How to Create an Incident Report (Best Practices & Templates)

Last updated / 8 min read
Jack Delaney Jack Delaney
How to Create an Incident Report (Best Practices & Templates)

Last updated July 2026

An incident report is a document that records the facts of an event that caused, or could have caused, injury, illness, damage, or loss. The smart way to build one is to start from a ready-made incident report template rather than a blank page, since the structure and required fields are already worked out for you. It captures what happened, when, who was involved, and what corrective action followed, so the same problem doesn't repeat itself.

Most workplaces need one for accidents and near misses. Some need one for security breaches, property damage, or conduct issues too. Paperform is a form builder with free incident report templates you can adjust to your own workplace, and it's designed so employees complete the form instead of abandoning it halfway. The report itself only works if two things are true: it captures the right details, and people fill it in. That second part is where most incident reporting breaks down, and it's the part this guide focuses on.

TL;DR

Question Answer
What is it? A record of an event that caused, or nearly caused, harm, damage, or loss
Who fills it out? Anyone: the person affected, a witness, or someone flagging a hazard before it becomes an incident
What must it include? Type of incident, date and time, people involved, a factual sequence of events, witness statements, and any evidence
Why forms beat documents Structured fields force the right details in, route submissions instantly, and don't get buried in a shared drive
Fastest way to start Use a ready-made incident report form template and adjust the fields to your workplace

Why so many incidents never get reported

Underreporting is the biggest problem in incident reporting, not the paperwork itself. Recent industry research puts the underreporting rate for workplace incidents, hazards, and near misses at 90%, up from 79% the year before (Work Safety 24/7). Separately, 78% of serious workplace incidents were preceded by one or more near misses that were never logged (OSHA).

That gap matters because near misses are predictive. For every 300 near misses in a workplace, there are roughly 29 minor injuries and 1 serious injury behind them, and companies that actively track and investigate near misses see a 23% reduction in major accidents within three years of starting (National Safety Council).

Friction, not a lack of concern, drives most of that underreporting. A paper form that sits in a drawer, a PDF that has to be printed, scanned, and emailed to three people, or a process that isn't clear enough for a stressed employee to follow in the moment. Fix the friction and the reporting rate follows.

What a good incident report needs to capture

Whatever format you use, an incident report needs the same core information every time:

  • Type of incident (injury, near miss, property damage, security issue, or conduct concern)
  • Date, time, and exact location of the event
  • A factual, sequential description of what happened, written without assigning blame
  • Full names and contact details of anyone involved or who witnessed it
  • Witness statements, recorded separately from the main account
  • Any medical treatment provided or required
  • Photo, video, or document evidence, attached directly to the report

Speed matters as much as detail. Reports filed within 24 hours are more accurate, because memory of specifics fades fast, and in some jurisdictions there's a legal window for filing certain incident types at all. The report's job is to establish facts, not to find someone to blame. If fault needs following up, that happens afterward, in a separate process.

Why a form works better than a document

A Word document or PDF depends entirely on the person filling it out to remember every field, format it correctly, and get it to the right inbox. A form removes that dependency. Required fields stop a report going in half-finished. Conditional logic can show a different set of questions for a vehicle incident versus a workplace injury, so nobody wades through irrelevant sections. File upload fields mean photo evidence attaches directly to the record instead of arriving in a separate, unlinked email. And a submission can notify your safety officer the moment it's filed, rather than waiting for someone to check a shared folder.

None of that requires custom software or a developer. You build the form the same way you'd write a document, adding fields, conditional logic, and file uploads directly into the layout. Submissions land in one place, and you can route them automatically as they come in.

Building an incident report form step by step

  1. **Start from a template.** The template linked above already has the standard fields (incident type, date, location, description, witnesses) built in, so you're editing rather than starting from a blank page.
  2. Add conditional logic for incident type. Set up branching so a "vehicle accident" selection reveals vehicle-specific fields, while a "near miss" selection skips the injury-treatment section entirely.
  3. Make evidence upload mandatory where it applies. Add a file upload field for photos or documents, and mark it required for incident types where evidence is standard practice.
  4. Separate witness statements from the main account. Use a repeatable field or a second short form so each witness gives their own version, rather than one person paraphrasing for everyone.
  5. Route submissions automatically. Connect the form to email, Slack, or a Google Sheet so your safety lead sees new reports the moment they land, instead of checking manually.
  6. Test the flow yourself. Submit a dummy report before rolling it out, and time how long it takes. If it's over a few minutes, cut fields.

What happens after the report is filed

Filing the report is the start of the process, not the end of it. A completed incident report that just sits in a folder doesn't prevent the next one.

  1. Acknowledge the report quickly. Whoever submitted it should get confirmation it was received, ideally an automatic one, so they know it went somewhere rather than disappearing.
  2. Triage severity and assign an owner. Not every report needs the same response. A near miss might need a quick review; a serious injury needs an owner and a clock running immediately.
  3. Investigate beyond the initial account. The original report captures what the submitter saw. An investigation goes further: additional witness interviews, a site visit, or a review of any equipment or process involved.
  4. Identify the root cause, not just the immediate one. A slip happened because the floor was wet is the immediate cause. Why the floor was wet, and why nobody noticed sooner, is usually the more useful question.
  5. Assign and track corrective action. Whatever needs to change (a repair, a new procedure, additional training) should have an owner and a deadline, not just a note in the file.
  6. Close the loop with the reporter. Following up, even briefly, on what came of a report is one of the biggest drivers of whether people bother reporting the next one.

If your team is handling more than a handful of reports, a tool like Stepper can take over some of this handoff automatically, routing a report to the right investigator based on its severity or type instead of relying on someone to notice it in a shared inbox.

Keeping incident records secure: retention and access

Incident reports often contain sensitive information: medical details, personal contact information, and sometimes an account of a workplace conduct issue. That makes access control and retention worth deciding on deliberately, not as an afterthought.

Who should have access: Generally, this means the safety lead or manager handling the case, HR if it involves a conduct or employment matter, and anyone directly assigned to investigate. Broad, company-wide visibility into incident reports isn't usually appropriate, and can discourage people from reporting in the first place.

How long to keep records: Retention requirements vary by jurisdiction and industry, and in some regions specific incident types carry legal minimum retention periods, so check what applies to your business rather than relying on a single rule of thumb. As a general reference point, OSHA recordkeeping rules in the US require injury and illness logs to be retained for five years, which is a reasonable default even outside a strict compliance requirement.

Storing reports securely matters as much as collecting them. Paperform is SOC 2 compliant, and role-based permissions mean you can control who sees submitted reports rather than leaving them accessible to anyone with a shared folder link.

Types of incident reports you might need

Not every incident fits the same template. If the incident-specific template linked above isn't the right shape, Paperform's reporting template library has more targeted options, including a near miss incident report, an injury incident report, a hazard report, a vehicle accident report, and a cybersecurity incident report for security breaches and data incidents. Start from whichever is closest to your use case and adjust the fields from there, rather than building from zero.

FAQ

What's the difference between an incident report and a near miss report? An incident report covers an event that already caused injury, damage, or loss. A near miss report covers an event that could have caused harm but didn't. Both should use the same reporting process, since near misses are a leading indicator of future incidents.

Who should be allowed to submit an incident report? Anyone: the person directly affected, a witness, or someone flagging a hazard before it causes harm. Restricting submissions to managers or supervisors is one of the most common reasons incidents go unreported.

How quickly should an incident report be filed? As close to the event as possible, ideally within 24 hours. Memory of specific details, like exact wording or sequence of events, degrades quickly, and some jurisdictions set legal filing windows for certain incident types.

Should an incident report assign blame? No. Its job is to record facts: what happened, when, and who was involved. Any follow-up on fault or corrective action against an individual happens in a separate process, after the facts are established.

Can an incident report form replace a paper-based safety process? Yes, in most workplaces. A digital form captures the same information as a paper report, adds required fields and conditional logic so nothing gets skipped, and routes submissions instantly instead of relying on someone to physically deliver or file paperwork.

Do I need different forms for different incident types? Not necessarily. One form with conditional logic can branch into vehicle, injury, near miss, or security-specific questions based on an initial selection, which is simpler to maintain than several separate forms.

Start from the template linked above, adjust the fields to match your workplace, and you'll have a working form ready to share in under 15 minutes.

Jack Delaney
Jack Delaney

Jack is the Content Manager at Paperform, a digital Swiss Army Knife that empowers you to create forms, eSignatures, surveys, bookings, payments, and more.

Form a better life now.

Get your 7 day unrestricted trial
No credit card needed. Continue with our completely free plan.
5 Client Onboarding Mistakes That Cause Scope Creep for Freelance Graphic Designers

Scope creep starts before the first design file opens. Learn the five client onboarding mistakes fre...

4 Ways Admin Fatigue Kills Your Freelance Profit

Freelance admin never shows up as a line item on an invoice, but it's still costing you billable hou...

Product retro: May 2025 to June 2026

The most consequential year in Paperform's history. We launched Stepper, our AI-native workflow auto...