Insights / Operations Design

Checklist design: seven rules from the flight deck

A checklist that nobody reads is a poster. Airlines have spent decades learning what makes the difference between the two, and almost none of it is about aviation. Seven rules, and a template you can use on Monday.

Insights / Checklist design: seven rules from the flight deck

Published September 24, 2026 · 9 min read

Why most checklists fail

Every organization has checklists, and most of them are not used. They are laminated, pinned to a wall, and consulted on the first day and never again. The organization concludes that its people do not like checklists. The truth is usually that the checklist was written as a to-do list by someone who was not going to use it, and a to-do list is a different object.

A checklist does one thing: it converts a belief into a verified observation. "The flaps are set" is a belief. "Flaps: 5, checked" is an observation. The distinction matters because knowing something and having verified it today are different states, and only one of them is evidence. Aviation checklists are engineered for that single purpose, and the engineering produced rules that transfer to an inspection routine, a shift handover or a clinic opening without modification.

The seven rules

RuleOn the flight deckWhat it looks like elsewhere
1. Confirm states, not actions"Landing gear: down, three green" not "lower the landing gear""North elevation: 12 frames, overlap checked" not "photograph north elevation"
2. ShortCritical checklists are five to nine items; the long version is a separate documentOne screen, one card. If it needs a second page, it is two checklists
3. Split by phaseBefore start, before taxi, before takeoff, after landing: each read at its momentDay before, before leaving, on arrival, before starting, before leaving site
4. Killer items firstThe items whose omission is fatal come first, so they are read even if the list is interruptedLegal, safety and irreversible items at the top; convenience items at the bottom
5. Read by the person who did not do itThe pilot monitoring reads, the pilot flying confirms; the doer sees what they expect to seeSecond person reads, or the doer reads aloud and physically points at each state
6. A trigger, not a habitEach checklist has a defined trigger: "after engine start", not "when you remember"Tie the read to an event that always happens: arriving on site, unlocking the door, opening the app
7. Owned and revisedOne owner, a revision date, a channel for crews to report items that are wrongA name and a date on the card; the people who use it can change it and know how

Rule one is the one that changes everything

If you adopt only one rule, adopt the first. Writing each line as a state to confirm rather than an action to take changes who the checklist is for. An action list is for the person who does not know the job. A state list is for the person who knows the job perfectly and might, today, tired, have skipped a step without noticing. The second person is the one the checklist is protecting.

It also changes what the line does in the reader's head. "Lower the gear" is an instruction the experienced pilot has already followed a thousand times, so the eye slides over it. "Gear: down, three green" demands a look at the indicator. The verification is forced by the grammar.

Rules two and three are the same rule

Short and phase-split are two views of the same constraint. A checklist is read in a moment, under time pressure, and anything that cannot be read in a moment will not be read. Aviation solved the length problem by splitting the day: the before-start checklist is short because the before-taxi checklist exists. Each is read at its trigger, and none of them is long enough to skip.

The common failure in other industries is the master checklist: forty items covering the whole day, read once at the start and never again. Splitting it into four or five cards of six to nine items each, read at the moment each becomes relevant, turns a document into a procedure. The five-stage drone pre-flight checklist is a worked example of exactly this split: day before, before departure, on site, before takeoff, in flight.

Rule five is the one people resist

Having a second person read the checklist feels like distrust. It is the opposite. Aviation established long ago that the person who performed an action is the worst person to verify it, because they will see the state they intended rather than the state that exists. The pilot monitoring reads; the pilot flying looks and confirms. Neither is being checked up on. Both are participating in a procedure designed around how attention actually works.

Where there is no second person, the fallback is the point-and-call: read the item aloud, physically point at or touch the thing being confirmed, say the state. Japanese railways have used this (shisa kanko) for a century, and it measurably reduces error precisely because it forces the eye and the hand to the object. It looks odd to a bystander. It works.

A template to copy

The following is the skeleton every aviation checklist follows, adapted for a task in any field. Replace the items; keep the structure.

[TASK] — [PHASE] CHECKLIST  Owner: [name]  Rev: [date]
Trigger: read when [event that always happens]
Read by: [second person / self, aloud with point-and-call]

1. [Killer item — state to confirm] .......... CONFIRMED
2. [Killer item — state to confirm] .......... CONFIRMED
3. [State] .................................... CONFIRMED
4. [State] .................................... CONFIRMED
5. [State] .................................... CONFIRMED
6. [State] .................................... CONFIRMED

"[PHASE] checklist complete."
Wrong or missing item? Tell [owner] — this card is revised [monthly / after every incident].

The closing line matters. "Checklist complete" spoken aloud is the signal that the phase is over and the next begins, and it is what makes an interruption visible: if nobody said it, the checklist was not finished.

Where checklists sit among the other mechanisms

A checklist is the cheapest and most visible of the five airline mechanisms, which is why it is the right place to start. It is not sufficient on its own. It is only read if a standard procedure says when, only honest if the culture makes it safe for the junior to say an item failed, and only useful if the items on it were chosen by someone who understands what actually goes wrong. Airline operations principles for other industries sets out how the five hold each other up. For the case where the checklist reveals that one person is the only one who can complete it, the single point of failure is the next article to read.

Tsuyoshi Kiyomine came to AI from airline operations control and founded KIYOMINE in Tokyo. He builds Airffic World, a drone operations, AI inspection and rostering platform, and writes here about designing operations for work that moves.