How to Write Incident Findings That Lead to Better Controls in 21 Days
A practical 21-day method for turning incident evidence into findings that name the failed control, expose decision gaps, and guide verifiable corrective action.

Key takeaways
- 01A useful incident finding names the exposure, the failed or missing control, the evidence, and the decision that allowed the condition to persist.
- 02Separate facts from interpretation before writing the finding, because a conclusion that outruns the evidence weakens the action that follows.
- 03Test whether the finding describes a local error, a latent organizational condition, or both, using James Reason’s systems view of failure.
- 04Assign each finding to a control owner who can change the work condition, not only to the investigator who wrote the report.
- 05Close a finding only after field evidence shows that the control changed and remains credible under the conditions that produced the exposure.
An incident finding should do more than describe what went wrong. It should identify the exposure, name the control that failed or was absent, show the evidence behind that conclusion, and point to the decision owner who can change the condition. When a report stops at “the procedure was not followed,” it often closes the story without reducing the risk.
That distinction matters because an investigation can be technically complete while the original pathway to harm remains available. Andreza Araujo’s work in Safety Culture: From Theory to Practice connects culture with repeated decisions under pressure, which makes the quality of an incident finding a test of management practice, not only of investigative writing.
This guide uses a 21-day workflow for investigators, EHS managers, and operational leaders who need findings that survive review. The central discipline is simple. Every finding must connect evidence to a control, a decision, an owner, and a verification condition.
What you need before starting
Collect the incident charter, the preserved evidence, the task method, relevant permits or isolation records, training and competence records, equipment information, and the names of people who can explain how the work was actually performed. If the evidence is still changing, first use this evidence-preservation procedure before drawing conclusions.
Use the investigation charter to define scope, decision rights, and the questions the review must answer. A charter created before interviews begin helps prevent the team from turning the report into a search for a convenient person to blame. The related incident investigation charter guide provides the setup for this phase.
Step 1: Freeze the question the finding must answer
Write the question in terms of exposure and control. “Why did the operator make the wrong choice?” is too narrow to guide a useful review. “Why was the person exposed to moving energy when the task required a protected state?” keeps attention on the condition that made harm possible.
Record the event boundary, the task, the affected people, and the potential consequence. Do not expand the investigation into every weakness in the department. A focused question gives the team a standard for deciding which facts belong in the finding and which belong in a separate improvement plan.
Step 2: Separate facts from interpretations
Create two columns before drafting prose. Put direct observations, records, timestamps, physical evidence, and consistent witness accounts in the facts column. Put explanations, assumptions, and proposed causes in the interpretation column until the team has tested them.
This separation protects the report from premature certainty. A missing signature may be a fact, while “the supervisor ignored the permit” is an interpretation that requires more evidence. The distinction also helps the investigator explain what is known, what is probable, and what remains unresolved.
Step 3: Reconstruct the decision path
Build the sequence from the first relevant condition to the exposure. Include changes in work scope, handovers, equipment state, staffing, time pressure, alarms, permits, isolations, and points where someone could have stopped or redirected the task.
Use the incident decision timeline method when the event involves several choices across shifts or functions. The purpose is not to create a longer chronology. It is to identify the decision point at which a stronger control could have changed the outcome.
Step 4: Name the expected control
State what should have prevented, detected, or limited the exposure. Use operational language such as verified isolation, physical exclusion, interlock, competent authorization, or a defined handover. Avoid phrases such as “greater awareness” because they describe a wish rather than a control state.
Then identify the control owner. The owner may sit in engineering, operations, maintenance, procurement, or supervision, depending on what must change. A finding becomes useful when the person responsible for the barrier can recognize the condition and accept a measurable next decision.
Step 5: Test whether the control existed in the field
Compare the expected control with what the worksite, equipment, documents, and people show. A procedure may require a verification step while the actual form has no field for it, the verifier lacks authority, or the equipment makes the step impractical. Those details change the finding.
Use five evidence questions to check whether the control was present, available, understood, used, and capable of holding under the conditions of the task. A control that exists only in the management system should not be written as if it protected the person at the point of exposure.
Step 6: Distinguish local failure from latent conditions
Describe the visible action without making it the whole explanation. James Reason’s work on active and latent failures shows why the final act can coexist with weaknesses in design, supervision, resourcing, maintenance, information, or decision-making.
Ask which conditions made the action likely, acceptable, or difficult to challenge. If the procedure was unclear, the barrier was unavailable, the schedule rewarded continuation, or the supervisor had no workable alternative, include that evidence in the finding. This does not remove personal responsibility. It makes the responsibility precise enough to change the system.
Step 7: Write the finding in one controlled sentence
Use a sentence structure that keeps the logic visible. State that a defined exposure was possible because a named control was absent, degraded, bypassed, or not verified under a specific condition, and identify the decision or organizational factor that allowed the gap to persist.
For example, a finding might state that personnel entered the line of fire during clearing because the isolation verification was not independently confirmed after the task changed, while the handover process gave no named person authority to pause the work. That sentence can lead to a control change. “The team needs to be more careful” cannot.
Step 8: Convert the finding into proof of change
Assign an action that changes the control, not only the document. The action may involve redesigning access, changing authorization, adding an independent verification, improving equipment, revising a handover, or removing a production condition that encourages bypass.
Set the proof before the action begins. Evidence might include a field demonstration, a sampled record tied to the exposure, a restart check, a supervised task, or a review of the first operating cycle after the change. The proof must be strong enough to show that the work condition changed, not simply that a task was marked complete.
Final verification before closure
Review the finding with the operational owner and the people who perform the work. Then compare the proposed action with the closure discipline in this corrective-action verification guide. Close the finding only when the evidence answers the original question and the control remains credible during normal variation.
- The exposure is stated in operational terms.
- The failed, missing, or weak control is named.
- Facts are separated from interpretation.
- The decision path and latent conditions are visible.
- A control owner, deadline, and proof of change are recorded.
- Field evidence confirms that the changed control works under the relevant task conditions.
Andreza Araujo’s book Make The Difference: Be a Leader in Health & Safety treats leadership as the quality of decisions made when pressure is real. Incident findings are one of those decisions. When they name the control and require proof, the investigation becomes part of prevention. When they name only a behavior, the report may close while the exposure waits for another shift.
For a practical next step, place the finding sentence, owner, proof condition, and closure date in the same review record. That small change makes it harder for a serious issue to disappear between the investigation report and the operating floor.
Frequently asked questions
What is an incident finding?
How long should it take to write incident findings?
Should an incident finding name a person?
What makes a finding actionable?
When is an incident finding closed?
About the author
Andreza Araújo
Safety Culture Expert | Senior EHS Executive
Andreza Araújo is a safety culture expert and senior EHS executive with more than 25 years of experience in environment, health and safety. She is a Civil Engineer and Occupational Safety Engineer from Unicamp, holds a Master's degree in Environmental Diplomacy from the University of Geneva, and completed sustainability studies at IMD Switzerland. Andreza has served in Global Head of EHS roles in Fortune 500 environments, leading cultural transformation programs across multinational operations. She has represented Brazil as a speaker at the United Nations in Paris and has spoken at the International Labour Organization in Turin. She is the author of more than 16 books on safety culture in Portuguese, Spanish, English and German. Her work has earned more than 10 EHS awards, including two recognitions from Indra Nooyi, former PepsiCo CEO.
- Civil & Safety Engineer (Unicamp)
- M.A. Environmental Diplomacy (University of Geneva)
- Sustainability Cert (IMD Switzerland)
- People Management & Coaching (Ohio University)
- UN Paris speaker representative for Brazil
- ILO Turin speaker
- LinkedIn Top Voice
- Indra Nooyi PepsiCo CEO recognition (2x)
Documentaries
Watch Andreza's documentaries
Three productions on safety culture, organizational failure and the human lessons behind major disasters.
Podcasts
Listen to Andreza's podcasts
She hosts three shows on safety leadership, EHS and organizational culture, in English and Portuguese.