CloudLog EASA FAA Digital Pilot Logbook

Checklist Practice in the Cockpit: Why “Flow, Then Checklist” Is the Standard

You’re in the cockpit, you’ve just run the pre-start check “on flow” the way you have a thousand times before — trim, flaps, instruments, everything in its familiar place. Then the checklist comes out, and you read through the very same items you just checked. Feels redundant? That’s exactly where the feeling is wrong. The separation between “acting from memory” and “verifying with the list” is not a bureaucratic ritual — it’s the result of roughly ninety years of accident research, and it only works if you understand why it exists.

How It All Started: The Crash of the Boeing Model 299

On 30 October 1935, the prototype Boeing Model 299 — the aircraft that would become the B-17 — crashed shortly after takeoff at Wright Field, Ohio. The aircraft climbed to roughly 60–90 metres, stalled, and crashed in flames. Test pilot Major Ployer P. Hill and Boeing test pilot Leslie R. Tower were killed; co-pilot Donald L. Putt and two observers survived.

The investigation found no structural defect — the cause was human error. The newly introduced gust lock on the elevator had not been released before takeoff, a single but decisive step an experienced pilot had missed. As surgeon and author Atul Gawande later put it, the aircraft was simply “too complicated to be left to memory alone.” Boeing engineers responded by developing a mandatory checklist for taxi, takeoff, and landing. With it, the first twelve aircraft together flew roughly 1.8 million miles without an accident, and the US Army went on to order nearly 13,000 B-17s. To this day, the US aviation community informally marks 30 October as “National Checklist Day.”

Three Philosophies, One Goal: Verification, Not Memorisation

Over the decades, several core methods for working through checklists have become established. They differ significantly in procedure and intended use:

  • Flow (Do-Verify)
    • Procedure: Actions are performed from memory in a fixed, memorised sequence; the checklist is then read a second time to verify each item individually.
    • Typical use: Routine, high-repetition configuration steps.
  • Challenge-Do-Verify (CDV)
    • Procedure: One crew member reads the item aloud (challenge); the other performs the action and confirms (response).
    • Typical use: The most safety-critical steps, multi-crew operations.
  • Read-and-do
    • Procedure: The checklist is read and each item is executed immediately after, without a prior flow.
    • Typical use: Abnormal procedures for which no memorised sequence exists.

The crucial point: in all three cases, the checklist is not an instruction manual — it’s a verification tool. This is reflected in FAA guidance (Order 8900.1): checklists should contain only operationally relevant items, follow the actual sequence of actions, and reserve challenge-and-response for only the most safety-critical tasks.

Interestingly, “flow” is often assumed to be the faster method. A test series conducted by one business-jet operator found the opposite: Challenge-Do-Verify was, on average, both faster and less error-prone than Do-Verify (CDV: roughly 1:33–2:55 min with rare errors, versus DV: roughly 2:17–3:14 min with occasional errors). It’s a single study without a large sample, but the finding is a useful corrective to the widespread assumption that flows are inherently more efficient.

Why the Brain Needs a Second Check

The scientific groundwork for the modern understanding of cockpit checklists was laid in 1990 by Asaf Degani and Earl L. Wiener in their NASA study “The Human Factors of Flight-Deck Checklists: The Normal Checklist”, followed in 1993 by “Cockpit Checklists: Concepts, Design, and Use” in the journal Human Factors. Their central finding: even though checklists had for decades been considered a cornerstone of standardisation, they had rarely been systematically studied from a human-factors perspective — and the principles the two researchers identified apply across industries, from maritime operations to medicine.

One core problem this research addresses is exactly the feeling of redundancy described above: once a pilot subjectively perceives an item as already done during the flow, the subsequent checklist reading easily loses its effect. The brain tends to “see” the expected state rather than actively checking the actual state — an effect the literature describes succinctly: the brain perceives things as they should be, not as the eyes actually report them. That’s precisely why a genuine, deliberate second verification — not a routine rubber-stamp — is what separates an effective checklist from an ineffective one.

Normal, Abnormal, and Emergency Checklists

Operating regulations systematically distinguish three categories of procedures:

  • Normal
    • Purpose: Accompanies routine flight operations for each phase of flight.
    • Typical method: Challenge-and-response.
  • Abnormal
    • Purpose: System malfunction or component failure for which no memorised flow is suitable; goal: maintain an acceptable level of airworthiness for safe continuation and landing.
    • Typical method: Read-and-do.
  • Emergency
    • Purpose: Immediate action required to protect the aircraft and occupants from serious harm.
    • Typical method: Memory items, followed by the QRH.

Within abnormal and emergency procedures there are also so-called memory items — items so time-critical that they must be performed immediately from memory, before the written checklist is even consulted, such as recovery from an unusual attitude. According to SKYbrary, ICAO Annex 6 requires operators to maintain checklists for normal, abnormal, and emergency procedures for all phases of flight within the operations manual; the exact implementation and terminology can vary depending on the responsible authority and operations manual.

“Killer Items”: The Points That Decide Life and Death

One concept with a firm place in the professional vocabulary is the so-called “killer item.” The FAA defines critical items (Order 8900.1) as those which, if not correctly performed, have a direct, adverse effect on safety — colloquially known as “killer items” because overlooking one can lead directly to an accident. Typical examples include pitch trim and flap setting, and, on larger or turbine-powered aircraft, also spoiler position or pitot heat.

The reason for this explicit emphasis: long, exhaustive universal checklists tend to lead pilots, in practice, to actually check only the items they subjectively perceive as critical — an effect safety research describes as “normalization of deviance.” Killer items are meant to deliberately direct attention to the items with the most severe consequences, rather than letting them get lost among routine items like cabin lighting or the transponder code. The FAA formalised the concept several decades ago and mandated additional technical backstops for airliners — takeoff warning systems that monitor trim setting, flap setting, parking brake, and control lock — precisely because each of these items had historically contributed, repeatedly, to fatal accidents.

Common Misconceptions

  • “Flow is always faster.” As the test series cited above shows, that’s far from guaranteed — a properly executed Challenge-Do-Verify can end up both faster and safer.
  • “The longer the checklist, the safer.” Per Atul Gawande’s design principle, good checklists are short and focused (a rule of thumb is 5–9 items) and highlight only what experience shows is most often missed. An overly long, imprecise list starts to read like a shopping list and loses its effect.
  • “The checklist replaces my professional judgment.” The opposite is true: checklists support professional judgment, they don’t replace it. They’re a memory aid and a standard verification procedure — the decision still rests with the crew.
  • “Checked off automatically means correctly verified.” This is exactly where the danger of expectation bias lies: an item counts as verified only once the actual state has been actively checked — not because it “felt” already done during the flow.

Conclusion

The separation between flow and checklist is not an end in itself — it’s a response, built up since 1935, to a very human problem: our brain likes to see what it expects, not always what’s actually there. Whether read-and-do, do-verify, or challenge-do-verify, the method must fit the situation, but its purpose stays the same: a deliberate, independent verification of the actual state, paired with a deliberate emphasis on the few items that, if missed, decide between a safe flight and a fatal one. Treating checklists as mere routine to get through gives away exactly the safety margin they were designed to provide.

The checklist discipline described above depends on continuity: pilots who keep their procedures, checklist variants, and flight preparation in one place find it easier to actually apply them consistently rather than letting them slide over time. This is exactly where the checklist feature in cloudlog.aero fits in: it extends the digital logbook with structured, reusable checklists for normal and abnormal procedures that can be adapted per aircraft type or club. It doesn’t replace any of the principles described above — flow, verification, killer items — it simply gives them a fixed, easy-to-find place in your own flight preparation.

Common Mistakes at a Glance

  • The checklist gets rubber-stamped instead of actively verifying the actual state.
  • Killer items get lost among routine points because the list is too long and unspecific.
  • Flow is unreflectively assumed to always be the faster method.
  • Memory items get confused with regular checklist items, even though they require immediate action without consulting a list first.

Sources

This article is provided for general information and reflects the sources consulted at the time of publication. It does not constitute legal advice or an authoritative statement by an aviation authority. The applicable laws, regulations, and the current guidance and decisions of the competent aviation authorities always take precedence.