Post-Incident Residual-Loss Assessment¶
Assessment protocol — instantiates Residual Harm Accounting and Allocation
A post-event protocol that separates the loss the defenses prevented from the loss that got through, and attributes the residual — with its uncertainty — to the layers and causes involved.
A Post-Incident Residual-Loss Assessment is a one-time forensic protocol run after a specific hazard, breach, failure, or disaster. Its defining task is to draw a line: given what the defenses actually stopped, what loss got through and must now be treated as residual — and why? It reconstructs the layers the harm passed, separates prevented loss from residual loss so that neither preventable damage is excused as inevitable nor real residual harm is buried in vague risk language, and it attributes the residual to causes with an honest note on what is certain, probable, or unknowable. It is not a running ledger and not a learning review; it is the bounded, per-incident act of establishing what is residual here and how it came to be, which everything downstream then acts on.
Example¶
A hospital's medication-safety system — barcode scanning, pharmacist review, automated dose limits, double-checks — nonetheless lets a patient receive a harmful overdose. The Post-Incident Residual-Loss Assessment convenes to answer, precisely, what got through and why. It first maps the defense layers the order passed: the scanner was bypassed during a system outage, the dose-limit alert was one of dozens that shift routinely overrode, the pharmacist review was in place but keyed on the wrong weight. Against that map it draws the residual boundary — the harm that a reasonably functioning barrier set should have caught (preventable, and owed a redesign) versus the harm that survived defenses working as designed (residual, and owed a response).
Then it attributes cause with explicit hedging: the weight error is established, the outage's contribution is probable, and whether an un-fatigued pharmacist would have caught it is genuinely uncertain. The assessment's product is not a compensation decision and not a punishment — it is a bounded finding that this much of the harm is residual, attributable this way, with these uncertainties, guarded against the pull of hindsight bias that makes every barrier look obviously flawed once the outcome is known.[n1] That finding is what lets the register, the fund, and the feedback review each do their job on a shared basis.
How it works¶
- Reconstruct the layer path. Map every defense the harm crossed and how each behaved — absent, overwhelmed, bypassed, or working-as-designed.
- Draw the residual boundary. Separate loss a functioning barrier set should have caught (preventable) from loss that survived defenses working correctly (residual), resisting the urge to file everything as one or the other.
- Attribute with hedges. Assign the residual to causes and mark each link as established, probable, or unknowable, so action does not wait on impossible certainty.
- Bound and hand off. Deliver a per-incident finding — not a verdict on payment or blame — that the register, remedy, and feedback mechanisms consume.
Tuning parameters¶
- Boundary standard — how strict the "reasonably functioning defenses" bar is. A strict bar labels more harm preventable (and owed redesign); a loose one labels more residual (and owed only response).
- Attribution depth — how far back the causal chain is traced. Deeper is more complete but slower and more contestable.
- Uncertainty candor — how explicitly unknowns are recorded versus smoothed into a clean story.
- Timing — how soon after the incident it runs, trading evidence freshness against the settling of delayed harm.
- Independence — how separated the assessors are from those whose defenses are under review.
When it helps, and when it misleads¶
Its strength is that it produces the shared, defensible boundary the whole loop needs: without it, actors argue endlessly over whether a harm was preventable or residual, and the accounting cannot start. By hedging attribution, it also lets response begin on partial causality rather than stalling for perfect proof.
Its failure mode is hindsight bias cutting both ways: after a bad outcome, every barrier looks negligent (over-labeling harm preventable, to scapegoat) or, if the assessors are the defenders, every gap looks unforeseeable (over-labeling harm residual, to launder preventable failure into accepted background). The classic misuse is exactly that second move — relabeling avoidable harm as "residual" to dodge redesign. The guarding discipline is an independent assessor, an explicit written boundary standard set before the outcome is known, and uncertainty recorded rather than resolved by narrative convenience.
How it implements the components¶
defense_layer_context_map— it reconstructs the specific layers the harm crossed and how each behaved, as the basis for judging residual status.residual_harm_boundary— its central act: separating, for this incident, preventable loss from loss that survived working defenses.causal_attribution_and_uncertainty_note— it attributes the residual to causes and marks each link's certainty, enabling action under partial knowledge.
It does not implement loss_channel_ledger, affected_bearer_map, or evidence_preservation_protocol — holding losses as a standing, bearer-bound, evidence-preserving book is Loss and Damage Register, its nearest twin: this protocol runs once per incident to draw the boundary and attribute cause, the register is the continuous catalog it writes into. Nor feedback_to_defense_layers, converting the finding into upstream design change, which is After-Action Loss Feedback Review.
Related¶
- Instantiates: Residual Harm Accounting and Allocation — supplies the per-incident boundary and attribution the rest of the loop acts on.
- Consumes: Loss and Damage Register — the preserved evidence and channel records the assessment reasons over.
- Sibling mechanisms: Loss and Damage Register · After-Action Loss Feedback Review · Residual Harm Eligibility Rule · Adaptation Gap Report · Claims and Compensation Fund · Harm-Bearer Agreement · Managed Retreat or Relocation Package · Residual-Risk Acceptance Signoff · Restorative Remedy Plan
Editorial Notes¶
Form Classification¶
Form family: Assessment, Review & Assurance
Rationale: Post-Incident Residual-Loss Assessment operates as a bounded evaluation of existing evidence or work that produces a finding or disposition because it a post-event protocol that separates the loss the defenses prevented from the loss that got through, and attributes the residual — with its uncertainty — to the layers and causes involved.
Independent corroboration: The frozen evidence defines Post-Incident Residual-Loss Assessment as 'A post-event protocol that separates the loss the defenses prevented from the loss that got through, and attributes the residual — with its uncertainty — to the layers and causes involved', so its operative form is Assessment, Review & Assurance.
Review outcome: Independent reviewer agreement; high confidence.
Origin Attribution¶
Primary origin: Engineering & Design
Origin pattern: Cross-disciplinary synthesis
Present-day reach: Multi-domain
Rationale: Separating prevented from residual loss and attributing failure across defenses is rooted in risk and reliability engineering.
Related originating lineages:
- Accounting & Auditing — Forensic evidence, causal traceability, and loss classification materially shape the bounded assessment protocol.
- Economics & Finance — Finance contributes loss accounting and risk-layer allocation.
- Statistics & Experimental Design — Statistics contributes uncertainty estimation and causal attribution limits.
Review resolution: Both blind reviewers agree that engineering design is the primary origin. Reconciliation resolves reported ambiguity, alternate origin disagreement. Formative alternate lineages are retained as economics_finance, statistics_experimental_design, accounting_auditing; later breadth of use is recorded separately as domain_reach=multi_domain, while origin_mode=cross_disciplinary_synthesis describes the relationship among origin lineages.
Attribution caveat: The mechanism combines engineering causation with accounting and risk-allocation traditions; the primary is chosen for its defense-layer focus.
Encyclopedia synthesis: The exact catalogued form synthesizes established practice rather than reproducing a single standard historical label.
Review outcome: Reconciled after independent review; medium confidence.
Notes¶
[n1] Hindsight bias is the tendency, once an outcome is known, to see it as having been predictable and its precursors as obvious failures. In post-incident assessment it corrupts the residual boundary in both directions, which is why the boundary standard is written down before the outcome is examined and assessors are kept independent of the defenders. ↩