Threat and Error Management, universally abbreviated TEM, is the conceptual backbone of modern Crew Resource Management (CRM) training. Originally developed through research by the University of Texas Human Factors Research Project and later integrated into FAA-endorsed CRM curricula, TEM shifts the safety conversation from post-accident blame to real-time, proactive crew behavior. Rather than asking only "what went wrong?" after an event, TEM asks "how do crews successfully manage the constant stream of challenges that every flight produces?" For the ATP certificate and for safe line operations, understanding TEM at a deep level is not optional — it is foundational.
The Three Pillars of TEM
TEM identifies three interconnected components that together define the operational safety environment: threats, errors, and undesired aircraft states (UAS). Each component is distinct, but they form a chain. Unmanaged threats breed errors; undetected errors produce undesired aircraft states; uncorrected UAS lead to incidents and accidents. Understanding each pillar precisely is critical for both the ATP written and the practical test.
Threats
A threat is any event or condition that exists independently of the crew — something that arrives from outside the cockpit and increases the complexity or risk of the operation. Threats are not caused by the crew, but they absolutely demand a crew response. The FAA's Risk Management Handbook (FAA-H-8083-2) categorizes hazards in a similar way: conditions that exist in the environment and that a pilot must identify, assess, and mitigate.
Threats fall into several broad categories. Environmental threats include convective weather, icing, wind shear, contaminated runways, and reduced visibility. Airline or organizational threats include tight turnaround schedules, fatigue induced by roster construction, unfamiliar airports, and maintenance write-ups that change aircraft configuration. ATC and procedural threats include last-minute runway changes, complex departure clearances, non-standard phraseology, and high-density traffic environments. Even a passenger medical event mid-flight qualifies as an external threat that now demands crew attention and mental bandwidth.
The key operational insight is this: effective crews do not wait for threats to materialize into problems. They anticipate threats during pre-flight planning and the departure briefing, explicitly naming them and assigning contingency responses. A crew that briefs, "Runway contamination is reported; our V-speeds are adjusted, and we will confirm directional control before V1" has managed a threat before it had the chance to generate an error.
Errors
An error is any crew action or inaction that deviates from what the organization, the SOPs, or the crew itself intended to do. Errors originate with the crew — they are the internal counterpart to the external threat. TEM draws heavily on human factors research and explicitly treats errors as normal products of the human-machine-environment interaction, not as moral failings or evidence of incompetence.
Errors are commonly classified by their nature. A slip is an action executed incorrectly despite the correct intention — for example, reaching for the flap lever and accidentally selecting the spoiler handle. A lapse is a memory failure — forgetting to arm the ground spoilers on a stabilized final approach. A mistake is an error in planning or decision-making where the wrong rule or mental model is applied — for instance, calculating a go-around performance using the incorrect gross weight.
TEM does not attempt to eliminate errors entirely — research shows that is impossible in complex human operations. Instead, TEM focuses on two critical error management behaviors: detection and trapping. Detection means recognizing that an error has occurred. Trapping means intervening before the error produces consequences. Standard operating procedures (SOPs), sterile cockpit rules required under 14 CFR Part 121.542, callout procedures, cross-checks, and checklists all exist as structured error-trapping mechanisms. When these tools are used with discipline, error chains are broken early. When they are bypassed — due to complacency, time pressure, or poor CRM — errors propagate unchecked.
An important sub-category is the unmanaged and uncountered threat that directly generates an error without an apparent intermediate step. For example, an unexpected ATC frequency change (threat) distracts the crew at a critical moment (countermeasure fails), and the result is a missed altitude restriction (error). TEM analysis after the fact would map this chain explicitly to understand where intervention was possible.
Undesired Aircraft States
A UAS is a position, speed, attitude, or configuration that has degraded the safety margin and that, if uncorrected, places the flight on a trajectory toward an incident or accident. It is the product of unmanaged threats and untrapped errors. Classic examples include: an unstabilized approach (aircraft configured or positioned outside stabilized approach criteria); inadvertent flight into IMC by a crew that lacks an instrument clearance; exceedance of structural limits due to uncontrolled turbulence penetration speed; or a landing configuration error — gear not extended — on final.
The vital distinction is that a UAS is not yet an accident. It is the final warning gate in the TEM model. A crew that recognizes an unstabilized approach and executes a go-around has successfully managed the UAS. A crew that presses on despite crew callouts that the approach is not stabilized has failed the last layer of defense. Research compiled in aviation safety databases consistently shows that continued VFR flight into IMC and unstabilized approach continuations are among the most lethal UAS patterns in general and commercial aviation alike.
TEM as a Dynamic, Continuous Process
One of TEM's most important contributions is reframing safety as a process, not a state. At any given moment during a flight, a crew is simultaneously managing multiple active threats, monitoring for errors just made or about to be made, and assessing whether the aircraft is drifting toward an undesired state. This is not a linear checklist — it is continuous, overlapping mental work. High-reliability crews develop habitual patterns of scanning for all three elements throughout every phase of flight.
The Aviation Instructor's Handbook (FAA-H-8083-9) reinforces that effective CRM instruction must teach pilots to verbalize their TEM awareness — naming threats in the brief, calling out errors when detected, and stating clearly when the aircraft has entered a UAS and what the recovery action will be. This verbalization creates shared situational awareness in a multi-crew environment and builds the habit of structured thinking in single-pilot operations as well.
TEM in the Regulatory and Training Context
Under 14 CFR Part 121 Subpart Y and the associated Advanced Qualification Program (AQP) framework, air carriers are required to incorporate CRM and TEM principles into initial and recurrent training. Simulator scenarios are deliberately designed to inject threats — ATC complexity, weather, equipment anomalies — and to evaluate whether crews detect and manage resulting errors and UAS in real time. The ATP Airman Certification Standards (ACS) require applicants to demonstrate knowledge of TEM and to apply it during flight scenarios, including explaining how a specific threat was managed or how an error was trapped before it produced a UAS.
Key Numbers, Rules, and Principles
- Three components: Threats (external), Errors (crew-generated), Undesired Aircraft States (outcome of unmanaged threats/errors).
- Sterile cockpit rule: 14 CFR 121.542 prohibits non-essential conversation below 10,000 feet MSL — a regulatory error-trapping mechanism aligned with TEM principles.
- Stabilized approach criteria: Most carriers require the aircraft to be stabilized by 1,000 feet AGL in IMC or 500 feet AGL in VMC; deviation below these gates constitutes a UAS requiring a go-around.
- Error types: Slips (execution errors), lapses (memory failures), mistakes (planning/decision errors) — all are normal, all are manageable.
- TEM applies beyond Part 121: The framework is equally relevant in Part 135 and Part 91 operations; single-pilot TEM thinking is explicitly supported by FAA-H-8083-2.
Common Test Traps
- Threats are never crew errors. A thunderstorm, a contaminated runway, or an ambiguous clearance comes from outside the crew. Classifying these as errors on a knowledge test is the most common TEM mistake.
- Errors are expected, not exceptional. Test questions sometimes imply that a well-trained crew makes no errors. TEM says the opposite: errors are inevitable; the measure of crew performance is detection and trapping, not error-free operation.
- A UAS still has a recovery path. Scenarios that describe an unstabilized approach or an altitude bust are describing a UAS, not yet an accident. The correct response is the appropriate recovery action — in most stabilized-approach scenarios, that means executing a go-around.
- Countermeasures are the active ingredient. Threats and errors alone do not cause accidents. It is the failure of countermeasures — SOPs, callouts, cross-checks — that allows a threat-error-UAS chain to reach its worst outcome. Test scenarios will ask you to identify which countermeasure failed or should have been applied.
- TEM is descriptive and prescriptive. It describes how accidents happen (chain model) and prescribes how to interrupt that chain. Do not confuse TEM with a simple accident investigation tool — it is equally a pre-flight and in-flight decision-making tool.
Memory aid
Picture TEM as a three-layer safety net stretched beneath every flight. The first net catches threats before they cause errors. The second net catches errors before they create a UAS. The third net catches the UAS before it becomes an accident. Fly through all three nets without catching anything, and the outcome can be catastrophic — but each net represents a concrete opportunity to break the chain.