I’m deep into my ATP training right now, and one thing keeps coming up more than any procedure or performance chart: how we actually think about risk.
In light of general aviation safety, I’ve been thinking a lot about maximizing survival and minimizing the chance of becoming another aviation news headline. The more I look at it, the more convinced I am that most of us are working with the wrong mental model.
### The Comforting Statistics We All Repeat
We like clean numbers.
“Piston engines fail every 1,000–10,000 hours.”
“Jet engines are good for 100,000 hours, and with two of them you’ll never have to worry about it.”
Those statements feel scientific. They give us a sense of control. They’re also almost useless for the decisions that actually keep you alive.
The real world is messy. It’s gray. It’s highly conditional. The probability of a serious problem on any given flight is not some fixed industry average you can pull from a table. It changes dramatically with the specific combination of airplane, pilot, environment, and pressure that exists *on that flight*.
A much better mental model is to throw those statistics away and build a risk model for every single flight you take. Because that is much closer to reality.
### Conditional Probability Is Everything
Some flights truly are in the 1-in-10-million range. You would have to repeat them ten million times before you expect an incident. Others—if we’re being intellectually honest—are closer to 1 in 100. Repeat that flight a hundred times and you will eventually have a serious accident.
We’ve all been in versions of this scenario:
You’re in an airplane you’re not yet intimately familiar with. It’s night. It’s IMC. A cold front is moving in, so the window is closing and the pressure to go now is real. The autopilot isn’t working. One fuel gauge is sticky. One manifold pressure gauge is sticky. But it’s only 30 nautical miles, you know both airports well, you’ve been averaging 50 hours a month, and you feel current and confident.
Most serious pilots have stood at that decision point. Some of us have gone. Some of us have stayed. Very few of us have done a clear-eyed calculation of the actual risk.
Stack two or three failures into that flight and it becomes a news headline. The likelihood of those failures lining up on a flight like that is not vanishingly small. It’s probably closer to 1 in 100 than we want to admit.
### Risk Asymmetry and the Insurance-Model Mindset
The risk asymmetry in aviation is far greater than our human meat computers naturally appreciate. We are not good at multiplying low-probability events that become high-probability under specific conditions.
The practical solution is to train yourself to become more computer-like in risk analysis—closer to an insurance underwriting model than to gut feel. Stop asking the binary question “Am I good to make this flight?” Start assigning a numerical risk score.
That single shift opens up a much more interesting conversation: mitigation.
Cancelling is only one possible outcome. Once you have a number, you can ask: *How do I move this flight from roughly 1 in 100 to 1 in 10,000?* In the scenario above, simply waiting until daylight and VFR conditions often does most of the work. The same airplane, the same pilot, the same route—just shifted ten hours—suddenly becomes something you can handle even with two or three stacked failures.
That kind of deliberate risk accounting does two valuable things. First, it actually lowers accident likelihood. Second, it reduces or eliminates those miserable hours spent airborne wishing you were already on the ground.
### How the Airlines Solved the Same Problem Differently
The airlines took a completely different approach. They don’t really allow meaningful risk to exist in the first place.
Part 121 is amazingly safe—not primarily because the pilots are exceptionally well trained (though many of them are phenomenal and receive outstanding training), but because the *system* itself is designed to eliminate risk. The airplanes are engineered and maintained so they essentially cannot fail in normal operations. The airspace, ATC, runway, and operational structure are likewise designed so the system as a whole does not fail. Of course I’m exaggerating a bit—failures still occur—but the spirit of the statement is close to the truth. The entire architecture is built to keep the probability of a serious event extraordinarily low before the pilot even starts the engines.
In Part 91 and Part 135 we have far more freedom. The system and the aircraft are deliberately more flexible, which allows the pilot to make many more decisions. That flexibility is one of the great joys of general aviation and on-demand flying. It is also why we still see unfortunate headlines and the loss of precious life. The system does not eliminate risk for us. We are expected to manage it ourselves—flight by flight.
### Why “Personal Minimums” Fall Short
The traditional tool most of us were taught—personal minimums—has two structural problems.
First, they tend to erode. Over time the numbers get lower and lower until they effectively disappear, and you find yourself flying approaches that are below the minima you once set for yourself. That is the opposite of good risk management.
Second, they are binary. You either go or you don’t. There is no built-in mechanism for the more sophisticated work of identifying the specific risk drivers and actively reducing them.
I think the FAA is somewhat naïve here. Teaching acronyms like PAVE, IMSAFE, or the 5Ps is a start, but those tools remain fairly shallow and not particularly actionable for the complex, real-world decisions we face when flying high-performance airplanes in actual weather. They don’t force the quantitative thinking that would make the difference on the nights when the margins are thin.
### The Practical Takeaway
In Part 91 and 135 we do not have the airline-style system that removes risk at the architectural level. That means the responsibility sits with us. Treat every flight as its own risk model. Assign a rough numerical probability instead of a yes/no. Then actively look for the highest-leverage mitigations available—time of day, weather window, equipment status, route, fuel state, currency on type, whatever the actual drivers are.
You will still fly most of the trips you want to fly. You will simply fly them under conditions that give you far more margin when things inevitably get messy. And you will spend a lot less time in the airplane negotiating with yourself about whether this was a good idea.
That’s the mental model I’m trying to lock in as I finish the ATP. It’s less comforting than the old statistics, but it feels a lot closer to the truth.
Comments
Post a Comment