5 Whys Root Cause Analysis Example for Safety (2026)

A 5 whys root cause analysis example shows how a safety team moves past the first plausible explanation to the system failure that actually allowed an incident. You state a specific problem, ask why it happened, and treat each answer as the next question until you reach a cause your organisation can change.

The worked example below follows a packaging line where operators repeatedly reach into a closing machine. It shows the evidence behind each why, where the chain branched, and what the corrective actions looked like.

Table of Contents

What Is 5 Whys Root Cause Analysis?

The 5 Whys is a root cause analysis technique that traces a problem back to its underlying cause by asking why about each answer in turn, usually five times, until the team reaches something it can actually change. Each answer must be backed by evidence rather than assumption.

It started in the Toyota Production System, where Sakichi Toyoda and Taiichi Ohno used repeated why questions to stop a machine line rather than accept a quick fix. That is where the emphasis sits: the machine stopped, so find out why the system allowed it to keep running.

Three things distinguish it from a blame conversation or a full incident investigation. It asks what allowed the event, not who was at fault. It runs in a short session with a small group, usually 15 to 30 minutes. And it produces a specific corrective action with an owner attached.

It suits problems with a traceable cause-and-effect chain: near-misses, recurring strain injuries, machine close calls, defect spikes, repeat equipment faults, service complaints that keep coming back. It works less well on problems with many interacting causes, where a single chain hides too much.

A 5 Whys Root Cause Analysis Example: Repeated Machine-Close Calls

A 5 Whys Root Cause Analysis Example: Repeated Machine-Close Calls

This composite example comes from a mid-sized food packaging operation. Over roughly six weeks, three near-miss reports and one minor hand injury involved operators reaching into a case coder to free a jammed carton as the machine closed. Nobody called it a pattern, because each event looked like a one-off.

The safety lead grouped them into one problem statement: an unplanned machine access hazard on line 2, three near-misses and one laceration in six weeks, each involving hand removal of a jammed carton during the closing cycle.

Notice what is not in that statement. It does not say the operator failed to follow procedure. It describes a condition, a place, a count and a window, so the team knows exactly what they are explaining.

What the evidence showed at each level of the chain

The team brought the jam reports, the machine’s guard interlock log, the training record and two hours of direct observation. That last item mattered most. Watching the cycle for twenty minutes showed operators reaching in roughly every fifteen minutes, which is not behaviour a poster changes.

LevelWhy askedAnswerEvidence used
Why 1Why were operators reaching into a closing machine?The carton jammed at the infeed and stopped the cycle, so hands went in to clear it.Jam reports, operator interviews
Why 2Why did a jam lead to reaching in?The jam reset button is on the operator side of the guard and the guards are hinged, so clearing it means opening the machine.Direct observation, layout drawing
Why 3Why was clearing the jam done this way?The only written clearing method was a supervisor-led stop, and supervisors are not on the line for most of the shift.Standard work document, shift roster
Why 4Why was the standard written around supervisor attendance?The machine was specified and installed before a jam-clearing task was ever documented, and the supplier’s manual assumed trained operators.Install records, supplier manual
Why 5Why did no process exist for identifying tasks that create unguarded access?Pre-installation risk review covered production, not the maintenance and jam-clearing tasks that came later.Commissioning checklist

Root cause statement and the branch the team added

The chain landed on a commissioning and task-identification gap: tasks that need the guard open were never assessed, designed out or given a compliant alternative. That is a system cause an organisation can change.

The team also split the chain at Why 2, because one cause could not explain every event. A second branch ran through the infeed design, where cartons could fold and wedge at an awkward angle. Fixing only the supervision branch would have left a jam-prone corner in place.

Why Does Each Round of 5 Whys Matter?

Each round should establish something new and move you further from the event. Why 1 describes what happened immediately before the harm. By Why 3 and 4 you should be looking at design, workload, standard work and decision history, not at people.

A useful test: if an answer would still be true if everyone involved behaved perfectly, it is describing a system rather than a person. Why was the jam clearance designed around a supervisor? That stays true no matter how careful the crew is.

Split the chain when two answers explain different parts of the same problem. Forcing multiple causes into one line is the most common way these analyses go wrong, and it hides the second contributing factor until the problem returns.

Stop when the answer is actionable and under your control. Three whys can be a complete analysis. Five is a useful default, not a quota.

How to Verify the Root Cause in a 5 Whys Analysis

An answer is not a root cause until the evidence holds it up. Before you commit money, test the candidate cause against records, direct observation, worker interviews, policies and equipment history.

For each answer, ask who can prove it. In the example, the interlock log confirmed the guards were opened without a lockout, the training record showed no jam-clearing competency, and observation showed the pattern across shifts rather than one team.

Then run the counterfactual: if you fix this cause, will the problem stop? Fixing supervisor attendance fails that test, because supervisors still are not there at 2am. Fixing the access design passes it, because the hands-in motion disappears.

Compare against comparable tasks too. If guarding elsewhere in the plant is fixed, isolation-first, the gap here is a decision that can be repeated rather than an unavoidable hazard.

What Are the Best Corrective Actions for This Example?

Corrective actions should follow the hierarchy of controls, so the highest effective control comes first rather than whichever is fastest to implement.

  • Elimination or engineering first. Interlocked fixed guards that will not open while the cycle runs, plus a jam-clearing tool so no one needs a hand inside the machine. Fixing the infeed to stop cartons wedging removes the trigger itself.
  • Administrative controls next. A written jam-clearing method that works at any hour, a lockout procedure with a named authoriser, and a competency check before anyone clears a jam.
  • PPE and signage last. Cut-resistant gloves and a warning label are useful layers, but neither stops a hand from entering a closing machine.

Sequence them: containment on the line now, engineering within weeks, administrative changes once the design is fixed. Rehearse the intervention before you judge whether it worked, and check whether a similar unguarded-access task exists elsewhere in the plant.

For the broader task-level risk assessment that should have happened at installation, our job hazard analysis step-by-step guide covers how to break a job into steps and look for hazards at each one.

When Should You Use a Different Root Cause Analysis Method?

Switch methods when the problem is too tangled for a single chain. A 5 Whys that needs a footnote on every line is telling you the tool does not fit.

  • Fishbone or Ishikawa diagram when you want to map many categories of cause at once, such as a quality defect with human, machine, method, material and environment branches.
  • Pareto analysis when you do not yet know which problem is worth analysing, because it ranks causes by frequency or cost first.
  • Fault tree analysis when a rare event has several interacting conditions and you need logic gates and probabilities rather than a narrative.
  • Human factors review when fatigue, shift design, workload, alarms, staffing or physical layout are the real issue and a linear chain will understate them.
  • Statistical or trend analysis when the pattern needs numbers over time, such as injury rates, exposure hours or defect frequency by shift.
  • 8D problem solving when the investigation must be formally documented for a customer, an auditor or a regulator, including containment and verification stages.

A practical rule: run 5 Whys first because it is fast and cheap, then escalate when the chain keeps splitting or the evidence contradicts the answer in front of you.

Common Problems With Workplace 5 Whys Examples

Most failed workplace analyses share the same three faults: they stop at human error, they ask leading questions, and they arrive at a solution before the evidence is in the room. Rewording the questions is the quickest fix.

Dead-end answerWhy it failsBetter question
The employee forgot to lock out.Makes the failure a personal trait, so nothing changes and the same event recurs.What made lockout the harder option at that moment?
Training was inadequate.Often stops the chain and hides the design, access or staffing problem underneath.When was this task last assessed, and who wrote the method for it?
Why didn’t you follow the procedure?Leading question. The answer is yes, and the analysis ends there.What did the procedure ask you to do, and what did the task require?
The supervisor should have inspected more.Moves the failure up the hierarchy without changing any system.What was the supervisor able to see on their shift, and what were they not shown?
They need to be more careful.Not a cause. Nothing in it can be assigned, measured or fixed.What conditions made careful behaviour unlikely at that time?

Two more traps: forcing a chronic, multi-factor problem into one linear chain, and writing no record at all, which means the same investigation happens again six months later.

Frequently Asked Questions

Is 5 Whys a root cause analysis or just an investigation checklist?

It is a root cause analysis method, not a checklist. A checklist tells you what to look at; the 5 Whys builds a cause-and-effect chain by treating each answer as the next question until you reach something you can control and change. Its weakness is that it follows one chain, so complex multi-cause problems need a different tool.

How many reasons should a 5 Whys analysis contain?

Treat five as a default, not a target. Three whys can be a complete and honest analysis if the third answer points to a cause you can act on. Keep going while the answer reveals a new contributing condition. The 5 whys root cause analysis example above needed five levels plus a branch, because the single chain did not explain every event.

What if the 5 Whys analysis identifies employee error?

Error is a symptom of the system that allowed it. Ask what made the error easier than the safe option at that moment, such as time pressure, missing equipment, unclear method or a task designed for a person who was not present. If your corrective action is a retraining session and nothing else, the analysis has probably stopped too early.

Should every answer receive another why question?

No. Stop when the answer is specific, under your control and linked to a corrective action you can assign. Continue past a generic answer such as human error or poor communication, because those hide the design, workload or policy problem underneath. Splitting the chain into two branches is better than forcing a second cause into the same line.

How do you document a completed 5 Whys analysis?

Record the problem statement, each why with the evidence behind it, any branches, the final root cause statement, and each corrective action with an owner and a due date. Add a verification note describing how you will confirm the problem stopped. Keep the record where your incident and near-miss reports live so the next investigation can build on it.

What is the difference between a 5 Whys analysis and a fishbone diagram?

The 5 Whys works one chain deep and quickly, which suits a single clear failure or near-miss. A fishbone diagram fans out into categories such as people, machine, method, material and environment, which suits a problem with many possible causes. Many teams run a fishbone first to shortlist causes, then use the 5 Whys to go deep on the ones that survive.

If you run one analysis this month, pick a recurring near-miss rather than the most serious incident, bring the records and the people who did the work, and refuse to accept an answer about human error without asking what made it easier to get hurt.

Leave a Comment