Skip to main content
What Happens to the No? The Not-So-Silent Veto
  1. Posts/

What Happens to the No? The Not-So-Silent Veto

·1722 words·9 mins
Table of Contents

Picture a pilot sitting in the cockpit before departure, looking at an instrument that’s stopped working as it should.

What they don’t get to do is decide, on the spot, that it’s probably fine and go anyway.

Whether an aircraft may dispatch with something inoperative isn’t a rule the captain gets to invent when it becomes inconvenient. The approved MEL (minum equipment list) establishes which inoperative items may be tolerated, and exactly what has to be true before the aircraft can dispatch with each one.

If an item required for airworthiness or safe operation has no applicable approved relief, the aircraft doesn’t dispatch merely because the captain personally believes the failure is harmless. [1]

If it is covered by the MEL, dispatch is still conditional. There might be a spare unit that has to remain working, a maintenance procedure that has to be completed, an operational restriction, or a deadline by which the item has to be fixed. [2] Every applicable condition has to be satisfied.

And here’s the part that took me a while to appreciate. Meeting every condition on the list still isn’t the end of it. EASA’s own guidance says that the conditions and limitations in the MEL do not relieve the operator of determining that the aircraft is actually in a condition for safe operation with the inoperative item. [3]

The checklist can be complete and the aircraft can still not go.

I have been circling this idea since Part 2 of the workshop rebuild Valerie and I have been doing this summer, because Part 2 ends on a person I only half-solved for.


Not the Silent Veto
#

Part 2 introduced the silent veto: the person who nods, asks no questions, and then quietly ensures nothing changes. The tell is the absence of objection. Find them by asking who has to work differently on Monday, because they’re rarely in the room saying no out loud.

This post is about someone else entirely.

This person does say no. Out loud, on record. You did the work from Part 2. You found the real lever, priced the ask honestly, and reduced it to something one person could say yes to. They understood the risk, and they chose to carry it.

That is not a failure of persuasion. Persuasion has a floor, and you’ve hit it.

The question past that floor isn’t how do I get to yes. It’s what happens to the no.

Usually, in my experience, the answer is nothing. The no evaporates into the oral tradition of the organization until an incident forces everyone to reconstruct who knew what from memory, under pressure, with a lawyer in the loop.

That’s the version I want to try to fix.


The Machinery Already Exists. Nobody Uses It Properly.
#

You don’t need to invent a new mechanism. Security and compliance work already has mechanisms for recording risks, deciding how they’re treated, assigning actions, and tracking what happens next. NIST’s Risk Management Framework, for example, includes formal processes for documenting risk responses and tracking actions required to address identified weaknesses. [4] ISO/IEC 27001 likewise requires organizations to operate a defined risk-assessment and risk-treatment process and retain evidence of that process. [5]

The problem is what actually happens instead.

A verbal “yeah, we know, we’ll get to it.” A hallway conversation. A comment thread that gets archived when the project closes. It feels like a decision until the moment it matters, when it turns out to have been nothing.

No owner. No date. No scope. Just competing memories.

There’s a reason this happens even among careful, competent people. Diffusion of responsibility describes what happens when accountability for an outcome is spread across a group rather than assigned to a person: individual responsibility can diminish even when nobody intends to shirk anything. [6]

A verbal acknowledgment in a group chat spreads the risk across everyone who saw the message and nobody who signed anything. It feels shared. It is, functionally, unowned.

Compare that to the MEL.

The important thing isn’t that the MEL makes the captain incapable of judgment. It doesn’t. The operator still has to determine that the aircraft is in a condition for safe operation, and for commercial air transport the crew has to accept the aircraft’s condition before operating with the inoperative item. [3]

If a failure occurs between commencement of the flight and takeoff, the operator’s MEL should provide guidance for dealing with it, and pilot judgment and good airmanship still matter. [7]

But that’s different from inventing the rules at the gate.

The approved framework establishes the permitted relief. The conditions are explicit. The responsibilities are explicit. And satisfying the conditions still isn’t a substitute for determining that the operation is actually safe.

That is the part worth stealing.


What Goes in the Log
#

The failure gets recorded. The permitted conditions get recorded. The decision gets recorded. That’s what makes it possible for the next person to know what they’re looking at.

So what should go in the log when the risk isn’t an aircraft fault but an organizational one?

The version I want is short. Six things. If you can’t fill in all six, you don’t have an acceptance yet. You have a deferral pretending to be one.

The risk, in the terms from Part 1. Name the lever, the one a named person could have pulled. Not “security posture is weak.” Patch KB-whatever was not applied to the externally facing host, and the fix was a maintenance window someone chose not to schedule.

The owner. One name. Not a team, not “the business,” not “leadership.” The person on record as having made this specific determination.

The conditions, not just the decision. What compensating control exists? What’s restricted while the risk stands? What has to happen before it’s closed? If the answer is “nothing, we’re just accepting it,” say that plainly.

The scope and the expiry. What exactly is being accepted, and for how long? A risk acceptance without a review date isn’t an acceptance. It’s abandonment with a signature on it.

The reasoning, in one sentence. Honest enough that the person signing it would be comfortable hearing it read back in a postmortem. If they wouldn’t sign it that way, that’s information too.

The residual risk. What remains after the decision and its conditions are taken into account? That’s the thing the organization is actually agreeing to carry.

The important thing isn’t that someone said yes. It’s that we can say what “yes” was conditional on.


This Is Not the Vindictive Version
#

The instinct that gets people to this idea is usually the wrong one to write from:

Now I can prove I was right when this blows up.

Understandable instinct.

Wrong document.

A risk acceptance signed to build a case against someone reads as a trap. And once it reads as a trap, you’ve made the no harder to surface honestly. Worse, you teach people to stop saying no out loud and go back to the silent veto instead.

The entry doesn’t exist to punish the person who signs it. It exists so the organization has a real decision instead of an unowned risk drifting between everyone’s memory and no one’s responsibility.

It protects the signer too. If the deferral turns out fine, there’s a record showing exactly what was known and exactly what was chosen, instead of a reconstruction assembled after the fact.

The record protects the organization regardless of who turns out to be right. That’s the entire point of writing it down before you find out.

And a documented decision is not the same thing as a safe decision.

The form doesn’t make the risk acceptable. The signature doesn’t make the control effective. The record doesn’t turn a bad decision into a good one.

What it does is make the decision real. Someone chose it. They knew what they were choosing. They knew what conditions applied. They knew when the decision stopped being valid.

Everyone else can stop pretending the risk belongs to some vague collective called “the business.”


Where This Leaves the Series
#

Three posts, three failure modes, one throughline.

Part 1 asked whether the number on your report was even connected to a hand. Part 2 asked what it costs that hand to pull it, and how you price the ask so the answer is yes. This one is for what’s left when the hand is attached to someone who understood the cost, understood the risk, and chose it anyway.

Most of the time you won’t need this. Most of the time Part 2 works, because most objections really are about trust, capability, status, or history, and those respond to being addressed properly.

But the floor exists.

When you hit it, the job stops being persuasion. It becomes making sure the organization has an actual decision on file, owned by a name, with explicit conditions, and with a date when someone has to look at it again.

That’s the difference between accepting a risk and merely noticing one.

Hold the framework if you need one. But when a real risk shows up, don’t let a checked box stand in for someone actually determining that the organization is prepared to carry it.

Log the conditions, not just the yes.


Join the Conversation
#

Does your organization have a real risk acceptance process, or a folder of verbal ones nobody wrote down? I’d be interested in the near-misses that finally got someone to take the form seriously. Find me on LinkedIn or BlueSky.


References
#

[1] Easy Access Rules for Master Minimum Equipment List (CS-MMEL), Issue 2 - European Union Aviation Safety Agency [2] ORO.MLR.105 Minimum equipment list, Annex III (Part-ORO) to Regulation (EU) No 965/2012 - European Union Aviation Safety Agency [3] CS-GEN-MMEL, Issue 2 - European Union Aviation Safety Agency [4] SP 800-37 Rev. 2: Risk Management Framework for Information Systems and Organizations - National Institute of Standards and Technology (2018) [5] ISO/IEC 27001:2022 - Information security management systems - International Organization for Standardization [6] Many Hands Make Light the Work: The Causes and Consequences of Social Loafing - Bibb Latané, Kipling Williams & Stephen Harkins, Journal of Personality and Social Psychology (1979) [7] CAP 549: Master Minimum Equipment Lists (MMEL) and Minimum Equipment Lists (MEL) - UK Civil Aviation Authority


Photo by Daniel Reche: https://www.pexels.com/photo/man-showing-stop-sign-by-his-palm-near-black-background-5202002/