After-Action Loss Feedback Review¶
Learning review — instantiates Residual Harm Accounting and Allocation
Turns the residual loss from a specific event into design changes upstream, so the same harm is strengthened against rather than merely paid for again.
An After-Action Loss Feedback Review is retrospective and generative. Triggered by a specific event whose residual harm has already been counted, its whole purpose is to route that loss evidence back into the layers of prevention, mitigation, and adaptation that let it through — so the system gets stronger rather than simply better at paying for the same damage twice. Its defining commitment is the direction of travel: it faces backward at a loss that landed and forward into design changes, and it is judged not by how well it describes the event but by what upstream decision it changes. It is the mechanism that keeps residual-harm accounting from degrading into a normalized budget line for recurring damage.
Example¶
A regional airline suffers a runway excursion in which no one is seriously hurt but an aircraft is damaged and passengers are traumatized. Containment, medical response, and compensation are handled elsewhere. The After-Action Loss Feedback Review convenes weeks later, once the residual harms are known, and asks a narrower question than the crash investigation did: given that this loss got through, what in our defenses should change? It reconstructs the causal chain and marks honestly what is established versus contested — a contaminated-runway braking assumption that held only in dry conditions, a checklist step that crews routinely compressed under schedule pressure, a warning that fired too late to act on.
Crucially it also asks over what horizon the loss really runs: the airframe damage is immediate, but the crew's confidence erosion and the passengers' reluctance to rebook are slower harms that a same-week debrief would have missed. The review's output is not a compensation figure and not a blame finding — it is a short list of design changes routed to the people who own the braking model, the checklist, and the warning threshold, each with an owner and a recheck date. The residual loss becomes a lesson wired into the next departure, not a line item awaiting its next recurrence.
How it works¶
- Wait for the residual to settle. Convene once the loss is characterized, not during containment, so the review reasons from actual harm rather than early guesses.
- Reconstruct causation, honestly hedged. Trace how the harm passed each layer and label each link as established, probabilistic, or contested rather than forcing a clean single cause.
- Extend the loss horizon. Deliberately look past the immediate damage to delayed, cumulative, and trust harms that a fast debrief truncates.
- Convert to upstream changes. Translate findings into specific edits to prevention, mitigation, adaptation, and warning layers — each with an owner and a recheck date.
- Close the loop. Track whether the routed changes were actually adopted, so feedback is measured by design change, not by report length.
Tuning parameters¶
- Trigger threshold — how large a loss convenes a review. Low catches weak signals but floods the process; high normalizes moderate recurring harm.
- Attribution rigor — how much causal certainty is demanded before a change is proposed. High rigor resists spurious fixes but delays learning past the window where anyone acts.
- Horizon depth — how far into delayed and cumulative loss the review reaches before closing.
- Blame separation — how firmly the review is walled off from accountability and discipline; the more it is, the more candid the causal account.
- Adoption tracking — whether routed changes are followed to adoption or merely recommended.
When it helps, and when it misleads¶
Its strength is that it is the one mechanism in the loop whose product is a stronger upstream system — it is how a residual-harm program earns the right to say it reduces future harm rather than just financing repeat damage. Done in a just-culture frame, where reporting is protected from punishment, it surfaces the honest causal account the fixes depend on.[1]
Its failure mode is hindsight-driven single-loop learning: the review patches the one proximate cause that is obvious after the fact, declares the lesson learned, and never questions the assumptions that generated the gap — so a near-identical loss returns through a slightly different path. It is also easily captured by blame, at which point the causal account goes quiet and the feedback dries up. The guarding discipline is to force at least one finding to the level of a challenged assumption, and to keep the review structurally separate from who-is-at-fault.
How it implements the components¶
feedback_to_defense_layers— its core output: realized-loss evidence converted into specific, owned edits to prevention, mitigation, adaptation, and warning layers.causal_attribution_and_uncertainty_note— it reconstructs how the harm crossed each layer and marks what is established, probabilistic, or contested, so fixes attach to real mechanisms.temporal_loss_horizon— it deliberately extends the accounting window to delayed, cumulative, and trust losses a fast debrief would truncate.
It does not implement defense_layer_context_map or policy_response_portfolio — the forward-looking survey of the current portfolio and its missing responses is Adaptation Gap Report, its prospective twin: the gap report finds holes before an event, this review learns from a loss that already came through. Nor does it implement remediation_or_compensation_path; repairing the specific bearer is done by the remedy mechanisms such as Claims and Compensation Fund.
Related¶
- Instantiates: Residual Harm Accounting and Allocation — supplies the learning loop that keeps the ledger from normalizing recurring harm.
- Consumes: Post-Incident Residual-Loss Assessment — the characterized residual loss the review reasons back from.
- Sibling mechanisms: Adaptation Gap Report · Post-Incident Residual-Loss Assessment · Loss and Damage Register · Claims and Compensation Fund · Harm-Bearer Agreement · Managed Retreat or Relocation Package · Residual Harm Eligibility Rule · Residual-Risk Acceptance Signoff · Restorative Remedy Plan
Editorial Notes¶
Form Classification¶
Form family: Assessment, Review & Assurance
Rationale: The mechanism turns the residual loss from a specific event into design changes upstream, so the same harm is strengthened against rather than merely paid for again, so its operative form is a bounded assessment of existing evidence or work.
Independent corroboration: The frozen evidence defines After-Action Loss Feedback Review as 'Turns the residual loss from a specific event into design changes upstream, so the same harm is strengthened against rather than merely paid for again', so its operative form is Assessment, Review & Assurance.
Review outcome: Independent reviewer agreement; medium confidence.
Origin Attribution¶
Primary origin: Engineering & Design
Origin pattern: Cross-disciplinary synthesis
Present-day reach: Multi-domain
Rationale: Safety and resilience engineering route realized loss and near-miss evidence back into prevention, mitigation, adaptation, and defense-layer redesign under just-culture conditions.
Related originating lineages:
- Accounting & Auditing — Traceable loss accounting and assignment of corrective actions contribute the control-review form.
- Disaster Management & Risk Reduction — Loss and damage assessment identifies who was harmed, over what horizon, and which preparedness or response layers failed.
- Environmental Science & Climate Studies — Residual-risk and adaptation practice distinguish unavoidable loss from preventable recurrence and warn against normalizing harm as a budget item.
- Military & Strategic Studies — After Action Reviews provide the intended-versus-actual reconstruction and disciplined forward lesson.
Review resolution: Safety and resilience engineering supply the upstream redesign loop. Traceable loss accounting, disaster assessment, residual climate risk, and military AAR practice materially form the generalized review; economics is useful context but not a separate formative lineage here.
Attribution caveat: Its corrective direction is safety-engineering, while the loss-accounting context spans disaster and climate practice.
Encyclopedia synthesis: The exact catalogued form synthesizes established practice rather than reproducing a single standard historical label.
Review outcome: Reconciled after independent review; high confidence.
References¶
[1] Reason, J. Managing the Risks of Organizational Accidents. Ashgate (1997). Frames just culture as protecting candid reporting of honest errors so organizations can learn from causal accounts and improve safety. registry ↩