Records & incidents
What is an incident report?
An incident report is the officer's written record of something that happened on site — what occurred, when, who was involved, what was done. It may later be used in evidence.
Use this diagram+
Free to use on your own site, in training material or in a handout, as long as the credit link stays on it. Paste this where you want the diagram to appear.
<figure>
<img src="https://secureoptix.co.uk/glossary/incident-report/diagram.svg" alt="incident report — diagram from SecureOptix" width="880" height="620" loading="lazy">
<figcaption>
<a href="https://secureoptix.co.uk/glossary/incident-report">What is an incident report?</a> — diagram by
<a href="https://secureoptix.co.uk">SecureOptix</a>
</figcaption>
</figure>It is written close to the event for a reason. Detail degrades quickly, and a report written the next day is a summary of a memory rather than a record of an event.
It may end up in a criminal or civil proceeding, which sets the standard it should be written to: factual, chronological, distinguishing what the officer saw from what they were told and from what they concluded.
Incidents also aggregate into something useful. A pattern of similar reports at one site is intelligence about a security problem, and it is usually invisible because each report is filed and read once.
What goes wrong in practice
- Written retrospectively at the end of a shift or later.
- Conclusions and opinions mixed with observations, which weakens the report in any proceeding.
- Personal data recorded without regard to data protection obligations.
- Reports filed per site with nobody looking across them for patterns.