The Near Miss: The Loss That Did Not Happen, and Why It Matters
A near miss is an event that could have produced a loss and did not. The cause is the same, the chain of controls is the same, and only the outcome differs, so it carries the same information as a loss and costs nothing at all to collect. Vindhya Commercial Bank Limited, an invented bank, collected five, two of which were the same failure as an incident that followed, and linked neither.
The subject rests on one asymmetry, and the asymmetry is worth stating before any figure appears. A loss teaches something and charges for the lesson. A near miss teaches the same thing and charges nothing. Given that, the puzzle is not why institutions want near miss registers. The puzzle is why the registers so often sit unread. The answer is that recording a near miss is easy and costs nothing, and connecting it to anything is work that nobody has been asked to do.
Operational risk punishes loose language more than most subjects do. A register states what one bank recorded, and it cannot state what happened and went unrecorded. Neither can the bank. A near miss that nobody wrote down leaves no trace anywhere in the record, so a near miss register counts what was collected and never what occurred. The distinction is not a caveat bolted on at the end; it is the subject.
What is a near miss, and when is an event one?
Start on a level crossing on a small road. A scooter goes over as the barrier is coming down, and the train passes eight seconds later. Nothing happened. There is no ambulance, no report, no insurance claim, no number for anybody to explain. Now change one thing: the scooter stalls for four seconds. Same road, same barrier, same rider, same train, and now there is a funeral. The two mornings differ in four seconds of engine behaviour and in nothing else that anyone designed, chose or controlled.
The four seconds are the whole idea. A near missAn event that could have produced a loss and did not, carrying the same cause and the same control chain as one that would have. is an event that could have produced a loss and did not. The cause is the same. The chain of things that were supposed to stop it is the same. The people are the same. The outcome differs, and in a great many cases it differed because of something nobody arranged. For anybody wanting to know what a set of arrangements is capable of producing, the morning with no funeral says exactly as much as the morning with one.
The test for whether an event is a near miss is therefore not how frightening it felt. The test is whether the same cause, running through the same chain, could have ended in a loss. The test has an edge, and the edge matters. A control that fires on a routine transaction every day is not a near miss; it is a control doing its job on the ordinary flow it was built for. An event becomes a near miss when something has genuinely gone wrong upstream and the only reason it did not cost money is that something later in the chain stopped it. The wrong instruction was actually built. The forged document set was actually presented. The account of a leaver actually stayed live. In each case the failure was real and the loss was not.
Why does a near miss carry the same information as a loss?
Take one entry from this bank's loss record and one from its near miss register, and put them side by side. Incident I10, month 10: the collateral valuation feed was stale for 11 working days and 340 loans were wrongly marked, at a gross loss of Rs 1.4 crore, nothing recovered, and Rs 1.4 crore net. Near miss N3, month 6: the same collateral valuation feed was stale for 2 working days and a data quality check caught it.
Read the two rows as records rather than as stories. The month is there in both. The category is there in both. The description of what went wrong is there in both, and it is the same description with a different number of days in it. The process is the same process. The feed is the same feed. Every column a loss record carries is present in both rows except three: gross loss, recovery and net loss. A near miss and a loss differ in exactly one field, and it is the only field a loss report is ever sorted on.
One field of difference is why the information content is identical and the visibility is not. Whether a collateral valuation feed at this bank can go stale without anything noticing was answered as clearly by month 6 as by month 10, and month 6 answered four months earlier. Month 10 added a bill.
Why does a system stop most failures, and where does a near miss sit in that picture?
The picture almost everyone reaches for here belongs to somebody, and it should be named rather than borrowed. The picture is James Reason's, from Human Error, published in 1990, and it is often drawn as a row of slices of cheese with holes in them. Reason describes a system as a series of barriers, each one imperfect, each one with openings that move about. A failure meets the first barrier. Most of the time it is stopped. When it is not, it meets the second. A loss requires an opening in every barrier at the same moment, all the way along the chain.
The picture gives a way of seeing that layered defencesThe picture of a system as a series of barriers, in which most failures are stopped by one of them and a loss needs a complete path through all of them. are not a wall. Defences are a series, and the series has a property worth sitting with: the great majority of failures stop somewhere. Stopping is not luck and it is not a happy accident: it is the barriers doing exactly what they were built and paid for. In any institution running at scale, on any given day, most of what goes wrong is caught.
On Reason's picture a near miss is not a lucky escape at all: it is a failure that reached one barrier further than usual and was stopped. The stop is a measurement of how close the path came to opening. The reframing does a lot of work. Treated as luck, a near miss is nothing to record. Luck does not repeat in any usable way. Treated as a measurement, it becomes the cheapest instrument available for finding out how deep into an institution's own defences a live failure can get.
Placing each of this bank's five recorded near misses on the barrier that stopped it gives the following. One was stopped by an automated check on a data feed. Two were stopped by an independent second pair of eyes. Two were stopped by a periodic review or a reconciliation running after the fact. Five entries fall across three of the four kinds of barrier, and a register of five entries is all that distribution describes. Two of the four kinds carry no entry at all, and an empty barrier means only that nothing was written against it, never that nothing was stopped there.
In a layered picture of defences, what is a near miss?
Why is a near miss free to collect, and why is it still not collected?
Think about the cost of writing down a loss. Somebody has to establish what left the bank, chase what came back, agree the net figure with finance, assign a category, name a risk owner, and then explain the whole thing to a committee that will ask why it was not stopped. The money moved, and money that has moved has to be accounted for somewhere, so none of that is optional.
Now think about the cost of writing down a near miss at the moment it happens. The checker who refused a document set already knows what was wrong with it. The reconciliation that caught a payment file already produced the exception. The access review that found a live account belonging to a leaver already generated the line. In every case the information exists, in somebody's hands, at the moment of the catch. Writing it into a registerA kept record, whose value here is not the keeping but what somebody is asked to do with it. costs a few minutes of the time of the person who already has it. With no figure, there is no reconciliation, no finance sign-off and no net figure to agree.
So why is the register thin almost everywhere? Because nothing compels it. A loss produces a number somebody has to explain, a report somebody has to file and a question somebody has to answer. A near miss produces none of those three. The record of a loss is forced by the money and the record of a near miss is forced by nothing at all, so it depends entirely on somebody having been asked.
There is a second reason and it is quieter. When a control fires, the person operating it experiences a good day. The system worked. The refusal was correct. From inside the moment it does not feel like an event, it feels like the job. A control firing as designed and logged as normal is the routine catchA control firing as designed and being recorded as normal operation, which is exactly what it is and also the moment information stops moving., and it is exactly what it appears to be: a control working. Nothing about a normal day travels anywhere, so a routine catch is also the precise moment at which information about a live failure stops moving.
A near miss costs nothing to collect. Why do institutions still not collect them?
What has to be recorded before a near miss is worth anything?
Three things, and the third is the one that is almost never written down. The cause. Which control held. And why it held.
The first two are easy and they are what registers usually contain. The feed went stale; a data quality check caught it. A document set carried a forgery pattern; a checker refused it. Both of those are true, both are useful, and both leave the most important question open. The third field is what tells a reader whether the control held by design or because somebody happened to be looking, and a register carrying only the first two cannot distinguish a working barrier from a coincidence.
The distinction is not academic. The two cases point at opposite decisions. If a control held by design, the barrier is known to work and can be relied on next time. If it held because an unusually careful person was on that desk that afternoon, nothing of the kind is known, and the barrier being relied on is a person's attention rather than an arrangement. Both entries look identical in a register with two fields. The two events are completely different objects.
On that third field, this bank's register carries the following. For near miss N3 the record says the catch was written up as a routine catch. For near miss N4 the record says the refusal was written up as a routine refusal. In neither case does the record say why the control held. For the other three, N1, N2 and N5, the record does not say how they were written up at all. A blank in a register is not a finding about the event; it is only a blank.
What three things does a near miss record need, and which is usually missing?
What did this bank actually record?
Vindhya Commercial Bank Limited recorded five near misses across twelve numbered months. The shape of the set is not visible from any single entry, so read all five before reading anything about them.
| Entry | Month | What happened, and what stopped it |
|---|---|---|
| N1 | 2 | A second duplicate settlement instruction, this one for Rs 68 crore, was stopped by the four eyes check before release. The same cause as incident I2, sent out ten days earlier and not stopped. |
| N2 | 4 | A payment file of 1,240 salary credits was queued against the wrong account and caught at reconciliation before value date. |
| N3 | 6 | The collateral valuation feed was stale for 2 working days and a data quality check caught it. Nobody raised it as an issue. |
| N4 | 7 | A trade finance document set carrying the same forgery pattern as incident I13 was refused by a checker. The refusal was recorded as routine and never linked to anything. |
| N5 | 10 | A privileged access account belonging to a leaver stayed live for 46 days and was found by the quarterly access review before it was used. |
Five entries. The two shaded rows are the two that turn out to matter, and the reason they matter is not visible in this table.
One entry deserves a note. A careful reader will spot it, and it changes nothing about the arithmetic. Near miss N1 shares its cause with incident I2: both are the same duplicate settlement instruction problem. But N1 came ten days after I2. N1 and I2 are the same failure appearing twice, and the second appearance was caught. On the day I2 happened the entry did not exist yet, so no search of the register could have found it. Direction matters as much as similarity, and a register can only ever be searched backwards.
What does the near miss register look like beside the loss record?
Set the two side by side and count. Five near misses and thirteen incidents is eighteen events collected in the year. The near misses are 5 of 18, being 27.8 per cent of the record. Now count the same eighteen events by money. The thirteen incidents produced Rs 97.7 crore gross, Rs 53.9 crore of recoveries and Rs 43.8 crore net. Nothing left the bank in any of the five near misses, so they carry 0 per cent of the Rs 43.8 crore on the net basis and 0 per cent of the Rs 97.7 crore on the gross basis too.
The combination is exactly why near misses disappear. More than a quarter of everything this bank collected sits in a set that contributes nothing to the only column a loss report is ordered on, so any report sorted by money puts the whole register below the fold or leaves it out entirely. Nobody decided to ignore the register. The ordering did.
There is a related trap in near miss N1 worth naming once and then leaving alone. The duplicate instruction it stopped was for Rs 68 crore. The Rs 68 crore is real in the sense that it was the amount on the instruction, and because it was prevented and nothing left, it appears in no loss total this bank publishes. The amount must never be added to a loss figure and never presented as money saved. The figure is the size of the instruction that was stopped and not a rupee of cost or of benefit.
Five near misses and thirteen incidents. What share of the record and what share of the money are the near misses?
What is linking, and why is it the whole value of the register?
Now the two entries that matter. LinkingConnecting a near miss to a later event, or to another near miss, on the ground that the cause is the same. is connecting a near miss to a later event on the ground that the cause is the same. Linking is a separate act from recording, it happens at a different time, and in this bank it happened zero times.
Near miss N3, month 6: the collateral valuation feed was stale for 2 working days and a data quality check caught it. Incident I10, month 10: the same collateral valuation feed was stale for 11 working days, 340 loans were wrongly marked, nobody lost money as a customer, and the net loss was Rs 1.4 crore. Same feed, same process PR3, same failure, four months apart.
Near miss N4, month 7: a trade finance document set carrying the same forgery pattern as incident I13 was refused by a checker. Incident I13 was discovered in month 8: a trade finance officer and an external party had issued nine letters of credit against forged shipping documents over fourteen months, discovered when a beneficiary bank claimed, gross Rs 22.4 crore, Rs 7.0 crore recovered and Rs 15.4 crore net. Same pattern, one month apart on the discovery basis.
State the arithmetic plainly and name the basis. Both matter here. Two of the five recorded near misses, being 40.0 per cent of the near miss record, were the same failure as an incident that followed. The two incidents downstream carry Rs 1.4 crore and Rs 15.4 crore net, being Rs 16.8 crore together and 38.4 per cent of the year's Rs 43.8 crore of net loss. Both near misses were collected and neither was linked. The whole finding is in those two facts: this register was kept and was never read against anything.
Dates are measured carefully throughout, so the one month gap deserves one caution. Incident I13 was discovered in month 8 and it ran for fourteen months ending there. The one month gap is measured from near miss N4 in month 7 to the month I13 entered the record. A new incident cannot be compared against anything before it is known to exist, and the month of entry is the only basis a search of the register could ever work on. On the occurrence basis the picture is very different, and it follows below.
Near miss N3 caught the collateral feed stale for 2 working days in month 6 and it was recorded as a routine catch. What went wrong?
How far back does a lookback have to reach before it finds anything?
A lookbackChecking a new event against the near miss register over a stated window, to see whether the same failure has already appeared. is the smallest possible piece of machinery for turning a register into something useful. When a new incident is recorded, somebody checks it against the near miss register over a stated window and asks one question: has this failure already appeared here? That is it. No method, no analysis, no meeting. A search and a question.
The obvious next question is how far back the window should reach, and the obvious instinct is that longer is better. Run it on this bank's record and the instinct turns out to be almost entirely wrong. The two links sit one month and four months apart, so a one month window reaches incident I13 alone, being Rs 15.4 crore and 35.2 per cent of the year. A four month window reaches incident I10 as well, taking it to Rs 16.8 crore and 38.4 per cent. The record contains two links and no third one for a longer window to find, so every window from five months to twelve reaches exactly the same Rs 16.8 crore.
Put the two numbers against each other. A one month lookback reaches 35.2 of the 38.4 points, or 91.7 per cent of everything the window can ever reach in this record. The value sits in the first month and not in the length of the window, and going from one month to twelve buys 8.3 per cent of what is there.
Two of this bank's five near misses were the same failure as an incident that followed. Before the control is moved: how long a lookback window is needed to reach both?
Move the lookback window and watch the staircase stop climbing
One control: w, the lookback window in months over which a new incident is compared against the near miss register, from nil to twelve. One consequence: the share of the year's Rs 43.8 crore of net loss sitting in incidents this register would have reached. The record holds two links. Near miss N4 in month 7 to incident I13 in the month it entered the record, month 8, a gap of one month, worth Rs 15.4 crore net. Near miss N3 in month 6 to incident I10 in month 10, a gap of four months, worth Rs 1.4 crore net. The solved points are these. At w nil the register reaches nothing at all. At w of one month it reaches incident I13, Rs 15.4 crore, 35.2 per cent. At two months and at three months, unchanged. At w of four months it reaches incidents I13 and I10, Rs 16.8 crore, 38.4 per cent. From five months to twelve, unchanged at 38.4 per cent: the record holds two links and no longer window can find a third. A one month lookback reaches 35.2 of the 38.4 points, being 91.7 per cent of everything available. The control starts at nil, the setting this bank actually used: both near misses were collected and neither was linked to anything, so the register reached none of the year's Rs 43.8 crore. Every figure on this panel is loss the learn stageThe point after an event at which an institution asks what it now knows, which is a formal step in incident handling and belongs to another sequence. would have been looking at and is never loss avoidedA claim that a loss would have happened and did not because of something, which cannot be made from a near miss and is refused throughout this material..
Over a 0 month lookback this register would have reached no incident at all, worth Rs 0.0 crore, being 0.0 per cent of the year's Rs 43.8 crore of net loss, which is what the learn stage would have been looking at.
Educational illustration. The readout is loss the learn stage would have been looking at and is never loss avoided: nobody can say that linking a near miss would have stopped what followed, and in the case of incident I13 the scheme was already at run month 13 of its 14 when near miss N4 was refused. The flat top is a property of this small record of eighteen collected events and is not a general finding about how far back a lookback should reach. Money is held in whole rupees and every share is computed from the rupee figures rather than from a rounded crore figure.
The lookback curve is flat from four months to twelve. Does that mean four months is the right window for any institution?
The reason a lookback is worth running at all is that it produces an object neither event carries on its own. A patternTwo or more events sharing a cause, which is a different object from either of them and is visible only to somebody comparing. is two or more events sharing a cause, and it exists nowhere in either entry. Near miss N3 on its own is a caught data problem. Incident I10 on its own is a Rs 1.4 crore processing error. The pattern is a third thing, made only by somebody putting the two beside each other, and nobody at this bank was asked to.
So what actually failed, and who failed at it?
Nobody, and that has to be said before anything else about it. The data quality check in near miss N3 fired and caught a stale feed. The checker in near miss N4 looked at a document set, saw that it was wrong, and refused it. Both of those controls worked exactly as designed and both of those people did precisely what the role asks. There is no carelessness in this story anywhere, and any account of it that finds some has stopped looking too early.
The failure is downstream of the catch, and it is a design failure
Near miss N3 was recorded as a routine catch, and no route existed from a routine catch to an issue. Near miss N4 was recorded as a routine refusal, and no route existed from a routine refusal to a pattern. Both entries stopped exactly where the process said they should stop.
Ask what the alternative would have required of the person at the desk. A checker who refuses a document set has done everything the role asks of them. Asking that same person to also notice that this is the second one this quarter, to remember the first, to work out that the two share a pattern, and to raise that pattern to somebody, is asking for a control that was never designed, never written down and never staffed. Noticing the pattern is not a small addition to the job; it is a different job.
The fix is a route and not a reminder, and the difference between those two words is the whole of what this bank got wrong. A reminder asks people to do more of what they already do well. A route is a piece of design: when this control fires, the entry goes here, and somebody at the other end has been asked to look at it against what is already there.
What may never be claimed about a near miss that was linked in time?
Here is the sentence that is very easy to write and must never be written. Linking near miss N4 in month 7 would have avoided the Rs 15.4 crore of incident I13. The sentence is wrong twice over, and the second reason is the more interesting one.
The first reason is that nobody can know it. Linking a near miss does not by itself stop anything. Linking puts an entry in front of somebody, who then has to read it, believe it, work out what it means, and get something changed, and every one of those steps can fail. A loss avoided claim is a claim about a world that did not happen, and no record anywhere contains evidence about a world that did not happen.
The second reason is that the arithmetic in this case makes the point unusually exact. Incident I13 ran for fourteen months ending in month 8, so case month 7, when near miss N4 was refused, is run month 13 of its 14. Take a straight line as the reader's own assumption, not a fact about this case, and the Rs 15.4 crore net accrues at Rs 1.10 crore a month. By the end of run month 13, Rs 14.3 crore of the eventual Rs 15.4 crore had already accrued, being 92.9 per cent of it. The near miss arrived when the scheme was 92.9 per cent complete, so what a link would have bought is not the Rs 15.4 crore, it is finding out one month sooner. Finding out a month sooner is worth something, and it is not worth Rs 15.4 crore.
A colleague writes that linking near miss N4 would have avoided Rs 15.4 crore. What is wrong with that sentence?
One last discipline belongs with that one, and it is the one stated at the outset. Everything above describes a record of eighteen collected events at one bank. The record says what was written down and cannot say what was not, so the honest form of every claim is about the record rather than about the year. An absence in a register is evidence that nothing was recorded and is never evidence that nothing happened, and the temptation to slide from the first to the second is the single most common error in this whole subject.
Who actually uses any of this, and how?
Purnima Ganeshan, the head of operational risk at this bank, uses the register for exactly one thing and it is not reporting. The loss record already tells her what the year cost. The near miss register can tell her, and only if somebody runs the lookback, whether a failure she is about to pay for has already shown up free of charge. On this year's record that question would have returned two hits, both of them process failures with a named feed and a named document type behind them. Her practical decision is not how long the window should be. Because a search nobody is asked to run is a search that does not happen, her decision is who is asked to run it and on what day.
A credit analyst at another institution, reading this bank from outside, uses near miss information differently and is usually unable to get it. Near miss information is rarely published. Where it is available, the ratio worth looking at is not the count of near misses; a bank with a good reporting culture will show more of them, not fewer, and a thin register is at least as likely to mean nobody is writing them down as it is to mean nothing is happening. The analyst reads for whether anything in the register was ever connected to anything in the loss record. A bank that can show two links and what it did about them is saying something real about how it runs. A bank that shows a long register and no links has said only that it keeps a list.
The mechanism is identical at every scale, and the household version shows it. Somebody paying a house help, a milk supplier and an electricity bill through a phone will one day almost send Rs 8,000/- to the wrong saved contact and catch it on the confirmation screen. Nothing happened. There is no bank statement entry and nothing to reconcile. The discipline is to write one line somewhere: what nearly went wrong, what stopped it, and whether it stopped because the app asks for confirmation or because the person happened to be paying attention. Six months later, when a payment does go astray, the single question that turns that line into something useful is whether anybody looks back at it. Looking back is the entire method, and it is as true of one line in a notebook as it is of eighteen events at a bank.
Where the obligations on collecting near misses actually come from
The mechanism is the same in every jurisdiction. An event with a cause and no loss, a register, a lookback and a link work the same way anywhere, and none of the arithmetic above depends on any rule.
The requirement to collect, keep and report differs by country. The operational risk framework in which loss and event data collection sits is published by the Basel Committee on Banking Supervision at the Bank for International Settlements, bis.org. The Basel Committee is a standard setting body and not an Indian supervisor, so naming only the global standard says nothing about what binds, and that is the confident and common error in this subject. The rules an Indian bank must actually follow when it collects, keeps and reports operational risk come from the Reserve Bank of India at rbi.org.in, and the reader is sent there for the text.
Collection requirements, reporting thresholds, register standards, retention periods, capital charges and effective dates are set by the issuing authority and must each be confirmed at source. Where a near miss touches a conduct duty or an information security duty, those obligations also come from the Reserve Bank of India, and where a control failure has to be reported on in the accounts, the duty on internal financial controls sits in the Companies Act, whose text and applicability come from the Ministry of Corporate Affairs at mca.gov.in, with the assurance standard from the Institute of Chartered Accountants of India at icai.org.
Sources
| Source | Document | Site |
|---|---|---|
| Bank for International Settlements | The Basel Committee on Banking Supervision publications setting out the operational risk framework and the seven event categories, within which loss and event data collection sits | bis.org |
| Reserve Bank of India | What an Indian bank must actually collect, keep and report on operational risk, and the related conduct and information security duties | rbi.org.in |
| James Reason | Human Error, 1990. The layered defences picture of a system as a series of imperfect barriers | Cambridge University Press |
| Ministry of Corporate Affairs | The Companies Act duty on internal financial controls, its applicability and the form of the report | mca.gov.in |
| Institute of Chartered Accountants of India | The assurance standard and guidance note behind reporting on internal financial controls | icai.org |
Vindhya Commercial Bank Limited and Purnima Ganeshan are invented.
Educational material. Not advice on any investment, tax, budget or market position.
