R364 SeriesWho decides what is true? Part 5 / 26

When an Institution Cannot Admit Error

Organizational silence, normalization of deviance, whistleblowers, and the difference between legitimate secrecy and concealment of responsibility

Institutions are not people. They do not have one mind, one fear, or one intention. But organizations can develop structures in which admitting an error becomes harder than continuing a flawed practice. This can happen without a grand conspiracy.

Leadership wants good numbers. A middle manager does not want to bring bad news. An employee knows a problem is real but sees what happens to people who challenge superiors. A small exception becomes routine.

A safety signal is interpreted as a “known risk.” A report is softened. Uncomfortable information never reaches the person who could act. Then a crisis occurs and the public asks:

How is it possible that so many people knew about the problem, yet the institution did not correct it in time?

That is the subject of this article.

The most dangerous error is not necessarily the one nobody sees

Many organizational disasters do not begin with an unknown risk. They begin with a known risk that is:

  • underestimated;
  • normalized;
  • fragmented across departments;
  • translated into technical language;
  • subordinated to production, sales, or policy targets.

When analyzing institutions, it is therefore important to distinguish:

ignorance

from

an organizational inability to get uncomfortable knowledge to the right place and trigger the right action.

Organizational silence

Elizabeth Morrison and Frances Milliken developed the concept of organizational silence in 2000.[1] Their central argument is that an organization can develop a climate in which employees systematically withhold information about:

  • problems;
  • mistakes;
  • misconduct;
  • improvements,

because they expect that speaking up:

  • will change nothing;
  • will create personal costs;
  • will be interpreted as disloyalty;
  • will endanger their career.

This is not the same as formal censorship. An environment in which people decide for themselves that speaking is not worth it can be even more effective.

Bad news travels upward less easily than good news

Leadership in almost every organization wants to know:

“What is really happening?”

But hierarchy itself creates a filter. Imagine a chain: technician → team leader → director → chief executive. At every level, uncomfortable information can be:

  • softened;
  • delayed;
  • translated into less alarming language;
  • combined with other data;
  • handled locally without being escalated.

At the top, an entirely sincere belief can therefore arise:

“We did not know.”

But the research question is:

Why did the system fail to make it possible for them to know?

Challenger: engineers knew there was a problem

The Challenger space-shuttle disaster on January 28, 1986 is one of the best-documented examples of organizational failure. The Rogers Commission concluded that the launch decision was flawed and that the people making the decision were not adequately informed about the history of O-ring problems and the continuing opposition of Thiokol engineers to launching at such a low temperature.[2]

This is essential:

the warning existed.

The problem was not only technical. It was also communicative and organizational.

A problem that becomes an “acceptable risk”

In its historical chapter, the Rogers Commission wrote that NASA and contractors first failed to recognize the seriousness of the booster-joint problem, then failed to correct it, and eventually began treating it as an acceptable flight risk.[3] This is an important pattern. If a system repeatedly survives a deviation without disaster, a psychological and organizational shift can occur:

“It is not ideal, but apparently it works.”

Every successful case without an accident then becomes informal evidence that the practice is acceptable. But absence of catastrophe is not the same as proof of safety.

Feynman: different worlds inside the same organization

In his appendix to the Challenger report, physicist Richard Feynman pointed to a large gap between reliability estimates he encountered among engineers and the more optimistic assumptions found in some parts of management.[4] His famous concluding idea was that successful technology cannot fool reality with public-relations logic. That principle is useful far beyond spaceflight.

An institution may temporarily manage:

  • reporting;
  • perception;
  • internal metrics.

But it cannot permanently manage:

a physical fact, a financial loss, pollution, abuse, or another real problem simply by changing the language used to describe it.

Normalization of deviance

Sociologist Diane Vaughan developed the concept of normalization of deviance in her analysis of Challenger.[13] The core idea is:

a departure from the original safety standard can gradually become the new normal if it repeatedly occurs without a catastrophic outcome.

This does not have to be conscious rule-breaking. It can be a slow cultural shift:

  1. an anomaly is observed;
  2. it is explained as acceptable;
  3. the decision is repeated;
  4. nothing catastrophic happens;
  5. the former exception becomes normal practice.

The process is dangerous precisely because at no single moment does it look like one dramatic leap.

Volkswagen: when the problem is not only silence but an intentional technical solution

The Volkswagen diesel emissions scandal is different. In 2015, the U.S. EPA identified software—a “defeat device”—that detected test conditions and changed how emissions controls operated.[5] The EPA later reported that Volkswagen representatives told the agency such a system was also present in all U.S. 3.0-liter diesel models from model year 2009 onward.[5]

Here we are no longer talking only about a mistaken risk assessment. We are talking about a system designed to behave differently during regulatory testing than in normal use. That is a qualitatively different type of institutional problem.

Launch of Space Shuttle Challenger STS-51-L on 28 January 1986, with black smoke visible near the right solid rocket booster.
28 January 1986: the Challenger launch. This NASA image shows an early trace of black smoke near the right solid rocket booster during the launch of STS-51-L. The later Rogers Commission examined technical warnings, communication paths and pre-launch decisions; the photograph documents the event and a visible symptom, not the organizational causes by itself. Image: NASA / Wikimedia Commons Public domain — NASA/U.S. federal government work

We therefore need several categories of institutional error

Not everything should be described as a “cover-up.” It is useful to distinguish:

A. Error without prior knowledge

The institution could not reasonably have known about the problem.

B. Misjudgment

The problem was known but sincerely assessed as less dangerous than it was.

C. Organizational silence

The information exists but is not transmitted or does not trigger action.

D. Normalized deviance

The system begins to treat a violation or dangerous practice as ordinary.

E. Negligent disregard

Warnings exist and are sufficiently strong, but the organization does not act.

F. Deliberate concealment or deception

Actors know about the problem and actively prevent regulators, the public, or other relevant people from understanding it. These categories require very different levels of evidence.

Wells Fargo: when the metric becomes the target

In 2016, the U.S. Consumer Financial Protection Bureau announced enforcement action against Wells Fargo over a widespread practice of opening unauthorized accounts.[6] The CFPB found that, under pressure from sales targets and incentive systems, employees opened deposit and credit-card accounts without customers' knowledge and in some cases transferred funds from existing accounts.[6]

The case is important because it shows another institutional mechanism:

people can begin optimizing a metric instead of the goal the metric was supposed to measure.

If the target is:

“more products per customer”

and career outcomes are tightly tied to that number, the question:

“Does the customer actually want this product?”

can recede into the organizational background.

A Goodhart-type problem

Charles Goodhart originally warned about a narrower problem: a statistical regularity that is useful as an indicator can change or break down once it becomes a target of active control and management. Later literature expanded the idea to organizational metrics and targets.[14]

The popular formulation:

“when a measure becomes a target, it ceases to be a good measure”

is useful as a simplified heuristic, not as a literal quotation from Goodhart's original formulation. If a school is judged almost entirely by one test, the system may begin optimizing the test result itself. If an organization is judged almost entirely by one number, behavior may begin following the metric rather than the purpose for which the metric was created.

In the Wells Fargo case, the relevant question is how a sales target and incentive structure can redirect attention away from the customer's actual interest and toward achieving a measurable target.[6] This does not prove that all measurement causes abuse. It shows why we must check:

whether the metric still measures the goal for which it was introduced.

A bad system can steer ordinary people toward bad behavior

This is an important safeguard against an oversimplified moral story. After a major scandal, it is tempting to find:

a few corrupt individuals.

Sometimes that is correct. But if similar misconduct appears:

  • in multiple locations;
  • over a long period;
  • among a large number of employees,

we also have to ask:

What did the system reward, punish, or tolerate?

That does not excuse individual responsibility. It offers a broader explanation.

The whistleblower as an organizational sensor

A whistleblower is someone inside an organization who reports:

  • a violation of law;
  • a danger;
  • fraud;
  • abuse;
  • serious misconduct.

In a well-functioning system, such a person can serve as an early-warning sensor. Instead of asking:

“How do we silence them?”

the institution should ask:

“What do they know that we are not seeing?”

But the whistleblower is not automatically right

An important boundary:

an internal source may be valuable, but is not infallible.

A whistleblower may:

  • see only part of the system;
  • misread a document;
  • have a personal conflict;
  • draw conclusions that go too far.

A report therefore requires independent investigation. Real whistleblower protection is not a system in which every allegation is automatically believed. It is a system in which an allegation can be:

raised safely and investigated fairly.

Why do people remain silent?

Research on whistleblowing and organizational silence often emphasizes the perceived risk of retaliation. In a representative Norwegian study, researchers examined experiences of retaliation after whistleblowing.[7] More recent research likewise finds that perceived retaliation risk affects employees' willingness to report wrongdoing.[8]

Before speaking, a person may weigh:

  • Will I lose my job?
  • Will I be transferred?
  • Will I be branded a problem employee?
  • Will anything change?
  • Does my manager even want to know?

If the expected personal cost is high and the expected institutional effect is low, silence can be a rational individual strategy. For the organization, however, it can be catastrophic.

Legal protection exists precisely because internal loyalty is not enough

In the United States, different regulators operate formal whistleblower programs. The SEC has a program created by Congress to encourage the reporting of specific, timely, and credible information about possible securities-law violations.[9] OSHA administers multiple anti-retaliation programs across workplace and other statutory areas.[10]

The existence of these structures reflects an important institutional recognition:

the organization itself is not always the safest place to expose the organization's problem.

Internal channel or external channel?

Organizations often want:

“Tell us first.”

That is understandable. An internal channel can:

  • solve the problem faster;
  • protect sensitive information;
  • avoid unnecessary public harm.

But an internal system is meaningful only if employees believe:

  • the report will be investigated;
  • the investigator is sufficiently independent;
  • the reporter will not be punished.

Without those conditions, “use the internal channel” can become a way:

to keep the problem inside the structure that created it.

Retaliation is not only dismissal

Retaliation can be obvious:

  • firing;
  • demotion.

But it can also be much subtler:

  • removal from projects;
  • social isolation;
  • poorer evaluations;
  • exclusion from meetings;
  • reputational labeling as a “difficult person.”

A formal rule saying:

“We do not fire whistleblowers”

therefore does not prove the culture is safe for speaking up.

The Pentagon Papers: secrecy and democratic accountability

The Pentagon Papers were a classified historical study of U.S. involvement in Vietnam. Daniel Ellsberg, who had worked with the documents, provided parts of the study to newspapers in 1971; the National Archives now publishes the complete declassified corpus.[11]

The case matters because of the question:

When does legitimate state secrecy begin to prevent democratic understanding of the state's own policy?

This is not a simple question. States have legitimate secrets. Intelligence sources, ongoing operations, and technical capabilities are not necessarily information that should be immediately public. But the category “secret” can also encompass information whose political inconvenience is not the same thing as operational danger.

Secrecy and concealment are not the same thing

It is useful to distinguish:

Legitimate secrecy

The purpose is to protect:

  • lives;
  • an ongoing operation;
  • personal data;
  • a sensitive source;
  • a genuine trade secret.

Institutional concealment

The purpose is to prevent disclosure of:

  • error;
  • illegality;
  • abuse;
  • political responsibility;
  • reputational damage.

In the real world the boundary can be disputed. That is precisely why we need:

independent oversight, classification rules, courts, regulators, audits, and protected reporting channels.

A document marked “secret” is not automatically proof of a conspiracy

This is important for THY-REALITY. A secret document may contain:

  • routine information;
  • diplomatic analysis;
  • a military assessment;
  • an operational plan.

The secrecy label itself does not mean:

the document reveals a crime.

Likewise, a declassified document that mentions an idea is not proof that the idea was carried out. Our already locked rule remains:

PROPOSAL ≠ APPROVAL ≠ EXECUTION ≠ PROOF OF AUTHORSHIP.

When an organization begins defending a previous decision

An error can acquire an additional psychological cost. If leadership has:

  • publicly defended a decision;
  • invested money in it;
  • tied it to its reputation,

correction becomes more expensive. Admitting:

“we were wrong”

may mean:

  • reputational loss;
  • legal liability;
  • political defeat;
  • a falling share price;
  • potential compensation claims.

The original technical problem can therefore become a problem of institutional identity and self-preservation.

Past investment and escalation of commitment

Organizational psychology has well documented escalation of commitment: after a negative outcome, a decision-maker may continue or even increase investment in an already chosen course, especially when they feel personally responsible for the original decision.[15] A similar problem can appear in institutions when much has been invested in:

  • a project;
  • a strategy;
  • a product;
  • a policy;
  • a doctrine.

This does not mean every institution automatically persists in a bad direction because of past costs. It means that sunk costs, reputation, and personal responsibility can create additional incentives against changing course. A useful question is therefore:

If we were not already invested in this decision, would we make it again today with the data we now have?

When persistence is not escalation

Persistence can be entirely rational when:

  • new evidence still supports the original goal;
  • the costs of changing direction exceed the benefits;
  • a negative intermediate result does not predict final failure.

We should therefore not label something escalation of commitment merely because an organization did not immediately retreat after criticism. We need a combination of:

negative results + continued investment + reasons increasingly tied to defending the previous decision rather than responding to new evidence.

Institutional memory can help—or hurt

An institution can learn from errors only if it preserves them. That requires:

  • archives;
  • incident reports;
  • post-mortems;
  • access to old decisions;
  • transparent corrections.

If history is rewritten after a failure so that the previous decision looks more reasonable, precisely the material that could prevent repetition is lost. This directly connects with our articles on religious doctrinal change.

“Lessons learned” are not the same as learning

After almost every major failure, a:

lessons-learned report

is produced. But the question is not whether a document existed. The question is:

  • Did the incentives change?
  • Did the structure change?
  • Is oversight stronger?
  • Do people have a safer way to raise concerns?
  • Does the same kind of problem recur?

An institution has not learned merely because it wrote:

“We will learn from this.”

It has learned if it changed the conditions that produced the error.

Reputation management can be legitimate—up to a point

When a crisis occurs, an organization may try to:

  • explain the event;
  • reassure customers;
  • prevent false rumors;
  • protect employees.

That is legitimate. But crisis communication becomes a problem when the goal is no longer:

to explain the facts

but:

to protect the image regardless of the facts.

At that point, PR begins competing with internal investigation.

The most dangerous institution is not necessarily the one that makes the most mistakes

All organizations make mistakes. The more important difference is:

how quickly they can detect, admit, and correct an error.

A mature institution needs:

  • internal dissent;
  • independent audit;
  • a way to escalate problems;
  • protection for people who bring bad news;
  • correction systems.

An organization without mistakes does not exist. But an organization without a safe path to admitting mistakes is especially vulnerable.

“Bad apples” and systemic problems

After a scandal is exposed, the first explanation is often:

a few individuals broke the rules.

Sometimes that is true. But research requires another test:

If we remove the individual, do the conditions that produced the behavior remain?

If the following remain unchanged:

  • the same targets;
  • the same hierarchy;
  • the same rewards;
  • the same punishment for bad news,

then we may have removed the symptom rather than the cause.

How do we distinguish error from a cover-up?

The word cover-up is a strong claim. It therefore needs stronger evidence. Useful signs include:

  • documented instructions to hide information;
  • destruction or concealment of evidence;
  • false public statements despite a known contrary internal state;
  • pressure on witnesses;
  • intentional alteration of records;
  • obstruction of an investigation.

A discrepancy between:

an internal document

and

a later public statement

can be an indication. It is not always enough to prove intentional concealment.

An institution can be both a victim of its system and responsible for it

This is an important paradox. Leadership may genuinely be unaware of a problem because subordinates filtered information. But leadership may also have:

  • created the targets;
  • rewarded optimism;
  • punished difficult voices;
  • designed the hierarchy

that made such filtering rational. Therefore:

“I did not know”

and

“I am not responsible for the system that caused me not to know”

are not the same claim.

Institutional responsibility is not the same as personal guilt

An organizational system can be criticized without claiming:

every member knew.

This is particularly important in large:

  • companies;
  • churches;
  • state institutions;
  • media organizations.

Thousands of people may perform their jobs honestly while working inside a system with a serious structural flaw. That is why we have to distinguish:

  • individual knowledge;
  • departmental knowledge;
  • institutional knowledge.

What does “the institution knew” actually mean?

That phrase is often too vague. It is better to ask:

Who exactly knew?

When?

What exactly?

From which document?

Did they have authority to act?

Did they pass the information onward?

Who received it?

This converts:

“the institution knew”

from rhetoric into a testable timeline of knowledge.

THY-REALITY: KNOWLEDGE CHAIN

For future institutional scandals, I would add a standard matrix: SIGNAL → WHO KNEW → WHEN → WHAT EXACTLY → ESCALATION → DECISION → PUBLIC STATEMENT → CORRECTION This allows us to separate:

  • an early warning;
  • later internal knowledge;
  • a leadership decision;
  • public communication.

The model is useful for:

  • a technological accident;
  • a financial scandal;
  • a religious institution;
  • a state operation;
  • a media error.

Six questions for an institution that says it has corrected itself

What exactly was wrong?

Not “we made a mistake,” but specifically.

Who knew, and when?

Why did the system fail to act?

Which incentive changed?

How will the next person who notices the same problem be able to speak up safely?

Can the public verify that the change is real?

If the answer remains only:

“We are committed to the highest standards,”

we have learned very little.

A good correction has a history

One of the healthiest properties of an institution is visible changelog logic. It does not hide the old version. It states:

  • what previously applied;
  • why it was wrong;
  • when it changed;
  • what evidence triggered the change.

That is normal in good technical documentation. It is much rarer in institutions whose reputation is tied to the idea:

“We were always right.”

A correction can carry a reputational cost too

Institutions may fear:

“If we admit an error, people will no longer trust us.”

The empirical literature on corrections shows a more complicated picture: corrections often improve belief accuracy, but revealing that a source was previously inaccurate can under some conditions reduce the perceived credibility of the source itself.[16] We therefore do not use the simple formula:

transparent correction = automatically more trust.

More important is:

  • whether the correction is clear;
  • whether it reaches people who saw the original claim;
  • whether the institution explains the cause of the error;
  • whether it changes the process that allowed the error;
  • whether it preserves a traceable historical record.

A correction can be reputationally painful. But concealing an error creates a different and potentially greater risk to future credibility.

But admission without consequences can become a ritual

An apology can also be institutionalized.

“We regret this.”

“This is not consistent with our values.”

“We will learn from this.”

If:

  • nothing changes;
  • the same people remain without oversight;
  • the incentives remain the same;
  • whistleblowers remain at risk,

the admission is primarily a reputational function.

How this model connects to religions

In religious institutions, admitting error carries additional weight. If an institution says only:

“Our policy was wrong,”

the correction is relatively straightforward. But if the earlier policy was presented as:

God's will,

a harder question arises:

How do we separate the institution's error from the authority with which the error was originally presented?

That is why, in our work on Jehovah's Witnesses, the LDS Church, and other examples, we pay so much attention to:

  • doctrinal changes;
  • the history of interpretation;
  • how the organization describes an earlier error.

How this model connects to the state

States have particular legitimate reasons for secrecy. But they also hold uniquely powerful categories:

  • classified;
  • national security;
  • state secret.

That is why they require particularly strong external controls. Not because a state is necessarily malicious. But because an institution with the greatest legitimate capacity to conceal information is also an institution in which abuse of that capacity can have especially large consequences.

How this model connects to corporations

A corporation has a legitimate right to protect:

  • intellectual property;
  • trade secrets;
  • privacy.

But if the same legal tools make it harder to expose:

  • a dangerous product;
  • fraud;
  • a regulatory violation,

a conflict arises between:

confidentiality

and

public accountability.

How this model connects to the media

A media institution can publish something wrong. What matters is:

  • how quickly it corrects it;
  • how visibly;
  • whether the headline is corrected as prominently as the original headline appeared;
  • whether a history of the correction is preserved.

If the false claim was:

front-page material,

while the correction is:

an inconspicuous paragraph three days later,

a formal correction may not be equivalent to the original informational effect.

An institution without critics is blind

An independent critic is uncomfortable. The critic can also be wrong. But a system that has no people who can:

  • say no;
  • demand a document;
  • stop a process;
  • alert a regulator

is extraordinarily dependent on its own internal picture of reality. And that is the theme of the entire series.

Conclusion: trust requires the possibility of a disloyal question

Institutions often want loyal people. That is understandable. But loyalty and truth are not always the same thing. Sometimes the most loyal person is the one who says:

“This is not working.”

“This number is wrong.”

“This decision is dangerous.”

“We need to tell the public.”

An institution that automatically interprets such a person as an enemy removes its own early-warning system. Perhaps the best test of institutional maturity is therefore:

Does the organization have a safe way for someone to tell it an uncomfortable truth before a catastrophe does?

If it does, an error can become learning. If it does not, silence may protect reputation for a while. But it does not remove reality.

Methodological note

The article deliberately distinguishes between:

  • individual error;
  • organizational silence;
  • normalization of risk;
  • misaligned incentives;
  • negligence;
  • deliberate deception;
  • concealment.

From the fact that an institution had an internal warning, we do not automatically infer that its top leadership knew all the details. From the fact that a public statement was false, we do not automatically infer that it was intentionally false.

Claims of a cover-up require additional evidence about intent, conduct, and the timeline of knowledge.

Sources and further reading

  1. Elizabeth Wolfe Morrison & Frances J. Milliken, “Organizational Silence: A Barrier to Change and Development in a Pluralistic World,” Academy of Management Review 25(4), 2000, 706–725. Used for the concept of organizational silence and climates in which employees do not transmit important information upward. DOI: 10.2307/259200 Source
  2. Presidential Commission on the Space Shuttle Challenger Accident, Rogers Commission Report, Vol. I, Chapter V. Used for the flawed launch decision, incomplete information reaching decision-makers, and Thiokol engineers' warnings. Source
  3. Rogers Commission Report, Vol. I, Chapter VI, An Accident Rooted in History. Used for the finding that the joint problem was initially under-recognized, then left unresolved, and later treated as an acceptable flight risk. Source
  4. Richard P. Feynman, Personal Observations on Reliability of Shuttle, Appendix F to the Rogers Commission Report. Source
  5. U.S. Environmental Protection Agency, Learn About Volkswagen Violations. Used for defeat devices and Volkswagen's disclosure to the EPA regarding 3.0-liter U.S. diesel models. Source
  6. Consumer Financial Protection Bureau, CFPB Fines Wells Fargo $100 Million for Widespread Illegal Practice of Secretly Opening Unauthorized Accounts, September 8, 2016. Used for unauthorized accounts, sales targets, and incentive structures. Source
  7. Brita Bjørkelo et al., “Silence is golden? Characteristics and experiences of self-reported whistleblowers,” European Journal of Work and Organizational Psychology, 2011. Used for whistleblowing and experiences of retaliation. Source
  8. Khan et al., “Examining Whistleblowing Intention: The Influence of Perceived Seriousness, Organizational Commitment and Perceived Retaliation,” 2022. Used for the link between perceived retaliation risk and willingness to report wrongdoing. Source
  9. U.S. Securities and Exchange Commission, Whistleblower Program. Used for the purpose of regulatory systems that solicit specific, timely, and credible reports. Source
  10. U.S. Department of Labor, OSHA, Whistleblower Protection Programs. Source
  11. U.S. National Archives, Pentagon Papers. Used for the history of the documents, Ellsberg's role, and later declassification/publication. Source 1 Source 2
  12. U.S. NASA History Office, Return to Flight after Challenger. Additional institutional review of the Rogers Commission findings and aftermath. Source
  13. Diane Vaughan, The Challenger Launch Decision: Risky Technology, Culture, and Deviance at NASA, University of Chicago Press, 1996; enlarged edition 2016. Used directly for the concept of “normalization of deviance” and its application to Challenger. Source
  14. Charles A. E. Goodhart, Problems of Monetary Management: The U.K. Experience, Reserve Bank of Australia conference contribution, 1975; and Goodhart, The ECB and the Conduct of Monetary Policy: Goodhart’s Law and Lessons from the Euro Area, JCMS 44(4), 2006. Used for the original narrower formulation of Goodhart's law and the caution that the popular “measure becomes a target” formulation is a later generalization. Source 1 Source 2
  15. Barry M. Staw, Knee-deep in the big muddy: a study of escalating commitment to a chosen course of action, Organizational Behavior and Human Performance 16(1), 1976, 27–44. Used for the original experimental literature on escalation of commitment after negative outcomes and personal responsibility. Source
  16. Ethan Porter & Thomas J. Wood, Factual corrections: Concerns and current evidence, Current Opinion in Psychology 55, 2024; additionally Dobbs, Butler & Swire-Thompson, The differential consequences of correcting misinformation for high and low credibility sources, Scientific Reports 16, 2026. Used for the more cautious formulation of the relationship between corrections, belief accuracy, and source credibility. Source 1 Source 2