Root Cause What, Not Who: Tim Page-Bottorff's Test for Better Incident Reviews
Tim Page-Bottorff's Headline Podcast conversation offers a precise test for incident reviews. Ask what conditions produced the event, rather than who can be made responsible for it, then turn the answer into an owned and verified change in the work.

Key takeaways
- 01Tim Page-Bottorff's root-cause what, not who test keeps an incident review focused on conditions, decisions, and barriers instead of personal blame.
- 02A complete review separates the event description from interpretations, assumptions, and the decisions that allowed exposure to remain.
- 03Investigators should test whether a procedure was usable in the real work, because a signed instruction does not prove that the system made compliance possible.
- 04Accountability becomes stronger when every corrective action has an owner, a due date, a verification method, and a clear connection to the evidence.
- 05The most valuable episode companion is a review conversation that changes the work and gives the affected team a visible response.
An incident review can close with a named person, a completed form, and no meaningful change in the work. That outcome feels decisive because it offers a simple explanation, yet it often leaves the conditions that produced the event untouched.
In Episode 10 of the Headline Podcast, Tim Page-Bottorff proposes a sharper test for investigation quality. He says, “I don't think we should do a root-cause who. I think we should do a root-cause what.” The distinction is small in wording and large in consequence. It moves the review from accusation toward evidence, decision ownership, and prevention.
What Tim Page-Bottorff's test changes in an incident review
A person is visible at the end of an incident sequence, while the decisions and work conditions that shaped the sequence may have accumulated for weeks or years. If the review stops at the person closest to the outcome, it can mistake proximity for causation.
The question “what produced this event?” does not mean that behavior is irrelevant. It means behavior belongs inside a wider explanation that includes the task design, the equipment, the instructions, the schedule, the supervision, the incentives, and the barriers that were expected to work.
That is consistent with James Reason's distinction between active failures and latent conditions. The action nearest to the event matters, but so do the organizational decisions that made the action more likely, harder to detect, or difficult to recover from.
Start with the work sequence, not the employee's character
The first account should describe the work as it unfolded. Record what task was underway, what changed, what the worker could see, which controls were available, and what time pressure or production constraint was present. Avoid labels such as careless, complacent, or inexperienced until the evidence shows what those words are supposed to explain.
A character label compresses several unanswered questions into one judgment. If the worker bypassed a guard, ask whether the guard interfered with the task, whether the bypass was common, whether the equipment could run without it, and whether anyone had raised the problem before.
The useful output is not a softer description of the worker. It is a more accurate description of the operating conditions that leaders can change.
Separate facts, interpretations, and assumptions
Incident teams lose clarity when an observation and an explanation appear in the same sentence. “The operator ignored the procedure” may contain a fact about the sequence, an interpretation of intent, and an assumption that the procedure was practical. Those elements require different evidence.
| Evidence layer | Useful question | Review discipline |
|---|---|---|
| Fact | What was observed or recorded? | Preserve the source and time. |
| Interpretation | What explanation fits the available facts? | Compare competing explanations. |
| Assumption | What are we treating as true without checking? | Mark the gap and assign verification. |
| Decision | Which choice allowed the exposure to remain? | Identify the owner with authority to change it. |
This separation gives the review a defensible trail. It also helps leaders resist the pressure to produce a complete story before the evidence is complete.
Test whether the procedure was usable in real work
A procedure can be technically correct and operationally unusable. The review should compare the approved method with the work that people actually perform, especially when the task includes interruptions, awkward access, changing materials, weather, staffing gaps, or equipment that behaves differently from its design assumption.
Ask whether the sequence could be completed with the available tools and time. Ask which step people had to improvise. Ask whether the supervisor knew about the workaround and whether the workaround had become the normal method. These questions reveal where the system expected individual discipline to compensate for a weak design.
Andreza Araujo's work across more than 250 cultural transformation projects reinforces this practical point. Leaders do not improve behavior by repeating a rule whose operating conditions make the rule difficult to follow. They improve the conditions, clarify the decision, and verify the behavior that the new design makes possible.
Trace the decisions that allowed exposure to remain
Every incident contains decisions, including decisions not to intervene. A maintenance backlog may remain open because a production priority outranks it. A staffing gap may persist because a vacancy is treated as temporary. A weak alarm may remain in service because nobody owns the risk between engineering and operations.
The investigator should trace those decisions without turning the exercise into a search for a villain. Which information was available? Who received it? What threshold would have required escalation? Which person had authority to change the condition? What made the chosen option seem acceptable at the time?
When the review reaches a decision that shaped exposure, it has found a possible control point. A corrective action that cannot identify such a point is often only a reminder to be more careful.
Keep accountability attached to authority
Accountability is credible when the person or group responsible for an action can actually change the condition. Assigning a training action to an operator when the problem is equipment design transfers responsibility without transferring authority.
Each action should identify the finding it addresses, the accountable owner, the completion date, the evidence of completion, and the test that will show whether the risk has reduced. The test might involve a field observation, a functional check, a revised maintenance record, or a comparison between the approved method and the next real task.
A closed action is not the same as an effective action. The review is complete only when the changed condition survives contact with normal work.
Use worker testimony as evidence, not decoration
The people who perform the task often know which barriers are fragile, which instructions conflict, and which workarounds keep the operation moving. Their accounts should be tested against other evidence, but excluding them deprives the review of information that may not exist in the formal record.
Tim Page-Bottorff also connects leadership with the quality of the conversation. A leader who asks for facts and then punishes the answer will receive a polished version of the event next time. A leader who explains what was learned, what remains uncertain, and what will change gives the team a reason to report earlier.
The test is visible. Can the affected workers explain what the organization changed after the review? If they cannot, the learning has not reached the worksite.
What to do when evidence points in several directions
Complex incidents rarely have one cause. The team may find a confusing interface, an incomplete handover, a production demand, a weak barrier, and a decision that delayed escalation. That complexity does not justify a vague report. It requires the team to rank the findings by consequence, controllability, and recurrence potential.
Use a short evidence conference in which each finding must answer three questions. What evidence supports it? What uncertainty remains? Which change would reduce the exposure if the finding is correct? Findings that cannot answer those questions should remain provisional rather than becoming permanent statements in the report.
This discipline keeps the investigation open to correction while still producing decisions. It is more useful than forcing every detail into a single causal sentence.
Recommendation
Use Tim Page-Bottorff's root-cause what test in the next incident review. Before assigning an action, require the team to identify the work condition, the decision, or the barrier that allowed exposure to remain. Then require the accountable owner to show how the changed condition will be verified.
Within the first review meeting, separate facts from interpretations and assumptions. Within 7 days, confirm that the interim controls still work. Within 30 days, test the permanent change during the task that most closely resembles the original exposure. If the report changes language but not the work, the investigation has not finished.
Conclusion
“Root-cause what, not who” is not an invitation to avoid responsibility. It is a demand for better responsibility. The question directs attention toward the conditions and decisions that leaders can redesign, verifies whether corrective actions work, and makes the incident review useful to the people who will face the risk again.
Listen to Episode 10 with Tim Page-Bottorff on the Headline Podcast, then bring this test to your next review. Safety improves when the explanation reaches the work, the owner has authority, and the affected team can see what changed.
For a practical safety culture and leadership perspective, explore the work of Andreza Araujo and the Headline Podcast.
Explore Headline PodcastFrequently asked questions
What does root-cause what, not who mean?
Does a what-focused investigation excuse unsafe behavior?
What evidence should an incident team review first?
How can leaders make corrective actions more effective?
How does this approach improve safety culture?
About the author
Andreza Araújo
Safety Culture Expert | Senior EHS Executive
Andreza Araújo is a safety culture expert and senior EHS executive with more than 25 years of experience in environment, health and safety. She is a Civil Engineer and Occupational Safety Engineer from Unicamp, holds a Master's degree in Environmental Diplomacy from the University of Geneva, and completed sustainability studies at IMD Switzerland. Andreza has served in Global Head of EHS roles in Fortune 500 environments, leading cultural transformation programs across multinational operations. She has represented Brazil as a speaker at the United Nations in Paris and has spoken at the International Labour Organization in Turin. She is the author of more than 16 books on safety culture in Portuguese, Spanish, English and German. Her work has earned more than 10 EHS awards, including two recognitions from Indra Nooyi, former PepsiCo CEO.
- Civil & Safety Engineer (Unicamp)
- M.A. Environmental Diplomacy (University of Geneva)
- Sustainability Cert (IMD Switzerland)
- People Management & Coaching (Ohio University)
- UN Paris speaker representative for Brazil
- ILO Turin speaker
- LinkedIn Top Voice
- Indra Nooyi PepsiCo CEO recognition (2x)
Documentaries
Watch Andreza's documentaries
Three productions on safety culture, organizational failure and the human lessons behind major disasters.
Podcasts
Listen to Andreza's podcasts
She hosts three shows on safety leadership, EHS and organizational culture, in English and Portuguese.