top of page

What Software Can and Cannot Surface From Your Investigations

  • Luke Dam
  • 5 hours ago
  • 12 min read

Investigation software has changed what organisations can do with incident information. Instead of individual reports sitting in folders, shared drives or separate business systems, investigation data can increasingly be structured, searched, compared and analysed across multiple events. That creates opportunities that were difficult to achieve when every investigation effectively existed as a standalone document.


Used well, technology can help an organisation see patterns across investigations, identify recurring contributing factors, examine the performance of controls, monitor recommendations and retain investigation knowledge that might otherwise disappear when people move roles or leave the business.

But there is an important distinction between making investigation information visible and understanding what that information means.

Software can organise evidence, aggregate classifications and surface patterns. It can help investigators work consistently and give leaders a much broader view of what is being found across the organisation. What it cannot do is remove the need for investigative judgement.


That distinction matters because the value of investigation data depends on the quality of the investigation that created it. GIGO surfaces yet again in these discussions.


Structured data creates organisational memory

One of the persistent challenges with incident investigation is that organisations can conduct a large number of investigations without necessarily building a strong picture of what those investigations are collectively telling them.

A report may contain useful findings. Recommendations may be implemented. The incident may be closed. Then attention moves to the next event.


Over time, hundreds of individual investigations can accumulate without anyone systematically examining the relationships between them.


Structured investigation systems can change that.


When information is captured consistently, an organisation can examine investigations by location, activity, equipment type, event classification, control performance, contributing factor, Organisational Factor or other meaningful dimensions. Instead of asking someone to manually review years of reports, the organisation can begin searching and comparing its investigation history.


That is particularly valuable for systems-level investigation methodologies such as ICAM, where the purpose is not simply to identify what an individual did immediately before an incident. The investigation seeks to understand the broader contributing factors and conditions that influenced the event, including the effectiveness of defences and the organisational systems behind them.


If that information is captured consistently, the organisation has the beginnings of a meaningful learning dataset.

Software can then help answer questions that are difficult to answer from individual reports. Are similar controls failing in different locations? Are particular Organisational Factors appearing repeatedly? Are different incidents producing recommendations aimed at the same part of the management system? Are investigation teams repeatedly identifying similar Task or Environmental Conditions?


Those are useful questions.

The difficulty begins when we assume the software can also provide the answers.

A pattern is a prompt for investigation, not automatically a conclusion

Suppose an organisation analyses its investigation database and discovers that a significant proportion of recommendations involve training.


There are several possible interpretations.


Perhaps capability genuinely is a recurring organisational weakness. Perhaps workers are being placed into tasks without sufficient preparation. Perhaps training systems have not kept pace with changes to equipment, processes or operating conditions.


But another explanation is also possible. 

Investigators may simply be defaulting to training as an easily available recommendation.

Those are very different organisational problems.


The first might require changes to competency systems. The second might indicate a weakness in investigation and recommendation quality.


The dashboard cannot decide between them.


To understand what the pattern means, someone needs to examine the investigations behind the numbers. Were the findings supported by evidence? Were the relevant controls properly examined? Did investigators look beyond the actions of the people involved? Were the recommendations actually linked to the identified contributing factors?


Software has surfaced the signal. Investigation capability determines whether the organisation interprets that signal correctly.

This is one of the reasons investigation analytics should never be separated from investigation quality.

Software can organise evidence. It cannot determine its significance.

An investigation begins with data gathering, and a disciplined approach requires investigators to look beyond the immediately obvious sources of information.


Within ICAM, PEEPO provides a structured way of considering potential evidence across People, Environment, Equipment, Procedures and Organisation. The purpose is not to mechanically complete five categories. It is to broaden the investigation team's field of view and reduce the risk that important information is overlooked.

Technology can support this process extremely well.


Documents can be stored against an investigation. Photographs can be indexed. Interview records can be retained. Equipment information, procedures, training records and other evidence can be linked to relevant events. Search tools can make large evidence sets considerably easier to navigate.


Artificial intelligence can extend those capabilities further by summarising documents, identifying references to particular controls, finding similarities between witness accounts or locating information across large collections of material.


All of that can save investigators time.

The difficult part is deciding what matters.

An investigator still has to determine whether the procedure being examined was applicable to the task as it was actually performed. They need to understand whether a control existed, whether it was implemented and whether it was capable of managing the relevant risk. They may need to reconcile conflicting evidence, determine which questions remain unanswered and decide what additional evidence is required.


The presence of information is not the same as evidence of causation or contribution.


That judgement remains central to investigation.


Witness interviews show the boundary particularly clearly

Interview technology is developing quickly. Transcription can remove hours of manual work. Search tools can help investigators revisit specific topics. AI-generated summaries can assist with reviewing lengthy interview records and comparing information from multiple witnesses.


These are valuable capabilities, but none of them guarantees a good interview.


Witness information is influenced by perception, retention and recall. People experience events from different positions and under different conditions. Stress, elapsed time, expectations and information received after the event can all influence what a person remembers and how they describe it.


The investigator therefore needs more than a list of questions.


They need to create conditions that support recall, use open questions effectively, listen for information that requires further exploration and recognise when their own assumptions may be influencing the direction of the interview. They also need to distinguish between what the witness observed, what the witness inferred and what may have been learned after the event.


Software can record the conversation perfectly and still preserve a poorly conducted interview.

That is an important principle for organisations adopting increasingly sophisticated investigation platforms. Technology can improve the efficiency of an investigative task without necessarily improving the quality of the thinking behind it.


Timelines are another example

Timeline reconstruction is one of the most useful tools available to an investigator because incidents rarely make sense when information is examined as disconnected fragments.


Placing events into sequence can reveal gaps, contradictions and relationships that were not obvious during initial data gathering. It can also help the investigation team identify where additional evidence is required.


Software is particularly effective at helping investigators manage this complexity. Events can be reordered, evidence attached, different information sources compared and large timelines filtered or searched.


The result can look impressively precise.


That appearance creates its own risk.


Not every point on a timeline has the same level of certainty. One event may be confirmed by electronic records, another estimated by a witness and another inferred from several pieces of evidence. If those distinctions disappear when the information enters a system, uncertainty can quickly begin to look like fact.

A skilled investigator understands that a timeline is not simply a chronology. It is a developing representation of the event that must be tested against the available evidence.

The software can arrange the information. The investigator determines how much confidence should be placed in it.


Coding is useful, but coding is not analysis

Structured investigation platforms often allow findings to be classified into categories. This is essential if an organisation wants to analyse investigations collectively.


ICAM provides a particularly useful structure because findings can be considered across Absent or Failed Defences, Individual or Team Actions, Task or Environmental Conditions and Organisational Factors.


At an individual investigation level, those categories help the team move beyond a simple description of what happened and examine why the event developed as it did.


Across multiple investigations, they can become even more valuable.


An organisation might discover recurring weaknesses associated with change management, maintenance systems, procedures, supervision, risk management or another organisational process. Similar findings may appear in operationally different incidents, suggesting that what looked like separate local events may share broader systemic characteristics.


This is where structured investigation data becomes powerful.


However, the value of the analysis depends on the quality of the classifications.

A dropdown menu does not make a finding correct. A causal code does not become meaningful simply because it has been selected repeatedly. Investigators still need to understand why a finding belongs in a particular category and be able to demonstrate the evidence supporting that conclusion.

Otherwise the organisation risks creating a sophisticated dataset built on inconsistent investigative reasoning.


The analytics may look impressive while the underlying information remains weak.


Human error is where simplistic analytics become particularly dangerous

Imagine an organisation reviews its incident database and discovers that a large proportion of investigations contain some form of human error.


What has it learned?


Potentially very little.


People make decisions and take actions within systems. If an investigation stops when it identifies an error, violation or departure from an expected process, it has described part of the event without necessarily explaining the conditions that influenced it.


A systems-based investigation needs to go further.


What information was available to the person at the time? What controls were expected to prevent the event? Were those controls present and effective? What were the task and environmental conditions? Were procedures practical and applicable? Were there competing priorities? Were there equipment or design influences? Were organisational systems shaping the circumstances in which the decision was made?


Those questions cannot be answered by counting how many investigations contain a human-performance classification.

This is one of the fundamental differences between collecting incident statistics and developing organisational learning.

Software can tell you that a category appears frequently. Skilled analysis determines what sits behind that frequency.


The real opportunity is finding relationships between investigations

The strongest case for investigation technology is not that it automates individual investigations. It is that it can help organisations connect them.


A single incident may identify an issue with a particular control. A second event at another location may reveal a similar weakness. A third may involve different equipment but point toward the same underlying organisational process.


Viewed independently, each investigation may appear to be a local problem.


Viewed collectively, a different picture may emerge.


This is where structured data, analytics and increasingly AI-assisted search can make an important contribution. Technology can examine a volume of information that would be difficult for any individual investigator to hold in memory. It can identify recurring language, classifications, controls, recommendations or Organisational Factors and direct attention toward relationships worth examining.

But the purpose of that capability should be to support human inquiry, not replace it.

A recurring pattern should prompt questions such as: Why are we seeing this? Are these investigations genuinely identifying the same issue? Is the pattern operational, organisational or perhaps a consequence of the way our investigators classify findings? What evidence across the cases supports the connection?


That last question is critical.

Similarity is not causation. Frequency is not significance. Correlation is not an investigation finding.

Your investigation data can also tell you something about your investigators

There is another use for structured investigation information that receives less attention.

It can help an organisation examine the quality and maturity of its investigation process.

Consider an organisation where most investigations identify Individual or Team Actions but very few identify Organisational Factors. That might accurately reflect the incidents being investigated.


It might also suggest that investigation teams are stopping too early.


Similarly, if almost every investigation produces procedural or training recommendations, the issue may not simply be the organisation's procedures and training. It may indicate that investigators need greater capability in control analysis, systems thinking or recommendation development.


This creates a valuable feedback loop.


Investigation data can support learning about operational systems while also identifying where investigation capability needs to develop.


For organisations seeking to mature their ICAM practice, this distinction is important. Completing ICAM training gives investigators the methodological foundation, but maintaining investigation quality requires continued application, calibration and practice. Investigators need opportunities to work through evidence, test classifications, challenge assumptions and strengthen the judgement required to move from information to defensible findings.



That is part of the thinking behind ICAM Mastery. Rather than treating investigation capability as something completed at the end of a course, the focus is on continuing to develop the practical judgement investigators need when working with real evidence, competing explanations and increasingly sophisticated investigation tools.

The better the technology becomes, the more important that capability is likely to become.


AI makes investigative discipline more important, not less

Artificial intelligence adds another layer to this discussion because it can perform some investigation-support tasks at extraordinary speed.


Large quantities of text can be summarised. Similar incidents can be identified. Themes can be clustered. Evidence repositories can become conversationally searchable. Draft timelines, comparison tables and preliminary classifications may be produced in seconds.


Those capabilities will continue to improve.


The danger is confusing fluent output with investigative validity.


An AI system can produce a convincing explanation from incomplete information. It can identify a relationship between events without establishing that the relationship contributed to the incident. It can summarise conflicting witness accounts without determining why they conflict. It can suggest a classification without understanding whether the evidence actually supports it.


Investigators therefore need to become better at testing outputs rather than simply generating them.


What evidence supports this conclusion? What evidence contradicts it? What assumptions are being made? What information is missing? Is this finding describing what happened or explaining a contributing factor? Does the recommendation address the finding or merely sound reasonable?


These are investigation questions, not software questions.


They are also precisely the kinds of questions that distinguish investigators who understand the mechanics of a methodology from investigators who can apply it with confidence.


As AI becomes embedded in investigation platforms, organisations will need both technological capability and investigative capability. Investing heavily in the first while allowing the second to decline would be a serious mistake.


Technology should make investigators more capable, not more passive

The most useful investigation software does not try to remove thinking from the process. It creates an environment in which good investigative thinking is easier to apply.


It can prompt structured data gathering. It can preserve evidence. It can make timelines easier to construct. It can help teams examine controls systematically. It can support consistent classification and make previous investigations accessible when investigators need to compare events.


At an organisational level, it can connect information that previously remained fragmented across reports and locations.


Those are substantial advantages.


But every one of them depends on the person using the system understanding what they are looking for and why.

An investigator who does not understand the difference between evidence and assumption will not become a stronger investigator because an AI system can summarise their evidence.

 Someone who does not understand control-based thinking will not necessarily produce better findings because the software provides a control-analysis screen. An investigation team that stops at human error will not automatically develop systems thinking because the platform contains an Organisational Factors dropdown.


Digitising a weak investigation process produces a digital weak investigation process.


The capability question organisations should be asking

The conversation around investigation technology often begins with functionality.


Can the platform transcribe interviews? Can it generate timelines? Can it search previous incidents? Can it identify trends? Can AI suggest themes or summarise evidence?


Those are reasonable questions, but they should be accompanied by another.

Do our investigators have the capability to evaluate what the technology surfaces?

That question becomes increasingly important as investigation systems become more powerful.


Organisations need investigators who can gather evidence systematically, conduct effective witness interviews, reconstruct events, understand controls, recognise the difference between failed and absent defences, identify contributing factors, examine organisational influences and develop findings that can withstand scrutiny.


They also need people who can challenge the outputs of the technology itself.


That capability does not come from software implementation. It comes from learning the methodology, applying it, receiving feedback and continuing to develop judgement through practice.


This is where ongoing capability development, including programs such as ICAM Mastery, sits alongside investigation technology rather than competing with it. The objective is not to teach investigators how to reproduce steps mechanically. It is to deepen their ability to work with evidence, make defensible analytical decisions and extract meaningful learning from increasingly complex information.


For organisations building large investigation datasets, that capability has another benefit. Better investigators create better data. Better data produces more reliable organisational analysis. More reliable analysis gives leaders a stronger basis for deciding where systemic improvement is required.


The relationship is circular.


Investigation capability improves the dataset, and the dataset creates new opportunities for capable investigators to learn across incidents.


Software can surface the signal. People still have to understand it.

There is enormous potential in structured investigation data.


For the first time, many organisations have the ability to move beyond treating incident investigations as isolated reports and begin examining them as a connected body of organisational knowledge. Analytics can expose recurring themes. AI can help navigate large evidence sets. Investigation platforms can preserve knowledge and make patterns visible across years of operational experience.


That should be welcomed.

But the purpose of technology should not be to create the appearance that judgement is no longer required.

A software platform cannot compensate for evidence that was never gathered. It cannot recover the questions that were never asked in an interview. It cannot correct an assumption that was recorded as fact unless someone recognises the problem. It cannot turn an unsupported classification into a defensible finding simply by including it in a dashboard.

Most importantly, it cannot decide what an organisation should learn from an incident.

That remains a human responsibility.


The organisations that gain the most from investigation technology are therefore unlikely to be those that simply collect the most data or deploy the most advanced AI. They will be those that combine structured systems with strong investigation capability, giving their people both the tools to surface information and the judgement to interrogate what that information actually means.


That is the opportunity.


Not software instead of investigators, and not investigators working without the advantages technology can provide. It is disciplined investigation supported by technology, with capable people remaining accountable for the interpretation.


Because software can surface the signal.


The quality of your investigators determines whether your organisation learns from it.

 
 
 

Comments


bottom of page