Incident Postmortem
A structured write-up of what went wrong during an incident, why it happened, and how to prevent it next time.
20 free credits on signup — no card needed
About this Document
What Is a Incident Postmortem?
An Incident Postmortem is a formal record of an unexpected event. In Australian business, this document serves two main goals. It helps you understand what went wrong and how to stop it from happening again. It also acts as a vital defence if you face legal action or a regulatory audit.
For tradespeople, manufacturers, and construction businesses, this document is often called an Incident Investigation Report. It deals with physical injuries, near misses, or property damage. For tech startups and service providers, it might be called a Data Breach Response Report. It deals with cyber attacks, data loss, or system outages.
Regardless of your industry, the purpose is the same. You must move from reacting to the problem to fixing the root cause. Under Australian law, simply apologising or fixing the immediate damage is often not enough. You have a duty of care to investigate.
When to Use This Document
You should complete a postmortem immediately after any significant operational failure. In Australia, the law dictates strict timelines for serious events. If you wait too long, you risk breaching the Work Health and Safety Act 2011 (WHS Act) or the Privacy Act 1988.
Workplace Safety Incidents
You must use this document for any "notifiable incident." According to SafeWork Australia, this includes the death of a person, a serious injury or illness, or a dangerous incident.
If someone is seriously hurt, you have specific legal obligations. You must notify the regulator in your state, such as SafeWork NSW or WorkSafe Victoria, immediately. You must also preserve the incident site. Do not disturb the scene until an inspector gives you permission or 36 hours have passed, unless you need to help an injured person or remove an immediate risk.
Data Breaches and Privacy
If you handle customer data, you use this document when you suspect an eligible data breach. The Notifiable Data Breaches (NDB) scheme applies to businesses with more than $3 million annual turnover, as well as healthcare providers and credit reporting bodies.
If you suspect a breach, you must conduct a "reasonable and expeditious assessment." You use the postmortem to document this assessment. You must decide if the breach is likely to cause serious harm to any individuals. If it is, you must notify the Office of the Australian Information Commissioner (OAIC) and the affected people within 30 days.
Near Misses and System Failures
You do not need to wait for a disaster to strike. It is best practice to use a postmortem for "near misses." These are situations where no one was hurt, but something went wrong that could have caused harm. Documenting these helps you comply with Australian Standards like AS/NZS ISO 45001:2018. This standard requires you to investigate nonconformities to prevent future problems.
Key Sections and Required Elements
A strong postmortem follows a logical structure. It moves from the facts of the event to the solution. Using a standard template helps ensure you do not miss legal requirements. You can use our Incident Report Template to get started.
Incident Classification and Metadata
Start with the basics. This section determines if the incident triggers mandatory reporting laws.
- Date and Time: When did it happen?
- Location: Where did it happen?
- People Involved: Names of employees, contractors, or members of the public.
- Notifiable Incident: Mark Yes or No. Check the definitions under Section 38 of the WHS Act.
- Eligible Data Breach: Mark Yes or No based on the threshold in the Privacy Act.
Description of Timeline
Write down exactly what happened. Keep this section factual. Avoid guessing why it happened at this stage. Just list the events in order.
Start with the "trigger." What was the first thing that went wrong? Then describe the response. What did your staff do? When did they call for help?
Include a disclaimer in this section. State that the account is based on the best available information at the time. This protects you if new facts come to light later.
Root Cause Analysis
This is the most important part for legal compliance. You need to find out why the incident happened. In Australian workplaces, we commonly use the "5 Whys" or "Fishbone" (Ishikawa) method.
Look beyond human error. Did a lack of training cause the mistake? Was the equipment faulty? Was the process unclear? Under the WHS Act, a breach of the primary duty of care occurs if you do not eliminate or minimise risks so far as is reasonably practicable. Identifying the systemic cause shows you are taking this duty seriously.
Action Items and Corrective Measures
You must list the steps you will take to prevent recurrence. This is a requirement of the Work Health and Safety Act and AS/NZS ISO 45001:2018. For every action item, assign a responsible person and a target date.
For example, if a worker fell because a ladder was slippery, your action item is not just "clean the ladder." It should be "inspect all ladders weekly" or "purchase non-slip ladder feet." You can link these actions back to your Safe Work Method Statements or broader safety management system.
Legal Disclaimer and Confidentiality
This section attempts to manage your legal risk. While a disclaimer does not guarantee protection, it sets the document's purpose.
You should include a statement like: "This document is created for the purpose of internal business improvement and risk prevention. It is prepared without prejudice to the rights of the company in any future legal proceeding. For the avoidance of doubt, nothing in this document constitutes an admission of liability."
This is particularly important if there is a risk of prosecution. Documents created for the dominant purpose of obtaining legal advice may attract Legal Professional Privilege. However, standard operational postmortems are usually "discoverable," meaning a regulator can demand them during an investigation.
How to Write a Incident Postmortem (Step by Step)
Writing a postmortem can feel stressful, especially if emotions are high. Following a clear process ensures you do not miss anything.
Step 1: Secure the Scene
Before you write anything, ensure safety is under control. If it is a physical incident, stop work. Make sure no one else gets hurt. If it is a data breach, isolate the affected systems to stop the leak.
Remember your legal duty to preserve evidence. Do not clean up a spill or repair a machine if a notifiable incident occurred, unless you have permission from an inspector.
Step 2: Gather the Facts
Interview the people involved as soon as possible. Do it while their memory is fresh. However, be mindful of the Fair Work Act 2009. If the incident might lead to disciplinary action, you must follow due process. Allow the employee to have a support person present.
Collect physical evidence. Take photos of the machinery, the floor condition, or the computer logs. Keep copies of relevant rosters or maintenance records.
Step 3: Draft the Narrative
Write the timeline. Be objective. Instead of saying "John was careless," say "The operator did not engage the safety guard before starting the machine." This language focuses on the process, not the person.
Step 4: Perform the Analysis
Use the 5 Whys technique. Ask "why" five times to get to the root cause.
- Why did the operator not engage the guard? Because the guard was stiff and hard to move.
- Why was it stiff? Because it had not been lubricated.
- Why had it not been lubricated? Because the maintenance schedule did not include weekly lubrication.
- Why was that missing? Because the maintenance schedule was created in 2015 and never reviewed.
- Why was it not reviewed? Because there is no process for annual reviews of equipment maintenance.
The root cause here is not the operator. It is the failure to review the maintenance schedule.
Step 5: Assign Actions
Assign tasks to specific people. "Management" is not a person. "John Smith, Site Manager" is a person. Set a deadline. Review these actions in your next safety meeting.
Step 6: Review and Sign Off
Have a senior manager review the document. If there is any risk of legal liability, have a lawyer look at it before you finalise it. Once complete, store it securely. You must keep incident records for at least five years in many jurisdictions, but check your specific state WHS regulations.
Common Mistakes to Avoid
Many Australian business owners make simple errors that expose them to greater risk.
Scapegoating Individuals
Blaming a single employee is a common mistake. Under Australian employment law, this can backfire. If the root cause is a system failure (like poor training), firing the worker does not fix the problem. It can also lead to an unfair dismissal claim under the Fair Work Act 2009. Focus on the system, not the person.
Writing Too Late
Memories fade quickly. If you write the report two weeks after the event, details will be missing. Regulators like SafeWork NSW view delays as a sign that you do not take safety seriously. Write it while the facts are fresh.
Being Too Vague
Saying "We will be more careful in the future" is not an action item. It is useless in court. You need specific, measurable steps. "We will install a safety sensor by next Friday" is a proper action item.
Using the Document to Self-Incriminate
Be careful with your language. Avoid saying "We broke the law by failing to provide training." Instead, say "The training records were incomplete." Stick to the facts. Do not offer legal conclusions in the document unless you have sought legal advice.
Legal Considerations (AU)
Australian law takes incident reporting very seriously. Failing to document an incident correctly can lead to heavy fines. In recent years, Industrial Manslaughter laws have been introduced in Victoria, Queensland, New South Wales, and the ACT. These laws allow for prison terms for business owners if their negligence causes a death.
WHS Duties
Under Section 19 of the WHS Act, a Person Conducting a Business or Undertaking (PCBU) has a primary duty of care. You must ensure, so far as is reasonably practicable, the health and safety of workers.
If you have an incident and do not investigate it, you are failing to take steps to prevent recurrence. A prosecutor will argue that you breached your duty of care. A well-written postmortem is your evidence that you took reasonable steps.
Corporations Act
Officers of a company (directors and senior managers) have their own duties under Section 27 of the Corporations Act 2001. They must exercise due diligence. An officer can be personally liable if they fail to keep informed about safety matters. Reading and signing off on postmortems is one way directors can show they are exercising this due diligence.
Privacy Act
For data breaches, the Privacy Act 1988 requires you to take "reasonable steps" to protect information. If a breach occurs, your postmortem is evidence of the steps you took to assess the damage and notify those affected. Failing to conduct an assessment can lead to fines of up to $2.1 million for serious or repeated breaches.
Evidence and Privilege
The Evidence Act 1995 (Cth) governs what documents can be used in court. Generally, incident reports are discoverable. This means the regulator or the other party in a lawsuit can force you to hand them over.
If you are concerned about criminal liability, you should seek legal advice immediately. A lawyer might advise that the investigation be conducted under Legal Professional Privilege. This changes the nature of the document. It means the report is created specifically to get legal advice, which may protect it from being discovered. However, this is a complex area of law and should not be navigated without professional help.
Frequently Asked Questions
Is an Incident Postmortem the same as an Incident Notification?
No. The notification is the immediate warning you send to the regulator (SafeWork or the OAIC) to tell them an event happened. The postmortem is the detailed investigation that happens afterwards.
Who is responsible for writing the postmortem?
Usually, the supervisor or manager in charge of the area where the incident occurred writes the report. In small businesses, the owner often does it. If the incident is complex, you might engage an external safety consultant or a lawyer to assist.
Can I write a postmortem if no one got hurt?
Yes. You should. "Near misses" are excellent opportunities to improve safety. They also show the regulator that you are proactive about risk management. This can work in your favour if a serious incident happens later.
How long do I need to keep the postmortem?
You generally need to keep safety records for at least five years. However, if a worker develops a disease (like silicosis) years after exposure, you may need these records decades later. It is best practice to keep incident investigation records permanently.
Do I need to show the postmortem to my employees?
Transparency is good for culture. Showing employees the findings (especially the action items) proves you are serious about fixing things. However, if the report contains sensitive personal information or details about a disciplinary investigation, be careful. You may need to redact names or sections to comply with privacy laws.
What if I disagree with the postmortem findings?
As a business owner, you have the final say. However, if an investigator or safety officer makes a recommendation you disagree with, document why you are rejecting it. You must still show that you are managing risks. Simply ignoring a recommendation is risky. You might need to seek alternative advice to prove that your chosen approach still meets the requirements of the WHS Act.
Required Sections
Incident Summary
Gives the incident name, severity, start and end times, and a one-paragraph overview.
Timeline of Events
A chronological record of what happened before, during, and after the incident.
Root Cause Analysis
Explains the underlying causes of the incident, not just the symptoms.
Impact Assessment
Describes who and what was affected by the incident.
Action Items
Lists the concrete steps to prevent a repeat of this incident.
Ready to create your document?
Use our free template or generate a custom version tailored to your needs.
20 free credits on signup — no card needed
This document is for informational purposes and serves as a general guide.
Last reviewed: July 27, 2026