Worked example library

Incident Report Examples: Complete Records & Factual Narratives

Start with the worked examples to see complete reasoning, then use the shorter pattern library for variation. Level guidance and frameworks show how the same task changes as the evidence, audience, or assignment becomes more demanding.

Before you copy

What to notice in the examples

A strong incident report lets a later reviewer reconstruct what was known at the time: it identifies when and where the event occurred, who was involved or witnessed it, what was directly observed, what immediate actions were taken, what evidence exists, and what remains uncertain without turning assumptions into facts.

  • Identify the incident type, date, time, exact location, reporter, and people involved using the organization’s required fields.
  • Describe the event in a neutral chronological sequence and distinguish direct observation from information reported by someone else.
  • Record injuries, damage, service impact, or near-miss consequences only at the level actually known.
  • Document immediate containment, first response, notifications, and evidence preserved.
  • Separate the event record from later root-cause findings or disciplinary conclusions unless the reporting process explicitly combines them.
Worked format lab

See complete reasoning, not just isolated lines

Use these fuller examples to see what changes between a recognizable pattern and a finished piece of writing. The examples are original or explicitly illustrative, so they demonstrate structure without inventing real-world evidence.

Worked example 1Completed workplace near-miss report

Illustrative example; required fields vary by employer and jurisdiction.

INCIDENT REPORT
Type: Near miss
Date/time: 9 September 2026, approximately 09:35
Location: Receiving area, aisle 3
Reported by: Jordan Lee, operations coordinator

Factual sequence
At approximately 09:35, a sealed carton fell from the second level of a storage rack into aisle 3. No person was in the fall area and no injury was reported. I was standing about six metres away and heard the impact; I did not see the carton begin to fall. Sam Ortiz, who was closer to the rack, reported seeing the carton shift as a pallet was moved in the adjacent bay.

Immediate action
The aisle was closed to foot traffic. The fallen carton was moved only after photographs were taken according to the site process. The shift supervisor and facilities lead were notified.

Known impact
No injury reported. One carton visibly damaged. Product condition has not yet been assessed.

Open facts / follow-up
The reason the carton moved has not been established. Facilities will inspect the rack and pallet position before the aisle reopens.

Why it works: The report distinguishes the writer’s own observation from a witness report, records containment, and leaves cause open for investigation.

Worked example 2Speculation → factual incident narrative

Illustrative rewrite.

Weak: The operator carelessly moved the pallet and almost caused a serious accident.

Stronger: Camera review shows the pallet began moving at 09:34:51. At 09:35:04, one carton fell from the adjacent rack into aisle 3. No one was in the fall area. The current record does not establish why the carton moved. The aisle was closed and the rack was referred for inspection.

Why it works: The revision removes blame and severity speculation while preserving the observable sequence and uncertainty.

Prompt → finished structure

See the decisions between the assignment and the final form

These transformations make the hidden planning step visible so the template does not become a fill-in-the-blanks substitute for judgment.

Transformation 1Witness-heavy notes → incident record

Starting material: Source notes contain direct observation, two witness accounts, a supervisor opinion, and a guessed cause.

Decisions
Separate each fact by source, build the timeline from the confirmed sequence, preserve the two witness differences, and move the supervisor’s cause theory to “unconfirmed” rather than the factual narrative.

Result: Finished structure: required fields → factual timeline → impact → immediate action → evidence/sources → open facts → follow-up.

Transformation 2Blame language → neutral record

Starting material: Draft says an employee was careless, ignored procedure, and caused the event.

Decisions
Replace character judgments with observable actions and conditions. Record which procedure applied only if verified, then leave causal or disciplinary conclusions to the appropriate review.

Result: Finished structure: observation rather than blame, with investigation questions separated from incident facts.

Depth by level

Increase the reasoning, not just the word count

LevelWhat changesQuality test
Routine internal incidentCapture required fields, factual sequence, immediate consequence, response, and follow-up without speculation.A later reader should be able to distinguish what happened from what is still being investigated.
Cross-functional / material incidentAdd evidence sources, impact boundaries, notifications, preservation actions, and clear separation between timeline and later analysis.The record should support investigation without pre-judging it.
Regulated / high-consequence contextUse the organization’s approved form, escalation, confidentiality, legal, safety, privacy, or regulatory process and qualified reviewers.A generic writing guide cannot replace mandatory reporting requirements.
Reusable frameworks

Start from the decisions the format requires

Framework 1
Observation → function
1. What can the viewpoint actually perceive?
2. Which 1–2 details matter now?
3. What do those details change in image, pace, relationship, or action?
4. What interpretation remains uncertain?
Framework 2
Generic → specific revision
Generic line: [x]
Observable evidence: [x]
Context/constraint: [x]
Unnecessary inference removed: [x]
Revised line: [x]
1

Workplace near miss: record that a box fell from an upper shelf, no one was struck, the aisle was closed temporarily, and facilities was asked to inspect the shelving; do not call the cause “poor stacking” unless an investigation establishes that.

2

IT service incident: record start time, affected service, observed symptoms, user impact, containment step, restoration time, evidence links, and follow-up owner while keeping suspected technical cause separate from confirmed cause.

3

Security incident: describe the observed access event, account or system involved, preservation actions, and escalation path without publishing sensitive credentials or investigative details in a broadly shared report.

4

Customer incident: distinguish what the customer reported from what staff directly observed, record the immediate service response, and preserve the case reference used for follow-up.

5

Property damage: identify the object, location, visible damage, discovery time, people present, and immediate safety action without estimating repair cost unless a qualified source provides it.

6

Equipment event: record operating state, alarms or readings, shutdown/containment action, and maintenance handoff while avoiding a technical-cause conclusion before inspection.

7

Short-form minor event: keep the narrative to event, consequence, immediate action, and follow-up while retaining all fields the organization requires.

8

Inconclusive report: state that camera footage was unavailable and two witness accounts differ on the sequence, then identify the next evidence source rather than choosing the cleaner story.

Turn an example into your own writing

Keep the underlying decision or pattern, then replace the subject, evidence, relationship, constraints, and tone with details that belong to your situation. If your final line still works after swapping only one noun, it may be too close to the example.