The self-certification here wasn’t part of the chain of events that led to the crashes; it appears to have been related to other issues the FAA uncovered as a side effect of their investigation.
The self-certification here wasn’t part of the chain of events that led to the crashes; it appears to have been related to other issues the FAA uncovered as a side effect of their investigation.
One component of that chain of failures is the self-certification process. If the FAA had the resource and mandate to actually understand each aircraft design change, then it's very likely (not guaranteed, but very likely) that the MCAS design having a single point of failure on the AoA sensor would have been flagged as problematic by FAA.
DOT OIG disagrees that this played no role. Here's from Page 2 of their report, i.e. the entire "Findings" summary:
While FAA and Boeing followed the established certification process for the 737 MAX 8, we identified limitations in FAA’s guidance and processes that impacted certification and led to a significant misunderstanding of the Maneuvering Characteristics Augmentation System (MCAS), the flight control software identified as contributing to the two accidents. First, FAA’s certification guidance does not adequately address integrating new technologies into existing aircraft models. Second, FAA did not have a complete understanding of Boeing’s safety assessments performed on MCAS until after the first accident. Communication gaps further hindered the effectiveness of the certification process. In addition, management and oversight weaknesses limit FAA’s ability to assess and mitigate risks with the Boeing ODA. For example, FAA has not yet implemented a risk-based approach to ODA oversight, and engineers in FAA’s Boeing oversight office continue to face challenges in balancing certification and oversight responsibilities. Moreover, the Boeing ODA process and structure do not ensure ODA personnel are adequately independent. While the Agency has taken steps to develop a risk-based oversight model and address concerns of undue pressure at the Boeing ODA, it is not clear that FAA’s current oversight structure and processes can effectively identify future high-risk safety concerns at the ODA.
https://www.oig.dot.gov/sites/default/files/FAA%20Certificat...
Maybe DOT OIG is confused? Big if true!
There are many types of designation in the system; your quote above is _not_ about Production Certification ODA staff (which this article is about), and indeed there is no world where Production Certification ODA would be expected to find the MCAS issue your quote is about. Those would be Type Certification ODA folks.
The self-certification process (airworthiness certificates) is the manufacturer (rather than the regulator's inspectors) stating "this one specific aircraft with serial number _______ has been built according to the design covered by its type certificate". Nothing more.
In other words, an airworthiness certificate only specifies that a specific aircraft is airworthy /because/ it is built according to an airworthy design. Whether the design is safe or not has always only been up to the regulator to decide. In this case, the regulator dropped the ball and approved an unsafe design. If Boeing was not allowed to self-certify their own aircraft, the FAA would still have issued airworthiness certificates for them, including the two aircraft that would have gone on to kill hundreds of people, because they were built according to the design the FAA approved.
You should read the OIG report. It actually discusses all of this. It is absolutely possible an FAA cert would've missed the MCAS issue as well, but as OIG points out, one variable was significant commercial pressure on Boeing's ODA to approve the (iterated-since-type-approved)-MCAS. Presumably FAA staff would be less susceptible to this type of commercial pressure.