Method

Contributing conditions vs. root cause

Anyone who has been told to find the root cause and suspects it is the wrong instruction.

Ask why five times and you will arrive somewhere. The problem is where. “Why did it happen? The straps were not checked. Why? They were rushing.” Two steps and the answer is a person, which is exactly where a causal chain that follows one thread tends to land. The chain is not wrong. It is just short, and it stops at the last human who touched the thing.

The alternative is not a longer chain. It is a different shape of answer — the set of conditions that were present around the person, most of which were there long before the incident and will still be there next week.

01

What a root cause is good for

The technique comes from manufacturing, and on a production line it works. A line is an environment engineered to hold almost everything constant: the same machine, the same station, the same materials, the same sequence, the same shift pattern. When output goes wrong in a place like that, the deviation is usually singular, recent, and findable — because everything around it was fixed on purpose.

That power belongs to the environment, not to the question. Asking why five times is effective on a line because a line has a baseline to deviate from. The method borrows its authority from the stability around it, and nobody says so out loud, which is how it ends up being recommended for work that has no stability at all.

An ambulance reversing in a stranger’s driveway at three in the morning has no baseline. Different crew, different vehicle, different weather, different surface, different patient, different hour of a shift that might be its second or its fourteenth. Nothing is held constant, so there is no deviation to find. The question arrives expecting a single thing that changed, and there was never a state for anything to change from.

02

Where the chain ends up

Follow one anyway and watch where it lands. Why did it happen? The straps were not checked. Why? The crew were rushing. Why? They were behind. Why? The previous call ran long.

By the second step, the subject of every sentence is a person. That is not an accident of this example — it is the grammar of the technique. A single thread has to pass through whoever was closest to the outcome, and it stops naturally at the last point where somebody could have done otherwise. So the chain terminates at a human being, and the finding writes itself: retraining, a reminder about expectations, a conversation with the crew member.

What that costs is not obvious on the day. It is obvious ninety days later, when the same thing happens to somebody else. The rushing was predictable. The staffing that produced it, the call volume that produced that, and the handover practice that made a lone reposition normal are all still exactly where they were, because none of them were ever written down. The record gained a name and lost the information.

Sidney Dekker puts the objection more sharply than a procedure document can: human error is not an explanation of a failure, it is the thing that still needs explaining. An investigation that finishes at human error has not reached its conclusion. It has stopped at the beginning and called it the end.

03

Conditions instead of causes

The alternative is not a longer chain or a more determined interviewer. It is a different shape of answer. Instead of one thing that caused it, you record the set of conditions that were true of the situation — most of which were true before the incident, and most of which will still be true next week.

A contributing condition is something that was the case, not something somebody did. A spotter was unavailable. The crew was under time pressure. The vehicle was unfamiliar. The shift was in its eleventh hour. The written policy said one thing and the practice on the ground had said something else for two years.

There is a usable test for whether you have written a condition or an act. Could it be true again tomorrow, with entirely different people on shift? If yes, it is a condition, and it is worth recording because it will recur. If it could only ever be true of that person on that day, it is an act, and recording it teaches you about one afternoon.

This feels weaker, and that is the main objection to it. One clean cause reads like an answer; six conditions read like a list. But conditions recur and causes do not, and recurrence is the only thing you can actually get in front of. A condition earns its place in the record when it is specific enough to check and general enough to turn up twice.

04

Co-occurrence is not causation

Once you are recording conditions, they start appearing together, and this is exactly where careful work turns into over-reading. Suppose the record shows backing in 54 of 214 incidents that happened on a post move, and a spotter unavailable in 68 of the same 214.

That sentence is a statement about a record. It is not a statement about the world, and it is emphatically not the sentence people repeat afterwards, which is that missing spotters cause backing collisions. Both conditions might follow from something neither one mentions — a staffing pattern that puts single crews on post moves, a station layout that makes a particular maneuver necessary, a scheduling change nobody connected to either.

So the discipline is to describe recurrence before cause, and to keep the language honest about which one you are doing. These appear together in 54 of 214. An observed relationship. The record supports testing this. Not: this causes that, or this drove a 20% increase.

This is not academic caution. A causal claim you cannot support is one that somebody will eventually test, and when it fails it does not fail alone — it takes the credibility of every other finding in the document with it. Claims that are stated at the strength the evidence actually supports are the ones still standing a year later.

05

Where this sits against systems safety

None of this is new, and it is worth being clear about whose work it descends from. Nancy Leveson’s systems-theoretic accident model treats safety as a control problem rather than a chain-of-failures problem: accidents arise from inadequate control over a system’s behavior, not only from components breaking in sequence. Dekker’s writing on human error argues the same case from the other direction, through the investigator’s side of it.

Condition-mapping shares a genuine amount with those principles. It refuses to treat human error as a sufficient explanation. It looks across organizational, process, equipment, human and environmental conditions rather than one of them. It avoids linear causal claims drawn from co-occurrence. It treats a recommendation as a candidate safety constraint to be validated rather than a conclusion already earned. It names an owner and an observable feedback signal. It asks whether a control is usable under real operating conditions. And it keeps claims about consequence separate from claims about recurrence.

It is also, plainly, not a system-theoretic analysis. A real one would additionally require defined unacceptable losses, stated system hazards and boundaries, a functional control structure, identified controllers and controlled processes, control actions and their feedback paths, the process models those controllers are operating from, the unsafe control actions available to each, and causal scenarios describing how inadequate control and feedback produce them. That is a substantial piece of work and a different discipline.

The honest way to say what condition-mapping does is narrow: it finds recurring conditions and the relationships between them, which tells you where a structured control analysis would be worth doing. It does not perform one, and it does not establish causation.

06

What to ask instead

The replacement question is unglamorous. Instead of asking why it happened, ask what was going on around the person when it happened.

That one substitution changes the interview. Why invites a justification, and a justification invites defensiveness, and a defensive account is thin by design. What was going on around you asks for description, which people give freely because nothing about it sounds like an accusation. You get the eleventh hour, the partner still inside finishing a handover, the radio dead spot, the practice everyone follows that is not in any document.

It also changes what you are listening for. A good investigation works several levels at once rather than in sequence: what was done, the conditions that made it likely, the supervision that let those conditions persist, and the organizational decisions underneath the supervision. Not four passes — four things held together, so that an answer at one level does not close the question at the others.

And it changes the artefact. Instead of a report naming a person and a corrective action about training, you get a record of conditions, each with a count and the population it was counted in — a document that can be compared against next quarter’s, and that tells the next reader something they can act on rather than something they have to take on trust.

The honest positioning is narrow and worth stating plainly: finding recurring conditions and the relationships between them tells you what deserves a structured control analysis. It does not perform one, and it does not prove causation.

See what this looks like on a real record

A full sample report — five sheets, every count shown over the population it came from, and a written account of what the record could not settle.

See a sample report