Still the case with most government procurement processes.
If you manage to jump through all the "certification" hoops, you can mark up your product to an insane rate and then lobby for certification to be expanded.
Then the government has a list of "approved" vendors who are basically in the "certification" club and sometimes you can only find a product of a particular type only by a particular company and when you ask them for the price, your jaw drops (especially if there is a 20x cheaper COTS one on the market at the same time).
Second, I'm sure big corporations take advantage of certification process to keep smaller players out but certification is extremely important, suppliers would not follow many of the safety requirements otherwise.
That buckle is a standard UI across every commercial aircraft in the World. That is very important in emergency situations. Billions of people know pull-to-release.
There is really no advantage to changing the design unless we also change to three-point harnesses as in cars. But that won't happen for cost reasons ( ' safety is our number one priority, profit is our zeroth' ).
I don't buy that. Process is CYA first and foremost. If something happens, you get to say, "We adhere to the strictest processes and best practices... blah, blah, blah."
Was there a lack of process in the space shuttle disasters? The flight 9525 crash? The Titanic?
You want safety? Get a third party (insurer, certification body, etc.) to assume responsibility (financial, legal, political, etc.) if anything goes wrong, regardless of the root cause. You might not get perfect safety, but you'll get responsibility, which is the next best thing.
Rigid processes are about diffusing responsibility, not taking it.
challanger: http://www.onlineethics.org/cms/12722.aspx http://www.engineering.com/Library/ArticlesPage/tabid/85/Art...
columbia: http://www.aero-news.net/index.cfm?do=main.textpost&id=9fe7f...
(notice that engineering requested hard photographic data to assess the damage, and her used gut feeling)
Well, as mgmt said, there was no evidence the O-rings were unsafe outside their operating limitations - because they'd never been tested at those temperatures before. I know, it's Twilight Zone material, but they found a hole in the launch rules (process) and ran with it. Previous O-ring failures had been within specs, so as far as they were concerned, it wasn't a temp issue, it was a known design flaw to be lived with.
> columbia
As for that article, pictures really didn't matter at that point so it wasn't "one decision." Rescue would have been a foolhardy venture more likely to kill both crews.
Columbia wasn't about mgmt, it was about engineering folks being placated by decades of success and making wrong assumptions about debris. There wasn't any workable solution anyway, it was a design flaw of the launch stack. The only solution was to never fly, and engineers weren't lined up to kill their own program.
Engineering knew pretty well that wasn't the case, and that is not how tolerance works.
Feynman in his reports goes a long way to list all the overrides management did and how much the whole shuttle program was built on wishful thinking.
http://science.ksc.nasa.gov/shuttle/missions/51-l/docs/roger...
Insurance also doesn't come free. The US government can also take on more risk than any particular insurer, so by purchasing those contracts would be in effect wasting taxpayer money.
The consequences of something like a failed launch can be hard to quantify economically. There is clearly opportunity cost for missed intelligence not having the satellite in orbit when it is needed. What happens if the satellite crashes in an unfriendly place, losing the exclusivity to a bit of technology could be very damaging as well. I think you would find it hard to place a particular insurable value on those; but minimizing that risk obviously costs money.
How much that risk minimization is worth is a question that I can't answer.
What a marvelously tame way of describing such a thing.