Resilience Engineering and Learning from Normal Work: How Theory Becomes Practice

In brief: Resilience engineering describes how complex systems sustain safe operations. Learning from Normal Work operationalizes that description through 14 field-tested tools mapped to each cornerstone. This post traces the structural connections, shows where theory stops and practice starts, and presents the measured outcomes that bridge the gap.

Resilience Engineering and Learning from Normal Work: How Theory Becomes Practice

Resilience engineering tells you that your system adapts, drifts, and succeeds for the same structural reasons it occasionally fails. It does not tell you what to do about that on Monday morning. Learning from Normal Work was built to answer that question, and the connection between the two is structural, not rhetorical. Each of LFNW’s 14 tools maps to a specific element of resilience engineering’s framework, turning descriptions of how systems behave into actions that change the conditions where work happens.

Key findings

  • Resilience engineering’s four cornerstones (anticipating, monitoring, responding, learning) describe what a resilient system does, while Learning from Normal Work provides the tools to build each capacity at the workstation level.
  • After 20 years of resilience engineering research, 52% of published studies remain focused on theory rather than practical application (Righi, Saurin and Wachs, 2015).
  • Walk-Through Talk-Through surfaces three to 12 error traps per task that existing risk assessments miss (Psychology Applied, 2022-2026).
  • A Learning from Normal Work program delivered a 37% injury reduction in 18 months (Nazaruk, 2023).
  • IOGP Report 642, authored by Dr Marcin Nazaruk, codified the approach as the primary industry guidance for learning from normal work in oil and gas operations (IOGP, 2022).
  • Learning from Normal Work draws from resilience engineering alongside human factors, HOP, and systems thinking. It is an integration of multiple traditions, not a one-to-one translation of any single one.

What does resilience engineering actually describe?

Resilience engineering is a specific academic discipline founded in 2004 at the first symposium in Soderkoeping, Sweden, and codified in the 2006 volume by Hollnagel, Woods and Leveson. It studies how complex sociotechnical systems sustain required operations under both expected and unexpected conditions. For a full account of what resilience engineering is and where it came from, the pillar post covers its history, founding scholars, and intellectual roots.

The discipline’s central insight is that performance variability is normal and is the source of both success and failure. Workers adapt, adjust timing, reorder steps, and compensate for missing resources because that is how work gets done. Hollnagel’s Safety-II framework captured this by shifting the analytical focus from why things occasionally go wrong to how things usually go right (Hollnagel, 2014).

The four cornerstones of resilience engineering provide the dominant framework for organizing these ideas. They describe four capacities a resilient system needs: anticipating (considering future threats beyond historical frequencies), monitoring (tracking conditions that could become critical), responding (acting when conditions demand it), and learning (changing the system based on experience). These were formally articulated in Hollnagel’s 2009 chapter and fully developed in the 2011 guidebook.

The cornerstones are powerful as a diagnostic lens. They are limited as an implementation guide.

Four-panel diagram mapping each resilience engineering cornerstone to its corresponding Learning from Normal Work tools

Each cornerstone describes a capacity. Each tool builds it.

Why can resilience engineering not tell practitioners what to do?

The answer lies in the discipline’s origins. Resilience engineering emerged from cognitive systems engineering and organizational safety science, traditions built for description and explanation rather than for generating repeatable interventions (Hollnagel and Woods, 1983). The founding scholars studied how complex systems behave, and their methods were designed to reveal patterns, not to prescribe changes.

Righi, Saurin and Wachs (2015) conducted the most comprehensive review of resilience engineering research, examining 237 studies published between 2006 and 2014 and finding that 52% focused on theory rather than application. They called for design-science methods to bridge the gap between description and prescription. This is the prescriptive gap in resilience engineering.

The gap has structural causes that go beyond any single researcher’s choices. Within the founding group itself, three distinct programs developed:

  • Hollnagel pursued Safety-II as the applied face of resilience engineering, emphasizing performance variability and the WAI/WAD distinction
  • Woods focused on graceful extensibility and sustained adaptability at Ohio State, developing the formal theory of how systems stretch when surprise exceeds their design envelope (Woods, 2018)
  • Leveson developed STAMP and STPA as a parallel systems-theoretic tradition with a more explicitly prescriptive orientation

Le Coze (2022) mapped the ambiguities among these traditions and stressed that they represent distinct intellectual commitments rather than a unified prescriptive system.

After 20 years of development, no peer-reviewed validated measurement instrument exists for resilience engineering (Pillay and Morel, 2020). The Resilience Analysis Grid produces qualitative profiles rather than scores. FRAM maps functional couplings rather than prescribing specific changes. Both are valuable analytical lenses, but neither generates the operational guidance that a site supervisor needs during a pre-shift briefing.

That is the gap Learning from Normal Work was designed to fill.

How does Learning from Normal Work connect to each cornerstone?

The connection is not a marketing claim. It is documented in IOGP Report 642 (2022), in the ASSP Professional Safety Journal article (Nazaruk, 2023), and in the Competency Pathway curriculum (Nazaruk, 2025). The table below shows how each cornerstone translates into specific tools with defined processes and measurable outputs.

Resilience engineering cornerstone What the theory describes What Learning from Normal Work does Tools
Anticipating The system needs the capacity to consider future threats beyond historical event frequencies Error Predictor identifies specific error traps before the job starts, using measured error-producing condition multipliers. Error Trap Hunt finds constraints and error traps that standard hazard identification misses. Risk Assessment+ adds error traps and human factors to conventional risk assessments Error Predictor, Error Trap Hunt, Risk+
Monitoring The system needs to track conditions that could become critical, including deciding what matters and revising that focus PATH Dialogue tracks what workers experience during normal work, including where they adapt and where capacity feels insufficient. Performance Compass provides leading indicators based on learning and system conditions rather than lagging injury rates PATH Dialogue, Performance Compass
Responding The system needs readiness and capacity to address regular and irregular conditions through prepared and adaptable action Learning Teams examine the conditions that made outcomes probable and produce system-level improvements. Constraint Mapper uncovers the systemic constraints driving risky adaptations, giving the organization specific targets for intervention Learning Teams, Constraint Mapper
Learning The system needs to change knowledge, procedures, resources, design, or practice as a result of experience, from ordinary success as well as failure Walk-Through Talk-Through surfaces variability at the task level by walking through each step with the people who do the work. Decision Decoder analyses why decisions made sense at the time. Restorative Relations Framework rebuilds trust and creates the conditions for honest reporting Walk-Through Talk-Through, Decision Decoder, Restorative Relations Framework

The mapping is not one-to-one. Several tools serve more than one cornerstone, and the cornerstones themselves overlap in practice. A Walk-Through Talk-Through that surfaces an error trap contributes to both learning and anticipating. A PATH Dialogue that reveals a constraint contributes to both monitoring and responding.

What does the WAI/WAD gap look like when you have tools for it?

The distinction between Work-as-Imagined and Work-as-Done is central to resilience engineering and Safety-II. Hollnagel formalized the terminology, though the underlying insight has roots in Francophone ergonomics, where the distinction between travail prescrit (prescribed work) and travail reel (actual work) predates the 2000s by decades.

The concept is valuable. It tells leaders that procedures, plans, and training assumptions describe one version of work while workers experience another. What it does not provide is a method for systematically surfacing the gap and acting on what is found.

Walk-Through Talk-Through provides that method. A facilitator walks through a task step by step with the person who does it, comparing formal expectations with actual conditions at each stage. The process examines adjustments and trade-offs, maps tools, information, interfaces, and resources, identifies what enables successful work, and locates recurring pressure and capacity limits.

In practice, this means a supervisor using a Walk-Through Talk-Through can surface three to 12 error traps per task that existing risk assessments miss (Psychology Applied, 2022-2026). These are not behavioral observations. They are conditions in the work system that make errors more likely, conditions that standard procedures assume away because the procedure was written from Work-as-Imagined.

Two-column comparison showing what resilience engineering describes versus what Learning from Normal Work prescribes

Theory describes. Tools prescribe.

A WAI/WAD difference is not automatically good or bad. It may reflect expertise and practical adjustment, or it may indicate chronic underresourcing and procedural obsolescence. The inquiry must establish why it exists, what purpose it serves, and what risks it creates or reduces. Learning from Normal Work tools are designed for that inquiry, not for labeling deviations.

How does Learning from Normal Work handle what resilience engineering calls performance variability?

Resilience engineering’s central proposition is that performance variability is not deviation. It is the mechanism through which work succeeds. Hollnagel (2009) named the Efficiency-Thoroughness Trade-Off (ETTO) principle to capture how people routinely sacrifice thoroughness for efficiency, not out of negligence, but because demands exceed available time, information, or resources.

The conventional safety response treats variability as a compliance problem. The standard corrective action sequence is to retrain, remind, or restrict. These actions target the worker’s behavior while leaving the system’s constraints untouched, which is why resilience engineering reframes worker adaptations as diagnostic information rather than evidence of fault.

Learning from Normal Work treats variability the same way resilience engineering describes it, as information about system conditions, but adds the tools to act on that information:

  • PATH Dialogue gives supervisors a structured method for asking what workers actually experience, where they adapt, and where the gap between what the system provides and what the task demands is widest
  • Constraint Mapper traces adaptations back to the systemic constraints that produce them, so corrective actions target the constraint rather than the worker
  • Decision Decoder analyses why a decision made sense at the time, using the conditions the decision-maker faced rather than the outcome that followed
  • Procedure Gap Finder identifies where procedures do not match the reality of the task, whether because conditions changed, equipment was modified, or the procedure was written without consulting the people who do the work

The shift is from asking “why did the worker deviate?” to asking “what conditions made the adaptation necessary, and what should the system provide instead?”

What does IOGP Report 642 say about this connection?

IOGP Report 642 (2022), authored by Dr Marcin Nazaruk, is the first industry-level guidance document that connects resilience engineering concepts directly to operational practice in oil and gas. The report states that valuable safety lessons can be learned from ordinary work without waiting for an incident, and it sets out a practical sequence for doing so.

That sequence reflects the structural logic of resilience engineering: select representative normal work (monitoring), engage the people performing it (learning), compare formal expectations with actual conditions (WAI/WAD), examine adjustments and trade-offs (performance variability), map tools, information, interfaces, and resources (system conditions), identify what enables successful work (Safety-II), locate recurring pressure and capacity limits (anticipating), change conditions around work (responding), and review work after change (sustained learning).

The industry guidance in IOGP 642 sets out the approach. Psychology Applied’s 14 structured tools provide the operational layer for putting it into daily practice. The tools themselves are proprietary to Psychology Applied; the industry guidance is public.

Psychology Applied’s Competency Pathway, a nine-day blended program, teaches resilience engineering concepts alongside these practical tools (Nazaruk, 2025). It is one of the few structured professional training programs that covers RE theory and operational application in a single curriculum.

What does Learning from Normal Work not claim about resilience engineering?

Positioning matters because overstatement invites challenge. Learning from Normal Work does not claim to be the complete implementation of all resilience engineering theory. The ASSP article (Nazaruk, 2023) names RE as one source among several, alongside human factors, HOP, and systems thinking.

Several distinctions are worth keeping clear:

LFNW is an integration, not a one-to-one translation. RE provides the theoretical framework. HOP provides the practitioner principles. Human factors provides the science of how people interact with systems. Systems thinking provides the analytical lens. LFNW draws from all four and adds the operational tools.

Findings from LFNW tools may require specialist follow-up. A Walk-Through Talk-Through that surfaces a design problem may need ergonomic analysis. A Learning Team that identifies a control failure may need STPA or FRAM analysis to understand the system’s functional couplings. A Constraint Mapper output may point to staffing, procurement, or management-of-change processes that sit outside the safety function.

LFNW does not replace RE’s analytical methods. The Resilience Analysis Grid, FRAM, and STAMP/STPA each serve purposes that LFNW tools do not. LFNW generates the operational data; RE’s methods can analyze it at the system level.

Large statistic showing three to twelve error traps identified per task through Walk-Through Talk-Through

3-12 error traps per task that existing risk assessments miss (Psychology Applied, 2022-2026).

What measured outcomes connect the two?

A Learning from Normal Work program delivered a 37% reduction in injuries over 18 months, attracting an industry safety award (Nazaruk, 2023). This result came from deploying specific tools that turned resilience thinking into structured conversations and system-level changes.

The mechanism is traceable. Resilience engineering says the system needs to learn from normal operations, not just from failures. Learning from Normal Work provides the Walk-Through Talk-Through to surface what happens during normal work, the PATH Dialogue to track what workers experience, and the Learning Team to produce system-level changes from what is found. The injury reduction followed from changing system conditions that the tools surfaced, not from changing worker behavior.

For organizations exploring how to put resilience engineering into practice, the starting point is not theory. It is a structured conversation at the workstation with the person doing the work, using tools designed to reveal what the system provides, what it does not, and what the worker does to bridge the difference.

That conversation is where resilience engineering’s description meets Learning from Normal Work’s prescription. It is where why resilience engineering’s learning cornerstone demands more than root cause analysis stops being a theoretical argument and becomes an operational reality.

References

Cooper, M.D. (2022). The Emperor has no clothes: A critique of Safety-II. Safety Science, 152, 105047.

Hollnagel, E. (2009). The four cornerstones of resilience engineering. In Nemeth, C., Hollnagel, E., and Dekker, S. (Eds.), Resilience Engineering Perspectives, Volume 2: Preparation and Restoration. Ashgate.

Hollnagel, E. (2009). The ETTO Principle: Efficiency-Thoroughness Trade-Off. Ashgate.

Hollnagel, E. (2011). Resilience Engineering in Practice: A Guidebook. Ashgate.

Hollnagel, E. (2014). Safety-I and Safety-II: The Past and Future of Safety Management. Ashgate.

Hollnagel, E. and Woods, D.D. (1983). Cognitive systems engineering: New wine in new bottles. International Journal of Man-Machine Studies, 18(6), 583-600.

Hollnagel, E., Woods, D.D. and Leveson, N. (Eds.) (2006). Resilience Engineering: Concepts and Precepts. Ashgate.

IOGP (2022). Report 642: How to Learn When Nothing Goes Wrong: A Guide to Learning from Normal Work. Lead author: Dr Marcin Nazaruk.

Le Coze, J.-C. (2022). The ‘new view’ of human error. Origins, ambiguities, successes and critiques. Safety Science, 154, 105853.

Nazaruk, M. (2023). Learning from Normal Work: How to Proactively Reduce Risk When Nothing Goes Wrong. Professional Safety Journal (ASSP).

Pillay, M. and Morel, G. (2020). Measuring Resilience Engineering: An Integrative Review and Framework for Benchmarking Organisational Safety. Safety, 6(3), 37.

Psychology Applied (2022-2026). Implementation data: error traps identified per task across client engagements.

Righi, A.W., Saurin, T.A. and Wachs, P. (2015). A systematic literature review of resilience engineering: Research areas and a research agenda proposal. Reliability Engineering and System Safety, 141, 142-152.

Woods, D.D. (2015). Four concepts for resilience and the implications for the future of resilience engineering. Reliability Engineering and System Safety, 141, 5-9.

Woods, D.D. (2018). The theory of graceful extensibility: Basic rules that govern adaptive systems. Environment Systems and Decisions, 38, 433-457.

Frequently asked questions

Where to go next