What this is
What is an incident investigation review?
What is an incident investigation review?
An incident investigation review is a quality check run against a completed investigation record, not against the investigator. It samples closed cases — usually quarterly — and is carried out by someone who had no role in the original investigation team. Its output is a quality percentage measured against ISO 19011's audit principles, not a performance score for the investigator.
What does 'independent of investigation' mean in practice?
It means the reviewer had no role authoring, gathering evidence for, or signing off the original case — not merely a different job title. A supervisor who approved the original RCA cannot mark this field Yes for their own team's case, because the review exists precisely to catch what that approval missed.
How is the Score Percent calculated?
Score Percent is the ratio of criteria passed to criteria assessed, with any field marked Not applicable removed from the denominator before the percentage is struck. Completeness Percent is tracked alongside it for exactly this reason — a high score on a half-answered review is not a high score.
Scope
When is an incident investigation review required?
This review sits downstream of the investigation itself. Running it on an open case, or using it to re-run the investigation rather than check it, produces a record neither the investigation nor the review can stand behind.
Use this template when
- A closed investigation case has reached the quarterly sample, or a trigger event calls for an out-of-cycle check
- A new record is needed; each one gets its own ID in the form IQR-2026-000
- You are running the Incident and Investigation programme and this is its quality-assurance step
- A linked record needs this one to exist: links to RCA
- Someone outside the original investigation team is available to carry out the check
Do not use it for
- Root Cause Analysis, which is the investigation itself, not the check on its quality.
- Just Culture Determination, which decides whether the individual's conduct was culpable, separate from whether the RCA process was sound.
- Effectiveness Verification, which checks whether a corrective action actually worked, not whether the investigation that raised it was well run.
- Incident Investigation Training, which builds the skill this review is measuring, rather than measuring it.
- Anything outside KnowSafe, which belongs in the workspace that owns that process
Compliance mapping
Which ISO 19011 requirements does this satisfy?
ISO 19011 is a method for auditing, not a certifiable standard in its own right — the clause references below describe how its audit principles map onto this review, not a certification requirement.
| Clause | Requirement | Where it lands |
|---|---|---|
| ISO 19011:2018 cl.4 — Principles of auditing | The review must be independent of the original investigation to have any evidentiary value. | Header |
| ISO 19011:2018 cl.6.4 — Conducting document review | Evidence and timeline underpinning the RCA must be checked, not just its conclusions. | Quality criteria |
| ISO 19011:2018 cl.7.6 — Evaluation of auditors | The reviewer judges whether cause coding and root-cause reasoning met the required standard, which is itself an evaluation of investigator competence. | Quality criteria |
| ISO 19011:2018 cl.6.6 — Preparing the audit report | Findings on action strength and extent of condition must be recorded against defined criteria, not general impression. | Quality criteria |
| ISO 19011:2018 cl.6.8 — Conducting audit follow-up | A review that finds the investigation deficient must trigger a reinvestigation or an improvement action, not just a low score. | Outcome |
| ISO 19011:2018 cl.5.6 — Reviewing and improving the audit programme | Completion against target and the resulting score feed back into how the wider review programme is run. | Outcome |
| ISO 19011:2018 cl.4 — Principles of auditing (fair presentation) | Feedback on the review's findings must reach the investigation lead, whether or not the score was high. | Outcome |
What it does not cover
- A high Score Percent, which can be produced by a reviewer working through a half-answered form — Completeness Percent has to be checked alongside it before the score means anything.
- Feedback Given To Lead marked Yes, which records that feedback was sent, not that the lead accepted or acted on it.
- Just Culture Applied marked Not applicable, which is only correct when the case genuinely carried no culpability question — not when the reviewer chose not to look.
- Reinvestigation Required marked No, which does not override an Action Strength Appropriate finding of No recorded earlier in the same review.
- Independent Of Investigation marked Yes, which confirms who ran the review, not that they had the standing to force a reinvestigation if one is warranted.
Global
Incident Investigation Review requirements by country
ISO 19011 is guidance rather than law, so what makes this review consequential varies by which regulatory or certification regime is reading the investigation file behind it.
ISO 45001:2018 cl.9.2 (internal audit) and cl.10.2 (nonconformity and corrective action)
A certification auditor sampling closed incidents will ask who checked the investigation's quality, not just whether an investigation happened.
This review is the evidence that answers that question — without it, a strong RCA template still leaves the management system unable to show its own quality check.
29 CFR 1904 recordkeeping, and general duty clause enforcement
OSHA does not mandate a meta-review of investigation quality, but a contested citation often turns on whether the underlying investigation was thorough and its cause analysis credible.
An independent quality check on the investigation record is what lets a company defend that thoroughness after the fact, rather than asserting it.
Management of Health and Safety at Work Regulations 1999, reg. 5 (review of preventive and protective measures)
Regulation 5 expects arrangements to be reviewed, not just followed.
A quarterly quality check on investigation records is the practical evidence that the review obligation is being met, not merely assumed.
How to complete it
How to complete an incident investigation review, step by step
Four judgement calls decide whether a Pass on this review actually means the underlying investigation would survive scrutiny.
Independence has to be defined by involvement, not job title. Anyone who gathered evidence, interviewed a witness, or signed off the original case is disqualified from reviewing it, even if their formal role was supervisory rather than 'investigator'.
Several criteria offer Partly as a middle option. Treat it as a No wherever the gap is the one that matters most for that criterion — a timeline validated in outline but not against physical evidence is not partly validated, it is unvalidated.
Root Cause Is Systemic exists to catch investigations that stopped at 'operator error'. If the stated root cause could be fixed by disciplining an individual, it has not reached a systemic cause, whatever else the investigation got right.
Reinvestigation Required should follow from the criteria that touch the finding itself — evidence preserved, timeline validated, causes coded — not from Completed Within Target. A late but sound investigation does not need reinvestigating; a fast but evidentially thin one does.
What auditors find
Most common incident investigation review findings
These are the patterns that turn up most often when someone other than the reviewer checks the review itself.
| Finding | Clause | What fixes it |
|---|---|---|
| Score Percent calculated including Not Applicable criteria in the denominator, inflating the result. | ISO 19011:2018 cl.6.6 | Recalculate excluding every field marked Not applicable, and correct the stored percentage before it feeds any programme-level reporting. |
| Independent Of Investigation marked Yes for a reviewer who signed off the original case as area manager. | ISO 19011:2018 cl.4 | Reassign the review to someone with no involvement in the case, and re-run the quality criteria from scratch rather than amending the existing record. |
| Root Cause Is Systemic marked Yes against a stated cause of 'operator failed to follow procedure'. | ISO 19011:2018 cl.7.6 | Mark the criterion No, and route the underlying RCA back for rework before closing this review. |
| Action Strength Appropriate marked Yes where the only action recorded was a toolbox talk on a fatality-potential case. | ISO 19011:2018 cl.6.6 | Fail the criterion, set Reinvestigation Required or Improvement Action Required to Yes, and record a CAPA reference rather than leaving the action as issued. |
| Feedback Given To Lead marked Yes with no record of what was fed back or when. | ISO 19011:2018 cl.4 | Capture the feedback itself against the review record, even briefly, so the criterion reflects a completed loop rather than an intention. |
| Completeness Percent not tracked, so a review answering half the criteria reports the same confidence as one answering all of them. | ISO 19011:2018 cl.5.6 | Make Completeness Percent mandatory alongside Score Percent, and flag any review below a completeness threshold for rework rather than acceptance. |
Case in point
Case in point: the review that passed a closed case twice
A serious-potential incident closed with a root cause of 'contractor did not follow lockout procedure' and a single retraining action. The quarterly review marked Root Cause Is Systemic and Action Strength Appropriate both Yes, scoring 88 percent — comfortably above the pass line.
A second look six months later, after a near-identical event, found the reviewer had not checked the RCA's own evidence trail: no lockout points had been identified as missing, no procedure gap existed, and the contractor had in fact followed the written steps exactly. The systemic cause — an unlockable point of isolation — was never found, because the review that was supposed to catch it scored the shortcut a pass.
The template
The template, field by field
The form exactly as it installs. Every field, option, score and conditional rule is editable, and the links to other templates come with it.
4 sections
- Reference
- SAF-012
- Archetype
- Review
- Record ID
- IQR-2026-000
- Scoring
- Quality percent
- Direction
- High is good
- Singleton
- No
- Basis
- ISO 19011
- Links
- Links to RCA
- Tags
- Investigation, Assurance
- Sections
- 4
- Fields
- 31
- Follow up fields
- 3
- Repeating sections
- 0
- Links out
- 3
Header
7 fieldsReview ID*
Auto sequence. Format IQR-2026-0000.
The record's own ID. Other templates point at this value.
Status*
Drives who this goes to next.
- Planned2 pts
- In progress2 pts
- Complete3 pts
- Deferred0 pts
- Open0 pts
- Closed3 pts
- Overdue0 pts
Purpose
This reviews the quality of a finished investigation, not the investigator. It is done on a sample of closed cases by somebody who was not on the team, so standards stay honest without anyone being scored during the work.
RCA ID Reviewed*
Links to FDN-013 RCA ID
Review Date*
Reviewer*
Independent Of Investigation*
- Yes2 pts
- No0 pts
Quality criteria
10 fieldsPotential Rated Correctly*
Was the investigation level set by potential rather than by actual outcome.
- Yes2 pts
- Partly1 pt
- No0 pts
Evidence Preserved*
- Yes2 pts
- Partly1 pt
- No0 pts
Timeline Validated*
- Yes2 pts
- Partly1 pt
- No0 pts
Causes Coded From Taxonomy*
- Yes2 pts
- Partly1 pt
- No, free text only0 pts
Root Cause Is Systemic*
A root cause naming a person means the investigation stopped too early.
- Yes2 pts
- Partly1 pt
- No, names a person0 pts
Extent Of Condition Considered*
- Yes2 pts
- No0 pts
- Not applicableexcluded from denominator
Actions Address The Cause*
- Yes2 pts
- Partly1 pt
- No0 pts
Action Strength Appropriate*
A serious investigation closing on weak actions alone is a failed investigation.
- Yes2 pts
- Partly1 pt
- No, weak actions only0 pts
Just Culture Applied
- Yes2 pts
- No0 pts
- Not applicableexcluded from denominator
Completed Within Target*
- Yes2 pts
- Late0 pts
Related records
1 fieldIncident Case ID
The incidents reviewed.
Links to SAF-001 Case ID
Outcome
13 fieldsItems Assessed*
Excludes anything marked N/A.
Items Failed*
Score Percent*
Calculated on submission. High is good. N/A items leave the denominator.
Result Band*
- Pass3 pts
- Caution1 pt
- Fail0 pts
Completeness Percent*
How much of the template was actually answered. A high score on a half completed form is not a high score.
Reinvestigation Required*
- No2 pts
- Yes0 pts
Feedback Given To Lead*
Improvement Action Required*
Raise the action record, then enter its reference here.
- No2 pts
- Yes0 pts
Priority
- High0 pts
- Medium1 pt
- Low3 pts
CAPA ID
Format CAPA-2026-00000.
Links to FDN-014 CAPA ID
Action Owner
Reviewer*
Signature*
SAF-012 · record IDs look like IQR-2026-000 · Links to RCA
Open in KnowellaRun it with agents
From a document you fill in to a programme that runs itself
The form is the easy part. Keeping it current, routing it to the right owner and holding the evidence together is the work that actually slips.
Holds the incident investigation review library against your registers, routes each record to its owner, and keeps the evidence trail together.
Tracks Score Percent and Completeness Percent across every review, and flags the pattern of partial reviews scoring as if they were complete.
Feeds a failed Root Cause Is Systemic or Action Strength Appropriate finding back into the investigator's own training record, closing the loop this review is meant to open.

Coordinates the crew, rolls completion and exceptions into one view, and holds every write for your approval before it touches a record.
This template lives in KnowSafe — safety and compliance. Incidents, hazards, permits, inspections and the critical controls behind them.
Meet KnowSafe→Glossary
Incident Investigation Review definitions and key terms
- RCA
- Root Cause Analysis — the underlying investigation record this review checks, not the review itself.
- Extent of condition
- A check for whether the same root cause could be present elsewhere, beyond the specific case being investigated.
- Just Culture
- A framework for separating honest error from reckless or wilful conduct, so discipline and system fixes aren't confused with each other.
- Cause taxonomy
- A fixed list of cause categories investigators code against, used so causes can be counted and trended rather than left as free text.
- Completeness percent
- The proportion of the review template actually answered, tracked separately from the quality score so a partial review can't pass as a full one.
FAQ
Frequently asked questions about incident investigation review
Who should carry out an incident investigation review?+
Someone with no role in the original investigation — not the investigation lead's manager by default, and not whoever is available first. Involvement, not seniority, is what disqualifies a reviewer.
Does a low Score Percent mean the investigator did badly?+
No. The review is designed to score the investigation record, not the investigator. A poor score should prompt a look at process, training or time allocation, not a conversation framed as discipline.
What happens if Reinvestigation Required is marked Yes?+
The original case gets reopened and the missing evidence, timeline or cause analysis is redone, rather than the review simply noting the gap and moving on.
Why is Completed Within Target scored separately from the quality criteria?+
Timeliness and quality are different failure modes. A fast investigation can still be shallow, and a thorough one can still be late — collapsing them into one score would hide whichever problem is smaller that quarter.
Can Just Culture Applied be skipped?+
It can be marked Not applicable, but only where the case genuinely carried no question of individual culpability. Skipping it because the question is uncomfortable is a finding in itself, not a valid answer.
How does this review connect to CAPA?+
Where Improvement Action Required is Yes, a CAPA record is raised and its ID entered here, so the review's own findings are tracked to closure the same way any other corrective action would be.
Keep going
Related templates and programmes
Industries this is written for
Programmes this belongs to
Used together in Incident and Investigation
Root Cause Analysis
Finds out why something happened rather than who was involved
Corrective and Preventive Action
The single action record used everywhere
Finding
Records a single deficiency picked up during an audit, inspection or check
Effectiveness Verification
Checks whether an action actually worked, some time after it was put in place
Just Culture Determination
Separates a system problem from a genuine choice to take a risk, using a consistent set of questions
Extent of Condition Review
Asks two questions after an investigation: where else does this same condition exist, and where else could this same cause bite us
More in Incidents
Incident Report
Records any unplanned event that caused harm, damage or loss
Near Miss Report
Records something that could have caused harm but did not
First Aid Report
Records a minor injury treated on site with no further medical care needed
Medical Treatment Report
Records an injury needing treatment beyond first aid
Lost Time Report
Records an injury that keeps a worker away from work beyond the day it happened
Property Damage Report
Records damage to equipment, buildings or stock where nobody was hurt

Written and reviewed by
Siddarth Singh
Founder & Chief Executive Officer, Knowella
Certified Safety Professional and industrial and systems engineer with more than a decade inside food supply chain, freight and manufacturing operations. This page was written against the current text of the standards it cites, not against secondary summaries of them.
- Certified Safety Professional (CSP), Board of Certified Safety Professionals
- MBA, University of Chicago Booth School of Business
- MS and BS, The Ohio State University, Industrial and Systems Engineering
- Six Sigma Black Belt
Sources and last review. Reviewed 16 August 2026 against:
- ISO 19011:2018 — Guidelines for auditing management systems
- ISO 45001:2018 cl.9.2 — Internal audit
- ISO 45001:2018 cl.10.2 — Nonconformity and corrective action
- ISO — International Organization for Standardization
This page is general guidance, not legal advice. Confirm requirements with your jurisdiction’s regulator.