Incident Report Checklist for Consulting Teams
An incident report checklist covering incident facts, immediate response, evidence and witnesses, follow-up actions and review criteria.

An incident report checklist helps the team capture facts before memories fade and records move. The goal is not to write a dramatic narrative. It is to record what happened, what was done immediately, what evidence exists, who was affected and what actions will prevent recurrence.
Use this consulting scenario. During a strategy review, an analyst accidentally shares a draft interview summary with a client distribution list that includes people who should not see employee comments. No one is physically injured, but there may be confidentiality, client relationship and data handling consequences. The incident report must be factual, careful and useful for follow-up.
Record incident facts first
Start with verified facts. Do not jump to cause or blame. OSHA encourages employers to investigate incidents and close calls, and says investigations should identify hazards, program shortcomings and corrective actions OSHA. OSHA also warns that focusing only on carelessness or failure to follow a rule can miss underlying causes OSHA.
Facts checklist:
- date and time discovered;
- date and time occurred, if known;
- location or system;
- people involved by role;
- immediate description of what happened;
- information, service, property or people affected;
- source of each fact;
- unknowns that require follow-up.
Draft language:
On [date] at approximately [time], [role] sent draft interview summary file [file name/version] to [distribution list]. The file contained comments from employee interviews for the [project name] strategy review. The issue was discovered by [role] at [time] when [source].
Review criterion: every factual statement should be traceable to a record, witness or direct observation.
Use a separate field for impact that is "known so far." Early reports often overstate or understate impact because the team wants closure. A better report says what is known, what is not yet known and who is checking. For the email incident, the known impact may be the number of unintended recipients; the unknown may be whether any recipient opened or downloaded the file.
Capture immediate response
Immediate response is what the team did to control harm. In a consulting confidentiality incident, this may include recalling a message, asking recipients not to open or forward the file, removing access, notifying the engagement lead and preserving evidence. Do not invent regulatory deadlines in the report; instead, escalate to the person responsible for legal, client or privacy reporting decisions.
Checklist:
- Was there any immediate danger to people?
- Was access restricted or removed?
- Were recipients contacted?
- Was the client sponsor or internal owner notified?
- Were legal, privacy, HR, safety or insurance contacts alerted where needed?
- Was evidence preserved before files were altered?
Draft language:
Immediate action taken: external sharing was disabled for the file at [time]. The engagement lead instructed unintended recipients not to open, copy or forward the attachment and asked them to confirm deletion. The privacy and legal review contacts were notified to determine any further reporting obligations.
Review criterion: the report should show what was done to stabilize the situation, not only what went wrong.
Record the timing of each response. The sequence helps later reviewers see whether the team acted promptly and whether any delay had a practical effect. Timing also helps separate discovery time from occurrence time, which may differ when an incident is found hours or days after it happened.
Preserve evidence and witness information
Evidence should be preserved without altering the underlying record. For a consulting incident, evidence may include email headers, access logs, file versions, chat messages, meeting notes, screenshots, recipient confirmations and the project procedure in effect at the time.
OSHA's incident investigation materials describe collecting information about the sequence of events, task, conditions, supervision, causal factors and corrective actions in workplace incidents OSHA reporting memo. That source addresses OSHA reporting investigations, but the evidence categories are useful for structuring a factual record.
Evidence checklist:
- evidence item;
- source;
- custodian or owner;
- location stored;
- access restrictions;
- date preserved;
- relevance.
Witness checklist:
- name and role;
- what they observed;
- when they were interviewed;
- whether the statement is direct observation or secondhand;
- confidentiality restrictions.
Draft language:
Evidence retained: sent email metadata, recipient list, file version history, access log from the project workspace and recipient deletion confirmations. Evidence is stored in [restricted location] with access limited to [roles].
Review criterion: do not paste sensitive personal or client information into the incident report unless needed. Reference secure evidence locations instead.
If witness details are sensitive, store them with access controls and refer to roles in the main report. The incident report should be useful to managers who need to approve actions, but it should not become a new source of unnecessary personal data exposure.
Analyze contributing factors without blame
After facts and response, analyze why the incident happened. OSHA says effective investigations should look beyond immediate causes to underlying or root causes and identify systemic changes OSHA. For this consulting incident, possible contributing factors might include confusing distribution list names, lack of external-send warning, no peer check for sensitive summaries, or deadline pressure.
Use careful wording:
Contributing factor: the project distribution list and client sponsor list had similar names in the email system. The analyst selected the wrong list while sending a draft summary under time pressure.
Avoid:
Cause: analyst negligence.
The second version may be unsupported and does not help improve controls.
Checklist:
- What task was being performed?
- What procedure applied?
- Were tools or naming conventions confusing?
- Were workload, training or supervision factors relevant?
- Did existing controls fail or not exist?
- What uncertainty remains?
Review criterion: every conclusion should be supported by facts already recorded or clearly marked as requiring further investigation.
Assign follow-up actions and closure
Follow-up actions turn the report into prevention. They should include immediate fixes and longer-term improvements.
Action examples:
- rename distribution lists to reduce confusion;
- disable autocomplete for sensitive project groups where possible;
- require workspace links instead of attachments for interview summaries;
- add a pre-send check for confidential material;
- brief the project team on updated sharing rules;
- review whether any contractual, privacy or client notification steps are required.
Draft action table language:
Action: update project sharing procedure to require restricted workspace links for interview summaries. Owner: engagement lead. Due: [date]. Evidence: revised procedure and team briefing record. Closure reviewer: [role].
HSE's investigation guidance for workplace incidents emphasizes understanding what happened and taking steps through an investigation process HSE. Whatever framework you use, closure should require evidence that actions were completed or intentionally deferred by an authorized person.
Review criterion: no action should be closed simply because it was assigned. Close it when evidence shows the control is in place or an authorized reviewer accepts the remaining risk.
Keep the report controlled and usable
Incident reports can contain sensitive information. Limit distribution, store the report securely and separate factual records from privileged legal advice where your organization requires that process. Escalate promptly if the incident may trigger regulatory, contractual, employment, safety, privacy or insurance duties.
For a structured starting point, the consulting incident report template includes editable sections for facts and immediate response, impact and evidence, investigation and contributing factors, actions and closure, preparation checks and approval. Use it as a record structure, then fill it with verified facts from the incident.
Final checklist:
- facts are separated from assumptions;
- immediate response is recorded;
- evidence and witnesses are controlled;
- contributing factors are supported;
- actions have owners and evidence;
- closure is approved by the right person.
An incident report is useful when a future reviewer can understand what happened, what changed and what risk remains.
Last updated: September 26, 2026
Frequently Asked Questions
Related Articles
Audit Checklist Best Practices
Best practices for audit checklists, including scope, evidence, findings, actions, closure review, failure modes and sample wording.
Audit Checklist Checklist: Review Your Audit Form Before You Use It
A practical audit checklist checklist with decision gates for scope, evidence, findings, actions and closure review.
Audit Checklist Examples: Scope, Evidence, Findings and Closure
Audit checklist examples for consulting work, covering audit scope, evidence to inspect, findings and actions, closure review and practical draft wording.
Business Continuity Plan Best Practices for Consulting Teams
Business continuity plan best practices for consulting teams, including critical services, recovery priorities, communications, exercises and review criteria.
Business Continuity Plan Checklist for Consulting Teams
A practical business continuity plan checklist for consulting work, covering critical services, recovery priorities, communications, exercises and review criteria.
Business Continuity Plan Examples: Consulting Scenarios and Recovery Priorities
Business continuity plan examples for consulting teams, with critical services, recovery priorities, communications, exercises and review criteria.