What Every Public Inquiry Is Really Telling Us About Logging

What Every Public Inquiry Is Really Telling Us About Logging

I’ve been watching the news around the various public inquiries running at the moment, and there’s a pattern that keeps showing up. It’s not really about the disaster, the failure, or the tragedy itself. It’s about what happened afterwards, when someone asks the question that always comes eventually: what did you know, and when did you know it?

Time and again, organisations struggle to answer that clearly. Not because they were negligent, necessarily, but because nobody was keeping a proper record while it was actually happening. Decisions were made in the heat of the moment and never written down. Phone calls happened that nobody minuted. Someone was “aware of the situation” but there’s no note of when, or what they did about it.

The duty of candour and a shift in expectation

There’s a new law that’s just cleared the House of Commons, officially called the Public Office (Accountability) Bill but much better known as the Hillsborough Law, that formalises exactly this. It places a legal duty on public officials to proactively identify, preserve and disclose information when things go wrong, rather than waiting to be asked. It’s now heading to the House of Lords, with hopes it’ll be fully law within the year. Either way, the direction of travel is already obvious. Regulators, inquiry chairs and the public all expect organisations to be able to reconstruct exactly what happened, in order, with evidence. And “we’re pretty sure this is roughly what occurred” doesn’t cut it any more.

Why the log matters more than the plan

This is where logging comes in, and it’s why I think it’s one of the most underrated skills in business continuity and crisis management. Not the plan. Not the flowchart. The log.

A good incident log is simply a written record of what happened, when, and who did it, kept as things unfold rather than reconstructed afterwards from memory. Time of the first call. Who was contacted, and when. What was decided, and on what basis. What was said to staff, customers or the press, and at what point. It sounds almost too simple to matter, but it’s usually the difference between an organisation that can stand behind its decisions and one that’s left guessing at an inquiry, a coroner’s court, or a regulator’s desk months later.

What good logging actually looks like

The good news is that logging isn’t complicated to do well. It just needs a bit of structure and a habit of doing it as you go, rather than trying to piece it together once the adrenaline has worn off. A few things that make the biggest difference:

Write things down in real time, not from memory afterwards. Even a rough note beats a polished account written three days later.

Record decisions, not just events. It’s not enough to note that the building was evacuated. Note who decided that, why, and what information they had at the time.

Keep it factual. A log isn’t the place for opinions or blame, just what happened.

Make sure whoever is logging isn’t also the one running the response. Trying to do both at once means neither gets done properly.

Why loggist is a role of its own

That last point is really the whole reason the role of “loggist” exists as a distinct skill. It’s a specific job within a crisis response team, separate from the people making the decisions, whose entire focus is capturing an accurate, contemporaneous record. It’s a role that gets overlooked constantly, right up until someone needs that record and it isn’t there.

Where to start

If you’re responsible for incident response, business continuity or crisis management in your organisation, and nobody currently has clear ownership of this, it’s worth fixing sooner rather than later. It’s a small gap that becomes a very large problem at exactly the moment you can least afford it.

We built our Loggist Training course for precisely this reason. It’s a short, practical course that walks through what good logging actually looks like in a live incident, and it remains one of the most popular courses on RiskReady, for what I suspect are exactly the reasons above. If logging isn’t something your organisation has properly nailed down yet, it’s a good place to start.

Share The Post

Helen Molyneux Director RiskReady

Helen Molyneux is the founder of Cambridge Risk Solutions, a specialist resilience consultancy with nearly two decades of experience in business continuity, crisis management and information security. She holds Lead Auditor certifications for ISO 22301 and ISO 27001, and has worked across both public and private sectors helping organisations prepare for, respond to, and recover from disruption. RiskReady is her e-learning platform, built to make that same practical expertise accessible to individuals and teams at every level.

Find out more about Cambridge Risk Solutions →

Leave a Comment

Your email address will not be published. Required fields are marked *