Investigation
How to run an EMS incident investigation
A safety officer who has just been handed the job and has no procedure to follow.
Most incident investigations fail at the same point, and it is not the paperwork. It is the interview. Either the person asking has never been trained to ask, or they are carrying nine other things and ask as little as they can get away with, or the person answering is frightened and volunteers nothing. What comes out the other end is a report that closes quickly and teaches nothing.
This guide is the procedure you were not given: what to collect before you talk to anyone, how to run the conversation so it produces something true, and what to write down so that the record is still useful to somebody in a year.
01
Before you talk to anyone
Collect the record first. The run sheet, the times, the crew assignment, the vehicle, the shift pattern that person was working, and whatever the form already captured. Fifteen minutes of this before the conversation changes the conversation more than any interviewing technique will.
The reason is not that you catch people out with it. It is that a generic opening produces a generic account. Tell me what happened invites a summary, and a summary is the version somebody has already told themselves three times. Whereas: you were on the second call of a twelve-hour shift, at a facility you had not been to before, and your partner was inside — walk me through the reposition. That question can only be answered with detail, because it already contains the outline.
It also tells the person that you did the work. Somebody who has been handed a form and asked to explain themselves is in a different posture from somebody whose investigator already knows the sequence and is asking about the parts the record could not hold. The second posture produces better information, and it costs you a quarter of an hour.
What you are looking for at this stage is not a theory. It is the set of things you would otherwise ask about and get wrong — the timings, the names, the vehicle, the conditions — so that none of the interview is spent establishing facts a document already contains.
02
The interview is the investigation
Everything downstream is determined here. The categorization, the corrective action, the pattern this incident eventually joins or fails to join — all of it is bounded by what the conversation surfaced. A thin interview cannot be rescued by good analysis, because the analysis has nothing to work with.
Interviews go thin in three predictable ways. The investigator has never been trained to ask, so they follow the form field by field. The investigator is carrying nine other things, so they ask the minimum that lets them close it. Or the person answering is frightened, and gives you the shortest true account available — which is usually accurate and almost useless.
The third one is the one you control. Somebody who believes this conversation may end in discipline will not tell you about the workaround, the shortcut everybody uses, or the fact that the equipment has been awkward for a year. Those are precisely the things worth knowing, and they are the first things to disappear when the room feels prosecutorial.
So the posture matters and it is not softness. The most useful mental model is the best safety manager you have worked with: someone who already assumes that most incidents are systems failing people rather than people failing systems, who asks follow-ups because they want the whole picture rather than because they doubt you, and who names a concerning thing directly when they find it — without accusation. Curious, not prosecutorial. That is a technique, not a temperament, and it can be practiced.
03
Working four levels at once
A good investigation works several levels simultaneously, even when the conversation appears to be sitting on one.
The first is what was done or not done at the moment — where attention was, what action was taken. The second is the state the person was in that made that more likely: hours into the shift, whether they had eaten, what else was pending, how familiar the vehicle was. The third is the supervisory layer that allowed that state to persist — whether this was a trained protocol or something a crew developed informally, whether anyone had noticed. The fourth is the organizational decisions underneath the supervision: staffing, scheduling, training budget, what gets discussed at briefings and what is left to crew discretion.
The mistake is treating these as four sequential passes. They are not stages; they are four things held open at once, so that an answer at one level does not close the question at the others. Somebody tells you they were tired. That is a level-two answer, and the temptation is to record fatigue and move on. Instead you follow it: how long had you been awake, was this a scheduled shift or overtime, is fatigue common on this run type, does anyone track it. Two of those questions are at level four, and you only reach them by refusing to let the first answer end the thread.
You will not label any of this out loud, and you should not. The person you are talking to does not need a framework. They need someone who keeps asking the next real question.
04
Questions that open, questions that close
Some questions can only be answered one way, and the way is short. Others cannot be answered without describing something. Most of the craft is in preferring the second kind.
Why did you do that closes. It sounds like an accusation because grammatically it is one, and the honest answer to it is usually a justification rather than an account. What were you thinking about at that moment, and what made that the right call given what you knew opens — same subject, no charge attached, and it asks for the reasoning as it actually was rather than as it looks in hindsight.
The same substitution works everywhere. Not: that was a violation of policy. Instead: you mentioned you knew there was a policy — what made it feel like the right call in the moment? Not: this answer needs more detail. Instead: that gives me part of the picture; what happened right before that? Not: please describe the incident. Instead, the specific thing you already know, handed back with a question attached.
And listen for the phrases that mark normalized practice, because they are the most valuable thing anyone will say to you. We usually just. Normally we. I know we are supposed to, but. It has not been a problem before. Diane Vaughan named this pattern normalization of deviance in her work on the Challenger accident — practice drifting from the standard, accepted a little more each time precisely because nothing has gone wrong yet.
When you hear it, do not challenge it. Reflect and expand: it sounds like that has become the standard way your crew does it — how long has it been done that way, and is it something supervisors know about? You will get the systemic picture without anybody feeling accused, which is the only way you get it at all.
05
What to write down
Write the record for the person who reads it in two years and has none of the context currently sitting in your head. That person will not know the station layout, the vehicle, the staffing at the time, or what everybody in the building understood without saying.
Which means: conditions rather than conclusions. Not the crew was rushing, but the call before this one ran forty minutes over and the crew were due back in service. Not human error, which is not a finding, but the specific description of what was going on around the person. Somebody reading it later can draw a conclusion from a condition; nobody can recover a condition from a conclusion.
Record the person’s own words where they matter. That is just how we do it most nights is data. Paraphrasing it into deviation from procedure destroys it — you have replaced the observation with your interpretation of the observation, and the interpretation cannot be re-examined later.
Separate what you observed from what you inferred, visibly. And write down what you could not establish, which is the part almost everybody skips. A record that says the crew could not recall whether the alarm sounded is far more useful than one that quietly omits the question, because the next reader knows the difference between a thing that did not happen and a thing nobody asked about.
06
When to stop
An investigation is not finished when you find somebody who could have done otherwise. You will always find that person, in every incident, and arriving there tells you nothing you did not already know when you started.
It is finished when you can state the conditions that were present, when you have followed each of them far enough to know whether it is specific to this event or standing in the background of many, and when you have written down what the record could not settle.
A useful stopping test: could this happen again next week with an entirely different crew? If the answer is yes and your findings do not explain why, you have not finished — you have found an individual and stopped. If the answer is no, and you can say precisely what about this situation was singular, you are done.
One more thing about the output. An investigation is initial fact-finding, not a final determination — findings are provisional, they are systemic until shown otherwise, and they exist to let somebody with context and authority make a good call rather than to make it for them. An investigation that closes quickly and surfaces nothing is worse than no investigation, because it produces a record that looks like knowledge and is not.
None of this requires software. It requires time, and a way of asking that a form built around fields cannot prompt for — which is how the same conditions keep arriving in the record without ever being named.
See what this looks like on a real record
A full sample report — five sheets, every count shown over the population it came from, and a written account of what the record could not settle.
See a sample report