Lessons from Other Fields
Elevator Safety
The verification we trust most completely is the one we never think about at all — and it works because someone independent checks it, on a schedule, forever.
In Brief
You step into an elevator without a second thought. You don’t read an inspection certificate, ask when the cables were last tested, or wonder whether the brakes work. A failure could kill you — yet Americans take an estimated 18 billion elevator trips a year with essentially no conscious trust at all. The worry has been engineered out of everyday life so completely that the machinery has become invisible.
That invisibility rests on an architecture most riders never see. Elevators are governed by ASME A17.1, the Safety Code for Elevators and Escalators — a roughly 500-page consensus standard refined for over a century. Most jurisdictions require that every elevator be inspected and tested on a recurring schedule by a third-party Qualified Elevator Inspector who is barred from inspecting equipment in which they have any financial interest, and that the unit carry a posted certificate of operation before anyone may ride it. The checker is independent of the party being checked, and the check repeats whether or not anything looks wrong.
The cautionary tale is the death of Suzanne Hart. On December 14, 2011, a maintenance crew at a Manhattan office tower deliberately disabled the circuit that keeps an elevator from moving with its doors open, finished their work, and put the car back in service without re-enabling the safety device or obtaining the required clearance. One minute later, Hart stepped in; the car lurched upward and killed her. The city issued 23 violations and suspended the contractor’s license. The failure was not a missing rule — it was a safety system bypassed and returned to service without the independent sign-off the architecture depends on.
The transfer to elections is about the model of verification, not just its existence. Elevator safety is not a crisis response; it is a standing, scheduled, independent re-check that runs in the background forever, which is exactly why nobody has to think about it. The election reporting layer — the step that carries precinct tabulator totals into official results — has no such standing check. Actual Vote supplies the missing routine inspection: an independent, primary-source record of what each tabulator actually reported, captured every election whether or not anything looks wrong, and held by someone with no stake in the result.
I. What This Domain Is
An elevator is the most-used form of transportation almost no one counts as transportation. By industry estimate there are roughly 900,000 elevators in the United States carrying about 18 billion passenger trips a year — far more boardings than conventional mass transit. Each of those trips is an act of trust so complete that riders almost never pause to register it as trust at all. The rider cannot see the hoist cables or test the brake; a dated inspection certificate is posted in the car, but almost no one reads it. They press a button and step into a box suspended in a shaft by steel cables — an act that, in almost any other circumstance, would be recklessly dangerous. What keeps it from being a reckless bet is precisely the framework this entry is about, and the rider has so thoroughly internalized that framework’s reliability that they do not experience the ride as a bet at all.
What makes this the same epistemic structure that runs through every entry in this collection is the gap it contains: the person whose safety is most at stake is structurally unable to verify the thing they are trusting. The rider has no way, on their own, to confirm that the cables are sound or the brake will hold, and no practical way to evaluate the maintenance and inspection history even if they tried. What is distinctive about the elevator is how completely that gap has been closed from the public’s point of view — not by giving riders the ability to verify, but by building a system so reliable that the need to verify has dropped out of awareness entirely. The trust is not re-earned on each ride; it has been made invisible. That invisibility is not the absence of a safety problem. It is the visible signature of a safety problem that was solved — and kept solved — by an architecture working quietly underneath.
The structure mirrors a citizen and an election result, but the danger registers very differently. The voter can sometimes watch the count — observation rights exist in many places, though they vary by jurisdiction and, as our state-specific guidance details, are rarely designed to let one person, or even an organized group, perform rigorous independent verification. A determined citizen can even confirm that the published number matches what the scanner printed: that is exactly what Bennie Smith did in Shelby County, Tennessee, when he photographed a poll tape.
The trouble is that doing so is neither easy nor something a voter should have to do — any more than an elevator rider should have to turn up on inspection day, film the inspector’s findings, transcribe them, and check them against the posted certificate. The deeper difference is perceptual: when an elevator or an airplane fails, the danger is vivid and immediate, while a failure in the election reporting layer is just as serious but nearly invisible — no falling box, no crash, only a wrong number that looks exactly like a right one. That invisibility is what makes the missing verification so easy to neglect.
This essay describes the architecture that earns that kind of unthinking trust for elevators — a code written incident by incident, recurring third-party inspection, and a posted certificate of fitness — and asks what it would take to extend the same standing, invisible verification to the least-checked step in American elections.
II. The Institutional Architecture
The foundation is the code. Elevators in the United States are built, maintained, and tested to ASME A17.1, the Safety Code for Elevators and Escalators, a standard that has been developed and revised for more than a century and now runs to roughly five hundred pages. It is not written by the manufacturers acting alone. A17.1 is an American National Standard produced through an ANSI-accredited consensus process in which the standards committee is capped in size and no single interest category may hold more than one-third of the seats, with hundreds of additional experts and a public-comment requirement on every proposed change. Since the 2000s it has been developed jointly with the Canadian CSA B44 committee and published as a single harmonized document. The rule-making body is deliberately balanced so that the regulated industry cannot quietly write the rules to suit itself.
The second layer is independent inspection, and this is where the architecture most resembles what elections lack. Most jurisdictions require that a new elevator pass an acceptance inspection and that every elevator then be re-inspected and tested on a recurring cycle — in California, for example, the periodic tests run on one-year and five-year intervals fixed in regulation. Critically, the inspection is performed by a Qualified Elevator Inspector certified under the ASME QEI-1 standard, and where the work is structured as a true third-party regime the inspector is forbidden from inspecting any equipment in which they hold a financial interest. The party attesting that the elevator is safe has no stake in the verdict. Inspection and testing are themselves split: the licensed mechanic performs the test, and the independent inspector witnesses it, so that no single party both does the work and attests to it.
The third layer is the certificate of operation. An elevator may not legally carry the public until the Authority Having Jurisdiction — the state or local body that adopts and enforces the code — issues a certificate confirming the unit was inspected, tested, and found compliant, and in most jurisdictions that certificate must be posted where it can be seen. The certificate is the visible token of an invisible process: a standing, dated, public attestation by an independent authority that the verification actually happened. And inspectors do not improvise. They work from ASME A17.2, the Guide for Inspection of Elevators and Escalators, a companion document that standardizes the procedure so the check means the same thing from one inspector and one building to the next.
Taken together these layers produce a verification model worth naming precisely, because its character is different from aviation’s. It is continuous and scheduled rather than triggered by catastrophe. The elevator is re-checked on a clock, by an independent party, against a standardized procedure, and re-licensed before it may carry anyone — every cycle, indefinitely, whether or not anything has ever gone wrong.
III. Why This Exists
The architecture exists for the same reason as the others in this collection: the consequences of a single failure are severe, immediate, and borne by someone who had no way to protect themselves. But the elevator code carries that logic into unusual granular detail, because much of it was written in response to specific people who were specifically hurt.
The mechanical door restrictor is the clearest example. When a car stalls between floors, a trapped occupant who forces the interior doors open may see the hoistway above and below and try to climb out through the gap — and fall to their death down the shaft. After exactly that class of fatality, A17.1 added a requirement, first introduced in 1980, that the car door cannot be opened more than four inches when the elevator is outside the landing zone. The rule reads as a dry dimensional specification. Behind it are the people who died before it existed. Much of A17.1 has this character: each revision cycle folds in the lesson of a particular failure, so the present-day code is, in effect, an accumulated record of harms that are not allowed to happen again.
The code’s deeper logic, though, is not only that failures teach lessons — it is that no one, however expert, is permitted to be the final judge of their own work. The people who design, build, maintain, and inspect elevators are overwhelmingly serious, well-trained professionals who care about safety, and the architecture does not assume otherwise. It assumes something more durable: that human judgment is subjective and bias-prone even at its most expert, that complex systems fail when independent weaknesses happen to line up — the Swiss-cheese model of accidents — and that in any large enterprise, uncontrolled incentives let small acts of inattention or expedience compound into catastrophe. Aviation supplies the proof that excellence alone is not enough: there are crashes in which an exemplary, highly experienced crew made a fatal error only because the circumstances happened to activate a cognitive bias. The conclusion the serious fields have drawn is the one elevators encode — precisely because the stakes are high, no party, not the most skilled engineer and not the most reputable firm, may certify its own work, because history shows self-certification to be a uniquely bias-vulnerable way to fail. Independent confirmation never makes a system perfect, but it is the only route to reasonable confidence, and the serious fields require it before they will let the public ride.
This is also why the architecture cannot rest on good intentions. A corporation formally accountable to shareholder value faces a standing incentive to treat safety regulation as a cost — to lobby it down, economize on it, and, when something goes wrong, to deflect the blame. The Boeing 737 MAX is the textbook case of what follows when an independent check is softened in deference to the regulated party’s own assurances. The point is not that the people involved are villains; it is that in a high-stakes domain the incentive structure must be assumed to drift toward erosion unless an independent check holds it in place. Honest professionals and reputable firms are necessary — and history shows they are never, by themselves, sufficient.
The payoff is a safety record so strong it has dissolved into invisibility. Against roughly 18 billion trips a year, passenger deaths in elevators number on the order of a dozen annually in the United States — and most elevator-related fatalities are workers servicing the equipment, not riders. This is not because riding an elevator is inherently low-risk. The act puts a person inside a heavy machine suspended in a shaft; the exposure is real, which is exactly why the regulation runs to hundreds of pages. What a mature verification architecture buys is a ratio of safety to risk-exposure so high that everyone except the specialists can treat riding as effectively routine — when it emphatically is not, as the paragraphs of code and inspection behind it attest. The danger has not been removed from the activity; it has been so thoroughly and reliably managed that it has been removed from public consciousness, which is a far more remarkable achievement than making something that was never dangerous merely feel safe.
The same logic transfers to elections, with two differences worth being precise about. The first is that a citizen can, in principle, check the reporting layer — just as a rider could, in principle, read the posted certificate and pull an elevator’s inspection history. A determined voter can record their own precinct’s poll tape and compare its totals against the published result, and a few have. What no individual can do alone is build the standing system that makes such a check independent, reliable, and universal. The second difference is that for elevators that system exists, and for the election reporting layer it does not: no agency is tasked with the independent verification; the checks election officials perform vary by jurisdiction and, however conscientious, cannot satisfy the independence requirement on their own; and Actual Vote — which makes the poll-tape comparison possible at scale — has existed for only about a decade and is not yet widely adopted.
That gap is the real lesson the elevator carries. Riding an elevator and relying on an election result are both routine, high-stakes acts that society should make trustworthy enough that no one has to think about them — where the only thought required is that the process matters too much to leave unverified, so a system of independent robustness equal to its importance has been built around it. We engineered that confidence for elevators with a century-old safety code and mandatory independent inspection. Elections are at least as consequential — their outcomes compound across policy, appointments, and the legitimacy of government itself, over decades and hundreds of millions of people — yet have no equivalent: no election analog to the ASME code requiring independent verification of each critical step. The case studies in our companion collection are, in effect, the cautionary tales the reporting-layer section of such a code would be written from, exactly as the elevator code was written from the failures that preceded each of its rules.
IV. The Cautionary Case: The Death of Suzanne Hart
The elevator architecture’s most instructive modern failure is not a flaw in the code. It is what happened when an existing safety system was bypassed and the independent check that should have caught it was skipped.
On the morning of December 14, 2011, a maintenance crew from Transel Elevator was working on elevator number 9 at 285 Madison Avenue, a Manhattan office tower. To reach the car, the crew deliberately disabled the electrical safety circuit that prevents an elevator from moving while its doors are open — a routine step during service. When they finished, they failed to re-enable that safety device, and they returned the elevator to passenger service without obtaining the clearance the law required. At 9:55 a.m. the crew left the building. About a minute later, Suzanne Hart, a 41-year-old advertising executive arriving for work, stepped into elevator 9. With its safety circuit still defeated, the car shot upward while its doors were open and crushed her between the first and second floors. She was killed instantly, in front of other passengers, in the most ordinary setting imaginable: walking into her own office building.
The rule the crew broke was not obscure. City law required that an elevator taken out of service for this kind of work not be returned to public use until the work was completed properly and the Department of Buildings notified — a clearance step meant to stand between the maintenance and the next passenger. But the case threw the requirement’s structural weakness into relief: it was self-administered. Nothing independent actually intervened at the moment of return to service. The same crew that disabled the safety circuit was trusted to restore it, stop the car, report the work, and wait — and a crew under time pressure could simply skip the step, which is what happened. The “check” existed on paper, but the party performing the work was also the only party verifying it was safe to resume.
The institutional response moved in the direction the failure exposed as missing. New York City’s Department of Buildings investigated, found that the crew had purposely disabled the safety device and failed to restore it before putting the car back in service, and issued 23 violations against Transel and suspended the company’s license, barring it from installations, upgrades, and inspections while it pursued full revocation. More structurally, the regulatory trajectory since has been toward independent credentialing of the people who do and verify elevator work: New York’s Elevator Safety Act, effective January 1, 2022, now requires a state-issued license for everyone who performs maintenance, inspection, or testing on an elevator, and New York City separately licenses the private inspectors and inspection-agency directors who attest to that work — formalizing the independence of the sign-off the architecture depends on. The wrongful-death litigation that followed reached the New York Appellate Division, which reinstated the economic-damages claim on appeal.
The lesson is specific, and it is not the same lesson as aviation’s. The 737 MAX failed at the design certification stage, where a manufacturer was allowed to certify its own work. Hart died at the return-to-service stage, where a crew defeated a working safety device and put the machine back in front of the public without the independent verification that exists precisely to confirm an elevator is safe before anyone rides it. The hazard was not an unwritten rule or an undiscovered flaw. It was a known safety mechanism switched off and not switched back on, with no independent check standing between that omission and the next passenger. The verification architecture works only when the check is actually performed — and the cost of skipping it, even once, was a life.
V. The Transfer to Elections
The structural parallel is exact where it counts: a process whose safe functioning no individual participant can directly observe, where the parties doing the work have an interest in the outcome looking clean, and where a single unverified step can produce serious, hard-to-reverse harm. Elevators have many such steps — design, installation, maintenance, testing, and the return of a machine to public service, the one our cautionary case happens to turn on. Elections likewise have many: every layer, from casting to counting to reporting, is critical and deserves transparent, independent verification. We call specific attention to the reporting layer — the transmission of precinct tabulator totals into the published official result — because that is the step Actual Vote is built to verify.
But the more useful transfer from elevators is the model of verification, not merely the fact of it. Every serious safety domain combines two modes: a reactive loop that investigates failures after they happen — aviation’s NTSB is the vivid example — and a proactive routine that re-checks the equipment on a schedule before anyone is hurt. Aviation has both, and so do elevators; the comparison is not reactive-versus-proactive. What the elevator case foregrounds is how much work the proactive, routine mode can do when it is independent and universal. The inspector returns on a fixed cycle, re-verifies the equipment whether or not anything has gone wrong, and the certificate of operation must be renewed before the public may ride — and it is this quiet, standing, always-already-happening check, more than any dramatic post-failure investigation, that has dissolved elevator risk from public worry.
Election reporting has neither model in place at the layer that matters. There is no independent party that re-verifies the reporting chain every cycle as a matter of course; the audits that do exist vary widely by state and are usually scoped to the counting layer rather than the reporting layer, and they are often triggered by closeness or controversy rather than performed as invariant routine. The result is that public trust in election results behaves like trust in an elevator with no inspection regime: fine until something looks wrong, and then with nothing concrete to fall back on (in Monmouth County, New Jersey, a “100 percent accuracy” audit reported a clean result while the wrong candidate held office — the official check that should have been the fallback gave false reassurance instead). The Hart case adds the sharpest warning. The danger is not only an absent rule but a check that is skipped — and in election reporting, the independent check is not skipped occasionally; for the reporting layer it is, in most places, simply never scheduled.
VI. Where Actual Vote Fits
Actual Vote is the election equivalent of the recurring independent inspection — for the reporting layer, at least. The other layers of an election deserve the same standing, independent scrutiny, though each calls for its own techniques; Actual Vote addresses the reporting layer specifically. It does not replace election officials, statutory audits, or the equipment vendors, any more than a Qualified Elevator Inspector replaces the mechanic who maintains the car. What it supplies is the element whose absence is most conspicuous in the election case: a standing, independent re-verification of the reporting layer, performed every election as routine, by a party with no stake in the result.
The elevator inspector’s value does not depend on finding a defect. Most inspections find nothing wrong — and that is the point. The recurring check is what allows the public to stop worrying, because the verification is known to be happening on a schedule regardless of whether trouble is suspected. Actual Vote plays the same role for vote reporting. It captures the vote totals each tabulator actually reported — printed on the poll tape — as an independent, primary-source record, and compares them against the official published total. When the comparison matches, the match is itself evidence that the reporting layer functioned, exactly as a clean inspection certifies that an elevator is sound — and that it will not be put back into service with a disabled safety circuit that could kill someone. When it does not match, the discrepancy is preserved in a form outsiders can examine, rather than vanishing into the custody of the parties whose work it concerns.
The deeper parallel is to what scheduled, independent verification does to public trust over time. Elevator safety became invisible not because elevators stopped failing but because an independent check became routine, dependable, and universal enough that the worry had nowhere to live. The reporting layer of American elections has not had that. Actual Vote’s immediate contribution is the per-precinct evidence each analysis produces; its long-run contribution is the same transformation the elevator inspector quietly performs — turning a step the public is currently asked to accept on the word of election administrators — sometimes partisan, and in any case unable to meet the standard high-stakes elections demand, no matter how conscientious their work — into one that is independently re-checked as a matter of course, until trusting the result no longer requires thinking about it.
VII. Cross-References
This entry illuminates the reporting-layer case studies through the lens of the routine independent check — and the failure that occurs when no such check stands between the work and the public:
-
Shelby County, Tennessee, 2015. Bennie Smith’s single photograph of a poll tape that did not match the official result is the evidence a routine reporting-layer inspection would have produced as a matter of course — one independent record turning an unverifiable result into a documented discrepancy, captured here only because one person happened to look.
-
Prince William County, Virginia, 2020. A reporting-layer error that survived a risk-limiting audit at greater than 99 percent confidence is the equivalent of an inspection scoped to the wrong subsystem — a check that was performed, and passed, while never examining the part that had actually failed.
-
Monmouth County, New Jersey, 2022. A “100 percent accuracy” audit that reported a clean result while the wrong candidate held office is a certificate of operation issued for a machine that was not, in fact, sound — the procedural sign-off completed while the substantive verification was missing.
-
The Fraction Magic Architecture. A vote-reporting system whose internal structure permits silent manipulation within the letter of its rules is the equivalent of a safety device that can be quietly defeated and the machine returned to service — the precise hazard the Hart case demonstrates, now living in the reporting software itself.
This entry is also the deliberate counterpart to Commercial Air Travel: aviation shows verification as the public investigation that follows catastrophe, while elevators show verification as the routine, scheduled inspection that prevents the public from ever having to worry in the first place. Election reporting needs the second model as much as the first.
VIII. Further Reading
-
ASME A17.1/CSA B44 — Safety Code for Elevators and Escalators. The governing safety code, refined through more than a century of revisions.
-
ANSI — ASME A17.1-2025 Safety Code for Elevators and Escalators. Overview of the current edition, its scope, and its joint development with CSA B44.
-
ANSI — ASME A17 Elevator Safety Standards and the consensus committee. How the balanced, ANSI-accredited committee writes the code so no single interest controls it.
-
ASME QEI-1 — Standard for the Qualification of Elevator Inspectors. The credentialing standard behind the independent inspector.
-
Maryland Division of Labor — Third-Party Qualified Elevator Inspector requirement. A working example of a mandatory third-party inspection regime, including the bar on inspecting equipment in which one has a financial interest.
-
California Code of Regulations, Title 8 §3141.6 — Periodic Tests. State regulation fixing the recurring inspection-and-test cycle and the witnessing requirement.
-
Fire Engineering — Mechanical Elevator Door Restrictors. The history of the 1980 door-restrictor requirement and the fall-to-death hazard that drove it.
-
CPWR / BLS — Deaths and Injuries Involving Elevators and Escalators. The data behind the safety record, including the breakdown between passenger and worker fatalities.
-
FindLaw — NYC Elevator Death Due to Disabled Safety Device. The Suzanne Hart case: the bypassed safety circuit, the city’s findings, and the violations against the contractor.
