RIDDOR and incident reporting: recording the event and the follow-up

When an incident happens, the immediate priority is always the people involved. Once that is handled, the reporting obligations begin, and this is where businesses often become uncertain. What needs to be reported, who decides, and what should be recorded for later?

The uncertainty is understandable. Reporting rules are specific and the consequences of getting them wrong can be significant. But the businesses that handle incidents well do not rely on memory in the moment. They have a process in place before anything happens.

What good incident recording covers

Incident management is a cycle, and each stage should leave a record:

  • the initial report of what happened, when, and where
  • the immediate response and any first aid or emergency action
  • an assessment of whether formal notification is required
  • any notification submitted, with dates and reference details
  • the investigation and its findings
  • the actions taken to prevent recurrence, tracked to completion

The notification is only one part of the cycle. The rest is what turns an incident from a one-off event into a control improvement.

Where businesses get stuck

The common gaps are not usually about the notification itself. They are:

  • no clear owner for deciding whether reporting is required
  • investigations that happen informally and produce nothing
  • corrective actions agreed in meetings but never tracked
  • records scattered across emails, notebooks, and personal files
  • no review of patterns across sites, so repeat incidents go unnoticed

When these gaps exist, the business is exposed in two directions. It may fail to report something it should have, and it cannot show the regulator, insurer, or claimant what it learned and changed afterwards.

Why the follow-up matters as much as the report

The follow-up is what separates compliance from luck. A notification tells the relevant bodies that an incident occurred. The investigation and the actions afterwards show that the business understood it and did something about it.

That distinction matters enormously when questions come later. A business that can demonstrate a structured response, with dated actions and evidence of change, is in a much stronger position than one that can only produce a copy of the notification.

Building a process that works at every site

For multi-site operators, incident control needs to be consistent:

  • one process for recording incidents, used at every site
  • clear criteria for when a report is escalated
  • a named owner for investigations and follow-ups
  • a central view of incidents, actions, and outcomes
  • regular reviews of patterns and recurring causes

When the process is consistent, a site with a growing incident pattern becomes visible centrally, and the business can act before the pattern becomes a problem.

The Northstead view

Incident reporting is the compliance activity that businesses hope never to use, which is exactly why it needs to be ready before it is needed. The process, the ownership, and the record-keeping should all be in place while things are calm.

When something happens, the businesses that respond well are not the ones that improvise best. They are the ones that already know who does what, what gets recorded, and how the follow-up is tracked. That preparation is what turns an unfortunate event into a controlled one.

Next step

Book a free compliance review.

If you need a clearer view of what your sites require, what is being missed, or how to reduce the admin burden on your team, speak to us now.