Summary

  • USS Fitzgerald and USS John S. McCain belong in the same institutional analysis because the Navy reviewed common readiness controls after both fatal collisions, but their immediate causal records must remain separate. Fitzgerald was a crossing-situation and bridge-team coordination failure; John S. McCain involved loss of situational awareness during a steering-control problem, deficient procedures and training, and a configuration that allowed unintended transfer of control.
  • Readiness certification should be treated as an auditable representation of demonstrated capability. Completed training events, nominal manning percentages and an administrative certification date are weak substitutes for evidence that a crew can navigate, coordinate, manage fatigue, understand its interfaces and respond correctly under realistic pressure.
  • The Navy, NTSB and GAO records serve different purposes. Accident investigations explain particular casualties; the Navy's comprehensive review examines service controls; the Fitzgerald supplemental inquiry documents post-impact response; and later GAO reports test whether repair mechanisms were implemented and evaluated. None of those scopes should be stretched to make claims it cannot support.
  • Accountability follows control. Watchstanders control immediate actions, ship commands control local preparation and watch organization, type and fleet commanders control certification and operational risk acceptance, headquarters influences policy and resources, and system authorities control bridge-interface design. Pairing the cases clarifies those layers without distributing blame indiscriminately.
  • Evidence of repair requires more than added course hours or closed action items. It requires reliable crewing data, independent performance assessment, realistic bridge and casualty drills, fatigue controls that work under operational demand, and feedback showing that policy changes produce durable proficiency rather than paper compliance.

Two casualties, one institutional test—and two different causal chains

The reason to study Fitzgerald and John S. McCain together is institutional, not mechanical. Fitzgerald collided with the container ship ACX Crystal off Japan on 17 June 2017. Seven sailors died. John S. McCain collided with the tanker Alnic MC near the Singapore Strait on 21 August 2017. Ten sailors died. The collisions occurred within the same forward-deployed fleet over a little more than two months, and the Navy responded with a comprehensive review that examined common controls across the surface force.

Later congressional oversight examined reforms involving training, fatigue, crewing, certification and the quality of readiness information. That shared response makes the cases a defensible pair.

It does not make them one accident. The distinction matters because institutional analysis becomes unreliable when a powerful systemic narrative erases the event-level record. Fitzgerald's bridge team faced a crossing situation in which the destroyer was the give-way vessel. The NTSB record identifies failure to take early and substantial action, weak cooperation between the bridge and combat information center, deficient transit planning, and contributing Navy oversight weaknesses involving scheduling, training and fatigue mitigation. John S. McCain's sequence centered on lost situational awareness during a steering-control problem.

The NTSB record identifies limited public evidence training, inadequate bridge procedures, ineffective operational oversight, failure to follow loss-of-steering procedures, and a steering configuration that allowed an unintended unilateral transfer of control.

Those are not interchangeable descriptions. Fitzgerald was not a steering-transfer casualty. John S. McCain was not simply a replay of Fitzgerald's crossing-situation failures. A common readiness system can expose ships to different failure modes because readiness is not a single technical property. It is the combined ability to plan a transit, maintain a coherent traffic picture, communicate across teams, understand equipment modes, manage watchstanders' workload and fatigue, execute abnormal procedures, challenge unsafe assumptions and delay operations when evidence of competence is inadequate.

The paired case therefore presents a demanding accountability test. It asks whether the institution recognized that different local failures might share upstream weaknesses without using those upstream weaknesses to excuse immediate decisions. It also asks whether individual mistakes were evaluated inside the conditions that commands and system owners controlled. The correct unit of analysis is neither a lone watchstander nor an abstract institution. It is the chain of operational representations and control decisions that put a particular crew, on a particular ship, into a particular traffic environment.

Fitzgerald: a crossing situation, delayed action and divided awareness

Fitzgerald's immediate record begins with the obligations and decisions of a bridge team navigating among commercial traffic. The destroyer and ACX Crystal approached a crossing situation. As the give-way vessel, Fitzgerald needed to act early and substantially enough to make its intention apparent and avoid creating a close-quarters emergency. The NTSB's finding is not merely that a collision occurred after someone misjudged distance. It is that the bridge team did not translate the developing traffic picture into timely, decisive avoidance.

That failure had a team dimension. A modern warship can hold relevant information in more than one place. The bridge controls navigation and ship handling; the combat information center can contribute sensors, contact tracking and analysis. Redundancy is useful only if information crosses organizational boundaries in time to change a decision. The Fitzgerald record identifies ineffective cooperation between those teams. That converts what might appear to be additional sensing capacity into a coordination risk: two groups may each possess fragments of awareness without producing a shared operational picture.

Transit planning is another distinct control. Planning does not predetermine every maneuver in congested water, but it establishes the anticipated route, navigation hazards, decision points, reporting expectations and conditions requiring heightened attention. Limited public evidence planning can leave a watch team reacting tactically without a common frame. It can also make supervision less effective because officers lack agreed triggers for intervention. The accountability question is consequently broader than whether a contact was visible.

It is whether the ship had built and maintained a decision system capable of turning visible risk into early action.

The NTSB record also places Navy oversight weaknesses in the contributing context, including scheduling, training and fatigue mitigation. Those factors should be handled with precision. They do not erase the bridge team's duty to navigate safely, and they do not prove that any single schedule decision caused the collision. They identify institutional controls capable of shaping the probability that a watch team will detect, communicate and respond to a threat.

An organization that certifies a ship while training is incomplete, experience is thin or rest controls are ineffective is making a risk representation, whether or not it labels the decision that way.

Fitzgerald therefore tests at least four layers of readiness evidence. The first is individual proficiency in collision avoidance and watchstanding. The second is team proficiency across bridge and combat information center. The third is command proficiency in planning, supervision and watch organization. The fourth is institutional assurance that deployment schedules, certification and fatigue controls do not accept risks that local teams cannot reliably manage.

Keeping those layers separate is essential to fair accountability. The immediate failure can be described without claiming that every headquarters policy directly produced it. The systemic context can be evaluated without claiming that the bridge team lacked agency. A rigorous causal record permits both propositions: the ship's watch organization failed to act as required, and higher-level controls were relevant to the conditions under which that failure became possible.

John S. McCain: steering control, lost situational awareness and unmastered procedures

John S. McCain's collision with Alnic MC requires a separate explanation because its critical sequence concerned steering control and the crew's response to an abnormal situation. The NTSB record identifies lost situational awareness, deficient training and procedures, failure to follow loss-of-steering procedures, and a steering configuration that permitted unintended unilateral transfer of control. The collision cannot be accurately understood by importing Fitzgerald's crossing-situation narrative.

The system-design issue is particularly important. Control interfaces do not merely display a ship's condition; they shape what operators can do, what they believe they have done and how quickly a team can diagnose a mismatch. A configuration that permits control to transfer unintentionally creates a foreseeable human-systems hazard. If the interface does not make control location and mode unmistakable, a crew under pressure may spend critical time interpreting the system instead of stabilizing the vessel. This does not mean design alone caused the casualty.

It means system authorities held a control surface that watchstanders could not redesign at sea.

Training and procedures are the bridge between design and operation. A steering arrangement may be manageable when crews understand its modes, practice transfers and casualties, and share a precise vocabulary for announcing control. It becomes dangerous when training does not build that mental model or when procedures are inadequate for the sequence operators are likely to face. The NTSB's emphasis on limited public evidence training and inadequate bridge procedures, associated with ineffective operational oversight, makes readiness certification central.

The relevant question is not whether a course or checklist existed somewhere in the system. It is whether the assigned team had demonstrated correct performance on the installed equipment under realistic conditions.

The failure to follow loss-of-steering procedures is an immediate operational fact with its own accountability weight. Abnormal procedures exist to prevent improvisation from amplifying uncertainty. Yet a procedural failure should still be examined in context: Was the procedure known, accessible and practiced? Did watchstanders recognize the condition to which it applied? Did the bridge team have enough shared understanding to execute it while managing traffic? Had supervisors observed performance on the actual configuration? Those questions do not deny the duty to follow procedure.

They test whether the institution did the work needed to make compliance reliable.

Lost situational awareness links the technical and navigation dimensions. While the team was trying to understand and regain steering control, the ship remained in constrained, busy waters near the Singapore Strait. A steering casualty cannot be managed as a self-contained equipment problem because the vessel continues to move in relation to other traffic. Effective response requires one part of the team to diagnose and control the casualty while another preserves the external picture and communicates risk. Certification should therefore test simultaneous demands, not just isolated equipment steps in a quiet setting.

John S. McCain also demonstrates why more personnel do not automatically create more control. During an abnormal event, additional voices and stations can increase ambiguity unless authority, terminology and handoffs are practiced. A team must know who has steering control, who is ordering course, who is verifying response, who is tracking contacts and who can call for emergency measures. Readiness is the ability to maintain that structure when the equipment state becomes confusing.

The causal boundary must remain firm. The configuration, training, procedures, situational-awareness loss and operational oversight described in the John S. McCain record belong to that casualty. They should not be retrofitted onto Fitzgerald. Conversely, Fitzgerald's bridge–combat information center coordination and crossing obligations should not be used as shorthand for the McCain sequence. The institutional comparison becomes stronger, not weaker, when it starts with accurate differences.

What the Navy's paired review adds—and what it cannot replace

The Navy described both collisions as avoidable and used their proximity to examine command, navigation, training, fatigue, certification, scheduling and wider surface-force practice. That comprehensive review adds a level of analysis that a transportation safety investigation does not need to supply. It can ask how the service generated forces, assigned missions, assessed crews and accepted operational risk. It can compare practices across commands and recommend changes to doctrine, training and oversight.

Its paired perspective is valuable because recurrent harm inside one operational system can reveal common assurance failures even when the last links in the causal chains differ. A crossing-situation failure and a steering-control failure can both be made more likely by superficial certification, limited public evidence team practice, weak fatigue controls or operational demand that leaves too little time for deliberate preparation. That is a hypothesis the system-level record can test.

The paired review should not replace the two accident records. Institutional documents may use broader categories, while NTSB records define immediate and contributing causes for specific events. The scopes answer different questions. Accident analysis asks what happened and why on the casualty voyage. A comprehensive review asks why the organization did not prevent or detect unsafe conditions across its force-generation system. Later oversight asks whether announced repairs became durable controls.

Confusing those scopes creates two opposite errors. One is reductionism: treating each collision as an isolated watchstander failure and ignoring the system that trained, crewed, equipped, scheduled and certified the ship. The other is diffusion: declaring a culture or institution responsible in such general terms that no accountable control owner can be identified. The better approach names the control, the actor with authority over it, the evidence available at the time and the decision that followed.

Personnel actions require similar restraint. Official Navy statements can establish that the service took or announced particular actions and how it characterized them procedurally. They do not license speculation about privileged material, hidden motives or criminal intent. Administrative, command and military justice processes have defined statuses. An accountability article should preserve those statuses rather than converting institutional conclusions into broader legal judgments.

Certification is an operational representation, not a ceremonial label

A readiness certification tells downstream decision-makers that a unit can perform assigned missions within accepted risk. That makes it a representation with consequences. Fleet commanders may rely on it when allocating missions; operational commanders may rely on it when setting schedules; ship leaders may rely on it when deciding how much additional training is necessary. If the representation is based mostly on completed events rather than demonstrated capability, the paperwork can remain green while operational risk accumulates.

The distinction between completion and proficiency is foundational. Completion answers whether an event occurred, a course was attended or a checklist was signed. Proficiency asks whether people can perform to standard, retain the skill, integrate with teammates and adapt it under realistic complexity. A bridge team that passes isolated drills may still fail when traffic density, equipment ambiguity, fatigue and communications demands arrive together. Certification evidence must be designed around the failure conditions that matter, not around the administrative ease of counting.

Certification should also identify its assumptions. A ship may be judged ready on the assumption that billets are filled by sufficiently experienced sailors, that watch rotations permit restorative sleep, that installed systems match the training environment, or that bridge teams receive time to practice together. If those assumptions change after certification, the representation may no longer be reliable. An auditable system records the assumptions and defines triggers for reassessment.

Independence matters because self-assessment contains structural incentives. A ship command is responsible for readiness but also faces pressure to meet operational commitments. A type commander develops units but is also measured on producing deployable forces. Fleet demand can reward optimistic reporting even when no one falsifies a record. Independent assessment reduces that conflict by placing some verification authority outside the immediate production chain.

Independence alone is not enough. The assessor must examine performance relevant to the mission and installed configuration. A standardized inspection that misses local equipment modes, team composition or navigation demands can produce formal consistency without operational validity. The strongest model combines common standards, platform-specific evaluation and authority to require remediation before a ship takes on high-risk operations.

The authority to say no is the final component. A certification system is hollow if commanders cannot delay or modify a mission when evidence is weak. That authority must be practical, not merely theoretical. Leaders need clear escalation routes, protection from informal retaliation and alternatives for managing demand. Otherwise the system asks local commanders to absorb strategic scheduling pressure while pretending the decision is purely technical.

The Fitzgerald and John S. McCain cases make this representation visible. The question is not simply whether both ships held the required status. It is whether the institution could show, before the casualties, that their teams possessed the integrated navigation, communication, equipment and fatigue-management capability their missions required. Afterward, the repair question becomes whether new certifications produced better evidence or merely more documentation.

Forward deployment, schedule pressure and the ownership of risk

Forward-deployed forces operate under demands different from those of units with long, protected training cycles. Missions recur, maintenance competes with operations, personnel turn over and geographic commitments do not disappear when a ship needs time to rebuild proficiency. These conditions do not make accidents inevitable, but they create a predictable risk of using the same limited time for mission execution, maintenance and training.

Schedule pressure is often discussed as though it were an atmospheric condition. In governance terms, it is a sequence of decisions. Someone sets demand; someone allocates ships; someone decides whether training can be deferred; someone accepts a waiver or altered certification path; someone decides whether a local concern justifies changing the schedule. Accountability becomes concrete when those decisions and their evidence are recorded.

The NTSB's Fitzgerald findings place scheduling, training and fatigue mitigation among the contributing oversight weaknesses. That does not establish a simple equation in which operational tempo caused the collision. It establishes that schedule design can influence the conditions of navigation performance. A tightly scheduled ship may have fewer opportunities for team training, less resilience when experienced personnel are unavailable and greater difficulty protecting rest. Those pathways should be measured rather than assumed.

Operational urgency can be real. Naval forces exist to meet strategic requirements, and risk cannot be eliminated. The accountability standard is not whether leaders accepted any risk; it is whether they understood the risk, tested their assumptions and assigned it to officials with authority to balance mission need against crew capability. A risk acceptance made through optimistic readiness data is not the same as a conscious decision made with credible evidence.

This is why local and higher-command duties must be linked. A commanding officer has direct responsibility for the ship's safe operation and can identify gaps that distant staffs cannot see. Fleet and type commanders control resources, certification structures and much of the demand that constrains local choices. Headquarters controls broader policy and force structure. None of those levels can substitute for another. Local leaders must report accurately and intervene; higher levels must make it possible for an accurate report to change the mission decision.

An effective readiness system therefore treats schedule changes as a normal safety control, not as evidence of organizational weakness. It establishes objective thresholds for additional assessment, creates reserve capacity where possible and learns from near misses or failed drills before harm occurs. The central institutional failure is not operating under pressure. It is allowing pressure to degrade evidence while preserving the appearance of readiness.

Navigation proficiency is a team property

Ship driving is sometimes described as an individual craft, but collision avoidance aboard a complex warship is produced by a team. The officer directing the ship, helmsmen, lookouts, radar operators, contact managers, supervisors and the combat information center may all contribute to the traffic picture. Their competence must converge at the pace of the situation.

Fitzgerald illustrates the risk of fragmented awareness. Information in the combat information center has limited protective value if it is not communicated, trusted and incorporated into bridge decisions. Bridge observations have limited value if they do not produce clear contact assessments and early maneuvers. Team proficiency therefore includes information routing, challenge procedures and a shared threshold for escalation.

John S. McCain illustrates a different coordination problem. When steering control becomes uncertain, the team needs a common model of equipment state and precise declarations about who has control. At the same time, some watchstanders must preserve the external navigation picture. If everyone turns toward the technical problem, traffic risk grows; if no one diagnoses the technical state, maneuvering remains unpredictable. This kind of divided task is exactly what realistic evaluation should reproduce.

Training should test communication failure as well as technical failure. Assessors can observe whether watchstanders use standardized language, whether orders are repeated and verified, whether a junior person can challenge an unsafe assumption, whether supervisors recognize overload and whether teams recover after an incorrect action. Those behaviors determine whether redundancy catches error or merely spreads it.

Experience also has a team dimension. A nominally filled watch may lack enough people who have seen difficult traffic, mastered a particular bridge configuration or practiced together. New personnel can be individually qualified yet unfamiliar with the habits and expectations of the current team. Certification should examine the distribution of experience across each watch section, not only total qualifications aboard the ship.

The installed-system question is equally important. Classroom and simulator training can build foundations, but the transfer to a ship's actual configuration must be verified. Controls, software states, displays and procedures may differ. If training assumes an interface that is simpler or different from the one operators use, completion statistics overstate readiness. Evaluation should include the equipment modes and failure sequences that have the highest consequence.

Proficiency also decays. A crew may demonstrate a skill and then lose key members, absorb a demanding schedule or go months without practicing a rare casualty. Certification cannot be a permanent fact established on one date. It is a time-limited judgment supported by recurring indicators: observed drills, navigation assessments, personnel changes, rest conditions, equipment changes and operational performance.

These requirements are demanding, but they are not an argument for endless inspection. The aim is targeted assurance. The paired collision record points to specific capabilities worth testing: early and substantial collision-avoidance action; bridge–combat information center coordination; transit planning; steering-control transfer; recognition of loss of steering; casualty procedures; workload division; and maintenance of the traffic picture during equipment confusion.

Fatigue control must survive contact with the schedule

Fatigue is often visible in policy long before it is controlled in practice. A command can publish a watchbill rule or rest standard, yet operational demands, maintenance, drills and administrative work may consume the protected time. The relevant evidence is not the schedule as written but sleep opportunity and performance under the schedule as lived.

The Fitzgerald record includes Navy fatigue-mitigation oversight among the contributing institutional weaknesses. Later GAO work examined fatigue and implementation across the surface force. These are different kinds of evidence. The accident record helps explain the conditions surrounding a 2017 casualty; later oversight evaluates the repair system. A later finding cannot be projected backward as the cause of a death, but it can show whether the organization developed reliable ways to address a known class of risk.

Fatigue accountability also follows control surfaces. An individual can use available rest responsibly, but cannot create hours that the watchbill, maintenance plan and mission schedule remove. A ship command designs local rotations and sets priorities among competing work. Higher commands establish policy, monitor compliance and influence operational demand. Headquarters determines resources and broader personnel structures. Each level needs evidence suited to its authority.

Useful fatigue assurance includes more than a signed schedule. It can examine actual duty patterns, interruptions, cumulative workload, high-risk navigation periods and whether watchstanders can report impairment without stigma. It can compare planned and executed rest. It can identify when personnel shortages force repeated exceptions. Most importantly, it can connect fatigue indicators to decisions: adding supervision, adjusting watches, rescheduling work or changing the mission plan.

The goal is not to claim that every tired watchstander is unfit or that fatigue explains every error. It is to prevent a known performance risk from becoming administratively invisible. When a readiness system certifies a crew, it should be able to explain how fatigue was assessed, what deviations existed and why the residual risk was accepted.

Crewing fill, crewing fit and the danger of reassuring percentages

Manning data can create false precision. A ship reported as nearly fully staffed may still lack the right grades, ratings, qualifications or experience for critical watch teams. This is the difference between fill and fit: how many positions are occupied versus whether the people assigned match the work the ship must perform.

Later GAO evidence is important here because it tests the information used for readiness decisions. GAO-21-366 examined crewing shortfalls alongside fatigue and implementation. GAO-24-105811 reported continuing reliability and transparency problems in ship-crewing fill and fit data. Those findings were published years after the collisions and do not prove that a particular present-day ship is unsafe. They do show why repair cannot be established by citing a top-line manning percentage.

Reliable crewing data should answer operational questions. Does each watch section contain enough qualified and experienced personnel? Are supervisory skills distributed across the day rather than concentrated in one team? Will an impending transfer remove a critical capability? Are temporary assignments masking a durable gap? Do certification records update when the crew changes materially?

Transparency matters because risk moves up the chain only when data retain their meaning. If local commands and headquarters use different definitions, or if fit problems disappear inside aggregate fill numbers, fleet leaders may assign missions on an inaccurate premise. A data system is not a clerical support function in this context. It is part of the safety control.

The 2024 GAO record is later repair evidence, not an accident finding. Its proper use is to test durability: years after the Navy announced reforms, could decision-makers rely on the crewing information needed to judge readiness? A weakness in that information is a reason for stronger verification and disclosure. It is not proof of a specific crew's incompetence, and it is not evidence that no reform worked.

This distinction protects both rigor and fairness. Institutions should not claim success from aggregate improvements that cannot be traced to operational capability. Critics should not convert a data-quality problem into a claim that every unit represented by the data is unsafe. The accountable response is to improve definitions, validation, reporting and decision rules so uncertainty becomes visible.

Interface design is command risk made physical

The John S. McCain record shows why interface design belongs inside readiness accountability. A steering-control configuration that permits unintended unilateral transfer of control is not simply an operator challenge. It is a system characteristic created, approved, installed and supported by organizations with authority over design and configuration.

Human operators remain responsible for using equipment correctly, but their performance depends on cues, modes and constraints. Good control design makes the location and status of steering authority salient, provides feedback after a transfer and reduces the chance that one action creates an unexpected state. Procedures and training should then reinforce the design. When design is ambiguous, training carries more burden; when training is thin, design ambiguity becomes more dangerous.

Certification must therefore include configuration control. Assessors need to know which bridge system is installed, whether procedures match it, whether the team trained on it and whether known hazards have been incorporated into drills. A generic qualification cannot establish competence on every configuration. System changes should trigger updated training and, where risk warrants, renewed demonstration.

The institutional lesson is not that technology can eliminate human error. It is that risk is jointly produced. Watchstanders, supervisors, training commands, procedure owners, acquisition organizations and technical authorities each control part of the operating envelope. An accountability system should avoid blaming the last person to touch the control for hazards that upstream owners were better positioned to prevent.

Damage control: evidence of competence after prevention failed

The Fitzgerald supplemental line-of-duty inquiry has a deliberately narrower place in this analysis. It addresses flooding, injuries, rescue, medical response, diving and the ship's return to port. It should not be used to reconstruct pre-collision navigation or to add facts to the NTSB causal account outside its scope.

Within its scope, the inquiry matters. The crew's post-impact response demonstrates that readiness is multidimensional. Weaknesses in collision prevention can coexist with courage, discipline and technical competence in damage control. Sailors responding to flooding and injured shipmates operate under extreme conditions, and effective action can preserve the ship and save lives.

That success does not cancel the prevention failure. Organizations sometimes use heroic response as evidence that their training system worked, while critics sometimes treat a preventable collision as proof that nothing aboard the ship worked. Both conclusions flatten the record. Prevention readiness and response readiness are different capabilities. Each needs its own evidence and accountability.

The inquiry also illustrates why source scope matters. A document designed to examine line-of-duty circumstances and post-impact response may contain rich operational detail, but its purpose does not make it the controlling record for navigation causation. Respecting that boundary is not a technicality. It prevents emotionally powerful response evidence from displacing the more precise accident findings.

For repair, the lesson is to evaluate both sides. Ships should demonstrate collision avoidance and bridge-team coordination, but they must also retain the capacity to contain damage when prevention fails. A mature safety system does not choose between prevention and resilience. It builds defenses before the event and recovery capacity after it.

Allocating accountability by control surface

System accountability becomes credible when it specifies who could change what. Individual watchstanders control observations, communications, compliance with orders and procedures, and immediate actions within their authority. Their decisions matter, and a systemic explanation should not erase them.

Ship commands control transit preparation, watch organization, local training, supervision, fatigue mitigation and the escalation of readiness concerns. They are closest to the crew's actual condition and have a duty to make gaps visible. They also operate inside demands and resource limits that they do not fully control.

Type commanders and fleet commanders control broader training and certification structures, allocate support, monitor readiness, set or transmit operational demand and hold authority over risk decisions that exceed a ship's capacity. Their accountability turns on whether they demanded credible evidence, responded to contrary information and preserved a meaningful option to delay or modify operations.

Headquarters establishes policy, resources, force structure and reporting systems. It can create incentives for honest readiness reporting or for administrative optimism. It can require independent assessment and reliable crewing data. It is too distant to make every local navigation decision, but it controls whether the assurance system detects recurring vulnerabilities.

Technical and acquisition authorities control interface requirements, configuration, feedback, procedures and correction of known design hazards. The John S. McCain steering sequence makes that ownership visible. A crew can train around a hazard, but system owners should also ask whether the hazard can be engineered out or made more apparent.

Accountability across these layers is not equal blame. It is differentiated responsibility tied to authority, knowledge and opportunity to intervene. The people closest to the final act may have immediate causal responsibility, while upstream actors may own conditions that made error more likely or less recoverable. The paired cases require both forms of analysis.

They also require procedural caution. Navy personnel decisions and statements should be reported according to their official status. An institutional finding is not automatically a legal judgment against an individual, and an administrative action does not justify speculation about undisclosed evidence. Privileged investigations cannot be filled in by inference. The public record is strong enough to support control analysis without inventing intent.

What the later GAO record can establish

Later GAO reports convert reform promises into questions that can be checked over time. Their value lies less in retelling the collision sequences than in examining whether the Navy created mechanisms to improve training, manage fatigue, crew ships and evaluate readiness. They are evidence about repair and oversight, not substitute accident reports.

GAO-20-154 found a major increase in planned ship-driving instruction after the collisions. More instructional time is a relevant input: navigation is a perishable skill, and expanded training can provide practice that operational schedules once crowded out. But the report also identified weaknesses in comprehensive evaluation of training effectiveness. That distinction is central. Hours planned or delivered show effort. They do not alone show that watchstanders retained skills, teams integrated them or casualty rates fell because of the training.

GAO-21-366 examined fatigue, crewing shortfalls and implementation. That scope tests whether reform moved from policy into operating conditions. A fatigue standard is weak if schedules repeatedly defeat it. A manning initiative is weak if critical watch teams remain short of experience. An implementation plan is weak if completion cannot be linked to observed capability. The report's proper role in this article is to keep those proof questions open and specific.

GAO-24-105811, published still later, reported problems with the reliability and transparency of ship-crewing fill and fit data. This is significant because readiness assurance depends on trustworthy inputs. Leaders cannot make calibrated risk decisions if the system obscures whether the right people, not merely enough people, are available. Yet the finding must be bounded: a data reliability problem does not itself prove that a particular ship was or is unsafe.

The chronology matters. The 2017 accident records explain the deaths and the conditions then under examination. The Navy's comprehensive review identifies common institutional weaknesses and reforms after the paired casualties. GAO's 2020, 2021 and 2024 work evaluates aspects of the evolving repair system. A finding made in 2024 cannot be cited as a cause of an event in 2017. It can be cited as evidence that a class of oversight problem remained important years into the reform effort.

Contemporaneous and follow-on GAO testimony in the bound record adds oversight context around the Navy's readiness challenges and response. Such testimony helps establish that certification and operational demand were subjects of public accountability, but it should not be made to carry accident-specific causal claims belonging to NTSB or Navy investigations. Likewise, later Navy readiness-assessment material can show how the service sought to determine whether ships were ready for sea without proving the present condition of every ship.

This division of labor among records prevents an easy but misleading narrative. Institutions often announce a reform, count activities and declare the problem solved. Critics may respond to any later weakness by declaring the entire reform a failure. The evidence supports a more disciplined conclusion: substantial action can coexist with incomplete evaluation; stronger policies can coexist with data weaknesses; and repair can be real without yet being fully demonstrated.

A proof-of-repair standard for readiness certification

Proof of repair begins with a causal map. For Fitzgerald, the repair program should address early collision-avoidance action, shared bridge and combat information center awareness, transit planning, training, fatigue mitigation and the oversight conditions identified in the record. For John S. McCain, it should address training on steering configuration, bridge procedures, loss-of-steering response, control-transfer awareness, workload division and operational oversight. Common initiatives can support both maps, but each casualty needs its own verification.

The second element is performance measurement. Course attendance, simulator hours and completed events are inputs. Outcome-oriented assurance asks whether watchstanders and teams meet observable standards. Can they identify a developing crossing risk and take early, substantial action? Can bridge and combat information center personnel reconcile contact information? Can they recognize an unexpected transfer of steering control, announce the condition and execute the correct procedure while maintaining awareness of traffic?

The third element is realism. Drills should combine conditions that interact in operations: dense traffic, ambiguous information, equipment-mode changes, fatigue-sensitive periods and communications load. Testing one skill at a time can establish basic technique, but it may not expose coordination failure. The purpose is not to surprise crews for its own sake. It is to evaluate the integrated capability that certification represents.

The fourth element is assessor independence and calibration. Independent teams need consistent standards, trained evaluators and authority to record failure honestly. Results should be comparable enough to identify fleet-wide patterns while retaining configuration-specific detail. A high pass rate is meaningful only if the assessment is difficult enough to discriminate proficiency from participation.

The fifth element is longitudinal evidence. A one-time pass can deteriorate as personnel rotate, schedules intensify or equipment changes. Readiness systems should track whether teams sustain performance, whether near misses decline, whether failed evaluations lead to remediation and whether repeated weaknesses trigger higher-level intervention. Changes in crew composition should prompt reassessment of affected capabilities.

The sixth element is reliable crewing evidence. Fill and fit data should be defined consistently, validated and visible to decision-makers. Certification should show not only total staffing but the qualifications and experience of each critical watch team. Uncertainty should be disclosed, not converted into a reassuring percentage.

The seventh element is fatigue evidence. Commands should compare planned rest with actual duty patterns and document exceptions. Evaluators should consider whether the watch organization can be sustained during the assigned mission. When fatigue risk rises, the system should require a control response rather than merely acknowledging the risk.

The eighth element is configuration assurance. Procedures, simulators and assessments should match installed steering and bridge systems. Known human-interface hazards should be tracked to design correction, clearer feedback, improved procedure or all three. Training should not become the permanent answer to a correctable design problem.

The ninth element is decision traceability. If a ship proceeds with a known gap, the record should identify the gap, compensating controls, decision authority, duration and review point. This protects neither bureaucracy nor commanders from accountability; it makes accountability possible. It allows later oversight to distinguish a reasoned risk acceptance from an unexamined assumption.

The final element is outcome humility. Safe operations after reform are encouraging but do not prove that every control is effective. An open recommendation does not prove that a later casualty is imminent. Proof of repair is cumulative: credible implementation, demonstrated proficiency, reliable information, sustained performance and evidence that leaders act when indicators turn adverse.

Under this standard, the expansion of ship-driving instruction reported by GAO is meaningful but incomplete evidence. Fatigue initiatives matter when actual schedules support them. Crewing reforms matter when fill and fit data accurately describe watch-team capability. Readiness assessments matter when they can fail a ship and change an operational decision. Administrative completion is one step in repair; it is not the endpoint.

Institutional legitimacy after preventable loss

The Navy's legitimacy in this case rests on more than acknowledging that the collisions were avoidable. It rests on showing how lessons move through command, training, personnel, technical and operational systems. Families of the seventeen sailors who died, serving crews and the public have reason to ask whether the institution can identify not only who made immediate mistakes but why its assurance mechanisms did not stop vulnerable conditions from reaching the sea.

That inquiry should resist moral simplification. The Fitzgerald bridge team's failures remain part of the causal record. The John S. McCain team's loss of situational awareness and procedural failures remain part of its record. Systemic contributors do not turn operators into passive entities. At the same time, the institution cannot define accountability so narrowly that the final watchstanders absorb risks created by schedules, crewing systems, certification design or equipment configurations outside their control.

Legitimacy also requires candor about uncertainty. The public record does not reveal every privileged investigation, complete watch history or actor's state of mind. The relative causal weight of operational tempo and local decisions cannot be reduced to a universal formula. Later GAO findings do not establish the current proficiency of named crews. Those limits should be stated rather than filled with inference.

The most credible institutional claim is therefore not that risk has been eliminated. It is that readiness representations are now supported by better evidence, challenged independently and tied to decisions. That claim remains testable. Oversight can examine whether training effectiveness is evaluated, whether fatigue controls survive operational demand, whether crewing data are trustworthy, whether interface hazards are corrected and whether commanders can stop an unsafe schedule.

The lasting accountability lesson

Fitzgerald and John S. McCain should be remembered together because their deaths forced one Navy to examine a common readiness system. They should be remembered separately because accuracy about immediate causes is the foundation of useful reform. Fitzgerald's crossing-situation, planning and bridge-team coordination failures are not interchangeable with John S. McCain's steering-control, procedure and situational-awareness sequence.

The paired record shows that readiness certification is a consequential assertion. It tells commanders that people, teams, equipment and procedures can withstand the demands about to be placed on them. When that assertion relies on completed events, nominal staffing or untested assumptions, it transfers hidden risk to crews at sea.

Accountability should follow the authority to control that risk. Watchstanders answer for immediate professional duties. Ship commands answer for local planning, training, watches and truthful reporting. Fleet and type commanders answer for certification, support, demand and risk acceptance. Headquarters answers for policy, resources and information systems. Technical authorities answer for bridge configurations and interface hazards. None can carry the entire explanation, and none should disappear from it.

The later repair record is neither a verdict of failure nor a certificate of success. Expanded instruction, new assessments and announced reforms are evidence of action. GAO's findings on evaluation, fatigue, crewing and data reliability are evidence that action must be tested. The responsible conclusion is conditional: repair becomes credible when demonstrated proficiency, reliable information and decision consequences align.

Seventeen sailors died in two avoidable collisions. The durable obligation is not to compress their deaths into one slogan or to close the record with a list of initiatives. It is to make every future declaration of readiness auditable—specific about the capability tested, honest about the assumptions made, independent enough to challenge demand and powerful enough to change what the Navy does next.

Sources

  1. https://www.ntsb.gov/investigations/Pages/DCA17PM024.aspx
  2. https://www.ntsb.gov/investigations/Pages/DCA17PM018.aspx
  3. https://www.ntsb.gov/investigations/AccidentReports/Reports/MAR1901.pdf
  4. https://data.ntsb.gov/Docket/?NTSBNumber=DCA17PM024
  5. https://data.ntsb.gov/Docket/TOCPrintable?data=95396
  6. https://www.secnav.navy.mil/foia/readingroom/HotTopics/CNO%20USS%20Fitzgerald%20and%20USS%20John%20S%20McCain%20Response/CNO%20USS%20Fitzgerald%20and%20USS%20John%20S%20McCain%20Response.pdf
  7. https://www.navy.mil/DesktopModules/ArticleCS/Print.aspx?Article=2253385&ModuleId=523&PortalId=1
  8. https://www.navy.mil/Press-Office/Press-Releases/display-pressreleases/Article/2252664/navy-releases-uss-fitzgerald-supplemental-line-of-duty-investigation/
  9. https://www.secnav.navy.mil/foia/readingroom/HotTopics/USS%20Fitzgerald/Supplemental%20Inquiry%20USS%20Fitzgerald.pdf
  10. https://www.navy.mil/DesktopModules/ArticleCS/Print.aspx?Article=2250871&ModuleId=685&PortalId=1
  11. https://www.c7f.navy.mil/Media/News/Display/Article/1416603/us-navy-statement-on-uss-fitzgerald-and-uss-john-s-mccain-consolidated-disposit/
  12. https://www.defense.gov/News/News-Stories/Article/Article/1361724/navy-committed-to-correcting-mistakes-that-led-to-collisions-deaths/
  13. https://www.gao.gov/products/gao-20-154
  14. https://www.gao.gov/assets/720/715081.pdf
  15. https://www.gao.gov/products/gao-21-366
  16. https://www.gao.gov/products/gao-24-105811
  17. https://www.gao.gov/assets/gao-17-809t.pdf
  18. https://www.gao.gov/products/gao-19-225t
  19. https://www.cpf.navy.mil/intelligence team/news/article/2704736/naval-surface-forces-assessing-if-ships-ready-for-sea/
  20. https://navalsafetycommand.navy.mil/Portals/100/Documents/TDINSH_USS_John_S_McCain_Collision_21Aug17.pdf?ver=YgR0Rj3FP0aOZbSI94nStg%3D%3D