Knowella

Risk Assessment Template

A risk assessment records what could cause harm, who could be harmed, what is already in place, and what more is needed. Its recurring failure is not the analysis but the arithmetic: a matrix score becomes the output, the hierarchy of controls is skipped, and the assessment concludes with training and personal protective equipment because those are the controls a safety function can implement alone.

EllaGeneralAssessmentFDN-01253 fields across 9 sectionsFull researchSee the form

Reviewed by Siddarth SinghCSPLast reviewed 16 August 2026

Basis
ISO 31000, ISO 45001 cl.6.1.2
Workspace
General
Form type
Assessment
Review trigger
Change, incident, or the stated interval
Feeds
Controls, training, procedures, monitoring

The short version

  • A risk assessment is required to be suitable and sufficient, not exhaustive. The legal test is whether the significant findings were identified and acted on, not whether the document is long.
  • Risk must be evaluated with existing controls in place, then reassessed with proposed controls added. Assessments that only score the raw hazard produce numbers that describe nothing anyone will experience.
  • The hierarchy of controls is a sequence, not a menu. Elimination, substitution, engineering and administrative controls all rank above personal protective equipment, and an assessment concluding in PPE without the higher levels being considered and documented is the most common substantive failure.
  • ISO 45001 clause 6.1.2 requires hazard identification to be proactive and ongoing, and to cover work organisation, social factors and human factors, not just physical hazards.
  • A matrix score is a communication device, not a conclusion. Two assessors will disagree on likelihood, and the score's value lies in prompting the control decision rather than in its precision.
  • The people who do the job must be consulted. Both ISO 45001 and most national regimes require it, and it is also the only reliable route to knowing how the task is actually performed.

What this is

What is a risk assessment?

What is a risk assessment?

A risk assessment is a structured examination of what in the work could cause harm to people, so that you can weigh whether the precautions already taken are enough or whether more should be done. It identifies hazards, determines who might be harmed and how, evaluates the risk with existing controls in place, records the significant findings, and sets a review point.

Who should carry out a risk assessment?

Someone competent in the process being assessed, working with the people who do the job. Competence here means understanding the work and the hazards rather than holding a qualification in assessment technique. Assessments written by a safety function alone consistently miss the informal methods, workarounds and shortcuts that the actual exposure depends on.

How often should a risk assessment be reviewed?

Whenever something changes that could affect it: a new substance, machine, layout, product, staffing pattern or method; after an incident or near miss; when monitoring shows a control is not working; and at a stated interval regardless. The change triggers matter more than the interval, because they are the ones that make an existing assessment wrong.

Scope

When is a risk assessment required?

Risk assessment is the general instrument, and its most common misuse is being applied where a specific method is legally expected. Where a dedicated assessment exists, a general risk assessment will not satisfy the requirement.

Use this template when

  • A new task, process, substance, machine or work area is being introduced
  • An existing activity has changed materially in method, volume, staffing or environment
  • An incident, near miss or monitoring result suggests the current controls are inadequate
  • A general workplace or activity assessment is required as the foundation for a programme
  • Work is being planned in an area where the hazards are not already covered by an existing assessment

Do not use it for

  • Manual handling tasks, which need a specific assessment such as the NIOSH equation or MAC, since a general score will not quantify the exposure
  • Substances hazardous to health, which require a COSHH-type assessment against the actual method of use
  • Fire, which requires a dedicated fire risk assessment covering means of escape, detection and compartmentation
  • Confined spaces, machinery and energy control, each of which has a specific assessment and a specific standard behind it
  • Display screen equipment, new and expectant mothers and young workers, which carry named assessment duties in several jurisdictions

Compliance mapping

Which ISO 31000 requirements does this satisfy?

Risk assessment is required almost everywhere and prescribed almost nowhere. Most regimes specify that it must be done and be adequate, leaving the method open, which is why the defensibility of an assessment rests on its reasoning rather than its format.

ClauseRequirementWhere it lands
ISO 45001 cl.6.1.2.1Hazard identification proactive and ongoing, covering work organisation, social factors, human factors and past incidentsScope
ISO 45001 cl.6.1.2.2Assessment of OH&S risks with defined methodology and criteria, applied and maintainedMethod
ISO 45001 cl.8.1.2Elimination of hazards and reduction of risk following the hierarchy of controlsControl adequacy
ISO 45001 cl.5.4Consultation and participation of non-managerial workers in hazard identification and risk assessmentReview
HSE MHSWR reg.3Suitable and sufficient assessment, with significant findings recorded where five or more are employedAcceptance
OSHA 5(a)(1)General Duty Clause obligation to address recognised hazards causing or likely to cause serious harmHeader
ISO 45001 cl.6.1.1Consideration of context, interested parties and the scope of the management systemScope
ISO 45001 cl.9.1.1Monitoring and measurement of the effectiveness of controlsReview

What it does not cover

  • Manual handling assessment, which needs a quantified method such as the revised NIOSH equation, MAC or RAPP rather than a general risk score.
  • COSHH or chemical assessment, which must address the substance as used, including quantity, method, duration and ventilation.
  • Fire risk assessment, which is a distinct legal instrument covering escape, detection, compartmentation and management arrangements.
  • Machine risk assessment, which should follow ISO 12100 and address every mode of operation including setting, clearing and cleaning.
  • The control implementation itself, which belongs in work instructions, training records and engineering change, not in the assessment document.

Global

Risk Assessment requirements by country

The duty to assess is close to universal. What differs is whether recording is mandatory, at what employer size, and how prescriptive the regulator is about method.

United States

OSH Act General Duty Clause; standard-specific requirements

No general risk assessment standard. Specific standards require assessment for particular hazards.

Enforcement for unassessed recognised hazards runs through the General Duty Clause, and the absence of a general standard is not an absence of duty.

United Kingdom

Management of Health and Safety at Work Regulations 1999, reg.3

Suitable and sufficient assessment required, with significant findings recorded where five or more are employed.

HSE's five steps are guidance rather than law, but an assessment departing from them needs to explain itself.

European Union

Framework Directive 89/391/EEC

Duty to evaluate risks, with documentation requirements set nationally.

Member state implementations vary in prescriptiveness, and several require assessments in specified formats.

Canada

Provincial OHS regulations

Hazard identification and risk assessment duties, with joint committee involvement in most provinces.

Worker representative participation is frequently a legal requirement rather than good practice.

Australia

Model WHS Act and Regulations

Duty to manage risks so far as reasonably practicable, with assessment required for specified hazards.

Reasonably practicable is defined in the Act and includes cost only where grossly disproportionate to the risk.

International

ISO 45001

Management system requirement with defined methodology and criteria, applied consistently.

Certification auditors examine whether the methodology is defined and whether it was actually followed.

How to complete it

How to complete a risk assessment, step by step

Most assessments are written to a template and scored to a matrix. The parts that determine whether the document is defensible are the ones the template does not prompt for.

Assess the task as performed, not as described

The procedure describes the intended method. The exposure comes from the actual one, including the shortcut taken when the line is running late and the workaround adopted because the designed method is awkward. Watching the task and asking the person doing it is the only reliable route to that, and it is what distinguishes an assessment from a document review.

Evaluate with existing controls in place

Risk should be rated as it stands today, with whatever controls currently exist, then rated again with proposed controls added. Assessments that rate the raw hazard produce a number describing a situation nobody experiences, and assessments that rate the intended future state produce a number that flatters the present one.

Work down the hierarchy explicitly

Record why elimination, substitution and engineering control were rejected before arriving at an administrative control or PPE. That reasoning is the substance of the assessment, and its absence is what makes an assessment indefensible after an incident, because the question asked will be why the higher control was not used.

State the review trigger, not just the review date

An assessment with an annual review date will be wrong the moment the process changes, and right on paper for eleven months. Naming the conditions that invalidate it, new substance, new machine, layout change, staffing change, incident, gives the assessment a way to become due before the calendar says so.

What auditors find

Most common risk assessment findings

Risk assessment findings are unusual in that the document almost always exists. The findings concern what is in it and whether it describes the work.

FindingClauseWhat fixes it
Assessment does not reflect the task as actually performed.ISO 45001 cl.6.1.2.1Observe the task and consult the people who do it; record who was consulted and when.
Hierarchy of controls not applied; assessment concludes in PPE and training.ISO 45001 cl.8.1.2Record why each higher control level was rejected, with the reasoning rather than the conclusion.
Risk rated without existing controls, or rated with proposed controls already assumed.ISO 45001 cl.6.1.2.2Rate current state with existing controls, then residual with proposed controls, as two distinct figures.
Workers not consulted, or consultation not evidenced.ISO 45001 cl.5.4Record participants by name and role; consultation is a requirement, not a courtesy.
Assessment not reviewed after a change to process, substance or layout.ISO 45001 cl.6.1.2.1Link the assessment to management of change so a change raises the review automatically.
Actions arising have no owner or date, or are closed without verification.ISO 45001 cl.8.1.2Assign owner and date at the point the action is raised; verify effectiveness rather than completion.
Generic assessment used where a specific method is required.Standard-specificRoute manual handling, chemical, fire, machinery and confined space to their dedicated assessments.
Human and organisational factors absent: fatigue, workload, shift pattern, competence.ISO 45001 cl.6.1.2.1Include work organisation and human factors explicitly; the standard names them.
Assessment not available to the people doing the work.ISO 45001 cl.7.5.3Communicate significant findings at the workface, in a form usable there.
Methodology and criteria undefined, so scores are inconsistent between assessors.ISO 45001 cl.6.1.2.2Define the methodology and criteria, and calibrate assessors against worked examples.

Case in point

Case in point: the assessment that was correct and useless

A distribution site assessed order picking. The assessment identified manual handling, vehicle movement and working at height from ladders, rated each as medium with existing controls, and concluded with training, high-visibility clothing and a reminder about safe lifting technique. It was reviewed annually and signed by a competent person.

Eighteen months later a picker was struck by a reversing truck in an aisle. The investigation found the aisle had been narrowed nine months earlier to add racking, which removed the pedestrian walkway the assessment had assumed. Nothing in the change to the racking had triggered a review of the assessment, because the racking project was a capital and layout activity and the assessment belonged to safety.

The assessment was not wrong when it was written. It became wrong when the site changed, and there was no mechanism by which a layout change could reach it. The corrective action was not a better assessment; it was linking assessments to management of change so that a layout modification raises the review automatically.

The template

The template, field by field

The form exactly as it installs. Every field, option, score and conditional rule is editable, and the links to other templates come with it.

53fields
9 sections
Reference
FDN-012
Archetype
Assessment
Record ID
RSK-2026-000
Scoring
Inherent, current, residual, target
Direction
High is bad
Singleton
Yes
Basis
ISO 31000, ISO 45001 cl.6.1.2
Links
Linked from every workspace
Tags
Risk
Sections
9
Fields
53
Follow up fields
0
Repeating sections
1
Links out
5
Field typesOwn ID, generated on saveCase thread and parentPick list from a registryLinked to another templateFollow up, dashed outlineScored

Header

6 fields
Text

Risk ID*

Generated on save

Format RSK-2026-00000.

The record's own ID. Other templates point at this value.

Date & Time

Assessment Date*

Text

Case ID

OptionalThread key

Fill only if this assessment follows an incident or finding.

Thread key. Same value across every record in this chain

Single Choice

Parent Type

Optional

What kind of record triggered this assessment.

IncidentNear missFindingAuditInspectionRisk assessmentComplaintEquipment failureNonconformanceManagement of change
Text

Parent ID

OptionalThread key

The ID of the record that triggered this.

Immediate predecessor record

Single Choice

Assessment Trigger*

Why this assessment is being done now.

ComplaintPermit requirementPlant changePeriodicNew installationAfter an incident

Scope

9 fields
Text

Risk Title*

Name the risk in plain language, so it reads sensibly in a register.

Pick List

Site*

From FDN-001 Site NameFilter: Status is Active
Text

Site ID*

Linked

Links to FDN-001 Site ID

Pick List

Task Assessed

OptionalFrom FDN-004 Task Name
Text

Job ID

OptionalLinked

Links to FDN-004 Job Task ID

Pick List

Asset Assessed

OptionalFrom FDN-002 Asset NameFilter: Site matches, Status is Active
Text

Asset ID

OptionalLinked

Links to FDN-002 Asset ID

Single Choice

Hazard Category*

Tags the risk so it can be grouped across the business.

Ammonia releaseFireMajor food safety failureStructural collapseConfined spaceMajor environmental release
Numeric Answer

People Exposed*

How many people this risk could affect.

Method

3 fields
Single Choice

Assessment Method*

Scored

Choose the method that suits the work. All methods normalise to the same enterprise score.

  • Facilitated workshop4 pts
  • Survey based2 pts
  • Desktop0 pts
Text

Method Justification

Optional

Why this method fits this risk.

Info

Assessment Guidance

Image showing the matrix and method guidance. Shown to the assessor while they work.

Inherent risk

4 fields
Single Choice

Inherent Likelihood*

Scored

How likely this is with no controls at all.

  • Almost certain, weekly or more1 pt
  • Likely, monthly2 pts
  • Possible, yearly3 pts
  • Unlikely, every few years4 pts
  • Rare, not known to happen5 pts
Single Choice

Inherent Severity*

Scored

The worst credible outcome, not the most likely one.

  • Catastrophic, multiple fatalities1 pt
  • Major, fatality or permanent disability2 pts
  • Serious, lost time injury3 pts
  • Moderate, medical treatment4 pts
  • Minor, first aid5 pts
Single Choice

Inherent Score*

Scored

Likelihood multiplied by severity, selected from the matrix.

  • 1 to 45 pts
  • 5 to 94 pts
  • 10 to 142 pts
  • 15 to 191 pt
  • 20 to 250 pts
Single Choice

Inherent Band*

Scored

Low, medium, high, very high or extreme.

  • Low, 1 to 45 pts
  • Medium, 5 to 94 pts
  • High, 10 to 142 pts
  • Very high, 15 to 191 pt
  • Extreme, 20 to 250 pts

Controls

Repeats7 fields
Text

Control Description*

What the control is. One row per control.

Single Choice

Control Level*

Scored

Elimination and substitution reduce risk far more than PPE. This is scored to reflect that.

  • Eliminated4 pts
  • Engineering3 pts
  • Aid provided3 pts
  • Administrative1 pt
  • Training only0 pts
Single Choice

Control Status*

Scored

In place, partially in place or planned.

  • In place and working3 pts
  • In place, effectiveness unproven2 pts
  • Partially in place1 pt
  • Planned only0 pts
Checkbox

Critical Control*

Tick if this is the last line of defence against a fatal outcome.

Text

Control ID

OptionalLinked

Fill if this control is on the Critical Control Register.

Links to FDN-011 Control ID

Users

Control Owner*

File Upload

Control Evidence

Optional

Photo showing the control actually in place.

Control adequacy

3 fields
Info

Control Hierarchy Warning

Reminder that administrative controls and PPE alone cannot reduce likelihood by more than one band.

Single Choice

Highest Control Level Applied*

Scored

The strongest control level actually in place.

  • Eliminate4 pts
  • Substitute4 pts
  • Engineer3 pts
  • Separate or isolate3 pts
  • Administrative1 pt
  • PPE0 pts
Single Choice

Control Adequacy*

Scored

Judgement on whether the controls genuinely address the hazard.

  • Fully addresses the hazard3 pts
  • Partially addresses it2 pts
  • Does not address it0 pts

Current and residual risk

10 fields
Single Choice

Current Likelihood*

Scored

With controls as they actually are today, not as designed.

  • Almost certain, weekly or more1 pt
  • Likely, monthly2 pts
  • Possible, yearly3 pts
  • Unlikely, every few years4 pts
  • Rare, not known to happen5 pts
Single Choice

Current Severity*

Scored
  • Catastrophic, multiple fatalities1 pt
  • Major, fatality or permanent disability2 pts
  • Serious, lost time injury3 pts
  • Moderate, medical treatment4 pts
  • Minor, first aid5 pts
Single Choice

Current Score*

Scored
  • 1 to 45 pts
  • 5 to 94 pts
  • 10 to 142 pts
  • 15 to 191 pt
  • 20 to 250 pts
Single Choice

Current Band*

Scored
  • Low, 1 to 45 pts
  • Medium, 5 to 94 pts
  • High, 10 to 142 pts
  • Very high, 15 to 191 pt
  • Extreme, 20 to 250 pts
Single Choice

Residual Likelihood*

Scored

Once all planned controls are fully in place and working.

  • Almost certain, weekly or more1 pt
  • Likely, monthly2 pts
  • Possible, yearly3 pts
  • Unlikely, every few years4 pts
  • Rare, not known to happen5 pts
Single Choice

Residual Severity*

Scored
  • Catastrophic, multiple fatalities1 pt
  • Major, fatality or permanent disability2 pts
  • Serious, lost time injury3 pts
  • Moderate, medical treatment4 pts
  • Minor, first aid5 pts
Single Choice

Residual Score*

Scored
  • 1 to 45 pts
  • 5 to 94 pts
  • 10 to 142 pts
  • 15 to 191 pt
  • 20 to 250 pts
Single Choice

Residual Band*

Scored
  • Low, 1 to 45 pts
  • Medium, 5 to 94 pts
  • High, 10 to 142 pts
  • Very high, 15 to 191 pt
  • Extreme, 20 to 250 pts
Single Choice

Target Score*

Scored

What this risk should get down to. The gap to current drives the action plan.

  • 1 to 45 pts
  • 5 to 94 pts
  • 10 to 142 pts
  • 15 to 191 pt
  • 20 to 250 pts
Text

ALARP Demonstration

Optional

Required where residual risk is 20 or above. Explain why no further reduction is reasonably practicable.

Acceptance

6 fields
Single Choice

Acceptance Authority*

Scored

Set by the residual score. Low risk closes at supervisor level. High risk requires an executive.

  • Supervisor3 pts
  • Site lead2 pts
  • Executive plus ALARP1 pt
Users

Accepted By*

Signature

Acceptance Signature*

Date & Time

Acceptance Date*

Checkbox

Actions Required*

Tick to open CAPA records for the gap between current and target.

Text

Related CAPA ID

OptionalLinked

Links to FDN-014 CAPA ID

Review

5 fields
Single Choice

Review Frequency*

Scored
  • Quarterly3 pts
  • Annually3 pts
  • Every 2 years1 pt
  • None set0 pts
Date & Time

Next Review Due*

Multi Choice

Review Triggers

Optional

Events that force an early review, beyond the scheduled date.

Post incidentPost management of changeRegulatory changeHigh potential near missNew equipment
Users

Assessor*

Text

Assessment Team

Optional

Everyone involved, including the workers who do the task.

FDN-012 · record IDs look like RSK-2026-000 · Linked from every workspace

Open in Knowella

Run it with agents

From a document you fill in to a programme that runs itself

The assessment is a document. What fails is the surrounding machinery: the change that never reached it, the action that closed without verification, and the version at the workface that is two revisions old.

KnowSafe

Holds the assessment library against the register of tasks, areas and equipment, flags assessments whose subject has changed, and routes review to the competent person.

Ella
Ella

Watches management of change, incident and inspection records for events that should invalidate an assessment, and raises the review rather than waiting for the annual date.

KnowTrain

Connects control decisions to the training they depend on, so an administrative control produces a competency requirement rather than an assumption.

KnowErgo

Takes manual handling and posture findings out of the general assessment and into the quantified method they need.

This template lives in Generalcontrol tower. The orchestration layer. Registries and engines every other workspace reads from.

Meet General

Glossary

Risk Assessment definitions and key terms

Hazard
Something with the potential to cause harm: a substance, a machine, a method, a condition, or an aspect of how work is organised.
Risk
The combination of the likelihood that a hazard causes harm and the severity of that harm, evaluated with existing controls in place.
Suitable and sufficient
The legal standard in Great Britain: proportionate to the risk, identifying the significant findings, and reflecting what is reasonably practicable rather than being exhaustive.
Hierarchy of controls
The ranked sequence of control types: elimination, substitution, engineering controls, administrative controls, then personal protective equipment.
Residual risk
The risk remaining once proposed controls are implemented, which is what determines whether the activity should proceed.
Reasonably practicable
A test weighing risk against the time, trouble and cost of controlling it, where cost only prevails if grossly disproportionate to the risk.
Significant finding
A hazard, the controls in place, and any further action needed, which is the content that must be recorded.
Dynamic risk assessment
On-the-spot reassessment when conditions change during a task, which supplements rather than replaces the written assessment.

FAQ

Frequently asked questions about risk assessment

Does a risk assessment have to be written down?+

In Great Britain, where five or more people are employed, the significant findings must be recorded. Under ISO 45001 the results of risk assessment must be maintained as documented information. In the United States there is no general recording requirement, though specific standards impose one. Practically, an unrecorded assessment cannot be communicated, reviewed or defended, so recording is the norm regardless of the minimum.

What does suitable and sufficient mean?+

That the assessment is proportionate to the risk, identifies the significant hazards, considers who could be harmed and how, evaluates existing controls, and identifies further action needed. It does not mean exhaustive. An assessment listing forty trivial hazards and missing the one that kills someone fails the test regardless of length.

Should we assess with or without existing controls?+

With. The current risk is what people are actually exposed to today, and that is the figure that determines whether action is urgent. Rating the raw hazard as though no controls existed produces alarming numbers that describe a situation nobody faces, and it obscures which activities genuinely need attention.

How detailed should the risk matrix be?+

Less detailed than most organisations use. A five by five matrix implies a precision in likelihood estimation that does not exist, and produces arguments about whether something is a three or a four. The matrix should be granular enough to distinguish action thresholds and no more, because the score's function is to prompt a control decision rather than to measure anything.

Who has to be consulted?+

The workers who do the job, and in many jurisdictions their representatives. ISO 45001 requires consultation and participation of non-managerial workers specifically in hazard identification and risk assessment, and most national regimes require consultation with safety representatives. It is also the only practical way to learn how the task is really performed.

When does an assessment become invalid?+

When the thing it describes changes. New equipment, substances, layout, staffing, volumes or methods all invalidate the assumptions, as does an incident revealing a hazard the assessment missed. A stated review interval is a backstop for change nobody noticed, not the primary trigger.

Keep going

Related templates and programmes

Siddarth Singh

Written and reviewed by

Siddarth Singh

Founder & Chief Executive Officer, Knowella

Certified Safety Professional and industrial and systems engineer with more than a decade inside food supply chain, freight and manufacturing operations. This page was written against the current text of the standards it cites, not against secondary summaries of them.

  • Certified Safety Professional (CSP), Board of Certified Safety Professionals
  • MBA, University of Chicago Booth School of Business
  • MS and BS, The Ohio State University, Industrial and Systems Engineering
  • Six Sigma Black Belt
Verify with BCSP →

Sources and last review. Reviewed 16 August 2026 against:

  • ISO 45001:2018 clauses 6.1.2, 8.1.2 and 5.4
  • Management of Health and Safety at Work Regulations 1999, regulation 3 (GB)
  • HSE guidance on risk assessment and the five steps
  • OSH Act Section 5(a)(1), General Duty Clause (US)
  • Framework Directive 89/391/EEC on measures to encourage improvements in safety and health
  • Model WHS Regulations and how to manage work health and safety risks code of practice (Australia)

This page is general guidance, not legal advice. Confirm requirements with your jurisdiction’s regulator.

Start in Minutes, Not Weeks

Launch a Ready-Made Template and Customize It Your Way

Every template is fully editable. Adjust fields, workflows, and branding to match your processes, then deploy to your team instantly.