Workplace incident reporting process flowchart (health and safety)
Workplace incident reporting process flowchart for accidents and near misses: first aid, reporting window, statutory report, investigation, corrective actions.
What the workplace incident reporting process flowchart (health and safety) process is
Workplace incident reporting is what happens to a health and safety event once the immediate danger has been dealt with. Someone is hurt, or very nearly was. The area is made safe, and then the event has to reach the right person inside a set window, be judged against the external reporting duties that apply to your organisation, be written into a record, be investigated in proportion to how serious it was or could have been, and end in actions that somebody owns and somebody checks. The same route carries accidents, injuries, occupational ill health, dangerous occurrences and near misses in which nobody was hurt at all.
This is not the emergency response itself. The first minutes (is the area safe to approach, do we evacuate or shelter, is everyone accounted for, who gives the all-clear) are a chain of decisions with a different shape, and they are drawn separately at /templates/emergency-response-flowchart. This chart picks up where that one stops: the danger is over and the organisation now owes a report, a record and a fix. Two neighbouring templates also use the word incident for something else entirely. /templates/incident-management-process is an IT service desk restoring a broken service, and /templates/incident-response-process is a security incident. If your event involved a person, a vehicle, a substance or a machine, this is the page you want.
The chart runs across five lanes (injured person or witness, line manager, health and safety officer, HR and the regulator) and five phases from immediate response to closure. It keeps three decisions that written procedures usually leave implicit: whether the event is a serious injury or dangerous occurrence that must be reported externally, what level of investigation it earns, and whether the corrective actions actually worked. It also stops where other processes take over: the investigation method itself is at /templates/root-cause-analysis-process, and a formal corrective and preventive action record is at /templates/capa-process. Reporting duties, deadlines and retention periods differ by country and by industry, so treat this as a structure to fill in with your own rules rather than a statement of what the law requires of you.
What this flowchart covers
In this template
- Five swimlanes (injured person or witness, line manager, health and safety officer, HR and the regulator) laid out across five phases: immediate response, report, record, investigation, and actions and review.
- The response before any paperwork: first aid and summoning help in the injured person's lane, then the line manager making the area safe, so the scene is stabilised before anyone starts writing it up.
- Reporting to the line manager inside your own window, then one logging step that both sends the event to the safety officer for assessment and, on a Time off branch, hands to HR to record the absence and arrange support.
- A Serious injury or dangerous occurrence? decision acting as the external reporting gate: the Reportable branch runs a report to the regulator and the regulator's own logging step, the Not reportable branch goes straight on, and both converge on the same incident record.
- A three-way Level of investigation required? decision (Full, with evidence gathering and witness interviews; Local, a team review led by the line manager; or Log only, a minor event that goes to the register for trending) with the two investigation branches rejoining at root cause and contributing factors.
- Verification instead of closure on trust: Actions complete and effective? loops back to re-agree corrective actions, owners and dates when the answer is no, and only an Effective answer leads to the accident book and register update, the safety committee trend review, and the incident being closed with the lessons shared.
When to use this template
- You are writing or revising an incident reporting procedure and need one page showing who reports, who decides whether it is externally reportable, who investigates and who closes it.
- Near misses are barely being reported, and you want to show people the route an event takes, how short the first part of it is, and that it does not end in blame.
- A reportable injury was notified late, and the decision about external reporting needs a named owner and a named deputy for when that person is away.
- Corrective actions are agreed after incidents but nobody goes back to check whether they worked, and you want that verification inside the process rather than in someone's diary.
- You are preparing for an ISO 45001 audit or a regulatory inspection and need to show how incidents are reported, recorded, investigated and followed through.
How it works
Rename the lanes to your real roles
Replace injured person or witness, line manager, health and safety officer, HR and regulator with the roles you actually have. Small organisations often have no dedicated safety officer, in which case name the person who holds the duty rather than deleting the lane — the decisions in that lane still have to be made by someone. Keep the regulator lane even if you rarely use it, because it is what makes the external reporting duty visible on the page.
Write your internal reporting window onto the report step
Decide how quickly an event must reach the line manager and put it on the 'Report the incident to the manager' step. Before the end of the shift is a common and workable rule. Say what happens when the line manager is the subject of the report or is unavailable, and give people a route that does not depend on one person being at their desk.
Fill in your own external reporting rules
Open the 'Serious injury or dangerous occurrence?' decision and replace the generic wording with the categories and deadlines that apply where you operate. In Great Britain, RIDDOR 2013 puts the duty on the responsible person, normally the employer, and separates deaths and specified injuries, which are notified without delay and followed by a report within ten days, from injuries that keep a worker off normal duties for more than seven consecutive days, which are reported within fifteen days. In the United States, OSHA requires a work-related fatality to be reported within eight hours and an in-patient hospitalisation, amputation or loss of an eye within twenty-four hours. Confirm the rules that apply to your sites rather than copying either set.
Set the investigation thresholds
The 'Level of investigation required?' decision only works if the trigger for each branch is written down. Scale it to potential severity, not only to the actual outcome: a near miss that could have killed someone earns the full branch, and a minor first-aid case usually does not. Without written triggers the level gets decided by who happens to be free that week, which is how repeat events get logged three times and investigated none.
Fix where the accident book entry is actually made
The chart shows the accident book and register being updated near closure, which is where the reconciliation happens. The entry itself belongs at the time of the accident. Mark on your version who makes the entry, where the book lives, and how individual entries are kept confidential — accident records contain health data and are read later by people with no need to see the rest of the book.
Give verification and the committee review real dates
Attach a due date and an owner to every corrective action, and a date to the 'Actions complete and effective?' check so the loop back to re-agree actions is triggered by a calendar rather than by the next similar incident. Then set the safety committee cadence and say what it looks at: counts by type, near miss reporting rate, overdue actions and repeat causes. Trend review is the only step in this process that finds the problem nobody reported.
Frequently asked questions
What is the difference between an accident, an incident and a near miss?
Incident is the umbrella term. An accident is an incident that caused harm — an injury, ill health or damage. A near miss caused none but had the realistic potential to, and occupational ill health develops over time rather than in one event. All of them travel the same route in this chart, because an accident and a near miss frequently differ only by where somebody happened to be standing. The point at which they diverge is the 'Level of investigation required?' decision, which is where severity and potential severity are weighed.
How quickly does a workplace incident have to be reported?
There are two clocks and they are not the same. The internal one is yours to set, and before the end of the shift is a common rule. The external one is set by law and varies by jurisdiction. As examples: in Great Britain, RIDDOR 2013 requires deaths and specified injuries to be notified without delay by the quickest practicable means and followed by a report within ten days, while injuries that keep a worker off normal duties for more than seven consecutive days are reported within fifteen days of the accident. In the United States, OSHA requires a fatality to be reported within eight hours and an in-patient hospitalisation, amputation or loss of an eye within twenty-four hours. Check the duties that apply to your own sites and industry.
Do near misses have to be reported to the regulator?
Usually not. Most external reporting duties are triggered by an actual injury, a case of occupational disease, or a specific listed event. In Great Britain those listed events are the RIDDOR dangerous occurrences, which are reportable whether or not anyone was hurt — so a near miss is externally reportable only if it falls into that list. Internally you want every near miss, because they are the cheapest information about your workplace you will ever get. That is why the Not reportable branch in this chart does not stop; it goes to the incident record like everything else.
How deep should the investigation be?
Proportionate to the actual and potential severity, which is why the chart makes it a decision rather than a fixed step. The Full branch gathers evidence and interviews witnesses before any cause is named; the Local branch is a team review run by the line manager; the Log only branch sends a minor event to the register so it still counts towards trends. All routes that investigate end at root cause and contributing factors, because stopping at operator error produces a corrective action that is really just a reminder. If you want the analysis method itself — problem statement, evidence, timeline, hypothesis testing — use the root cause analysis process template.
How is this different from the emergency response or IT incident templates?
Scope. The emergency response flowchart covers the first minutes only: whether it is safe to approach, whether to evacuate or shelter, the roll call, and who gives the all-clear. This chart starts after that and covers reporting, recording, investigating and fixing. The incident management process and the incident response process use the same word for IT service disruption and for security events respectively, and neither involves first aid, an accident book or a health and safety regulator.
Does using this template make us compliant with ISO 45001 or with our reporting regulations?
No. It is a starting structure, not a compliance document, and no diagram can create compliance on its own. What it does is make the obligations visible so you can check them against your own rules. ISO 45001 clause 10.2 covers incident, nonconformity and corrective action, and expects incidents to be investigated, causes determined, action taken and the effectiveness of that action evaluated — which is the reason the verification decision and the loop back to re-agree actions are drawn rather than assumed. Replace the reporting criteria, deadlines and retention periods with the ones that actually apply to you, and have the finished process approved by whoever is accountable for health and safety.