Knowella

Security Risk Assessment Template

Security assessments default to the perimeter because the perimeter is visible and buyable. The threats that produce actual harm are mostly inside it: aggression toward staff from people who are supposed to be there, and access by someone with a legitimate reason to be on site.

KnowSafeAssessmentSAF-142Pinned in navigation46 fields across 4 sectionsFull researchSee the form

Reviewed by Siddarth SinghCSPLast reviewed 16 August 2026

Basis
ISO 45001 cl.6.1.2
Workspace
KnowSafe
Form type
Assessment
Covers
People, premises, product, information
Bias to correct
Outward-facing controls

The short version

  • The insider is the design case for most operational security exposures, and perimeter controls do not constrain someone with legitimate access.
  • Workplace violence toward staff is now a regulated subject in a growing number of jurisdictions rather than a general duty matter.
  • California's SB 553 requires most employers with any California location to hold a written workplace violence prevention plan, a violent incident log and annual training, in force since July 2024, with penalties for serious violations reaching into five figures.
  • There is no exemption for organisations headquartered elsewhere. Any California location brings the obligation.
  • Cal/OSHA was directed to propose a general industry workplace violence standard by December 2025 with adoption due by the end of 2026, while federal rulemaking has not produced a proposed rule.
  • Assessment should cover people first, then product and premises. Most assessments run that order backwards.

What this is

What is a security risk assessment?

What is a security risk assessment?

An assessment of threats to people, premises, product and information, the controls in place, and the gaps between them. In an operational setting it spans workplace violence toward staff, unauthorised access, theft and, where food or pharmaceutical product is handled, deliberate contamination.

How does it relate to food defense?

Food defense under the FSMA Intentional Adulteration rule is a specific regime addressing deliberate contamination intended to cause wide-scale public health harm, organised around actionable process steps. A general security assessment is broader and does not satisfy it. Where both apply, they should reference each other rather than merge.

Scope

When is a security risk assessment required?

This assessment covers security threats across people, premises, product and information. Specific regimes sit alongside it.

Use this template when

  • Threats to staff including aggression from the public, service users, contractors and colleagues
  • Unauthorised access to premises, restricted areas and vehicles
  • Theft of product, equipment, materials and data
  • Site security supporting food defense, where a separate plan is also required
  • Following an incident, a threat, or a change to site layout, occupancy or operating hours

Do not use it for

  • The food defense plan under 21 CFR Part 121, which is a distinct regime organised around actionable process steps
  • The workplace violence prevention plan, which in California has prescribed content and its own log
  • Information security risk assessment, which addresses systems and data with its own methodology
  • Lone working assessment, which addresses a specific exposure this may reference
  • Physical access control administration, which implements the conclusions rather than reaching them

Compliance mapping

Which ISO 45001 cl.6.1.2 requirements does this satisfy?

Security spans an occupational safety duty, a fast-moving workplace violence regime, and product-specific requirements where food or pharmaceuticals are handled.

ClauseRequirementWhere it lands
ISO 45001 cl.6.1.2Hazard identification including violence and work organisation factorsThreats considered
Cal Labor Code 6401.9Written workplace violence prevention plan, violent incident log, training and post-incident investigationControls in place
OSHA General Duty ClauseDuty to address recognised hazards including workplace violence where feasible controls existThreats considered
21 CFR Part 121Food defense plan with vulnerability assessment and mitigation strategies, where the IA rule appliesControls in place
GFSI schemesSite security and food defense requirements including access control and visitor managementControls in place
CTPATSupply chain security criteria including yard security, seal verification and container inspectionControls in place
ISO 27001 A.7Physical entry controls, securing offices and facilities, and working in secure areasControls in place
ISO 45001 cl.8.2Emergency preparedness covering security incidents alongside other emergenciesOutcome

What it does not cover

  • The food defense plan under the Intentional Adulteration rule, which is a distinct regime with its own required components.
  • The workplace violence prevention plan, which where required has prescribed content, training and a separate incident log.
  • Information security risk assessment, which addresses systems, data and access with a different methodology.
  • Access control administration, which implements the conclusions rather than producing them.
  • Lone working assessment, which covers a specific exposure this assessment should reference.

How to complete it

How to complete a security risk assessment, step by step

Order matters here more than in most assessments, because the default order produces the wrong controls.

Assess people before premises

Start with who is exposed to aggression, when, and with what support available. Counter staff, drivers, home visitors, night shift, lone workers and anyone handling refusals or enforcement. Premises and product follow. Assessments that start with the building reliably conclude with cameras and gates and leave the front desk unaddressed.

Map who can reach what

For each restricted area, who holds access, why, and when it was last reviewed. Access accumulates through role changes and project work and is almost never removed. The list of people who can reach the most sensitive area of a site is usually longer than anyone expects and older than anyone realises.

Include contractors, drivers and visitors

They are on site, frequently unescorted, and outside the induction and access systems that cover employees. In yards, delivery drivers are alone with vehicles and product for extended periods. Any assessment omitting them has left out the population with the most access and the least oversight.

Connect to the plans that have prescribed content

Where a workplace violence prevention plan or a food defense plan is required, this assessment should feed them and reference them, not attempt to be them. Both have specified components and retention requirements that a general security assessment does not satisfy.

What auditors find

Most common security risk assessment findings

Security findings concentrate on the inside of the fence.

FindingClauseWhat fixes it
Assessment addresses perimeter only, with no aggression exposure assessed.ISO 45001 cl.6.1.2Assess people first; the perimeter does not constrain someone already inside.
California location without a written workplace violence prevention plan.Cal Labor Code 6401.9Required since July 2024; there is no exemption for out-of-state headquarters.
Violent incident log absent or missing required fields.Cal Labor Code 6401.9Maintain with the prescribed content, retained five years and viewable by employees on request.
Access lists not reviewed, with former employees or completed projects still holding access.ISO 27001 A.7Review on a cycle and on role change; access accumulates and is never removed by default.
Contractors and delivery drivers outside the assessment scope.ISO 45001 cl.8.1.4Include them; they have the most access and the least oversight.
General security assessment presented as a food defense plan.21 CFR Part 121They are different regimes; the IA rule requires specific components a security assessment does not contain.
No de-escalation training for roles exposed to aggression.Cal Labor Code 6401.9Train the exposed roles; where a plan is required, training is a specified element.
Incidents not recorded because no injury resulted.Cal Labor Code 6401.9Log every violent incident regardless of injury; that is the requirement and the trend data.
Assessment not reviewed after a change to hours, layout or occupancy.ISO 45001 cl.6.1.2Extended hours and layout changes alter exposure; treat both as triggers.
Staff not consulted on which situations feel unsafe.ISO 45001 cl.5.4Ask; the people at the counter know which interactions escalate.

Case in point

Case in point: the regime that arrived without being noticed

California's SB 553 took effect on 1 July 2024, adding Labor Code section 6401.9. It requires nearly all California employers to establish, implement and maintain a written workplace violence prevention plan, keep a violent incident log with prescribed fields, provide initial and annual training, investigate incidents, and retain hazard and incident records for five years and training records for one year.

The exemptions are narrow: worksites with fewer than ten employees not open to the public, employees teleworking from a location of their own choosing, healthcare settings covered by a separate Cal/OSHA standard, and certain law enforcement and corrections facilities. There is no exemption based on where the organisation is headquartered.

Cal/OSHA was directed to propose a general industry standard by December 2025, with the standards board due to adopt one by the end of 2026. Federal OSHA convened a small business panel in 2023 but had not published a proposed rule as of early 2026.

The template

The template, field by field

The form exactly as it installs. Every field, option, score and conditional rule is editable, and the links to other templates come with it.

46fields
4 sections
Reference
SAF-142
Archetype
Assessment
Record ID
SRA-2026-000
Scoring
Residual band
Direction
Low is good
Singleton
Yes
Basis
ISO 45001 cl.6.1.2
Links
Links Food defense, Access control
Tags
Security
Sections
4
Fields
46
Follow up fields
3
Repeating sections
0
Links out
3
Field typesOwn ID, generated on saveCase thread and parentPick list from a registryLinked to another templateFollow up, dashed outlineScored

Header

10 fields
Text

Assessment ID*

Generated on save

Auto sequence. Format SRA-2026-000.

The record's own ID. Other templates point at this value.

Single Choice

Status*

Scored

Drives who this goes to next.

  • Planned2 pts
  • In progress2 pts
  • Complete3 pts
  • Deferred0 pts
  • Open0 pts
  • Closed3 pts
  • Overdue0 pts
Date & Time

Date and Time*

Users

Completed By*

Pick List

Site*

From FDN-001 Site NameFilter: Status is Active
Text

Site ID*

Linked

Format SITE-000.

Links to FDN-001 Site ID

Info

Security And Food Defense Are The Same Assessment

On a food site, the person who can get in unnoticed can also contaminate product. Assess both together rather than running two overlapping exercises.

Single Choice

Assessment Trigger*

ComplaintPermit requirementPlant changePeriodicNew installationAfter an incident
Users

Assessor*

Single Choice

Scope*

Whole siteSingle areaSingle processAll sites

Threats considered

9 fields
Single Choice

Theft Of Product*

Scored
  • Low3 pts
  • Medium1 pt
  • High0 pts
Single Choice

Theft Of Equipment Or Fuel*

Scored
  • Low3 pts
  • Medium1 pt
  • High0 pts
Single Choice

Unauthorised Access*

Scored
  • Low3 pts
  • Medium1 pt
  • High0 pts
Single Choice

Deliberate Product Contamination*

Scored
  • Not credible4 pts
  • Low3 pts
  • Medium1 pt
  • High0 pts
Single Choice

Sabotage Of Plant*

Scored
  • Not credible4 pts
  • Low3 pts
  • Medium1 pt
  • High0 pts
Single Choice

Insider Threat*

Scored

The hardest to control and the most commonly ignored. Access, supervision and grievance handling all matter here.

  • Not credible4 pts
  • Low3 pts
  • Medium1 pt
  • High0 pts
Single Choice

Cargo Theft In Transit

OptionalScored
  • Not credible4 pts
  • Low3 pts
  • Medium1 pt
  • High0 pts
Single Choice

Trespass Or Protest

OptionalScored
  • Not credible4 pts
  • Low3 pts
  • Medium1 pt
  • High0 pts
Single Choice

Cyber Enabled Physical Impact

OptionalScored
  • Not credible4 pts
  • Low3 pts
  • Medium1 pt
  • High0 pts

Controls in place

12 fields
Single Choice

Perimeter Secure*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

Access Controlled At Entry Points*

Scored
  • All points3 pts
  • Some1 pt
  • None0 pts
Single Choice

Visitor Handling Controlled*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

Restricted Areas Defined And Enforced*

Scored
  • Yes3 pts
  • Defined not enforced1 pt
  • No0 pts
Single Choice

Key And Code Control*

Scored
  • Documented and current3 pts
  • Informal1 pt
  • None0 pts
Single Choice

CCTV Coverage Adequate*

Scored
  • Yes3 pts
  • Partial1 pt
  • None0 pts
Single Choice

Recruitment Screening Applied*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

Contractor And Agency Screening*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

Out Of Hours Arrangements*

Scored
  • Robust3 pts
  • Basic1 pt
  • None0 pts
Single Choice

Ingredient And Water Points Protected*

Scored

Open silos, bulk intake and water tanks are the food defense points that matter most.

  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

Tamper Evidence On Product

OptionalScored
  • Yes3 pts
  • Not applicable3 pts
  • No0 pts
Single Choice

Reporting Route For Concerns*

Scored
  • Yes3 pts
  • Informal1 pt
  • None0 pts

Outcome

15 fields
Single Choice

Highest Control Level Applied*

Scored
  • Eliminate4 pts
  • Substitute4 pts
  • Engineer3 pts
  • Separate or isolate3 pts
  • Administrative1 pt
  • PPE0 pts
Single Choice

Residual Band*

Scored
  • Low, 1 to 45 pts
  • Medium, 5 to 94 pts
  • High, 10 to 142 pts
  • Very high, 15 to 191 pt
  • Extreme, 20 to 250 pts
Single Choice

Risk Acceptable*

Scored
  • Yes3 pts
  • Marginal1 pt
  • No0 pts
Text

Further Controls Required

Optional
Pick List

Risk Assessment

OptionalFrom FDN-012 Risk Title
Text

Risk ID

OptionalLinked

Format RSK-2026-00000.

Links to FDN-012 Risk ID

Single Choice

Action Required*

Scored

Raise the action record, then enter its reference here.

  • No2 pts
  • Yes0 pts
Single Choice

Priority

OptionalScoredShows if Action Required equals Yes
  • High0 pts
  • Medium1 pt
  • Low3 pts
Text

CAPA ID

OptionalLinkedShows if Action Required equals Yes

Format CAPA-2026-00000.

Links to FDN-014 CAPA ID

Users

Action Owner

OptionalShows if Action Required equals Yes
Date & Time

Next Review Due*

Users

Assessor*

Signature

Signature*

Users

Site Manager*

Signature

Second Signature*

SAF-142 · record IDs look like SRA-2026-000 · Links Food defense, Access control

Open in Knowella

Run it with agents

From a document you fill in to a programme that runs itself

The assessment covers four domains. What fails is the access list nobody reviewed and the aggression exposure nobody assessed.

KnowSafe

Holds the assessment across people, premises and product, and links exposed roles to training and to the incident log where one is required.

KnowContractor

Brings contractors, drivers and visitors into scope, with access tied to the work and expiring when it completes.

Ella
Ella

Reviews access lists on a cycle and on role change, since access accumulates through project work and is rarely removed.

KnowQuality

Connects site security to the food defense plan where the Intentional Adulteration rule applies, keeping the two distinct but linked.

This template lives in KnowSafe — safety and compliance. Incidents, hazards, permits, inspections and the critical controls behind them.

Meet KnowSafe→

Glossary

Security Risk Assessment definitions and key terms

Workplace violence
Any act or threat of physical violence, harassment, intimidation or other threatening behaviour at the worksite.
Violent incident log
A record of every workplace violence incident with prescribed fields, retained five years in California, with identifying details omitted.
Insider threat
Risk from someone with legitimate access, which perimeter controls do not address.
Actionable process step
Under the food defense regime, a point where a significant vulnerability exists and mitigation can be applied.
Escorted access
A control requiring a visitor or contractor to be accompanied within defined areas, only effective where the escort is available.
Access review
Periodic confirmation that each person holding access still requires it, without which access accumulates indefinitely.
De-escalation
Technique for reducing the intensity of a confrontation, a specified training element where a violence prevention plan is required.
Post-incident investigation
Review following a violent incident, required as a plan element and distinct from a general incident investigation.

FAQ

Frequently asked questions about security risk assessment

Does a security assessment satisfy food defense requirements?+

No. The Intentional Adulteration rule at 21 CFR Part 121 requires a specific set of components: a vulnerability assessment identifying actionable process steps with reasoning recorded either way, mitigation strategies, monitoring, corrective action and verification. A general security assessment contains none of those in the required form, though it should feed and reference the food defense plan.

Who does California's SB 553 apply to?+

Nearly all California employers, with narrow exemptions: worksites with fewer than ten employees not open to the public, employees teleworking from a location of their own choosing, healthcare settings under the separate Cal/OSHA standard, and certain law enforcement and corrections facilities. There is no exemption based on headquarters location, so any California site brings the obligation.

What must be in the violent incident log?+

The date, time and location, a description of the incident, its classification, the type of violence, the consequences and actions taken, and who completed the log, with personal identifying information omitted. It is retained five years and employees may view and copy it within fifteen calendar days of a request.

Why start with people rather than premises?+

Because the threats that most often materialise involve someone already inside: aggression at a counter, a contractor with unescorted access, a driver alone in a yard. Perimeter controls do not address any of them. Assessments that begin with the building reliably conclude with cameras and leave the exposed roles unaddressed.

Should incidents without injury be recorded?+

Yes. Where a violence prevention plan is required the log covers every incident regardless of whether injury resulted, and even where it is not required, threats and near misses are the leading data. Recording only injuries produces a log that describes outcomes rather than exposure.

Keep going

Related templates and programmes

Siddarth Singh

Written and reviewed by

Siddarth Singh

Founder & Chief Executive Officer, Knowella

Certified Safety Professional and industrial and systems engineer with more than a decade inside food supply chain, freight and manufacturing operations. This page was written against the current text of the standards it cites, not against secondary summaries of them.

  • Certified Safety Professional (CSP), Board of Certified Safety Professionals
  • MBA, University of Chicago Booth School of Business
  • MS and BS, The Ohio State University, Industrial and Systems Engineering
  • Six Sigma Black Belt
Verify with BCSP →

Sources and last review. Reviewed 16 August 2026 against:

This page is general guidance, not legal advice. Confirm requirements with your jurisdiction’s regulator.

Start in Minutes, Not Weeks

Launch a Ready-Made Template and Customize It Your Way

Every template is fully editable. Adjust fields, workflows, and branding to match your processes, then deploy to your team instantly.