air Flight 610 crashed on October 29, 2018, and Ethiopian Airlines Flight 302 crashed on March 10, 2019. The two accidents killed 346 people. These dates are not just historical markers. They show how a risk that remains unresolved in one operation can reappear in another operation with similar conditions.
The measured result was therefore larger than a damaged component or a failed software response. The case demonstrated a breakdown across design, training, certification, communication, oversight, and leadership visibility. The U.S. Federal Aviation Administration grounded the aircraft worldwide after the second crash, and the subsequent reviews required changes to the aircraft, training, certification process, and oversight arrangements.
James Reason's work on organizational accidents helps explain why the outcome cannot be reduced to the final cockpit actions. Latent conditions accumulate when decision rights, information, incentives, and defenses are misaligned. A visible error may be the last movement in the chain, but leadership controls the conditions that decide whether the chain is likely to form.
| Governance question | Weak pattern | Stronger pattern |
|---|---|---|
| Who owns residual risk? | Each function closes its own task. | One accountable leader accepts or rejects the complete exposure. |
| How is uncertainty handled? | Concern must become proof before escalation. | Uncertainty triggers review proportional to consequence. |
| What does production pressure change? | Delay becomes harder to propose. | Release criteria remain fixed when schedule pressure rises. |
| Can dissent survive? | Challenge is treated as friction. | Challenge is preserved in the decision record and answered by an owner. |
Generalizable lessons for safety leaders
Safety-critical decisions need one visible owner
A distributed review can produce many approvals without producing one accountable decision. Senior leaders should be able to answer five questions without opening a maze of documents. What changed, what could fail, what evidence supports the assumption, who challenged it, and who accepted the remaining exposure?
This is the same logic behind a clear control ownership model. Ownership is not a name beside an action. It is the authority to delay, alter, or reject the work when the evidence does not support release.
Independent challenge must arrive before release
Independent challenge is not a ceremonial second signature. It is a different route through which assumptions are tested, evidence is questioned, and the consequences of failure are considered by someone who does not carry the same delivery incentive.
Leaders should review whether the challenge function has access to source data, time to investigate, and authority to escalate outside the project chain. The evidence layers that keep controls credible are useful only when the reviewer can see the evidence before the decision becomes irreversible.
A green gate can hide a red assumption
Many organizations report that a project passed its gates, but a gate is only as strong as the assumption beneath it. A review can be green because a question was excluded, a failure mode was judged improbable, or a dependency was treated as someone else's responsibility.
That is why a senior safety review should sample decisions rather than only count completed reviews. Compare the original assumption with field evidence, look for unresolved dissent, and examine how the organization treats a late concern. A process that closes every gate on time may be demonstrating schedule discipline rather than risk control.
What to apply in your operation
Start with the next high-consequence change, not with a culture campaign. Trace one decision from the first concern to the final release and record the people, evidence, assumptions, escalation time, and residual risk. Then ask an independent leader to challenge the record before the change is repeated elsewhere.
Use the review to test four practical conditions. The accountable owner must have authority to stop the release. The technical basis must be visible to the decision-maker. Dissent must remain in the record after closure. The post-release check must be scheduled before the work begins, because verification that depends on memory will usually arrive after the organization has normalized the change.
For a plant manager, the exercise can fit inside an existing management-of-change review. Select one modification with a credible high-consequence pathway, invite the operations owner and an independent technical challenger, and ask both to explain what evidence would make them delay the release. If they give different answers, the disagreement is not a meeting problem. It is the risk decision that leadership needs to own.
This approach complements an evidence-based incident review, because the same weaknesses that hide a precursor event can hide a design concern before an event occurs. Andreza Araujo's *Safety Culture: From Theory to Practice* makes a related point from the leadership side. Culture becomes visible through the decisions leaders reward, question, and allow to remain unresolved.
Conclusion: governance is the control before the control
The Boeing 737 MAX case shows that catastrophic risk can pass through competent teams when production pressure outruns safety governance. The decisive question is not whether an organization has a procedure. It is whether a leader can see the assumption, hear the challenge, own the residual risk, and stop the release before the system makes the decision for them. That is the leadership test.
Headline Podcast explores the human and organizational choices behind high-consequence work. Follow the podcast for conversations on safety leadership, and use this case as a prompt for your next decision-rights review.
Frequently asked questions
What does the Boeing 737 MAX case teach about safety leadership?
Was the Boeing 737 MAX problem only a software problem?
How does production pressure create safety risk?
What should a safety director audit after reading this case?
Can this lesson apply outside aviation?
About the author
Andreza Araújo
Safety Culture Expert | Senior EHS Executive
Andreza Araújo is a safety culture expert and senior EHS executive with more than 25 years of experience in environment, health and safety. She is a Civil Engineer and Occupational Safety Engineer from Unicamp, holds a Master's degree in Environmental Diplomacy from the University of Geneva, and completed sustainability studies at IMD Switzerland. Andreza has served in Global Head of EHS roles in Fortune 500 environments, leading cultural transformation programs across multinational operations. She has represented Brazil as a speaker at the United Nations in Paris and has spoken at the International Labour Organization in Turin. She is the author of more than 16 books on safety culture in Portuguese, Spanish, English and German. Her work has earned more than 10 EHS awards, including two recognitions from Indra Nooyi, former PepsiCo CEO.
- Civil & Safety Engineer (Unicamp)
- M.A. Environmental Diplomacy (University of Geneva)
- Sustainability Cert (IMD Switzerland)
- People Management & Coaching (Ohio University)
- UN Paris speaker representative for Brazil
- ILO Turin speaker
- LinkedIn Top Voice
- Indra Nooyi PepsiCo CEO recognition (2x)
Documentaries
Watch Andreza's documentaries
Three productions on safety culture, organizational failure and the human lessons behind major disasters.
Podcasts
Listen to Andreza's podcasts
She hosts three shows on safety leadership, EHS and organizational culture, in English and Portuguese.