Non-Fiction / Free articles / Event investigation

Root Cause Analysis vs. Learning From Events

By Todd Jerome Jenkins · September 30, 2026

After a workplace incident, one question appears almost automatically:

What was the root cause?

The question sounds reasonable.

If something went wrong, find the underlying cause, correct it, and prevent the event from happening again.

Root Cause Analysis has helped organizations move beyond immediate explanations such as:

  • the employee made a mistake,
  • the procedure was not followed,
  • the equipment failed, or
  • someone was not paying attention.

That is valuable progress.

But there is another question worth asking:

What if there is not one root cause?

Complex workplace events can develop through combinations of conditions, decisions, controls, equipment, organizational systems, normal work practices, and changing circumstances.

The goal of an investigation should therefore not be to force the event into a single causal box.

The goal should be to develop the best-supported understanding of the event and use that understanding to improve the work system.

What Is Root Cause Analysis?

Root Cause Analysis, or RCA, is a general approach for looking beyond the immediate cause of an event and identifying deeper conditions that allowed it to occur.

For example:

A worker slips on oil.

The immediate explanation might be:

The employee slipped because oil was on the floor.

A deeper analysis asks:

Why was the oil there?

Perhaps a machine was leaking.

Then:

Why was the machine leaking?

Perhaps a component had deteriorated.

Then:

Why wasn't the deterioration detected?

Perhaps the inspection or maintenance system did not identify it.

The investigation has moved from the injury to the condition that allowed the exposure to exist.

That is the basic value of Root Cause Analysis.

OSHA and EPA guidance similarly encourages employers to look beyond immediate causes and identify underlying or system-related reasons for incidents.

Root Cause Analysis Is Not the Problem

The phrase root cause sometimes receives criticism because it can imply that every event has one fundamental cause waiting to be discovered.

But that is not necessarily how Root Cause Analysis must be practiced.

OSHA's current safety-management guidance explicitly recognizes that an incident can have more than one root cause and recommends examining underlying hazards and safety-program shortcomings rather than stopping at the immediate trigger.

So the problem is not asking deeper questions.

The problem begins when the investigation assumes in advance that:

There must be one root cause, and we are finished when we find it.

Complex events may not cooperate with that assumption.

Events Usually Have More Than One Influence

Consider a forklift and pedestrian incident.

An investigation might identify:

  • restricted visibility,
  • pedestrian traffic,
  • equipment movement,
  • noise,
  • site layout,
  • production activity,
  • communication practices,
  • operator decisions,
  • pedestrian decisions,
  • supervision,
  • traffic controls, and
  • equipment design.

Which one is the root cause?

Perhaps several conditions interacted.

Remove one and the event might not occur.

Change another and the outcome might be different.

The useful question becomes less:

Which one caused the event?

and more:

How did these conditions interact to produce this outcome?

Immediate Cause vs. Deeper Explanation

One useful contribution of traditional Root Cause Analysis is the distinction between an immediate cause and a deeper explanation.

Suppose an employee reaches into a machine.

The immediate action matters.

But the investigation should continue.

Ask:

  • Why was reaching into the machine possible?
  • Why did the employee need to reach there?
  • Was the machine operating?
  • What guarding existed?
  • What interlocks existed?
  • Was material routinely becoming stuck?
  • How was that problem normally resolved?
  • What did the procedure require?
  • Did the procedure match the work?
  • What production conditions existed?
  • Had similar situations occurred before?

The employee's action may remain an important part of the event.

It simply does not have to be the end of the investigation.

OSHA specifically cautions that concluding a worker was careless, made an error, or failed to follow a procedure can prevent investigators from discovering the underlying conditions that need correction.

Human Error Is a Starting Point

Suppose the investigation determines:

The operator selected the wrong control.

That tells us something.

Now ask:

  • Were similar controls located together?
  • Were they clearly labeled?
  • Was feedback immediate?
  • Was the control arrangement familiar?
  • Was the operator interrupted?
  • Was visibility limited?
  • What normally prevents an incorrect selection?
  • What detected the mistake?
  • Why could the error progress into an incident?

Humans make errors.

A well-designed system should anticipate at least some predictable errors and provide opportunities to prevent, detect, recover from, or reduce their consequences.

The useful investigation question is therefore not simply:

Who made the mistake?

It is also:

How did the system respond when the mistake occurred?

Procedure Violation Is Also a Starting Point

Another common conclusion is:

The employee failed to follow the procedure.

That may be factually correct.

It still leaves questions.

Was the procedure:

  • available,
  • current,
  • understandable,
  • practical,
  • compatible with the equipment,
  • compatible with the environment, and
  • consistent with how the work was normally performed?

Was the deviation unusual?

Or was it how experienced employees normally completed the task?

Did supervisors know?

Were there conflicting expectations?

Was the procedure slower, more difficult, or impossible under certain conditions?

None of those questions automatically excuse the behavior.

They help explain it.

OSHA's incident-investigation guidance makes essentially the same point: when a procedure or rule was not followed, investigators should continue asking why rather than treating the violation itself as the complete cause.

The Limits of Asking “Why?”

The 5 Whys technique can be useful.

Each answer produces another question.

Why did the machine stop?

Why did the employee enter the area?

Why was the equipment still energized?

Why did the procedure not prevent that?

Why had the condition not been identified previously?

This can move an investigation deeper.

But the technique can also create a problem.

If investigators follow only one chain of “why,” they may produce one neat causal path through an event that actually contained several interacting conditions.

The problem is not asking why.

The problem is assuming there is only one direction in which to ask it.

Instead of drawing only a straight line:

Event → Cause → Cause → Root Cause

consider building a network:

Event → People + Equipment + Environment + Controls + Planning + Organizational Conditions + Normal Work

Now the investigation can explore multiple paths.

Root Cause Analysis Can Become a Search for the Label

Some investigation systems require a root cause before the report can be closed.

That creates an unintended incentive.

The investigator may begin searching for something that fits the available category.

Common labels include:

  • inadequate training,
  • lack of supervision,
  • procedure not followed,
  • poor communication,
  • human error, or
  • management failure.

A label can make a report look complete.

But ask:

What does the label actually explain?

“Inadequate training,” for example, should lead to additional questions:

  • What specifically did the worker not know?
  • What evidence demonstrates the knowledge gap?
  • Was the task covered by training?
  • Had the employee performed it successfully before?
  • Would additional training realistically change the condition?
  • Were other controls available?

Without those questions, training can become another convenient stopping point.

Learning From Events Takes a Broader View

Learning from events begins with a different objective.

Instead of asking only:

What failed?

ask:

What can this event teach us about the work?

That can include:

  • what happened,
  • how work normally happens,
  • what changed,
  • what conditions existed,
  • what people were trying to accomplish,
  • what information they had,
  • what controls were expected to work,
  • what controls actually worked,
  • what controls failed,
  • what adaptations people made, and
  • why the outcome was unusual.

The event becomes a window into the system.

Learn From What Worked

Imagine a worker loses control of a heavy load.

The investigation naturally examines what failed.

But suppose the same task has been completed successfully 2,000 times.

That creates another valuable question:

Why does this normally work?

Perhaps workers usually:

  • communicate informally,
  • reposition themselves,
  • adjust equipment,
  • wait for better conditions,
  • use experience to recognize instability, or
  • compensate for weaknesses in the formal process.

Those successful adaptations may not appear anywhere in the procedure.

Understanding them can reveal both strengths and vulnerabilities.

Examine the Controls

Whether you call the process Root Cause Analysis, event learning, or incident investigation, controls deserve special attention.

Ask:

What was supposed to prevent this?

Then examine each relevant control.

Was it:

  • present,
  • available,
  • functional,
  • understood,
  • practical,
  • used,
  • reliable, and
  • capable of controlling the exposure?

Also ask:

What prevented the outcome from being worse?

A control may fail partially rather than completely.

An incident can therefore reveal both weaknesses and strengths.

Avoid Hindsight Bias

After an event, the correct action often looks obvious.

Before the event, it may not have been.

Investigators know the outcome.

The people involved did not.

Try to reconstruct the situation from their perspective.

What information did they have?

What were they expecting?

What normally happened?

What signals were available?

Which signals seemed important?

What competing demands existed?

What alternatives appeared reasonable?

Understanding that context does not eliminate accountability.

It improves the accuracy of the investigation.

Accountability and Learning Can Coexist

Moving beyond blame does not mean organizations cannot hold people accountable.

Deliberate misconduct, reckless actions, intentional violations, and other behaviors may require an appropriate organizational response.

But accountability and causal explanation answer different questions.

Accountability asks how the organization should respond to behavior.

Investigation asks how and why the event developed.

Stopping the investigation because accountability has been assigned can leave important conditions undiscovered.

Likewise, identifying system conditions does not automatically determine that every individual action was acceptable.

Both questions can be addressed.

Better Corrective Actions Come From Better Explanations

The quality of the corrective action depends heavily on the quality of the explanation.

If the conclusion is:

Employee was careless

the corrective action may be:

Counsel employee to be more careful.

If the investigation discovers that:

  • visibility was restricted,
  • pedestrians and equipment shared the same route,
  • warning devices were difficult to hear,
  • traffic increased during shift change, and
  • there was no physical separation,

the corrective-action discussion changes.

Now the organization can consider stronger controls.

The purpose of deeper investigation is not philosophical.

It is practical.

Better understanding creates more options for prevention.

Root Cause Analysis and Learning From Events Can Work Together

Organizations do not necessarily need to choose between Root Cause Analysis and modern learning approaches.

A strong investigation can use both.

Use Root Cause Analysis to keep asking beyond immediate explanations.

Use broader event-learning methods to prevent that questioning from collapsing into a single predetermined causal chain.

Together, the investigation can ask:

What happened?

What evidence supports that account?

What conditions contributed?

Why did those conditions exist?

How did the controls perform?

What normally makes this work successful?

What did the situation look like to the people involved?

What can we change?

That is a much richer investigation.

When a Learning Team Can Help

Sometimes the formal investigation establishes what happened but exposes questions about normal work.

That can be a good point to use a Learning Team.

An investigation may establish:

  • the event sequence,
  • relevant evidence,
  • contributing conditions, and
  • control performance.

A Learning Team can explore:

  • how the task normally happens,
  • where work varies,
  • what makes it difficult,
  • what employees routinely adapt,
  • what helps them succeed, and
  • where the formal process differs from actual work.

Learning Teams can also be used proactively, without waiting for an incident.

The two methods are complementary.

Investigation establishes a supported account and tests the controls surrounding an event.

A Learning Team explores how the work actually happens when deeper understanding is useful.

Do We Still Need Root Causes?

Organizations can continue using the term if it serves them.

OSHA itself uses it extensively and defines root causes in system-oriented terms. OSHA and EPA guidance also emphasizes that an incident may have multiple root causes rather than one.

The important issue is not the vocabulary.

It is the quality of the investigation.

If root cause means:

Look beyond the immediate event and identify deeper correctable system conditions

then the concept remains useful.

If it means:

Find the one cause, assign the category, and close the investigation

then it may limit learning.

The Better Question

Instead of ending with:

What was the root cause?

try asking:

What does the evidence support about how this event developed, what conditions contributed to it, how the controls performed, and what can we learn that will improve the system?

That question does not guarantee a simple answer.

Real work is not always simple.

But an investigation does not exist to produce the simplest explanation.

It exists to produce the most useful supported understanding.

That is the difference between merely identifying a cause and genuinely learning from an event.

Go Deeper: Modern Event Investigation Techniques

Modern Event Investigation Techniques provides a practical framework for evidence-based workplace investigations, including developing supported accounts, evaluating controls, testing competing explanations, and moving beyond simplistic conclusions.

It is designed for safety professionals, supervisors, managers, and others responsible for investigating and learning from workplace events.

Available in paperback and Kindle on Amazon.

Download the free MEIT companion workbook and fictional evidence pack to practice evidence-supported investigation.

Related reading