Incident Report Template
One record for something that went wrong, written so it still stands up months later when somebody asks how it happened.
- Facts in one part, cause and analysis in another
- Actual severity and potential severity, rated separately
- Reportable to a regulator, answered in the first day
- Every corrective action graded by control type
Incident Report
Facts first, analysis after
| # | Immediate action | Done | By | Time |
|---|---|---|---|---|
| 1 | Scene made safe | |||
| 2 | Photographs taken before anything was moved | |||
| 3 | Equipment taken out of service and locked off |
The document you will get. Download for the full, editable file.
Who this incident report is for
Four people read this document, and two of them may never have set foot on the site.
Whoever was there
You are writing the first half, often shaken and in a hurry. It asks only for what you saw and did, in order, because that is the part nobody else can supply later.
Safety or HSE lead
You are investigating. The separation of fact from cause is what lets you reach a root cause instead of inheriting somebody's first theory as evidence.
Compliance or legal
You are deciding whether this is reportable, and by when. The reportability block is answered in the first day because the deadline runs from the incident, not from the investigation.
Insurer or finance
You are pricing exposure. Actual against potential severity, the damage estimate and the days away from work are the four entries that shape a claim.
Which field matters the most in your sector
The form is the same shape everywhere. What changes is which field carries the weight, and it is usually the one a regulator or an insurer reads first. If you run one of these, the sector page goes further than the template does.
- Healthcare
Reportability. Patient and staff incidents carry statutory duties with short clocks, and the deadline runs from the day it happened.
Healthcare maintenance software - Education
The person involved block. Pupil, visitor, contractor and staff incidents follow entirely different reporting routes.
Campus maintenance software - Retail and malls
Members of the public. A slip in a mall concourse is a liability claim, and the witness table is what decides it.
Retail maintenance software - Commercial real estate
Potential severity. Across a portfolio, near misses are the only early warning you get before an incident that costs real money.
Portfolio maintenance software - FM service providers
Employment status. Employee, agency and subcontractor incidents are reported by different parties, and getting that wrong is its own breach.
FM service provider software - Corporate facilities
Conditions at the time. Lighting, floor surface, noise and time pressure are what turn one person's accident into a building problem.
Corporate facilities software
What an incident report should include
An incident report is the record of something that went wrong: what happened, who was involved, what was done immediately, and why it happened. It keeps the facts separate from the analysis, rates both the actual and the potential severity, answers whether a regulator has to be told, and grades every corrective action by control type.
A. Fields specific to an incident report
| Field | What goes in it | Why it earns its place |
|---|---|---|
| Incident type | Injury, illness, near miss, property damage, environmental, security, fire or vehicle | Decides the reporting route before anything else. A near miss logged as an injury and an injury logged as a near miss are both failures of the same field. |
| Exact location | Specific enough to find the spot again | Not the building, the spot. An investigator returning three weeks later needs to stand where it happened, and photographs need a reference. |
| Person involved and their status | Employee, contractor, agency, visitor, tenant or member of the public | Status decides who reports it, who is liable and which log it goes on. It is the field most often assumed and most consequential when wrong. |
| Sequence of events, in order | What they were doing immediately before, then what went wrong | Facts only. Cause, opinion and blame belong in the analysis part, and a narrative that mixes them cannot be used by an investigator or an insurer. |
| Conditions at the time | Lighting, floor surface, weather, noise, time pressure, staffing | The entries that turn a personal accident into a systemic finding. Nobody remembers them a week later, which is why they are captured now. |
| Immediate response | Ten actions, each with who did it and the time | Photographs before anything is moved is the line most often skipped and least often recoverable. Once the scene is cleared it cannot be reconstructed. |
| Actual and potential severity | Both rated, from fatality down to negligible | Rated separately on purpose. A report that only records what happened will always underrate the near miss that nearly killed someone. |
| Reportability | Whether a regulator must be told, the deadline, and the reference once reported | Answered in the first day. Reporting deadlines are short and they start from the day of the incident, not the day somebody finished investigating. |
| Corrective actions with control type | Eliminate, substitute, engineering, administrative or PPE, strongest to weakest | Grades the fix, not just the finding. The distribution across those five is the most honest measure of whether the investigation did its job. |
If you cut the form down, keep potential severity and the control type column. The first stops a near miss being filed as trivia; the second stops a serious investigation closing with a toolbox talk. Both are single fields, and both are the ones that get dropped when a form is shortened for speed.
B. What it looks like filled in
The control type summary from one investigation. This is the table that grades the investigation rather than the workforce, and the Excel version counts it for you.
| Control type | Strength | Actions | What was raised on this incident |
|---|---|---|---|
| Eliminate | Strongest | 0 | |
| Substitute | 0 | ||
| Engineering | 1 | Fixed guard fitted to the infeed roller | |
| Administrative | 2 | Toolbox talk delivered, method statement revised | |
| PPE | Weakest | 1 | Cut-resistant gloves issued |
| Total actions raised | 4 |
Report INC-2026-0087, infeed roller, actual severity first aid, potential severity major injury. Four actions, and only one of them is engineering. Three quarters of the response asks people to behave differently around a hazard that is still there, which is exactly the pattern the document warns about: a column that is all administrative and PPE is a warning about the investigation, not about the workforce. Read alongside the potential severity of major injury, the honest conclusion is that the guard was the answer and the other three were comfort.
Word to edit the incident types and your own reporting routes, Excel to count the control type distribution and the action totals, PDF for the file and the insurer. Free, and yours to rebrand.
How do you fill in an incident report?
Fill Part A while it is fresh and resist the urge to explain anything. The explaining has its own part, and keeping them apart is the whole method. Six steps.
Log the incident and its type first
Report number, the date and time it happened, the date and time it was reported and to whom, the incident type, the site and the exact location. Specific enough that somebody can stand on the spot weeks later.
Record the person and their status
Name, job title, whether they are an employee, contractor, agency, visitor, tenant or a member of the public, their department or employer, and how long they have been in the role. Status decides the reporting route.
Write what happened as facts, in order
What they were doing immediately before, what went wrong, the PPE worn, the equipment or substance involved, and the conditions at the time. No cause, no opinion, no blame. Those have their own section.
Work the immediate response block, with names and times
Scene made safe, medical help, emergency services, area isolated, equipment locked off, and photographs taken before anything was moved. That last one cannot be done later.
Analyse it separately: immediate cause, then root cause
The unsafe act or condition at the moment, the contributing factors, and why the condition was allowed to exist. Rate actual severity and, separately, what the severity could have been.
Answer reportability, then grade the actions
Decide within the first day whether a regulator must be told and note the deadline. Then raise corrective actions and mark each one eliminate, substitute, engineering, administrative or PPE, and look hard at the distribution.
Why the facts and the analysis are separate parts
The document is deliberately in parts, and the split between them is the thing most incident forms get wrong.
| Aspect | Part A, the facts | Part C, the analysis |
|---|---|---|
| Written when | Immediately, while it is fresh | After, once evidence is gathered |
| Written by | Whoever was there | Whoever investigates |
| Contains | What was seen, done, worn, and the conditions | Immediate cause, contributing factors, root cause |
| Standard applied | Observable and checkable | Reasoned and arguable |
| If they are mixed | A first theory becomes evidence and cannot be unpicked | The facts inherit somebody's opinion |
| Who relies on the split | An investigator, an insurer and a regulator, all of them | The organisation, when deciding what to change |
This is the single reason most incident forms fail. A narrative that says the operator was rushing and reached in has already decided the cause, and no investigator can now separate what was seen from what was assumed. Write that they reached into the infeed while the roller was turning in Part A, and put rushing, staffing and time pressure where they belong in Part C.
When the template starts to feel limiting
A form handles one incident well. It handles a safety programme badly, and always in the same four ways.
Reporting deadlines cannot count themselves
The clock starts on the day of the incident and it is short. A form in a folder does not tell you the deadline passes on Friday, and a missed statutory report is its own offence on top of the original event.
Corrective actions drift out of sight
Each action has an owner and a date, on a sheet, in a drawer. Nothing chases them, and the verification line at the end is signed long before anyone checks whether the guard was actually fitted.
Repeats are invisible
The question that matters is whether anything like this has happened before. On paper that is a folder search, so the honest answer is usually nobody knows, and the same incident gets investigated from scratch.
You cannot see the pattern
Which location, which task, which shift, which control type keeps failing. Every one of those answers lives across dozens of reports, and a folder cannot count them.
What running this in Facilio looks like
The template is the paper version of this record. The fields are the same ones; the difference is that a corrective action stops being a line on a sheet and becomes work with an owner, a date and a verification step.
Work Completion Validator
An action cannot be closed by being ticked
On paper an action is complete when somebody signs the bottom of the form. Work Completion Validator holds each corrective action against evidence that it was actually done, so a guard signed off as fitted with nothing attached is caught before the report closes.
Ops Performance Intelligence
Reporting deadlines and action dates chase themselves
The reportability clock starts from the incident date, and every corrective action carries its own due date, so a statutory deadline or an overdue action surfaces before it lapses rather than at the next audit.
Audit Report Intelligence
Repeats and patterns become a query
Location, task, injury type, control type and potential severity are held as data rather than prose, so the question of whether this has happened before is answered in seconds instead of being assumed to be no.
Contractor Work Tracker
Actions become real work, including a contractor's
An engineering control raised at an investigation becomes a job with a trade, a cost and a completion record, whether it goes to your own team or out to a contractor, so the fix is tracked like any other work rather than living only in the report.
Audit-trailed. Every answer Atom AI gives traces back to the record it came from, so a claim in a report can be followed to the visit that produced it.
Frequently asked questions
What is an incident report?
An incident report is the record of an event that caused harm or could have caused harm: an injury, an illness, a near miss, property damage, an environmental release, a security event, a fire or a vehicle incident. It captures what happened, who was involved, what was done immediately, why it happened, whether it is reportable, and what is being changed as a result.
The structure matters as much as the content. Facts are recorded separately from cause, because an investigator, an insurer and a regulator all need to see what was observed without somebody's first theory mixed into it.
What should an incident report include?
At minimum: a unique report number, the date and time of the incident and of the report, who it was reported to, the incident type, the site and exact location, what was being done at the time, the person involved with their employment status, any injury with the body part, nature and treatment, the sequence of events as facts, the PPE and equipment involved, the conditions at the time, witnesses with statements, the immediate response actions with names and times, the immediate and root cause, actual and potential severity, likelihood of recurrence, reportability with the deadline, corrective actions graded by control type, and two signatures.
Why keep the facts and the analysis in separate sections?
Because once they are mixed, nobody can separate what was seen from what was assumed. A narrative that says the operator was rushing has already decided the cause, and that theory is now embedded in the evidence.
Write the observable events in the facts section and put rushing, staffing and time pressure in the analysis, where they can be argued with and where a reviewer can disagree without rewriting history.
What is the difference between actual and potential severity?
Actual severity is what happened. Potential severity is what could reasonably have happened had circumstances differed slightly, and it is rated separately.
Without it, a near miss that could have killed someone is filed below a cut that needed a plaster, and the report ranks its own findings wrongly. Potential severity is what makes a near miss worth investigating at all.
What does the control type column actually do?
It grades each corrective action against the hierarchy of control: eliminate, substitute, engineering, administrative, then PPE, strongest to weakest. The document then counts the distribution.
The distribution is the useful part. If every action is administrative or PPE, the hazard is still there and the response has asked people to behave differently around it. That is a finding about the investigation, not about the workforce.
How quickly do I have to report an incident to a regulator?
It depends on the jurisdiction and the severity, which is why the form asks for the regulator, the deadline and the date reported rather than assuming a number. Some categories are same-day, others are a matter of days.
What the template insists on is answering the question within the first day. The deadline runs from the date of the incident, not from the date the investigation finishes, so leaving it until the analysis is complete is how deadlines get missed.
Can I edit and rebrand this template?
Yes. It is free to use, edit, rename and put your own logo on, internally or for clients. No attribution required.
The Word version is the one to edit if you want to change the incident types, the severity scales or your own reporting routes; the Excel version is the one to use if you want the control type distribution and the action counts to work themselves out.
In one paragraph
An incident report is the record of something that went wrong, and it is only useful if it is disciplined. Log the type, the exact location and the person's employment status first, because those three decide the reporting route. Write the sequence of events as facts, with the PPE, the equipment and the conditions at the time, and keep every explanation out of that section. Work the immediate response block with names and times, and take the photographs before anything is moved. Then analyse it separately: immediate cause, contributing factors, root cause, and rate the potential severity as well as the actual. Answer reportability inside the first day, and grade every corrective action by control type, because a response that is all administrative and PPE has left the hazard where it was.
The template is the floor, not the ceiling
Take the template; it will carry one incident from the moment it happened to a verified corrective action. When one form per incident stops being enough, a connected CMMS runs the programme: reporting deadlines that count themselves, actions that become tracked work, and the question of whether this has happened here before answered as a query.