Critical systems depend on more than equipment, infrastructure and technology. They also depend on people remembering why things are done in a particular way.
A serious incident happens. It is investigated. Something is learned. A procedure changes or a safeguard is introduced. At the time, everyone understands why. Then the years pass.
People leave. Managers change. Technology is replaced. Documents are rewritten. The incident itself becomes something that happened a long time ago. The safeguard may remain. The reason for it can slowly disappear.
This bulletin looks at what happens when a system still carries the lessons of the past but no longer remembers why they matter. It is part of the open-access archive of bulletins and studies.
Imagine a workplace where an important process requires two checks before something can proceed.
It has been done that way for years.
A new manager arrives and asks why both checks are necessary.
Nobody is quite sure.
The procedure says that two checks are required, but it does not explain why. The people who introduced the rule left years ago.
It begins to look like unnecessary work.
So the process is simplified.
What nobody remembers is that the second check was introduced after an earlier failure. The problem has not happened since.
That could easily be taken as evidence that the safeguard is no longer needed.
But there is another possibility.
Perhaps the problem has not happened because the safeguard has been working.
This creates a difficult question.
How do we tell the difference between a rule that has outlived its purpose and a rule whose purpose has simply been forgotten?
Not everything an organisation knows is written down.
Experienced people often carry knowledge that is difficult to see until they leave.
They remember previous failures. They know which parts of a system behave strangely. They know why certain shortcuts are avoided and why apparently unnecessary steps were introduced.
Some of that knowledge makes its way into procedures and documentation.
Some does not.
This means losing experienced staff can involve more than losing skills.
It can also mean losing part of the history of the system.
The equipment may remain. The procedures may remain. The organisation may continue operating normally.
But some of the understanding behind those procedures has gone.
This is one way institutional memory can slowly weaken without anyone noticing. The foundational study on Incident Memory explores how the lessons of past events are preserved, and how they can be lost.
Documentation helps preserve knowledge, but documentation has limits.
A procedure can tell someone what to do without explaining why they are doing it.
Over time, documents are also cleaned up, shortened and rewritten. Old explanations disappear because they no longer seem important.
Eventually an organisation may inherit a collection of rules without the history that produced them.
That matters because rules without explanations are easier to question.
Sometimes questioning them is exactly the right thing to do. Systems change, and old controls can become unnecessary.
But removing something is harder to judge when nobody remembers what problem it was originally intended to solve.
The question of how institutional memory survives as systems and governance change was raised in Issue 01. This bulletin returns to that question from a slightly different angle.
The issue is not that old rules should always be kept.
It is whether the organisation still has enough memory to understand what it is changing.
There is a strange problem with safeguards that work well.
When something prevents failure for long enough, the failure itself becomes less visible.
Years without an incident can gradually change how a risk is perceived.
People begin to ask why so much effort is being spent preventing something that never seems to happen.
That can be perfectly reasonable.
But absence of failure does not always mean absence of risk.
Sometimes it means the protection is doing its job.
This can happen with maintenance, safety procedures, backup arrangements, security controls and many other parts of critical systems.
The longer something works, the easier it can become to forget what conditions existed before it was introduced.
We normally think about dependencies as things a system needs in order to operate.
Power.
Networks.
Suppliers.
Equipment.
Specialist staff.
But systems can also depend on accumulated knowledge.
Someone needs to remember what has been tried before.
Someone needs to understand why an unusual safeguard exists.
Someone needs to recognise a warning sign because they have seen it before.
When that knowledge disappears, the physical system may look exactly the same.
What has changed is the organisation's ability to understand it.
That makes memory a particularly difficult dependency to see.
We often discover that it was important only after it has gone.
Systems change continuously.
People leave, equipment is replaced and procedures are rewritten. Some loss of knowledge is unavoidable.
The more difficult question is whether the important lessons survive those changes. A system can continue to operate while slowly losing the history that explains why it operates the way it does.
That loss may remain invisible for years. Sometimes the first sign that something important has been forgotten is when the same lesson has to be learned again.