An example here might be the all weather automatic landing system for aeroplanes.
The military adopted the system with a failure rate of 1 in 120,000 (where the pilot would retake the controls and abort the touchdown). For civil aviation use they needed to go from a simplex to a triplex system (where the landing would not be aborted as long as two of three computers were in agreement – and the errant one was ignored) to achieve a failure rate of better than 1 in 10 million.
What failure rate can we put on any cheap pressure regulator – when used for a different set of conditions? At Thurleigh, the pilots were highly trained to recognise any failure, or impending failure, but here we have personnel who may not have any training at all, but still operating with a potentially catastrophic outcome.
Competency cannot be transferred by simple forum postings.