A report may be the only account a supervisor, client, investigator, attorney, or regulator sees after an event. Knowing how to write incident reports is not a clerical skill. It is part of your professional responsibility as a security officer, protective-services professional, or investigator.
A strong incident report preserves what happened without adding assumptions, opinions, or details you cannot support. It gives management a usable record, helps protect the client, and demonstrates that you acted within post orders, policy, training, and your lawful authority. A weak report can create confusion, damage credibility, and make an otherwise appropriate response difficult to defend.
The Purpose of an Incident Report
An incident report documents an unusual event, safety concern, policy violation, crime, injury, complaint, or response that occurred during your assignment. It is not a place to prove that you were right, criticize a coworker, diagnose a person, or recreate a dramatic version of events.
Your report should allow a reader who was not present to understand five things: what occurred, when and where it occurred, who was involved, what actions were taken, and what happened after those actions. The reader should not need to guess at the order of events or separate facts from your personal interpretation.
For private-security personnel in Virginia, Washington, DC, and Maryland, this standard matters because reports may be reviewed by a client, site management, law enforcement, insurance representatives, licensing authorities, or legal counsel. Requirements differ by employer, contract, and jurisdiction, so always follow your company report format, post orders, chain-of-command procedures, and evidence-handling policy.
How to Write Incident Reports From Facts, Not Opinions
Start with what you personally observed. Identify the date, time, exact location, assignment, and people involved as accurately as possible. If you did not witness an event, say who provided the information and distinguish it from your own observations.
For example, write: “At approximately 2145 hours, I observed a male later identified by his Virginia driver’s license as John Smith standing near the east entrance.” This tells the reader what you saw, when you saw it, where you saw it, and how identification was made.
Avoid writing: “A suspicious man was lurking by the door.” Suspicious and lurking are conclusions. They do not describe observable behavior. If a person repeatedly checked door handles, attempted to enter a restricted area, or refused to leave after being directed to do so, document those actions. The facts allow the reader to understand why you responded.
Use the same discipline with emotional or medical language. Do not write that someone was intoxicated, mentally unstable, aggressive, or injured unless you have a qualified basis to make that determination. Instead, document behavior: the person had a strong odor of an alcoholic beverage, spoke with slurred speech, clenched fists, shouted threats, had visible bleeding, or stated that they were experiencing chest pain. If EMS, law enforcement, or a supervisor made a determination, identify the source rather than adopting it as your own conclusion.
Build the Report in a Clear Sequence
Most reports are easiest to write in chronological order. Begin with how you became aware of the incident, then document your observations, notifications, actions, and disposition. Use actual times when available. If you are estimating, use language such as approximately and do not present an estimate as an exact fact.
A workable sequence includes:
- the initial observation, call for service, complaint, or notification;
- your arrival or response and the conditions you observed;
- the persons involved, including identifying information when authorized;
- each action you took and each person you notified;
- the final disposition, such as release to management, EMS transport, law-enforcement response, or return to normal operations.
This order prevents a common reporting failure: placing the outcome first and then forcing the facts to fit it. Write what happened as it developed. If law enforcement arrested a subject, document the officers’ names or badge numbers when available, the agency, arrival and departure times, and any property or evidence transferred according to policy. Do not state that a person committed a crime unless that is a verified finding you are authorized to report.
Include the Details That Make a Report Usable
Specificity is not the same as length. A one-page report can be complete if it answers the necessary questions. Include exact addresses, building areas, gate numbers, unit numbers, vehicle descriptions, plate numbers, direction of travel, and camera locations when they are relevant and known.
Names should be spelled correctly whenever possible. Confirm them from an identification card, company roster, dispatch record, or another reliable source. If a person refuses identification or leaves before you can obtain it, document that fact. A physical description should be factual and useful: approximate age, height, build, clothing, hair, distinguishing features, and any items carried. Do not use disrespectful, speculative, or unnecessarily personal descriptions.
Direct statements can matter, especially in threats, complaints, trespass incidents, and use-of-force reviews. Record key statements as accurately as you can, using quotation marks only for words you are confident were said. If you cannot recall the exact language, paraphrase and identify it as a statement or claim. Never create a quotation from memory simply because it sounds more persuasive.
Document notifications with the same care. Record whom you contacted, how you contacted them, the time of contact, and any instructions received. If a supervisor directs you to preserve video, separate parties, complete a specific form, or remain on scene, include that direction and your compliance with it.
Write Professionally Under Pressure
Incident reports are often completed after a stressful event, at the end of a long shift, or while operations are still active. That is exactly when disciplined note-taking matters. Record key times and observations as soon as conditions safely permit. If your employer authorizes body-worn camera, CCTV review, dispatch logs, or electronic reporting tools, use them according to policy. Do not alter, delete, or share records outside authorized procedures.
Use plain language, short sentences, and professional grammar. Write in the first person when describing your own actions: “I notified the shift supervisor,” not “The supervisor was notified.” Active language establishes responsibility and makes the timeline easier to follow.
Check tense and pronouns before submission. A report becomes unclear when it shifts between present and past tense or refers to several people only as he, she, or they. Reuse names, titles, or clear identifiers when needed. If multiple officers responded, state each officer’s role rather than assuming the reader knows who did what.
Do not use sarcasm, slang, profanity, unsupported accusations, or emotional commentary. Avoid phrases such as obviously, clearly, appeared guilty, had an attitude, or was acting crazy. These phrases do not improve the report. They invite questions about bias and professionalism.
Review Before You Submit
Before submitting, read the report as if you were a supervisor who was not on site. Verify the date, report number, location, times, spelling of names, and contact information. Make sure the narrative matches any checkboxes, attachments, photographs, witness statements, property logs, or use-of-force forms.
Ask whether every significant action has an explanation. If you contacted police, explain why. If you used force, restraints, OC spray, a baton, or another defensive tool, the documentation must be especially precise and must follow employer policy, approved training, reporting deadlines, medical-response procedures, and required notifications. Do not try to write around a difficult fact. Accurate reporting is safer than incomplete reporting.
A report should also identify what you did not know. If a camera was not functioning, a witness declined to provide a statement, a subject left before police arrived, or you could not verify an allegation, document it. Limits in the information are themselves relevant facts.
A Practical Report-Writing Standard
The best incident reports are objective, complete, timely, and easy to follow. They do not exaggerate routine events, but they do not minimize serious ones. They show that the officer recognized the issue, followed procedure, communicated through the proper channels, and documented the outcome with care.
Treat every report as a professional record that may be reviewed months later by someone who has never met you or visited the site. Write it with the same control, accuracy, and judgment you are expected to show on post. That habit strengthens your credibility long after the shift ends.
