Every organization that has weathered a significant incident—whether a workplace injury, a data breach, a failed product launch, or a service interruption that cost clients money—faces a critical decision in the hours and days that follow. The immediate crisis may have passed, but a second challenge emerges that will determine whether the organization genuinely learns from what happened or whether it simply returns to business as usual until the next preventable failure occurs. This second challenge is the post-incident review, and despite its widespread acknowledgment as a best practice across virtually every sector, most organizations conduct these reviews poorly, superficially, or in ways that actively prevent the kind of learning that would reduce future risk.
The post-incident review exists because incidents are information-rich events. When something goes wrong—when the usual defences fail, when the safeguards prove inadequate, when human error combines with system weakness to produce harm—the organization receives a detailed map of its vulnerabilities. This map is drawn in consequences rather than theory, which makes it both more accurate and more painful than the hypothetical risk assessments that occupy most risk management efforts. The question is whether the organization will read this map with honest eyes and use it to navigate toward genuine improvement, or whether it will fold the map away, assure itself that the incident was an aberration, and continue along the same path until the next failure demonstrates that nothing fundamental has changed.
The professional standards that govern post-incident review across Canadian industries share several common principles, even as they vary in their specific requirements. The Canadian Standards Association's various sector-specific standards, workplace health and safety legislation in every province and territory, and regulatory requirements from bodies ranging from the Office of the Privacy Commissioner to provincial securities commissions all emphasize that incidents require systematic examination aimed at understanding root causes rather than simply assigning blame. As of the date of authorship, the Canada Labour Code and its provincial counterparts require incident investigation for workplace injuries, and while the specific procedural requirements differ across jurisdictions, the underlying principle remains consistent: organizations must examine what happened and why in order to prevent recurrence.
In Quebec, the Civil Code creates obligations around diligence and prudent administration that inform how organizations must approach learning from incidents. Unlike the common law provinces where negligence principles focus heavily on the reasonable person standard, Quebec's civil law framework emphasizes positive obligations of good management and care. For Quebec organizations, a post-incident review is not merely a defensive exercise aimed at demonstrating due diligence after the fact—it is part of the ongoing administrative obligation to manage organizational affairs prudently. Failing to conduct a meaningful review, or conducting one that systematically avoids difficult conclusions, can itself become evidence of inadequate diligence if a similar incident occurs in the future.
The practice of post-incident review has evolved considerably over the past two decades, influenced heavily by work in high-reliability organizations such as aviation, healthcare, and nuclear power. The concept of "just culture" emerged from this evolution, offering a framework that distinguishes between human error, at-risk behaviour, and reckless behaviour as a way of calibrating organizational response. Under a just culture approach, human error—the unintentional slip or mistake that anyone might make—is understood as a symptom of system design rather than a moral failing requiring punishment. At-risk behaviour, where an individual takes shortcuts or bypasses safeguards without recognizing or weighing the risk appropriately, calls for coaching and system examination to understand why the behaviour seemed reasonable. Only reckless behaviour, where an individual consciously disregards a substantial and unjustifiable risk, warrants punitive response. This framework matters because the traditional approach to incident review—find someone to blame, punish them, declare the problem solved—systematically prevents genuine learning by ensuring that everyone in the organization understands that honestly reporting problems, near-misses, and contributing factors will be career-limiting.
The disconnect between what organizations say they want from incident reviews and what they actually do reflects several persistent challenges. First, there is genuine ambiguity about the purpose of the review. Is it a learning exercise aimed at preventing future incidents, an accountability exercise aimed at determining consequences for those involved, a legal exercise aimed at establishing a defensible position for potential litigation, or a compliance exercise aimed at satisfying regulatory requirements? These purposes are not necessarily contradictory, but they require different approaches, different questions, and often different levels of candour. An organization that conducts its review primarily through its legal department, with the goal of producing a privileged document that minimizes organizational exposure, will not generate the same insights as an organization that conducts its review with the genuine goal of understanding how its systems failed to prevent harm.
Second, there is the problem of expertise. Meaningful incident review requires skills that many organizations lack internally. The ability to conduct effective interviews that elicit honest information without leading witnesses toward predetermined conclusions is not intuitive. The ability to trace chains of causation back beyond the immediate triggering event to the organizational conditions that made the event possible requires both analytical skill and organizational knowledge. The ability to distinguish between genuine root causes and comfortable scapegoats requires intellectual honesty that is often in short supply when careers and reputations are at stake. Small and medium-sized organizations in particular may lack both the internal expertise and the budget to engage external specialists, which means that reviews are often conducted by people who are well-intentioned but inadequately prepared for the task.
Third, there is the problem of time and attention. Incidents create immediate demands—managing consequences, communicating with stakeholders, satisfying regulatory requirements, addressing the concerns of affected parties. By the time these immediate demands have been met, organizational attention has often moved on to the next pressing matter. The review, if it happens at all, becomes a perfunctory exercise conducted weeks or months after the incident, when memories have faded and the emotional urgency that might have driven genuine change has dissipated. Organizations that successfully extract learning from incidents treat the review as an immediate priority rather than a delayed obligation, recognizing that the quality of the information available and the organization's willingness to act on it both decay rapidly with time.
Consider a mid-sized construction company operating across Western Canada, with offices in Calgary and Vancouver and projects scattered throughout British Columbia, Alberta, and occasionally Saskatchewan. In the early months of 2026, a serious incident occurred at a residential development site in Surrey, British Columbia. A section of temporary shoring collapsed during excavation work, seriously injuring two workers and narrowly avoiding fatalities. The immediate regulatory response was significant—WorkSafeBC attended the site, issued a stop-work order pending investigation, and opened a file that could potentially result in penalties and mandatory corrective measures. The company's insurance carrier was notified, and the prospect of a substantial workers' compensation claim, along with potential civil action, became immediately apparent.
The company's leadership faced exactly the kind of decision that separates organizations that learn from those that do not. One option was to approach the situation defensively—engage legal counsel immediately, limit documentation to what was strictly required, prepare for potential litigation, and resist any internal findings that might create additional liability exposure. This approach would satisfy the company's immediate need to protect itself, and it would likely produce an incident report that attributed the collapse to a specific technical failure or to worker non-compliance with shoring specifications, thereby localizing the problem and limiting the scope of required remediation. Another option was to approach the situation as a learning opportunity—conduct a genuine investigation aimed at understanding not just what failed but why the failure was possible, examine the organizational systems and cultures that contributed to the conditions at the time of the incident, and commit to acting on findings even when those findings were uncomfortable or expensive.
The company chose an approach somewhere between these poles, which is where most organizations end up. It engaged external counsel early, as any prudent organization would, but it also recognized that a purely defensive posture would likely result in a failure to address underlying problems. The principals remembered that this was not the first shoring-related near-miss in the company's recent history—there had been an incident in Edmonton eighteen months earlier that had been resolved without injury and had generated a brief internal memo but no systematic examination. They recognized that a pattern might be emerging and that the Surrey incident, as serious as it was, might be a symptom of a more fundamental problem with how the company managed shoring design, installation, and inspection.
The review process that unfolded over the following three weeks revealed several things that a superficial investigation would have missed. The immediate technical cause of the collapse was indeed a failure to follow the engineered shoring design—a horizontal strut had been omitted, reducing the system's capacity to resist the lateral earth pressure that developed during excavation. A surface-level review might have stopped there, concluded that workers failed to follow the design, issued retraining requirements and enhanced supervision, and moved on. But the review team—which included an external engineering consultant, the company's safety manager, and a senior project manager from a different region—pushed further into the question of why this omission had occurred and why it had not been caught before the collapse.
What emerged was a picture of accumulated organizational drift. The company had grown significantly over the previous five years, taking on more projects across a wider geography without proportionally expanding its technical supervision capacity. The professional engineers who designed shoring systems were stretched thin, often reviewing designs under time pressure and with incomplete site information. Field supervisors, many of whom had been promoted based on their craft skills rather than their engineering knowledge, were expected to ensure that shoring was installed according to design but often lacked the training to identify when installation deviated meaningfully from specification. The inspection protocols that existed on paper were inconsistently applied in practice—when projects were on schedule and weather cooperated, inspections happened as required, but when projects faced pressure, inspections were sometimes compressed or skipped with the implicit understanding that experienced crews knew what they were doing.
The review also revealed cultural factors that had made deviations more likely. Workers and supervisors who raised safety concerns were not formally punished, but there was an informal understanding that raising concerns too frequently marked someone as difficult or insufficiently committed to getting projects done. Several interviewees mentioned specific instances where they had noticed something that seemed problematic but had decided not to raise it because of how previous concerns had been received. This was not a culture of deliberate recklessness—no one in leadership had instructed anyone to cut corners on safety—but it was a culture that had evolved in ways that made cutting corners more likely and catching problems before they caused harm less likely.
The findings from this review carried significant implications for the company. On one level, they pointed toward specific technical remediation—enhanced shoring inspection protocols, clearer escalation procedures when field conditions deviated from design assumptions, additional training for field supervisors on shoring systems and their failure modes. These were relatively straightforward operational improvements, the kind of thing that organizations routinely implement after incidents without fundamentally changing anything. But the findings also pointed toward more uncomfortable questions about organizational growth, resource allocation, and the relationship between schedule pressure and safety culture. Addressing these deeper issues would require examining executive decisions about staffing, about the pace of growth, and about how project performance was measured and rewarded—questions that implicated leadership judgment in ways that simply blaming field workers never would.
The company's response to these findings over the following months illustrated both the potential and the limits of post-incident learning. The technical improvements were implemented relatively quickly—new inspection checklists, revised training requirements, clearer documentation standards. These changes were visible, measurable, and easy to verify, making them attractive both operationally and from a regulatory and insurance perspective. They demonstrated that the company was taking the incident seriously and making concrete improvements. But the deeper cultural and structural issues proved more difficult to address. Conversations about staffing levels and growth pace touched on business strategy and profitability in ways that made senior leadership uncomfortable. The informal dynamics around raising safety concerns were acknowledged in management discussions but proved resistant to change through formal policy alone—culture shifts slowly and often incompletely.
The experience of this construction company illustrates several general principles about extracting genuine learning from post-incident review. The first is that the depth of learning is often inversely proportional to the comfort of the findings. Surface causes are comfortable because they localize responsibility and limit the scope of required change. Deep causes are uncomfortable because they implicate organizational systems, leadership decisions, and cultural patterns that are difficult to acknowledge and more difficult to change. Organizations that consistently stop at surface causes will consistently fail to address the conditions that make incidents possible, which means they will consistently experience the same types of incidents with variations in specific detail.
The second principle is that review quality depends heavily on process design. Who conducts the review, what questions they are asked to answer, how much time and authority they are given, and what happens to their findings all shape what the review can discover and whether discoveries will translate into action. A review conducted by people who report to individuals whose decisions may have contributed to the incident will face inherent limitations in how far it can push. A review given two weeks to examine a complex incident will necessarily treat some issues superficially. A review whose findings are received, acknowledged, and then quietly set aside will teach the organization that reviews are exercises in appearance rather than substance.
The third principle is that documentation serves multiple functions that must be balanced thoughtfully. The written record of an incident review may become evidence in litigation, regulatory proceedings, or insurance disputes. This reality creates pressure toward documentation that is careful, qualified, and protective of organizational interests. But documentation also serves as the vehicle through which findings are communicated, remembered, and acted upon. Documentation that is so hedged and cautious that it obscures the actual findings will not effectively drive improvement. Organizations must navigate this tension thoughtfully, often with legal guidance, recognizing that the way they document findings will shape both their legal exposure and their capacity to learn.
For readers who are responsible for incident response and review within their own organizations, several practical considerations emerge from these principles. The first is to establish review processes before incidents occur, not in their aftermath. When an incident happens, the organization should already know who will lead the review, what authority they will have, what timeline they will work within, and how their findings will be communicated and acted upon. Making these decisions in advance, when there is no specific incident creating pressure, allows for more thoughtful process design than is possible when everyone is reacting to a crisis.
The second consideration is to invest in building internal capacity for incident review, recognizing that this is a specialized skill that does not automatically accompany other forms of operational or technical expertise. This might mean formal training for specific individuals who will serve as lead reviewers, or it might mean establishing relationships with external specialists who can be engaged when significant incidents occur. Small organizations may lack the resources for extensive internal capacity building but can still identify individuals who will take responsibility for review and ensure that those individuals have access to appropriate guidance and templates.
The third consideration is to attend carefully to what happens after the review concludes and findings are delivered. The most thorough review process imaginable produces no value if findings are received, discussed briefly, and then forgotten. Findings must be translated into specific action items with clear ownership and timelines. Action items must be tracked and verified. And the organization must be willing to reopen questions if initial actions prove ineffective—sometimes the first attempt at remediation does not work, and organizations must be willing to try again rather than declaring victory prematurely.
The fourth consideration is to examine near-misses and minor incidents with the same seriousness as significant ones. The construction company in the scenario had experienced a near-miss eighteen months before the serious incident—a warning that was noted but not genuinely examined. Near-misses are gifts because they reveal system weaknesses without extracting the full cost of failure. Organizations that cultivate reporting of near-misses and treat them as learning opportunities will often prevent serious incidents that would otherwise occur. Organizations that dismiss near-misses as unimportant because no one was hurt will continue to operate systems that produce near-misses until probability catches up and harm results.
Finally, leaders must model the kind of honest examination they want the organization to practice. If senior leaders respond to unflattering findings defensively, dismiss uncomfortable conclusions, or consistently seek someone else to blame, the organization will learn that honest reporting and genuine analysis are not actually valued regardless of what official policies say. If senior leaders demonstrate that they can hear difficult truths about their own decisions and respond with genuine curiosity rather than defensiveness, the organization will gradually become more capable of the honest self-examination that meaningful post-incident learning requires. This modelling is perhaps the most important factor in determining whether an organization genuinely learns from what goes wrong, and it is entirely within leadership's control regardless of organizational size, sector, or resource constraints.