The FAA spent two years fixing the defect and never checked whether the decision-making that produced it had changed.
Why This Matters
Two crashes, five months apart, killed 346 people over a single design decision that was approved by someone who did not understand it.
The correction that followed is treated, in public, as complete. The regulator's own report never claims to have checked whether the organisation that produced the failure had itself changed.
The same pattern shows up at three different levels of the same case, an engineer, a company's leadership, and a regulator investigating its own conduct, which is what makes this worth more than one read.
A senior engineer told a congressional committee, under oath, that he had approved a flight-control system without understanding how it worked. Asked to confirm it directly, he said: "That is correct."
Michael Teal was Boeing's Chief Project Engineer for the 737 MAX, and Deputy Program Manager of the entire programme. In March 2016, at a leadership review meeting in Everett, Washington, he approved a redesign of a flight control function called MCAS, so that it would activate at lower speeds than originally planned. He did not know, at the moment he signed, thatMCAS depended on a single angle-of-attack sensor with no backup. He did not know it could fire repeatedly on the same fault, resetting itself each time. He did not know that Boeing's own test pilot had needed more than ten seconds to recover from an uncommanded MCAS activation in a simulator three years earlier, a delay Boeing's own engineers had already classified as catastrophic. Years later, asked to confirm all of this directly, he did not dispute a word of it.
The room he approved it in had a clock in it. Boeing's programme leadership had installed a countdown timer in the MAX conference room years before, marking milestones: engine power on, first flight. Keith Leverkuhn, the programme's Vice President and General Manager, later called it "an excitement generator." Teal described it as something closer to a discipline device, telling the Committee it was "very prevalent to keep everyone on schedule to get the airplane flying." Nobody in that room needed to say the word deadline. The room said it for them. This is where Strategic Conviction, whether a commitment is tested or simply carried along by momentum, failed first, years before MCAS itself existed.
The warning that should have stopped this had already been written down, more than once. In December 2015, an engineer working inside Boeing's FAA-delegated certification unit asked a direct question in writing: were they vulnerable to single AOA sensor failures with the MCAS implementation, or was there some checking that occurred. No resolution reached the people above him. Six months later, another engineer flagged that MCAS was fighting a test pilot's owncontrol inputs during a low speed manoeuvre. A colleague's written reply dismissed it as not a safety issue, other than that the pilot could fight the MCAS input. That sentence is, almost word for word, a description of what happened on both aircraft that later crashed. The picture that reached Teal in March 2016 was Decision Posture already narrowed before it got to him, not because anyone lied to him directly, but because the certification paperwork was never updatedto describe what the redesign actually did.
The most damning fact in the entire record predates all of this. In November 2012, a Boeing testpilot ran an MCAS failure scenario in a flight simulator and failed to recover within ten seconds, the margin FAA guidance treats as the boundary between manageable and catastrophic. Boeing logged that result, then logged it again in an internal coordination document in 2015, again in 2016, again in 2017, and once more in 2018, after the aircraft had already been certified. Six separate internal records of a test failure serious enough to end a certification programme, and Boeing has told congressional investigators it can find no evidence any of them were ever given to the regulator.
None of this happened in a vacuum of commercial pressure. Mark Forkner, the 737's chief technical pilot, spent much of 2016 and 2017 working to keep MAX pilots out of a flight simulator entirely, so airlines transitioning from the older 737 NG would not face the cost and delay of full retraining. "There is absolutely no reason to require your pilots to require a MAX simulator to begin flying the MAX," he wrote to one airline. To another, on the same question: "Boeing will not allow that to happen. We'll go face to face with any regulator who tries to make that a requirement." When one airline's engineers pushed back anyway, he described it to a colleague by instant message: "Now friggin Lion Air might need a sim to fly the MAX, and maybe because of their own stupidity. I'm scrambling to figure out how to unscrew this now! idiots." A few months later, describing to a colleague how he had talked a foreign airline out of extra training requirements: "I just jedi mind tricked this fools. I should be given $1000 every time I take one of these calls. I save this company a sick amount of $$$$." The same year he was fighting this battle, Forkner was also the person who, on the morning MCAS was redesigned, asked the FAA to remove references to it from the pilot manual. What airlines were told and what Forkner privately knew were two different accounts of the same aircraft, a Stakeholder Reality failure as clean as this record produces.
Ed Pierson was a senior manager on Boeing's 737 production line in Renton. He resigned in August 2018, two months before Lion Air, after warning his own management that the production system was in the worst state he had seen in his career. After the crash killed 189 people, he wrote directly to Boeing's chief executive, Dennis Muilenburg: "Admittedly the information I need to share isn't favorable to Boeing, but I believe it is very important nonetheless." Weeks later, writing to Boeing's own general counsel, he said employees with twenty years of experience on the 737 line had told him they had never seen the production system in such bad shape, and that the question was whether there was "the ethical leadership and will to set aside pride and potential liabilities to get to the truth." Production did not slow. It kept ramping up through the winter. Only in April 2019, after the second crash had already happened, did Boeing reduce the build rate at all.

None of the people in this record were short of capability. What was short, at every one of thesemoments, was the distance between what they knew and the point where a decision was actually being made.
The clearest single instance of that sits inside the regulator, not the manufacturer. Five weeks after Lion Air, the FAA completed a formal risk analysis using its own established methodology and presented it to its Seattle Corrective Action Review Board on 11 December 2018. The finding, using an assumption the congressional investigation later called a gross overestimate ofhow reliably pilots would react: without a design fix, the MCAS fault could produce more than fifteen further fatal crashes and over 2,900 more deaths across the fleet's operating life, a rate of roughly one fatal crash every two years for thirty years. The aircraft did not stop flying. Boeingdelivered around 150 more of them in the following months, growing the in-service fleet by nearly half. Three months after that board meeting, Ethiopian Airlines Flight 302 went down, killing all 157 people aboard. A real, quantified finding reached a review board and converted into no dated, owned action, an Execution Integrity failure at the highest stakes in this entire record.

When investigators later asked who inside FAA leadership had been briefed on that analysis, the FAA's formal answer described who had prepared it, not who had known about it, a non-answer the congressional report calls exactly that. The FAA's own Associate Administrator for Aviation Safety, asked directly about the analysis, said only: "I'm not familiar with the details of it." The FAA Administrator told the same committee, at a hearing, that the agency "didn't know what the root cause of the accident" was at the relevant time. In a later written answer to the same committee, he described, in detail, the FAA's understanding of the faulty sensor and the MCAS chain of causation immediately after Lion Air. The committee calls this what it is: a contradiction.
Dennis Muilenburg's own account of all this, given under oath, was that Boeing operates in "a tough, globally competitive world" but that this "never, never takes priority over safety." The congressional committee's response to that sentence, in its own report, is one line: "Unfortunately, that is not what the Committee's investigation of the 737 MAX has revealed." An internal Boeing survey the company never intended to make public, surfaced to investigators by a whistleblower, found that 39 percent of the FAA-delegated engineers working inside Boeing, people paid and managed by Boeing while certifying aircraft on the regulator's behalf, said they had personally experienced undue pressure, and 80 percent of those had experienced it more than once. Muilenburg's public response to that figure was to cite the 97 percent who understood the reporting process, while, in the committee's own words, "completely ignoring" what the 39 percent were actually reporting.
This is where the story is usually left. The correction that followed the two crashes is itself a second, separate case of the same pattern, and it is the part almost nobody tells.
An independent international panel, the Joint Authorities Technical Review, chaired by a former chairman of the US National Transportation Safety Board, issued seven structural recommendations in October 2019. Rebuild the rule governing incremental design changes so itforces a whole-aircraft view rather than a piecemeal one. Modernise certification guidance that had not kept pace with how aircraft are actually designed. Review whether the FAA's own oversight office in Seattle, which had roughly two dozen engineers overseeing fifteen hundred Boeing certification staff, was adequately resourced, and whether its people could raise concerns without fear of punitive consequences. Build a genuinely independent safety function, rather than one dependent on the goodwill of the company it exists to check.
The FAA's own report on returning the aircraft to service, published thirteen months later, runs to nearly a hundred pages. It is genuinely rigorous on the specific defect: dual sensor input restored, repeat activation capped, trim authority limited, a functioning cockpit alert reinstated, new checklists, new training, all reviewed by an independent technical board that had no role in the original certification. The FAA states plainly, and unusually, that for this specific redesign it retained every compliance finding itself rather than delegating any of it back to Boeing, a direct reversal of the practice that produced the original failure. And then, on the recommendations that addressed the structure rather than the part, the report's own language, repeated almost word for word across several separate items, is that they represent future research and coordination, not settled change. Execution Integrity succeeded on the artefact in this documentand failed on the pattern, within the same pages. The document closes with a sentence that is, in its own quiet way, the most important one in either report: it does not address whether the airline maintenance practices, the operators' compliance, or the organisation's broader safety culture had themselves changed.
A regulator spent twenty-two months and more than sixty thousand working hours proving that one flawed system had been fixed. It never claimed to have checked whether the decision posture that produced the flaw had changed. That is not a criticism made from outside the profession. It is the regulator's own account of its own scope.
What Was Learned, and What Wasn't
Where this record makes a specific individual's choice clear, Teal's approval, Forkner's messages, this account names them. Where the failure is structural, fragmented FAA oversight, delegation without adequate staffing, that is named as structural rather than pinned to any one official, because the record itself does not support pinning it there.
Every organisation under real pressure builds structures for the things that are easy to audit: spend, schedule, compliance with a written rule. Almost none of them build anything that checksthe quality of the decisions being made inside those structures, not until an outcome forces the question, the way 346 deaths forced it here.
Three months after a regulator's own board saw the number 2,900 attached to a known and unfixed defect, that number stopped being theoretical for 157 more families. The aircraft has since been fixed. Whether the decision posture that let it fly anyway has been is a harder question, and it is one neither report claims to have answered.
How This Carries Forward
Fixing the specific defect and confirming that the structure which produced it has changed are two different pieces of work. A correction that only does the first is a partial correction, however rigorous it is on its own terms.
A quantified, board-level risk deserves the same weight regardless of which department's letterhead it arrives on. The five weeks between that finding and the second crash is the clearest evidence in this record that weight was not equally applied.
Of any correction that follows a failure, the harder and more useful question is not whether the part was fixed, but whether the pattern was, since a regulator's own report can answer the first honestly while leaving the second entirely open.
References
If any part of this, the warning that never reached the room, the number that didn't change the decision, the investigation that fixed the part but not the pattern, is one you recognise inside your own organisation, I'm glad to talk it through. Contact DDR here.


