{"templateId":"markdown","sharedDataIds":{},"props":{"metadata":{"markdoc":{"tagList":["typography","box","badge"]},"redocly_category":"Articles","type":"markdown"},"seo":{"title":"Why post-incident reviews matter to Access Worldpay","description":"Just sometimes, something goes wrong. In IT operations, we call this an 'incident'. After high-impact incidents, it's industry best practice to hold Post-Incident Reviews (PIRs).","siteUrl":"https://docs.worldpay.com/access","image":"/access/assets/worldpay-logo-light.21b7daf79984773a9fcd7d4fbcb07ae5289dfffd6023c4c3dca720c7058e53dc.33f780a6.svg","keywords":"documentation, api, openapi, sdks, developer, payments, json, payouts, 3ds","jsonLd":{"@context":"https://schema.org","@type":"Organization","url":"https://docs.worldpay.com/access","name":"Worldpay"},"meta":[{"name":"google-site-verification","content":"zjziIKaP3ImsqsfhYnEBnq1R85UabiSwl7HTXuwtZuo"},{"name":"doc_product","content":"Access"},{"name":"doc_category","content":"Documentation"}],"llmstxt":{"hide":false,"sections":[{"title":"Payments API","description":"Payment orchestration API combining fraud assessment, 3ds authentication, SCA exemptions, Worldpay Token creation and a card or wallet based payment.","includeFiles":["products/payments/@20240601/**/*"],"excludeFiles":[]},{"title":"Payment Queries API","description":"Querying your payments data, based on a variety of parameters.","includeFiles":["products/payment-queries/@v1/**/*"],"excludeFiles":[]},{"title":"Card BIN Data API","description":"Provides detailed information about a card.","includeFiles":["products/card-bin/@v1/**/*"],"excludeFiles":[]},{"title":"3DS Authentication API","description":"Request 3DS authentication to protect against fraud, be SCA compliant and to shift liability using this standalone API.","includeFiles":["products/3ds/@v3/**/*"],"excludeFiles":[]},{"title":"FraudSight API","description":"Request a risk assessment and receive a response with an outcome (e.g. lowRisk) using this standalone API.","includeFiles":["products/fraudsight/@v1/**/*"],"excludeFiles":[]},{"title":"Checkout SDK","description":"Integrate using our clientside SDKs for both web and native devices. Benefit from SAQ-A/PCI-SSF compliance.","includeFiles":["products/checkout/web/@v2/**/*","products/checkout/ios/@v4/**/*","products/checkout/android/@v4/**/*","products/checkout/react-native/@v3/**/*","products/checkout/flutter/@v1/**/*"],"excludeFiles":[]},{"title":"Tokens API","description":"Minimizes the exposure of sensitive card details and increases the security of your customer's card details.","includeFiles":["products/tokens/@v3/**/*"],"excludeFiles":[]},{"title":"Card Payments API","description":"Request a card payment using this standalone API, requires separate requests for 3DS, Fraud assessment etc.","includeFiles":["products/card-payments/@v7/**/*"],"excludeFiles":[]},{"title":"Card Verifications API","description":"Verify your customer's card to maximize your authentication rates.","includeFiles":["products/card-verifications/@v6/**/*"],"excludeFiles":[]},{"title":"Account Payouts API","description":"Send funds to your customer's bank accounts and search for payouts using parameters.","includeFiles":["products/account-payouts/@20250101/**/*"],"excludeFiles":[]},{"title":"APMs","description":"Pay using eWallets, bank transfers, direct debits, local card schemes, Postpay and eInvoice/ Buy Now Pay Later.","includeFiles":["products/apms/@20240701/**/*"],"excludeFiles":[]},{"title":"Balance API","description":"Request your account details for a single account or all accounts under an entity.","includeFiles":["products/balance/@20250101/**/*"],"excludeFiles":[]},{"title":"Card Payouts API","description":"Send funds to your customer's cards.","includeFiles":["products/card-payouts/@v4/**/*"],"excludeFiles":[]},{"title":"Events (Webhooks)","description":"Receive status updates from Access Worldpay by setting up a webhook.","includeFiles":["products/events/@v1/**/*"],"excludeFiles":[]},{"title":"FX API","description":"Manage Foreign Exchange (FX) on your payments.","includeFiles":["products/fx/@v1/**/*"],"excludeFiles":[]},{"title":"Hosted Payment Pages (HPP) API","description":"Our low-code option to take payments securely at the lowest PCI compliance level - SAQ A.","includeFiles":["products/hosted-payment-pages/@v1/**/*"],"excludeFiles":[]},{"title":"Money Transfers API","description":"Money Transfer OCTs (Original Credit Transaction) allow funds to be pushed to an eligible card in 30 minutes or less.","includeFiles":["products/money-transfers/@v1/**/*"],"excludeFiles":[]},{"title":"Parties API","description":"Create parties, manage your payout instruments and beneficial owners and carry out identity verification checks.","includeFiles":["products/parties/@20250101/**/*"],"excludeFiles":[]},{"title":"SCA Exemptions API","description":"Maximize a frictionless checkout experience by using issuer data insights to apply exemptions.","includeFiles":["products/sca-exemptions/@v1/**/*"],"excludeFiles":[]},{"title":"Split Payments API","description":"Divide funds from a single payment amongst yourself and your parties/sellers.","includeFiles":["products/split-payments/@20250625/**/*"],"excludeFiles":[]},{"title":"Statements API","description":"Retrieve your account statement and see individual entries for all credits and debits.","includeFiles":["products/statements/@20250101/**/*"],"excludeFiles":[]},{"title":"Transfers API","description":"Transfer funds from source account to target account.","includeFiles":["products/transfers/@20250101/**/*"],"excludeFiles":[]},{"title":"Verified Tokens API","description":"Verified Tokens ensures that your customer's payment details are valid and CIT compliant when creating a token.","includeFiles":["products/verified-tokens/@v3/**/*"],"excludeFiles":[]}],"excludeFiles":[]}},"dynamicMarkdocComponents":[],"compilationErrors":[],"ast":{"$$mdtype":"Tag","name":"article","attributes":{},"children":[{"$$mdtype":"Tag","name":"Typography","attributes":{"fontSize":"1.2em","as":"div"},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/products/articles"},"children":["← Back to articles list"]}]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":1,"id":"why-post-incident-reviews-matter-to-access-worldpay","__idx":0},"children":["Why post-incident reviews matter to Access Worldpay"]},{"$$mdtype":"Tag","name":"Box","attributes":{"display":"inline-flex","gridTemplateColumns":["1fr 1fr","1fr 1fr 1fr","1fr 1fr 1fr"],"gridGap":"1rem","mt":"1rem","mb":"1rem"},"children":[{"$$mdtype":"Tag","name":"Badge","attributes":{"size":"small","fontWeight":"bold","color":"white","mt":"0rem","mb":"0.5rem","px":"1rem","py":"0.5rem","borderRadius":"6rem","bg":"var(--wp-colour-light-blue)"},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Ways of working"]}]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Written by ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Andy Brodie"]},{"$$mdtype":"Tag","name":"br","attributes":{},"children":[]}," ","15 July 2020"]},{"$$mdtype":"Tag","name":"hr","attributes":{},"children":[]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Just sometimes, something goes wrong. In IT operations, we call this an 'incident'. After high-impact ",{"$$mdtype":"Tag","name":"i","attributes":{},"children":["incidents"]},", it's industry best practice to hold Post-Incident Reviews (PIRs). These examine what happened, why, and how we can improve. In the first of two articles, Andy Brodie explains why Access Worldpay values PIRs so highly that it now uses them to learn from every single 'incident'."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["It's simply a fact that computers and the services they run are fallible. This is partly because the humans that create and program them are also imperfect, and because it's impossible to test the infinite combinations of potential scenarios within live service. Naturally, we want our creations to be as close to perfect as possible, however, so when things do go wrong, we're determined to find out why."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Like many organizations, Worldpay from FIS uses the ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"https://www.axelos.com/best-practice-solutions/itil"},"children":["ITIL"]}," (Information Technology Infrastructure Library) ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"https://en.wikipedia.org/wiki/IT_service_management"},"children":["ITSM"]}," (IT Service Management) framework. As a result, something going wrong is described as an 'incident' which, for many years, has been managed by a thorough and well-defined ITIL-based process."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["For high-impact ",{"$$mdtype":"Tag","name":"i","attributes":{},"children":["incidents"]},", this includes the Post-Incident Review (PIR), which provides a process to discuss what went wrong and why, plus how we might prevent things going wrong in the future - specifically, by specifying new covering requirements and acceptance criteria on future work."]},{"$$mdtype":"Tag","name":"div","attributes":{"className":"md-table-wrapper"},"children":[{"$$mdtype":"Tag","name":"table","attributes":{"className":"md"},"children":[{"$$mdtype":"Tag","name":"thead","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"What's an 'incident'?"},"children":["What's an 'incident'?"]}]}]},{"$$mdtype":"Tag","name":"tbody","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["It's a record we create whenever something has gone wrong and has been detected by anything or anybody inside or outside Worldpay (e.g. a customer or supplier). The 'incident' is closed once its impact has ended, but this doesn't mean the underlying problem has been solved. For example: an incident with a service's operation in a single AWS Availability Zone (AZ) can be mitigated and closed by redirecting traffic to another AZ, but that hasn't fixed the problem (or 'root cause') in the first AZ."]}]}]}]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"expand-and-adapt","__idx":1},"children":["Expand and adapt"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"b","attributes":{},"children":["\"Every incident is a learning opportunity for the teams. Not only is it important to identify and resolve the root cause but also to learn from it."," ","We're looking at monitoring and alerting improvements, increasing engineer training, plus expanding knowledge and experience sharing across the whole tribe.We have seen invaluable conversations happening within Access Worldpay since starting the PIRs for every incident. This will help stop some of the future ",{"$$mdtype":"Tag","name":"i","attributes":{},"children":["incidents"]},"\""," ","Sophie Hirst - Technical Service Owner."]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Within FIS, the Access Worldpay tribe decided to hold PIRs for every incident that happened, whatever its size or impact, simply because the process yields such valuable outcomes. Specifically:"]},{"$$mdtype":"Tag","name":"ol","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Access Worldpay teams work in a BRO (Build-Release-Operate) model in which the team building a service also operates it once it has been released. By requiring manual intervention in a service's operation, ",{"$$mdtype":"Tag","name":"i","attributes":{},"children":["incidents"]}," take engineers away from writing new code. To maximize productivity, therefore, we must minimize both the number and impact of ",{"$$mdtype":"Tag","name":"i","attributes":{},"children":["incidents"]},"."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Embedding high-quality incident management into our culture has its own value, particularly for new engineers who may be unfamiliar with the benefits of best-practice 'incident' management, particularly with respect to minimizing customer impact."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Low-impact ",{"$$mdtype":"Tag","name":"i","attributes":{},"children":["incidents"]}," or near-misses often act like compiler warnings - a 'smell' that something is wrong that, left unaddressed, could lead to a high-impact 'incident' in the future."]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["However, PIRs can be extremely time-consuming, which also takes engineers away from writing new code. As a result, Access Worldpay adapted the PIR process to capture the benefits of the process at a lower time-cost."]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"three-key-principles","__idx":2},"children":["Three key principles"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Access Worldpay has three principles by which it treats ",{"$$mdtype":"Tag","name":"i","attributes":{},"children":["incidents"]}," and, by extension, PIRs. These are:"]},{"$$mdtype":"Tag","name":"ol","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"i","attributes":{},"children":["Incidents"]}," are inevitable - no service or system will ever be perfect."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"i","attributes":{},"children":["Incidents"]}," are a learning opportunity to improve and ensure that we can continue to innovate and build world-class services."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Blame is counter-productive and erodes trust, thereby damaging our culture and ultimately undermining the quality of our services."]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["The second and third points may sound rather trite. However, experience shows that this approach is the most effective way to get the best outcome - high-quality services developed and operated by skilled, motivated teams, both of which are always improving."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["On the third principle, an unspoken and troublesome kind of blame is the self-inflicted kind. Everybody makes mistakes, so it's important for everybody involved in PIRs to remember this and continue to promote these three key points so that confidence is built up, not knocked down."]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"towards-better-services","__idx":3},"children":["Towards better services"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["For everything but long-running ",{"$$mdtype":"Tag","name":"i","attributes":{},"children":["incidents"]},", a PIR is held after the relevant 'incident' is closed but often before the underlying problem is resolved."]},{"$$mdtype":"Tag","name":"div","attributes":{"className":"md-table-wrapper"},"children":[{"$$mdtype":"Tag","name":"table","attributes":{"className":"md"},"children":[{"$$mdtype":"Tag","name":"thead","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"What's a 'problem'?"},"children":["What's a 'problem'?"]}]}]},{"$$mdtype":"Tag","name":"tbody","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["It's the term used to describe the root cause of an 'incident', or the potential root cause of a future 'incident'. This might be:",{"$$mdtype":"Tag","name":"br","attributes":{},"children":[]}," 1. a code or infrastructure problem that requires a change;",{"$$mdtype":"Tag","name":"br","attributes":{},"children":[]},"2. a documentation problem that requires a clarification or correction;",{"$$mdtype":"Tag","name":"br","attributes":{},"children":[]},"3. a problem with a process that needs a step added - or better yet, removed."]}]}]}]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["The main goal of the PIR is to work out, as a team, if there's anything we can do better in future. This is deliberately broad; it means not only avoiding future ",{"$$mdtype":"Tag","name":"i","attributes":{},"children":["incidents"]}," completely but, if the problem has yet to be resolved, how to deal with future ",{"$$mdtype":"Tag","name":"i","attributes":{},"children":["incidents"]}," faster or with less human intervention."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["In summary, Access Worldpay holds PIRs to maximize our productivity and optimize our services and culture. PIRs achieve this most successfully when they promote learning, eschew blame and recognize that prevention is better - and far cheaper - than cures. This first article has sought to explain why we value PIRs in principle and, broadly, what we seek to gain from them."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["My ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/products/articles/post-incident-reviews-how-they-happen-at-accessworldpay"},"children":["second article"]}," details how we conduct PIRs in practice and use them to maximize both our productivity and service quality. I hope you find both articles useful."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"b","attributes":{},"children":["Andy Brodie is Senior Product Manager for Quality of Service at Access Worldpay. "]}]}]},"headings":[{"value":"Why post-incident reviews matter to Access Worldpay","id":"why-post-incident-reviews-matter-to-access-worldpay","depth":1},{"value":"Expand and adapt","id":"expand-and-adapt","depth":2},{"value":"Three key principles","id":"three-key-principles","depth":2},{"value":"Towards better services","id":"towards-better-services","depth":2}],"frontmatter":{"seo":{"title":"Why post-incident reviews matter to Access Worldpay","description":"Just sometimes, something goes wrong. In IT operations, we call this an 'incident'. After high-impact incidents, it's industry best practice to hold Post-Incident Reviews (PIRs)."},"markdown":{"toc":{"hide":true}}},"lastModified":"2025-10-28T16:40:42.000Z","pagePropGetterError":{"message":"","name":""}},"slug":"/products/articles/post-incident-reviews-why-they-matter-to-access-worldpay","userData":{"isAuthenticated":false,"teams":["anonymous"]},"isPublic":true}