Incident Report Examples: Draft Wording for Facts, Response, Evidence and Follow-Up
Incident report examples for a consulting engagement, with draft wording for incident facts, immediate response, evidence and witnesses, and follow-up actions, plus a review checklist to use before you close the report.

An incident report is the written record of something that went wrong or nearly did: what happened, what was done, what the evidence shows and what will change. Examples help because the hard part is rarely the form. It is deciding what belongs in each field, and how to word it so a later reader can tell fact from guesswork.
This guide walks through a fictional consulting example and breaks the report into four parts: incident facts, immediate response, evidence and witnesses, and follow-up actions. Each part has draft wording you can adapt and a check you can apply. All names, dates and numbers are placeholders. Replace them with facts you have verified.
The scenario used throughout
A small consulting team is running a six-week strategy review for a regional distributor. On day 12, a team member sends the weekly interview summary to the client's project mailbox. The attachment includes a tab of notes from a second client's engagement, which was left in a working file by mistake. The sender notices within the hour and tells the engagement lead.
No one was hurt and no systems failed, but confidential material has gone outside the project it belongs to. That makes it worth recording properly. The same four-part structure works for a safety event, a service failure or a security event; only the specific fields change.
Why the structure matters
Two US government sources show the same pattern from different angles, and both are useful as drafting guidance even though neither is written for consulting firms.
OSHA's page on incident investigation says investigations give employers and workers the opportunity to identify hazards in their operations and shortcomings in their safety and health programs. It also says teams should look beyond the immediate causes of an incident. That is the difference between a report that says "an attachment was sent by mistake" and one that asks why the working file held another client's notes in the first place.
The FTC's Data Breach Response Guide for Business is aimed at breaches of personal information, but its sequence is transferable: mobilise the right people quickly, secure the affected areas, interview the people who discovered the problem, document the investigation and do not destroy evidence.
Both are US sources. Which duties actually apply to your incident, and by when, depends on the jurisdiction, your contracts and the kind of information involved.
Part 1: Incident facts
The facts section states what is known, when it was known and how. Keep it short, chronological and free of adjectives.
Draft wording:
Reference: [Incident number]. Reported by: [name, role]. Date and time reported: [date, time, time zone].
What happened. On [date] at approximately [time], [name] sent the weekly interview summary for the [engagement name] engagement to [client mailbox]. The attachment contained an additional worksheet ("[tab name]") with notes belonging to a different engagement. The sender identified this at approximately [time] and notified [engagement lead] at [time].
Known. Recipients of the message: [names or distribution list]. Attachment size and file name: [details]. The message was sent from [account].
Not yet known. Whether the attachment has been opened, forwarded or saved by any recipient; whether the worksheet contains personal information.
The "not yet known" line is the most useful in the whole report. Writing down what you have not established stops it being quietly treated as a fact by the second draft.
Watch for conclusions disguised as facts. "The analyst carelessly attached the wrong file" is a judgment. "The attached file contained a worksheet from another engagement" is a fact. Add "per [name]" where a fact comes from one person and has not been checked against a record.
Facts check: Could a reader who was not there tell which statements are verified, which come from one person and which are still unknown?
Part 2: Immediate response
This section records what was done straight away to stop the problem getting worse. If anyone is at risk, follow your approved emergency arrangements before doing any administrative recording. The paperwork comes second.
The FTC guide's advice to mobilise a response team right away to prevent additional data loss, and to remove improperly posted information, translates here into: contain first, then write it up. Draft wording:
Containment actions. [Time]: [Engagement lead] asked the client's project contact by phone to delete the message without opening the attachment and to confirm in writing. [Time]: the client contact confirmed deletion by email. [Time]: [Name] recalled the message from the sending account where supported and listed the actions taken.
People notified. [Role/name] at [time]; [role/name] at [time]. Reason: [company policy or contract clause].
Decisions pending. Whether the affected engagement's client must be told is with [named decision-maker] for review against the relevant contract by [date].
The last line matters. Decisions about notifying clients, insurers, regulators or affected individuals can carry legal deadlines, and the person writing the incident report is often not the right person to make them. Assign the decision to a named owner and record the date. Have contract and legal duties reviewed by a qualified professional; a report template cannot determine them for you.
Response check: Is every action time-stamped, attributed to a person and clearly separated from decisions that are still open?
Part 3: Evidence and witnesses
Evidence is what lets someone else reconstruct events later without relying on memory. The FTC's guidance is direct about two habits that apply well beyond data incidents: interview the people who discovered the problem and anyone else who may know about it, and do not destroy evidence while investigating or fixing.
Draft wording:
Evidence held. (1) Copy of the sent message with headers, stored at [location] with access limited to [roles]. (2) File version history for [file name]. (3) Client's written deletion confirmation. Custody: copies were saved by [name] on [date] and have not been edited.
Witnesses. [Name, role]: sender, identified the error. [Name, role]: engagement lead, received the report. Statements were taken on [date] by [name], recorded as [notes/written statement] and stored at [location].
Access restriction. Witness details and the affected worksheet are visible only to [named roles] until the review is closed.
Preserve, don't tidy: do not edit, rename or delete original files to make the record neater. Work from copies and say so. Statements can contain personal information, so restrict access. Open questions such as "walk me through how the summary was assembled" invite a fuller account than "why did you attach the wrong file?"
Evidence check: Can you point to where each piece of evidence is kept, who has touched it and who is allowed to see it?
Part 4: Follow-up actions
An incident is not closed when the immediate problem stops. It closes when the conditions that let it happen have been dealt with. OSHA's investigation guidance says investigators should look beyond the immediate causes, and that investigations focused on root causes rather than fault or blame also improve workplace morale and increase productivity.
For the scenario, contributing factors might include the following, each recorded as something to test rather than assume:
- Working files hold material from more than one engagement.
- No pre-send check for attachments.
- No rule about which folder templates and summaries are built from.
"Contributing factor to be confirmed by review" starts an investigation. "Cause: human error" ends one without learning anything.
Draft wording for the action table:
| Action | Owner | Due | Evidence of completion |
|---|---|---|---|
| Separate working files by engagement in the document store | [Engagement lead] | [Date] | Folder structure screenshot and access list |
| Add a pre-send attachment check to the client delivery procedure | [Practice lead] | [Date] | Revised procedure, version number and approval record |
| Brief the team on the revised procedure | [Engagement lead] | [Date] | Attendance record |
| Confirm notification decision against contract terms | [Named decision-maker] | [Date] | Written decision |
| Review whether corrective actions worked | [Reviewer, not the engagement lead] | [Date] | Review note |
Each action names one owner, a date and something a reviewer can inspect. "Improve awareness" fails all three.
Closure statement. [Reviewer] confirmed on [date] that the actions above are complete and effective, and records these continuing restrictions: [restrictions or "none"]. This report is closed.
Closure check: Would a reviewer who was not involved accept the evidence of completion for every action, and has anyone other than the incident owner signed the closure?
Review the report before you close it
Use these prompts on a read-through by someone who was not involved:
- Facts: Are verified facts, single-source statements and unknowns clearly separated?
- Tone: Does the report avoid blame, and describe conditions rather than character?
- Timing: Do all entries have times, and is the sequence consistent?
- Response: Are containment actions separated from decisions still awaiting an owner?
- Evidence: Is each item located, protected and unchanged?
- Witnesses: Are statements stored securely with restricted access?
- Actions: Does each action have one owner, one date and proof of completion?
- Notification: Has a qualified person reviewed any legal, contractual or regulatory notification duties?
- Closure: Has someone other than the author confirmed completion?
Adapt the examples in a structured Word draft
If you would rather not rebuild these sections for every event, the consulting incident report template is an editable Word file organised around facts and immediate response, impact and evidence, investigation and contributing factors, and actions and closure, plus preparation and approval sections. It is a starting draft, not a guarantee that any report is complete, compliant or legally sufficient.
If the incident touches contract terms, check the wording in your consulting statement of work or engagement letter.
Sources: Incident Investigation, OSHA, Data Breach Response: A Guide for Business, FTC
Last updated: September 26, 2026
Frequently Asked Questions
Related Articles
Audit Checklist Best Practices
Best practices for audit checklists, including scope, evidence, findings, actions, closure review, failure modes and sample wording.
Audit Checklist Checklist: Review Your Audit Form Before You Use It
A practical audit checklist checklist with decision gates for scope, evidence, findings, actions and closure review.
Audit Checklist Examples: Scope, Evidence, Findings and Closure
Audit checklist examples for consulting work, covering audit scope, evidence to inspect, findings and actions, closure review and practical draft wording.
Business Continuity Plan Best Practices for Consulting Teams
Business continuity plan best practices for consulting teams, including critical services, recovery priorities, communications, exercises and review criteria.
Business Continuity Plan Checklist for Consulting Teams
A practical business continuity plan checklist for consulting work, covering critical services, recovery priorities, communications, exercises and review criteria.
Business Continuity Plan Examples: Consulting Scenarios and Recovery Priorities
Business continuity plan examples for consulting teams, with critical services, recovery priorities, communications, exercises and review criteria.