Incident Report Examples: Draft Wording for Facts, Response, Evidence and Follow-Up

Incident report examples for a consulting engagement, with draft wording for incident facts, immediate response, evidence and witnesses, and follow-up actions, plus a review checklist to use before you close the report.

DocStaple editorial team
September 26, 20268 min read
The sections behind a useful document: Incident facts; Immediate response; Evidence and witnesses; Follow-up actions.

An incident report is the written record of something that went wrong or nearly did: what happened, what was done, what the evidence shows and what will change. Examples help because the hard part is rarely the form. It is deciding what belongs in each field, and how to word it so a later reader can tell fact from guesswork.

This guide walks through a fictional consulting example and breaks the report into four parts: incident facts, immediate response, evidence and witnesses, and follow-up actions. Each part has draft wording you can adapt and a check you can apply. All names, dates and numbers are placeholders. Replace them with facts you have verified.

The scenario used throughout

A small consulting team is running a six-week strategy review for a regional distributor. On day 12, a team member sends the weekly interview summary to the client's project mailbox. The attachment includes a tab of notes from a second client's engagement, which was left in a working file by mistake. The sender notices within the hour and tells the engagement lead.

No one was hurt and no systems failed, but confidential material has gone outside the project it belongs to. That makes it worth recording properly. The same four-part structure works for a safety event, a service failure or a security event; only the specific fields change.

Why the structure matters

Two US government sources show the same pattern from different angles, and both are useful as drafting guidance even though neither is written for consulting firms.

OSHA's page on incident investigation says investigations give employers and workers the opportunity to identify hazards in their operations and shortcomings in their safety and health programs. It also says teams should look beyond the immediate causes of an incident. That is the difference between a report that says "an attachment was sent by mistake" and one that asks why the working file held another client's notes in the first place.

The FTC's Data Breach Response Guide for Business is aimed at breaches of personal information, but its sequence is transferable: mobilise the right people quickly, secure the affected areas, interview the people who discovered the problem, document the investigation and do not destroy evidence.

Both are US sources. Which duties actually apply to your incident, and by when, depends on the jurisdiction, your contracts and the kind of information involved.

Part 1: Incident facts

The facts section states what is known, when it was known and how. Keep it short, chronological and free of adjectives.

Draft wording:

Reference: [Incident number]. Reported by: [name, role]. Date and time reported: [date, time, time zone].

What happened. On [date] at approximately [time], [name] sent the weekly interview summary for the [engagement name] engagement to [client mailbox]. The attachment contained an additional worksheet ("[tab name]") with notes belonging to a different engagement. The sender identified this at approximately [time] and notified [engagement lead] at [time].

Known. Recipients of the message: [names or distribution list]. Attachment size and file name: [details]. The message was sent from [account].

Not yet known. Whether the attachment has been opened, forwarded or saved by any recipient; whether the worksheet contains personal information.

The "not yet known" line is the most useful in the whole report. Writing down what you have not established stops it being quietly treated as a fact by the second draft.

Watch for conclusions disguised as facts. "The analyst carelessly attached the wrong file" is a judgment. "The attached file contained a worksheet from another engagement" is a fact. Add "per [name]" where a fact comes from one person and has not been checked against a record.

Facts check: Could a reader who was not there tell which statements are verified, which come from one person and which are still unknown?

Part 2: Immediate response

This section records what was done straight away to stop the problem getting worse. If anyone is at risk, follow your approved emergency arrangements before doing any administrative recording. The paperwork comes second.

The FTC guide's advice to mobilise a response team right away to prevent additional data loss, and to remove improperly posted information, translates here into: contain first, then write it up. Draft wording:

Containment actions. [Time]: [Engagement lead] asked the client's project contact by phone to delete the message without opening the attachment and to confirm in writing. [Time]: the client contact confirmed deletion by email. [Time]: [Name] recalled the message from the sending account where supported and listed the actions taken.

People notified. [Role/name] at [time]; [role/name] at [time]. Reason: [company policy or contract clause].

Decisions pending. Whether the affected engagement's client must be told is with [named decision-maker] for review against the relevant contract by [date].

The last line matters. Decisions about notifying clients, insurers, regulators or affected individuals can carry legal deadlines, and the person writing the incident report is often not the right person to make them. Assign the decision to a named owner and record the date. Have contract and legal duties reviewed by a qualified professional; a report template cannot determine them for you.

Response check: Is every action time-stamped, attributed to a person and clearly separated from decisions that are still open?

Need a ready-made incident report template for your consulting?

Download a pre-built document with industry-specific categories, sections, and formatting.

Part 3: Evidence and witnesses

Evidence is what lets someone else reconstruct events later without relying on memory. The FTC's guidance is direct about two habits that apply well beyond data incidents: interview the people who discovered the problem and anyone else who may know about it, and do not destroy evidence while investigating or fixing.

Draft wording:

Evidence held. (1) Copy of the sent message with headers, stored at [location] with access limited to [roles]. (2) File version history for [file name]. (3) Client's written deletion confirmation. Custody: copies were saved by [name] on [date] and have not been edited.

Witnesses. [Name, role]: sender, identified the error. [Name, role]: engagement lead, received the report. Statements were taken on [date] by [name], recorded as [notes/written statement] and stored at [location].

Access restriction. Witness details and the affected worksheet are visible only to [named roles] until the review is closed.

Preserve, don't tidy: do not edit, rename or delete original files to make the record neater. Work from copies and say so. Statements can contain personal information, so restrict access. Open questions such as "walk me through how the summary was assembled" invite a fuller account than "why did you attach the wrong file?"

Evidence check: Can you point to where each piece of evidence is kept, who has touched it and who is allowed to see it?

Part 4: Follow-up actions

An incident is not closed when the immediate problem stops. It closes when the conditions that let it happen have been dealt with. OSHA's investigation guidance says investigators should look beyond the immediate causes, and that investigations focused on root causes rather than fault or blame also improve workplace morale and increase productivity.

For the scenario, contributing factors might include the following, each recorded as something to test rather than assume:

  • Working files hold material from more than one engagement.
  • No pre-send check for attachments.
  • No rule about which folder templates and summaries are built from.

"Contributing factor to be confirmed by review" starts an investigation. "Cause: human error" ends one without learning anything.

Draft wording for the action table:

ActionOwnerDueEvidence of completion
Separate working files by engagement in the document store[Engagement lead][Date]Folder structure screenshot and access list
Add a pre-send attachment check to the client delivery procedure[Practice lead][Date]Revised procedure, version number and approval record
Brief the team on the revised procedure[Engagement lead][Date]Attendance record
Confirm notification decision against contract terms[Named decision-maker][Date]Written decision
Review whether corrective actions worked[Reviewer, not the engagement lead][Date]Review note

Each action names one owner, a date and something a reviewer can inspect. "Improve awareness" fails all three.

Closure statement. [Reviewer] confirmed on [date] that the actions above are complete and effective, and records these continuing restrictions: [restrictions or "none"]. This report is closed.

Closure check: Would a reviewer who was not involved accept the evidence of completion for every action, and has anyone other than the incident owner signed the closure?

Review the report before you close it

Use these prompts on a read-through by someone who was not involved:

  • Facts: Are verified facts, single-source statements and unknowns clearly separated?
  • Tone: Does the report avoid blame, and describe conditions rather than character?
  • Timing: Do all entries have times, and is the sequence consistent?
  • Response: Are containment actions separated from decisions still awaiting an owner?
  • Evidence: Is each item located, protected and unchanged?
  • Witnesses: Are statements stored securely with restricted access?
  • Actions: Does each action have one owner, one date and proof of completion?
  • Notification: Has a qualified person reviewed any legal, contractual or regulatory notification duties?
  • Closure: Has someone other than the author confirmed completion?

Adapt the examples in a structured Word draft

If you would rather not rebuild these sections for every event, the consulting incident report template is an editable Word file organised around facts and immediate response, impact and evidence, investigation and contributing factors, and actions and closure, plus preparation and approval sections. It is a starting draft, not a guarantee that any report is complete, compliant or legally sufficient.

If the incident touches contract terms, check the wording in your consulting statement of work or engagement letter.

Sources: Incident Investigation, OSHA, Data Breach Response: A Guide for Business, FTC

Last updated: September 26, 2026

Frequently Asked Questions

Get the Consulting Incident Report Template

Download a pre-built incident report template with consulting-specific sections, wording, and drafting guidance.

Editable Word files. One-time purchase.