On paper, an ICAM investigation is a disciplined sequence. In practice (spreadsheets, photos in email threads, statements in Word) the discipline leaks. Here is what the same sequence looks like when the platform carries the structure, using the phases SafetyPulse walks investigators through.
Phase 1. Planning: scope before evidence
The investigation opens with the factual event description (no analysis, no blame), then the two-layer severity assessment ICAM scopes by: what actually happened, and the credible worst outcome. A near-miss with fatality potential gets full rigour. The platform requires the SIF-potential call to be made explicitly, with justification, before anything unlocks. Scope, objectives and team round out planning.
Phase 2. PEEPO: plan the evidence, then collect it
PEEPO (People, Environment, Equipment, Procedures, Organisation) turns evidence collection from a scramble into a plan: what exists, what disappears if not captured today, who saw what. Digitally, each line of inquiry becomes a trackable item (planned, assigned, collected) and field evidence (photos, voice-recorded interviews, documents) lands directly against it rather than in someone's inbox.
Phase 3. The factual timeline, three layers deep
The timeline is where ICAM earns its keep. Beyond the factual sequence, investigators capture work-as-imagined (what the procedure says), work-as-normal (what usually happens) and work-as-done (what happened that day). The divergences between those layers are where contributing factors hide. A digital matrix keeps the four views aligned against the same events, nearly impossible to maintain on paper.
Phase 4. Contributing factors across the four families
Each divergence gets tested against the ICAM families: Absent/Failed Defences, Individual/Team Actions, Task/Environmental Conditions (including human factors), and Organisational Factor Types. The platform holds each factor against its evidence, and (because individual actions are analysed in context, never as blame) prompts investigators to trace every IT factor back to the conditions and organisational factors that shaped it.
Phase 5. Recommendations that trace back
Systemic fixes land at DF and OFT. Each recommendation is linked to the factors it addresses, with an owner, a target date and a hierarchy-of-controls level, so "retrain and remind" can be spotted for what it usually is: an administrative control standing in for an engineering fix.
Phase 6. The report writes itself from the record
Because every element is structured, the final report is generated from the investigation record: executive summary, factual information, timeline, factor analysis with evidence references, recommendations with linked factors, and appendices (evidence register, corrective action plan). Investigators edit and approve. Hours of assembly become minutes of review, and the report can never drift out of sync with the analysis behind it.
The gaps between what the procedure says, what normally happens and what happened that day are where systemic learning hides.
Want to see the whole flow on a real scenario? Book a demo. We run it on a fully-worked mining investigation, end to end.