Skip to main content

Article

Managing shared risk to mitigate major aviation losses

In the first two editions of Cross Check, we explored two related ideas: first, that the aviation system is becoming more complex and interdependent; and second, that organisations need a safety intelligence strategy to turn data into actionable risk insight that creates a greater level of foresight and supports proactive decision-making.

In the first two editions of Cross Check, we explored two related ideas: first, that the aviation system is becoming more complex and interdependent; and second, that organisations need a safety intelligence strategy to turn data into actionable risk insight that creates a greater level of foresight and supports proactive decision-making.

Recent events, including the mid-air collision in Washington, DC, in January 2025, referenced in a previous article, have reinforced how safety-critical risks can, and do, emerge at the interfaces among multiple stakeholders rather than within any one organisation. In this article, we build on those themes to examine why aviation needs a more integrated, total-system approach to risk management, and how an enhanced connected model could help the industry to more effectively identify, understand, and mitigate the conditions that could lead to major operational, financial, and reputational loss events.

Are safety management systems enough?

Aviation operational risk has always depended on coordination across multiple parties, but the operating environment is now more interconnected, more specialised, and more pressured than the models often used to manage it.

Airlines, airports, air navigation service providers (ANSPs), ground handlers, maintenance organisations, manufacturers, and other service partners each manage safety within their own remit through formal safety management system (SMS) requirements, yet many of the most consequential risks no longer lie completely within those boundaries. They emerge through competing priorities, fragmented information, and unclear ownership across organisations’ interfaces. In that context, even a mature SMS can leave important exposures insufficiently identified or managed if they are designed primarily around a single-entity view.

The pushback collision involving a Boeing 737 at London Stansted in August 2024 showed how risk at the aircraft-airport-ground handling interface can arise not from a single failure, but from the interaction of operator procedures, ground crew actions, and airport design and markings. Similarly, the collision between a Boeing 737 and de-icing vehicles at Denver in March 2026 highlighted how aircraft movement, contractor operations, communication protocols, and local operating controls must work together to more effectively manage risk in shared operational spaces.

This does not mean SMS is no longer fit for purpose; it remains the foundation of aviation safety, providing organisations with a structured way to identify hazards, assess risk, and determine whether controls are present and effective. But SMS was largely designed for a single accountable entity, while many of today’s most significant risks are created, transferred, or amplified across the boundaries of multiple entities.

As a result, organisations can have mature internal processes and still miss how risk is building across external interfaces. When data, decision-making, and control ownership are fragmented across multiple parties, the result is not necessarily an absence of safety activity, but an absence of shared safety understanding and, at times, disjointed actions.

How can this be addressed?

What is needed next is not a replacement for SMS, but an additional layer of oversight and coordination allowing for a total system risk-based approach (TSRBA). That means looking beyond the performance of individual organisations to understand how risk originates and is managed across the wider system of operators, airports, service providers, regulators, and suppliers. A TSRBA shifts the focus from whether each party is managing its own activities adequately to whether the system as a whole is identifying weak signals, aligning controls, and responding effectively at critical interfaces.

For risk and business leaders, the question is simple: Can your organisation visualise and manage the risks that lie beyond its own boundaries? We believe that the following four capabilities matter most.

 

Identify where safety-critical activity crosses organisational boundaries: between airlines and airports, operators and ground handlers, operators and maintenance providers, airports and fuel suppliers, or flight crews and ANSPs. In many cases, the most material exposures lie not within a single task, but in the assumptions and dependencies that connect tasks.

Once those interfaces are visible, organisations need to identify which risks are genuinely shared and which safeguards depend on coordinated action. This requires clarity on where one party’s control ends, where another’s begins, and which defences only work if several parties perform their roles as intended. Without that clarity, protections can appear sound on paper but be fragmented in practice.

Many organisations now invest in analysing their own safety data, but interface risk is difficult to understand if each party sees only part of the picture. A TSRBA therefore depends on mechanisms for sharing relevant occurrence data, weak signals, operational trends, and lessons learned across organisational boundaries. The aim is not unrestricted transparency and total data sharing, but sufficient shared visibility to spot common emerging patterns early and act on them.

Where risk is shared, oversight also needs a shared forum. That may mean regular cross-organisational reviews focused on specific interfaces, agreed escalation routes for recurring issues, and clearer leadership attention on risks that no single party can resolve alone. The aim is to minimise the possibility that a risk with multiple owners ends up with no effective owner.

Good practice

In the UK, London Luton Airport’s “Safety Stack” offers a practical example of how a TSRBA can work. By bringing together airlines, air traffic services, ground handlers, and other operational partners to share safety insights, harmonise procedures, and address risks collectively, the initiative has been associated with lower incident rates, a stronger reporting culture, and faster resolution of cross-organisational safety issues.

In the Netherlands, Amsterdam Schiphol Airport’s Integral Safety model offers another example of a TSRBA in practice, bringing together the airport, airlines, air traffic control, and ground handlers to manage the safety risks that arise among their operations rather than within each organisation in isolation. By creating a formal structure for jointly identifying, assessing, and addressing interface risk, the model shows how shared governance can help to build a more coordinated and resilient safety system across a complex airport environment.

Brokers, insurers, and independent risk advisers can also help to enable a greater level of interconnection. As they often see risk across multiple organisations, they can help to connect operational, safety, and insurance perspectives that might otherwise remain separate. They can support more structured dialogue across stakeholders, help the stakeholders to challenge blind spots at key interfaces, and bring comparative insights from broad market experience. That can help organisations translate operational concerns into strategic risk decisions and strengthen controls before losses occur.

The next step in aviation safety is to extend the logic of SMS to the network of relationships through which modern aviation actually operates and develop a total system risk-based approach. For risk managers and senior leaders, that means asking a broader set of questions:

  • Where do our most important cross-boundary risks lie?
  • Who shares ownership of them?
  • How are they governed?
  • What evidence do we have that the safeguards will hold under pressure?

Those are the questions leaders should now be putting to their safety, operations, and assurance teams. Organisations that can answer them tend to be better placed to identify emerging threats early, strengthen resilience across the operating system, and reduce the likelihood of the next major loss event.

Contact us and learn how a total system risk-based approach can help you spot interface risks, strengthen safeguards, and act sooner on emerging threats.