Practical resources

Incident investigation evidence timeline

Separate verified facts, source records and unanswered questions in an investigation timeline.

The timeline is an evidence-organising aid. It does not determine cause, blame or legal reporting requirements.

Worked example

In the fictional example, a system log records an alarm at 10:04 and a later account mentions a door condition. Each entry retains its own source and reliability question. The timeline does not infer a causal relationship simply because events appear close together.

Use the resource

Protect original records and their access controls. Use appropriate authorised investigation procedures for real incidents, including any urgent response or reporting. Do not upload witness statements, medical details or identifying records through a public enquiry.

Worked record

Illustrative example — replace with verified information
Time/sequenceFact or accountSource/referenceVerified statusOpen questionFollow-up owner
10:04 (illustrative)Alarm recordedExample system logLog entry identifiedWhat does this timestamp represent?Assign investigator
Later account (illustrative)Door described as openExample interview referenceAccount not independently confirmedWhen was the condition observed?Assign investigator

How to use it

  1. Preserve source and timestamp context.
  2. Label accounts and assumptions.
  3. Record questions without inventing answers.
  4. Assign evidence follow-up through the authorised process.

Your working record

Enter your information, then download a copy to keep it. Entries stay in this tab and are not saved automatically.

Complete the fields that apply to your requirement
Time/sequenceFact or accountSource/referenceVerified statusOpen questionFollow-up owner

Blank record

Download a blank copy for offline reference or printing. Complete the editable record above to save your entries.

Download blank record

Related guidance and resources

Source context

Source context checked 6 October 2026. Examples are illustrative.