Incident Investigation

5 Whys vs Fishbone vs Fault Tree: Which Investigation Method Fits the Evidence?

The best incident investigation method depends on the evidence, the system boundary, and the decision leaders need to make. Compare 5 Whys, Fishbone, and Fault Tree before choosing a method that could oversimplify a serious event.

By 7 min read
investigative scene on 5 whys vs fishbone vs fault tree which investigation method fits the evidence — 5 Whys vs Fishbone vs

Key takeaways

  1. 01Choose 5 Whys when one visible causal chain can be tested against evidence, not when the team wants a fast answer.
  2. 02Use Fishbone to organize multiple evidence streams before deciding which causal paths deserve deeper testing.
  3. 03Use Fault Tree Analysis when a defined top event depends on combinations of failed barriers, conditions, or safeguards.
  4. 04Require investigators to state the evidence boundary and the decision question before selecting a method.
  5. 05Use the investigation method to improve the work, with Andreza Araujo's safety resources as a practical reference for leaders.

When an incident investigation begins with a blank template, the team often reaches for the method it knows best. That habit can turn a complex event into a neat story before the evidence has had a chance to challenge it.

5 Whys, Fishbone, and Fault Tree Analysis are not interchangeable drawing styles. Each one defines a different boundary around the event, asks a different question of the evidence, and creates a different risk of oversimplification. The right choice is therefore not the method that looks fastest. It is the method that can support the decision leaders must make after the facts are tested.

Evaluation criteria that should come before the diagram

The first criterion is the shape of the evidence. A single broken component, a missed verification, and a sequence of management decisions do not produce the same investigative problem, even when the outcome is similar. The team should identify what is known, what is inferred, and what remains untested, because the method must expose uncertainty rather than decorate it.

The second criterion is the system boundary. If the event can be understood inside one task, a focused causal chain may be enough. If the event crosses maintenance, production, procurement, supervision, and design, a method that only follows the last visible action will leave important conditions outside the frame.

The third criterion is the decision that follows. A plant manager may need to decide whether to redesign a safeguard, change a permit rule, stop a process, or accept residual risk temporarily. Since each decision needs a different level of proof, the investigation method should be selected after the decision question is stated.

Criterion5 WhysFishboneFault Tree Analysis
Best starting questionWhat causal chain can the evidence support?Which causal families deserve examination?How could this defined top event occur?
StrengthFocus and speed when the chain is clearCoverage across multiple evidence familiesLogic for combinations of failures and conditions
Main riskPrematurely linear explanationLong list without tested causationTechnical complexity without operational action
Good fitFocused event or branchEarly evidence organizationHigh-consequence, barrier-dependent event

5 Whys fits a focused causal chain, not every incident

5 Whys works when the team can describe a specific problem and test each answer against evidence. It is useful for a narrow equipment failure, an omitted verification, or a local process breakdown whose causal path is reasonably bounded. The method becomes weak when every answer is simply another broad label, such as “poor training” or “human error,” because those labels stop the investigation instead of extending it.

A disciplined team treats each why as a hypothesis. If the first answer is that a worker entered an unguarded area, the next question is not automatically “why did the worker choose that?” The team should ask what allowed the area to be unguarded. It should then identify which control was expected to prevent entry and what records show about the condition at the time. This keeps the investigation connected to observable work.

James Reason's distinction between active and latent failures is valuable here because a visible action may be only the final expression of earlier decisions. As Andreza Araujo argues in Sorte ou Capacidade, incident analysis must separate apparent chance from the organizational conditions that shaped the exposure. 5 Whys can support that discipline, although it should not be allowed to force every event into one straight line.

The method is strongest when the investigator defines a stopping rule. Stop when the team reaches a condition that can be changed, verified, and owned, not when it reaches a vague statement about attitude. A useful final why points toward a control decision, such as a redesign, a verification requirement, or a change in authority, while a weak final why only restates the outcome.

Fishbone is the better first map when evidence is distributed

Fishbone analysis is useful when the event may involve several evidence families and the team needs a shared map before it chooses a deeper line of inquiry. The familiar categories, such as equipment, methods, people, environment, measurement, and management, are not conclusions. They are prompts that help investigators search beyond the last person who touched the task.

That distinction matters because a Fishbone can either widen the investigation or become a storage place for speculation. Each branch should therefore carry an evidence status. The team can mark a factor as verified, plausible, contradicted, or still requiring a record, interview, inspection, or technical test. Without that discipline, the diagram may contain twenty ideas and no defensible causal finding.

Across 25+ years leading EHS work in multinational operations, Andreza Araujo has seen that the quality of an investigation depends less on the visual format than on whether leaders are willing to examine the work system that produced the exposure. In more than 250 cultural-transformation projects supported by her team, the practical question has remained consistent: which condition can the operation change before the same exposure returns?

Fishbone is especially valuable before a serious investigation team assigns blame or selects a corrective action. It makes missing evidence visible, which helps the team avoid treating an interview statement as equivalent to a maintenance record or a verified barrier test. Because the method is broad, however, the lead investigator should narrow the final analysis to the branches that can explain the event and change the decision.

Fault Tree Analysis earns its complexity when the top event is clear

Fault Tree Analysis starts from a defined top event and works backward through logical relationships that could produce it. The method is valuable when the event depends on combinations of failed safeguards, equipment states, human actions, environmental conditions, or management decisions. It is not merely a more technical Fishbone, because its purpose is to test how conditions combine rather than to group possible contributors.

The top event must be precise. “An unsafe workplace” is too broad, while “loss of containment during transfer from tank A to tanker B” gives the team a boundary that can be inspected. Once the top event is defined, the team can examine whether the event required one failure, several simultaneous failures, or a condition that defeated multiple barriers at once.

Fault Tree Analysis is valuable for serious injuries and fatalities because it can expose dependence between safeguards that appear independent on paper. If two controls rely on the same power supply, the same supervisor, or the same unverified assumption, their presence may create less protection than the register suggests. The analysis does not prove that every branch caused the event, but it clarifies which combinations deserve testing.

The method has a practical limit. A detailed tree that does not change a design, a maintenance requirement, a test frequency, or an escalation rule becomes an engineering exercise detached from the operation. For that reason, the team should connect each critical branch to an owner, a verification method, and a date by which the control will be tested in the field.

Decision matrix: match the method to the evidence

The comparison becomes useful when investigators stop asking which method is best in general and ask which method can answer the present decision. The matrix below is a starting point, not a substitute for professional judgment, because evidence quality and consequence can change the appropriate depth of analysis.

Investigation conditionPreferred first methodWhyWhat to add when needed
One visible failure with a bounded task5 WhysTests a focused causal chain quicklyRecords review and barrier verification
Several departments, records, and work conditionsFishboneCreates an evidence map before narrowing5 Whys on verified branches
High-consequence event with interacting safeguardsFault Tree AnalysisTests combinations and dependencyField validation of critical barriers
Unclear event boundaryFishboneHelps define what the investigation must explainFault Tree or 5 Whys after scope is fixed
Repeated event with a known mechanism5 Whys plus trend evidenceConnects the local chain to recurrenceFishbone for organizational conditions

A simple scorecard can help a review board make the choice explicit. Rate the event from one to five for consequence, interaction between safeguards, evidence dispersion, and uncertainty. High consequence combined with high interaction favors Fault Tree Analysis, while high evidence dispersion and uncertain boundaries favor Fishbone. A focused event with low interaction may justify 5 Whys, provided the team still checks for latent conditions.

Recommendation by investigation context

For a supervisor reviewing a minor but recurring task failure, start with 5 Whys and require the final answer to identify a changeable control. The supervisor should then compare the explanation with prior events, because a method that explains one occurrence but ignores recurrence has not reached the operational problem.

For an EHS manager leading a cross-functional investigation, start with Fishbone and assign evidence owners to each credible branch. Once the map is tested, use 5 Whys for a focused causal chain or Fault Tree Analysis for a serious event whose safeguards interact. This sequence prevents the team from choosing complexity before it knows what the evidence requires.

For a plant manager or risk committee reviewing a potential SIF, use Fault Tree Analysis when the top event and critical barriers can be defined. The review should ask whether the proposed controls are independent, verifiable, and available at the point of exposure. Since a polished diagram can still hide weak controls, leaders must walk the field and test the assumptions that support the tree.

Andreza Araujo's Safety Culture: From Theory to Practice makes the same broader point from a culture perspective: a method matters only when it changes how leaders see and manage the work. The investigation should therefore end with a decision trail that links evidence, control ownership, verification, and learning, rather than with a document that closes because the meeting ended.

Use one method deliberately, then combine methods when the evidence demands it

5 Whys, Fishbone, and Fault Tree Analysis answer different questions. 5 Whys tests a focused chain, Fishbone organizes distributed evidence, and Fault Tree Analysis examines combinations around a defined top event. Selecting among them is an act of risk judgment, because the wrong method can make an incomplete explanation look settled.

The practical rule is simple. Define the event, state the decision, inspect the evidence boundary, and then select the least complex method that can still test the serious possibilities. When the evidence crosses that method's limits, combine methods intentionally and record why the additional analysis was necessary.

If your investigation process needs a clearer decision trail, explore Andreza Araujo's safety resources and use the comparison above as a review-board prompt. The goal is not to produce a more impressive diagram. It is to prevent the next exposure by improving the condition that allowed the event to develop.

For teams building a stronger investigation standard, Andreza Araujo's work connects technical analysis with leadership behavior, evidence quality, and field verification. That combination helps the organization make fewer assumptions when the consequences of a wrong conclusion are high.

Topics 5-whys fishbone-diagram fault-tree-analysis root-cause-analysis incident-investigation serious-injuries-fatalities

Frequently asked questions

Is 5 Whys better than a Fishbone diagram?
Neither method is universally better. 5 Whys is useful for testing a relatively focused causal chain, while Fishbone is better when the team needs to organize evidence across people, equipment, procedures, environment, and management conditions.
When should a team use Fault Tree Analysis?
Use Fault Tree Analysis when the investigation has a clearly defined top event and the team needs to test how combinations of failures and conditions could produce it. It is especially useful for high-consequence events and barrier-dependent systems.
Can these methods be used together?
Yes. A team may use Fishbone to map the evidence landscape, 5 Whys to test a focused branch, and Fault Tree Analysis to examine a critical top event or barrier combination. The sequence should follow the evidence rather than a fixed template.
What is the biggest mistake in choosing an investigation method?
The biggest mistake is choosing the familiar method before defining the evidence and the decision. A simple method can hide interacting conditions, while a complex method can create diagrams that no one uses to change the work.
Who should decide which method to use?
The investigation lead should recommend the method, but the operational owner and technical specialists should confirm that it matches the event, the available evidence, and the decisions that must follow. Serious events may require more than one analytical view.

About the author

Andreza Araújo

Safety Culture Expert | Senior EHS Executive

Andreza Araújo is a safety culture expert and senior EHS executive with more than 25 years of experience in environment, health and safety. She is a Civil Engineer and Occupational Safety Engineer from Unicamp, holds a Master's degree in Environmental Diplomacy from the University of Geneva, and completed sustainability studies at IMD Switzerland. Andreza has served in Global Head of EHS roles in Fortune 500 environments, leading cultural transformation programs across multinational operations. She has represented Brazil as a speaker at the United Nations in Paris and has spoken at the International Labour Organization in Turin. She is the author of more than 16 books on safety culture in Portuguese, Spanish, English and German. Her work has earned more than 10 EHS awards, including two recognitions from Indra Nooyi, former PepsiCo CEO.

  • Civil & Safety Engineer (Unicamp)
  • M.A. Environmental Diplomacy (University of Geneva)
  • Sustainability Cert (IMD Switzerland)
  • People Management & Coaching (Ohio University)
  • UN Paris speaker representative for Brazil
  • ILO Turin speaker
  • LinkedIn Top Voice
  • Indra Nooyi PepsiCo CEO recognition (2x)

Documentaries

Watch Andreza's documentaries

Three productions on safety culture, organizational failure and the human lessons behind major disasters.

Podcasts

Listen to Andreza's podcasts

She hosts three shows on safety leadership, EHS and organizational culture, in English and Portuguese.

Summarize with AI