Electronics Guide

Human Factors in Aviation Systems

Human factors is the discipline that treats the flight crew as a component of the aircraft system rather than as an external user of it. For the avionics engineer, this reframing has a concrete consequence: the pixel layout of a display, the color of an annunciator, the priority queue of an alerting computer, and the state machine of an autoflight system are all safety-critical design decisions. A display that is technically correct but misread under vibration has failed. An alert that fires correctly but arrives buried among forty others has failed. Certification authorities now treat these failures as airworthiness problems in their own right, subject to the same evidence and approval discipline as a structural or a software defect.

The discipline earned that status through accidents. As glass cockpits and flight management systems spread through the commercial fleet in the 1980s, a new accident pattern emerged in which every component worked to specification and the aircraft was nonetheless flown into terrain, into a stall, or into the ground short of a runway. The Federal Aviation Administration convened a human factors team in response, and its June 1996 report, The Interfaces Between Flightcrews and Modern Flight Deck Systems, concluded that design teams lacked human factors expertise and had concentrated on the physical ergonomics of the workstation while neglecting its cognitive demands. That report drove the regulatory changes described later in this article, and its findings still shape flight deck electronics today.

This article covers the electronics side of aviation human factors: how flight information is generated and presented, how alerts are prioritized and annunciated, how automation states are made visible, how displays survive sunlight and vibration, and what evidence a manufacturer must produce to certify the result.

The Glass Cockpit and the Primary Flight Display

The transition from electromechanical instruments to electronic displays removed a physical constraint and replaced it with a design problem. A mechanical altimeter occupies a fixed position and shows one quantity. A display unit can show anything, anywhere, in any format, and the engineer must decide what it shows and when.

Inheriting the Basic T

Early glass cockpits did not abandon the layout pilots already knew. The basic T arrangement—attitude at the center, airspeed to the left, altitude to the right, heading below—had been standardized on instrument panels for decades, and the primary flight display (PFD) reproduces it in software. Airspeed and altitude became vertical moving tapes rather than round dials, and the artificial horizon expanded to fill the center of the screen, but the spatial relationships survived. This continuity was deliberate. It preserved the scan pattern that pilots had trained into procedural memory and limited the negative transfer that occurs when a pilot moves between aircraft types.

The moving-tape format itself involves a trade-off. A round dial conveys rate and trend through pointer motion and gives an instant coarse reading from needle position alone. A tape gives a precise digital value but weaker rate cues, so designers add trend vectors—a line projecting the value the parameter will reach in about ten seconds at the current rate of change—to restore the information the dial provided for free.

Display Suite Organization

A transport-category flight deck typically divides information across several display units. The PFD carries attitude, airspeed, altitude, vertical speed, heading, and the flight mode annunciations. The navigation display (ND) presents a moving map with the active route, terrain, weather radar returns, and traffic. Multi-function displays carry engine parameters, system synoptics, electronic checklists, and charts. The allocation is not arbitrary: information needed for immediate manual control sits in the forward field of view, and information needed for planning and monitoring sits outboard or on the center pedestal.

Redundancy in this architecture is a human factors question as much as an availability question. Display units are driven by separate graphics generators on separate electrical buses so that a single failure never blanks both pilots' primary displays. Reversionary switching allows a working display unit to assume the role of a failed one, and the design must make the resulting non-normal configuration obvious rather than merely functional, so that a pilot glancing at an unfamiliar screen layout immediately understands why it changed.

Separating Display Content from Display Hardware

ARINC 661, first adopted in 2001 and extended by successive supplements, defines a standard interface between cockpit display systems and the avionics applications that supply their content. A display system hosts a server that owns the widget library and the rendering pipeline; user applications such as the flight management system or a systems monitor send commands that create and update widgets. The layout of each display page is defined in a binary definition file loaded by the server.

The human factors value of this separation is that display appearance and behavior become a controlled, reviewable artifact rather than a byproduct of application code scattered across suppliers. A change to a symbol's color or position is a change to a definition file that can be inspected, tested against a style guide, and traced to a requirement. It also lets an airframer enforce visual consistency across equipment from different vendors, which matters because inconsistent symbology between screens is a documented source of misinterpretation.

Designing for Attention: The Dark Cockpit

A flight deck contains hundreds of indications. If each one is visible whenever it is true, the pilot must read and interpret the whole panel to determine whether anything is wrong. The dark-cockpit philosophy inverts this. Overhead panel indications are extinguished when the associated system is configured normally and illuminate only when a system is not in its normal state or requires crew action. A pilot scanning a dark overhead panel needs no interpretation at all: darkness means normal.

Airbus adopted this principle systematically from the A320 onward, and the approach has spread widely. It converts a reading task into a detection task, and human vision is far better at detecting a lit element against a dark field than at parsing many similar illuminated labels. The design discipline required is significant, because it forces engineers to define a single unambiguous normal state for every system and to resist adding status lights that convey information without demanding action.

The same reasoning governs color. 14 CFR 25.1322 fixes the alerting convention: warning indications must be red, caution indications must be amber or yellow, and advisory indications may use any color except red or green. The rule does not ban those colors elsewhere outright. It requires instead that any use of red, amber, or yellow for functions other than flightcrew alerting be limited and not adversely affect alerting, which in practice amounts to the same design discipline. Outside the alerting set, green typically indicates a normal or engaged condition, white indicates status or armed conditions, and magenta commonly marks a commanded or target value such as a selected altitude. Treating color as a scarce resource is the whole point: every additional use of amber for a non-alerting purpose reduces the attention-getting value of every genuine caution.

Color can never be the only channel. Roughly one man in twelve of northern European descent has some form of color vision deficiency, cockpit lighting shifts perceived hue, and sunlight washes out saturation. Alert states are therefore encoded redundantly through position, shape, text, flashing, and aural cues, so that the color carries emphasis rather than the entire message.

Alerting and the Caution-Warning Hierarchy

The Alert Taxonomy

Flight deck alerting is built on a three-level urgency hierarchy that the FAA codified in 14 CFR 25.1322, adopted as Amendment 25-131 and published on November 2, 2010, with guidance in AC 25.1322-1. A warning identifies a condition requiring immediate crew awareness and immediate crew response. A caution requires immediate crew awareness and subsequent crew response. An advisory requires crew awareness and may require subsequent response. EASA maintains a corresponding requirement in CS-25.

The rule constrains the electronics directly. Alerts must be readily detectable and intelligible under all foreseeable operating conditions, explicitly including conditions in which multiple alerts are present at once. For warnings and cautions specifically, attention-getting cues must reach the crew through at least two different senses, combining aural, visual, or tactile indications, which is why a stall warning pairs an aural call with a tactile stick shaker rather than relying on a light. The rule further requires that the alerting function be designed to minimize false and nuisance alerts, and that an alert be removed once its condition no longer exists. The alerting function must also tell the crew what is wrong and what to do about it, not merely that something is wrong.

SAE ARP4102/4 provides the recommended practice for flight deck alerting system design, and ICAO addresses the same territory in its human factors guidance, including Doc 9683, the Human Factors Training Manual. Military practice follows a parallel structure through MIL-STD-411F for aircrew station alerting systems.

Prioritization, Inhibition, and Suppression

An alerting computer is fundamentally a priority queue with a real-time scheduler. When several conditions are true simultaneously, the system must present them in an order that reflects urgency rather than detection sequence. The ordering follows how little time the crew has to act: a stall warning outranks a windshear warning, which outranks a ground-proximity warning, which outranks a traffic collision avoidance resolution advisory, which in turn outranks a configuration caution and then an advisory about a cabin system. The lower-priority alert is not merely queued but actively inhibited, so that two incompatible escape maneuvers are never called at once.

Equally important is what the system withholds. Phase-of-flight inhibition suppresses non-essential alerts during takeoff and landing, when the crew has no spare capacity and no useful response. Thresholds are keyed to airspeed and radio altitude: inhibition typically begins at a defined speed on the takeoff roll and lifts at a defined height in the climb, with a matching window that opens at a defined height on approach and closes once the aircraft has slowed on the rollout. Alerts that remain valid are queued and released once the aircraft is established in a phase where the crew can act.

Suppression logic must also handle the cascade problem. A single root-cause failure, such as the loss of an electrical bus, generates dozens of downstream indications from every system that bus supplied. A well-designed alerting system recognizes the causal relationship and presents the root cause with its dependents subordinated, rather than presenting fifty equal-weight symptoms.

EICAS and ECAM

Two implementations dominate commercial aviation. Boeing introduced the Engine Indicating and Crew Alerting System (EICAS) on the 767 in the early 1980s. It combines engine parameter display with a message list that presents alerts in priority order, color-coded by urgency, with the crew referring to a checklist—paper originally, electronic on later types—for the response.

Airbus introduced the Electronic Centralized Aircraft Monitor (ECAM) on the A310 in the same period, and took the integration further. ECAM presents the alert and the associated procedure together on the upper display, with a system synoptic on the lower display showing the affected system's configuration. The crew works the procedure line by line, and completed items clear from the screen. This coupling of alert to action reduces the interpretation step, but it also places heavy trust in the logic that selected the procedure, which becomes a liability when the failure is one the designers did not anticipate.

Both architectures depend on a centralized fault-monitoring layer that collects data from system controllers over the aircraft data buses, applies detection logic, and drives the display and aural outputs. The alerting function is typically assigned a high design assurance level, because a failure to annunciate and a spurious annunciation are both hazardous.

Alarm Flooding

Alarm flooding occurs when the rate of alerts exceeds the rate at which a crew can process them, converting an information system into a noise source. Aviation inherited both the problem and much of its vocabulary from process control, where the phenomenon has been studied since the Three Mile Island accident of 1979.

The reference case in aviation is Qantas Flight 32 of November 4, 2010, in which an uncontained failure of the number two engine on an Airbus A380 severed wiring and hydraulic lines across the left wing. The Australian Transport Safety Bureau investigation, AO-2010-089, documents a crew confronted by more than fifty ECAM messages, with further messages appearing as the flight progressed. Each individual message was correct. Collectively they exceeded what any procedure had anticipated. Five pilots were on the flight deck—the three operating crew plus two check captains present for a check sequence—and they worked the ECAM procedures for roughly fifty minutes, landing safely at Singapore about two hours after departure.

The design responses are structural. Root-cause consolidation reduces message count. Message paging with clear indication of how many items remain prevents the crew from losing track. Status pages that summarize the aircraft's remaining capability, rather than the sequence of failures that produced it, answer the question the crew actually needs answered: what can this aircraft still do? Some manufacturers now include explicit summary displays of degraded system capability for exactly this reason.

Automation, Modes, and the Flight Management System

Mode Confusion

A modern autoflight system is a mode-rich state machine. Lateral and vertical guidance each have many modes, autothrottle has its own set, and modes change both when the crew commands them and automatically when the system reaches a trigger condition. Mode confusion occurs when the crew's mental model of the active mode diverges from the actual state, so that subsequent inputs produce unexpected behavior.

Nadine Sarter and David Woods gave the phenomenon its canonical treatment in "How in the World Did We Ever Get into That Mode? Mode Error and Awareness in Supervisory Control," published in Human Factors volume 37 in 1995. Their central argument is that designers proliferated modes without adding the feedback needed to track them, and that automation which changes state on its own initiative creates a monitoring burden that the interface does not support. The related term automation surprise describes the moment the divergence becomes apparent, usually through unexpected aircraft behavior rather than through any annunciation.

The Air Inter accident near Mont Sainte-Odile on January 20, 1992, illustrates how narrow the design margin can be. The flight control unit displayed vertical speed and flight path angle in the same window, selected by the same knob, distinguished only by the format of the digits. A crew intending a flight path angle of 3.3 degrees while the unit was in vertical speed mode would command a descent of 3,300 feet per minute. Investigators identified this as a leading explanation for the descent rate flown, and Airbus subsequently changed the display so that vertical speed appears as a four-digit value that cannot be mistaken for an angle.

Asiana Airlines Flight 214, which struck the seawall at San Francisco on July 6, 2013, shows the same failure mode in autothrottle logic. The NTSB report, AAR-14/01, found that moving the thrust levers to idle transitioned the autothrottle to HOLD, a mode in which it does not control airspeed. None of the three pilots on the flight deck noticed the transition, and the aircraft decelerated below approach speed. The Board identified the complexity of the autoflight system, and inadequate documentation of that complexity, as contributing factors.

Feedback: The Flight Mode Annunciator

The primary countermeasure is the flight mode annunciator (FMA), a band across the top of the primary flight display that shows the active and armed modes for autothrottle, lateral guidance, and vertical guidance, together with the engagement status of the autopilot and flight directors. Its position is chosen deliberately: it sits directly above the attitude indicator, inside the region a pilot already scans continuously.

Effective FMA design does more than list states. Mode changes are highlighted transiently—typically boxed for about ten seconds—so that a change draws the eye even when the pilot is not looking for it. Uncommanded reversions receive stronger emphasis than commanded ones, because those are the transitions most likely to go unnoticed. Airline procedures reinforce the display by requiring pilots to call out mode changes aloud, which converts a private perception into a shared crew observation.

The PARC/CAST Flight Deck Automation Working Group revisited this territory in its 2013 report Operational Use of Flight Path Management Systems, which produced twenty-eight findings and eighteen recommendations. It confirmed that mode confusion, programming errors, and reluctance to intervene in automation remained live risks nearly two decades after the 1996 FAA report, and that highly integrated flight decks combined with retrofitted add-on features had increased the knowledge burden on crews.

Envelope Protection and the Manufacturer Split

Fly-by-wire removed the mechanical connection between the pilot's inceptor and the control surfaces, which allowed flight control computers to limit what the pilot can command. How far that limiting should go is the most visible philosophical disagreement in transport aircraft design, and it is a human factors position as much as an engineering one.

Airbus implements hard protections. In normal law, the flight control computers enforce limits on pitch attitude, bank angle, angle of attack, and load factor that the pilot cannot exceed regardless of sidestick input. The reasoning is that a pilot in a startled or disoriented state may command a maneuver that destroys the aircraft, and that the computer should refuse. When sensor data degrades sufficiently, the system reverts to alternate or direct law, and protections are progressively lost—a transition that must itself be annunciated clearly, because the pilot's assumptions about what the aircraft will refuse to do have just changed.

Boeing implements soft protections. The flight control system resists movement toward the edges of the envelope through increasing control column force and provides strong cues, but a pilot who applies sufficient force retains full authority. The reasoning is that no designer can enumerate every situation, and that the pilot must be able to exceed a normal limit deliberately when the alternative is worse.

Both positions are defensible and both are certified. The genuine human factors requirement is not that one philosophy prevail but that the aircraft's behavior at the limit be unambiguous, consistent, well annunciated, and thoroughly trained, so that a pilot never has to guess whether the aircraft will honor an input.

Head-Up and Helmet-Mounted Displays

Head-Up Displays

A head-up display projects collimated symbology onto a combiner glass in the pilot's forward field of view. Because the image is focused at optical infinity, the pilot reads the symbols without refocusing from the outside scene, which removes the accommodation and reaccommodation delay that head-down instruments impose on every transition between inside and outside references.

The core symbol is the flight path vector, which marks where the aircraft is actually going rather than where its nose points. Conformal symbology—a runway outline, a horizon line, a flight path angle reference—is drawn to overlay the corresponding real-world features, which requires accurate attitude and position data and tight control of latency, since a conformal symbol that lags the world it annotates is worse than no symbol at all.

Head-up displays also carry a well-documented cost. Attentional tunneling occurs when compelling symbology captures the pilot's attention so completely that unexpected events in the outside scene go unnoticed, even though they fall within the visual field. Design mitigations include minimizing clutter, decluttering automatically in certain phases, and avoiding symbology that competes with the real-world features it is meant to support.

Helmet-Mounted Displays

Helmet-mounted displays extend the head-up concept by referencing symbology to head orientation rather than to the airframe. A head-tracking system measures helmet position and attitude, and the display draws symbols that remain fixed relative to the world as the pilot looks around. Military applications include off-boresight weapon cueing, where the pilot designates a target by looking at it, and sensor cueing, where a turreted sensor slaves to head direction.

The F-35 Helmet Mounted Display System takes this to its conclusion: the aircraft carries no head-up display at all, and the helmet provides both the primary flight symbology and imagery from the distributed aperture system, which stitches together six infrared cameras to give the pilot a view through the airframe in any direction. Rotorcraft applications use similar technology to present flight symbology overlaid on forward-looking infrared imagery for night and degraded-visibility operations.

The engineering constraints are severe. Total helmet mass and its center of gravity determine neck loads under acceleration and during ejection, so every gram of display hardware trades against pilot safety and fatigue. Head-tracker latency and accuracy determine whether conformal symbology sits on the target or beside it. Binocular displays must be aligned precisely, because misalignment between the two eyes' images produces eye strain, headache, and in some cases spatial disorientation.

Synthetic and Enhanced Vision

Synthetic vision systems render the outside world from a terrain and obstacle database using the aircraft's own position and attitude solution. The result is a computer-generated view that is available in any weather and at night, and that shows terrain shape and runway location with a clarity the real world often does not offer. Its weakness is that it shows only what the database contains: it cannot show another aircraft on the runway, a construction vehicle, or an obstacle built since the database was compiled.

Enhanced vision systems take the opposite approach, using infrared or millimeter-wave sensors to image the actual scene. Infrared sensors readily detect the hot filaments of approach lighting and the thermal signature of a runway surface, penetrating haze and some obscurants that defeat the unaided eye. Enhanced flight vision systems, the variant approved for operational credit, allow a pilot to continue an approach below the published decision altitude using sensor imagery in place of natural vision. A 2016 FAA rulemaking restructured that credit into two operations under 14 CFR 91.176: descent to 100 feet above the touchdown zone elevation, and, for suitably equipped aircraft flown by qualified crews under an appropriate authorization, descent through 100 feet to touchdown and rollout.

Combined vision systems merge both sources, typically presenting synthetic terrain as a background with sensor imagery inset or overlaid. RTCA DO-315 and its revisions, developed jointly by RTCA Special Committee 213 and EUROCAE Working Group 79, define the minimum aviation system performance standards for these systems, covering database integrity, alerting, pilot controls, display, and symbology. The human factors question they must answer is how the pilot knows which parts of the image are measured and which are rendered, because a synthetic image that looks photographic invites a trust it has not earned.

Legibility in the Physical Environment

Sunlight Readability

A cockpit display faces an optical environment no consumer screen encounters. Direct sunlight through a windscreen, or sunlight reflected from cloud tops, produces ambient illumination on the order of 10,000 foot-candles, roughly 100,000 lux. An active-matrix liquid crystal display that achieves a contrast ratio of several hundred to one in a darkroom can fall below usable contrast under that illumination, because reflected ambient light adds to both the bright and dark states and compresses the difference between them.

The countermeasures work on both terms of the contrast ratio. High-luminance backlights raise the signal, with avionics displays commonly specified in the hundreds of foot-lamberts. Anti-reflective coatings, optical bonding of the cover glass to the display stack to eliminate internal air gaps, and circular polarizers reduce the reflected component. Physical design contributes through glareshields, display recessing, and screen tilt chosen so that specular reflections of the windscreen and the pilot's own light-colored shirt fall outside the viewing cone.

The same display must also work at the other extreme. Night operations require dimming to a fraction of a foot-lambert without color shift, banding, or loss of gray-scale resolution, so that the display does not destroy the dark adaptation a pilot needs to see outside. A dimming range of roughly four orders of magnitude follows directly from those two ends of the requirement, and it is a demanding one for backlight and drive electronics.

Vibration and Symbol Sizing

Vibration degrades legibility by moving the image on the retina. In turbulence, in rotorcraft, and in high-performance aircraft under buffet, the relative motion between the pilot's head and the display blurs fine detail and can make small characters unreadable at exactly the moment they matter most. RTCA DO-160 Section 8 defines the vibration environments that airborne equipment must endure, and military equipment follows MIL-STD-810 for the equivalent testing.

Surviving vibration is not the same as remaining readable during it. Human engineering practice, codified for military systems in MIL-STD-1472, drives designers toward larger characters, heavier stroke weights, and greater contrast for information that must be read in a vibrating environment. Because legibility depends on visual angle rather than physical size, the specification must account for the pilot's design eye position: a symbol sized adequately at twenty-four inches may be marginal at thirty-six. Critical values are therefore drawn larger than the display's resolution would permit, and non-essential detail is removed rather than shrunk.

Night Vision Goggle Compatible Lighting

Night vision goggles amplify near-infrared and visible red light that the unaided eye barely registers. A cockpit lit conventionally will therefore bloom in the goggles, destroying their gain and rendering the outside scene invisible. Making a flight deck goggle-compatible means removing the energy the goggles are sensitive to while retaining enough visible light for a pilot to read the panel underneath or around the goggles.

MIL-STD-3009, Lighting, Aircraft, Night Vision Imaging System (NVIS) Compatible, dated February 2, 2001, superseded MIL-L-85762A and defines the interface and performance requirements. It specifies chromaticity coordinates for a defined set of colors, among them NVIS Green A, NVIS Green B, NVIS Yellow, NVIS Red, and NVIS White, and sets limits on NVIS radiance, a figure of merit computed by weighting a source's spectral radiance against the goggle's spectral response. The standard distinguishes Class A goggles, which use a 625-nanometer minus-blue objective filter and impose the tightest constraints, from Class B goggles, whose 665-nanometer filter allows limited use of red.

Compliance shapes component selection throughout the flight deck. Backlights and annunciators use narrow-band emitters, typically light-emitting diodes chosen for spectral purity, combined with filters that cut the infrared tail. Every illuminated element counts, including switch legends, circuit breaker panels, and the emitted spectrum of the primary displays themselves. The trade-off is real: the filtering that achieves compatibility also removes color information, so a goggle-compatible display has a narrower usable color gamut than an unfiltered one, and the color-coding scheme must be designed to survive that restriction.

Controls and Inceptors

Physical controls remain subject to the same discipline. Shape coding gives critical controls distinguishable tactile identities—the traditional wheel-shaped landing gear handle and flap-shaped flap lever exist so that a pilot can identify them by touch without looking. Guards, detents, and required force levels prevent inadvertent actuation. Spacing accounts for gloved hands and for the displacement that turbulence imposes between intention and contact.

Touchscreens have entered the flight deck and bring a specific set of problems: no tactile feedback, sensitivity to turbulence-induced misses, and the loss of the ability to find a control by feel while looking elsewhere. Mitigations include large targets, palm rests or bezels that stabilize the hand, confirmation steps for consequential actions, and the retention of physical controls for the functions most likely to be needed in the conditions where a touchscreen performs worst.

Startle, Surprise, and Crew Response

Startle is an involuntary physiological reflex to a sudden intense stimulus, complete within a fraction of a second. Surprise is the longer cognitive process of revising a mental model that events have contradicted. Both degrade performance: attention narrows, fine motor control suffers, and the ability to reason through an unfamiliar problem drops sharply for a period that research places in the range of tens of seconds. Accident investigations have repeatedly found crews performing far below their demonstrated capability in the first moments of an unexpected event.

The design implication is that the alerting and display system must be usable by a degraded operator. An alert that requires careful reading, a display that demands interpretation, or a procedure whose first step is a diagnosis will not be executed correctly by a crew in the first thirty seconds after a startling event. This argues for unambiguous first indications, for procedures whose opening actions are memory items requiring no reading, and against alerting designs that present a puzzle at the moment of highest arousal.

Air France Flight 447, lost over the Atlantic on June 1, 2009, demonstrates how alerting behavior can compound the problem. Ice crystals blocked the pitot probes, airspeed indications became invalid, the autopilot disconnected, and the crew was startled into a situation for which the displays gave contradictory evidence. The BEA final report of July 2012 documents a particularly damaging interaction: the stall warning is inhibited when measured airspeed falls below sixty knots, so as the aircraft descended in a deep stall with very low indicated airspeed the warning fell silent, and it resumed when a pilot lowered the nose and the airspeed indication became valid again. The feedback was thus inverted—the correct recovery input produced the alarm, and the incorrect input silenced it.

The Colgan Air Flight 3407 accident of February 12, 2009, investigated by the NTSB in report AAR-10/01, showed a startle response to a stick shaker met with an aft column input opposite to the required recovery. These accidents, among others, drove changes in training, including the upset prevention and recovery training guidance in FAA AC 120-111 and the extended envelope training required of part 121 crews by 14 CFR 121.423. The design lesson that accompanies the training lesson is that clarity of indication and consistency of feedback are what allow trained responses to actually be produced under stress.

Certification of the Human Interface

The Rule and Its Guidance

The 1996 FAA human factors report produced regulation on both sides of the Atlantic. EASA moved first, introducing CS 25.1302 with CS-25 Amendment 3 on September 19, 2007, together with the acceptable means of compliance AMC 25.1302. The FAA followed with a harmonized 14 CFR 25.1302, published as a final rule on May 3, 2013 at 78 FR 25846, alongside advisory circular AC 25.1302-1 issued the same day.

The rule requires that installed systems and equipment intended for flight crew use be designed so that qualified crews can safely perform their tasks. Its paragraphs address four things. The flight deck must allow the crew to accomplish its tasks and must supply the information needed to do so. Controls and information must be clear and unambiguous, must be accessible and usable in a manner consistent with the urgency, frequency, and duration of the task, and must make the effects of crew actions apparent. Equipment behavior must be predictable and unambiguous and must permit the crew to intervene appropriately. Finally, to the extent practicable, the design must provide means for the crew to manage the errors that reasonably expected interactions produce, a duty that stops short of covering deliberately reckless or malicious acts. The premise stated explicitly in the guidance is that even well-trained, qualified, healthy, and alert crew members make errors, so error tolerance is a design property rather than a training problem.

Compliance is demonstrated through an evidence chain rather than a single test. Applicants use similarity to previously approved designs, design description and analysis, engineering evaluations in part-task rigs and fixed-base simulators, and full evaluations in high-fidelity simulators or in flight. The chosen method must match the significance of the human factors issue, and the applicant must define representative task scenarios covering normal, non-normal, and emergency conditions, evaluated by pilots representative of the intended population rather than by the engineers who built the system.

What DO-178C Does and Does Not Cover

RTCA DO-178C, published in December 2011 and issued by EUROCAE as ED-12C, governs the development assurance of airborne software. It assigns design assurance levels A through E according to the severity of the failure condition the software could cause, from catastrophic at Level A to no safety effect at Level E, and scales objectives for requirements traceability, verification, and configuration management accordingly. At Level A, verification must demonstrate modified condition/decision coverage, proving that each condition in a decision independently affects the outcome. DO-254 provides comparable assurance for complex electronic hardware.

The critical point for human factors is what DO-178C guarantees. It establishes that the software correctly implements its requirements. It says nothing about whether those requirements describe a system a pilot can use. An autothrottle whose mode logic is implemented perfectly to Level A can still transition to a mode the crew does not expect and does not notice; the software is not defective, the requirement is. This gap is precisely what 25.1302 and AC 25.1302-1 exist to close, and it is why human factors evaluation must be run in parallel with software assurance rather than treated as a subset of it.

Related standards fill in the surrounding structure. SAE ARP4754B, issued in December 2023 in place of ARP4754A, addresses the development of civil aircraft and systems and provides the framework in which human factors requirements are derived and validated. Its companion ARP4761A, issued at the same time, covers the safety assessment process, in which crew response is often credited as a mitigation—a credit that is only valid if the crew can actually detect the condition and respond in the assumed time. Establishing that the assumption holds is a human factors task, and an optimistic assumption here quietly invalidates the safety analysis that depends on it.

Current Directions

Several trends are reshaping the field. Reduced-crew and single-pilot operations for commercial transports would remove the cross-monitoring that two-pilot crews provide, and would require alerting and automation designs capable of detecting pilot incapacitation and degraded performance rather than merely presenting information. Certifying such a system means demonstrating that the electronics compensate for a monitoring channel that has been deleted.

Machine learning in cockpit systems raises the question of how a pilot can understand, predict, and appropriately trust a system whose behavior is not specified by explicit rules. The existing certification framework assumes deterministic, traceable requirements, and both EASA and the FAA are developing guidance for systems that do not fit that assumption. Adaptive automation, which varies its level of assistance according to inferred workload, adds a further complication: a system that changes its own behavior is a system whose mode the pilot must track.

Electric vertical takeoff and landing aircraft present a different problem. Their intended pilot population is less experienced than the airline population, their operating environment is dense and low-altitude, and their flight envelopes differ substantially from conventional aircraft. Simplified vehicle operations aim to reduce the interface to something closer to a supervisory task, which shifts nearly the entire safety burden onto the display and automation design. In every one of these directions, the constraint is the same one the 1996 report identified: capability is limited less by what the electronics can compute than by what a human being can perceive, understand, and act upon in time.

Summary

Human factors in aviation systems is the engineering of the interface between flight crew and aircraft electronics. Its core principles are consistent across every subsystem discussed here. Present information in the format the task requires, in the location the pilot already scans. Reserve attention-getting resources such as color and sound for conditions that genuinely require action. Make automation state visible without requiring the pilot to search for it. Assume the operator will sometimes be startled, overloaded, or mistaken, and design so that recovery remains possible. Prove the result with representative pilots on representative tasks, rather than assuming that correct implementation implies usable design. Regulation now enforces these principles through 14 CFR 25.1302, CS 25.1302, and their supporting guidance, but the underlying reasoning predates the rules and applies wherever a person must control a complex machine under time pressure.

Related Topics