Incident Investigation

RCA vs Barrier Review vs Action-Effectiveness Audit: Which Investigation Path Finds Repeat Events?

RCA, barrier review, and action-effectiveness audits answer different questions after an incident. This comparison helps EHS leaders select the investigation path that can change the work and prevent a repeat event.

By 8 min read

Key takeaways

  1. 01RCA explains how an event became possible, while a barrier review tests which protections failed, were absent, or were never designed for the exposure.
  2. 02An action-effectiveness audit answers a later question because a completed action is not evidence that the risk has changed.
  3. 03The best investigation path follows the decision required, the quality of available evidence, and the type of repeat-event risk leadership must control.
  4. 04A polished report can still be operationally weak when it names causes without assigning control owners, acceptance criteria, and a verification date.
  5. 05Across more than 250 cultural transformation projects, Andreza Araujo has seen repeat events persist when closure is treated as paperwork instead of a changed condition of work.

The investigation closes on a Friday afternoon. The report is approved, the corrective actions are assigned, and the dashboard turns green. Three months later, the same exposure appears in another area because the organization solved the narrative instead of the control.

That failure does not always mean the investigation team lacked technical skill. It often means the team selected a method that answered the wrong question. Root cause analysis explains how the event became possible. A barrier review tests whether the protections were capable of stopping it. An action-effectiveness audit checks whether the promised change survived contact with the work.

This comparison is written for EHS managers, plant leaders, and investigation owners who need to decide what to do after a serious event or a repeated near miss. The central thesis is practical: the investigation method should be chosen by the decision that must improve, not by the template the organization already knows.

The investigation method should follow the decision

Every post-incident review contains at least three decisions. Leaders need to understand what happened, determine which controls failed, and decide whether the actions changed the exposure. Those decisions overlap, but they are not interchangeable, which is why one method rarely gives a complete answer by itself.

The distinction becomes visible when a team asks, “Why did the operator do that?” The question can produce a narrow behavioral explanation, or it can open a wider examination of work design, supervision, equipment condition, production pressure, and the assumptions built into the procedure. James Reason’s work on active and latent failures is useful here because it keeps the investigation from ending at the last visible action.

Andreza Araujo’s book Luck or Capability, known in Portuguese as Sorte ou Capacidade, makes a related point through its treatment of accidents as more than bad luck. The practical implication is that an investigation must identify the conditions that made the event plausible, then convert those conditions into decisions that somebody can own and verify.

Evaluation criteria for choosing the path

Choose among RCA, barrier review, and action-effectiveness audit by testing five dimensions. The first is timing, because a method used during emergency stabilization has a different job from a method used months after closure. The second is the decision horizon, since leaders may need immediate containment, system redesign, or confidence that a completed action still works.

The third dimension is evidence. A team with strong scene evidence, equipment records, interviews, and work documents can reconstruct conditions with greater confidence than a team that only has a short report. The fourth is control criticality. If the event exposed a control whose failure could cause a serious injury or fatality, the investigation must make that control visible rather than burying it inside a broad narrative.

The final dimension is repeatability. If the same failure mode can appear across shifts, contractors, sites, or routine tasks, the method must reveal what is transferable. The facts, interpretations, and assumptions in incident evidence should be separated before the team claims that a local explanation applies everywhere.

RCA is strongest when the system story is unclear

Root cause analysis is the best starting point when leaders cannot explain how the event developed across decisions, conditions, and controls. It creates a structured account of the sequence, which allows the team to examine what was known, what was expected, what changed, and which organizational conditions shaped the work.

RCA becomes weak when the team treats “root cause” as a single sentence. Serious events usually involve several layers of influence, including equipment design, planning, training, supervision, maintenance, workload, and management assumptions. A good analysis does not multiply causes for appearance. It identifies the few conditions that, if changed, would materially reduce the chance of recurrence.

RCA also fits cases where the event raises questions about how the organization makes decisions. A procedure may have existed, yet the job may have been planned in a way that made the procedure impractical. The relevant question is not whether the document was available. It is whether the operating system made the safer choice feasible at the moment of exposure.

Its limitation is equally important. RCA can produce a persuasive story without proving that each control works. When the report ends with retraining, reminders, or a revised form, the organization may have explained the event while leaving the hazard intact.

Barrier review is strongest when control failure is the decision

A barrier review starts with the unwanted event and maps the protections that should have prevented it, detected it, or reduced its consequences. It asks whether each barrier was present, suitable, independent enough for the scenario, available at the point of work, and owned by a person or function that can maintain it.

This method is especially useful after a serious injury, a high-potential near miss, or a process event in which the organization needs to know whether critical controls can be trusted. The Swiss cheese model and its layers of defense provide a clear way to discuss how several weaknesses can align without reducing the analysis to operator fault.

The strength of a barrier review is its operational precision. Instead of saying that “supervision failed,” the team can ask which supervisory action was required, when it had to occur, what evidence would show completion, and what condition would make the action ineffective. That level of detail gives leaders a better basis for deciding whether to redesign, isolate, engineer, or verify the control.

Its limitation is that a barrier map can become a static diagram. If the team does not investigate why the barrier was weak, unavailable, or bypassed, the review may identify the missing defense without addressing the management conditions that allowed the gap to persist.

Action-effectiveness audits are strongest after closure

An action-effectiveness audit begins after the organization says the investigation is complete. Its purpose is not to inspect whether an action was performed. Its purpose is to test whether the original risk changed in the operating environment.

That distinction matters because implementation evidence is not performance evidence. A new guard may be installed, but the audit must establish that it remains in place, does not create a new exposure, and is used under the conditions in which the incident occurred. A revised procedure may be signed, but the audit must test whether the work sequence, supervision, and equipment support the new expectation.

The audit should compare the original failure mode with current field conditions. Interviews, observations, maintenance records, control checks, and repeat-event data can show whether the action reduced exposure or simply changed the language in the report. Andreza Araujo’s Safety Culture: From Theory to Practice is relevant here because compliance with a formal requirement does not prove that the underlying culture and operating habits have changed.

Its limitation is timing. An audit performed too soon can mistake enthusiasm for control maturity, while an audit performed without a clear acceptance criterion becomes another paperwork exercise. The action needs a defined operating period, an owner, and a test that would distinguish genuine risk reduction from superficial completion.

Decision matrix for repeat-event investigations

The following matrix keeps the choice tied to the decision rather than the preferred vocabulary of the investigation team.

MethodPrimary questionBest evidenceTypical outputMain risk
RCAHow did the event become possible?Timeline, interviews, work documents, equipment and management recordsSystem causes and change prioritiesA convincing story with weak control verification
Barrier reviewWhich protections failed or were not capable?Control specifications, field checks, permits, maintenance and assurance recordsBarrier owners, requirements, and verification testsA diagram that ignores the conditions behind failure
Action-effectiveness auditDid the corrective action change the exposure?Post-action observations, repeat data, interviews, inspections, and performance recordsEvidence of sustained risk reduction or required escalationConfusing action completion with effectiveness

For a high-consequence event, the strongest sequence is often RCA followed by a barrier review and then an action-effectiveness audit. That sequence is not a rule for every case. It is a way to preserve the logic from event reconstruction to control ownership to proof that the change held.

Recommendation by operating context

A plant manager facing a serious injury with unclear contributing conditions should begin with RCA, while requiring the team to identify the critical barriers inside the analysis. This prevents the report from becoming a blame exercise and gives leadership a system-level explanation that can inform design, planning, supervision, and resource decisions.

An EHS leader facing a high-potential near miss involving a known critical control should begin with a barrier review. The immediate need is to determine whether the control is capable, available, and verified across similar work. RCA can follow when the organization needs to understand why the control drifted or why the weakness was normalized.

A site with several closed actions and a repeat event should begin with an action-effectiveness audit. The central question is no longer whether the action was assigned or completed. It is whether the exposure remains possible, which means the audit must return to the field and test the condition that the action was supposed to change.

In a multi-site operation, leadership should avoid comparing closure percentages without comparing the quality of the effectiveness test. Across more than 25 years of executive EHS experience, including work across 30+ countries, Andreza Araujo has consistently connected credibility with visible follow-through. A dashboard that reports closure without field evidence can create confidence without control.

How to prevent the three methods from becoming three disconnected reports

Use one event definition, one control vocabulary, and one ownership trail across the methods. The RCA should identify the conditions that mattered. The barrier review should translate those conditions into prevention and mitigation requirements. The action-effectiveness audit should test whether those requirements are operating under real work conditions.

The handoff between methods should preserve uncertainty rather than hide it. If an interview statement is not supported by evidence, label it as an interpretation. If a control is assumed to be independent but nobody has tested that independence, treat it as an open decision. The common corrective-action myths investigators still believe often begin when an assumption is promoted to a fact because the report needs to close.

Each action should also have a control owner, an acceptance criterion, a verification method, and a date that reflects when the change can be observed. When the risk crosses organizational boundaries, the owner must have authority to change the work, not merely responsibility for updating the tracker.

The practical test is whether the work is different

The investigation is not strong because it contains more pages, more causes, or more technical language. It is strong when the organization can explain what changed, who owns the change, how the control will be checked, and what evidence would trigger further action.

Andreza Araujo’s record of 250+ cultural transformation projects and the 50% accident-ratio reduction achieved in six months at PepsiCo South America support a practical leadership standard. The report should help people make better decisions before the next exposure, while the follow-up should prove that those decisions survived normal operating pressure.

For investigation owners who need a deeper framework, the books and safety resources from Andreza Araujo connect incident learning with leadership, culture, and field practice. The right method is the one that leaves the operation with fewer plausible paths to the same event.

Topics incident-investigation rca root-cause-analysis corrective-actions critical-controls field-evidence control-effectiveness decision-quality

Frequently asked questions

What is the difference between RCA and a barrier review?
RCA reconstructs how the event developed and identifies contributing conditions, decisions, and system weaknesses. A barrier review focuses on the controls that should have prevented or limited the event, including their design, ownership, availability, and performance.
When should an organization use an action-effectiveness audit?
Use an action-effectiveness audit after corrective actions have had enough time to operate. The audit should test whether the exposure changed in the field, whether the control is being used as designed, and whether the original failure mode can still occur.
Can a barrier review replace root-cause analysis?
Usually not. A barrier review can be the primary method when the decision concerns critical controls, but RCA adds value when leaders need to understand work conditions, management decisions, and organizational causes that allowed the barrier weakness to exist.
Why do repeat incidents happen after corrective actions are closed?
Repeat incidents happen when the action addresses the report rather than the exposure, when ownership ends at implementation, or when nobody verifies whether the control survives production pressure, maintenance, staffing changes, and normal work variation.
Which method should a plant manager choose first?
The plant manager should start with the decision that cannot wait. If the immediate concern is a failed life-saving control, begin with a barrier review. If the event reveals unclear accountability or work design weakness, use RCA. If actions are already closed but confidence is low, begin with an action-effectiveness audit.

About the author

Andreza Araújo

Safety Culture Expert | Senior EHS Executive

Andreza Araújo is a safety culture expert and senior EHS executive with more than 25 years of experience in environment, health and safety. She is a Civil Engineer and Occupational Safety Engineer from Unicamp, holds a Master's degree in Environmental Diplomacy from the University of Geneva, and completed sustainability studies at IMD Switzerland. Andreza has served in Global Head of EHS roles in Fortune 500 environments, leading cultural transformation programs across multinational operations. She has represented Brazil as a speaker at the United Nations in Paris and has spoken at the International Labour Organization in Turin. She is the author of more than 16 books on safety culture in Portuguese, Spanish, English and German. Her work has earned more than 10 EHS awards, including two recognitions from Indra Nooyi, former PepsiCo CEO.

  • Civil & Safety Engineer (Unicamp)
  • M.A. Environmental Diplomacy (University of Geneva)
  • Sustainability Cert (IMD Switzerland)
  • People Management & Coaching (Ohio University)
  • UN Paris speaker representative for Brazil
  • ILO Turin speaker
  • LinkedIn Top Voice
  • Indra Nooyi PepsiCo CEO recognition (2x)

Documentaries

Watch Andreza's documentaries

Three productions on safety culture, organizational failure and the human lessons behind major disasters.

Podcasts

Listen to Andreza's podcasts

She hosts three shows on safety leadership, EHS and organizational culture, in English and Portuguese.

Summarize with AI