Knowella

Security Risk Assessment Template

Security assessments default to the perimeter because the perimeter is visible and buyable. The threats that produce actual harm are mostly inside it: aggression toward staff from people who are supposed to be there, and access by someone with a legitimate reason to be on site.

KnowSafeAssessmentSAF-142Pinned in navigationFull guide
Covers
People, premises, product, information
Bias to correct
Outward-facing controls

Summary

In short

  • The insider is the design case for most operational security exposures, and perimeter controls do not constrain someone with legitimate access.
  • Workplace violence toward staff is now a regulated subject in a growing number of jurisdictions rather than a general duty matter.
  • California's SB 553 requires most employers with any California location to hold a written workplace violence prevention plan, a violent incident log and annual training, in force since July 2024, with penalties for serious violations reaching into five figures.
  • There is no exemption for organisations headquartered elsewhere. Any California location brings the obligation.
  • Cal/OSHA was directed to propose a general industry workplace violence standard by December 2025 with adoption due by the end of 2026, while federal rulemaking has not produced a proposed rule.
  • Assessment should cover people first, then product and premises. Most assessments run that order backwards.

What it is

What it is

What is a security risk assessment?

An assessment of threats to people, premises, product and information, the controls in place, and the gaps between them. In an operational setting it spans workplace violence toward staff, unauthorised access, theft and, where food or pharmaceutical product is handled, deliberate contamination.

How does it relate to food defense?

Food defense under the FSMA Intentional Adulteration rule is a specific regime addressing deliberate contamination intended to cause wide-scale public health harm, organised around actionable process steps. A general security assessment is broader and does not satisfy it. Where both apply, they should reference each other rather than merge.

When to use it

When to use it, and when not to

This assessment covers security threats across people, premises, product and information. Specific regimes sit alongside it.

Use it for

  • Threats to staff including aggression from the public, service users, contractors and colleagues
  • Unauthorised access to premises, restricted areas and vehicles
  • Theft of product, equipment, materials and data
  • Site security supporting food defense, where a separate plan is also required
  • Following an incident, a threat, or a change to site layout, occupancy or operating hours

Not for

  • The food defense plan under 21 CFR Part 121, which is a distinct regime organised around actionable process steps
  • The workplace violence prevention plan, which in California has prescribed content and its own log
  • Information security risk assessment, which addresses systems and data with its own methodology
  • Lone working assessment, which addresses a specific exposure this may reference
  • Physical access control administration, which implements the conclusions rather than reaching them

Standards

What it is built against

Security spans an occupational safety duty, a fast-moving workplace violence regime, and product-specific requirements where food or pharmaceuticals are handled.

ClauseRequirementWhere it lands
ISO 45001 cl.6.1.2Hazard identification including violence and work organisation factorsThreats considered
Cal Labor Code 6401.9Written workplace violence prevention plan, violent incident log, training and post-incident investigationControls in place
OSHA General Duty ClauseDuty to address recognised hazards including workplace violence where feasible controls existThreats considered
21 CFR Part 121Food defense plan with vulnerability assessment and mitigation strategies, where the IA rule appliesControls in place
GFSI schemesSite security and food defense requirements including access control and visitor managementControls in place
CTPATSupply chain security criteria including yard security, seal verification and container inspectionControls in place
ISO 27001 A.7Physical entry controls, securing offices and facilities, and working in secure areasControls in place
ISO 45001 cl.8.2Emergency preparedness covering security incidents alongside other emergenciesOutcome

What it does not cover

  • The food defense plan under the Intentional Adulteration rule, which is a distinct regime with its own required components.
  • The workplace violence prevention plan, which where required has prescribed content, training and a separate incident log.
  • Information security risk assessment, which addresses systems, data and access with a different methodology.
  • Access control administration, which implements the conclusions rather than producing them.
  • Lone working assessment, which covers a specific exposure this assessment should reference.

Filling it in

Filling it in well

Order matters here more than in most assessments, because the default order produces the wrong controls.

Assess people before premises

Start with who is exposed to aggression, when, and with what support available. Counter staff, drivers, home visitors, night shift, lone workers and anyone handling refusals or enforcement. Premises and product follow. Assessments that start with the building reliably conclude with cameras and gates and leave the front desk unaddressed.

Map who can reach what

For each restricted area, who holds access, why, and when it was last reviewed. Access accumulates through role changes and project work and is almost never removed. The list of people who can reach the most sensitive area of a site is usually longer than anyone expects and older than anyone realises.

Include contractors, drivers and visitors

They are on site, frequently unescorted, and outside the induction and access systems that cover employees. In yards, delivery drivers are alone with vehicles and product for extended periods. Any assessment omitting them has left out the population with the most access and the least oversight.

Connect to the plans that have prescribed content

Where a workplace violence prevention plan or a food defense plan is required, this assessment should feed them and reference them, not attempt to be them. Both have specified components and retention requirements that a general security assessment does not satisfy.

Audit findings

Common audit findings

Security findings concentrate on the inside of the fence.

FindingClauseWhat fixes it
Assessment addresses perimeter only, with no aggression exposure assessed.ISO 45001 cl.6.1.2Assess people first; the perimeter does not constrain someone already inside.
California location without a written workplace violence prevention plan.Cal Labor Code 6401.9Required since July 2024; there is no exemption for out-of-state headquarters.
Violent incident log absent or missing required fields.Cal Labor Code 6401.9Maintain with the prescribed content, retained five years and viewable by employees on request.
Access lists not reviewed, with former employees or completed projects still holding access.ISO 27001 A.7Review on a cycle and on role change; access accumulates and is never removed by default.
Contractors and delivery drivers outside the assessment scope.ISO 45001 cl.8.1.4Include them; they have the most access and the least oversight.
General security assessment presented as a food defense plan.21 CFR Part 121They are different regimes; the IA rule requires specific components a security assessment does not contain.
No de-escalation training for roles exposed to aggression.Cal Labor Code 6401.9Train the exposed roles; where a plan is required, training is a specified element.
Incidents not recorded because no injury resulted.Cal Labor Code 6401.9Log every violent incident regardless of injury; that is the requirement and the trend data.
Assessment not reviewed after a change to hours, layout or occupancy.ISO 45001 cl.6.1.2Extended hours and layout changes alter exposure; treat both as triggers.
Staff not consulted on which situations feel unsafe.ISO 45001 cl.5.4Ask; the people at the counter know which interactions escalate.

Worked case

Case in point: the regime that arrived without being noticed

California's SB 553 took effect on 1 July 2024, adding Labor Code section 6401.9. It requires nearly all California employers to establish, implement and maintain a written workplace violence prevention plan, keep a violent incident log with prescribed fields, provide initial and annual training, investigate incidents, and retain hazard and incident records for five years and training records for one year.

The exemptions are narrow: worksites with fewer than ten employees not open to the public, employees teleworking from a location of their own choosing, healthcare settings covered by a separate Cal/OSHA standard, and certain law enforcement and corrections facilities. There is no exemption based on where the organisation is headquartered.

Cal/OSHA was directed to propose a general industry standard by December 2025, with the standards board due to adopt one by the end of 2026. Federal OSHA convened a small business panel in 2023 but had not published a proposed rule as of early 2026.

Definitions

Definitions and key terms

Workplace violence
Any act or threat of physical violence, harassment, intimidation or other threatening behaviour at the worksite.
Violent incident log
A record of every workplace violence incident with prescribed fields, retained five years in California, with identifying details omitted.
Insider threat
Risk from someone with legitimate access, which perimeter controls do not address.
Actionable process step
Under the food defense regime, a point where a significant vulnerability exists and mitigation can be applied.
Escorted access
A control requiring a visitor or contractor to be accompanied within defined areas, only effective where the escort is available.
Access review
Periodic confirmation that each person holding access still requires it, without which access accumulates indefinitely.
De-escalation
Technique for reducing the intensity of a confrontation, a specified training element where a violence prevention plan is required.
Post-incident investigation
Review following a violent incident, required as a plan element and distinct from a general incident investigation.

FAQ

Frequently asked questions

Does a security assessment satisfy food defense requirements?+

No. The Intentional Adulteration rule at 21 CFR Part 121 requires a specific set of components: a vulnerability assessment identifying actionable process steps with reasoning recorded either way, mitigation strategies, monitoring, corrective action and verification. A general security assessment contains none of those in the required form, though it should feed and reference the food defense plan.

Who does California's SB 553 apply to?+

Nearly all California employers, with narrow exemptions: worksites with fewer than ten employees not open to the public, employees teleworking from a location of their own choosing, healthcare settings under the separate Cal/OSHA standard, and certain law enforcement and corrections facilities. There is no exemption based on headquarters location, so any California site brings the obligation.

What must be in the violent incident log?+

The date, time and location, a description of the incident, its classification, the type of violence, the consequences and actions taken, and who completed the log, with personal identifying information omitted. It is retained five years and employees may view and copy it within fifteen calendar days of a request.

Why start with people rather than premises?+

Because the threats that most often materialise involve someone already inside: aggression at a counter, a contractor with unescorted access, a driver alone in a yard. Perimeter controls do not address any of them. Assessments that begin with the building reliably conclude with cameras and leave the exposed roles unaddressed.

Should incidents without injury be recorded?+

Yes. Where a violence prevention plan is required the log covers every incident regardless of whether injury resulted, and even where it is not required, threats and near misses are the leading data. Recording only injuries produces a log that describes outcomes rather than exposure.

The agents

What the agents do with it

The assessment covers four domains. What fails is the access list nobody reviewed and the aggression exposure nobody assessed.

KnowSafe

Holds the assessment across people, premises and product, and links exposed roles to training and to the incident log where one is required.

KnowContractor

Brings contractors, drivers and visitors into scope, with access tied to the work and expiring when it completes.

Ella

Reviews access lists on a cycle and on role change, since access accumulates through project work and is rarely removed.

KnowQuality

Connects site security to the food defense plan where the Intentional Adulteration rule applies, keeping the two distinct but linked.

This template lives in KnowSafesafety and compliance. Incidents, hazards, permits, inspections and the critical controls behind them.

Meet KnowSafe

Sources

Sources

KnowSafe

Also in Security and Lone Working

6Browse the whole library
Assessment

Violence and Aggression Assessment

Assesses roles exposed to aggression from the public, hauliers or colleagues, and the controls in place. Carried out for each exposed role. Completed by safety with the people doing the job. Aggression is a psychosocial hazard with a physical outcome.

Assessment

Lone Working Risk Assessment

Assesses tasks done alone, out of hours or out of sight, and how the person would raise an alarm. Carried out per task. Completed by the supervisor with safety. Most lone working controls fail because nobody tested whether the alarm actually reaches anybody.

Record

Lone Worker Check In Record

Records the agreed contact points during a period of lone working, and that each one happened. Completed for every lone working shift. Kept by the nominated contact. A missed check in starts an escalation, not a shrug.

Record

Security Incident Investigation

Records theft, break in, unauthorised access, tampering or threat. Raised as soon as the situation is safe. Completed by whoever discovered it. Handled with care over who can see it, and separated from the safety incident stream where needed.

Review

Access Control Review

Reviews who holds access to which areas and whether that is still justified. Run every six months. Carried out by security with area owners. Access granted for a project three years ago is the most common finding.

Review

CCTV and Monitoring Review

Reviews camera coverage, recording retention, image quality and who can view footage. Run yearly. Carried out by security with the privacy owner. Coverage that does not work in the dark is coverage on paper only.

Start in Minutes, Not Weeks

Launch a Ready-Made Template and Customize It Your Way

Every template is fully editable. Adjust fields, workflows, and branding to match your processes, then deploy to your team instantly.