Incident Report Best Practices: Facts, Evidence, Witnesses and Follow-Up

Incident report best practices for recording facts, immediate response, evidence, witnesses, contributing factors, follow-up actions and review criteria.

DocStaple editorial team
September 26, 20266 min read
A document improves through review: Incident facts; Immediate response; Evidence and witnesses; Follow-up actions.

An incident report should preserve facts before memory, evidence and context disappear. It is not a place to speculate, assign blame or quietly rewrite what happened. A useful report records what is known, what was done immediately, what evidence exists, who can help clarify the event and what follow-up actions are required.

This guide uses a consulting scenario, but the principles apply widely. A consultant preparing a strategy review accidentally shares a folder link containing client interview notes with a person outside the approved project team. The incident may involve confidentiality, client trust, personal data and delivery risk. The report needs to capture the facts without turning into a legal conclusion or a defensive narrative.

OSHA encourages employers to investigate incidents and close calls to identify hazards and corrective actions, and it recommends focusing on root causes rather than fault or blame OSHA incident investigation. For information incidents, jurisdiction matters. In the UK, the ICO says organizations must assess the likely risk to people's rights and freedoms after a personal data breach and report notifiable UK GDPR breaches within the required timeframe ICO personal data breach guide. Your incident report should support the approved reporting process, not replace it.

Record incident facts separately from assumptions

Start with facts that can be verified:

  • date and time discovered
  • date and time the event occurred, if known
  • location or system
  • people or roles involved
  • activity underway
  • what was observed
  • who was notified
  • immediate restrictions or containment

Weak wording:

The analyst carelessly sent confidential files to the wrong person.

That assigns blame and may be wrong.

Stronger wording:

At 10:15 on [date], [name or role] discovered that a project folder link for [Client] strategy review had been sent to [recipient role] outside the approved project team. The link appeared in email [reference]. At 10:25, the sender notified the engagement lead and information security contact. Access was removed at 10:35, pending review of access logs.

This wording records facts and immediate response. It leaves conclusions for the review.

Capture the immediate response

The immediate response section should show what was done to protect people, information, services or property. It should not wait for the full investigation.

For the consulting folder incident:

TimeActionOwnerEvidence
10:25Engagement lead notifiedSenderEmail
10:30Information security contact notifiedEngagement leadTicket
10:35Folder access removedProject adminAccess log
10:50Recipient asked not to access or forward materialEngagement leadEmail
11:30Access log review startedSecurity contactTicket note

OSHA's incident investigation guide materials emphasize corrective actions that address root causes, not only immediate fixes OSHA root cause fact sheet. Still, immediate containment comes first. In an information incident, that might mean removing access and preserving logs before debating why the link was sent.

If the immediate response is incomplete, say so. "Access log review pending" is better than leaving the reader to assume the review happened. Incident reports are allowed to have open questions as long as those questions have owners.

Do not delay obvious containment while waiting for perfect information. A report can be updated, but lost evidence, uncontrolled access or continued exposure may be hard to repair later.

Time-stamped notes make later reconstruction far easier.

Preserve evidence and witness information

Evidence should be preserved without alteration. For a workplace injury, evidence may include photographs, equipment records and witness accounts. For a consulting confidentiality incident, evidence may include emails, access logs, folder permissions, project instructions and witness notes.

Record:

  • what evidence exists
  • where it is stored
  • who controls access
  • whether it contains personal or confidential information
  • whether the original has been preserved
  • who collected it and when

Witness notes should distinguish between what the person saw and what they think happened. Use neutral prompts:

  • What did you see or receive?
  • When did you become aware of it?
  • What action did you take?
  • Did you forward, save or delete anything?
  • Who else may have relevant information?

For OSHA-reportable workplace incidents in the United States, OSHA materials list information that may be collected during investigations, including narrative sequence, task characteristics, supervision and corrective actions OSHA reporting procedure memo. For consulting incidents, adapt the principle: record enough sequence and context for a reviewer to understand what happened.

Need a ready-made incident report template for your consulting?

Download a pre-built document with industry-specific categories, sections, and formatting.

Analyze contributing factors without guessing

A useful incident report asks why the incident was possible. It does not stop at "human error."

For the folder incident, contributing factors might include:

  • project folders with similar names
  • unclear rule for external sharing
  • default link setting allowed broad access
  • deadline pressure before client workshop
  • no review step before sending interview material

Write findings carefully:

The review identified that the project workspace allowed link sharing outside the approved team. The analyst used that setting while preparing workshop material. The report has not determined whether any unauthorized person accessed the interview notes; access logs are still under review.

That wording is honest about uncertainty. It also identifies a system condition that can be corrected.

Assign follow-up actions and closure criteria

Follow-up actions need owner, due date, evidence and closure approval.

Example:

ActionOwnerDue dateEvidenceClosure reviewer
Complete access log reviewSecurity contact[date]Log summaryInformation security lead
Notify client sponsor under engagement procedure if requiredEngagement partner[date]Notification recordManaging partner
Change default sharing setting for client foldersIT admin[date]Configuration screenshotSecurity lead
Brief project team on sharing ruleEngagement lead[date]Attendance recordDelivery director

Closure should not mean "we wrote the report." It means the authorized reviewer has checked required actions, remaining restrictions and whether any further reporting is needed.

Draft language:

The incident is closed only when immediate containment is complete, required notifications have been considered under the approved procedure, corrective actions are verified and the authorized reviewer records any remaining restrictions.

Review criteria before approval

Before approving an incident report, check:

  • Facts: Are date, time, location, activity and people or roles recorded?
  • Neutrality: Does the report avoid blame language and unsupported conclusions?
  • Immediate response: Are containment and notifications documented?
  • Evidence: Are records preserved and access controlled?
  • Witnesses: Are witness notes separated from assumptions?
  • Contributing factors: Does the report look beyond the immediate act?
  • Actions: Does every follow-up have an owner, due date and evidence?
  • Jurisdiction: Have regulated reporting obligations been routed to the approved owner?
  • Closure: Is closure approved by someone with authority?

If you want a structured starting document, the consulting incident report template is an editable Word file with sections for facts and immediate response, impact and evidence, investigation, actions, preparation checks and approval. Use it to organize the record, then follow the reporting procedure that applies to your organization and jurisdiction.

Last updated: September 26, 2026

Frequently Asked Questions

Get the Consulting Incident Report Template

Download a pre-built incident report template with consulting-specific sections, wording, and drafting guidance.

Editable Word files. One-time purchase.