How to run a root cause analysis that leads to action
Short answer
Run a root cause analysis by building a timeline, finding contributing factors and asking why until you reach a system cause. Rank actions by strength and scale effort to severity. CMS tells surveyors to check whether a facility stops at staff error or digs into causes.
What a root cause analysis is, and when
A root cause analysis finds the system causes behind an event and ends in actions that stop a repeat. Match depth to severity. OSHA says to investigate close calls, ask why, and include managers and workers.
| Trigger | Depth |
|---|---|
| Death, permanent harm, severe temporary harm or a serious process release | Full team review at once. Sentinel events have accreditor and state deadlines |
| Harm with a temporary effect | Focused review: timeline, factors, five whys |
| Near miss with high potential | Focused review |
| A repeat of a known event | Full review: the old fix failed |
Eight steps from event to action
Eight steps, from secured facts to verified actions.
- Secure factsPreserve equipment, records and the scene. Collect first accounts that day.
- Form a teamInclude a worker, an outsider and a facilitator.
- Build the timelineList events in order, with times. Mark where reality differed from the plan.
- Find factorsUse the table below.
- Ask whyKeep asking until you reach something you control, like a layout or a missing check.
- State causesWrite each cause and its effect, without blame.
- Rank actionsPrefer design changes to reminders.
- Assign and verifyOne owner and a check date each. Share findings with managers, supervisors and workers.
Interview for facts, not fault
- Interview people one at a time, away from supervisors.
- Start open: walk me through what happened.
- Ask what normally happens and how that day differed.
- Ask what would make the task safer. Workers often know.
- Save why for the system: ask what led to the step, not who skipped it.
OSHA stresses objectivity and open-mindedness. That starts with how you ask.
Contributing factor categories
Look across seven categories, not just the person closest to the event.
| Category | Healthcare example | Industrial example |
|---|---|---|
| Task and process | No standard handoff | Lockout step missing |
| Equipment | Look-alike vials, pump defaults | Guard off, interlock bypassed |
| Environment | Poor lighting, wet floors | Noise, heat, blind corner |
| Communication | Verbal order not read back | Handover misses open permit |
| Staffing and workload | Understaffed medication pass | Overtime, thin crew |
| Training and supervision | Unoriented agency staff | Contractor skipped site induction |
| Policy and leadership | Conflicting procedures | Targets discourage stopping the line |
Write causal statements, not blame
Name a cause the organization can change, its effect and the event. CMS's ASC guidance gives the model: dismissing the nurse who made a medication error is not a systems approach. Ask about storage, orders and training.
| Weak | Strong |
|---|---|
| The nurse failed to verify the dose. | Two strengths of one drug sat side by side with similar labels, so a wrong pick was likely. |
| The operator did not follow the procedure. | The job card left out the guard check, so the step relied on memory during a rushed changeover. |
Both strong statements are illustrations, not real findings.
Pick actions by strength
RCA2 guidance in patient safety ranks actions by strength. Forcing functions are strong. Education and new policies are weak: they rely on memory. Industry uses the hierarchy of controls.
One cause, three actions. The cause: two strengths of one drug sit side by side.
- Weak: remind staff to check the strength.
- Middle: add a read-back step.
- Strong: store the strengths apart, in marked places.
Use a weak action alongside a stronger one, never in place of it. See closing corrective actions.
Mistakes to avoid
These habits turn a review into paperwork.
- Stopping at human error. Ask what made it likely.
- Asking who instead of why.
- Running one five-whys chain for several causes.
- Investigating alone. A team sees more.
- Keeping findings from workers. OSHA says share results with managers, supervisors and workers.
- Calling the review done before anyone checks the fix worked.
How IncidentKit changes the job
Lauren drafts the investigation: timeline, contributing factors and five whys, marked Lauren · draft. A person reviews, edits and signs. Human-authored RCA templates are rolling out.
Corrective actions link to the factors they answer. The audit trail shows every edit. Analytics show whether a cause keeps appearing.
The parts of IncidentKit behind this
- Investigations and RCA: A guided investigation: find causes, pick a disposition, and a person signs.
- Lauren, the AI assistant: Tell Lauren what happened. She asks, fills the form, and a person signs.
- Incident reporting: The full record holds who, what, where, harm, evidence and what happens next.
- Corrective actions (CAPA): Every fix has an owner, a date and proof. Unverified fixes keep it open.
- Analytics: See which rooms, shifts and equipment keep showing up in your incidents.
- Audit trail: Every edit is logged, so you can show who changed what, and when.
Frequently asked questions
How is root cause analysis different from an incident report?
An incident report records what happened. A root cause analysis asks why. Every serious event needs a report; only some need a full analysis.
How long should a root cause analysis take?
It depends on severity. Gather facts the same day and finish a full analysis while evidence is fresh. Accreditors set sentinel event deadlines; your state or CMS may add others.
Which method should I use: five whys, fishbone or fault tree?
Use five whys for simple events, a fishbone to list factors with a team, and a fault tree for complex failures. See five whys vs fishbone vs fault tree.
Can software do the root cause analysis for me?
No. People decide. Lauren drafts, marked Lauren · draft, and a person reviews, edits and signs. The conclusions are the team's. Human-authored RCA templates are rolling out.
Sources
- OSHA: Recommended practices, hazard identification and incident investigation
- CMS: State Operations Manual Appendix L, QAPI systems approach (Q-0082)
- AHRQ PSNet: RCA2 and the evolution of root cause analysis
- IHI: RCA2, Improving Root Cause Analyses and Actions to Prevent Harm
- CMS: State Operations Manual Appendix PP, F867 (42 CFR 483.75(d)(2))
Reviewed against the sources above on Oct 5, 2026. Rules change: confirm current requirements with the issuing body or your counsel before relying on any summary.
Start with one incident.
Create your kit in about ten minutes and report the first incident the same day. Free to start, no card.