
The Anatomy of a Crisis: Lessons from the Vale Dam Collapse
The Brumadinho dam collapse was not an unforeseeable accident; it was a catastrophic governance failure rooted in the normalization of deviance and the suppression of bad news. This analysis breaks down the behavioral drivers behind the tragedy and the critical lessons for risk and compliance leaders.
On January 25, 2019, the Brumadinho dam in Brazil, owned by the mining giant Vale S.A., collapsed, unleashing a torrent of toxic mud that killed 270 people. This was not merely an engineering problem; it was a profound failure of governance, culture, and human risk management. The disaster revealed a corporate culture where warnings were systematically ignored, and the pressure to maintain production overrode clear safety imperatives. For compliance and risk leaders, the Vale case is a sobering lesson in how organizational behavior, not just structural safeguards, creates the conditions for catastrophe.
Most governance, risk, and compliance (GRC) frameworks are designed to monitor known, quantifiable risks. They excel at tracking policy adherence, system controls, and financial irregularities. Where they fail, as the Vale tragedy demonstrates, is in detecting the slow, creeping normalization of deviance—the process by which unacceptable practices become acceptable over time. The organization had the data, the audits, and the technical reports, yet the system as a whole failed to act. This is because traditional GRC systems are blind to the human factors that distort how risk is perceived and communicated, particularly the fear of speaking up.
This gap between data and decision-making is where human risk lives. It’s the space where an engineer feels unable to deliver bad news to a manager, where a team rationalizes a small anomaly to avoid a shutdown, and where executives unconsciously filter out information that contradicts production goals. Emerald EI Academy focuses on this human layer, examining the behavioral drivers—like pressure, fear, and cognitive biases—that lead well-intentioned people to make catastrophic decisions. The Vale collapse was not a "bad apple" problem; it was a systemic failure of human risk governance.
What the research shows is that disasters are rarely sudden events. They are the outcome of accumulated, unaddressed problems. Organizational theorist Diane Vaughan famously termed this phenomenon the "normalization of deviance" in her study of the Space Shuttle Challenger disaster. It describes how organizations can incrementally accept lower and lower standards of performance until those lower standards become the new normal. At Vale, internal and external auditors had repeatedly warned about the dam's instability. Yet, with each warning that didn't result in immediate failure, the organization's tolerance for the risk grew. The deviation from safety standards became the accepted baseline.
A second critical finding comes from research on psychological safety, pioneered by Harvard’s Amy Edmondson. Psychological safety is the shared belief that a team is safe for interpersonal risk-taking, like speaking up with a concern or admitting a mistake. In environments lacking this safety, information is suppressed. A 2019 report revealed that Vale engineers felt pressured to certify the dam's stability despite their reservations. This illustrates a classic breakdown of psychological safety, where the perceived career risk of raising an alarm outweighs the perceived organizational risk of staying silent. Without psychological safety, all other compliance controls are built on a foundation of sand.
Finally, the concept of "willful blindness," explored by Margaret Heffernan, explains why leaders often ignore obvious threats. Leaders aren’t just uninformed; they are often surrounded by systems and people that actively filter out inconvenient truths. This is driven by a mix of cognitive biases, such as confirmation bias (favoring information that confirms existing beliefs) and the powerful incentive to maintain operational momentum. At Vale, the executive focus on production and cost-efficiency created a powerful incentive structure that made the inconvenient truth of the dam’s instability a threat to careers and bonuses, leading to its systemic avoidance.
Why does this matter for governance and compliance leaders today? Because regulators are no longer just looking at whether you have a program; they are scrutinizing its effectiveness in practice. The U.S. Department of Justice’s Evaluation of Corporate Compliance Programs guidance explicitly asks prosecutors to assess whether a company’s compliance program is “being implemented effectively.” This includes evaluating if employees are comfortable raising concerns without fear of retaliation—a direct inquiry into the state of psychological safety. The Vale case shows that having audit reports is meaningless if the culture prevents those reports from being acted upon.
The legal and financial consequences are staggering. In 2021, Vale agreed to pay over $7 billion in compensation. Several employees and executives were charged with homicide. For any publicly traded company, a similar failure in risk oversight could trigger shareholder derivative lawsuits, massive regulatory fines, and irreparable reputational damage. The lesson is clear: a compliance program that cannot prove it fosters a culture of open communication and responds to bad news is, in the eyes of regulators, a failed program. This is the central challenge of modern human risk governance.
Traditional compliance approaches are ill-equipped to solve this. They rely on annual training, policy attestations, and whistleblower hotlines—tools that are passive and reactive. Training can’t teach courage, and a policy cannot create psychological safety. Hotlines are a last resort for when the organizational culture has already failed. These methods do not measure the precursor behaviors that lead to misconduct or disaster. They measure completion, not competency; policy awareness, not the pressure to ignore it.
These legacy systems fail because they treat humans as a source of error to be controlled by rules, rather than a source of insight to be cultivated. They are designed to manage conformity, not to encourage the very dissent and constructive conflict that uncovers hidden risks. By focusing on documented controls, organizations create a "compliance mirage"—a program that looks robust on paper but collapses under real-world operational and social pressures, as seen in the Anatomy of a Cultural Collapse: Lessons from Wells Fargo.
A Human Risk Governance perspective reframes the problem entirely. It posits that risk lives in the daily decisions and interactions of people, not just in systems and spreadsheets. The most critical risk data isn't in an audit report; it's in the "near miss" conversations that never happen, the safety concerns that go unvoiced, and the meetings where teams rationalize away a known problem. The goal is not just to document controls, but to create an environment where risk-relevant information flows freely and is acted upon.
Emerald EI Academy applies behavioral science to make these invisible dynamics visible and measurable. This involves assessing the specific emotional competencies—like self-awareness and empathy—that enable leaders to create psychological safety and the organizational factors that promote it. It shifts the focus from blaming individuals for failure to examining the systemic pressures and cultural norms that shaped their choices. This is the only way to move from a reactive, "check-the-box" posture to a proactive, evidence-based system of governance, one that can withstand regulatory scrutiny in the wake of a crisis like the one described in "The Willful Blindness Paradox: Why Leaders Ignore Obvious Risk."