The Pre-Mortem Method: Surface Failure Before Commitment
Imagine a committed plan has failed, generate independent causes, convert them into evidence and controls, and define stop conditions before launch.
Run a pre-mortem after a concrete plan exists but before commitment: tell participants the plan has failed, have them independently write plausible causes, pool and cluster them, seek disconfirming evidence, prioritize by consequence and detectability, and assign controls, signals, owners, contingencies, and stop conditions. Keep the original plan and assumptions visible.
Use this after a real plan exists and before lock-in
Use this when a team has enough of a plan to expose assumptions, yet can still change scope, sequence, controls, or whether to proceed. It is useful before a launch, investment, migration, hiring decision, research program, or public commitment.
Do not use it as a substitute for a baseline, technical review, red team, legal analysis, or incident response. Do not use it to demoralize a team during an active emergency or to reopen a decision when no meaningful option remains. A pre-mortem generates hypotheses; it does not establish that any imagined cause is likely.
Prospective-hindsight research examined how treating an uncertain future event as certain changes causal explanations. hindsight, klein Gary Klein translated the technique into a project practice centered on imagining failure and eliciting concerns. klein
Failure modes of the pre-mortem itself
- Starting before a plan exists.
- Letting the leader name the first causes.
- Listing vague categories without causal paths.
- Ranking by drama rather than evidence.
- Treating every imagined cause as equally probable.
- Assigning “the team” as owner.
- Adding controls without cost or side-effect analysis.
- Filing the output without changing the plan.
If participants cannot safely state a failure involving leadership, address the governance problem before trusting the exercise.
The failure surface register
Every retained risk receives one row:
| Failure path | Evidence now | Early signal | Prevention | Contingency | Owner | Stop condition | |---|---|---|---|---|---|---| | Critical supplier misses delivery | Lead-time variance, no backup | Slips in first milestone | Dual source | Reduce launch scope | Operations lead | No verified stock by date |
The asset is complete only when a risk changes a decision, control, monitoring signal, or contingency. A list without ownership is anxiety captured in a spreadsheet.
Evidence for the diagnosis: the Failure Surface and Control Register
Research supports the claim that assumed certainty can alter the type and amount of causal explanation, while practitioner work describes the project pre-mortem procedure. Evidence does not establish that every pre-mortem improves outcomes or supplies calibrated probabilities. The control register is an original extension.
hindsight, kleinRun the independent failure reconstruction
Step 1 — Freeze the plan. Record goal, scope, baseline, dependencies, assumptions, decision owner, and commitments already made.
Step 2 — State the future fact. “It is six months later. The plan failed badly in a way we care about.” Do not ask whether it failed.
Step 3 — Write silently. Each participant generates causes alone. Independence prevents the first senior voice from defining the search space.
Step 4 — Round-robin the causes. Collect one cause per person per round without debate. Preserve uncomfortable and minority entries.
Step 5 — Build failure paths. Replace labels such as “communication” with a chain from condition to event to consequence.
Step 6 — Seek evidence. Mark source, base rate, analogous case, dependency data, or “unknown.” Add a rival explanation.
Step 7 — Prioritize. Use consequence, plausibility, detectability, and control cost separately. Do not hide them in one magic score.
Step 8 — Redesign. Assign prevention, early signal, contingency, owner, and stop condition. Record how the plan changed.
Worked case: a 200-page knowledge launch
A team plans to release a large evidence-led site at once. Silent generation surfaces distinct paths: duplicated search intent, unverified current facts, broken contextual links, inconsistent claims, and indexing before approval.
“Quality failure” is too broad. One path becomes: rushed final integration causes manifest drift; sitemap includes a missing page; crawlers receive inconsistent signals; launch evidence becomes unreliable. The control is a manifest-derived build, URL validation, draft gate, and a named release owner. The stop condition is any mismatch between manifest count, route count, and sitemap immediately before authorization.
The method has improved the plan because a failure path now owns a test and stop rule.
Adaptations without losing independence
- Solo variant: write causes on separate passes from user, operator, adversary, and maintainer perspectives.
- Large group: collect anonymous entries before a facilitated session.
- High uncertainty: build scenarios first, then pre-mortem each scenario.
- Recurring operation: compare imagined causes with the actual incident ledger.
- Sensitive hierarchy: let an independent facilitator aggregate themes without attribution.
Adaptation must protect independent generation and the ability to change the plan.
The transfer test for the Failure Surface and Control Register
Give a different plan to a facilitator who has only the method card. Without seeing the first register, they must freeze assumptions, protect independent generation, build at least three causal paths, attach evidence and rivals, and convert one path into an owned control and stop condition. A reviewer scores procedure fidelity and whether the new plan materially changed.
Preserve the forecasts in The Decision Journal Method, update their evidence in The Hypothesis Ledger, and map interacting causes with Systems Thinking.
Imagined failure is not forecast evidence
Availability, status, fear, and recent incidents can dominate imagined causes. Participants may use the ritual to attack a disliked plan or suppress it to protect a sponsor. The exercise does not produce probabilities, reveal unknown unknowns, or replace domain-specific assurance. Use reference classes, technical evidence, and accountable review before consequential commitment.
A pre-mortem earns its place when the plan becomes harder to fool, easier to stop, and clearer about who watches each important failure path.
Named sources
Evidence and further reading
Published July 29, 2026. No substantive revision has been recorded. Evidence last verified July 28, 2026.