Incident Investigation

Incident Investigation: 4 Assumptions That Weaken Action

Incident reports fail when they explain the last action but leave the operating conditions unchanged. Test four assumptions before approving corrective action.

By 6 min read
investigative scene on incident investigation 4 assumptions that weaken action — Incident Investigation: 4 Assumptions That W

Key takeaways

  1. 01Test the conditions behind the last visible action instead of stopping at personal behavior.
  2. 02Compare the written procedure with the work people had to perform in the field.
  3. 03Treat training as support for a control change, not as automatic proof of prevention.
  4. 04Define field verification and a failure response before closing corrective action.
  5. 05Escalate recurring causes to the leader who controls the operating condition.

A report can be accurate, signed, and filed on time while the next serious event remains entirely possible. The failure is often not a missing investigation form. It is an assumption that the investigation never tests.

Incident investigation creates value only when evidence changes a decision, a control, or an operating condition. When the report merely explains what happened after the fact, the organization gets a polished narrative instead of a stronger barrier. This is why leaders should examine the assumptions beneath the corrective action, not only the quality of the final document.

Why a complete report can still leave the risk intact

Most investigation systems reward closure. A team gathers statements, identifies a cause, assigns an owner, and closes the action. Those steps can be useful, although none proves that the hazard has become harder to repeat.

The more important test is whether the investigation reached the conditions that made the event possible. James Reason's work on latent failures explains why an operator's final action is often only the visible part of a longer chain that includes design, supervision, maintenance, workload, and decision rules.

Andreza Araujo makes a related point in Safety Culture: From Theory to Practice. A safety culture is expressed through the decisions an organization makes under pressure, which means an investigation must examine those decisions rather than stopping at personal behavior.

Assumption 1: The last visible action is the main cause

Investigators often begin with the final movement before the event. Someone entered an area, bypassed a check, selected the wrong setting, or failed to notice a change. Because that action is easy to describe, it can become the center of the report.

The problem is not that the action is irrelevant. The problem is that the action may be the endpoint of conditions that narrowed the person's choices. If the task design rewarded speed, if the instruction conflicted with production priorities, or if the control was difficult to verify, blaming the final movement leaves the system that shaped it untouched.

Ask what made the action reasonable at that moment. Identify the information available to the worker, the competing objective, the condition of the equipment, and the supervision actually present. The answer should explain the decision environment, not invent a personality defect.

This does not remove accountability. It places accountability at the level where the organization can change the exposure, which is why a useful investigation distinguishes an unsafe act from the conditions that made it likely.

Assumption 2: The written procedure describes the real work

A procedure is evidence, but it is not proof of how the job was performed. Many investigations compare the event with the written method and then conclude that the deviation caused the loss. That comparison is incomplete when the procedure has not been tested against field conditions.

Compare the procedure with the actual sequence, tools, access, staffing, handoffs, and time pressure. A control that exists only on paper may be impossible to execute during a normal shift, especially when it requires information from another team or a decision that no role is authorized to make.

The strongest investigation records both versions of the work. One describes the intended process. The other shows what people had to do to complete the task with the resources and constraints they had. The gap between them is not automatically misconduct. It is evidence about design quality.

For a deeper treatment of evidence quality, connect this review with timeline reconstruction, witness accounts, physical evidence, and digital records, because the real sequence often reveals a control failure that the procedure hides.

Assumption 3: A training action is a control improvement

Training is an attractive corrective action because it is visible, assignable, and easy to close. It can be appropriate when people lack essential knowledge or practice, yet it is weak when the event resulted from an unavailable barrier, poor equipment, ambiguous authority, or conflicting targets.

Before approving training, ask what the learner will be able to do that was not possible before. Then ask how the organization will verify that the new capability survives a busy shift. If the answer is attendance at a refresher session, the action measures exposure to information rather than risk reduction.

A stronger action changes the task or decision path. It may redesign the interface, add a physical interlock, clarify stop-work authority, alter the handoff, or require a field verification that cannot be completed from a desk. Training can support those changes, but it should not substitute for them.

When the same event pattern has appeared before, review the evidence breaks that let a known hazard return. Repeating a lesson does not close a recurring exposure if the barrier that failed remains unchanged.

Assumption 4: Closing the action proves the risk is controlled

An action can be marked complete while the risk remains present. A revised form may be issued, a briefing may be delivered, and a manager may sign the record, although none of those events demonstrates that the control works where the hazard exists.

Define the verification before the action is approved. State what condition must be observable, who will check it, and what evidence will count. A verification should occur in the operating environment, under the conditions that previously allowed the failure, rather than in a meeting room where the control appears orderly.

The verification should also have a failure response. If the barrier is missing, bypassed, or difficult to use, the owner needs authority to reopen the action and escalate the decision. Without that route, verification becomes another administrative milestone.

Leaders can use the five questions that test whether evidence changed the control as a review screen before accepting closure. The purpose is not to create more paperwork. It is to prevent a closed action from being confused with a controlled risk.

What an evidence-led corrective action contains

A corrective action is stronger when it describes the barrier, the change, the owner, and the verification condition in one chain. It should make clear which part of the operating system will be different after implementation.

  • The failed or missing barrier is named in operational language.
  • The action changes equipment, design, authority, sequence, supervision, or information flow.
  • The owner controls the resources needed to complete the change.
  • The verification occurs in the field and uses observable evidence.
  • The action has a defined response if the barrier does not hold.

These criteria also help separate a corrective action from a recommendation. A recommendation expresses a desirable direction. A corrective action specifies a change that can be tested.

How supervisors can challenge the report in ten minutes

Supervisors do not need to rewrite every investigation. They need a short challenge that exposes unsupported assumptions before the report becomes organizational memory.

  1. Ask which barrier should have prevented the event and whether it existed in the work area.
  2. Ask what the person knew, saw, and was authorized to decide at the time.
  3. Ask which condition made the selected action appear workable.
  4. Ask how the proposed action changes that condition.
  5. Ask what will be observed in the field before closure is accepted.

If the team cannot answer these questions, the investigation is not ready for approval. The gap is useful because it shows where the reasoning still depends on assumption rather than evidence.

What leaders should do when the same cause keeps returning

Recurring causes usually indicate that the organization is treating symptoms at the wrong level. If every event ends with a reminder, the system may be learning that reminders are the only intervention it is willing to fund.

Escalate the pattern from the individual action owner to the leader who controls design, staffing, maintenance, procurement, or production priorities. The recurring issue may require a decision outside the investigation team's authority, which is why closure rates alone cannot show whether the system is improving.

Review the distribution of actions by type. If nearly all actions depend on attention, memory, or perfect execution, the portfolio is exposing a design weakness. A safer portfolio contains changes that reduce reliance on human recovery while preserving the knowledge and supervision needed for the remaining risk.

For the operational method, see how to reconstruct an incident decision timeline in 48 hours. A precise decision timeline helps leaders see where authority, information, and pressure interacted before the event.

The investigation standard leaders should accept

A strong investigation does more than answer why the event occurred. It explains why the controls available at the time did not stop the event, why the selected corrective action should work, and how the organization will know if it does not.

That standard changes the meeting. Instead of asking whether the report is complete, leaders ask whether the evidence is sufficient for the decision being requested. Instead of asking who owns the action, they ask who owns the condition that must change.

ISO 45001:2018 supports this logic through its emphasis on corrective action, evaluation of effectiveness, and improvement. The standard does not turn a form into a barrier. The organization still has to connect the investigation to the operating conditions where risk is created.

Incident investigation becomes credible when it makes weak assumptions visible and converts them into testable changes. The report is finished only after the control has been changed, observed, and defended under real work conditions.

Andreza Araujo's books and leadership resources develop this connection between culture, decisions, and operating discipline. Visit Andreza Araujo's official site for the broader body of work.

Topics incident-investigation corrective-action root-cause-analysis field-verification supervisor

Frequently asked questions

What is the main weakness in many incident investigations?
Many investigations explain the final visible action but do not test the design, authority, workload, equipment, or supervision that shaped it. The result is a plausible narrative without a durable control change.
When is training an appropriate corrective action?
Training is appropriate when the event exposed a genuine knowledge or skill gap and the organization can verify performance in the field. It is weak when the primary failure involves equipment, design, authority, or conflicting operating priorities.
How can a supervisor verify that a corrective action works?
The supervisor should define an observable barrier condition, check it in the operating environment, and confirm what happens when the barrier is missing or bypassed. A signed record alone is not effectiveness evidence.
Should an investigation identify an individual at fault?
The investigation should identify decisions and actions without treating the final operator action as the whole cause. Accountability is stronger when it reaches the leaders who control the conditions that made the failure likely.
How do leaders handle a recurring investigation cause?
They should examine whether previous actions changed the exposure, review the action portfolio for overreliance on attention and memory, and escalate the issue to the role that controls design, staffing, maintenance, procurement, or priorities.

About the author

Andreza Araújo

Safety Culture Expert | Senior EHS Executive

Andreza Araújo is a safety culture expert and senior EHS executive with more than 25 years of experience in environment, health and safety. She is a Civil Engineer and Occupational Safety Engineer from Unicamp, holds a Master's degree in Environmental Diplomacy from the University of Geneva, and completed sustainability studies at IMD Switzerland. Andreza has served in Global Head of EHS roles in Fortune 500 environments, leading cultural transformation programs across multinational operations. She has represented Brazil as a speaker at the United Nations in Paris and has spoken at the International Labour Organization in Turin. She is the author of more than 16 books on safety culture in Portuguese, Spanish, English and German. Her work has earned more than 10 EHS awards, including two recognitions from Indra Nooyi, former PepsiCo CEO.

  • Civil & Safety Engineer (Unicamp)
  • M.A. Environmental Diplomacy (University of Geneva)
  • Sustainability Cert (IMD Switzerland)
  • People Management & Coaching (Ohio University)
  • UN Paris speaker representative for Brazil
  • ILO Turin speaker
  • LinkedIn Top Voice
  • Indra Nooyi PepsiCo CEO recognition (2x)

Documentaries

Watch Andreza's documentaries

Three productions on safety culture, organizational failure and the human lessons behind major disasters.

Podcasts

Listen to Andreza's podcasts

She hosts three shows on safety leadership, EHS and organizational culture, in English and Portuguese.

Summarize with AI