Ask a Kenyan student pilot what framework they use for risk and you get PAVE, IMSAFE, maybe DECIDE if their instructor is thorough. Ask an airline captain the same question and you get a different name entirely: Threat and Error Management, TEM.
Almost no PPL or CPL syllabus at the flying-school level in Kenya teaches TEM by name, even though the regulator your school answers to already expects human-factors training from its instructors. That gap is the subject of this article.
The Short Version
- Threat and Error Management (TEM) is the framework airlines use to manage everyday hazards and mistakes, built from real flight-deck observation, not theory.
- It has three parts: threats you did not create, errors you did, and undesired aircraft states, the point where the first two turn into something that actually threatens the flight.
- TEM is not a replacement for PAVE or IMSAFE. Those are pre-flight go or no-go tools; TEM works during the flight and in the debrief afterward.
- Kenyan training already has a specific, nameable set of threats: thin weather reporting away from five towered fields, shared fleets, murram and grass surfaces, wildlife on bush strips, and a congested Wilson frequency.
- You do not need an airline's safety department to use TEM. A five-minute debrief structure, run after every lesson, gets you most of the value.
What TEM actually is
TEM is not a checklist and it is not a mood. It is a way of describing what happens on every flight, built around three components that SKYbrary's operational summary lays out plainly: threats, errors, and undesired aircraft states.
A threat is anything that increases the complexity of the flight and sits outside your control: weather, a rushed handover, an unfamiliar aerodrome. An error is something you or your crew actually did or failed to do, a wrong readback, a missed checklist item, a late flap selection.
An undesired aircraft state is what happens when a threat or an error gets away from you, an unstable approach, a track deviation, an aircraft that ends up somewhere it should not be. The whole point of TEM is that none of these three are failures on their own.
They are ordinary. What matters is whether you catch them before they compound.
Where this came from, and why it is not a fad
TEM was not invented in a classroom. It grew out of the University of Texas Human Factors Research Project's observation of real airline flight decks in normal operations, work later summarised by ICAO's own flight safety programme in a journal article by Captain Daniel Maurino that is still hosted in SKYbrary's bookshelf.
The researchers were not looking for accidents. They were watching ordinary, successful flights, and they found that every single one of them involved crews managing threats and catching their own errors constantly, all flight, every flight.
That finding reframed the entire safety conversation. The old model assumed good pilots simply do not make errors; TEM starts from the opposite, better-supported assumption that error is a normal part of human performance and the job is to build a system that catches it.
Regulators noticed. Australia's Civil Aviation Safety Authority made TEM a mandatory assessment item on private and commercial pilot flight tests and human-factors exams from July 2009, a regulatory shift documented in the peer-reviewed case study by Lee, Bates, Murray, and Zhang on TEM's implementation across Australian general aviation.
Transport Canada and New Zealand's Civil Aviation Authority both now publish TEM material aimed squarely at general aviation, not just airline crews, which is worth noticing. Transport Canada's introduction and the New Zealand CAA's awareness material both frame TEM as something a single pilot in a C172 needs as much as a two-crew jet.
The three parts, and why the order matters
Threats: anticipated, unexpected, and latent
EASA's own TEM guidance splits threats into three kinds, and the split is genuinely useful, not academic. Anticipated threats are ones you can brief for, a forecast crosswind, a busy circuit.
Unexpected threats appear without warning, a sudden aircraft malfunction, a NOTAM you missed. Latent threats are the quiet ones baked into the system itself, a scheduling practice, a runway with a known optical illusion, a habit your school has always had that nobody has questioned.
Most training only teaches you to brief the first kind. The second and third kinds are exactly where accidents actually start.
Errors: what you do about the threat, or fail to do
EASA's material describes three ways a crew responds to an error once it exists. It gets trapped, caught and corrected before it costs anything.
It gets exacerbated, noticed but handled badly, making things worse rather than better. Or it goes unmanaged entirely, because nobody noticed it at all.
Only one of those three outcomes is actually fine. The other two are how an ordinary mistake becomes a story you tell afterward, if you are lucky enough to still be telling stories.
Undesired aircraft states: the last exit before an unsafe outcome
SKYbrary's material calls undesired aircraft state management "as important as threat and error management" itself, and the reasoning is straightforward. By the time you are in one, an unstable approach, a track you should not be on, a configuration that is wrong for the phase of flight, threat and error management have already failed somewhere upstream.
Recognising the state itself, and having a rehearsed response, a go-around, a level-off, a return to a known-good point, is your last chance to keep a mismanaged threat from becoming an incident.
A worked example, because the theory means nothing until you see it happen
Picture a solo cross-country from Wilson toward Naivasha. The forecast crosswind at Wilson is an anticipated threat, briefed and accepted before start-up.
Thirty minutes in, a NOTAM you did not catch on your pre-flight brief closes part of your intended routing, an unexpected threat you are now meeting in the air rather than on the ground. If you notice it early and reroute calmly, that is a trapped threat, no harm done.
If you notice it late, get flustered, and let your altitude drift while you argue with the chart on your lap, that is an exacerbated error, and a drifting altitude near rising terrain is exactly the undesired aircraft state this whole framework exists to catch before it becomes something worse. Nothing in that sequence required a mechanical failure or a dramatic mistake.
It required one missed NOTAM and one moment of poor error recovery, which is precisely the ordinary, survivable chain TEM is built to interrupt.
TEM is not PAVE, and it is not IMSAFE
Our piece comparing PAVE, DECIDE, and 3P makes the point that different frameworks solve different moments in a flight. PAVE and IMSAFE are pre-flight tools, they ask whether you should launch at all, using information you have before the engine starts.
TEM does not replace that question. It picks up exactly where PAVE and IMSAFE stop, inside the flight itself and in the debrief afterward, tracking what actually happened rather than what you predicted would happen.
A clean PAVE assessment and a perfect IMSAFE check do not stop a missed NOTAM from becoming a threat at 4,500 feet. Only a TEM habit, noticing it, naming it, and correctly classifying your own response to it, does that.
Kenya's threats have names. Use them.
Generic TEM material talks about weather and workload in the abstract. Kenyan training has specific, recurring threats that deserve to be named exactly, not gestured at.
Anticipated threats in Kenyan training are the ones every syllabus already covers somewhat: a forecast crosswind on a murram strip, known convective buildup over the Rift Valley escarpment in the afternoon, a busy Wilson frequency during peak training hours.
Unexpected threats show up more often here than the generic material assumes, precisely because Kenya's weather-reporting network is thin. Wilson, Jomo Kenyatta, Mombasa, Kisumu, and Eldoret carry METAR reporting; the great majority of Kenya's other licensed and private aerodromes do not, which means an in-flight weather change on an upcountry route is far more likely to arrive as a genuine surprise than the same change would on a route with denser reporting.
Latent threats are the ones worth sitting with, because they are baked into how Kenyan schools run rather than into any single flight. A shared training fleet that pressures every student to fly through a marginal day rather than lose an irreplaceable slot is a latent threat with a schedule attached to it, not a personal failing of the student who accepts it.
Wildlife on an unlicensed bush strip, a runway surface that shifts from grass to mud within a single rainstorm, an examiner's diary that only opens once a month, these are threats too, and naming them as threats rather than as background noise is the entire discipline TEM asks of you.
Do not try to build an airline safety department at your flying school
Here is the honest opinion this piece is going to commit to. Most Kenyan flying schools should not attempt a full, airline-style TEM programme, and trying to import one wholesale will fail.
The peer-reviewed case study of TEM's rollout across Australian general aviation by Lee, Bates, Murray, and Martin found exactly this problem even in a country with a mandatory regulatory push behind it. Small GA operations lack the formal reporting systems, dedicated safety staff, and structured audit data that make airline-style TEM programmes work, and bolting that machinery onto a small ATO produces paperwork nobody reads rather than a safer cockpit.
The lesson is not to abandon TEM. It is to strip it down to the two or three habits that do not require a safety department to run, which is exactly what the rest of this article gives you.
A debrief structure any CFI can run in five minutes
A good CFI (Certified Flight Instructor) already debriefs every lesson. The change TEM asks for is not more time, it is a sharper structure for the same conversation.
Kenya's own Civil Aviation (Personnel Licensing) Regulations, 2018 already sit behind the human-performance training every KCAA-approved training organisation's instructional staff must complete. Ask your Head of Training exactly what that covers at your school, but TEM is the sharpest, cheapest way to put that kind of training into daily practice rather than leaving it as a line in a manual nobody re-reads after the initial course.
Three questions, asked after every lesson, do most of the work:
- What threats actually showed up today? Name them specifically: the crosswind that arrived early, the radio call that came in faster than expected, the NOTAM neither of you had briefed.
- Did we trap it, exacerbate it, or miss it entirely? Say the actual word. "We trapped it" and "we missed it" are both useful data; a vague "it worked out fine" is not.
- Did anything become an undesired aircraft state, even briefly? An altitude bust corrected in five seconds still counts, and naming it small, while it is still small, is exactly how you keep it small next time.
A pre-brief that deliberately embeds one manageable threat, a slightly non-standard radio call, a runway change announced late, gives the debrief something concrete to reference. Referring back to what was briefed before the flight, rather than judging performance in a vacuum, is a practice worth building deliberately.
Self-debriefing after a solo, without anyone in the other seat
A solo student does not get the benefit of a second set of eyes running the same three questions, which makes the habit more important, not less. Land, shut down, and before you walk to the school office, answer the same three questions honestly on paper.
Name the threat, name your response to it, name whether anything briefly became an undesired state. Do this even, especially, after a flight that felt uneventful, because uneventful and well-managed are not the same thing, and the only way to tell them apart is to look.
What pilots admit on the forums
TEM-adjacent threads on pilot forums have a recognisable pattern, and it rarely involves a single dramatic failure. The recurring shape is a chain: one small threat noticed late, one error made worse by the scramble to catch up, and a near miss that in hindsight had two or three earlier points where a calm response would have ended the sequence.
What comes up again and again is pilots realising, only after the fact, that they never had a name for what was happening while it was happening. They describe noticing something was "off" without being able to say whether it was a threat they had not briefed, an error they had not caught, or a state they had already drifted into.
That gap, between sensing a problem and being able to classify it while there is still time to act, is precisely what a TEM vocabulary closes.
AngaBrief's assessment wizard focuses on the pre-flight PAVE and IMSAFE picture, not on in-flight threat management, and it makes no claim to be a dispatch authority. The framework in this article belongs in your instructor's debrief chair and your own post-flight habit, and the decision to fly, continue, or divert always rests with the pilot in command and their instructor.
Key Takeaways
- Threat and Error Management has three parts: threats you did not create, errors you did, and undesired aircraft states where the two combine into real danger.
- TEM assumes error is normal and builds a system to catch it, rather than assuming good pilots simply do not make mistakes.
- TEM works during and after the flight, picking up exactly where pre-flight tools like PAVE and IMSAFE leave off.
- Kenyan training has specific, nameable threats: thin weather reporting upcountry, shared fleets, murram and grass surfaces, wildlife on bush strips, and scheduling pressure.
- Skip the airline-style safety department. A three-question debrief, run after every lesson or every solo, delivers most of TEM's value for free.
