Knowella

Root Cause Analysis Template

Root cause analysis fails in a predictable direction. It stops at the person. Someone did not follow the procedure, the finding is recorded as human error, the corrective action is retraining, and the same event recurs eighteen months later with a different name attached to it.

EllaGeneralRecordFDN-01351 fields across 9 sectionsFull researchSee the form

Reviewed by Siddarth SinghCSPLast reviewed 16 August 2026

Basis
ICAM, TapRooT, ISO 9001 cl.10.2
Workspace
General
Form type
Record
Triggered by
Incident, nonconformance, repeat failure
Closes on
Verified effectiveness, not implementation

The short version

  • Human error is a starting point, not a conclusion. If the analysis ends with a person, it has found where the sequence became visible rather than why it happened.
  • The five whys frequently stop at four, because the fifth answer implicates a decision someone in the room is accountable for.
  • ISO 45001 clause 10.2 and ISO 9001 clause 10.2 both require evaluating the need for action to eliminate causes, and reviewing the effectiveness of the action taken. Effectiveness review is the requirement most often unmet.
  • Analysis should distinguish the causal chain from contributing factors. A cause, removed, prevents the event; a contributing factor made it more likely or worse.
  • Blame and analysis are mutually exclusive. Investigations conducted where discipline is a possible outcome produce accounts constructed for that outcome.
  • The test of a root cause is whether the proposed action, applied before the event, would have prevented it. If not, the analysis has not finished.

What this is

What is root cause analysis?

What is root cause analysis?

Root cause analysis is a structured method for finding why something happened, far enough back that acting on the finding prevents recurrence rather than treating the symptom. It works from evidence through a causal chain to the organisational conditions that made the event possible, and it produces corrective actions that are verified as effective.

What is the difference between a correction and a corrective action?

A correction fixes the immediate problem: the product is scrapped, the machine is repaired, the spill is cleaned. A corrective action addresses the cause so the problem does not return. Most systems record both in the same field, which is why so many corrective actions are corrections wearing the wrong label.

Scope

When is a root cause analysis required?

Root cause analysis is expensive in time and attention, which is why it should be reserved for events where the answer will change something.

Use this template when

  • A serious incident or high-potential near miss, regardless of the actual outcome
  • A nonconformance that is significant, recurring, or reached a customer
  • A repeat failure on an asset or in a process, where the previous fix did not hold
  • An audit finding that recurs, which indicates the previous closure did not address the cause
  • A trend in the data, where individually minor events share a pattern

Do not use it for

  • Single minor events with an obvious and contained cause, where a correction is proportionate
  • The incident report itself, which captures facts and should not lead the analysis toward a conclusion
  • Performance management, which is a separate process and must not share a record with analysis
  • Design reviews and FMEA, which look forward at what could happen rather than back at what did
  • Routine variance investigation, which has its own lighter process

Compliance mapping

Which ICAM requirements does this satisfy?

Root cause analysis is required by implication rather than by name in most standards. What they require is that causes are determined and that action addressing them is verified effective.

ClauseRequirementWhere it lands
ISO 45001 cl.10.2Investigate incidents, determine causes, evaluate need for action to eliminate causes, review effectivenessHeader
ISO 9001 cl.10.2Evaluate need for action to eliminate causes so nonconformity does not recur, review effectivenessCausal analysis
ISO 45001 cl.10.2(d)Assess existing OH&S risks and determine whether new hazards have arisenFindings
IATF 16949 cl.10.2.3Documented problem solving process with defined methodology and containmentInvestigation level
FDA 21 CFR 820.100CAPA procedures including investigating the cause of nonconformities and verifying effectivenessClosure
OSHA 1910.119(m)Incident investigation within 48 hours for PSM events, with findings resolved and documentedClosure
ISO 45001 cl.10.2(f)Make changes to the management system where necessaryFindings
ISO 9001 cl.10.2.2Retain documented information on the nature of nonconformities and results of corrective actionClosure

What it does not cover

  • The incident report, which captures facts and should be kept separate so the analysis is not led by an early conclusion.
  • Disciplinary process, which must not run through the same record, because an analysis conducted under threat produces accounts shaped for that threat.
  • The corrective action tracker, which manages the actions arising rather than the reasoning that produced them.
  • FMEA, which is prospective analysis of what could fail rather than retrospective analysis of what did.
  • Risk assessment, which should be updated as an output of the analysis rather than replaced by it.

How to complete it

How to complete a root cause analysis, step by step

The structure of a root cause analysis matters less than the discipline applied to it. Any of the common methods will work; all of them fail the same way.

Define the problem before analysing it

A problem stated as "operator injured" produces a different analysis from "guard was open during a jam clearance that occurs forty times per shift". Specify what, where, when, how much and how often. Most weak analyses trace to a problem statement that was too vague to analyse, and the vagueness usually conceals an assumption about the cause.

Separate the causal chain from contributing factors

The chain answers how the event came about, step by step, each link necessary. Contributing factors made it more likely, harder to detect or worse in outcome. Both matter and they demand different actions: breaking a chain prevents recurrence, addressing a contributing factor reduces likelihood or severity.

Test each proposed cause against prevention

For every candidate cause, ask whether removing it before the event would have prevented the event. If the answer is no, it is a contributing factor or a symptom. This single test eliminates most of what gets recorded as root causes, including nearly all findings of human error.

Verify effectiveness, not implementation

Both ISO 45001 and ISO 9001 require review of the effectiveness of corrective action. That means evidence, after enough time and enough occurrences, that the problem has not returned. Closing when the action is implemented records that something was done; it does not record that it worked, and repeat findings are the measure of the difference.

What auditors find

Most common root cause analysis findings

Audit findings on root cause analysis are strikingly consistent across industries and standards.

FindingClauseWhat fixes it
Analysis concludes at human error with retraining as the corrective action.ISO 45001 cl.10.2Continue past the person to why the method failed for a competent person doing the job normally.
Corrective action closed on implementation with no effectiveness review.ISO 9001 cl.10.2Set a verification date and method when the action is raised, and close only after it.
Correction recorded as corrective action; the immediate fix is the whole response.ISO 9001 cl.10.2Separate the fields; a repaired machine and a prevented recurrence are different things.
Repeat events with prior corrective actions closed, indicating cause was never addressed.ISO 45001 cl.10.2Trend by cause code; repeat by cause is the honest measure of analysis quality.
Analysis performed by one person, usually the area supervisor.ISO 45001 cl.5.4Include the people who do the work; they know the actual method and the usual workarounds.
Problem statement too vague to support analysis.IATF 16949 cl.10.2.3Quantify what, where, when, how much, how often before starting.
Risk assessment not updated after the analysis identified a new hazard.ISO 45001 cl.10.2(d)Make assessment review a required output where a new hazard or control gap is found.
Actions raised without owner, date or verification method.ISO 9001 cl.10.2Require all three at the point the action is created, not at review.
Containment not applied or not bounded while analysis proceeds.IATF 16949 cl.10.2.3Contain first to the last known good point, then analyse.
Investigation conducted alongside a disciplinary process.ISO 45001 cl.10.2Separate the processes and the records; concurrent discipline corrupts the account.

Case in point

Case in point: the fifth why nobody asked

A packing operator was injured clearing a jam. The analysis ran: why was the operator injured, because they reached into the machine; why did they reach in, because the machine jammed; why did they reach in without isolating, because isolation takes four minutes; why does it take four minutes, because the isolation point is on the far side of the guard cage. The analysis stopped there and recorded the cause as failure to follow the isolation procedure, with retraining as the action.

The unasked fifth why was why the isolation point is on the far side of the cage. It had been moved during a layout change two years earlier to make room for a new conveyor, a change made without assessing its effect on the isolation procedure. Every operator on that line cleared jams without isolating, because the alternative was four minutes on a line paced at forty jams a shift.

The retraining was delivered to eleven people who already knew the procedure and had rational reasons for not following it. Nine months later a second operator was injured on the same machine, doing the same thing.

The template

The template, field by field

The form exactly as it installs. Every field, option, score and conditional rule is editable, and the links to other templates come with it.

51fields
9 sections
Reference
FDN-013
Archetype
Record
Record ID
RCA-2026-000
Scoring
Not scored, causes counted
Direction
n/a
Singleton
Yes
Basis
ICAM, TapRooT, ISO 9001 cl.10.2
Links
Linked from every workspace
Tags
Investigation
Sections
9
Fields
51
Follow up fields
0
Repeating sections
2
Links out
6
Field typesOwn ID, generated on saveCase thread and parentPick list from a registryLinked to another templateFollow up, dashed outlineScored

Header

6 fields
Text

RCA ID*

Generated on save

Format RCA-2026-00000.

The record's own ID. Other templates point at this value.

Text

Case ID*

Thread key

Copied from the event that triggered this investigation.

Thread key. Carries the parent event through the whole chain

Single Choice

Parent Type*

Incident, finding, nonconformance, failure or complaint.

IncidentNear missFindingAuditInspectionRisk assessmentComplaintEquipment failureNonconformanceManagement of change
Text

Parent ID*

Thread key

Immediate predecessor record

Date & Time

Investigation Start Date*

Date & Time

Target Completion Date*

Investigation level

5 fields
Info

Level Guidance

Explains that investigation depth is set by potential, not actual outcome. A first aid with fatality potential is a level 4.

Single Choice

Maximum Potential Loss*

Scored

The worst credible outcome had circumstances been slightly different.

  • Minor4 pts
  • Moderate3 pts
  • Serious2 pts
  • Fatal or catastrophic0 pts
Single Choice

Investigation Level*

Scored

Set by potential loss. Level 4 requires an independent lead and executive sponsor.

  • None required3 pts
  • Quick debrief2 pts
  • 5 Why2 pts
  • Full RCA1 pt
  • Cross functional RCA0 pts
Single Choice

Method Required*

5 Why for level 1, ICAM or TapRooT for level 3 and above.

5 WhyFishboneFault treeICAMTapRooT
Single Choice

Recurrence In Last 24 Months*

Scored

If yes, the previous action failed and that is itself a finding.

  • No2 pts
  • Yes, one similar event1 pt
  • Yes, two or more0 pts

Team

5 fields
Users

Investigation Lead*

Must be independent of the area for level 3 and above.

Text

Lead Person ID*

Linked

Links to FDN-003 Person ID

Checkbox

Lead Trained In Method*

An untrained lead invalidates a level 3 or 4 investigation.

Users

Executive Sponsor

Optional

Required for level 4.

Text

Team Members*

Cross functional for level 3 and above. Include someone who does the work.

Evidence preservation

7 fields
Info

Evidence Guidance

The five P's. People, position, parts, paper and recordings. Capture before the scene changes.

Checkbox

Scene Secured*

File Upload

Scene Photographs*

Wide shots and close ups. Take more than you think you need.

Checkbox

Parts Retained

Optional
Multi Choice

Records Collected

Optional

Which records were gathered as evidence.

Production recordsMaintenance historyTraining recordsShift handoverPermitsCleaning records
Checkbox

Recordings Secured

Optional

CCTV, telematics and system logs overwrite quickly.

Text

Chain of Custody Note

Optional

Who holds the physical evidence and where.

Timeline

Repeats6 fields
Info

Timeline Guidance

Build and validate the sequence before attempting any causal analysis.

Date & Time

Event Time*

One row per event or condition.

Single Choice

Event or Condition*

Events are things that happened. Conditions are things that were true.

EventCondition
Text

Description*

Single Choice

Evidence Source*

How you know this. Witness, record, physical evidence or inference.

Witness accountSystem recordPhysical evidenceInference
Checkbox

Validated*

Tick only where evidence supports this, not where it is assumed.

Causal analysis

Repeats6 fields
Single Choice

Cause Level*

Failed defence, individual action, task condition or organisational factor.

Absent or failed defenceIndividual or team actionTask or environmental conditionOrganisational factor
Pick List

Cause Code*

From FDN-010 Cause NameFilter: Cause Level matches

Selected from the governed taxonomy so causes can be counted across investigations.

Text

Cause Code ID*

Linked

Links to FDN-010 Cause Code

Text

Related Control ID

OptionalLinked

Fill where a critical control failed.

Links to FDN-011 Control ID

Text

Cause Explanation*

Why this cause was present, in your own words.

Text

Evidence For This Cause*

What supports this. A cause without evidence is an opinion.

Human factors

4 fields
Single Choice

Action Type

Optional

Skill based slip or lapse, rule based mistake, knowledge based mistake or violation.

Skill based slip or lapseRule based mistakeKnowledge based mistakeViolation
Single Choice

Violation Type

Optional

Routine, situational or exceptional. Only complete where a violation occurred.

RoutineSituationalExceptional
Single Choice

Substitution Test Result

OptionalScored

Would another competent person in the same situation likely have done the same.

  • Yes2 pts
  • No0 pts
  • N/Aexcluded from denominator
Text

Just Culture ID

OptionalLinked

Link to the Just Culture record where a person's actions are involved.

Links to FDN-017 Determination ID

Findings

5 fields
Text

Root Cause Statement*

The underlying system weakness. If it names a person, go deeper.

Checkbox

Systemic Issue*

Tick if this could affect areas beyond where it occurred.

Text

Extent of Condition ID

OptionalLinked

Required where a systemic issue is flagged.

Links to FDN-018 Review ID

Text

Contributing Factors

Optional
Text

What Went Well

Optional

Things that limited the outcome are worth protecting.

Closure

7 fields
Numeric Answer

Actions Raised*

Number of CAPA records opened from this investigation.

Text

CAPA IDs*

Linked

Comma separated where several actions were raised.

Links to FDN-014 CAPA ID

Checkbox

Investigation Complete*

Date & Time

Completion Date*

Signature

Lead Signature*

Signature

Sponsor Signature

Optional

Required for level 4.

File Upload

Report File

Optional

FDN-013 · record IDs look like RCA-2026-000 · Linked from every workspace

Open in Knowella

Run it with agents

From a document you fill in to a programme that runs itself

The analysis is a document. What fails around it is the containment boundary, the action that closed without verification, and the third occurrence nobody connected to the first two.

Ella
Ella

Watches incidents and nonconformances for repeat causes across areas and time, and surfaces the pattern before the third occurrence rather than after it.

KnowSafe

Holds the analysis against the incident record while keeping facts and conclusions in separate documents, and reopens the risk assessment where a new hazard is found.

KnowQuality

Manages containment scope and disposition on nonconformances, and blocks closure where effectiveness has not been verified.

KnowMaintain

Supplies asset history so a repeat failure can be seen as a pattern rather than as three separate repairs.

This template lives in General — control tower. The orchestration layer. Registries and engines every other workspace reads from.

Meet General→

Glossary

Root Cause Analysis definitions and key terms

Root cause
A cause which, if removed before the event, would have prevented it, and which lies within the organisation's ability to control.
Contributing factor
A condition that made the event more likely, harder to detect, or worse in outcome, without being necessary to it.
Correction
Action eliminating the detected problem itself: repair, scrap, clean up. Necessary and not sufficient.
Corrective action
Action eliminating the cause so the problem does not recur, which is a different activity from the correction.
Containment
Bounding the affected population back to the last point at which the process was demonstrably in control, applied before analysis begins.
Five whys
An iterative questioning technique. Effective in disciplined hands, and prone to stopping at whichever answer is comfortable.
Fishbone diagram
Cause categorisation across method, machine, material, measurement, environment and people, useful for breadth before depth.
Effectiveness verification
Evidence gathered after implementation, over enough occurrences, that the corrective action worked.

FAQ

Frequently asked questions about root cause analysis

Is human error ever a root cause?+

Almost never as a stopping point. Error is a consequence of conditions: procedure design, time pressure, equipment layout, competence, fatigue, competing priorities. Recording human error as the cause identifies where the failure surfaced and leaves untouched everything that made it likely. The exception is deliberate violation, and even then the question of why the safe method was worth avoiding remains worth asking.

Which method should we use?+

Any structured one, applied with discipline. Five whys suits simple sequences, fishbone gives breadth before depth, fault tree suits complex systems with multiple failure paths, and 8D suits customer-facing problems needing containment. The method matters far less than whether the analysis is willing to reach findings that implicate decisions rather than individuals.

How do we know when we have reached the root cause?+

Apply the prevention test: would removing this, before the event, have prevented it? And the control test: is this within our ability to change? A cause passing both is actionable. Most analyses stop one or two levels above that point, at something true but not sufficient.

How long should we wait to verify effectiveness?+

Long enough for the problem to have recurred if the action failed. For a daily process that may be weeks; for a quarterly one it is quarters. Verifying too early is the most common way effectiveness review becomes a formality, because the absence of recurrence over two days proves nothing.

Should the analysis be blame-free?+

It has to be, and that requires structural separation rather than assurance. If discipline can result from the same process, people will construct accounts that protect them, and the account is the only raw material the analysis has. Run any performance process separately, on its own record, and make the separation visible to the people being asked to explain what happened.

Keep going

Related templates and programmes

Siddarth Singh

Written and reviewed by

Siddarth Singh

Founder & Chief Executive Officer, Knowella

Certified Safety Professional and industrial and systems engineer with more than a decade inside food supply chain, freight and manufacturing operations. This page was written against the current text of the standards it cites, not against secondary summaries of them.

  • Certified Safety Professional (CSP), Board of Certified Safety Professionals
  • MBA, University of Chicago Booth School of Business
  • MS and BS, The Ohio State University, Industrial and Systems Engineering
  • Six Sigma Black Belt
Verify with BCSP →

Sources and last review. Reviewed 16 August 2026 against:

  • ISO 45001:2018 clause 10.2, incident, nonconformity and corrective action
  • ISO 9001:2015 clause 10.2, nonconformity and corrective action
  • IATF 16949:2016 clause 10.2.3, problem solving
  • 21 CFR 820.100, corrective and preventive action, FDA
  • 29 CFR 1910.119(m), incident investigation, OSHA

This page is general guidance, not legal advice. Confirm requirements with your jurisdiction’s regulator.

Start in Minutes, Not Weeks

Launch a Ready-Made Template and Customize It Your Way

Every template is fully editable. Adjust fields, workflows, and branding to match your processes, then deploy to your team instantly.