01

Quick answer

See the highlighted block above. Drift is a slow process, which makes it different from a weak signal , a weak signal is a faint data point; drift is the current that moves the whole operation. The two are related: drift is one of the things weak signals can be early evidence of.

02

What operational drift is

Every operation is designed with margin, a distance between how the work is meant to be done and the point at which it becomes unsafe. Drift is the gradual consumption of that margin, not through any decision to be unsafe, but through a long series of small, locally sensible adaptations.

Safety scholarship has described this from several angles, and they agree on the shape. Jens Rasmussen described systems migrating toward the boundary of safe operation under the steady pressure of efficiency and workload. Sidney Dekker called the result drift into failure, failure produced not by a broken component but by an organisation slowly adapting its way to the edge. Diane Vaughan, studying the Challenger accident, named the mechanism the normalisation of deviance: each deviation that passes without harm becomes the accepted baseline for the next.

The common thread is that drift is a property of normal, well-intentioned work under pressure, not of recklessness. That is what makes it the hardest risk to manage with a system built around events and rule-breaking. Drift breaks no rule on any given day; it simply moves the day.

03

Why drift happens

Drift is not an accident of bad operators; it is the predictable result of ordinary forces acting on ordinary people doing demanding work.

The efficiency-thoroughness trade-off. Erik Hollnagel observed that people constantly trade between doing a task thoroughly and doing it efficiently, because there is rarely time and resource to maximise both. Each trade is reasonable in its moment. Drift is what accumulates when the balance tips, slightly and repeatedly, toward efficiency, usually because that is what the schedule, the workload and the unspoken expectations reward.

Local rationality. The adaptations that produce drift make sense from where the person stands. A step is skipped because, in their experience, it never changes the outcome. A procedure is shortcut because the written version assumes conditions that do not hold on the line. People are not being careless; they are being locally sensible, with the information and pressures they have.

Success hides the cost.The deepest driver is that drift is reinforced by success. Every time a shortcut works, it gathers evidence that it is fine. The margin that was consumed is invisible, nothing happened, so the only feedback is positive. The operation learns, correctly on the available evidence and dangerously in fact, that the new way is safe. The gap between the procedure (work-as-imagined) and the practice (work-as-done) widens with the operation's full, untroubled confidence.

04

Why nobody reports it

Here is the part that should worry any head of safety. The entire safety reporting apparatus, the occurrence report, the hazard report, the audit finding, is built to capture events and deviations. Drift produces neither.

To the people inside a drifted operation, the current way of working is not a deviation. It is simply how the job is done, the normal that everyone shares and no one questions. There is no moment of departure to notice, no breach to flag, no occurrence to file. A reporting system waits for someone to recognise something as wrong and tell it. Drift, by its nature, is the thing nobody recognises as wrong, because it arrived too slowly and never caused harm. The trigger never fires.

This is why drift is invisible to a conformance check and to a report-fed SMS alike. A compliance audit samples the documented system, which still looks correct. The reporting system waits for an event that, by definition, has not happened yet. Drift sits precisely in the blind spot between them, one of the structural reasons covered in why mature SMS programs miss emerging risk. The operation can be fully compliant, fully reporting, and steadily drifting, all at once.

05

Making drift visible

Because drift will not report itself, the only way to manage it is to look for it on purpose. That means changing what the safety function watches.

  • Compare work-as-done with work-as-imagined. Use normal-operations observation and line monitoring of routine, uneventful flights to see how the task is actually performed, not how the manual assumes it is. The gap between the two is the measure of drift.
  • Watch trends, not thresholds. Drift shows up as a slow slope inside the limits long before it crosses one. A measure that only fires at a threshold is built to miss it; a leading indicator on adherence, read for its direction, is built to catch it.
  • Connect signals across modules. A widening gap usually leaves faint traces in several places, a recurring minor write-up, a competency repeatedly at the margin, an exceedance trending the wrong way. Read together against the same barrier, they describe the drift that no single one reports.
  • Make it safe to name. Drift comes from real pressures, so surfacing it has to be a learning conversation, not a disciplinary one. A Just Cultureis what lets people say “this is how we actually do it, and here is why”, which is the only honest starting point for closing the gap.

Doing this continuously, across the whole operation, is the work of aviation safety intelligence: connecting the faint traces and reading them for direction, so the migration toward the edge becomes visible while there is still margin to recover. In eAviora's barrier engine each barrier carries a live effectiveness state, effective, partially effective, ineffective or missing, updated as events touch it, and a Safety Action Group trigger engine surfaces repeated-pattern signals such as three or more events in the same family within ninety days, so the cross-module read that reveals drift happens by default rather than by hand. The broader operating rhythm is set out in how airlines detect emerging risk before incidents occur.

06

Frequently asked questions

What is operational drift in aviation?

Operational drift is the slow, often unnoticed migration of how work is actually done away from how it was designed to be done. It happens one reasonable adjustment at a time, a step skipped because it rarely matters, a tolerance quietly widened because the tighter one was impractical, until the everyday operation sits much closer to the edge of safe than anyone intended. No single step is a violation, and no single step feels dangerous, which is exactly why drift is so hard to see from inside it.

What is the normalisation of deviance?

It is the process by which a deviation from the standard, having been done without harm, gradually becomes accepted as normal. The first time a shortcut is taken it feels like a shortcut; after it works a hundred times it simply feels like the way the job is done. The term was popularised in the study of the Challenger accident. In aviation it describes how a practice that would have raised concern if proposed openly becomes routine when it arrives gradually and never causes an immediate problem.

Why does operational drift go unreported?

Because there is nothing that feels report-worthy. Reporting systems are built around events and deviations, and drift produces neither, it produces a new normal. To the people living inside the drifted operation, the current way of working is simply how things are done; it does not register as a deviation to be reported. There is no occurrence, no breach, no obvious moment. The risk is real and the trigger that would put it into the safety system never fires.

How is drift different from a violation?

A violation is a discrete, conscious departure from a rule. Drift is gradual, collective and largely unconscious, and usually well-intentioned, made up of adaptations that help get the job done under real pressure. Treating drift as a series of violations to be disciplined is both unfair and counter-productive: it drives the adaptations underground without removing the pressures that created them. Drift is better understood as a signal that work-as-done and work-as-imagined have diverged, and that the gap needs managing.

How can an airline detect operational drift?

By deliberately comparing how work is actually done with how procedures assume it is done, and by watching for the slow trends drift produces rather than waiting for an event. Practical methods include normal-operations observation, line monitoring of routine flights, leading indicators on procedure adherence, and connecting signals across modules so a steadily widening gap shows up before it produces an occurrence. The point is to look for drift on purpose, because it will not report itself.