Skip to main content
v2026.11,610 entries · CC-BY 4.0

RCA2 Action Hierarchy: Weak, Intermediate, and Strong Actions After a Root Cause Analysis

How the RCA2 action hierarchy sorts corrective actions from weak (training, warnings) to strong (forcing functions, redesign) — and how to use it as a working decision tool, not just a checklist, when a hospital RCA action plan is at risk of defaulting entirely to retraining.

Ask about RCA2 Action Hierarchy: Weak, Intermediate, and Strong Actions After a Root Cause Analysis

Answers are drawn from this guide and the rest of the CASRAI corpus, with a link to every source.

Answers are AI-generated from CASRAI’s own published pages and can be wrong, so check the linked sources before relying on one; your question is logged without personal data — never sold, never used to train a third-party model — to show us what CASRAI is missing, so please do not type personal or confidential details. How we use this

Written and maintained by CASRAI Editorial Board

Last updated

RCA2 is not a different way of finding a root cause — it is a different standard for what counts as an acceptable action once you’ve found one. A hospital root cause analysis (RCA) team can do rigorous causal analysis and still produce an action plan that changes nothing, because the actions it lands on are the ones that are easiest to write down: re-educate the staff involved, issue a reminder memo, add a warning sign. RCA2 — the framework the National Patient Safety Foundation (NPSF) published in 2015, now maintained by the Institute for Healthcare Improvement (IHI) after NPSF’s 2017 merger into IHI — exists specifically to stop that pattern. Its core contribution is the Action Hierarchy Tool, a ranked classification of intervention types by how much they actually depend on a person doing the right thing every single time. This guide is about using that hierarchy as a working decision tool during action planning, not as background theory.

Written for hospital patient-safety officers, quality directors, risk managers, and infection preventionists who sit on or facilitate RCA teams. It assumes you already know how to run the causal-analysis portion of an RCA (five whys, causal statements, contributing-factor identification) and are looking specifically at what to do with the findings once you have them.

What RCA2 Actually Changes About a Root Cause Analysis

The name change from “RCA” to “RCA2” — root cause analysis and action — is the point, not a rebrand. NPSF’s rationale, echoed since in patient-safety literature reviewing why RCAs fail, is that the analysis phase of most hospital RCAs was already reasonably competent; the failure point was almost always the action phase. A 2017 commentary reviewing RCA effectiveness identified overreliance on weak solutions — educational interventions and simply re-enforcing existing policy — as a leading reason RCA-generated action plans don’t prevent recurrence. RCA2 doesn’t add new causal-analysis technique on top of what most quality teams already do; it adds a structured requirement to grade the strength of every proposed action before the plan is finalized, using the Action Hierarchy below.

This matters because an RCA that stops at a well-written causal statement but assigns “retrain staff” as the corrective action has, in practice, not reduced the probability of recurrence at all — it has documented the problem and then relied on the exact human vigilance that already failed once. RCA2’s contribution is making that gap visible and auditable at the point the action plan is signed off, not after the same event recurs eighteen months later.

The Action Hierarchy: Weak, Intermediate, and Strong Actions

IHI’s Action Hierarchy Tool sorts corrective-action types into three tiers, ordered by how much of the safety burden they leave sitting on an individual’s memory, attention, or willpower versus how much they remove the opportunity for the error to happen at all. A useful way to read the hierarchy: weaker actions ask a person to behave differently; stronger actions make the undesired behavior physically harder or impossible, regardless of who is on shift, how tired they are, or how new they are to the unit.

Weaker actions — depend entirely on someone remembering and complying

  • Double checks. Asking a second person to verify — useful as a stopgap, but it adds a second point of human fallibility rather than removing the first one, and independent double-checks are documented to catch a minority of errors in practice.
  • Warnings and labels. A caution sticker or alert box assumes the reader notices it, reads it, and acts on it correctly every time, including the 400th time they’ve seen it.
  • New procedure, memorandum, or policy. Writing a rule down does not make anyone follow it; policy-writing is often mistaken for corrective action because it produces a concrete deliverable.
  • Training and education. The single most common action assigned after a hospital RCA, and one of the two the 2017 effectiveness literature names explicitly as overrelied-upon. Training addresses a knowledge gap; most RCA-triggering events are not caused by a knowledge gap, they’re caused by a system that makes the correct action hard to do consistently even for someone who already knows the right answer.
  • Additional study or analysis. Commissioning a further review is sometimes genuinely necessary, but a plan that ends in “study the issue further” without a strong or intermediate action attached to it is not a completed corrective action.

Intermediate actions — reduce reliance on vigilance without removing it entirely

  • Increased staffing or reduced workload on the unit or process where the event occurred, when workload was a documented contributing factor.
  • Software enhancements or modifications that add a soft alert, default value, or decision-support prompt — stronger than a paper warning because it appears at the point of action, but still overridable.
  • Checklists and cognitive aids built into the workflow at the moment the risky step occurs, not filed in a binder.
  • Elimination or reduction of look-alike/sound-alike conditions — separating similarly named or similarly packaged medications, standardizing label formats.
  • Reduction of distractions and interruptions during a high-risk task (for example, a documented no-interruption zone around medication preparation).
  • Standardized order sets that remove free-text variation from a high-risk order type.
  • Redundancy built into the process itself — distinct from a double check, this is a structural second layer (e.g., an independent system cross-check) rather than a second person relying on the same information.

Stronger actions — remove the opportunity for the error, not just the incentive

  • Forcing functions and engineering controls. A physical or system design that makes the wrong action impossible or very difficult — the reference example in patient safety is non-interoperable enteral and intravenous connectors under ISO 80369-3 (“ENFit”-type designs), which physically cannot be connected to IV tubing, closing off a category of misconnection error that warnings and training had failed to prevent for years. Barcode medication administration that blocks documentation without a scanned match, and IV smart-pump dose-error-reduction software that hard-stops (not just alerts on) an out-of-range programmed dose, are the same category applied to medication safety.
  • Architectural or physical-plant changes — relocating a hazard, redesigning a room layout, changing storage location so an error-prone step is no longer physically possible in the old sequence.
  • New equipment selected and usability-tested before purchase, rather than adopted and then patched with a training session once problems surface.
  • Simplifying the process by removing unnecessary steps entirely — every step removed is a step that can no longer be done wrong.
  • Standardizing equipment or process across every unit where the same task occurs, so staff moving between units or covering shifts encounter one version of the workflow, not several.
  • Tangible, resourced leadership action — committing budget, staff time, or a schedule change that makes a structural fix actually happen, as distinct from a memo endorsing the idea of safety.

Why RCA Action Plans Stall at the Weak End

The hierarchy itself is not new information to most quality teams — practitioners who have sat through RCA training generally recognize “forcing function beats retraining” as a stated principle. The gap is between recognizing it and acting on it under real constraints:

  • Cost and timeline. A forcing function often means capital spend, a vendor contract, or an IT change-control cycle measured in months. A training memo can be issued by end of week, which matters when the RCA process itself is running against a fixed reporting deadline (see below).
  • Authority. The RCA team frequently does not control the budget, staffing model, or procurement decision a strong action requires — they can recommend it, but the decision sits with a department or executive the team doesn’t report to, and the recommendation can quietly die at that handoff.
  • It looks like closure. “Staff retrained on [date]” is a clean, verifiable, closeable action-plan line item. “Redesign the medication room layout” is an open-ended project with no obvious completion date, which is uncomfortable to leave open on an action plan a surveyor or board will review.
  • Blame is easier to act on than systems. Assigning an action to “the individual should have caught this” is psychologically simpler than acknowledging the process itself set the individual up to fail — even on teams that have formally adopted a just culture framework and know better in principle.

Using the Hierarchy as a Decision Tool During Action Planning

The hierarchy is most useful applied at a specific moment: when the action-planning portion of the RCA meeting starts generating candidate actions, before the plan is finalized. Three practical checks turn it from a poster on the wall into something that changes what actually gets approved:

  • Require a tier label on every action in the written plan. If a facilitator makes the team classify each proposed action as weak, intermediate, or strong at the point it’s proposed — not after the fact — teams tend to self-correct, because “weak” written next to an action is harder to sign off on than an unlabeled one.
  • Set a floor, not just a ceiling. A plan consisting entirely of weak actions should not clear sign-off without an explicit, documented reason a stronger action isn’t feasible right now, plus an interim compensating measure and a re-evaluation date. This forces the cost/authority tradeoff into the open instead of letting it happen silently.
  • Separate the immediate action from the durable one. A weak action (retraining, a temporary warning) is often the only thing achievable before the team disperses, and that’s legitimate as a bridge — the failure mode is treating the bridge action as the final answer rather than tracking the stronger fix that was supposed to follow it.

Measuring Whether the Action Actually Worked

RCA2’s second major departure from a typical RCA process is treating “action completed” and “action effective” as two different questions that both need answering. Documenting that training occurred, or that a policy was issued, confirms the action happened — it says nothing about whether the underlying risk is now lower. A completed action needs a measure attached to it that can show whether the specific failure mode the RCA identified is actually occurring less often, tracked for long enough to distinguish a real change from random variation in a low-frequency event. For teams already running PDSA cycles for other improvement work, the same study-and-act discipline applies directly here: an RCA action plan that has no follow-up measurement point is, functionally, an action plan nobody ever checked.

RCA2 and the Sentinel Event Reporting Timeline

RCA2 is a methodology for doing the analysis and action-planning well; it is not itself a regulatory or accreditation requirement. The requirement most hospitals are actually working against is The Joint Commission’s Sentinel Event Policy, which is reported to call for a comprehensive systematic analysis and corrective action plan within 45 business days of the event or its discovery (verify the current day count against the Sentinel Event chapter of your organization’s applicable accreditation manual, since Joint Commission periodically revises the policy). RCA2’s action hierarchy is compatible with that timeline, not in tension with it — the discipline of labeling actions by tier and requiring justification for weak-only plans fits inside a 45-business-day process; it just prevents that deadline pressure from being the reason a plan defaults entirely to training and memos.

Frequently Asked Questions

What is RCA2, and how is it different from a standard root cause analysis?

RCA2 (“root cause analysis and action”) is the framework NPSF published in 2015, now maintained by IHI, that adds a required action-classification step — the Action Hierarchy — to standard RCA methodology. The causal-analysis techniques are largely the same as a conventional RCA; what RCA2 changes is the requirement to grade and justify the strength of every corrective action before the plan is considered complete.

What is a forcing function, and what does one look like in a hospital setting?

A forcing function is a physical or system design that makes an unsafe action impossible or very difficult, rather than relying on a person choosing not to do it. Non-interoperable enteral and IV tubing connectors (ISO 80369-3) and hard-stop dose limits on smart infusion pumps are commonly cited hospital examples — both close off an error category structurally instead of warning against it.

Why do hospital RCA action plans default to weak actions like retraining?

Mainly cost, timeline, and authority: a training session or memo can be issued within days by the team itself, while a forcing function or equipment change usually requires capital, a vendor, or an IT change-control cycle and a decision from outside the RCA team — and it produces a clean, closeable line item on the action plan where a systems fix does not.

Can a weak action ever be the right choice in an RCA2 action plan?

Yes, as an explicitly labeled interim bridge while a stronger action is developed — for example, a temporary alert while a forcing function is procured — but RCA2’s premise is that a plan consisting only of weak actions, with no stronger action tracked to follow it, has not meaningfully reduced the probability of recurrence.

How long does a hospital have to complete an RCA after a sentinel event?

Under The Joint Commission’s Sentinel Event Policy, a comprehensive systematic analysis and corrective action plan is reported to be due within 45 business days of the event or its discovery — confirm the current figure against your accreditation manual’s Sentinel Event chapter, since the policy is revised periodically.

Follow CASRAI

Research-administration guidance, standards updates and independent tool reviews.

Referenced across the research world

University of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logoUniversity of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logo
  • University of Cambridge logo
  • Columbia University logo
  • Crossref logo
  • University of Edinburgh logo
  • Harvard University logo
  • University of Oxford logo
  • Princeton University logo
  • Stanford School of Medicine logo
  • University College London logo
  • ORCID logo

View CASRAI adoption →

Regulatory Radar

Stop finding out after the fact

$29/month, cancel anytime. Daily digest updates from our analysis, a dashboard holding the same items, and a cited assistant for everything they raise.

  • Federal Register, Federal Register+, Grants.gov, Regulations.gov, NSF News, UKRI, plus CASRAI’s own published content.
  • 44,322 indexed passages, and every answer cites the ones it drew on.