PropoDoc provides self-help document templates and tools. It is not a law firm and does not provide legal advice. Learn more.
Skip to main content

Incident Report

A formal report documenting an accident, injury, or security breach with details and corrective actions.

Use Free Template
Create your custom version — free to start

20 free credits on signup — no card needed

guide
moderate
low Risk
Government
Healthcare
Manufacturing
Operations
Risk Management

About this Document

Incident Report

What is a Incident Report?

An incident report is a formal document that records the specific details of an unexpected event, accident, security breach, or workplace disruption. It serves as the foundational record of what happened, when it happened, who was involved, and what immediate actions were taken. In a business context, this is not merely a bureaucratic exercise; it is a critical tool for risk management, legal protection, and operational improvement.

The primary purpose of an incident report is to create an objective, factual narrative of an event. Unlike a police report, which focuses on legal culpability, or a business proposal, which focuses on persuasion, an incident report focuses on accuracy and fact-finding. It is utilized by management, HR, safety officers, insurance adjusters, and potentially legal counsel to determine the root cause of an issue and develop strategies to prevent recurrence.

Incidents can range from minor mishaps, such as a slip in the breakroom that causes no injury, to major crises like a data breach exposing customer financial records or a severe injury on a construction site. Regardless of severity, the discipline of documenting the event remains the same. The report transforms a chaotic or anecdotal event into structured data that the organization can analyze.

Furthermore, an incident report often serves as an official corporate record. In regulated industries—such as healthcare, manufacturing, and finance—submitting these reports is not optional; it is a compliance requirement. For example, OSHA (Occupational Safety and Health Administration) in the United States requires employers to record specific workplace illnesses and injuries. Similarly, a data breach may trigger mandatory reporting deadlines under laws like GDPR or CCPA. Failure to document these incidents properly can result in significant fines, legal liability, and reputational damage.

Ultimately, an incident report is a mechanism for organizational learning. By capturing the "who, what, where, when, and how," a business can move from reactive problem-solving to proactive risk mitigation. It answers the question not just of what went wrong, but how the systems in place allowed it to go wrong, paving the way for corrective actions.

When to Use an Incident Report

Understanding when to trigger an incident report is just as important as knowing how to write one. Many organizations make the mistake of treating incident reporting as a reactionary measure used only for catastrophic events. However, the most effective safety and risk management cultures encourage reporting for a wide spectrum of events.

Workplace Injuries and Illnesses The most common use case is any physical harm to an employee or visitor. This includes obvious injuries requiring hospitalization, but also near-misses. A near-miss is an event that did not cause injury but had the potential to do so. For example, a hammer falling from a scaffold but missing a worker below is a near-miss. Reporting these is vital because they often reveal systemic hazards before they result in actual harm.

Property Damage Incident reports should be filed whenever company property, or the property of a client/visitor, is damaged. This could be a company vehicle scratched in a parking lot, expensive machinery malfunctioning due to user error, or a water pipe bursting in the office. Documenting property damage is essential for insurance claims and tax records, and it helps facilities teams track maintenance issues.

Security Breaches and IT Incidents In the digital age, "incidents" are frequently cyber-related. Unauthorized access to a server, a lost laptop containing unencrypted client data, a phishing attack that succeeds in tricking an employee, or a ransomware infection all require immediate incident reporting. These reports often trigger specific protocols outlined in a company's Incident Response Plan, which may be linked to a broader statement of work if IT security is managed by an external vendor.

Policy Violations and Behavioral Issues Not all incidents involve physical safety or hardware. Incidents of harassment, discrimination, violence, or gross misconduct must be documented. These reports are crucial for HR investigations. If an employee engages in verbal abuse or threatens a colleague, a written account creates a paper trail that justifies disciplinary action or termination, protecting the company from wrongful termination lawsuits later.

Client and Customer Incidents If a client is injured on your premises, or if a product you provided malfunctions and causes damage at a client site, an incident report is mandatory. It serves as the first line of defense in liability claims. It establishes that the company took the event seriously and acted with due diligence.

"Always Document" vs. "Triage" A best practice for most businesses is the "if in doubt, write it out" rule. It is far better to file a report for a minor incident that turns out to be nothing than to ignore a minor incident that later develops into a serious legal or medical complication. However, organizations should establish a triage system. Level 1 incidents (minor paperwork errors) might require a simple log entry, while Level 4 incidents (multiple fatalities) require immediate legal involvement and extensive documentation.

Key Components and Sections

To be effective, an incident report must be standardized. A lack of structure leads to incomplete data, which makes analysis difficult. While templates may vary by industry, a comprehensive incident report must contain the following core components.

1. General Information

This section sets the stage and organizes the document for retrieval.

  • Report Title: Clear and descriptive (e.g., "Chemical Spill in Warehouse B").
  • Report Number: Unique ID for tracking.
  • Date and Time of Incident: Be specific. Use 24-hour format or AM/PM to avoid ambiguity.
  • Date of Report: When the report was actually written (often different from the incident date).
  • Location: Specific address, floor, room number, or GPS coordinates.

2. Involved Parties

Identifying everyone connected to the event is crucial for follow-up.

  • The Injured/Impacted Party: Name, ID, contact info, and role (employee, contractor, visitor).
  • Witnesses: Names and contact information of anyone who saw what happened.
  • The Person Reporting: Name and title of the author.
  • Supervisor Notification: Name of the manager informed and the time they were told.

3. The Incident Description (The Narrative)

This is the core of the document. It should provide a chronological account of the events leading up to, during, and immediately following the incident. It must be factual, non-accusatory, and detailed.

4. Nature of Injury or Damage

If applicable, this section details the consequences.

  • Type of Injury: Laceration, burn, sprain, psychological trauma.
  • Part of Body Affected: Right hand, lower back, eyes.
  • Property Damage: Description of damaged equipment or structures and estimated repair costs.
  • First Aid/Medical Treatment: Was an ambulance called? Did the employee go to the ER? Was ice applied?

5. Root Cause Analysis

This section moves from what happened to why it happened.

  • Immediate Cause: The obvious reason (e.g., "floor was wet").
  • Underlying Cause: The systemic issue (e.g., "water cooler leaked because maintenance schedule was missed").
  • Contributing Factors: Weather, lighting, lack of training, equipment failure.

6. Immediate Actions Taken

What did the organization do right after the event?

  • Scene Securing: Barricades placed, equipment shut down.
  • Medical Aid: Administered by whom?
  • Cleanup: How was the mess addressed?
  • Notifications: Who else was called (police, fire department, executive team)?

7. Signature and Review

  • Reporter Signature: Verifies the information is true to the best of their knowledge.
  • Supervisor/Manager Signature: Indicates review and awareness.
  • Date of Signatures: Essential for audit trails.

How to Write a Incident Report (step by step)

Writing an incident report is a skill that requires objectivity, precision, and clarity. Emotional language, assumptions, and vagueness can render a report useless or even dangerous in a legal setting. Follow this step-by-step process to ensure your report stands up to scrutiny.

Step 1: Act Immediately and Secure the Scene

Before writing a single word, ensure the immediate safety of the environment. Administer first aid if necessary and call emergency services. Only once the scene is safe and stable should you begin the documentation process. If the incident involves a crime or a major hazard, preserve the scene—do not clean up or move equipment until it has been photographed and authorized for movement.

Step 2: Gather the Facts (Information Collection)

Start by filling out the "General Information" fields. The basics—the 5 Ws (Who, What, Where, When, Why)—are your framework.

  • Interview witnesses separately: Do not let witnesses confer, as this can taint their recollections. Ask open-ended questions like "What did you see?" rather than leading questions like "Did he slip on the oil?"
  • Take photos and videos: Visual evidence is indispensable. Take wide shots to show context and close-ups to show specific damage or hazards. Include a ruler or a common object (like a pen) in the photo to provide scale.
  • Check logs: Look at timekeeping systems, access logs, or server logs to establish precise timestamps.

Step 3: Draft the Narrative

When writing the description of the incident, adopt a neutral, journalistic tone.

  • Use active voice: "The operator pressed the wrong button" is better than "The wrong button was pressed." Active voice clarifies who did what.
  • Be chronological: Start from the beginning and move forward. Do not jump around in time.
  • Be specific: Instead of writing "The employee was injured," write "The employee sustained a 2-inch laceration on the left forearm."
  • Do not speculate: If you don't know why something happened, say so. Do not guess. "The cause of the slip is currently unknown" is an acceptable sentence; "The employee probably wasn't looking where he was going" is not.

Step 4: Determine the Root Cause

This is the analytical phase. Use a technique like the "5 Whys" to drill down to the source.

  1. Why did the machine stop? (Because it overheated.)
  2. Why did it overheat? (Because the cooling fan failed.)
  3. Why did the fan fail? (Because it was clogged with dust.)
  4. Why was it clogged? (Because there was no preventive maintenance schedule.)
  5. Why was there no schedule? (Because maintenance was outsourced and not specified in the contract.) This reveals that the fix isn't just fixing the fan, but revising the maintenance contract.

Step 5: Outline Corrective Actions

Based on the root cause, propose solutions. These should be SMART (Specific, Measurable, Achievable, Relevant, Time-bound).

  • Bad: "We need to be more careful."
  • Good: "All shift supervisors will complete a safety walkthrough of the loading dock by 8:00 AM daily, starting Monday."

Step 6: Review and Refine

Put the report aside for an hour if possible, then review it with fresh eyes. Check for:

  • Clarity: Will someone unfamiliar with the incident understand this?
  • Bias: Did you use emotional words like "negligent," "careless," or "stupid"? Remove them.
  • Completeness: Are all the names spelled correctly? Are the dates right?

Step 7: Submit and Distribute

Submit the report according to company protocol. This usually involves sending a digital copy to HR, the Safety Officer, and the direct manager. Ensure you keep a copy for your own records. If the incident involves external vendors, you may need to coordinate with your procurement team to review the relevant service level agreement.

Common Mistakes to Avoid

Even experienced professionals can fall into traps when writing incident reports. Being aware of these common pitfalls will help you produce higher-quality documents.

1. Opinions and Speculation The number one rule is to report facts, not opinions. Phrases like "The employee seemed drunk" or "The machine acted aggressively" are subjective. Instead, describe the observable evidence: "The employee smelled of alcohol and slurred their speech" or "The machine vibrated violently before seizing." Let the reader draw the conclusion.

2. Vague Language Ambiguity is the enemy of a good report. Words like "several," "later," "a while," "approximately," and "some" weaken the account.

  • Vague: "A while after the shift started, the fire alarm went off."
  • Precise: "At 09:15 AM, approximately 45 minutes after the shift started, the fire alarm activated."

3. Omitting "Near-Misses" Failing to report near-misses is a critical strategic error. Near-misses are free lessons; they tell you that your defenses almost failed. Ignoring them guarantees that you will not fix the hazard until someone actually gets hurt.

4. Delaying the Report Memory fades quickly. The best time to write a report is immediately after the incident, while details are fresh. If you wait three days, you will forget crucial nuances, and you may inadvertently fill in the gaps with assumptions.

5. Blaming and Shaming While it may be necessary to assign accountability later, the incident report is not the place for a witch hunt. If the report reads like an indictment of a specific employee, that employee may become defensive, uncooperative, or may threaten legal action against the company for defamation. Focus on the process, not the person.

6. Inconsistent Terminology If you use the term "Unit A" in the first paragraph, do not call it "the machine" or "the pump" later in the document. Consistent terminology prevents confusion, especially in technical reports.

7. Ignoring the "Why" Many reports stop at the description of the event. "Worker fell off ladder." Without the root cause analysis (e.g., "Ladder was missing a safety foot"), the report is merely a story, not a tool for prevention. Always include the underlying cause.

Tips for Success

To elevate the quality and utility of your incident reports, consider these professional tips.

Use Templates Do not reinvent the wheel every time an accident happens. Use a standardized template for different types of incidents (e.g., IT Security, Workplace Injury, Vehicle Accident). This ensures you never miss a critical data field and makes data aggregation easier for management.

Leverage Technology Consider using mobile reporting apps. These allow employees to take photos and dictate notes directly from the scene of the incident. Mobile forms can also auto-populate date, time, and GPS location data, increasing accuracy.

Maintain Objectivity through Grammar Be mindful of the connotations of words.

  • Use "collided with" instead of "smashed into."
  • Use "stated" instead of "claimed."
  • Use "employee did not follow procedure" instead of "employee violated policy."

Focus on the Chain of Events Visualizing the incident as a chain of events can help you understand how to break that chain in the future. If you can remove one link in the chain—better training, a guardrail, a warning light—the incident cannot happen again.

Keep it Confidential Incident reports contain sensitive personal information (medical details, home addresses). Handle these documents with strict confidentiality. Store them in secure, access-controlled folders, both physically and digitally.

Follow Up The incident report is just the beginning. The success of the process is measured by the implementation of the corrective actions. Schedule a follow-up review 30 days after the incident to verify that the proposed fixes have actually been put in place.

Training Ensure that all employees, not just managers, know how to submit an incident report. The person closest to the incident is often the best person to write the initial details. Conduct annual training workshops on report writing.

Example Incident Report

INCIDENT REPORT

Report ID:INC-2023-0842
Date of Incident:October 24, 2023
Time of Incident:10:15 AM
Location:Loading Dock, Warehouse 2, North Campus
Reported By:Sarah Jenkins, Logistics Manager
Date Reported:October 24, 2023

1. Description of Incident

At approximately 10:15 AM on October 24, 2023, temporary employee Mark Evans (ID: T-9921) was operating a forklift (Unit #FL-09) to stack pallets of inventory on Shelf B-12. While reversing the forklift to maneuver into position, the rear left tire struck a concrete loading bumper.

The impact caused a pallet of boxes (weighing approximately 400 lbs) to become unstable and shift. The pallet tilted and slid off the forks, striking Mr. Evans on the left shoulder.

2. Persons Involved

  • Injured Party: Mark Evans, Temporary Warehouse Associate.
  • Witness: Lisa Wong, Inventory Specialist (Witnessed event from 20 feet away).
  • Supervisor Notified: David Miller, Warehouse Director (Notified at 10:20 AM).

3. Injury/Damage Assessment

  • Injury: Mr. Evans reported immediate pain and limited mobility in the left shoulder. There was visible bruising but no open laceration.
  • Damage: The forklift sustained a scratch to the paint on the rear fender. Three boxes of inventory were crushed. Estimated value of damaged goods: $450.

4. Immediate Actions Taken

  1. Lisa Wong (Witness) immediately called for help on the radio.
  2. Forkift operation was ceased. The ignition key was removed to prevent unauthorized movement.
  3. Sarah Jenkins (Reporter) administered first aid, applying an ice pack to Mr. Evans' shoulder.
  4. Mr. Evans was transported to Urgent Care West by taxi for professional medical evaluation (departed 10:45 AM).
  5. The area was cordoned off with yellow caution tape.
  6. Photos of the scene, equipment, and Mr. Evans' shoulder were taken.

5. Root Cause Analysis

  • Immediate Cause: The forklift struck the bumper because the operator misjudged the distance while reversing.
  • Contributing Factor: The reverse alarm on Unit #FL-09 was found to be non-functional during the post-incident inspection (Tested by Maintenance at 11:00 AM).
  • Systemic Issue: The daily pre-shift inspection checklist for Unit #FL-09 was signed by the previous shift operator, but the "Reverse Alarm" box was checked as "Pass" without verification.

6. Corrective Actions

  1. Immediate: Unit #FL-09 has been "Red Tagged" and removed from service until the reverse alarm is repaired.
  2. Short Term: Review pre-shift inspection protocols with all temporary staff by end of week.
  3. Long Term: Install a sensor-based backup camera system on all heavy machinery in Warehouse 2.

Signatures:

  • Reporter: Sarah Jenkins (Date: 10/24/23)
  • Supervisor: David Miller (Date: 10/24/23)
  • Employee (If available): N/A (Employee at medical facility)

Frequently Asked Questions

1. Who is responsible for writing an incident report? Typically, the responsibility falls to the supervisor or manager on duty at the time of the incident. However, if an employee is involved, they are often encouraged to write a "witness statement" or a personal account that is then attached to the official report. In IT security, the system administrator or the Chief Information Security Officer (CISO) usually handles the reporting.

2. How long do I have to file an incident report? Timeliness is critical. For minor incidents, the report should ideally be completed within 24 hours. For serious injuries or major security events, the preliminary report should be filed immediately (within hours), followed by a more detailed final report within 24 to 48 hours. Regulatory bodies often have strict deadlines; for example, OSHA requires reporting of fatalities within 8 hours.

3. Can I edit an incident report after it has been submitted? Yes, but it must be done carefully. You should never alter the original facts of an event. If you remember new details later, you should submit an "addendum" or "supplemental report" rather than changing the original document. This maintains the integrity of the timeline and prevents accusations of falsifying records.

4. What if the person involved refuses to sign the report? The report is a record of the company’s findings, not necessarily a contract that requires the employee's agreement. If an employee refuses to sign, you should note on the signature line "Refused to sign" and have a second manager witness this note. However, you should explain to the employee that signing does not admit guilt; it merely acknowledges that they have seen the report.

5. Should I mention if the employee was violating a company policy? Yes, if it is a fact. If the employee was not wearing required safety glasses, and that fact is relevant to the injury, it must be included. However, stick to the factual description of the violation ("Employee was not wearing safety glasses as mandated by Handbook Section 4.2") rather than character judgment ("Employee was reckless").

6. Is an incident report the same as an accident report? The terms are often used interchangeably, but there is a subtle difference. An "accident" implies an unforeseeable, unavoidable event. An "incident" is a broader term that encompasses accidents but also includes near-misses and intentional acts (like sabotage or violence). In business, "incident report" is generally preferred because it is neutral and non-judgmental.

Ready to create your document?

Use our free template or generate a custom version tailored to your needs.

Use Free Template
Create your custom version — free to start

20 free credits on signup — no card needed

This document is for informational purposes and serves as a general guide.