← All postsHow-to

Risk assessment: identifying what can go wrong before it does

A risk assessment is not a document you produce for an inspector. It is the half hour in which somebody walks the actual work and asks what could hurt a person here — and writes down what will be done about it.

How-toR

A risk assessment is a systematic look at what could cause harm in a piece of work, how likely and how serious that harm would be, and what you are going to do to reduce it. Most jurisdictions require one for workplaces of any size, and the requirement is often met with a downloaded template that describes somebody else's premises — which satisfies the filing cabinet and nobody standing near the machine.

It is a different exercise from keeping a risk register. The register is the ongoing list of risks a project or organisation carries; the assessment is the act of examining a specific activity, place or change and deciding what to do. One is a record you maintain, the other a process you run — and the assessment feeds the register rather than replacing it.

The five steps

  1. Identify the hazards. Walk the work as it is actually done, not as the procedure describes it, and talk to the people doing it. They know the shortcuts.
  2. Decide who might be harmed and how. Employees, contractors, visitors, members of the public — and be specific about the mechanism, not just the category.
  3. Evaluate the risk and decide on controls. Eliminate the hazard where you can; where you cannot, substitute, engineer it out, change the procedure, and only then reach for protective equipment. That order matters and is inverted in most quick assessments.
  4. Record what you found and what you decided, with who is doing it and by when. An assessment without an owner and a date is a description, not a control.
  5. Review it — after an incident, after a change to the work, and periodically regardless. An assessment describing equipment you replaced two years ago is worse than none, because it is evidence you were not looking.

The matrix, and its limits

Scoring likelihood against severity on a grid is the standard tool and a genuinely useful way to compare unlike risks quickly. It also invites two mistakes. The first is precision theatre: a score of twelve looks objective and is a judgement dressed as arithmetic. The second is that the grid handles a rare catastrophic outcome badly — a low-likelihood, fatal-consequence hazard can score below a frequent minor one and drop down the list, which is exactly backwards. Use the matrix to sort and argue, never to decide on its own.

The most common failure is assessing the written procedure instead of the work. People take shortcuts because the official method is slow, awkward or impossible with the staffing available, and those shortcuts are where the injuries happen. An assessment produced at a desk describes a workplace that does not exist; the only version worth having comes from watching and asking.

What makes one suitable and sufficient

  • It covers the significant hazards, not every conceivable one. A list of forty trivial risks buries the three that matter.
  • The controls are specific and assigned. Be careful is not a control; a guard, a barrier, a two-person rule or a changed sequence is.
  • It reflects the people actually present, including new starters, young workers, anyone working alone, and anyone whose circumstances change the risk.
  • It is dated, and the review date is in somebody's calendar rather than in the document.
  • The people doing the work have seen it and recognise their own job in it.

Where it lives

Ettex Records holds assessments as structured entries you can filter by area, activity or review date, so the ones falling due surface before an inspection rather than after. Actions coming out of an assessment belong on a board with owners and dates, the ongoing exposure list in risk register, and what happens after something does go wrong in incident report and corrective action.

The boundary is worth stating: Ettex is not a health and safety management system and does not know your jurisdiction. There is no library of regulation-specific templates, no compliance checking, and nothing that will tell you whether an assessment meets a legal standard. What the law requires of you — and for some activities it is specific and detailed — depends on where you operate, and is a question for the applicable regulator or a qualified safety professional.

Frequently asked

What is the difference between a risk assessment and a risk register?

The assessment is the process of examining an activity and deciding on controls. The register is the running list of risks an organisation or project carries. Assessments feed the register; they are not the same document.

How often should risk assessments be reviewed?

After any incident, after any change to the work, equipment or staffing, and on a periodic cycle regardless. An assessment describing conditions that no longer exist is evidence of not looking.

Who should carry out a risk assessment?

Someone competent in the work, together with the people who do it. Complex or specialised hazards need a qualified professional, but the routine assessment belongs with the team rather than with a consultant who has never seen the place.

Is a risk matrix enough to prioritise?

It is a good sorting tool and a poor decider. Rare catastrophic outcomes score misleadingly low against frequent minor ones, so treat the number as a prompt for discussion rather than a ranking to act on.

SL
Written by Sofia L.

Part of the Ettex team — writing about product, engineering and the future of work.

More posts
Get the best of the Ettex blogProduct news, guides and tips — straight to your inbox, no spam.