Breaking

Site add
blog single post
Reporting

Root cause analysis after investigation findings

Why findings alone rarely fix anything

A workplace investigation has done its job when it establishes what happened, who was involved and whether policies were breached. That is a significant achievement, and it deserves proper recognition. But if the report lands on a desk, prompts a disciplinary outcome and then quietly disappears into a filing system, you can be fairly confident the same issue will surface again within eighteen months.

Root cause analysis is the step that turns an investigation from a record of failure into a genuine improvement tool. It asks a different question from the one the investigation itself answered. Rather than "who did what, and was it a breach?", it asks "what conditions made this outcome likely, and what would need to change for it to be unlikely in future?" That shift in focus is uncomfortable for some organisations, because it tends to spread responsibility wider than a single individual. But it is also where the real value sits.

Separating proximate causes from root causes

Most investigation reports identify what we might call proximate causes: the immediate action or omission at the centre of the complaint. These matter, but they are rarely the whole story.

Consider a familiar example. A manager approves a supplier payment without completing the required checks. The proximate cause is straightforward: the manager did not follow the approval process. A root cause analysis would go further and ask:

  • Was a second-approval step required by the finance system, or does it permit single sign-off?
  • When was the approval process last communicated to managers, and in what format?
  • Was the manager under unusual pressure that week, and is that pressure structural rather than personal?
  • Have other managers made similar approvals without anyone noticing?
  • Does the policy itself reflect how the work is actually done?

Each of these questions points towards a fixable condition. None of them excuses the individual behaviour, but together they explain why the behaviour was possible, and they give you somewhere practical to intervene.

Three lenses: systems, culture and training

Root causes tend to cluster around three areas, and it helps to examine each deliberately rather than relying on whichever one comes to mind first.

Systems covers processes, controls, IT configuration, staffing levels and workload design. If a control can be bypassed without detection, that is a systems issue regardless of who bypassed it. If a team is routinely working beyond capacity, no amount of individual diligence will reliably prevent shortcuts.

Culture covers what people believe is genuinely expected of them, as opposed to what the policy says. Does a manager feel able to raise a concern about a senior colleague? Is speaking up treated as helpful or as troublemaking? Culture is often the hardest lens to look through, because the evidence is anecdotal and the findings can feel personal to leaders. It is also frequently the most decisive.

Training covers knowledge, confidence and skill. A common finding is that training was delivered once, at induction, and never revisited. Another is that training covered the policy but not the awkward judgement calls people actually face. Both are fixable.

Looking through all three lenses usually reveals that no single change would have prevented the incident on its own. That is itself a useful finding, because it means single measures are unlikely to be sufficient now.

Techniques that keep the analysis honest

You do not need elaborate methodology. A few structured approaches, applied with discipline, will do the job.

  • Five whys. Ask "why?" repeatedly until you reach a condition rather than a person. Stop when the answer is something you can actually change.
  • Timeline mapping. Lay out events, decisions and communications in sequence. Gaps and contradictions often appear that no single interview revealed.
  • Contributing factors grid. List each factor and rate its influence as high, medium or low. This prevents the loudest factor from crowding out the quieter ones.
  • Counterfactual testing. For each proposed root cause, ask whether removing it would plausibly have changed the outcome. If not, it may be background rather than cause.

Keep a written record of what you considered and discounted, along with your reasoning. It demonstrates rigour and helps if recommendations are later challenged.

Turning analysis into recommendations that stick

Recommendations are where many otherwise strong reports lose their impact. Vague intentions such as "remind all staff of the policy" or "ensure greater awareness" rarely change anything. Good recommendations share a few characteristics: they are specific, they name an owner, they are resourced, they carry a deadline, and they have a review date.

It also helps to separate two categories. Corrective actions address the specific incident: fixing a record, retraining a team, adjusting a contract. Preventive actions address the underlying condition across the organisation: redesigning an approval step, changing how concerns are escalated, refreshing training annually with scenario-based content. Both are needed, but preventive actions are the ones that reduce future risk.

Be realistic about capacity. Five well-implemented recommendations will outperform twenty that nobody owns. Where a recommendation requires budget or senior sign-off, say so explicitly rather than leaving it implied.

Making root cause analysis routine

The organisations that handle this best do not treat root cause analysis as an exceptional exercise reserved for serious cases. They build it into their standard investigation close-out, with a short template, a named reviewer and a standing agenda item at a quarterly people or risk meeting.

Review your actions at three, six and twelve months. Feed the findings into your policy cycle, your induction content and your training needs analysis. Over time, patterns emerge across apparently unrelated cases, and those patterns are usually the most valuable thing your investigation process produces.

Blame closes a case. Analysis closes a gap. Done thoughtfully, and with a measure of compassion for everyone involved, it is how a difficult episode becomes the reason things genuinely improve.

Comments