"Any Landing You Can Walk Away From" Is Not the Standard
There’s a piece of hangar wisdom that gets repeated so often it stops being examined: any landing you can walk away from is a good landing. It’s meant as reassurance, and as reassurance it’s fine. As a standard for judging Aeronautical Decision Making, it’s wrong, and the way it’s wrong is worth taking seriously, because the same error shows up in how pilots judge decisions after the fact, how they make decisions in the moment, and eventually how entire operations redefine what “normal” risk looks like.
This isn’t really about any one accident. The error applies generally, but three specific failures of judgment are worth pulling apart because they each hide behind good outcomes in different ways.
What “walking away” actually tells you
Walking away from a landing tells you exactly one thing: you survived it. That’s not nothing (survival matters, obviously), but it’s a statement about the outcome, not about the decisions that produced it. ADM is the evaluation of the decisions: what you knew, what risks you identified, what options were actually available to you, what you chose, and why.
Outcome and decision quality are correlated, but they are not the same variable, and conflating them is a specific, well-documented error called outcome bias: judging the quality of a decision by how it turned out rather than by whether it was reasonable given what was known at the time. It’s one of the more stubborn biases in human judgment because it feels like evidence. A good outcome feels like proof of a good decision. It isn’t.
A good outcome doesn’t prove good ADM. You can make a bad decision: fly into deteriorating weather you should have avoided, continue an approach past a stabilized-approach gate, take off into known icing with inadequate protection, and get away with it. The airplane doesn’t know you made a mistake, and physics doesn’t automatically punish bad decisions; it just makes them more likely to go wrong. Getting away with a bad decision doesn’t make it a good one, and it’s not something you can count on repeating.
A bad outcome doesn’t prove bad ADM either. This one is less comfortable, because it means a pilot can do everything right and still end up somewhere bad. You can gather the available information, weigh the real risks, choose a reasonable course of action, and still get bitten — by a mechanical failure you had no way to anticipate, by conditions that changed faster than forecast, by something genuinely outside the envelope of what a reasonable pilot would have planned for. ADM is not a guarantee against bad outcomes. It’s a discipline for improving the odds and for making sure that when things do go wrong, they go wrong for reasons outside your control rather than reasons inside your judgment.
If you accept both of these, the walk-away standard collapses. It’s measuring the wrong thing entirely: outcome, when the thing that actually reflects a pilot’s skill and judgment is the decision process, which happened before the outcome was determined.
The second trap: protecting the airplane
There’s a second failure mode that gets tangled up with the first one but is actually mechanically different, and it’s worth separating clearly because it operates at a different point in time.
Outcome bias is a retrospective judgment error: it’s how you (or an instructor, or an accident board) mis-evaluate a decision after the fact by looking at how it turned out. “Save the airplane” is a real-time decision error: it’s a bias that operates while you’re still flying, actively distorting the decision itself as you’re making it.
The instinct to protect the aircraft is completely understandable. It’s expensive, it’s someone’s asset, and there’s a natural reluctance to be the pilot who put a dent in it or worse. But that reluctance can quietly become its own decision-making trap. Trying to save the airplane can push a pilot to stretch a bad situation past the point where it should have been abandoned: to keep the gear up a little longer, to try one more approach, to delay a decision that should have already been made, all in the service of protecting hardware rather than protecting the flight.
The airplane is replaceable. Insurance exists for exactly this reason. You are not replaceable, and neither is anyone else on board. When “don’t damage the airplane” competes with “make the safest decision available,” and the airplane wins that competition, that’s not good ADM wearing a conservative face. It’s a bias with a sympathetic cover story.
Which means good ADM sometimes is choosing to damage the airplane, not as an unfortunate side effect of a decision made for other reasons, but as the correct decision itself. An engine failure over terrain with no good runway in glide range and a marginal field is the clearest version of this: stretching the glide to reach pavement, rather than committing early to the field you can actually make, is exactly the “save the airplane” trap in action. The pilot who takes the field, accepting a gear-up, a prop strike, real damage, while there was still altitude and airspeed to work with is very likely making the better decision, even though it costs more in dollars than the pilot who gambled on the runway and got there. If the standard were “did you save the airplane,” that pilot made the wrong call. By the actual standard (given what I knew, did I make the best decision I reasonably could), they didn’t.
There’s a starker version of the same trap in a gear-up landing. Some pilots, forced into an unplanned gear-up on short final, will try to shut the engine down and secure the prop in those last seconds specifically to avoid a prop strike and the mandatory teardown that follows, trying to save the engine and the money it represents. That’s exactly the wrong moment to be running an engine-securing checklist. Short final in a degraded airplane is already maximum workload, and diverting attention to protect a component has caused pilots to lose control of the airplane. This isn’t hypothetical. It’s a pattern that shows up in accident reports: stalls and crashes that kill everyone on board, over a decision that was never actually about survival. Once you’re in that situation, the insurance company owns the airplane. The only decision that matters is flying it under control to the ground. Good ADM may not save the plane, and worrying about the parts instead of the flight path is how “save the airplane” gets people killed rather than just costing them money.
But choosing to sacrifice the airplane is only good ADM when it’s actually the best option available. If there’s a runway cleared for you with fire rescue standing by and emergency procedures you haven’t finished working, abandoning that for something that feels safer isn’t prioritizing survival over hardware. It’s a failure to evaluate what was actually available before committing.
This is why walk-away and save-the-plane are not two versions of the same idea, even though they get invoked together. Walk-away is an after-the-fact yardstick that rewards good luck. Save-the-plane is an in-the-moment pressure that can actively produce worse decisions. Both are wrong, but they’re wrong in different places and for different reasons, and a pilot needs to guard against both separately.
What the actual standard is
If neither “did I walk away” nor “did I save the airplane” is the standard, what is?
That’s it. The standard is about the quality of the reasoning process at the moment the decision was made, evaluated against the information that was actually available then, not the information that showed up afterward, and not how things happened to turn out.
This is harder to apply than the walk-away rule, because it requires actual self-scrutiny rather than a pass/fail check against whether you’re still alive. A useful decision, evaluated honestly, should be able to answer a few concrete questions:
- Did I have a plan for what I’d do if conditions changed, or was I purely reacting?
- Did I use the information and resources actually available to me (weather briefings, aircraft performance data, ATC, other pilots’ reports), or did I skip steps under time pressure?
- Did I reassess as new information came in, or did I lock onto an earlier decision and defend it past the point it made sense?
- Was there a point where a reasonable pilot with my training would have chosen differently, and if so, why didn’t I?
None of these questions can be answered by looking at whether the landing was survivable or the airplane came home undamaged. They can only be answered by reconstructing the decision itself.
Why this matters beyond any single flight: normalization of deviance
Here’s where this stops being just an individual-decision problem and becomes a cultural one.
Outcome bias doesn’t just distort how you judge a single flight in isolation. It compounds. Every time a marginal decision produces a fine outcome, it quietly recalibrates what feels acceptable next time. Skip a preflight item and nothing happens — the mental bar for “this is fine to skip” drops slightly. Push a personal weather minimum and land safely, the minimum quietly shifts. No single instance feels like a big deal, because in isolation, each one worked. That’s exactly the mechanism.
Sociologist Diane Vaughan called this normalization of deviance. I’ve written about the mechanism in detail before. The pattern it creates is specific: each departure from the standard gets followed by a good outcome, which quietly lowers the bar for next time, until a genuinely marginal practice has become “just how we do it.”
This is what makes outcome bias more dangerous than a one-time judgment error. A pilot, or a flight department, or a training culture, that repeatedly rewards decisions based on outcome instead of process isn’t just making isolated mistakes. They’re training themselves, flight after flight, to recognize a lower and lower bar as the real standard. And because each individual step down feels small and each individual outcome feels fine, there’s rarely a moment that feels like a decision to accept more risk. It just accumulates until a flight happens where the accumulated risk finally meets circumstances that don’t forgive it.
The pattern shows up in ordinary, unglamorous places, which is exactly why it’s dangerous. Flying with an expired database because the airspace and procedures “probably” haven’t changed. Flying out of annual because the airplane “flew fine yesterday” and the paperwork is just paperwork. Cutting the preflight short because you did a full one yesterday and nothing’s touched the airplane since. None of these, individually, look like a decision to accept more risk. Each one gets rationalized on its own terms, and each one, so far, has been followed by a normal flight, which is exactly the reinforcement that makes the next shortcut easier to take.
I’ve done this myself. Coming back from Las Vegas one night, over the southern Sierras near Bakersfield, South County (E16) was reporting IFR and my airplane wasn’t equipped for an RNAV approach. I made a bet that I could sneak under the clouds south of Hollister and run at 1,300 feet all the way up to E16. It worked. I landed fine. But the decision to press into marginal conditions in the mountains at night, in an airplane that couldn’t shoot the approach if I needed one, wasn’t a decision I’d have made at 2 in the afternoon. I made it at 1 AM because I had get-there-itis — I just wanted to be home, and because every other time I’d pushed a marginal weather call on a familiar route, it had worked out. That history of good outcomes wasn’t evidence that the decision was sound. It was the accumulated drift that made a genuinely risky call feel routine.
This is also why “any landing you can walk away from is a good landing” is worse than merely imprecise. It’s actively corrosive as a repeated standard. Every time it gets applied as the actual yardstick, it rewards outcome over process by definition, and does exactly the compounding work described above. A pilot who has internalized it as their real standard isn’t just occasionally miscalibrated. They’re on a specific trajectory toward normalized deviance, one successful outcome at a time.
The actual discipline
Outcomes still matter, and a pattern of bad outcomes is real information. But outcomes are a contaminated measure of decision quality, because luck runs in both directions: good luck can make a bad decision look fine, and bad luck can make a good decision look catastrophic. Using outcome as the primary yardstick means your judgment gets calibrated by noise as much as by signal.
The discipline is to evaluate decisions on their own terms, using the information available at the time they were made, independent of how things turned out, and to do that consistently enough that it doesn’t get quietly replaced by “well, it worked out” as the real standard. That’s harder than checking whether you walked away, and it’s slower to feel satisfying. It’s also the only version of ADM that actually improves your judgment instead of just confirming whatever you already did.
David Stites, MEI
Multi-engine flight instructor and professional ferry pilot in the San Francisco Bay Area.
Ready to Start Your Multi-Engine Training?
Contact me today to discuss your training goals and schedule your first lesson.
Get in Touch