top of page

ICAM vs Root Cause Analysis: Why Modern Incident Investigations Need More Than a Single Cause

  • Luke Dam
  • 9 hours ago
  • 9 min read

“What was the root cause?”


It is one of the most common questions asked after a workplace incident.


The question sounds reasonable. Something went wrong, so the organisation wants to identify the cause, correct it and prevent the incident from happening again.


The problem is not the intention behind the question. The problem is the assumption built into it.


Asking for the root cause suggests that an incident can be traced back to one decisive failure. It encourages investigators to search for a single answer, often represented as the final box in a causal chain.


In simple events, that approach may provide a practical result. In complex incidents, however, it can significantly narrow the investigation.


Workplace incidents rarely result from one isolated failure. They usually emerge from several interacting conditions, decisions, control weaknesses and organisational influences. This is the central distinction between conventional root cause thinking and the Incident Cause Analysis Method, or ICAM.


ICAM does not simply ask, “What caused this incident?”


It asks:


  • What happened?

  • What conditions influenced the event?

  • Which controls were absent, inadequate or ineffective?

  • Why did the actions of the people involved make sense at the time?

  • What organisational factors allowed those conditions to develop?

  • What must change to reduce the likelihood or consequence of recurrence?


This shift matters because the quality of the question shapes the quality of the investigation.


What Is Root Cause Analysis?

Root Cause Analysis, commonly abbreviated to RCA, is not one single investigation method. It is a broad term used to describe a range of tools intended to move beyond the immediate symptoms of a problem and identify underlying causes.


RCA tools may include:


  • 5 Whys

  • cause-and-effect diagrams

  • fault trees

  • causal factor charts

  • barrier analysis

  • various checklist or classification systems


These tools differ in complexity and purpose. It would therefore be inaccurate to claim that every RCA process is simplistic or blame focused.


At its best, RCA encourages investigators to look beyond the visible event. Instead of concluding that a machine stopped because a component failed, for example, the investigator may explore why the component failed, why the developing problem was not detected and why the organisation’s maintenance arrangements did not prevent the outcome.


That is useful thinking.


The difficulty arises when RCA is treated as a search for one definitive endpoint.


A complex event may have several credible causal pathways. Selecting one of them as the root cause can create the impression that the investigation has reached the deepest or most important explanation, even though other contributing factors remain active within the system.


The Attraction of a Single Root Cause

Organisations are often drawn to single-cause explanations because they provide certainty.


A statement such as “the root cause was a failure to follow procedure” is easy to communicate. It creates a clear narrative and appears to support a straightforward response.


The organisation can retrain the worker, revise the procedure, issue a safety alert and close the action.


The investigation appears complete.


But the simplicity of the conclusion may hide important questions:


  • Was the procedure available at the point of work?

  • Was it clear, accurate and practical?

  • Did training reflect how the task was actually performed?

  • Were workers expected to meet production targets that conflicted with the procedure?

  • Had supervisors previously accepted similar deviations?

  • Did equipment design make compliance difficult?

  • Was there a control that should have detected the deviation before harm occurred?

  • Had earlier warning signs been reported but not acted upon?


“Procedure not followed” may describe an individual or team action. It does not explain the system that influenced the action.


Safety Wise (and ICAM) emphasises that human error should not be treated as the endpoint of analysis.


Investigators need to understand the conditions that made the error more likely and the controls that failed to prevent or mitigate the outcome.


How ICAM Approaches Incidents Differently

ICAM is a systemic, learning-focused investigation methodology developed by Gerry Gibb at BHP, with its foundations influenced by Professor James Reason’s work on organisational accidents.


Rather than searching for a single root cause, ICAM identifies the contributing factors that combined to produce an event.


This distinction is fundamental.


A contributing factor is something that influenced the occurrence or its consequences. Removing or changing that factor may have reduced the likelihood of the incident, interrupted the event sequence or limited the severity of the outcome.


Several factors may contribute at the same time. They may also sit at different levels of the organisation.


ICAM structures its analysis across four key areas:


1. Absent or Failed Defences

These are the controls, barriers or safeguards that should have prevented the event or reduced its consequences.


Examples might include:


  • a missing physical guard

  • an ineffective isolation system

  • an alarm that was not noticed

  • a risk assessment that did not identify the exposure

  • a verification step that was not required

  • inadequate supervision or inspection

  • emergency arrangements that did not function as intended


This part of the analysis keeps the investigation connected to risk management. It asks not only what went wrong,

but also what should have stopped it.


2. Individual or Team Actions

These are the actions or decisions of the people directly involved in the event.


ICAM does not ignore individual behaviour. It examines it in context.


The important question is not simply, “What did the person do wrong?”


The investigator asks, “Why did that action make sense to the person or team at the time?”


This opens the analysis to factors such as available information, competing priorities, workload, experience, communication, assumptions, equipment feedback and normal workplace practices.


3. Task or Environmental Conditions

These are the local conditions that influenced performance.


They may include:


  • time pressure

  • fatigue

  • lighting

  • noise

  • heat

  • equipment layout

  • task complexity

  • unclear responsibilities

  • poor communication

  • inadequate tools

  • conflicting procedures

  • unusual operational conditions


These factors help explain why an action occurred. They shift the analysis from judging behaviour after the event to understanding the conditions under which the work was performed.


4. Organisational Factors

These are the broader systems and management influences that created or allowed the local conditions.


Examples include:


  • risk management

  • training systems

  • change management

  • contractor management

  • procurement

  • maintenance strategy

  • organisational culture

  • supervision arrangements

  • communication systems

  • workforce planning

  • procedures and standards

  • leadership decisions

  • incompatible goals


Safety Wise describes ICAM as a holistic, systemic method that identifies local factors and failures within the broader organisation and productive system. Its purpose is to support risk reduction and stronger, more error-tolerant defences.


Root Cause Thinking Can Become Too Linear

Many RCA tools present incidents as a chain:

Event A caused Event B, which caused Event C, which produced the incident.

This can be useful for organising a simple sequence. However, complex work rarely operates as a single line.

Consider a mobile plant collision.

An investigation might identify that the operator did not see a light vehicle and conclude that the cause was poor visibility.

But visibility may have been influenced by several interacting factors:



  • blind spots in the plant design

  • dust in the operating area

  • inadequate separation between vehicles

  • radio congestion

  • a poorly positioned intersection

  • production pressure

  • inconsistent traffic rules

  • a missing proximity detection system

  • fatigue

  • assumptions created by normal traffic patterns

  • previous near misses that were not effectively reviewed



Which one is the root cause?


Choosing one factor may make the report easier to summarise, but it does not make the event less complex.


ICAM allows these factors to be examined together. The objective is not to nominate a winner. It is to understand how the system combined to create the outcome.


ICAM Is Not Just a More Detailed 5 Whys

The 5 Whys is one of the most familiar RCA techniques. It involves repeatedly asking “why” to move from an immediate event toward a deeper organisational issue.


Used correctly, it can help investigators avoid stopping at a symptom. It is accessible, easy to teach and useful for straightforward, lower-level incidents.


It also has limitations.


The result can depend heavily on who is asking the questions. Different investigators may follow different causal paths and reach different conclusions. The technique can encourage a single chain of reasoning even where several pathways exist. Investigators may also stop when they reach a plausible answer rather than testing whether the evidence supports it.


Safety Wise recommends selecting the investigation method according to the risk and complexity of the event. The 5 Whys may be appropriate for lower-level incidents with relatively clear causal pathways, while ICAM is more suitable for serious, high-potential or complex events involving multiple contributing factors.


Safety Wise also cautions against treating 5 Whys as a compulsory step within every ICAM investigation. Conducting both analyses can duplicate effort because both ultimately aim to identify organisational factors.


The practical principle is simple: use the right tool for the event.


Evidence Before Explanation

Another important difference is that ICAM is more than an analysis diagram.


A credible ICAM investigation begins with disciplined information gathering.

Investigators use PEEPO to consider evidence across five areas:


  • People

  • Environment

  • Equipment

  • Procedures

  • Organisation


This helps prevent the investigation from focusing too early on the person closest to the event.


The evidence is then organised into a timeline showing what occurred before, during and after the incident. Conditions, actions and decision points can be placed in sequence, allowing investigators to identify gaps, conflicts and areas requiring further evidence.


Only after the event has been adequately reconstructed should the team move into formal ICAM analysis.

This order is important.


When investigators decide on the cause before gathering sufficient evidence, they become vulnerable to confirmation bias. They may seek information that supports the initial theory and discount evidence that challenges it.


ICAM’s structured process is designed to keep investigators in question mode for longer.


Facts should be separated from assumptions. Findings should be traceable to evidence. Alternative explanations should be considered. Unsupported statements should not be elevated into conclusions.


The Problem With Stopping at Human Error

Human error is often visible at the point where the system fails.


A person presses the wrong button, overlooks an alarm, enters the wrong area, omits a task step or makes an incorrect decision.


These actions matter, but simply labelling them as causes adds little investigative value.


Saying “the worker made an error” is similar to saying “the equipment broke.” It describes part of what happened. It does not explain why.


A systems-based investigation explores:


  • what information the person had

  • how the task was normally performed

  • whether the procedure matched the actual work

  • what pressures or trade-offs were present

  • whether the equipment supported correct action

  • what supervision and verification existed

  • whether similar errors were predictable

  • which defences should have detected or tolerated the error


ICAM recognises that people operate within systems. Their actions are shaped by the environment, tools, processes, leadership, priorities and control arrangements around them.


This does not remove personal accountability. It separates accountability decisions from causal analysis.

An organisation can address deliberate misconduct where the evidence supports it while still investigating the system conditions that allowed the behaviour to produce harm.


Different Methods Produce Different Recommendations

The difference between ICAM and narrow root cause thinking becomes particularly clear when recommendations are developed.


When an investigation identifies the cause as “operator error,” the recommendations are often predictable:


  • retrain the operator

  • remind workers to follow the procedure

  • issue a safety communication

  • increase supervision

  • apply disciplinary action


Some of these actions may be justified, but they are generally administrative and person dependent.

They may do little to change the conditions that influenced the event.


An ICAM investigation links recommendations directly to identified contributing factors and control weaknesses.


For example, the investigation may recommend:


  • redesigning an access point

  • introducing engineered separation

  • improving equipment feedback

  • revising the planning process

  • strengthening verification requirements

  • changing workload allocation

  • improving change management

  • introducing an independent control check

  • redesigning an impractical procedure

  • addressing conflicting operational priorities


The focus is not on producing more actions. It is on producing actions that improve the system.


Recommendations should be specific, linked to findings and focused on improving controls. Investigations that target individuals rather than the conditions and systems surrounding the work are less likely to prevent recurrence.


Is ICAM Better Than Root Cause Analysis?

The most accurate answer is that the comparison depends on what is meant by Root Cause Analysis.


RCA is an umbrella term. Some RCA methodologies are sophisticated and systems focused. Others are simple tools intended for relatively uncomplicated problems.


ICAM should not be positioned as rejecting every form of RCA.


The stronger distinction is this:


Traditional root cause thinking often seeks a primary, deepest or final cause.


ICAM seeks to identify the multiple contributing factors and control weaknesses that interacted across the system.

For a simple event, a concise RCA tool may be entirely appropriate.


For a serious or complex incident, the search for a single root cause can constrain learning. ICAM provides a broader framework for evidence gathering, timeline development, control analysis, human factors analysis and organisational learning.


The Real Measure of an Investigation

The value of an investigation is not determined by the size of its report, the number of diagrams it contains or whether it identifies something labelled as a root cause.


Its value is determined by what the organisation learns and what changes as a result.


A strong investigation should help the organisation:


  • understand how the event developed

  • identify where controls were missing or ineffective

  • explain human actions in context

  • recognise broader organisational influences

  • develop recommendations connected to evidence

  • strengthen controls

  • share learning across relevant parts of the business

  • verify that implemented actions are effective


ICAM supports these outcomes by treating investigation as an organisational learning process rather than a search for someone or something to blame.


The most important question is therefore not:

“What was the root cause?”


A more useful question is:

“What combination of factors and control weaknesses allowed this event to occur, and what must we change to make the system safer and more resilient?”


That is the difference between closing an investigation and learning from one.


 
 
 

Comments


bottom of page