QUICK ANSWER
What should an after action report template include?
An after action report template should include record ownership, event or exercise scope, objectives and targets, evaluation methods, sanitized evidence, a structured review of what was expected and what occurred, strengths, areas for improvement, analysis of why differences occurred, lessons, contested views, and an improvement plan. Each corrective action needs source observations, a role owner, due date, verification criteria, validation date, evidence, and an honest closure state.
An after-action report turns an exercise or stabilized operational response into a reviewable improvement record. It connects declared objectives to evidence-backed observations, separates strengths from areas for improvement, records why differences occurred, and gives each corrective action an owner, due date, verification criterion, and follow-up state.
This downloadable pack includes an editable review worksheet, a valid JSON starter, a fictional completed example, a closed JSON Schema, and a dependency-free validator with deterministic tests. It is not an official FEMA, CISA, WHO, emergency-services, or military template, and it does not replace live response, an incident report, an incident or project postmortem, legal findings, agency policy, public communication, or proof of readiness.

Move from observations to an accountable improvement plan
Review the bounded exercise or response against its declared objectives, preserve evidence and disagreement, then separate each observation from the corrective action chosen to address it.
Define the reviewed event, owner, audience, and limits
Give the report a stable ID and revision, link the exercise or response record, name the preparer and facilitator roles, declare the audience and confidentiality, and state what is outside the review. Live response and urgent reporting duties remain with their existing owners.
Sources: [aar-pack], [who-aar-overview], [houston-aar]
Evaluate declared objectives with attributable evidence
For each objective, record the expected capability, target, and evaluation method before writing a conclusion. Link observer notes, exercise timelines, records, and sanitized references by stable ID. Preserve limitations and protect restricted or identifying material.
Sources: [aar-pack], [fema-hseep-training], [cisa-aar-template]
Facilitate the four core review questions
Ask what was expected, what occurred, why differences occurred, and what should change next. Capture what went well as deliberately as gaps, invite multiple perspectives, and preserve contested views instead of manufacturing consensus.
Sources: [aar-pack], [who-aar-guidance], [nwcg-aar]
Separate strengths and improvement observations from actions
Write each observation against one objective with its evidence, analysis, consequence, applicable reference, and consensus state. A strength explains what enabled performance. An area for improvement describes the observed gap and its implications without hiding a recommendation inside the observation.
Sources: [aar-pack], [cisa-aar-template], [fema-hseep-training]
Build a dynamic improvement plan
Link every corrective action to one or more accepted observations, then assign a role owner, due date, observable verification criteria, validation date, and evidence requirement. Track the plan as work changes instead of treating the published report as the end of improvement.
Sources: [aar-pack], [fema-improvement-planning], [cisa-aar-template]
Validate outcomes and close only from evidence
At the follow-up date, mark the action validated, ineffective, or superseded from observed evidence and record a closure note. Implementation alone does not demonstrate effectiveness. Keep the plan open when the outcome is unknown.
Sources: [aar-pack], [fema-improvement-planning], [who-aar-overview]
The after-action report and improvement-plan boundary
Use this owner for evidence-linked performance review after an exercise or stabilized operational response. Reference adjacent records without absorbing their authority.
Included
- Report ID, source event or exercise ID, revision, status, preparer and facilitator roles, audience, confidentiality, scope, and explicit exclusions
- Objectives, capabilities, targets, evaluation methods, sanitized evidence, limitations, and safe references
- What was expected, what occurred, what went well, what needs improvement, why differences occurred, lessons, and dissenting views
- Strength and area-for-improvement observations linked to objectives, evidence, analysis, consequence, references, and consensus state
- Corrective actions linked to observations with role owners, due dates, verification criteria, validation dates, evidence, and closure notes
- Dynamic follow-up with open, validated, ineffective, or superseded states
Not included
- Live incident command, emergency instructions, containment, recovery execution, responder safety direction, regulator notification, or a response runbook
- The contemporaneous incident report, raw evidence store, forensic record, public status update, customer notice, or legal or employment finding
- An incident postmortem’s deeper service-learning record, a project postmortem’s delivery retrospective, an event debrief, or a post-event performance report
- Official FEMA, CISA, WHO, HSEEP, emergency-services, military, safety, security, privacy, legal, audit, or regulatory certification
- Corrective-action implementation authority, budget or capacity commitment, change or release approval, compliance assurance, or proof of future readiness
DOWNLOADABLE RESOURCE
Download the after-action report template pack
Use the Markdown worksheet for a facilitated review or the JSON starter for a bounded workflow. Inspect the fictional example, closed schema, validator, and mutation tests before adapting the record.
After-action report and improvement plan template pack
A fictional exercise review connecting two objectives to sanitized evidence, one strength, two improvement observations, two owned actions, and open validation follow-up.
Format: Markdown, JSON, JSON Schema, and dependency-free Node.js validator/tests in one ZIP
Locally reproduced August 1, 2026. SHA-256: 580e7b8dd2d6542c5ee5403b892641f512fe39405ad49b6e8e44fc38e5c270bc
Included
- Editable Markdown review worksheet and a valid JSON starter
- Completed fictional JSON example for one bounded service-continuity tabletop exercise
- Closed Draft 2020-12 JSON Schema covering every root and nested record shape
- Dependency-free validator for exact keys, IDs, references, chronology, safe fictional URLs, acceptance and closure states, and all-false boundaries
- Twenty-eight deterministic tests covering both valid records and rejected unsafe or contradictory mutations
- README, package commands, fixed timestamps, exact file allowlist, and reproducible ZIP bytes
Verification boundary
Validated the starter and completed example, passed 28 mutation tests, checked closed object shapes and cross-record references, copied an exact nine-file allowlist, stripped ZIP metadata, and reproduced the same archive hash.
Three after-action report patterns
The evaluation graph stays stable while the setting changes. Local agency policy, safety rules, and reporting duties still control each real use.
Tabletop exercise review
Use when: A facilitated exercise tested declared capabilities and observers captured enough evidence to compare performance with objective targets.
Map each observation to an exercise objective, distinguish strengths from improvement areas, preserve facilitator and participant perspectives, then build a corrective-action plan with validation dates.
Structure
- Objectives and targets precede observations and ratings
- Observer notes and exercise records remain attributable and sanitized
- Corrective actions stay separate from the observation statements they address
Watch for: A fictional or controlled exercise cannot prove live response performance, official HSEEP conformance, certification, compliance, or readiness for every scenario.
Sources: [fema-hseep-training], [cisa-aar-template], [fema-improvement-planning]
Stabilized emergency-response review
Use when: The active response has ended or stabilized and qualified owners can review actions, strengths, gaps, and prioritized improvements without disrupting urgent work.
Use response records as evidence, facilitate structured questions across the relevant roles, identify best practices and challenges, and track approved corrective actions after the report is accepted.
Structure
- Live command and time-bound notifications close or transfer before the ordinary review
- Sensitive records stay restricted while the general report uses sanitized references
- Local public-health, safety, legal, and regulator policy remains authoritative
Watch for: This general pack is not a WHO, FEMA, CISA, hospital, regulator, or jurisdiction-specific response record and does not establish legal or clinical adequacy.
Sources: [who-aar-overview], [who-aar-guidance], [houston-aar]
Operational continuity response review
Use when: A bounded service, facility, vendor, or handoff disruption is stable and the organization needs evidence-linked performance learning plus accountable follow-up.
Review the intended operating objective, actual sequence, strengths that limited impact, gaps that created friction, and actions that can be verified in a later dry run or controlled test.
Structure
- The source incident or event record remains authoritative for contemporaneous facts
- The review focuses on what and why rather than assigning personal blame
- Follow-up evidence determines whether an action is validated, ineffective, or superseded
Watch for: An operational AAR does not replace incident RCA, contractual review, public communication, release approval, or proof that the same response will succeed again.
Sources: [nwcg-aar], [fema-improvement-planning], [aar-pack]
Decide whether the report is ready for acceptance
The validator can expose broken references and contradictory states. Qualified reviewers still own safety, reporting, findings, action selection, and acceptance.
The event is active, people remain at risk, or a time-bound notification or response decision is still open.
Choose: Keep the AAR in draft and return authority to the live response, safety, security, privacy, legal, or regulator-notification process.
Tradeoff: The review waits, but it does not compete with urgent protection or become an unofficial command channel.
An observation is not linked to an objective, evidence, analysis, consequence, and applicable reference or explicit not-applicable state.
Choose: Keep it in draft, repair the evidence contract, and preserve disagreement when participants do not accept the finding.
Tradeoff: The report may take longer, but unsupported impressions do not become accepted organizational findings.
An area-for-improvement observation already contains a prescribed corrective action or names one person as the cause.
Choose: Rewrite the observation around the observed performance gap and system context, then evaluate corrective actions separately.
Tradeoff: The report becomes less immediate, but reviewers can compare solutions and avoid disguising blame as analysis.
A corrective action has no source observation, role owner, due date, verification criteria, or validation date.
Choose: Keep it out of the accepted improvement plan until ownership and evidence expectations are explicit.
Tradeoff: Fewer actions leave the meeting, but accepted actions can be tracked and audited.
An action was implemented but the observed result is missing, contradictory, or outside the agreed validation conditions.
Choose: Record implementation without marking the action validated; keep follow-up open or mark it ineffective or superseded from evidence.
Tradeoff: Closure waits, but activity is not confused with demonstrated improvement.
TURN REVIEW INTO FOLLOW-UP
Download the AAR and validate the improvement graph
Open the review worksheet or JSON starter, inspect the fictional tabletop example, and run the dependency-free mutation tests before adapting the record.
Download the after-action report packThe ZIP is reproduced locally. Public availability, local agency requirements, adapted evidence quality, report acceptance, and real corrective-action outcomes require separate verification.
Keep deeper incident learning in the postmortemUse this page for objective-based after-action evaluation and improvement planning. Use the postmortem owner for broader incident impact, causal factors, lessons, decisions, and follow-up.
What an after-action report cannot prove
A structured AAR improves traceability from objectives to follow-up. Its conclusions remain limited by exercise design, observability, evidence access, participant coverage, facilitation, analysis, local policy, and validation time.
- A tabletop or simulated exercise does not reproduce every live hazard, workload, dependency, authority boundary, or human response.
- Observer notes can conflict, omit decisions, reflect different timestamps, or overrepresent visible actions.
- A strength in one scenario does not prove capability under a different event, team, location, duration, or resource constraint.
- An accepted improvement area does not independently establish root cause, negligence, liability, regulatory breach, or blame.
- A published action plan does not authorize spending, staffing, implementation, change, release, or policy changes.
- Implementation and a quiet validation window do not prove permanent effectiveness or future readiness.
- This pack is not official FEMA, CISA, WHO, HSEEP, emergency-services, military, hospital, safety, security, privacy, legal, audit, or regulator guidance.
- This ordinary informational article does not grant AI signup credits. The linked product page follows its own current eligibility rules.
Sources and verification record
The same-release artifact supports the fictional record and validator claims. Current first-party government and public-health sources support the review model without certifying this pack or making agency-specific rules universal.
[aar-pack] Playcode:Fictional after-action report example
Checked August 1, 2026. Supports: The locally reviewed fictional record, source graph, validation rules, tests, and reproducible archive. Public availability remains unverified until deployment.
[fema-improvement-planning] Federal Emergency Management Agency Preparedness Toolkit:Improvement Planning Templates
Checked August 1, 2026. Supports: FEMA’s current first-party description of exercise evaluation, dynamic improvement plans, corrective-action monitoring, and AAR/IP templates. It does not make this pack HSEEP-conformant or official.
[fema-hseep-training] Federal Emergency Management Agency National Standard Exercise Curriculum:Homeland Security Exercise and Evaluation Program
Checked August 1, 2026. Supports: FEMA’s first-party description of objectives, capabilities, strengths, areas for improvement, performance, corrective actions, and improvement planning. Program doctrine and training requirements remain authoritative for HSEEP use.
[cisa-aar-template] Cybersecurity and Infrastructure Security Agency:Emergency Services Sector After-Action Report/Improvement Plan Template
Checked August 1, 2026. Supports: CISA’s sector-specific template fields for objectives, strengths, improvement observations, references, analysis, corrective actions, timelines, and responsible parties. Its emergency-services context and agency wording are not universal.
[who-aar-overview] World Health Organization:After Action Review
Checked August 1, 2026. Supports: WHO’s current overview of structured facilitated review, best practices, challenges, what happened, why, corrective actions, and continuous learning after public-health responses. It does not certify a general business or software workflow.
[who-aar-guidance] World Health Organization:Guidance for After Action Review
Checked August 1, 2026. Supports: WHO’s 1 April 2019 methodology for planning, conducting, reporting, and following up after public-health events across several facilitation formats. Public-health and IHR context remains specific.
[nwcg-aar] National Wildfire Coordinating Group:After Action Reviews
Checked August 1, 2026. Supports: NWCG’s current first-party facilitation guidance around what was planned, what happened, why, what to sustain or improve, multiple perspectives, focus on what rather than who, and follow-up. Wildland-fire practice and examples are domain-specific.
[houston-aar] University of Houston Office of Emergency Management:After Action Report
Checked August 1, 2026. Supports: The university’s first-party purpose statement for reviewing incidents, exercises, or events through strengths, improvement areas, lessons, best practices, recommendations, and plan updates. Its departmental template is not universal policy.
After action report template questions
What is an after action report?
An after action report is a post-exercise or post-response evaluation record. It compares declared objectives and expected performance with what occurred, documents strengths and areas for improvement from evidence, records why differences occurred, and creates an improvement plan with corrective actions, owners, due dates, verification criteria, and follow-up.
What is the difference between an after action review and an after action report?
The after action review is the facilitated discussion: what was expected, what occurred, what went well, what needs improvement, why, and what should change. The after action report preserves the accepted scope, evidence, observations, analysis, lessons, contested views, and resulting improvement plan. The discussion can happen without a complete report, but accountable follow-through needs a durable record.
What should an improvement plan include?
Each improvement-plan action should link to one or more accepted observations and include a stable ID, title, role owner, due date, status, observable verification criteria, validation date, evidence references, and closure note. Implementation is not the same as validation, so keep the action open until the expected result is observed or mark it ineffective or superseded.
Is an after action report the same as an incident postmortem?
No. An AAR evaluates an exercise or stabilized response against declared objectives and capabilities, then produces observations and an improvement plan. An incident postmortem is a broader service-learning record around measured impact, the incident timeline, causal, contributing, and protective factors, lessons, decisions, and follow-up. A real incident can require both, but their evidence and owners should remain explicit.
Is an after action report the same as an event debrief or post-event report?
No. An ordinary event debrief captures participant perspectives and handoffs. A post-event report summarizes approved performance evidence and outcomes. An emergency or exercise AAR evaluates declared objectives, strengths, areas for improvement, analysis, corrective actions, and validation follow-up. Do not use the AAR label to imply emergency-governance rigor on a routine meeting summary.
Does this template comply with FEMA, CISA, WHO, or HSEEP?
No compliance or conformance claim is made. The article cites current first-party sources to explain common fields and boundaries, but the downloadable pack is a Playcode-created general template. Organizations using an agency program, jurisdictional requirement, grant condition, health protocol, or emergency-services doctrine should use the authoritative current forms, instructions, reviewers, and retention rules for that program.
Can Playcode turn this AAR into a workflow?
Playcode can help build a bounded workflow around reviewed objectives, evidence, observations, consensus states, corrective actions, owners, dates, validation, and follow-up. Before operational use, verify restricted access, redaction, attachments, retention, audit, notifications, concurrent edits, integrations, export, monitoring, backup, recovery, agency requirements, and release ownership with the accountable people.
BUILD THE REVIEWED IMPROVEMENT WORKFLOW
Turn the accepted AAR into a bounded app
Give Playcode the reviewed objectives, roles, evidence rules, observation states, action ownership, validation contract, and policy boundaries. Verify restricted access, retention, audit, notifications, integrations, monitoring, backup, recovery, and release control before operational use.
Build and verify the AAR workflowThis informational article does not grant AI signup credits. No official conformance, report completeness, response adequacy, root-cause accuracy, action effectiveness, recovery, safety, security, privacy, compliance, legal sufficiency, or readiness outcome is guaranteed.