info@lighthc.london

+44 2078710485

10 Root Cause Analysis Methods for UK Investigations

A small unexplained payment can become a serious dispute before anyone agrees on what happened. A director may see an accounting error, while a lender sees possible management failure. An insurer may challenge a business interruption claim, a shareholder may allege concealment, or a solicitor may need to explain a loss to the court. Meanwhile, the underlying records sit across bank statements, emails, accounting software, contracts, payroll files and system logs.

Finding the symptom isn't enough. Decision-makers need a defensible chain from the event, through the contributing failures, to the cause and quantified financial impact. UK public-sector guidance treats root cause analysis as a structured, reactive method for distinguishing immediate causes from underlying management or organisational failings, while also recommending that teams understand the data journey and fix problems as close to source as possible. Government Data Quality Framework guidance sets out that practical direction.

Some organisations hesitate to appoint a forensic accountant because they expect high cost, operational disruption, confidentiality concerns or escalation into litigation. A scoped discovery can reduce those risks. It lets the investigator define the records, preserve evidence, agree priorities and produce an action plan before the work expands.

Lighthouse Consultants is a London-based option for independent forensic accounting, audit and financial analysis. Its structured approach covers discovery, scoping and reporting for fraud, disputes, insurance claims, insolvency and unexplained losses. The ten root cause analysis methods below show how practitioners connect evidence to decisions, whether they're testing a suspected fraud, quantifying a claim or preventing a recurring operational incident. For wider business perspective, explore these latest thinking insights.

1. The Five Whys Technique

Five Whys works best when an investigation begins with a precise event, not a broad accusation. “The company suffered a loss” gives little direction. “Invoices were paid without valid purchase orders during the migration period” defines a testable issue and a clear evidence trail.

Start with the event, ask why it occurred, then test each answer against records. In a suspected fraudulent invoice case, the sequence may move from purchase order matching to system access, segregation of duties and management review. The underlying cause may sit in control design rather than with the clerk who processed the payment. One person may have been able to create a supplier, approve an invoice and release funds because responsibilities and system permissions were poorly configured.

UK healthcare guidance commonly pairs RCA with information gathering, event mapping, analysis, barrier analysis, solution design and reporting. The questioning may require “three”, “seven” or “nine” rounds, depending on how many are needed to reach the primary cause. The Government Data Quality Framework also emphasises logging problems, categorising severity and escalating serious issues.

Where the method helps, and where it fails

Use Five Whys for a focused accounts payable irregularity, an unexplained claim calculation or a control breakdown with a reasonably clear sequence. It is a questioning structure, not proof by repetition. An unsupported answer remains unsupported, however many times the investigator asks “why”.

Practical rule: Stop when the evidence becomes circular, not when the question reaches an arbitrary number.

A defensible working file should contain:

  • Interview records: Record each stakeholder's account separately.
  • Transaction support: Test the proposed cause against invoices, approvals, bank records and system activity.
  • Alternative explanations: Document plausible explanations that the evidence rejects, not only the theory that survives.
  • Corrective actions: Identify the control owner, required change and evidence needed to confirm implementation.

Five Whys can expose bribery risks where procurement bypassed competitive tendering, or explain a shortfall in a business interruption claim where revenue calculations lacked review. Its conclusions are stronger when supported by data analytics, document examination and process mapping, with each inference tied to an identifiable record.

2. Fishbone and Process Mapping

A supplier payment can pass through procurement, finance and banking controls before anyone notices the loss. A Fishbone, or Ishikawa, diagram helps investigators examine that chain without assigning blame to the first identifiable person. The undesired event sits at the centre, while branches organise possible causes under people, process, systems, materials, methods, management or environment. This structure prompts questions about design failures, missing controls, weak supervision and deliberate circumvention.

Process mapping tests the same issue against the route a transaction should have taken. In a purchase-to-pay review, that route may include supplier due diligence, a purchase order, receipt confirmation, invoice matching and dual approval. Actual records may instead show manual invoices, bypassed approvals or access rights that no longer match job responsibilities. The gap between the approved process and the recorded activity often provides the clearest starting point for further testing.

Use workshops to establish how work is performed in practice. Department heads, finance leads and operational staff can identify exceptions and informal handovers, while the investigator checks those accounts against transactions, system records and audit logs. These fishbone diagram exercises can help teams practise the visual technique before applying it to a live matter.

A diagram is an investigation aid, not a finding. Each branch needs evidence and a stated connection to the event. For example, weak training may contribute to an error, but it does not by itself explain a loss where unauthorised access and absent exception review also existed.

Keep the original diagram, later versions and the reasons for each change. That audit trail records how hypotheses were narrowed and gives an expert a defensible basis for explaining the analysis under scrutiny.

Use the map to test:

  • People: Roles, supervision, incentives and conflicts of interest.
  • Process: Approval steps, exceptions, handovers and undocumented workarounds.
  • Technology: Access controls, configuration changes, interfaces and audit logs.
  • Evidence: Transaction samples, emails, contracts, reconciliations and confirmations.

The visual comparison below can help determine whether Five Whys provides enough structure for the issue.

An infographic detailing the advantages and limitations of the Five Whys technique for root cause analysis.

Process mapping can also clarify a covenant breach, disputed valuation or supplier dispute while keeping causal analysis separate from premature liability conclusions. Review the map before watching this practical explanation:

3. Fault Tree Analysis

Fault Tree Analysis starts with a defined top event, such as a fraudulent payment, rejected insurance claim or quantified financial loss. The investigator then works backwards through logical conditions to show what had to occur for that event to happen. Unlike a simple linear narrative, a fault tree can represent combinations of failures using “and” and “or” relationships.

That distinction matters in litigation and insurance work. A loss may require both management override and absent procurement controls. Alternatively, either of two independent system weaknesses may have allowed the same payment to proceed. The tree makes those relationships visible and helps the reader distinguish a necessary condition from a background factor.

For example, an investment valuation dispute might involve inadequate due diligence, weak baseline assumptions and unchallenged vendor estimates. A business interruption analysis might show that the loss calculation omitted supply-chain dependencies, so the model understated the operational effect of the incident.

Build the tree from the loss

Start with the specific loss and its value, then identify the controls that should have prevented or detected it. Work with process owners and systems teams to confirm how the controls operate in practice. Label controls as absent, designed incorrectly or operating unsuccessfully, because each category supports a different recommendation.

Don't assign probabilities merely to make the tree look technical. If the investigation needs probability weighting, base it on transaction testing and reliable operational evidence. Otherwise, describe the relationship qualitatively and explain the limitation.

A clear fault tree can help a board understand why a control investment addresses exposure rather than treating an isolated incident. Lighthouse's risk management process for UK teams provides further context for structuring that governance conversation.

4. Pareto Analysis

Pareto Analysis helps boards allocate limited remediation resources against the exposures that matter most. It ranks causes by frequency, financial impact, or both. A frequent weakness may create cumulative losses, while an infrequent event may warrant urgent action because one occurrence can have serious consequences.

The familiar 80/20 expression is a prioritisation principle, not a finding. In a forensic investigation, calculate the actual distribution from tested records. If three suppliers account for most unrecovered claim value, the conclusion should rest on the reviewed transactions and supporting documents, not on a template that assumes a particular pattern.

Start with the population and test the concentration

Define the population before building the chart. It might comprise disputed invoices, rejected claim components, audit findings, unauthorised payments, or valuation adjustments. Apply consistent categories, calculate each item's financial effect, and rank the results from highest to lowest. Review frequency and magnitude separately before considering them together.

The pattern usually supports different decisions:

  • High-frequency, low-value items: These may justify process automation or targeted training.
  • Low-frequency, high-value items: These may require senior escalation despite limited occurrence.
  • Recurring control failures: These point to a systemic weakness rather than isolated human error.
  • Unclassified losses: These require further investigation before management relies on the chart.

A Pareto chart can help an audit committee agree priorities, but it cannot establish causation. It shows concentration. Interviews, transaction testing, documents and control analysis must explain why that concentration exists. In disputes or insurance claims, retain the population definition, exclusions, coding rules and calculation file so another reviewer can reproduce the result.

Revisit the chart after remediation. As the most visible problems reduce, previously minor categories may become more significant. That reflects a changed risk profile, not necessarily an error in the original analysis.

5. Failure Mode and Effects Analysis

Failure Mode and Effects Analysis, or FMEA, shifts the organisation from reacting to losses toward preventing them. The team lists realistic ways a process, system or control might fail, then assesses the consequences, the likelihood of occurrence and the ability of existing controls to detect the failure.

A procurement FMEA might identify the circumvention of competitive tendering as a serious exposure, especially where one person can select a supplier and approve payment. A treasury review may find that email confirmation offers weak protection against impersonation. A payroll review may reveal that ghost-employee detection depends on managers reporting anomalies, yet the process doesn't require anyone to act on those reports.

The method works best with a cross-functional team. Finance understands the accounting effect, operations understands the workflow, IT understands system permissions and compliance understands regulatory exposure. A workshop that excludes one of those perspectives may rank the risks inaccurately.

Score honestly, then act

Severity should reflect financial, legal, regulatory and reputational consequences, not only the amount of money involved. Occurrence should reflect transaction volumes and known incidents. Detection should reflect what the controls catch. If similar failures passed through existing controls, the detection assessment shouldn't imply that those controls are reliable.

The scoring system supports prioritisation, but it doesn't replace judgement. A low-frequency failure with severe consequences may deserve action even if its combined ranking looks modest. Likewise, a high-ranked issue may need better evidence before management commits to an expensive redesign.

FMEA produces value when each priority becomes an owned action. The action should specify the control change, accountable owner, target date, testing method and escalation route if implementation stalls.

6. Root Cause Analysis Using Data Analytics

Data analytics turns a broad suspicion into a defined testing programme. The practitioner can examine transaction amounts, dates, vendors, approvers, user activity, exception reports and system logs rather than relying solely on recollections. This matters when a fraud spans a long period or when the investigator must quantify a loss across a large ledger.

Begin with scope. Define the date range, transaction classes, approval thresholds, entities and systems. Then assess data quality before drawing conclusions. Missing fields, duplicated records, changed supplier identifiers or incomplete logs can create false anomalies and undermine an otherwise plausible theory.

A purchase-to-pay review might flag newly created vendors, unusual approval times, repeated round-value invoices or one approver outside normal patterns. Those indicators don't prove fraud. They identify transactions for corroboration through invoices, delivery evidence, bank statements, emails and supplier confirmation.

Match testing to the risk

Low-frequency, high-value payments may justify complete testing. A high-volume population may need stratified sampling, with particular attention to exceptions and transactions near approval limits. The working paper should document filters, exclusions, formulas, software used and the investigator responsible for each step.

For business interruption work, the analysis might compare daily transaction activity before and after an incident, then test whether the observed variance reflects the insured event or other causes such as seasonality, customer loss, pricing changes or supply disruption. For payroll, cross-referencing personnel records, PAYE filings and access logs can identify records requiring further examination.

A laptop screen displaying an anomaly detected in transaction heatmap and timeline data for business analysis.

Internal teams may lack the time or technical capacity to process complex datasets. Lighthouse's business intelligence consulting service is relevant where management needs structured analysis alongside financial interpretation.

7. Causal Factor Charting

Causal Factor Charting creates a chronological explanation of how an event developed. It begins with documented events and connects them through actions, inaction and system design. The result helps the reader understand not only what happened, but also which earlier conditions made the outcome possible.

In a fraud matter, the sequence might run from recruitment, through an incomplete segregation-of-duties migration, to expanded approval access and false claims. In an insurance dispute, the sequence could cover policy issuance, a requested amendment, the insurer's response or non-response, the subsequent loss and the coverage decision. In contract litigation, an ambiguous clause may precede a favourable supplier interpretation, unchallenged performance and accumulated costs.

Keep causation separate from blame

Build the chart from emails, transactions, meeting notes, system logs and signed documents. Work backwards from the incident and ask what had to happen for the outcome to occur. Mark each event as an action, omission or design condition. That classification often reveals why a human-error conclusion is incomplete.

The chart should show dates where the evidence supports them and should identify uncertainty where records conflict. Don't force a clean sequence if the evidence doesn't justify one. A court, insurer or opposing expert will test the gaps.

Before presenting the chart, arrange an independent review. A second practitioner can challenge unsupported links, identify competing explanations and test whether the claimed financial loss follows from the causal chain. The final visual should remain understandable to a non-specialist, while the working file preserves the detailed evidence behind each connection.

8. SCAMPER Analysis

SCAMPER tests how an ordinary process could be altered, bypassed or repurposed to create fraud, error or operational loss. Its seven prompts are Substitute, Combine, Adapt, Modify, Put to another use, Eliminate and Reverse. Use them to generate specific failure hypotheses, then test those hypotheses against records.

Treasury payments provide a practical example. Substituting system verification with manual email confirmation may let an impersonator influence payment instructions. Eliminating receipt requirements can permit unsupported expense claims. Reversing procurement's challenge process, so a preferred supplier is treated as automatically acceptable, can conceal weak value testing or conflicts of interest.

Test each proposed weakness against evidence

Apply every prompt to the workflow, including workarounds that staff consider harmless. For each change, record who could benefit, what transaction or system evidence would expose it, and which control should prevent it. Compare those predictions with approval histories, payment records, emails and system activity.

A workshop output is a hypothesis register, not a finding. SCAMPER encourages creative possibilities, but high-stakes fraud, dispute, insurance and audit work requires independent testing. An analyst should identify the supporting records, contradictory evidence and alternative explanations before linking a vulnerability to an actual loss.

The method is most useful when it ends with a control decision:

  • Mandatory tendering: Require documented competition above an approved threshold.
  • Independent verification: Confirm payment changes through a separate channel.
  • Role rotation: Reduce the risk that one person controls a supplier relationship indefinitely.
  • Evidence gates: Prevent submission until required receipts or approvals exist.

Keep the workshop agenda, attendees, assumptions, prompt responses, source records and remediation decisions. Record who approved each action and how completion will be evidenced. That file shows that management considered foreseeable routes to failure and gives investigators a clear basis for assessing whether controls operated as designed.

9. Forensic Document and Transaction Analysis

Documents often settle the difference between an allegation and a defensible finding. Forensic document and transaction analysis compares contracts, invoices, emails, bank records, system logs, approval histories and vendor confirmations to establish what happened and when.

A mismatch between invoice dates, delivery records and email timestamps may indicate an administrative error, backdating or deliberate circumvention. The investigator shouldn't decide which explanation applies until the surrounding records support it. Similarly, a valuation challenge may require examination of related-party transactions, unusual pricing and the assumptions that flowed into the financial model.

Preserve the evidential trail

Request complete transaction reports rather than selected spreadsheets. Missing records may reflect poor retention, system migration or deliberate removal, and each possibility needs separate treatment. Obtain access logs, workflow records and configuration histories where the issue involves system permissions or changed approval routes.

Chain of custody matters. Record how each item was obtained, who handled it, where it was stored and whether anyone altered the working copy. Preserve originals and perform analysis on controlled duplicates. If the matter may reach court, use specialists with suitable digital forensics experience for email, server or device examination.

Lighthouse's evidence-gathering service is relevant where a financial investigation needs a structured approach to records before the analysis begins.

Cross-reference every important conclusion. A bank payment should align, where possible, with the accounting entry, approval record, invoice, contract and delivery evidence. One document rarely proves the entire causal chain.

A magnifying glass inspecting details on a formal business invoice next to a smartphone and flash drive.

10. Control Self-Assessment and Workshops

Control Self-Assessment, or CSA, asks the people closest to a process to test whether controls work in practice. A facilitated workshop can expose workarounds that policy documents conceal. It can also identify emerging risks before an independent audit or external investigation reveals them.

A procurement team may describe repeated “emergency” purchasing that bypasses tendering. An expenses team may acknowledge that the system accepts claims without receipts. A treasury team may report delayed reconciliations and unresolved exceptions. Those admissions don't establish negligence, but they show where management should test design, operation and accountability.

Make workshop findings auditable

External facilitation helps reduce groupthink and gives participants a safer route to report concerns. Use consistent risk and control templates so different departments describe issues in comparable terms. Ask whether each control exists, whether staff understand it, whether they perform it and whether anyone checks the result.

Quantify the financial exposure where the evidence permits. A board is more likely to prioritise a control redesign when the report explains the affected transaction population, potential loss mechanism and legal or operational consequence. However, don't manufacture precision. State assumptions and ranges qualitatively where the records don't support a reliable amount.

Every finding needs an owner, action, deadline and verification method. Unaddressed CSA findings can later become important evidence about governance, particularly if management knew about a weakness and didn't respond. CSA therefore works best as a continuing feedback loop, not a workshop that ends when the meeting does.

Top 10 Root Cause Analysis Methods Comparison

Method Implementation Complexity 🔄 Resource Requirements ⚡ Expected Outcomes ⭐ / 📊 Ideal Use Cases 📊 Key Advantages 💡
The Five Whys Technique Low, simple iterative questioning; risk of oversimplification 🔄 Very low, few people, no special tools ⚡ Rapid qualitative root-cause hypotheses; needs verification ⭐ 📊 Quick triage, small-scale fraud or loss investigations 📊 Low-cost, engages teams, creates a clear narrative for review 💡
Fishbone (Ishikawa) & Process Mapping Medium, facilitated workshops; can grow complex 🔄 Medium, cross-functional time, mapping tools, observation ⚡ Visual multi-factor cause maps and process gap identification ⭐ 📊 Complex incidents with many contributors; process redesign 📊 Holistic visualization that aligns teams and is court‑ready 💡
Fault Tree Analysis (FTA) High, logical decomposition and gate modelling 🔄 High, forensic expertise, data, modelling software ⚡ Quantifiable causal chains and probability assessment; defensible conclusions ⭐ 📊 Litigation, insurance quantification, critical-system failures 📊 Rigorous, mathematical, shows which fixes yield most risk reduction 💡
Pareto Analysis (80/20 Rule) Low, ranking and charting of quantified causes 🔄 Low, reliable financial data and basic analytics ⚡ Prioritised list showing major contributors by impact/frequency ⭐ 📊 Prioritisation when resources constrained; remediation planning 📊 Focuses effort on highest-value issues; board-friendly justification 💡
Failure Mode and Effects Analysis (FMEA) Medium–High, structured scoring (severity/occurrence/detection) 🔄 Medium–High, cross-functional workshops, scoring consensus ⚡ Ranked failure modes (RPN) to prioritise preventive fixes ⭐ 📊 Preventive governance, control redesign for high‑risk processes 📊 Prevents loss proactively and demonstrates rigorous governance 💡
Root Cause Analysis Using Data Analytics High, data preparation, statistical and forensic methods 🔄 High, full datasets, forensic analysts, specialised tools ⚡ Objective, transaction‑level findings and precise quantification ⭐ 📊 Large-volume/long-duration fraud, precise loss quantification 📊 Data-driven, unbiased evidence that withstands litigation scrutiny 💡
Causal Factor Charting (CFC) Medium, chronological causal linking; careful interpretation 🔄 Medium, documentary evidence, timelines, facilitator ⚡ Coherent event sequence and causal links for liability assessment ⭐ 📊 Litigation, disputes where event order and causality matter 📊 Clear timeline narrative that links actions, systems and liability 💡
SCAMPER Analysis Low–Medium, creative checklist approach; needs focus 🔄 Low, workshops, diverse participants, facilitator ⚡ Identifies inventive exploitation paths and control ideas (qualitative) ⭐ 📊 Proactive vulnerability assessment and control ideation sessions 📊 Finds non‑obvious exploit routes and generates rapid preventive ideas 💡
Forensic Document & Transaction Analysis High, specialist techniques, meticulous validation 🔄 Very high, forensic experts, digital tools, chain‑of‑custody ⚡ Objective, evidentiary conclusions; detects forgeries and precise losses ⭐ 📊 Suspected forgeries, complex fraud, evidence for court or arbitration 📊 Strong evidentiary weight; uncovers manipulations and quantifies loss precisely 💡
Control Self‑Assessment (CSA) & Workshops Low–Medium, facilitated self-testing; bias risk if uncontrolled 🔄 Medium, operational time, templates, facilitation ⚡ Early detection of control gaps and increased ownership; needs validation ⭐ 📊 SMEs, continuous monitoring, building control culture 📊 Cost‑effective, builds buy‑in, and documents active governance efforts 💡

Turn Findings Into Defensible Action

No single method answers every investigation. Interview-led Five Whys can scope a focused control failure quickly, while Fishbone diagrams and process maps help teams investigate several interacting causes. Fault trees suit complex causal relationships, especially where the question involves combinations of failed or absent controls. Data analytics and forensic document examination test whether the proposed explanation matches the records.

Prevention requires a different emphasis. FMEA ranks potential failures before they mature into losses. SCAMPER challenges the process from the perspective of someone seeking to bypass it. CSA brings operational knowledge into governance and creates a route for staff to report control weaknesses. Pareto Analysis helps management decide which causes deserve attention first, but it doesn't replace causal testing.

UK practice increasingly treats RCA as a governance and learning tool rather than a blame-avoidance exercise. The Civil Aviation Authority's root cause analysis process for airworthiness and compliance reflects the importance of sector-specific, defensible investigation. HSE guidance also directs investigators to gather information, analyse causes, select controls and follow through on implementation, while considering human and organisational factors. HSE investigation guidance is particularly relevant where the matter may involve enforcement, insurance or litigation.

A report should make its reasoning easy to audit. Include:

  • Scope: Define the question, period, entities, records and exclusions.
  • Source records: Identify what you received, what remains outstanding and how reliability affects the conclusion.
  • Assumptions: Explain calculation inputs, financial conventions and alternative treatments.
  • Limitations: State missing data, contradictory evidence and issues that require further work.
  • Calculations: Show the method, source figures, adjustments and reconciliation to the underlying records.
  • Chain of custody: Record how electronic and physical evidence was collected, stored and analysed.
  • Competing explanations: Address plausible alternatives instead of presenting only the preferred theory.
  • Control ownership: Name the person or function responsible for each remediation.
  • Deadlines: Set a target date and a method for checking that the action works.

The report should separate fact from inference. It should say what the bank statement proves, what the email suggests and what remains uncertain. It should explain whether the loss resulted from one event, a combination of failures or a wider pattern. It should also distinguish financial impact from legal conclusions, because the court, insurer or decision-maker may apply a different test.

The scale of UK fraud makes this discipline practical, not theoretical. The Crime Survey for England and Wales estimated 4.5 million fraud incidents and 3.8 million victims in the year ending March 2026, with a prevalence rate of 7.8% of people aged 16 and over. The release also explains that, from 4 December 2025, fraud reporting combined public reports with reports from Cifas and UK Finance, so the reporting mechanics matter when interpreting the headline figure. The Office for National Statistics fraud release provides that UK context.

For businesses facing suspected fraud, insolvency or disputed losses, early preservation matters. Cifas recorded more than 444,000 cases on the National Fraud Database in 2025, while members reported preventing £2.4 billion in fraud losses. It recorded more than 220,000 cases in the first six months of 2026, with identity fraud representing 59% of those cases. Cifas fraud data shows why organisations need to explain the mechanism behind a suspected loss, not merely describe the incident.

Financial pressure can also create the setting for disputes over management conduct, creditor treatment and unexplained withdrawals. In England and Wales, registered company insolvencies reached 1,868 in May 2026, including 285 compulsory liquidations, 1,423 creditors' voluntary liquidations, 135 administrations and 25 company voluntary arrangements. Over the 12 months to 31 May 2026, one in 196 companies on the Companies House effective register entered insolvency, a rate of 50.9 per 10,000 companies. The UK company insolvency statistics provide a precise benchmark for the frequency of live insolvency issues.

Insurance investigations need the same causal discipline. The FCA's business interruption insurance test case established that cover may apply to partial closure as well as full closure, and that mandatory closure orders need not be legally binding to trigger cover. It also held that valid claims shouldn't be reduced merely because the loss would have happened anyway because of the pandemic, and confirmed cover under two additional QBE policy types. The FCA's business interruption insurance materials show why a claim analysis must test policy wording, causation and quantification together.

A free discovery can provide the appropriate next step. Lighthouse Consultants can scope the suspected fraud, dispute, claim or interruption, identify the key records, agree an action plan and provide independent financial analysis. Where appropriate, its directors can support negotiations, disciplinary hearings or court proceedings as expert witnesses. The engagement should remain proportionate, with uncertainty explained rather than hidden and the working file preserved for scrutiny.


Lighthouse Consultants provides forensic accounting, audit and financial analysis for UK businesses, law firms, insurers, boards and individuals dealing with fraud, disputes, claims and unexplained losses. Visit Lighthouse Consultants to request a free discovery and discuss a scoped root cause analysis action plan.

Share this article:

Facebook
Twitter
LinkedIn
Email

Other Articles