Summary
In short
- Human error is a starting point, not a conclusion. If the analysis ends with a person, it has found where the sequence became visible rather than why it happened.
- The five whys frequently stop at four, because the fifth answer implicates a decision someone in the room is accountable for.
- ISO 45001 clause 10.2 and ISO 9001 clause 10.2 both require evaluating the need for action to eliminate causes, and reviewing the effectiveness of the action taken. Effectiveness review is the requirement most often unmet.
- Analysis should distinguish the causal chain from contributing factors. A cause, removed, prevents the event; a contributing factor made it more likely or worse.
- Blame and analysis are mutually exclusive. Investigations conducted where discipline is a possible outcome produce accounts constructed for that outcome.
- The test of a root cause is whether the proposed action, applied before the event, would have prevented it. If not, the analysis has not finished.
What it is
What it is
What is root cause analysis?
Root cause analysis is a structured method for finding why something happened, far enough back that acting on the finding prevents recurrence rather than treating the symptom. It works from evidence through a causal chain to the organisational conditions that made the event possible, and it produces corrective actions that are verified as effective.
What is the difference between a correction and a corrective action?
A correction fixes the immediate problem: the product is scrapped, the machine is repaired, the spill is cleaned. A corrective action addresses the cause so the problem does not return. Most systems record both in the same field, which is why so many corrective actions are corrections wearing the wrong label.
When to use it
When to use it, and when not to
Root cause analysis is expensive in time and attention, which is why it should be reserved for events where the answer will change something.
Use it for
- A serious incident or high-potential near miss, regardless of the actual outcome
- A nonconformance that is significant, recurring, or reached a customer
- A repeat failure on an asset or in a process, where the previous fix did not hold
- An audit finding that recurs, which indicates the previous closure did not address the cause
- A trend in the data, where individually minor events share a pattern
Not for
- Single minor events with an obvious and contained cause, where a correction is proportionate
- The incident report itself, which captures facts and should not lead the analysis toward a conclusion
- Performance management, which is a separate process and must not share a record with analysis
- Design reviews and FMEA, which look forward at what could happen rather than back at what did
- Routine variance investigation, which has its own lighter process
Standards
What it is built against
Root cause analysis is required by implication rather than by name in most standards. What they require is that causes are determined and that action addressing them is verified effective.
| Clause | Requirement | Where it lands |
|---|---|---|
| ISO 45001 cl.10.2 | Investigate incidents, determine causes, evaluate need for action to eliminate causes, review effectiveness | Whole record |
| ISO 9001 cl.10.2 | Evaluate need for action to eliminate causes so nonconformity does not recur, review effectiveness | Causal analysis and verification |
| ISO 45001 cl.10.2(d) | Assess existing OH&S risks and determine whether new hazards have arisen | Risk reassessment |
| IATF 16949 cl.10.2.3 | Documented problem solving process with defined methodology and containment | Method and containment |
| FDA 21 CFR 820.100 | CAPA procedures including investigating the cause of nonconformities and verifying effectiveness | Corrective action |
| OSHA 1910.119(m) | Incident investigation within 48 hours for PSM events, with findings resolved and documented | Timing and closure |
| ISO 45001 cl.10.2(f) | Make changes to the management system where necessary | Systemic action |
| ISO 9001 cl.10.2.2 | Retain documented information on the nature of nonconformities and results of corrective action | Record retention |
What it does not cover
- The incident report, which captures facts and should be kept separate so the analysis is not led by an early conclusion.
- Disciplinary process, which must not run through the same record, because an analysis conducted under threat produces accounts shaped for that threat.
- The corrective action tracker, which manages the actions arising rather than the reasoning that produced them.
- FMEA, which is prospective analysis of what could fail rather than retrospective analysis of what did.
- Risk assessment, which should be updated as an output of the analysis rather than replaced by it.
Filling it in
Filling it in well
The structure of a root cause analysis matters less than the discipline applied to it. Any of the common methods will work; all of them fail the same way.
A problem stated as "operator injured" produces a different analysis from "guard was open during a jam clearance that occurs forty times per shift". Specify what, where, when, how much and how often. Most weak analyses trace to a problem statement that was too vague to analyse, and the vagueness usually conceals an assumption about the cause.
The chain answers how the event came about, step by step, each link necessary. Contributing factors made it more likely, harder to detect or worse in outcome. Both matter and they demand different actions: breaking a chain prevents recurrence, addressing a contributing factor reduces likelihood or severity.
For every candidate cause, ask whether removing it before the event would have prevented the event. If the answer is no, it is a contributing factor or a symptom. This single test eliminates most of what gets recorded as root causes, including nearly all findings of human error.
Both ISO 45001 and ISO 9001 require review of the effectiveness of corrective action. That means evidence, after enough time and enough occurrences, that the problem has not returned. Closing when the action is implemented records that something was done; it does not record that it worked, and repeat findings are the measure of the difference.
Audit findings
Common audit findings
Audit findings on root cause analysis are strikingly consistent across industries and standards.
| Finding | Clause | What fixes it |
|---|---|---|
| Analysis concludes at human error with retraining as the corrective action. | ISO 45001 cl.10.2 | Continue past the person to why the method failed for a competent person doing the job normally. |
| Corrective action closed on implementation with no effectiveness review. | ISO 9001 cl.10.2 | Set a verification date and method when the action is raised, and close only after it. |
| Correction recorded as corrective action; the immediate fix is the whole response. | ISO 9001 cl.10.2 | Separate the fields; a repaired machine and a prevented recurrence are different things. |
| Repeat events with prior corrective actions closed, indicating cause was never addressed. | ISO 45001 cl.10.2 | Trend by cause code; repeat by cause is the honest measure of analysis quality. |
| Analysis performed by one person, usually the area supervisor. | ISO 45001 cl.5.4 | Include the people who do the work; they know the actual method and the usual workarounds. |
| Problem statement too vague to support analysis. | IATF 16949 cl.10.2.3 | Quantify what, where, when, how much, how often before starting. |
| Risk assessment not updated after the analysis identified a new hazard. | ISO 45001 cl.10.2(d) | Make assessment review a required output where a new hazard or control gap is found. |
| Actions raised without owner, date or verification method. | ISO 9001 cl.10.2 | Require all three at the point the action is created, not at review. |
| Containment not applied or not bounded while analysis proceeds. | IATF 16949 cl.10.2.3 | Contain first to the last known good point, then analyse. |
| Investigation conducted alongside a disciplinary process. | ISO 45001 cl.10.2 | Separate the processes and the records; concurrent discipline corrupts the account. |
Worked case
Case in point: the fifth why nobody asked
A packing operator was injured clearing a jam. The analysis ran: why was the operator injured, because they reached into the machine; why did they reach in, because the machine jammed; why did they reach in without isolating, because isolation takes four minutes; why does it take four minutes, because the isolation point is on the far side of the guard cage. The analysis stopped there and recorded the cause as failure to follow the isolation procedure, with retraining as the action.
The unasked fifth why was why the isolation point is on the far side of the cage. It had been moved during a layout change two years earlier to make room for a new conveyor, a change made without assessing its effect on the isolation procedure. Every operator on that line cleared jams without isolating, because the alternative was four minutes on a line paced at forty jams a shift.
The retraining was delivered to eleven people who already knew the procedure and had rational reasons for not following it. Nine months later a second operator was injured on the same machine, doing the same thing.
Definitions
Definitions and key terms
- Root cause
- A cause which, if removed before the event, would have prevented it, and which lies within the organisation's ability to control.
- Contributing factor
- A condition that made the event more likely, harder to detect, or worse in outcome, without being necessary to it.
- Correction
- Action eliminating the detected problem itself: repair, scrap, clean up. Necessary and not sufficient.
- Corrective action
- Action eliminating the cause so the problem does not recur, which is a different activity from the correction.
- Containment
- Bounding the affected population back to the last point at which the process was demonstrably in control, applied before analysis begins.
- Five whys
- An iterative questioning technique. Effective in disciplined hands, and prone to stopping at whichever answer is comfortable.
- Fishbone diagram
- Cause categorisation across method, machine, material, measurement, environment and people, useful for breadth before depth.
- Effectiveness verification
- Evidence gathered after implementation, over enough occurrences, that the corrective action worked.
FAQ
Frequently asked questions
Is human error ever a root cause?+
Almost never as a stopping point. Error is a consequence of conditions: procedure design, time pressure, equipment layout, competence, fatigue, competing priorities. Recording human error as the cause identifies where the failure surfaced and leaves untouched everything that made it likely. The exception is deliberate violation, and even then the question of why the safe method was worth avoiding remains worth asking.
Which method should we use?+
Any structured one, applied with discipline. Five whys suits simple sequences, fishbone gives breadth before depth, fault tree suits complex systems with multiple failure paths, and 8D suits customer-facing problems needing containment. The method matters far less than whether the analysis is willing to reach findings that implicate decisions rather than individuals.
How do we know when we have reached the root cause?+
Apply the prevention test: would removing this, before the event, have prevented it? And the control test: is this within our ability to change? A cause passing both is actionable. Most analyses stop one or two levels above that point, at something true but not sufficient.
How long should we wait to verify effectiveness?+
Long enough for the problem to have recurred if the action failed. For a daily process that may be weeks; for a quarterly one it is quarters. Verifying too early is the most common way effectiveness review becomes a formality, because the absence of recurrence over two days proves nothing.
Should the analysis be blame-free?+
It has to be, and that requires structural separation rather than assurance. If discipline can result from the same process, people will construct accounts that protect them, and the account is the only raw material the analysis has. Run any performance process separately, on its own record, and make the separation visible to the people being asked to explain what happened.
The agents
What the agents do with it
The analysis is a document. What fails around it is the containment boundary, the action that closed without verification, and the third occurrence nobody connected to the first two.
Watches incidents and nonconformances for repeat causes across areas and time, and surfaces the pattern before the third occurrence rather than after it.
Holds the analysis against the incident record while keeping facts and conclusions in separate documents, and reopens the risk assessment where a new hazard is found.
Manages containment scope and disposition on nonconformances, and blocks closure where effectiveness has not been verified.
Supplies asset history so a repeat failure can be seen as a pattern rather than as three separate repairs.
This template lives in General — control tower. The orchestration layer. Registries and engines every other workspace reads from.
Meet General→Sources
Sources
- ISO 45001:2018 clause 10.2, incident, nonconformity and corrective action
- ISO 9001:2015 clause 10.2, nonconformity and corrective action
- IATF 16949:2016 clause 10.2.3, problem solving
- 21 CFR 820.100, corrective and preventive action, FDA
- 29 CFR 1910.119(m), incident investigation, OSHA
