Incident Investigation: 5 failures that keep the report from changing the work
Most incident reports fail because they collect facts before deciding what the facts must prove. This article shows how to preserve context, test stories, and close with controls that change the work.

Key takeaways
- 01A report is not useful just because it is complete; it is useful only when it changes the work that produced the incident.
- 02The best investigations start with the decision to verify, not with the report template.
- 03Witness statements should test the first theory, not confirm it.
- 04Corrective action has to change the control system, not just the wording of the closure note.
- 05Andreza Araujo's experience across 25+ years and 250+ projects supports a control-first investigation model.
An incident investigation can feel complete while the work is still untouched. The form is filled, the timeline is neat, and the corrective action list looks active, yet the same control gaps remain in place because the team documented the event before it truly understood the decision chain that produced it.
Across 25+ years in multinational EHS work, Andreza Araujo has seen this pattern repeat in different countries and sectors. In more than 250 cultural transformation projects, the same failure appears in a new uniform: the team starts with the report template, not with the field evidence. When that happens, the investigation becomes a story about the event, not a system for changing the work.
This article is for investigators, plant managers, EHS leaders, and supervisors who need the next investigation to do more than close a file. If you want the adjacent process view, Incident Triage Meetings: 4 Decisions That Keep RCA Honest shows the decisions that should happen before analysis starts, while 5 Whys vs Fishbone vs Fault Tree: Which RCA Method Fits a SIF Review? helps the team choose the right analysis tool instead of forcing one method on every case.
Why the report feels complete before the work is understood
ISO 45001:2018 requires organizations to investigate incidents and take corrective action, but the standard does not guarantee that the investigation will improve the system. A report can satisfy the process requirement and still fail the operating test if it never explains why the barrier failed, who owned the barrier, and what has to change in the field.
That gap is the real problem. The team sees a document with dates, names, and causes, so it assumes the work is done. In practice, the investigation is only useful when it changes supervision, control verification, task design, or escalation. James Reason is still the right reference here, because the visible event usually sits on top of latent conditions that were already in the system before the incident became obvious.
The strongest investigations do not start by asking what wording will satisfy the form. They start by asking what decision the organization needs to make before the same exposure returns. That is a different question, and it changes everything that follows.
Failure 1: The template replaces the decision
The first failure is subtle. The team opens the investigation form, and the form begins to steer the inquiry. Instead of asking what must be verified, the investigator asks which box should be filled next. Once that happens, the report becomes a sequence of document fields rather than a method for understanding the event.
Template-first investigations usually produce tidy language and weak decisions. They name a cause, name an action, and close the case, but they do not tell the organization what control was missing or what assumption was wrong. As Andreza Araujo explains in Safety Culture: From Theory to Practice, repeated decisions reveal the real operating culture. A form that only rewards completion reveals a paperwork culture, not a learning culture.
A better investigation begins with a decision statement. The team should know whether the next output must confirm a failed control, expose a design gap, or explain a supervision gap. When the decision is clear, the evidence collection stays focused and the report stops drifting toward generic language.
Failure 2: Evidence is collected without preserving context
Many investigations collect photographs, statements, and log extracts, yet they lose the condition that gave those facts meaning. The team remembers what was seen, but not the sequence, the location, the shift pressure, the permit state, or the work order that made the scene what it was. Without context, evidence becomes decoration.
This is why early field preservation matters. A static photo rarely explains whether a guard was removed, a permit was re-used, or the task had already drifted from the original plan. If the context is not captured while the work is still live, the later analysis has to guess what the scene actually meant. That is where weak conclusions begin.
If your organization still treats evidence collection as a clerical task, use the method view in How to Build a Safety Decision Trail in 30 Days. It is a useful way to separate facts that can be verified from opinions that only sound plausible after the event.
Failure 3: Witness interviews are treated as confirmation
A witness interview should test a story, not confirm the first version the team already likes. Yet many investigators enter the room with a preferred conclusion and then ask questions that only make that conclusion sound smoother. That is not inquiry. It is endorsement with a clipboard.
The danger is not that people lie. The danger is that memory is shaped by stress, sequence, and social pressure, so two honest witnesses can describe the same event differently. If the interviewer is trying to defend an early theory, those differences get shaved down instead of examined. The result is a single story that feels coherent and may still be wrong.
Use witness statements to identify where the event changed shape, where the person saw the work differently, and where the control was no longer visible. Then compare those statements against the field conditions and the barrier map. If the statements never get tested against the scene, the investigation is still inside the first story.
Failure 4: The last visible step is mistaken for the cause
One of the oldest investigation traps is to stop at the last visible human action. The worker moved, the supervisor signed, the contractor entered, the mechanic isolated, or the operator pressed the button, and the team stops there because the last step is easy to name. It is also often the least useful place to stop.
James Reason remains useful because the event is usually the final expression of earlier conditions. If the report stops at the last action, it misses the line management gap, the equipment condition, the procedure weakness, the permit failure, or the design choice that made the final action possible. That is how investigations blame the surface while leaving the structure untouched.
Heinrich and Bird still have value here, not as a slogan, but as a reminder that serious events are often preceded by many smaller precursors. The job of the investigator is not to prove that the final person was present. The job is to show which earlier control drift made that final step possible.
Failure 5: Corrective actions never touch the control system
The final failure is the most expensive. The report ends with actions such as refresher training, a reminder email, a new poster, or a note to be more careful next time. Those actions may be easy to launch, but they rarely change the control system that allowed the event to happen in the first place.
ISO 45001:2018 expects corrective action, not symbolic closure. That means the response should change ownership, verification, maintenance, supervision, or design. If the barrier failed because it was not inspected, then the fix has to change inspection. If the barrier failed because the permit process was weak, then the fix has to change the permit process. If the barrier failed because a critical decision sat too low in the hierarchy, then the fix has to change decision rights.
Training can still be part of the response, but only when the failure is competence-related and the control can actually be used as designed. When the real problem is a weak design or a missing verification loop, training only teaches people how to live with the defect more politely.
What a strong incident investigation must produce
A strong investigation produces four things that a paper investigation usually misses. It identifies the decision that failed, it preserves the context that gave the evidence meaning, it verifies the barrier that was supposed to break the event chain, and it assigns corrective action to a control owner who can change the system. If any one of those is missing, the report is incomplete.
The next step is not abstract. The investigator should write the findings so that a line supervisor, a plant manager, and a board member can all see the same logic. The supervisor needs to know what to stop doing now. The manager needs to know what to fund or reinforce. The board needs to know whether the organization actually learned something that will survive pressure.
If you want the ownership side of that logic, Risk Register Explained: 4 Fields That Keep It Live and Decision Rights Matrix Explained: 4 Levels That Keep Safety Escalation Moving are useful companions, because a good investigation usually fails or succeeds on the same decision architecture that governs the rest of the operation.
Paper investigation vs operating investigation
The table below shows the difference between a report that looks finished and a report that actually changes the work.
| Dimension | Paper investigation | Operating investigation |
|---|---|---|
| Starting point | Template fields | Decision to verify |
| Evidence | Collected after context has faded | Preserved while the scene is still readable |
| Witness use | Confirmation of the first story | Test of competing explanations |
| Cause statement | Last visible action | Control gap and latent condition |
| Corrective action | Training or reminder | Change to control, design, or ownership |
| Closure test | Report submitted | Work changed in the field |
The pattern is consistent. The paper investigation closes when the document is complete, while the operating investigation closes only when the control gap has been addressed and the field can prove it. That difference is what makes one process decorative and the other operational.
Who should own the next 24 hours
The investigator should own the first evidence pass, the supervisor should own immediate control preservation, and the manager should own the first decision about what changes now versus what waits for the formal report. If those roles blur, the organization loses time and starts solving the wrong problem at the wrong level.
In more than 250 cultural transformation projects, Andreza Araujo has seen one constant: the first day shapes the quality of the final learning. If the first 24 hours preserve context, separate facts from theories, and force ownership of barriers, the report usually improves. If the first 24 hours are spent polishing language, the report usually becomes a cleaner version of the same blind spot.
That is why the next conversation should not be, "Who wrote the report?" It should be, "Which control failed, who owns it, and what in the field will look different after this is closed?"
Conclusion
An incident investigation only earns its place when it changes the work. If the process starts with the template, loses the context, confirms the first story, stops at the last visible action, or closes with symbolic action, the organization gets documentation instead of learning.
The better standard is simple. Verify the decision, preserve the scene, test the witness story, map the barrier, and make the corrective action change the control system. If you need the operational bridge from report to ownership, start with the RCA method comparison, then use Andreza Araujo to turn the investigation into a decision that survives the next shift.
Frequently asked questions
What is the main failure in most incident investigations?
Why are witness interviews often weak?
Is training a valid corrective action after an incident?
How does James Reason help here?
Which article should I read next?
About the author
Andreza Araújo
Safety Culture Expert | Senior EHS Executive
Andreza Araújo is a safety culture expert and senior EHS executive with more than 25 years of experience in environment, health and safety. She is a Civil Engineer and Occupational Safety Engineer from Unicamp, holds a Master's degree in Environmental Diplomacy from the University of Geneva, and completed sustainability studies at IMD Switzerland. Andreza has served in Global Head of EHS roles in Fortune 500 environments, leading cultural transformation programs across multinational operations. She has represented Brazil as a speaker at the United Nations in Paris and has spoken at the International Labour Organization in Turin. She is the author of more than 16 books on safety culture in Portuguese, Spanish, English and German. Her work has earned more than 10 EHS awards, including two recognitions from Indra Nooyi, former PepsiCo CEO.
- Civil & Safety Engineer (Unicamp)
- M.A. Environmental Diplomacy (University of Geneva)
- Sustainability Cert (IMD Switzerland)
- People Management & Coaching (Ohio University)
- UN Paris speaker representative for Brazil
- ILO Turin speaker
- LinkedIn Top Voice
- Indra Nooyi PepsiCo CEO recognition (2x)
Documentaries
Watch Andreza's documentaries
Three productions on safety culture, organizational failure and the human lessons behind major disasters.
Podcasts
Listen to Andreza's podcasts
She hosts three shows on safety leadership, EHS and organizational culture, in English and Portuguese.