Incident Report Best Practices: Facts, Evidence, Witnesses and Follow-Up
Incident report best practices for recording facts, immediate response, evidence, witnesses, contributing factors, follow-up actions and review criteria.

An incident report should preserve facts before memory, evidence and context disappear. It is not a place to speculate, assign blame or quietly rewrite what happened. A useful report records what is known, what was done immediately, what evidence exists, who can help clarify the event and what follow-up actions are required.
This guide uses a consulting scenario, but the principles apply widely. A consultant preparing a strategy review accidentally shares a folder link containing client interview notes with a person outside the approved project team. The incident may involve confidentiality, client trust, personal data and delivery risk. The report needs to capture the facts without turning into a legal conclusion or a defensive narrative.
OSHA encourages employers to investigate incidents and close calls to identify hazards and corrective actions, and it recommends focusing on root causes rather than fault or blame OSHA incident investigation. For information incidents, jurisdiction matters. In the UK, the ICO says organizations must assess the likely risk to people's rights and freedoms after a personal data breach and report notifiable UK GDPR breaches within the required timeframe ICO personal data breach guide. Your incident report should support the approved reporting process, not replace it.
Record incident facts separately from assumptions
Start with facts that can be verified:
- date and time discovered
- date and time the event occurred, if known
- location or system
- people or roles involved
- activity underway
- what was observed
- who was notified
- immediate restrictions or containment
Weak wording:
The analyst carelessly sent confidential files to the wrong person.
That assigns blame and may be wrong.
Stronger wording:
At 10:15 on [date], [name or role] discovered that a project folder link for [Client] strategy review had been sent to [recipient role] outside the approved project team. The link appeared in email [reference]. At 10:25, the sender notified the engagement lead and information security contact. Access was removed at 10:35, pending review of access logs.
This wording records facts and immediate response. It leaves conclusions for the review.
Capture the immediate response
The immediate response section should show what was done to protect people, information, services or property. It should not wait for the full investigation.
For the consulting folder incident:
| Time | Action | Owner | Evidence |
|---|---|---|---|
| 10:25 | Engagement lead notified | Sender | |
| 10:30 | Information security contact notified | Engagement lead | Ticket |
| 10:35 | Folder access removed | Project admin | Access log |
| 10:50 | Recipient asked not to access or forward material | Engagement lead | |
| 11:30 | Access log review started | Security contact | Ticket note |
OSHA's incident investigation guide materials emphasize corrective actions that address root causes, not only immediate fixes OSHA root cause fact sheet. Still, immediate containment comes first. In an information incident, that might mean removing access and preserving logs before debating why the link was sent.
If the immediate response is incomplete, say so. "Access log review pending" is better than leaving the reader to assume the review happened. Incident reports are allowed to have open questions as long as those questions have owners.
Do not delay obvious containment while waiting for perfect information. A report can be updated, but lost evidence, uncontrolled access or continued exposure may be hard to repair later.
Time-stamped notes make later reconstruction far easier.
Preserve evidence and witness information
Evidence should be preserved without alteration. For a workplace injury, evidence may include photographs, equipment records and witness accounts. For a consulting confidentiality incident, evidence may include emails, access logs, folder permissions, project instructions and witness notes.
Record:
- what evidence exists
- where it is stored
- who controls access
- whether it contains personal or confidential information
- whether the original has been preserved
- who collected it and when
Witness notes should distinguish between what the person saw and what they think happened. Use neutral prompts:
- What did you see or receive?
- When did you become aware of it?
- What action did you take?
- Did you forward, save or delete anything?
- Who else may have relevant information?
For OSHA-reportable workplace incidents in the United States, OSHA materials list information that may be collected during investigations, including narrative sequence, task characteristics, supervision and corrective actions OSHA reporting procedure memo. For consulting incidents, adapt the principle: record enough sequence and context for a reviewer to understand what happened.
Analyze contributing factors without guessing
A useful incident report asks why the incident was possible. It does not stop at "human error."
For the folder incident, contributing factors might include:
- project folders with similar names
- unclear rule for external sharing
- default link setting allowed broad access
- deadline pressure before client workshop
- no review step before sending interview material
Write findings carefully:
The review identified that the project workspace allowed link sharing outside the approved team. The analyst used that setting while preparing workshop material. The report has not determined whether any unauthorized person accessed the interview notes; access logs are still under review.
That wording is honest about uncertainty. It also identifies a system condition that can be corrected.
Assign follow-up actions and closure criteria
Follow-up actions need owner, due date, evidence and closure approval.
Example:
| Action | Owner | Due date | Evidence | Closure reviewer |
|---|---|---|---|---|
| Complete access log review | Security contact | [date] | Log summary | Information security lead |
| Notify client sponsor under engagement procedure if required | Engagement partner | [date] | Notification record | Managing partner |
| Change default sharing setting for client folders | IT admin | [date] | Configuration screenshot | Security lead |
| Brief project team on sharing rule | Engagement lead | [date] | Attendance record | Delivery director |
Closure should not mean "we wrote the report." It means the authorized reviewer has checked required actions, remaining restrictions and whether any further reporting is needed.
Draft language:
The incident is closed only when immediate containment is complete, required notifications have been considered under the approved procedure, corrective actions are verified and the authorized reviewer records any remaining restrictions.
Review criteria before approval
Before approving an incident report, check:
- Facts: Are date, time, location, activity and people or roles recorded?
- Neutrality: Does the report avoid blame language and unsupported conclusions?
- Immediate response: Are containment and notifications documented?
- Evidence: Are records preserved and access controlled?
- Witnesses: Are witness notes separated from assumptions?
- Contributing factors: Does the report look beyond the immediate act?
- Actions: Does every follow-up have an owner, due date and evidence?
- Jurisdiction: Have regulated reporting obligations been routed to the approved owner?
- Closure: Is closure approved by someone with authority?
If you want a structured starting document, the consulting incident report template is an editable Word file with sections for facts and immediate response, impact and evidence, investigation, actions, preparation checks and approval. Use it to organize the record, then follow the reporting procedure that applies to your organization and jurisdiction.
Last updated: September 26, 2026
Frequently Asked Questions
Related Articles
Audit Checklist Best Practices
Best practices for audit checklists, including scope, evidence, findings, actions, closure review, failure modes and sample wording.
Audit Checklist Checklist: Review Your Audit Form Before You Use It
A practical audit checklist checklist with decision gates for scope, evidence, findings, actions and closure review.
Audit Checklist Examples: Scope, Evidence, Findings and Closure
Audit checklist examples for consulting work, covering audit scope, evidence to inspect, findings and actions, closure review and practical draft wording.
Business Continuity Plan Best Practices for Consulting Teams
Business continuity plan best practices for consulting teams, including critical services, recovery priorities, communications, exercises and review criteria.
Business Continuity Plan Checklist for Consulting Teams
A practical business continuity plan checklist for consulting work, covering critical services, recovery priorities, communications, exercises and review criteria.
Business Continuity Plan Examples: Consulting Scenarios and Recovery Priorities
Business continuity plan examples for consulting teams, with critical services, recovery priorities, communications, exercises and review criteria.