Safety incident investigation process flowchart (scene to controls)

Safety incident investigation process flowchart: preserve the scene, classify potential severity, notify the regulator, gather evidence, interview witnesses, reach the organisational causes, verify the controls.

How it works

  1. Rename the lanes to your own site

    Replace Site supervisor, HSE adviser, Investigation lead and Site leadership with the roles that genuinely exist where you operate. Where there is no safety professional, put whoever actually holds the duty into that lane instead of deleting it: the statutory clocks in it still have to be watched by somebody. Add a contractor lane if your incidents routinely involve one, because the permit, the induction record and the equipment history you will need belong to them and not to you. If two of these lanes are the same person on a night shift, say so on the chart rather than pretending otherwise.

  2. Write your own reportability criteria onto the decision

    "Reportable to the regulator?" is inert until you attach the categories and deadlines that bind you. Replace the generic wording with your jurisdiction's list — in Great Britain that is RIDDOR 2013 and its specified injuries, over-seven-day injuries, occupational diseases and dangerous occurrences; in the United States it is the OSHA eight-hour and twenty-four-hour rules. Name the person who makes the call and a deputy for holidays and night shifts, and record the time the notification was made, because the first question after a late report is who knew and when.

  3. Define potential severity and what each level triggers

    "Potential severity high?" only scales anything if the words behind it are written down. Most sites use a small matrix of realistic worst outcome against how likely that outcome was, and set the threshold where a plausible fatality or life-changing injury falls. Then state what each level actually buys: who leads, how many people, how long they get, and who receives the report. Without that the level is set by whoever is free that week, and the Lower, line-led branch quietly becomes the default. Say on that branch who holds the investigation lead's role, so the lane still has an owner.

  4. List the evidence and its shelf life

    Turn "Secure physical and paper evidence" into a named checklist rather than a heading. CCTV and machine logs overwrite on a fixed cycle, so write the cycle down and name who can freeze them at three in the morning, because that is when the request will come. Then list the paper you will want and rarely have: the permit, the risk assessment for that task, the shift roster, the maintenance history, training and competence records, and the last three versions of the procedure people were actually working to. Say who holds each one.

  5. Turn the hierarchy of controls into a written test

    Make "Can the hazard be eliminated?" a question the team has to answer on the record, and require a written reason with a name against it before the answer is allowed to drop a level. Test each proposed action the same way: would it still work on a night shift, with a new starter, under time pressure, with the usual person off sick? Ask what it costs the operator in time, because a control that makes the job slower is a control somebody will defeat. And put a review date against the level you refused, so it can be reopened when the money exists.

  6. Fix the verification date, then walk it through and publish

    Set the date for "Verify the controls in the workplace" at the moment the action is assigned, not when the action is closed, and put it in the same diary as the audit programme so it survives a change of safety adviser. Decide what evidence the verifier has to bring back with them. Then walk the finished chart through with a supervisor, the HSE adviser, somebody who has been interviewed as a witness and whoever signs the reports, correct it to what they really do, and publish that revision while keeping the earlier ones so anyone opening it later knows which version they are reading.

Frequently asked questions

What are the steps in a safety incident investigation process?

Care for the injured person, make the scene safe and preserve it, classify the actual and the potential severity, decide whether the event is reportable and notify the regulator within the statutory deadline, scale the investigation team to the potential severity, gather physical and documentary evidence before it decays, interview witnesses separately and early, build a timeline of what actually happened, analyse the causes with a systemic method until they reach organisational factors, choose controls by working down the hierarchy from elimination, get them approved and funded, assign actions with owners and dates, verify in the workplace that the controls are working, then approve the report, close it and share the lessons. Methods label these differently — ICAM separates absent or failed defences, individual and team actions, task and environmental conditions and organisational factors — but the spine is the same. The step organisations skip is verification.

How is this different from the workplace incident reporting process?

They are consecutive, not alternative. The workplace incident reporting process covers what happens to an event as an event: first aid, telling the line manager inside your internal window, the accident book entry, the statutory report, and a decision about what level of investigation it earns. It ends by handing the serious ones on. This page picks up at exactly that point, and it is far deeper in the middle: scene preservation as a step of its own, evidence ordered by how fast it perishes, witnesses interviewed separately, a timeline, a cause analysis that has to reach organisational factors before it may proceed, and controls selected against the hierarchy. If you are documenting how an incident gets reported and recorded, use the reporting template. If you are documenting how it gets investigated, use this one. Most organisations need both, and the join between them is the level-of-investigation decision.

How do you stop an investigation ending at operator error?

Treat operator error as the start of the analysis rather than the end of it. The quickest check is the substitution test: would a competent colleague, in the same conditions, with the same information and under the same pressure, probably have done the same thing? If the honest answer is yes, the person is not the cause. It also helps to name the kind of error — a slip or a lapse in a routine action, a mistake in judgement, or a deliberate departure from the procedure — because each has a different set of conditions behind it, and a departure that everybody on the shift makes is evidence about the procedure rather than about the individual. Then ask what would have to change for the same action to stop being the easiest one to take. This chart enforces the discipline structurally: the decision "Causes reach organisational factors?" has a backward branch labelled Stops at the person that sends the analysis round again instead of letting the report be written.

What is the hierarchy of controls and how does it change the actions?

It is the order in which control measures are considered: eliminate the hazard, substitute something less hazardous, engineer a control such as a guard, an interlock or an extraction system, then administrative controls like procedures, permits and training, and personal protective equipment last. The order is not a preference. Elimination and substitution remove the exposure whatever anybody does next, while administrative controls and PPE work only while people behave exactly as intended, every shift, including the bad ones. It changes the actions because it forces a stated reason for each level you skip. A corrective action list made entirely of retraining, briefings and new signage is a list of the two weakest controls available, and it is the single most reliable predictor that the same incident will happen again.

How do you verify that a safety control is actually working?

Not by looking at whether the action was closed. Verification means going back to the workplace after the control has been in place long enough for ordinary work to have tested it, and answering three separate questions: does the control exist as it was described, does it do what it was meant to do, and are people using it rather than working around it? The third catches most of the failures, because a control that costs the operator time gets defeated quietly and nobody reports it. Look as well for the hazard the control introduced — a guard that pushes maintenance into a worse position, an interlock that invites a bypass, a permit that adds an hour to a job people already start late. Give the check to somebody other than the person who owned the action, and let an observation or a measurement carry more weight than a completed field in a tracker. ISO 45001 clause 10.2 expects the effectiveness of corrective action to be evaluated, which is why this chart loops "Controls effective?" back to control selection instead of straight to closure.

Use this template

More in Operations and maintenance process templates

More in Process map templates

Browse all Operations and maintenance process templates