Every incident and near miss is a free lesson in how the system really fails. An investigation turns that lesson into a change, provided it looks for system causes and not someone to blame, and provided people feel safe enough to report in the first place.
This guide covers what to report, how to build a near-miss reporting system, how to triage by potential severity, a nine-step investigation process, interviewing, root-cause methods and their stopping-point traps, how to choose strong corrective actions, and how to measure the system. A worked forklift near miss shows a timeline, a chain of whys, and the actions by strength.
Reporting rules differ by country. The US OSHA deadlines are given as an example. Check the requirements that apply to you.
Before You Start
Why Investigate Incidents and Near Misses
An incident or a near miss is the cheapest lesson a workplace will ever get. It shows how the system actually fails, with the details, before the next event does more harm. The aim of an investigation is to find what in the system allowed the event, and to change it. The aim is not to find someone to blame.
Learn From Events That Did Not Hurt
A near miss has the same causes as an injury, without the injury. Most of the learning is available if people report.
Find System Causes
Behind a single mistake there are usually conditions that made it likely: layout, tools, time pressure, unclear procedures.
Fix It for Everyone
A good investigation produces changes that protect all workers, not a warning to one person.
Meet the Rules
Some events must be reported to the authorities within set times, and good records show the organization responded properly.
Terms and What to Report
| Term | Meaning | Example |
|---|---|---|
| Incident | An event that caused, or could have caused, harm | Any of the below |
| Injury or illness | An event with harm to a person | A cut that needs stitches |
| Near miss | An unplanned event that did not cause harm but could have | A forklift stops 1 m from a pedestrian |
| Hazard report or unsafe condition | A condition that could cause harm, spotted before an event | A missing guard; a leaking hose |
| Property damage or process event | Damage or loss with no one hurt | A pallet rack hit by a truck |
Ask people to report all of them. Judge the response by the potential severity: the worst credible outcome, not the actual one. A near miss with the potential for a fatality deserves a thorough investigation, and a minor first-aid case may need only a quick check.
In the US, employers must report a work-related fatality to OSHA within 8 hours, and an in-patient hospitalization, amputation, or loss of an eye within 24 hours (29 CFR 1904.39). Other countries have their own rules and time limits. Check the requirements that apply to you.
Building a Near-Miss Reporting System
- Make it easy. A report should take less than two minutes: a QR code to a short form, a card in the area, or a word to the supervisor. Anyone should be able to report, including contractors.
- Make it safe. Say in writing that reporting a near miss or hazard will not lead to discipline for the reporter, and act on that promise every time. One punished report can end the flow of reports.
- Respond fast. Acknowledge each report within a day, and tell the reporter what happened. People stop reporting when nothing seems to happen.
- Triage by potential. Score each report by the worst credible severity and the likelihood of a repeat, with the risk matrix in the risk assessment guide. Investigate the high-potential ones fully, and handle the others by quick fix and trend.
- Look at the pattern. Group reports by type and area. A Pareto chart of reports shows where your system is leaking.
- Celebrate the reports, not the quiet. A rising number of near-miss reports usually means that trust is growing. A falling number may mean that people stopped reporting.
The Investigation Process
- Respond and make safe. Care for anyone hurt, secure the area, stop the hazard, and preserve the scene.
- Notify and report. Tell the supervisor and the safety coordinator, and make any report that the rules require within the time limit.
- Form a small team. A supervisor, a worker representative, the safety coordinator, and someone who knows the process. Include people who were not involved in the event.
- Gather evidence quickly. Photos and measurements of the scene, equipment state, records, procedures, and training and maintenance history. Evidence fades fast.
- Interview. Talk to the people involved and the witnesses, separately, soon after the event, in a private and supportive way. Ask open questions.
- Build the timeline. What happened, in order, with times, and what was normal that day. Mark where a defense could have stopped it.
- Find the causes. Move from what happened to why: immediate causes, contributing conditions, and the system causes behind them.
- Decide actions. Prefer actions from the top of the hierarchy of controls. Give each an owner and a date.
- Share and verify. Tell the people affected, share the learning with other areas, and check later that the actions were done and worked.
Interviewing Well
| Do | Do not |
|---|---|
| Interview soon, one person at a time, in a private place | Interview people as a group, or in front of their boss |
| Say clearly that the aim is to understand, not to blame | Hint at discipline |
| Ask open questions: “Tell me what happened,” “What did you expect?” | Ask leading questions: “Weren’t you in a hurry?” |
| Ask what was normal: “How is this job usually done?” | Ask only about what went wrong |
| Ask what would have helped | Ask “Why didn’t you follow the procedure?” as the first question |
| Thank them, and give feedback on what was done | Collect statements and never respond |
Finding the Causes
Every event has more than one cause. An immediate cause, such as a slip, is what happened. The conditions that made it likely, such as a wet floor, poor drainage, and a rushed schedule, are the contributing causes, and the system factors behind them, such as no inspection routine or no owner for the area, are the root causes you need to fix.
| Method | How it works | Best for |
|---|---|---|
| 5 Whys | Ask why repeatedly until you reach a cause you can change at system level | Simple events with a single chain. See the 5 Whys guide |
| Fishbone diagram | Group causes by category: people, methods, equipment, materials, environment, management | Events with several contributing factors. See the Fishbone guide |
| Barrier analysis | List the defenses that should have stopped the event, and ask why each did or did not | Events where a control failed |
| Change analysis | Compare the event with a normal case and list what was different | Events where “something was different” |
| Timeline and causal tree | Map events and conditions, and the logic between them | Complex, multi-party events |
| Fault tree | Work backward logically with AND/OR gates | Serious or complex process events |
Corrective Actions That Work
Actions fall on the same hierarchy as controls for any hazard, and their strength falls in the same order.
| Strength | Examples | Why |
|---|---|---|
| Strong | Eliminate the hazard; redesign the layout; physical barriers; interlocks; automatic stop | Work without relying on anyone remembering |
| Intermediate | Checklists, standardized procedures, better tools, visual cues, supervision, software prompts | Reduce reliance on memory but can drift |
| Weak | Training, warning signs, memos, “be more careful,” discipline | Depend on people to do the right thing every time |
- Use at least one strong action for any event with serious potential. If only weak actions are listed, ask whether a stronger one is possible.
- Look sideways. Where else is the same hazard? Fix the type of problem, not just the single machine.
- Check the fix. Verify that the action was done, and look later for evidence that it worked, such as fewer near misses of that type.
- Link to CAPA. Treat important actions as corrective and preventive actions with owners and effectiveness checks. See the CAPA guide.
Worked Example: A Forklift Near Miss at Riverside Plant
At Riverside Plant, an illustrative 140-employee metal fabrication and assembly plant, a forklift driver braked hard to avoid a pedestrian coming through the shipping door. Nobody was hurt, but the driver reported it to the supervisor within ten minutes. The potential severity was a fatality (severity 5) and the likelihood of a repeat was possible (3), a risk score of 15, which is High. The team investigated the next day. The facts below are illustrative.
What the team did not conclude. They did not write “driver speeding” or “pedestrian inattentive.” Both were true in a narrow sense, but neither explained why two people who were each doing their jobs could not see one another. They asked what the layout and the schedule had set up.
| # | Action | Level | Owner and date | Strength |
|---|---|---|---|---|
| 1 | Clear the pallets from the door; paint a no-staging zone with a stop line | Elimination | Shipping supervisor, same day | Strong |
| 2 | Fit a convex mirror and a motion-activated beacon at the door | Engineering | Maintenance, 2 weeks | Strong |
| 3 | Separate the pedestrian door from the forklift lane with a barrier and a marked crossing | Engineering | Facilities, 6 weeks | Strong |
| 4 | Review the shipping layout through management of change; set a pallet limit for staging | Administrative (system) | Operations manager, 30 days | Intermediate |
| 5 | Add the walkway plan to the monthly safety walk checklist | Administrative (verify) | Safety coordinator, 30 days | Intermediate |
| 6 | Share the event at shift huddles and thank the driver for the report | Communication | Supervisors, 1 week | Weak, but needed |
Result. With the actions in place the team re-scored the risk as severity 5 and likelihood 1 (rare), a score of 5, which is Medium. Three of the six actions are strong (elimination or engineering), and two address the system. The plant also checked the other three doors and found one with a similar blind corner.
Record your own events in the Incident Investigation Report workbook, which keeps the report, timeline, cause analysis, actions by strength, and a log of all events, or use the 5 Why Root Cause Tool for the cause chain.
Reading the Program: A Year of Near Misses
Across the year the plant received 47 near-miss reports, the same count used in the KPI guide. 41 of the 47 (87%) were triaged and investigated or closed within seven days, and 11 were judged to have the potential for a serious injury.
- Slips, trips, and falls, forklift and vehicle, and contact with machinery together account for 29 of the 47 reports (62%). These are the first targets for engineering controls.
- 11 serious-potential events got a full investigation. That is more learning about serious risk than the plant’s one lost-time injury could have given.
- A low count of reports is not good news. At 47 reports for 140 employees, the plant gets about one report for every three employees a year. The committee set a goal of reports from every area every month.
Measuring the System
| Measure | How | What it tells you |
|---|---|---|
| Reports per 100 employees per month | Near-miss and hazard reports ÷ employees × 100 | Whether people trust and use the system |
| Time to acknowledge and to investigate | Days from report to first response and to closure | Whether the system is responsive |
| Share of high-potential events fully investigated | High-potential events with a full investigation ÷ all high-potential events | Whether effort goes where the risk is |
| Share of investigations with at least one strong action | Investigations with a strong action ÷ investigations | Whether we fix the system or the person |
| On-time action closure | Actions closed by the due date ÷ actions due | Whether the learning turns into change |
| Repeat events | Events of a type already investigated | Whether the fixes worked |
Common Mistakes
Blame as a Conclusion
“Operator error” closes the case, and nothing changes.
Punishing Reporters
One disciplined report and the flow stops.
Investigating Only Injuries
Near misses with serious potential go unexamined.
Weak Actions Only
Retraining and warning signs, with no change to the system.
Slow Response
Evidence is lost and people stop reporting.
No Follow-Up
Actions are not verified, so the same event happens again.
Self-Assessment Questions
- Can anyone report a near miss in two minutes, and without fear?
- Do we triage by potential severity and investigate the serious-potential events fully?
- Do our investigations go past “operator error” to system causes?
- Does every serious-potential investigation include at least one strong action?
- Do we verify actions and look for repeats?
Incident Investigation and Near-Miss Reporting: Frequently Asked Questions
What is the difference between an incident and a near miss?
An incident is any event that caused or could have caused harm. A near miss is an unplanned event that did not cause injury, illness, or damage but could have. Near misses share causes with injuries, so investigating them gives the lessons without the harm.
What should be investigated?
Every injury and illness, and every near miss or hazard with the potential for a serious outcome. Judge the depth of the investigation by the worst credible outcome, not by what actually happened. A near miss that could have killed someone deserves more than a minor injury.
Is the injury pyramid (1:29:300) a reliable ratio?
No. The ratio comes from H. W. Heinrich in the 1930s and later research does not support fixed ratios between near misses, minor injuries, and serious injuries. Near misses and serious events often share causes, but they do not follow a fixed ratio, so judge each event by its potential severity.
What is a root cause?
A cause at the system level, such as a layout change that was not risk-assessed or an unclear ownership, which, if fixed, would prevent the event and similar ones. Findings like “operator error” or “lack of attention” are a starting point, not a root cause: ask why the action made sense at the time.
What makes a corrective action strong?
A strong action does not depend on people remembering or being careful: eliminating the hazard, redesigning the layout, adding physical barriers, or interlocks. Intermediate actions include checklists, better tools, and standard procedures. Weak actions are training, warning signs, memos, and discipline. For serious events, include at least one strong action.
Sources and Further Reading
- US Occupational Safety and Health Administration, Incident [Accident] Investigations: A Guide for Employers (2015), and 29 CFR 1904.39 on reporting fatalities and severe injuries.
- ISO 45001:2018, clause 10.2 on incident, nonconformity and corrective action (check current edition).
- UK Health and Safety Executive, Investigating accidents and incidents (HSG245).
- Reason, J., Human Error (Cambridge University Press, 1990) and Managing the Risks of Organizational Accidents (Ashgate, 1997).
- Dekker, S., The Field Guide to Understanding ‘Human Error’ (3rd ed., CRC Press, 2014).
- Heinrich, H. W., Industrial Accident Prevention (1931), for the original pyramid, and later critiques of its ratios.
- US Department of Veterans Affairs National Center for Patient Safety, and the Joint Commission, on the action hierarchy (stronger, intermediate, weaker actions).