Behavioural Root Cause Analysis (bRCA): A Practitioner's Guide to Moving From Surface Symptoms to Durable Systemic Resilience
- Aug 7
- 16 min read
By Allan Ung | Founder & Principal Consultant, Operational Excellence Consulting (OEC)
Published: 07 August 2026

Allan Ung is the Founder and Principal Consultant of Operational Excellence Consulting (OEC), a Singapore-based management training and consulting firm established in 2009. With over 30 years of experience spanning senior roles at IBM, Microsoft, and Underwriters Laboratories (UL), Allan developed OEC's proprietary 4-Lens Critical Thinking Model and has facilitated root cause, risk, and Just Culture programmes for organisations including PSA, Cisco, ST Electronics, Borouge, Infineon Technologies, the Health Sciences Authority, and the Ministry of Social and Family Development.
He holds a Bachelor of Engineering (Mechanical) from the National University of Singapore and completed advanced consultancy training in Japan as a Colombo Plan Scholar. Allan is a Certified Management Consultant (Japan), a Certified Lean Six Sigma Black Belt, and an accredited TPM Instructor.
If your root cause analysis keeps landing on "human error," you have not found the root cause — you have found where the investigation stopped. This guide walks through bRCA, OEC's behavioural diagnostic pipeline, and the four tools that trace an incident past the individual to the structures and mental models that made the risky choice rational.
A field team repositions an oversized equipment module at a vendor's request. It looks like a two-minute move, so nobody pauses for the paperwork. The module collides with an automated transport system. Two floors up, in an entirely different industry, a portfolio manager under pressure to lock in a currency hedge before the market moves bypasses a mandatory pre-trade risk check because the approval queue will not clear in time. Neither professional set out to cause an incident. Both made a call that, in the moment, made complete sense to them.
This is the pattern that traditional root cause analysis (RCA) consistently misses. RCA is meant to be a structured approach to identifying the underlying, fundamental reasons for an operational risk event — going beyond surface-level symptoms to implement remediation that actually holds. In practice, most investigations sort findings into people, process, and systems, write up what broke, and stop. That captures the mechanics of the failure. It rarely captures why the breakdown made sense to the person living through it, which is the only version of the finding that leads to a fix someone can actually build.
Behavioural Root Cause Analysis (bRCA) is the diagnostic pillar I built to close that gap. It sits inside OEC's 4-Lens Critical Thinking Model — specifically, it is where the Systems Thinking lens gets applied to the messiest, most human category of operational failure: the moment a capable, well-intentioned professional makes a choice that a policy document says they should not have made. Where the broader 4-Lens Model teaches you which lens to reach for, bRCA is the deep-dive toolkit for the Systems Thinking lens applied to incident investigation, blame culture, and durable behavioural fixes.
This guide covers the full bRCA pipeline as I run it in a one-day masterclass: the Just Culture mindset that makes honest diagnosis possible, three diagnostic tools that trace an event down to its systemic root, and the intervention model and pilot structure that turn a diagnosis into a fix that survives contact with the organisation.
🛠️ Bring the Full bRCA Masterclass Into Your Organisation The complete 78-slide facilitator-grade toolkit behind this guide — the Human-Factored Fishbone, Behavioural 5 Whys, Systems Thinking Iceberg, and McKinsey Influence Model, plus printable worksheets and a 30/60/90-day pilot canvas, ready to run as a one-day workshop. 👉 Get the Behavioural Root Cause Analysis (bRCA) Training Presentation Here |
Why Traditional Root Cause Analysis Stops Short
The deepest-level cause of a problem is its root cause — what I sometimes call the "evil at the bottom," the point that set the entire cause-and-effect chain in motion. Most risk and quality functions know this in theory. In practice, the categorisation habit of sorting a finding into people, process, or systems buckets is itself the limiting factor. It tells you what broke. It does not tell you why the breakdown made sense to the people involved at the time — and that omission is where the same finding comes back around, cycle after cycle.
The business case for going deeper is not a compliance argument. Across manufacturing floors and trading desks alike, complex decisions get made under cognitive load, information asymmetry, and structural incentive pressure — and left undiagnosed at the root, those decisions quietly erode the safety, quality, and performance an organisation exists to protect. The driver for bRCA is positive operational impact, fewer recurring incidents, not a box to tick for an auditor. Remediation has to address the underlying conditions and behaviours driving an incident, not only its symptoms.
None of that diagnostic depth is available to an investigator operating from a blame reflex. This is why every tool in the bRCA pipeline sits on top of a single mindset shift: from "who is to blame?" to "what conditions shaped this decision?" — what Sidney Dekker's work on Just Culture calls treating the professional involved as a capable adult operating inside a system, not a suspect to be caught out. Get this mindset wrong at the interview stage and every tool downstream produces defensive, unusable answers. Get it right, and the same three questions that used to trigger a disciplinary conversation start producing a genuinely diagnostic one.
The Two-Phase bRCA Pipeline
bRCA runs in two phases. Phase 1, Behavioural Diagnosis, uses three tools in sequence — the Human-Factored Fishbone, the Behavioural 5 Whys, and the Systems Thinking Iceberg — to take a single incident from its visible surface down to a named Structure and Mental Model. Phase 2, Systemic Intervention, takes that diagnosis and, using the McKinsey Influence Model and a 30/60/90-day pilot plan, turns it into a fix reinforced across systems, capability, and leadership behaviour, rather than a training slide nobody remembers by the following quarter.
I keep two vignettes running through both phases throughout this guide — one from manufacturing/field operations, one from financial services — because the value of bRCA is precisely that the same four tools produce the same category of finding regardless of industry. Every example below is illustrative, built to demonstrate how the tools work, not a report on any specific organisation's incident.
Phase 1, Lens One: The Human-Factored Fishbone
The classic cause-and-effect Fishbone sorts failure factors into Manufacturing's 4M categories — Man, Machine, Material, Method. That framework was built for mechanical defects, and it shows: it has no natural branch for "the team was juggling three competing priorities" or "the escalation norm quietly discourages raising your hand." The Human-Factored Fishbone re-skins the same structure around four behavioural branches instead: Cognitive Load, Environment & Systems, Culture & Incentives, and Communication & Handovers.


Run the manufacturing vignette through all four branches and a pattern appears quickly. Cognitive Load: the team is juggling a vendor's on-the-spot request against a live schedule. Environment & Systems: there is no quick, on-site checkpoint for what looks like a "minor" repositioning move. Culture & Incentives: a schedule-adherence KPI treats any pause as a delay, and an unwritten no-escalation norm means vendor requests get resolved on the spot rather than kicked upstairs. Communication & Handovers: EHS and Field Operations sit in separate reporting lines with no shared, real-time hazard checkpoint between them.
Run the financial services vignette and the branches land in a different vocabulary but the same shape. Cognitive Load: an urgent currency hedge under real time pressure. Environment & Systems: a mandated fifteen-minute risk-approval window that cannot clear before the market moves. Culture & Incentives: desk performance judged on slippage, with bonus pools tied to volume and velocity. Communication & Handovers: Risk and Front-Office sit in separate reporting lines with no shared metric to reconcile speed against control.
What the Fishbone reveals, across both industries, is that nothing points to a single careless individual. In each case the Culture & Incentives branch is the thickest one — the branch carrying metrics and unwritten norms that reward moving fast over pausing to check. And in both cases the Communication branch surfaces a structural silo: EHS and Operations in one industry, Risk and Front-Office in the other, with no shared checkpoint reconciling the two. The Fishbone has now mapped the full behavioural ecosystem around the incident. It has not yet traced any single branch down to its root — that is exactly what the next tool does.
A word of caution I give every cohort: the Fishbone is a mapping exercise, not a courtroom. If a branch starts filling up with named individuals rather than named conditions, the exercise has drifted back into blame, and the honest information will stop flowing.
Phase 1, Lens Two: The Behavioural 5 Whys
The Behavioural 5 Whys is an iterative, human-centric questioning technique that asks "why" until the chain reaches a fixable, systemic cause — typically five iterations, though this is a guide and not a hard rule. The shift it makes is from a mechanical "what" to a cognitive "why": not what setting was wrong, but why that risky choice made sense to the professional at that exact moment.
Run the financial services vignette. Why did the portfolio manager bypass the risk check? The fifteen-minute approval window could not clear before the market moved. Why couldn't it clear in time? The approval queue was not prioritised for urgent hedges. Why wasn't it prioritised? No fast-track exists for time-sensitive, low-ambiguity trades. Why is there no fast-track? Slippage and volume/velocity KPIs reward speed, and Risk and Front-Office share no common metric — that is the Structure. Why do these KPIs coexist with the risk check at all? Because the desk operates on an unspoken belief: speed is the desk's job, safety is Risk's job — that is the Mental Model.
Two consistent landing points recur across both vignettes, and in my experience, across most workplace incidents once you push past the first technical-sounding answer. Why 4 lands on a Structure — a system-level design, a KPI, a policy, an incentive, that makes the risky choice the rational one. In manufacturing, that is the schedule-adherence KPI that treats a safety pause as a delay; in financial services, the slippage and volume/velocity metrics that reward speed over verification. Why 5 lands on a Mental Model — an unspoken belief that keeps the Structure in place, usually a silo mentality about whose job safety actually is. "Safety review is EHS's job, not Ops's." "Speed is the desk's job, safety is Risk's job." Different industries, nearly identical sentence.
Four failure modes account for most bad 5 Whys sessions I have facilitated or reviewed. Stopping at the first technical-sounding answer — treating "the setting was wrong" as the end of the chain instead of asking why the setting was wrong. Leading the witness toward a pre-decided conclusion, asking questions that already assume the answer instead of following where the evidence leads. Treating Why 5 as a finish line rather than a doorway — the Mental Model you surface at Why 5 is the entry point into Systems Thinking, not the end of the exercise. And the most common of all: the blame reflex reappearing as "who" instead of "why," which is the fastest way to shut down an honest answer.
How the facilitator asks the question determines whether it surfaces honest information or a defensive one. "Why did you skip the check?" invites a justification. "Walk me through what made pausing feel like the wrong call in that moment" invites a description. The words matter more than most investigators assume.
Phase 1, Lens Three: The Systems Thinking Iceberg
Every Why 4 and Why 5 answer is, in effect, an entry ticket into Systems Thinking. The Iceberg model — drawing on the systems tradition Peter Senge set out in The Fifth Discipline — is where that entry ticket gets used. It maps four levels. Events: the single, visible incident, what actually happened. Patterns & Trends: has this happened before, is it clustering around certain conditions? Structures: the policies, KPIs, and incentives, the system-level design driving the pattern. Mental Models: the unspoken beliefs that keep the Structures in place — the deepest, most durable level of the four.

Placed on the Iceberg, the manufacturing vignette reads as follows. Event: a field team repositions equipment without a Job Hazard Analysis; the module collides with the automated transport system. Pattern: rushed repositioning moves cluster around vendor deadlines and dock-schedule crunches — this is not a one-off lapse. Structure: schedule-adherence KPIs treat any pause as a delay, and EHS and Field Operations report through separate lines with no shared hazard checkpoint. Mental Model: the unspoken belief that safety review is EHS's job and keeping the line moving is Ops's job — the silo mentality itself.
The financial services vignette maps onto the identical architecture. Event: a portfolio manager bypasses the pre-trade risk check to execute an urgent hedge. Pattern: bypasses cluster around volatile market windows and urgent hedges. Structure: slippage and volume/velocity KPIs reward speed, with Risk and Front-Office sharing no common metric. Mental Model: speed is the desk's job, safety is Risk's job.
Different industries, same architecture: a misaligned Structure sitting on top of a shared "not my job" Mental Model. This is the finding that traditional RCA cannot produce, because a fix pitched at the Events level — disciplining the individual involved, retraining them on the existing procedure — leaves the Structure and the Mental Model completely untouched, which will simply produce the next incident. Phase 1 is now complete. Phase 2 exists to design the fix that Phase 1's finding actually demands.
Where Diagnosis Goes Wrong
Before moving to the fix, it is worth naming where I most often see teams fail during diagnosis, because the same four mistakes recur across the Fishbone and the 5 Whys regardless of industry. Stopping at the first technical-sounding answer closes the investigation exactly where it should be opening. Leading the witness produces a finding that confirms what the investigator already believed, rather than what the evidence shows. Treating the Mental Model at Why 5 as an endpoint, rather than handing it straight into the Iceberg, wastes the most valuable finding the whole session produced. And reverting to "who" instead of "why" — even once, even briefly — resets the room back to the blame reflex that a Just Culture mindset was supposed to have already dismantled.
I tell every cohort that the discipline of behavioural diagnosis is less about mastering four tools and more about staying inside a single question for long enough: not what broke, but why the break made sense.
Phase 2: Designing a Fix With the McKinsey Influence Model
A diagnosis without a durable fix just produces a well-documented recurrence. Phase 2 is where the McKinsey Influence Model earns its place in the pipeline: sustainable change needs all four of its blocks working together, because a fix that lives in only one of them rarely survives contact with the organisation.

Understanding & Conviction aligns leadership vision with frontline belief, framed in terms the audience already tracks — safety, quality, performance — rather than compliance for its own sake. Field teams already care about getting home safe; frame the fix around fewer collisions and less rework, not a new administrative step. Portfolio managers already care about performance; frame the fix around protecting client returns, not adding friction to the desk.
Formal Mechanisms aligns incentives and structures so the desired behaviour becomes the path of least resistance — this is the block that directly repairs the Structure named at Why 4. A shared EHS/Field Operations metric that scores both schedule adherence and hazard-check completion means pausing no longer looks like a pure loss. A shared Risk/Front-Office metric that scores both execution speed and control adherence means the risk check no longer looks like a pure cost.
Skills builds the capability to run the bRCA pipeline independently on future events — training the room to run Fishbone, then 5 Whys, then Iceberg, on their own. Field leads practise a blame-free Fishbone and 5-Whys pass on a near-miss within thirty days of the workshop, with facilitator coaching. Desk supervisors run the same pipeline on a near-miss trade flag, building internal facilitation confidence for blame-free interviews.
Role Modelling is leaders visibly demonstrating the desired behaviour — the block that directly repairs the Mental Model named at Why 5. Team leads invoke Stop-Work themselves under time pressure, and leadership publicly recognises a paused move as a good outcome rather than a missed deadline. Desk heads use the escalation path themselves, including under time pressure, and leadership publicly recognises a paused trade as protecting the desk rather than costing it an opportunity.
Skip any one of these four and the pattern is predictable. Mechanism without conviction produces a policy nobody believes in, quietly worked around within a quarter. Conviction without mechanism produces good intentions with no formal support, fading under the next deadline. Understanding and mechanism without skills leaves a team that agrees with the fix and has the right incentive but cannot yet run the diagnostic itself. And all three without role modelling leaves frontline staff waiting to see whether leaders actually behave differently first — which, fairly often, they do not.
Turning Diagnosis Into a Workplace Pilot
The masterclass closes by structuring a 30/60/90-day pilot, because a diagnosis and a designed fix are still only theory until they meet a real, recurring issue in the reader's own workplace.

Day 30 is Select & Diagnose: choose a recurring issue, then complete a full diagnostic pass using the Fishbone, the 5 Whys, and the Iceberg. Day 60 is Design & Begin: develop the intervention using the Influence Model, and initiate the pilot. Day 90 is Assess & Decide: evaluate impact and determine, honestly, whether the diagnostic surfaced insights that traditional methods would have missed — before deciding whether to scale the approach more broadly.
The closing exercise I run in every cohort is deliberately individual rather than collective. Each participant states, in the room, one thing they will personally do and by when, to support the pilot. A shared list that nobody owns dissolves within a week. A named commitment, stated out loud, tends to survive contact with a Monday morning inbox rather better.
Why Risk, Audit, and HR Belong in the Room
bRCA is not a tool I hand to a single function and walk away from. Sessions 1 through 4 diagnose a Structure or a Mental Model — territory where Quality, Risk, and Compliance functions have a direct stake, not just an observer's seat. The Behavioural 5 Whys and the Systems Thinking Iceberg give reviewers a structured, defensible way to test whether a control that operated exactly as designed was nonetheless working against a Structure that made bypassing it rational. Recurring audit or quality findings are very often a symptom of precisely the Structures and Mental Models this pipeline surfaces, and reviewers who have run the diagnostic themselves leave with a repeatable way to reduce the same finding recurring cycle after cycle. Independent involvement in designing the pilot and its impact-assessment criteria also gives the eventual findings independent standing when they are brought back to leadership.
Session 5 designs the fix using the Influence Model's Formal Mechanisms and Role Modelling blocks — territory HR is very often best placed to help design and reinforce. A blame-free interview protocol is, at its core, an HR-relevant design question: psychological safety, fair process, and how performance conversations get framed. Where a root cause points to conflicting KPIs, incentive design, or performance-review structures, HR very often owns the mechanism that needs to change, which is why involving HR at diagnosis rather than only at implementation is what determines whether a fix gets adopted or shelved. Working through a live scenario together, rather than receiving recommendations after the fact, gives Operations, Risk or Quality, and HR a shared vocabulary — in my experience, the single biggest determinant of whether a fix survives contact with the organisation at all.
The Discipline of Asking "Why It Made Sense"
Every tool in this pipeline exists to answer one question honestly: not who is to blame, but what conditions made the risky choice the rational one. That question is uncomfortable the first time a team asks it out loud, because it requires treating the professional at the centre of an incident as a capable adult operating inside a system rather than a suspect awaiting a verdict. It gets easier the second time, and by the third bRCA pass most teams stop needing to be reminded to ask it.
The organisations that get real value out of this pipeline are not the ones that run it once, after a serious incident, and shelve the deck. They are the ones that build the skill into their frontline leads and their reviewers, so that the next near-miss gets the same treatment the last serious incident finally received. That is the shift bRCA is built to protect: from surface-level blame to strategic, systemic resilience.
Build bRCA Capability in Your Organisation
If your risk, audit, quality, or HR function is still investigating incidents on a people/process/systems template, the gap this guide describes is already showing up in your recurring findings. OEC's related capability-building resources:
Behavioural Root Cause Analysis (bRCA) Training Course — the facilitated, in-person delivery of the full masterclass this guide is drawn from.
Critical Thinking for Problem Solving Training Course — the foundational 4-Lens Model programme, of which bRCA is a core pillar.
Root Cause Analysis (RCA) Training Course — for teams that need to build the traditional RCA foundation before layering behavioural diagnosis on top.
Systems Thinking Training Course — deepens the Iceberg work into a fuller systems-mapping capability.
About the Author

Allan Ung is the Founder and Principal Consultant of Operational Excellence Consulting (OEC), a Singapore-based management training and consulting firm he established in 2009. Before founding OEC, Allan spent years with Singapore's National Productivity Board, where his work on Cost of Quality and Total Quality Process initiatives helped client organisations cut quality-related costs by as much as 50%. He went on to hold senior roles at IBM, Microsoft, and Underwriters Laboratories (UL), where he led Lean Sigma deployment and saw first-hand how even the most robust controls fail when they work against misaligned structural incentives — the observation that eventually became bRCA.
Allan holds a Bachelor of Engineering (Mechanical) from the National University of Singapore and completed advanced consultancy training in Japan as a Colombo Plan Scholar. He is a Certified Management Consultant (CMC, Japan), a Certified Lean Six Sigma Black Belt, a JIPM-accredited TPM Instructor, a TWI Master Trainer, an ISO 9001 Lead Auditor, and a Singapore Quality Award National Examiner. He developed OEC's proprietary 4-Lens Critical Thinking Model, of which bRCA forms the behavioural diagnostic pillar, and has facilitated root cause, risk, and Just Culture programmes for organisations including PSA, Cisco, ST Electronics, Borouge, Infineon Technologies, the Health Sciences Authority, and the Ministry of Social and Family Development.
Allan's operating philosophy is a practical one: the tools are never the hard part; the mindset of the people using them is. He built bRCA as a "below the waterline" lens for professionals who already know their controls are not the problem — the Structures and Mental Models sitting beneath them are.
OEC's training toolkits and practitioner guides have been used by managers and practitioners across Asia, Europe, and North America to build Lean and Systems Thinking capability and drive sustainable organisational improvement.
👉 Learn more at: www.oeconsulting.com.sg
Further Learning Resources
Critical Thinking for Problem Solving: A Practitioner's Guide to the 4-Lens Model — the hub article this guide sits under; explains how Analytical, Lean, Design, and Systems Thinking combine, and where bRCA fits as the Systems Thinking lens applied to incident diagnosis.
Behavioural Root Cause Analysis (bRCA) Training Presentation — the full 78-slide facilitator toolkit this guide is distilled from, including printable Fishbone, 5 Whys, Iceberg, and Influence Model canvases.
Sidney Dekker, Just Culture — the foundational text behind the "capable professional operating in a system, not a suspect" mindset that underpins every tool in this pipeline.
Peter Senge, The Fifth Discipline — the systems-thinking tradition the Iceberg model draws on, for readers who want to take the below-the-waterline lens further than a single incident.
