Why Your Investigation Needs a Timeline Before It Needs an Answer
- Jim Ball

- 7 days ago
- 3 min read
Walk into most investigation kickoff meetings and the first question in the room is usually "who did it?" That instinct fades fast once people settle in, and it's quickly replaced by the one everyone actually wants answered right away: "So what caused this?"
It's an understandable question. It's also premature.
Before anyone in the room can meaningfully answer what caused this, they need to agree on what happened: in what order, at what time, and according to whom. Skip that step, and the investigation isn't really investigating. It's confirming whatever theory walked into the room first.

The Rush to Explain
There's real pressure behind this. A line is down. A batch is on hold. A regulator wants answers. Everyone wants to move from "something went wrong" to "here's the fix" as fast as possible.
So investigators default to asking why almost immediately. Why did the operator miss the step? Why wasn't the deviation caught sooner? Each why pulls the team further into interpretation, and further away from the facts the interpretation is supposed to rest on.
The problem is that interpretation formed early tends to stay. Once someone in the room says "sounds like a training issue," that framing quietly shapes every question that follows. People stop gathering evidence and start gathering confirmation.
What a Timeline Actually Does
Building a timeline first (a plain, sequential account of events, conditions, and decisions in the order they occurred) does something deceptively simple. It separates the facts from the story.
A timeline doesn't ask why yet. It asks what happened, when, and who was involved or aware. Nothing more. That restraint is the whole point.
Once the sequence is laid out, patterns tend to surface on their own. Gaps become visible: the four hours between when a condition started and when anyone noticed it, or the step that got skipped without anyone deciding to skip it. Those gaps are where the real investigation lives. You can't see them if you've already decided what the story is.
There's a practitioner benefit here too. A shared timeline gives everyone in the room (the operator, the supervisor, the quality lead) something neutral to look at together. Nobody has to defend a theory. They're just confirming a sequence. That alone lowers the temperature in a room that might otherwise feel like an interrogation.
Why Skipping This Step Costs You Later
Investigations that skip the timeline and move straight to root cause tend to produce conclusions that don't hold up under scrutiny: from a regulator, an auditor, or simply six months later when the same failure happens again.
That's because a conclusion built without a verified sequence of events is really just the most plausible-sounding story someone told early on. It might be right. But nobody actually checked.
A timeline is slower at the start. It's faster everywhere else. Corrective actions land better because they're addressing something the team can actually point to and defend. Reports write themselves faster because the narrative is already established in order. And when someone challenges a finding later, you have a sequence to stand on instead of a theory to defend.
Facts First, Explanations Second
None of this means causes don't matter. Understanding how something happened is the whole point of the investigation. It just works better when it's built on a foundation that's actually solid.
Next time your team opens an investigation, resist the pull toward the first plausible explanation. Build the timeline first. Get the facts aligned: what happened and how it happened. Once that foundation is in place, explanations and potential causes become much easier to identify, and the trust you build with the people you're investigating alongside will hold up just as well as your conclusions.
--
Curious how this fits into a full investigation? Beyond Human Error, a self-paced course on shifting from blame to learning, is open now. Start the course.



Comments