Incident Investigation

Five Whys vs Fishbone vs Fault Tree Analysis: Which Method Should Leaders Use After a Serious Incident?

Five Whys, Fishbone, and Fault Tree Analysis answer different investigation questions. This executive comparison shows when each method fits, where each can mislead, and how leaders can connect findings to verified controls after a serious incident.

By 9 min read
investigative scene on five whys vs fishbone vs fault tree analysis which method should leaders use — Five Whys vs Fishbone v

Key takeaways

  1. 01Five Whys is strongest for tracing a bounded, evidence-supported causal chain without stopping at the final human action.
  2. 02Fishbone is strongest for widening an investigation when several functions or conditions may have contributed.
  3. 03Fault Tree Analysis is strongest for testing combinations of failures around a defined high-consequence top event.
  4. 04A method diagram does not prove that a control works; field verification must connect the finding to the changed condition.
  5. 05Leaders should document why the method was selected, what it cannot answer, and who will verify the resulting controls.

A serious incident can leave a leadership team with a full report and an unresolved decision. The investigation method may be technically respectable, yet the result still fails to show which conditions made the event possible, which controls should change, and who has authority to verify that change. The choice between Five Whys, Fishbone, and Fault Tree Analysis matters because each method exposes a different shape of evidence.

Five Whys, Fishbone, and Fault Tree Analysis are incident-investigation methods with different purposes. Five Whys traces a selected causal chain, Fishbone organizes contributing conditions across categories, and Fault Tree Analysis tests how combinations of failures can produce a defined top event.

This comparison is for plant managers, EHS directors, operations leaders, and investigation chairs who must decide what analysis is proportionate after a serious injury, high-potential near miss, or process upset. The thesis is practical. No method is automatically rigorous because it is familiar. The strongest investigation uses the method that matches the uncertainty, then verifies the resulting controls in the work.

What should leaders evaluate before choosing an investigation method?

The first evaluation criterion is the decision the investigation must support. A team that needs to understand one visible chain of events requires a different tool from a team that must test combinations of technical failures, human actions, and management conditions.

Five criteria make the choice disciplined. First, define the object of analysis, whether it is one event sequence, a broad set of contributing conditions, or a specified top event. Second, identify the kind of uncertainty, such as sequence, categorization, interaction, or probability. Third, decide how much evidence is available and how much must still be collected. Fourth, identify the audience that will act on the result. Fifth, specify how control effectiveness will be verified after actions are closed.

CriterionFive WhysFishboneFault Tree Analysis
Best objectA selected causal chainMany possible contributing conditionsA defined top event
Best questionWhy did this condition lead to the event?Which categories may contain contributing causes?How can combinations of failures produce the top event?
Primary strengthSpeed and narrative clarityBreadth and team explorationLogical structure and barrier interaction
Main riskStopping at one convenient causeListing possibilities without evidenceBuilding a precise diagram from weak assumptions
Best decision levelLocal corrective actionInvestigation scope and evidence planCritical-control, design, or reliability decision

OSHA's incident-investigation guidance emphasizes identifying and correcting root causes rather than assigning blame. That principle does not select one method for every event. It establishes the standard against which the method should be judged, namely whether the analysis leads to stronger prevention and a credible correction.

When does Five Whys produce a useful causal chain?

Five Whys is strongest when the investigation has a clearly bounded event and a traceable sequence that can be tested against evidence.

The method begins with a factual problem statement, not a judgment about a person's attitude. “A technician's hand entered the line of fire during jam clearing at 14:20” is more useful than “the technician was careless,” because the factual statement leaves room to examine equipment state, authorization, isolation, supervision, and time pressure.

Each why should connect the previous condition to the next condition through evidence. If the answer says that the worker did not follow the procedure, the next question should examine why the procedure was not followed under those conditions. The team should ask whether the isolation point was accessible, whether the procedure matched the equipment, whether the task was planned, and whether the supervisor had a realistic way to verify the control.

Andreza Araujo's The Illusion of Compliance is relevant here because a signed rule can coexist with work conditions that make the expected action difficult. Five Whys becomes weak when it treats the last human action as the endpoint. It becomes useful when the chain continues into design, planning, resources, supervision, and the assumptions that allowed the exposure to persist.

Five Whys should not be used as a ritual number. An investigation may require three questions or eight, depending on where the evidence stops. The method is complete when the team reaches a condition that an accountable owner can change and verify, not when someone has written the fifth answer.

When does Fishbone create breadth without losing discipline?

Fishbone is strongest when the team needs to widen the search before it commits to a single causal explanation.

A serious event rarely belongs to one category. The investigation may need to examine equipment, task design, materials, environment, people, procedures, supervision, and management decisions. A Fishbone diagram gives the team a visible way to distribute questions across those areas, which helps prevent the first plausible explanation from becoming the final conclusion.

The danger is that breadth can become decoration. A branch labelled “training,” “communication,” or “human factors” is not evidence. Each branch needs a testable question, such as whether the training covered the actual task, whether the communication reached the shift that performed the work, or whether the work design made the expected behavior possible at the time of the event.

Use a Fishbone when the investigation chair is uncertain about scope, when several functions hold partial evidence, or when the event crosses organizational boundaries. The diagram is especially useful during the first structured workshop because it creates an evidence plan before interviews and document review become narrowly focused.

NIOSH's FACE program illustrates why incident learning must look beyond the final movement. Its investigations examine the worksite, the sequence, and the surrounding conditions so that recommendations can prevent similar injuries. Fishbone supports that broad search, but the team must still eliminate unsupported branches and convert verified contributors into decisions.

When does Fault Tree Analysis justify its added rigor?

Fault Tree Analysis is strongest when leaders need to understand how combinations of failures can produce a defined high-consequence event.

The team starts with a top event, such as loss of containment, failure of emergency shutdown, or exposure to an uncontrolled energy source. It then works backward through logical gates to identify combinations of initiating failures, protection failures, and unavailable safeguards. The value comes from making the structure of the scenario explicit rather than relying on a linear story.

Fault Tree Analysis is appropriate when the decision concerns a safety-critical system, a major accident hazard, a reliability problem, or the independence of protective layers. It can reveal that two barriers described as separate depend on the same power supply, maintenance team, sensor, assumption, or emergency response. That shared dependency can turn apparent redundancy into a single point of failure.

The method also imposes a burden. A clean tree can create false confidence if the initiating events, logic gates, or failure assumptions are not supported by field evidence. The investigation must record what is known, what is estimated, and what remains uncertain. If probability data is used, the source and date need to be visible. If probability data is not available, the tree can still support qualitative decision-making, but it should not be presented as a precise risk calculation.

Rodney Rocha's Columbia lessons, discussed through Headline Podcast's focus on how technical concerns reach leaders, show why system relationships matter. A technical warning can exist without becoming an executive decision when communication paths, schedule pressure, and authority boundaries prevent the evidence from changing the plan. Fault Tree Analysis cannot repair governance by itself, but it can make dependencies and missing barriers harder to hide.

How should evidence determine the method rather than the other way around?

Evidence should determine the method by showing whether the investigation is dealing mainly with sequence, scope, or interaction.

Start with the event chronology, photographs, equipment condition, permits, work orders, training records, interviews, and relevant control-verification evidence. Do not treat a method's diagram as evidence. The diagram is a way to organize evidence that has already been collected or is explicitly marked for verification.

Use Five Whys when the chronology is stable and one chain must be traced to an actionable organizational condition. Use Fishbone when the chronology is incomplete, the event crosses functions, or the team needs to challenge its initial framing. Use Fault Tree Analysis when the top event is clear and the decision depends on interactions between barriers or failure combinations.

Some investigations need a sequence. A Fishbone can widen the initial search, Five Whys can trace selected contributors, and Fault Tree Analysis can test a high-consequence scenario that remains after the event review. That sequence is not automatically better. It is justified only when each method resolves a different uncertainty and the outputs are reconciled rather than filed separately.

The existing Headline guide on evidence chains in safety investigations makes the same operational point. A conclusion is decision-ready only when the facts, interpretation, control, and owner remain connected.

What failure modes make each method misleading?

Each method can mislead leaders when its output is mistaken for proof of control.

  • Five Whys becomes misleading when the chain ends at “operator error,” when each answer merely repeats the previous one, or when the team forces a single cause onto a multi-causal event.
  • Fishbone becomes misleading when every branch is filled with generic categories, when unverified ideas are reported as causes, or when the team never prioritizes the conditions that changed exposure.
  • Fault Tree Analysis becomes misleading when the top event is vague, when dependent barriers are counted as independent, or when a detailed diagram is treated as stronger than the assumptions behind it.

James Reason's work on latent conditions helps explain the common thread. An investigation should not stop at the final action when earlier design, planning, supervision, or management decisions shaped the conditions in which that action occurred. The analysis must still preserve individual responsibility where it exists, but responsibility becomes more accurate when the decision chain is visible.

OSHA's root-cause-analysis guidance supports this distinction by framing investigation around underlying, system-related reasons. That does not mean every event requires a large committee. It means the chosen method must be capable of reaching the condition that management can actually change.

Which method belongs in the decision matrix?

The decision matrix should match the method to the uncertainty, the consequence, and the action that must follow.

Investigation needPreferred methodWhy it fitsRequired safeguard
Trace one verified event chainFive WhysIt keeps the causal narrative focusedTest each why against records, interviews, and conditions
Explore a broad set of contributorsFishboneIt prevents premature closureConvert branches into evidence questions and remove unsupported causes
Test interacting failures around a top eventFault Tree AnalysisIt shows logic, dependencies, and combinationsDocument assumptions, independence, and data sources
Serious event with uncertain scopeFishbone followed by targeted analysisIt widens the search before choosing depthLet verified evidence determine the second method

The matrix is not a ranking from simple to advanced. A short Five Whys can be more rigorous than a Fault Tree built from guesses, while a Fishbone can be more valuable than either when the investigation has not yet defined the problem correctly.

How should leaders choose after a serious incident?

Leaders should choose Five Whys for a bounded causal chain, Fishbone for disciplined breadth, and Fault Tree Analysis for interacting failures around a defined high-consequence event.

If the event involves a single task and the evidence is strong, begin with Five Whys and verify that the chain reaches work design and management conditions. If several functions disagree about what mattered, begin with Fishbone and make each branch an evidence question. If the event exposes a safety-critical system or a potential major-accident pathway, define the top event and use Fault Tree Analysis to examine barrier dependencies.

The investigation chair should document why the method was selected, what it cannot answer, and what additional review is required. That short statement prevents a familiar template from becoming the organization's default explanation for every event.

Andreza Araujo's work on safety culture keeps the conclusion close to the operating decision. A report has value only when someone with authority changes a condition, communicates the reason, and verifies that the new control performs under real work pressure. The method is a means to that end, not the evidence of success.

The next serious incident will test the quality of the investigation method before the report is written. Decide now which evidence would justify a local causal chain, a broad contributor map, or a system-level failure tree, then make the decision rule visible to the people who will lead the review.

Frequently asked questions about investigation methods

The best investigation method is the one that matches the uncertainty the decision-maker must resolve and produces controls that can be verified in the work.

Topics incident-investigation root-cause-analysis five-whys fishbone-diagram fault-tree-analysis serious-incident safety-leadership headline-podcast

Frequently asked questions

Is Five Whys enough for a serious incident?
Five Whys can be enough when the event is bounded, the chronology is reliable, and each answer is tested against evidence until the team reaches an actionable organizational condition. It is not enough when the event involves interacting failures or an uncertain scope that requires broader analysis.
What is the difference between Fishbone and Fault Tree Analysis?
Fishbone organizes possible contributors across categories so the team can widen its evidence search. Fault Tree Analysis works backward from a defined top event to test logical combinations of failures and unavailable barriers.
Should every incident investigation use all three methods?
No. Use all three only when each method resolves a different uncertainty. A Fishbone may widen the initial scope, Five Whys may trace selected contributors, and Fault Tree Analysis may test a high-consequence pathway, but unnecessary layering can create paperwork without better decisions.
Can Fault Tree Analysis be qualitative?
Yes. A qualitative Fault Tree can show logical relationships and barrier dependencies without claiming precise probabilities. Any probability estimate should identify its source, date, assumptions, and limitations.
How do leaders know an investigation finding worked?
Leaders know a finding worked when the relevant condition changes, the control performs under actual operating pressure, and an accountable owner verifies the result using evidence rather than a closed action record alone.

About the author

Andreza Araújo

Safety Culture Expert | Senior EHS Executive

Andreza Araújo is a safety culture expert and senior EHS executive with more than 25 years of experience in environment, health and safety. She is a Civil Engineer and Occupational Safety Engineer from Unicamp, holds a Master's degree in Environmental Diplomacy from the University of Geneva, and completed sustainability studies at IMD Switzerland. Andreza has served in Global Head of EHS roles in Fortune 500 environments, leading cultural transformation programs across multinational operations. She has represented Brazil as a speaker at the United Nations in Paris and has spoken at the International Labour Organization in Turin. She is the author of more than 16 books on safety culture in Portuguese, Spanish, English and German. Her work has earned more than 10 EHS awards, including two recognitions from Indra Nooyi, former PepsiCo CEO.

  • Civil & Safety Engineer (Unicamp)
  • M.A. Environmental Diplomacy (University of Geneva)
  • Sustainability Cert (IMD Switzerland)
  • People Management & Coaching (Ohio University)
  • UN Paris speaker representative for Brazil
  • ILO Turin speaker
  • LinkedIn Top Voice
  • Indra Nooyi PepsiCo CEO recognition (2x)

Documentaries

Watch Andreza's documentaries

Three productions on safety culture, organizational failure and the human lessons behind major disasters.

Podcasts

Listen to Andreza's podcasts

She hosts three shows on safety leadership, EHS and organizational culture, in English and Portuguese.

Summarize with AI