The Boeing Seven Thirty-Seven MAX, the MCAS, and the Two Crashes That Changed How Aviation Certifies Cockpit Automation

How MCAS design flaws and a broken certification process caused 346 deaths across two 737 MAX crashes and permanently changed how aviation certifies cockpit automation.

Aviation Technology Analyst

The Boeing 737 MAX’s Maneuvering Characteristics Augmentation System - the MCAS - caused two fatal accidents in five months: Lion Air Flight 610 on October 29, 2018, and Ethiopian Airlines Flight 302 on March 10, 2019, killing 346 people combined. Both crews fought a flight control system they had never been fully trained to understand. The investigations that followed didn’t just ground a fleet - they exposed systemic failures in how the FAA certifies automated aircraft systems and how much commercial pressure a manufacturer can apply before safety margins erode.

Why Boeing Built the 737 MAX - and the Corner It Painted Itself Into

The Boeing 737 has been in production since 1968. More than 10,000 have been built and delivered, making it the best-selling commercial jet in history. That legacy created enormous economic inertia: airlines had type-rated pilots, trained mechanics, and amortized infrastructure. When Airbus launched the A320neo family in 2010 - a fuel-efficient competitor threatening significant market share - Boeing faced a choice between building an entirely new aircraft (a ten-to-fifteen year, multi-billion-dollar program) or updating the 737 again. Boeing chose to update.

The catch was the engine. The new CFM International LEAP powerplant is substantially larger in diameter than the engine the 737 was originally designed to carry. The 737 was built as a low-slung short-haul aircraft, close to the ground, without the fuselage height to simply drop a bigger engine in place. To fit the LEAP under the wing, Boeing moved it forward and higher on the pylon. That repositioning changed the aerodynamics of the entire powerplant installation.

At high angles of attack, the new engine position created a pitch-up moment absent in previous 737 generations. The aircraft wanted to climb more aggressively with the nose high and speed low.

Why Boeing Chose Software Instead of Airframe Changes

The aerodynamic problem had structural solutions: a taller landing gear, a revised fuselage, a modified wing. But any of those changes would have triggered a new type certificate - full recertification and, critically, full pilot training requirements including simulator time. Simulator transitions cost airlines millions of dollars per pilot. American Airlines alone had thousands of pilots to convert.

Boeing instead designed a software fix. The MCAS would sense when the aircraft approached a high angle of attack and automatically apply nose-down stabilizer trim, making the MAX handle like the previous 737 generation. If it handled the same, the FAA could authorize transition training without simulator time. The economics were compelling. The decision was not irrational on its face. What followed was.

How the MCAS Design Changed - and What Wasn’t Disclosed

The MCAS as originally submitted for certification was authorized to move the horizontal stabilizer by 0.6 degrees per activation. By the time the aircraft was certified and flying, that authority had grown to 2.5 degrees per activation. The system could activate up to ten consecutive times - a total potential stabilizer deflection of 25 degrees nose-down from a system pilots hadn’t been told existed.

The revised authority figures were not fully disclosed to the FAA in the manner the original safety assessment required. The safety documentation on file described the earlier, lower-authority design. What actually flew had more than four times that authority.

Internal Boeing communications reviewed during the congressional investigation documented engineers raising concerns during development. One engineer wrote that the MAX was “designed by clowns supervised by monkeys” - a line that became widely quoted during hearings. Those concerns did not stop the program.

The MCAS also drew its inputs from a single angle-of-attack sensor, despite the 737 MAX having two. If that one sensor produced an erroneous reading, the system would activate with no cause. There was no direct means for pilots to command the MCAS off. Boeing’s internal position was that a MCAS malfunction would present as a runaway trim condition, covered by the existing runaway stabilizer checklist - an assumption that turned out to be fatally flawed.

The Night Before: What the Prior Crew Encountered

The evening before the Lion Air accident, a different crew flew the same aircraft on the same route - from Bali to Jakarta. Around 10,000 feet, they encountered the same MCAS activation. They recovered by disabling the electric trim switches, which cut power to the system. The captain later reported he didn’t know what had caused the nose to pitch down; he only knew that cutting electric trim stopped it.

A maintenance write-up was logged, but the description was ambiguous. A replacement angle-of-attack sensor was installed. It was not verified for correct calibration after installation. It was reading 13 degrees higher than the actual angle of attack. The aircraft was released for the next day’s flights.

Lion Air Flight 610 - October 29, 2018

On October 29, 2018, Lion Air Flight 610 departed Jakarta with 181 people on board in a 737 MAX 8 that had been in service for fewer than three months. The miscalibrated sensor triggered the MCAS almost immediately after liftoff. The first officer, who was pilot flying, fought the system for most of the twelve-minute flight. Multiple interventions were attempted. The aircraft struck the Java Sea at approximately 500 miles per hour. Everyone on board was killed.

The accident investigation in Indonesia took months. Boeing issued service bulletins. The FAA issued airworthiness directives. Updated procedures and memos went to airlines. The MAX was not grounded.

Ethiopian Airlines Flight 302 - March 10, 2019

On March 10, 2019, Ethiopian Airlines Flight 302 departed Addis Ababa on a clear morning with 157 people on board. A disturbance near the angle-of-attack vanes shortly after takeoff - consistent with a bird strike - produced erroneous sensor readings that triggered the MCAS.

The crew had received Boeing’s post-Lion Air updated training, which now referenced the MCAS by name. They executed the updated procedure. They cut the electric trim switches. The nose began to stabilize.

What followed is the hardest detail in the accident record. With electric trim cut, the only way to adjust the stabilizer was the manual trim wheel. By this point the aircraft was at high speed and significantly out of trim. The manual wheel could not be effectively moved against the aerodynamic loads. The crew, apparently attempting to regain control authority, briefly re-engaged electric trim to reposition the stabilizer. In that window, the MCAS activated again, driving the stabilizer further into the dive range. The aircraft struck terrain near Bishoftu at high speed. All 157 people on board were killed.

The crew of Ethiopian 302 executed the procedure Boeing had revised specifically because of the first crash. It did not save them.

How the Grounding Happened - and Why It Took Two Crashes

Three days after the Ethiopian accident, China grounded the MAX. Within 24 hours, most major regulators worldwide followed. The FAA grounded the fleet on March 13, 2019 - after most other aviation authorities had already acted. The grounding lasted twenty months.

The delay between the two accidents had regulatory causes rooted in how certification authority was structured. The FAA had established the Organization Designation Authorization (ODA) program, under which designated Boeing employees performed certain certification functions on behalf of the FAA. The logic was capacity: the FAA doesn’t have enough engineers to personally review every system on every new aircraft. When those designated engineers are insulated from commercial pressure, the system can work. The congressional investigation found that Boeing managers had interfered with the certification process in ways that compromised that independence. Engineers who raised concerns about MCAS authority were overruled. Revised performance figures were not escalated through FAA channels as required.

This was an organizational failure as much as an engineering failure. The aviation safety system depends on institutional boundaries holding between the commercial interests of a manufacturer and the technical independence of certification. When that boundary erodes, the safety margin erodes with it.

What the Fix Required

The MCAS Boeing ultimately redesigned was substantially different from what had been certified:

  • The system now reads from both angle-of-attack sensors simultaneously. If the two sensors disagree by more than a defined threshold, the MCAS will not activate.
  • The system was limited to a single activation cycle per encounter.
  • Maximum stabilizer authority was reduced.
  • Full simulator training became required for pilots transitioning to the MAX - not tablet-only training.
  • The angle-of-attack disagree alert, previously an optional feature airlines could purchase separately, was made standard equipment.
  • New checklists and revised crew procedures were issued.

The 737 MAX returned to commercial service in November 2020. It is flying today on American, United, Southwest, Ryanair, and dozens of other carriers worldwide. Since recertification, the aircraft has accumulated millions of flight hours without another MCAS-related incident.

What Changed in How Aviation Certifies Automation

The certification reforms that followed the MAX investigations established new requirements for human factors evaluation. Any new automated cockpit system must now demonstrate, under realistic conditions, that a trained crew can recognize and respond to its failures - not just in a best-case scenario. That requirement sounds like a baseline that was always there. In the case of the MCAS, it was not the standard that was applied. Now it is written into the process, and regulators are checking compliance.

Why This Matters Beyond Airline Operations

Pilots who will never sit in a 737 MAX still have something to take from this.

Every automated system in a modern cockpit was designed by engineers who made assumptions about pilot knowledge, available information, and failure response. Glass cockpit systems in trainers and light aircraft include electronic stability augmentation, pitch compensation, autotrim, and in some cases emergency descent modes. Most are well-designed. Most are documented. The pilot’s operating handbook supplement for your avionics suite is not optional reading - it describes the systems that may intervene in aircraft control, the conditions that trigger them, and the conditions under which they fail.

The philosophy that enabled this accident - the assumption that pilots will recognize and recover from failures in systems they were never trained on - is not unique to one aircraft program. It was present when the first accident happened. It was still present when the second accident happened with a crew that had received updated training. It is worth examining in your own cockpit before it is tested in one.


Key Takeaways

  • The MCAS was designed to make the 737 MAX handle like previous 737 generations, specifically to avoid simulator training requirements - a commercial decision that shaped a safety-critical design.
  • The system’s certified authority was more than four times what original safety documents described, relied on a single sensor, and gave pilots no direct override.
  • Both accident crews were fighting a system they were not adequately trained to recognize. The Ethiopian crew followed Boeing’s post-Lion Air updated procedure. It still failed.
  • The FAA’s ODA certification framework allowed manufacturer commercial pressure to compromise the independence of safety evaluations - a structural problem, not just an engineering one.
  • Post-grounding reforms require dual-sensor inputs, single-cycle activation limits, reduced authority, mandatory simulator training, and human factors verification for any new automated system - standards that should have governed the original certification.

Sources: Indonesian National Transportation Safety Committee final report on Lion Air Flight 610; Ethiopian Accident Investigation Bureau report on Ethiopian Airlines Flight 302; House Transportation Committee report “The Design, Development and Certification of the Boeing 737 MAX,” September 2020; reporting by Dominic Gates, Seattle Times.

Radio Hangar. Aviation talk, built by pilots. Listen live | More articles