Summary
In short
- A risk assessment is required to be suitable and sufficient, not exhaustive. The legal test is whether the significant findings were identified and acted on, not whether the document is long.
- Risk must be evaluated with existing controls in place, then reassessed with proposed controls added. Assessments that only score the raw hazard produce numbers that describe nothing anyone will experience.
- The hierarchy of controls is a sequence, not a menu. Elimination, substitution, engineering and administrative controls all rank above personal protective equipment, and an assessment concluding in PPE without the higher levels being considered and documented is the most common substantive failure.
- ISO 45001 clause 6.1.2 requires hazard identification to be proactive and ongoing, and to cover work organisation, social factors and human factors, not just physical hazards.
- A matrix score is a communication device, not a conclusion. Two assessors will disagree on likelihood, and the score's value lies in prompting the control decision rather than in its precision.
- The people who do the job must be consulted. Both ISO 45001 and most national regimes require it, and it is also the only reliable route to knowing how the task is actually performed.
What it is
What it is
What is a risk assessment?
A risk assessment is a structured examination of what in the work could cause harm to people, so that you can weigh whether the precautions already taken are enough or whether more should be done. It identifies hazards, determines who might be harmed and how, evaluates the risk with existing controls in place, records the significant findings, and sets a review point.
Who should carry out a risk assessment?
Someone competent in the process being assessed, working with the people who do the job. Competence here means understanding the work and the hazards rather than holding a qualification in assessment technique. Assessments written by a safety function alone consistently miss the informal methods, workarounds and shortcuts that the actual exposure depends on.
How often should a risk assessment be reviewed?
Whenever something changes that could affect it: a new substance, machine, layout, product, staffing pattern or method; after an incident or near miss; when monitoring shows a control is not working; and at a stated interval regardless. The change triggers matter more than the interval, because they are the ones that make an existing assessment wrong.
When to use it
When to use it, and when not to
Risk assessment is the general instrument, and its most common misuse is being applied where a specific method is legally expected. Where a dedicated assessment exists, a general risk assessment will not satisfy the requirement.
Use it for
- A new task, process, substance, machine or work area is being introduced
- An existing activity has changed materially in method, volume, staffing or environment
- An incident, near miss or monitoring result suggests the current controls are inadequate
- A general workplace or activity assessment is required as the foundation for a programme
- Work is being planned in an area where the hazards are not already covered by an existing assessment
Not for
- Manual handling tasks, which need a specific assessment such as the NIOSH equation or MAC, since a general score will not quantify the exposure
- Substances hazardous to health, which require a COSHH-type assessment against the actual method of use
- Fire, which requires a dedicated fire risk assessment covering means of escape, detection and compartmentation
- Confined spaces, machinery and energy control, each of which has a specific assessment and a specific standard behind it
- Display screen equipment, new and expectant mothers and young workers, which carry named assessment duties in several jurisdictions
Standards
What it is built against
Risk assessment is required almost everywhere and prescribed almost nowhere. Most regimes specify that it must be done and be adequate, leaving the method open, which is why the defensibility of an assessment rests on its reasoning rather than its format.
| Clause | Requirement | Where it lands |
|---|---|---|
| ISO 45001 cl.6.1.2.1 | Hazard identification proactive and ongoing, covering work organisation, social factors, human factors and past incidents | Hazard identification |
| ISO 45001 cl.6.1.2.2 | Assessment of OH&S risks with defined methodology and criteria, applied and maintained | Risk evaluation |
| ISO 45001 cl.8.1.2 | Elimination of hazards and reduction of risk following the hierarchy of controls | Control decision |
| ISO 45001 cl.5.4 | Consultation and participation of non-managerial workers in hazard identification and risk assessment | Consultation record |
| HSE MHSWR reg.3 | Suitable and sufficient assessment, with significant findings recorded where five or more are employed | Significant findings |
| OSHA 5(a)(1) | General Duty Clause obligation to address recognised hazards causing or likely to cause serious harm | Whole record |
| ISO 45001 cl.6.1.1 | Consideration of context, interested parties and the scope of the management system | Scope and context |
| ISO 45001 cl.9.1.1 | Monitoring and measurement of the effectiveness of controls | Review and verification |
What it does not cover
- Manual handling assessment, which needs a quantified method such as the revised NIOSH equation, MAC or RAPP rather than a general risk score.
- COSHH or chemical assessment, which must address the substance as used, including quantity, method, duration and ventilation.
- Fire risk assessment, which is a distinct legal instrument covering escape, detection, compartmentation and management arrangements.
- Machine risk assessment, which should follow ISO 12100 and address every mode of operation including setting, clearing and cleaning.
- The control implementation itself, which belongs in work instructions, training records and engineering change, not in the assessment document.
Filling it in
Filling it in well
Most assessments are written to a template and scored to a matrix. The parts that determine whether the document is defensible are the ones the template does not prompt for.
The procedure describes the intended method. The exposure comes from the actual one, including the shortcut taken when the line is running late and the workaround adopted because the designed method is awkward. Watching the task and asking the person doing it is the only reliable route to that, and it is what distinguishes an assessment from a document review.
Risk should be rated as it stands today, with whatever controls currently exist, then rated again with proposed controls added. Assessments that rate the raw hazard produce a number describing a situation nobody experiences, and assessments that rate the intended future state produce a number that flatters the present one.
Record why elimination, substitution and engineering control were rejected before arriving at an administrative control or PPE. That reasoning is the substance of the assessment, and its absence is what makes an assessment indefensible after an incident, because the question asked will be why the higher control was not used.
An assessment with an annual review date will be wrong the moment the process changes, and right on paper for eleven months. Naming the conditions that invalidate it, new substance, new machine, layout change, staffing change, incident, gives the assessment a way to become due before the calendar says so.
Audit findings
Common audit findings
Risk assessment findings are unusual in that the document almost always exists. The findings concern what is in it and whether it describes the work.
| Finding | Clause | What fixes it |
|---|---|---|
| Assessment does not reflect the task as actually performed. | ISO 45001 cl.6.1.2.1 | Observe the task and consult the people who do it; record who was consulted and when. |
| Hierarchy of controls not applied; assessment concludes in PPE and training. | ISO 45001 cl.8.1.2 | Record why each higher control level was rejected, with the reasoning rather than the conclusion. |
| Risk rated without existing controls, or rated with proposed controls already assumed. | ISO 45001 cl.6.1.2.2 | Rate current state with existing controls, then residual with proposed controls, as two distinct figures. |
| Workers not consulted, or consultation not evidenced. | ISO 45001 cl.5.4 | Record participants by name and role; consultation is a requirement, not a courtesy. |
| Assessment not reviewed after a change to process, substance or layout. | ISO 45001 cl.6.1.2.1 | Link the assessment to management of change so a change raises the review automatically. |
| Actions arising have no owner or date, or are closed without verification. | ISO 45001 cl.8.1.2 | Assign owner and date at the point the action is raised; verify effectiveness rather than completion. |
| Generic assessment used where a specific method is required. | Standard-specific | Route manual handling, chemical, fire, machinery and confined space to their dedicated assessments. |
| Human and organisational factors absent: fatigue, workload, shift pattern, competence. | ISO 45001 cl.6.1.2.1 | Include work organisation and human factors explicitly; the standard names them. |
| Assessment not available to the people doing the work. | ISO 45001 cl.7.5.3 | Communicate significant findings at the workface, in a form usable there. |
| Methodology and criteria undefined, so scores are inconsistent between assessors. | ISO 45001 cl.6.1.2.2 | Define the methodology and criteria, and calibrate assessors against worked examples. |
Worked case
Case in point: the assessment that was correct and useless
A distribution site assessed order picking. The assessment identified manual handling, vehicle movement and working at height from ladders, rated each as medium with existing controls, and concluded with training, high-visibility clothing and a reminder about safe lifting technique. It was reviewed annually and signed by a competent person.
Eighteen months later a picker was struck by a reversing truck in an aisle. The investigation found the aisle had been narrowed nine months earlier to add racking, which removed the pedestrian walkway the assessment had assumed. Nothing in the change to the racking had triggered a review of the assessment, because the racking project was a capital and layout activity and the assessment belonged to safety.
The assessment was not wrong when it was written. It became wrong when the site changed, and there was no mechanism by which a layout change could reach it. The corrective action was not a better assessment; it was linking assessments to management of change so that a layout modification raises the review automatically.
By jurisdiction
How the duty differs by jurisdiction
The duty to assess is close to universal. What differs is whether recording is mandatory, at what employer size, and how prescriptive the regulator is about method.
OSH Act General Duty Clause; standard-specific requirements
No general risk assessment standard. Specific standards require assessment for particular hazards.
Enforcement for unassessed recognised hazards runs through the General Duty Clause, and the absence of a general standard is not an absence of duty.
Management of Health and Safety at Work Regulations 1999, reg.3
Suitable and sufficient assessment required, with significant findings recorded where five or more are employed.
HSE's five steps are guidance rather than law, but an assessment departing from them needs to explain itself.
Framework Directive 89/391/EEC
Duty to evaluate risks, with documentation requirements set nationally.
Member state implementations vary in prescriptiveness, and several require assessments in specified formats.
Provincial OHS regulations
Hazard identification and risk assessment duties, with joint committee involvement in most provinces.
Worker representative participation is frequently a legal requirement rather than good practice.
Model WHS Act and Regulations
Duty to manage risks so far as reasonably practicable, with assessment required for specified hazards.
Reasonably practicable is defined in the Act and includes cost only where grossly disproportionate to the risk.
ISO 45001
Management system requirement with defined methodology and criteria, applied consistently.
Certification auditors examine whether the methodology is defined and whether it was actually followed.
Definitions
Definitions and key terms
- Hazard
- Something with the potential to cause harm: a substance, a machine, a method, a condition, or an aspect of how work is organised.
- Risk
- The combination of the likelihood that a hazard causes harm and the severity of that harm, evaluated with existing controls in place.
- Suitable and sufficient
- The legal standard in Great Britain: proportionate to the risk, identifying the significant findings, and reflecting what is reasonably practicable rather than being exhaustive.
- Hierarchy of controls
- The ranked sequence of control types: elimination, substitution, engineering controls, administrative controls, then personal protective equipment.
- Residual risk
- The risk remaining once proposed controls are implemented, which is what determines whether the activity should proceed.
- Reasonably practicable
- A test weighing risk against the time, trouble and cost of controlling it, where cost only prevails if grossly disproportionate to the risk.
- Significant finding
- A hazard, the controls in place, and any further action needed, which is the content that must be recorded.
- Dynamic risk assessment
- On-the-spot reassessment when conditions change during a task, which supplements rather than replaces the written assessment.
FAQ
Frequently asked questions
Does a risk assessment have to be written down?+
In Great Britain, where five or more people are employed, the significant findings must be recorded. Under ISO 45001 the results of risk assessment must be maintained as documented information. In the United States there is no general recording requirement, though specific standards impose one. Practically, an unrecorded assessment cannot be communicated, reviewed or defended, so recording is the norm regardless of the minimum.
What does suitable and sufficient mean?+
That the assessment is proportionate to the risk, identifies the significant hazards, considers who could be harmed and how, evaluates existing controls, and identifies further action needed. It does not mean exhaustive. An assessment listing forty trivial hazards and missing the one that kills someone fails the test regardless of length.
Should we assess with or without existing controls?+
With. The current risk is what people are actually exposed to today, and that is the figure that determines whether action is urgent. Rating the raw hazard as though no controls existed produces alarming numbers that describe a situation nobody faces, and it obscures which activities genuinely need attention.
How detailed should the risk matrix be?+
Less detailed than most organisations use. A five by five matrix implies a precision in likelihood estimation that does not exist, and produces arguments about whether something is a three or a four. The matrix should be granular enough to distinguish action thresholds and no more, because the score's function is to prompt a control decision rather than to measure anything.
Who has to be consulted?+
The workers who do the job, and in many jurisdictions their representatives. ISO 45001 requires consultation and participation of non-managerial workers specifically in hazard identification and risk assessment, and most national regimes require consultation with safety representatives. It is also the only practical way to learn how the task is really performed.
When does an assessment become invalid?+
When the thing it describes changes. New equipment, substances, layout, staffing, volumes or methods all invalidate the assumptions, as does an incident revealing a hazard the assessment missed. A stated review interval is a backstop for change nobody noticed, not the primary trigger.
The agents
What the agents do with it
The assessment is a document. What fails is the surrounding machinery: the change that never reached it, the action that closed without verification, and the version at the workface that is two revisions old.
Holds the assessment library against the register of tasks, areas and equipment, flags assessments whose subject has changed, and routes review to the competent person.
Watches management of change, incident and inspection records for events that should invalidate an assessment, and raises the review rather than waiting for the annual date.
Connects control decisions to the training they depend on, so an administrative control produces a competency requirement rather than an assumption.
Takes manual handling and posture findings out of the general assessment and into the quantified method they need.
This template lives in General — control tower. The orchestration layer. Registries and engines every other workspace reads from.
Meet General→Sources
Sources
- ISO 45001:2018 clauses 6.1.2, 8.1.2 and 5.4
- Management of Health and Safety at Work Regulations 1999, regulation 3 (GB)
- HSE guidance on risk assessment and the five steps
- OSH Act Section 5(a)(1), General Duty Clause (US)
- Framework Directive 89/391/EEC on measures to encourage improvements in safety and health
- Model WHS Regulations and how to manage work health and safety risks code of practice (Australia)
