Quick answer
The block above is the short version. Below, each stage gets a section: what it produces, who owns it, and the failure mode that ends the chain there. The table contrasts what each stage looks like when records are filed separately against what it looks like when they are connected.
| Stage | When records are filed separately | When records are connected |
|---|---|---|
| 1. Intake | A long form, often skipped, or an email to a shared mailbox | Reporter facts only, with the reference and location added by the system |
| 2. Classification | Coded by hand weeks later, or not at all | Proposed on arrival with a confidence, accepted by a person, version pinned |
| 3. Barrier | The hazard register is a separate document nobody opens | The occurrence updates the assessed condition of a named barrier |
| 4. Indicator | Counted into a monthly total and read as a bar chart | Plotted on a control chart where a statistical rule can trip on its own |
| 5. Action | Closed on a checkbox by the person who owned it | Closed only after a second person verifies the risk actually fell |
| 6. Decision | An agenda assembled by hand the week before the meeting | An agenda derived from what the safety data escalated |
Stage 1: intake
The person who saw it is usually standing outside. Intake should ask only for what they hold: what happened, where, when, who was involved, whether anyone was hurt, and what state the aircraft is in. Everything else, the reference, the location, the taxonomy code, the risk band, is the system job.
The failure mode: asking the reporter to classify. A form that requires a ramp agent to pick an aviation taxonomy code produces fewer reports and worse ones. Reporting volume is the raw material of the whole system, and every field you add to intake costs you some of it.
Stage 2: classification and risk band
Classification places the occurrence in a taxonomy so it can be compared with others. Risk banding places it on the matrix so it can be prioritised. Software can propose both; a safety professional owns both, and the acceptance belongs on the record.
The matrix should be fixed rather than tuned per assessment, because a band only carries meaning if the same severity and probability produce the same answer across fleets and across years. See the aviation risk matrix explained for how tolerability is derived, and hazard versus risk for the distinction this stage depends on.
Stage 3: the barrier
This is the stage most operations never reach, and it is the one that turns a report into prevention. The occurrence is evidence about a hazard, and usually about one specific control that did not hold. A ramp vehicle collision hazard might carry eight named barriers; a tug contact tells you which of them was degraded at the moment it mattered.
Because barriers are shared between hazard models, degrading one moves every model that leans on it. That is the whole argument for keeping barriers as named objects rather than as prose inside a risk assessment document. See bow-tie without the spreadsheet.
Stage 4: the indicator
One occurrence is an anecdote. The indicator is where it becomes a trend. Ground damage rate plotted on a control chart with limits will trip a statistical rule when the process shifts, which is a different and much earlier signal than a bar going up in a monthly pack.
The failure mode: indicators recalculated by hand each month and presented as coloured arrows. Nobody can act on an arrow, and by the time three months of arrows point the same way the drift has been running for a quarter. See control charts versus trend bars and leading versus lagging indicators.
Stage 5: the corrective action
An action that closes on a checkbox proves that something was done, not that risk fell. Both EASA Part-ORO and FAA 14 CFR Part 5 expect effectiveness verification, and the practical rule that makes it real is that the owner of an action is never its verifier.
This is where old chains come back. An action closed unverified months ago is frequently the reason a barrier was still degraded when the next occurrence arrived. See the closure gate for the mechanism.
Stage 6: the decision
Where the risk warrants it, a safety action group or safety review board takes a decision and records it: what was decided, who voted, what changes, and who is accountable for the residual risk. The vote and the signatures belong to the record rather than to a separate set of minutes.
The useful test of a governance layer is whether its agenda can be derived from the safety data. If it is assembled by hand the week before, the board reviews what was remembered rather than what escalated. For how these records wire together across the system, see connecting occurrence, CAPA, SPI and the risk profile.
Frequently asked questions
What happens after you submit an occurrence report?
A well run occurrence report moves through six stages. It is received and given a reference; it is classified and risk assessed against a matrix; the hazard and barrier it exercised are identified; the indicators that track that hazard are updated; a corrective action is raised where the risk requires one and closed only when its effectiveness has been verified; and where the risk is significant, a decision is taken and recorded by a safety action group or safety review board. In a disconnected system the report usually stops after stage one or two, which is why reporters conclude that filing reports changes nothing.
How long should an occurrence report take to file?
Intake should take a minute or two, not a form-filling session. The reporter is often standing on a ramp or in a hangar, so the questions they answer should be the facts only they hold: what happened, where, when, who was involved, and whether anyone was hurt. Classification, taxonomy coding, risk banding and linking are the system job, proposed automatically and confirmed by a safety professional. Operations that ask reporters to classify their own occurrence in aviation taxonomy get fewer reports and worse data.
Who assigns the risk band to an occurrence?
A safety professional, using the organisation risk matrix, on the facts in the record. Software can propose the band and should show its confidence, but the person accepting it owns the assessment and that acceptance belongs on the audit trail. The matrix itself should be fixed rather than adjusted per assessment, because a band only means something if the same combination of severity and probability produces the same answer across fleets and across years.
What is the difference between an occurrence, a hazard and a barrier?
An occurrence is something that happened. A hazard is a condition with the potential to cause harm, which exists whether or not it has produced an occurrence yet. A barrier is a control placed between the hazard and the harm. One occurrence is evidence about a hazard and usually about a specific barrier that did not hold. Treating occurrences as the whole of safety data is the most common structural mistake, because it limits the system to reacting to events that already happened rather than managing the conditions that produce them.
When does an occurrence go to the safety review board?
When the assessed risk, the trend, or the failure of a control crosses the threshold the organisation has set for executive attention, rather than when someone remembers to add it to an agenda. A safety action group typically handles operational oversight and escalates to the safety review board where a decision needs authority or resources it does not hold. The useful test is whether the agenda can be derived from the safety data itself. If the agenda is assembled by hand the week before, the board is reviewing what was remembered rather than what matters.