Chips & Truths No spin. Just the math.
Home/Back of House/Casino Operations & Management/Incident Reporting

Incident Reporting

A strong incident report lets someone who was not present reconstruct what happened, what was observed, what was done, who was notified, and what remains open.

A casino incident report is a controlled factual record of an event that may affect people, money, gaming integrity, property, evidence, compliance, or the casino license. Its job is not to make the writer sound decisive after the fact. Its job is to let a qualified person who was not present reconstruct what happened, understand what was done, see what evidence exists, and decide what still needs attention.

Incidents can involve injuries, threats, disruptive behavior, payout disputes, suspected cheating, employee conduct, missing property, intoxication concerns, equipment failures, data events, exclusions, cash exceptions, technical alarms, or emergency response. The severity varies, but the reporting discipline should not depend on how dramatic the event felt in the moment.

Incident, exception, complaint, and routine log entry are different records

An incident is an event requiring factual documentation and response. An exception is a departure from an expected rule, threshold, process, or result. A complaint records a guest or employee concern. A routine log entry records normal operating information that matters to the next shift. One event can create more than one record, but the records should not be collapsed into one vague narrative.

A patron fall is an incident. A late safety inspection may be an exception. A patron who says staff ignored the fall may also create a complaint. The shift log may need a short operational note so the next manager knows the area remains restricted. Each record has a different purpose.

For the control side, read Exception Reporting. For live response and scene coordination, read Security Response Procedure.

Build the record around reconstruction, not storytelling

A strong report allows a reviewer to answer seven practical questions:

  • Who was involved, present, notified, interviewed, or responsible for an action?
  • What was directly observed, recorded by a system, stated by a witness, or inferred later?
  • When did discovery, response, escalation, evidence preservation, and closure occur?
  • Where did the event happen, and did the location change during the response?
  • What was done, by whom, and under what authority?
  • What evidence exists and where is it controlled?
  • What remains open, who owns it, and when is the next action due?

The report should make the source of important facts visible. “The guest was intoxicated” is a conclusion. “The guest had slurred speech, stumbled while standing, and was refused further alcohol by the beverage supervisor at 01:14” records observable facts and an action. “The dealer intentionally short-paid the guest” is an allegation unless intent is established. “Surveillance review showed the dealer paid four units on a five-unit wager” describes what the evidence showed without inventing motive.

Capture the timeline before memory smooths it out

Casino environments are noisy, interrupted, and fast. A manager may speak to security while watching a game, answer a radio call, move a guest, then review a transaction ten minutes later. Human memory tends to compress that sequence into a cleaner story than what actually happened.

Write the key timeline early. Use the source of each time when possible because surveillance, gaming systems, access control, radios, point-of-sale systems, and employee recollection may not use identical clocks.

TimeSourceEventAction / owner
22:08:14Slot event logDoor-open event recordedSlot supervisor notified
22:09Radio logAttendant reports damaged panelTechnician dispatched
22:13:31Surveillance reviewGuest leaves machine areaVideo bookmarked
22:18Manager entryMachine placed out of serviceTechnical review assigned

A table like this exposes gaps. If the record jumps from 22:09 to 22:18, the reviewer knows to ask what happened in between instead of assuming a smooth sequence.

Separate observation, statement, system record, and conclusion

One of the most useful habits in incident writing is source labeling. A report becomes much stronger when it distinguishes:

  • what the writer personally saw;
  • what another employee reported;
  • what a guest said;
  • what surveillance later confirmed;
  • what a machine or transaction log recorded;
  • what management concluded after review.

These categories should not be blended. A witness may be sincere and still be wrong. A camera may show only part of the event. A system timestamp may identify a transaction but not the human reason behind it. A manager’s conclusion may be valid, but it belongs after the evidence, not disguised as the original observation.

If exact words matter, record them accurately. Do not “improve” a statement into more formal language if the wording changes meaning. If only the substance matters, summarize it neutrally and identify who said it.

Preserve evidence without contaminating it

Incident reporting often overlaps with evidence control. Depending on the event, staff may need to preserve:

  • surveillance video or review references;
  • table-game, slot, cage, player-account, or point-of-sale logs;
  • chips, tickets, cards, documents, or receipts;
  • photographs taken under approved procedure;
  • access-control, radio, telephone, or dispatch records;
  • witness names and statements;
  • damaged equipment;
  • digital audit trails or system alerts.

Preservation and interpretation are different tasks. A floor supervisor who asks surveillance to retain video is preserving potential evidence. A later review that identifies a payout sequence is interpretation. Employees should not copy sensitive material to personal devices, alter a live system merely to reproduce a fault, or handle physical evidence more than necessary.

If chain of custody applies, the report should show who collected, transferred, stored, or accessed the item. “Photo attached” is weak if nobody can establish who took it, when it was taken, or whether the image belongs to the same event.

Neutral language protects both the investigation and the writer

Incident reports should describe behavior before assigning labels. Replace loaded shorthand with facts:

  • “cheater” becomes “patron whose play was referred for game-protection review”;
  • “fake injury” becomes the observed behavior, claimed injury, and medical response;
  • “drunk” becomes specific signs, service decisions, and actions;
  • “stole” becomes the observed removal or missing property unless theft is established;
  • “aggressive” becomes the words, gestures, threats, contact, or refusal that made the behavior significant.

Neutral writing is not timid writing. It is disciplined. It reduces the risk that an early assumption becomes treated as a fact merely because it appeared in the first report.

Record decisions and authority, not only events

Many weak reports describe what happened but omit the management decisions that changed the outcome. If a guest was removed, who authorized it? If a table was closed, who made the call? If chips were held pending review, what procedure allowed that? If medical help was declined, who offered it and how was the refusal documented?

A useful report records both the action and its owner. “Security notified” is incomplete if the next step depended on security. “Security supervisor M. Perez notified at 02:06; scene control transferred to Security while Table Games preserved the wager state” is much more useful.

Notification also does not automatically transfer ownership. Compliance may need to know about an event without becoming the operational owner. Surveillance may review footage without controlling guest contact. Human Resources may receive an employee-conduct report without directing the live floor response.

Use role-based notification paths

Not every incident belongs in a property-wide message. Privacy, investigation integrity, employee confidentiality, regulatory rules, and legal privilege may restrict access. The property should define when an event requires notification to roles such as:

  • shift or department management;
  • security;
  • surveillance;
  • medical responders;
  • compliance or AML personnel;
  • human resources;
  • legal or risk management;
  • information security;
  • senior executives;
  • law enforcement;
  • a gaming regulator or other authority.

The report should show the actual notification, not merely what the writer believes normally happens. If a regulator notification deadline applies, the report should also identify who owns that obligation rather than assuming “compliance will handle it.”

Closure means the open actions were actually resolved

An incident report should support action after the immediate scene is stable. Management may need to determine:

  1. Was the immediate risk controlled?
  2. Did policy work as intended?
  3. Did staffing, training, layout, equipment, or communication contribute?
  4. Is regulatory, insurance, legal, or employee follow-up required?
  5. Does the event connect to a repeated pattern?
  6. What corrective action is proportionate?
  7. Who owns the corrective action?
  8. How will closure be verified?

A report marked “closed” simply because the guest left or the shift ended is not necessarily closed. Useful closure reasons might include no further action, coaching completed, repair completed, claim transferred, policy change approved, regulator referral, law-enforcement referral, duplicate report, or investigation completed.

Measure report quality as well as filing speed

A fast report can be incomplete, while a perfect report filed days late can be operationally useless. A balanced review can track both timeliness and usefulness.

[ \text{Timely filing rate}=\frac{\text{reports filed within standard}}{\text{reports due}} ]

[ \text{First-review acceptance}=\frac{\text{reports accepted without material correction}}{\text{reports reviewed}} ]

[ \text{Open-action aging}=\text{current date}-\text{action assignment date} ]

If 92 of 100 reports were filed on time but only 54 were accepted without material correction, the operation has a quality problem hidden behind a good speed statistic. If quality is high but open actions remain unresolved for weeks, the weakness is follow-through rather than writing.

Report design should prompt facts, not manufacture conclusions

A practical incident form can prompt for:

  • event category and exact location;
  • discovery, response, escalation, and closure times;
  • persons involved and contact status;
  • direct observations;
  • statements and their sources;
  • actions taken and authority;
  • evidence references;
  • notifications;
  • immediate outcome;
  • follow-up action, owner, and due date;
  • regulatory, insurance, legal, or HR status;
  • supervisor quality review.

Dropdowns are useful for classification, but they should not replace the narrative. Selecting “guest misconduct” does not describe what the guest did. Selecting “payout dispute” does not identify the wager, amount, decision, or evidence.

Review reports against underlying evidence

Supervisors should periodically compare selected reports with video, transaction logs, dispatch records, system timestamps, or other underlying evidence. The purpose is not to catch writers making minor wording mistakes. It is to identify systematic weaknesses such as vague descriptions, missing decisions, late entries, incorrect times, unclear ownership, or open actions without due dates.

Monthly incident counts alone can mislead. Ten reports may mean ten separate problems, better reporting compliance, one recurring control failure, or a new classification rule. Trend analysis becomes more useful when incidents are grouped by severity, location, shift, event type, contributing factor, response time, and closure quality.

Incident reporting succeeds when the record improves the next decision. If the same hazard, dispute pattern, communication failure, or handover weakness appears repeatedly, the value of the report is not that it exists in storage. The value is that management can see the pattern early enough to change the operation.

Curated internal reading

Continue exploring

Play smart. Gambling involves real financial risk. If the game stops being entertainment, it's time to stop playing.