Incident Investigation: 5 Decision Gates That Keep Serious Reviews From Becoming Blame Exercises
A critical F1 analysis of five decision gates that keep serious incident investigations evidence-led, system-aware, and focused on risk change rather than convenient blame.

Key takeaways
- 01A serious incident review becomes unreliable when the first explanation is treated as a conclusion instead of a question.
- 02Five decision gates keep the investigation open long enough to test evidence, system conditions, control performance, and management choices.
- 03James Reason's distinction between active failures and latent conditions helps investigators move beyond the last visible action without erasing personal responsibility.
- 04The investigation leader should separate fact, inference, and unresolved uncertainty before assigning corrective actions.
- 05Andreza Araujo's experience across more than 250 cultural transformation projects supports a practical rule: the report must explain how the work was shaped, not only who touched the hazard.
The first explanation after a serious incident is usually the most available one. Someone crossed a line, missed a check, selected the wrong setting, or failed to speak up. That account may describe the final action, but it rarely explains why the action made sense to the person doing the work or why the surrounding controls did not interrupt it.
This article argues that a serious incident investigation needs five decision gates before it is allowed to settle on cause or corrective action. The gates keep the review open long enough to test evidence, work conditions, control performance, and management choices. They also protect the investigation from a familiar failure, turning a complex event into a story about one person's mistake.
Why does the first explanation become the wrong conclusion?
Investigators face pressure to produce a clear answer quickly. Leaders need to brief employees, regulators may request information, and production teams want to know whether work can resume. Under that pressure, the first plausible explanation gains authority simply because it arrives early.
The problem is not that the first explanation is always false. It is that it is usually incomplete. James Reason's work on organizational accidents separates active failures, which appear close to the event, from latent conditions that may have been created by design, planning, supervision, resource allocation, or management decisions. A review that stops at the active failure leaves the conditions that made it possible intact.
Andreza Araujo's book Sorte ou Capacidade, translated as Luck or Capability, reinforces a related question. Was the event an isolated act of bad luck, or did the organization repeatedly place people in conditions where success depended on improvisation? The answer changes what the investigation must examine.
Decision Gate 1: What is confirmed, and what is only assumed?
The first gate protects the evidence base. Before discussing cause, the investigation team should mark every important statement as a confirmed fact, a supported inference, or an unresolved question. A time stamp from a control system is not equivalent to a witness recollection, and neither should be presented with the same level of certainty.
Build the initial chronology from independent sources such as access records, equipment data, work permits, photographs, radio traffic, maintenance history, and interviews. The aim is not to create a polished story. It is to show where the record is strong and where the investigation still depends on memory.
A useful test is simple. If removing one witness statement makes the entire sequence collapse, the sequence is not yet proven. Preserve the uncertainty in the report, because false precision encourages leaders to approve corrective actions against an event that may not have happened as described.
Decision Gate 2: What conditions shaped the work?
The second gate moves the review from the event scene to the work system. Ask what the person was expected to achieve, what information was available, which resources were present, and what competing demands were active at the time. These questions do not excuse a dangerous action. They explain the operating environment in which the action occurred.
Check the task plan against the task that actually unfolded. Compare staffing, production sequence, access, equipment status, contractor interfaces, shift handover, supervision, and time pressure. A procedure may say one thing while the field requires another, especially when the job has been changed by a late delivery, a failed component, an unavailable specialist, or a temporary workaround.
In more than 250 cultural transformation projects supported by Andreza Araujo's team, the gap between declared practice and operated practice is a recurring source of insight. When the gap is visible, the investigation should treat it as evidence about the system, not as proof that workers simply ignored the rule.
Decision Gate 3: Which controls were supposed to interrupt the event?
The third gate identifies the barriers that should have prevented the event, detected the developing condition, or limited the consequence. List them in sequence and ask what each control was designed to do, who owned it, and how its performance could be verified before the incident.
Do not confuse the presence of a control with its effectiveness. A permit may exist, a guard may be installed, a training record may be current, and a supervisor may have signed the pre-task review, although none of those facts proves that the control worked in the relevant moment. The investigation should ask whether the control was available, understood, physically capable, used as intended, and resilient to the variation present in the task.
Use the barrier health review to test whether a control still holds under real conditions. If the barrier failed because its ownership, inspection, design, or escalation path was weak, the corrective action must address that weakness rather than adding another reminder to the worker.
Decision Gate 4: What evidence would disprove the favored story?
The fourth gate is deliberately uncomfortable. Once an investigation has a preferred explanation, the team should name the evidence that could prove it wrong. This protects the review from confirmation bias, which Daniel Kahneman describes as the tendency to favor information that supports an existing interpretation.
For example, if the favored story says that the operator bypassed a control, examine whether the control was functional, whether the normal sequence was physically possible, whether similar bypasses were accepted by supervision, and whether the task design made the bypass the fastest way to complete the work. If the evidence points elsewhere, the original narrative must change.
Invite a person who understands the task but did not write the first account to challenge the interpretation. A credible challenge is not an obstacle to closure. It is a test of whether the conclusion can survive contact with the work as performed.
Decision Gate 5: Did the proposed action change the risk?
The fifth gate prevents the report from ending with activity that looks responsible but leaves exposure unchanged. Every action should state which contributing condition it changes, who owns the change, when evidence will be available, and how the organization will verify that the risk or control performance moved.
Training may be appropriate when knowledge or skill was genuinely missing, but training alone is a weak response when the event involved poor design, unavailable equipment, conflicting priorities, unclear authority, or an unreliable barrier. A Ilusão da Conformidade, translated as The Illusion of Compliance, is relevant here because a completed form can create the appearance of control without changing the conditions that people face.
Use the corrective-action verification guide to define the proof before closing the action. A revised procedure is not proof by itself. A stronger test might involve field observation, control-function testing, recurrence review, independent sampling, or a documented decision that shows how the work changed.
How should the five gates appear in the investigation meeting?
The gates work best as decisions in the meeting agenda rather than as another form for investigators to complete. Ask the team to pause after each gate and record what is known, what remains uncertain, and what evidence is needed before the review advances.
| Gate | Core question | Weak answer | Useful evidence |
|---|---|---|---|
| 1 | What is confirmed? | “Everyone agrees it happened this way.” | Independent records and clearly bounded uncertainty. |
| 2 | What shaped the work? | “The procedure was available.” | Actual staffing, sequence, resources, interfaces, and field conditions. |
| 3 | Which controls should have worked? | “The permit was signed.” | Evidence that the barrier was present, capable, understood, and verified. |
| 4 | What could disprove the story? | “There is no need to look further.” | Contradictory records, alternative sequences, and an independent challenge. |
| 5 | Did the action change risk? | “The team was retrained.” | Field proof that the contributing condition or control performance changed. |
For senior leaders, the meeting should end with a decision about evidence quality, not just a list of actions. The incident evidence status guide can help the team distinguish what is ready for causal analysis from what still needs verification.
What should leaders refuse to accept in the final report?
Leaders should challenge any report that names a person but cannot explain the conditions that shaped the decision. They should also challenge a report that contains many actions without a clear connection between each action and a contributing condition.
A credible report can acknowledge individual responsibility while still examining the organization around the event. It can state what the person did, what the person knew, what options were available, what controls were functioning, and what decisions upstream made the exposure more likely. That level of precision is stronger than either personal condemnation or vague language about the system.
The final test is whether a supervisor in another area could recognize the same exposure before another incident occurs. If the report only describes the past event, it has not yet converted evidence into prevention.
FAQ
The five decision gates are evidence status, work conditions, control performance, disconfirming evidence, and risk change. Together, they keep a serious incident review from treating the last visible action as the whole cause.
Can the five gates be used after a near miss? Yes. A near miss often provides stronger evidence because the consequences were limited while the control sequence can still be reconstructed. Use the same gates, but match the depth of the review to the credible consequence and the learning value.
Should the investigation team name an individual? Name actions and decisions when the evidence supports them, but do not let a name substitute for analysis. The report should explain both the person's action and the conditions that influenced the available choices.
What if evidence conflicts? Preserve the conflict, test the sources, and state the remaining uncertainty. A transparent unresolved question is more useful than a confident conclusion built on a weak record.
How long should a serious investigation take? The time should reflect consequence, complexity, evidence availability, and the need to protect people and operations. Speed matters, but premature closure creates a second risk because the organization may act on the wrong cause.
Where can leaders start? Put the five gates on the next investigation agenda and ask the team to record one confirmed fact, one unresolved question, one control test, one disconfirming challenge, and one verification measure before approving the report.
A serious incident report is not finished when it assigns fault. It is finished when the organization can explain the event clearly enough to change the conditions that made it possible, then verify that the change holds in the work.
For more evidence-based conversations where leadership and safety meet, explore the Headline Podcast blog.
Frequently asked questions
What is a decision gate in incident investigation?
Why do serious incident investigations become blame exercises?
How does James Reason help an incident investigation?
Who should lead a serious incident review?
What makes an incident corrective action credible?
About the author
Andreza Araújo
Safety Culture Expert | Senior EHS Executive
Andreza Araújo is a safety culture expert and senior EHS executive with more than 25 years of experience in environment, health and safety. She is a Civil Engineer and Occupational Safety Engineer from Unicamp, holds a Master's degree in Environmental Diplomacy from the University of Geneva, and completed sustainability studies at IMD Switzerland. Andreza has served in Global Head of EHS roles in Fortune 500 environments, leading cultural transformation programs across multinational operations. She has represented Brazil as a speaker at the United Nations in Paris and has spoken at the International Labour Organization in Turin. She is the author of more than 16 books on safety culture in Portuguese, Spanish, English and German. Her work has earned more than 10 EHS awards, including two recognitions from Indra Nooyi, former PepsiCo CEO.
- Civil & Safety Engineer (Unicamp)
- M.A. Environmental Diplomacy (University of Geneva)
- Sustainability Cert (IMD Switzerland)
- People Management & Coaching (Ohio University)
- UN Paris speaker representative for Brazil
- ILO Turin speaker
- LinkedIn Top Voice
- Indra Nooyi PepsiCo CEO recognition (2x)
Documentaries
Watch Andreza's documentaries
Three productions on safety culture, organizational failure and the human lessons behind major disasters.
Podcasts
Listen to Andreza's podcasts
She hosts three shows on safety leadership, EHS and organizational culture, in English and Portuguese.