What does a compliant digital incident logging system need in the UAE?
Updated 5 August 2026
Short answer
A compliant digital incident logging system must capture the incident within the notification window, classify it (near miss, first aid, medical treatment, lost time, dangerous occurrence, environmental), and hold the investigation, root cause, corrective actions and verification in the same record. It must also produce the authority notification in the format the relevant UAE regulator expects and retain an unedited audit trail of every change.
Key points
- Classification drives the reporting duty — misclassifying an LTI as a first aid case is the most common reporting failure.
- Serious incidents and fatalities carry short notification windows to the relevant authority and to the client; the system should alert responsible people immediately, not at the end of shift.
- Investigation records need witness statements, scene evidence and a structured root-cause method, not just a narrative.
- Every corrective action needs an owner, due date and verification of effectiveness before closure.
Capture: fast, on-site, offline
The person closest to the event should be able to log it in under two minutes from a phone, offline if signal is poor, with photos attached. Delayed capture is why near misses go unrecorded and why leading indicators look artificially good.
Classification and escalation
The classification decides who is notified and how fast. Build escalation rules so that a high-severity classification pages the HSE manager, project manager and client representative automatically rather than relying on a phone tree.
Investigation and root cause
Hold witness statements, scene photographs, sequence of events and a structured root-cause analysis (5 Whys or a tree method) against the incident. Investigators should be able to see prior similar incidents on the same site or with the same subcontractor.
CAPA and verification
Corrective and preventive actions are the part auditors test hardest. Each action needs an owner, a due date, evidence of completion and a separate verification step confirming the action actually worked before the incident can be closed.
Reporting and trend analysis
Monthly KPI reporting — TRIR, LTIFR, severity rate, man-hours, near-miss ratio — should be generated from the incident records themselves so the numbers reported to the client match the underlying data.
Frequently asked questions
Do near misses have to be logged in the UAE?
Near misses are not usually notifiable to an authority, but clients and ISO 45001 both expect them to be recorded and trended. A healthy near-miss to lost-time ratio is one of the strongest indicators auditors look for.
Who should be able to see incident records?
Restrict personal and medical details to HSE and HR, and give site management access to the incident, its actions and its lessons learned. Role-based access is a requirement under ISO 45001 clause 7.5 documented-information controls and under UAE data expectations.
How do you stop incident data from being edited after the fact?
Use a system that writes an immutable audit trail: who created the record, every subsequent change, and who approved the closure. Editable spreadsheets cannot demonstrate this and are routinely challenged during investigations.
Put this into practice
Site Safety UAE runs these workflows for UAE and GCC contractors. Start free on one site, or ask the founding team for a walkthrough on your own permit types.