# Root cause analysis worksheet

> A root cause analysis worksheet for incidents and near misses. It walks a small team through the event timeline, five whys, contributing-factor categories, causal statements and a ranked set of actions. Fixes lean on design changes instead of reminders. Each action leaves with a measure and a review date.

Source: https://incidentkit.ai/templates/root-cause-analysis-worksheet · Updated Oct 5, 2026

## When to use it

- A serious event, like severe harm, death, permanent harm or a sentinel event, where an accrediting body expects a full analysis.
- A cluster or repeat of lower-severity events that points to a shared cause, found in your trend data.
- A near miss with high potential for harm, where the safeguards held by chance.
- The QAPI committee has chosen a performance improvement project and needs the cause before it picks an action.
- A recordable injury or a survey finding needs a documented cause and a lasting corrective action.

## The template

### 1. Event summary

- Incident reference number
- Date of event
- Event in one sentence (Say what happened, not who did it: 'Resident fell while toileting alone at night and fractured a hip.')
- Harm level: No harm or near miss / Mild harm / Moderate harm / Severe or permanent harm / Death
- Meets your sentinel or serious reportable event definition (The Joint Commission expects the analysis and action plan within 45 business days of the event or of learning about it.)
- Analysis team (names and roles) (Include someone who does this work daily, someone who does not, and a leader who can approve changes.)
- Date analysis started

### 2. Facts and timeline

- Sequence of events with clock times (List what happened in order. Mark the last normal step and where it went wrong. Use records, not memory alone.)
- What should have happened (the intended process) (Write the standard, then compare. The gap is where to look.)
- Sources reviewed (Records, logs, device data, policies, photos, schedules, staffing sheets. Note who was interviewed.)
- What people say made it difficult (Ask 'what made this a sensible thing to do at that moment?' not 'why did you do that?')
- Similar earlier events (Search your incident log for the same place, equipment, drug, step or shift.)

### 3. Five whys

- Problem statement (One sentence on what went wrong, not who: 'A heparin infusion ran at the wrong concentration.')
- Why 1: why did the problem happen?
- Why 2: why did that happen?
- Why 3: why did that happen?
- Why 4: why did that happen?
- Why 5: or where the chain stops at something you can change (Stop at a process, design or management choice you can change. 'Be more careful' is not a root cause. If the chain splits, copy this section.)

### 4. Contributing factors by category

- Task and process design (Was the process clear and easy to follow? Any workarounds or easy-to-skip steps? Write 'not a factor' if none.)
- Communication and handoffs (Were orders and handoffs complete? Was anything spoken that should be written, or lost at shift change?)
- Staffing, workload and scheduling (What were staffing and workload? Were staff new, floating, on a long shift or covering several tasks?)
- Equipment, technology and software (Did equipment, alarms, software or defaults help or get in the way? Was it the right tool, and maintained?)
- Environment and layout (Lighting, noise, clutter, space, storage, signs, distance to supplies.)
- Training, competence and supervision (Was training and competency current for this task? Was supervision easy to reach?)
- Policies, procedures and leadership oversight (Did a policy exist, match real work and get audited? Did leaders know of earlier warning signs?)
- Patient, worker and external factors (Condition, behavior, language, or outside factors like a supplier change.)

### 5. Root causes

- Root cause 1, as a causal statement (Use cause and effect: '[Condition] made [event] more likely because [mechanism].' Name conditions, not people or 'failure to'.)
- Root cause 2, as a causal statement
- Root cause 3, as a causal statement
- Evidence for each cause (Point to the record, log or interview that supports it. No evidence means a guess.)
- Just culture screen: no reckless or intentional conduct found (If an act looks deliberately unsafe, send it to HR or peer review. IHI says RCA2 is not advised for blameworthy acts.)

### 6. Action plan using the action hierarchy

- Stronger actions chosen (Need the least memory from people: redesign, add a forcing function, simplify, standardize equipment, involve leaders. Industrial sites: remove, swap or engineer out the hazard before administrative controls or PPE.)
- Intermediate actions chosen (Two independent checks, more staff or less workload, software changes, fewer distractions, checklists, separating look-alikes, read-back.)
- Weaker actions chosen (Double checks, warnings, new procedures, training. Alone they rarely hold.)
- Every root cause has at least one stronger or intermediate action (IHI recommends at least one stronger or intermediate action for each cause.)
- An interim safety measure is in place while the permanent fix is built
- Leadership reviewed and approved the actions (If an action is not approved, record why and choose a replacement.)

### 7. Measures and follow-up

- Process measure: is the fix being done? (For example, percent of scans completed, rounds done or audits passed.)
- Outcome measure: is the harm falling? (For example, falls per 1,000 resident-days, or events by location.)
- Target, and how long it must hold
- Date to review results (Set it now, before the action ships.)
- Lessons to share (units, sites, committees)

### 8. Approval

- Date analysis completed
- Facilitator
- Quality, risk or EHS leader
- Senior leader approving the actions
- Date reported to the QAPI committee or governing body

## How to fill it out well

1. Match depth to risk. Use the whole worksheet for serious harm, repeat events and high-potential near misses. For lower-risk events, sections 1 to 3 and 6 are enough.
2. Build the timeline first, from records, logs and interviews. Mark the last normal step and where it went wrong.
3. Run the five whys from the problem statement until the answer is something you can change. If the chain splits, copy section 3 and follow each branch.
4. Use the factor categories to catch what the whys missed. Write 'not a factor' where none applies, so readers know you looked.
5. Write each root cause as a cause-and-effect statement about a condition, not a person, and link it to evidence.
6. Pick actions from the stronger and intermediate levels, and use weaker actions to support them. Get a senior leader to approve.
7. Move each approved action into the [corrective action plan](https://incidentkit.ai/templates/corrective-action-plan) with an owner, a due date, evidence and an effectiveness check.

## Tips

- Five whys follows one path. The factor categories check that you did not stop at the first plausible chain.
- 'Human error' is where the analysis starts. Ask what made the error easy to make and hard to catch.
- Retraining and a new policy rarely hold alone. IHI calls them weaker actions.
- For a sentinel event reported to the Joint Commission, the analysis and action plan are expected within 45 business days. Every sentinel event needs the analysis, reported or not.
- Set the effectiveness review date while the team is still in the room.

## Frequently asked questions

### What is the five whys technique?

Five whys moves from a problem to a cause you can change by asking 'why did that happen?' about five times. It suits simple, single-path problems. For complex events, add a timeline and contributing-factor categories, because causes often combine. See [five whys vs fishbone vs fault tree](https://incidentkit.ai/blog/five-whys-vs-fishbone-vs-fault-tree).

### What is the action hierarchy?

It ranks fixes by how much they rely on people remembering. Stronger: design changes, forcing functions, simpler processes, standard equipment. Intermediate: redundancy, checklists, software changes. Weaker: double checks, warnings, new policies, training. IHI's version, part of RCA2, builds on VA National Center for Patient Safety tools.

### How long does the Joint Commission allow for a root cause analysis?

The Joint Commission expects a thorough analysis and action plan within 45 business days of the event or of learning about it. Reporting is encouraged, not required. The analysis is required for every sentinel event.

### Why do root cause analyses so often fail to prevent repeats?

AHRQ PSNet says RCAs often fail to produce lasting fixes because they rely on weak steps like education and policy enforcement. Leadership involvement, stronger actions and measured results help. This worksheet ranks actions and requires a measure and review date.

### Does OSHA expect a root cause analysis?

OSHA's guidance asks employers to investigate injuries and close calls to find root causes, not to assign blame, using a team of managers and employees. It requires no single method. A timeline, five whys and the hierarchy of controls are common choices.

## Sources

- [IHI Patient Safety Essentials Toolkit: Action Hierarchy (part of RCA2), as hosted by the Minnesota Department of Health](https://www.health.mn.gov/facilities/patientsafety/adverseevents/toolkit/docs/safetytoolkit_actionhierarchy.pdf)
- [IHI: RCA2, Improving Root Cause Analyses and Actions to Prevent Harm](https://www.ihi.org/library/tools/rca2-improving-root-cause-analyses-and-actions-prevent-harm)
- [AHRQ PSNet: Root cause analysis (primer)](https://psnet.ahrq.gov/primer/root-cause-analysis)
- [The Joint Commission: Sentinel Event Policy (Comprehensive Accreditation Manual, SE chapter)](https://www.jointcommission.org/-/media/tjc/documents/resources/patient-safety-topics/sentinel-event/camncc_20_se_all_current.pdf)
- [OSHA: Incident investigation](https://www.osha.gov/incident-investigation)
- [CDC NIOSH: Hierarchy of controls](https://www.cdc.gov/niosh/hierarchy-of-controls/about/index.html)

## Related

- [Root cause analysis and CAPA: methods and strong actions](https://incidentkit.ai/guides/root-cause-analysis-and-capa-guide)
- [Root Cause Analysis: How to Run One That Leads to Action](https://incidentkit.ai/use-cases/root-cause-analysis)
- [Five whys vs fishbone vs fault tree: how to choose](https://incidentkit.ai/blog/five-whys-vs-fishbone-vs-fault-tree)
- [Five whys: definition and meaning](https://incidentkit.ai/glossary/five-whys)
- [Corrective Action Plan Template (CAPA, Printable)](https://incidentkit.ai/templates/corrective-action-plan)
- [Incident investigations and root cause analysis](https://incidentkit.ai/product/investigations)
