Aerospace

Virgin Galactic: how a missing interlock turned human error fatal

Case file #47·August 12, 2026·6 min read·analysis by Peter Stasko

Case file

  • What happened: On 31 October 2014, Virgin Galactic's SpaceShipTwo VSS Enterprise broke apart in mid-air over the Mojave Desert during a rocket-powered test flight, killing co-pilot Michael Alsbury and seriously injuring pilot Peter Siebold.
  • Scale: One fatality, one serious injury, total loss of a crewed flight vehicle, and a multi-year suspension of the commercial spaceflight programme.
  • Root cause: The co-pilot prematurely unlocked the "feather" descent system at roughly Mach 1 instead of the prescribed Mach 1.4. The system imposed no mechanical or software interlock to prevent deployment at a speed where aerodynamic forces would force the tail booms into their feathered position and tear the airframe apart.
  • The bill: One life lost, a second nearly taken, the complete destruction of a vehicle reportedly valued in the hundreds of millions of dollars, and credibility damage from which the programme took years to recover.
I have sat in enough 8D review rooms to know the pattern. The room goes quiet. The timeline goes on the wall. The discussion drifts toward "operator error." Someone reaches for stricter procedures, a re-training plan, perhaps a new placard on the station. I stop them. If a single human action, taken a few seconds early, can tear apart a crewed spacecraft and kill someone, the problem is not the human. It never was. The problem is upstream — in a failure mode analysis that recognised the hazard and then accepted it.
1co-pilot killed
Mach 1premature unlock speed
0interlocks on the feather lever

The situation

VSS Enterprise was the second SpaceShipTwo vehicle built by Scaled Composites for Virgin Galactic. The feather system — a pair of tail booms that rotate upward to create drag for atmospheric re-entry — was the design's signature innovation, borrowed from the smaller SpaceShipOne. In normal operation, the pilot unlocks the feather at Mach 1.4, where aerodynamic loads are low enough that the booms stay stowed until a second command actuates rotation. Unlock earlier, and the same aero forces become destructive: the booms are pushed into feather uncommanded, structural limits are exceeded within seconds, and the airframe fails.

The test flight on 31 October 2014 was the fourth powered flight of the vehicle. The crew had flown the profile before. The co-pilot, Michael Alsbury, was experienced. None of that mattered. The design had given him a lever he could pull at the wrong time, and nothing in the system architecture prevented it.

How it unfolded

Rocket ignition was nominal. The vehicle accelerated through the transonic regime. At roughly Mach 1, several seconds before the planned Mach 1.4 unlock point, Alsbury moved the feather unlock lever. Aerodynamic forces immediately forced the tail booms into the feathered position. The vehicle broke apart moments later. Siebold survived because his seat and harness separated cleanly enough that he free-fell, unconscious, from an altitude estimated at roughly 50,000 feet. He regained consciousness during descent and deployed his parachute. Alsbury did not survive.

The NTSB investigation that followed was unequivocal on one point: the co-pilot's premature action was a probable cause. But the board was equally clear on the second — that the system design allowed a single human error to become catastrophic, and that Scaled Composites had not adequately considered this failure mode.

Root-cause anatomy

Technically, the failure is straightforward: an unlock mechanism with no speed-aware interlock, coupled to aerodynamic forces capable of destroying the vehicle if actuated outside a defined envelope. A textbook single-point failure. One action, one path, no redundancy, no physical prevention.

The organisational story underneath is worse. The PFMEA — if it was performed rigorously — should have identified "premature unlock" as a failure mode with severity rated at the highest possible level, because the consequence was loss of vehicle and crew. Having identified it, the engineering controls hierarchy demands that you eliminate the hazard or engineer it out. A checklist item is administrative control. It sits at the bottom of the hierarchy, below PPE. It is the weakest defence you can mount against a catastrophic risk.

If a single human action can destroy your system, the defect is not in the human. The defect is in the analysis that accepted the design.

Where the quality system failed

The discipline that failed here is PFMEA, and specifically its interface with design controls under the APQP framework. Consider the line items that should have existed:

  • Failure mode: feather unlock commanded outside safe speed envelope.
  • Severity: 10 — catastrophic, loss of life and vehicle.
  • Current controls — prevention: crew procedure only.
  • Detection: none. The system would not flag a premature command, nor would it prevent it.

That PFMEA line, if written honestly, would have screamed. A severity of 10 with prevention controls limited to "procedure" is an unacceptable residual risk by any aerospace or automotive standard I have worked under — AS9100, IATF 16949, ISO 9001, all of them. The CAPA gate should have caught it. Design review should have caught it. Change control, when the feather system was adapted from SpaceShipOne's smaller envelope to SpaceShipTwo's higher-energy regime, should have re-examined whether the original assumptions about actuation speed still held.

None of that happened, or if it did, the documentation did not survive the NTSB's scrutiny.

What would have caught it

A mechanical interlock tied to airspeed — a pin or locking mechanism that physically prevents the unlock lever from moving until the vehicle is within the safe envelope. Or a software gate that ignores the unlock command when Mach number is outside the validated range. Either solution is standard practice in flight control systems across the industry. Scaled Composites had flown the feather concept successfully on SpaceShipOne, but the larger vehicle operated in a more demanding envelope, and the design did not adapt the controls to match.

In two decades of quality work across automotive and aerospace, the principle holds whether the product is a seat latch or a flight control: if the severity is catastrophic, you do not delegate prevention to training. You engineer the impossible state out of existence. A poka-yoke that physically blocks the wrong action. An interlock that makes the error mechanically impossible. A sensor that detects the out-of-sequence condition and halts the process. The hierarchy of controls exists for a reason, and the reason is that humans will eventually do everything the system allows them to do — including the things that kill people.

My take

Across two decades in automotive and aerospace quality, I have seen this pattern repeat in lower-stakes contexts. An operator installs a fastener in the wrong sequence and the joint fails. A technician skips a torque step and a brake caliper walks loose. In every case, the first instinct of the organisation is to retrain the operator. And in every case, the correct response is to redesign the station so the error cannot occur. At Witte Automotive, I drove substantial failure-cost reduction not by writing better work instructions but by enforcing engineering controls — sensors, fixtures, blocking pins — that made the defect physically impossible. At SNOP, building a greenfield QA function for over 900 people, the same principle applied: systems before people, interlocks before instructions.

The VSS Enterprise crash is the same failure, written in the most expensive and tragic ink possible. A lever without an interlock is not a design. It is a bet that no one will ever pull it at the wrong moment. In aerospace, that bet will eventually be lost.

What this means on your floor

  • If your PFMEA lists a catastrophic failure mode with "operator procedure" as the only prevention control, you do not have a control. You have a deferred incident.
  • Engineering controls — interlocks, poka-yoke, hard stops, sensor-based inhibits — must be mandatory for any failure mode rated at the highest severity, regardless of occurrence probability.
  • When a design is scaled from one application to another, revisit every original assumption. SpaceShipOne's feather worked. That does not mean SpaceShipTwo's feather would, at higher energy and speed.
  • CAPA systems must require evidence that residual risk has been reduced to acceptable levels, not merely documented and accepted.

VSS Enterprise did not fail because a co-pilot pulled a lever a few seconds early. It failed because an engineering organisation, somewhere between the PFMEA worksheet and the design review, accepted that a single premature human action could destroy the vehicle and kill the crew — and decided that was tolerable. That decision is the root cause. Everything else is consequence.

This case file analyses publicly documented events and reports. I had no involvement in the engagements described; company statements and official findings are matters of public record. The lessons and opinions are my own.

Peter Stasko

Peter Stasko

Corporate operator across automotive and aerospace — Airbus, SNOP and Witte Automotive. Building production AI hands-on since 2016.

Seeing the same failure mode on your floor?

Every case in this library ended as a headline. A one-hour conversation is cheaper. No slides, no pitch — just an experienced pair of eyes on your situation.

Book a conversation