The problem
After an incident, there is strong pressure to explain what happened quickly. Managers want answers, people involved want reassurance, and investigators often have an early theory. Within hours, a cause may be named, sometimes before the people involved have been interviewed or the scene has been properly examined.
Once a cause has been named, the investigation tends to look for evidence that supports it. Facts that do not fit are given less weight. Questions that would have tested the theory are never asked.
Why it matters
The value of an investigation lies in its conclusions and the actions that follow. If the conclusions rest on an early assumption rather than evidence, the actions may address the wrong problem. The real causes remain, and a similar incident can happen again.
A weak sequence also damages trust. People involved in an incident notice when conclusions are reached before they have been heard. Reports that cannot show how a cause was established are hard to defend to regulators, clients or the workforce.
A practical approach
A more reliable investigation follows a deliberate order: collect facts first, examine hypotheses next and confirm causes last.
Establish the facts. Record what is known: what happened, where, when, who was involved, what the conditions were. Keep facts separate from interpretation.
Build a timeline. Arrange events in order. A timeline often reveals gaps and contradictions that are not obvious from individual statements.
Record findings and open questions. Note what has been established, what still needs to be found out and who is responsible for finding it. Information gaps should be visible, not quietly filled with assumptions.
State hypotheses explicitly. Possible explanations should be written down as hypotheses, each with a status: open, needs evidence, supported or rejected. A supported hypothesis is still not a confirmed cause.
Confirm causes only with support. A cause should be confirmed only when it can be traced to findings, supported hypotheses or barrier analysis. Distinguishing immediate, contributing, underlying and root causes helps avoid stopping at the first explanation.
Analyse barriers. Ask which barriers should have prevented the event, limited its consequences or supported recovery, and whether each was effective, partially effective or ineffective.
Allow honest outcomes. Sometimes the evidence is not enough. "Inconclusive" or "insufficient evidence" is a more honest conclusion than a cause that cannot be supported.
Plan actions from the analysis. Actions should address confirmed causes and failed barriers, with owners and dates. Whether those actions actually work is a separate question, explored in A Verified Action Is Not Necessarily an Effective Action.
Issue a report that does not change. Once issued, the report should remain as it was. New information leads to a new version, not silent edits.
What a good system should provide
A good investigation tool should support this sequence rather than a single free-text form. It should:
Provide stages that move from fact-finding to analysis, action planning and finalisation.
Record timeline events, findings, questions and information gaps.
Keep hypotheses separate from causes, with clear statuses.
Require supporting evidence before a cause is confirmed.
Support barrier analysis and structured techniques such as 5 Whys.
Allow inconclusive outcomes.
Link actions to the investigation and track their follow-up.
Produce an issued report that cannot be changed afterwards.
How Incident Investigation & RCA addresses it
Incident Investigation & RCA is a module of the Sospita HSE Platform. It is currently coming soon.
Investigations follow a staged lifecycle, from draft through investigating, analysis and action planning to finalisation and closure. Timeline events, findings, questions and information gaps are recorded as structured items. Hypotheses have their own statuses (open, needs evidence, supported or rejected) and remain separate from causes.
Causes are organised in a causal graph as immediate, contributing, underlying or root causes. A cause can only be confirmed once it is linked to a supporting finding, hypothesis or barrier. Barriers are categorised as preventive, mitigative or recovery and rated as effective, partial or ineffective. A 5 Whys view is derived from the causal graph, and RCA outcomes include "inconclusive" and "insufficient evidence".
Actions are created as shared HSE Platform Actions. The issued report is an immutable PDF snapshot that requires the finalise permission and acknowledgement of any warnings.
AI support for investigators is coming soon and is not currently available. When it is released, AI will make suggestions only: a person must accept each one, AI-suggested causes will remain candidates, and the AI will not confirm causes or write the issued report. AI assists; people decide.
Limitations and human responsibility
A structured tool supports a good sequence. It cannot make an investigation thorough.
The quality of an investigation depends on the investigators: how well they gather evidence, how fairly they interview people, how critically they test hypotheses and how honestly they report uncertainty. A system can require support before a cause is confirmed, but it cannot judge whether that support is strong enough.
Investigations may also be subject to legal, regulatory or contractual requirements that go beyond any tool. Those obligations remain with the organisation and the people conducting the investigation.