What this is
What is a risk assessment?
What is a risk assessment?
A risk assessment is a structured examination of what in the work could cause harm to people, so that you can weigh whether the precautions already taken are enough or whether more should be done. It identifies hazards, determines who might be harmed and how, evaluates the risk with existing controls in place, records the significant findings, and sets a review point.
Who should carry out a risk assessment?
Someone competent in the process being assessed, working with the people who do the job. Competence here means understanding the work and the hazards rather than holding a qualification in assessment technique. Assessments written by a safety function alone consistently miss the informal methods, workarounds and shortcuts that the actual exposure depends on.
How often should a risk assessment be reviewed?
Whenever something changes that could affect it: a new substance, machine, layout, product, staffing pattern or method; after an incident or near miss; when monitoring shows a control is not working; and at a stated interval regardless. The change triggers matter more than the interval, because they are the ones that make an existing assessment wrong.
Scope
When is a risk assessment required?
Risk assessment is the general instrument, and its most common misuse is being applied where a specific method is legally expected. Where a dedicated assessment exists, a general risk assessment will not satisfy the requirement.
Use this template when
- A new task, process, substance, machine or work area is being introduced
- An existing activity has changed materially in method, volume, staffing or environment
- An incident, near miss or monitoring result suggests the current controls are inadequate
- A general workplace or activity assessment is required as the foundation for a programme
- Work is being planned in an area where the hazards are not already covered by an existing assessment
Do not use it for
- Manual handling tasks, which need a specific assessment such as the NIOSH equation or MAC, since a general score will not quantify the exposure
- Substances hazardous to health, which require a COSHH-type assessment against the actual method of use
- Fire, which requires a dedicated fire risk assessment covering means of escape, detection and compartmentation
- Confined spaces, machinery and energy control, each of which has a specific assessment and a specific standard behind it
- Display screen equipment, new and expectant mothers and young workers, which carry named assessment duties in several jurisdictions
Compliance mapping
Which ISO 31000 requirements does this satisfy?
Risk assessment is required almost everywhere and prescribed almost nowhere. Most regimes specify that it must be done and be adequate, leaving the method open, which is why the defensibility of an assessment rests on its reasoning rather than its format.
| Clause | Requirement | Where it lands |
|---|---|---|
| ISO 45001 cl.6.1.2.1 | Hazard identification proactive and ongoing, covering work organisation, social factors, human factors and past incidents | Scope |
| ISO 45001 cl.6.1.2.2 | Assessment of OH&S risks with defined methodology and criteria, applied and maintained | Method |
| ISO 45001 cl.8.1.2 | Elimination of hazards and reduction of risk following the hierarchy of controls | Control adequacy |
| ISO 45001 cl.5.4 | Consultation and participation of non-managerial workers in hazard identification and risk assessment | Review |
| HSE MHSWR reg.3 | Suitable and sufficient assessment, with significant findings recorded where five or more are employed | Acceptance |
| OSHA 5(a)(1) | General Duty Clause obligation to address recognised hazards causing or likely to cause serious harm | Header |
| ISO 45001 cl.6.1.1 | Consideration of context, interested parties and the scope of the management system | Scope |
| ISO 45001 cl.9.1.1 | Monitoring and measurement of the effectiveness of controls | Review |
What it does not cover
- Manual handling assessment, which needs a quantified method such as the revised NIOSH equation, MAC or RAPP rather than a general risk score.
- COSHH or chemical assessment, which must address the substance as used, including quantity, method, duration and ventilation.
- Fire risk assessment, which is a distinct legal instrument covering escape, detection, compartmentation and management arrangements.
- Machine risk assessment, which should follow ISO 12100 and address every mode of operation including setting, clearing and cleaning.
- The control implementation itself, which belongs in work instructions, training records and engineering change, not in the assessment document.
Global
Risk Assessment requirements by country
The duty to assess is close to universal. What differs is whether recording is mandatory, at what employer size, and how prescriptive the regulator is about method.
OSH Act General Duty Clause; standard-specific requirements
No general risk assessment standard. Specific standards require assessment for particular hazards.
Enforcement for unassessed recognised hazards runs through the General Duty Clause, and the absence of a general standard is not an absence of duty.
Management of Health and Safety at Work Regulations 1999, reg.3
Suitable and sufficient assessment required, with significant findings recorded where five or more are employed.
HSE's five steps are guidance rather than law, but an assessment departing from them needs to explain itself.
Framework Directive 89/391/EEC
Duty to evaluate risks, with documentation requirements set nationally.
Member state implementations vary in prescriptiveness, and several require assessments in specified formats.
Provincial OHS regulations
Hazard identification and risk assessment duties, with joint committee involvement in most provinces.
Worker representative participation is frequently a legal requirement rather than good practice.
Model WHS Act and Regulations
Duty to manage risks so far as reasonably practicable, with assessment required for specified hazards.
Reasonably practicable is defined in the Act and includes cost only where grossly disproportionate to the risk.
ISO 45001
Management system requirement with defined methodology and criteria, applied consistently.
Certification auditors examine whether the methodology is defined and whether it was actually followed.
How to complete it
How to complete a risk assessment, step by step
Most assessments are written to a template and scored to a matrix. The parts that determine whether the document is defensible are the ones the template does not prompt for.
The procedure describes the intended method. The exposure comes from the actual one, including the shortcut taken when the line is running late and the workaround adopted because the designed method is awkward. Watching the task and asking the person doing it is the only reliable route to that, and it is what distinguishes an assessment from a document review.
Risk should be rated as it stands today, with whatever controls currently exist, then rated again with proposed controls added. Assessments that rate the raw hazard produce a number describing a situation nobody experiences, and assessments that rate the intended future state produce a number that flatters the present one.
Record why elimination, substitution and engineering control were rejected before arriving at an administrative control or PPE. That reasoning is the substance of the assessment, and its absence is what makes an assessment indefensible after an incident, because the question asked will be why the higher control was not used.
An assessment with an annual review date will be wrong the moment the process changes, and right on paper for eleven months. Naming the conditions that invalidate it, new substance, new machine, layout change, staffing change, incident, gives the assessment a way to become due before the calendar says so.
What auditors find
Most common risk assessment findings
Risk assessment findings are unusual in that the document almost always exists. The findings concern what is in it and whether it describes the work.
| Finding | Clause | What fixes it |
|---|---|---|
| Assessment does not reflect the task as actually performed. | ISO 45001 cl.6.1.2.1 | Observe the task and consult the people who do it; record who was consulted and when. |
| Hierarchy of controls not applied; assessment concludes in PPE and training. | ISO 45001 cl.8.1.2 | Record why each higher control level was rejected, with the reasoning rather than the conclusion. |
| Risk rated without existing controls, or rated with proposed controls already assumed. | ISO 45001 cl.6.1.2.2 | Rate current state with existing controls, then residual with proposed controls, as two distinct figures. |
| Workers not consulted, or consultation not evidenced. | ISO 45001 cl.5.4 | Record participants by name and role; consultation is a requirement, not a courtesy. |
| Assessment not reviewed after a change to process, substance or layout. | ISO 45001 cl.6.1.2.1 | Link the assessment to management of change so a change raises the review automatically. |
| Actions arising have no owner or date, or are closed without verification. | ISO 45001 cl.8.1.2 | Assign owner and date at the point the action is raised; verify effectiveness rather than completion. |
| Generic assessment used where a specific method is required. | Standard-specific | Route manual handling, chemical, fire, machinery and confined space to their dedicated assessments. |
| Human and organisational factors absent: fatigue, workload, shift pattern, competence. | ISO 45001 cl.6.1.2.1 | Include work organisation and human factors explicitly; the standard names them. |
| Assessment not available to the people doing the work. | ISO 45001 cl.7.5.3 | Communicate significant findings at the workface, in a form usable there. |
| Methodology and criteria undefined, so scores are inconsistent between assessors. | ISO 45001 cl.6.1.2.2 | Define the methodology and criteria, and calibrate assessors against worked examples. |
Case in point
Case in point: the assessment that was correct and useless
A distribution site assessed order picking. The assessment identified manual handling, vehicle movement and working at height from ladders, rated each as medium with existing controls, and concluded with training, high-visibility clothing and a reminder about safe lifting technique. It was reviewed annually and signed by a competent person.
Eighteen months later a picker was struck by a reversing truck in an aisle. The investigation found the aisle had been narrowed nine months earlier to add racking, which removed the pedestrian walkway the assessment had assumed. Nothing in the change to the racking had triggered a review of the assessment, because the racking project was a capital and layout activity and the assessment belonged to safety.
The assessment was not wrong when it was written. It became wrong when the site changed, and there was no mechanism by which a layout change could reach it. The corrective action was not a better assessment; it was linking assessments to management of change so that a layout modification raises the review automatically.
The template
The template, field by field
The form exactly as it installs. Every field, option, score and conditional rule is editable, and the links to other templates come with it.
9 sections
- Reference
- FDN-012
- Archetype
- Assessment
- Record ID
- RSK-2026-000
- Scoring
- Inherent, current, residual, target
- Direction
- High is bad
- Singleton
- Yes
- Basis
- ISO 31000, ISO 45001 cl.6.1.2
- Links
- Linked from every workspace
- Tags
- Risk
- Sections
- 9
- Fields
- 53
- Follow up fields
- 0
- Repeating sections
- 1
- Links out
- 5
Header
6 fieldsRisk ID*
Format RSK-2026-00000.
The record's own ID. Other templates point at this value.
Assessment Date*
Case ID
Fill only if this assessment follows an incident or finding.
Thread key. Same value across every record in this chain
Parent Type
What kind of record triggered this assessment.
Parent ID
The ID of the record that triggered this.
Immediate predecessor record
Assessment Trigger*
Why this assessment is being done now.
Scope
9 fieldsRisk Title*
Name the risk in plain language, so it reads sensibly in a register.
Site*
Site ID*
Links to FDN-001 Site ID
Task Assessed
Job ID
Links to FDN-004 Job Task ID
Asset Assessed
Asset ID
Links to FDN-002 Asset ID
Hazard Category*
Tags the risk so it can be grouped across the business.
People Exposed*
How many people this risk could affect.
Method
3 fieldsAssessment Method*
Choose the method that suits the work. All methods normalise to the same enterprise score.
- Facilitated workshop4 pts
- Survey based2 pts
- Desktop0 pts
Method Justification
Why this method fits this risk.
Assessment Guidance
Image showing the matrix and method guidance. Shown to the assessor while they work.
Inherent risk
4 fieldsInherent Likelihood*
How likely this is with no controls at all.
- Almost certain, weekly or more1 pt
- Likely, monthly2 pts
- Possible, yearly3 pts
- Unlikely, every few years4 pts
- Rare, not known to happen5 pts
Inherent Severity*
The worst credible outcome, not the most likely one.
- Catastrophic, multiple fatalities1 pt
- Major, fatality or permanent disability2 pts
- Serious, lost time injury3 pts
- Moderate, medical treatment4 pts
- Minor, first aid5 pts
Inherent Score*
Likelihood multiplied by severity, selected from the matrix.
- 1 to 45 pts
- 5 to 94 pts
- 10 to 142 pts
- 15 to 191 pt
- 20 to 250 pts
Inherent Band*
Low, medium, high, very high or extreme.
- Low, 1 to 45 pts
- Medium, 5 to 94 pts
- High, 10 to 142 pts
- Very high, 15 to 191 pt
- Extreme, 20 to 250 pts
Controls
Repeats7 fieldsControl Description*
What the control is. One row per control.
Control Level*
Elimination and substitution reduce risk far more than PPE. This is scored to reflect that.
- Eliminated4 pts
- Engineering3 pts
- Aid provided3 pts
- Administrative1 pt
- Training only0 pts
Control Status*
In place, partially in place or planned.
- In place and working3 pts
- In place, effectiveness unproven2 pts
- Partially in place1 pt
- Planned only0 pts
Critical Control*
Tick if this is the last line of defence against a fatal outcome.
Control ID
Fill if this control is on the Critical Control Register.
Links to FDN-011 Control ID
Control Owner*
Control Evidence
Photo showing the control actually in place.
Control adequacy
3 fieldsControl Hierarchy Warning
Reminder that administrative controls and PPE alone cannot reduce likelihood by more than one band.
Highest Control Level Applied*
The strongest control level actually in place.
- Eliminate4 pts
- Substitute4 pts
- Engineer3 pts
- Separate or isolate3 pts
- Administrative1 pt
- PPE0 pts
Control Adequacy*
Judgement on whether the controls genuinely address the hazard.
- Fully addresses the hazard3 pts
- Partially addresses it2 pts
- Does not address it0 pts
Current and residual risk
10 fieldsCurrent Likelihood*
With controls as they actually are today, not as designed.
- Almost certain, weekly or more1 pt
- Likely, monthly2 pts
- Possible, yearly3 pts
- Unlikely, every few years4 pts
- Rare, not known to happen5 pts
Current Severity*
- Catastrophic, multiple fatalities1 pt
- Major, fatality or permanent disability2 pts
- Serious, lost time injury3 pts
- Moderate, medical treatment4 pts
- Minor, first aid5 pts
Current Score*
- 1 to 45 pts
- 5 to 94 pts
- 10 to 142 pts
- 15 to 191 pt
- 20 to 250 pts
Current Band*
- Low, 1 to 45 pts
- Medium, 5 to 94 pts
- High, 10 to 142 pts
- Very high, 15 to 191 pt
- Extreme, 20 to 250 pts
Residual Likelihood*
Once all planned controls are fully in place and working.
- Almost certain, weekly or more1 pt
- Likely, monthly2 pts
- Possible, yearly3 pts
- Unlikely, every few years4 pts
- Rare, not known to happen5 pts
Residual Severity*
- Catastrophic, multiple fatalities1 pt
- Major, fatality or permanent disability2 pts
- Serious, lost time injury3 pts
- Moderate, medical treatment4 pts
- Minor, first aid5 pts
Residual Score*
- 1 to 45 pts
- 5 to 94 pts
- 10 to 142 pts
- 15 to 191 pt
- 20 to 250 pts
Residual Band*
- Low, 1 to 45 pts
- Medium, 5 to 94 pts
- High, 10 to 142 pts
- Very high, 15 to 191 pt
- Extreme, 20 to 250 pts
Target Score*
What this risk should get down to. The gap to current drives the action plan.
- 1 to 45 pts
- 5 to 94 pts
- 10 to 142 pts
- 15 to 191 pt
- 20 to 250 pts
ALARP Demonstration
Required where residual risk is 20 or above. Explain why no further reduction is reasonably practicable.
Acceptance
6 fieldsAcceptance Authority*
Set by the residual score. Low risk closes at supervisor level. High risk requires an executive.
- Supervisor3 pts
- Site lead2 pts
- Executive plus ALARP1 pt
Accepted By*
Acceptance Signature*
Acceptance Date*
Actions Required*
Tick to open CAPA records for the gap between current and target.
Related CAPA ID
Links to FDN-014 CAPA ID
Review
5 fieldsReview Frequency*
- Quarterly3 pts
- Annually3 pts
- Every 2 years1 pt
- None set0 pts
Next Review Due*
Review Triggers
Events that force an early review, beyond the scheduled date.
Assessor*
Assessment Team
Everyone involved, including the workers who do the task.
FDN-012 · record IDs look like RSK-2026-000 · Linked from every workspace
Open in KnowellaRun it with agents
From a document you fill in to a programme that runs itself
The assessment is a document. What fails is the surrounding machinery: the change that never reached it, the action that closed without verification, and the version at the workface that is two revisions old.
Holds the assessment library against the register of tasks, areas and equipment, flags assessments whose subject has changed, and routes review to the competent person.

Watches management of change, incident and inspection records for events that should invalidate an assessment, and raises the review rather than waiting for the annual date.
Connects control decisions to the training they depend on, so an administrative control produces a competency requirement rather than an assumption.
Takes manual handling and posture findings out of the general assessment and into the quantified method they need.
This template lives in General — control tower. The orchestration layer. Registries and engines every other workspace reads from.
Meet General→Glossary
Risk Assessment definitions and key terms
- Hazard
- Something with the potential to cause harm: a substance, a machine, a method, a condition, or an aspect of how work is organised.
- Risk
- The combination of the likelihood that a hazard causes harm and the severity of that harm, evaluated with existing controls in place.
- Suitable and sufficient
- The legal standard in Great Britain: proportionate to the risk, identifying the significant findings, and reflecting what is reasonably practicable rather than being exhaustive.
- Hierarchy of controls
- The ranked sequence of control types: elimination, substitution, engineering controls, administrative controls, then personal protective equipment.
- Residual risk
- The risk remaining once proposed controls are implemented, which is what determines whether the activity should proceed.
- Reasonably practicable
- A test weighing risk against the time, trouble and cost of controlling it, where cost only prevails if grossly disproportionate to the risk.
- Significant finding
- A hazard, the controls in place, and any further action needed, which is the content that must be recorded.
- Dynamic risk assessment
- On-the-spot reassessment when conditions change during a task, which supplements rather than replaces the written assessment.
FAQ
Frequently asked questions about risk assessment
Does a risk assessment have to be written down?+
In Great Britain, where five or more people are employed, the significant findings must be recorded. Under ISO 45001 the results of risk assessment must be maintained as documented information. In the United States there is no general recording requirement, though specific standards impose one. Practically, an unrecorded assessment cannot be communicated, reviewed or defended, so recording is the norm regardless of the minimum.
What does suitable and sufficient mean?+
That the assessment is proportionate to the risk, identifies the significant hazards, considers who could be harmed and how, evaluates existing controls, and identifies further action needed. It does not mean exhaustive. An assessment listing forty trivial hazards and missing the one that kills someone fails the test regardless of length.
Should we assess with or without existing controls?+
With. The current risk is what people are actually exposed to today, and that is the figure that determines whether action is urgent. Rating the raw hazard as though no controls existed produces alarming numbers that describe a situation nobody faces, and it obscures which activities genuinely need attention.
How detailed should the risk matrix be?+
Less detailed than most organisations use. A five by five matrix implies a precision in likelihood estimation that does not exist, and produces arguments about whether something is a three or a four. The matrix should be granular enough to distinguish action thresholds and no more, because the score's function is to prompt a control decision rather than to measure anything.
Who has to be consulted?+
The workers who do the job, and in many jurisdictions their representatives. ISO 45001 requires consultation and participation of non-managerial workers specifically in hazard identification and risk assessment, and most national regimes require consultation with safety representatives. It is also the only practical way to learn how the task is really performed.
When does an assessment become invalid?+
When the thing it describes changes. New equipment, substances, layout, staffing, volumes or methods all invalidate the assumptions, as does an incident revealing a hazard the assessment missed. A stated review interval is a backstop for change nobody noticed, not the primary trigger.
Keep going
Related templates and programmes
Industries this is written for
Programmes this belongs to
Used together in Critical Control and Fatal Risk
Bow Tie Analysis Record
Maps threats, the top event, consequences and the barriers on each side for a major hazard
Barrier Health Review
Reviews whether the barriers relied on in a bow tie are actually in place and working
Critical Control Register
Lists the controls that stand between your people and a fatal or catastrophic event, with an owner and a required check frequency for each
Serious Potential Incident Report
Used when an event could have killed or seriously injured someone, whatever the actual outcome
Job Safety Analysis
Breaks a job into steps, finds the hazards in each and sets the controls
Pre-Task Risk Assessment
A short check done by the crew right before work starts, covering what has changed today
More in Engines
Root Cause Analysis
Finds out why something happened rather than who was involved
Corrective and Preventive Action
The single action record used everywhere
Finding
Records a single deficiency picked up during an audit, inspection or check
Effectiveness Verification
Checks whether an action actually worked, some time after it was put in place
Just Culture Determination
Separates a system problem from a genuine choice to take a risk, using a consistent set of questions
Extent of Condition Review
Asks two questions after an investigation: where else does this same condition exist, and where else could this same cause bite us
Written and reviewed by
Siddarth Singh
Founder & Chief Executive Officer, Knowella
Certified Safety Professional and industrial and systems engineer with more than a decade inside food supply chain, freight and manufacturing operations. This page was written against the current text of the standards it cites, not against secondary summaries of them.
- Certified Safety Professional (CSP), Board of Certified Safety Professionals
- MBA, University of Chicago Booth School of Business
- MS and BS, The Ohio State University, Industrial and Systems Engineering
- Six Sigma Black Belt
Sources and last review. Reviewed 16 August 2026 against:
- ISO 45001:2018 clauses 6.1.2, 8.1.2 and 5.4
- Management of Health and Safety at Work Regulations 1999, regulation 3 (GB)
- HSE guidance on risk assessment and the five steps
- OSH Act Section 5(a)(1), General Duty Clause (US)
- Framework Directive 89/391/EEC on measures to encourage improvements in safety and health
- Model WHS Regulations and how to manage work health and safety risks code of practice (Australia)
This page is general guidance, not legal advice. Confirm requirements with your jurisdiction’s regulator.