ISO 45001 Incident Investigation: Root Cause Analysis That Prevents Recurrence
An incident happens. You investigate. You find that a worker wasn’t wearing required PPE. Conclusion: worker non-compliance. You discipline the worker and move on.
Two months later, the same type of incident occurs, different worker, same PPE issue. You’re puzzled — you already addressed this.
You never addressed it. You punished a symptom and ignored the cause.
Real incident investigation under ISO 45001 Clause 10.2 asks a harder question: Why wasn’t PPE being worn? Was it uncomfortable? Was it unavailable? Did the worker not understand the requirement? Did supervision not notice? Did the culture not support it? Did the hazard feel abstract to the worker — low probability, so why bother?
Until you understand why, you can’t prevent recurrence. You can only hope it doesn’t happen again.
This article walks you through incident investigation as a systematic discipline: how to investigate, what to look for, tools for root cause analysis, and how to use incident findings to drive system-wide improvement.
Types of Events: Incidents, Near-Misses, and Dangerous Occurrences
ISO 45001 requires investigation of “incidents” but doesn’t define exactly what that means. The broader concept includes several event types, all worth investigating for different reasons.
Incidents (Injuries or Illnesses)
Someone was actually harmed. Lost time injury, medical treatment injury, first aid treatment — these are incidents. Investigation is mandatory and urgent. Someone was hurt; the system failed to protect them.
Near-Misses (Close Calls)
Someone could have been harmed but wasn’t, usually by chance. A worker trips but doesn’t fall. A tool slips but doesn’t hit anyone. A hazardous condition exists but the person in that area is wearing PPE that would have protected them anyway.
Near-misses are gold. They reveal that your system isn’t protecting people — it’s just lucky. The barrier between this near-miss and an actual incident is thin. Investigating near-misses finds gaps in your defences before someone is harmed.
Yet many organisations don’t investigate near-misses systematically. If you only investigate after someone is injured, you’re missing 95% of the warning signals.
Dangerous Occurrences
An event that could have led to harm even if it didn’t. A scaffold collapsed but nobody was working under it. A chemical container leaked but was handled properly. A machine failure occurred but the area was cleared.
These should be investigated. They represent control failures that, under slightly different circumstances, would have resulted in injury.
Regulatory Reportable Events
Depending on your jurisdiction, certain events must be reported to regulators (fatalities, serious injuries, dangerous occurrences) within a specified timeframe. Investigation needs to happen quickly to gather facts before memories fade and details are lost.
Your procedure should clarify: Which events must be reported? What’s the timeline? Who decides? This prevents either over-reporting (every incident is reported) or under-reporting (serious incidents are hidden).
The Investigation Process: From Event to Learning
A structured investigation follows a sequence.
Phase 1: Immediate Response (First Hours)
Stop the hazard. If someone is injured, provide first aid. If the hazard is still active, make it safe immediately. Document what happened while it’s fresh (record the state of equipment, any visible issues, the environment). Notify relevant parties (supervisor, health and safety officer, first aiders). Isolate the scene if appropriate to preserve evidence.
If regulatory reporting is required, initiate that process. Report to the regulator within the legal timeframe (often 24-48 hours for serious incidents).
Phase 2: Scene Preservation and Initial Documentation
If it’s appropriate and safe, preserve the scene for investigation. Take photos. Document equipment position, material states, work in progress. This is critical for reconstructing what happened.
Gather the people involved or who witnessed the event. Get initial statements while memories are fresh. Don’t interrogate; just ask: What were you doing? What did you observe? What was different about this situation?
Phase 3: Formal Investigation Preparation
Assign an investigation team. Include someone with authority (ensures findings get acted on), someone with technical knowledge of the area (understands the process), and someone external to the area (brings fresh perspective). Critically, include someone independent from the person being investigated (prevents bias or retaliation perception).
Schedule the investigation. For serious incidents, start within 24-48 hours while details are still accessible. For minor incidents, within a week is reasonable.
Phase 4: Evidence Gathering
Interview the person involved, witnesses, supervisors, managers. Ask open-ended questions: “Walk me through what happened step by step.” Listen for contradictions (different witnesses remember events differently — these contradictions are clues). Don’t interrupt or lead answers. Get people’s own words, not your interpretation.
Examine the equipment, tools, work site. Does it match the accident report? Are there obvious defects? Are there hazards the person might have encountered?
Review procedures, training records, inspection logs. Was the person trained? Was the procedure current? Had this area been inspected recently? Were hazards known?
Phase 5: Root Cause Analysis
Use a structured tool (5 Whys, fishbone, barrier analysis) to push beyond the obvious. What actually caused the incident? Not the worker’s action, but what made that action possible or likely?
Map out the sequence: What conditions had to be true for this incident to occur? Which of those conditions could have been controlled? Which were controlled but the control failed?
Phase 6: Contributing Factors Identification
Most incidents are multicausal. Identify all contributing factors: human factors (training, fatigue, complacency), environmental factors (noise, lighting, congestion), system factors (procedure inadequacy, lack of supervision), and equipment factors (design flaw, poor maintenance).
Don’t stop at one cause. The more factors you identify, the more leverage points for prevention.
Phase 7: Corrective and Preventive Action
Design actions that address each root cause. If the incident revealed that a hazard wasn’t controlled, implement control. If training was inadequate, revise training. If a procedure was unclear, redesign it. If equipment was defective, repair or replace it.
Consider preventive actions: Could the same incident type occur elsewhere? If yes, assess and control those risks proactively.
Phase 8: Findings Communication and Learning
Share what you learned. In toolbox talks, email updates, or team meetings, communicate the incident, the root cause, and the actions taken. This prevents the same incident in other areas and builds safety awareness.
Don’t hide incidents. The more visible they are, the more seriously people take prevention.
Phase 9: Verification of Effectiveness
After corrective actions are implemented, verify they worked. Is the control in place? Are people following the new procedure? Has the hazard been eliminated or controlled?
Don’t assume implementation equals effectiveness. Check.
Root Cause Analysis Tools for Incident Investigation
Structured tools force rigorous thinking and prevent jumping to conclusions. Here are three that work well for incidents:
The 5 Whys
Ask “why” at least five times, each time peeling back a layer of causation.
Example:
Q1: Why was the worker injured? A: They slipped on the floor.
Q2: Why was the floor slippery? A: It had been wet from washing and hadn’t dried.
Q3: Why was the floor wet and not dried? A: The area was still in use; they couldn’t close it for drying time.
Q4: Why couldn’t they close the area? A: It’s a high-traffic zone; operations require it to be open.
Q5: Why didn’t they use slip-resistant matting? A: Nobody thought of it; it wasn’t in the procedure.
Now you’ve moved from “worker was careless” to “system doesn’t have controls for this high-traffic, wet-floor situation.” That’s a root cause you can address.
Barrier Analysis
Barriers are controls designed to prevent incidents. Barrier analysis asks: What barriers should have protected the person? Which barriers failed? Why?
Example: A worker is burned by hot liquid.
Barrier 1 (Engineering): Equipment should have insulation. (Failed — insulation was missing.)
Barrier 2 (Administrative): Workers should be trained to use PPE. (Barrier exists but worker didn’t wear it.)
Barrier 3 (PPE): Protective gloves should protect from heat. (Barrier exists but not used.)
Barrier 4 (Supervision): Supervisor should notice missing insulation. (Barrier failed — no inspection done recently.)
Multiple barriers failed. Corrective action addresses all of them: repair the insulation, review supervision inspections, investigate why the worker didn’t wear PPE.
Fault Tree Analysis
Work backward from the incident. What combinations of failures had to occur?
Example: Person cut their hand on sharp metal edge.
This required: Contact with sharp edge AND insufficient protection.
Contact required: Person working in that area AND sharp edge at hand level.
Insufficient protection required: No gloves worn OR gloves inadequate OR no guarding on edge.
Map it visually. You see that you could have prevented the incident by any of these: removing the sharp edge (guarding), ensuring PPE is always worn and adequate, or preventing people working near that edge. Which is most feasible? That’s your corrective action.
Near-Miss Investigation: The Overlooked Goldmine
Near-miss investigation is not required by ISO 45001, but it should be. Near-misses reveal your defences are inadequate — not that they failed catastrophically, but that they’re fragile.
Example: A worker’s hand slides toward a moving blade but they pull back at the last moment. Investigation shows the guard is ineffective — the hand can easily reach the blade. This isn’t an incident, but it proves your control is broken. Fix it now, before someone doesn’t pull back in time.
Near-miss investigation should follow the same discipline as incident investigation — not quite as urgent (nobody was harmed), but equally thorough. The question is the same: Why did this happen, and how do we prevent it system-wide?
Many organisations don’t investigate near-misses because workers don’t report them. Workers don’t report because they fear retaliation (if I report that I almost got hurt, will I be blamed?) or because they don’t think anything will happen (I’ll report it and nothing will change).
Building a near-miss reporting culture requires:
- Psychological safety: Workers trust they won’t be blamed for reporting near-misses.
- Visible response: When someone reports a near-miss, something happens. The hazard is investigated. Controls are improved. Workers see that reporting leads to action.
- Regular communication: Celebrate near-miss reports. “This quarter we had 47 near-miss reports, and we’ve made 6 improvements as a result.” This signals that near-miss reporting is valued.
Documenting Incident Investigation
Investigation findings must be documented. Your record should include:
- What happened: Clear description of the incident — when, where, who, what occurred.
- Who was involved: Names of the person injured, witnesses, supervisors.
- Injuries/damage: Nature and severity of harm (first aid, medical treatment, lost time, damage to equipment).
- Environment and context: Time of day, weather, staffing levels, production pressure, any unusual conditions.
- Root cause analysis: What caused the incident? What barriers failed? Why?
- Contributing factors: All factors that contributed (not just the primary cause).
- Corrective and preventive actions: What will be done to prevent recurrence? Who owns each action? When will it be completed?
- Verification: How will effectiveness be verified?
- Communication: How will findings be shared with the organisation?
Documentation is important for three reasons:
First, it forces rigorous thinking. Writing down your findings makes you articulate exactly what happened and why. This often reveals gaps in your analysis.
Second, it creates accountability. With documented actions, owners, and dates, something actually happens. Without documentation, the investigation conclusion stays in someone’s head and fades.
Third, it provides evidence for auditors. Certification auditors will review a sample of incident investigations. They’re looking for evidence of rigorous analysis, not superficial explanation.
Sharing Learnings From Incidents
An investigation is wasted if the learning stops with correction of the immediate incident. Use incidents to educate and improve the broader organisation.
Safety alerts: For significant incidents, send an alert to all relevant areas: “On [date], an incident occurred involving [hazard]. Investigation found [root cause]. We’ve made these changes [actions]. Watch out for this hazard in your area.”
Toolbox talks: Use incidents as case studies. “This week we’re discussing an incident that happened in another area. Here’s what caused it. Here’s how we’ve prevented it. Are there similar hazards in your work area?”
Training updates: If incident investigation reveals a competence gap, revise training. Everyone should learn from every serious incident.
Procedure revisions: If a procedure was unclear and contributed to an incident, revise it. Communicate the change: “We’ve updated this procedure based on an incident we experienced. Here’s what’s different and why.”
Common Incident Investigation Failures
Failure 1: Stopping at the Worker
You investigate and conclude the worker made an error or was negligent. Investigation ends. You miss the systemic failures that made the worker’s error possible.
Fix: Always ask: Why did the worker do what they did? Train inadequate? Procedure unclear? Supervision absent? Equipment defective? Focus on the system, not the person.
Failure 2: Investigation Takes Too Long
You investigate two weeks after the incident. Memories have faded. Scene has been changed. Details are lost.
Fix: Investigate quickly. For serious incidents, start within 24-48 hours. Get people’s memories while they’re fresh. Gather evidence before conditions change.
Failure 3: Shallow RCA
You ask “why?” once and call it root cause. You miss the deeper systemic failures.
Fix: Use structured tools. Ask “why?” at least five times. Map barriers and see which failed. Work backward from the failure and identify all contributing factors, not just the obvious one.
Failure 4: No Verification of Corrections
You implement a corrective action and assume it worked. You never check whether it’s actually effective or whether the problem actually recurs.
Fix: Schedule verification. After the action is implemented, check: Is the control in place? Are people using it? Does the underlying problem still exist?
Failure 5: No Learning Sharing
You investigate, you document findings, but the organisation never hears about it. Other areas are at risk of the same incident.
Fix: Communicate findings. Send alerts. Use incidents in toolbox talks and training. Make the learning visible and actionable.
What Auditors Look For in Incident Investigation
Certification auditors will review your incident investigations. They’re assessing:
Responsiveness: How quickly did you investigate? For serious incidents, did you start within 24-48 hours? Or did you wait weeks?
Thoroughness: Is the RCA credible? Does it dig beyond the obvious? Can the auditor see evidence that you considered multiple causes?
Systemic thinking: Did you ask whether similar hazards exist elsewhere and investigate those areas? Or did you treat this incident as an isolated event?
Verification: Do you have evidence that corrective actions were implemented and are effective? Or do you just assume they worked?
Learning: Can you show that organisation-wide learning occurred? Were other areas notified? Did procedures get updated? Did training change?
Organisations that can walk an auditor through a well-investigated incident (from discovery through RCA through corrective action through verification through learning) demonstrate a mature investigation process. Those with superficial investigations will struggle in audit.
Practical Checklist: Strong Incident Investigation
- Have a clear procedure for reporting incidents (accessible, protected, no retaliation)
- Classify incidents appropriately (injury, near-miss, dangerous occurrence)
- For all significant incidents, investigate within 24-48 hours while details are fresh
- Assemble an investigation team with authority, technical knowledge, and independence
- Use a structured RCA tool (5 Whys, barrier analysis, or fault tree) — don’t rely on intuition
- Document findings comprehensively: what happened, root cause, contributing factors, actions, owners, dates
- For each action, define how you’ll verify effectiveness
- Assess whether similar hazards exist elsewhere; investigate those areas proactively
- Communicate findings to the organisation through alerts, toolbox talks, or training updates
- Follow up after corrective actions to verify they’re working
- Build a culture where near-misses are reported and investigated as readily as incidents
- Use incident data to identify patterns and drive continuous improvement
Want to strengthen your incident investigation process? Our consultants can train your investigation teams, review your current practices, and help you build a discipline that turns incidents into systematic learning. Let’s improve your investigation capability.
FAQ: Incident Investigation in Practice
Recent Comments