← All postsHow-to

Incident report: writing one that is still useful in six months

Most incident reports are written to close the file. The useful ones separate what happened from who is to blame — and organisations that cannot make that separation stop hearing about incidents at all.

How-toI

An incident report is the record of something that went wrong: an injury, a near miss, a spill, a security breach, an outage. Its purpose is to establish what actually happened while people still remember, so the same thing is less likely to happen again. Almost every organisation writes them and a striking number gain nothing from it, because the reports are written to satisfy a process rather than to be read.

The distinction that decides whether the system works is between a report and a judgement. A report states facts, times and sequence. A judgement assigns cause and responsibility, and belongs in a later stage, done by someone with time to look. Merging them produces documents that are defensive, vague, and useless as evidence.

What an incident report needs

  • When and where, precisely. Time to the minute where it matters, and the specific location rather than the building.
  • Who was involved and who witnessed it, with their own account recorded separately rather than summarised into one narrative.
  • What happened, in sequence, in plain language. The step-by-step matters more than the description.
  • What was done immediately — first aid, shutdown, containment, who was told.
  • The outcome: injury and its severity, damage, downtime, data affected.
  • Whether it was a near miss. These are the cheapest information a business ever gets and the first thing to stop being reported when the culture goes wrong.
  • Photographs and the physical evidence, where relevant, before the scene is tidied.

Getting it filed at all

  1. Make reporting take under five minutes. Every additional field costs you reports, and the marginal field is almost never worth the marginal report.
  2. Let anyone report, including contractors and visitors, without needing a login or a manager's permission.
  3. Acknowledge every report within a day, even if only to say it has been read. Silence is what teaches people not to bother.
  4. Separate reporting from investigation explicitly, in the form itself. The person filing states what they saw; cause is decided later.
  5. Feed back what changed. A quarterly note saying these six things were reported and here is what was done does more for reporting rates than any campaign.

A falling number of incident reports is ambiguous and usually misread as good news. It means either that fewer things are going wrong or that fewer people are telling you — and the second is far more common after an investigation that felt like a search for someone to blame. Watch near-miss reports specifically: they are voluntary, so they fall first and fastest when trust goes.

What happens next

A report that closes on filing has wasted the reporting. The sequence that works is: report the facts, triage by severity and recurrence, investigate the ones that warrant it, decide corrective actions with owners and dates, and check later whether the action worked. The middle of that chain is covered in root cause analysis and the end in corrective action; the underlying question of what could have caused it in the first place belongs to risk assessment.

Where it lives

Ettex Forms is the reporting end — a short form anyone can reach, on a phone, without an account — and the submissions land as records in Ettex Records where they can be filtered by type, area and severity, and where the investigation and its actions attach to the original report rather than living in a separate document.

Stating the limits plainly: there is no anonymous reporting channel with the guarantees a whistleblowing scheme requires, no regulatory notification — several jurisdictions require certain injuries and data breaches to be reported to an authority within a fixed period, and that remains your obligation and your deadline — and no incident-management platform features such as on-call escalation. What we hold is the record and the trail from it to the change.

Frequently asked

What should an incident report include?

Time, place, people involved and witnesses, the sequence of events in plain language, immediate actions taken, and the outcome. Cause and responsibility belong to the investigation, not the report.

Should near misses be reported?

Yes — they are the cheapest safety information available, arriving without the injury. They are also the first reports to disappear when people stop trusting what happens next.

How quickly should an incident be reported?

Same day, while memory is accurate and evidence intact. Some categories carry legal deadlines for notifying an authority, which depend on your jurisdiction and are worth knowing before you need them.

Why do incident reports dry up?

Almost always because an earlier report led to blame rather than change, or to no visible response at all. Acknowledging every report and publishing what changed does more than any reminder.

AS
Written by Alex S.

Part of the Ettex team — writing about product, engineering and the future of work.

More posts
Get the best of the Ettex blogProduct news, guides and tips — straight to your inbox, no spam.