The 5 steps to risk assessment: the risk assessment steps in order, what each involves, and the one firms skip

Updated

The five steps are the regulator's own framing and they are genuinely useful, because they separate four things that firms otherwise do at once and badly. What the list does not tell you is how much of the work sits in each step, which is why assessments get written enthusiastically and reviewed never. This page walks the five, says what each one takes in practice, and is honest about the one that is quietly dropped in almost every firm that has an assessment set at all.

The five, as the regulator states them

Identify the hazards. Assess the risks. Control the risks. Record your findings. Review the controls. The framing matters because two of those five are about the work itself and three are about knowing what you decided: assessing without recording leaves nothing to review, and reviewing without a record is a conversation. The regulator is also explicit that paperwork is not the priority and controlling risk in practice is, which is the right emphasis and the reason this site prices the paperwork rather than selling more of it.

Recording is a duty above a threshold, and a good idea below it

If you employ five or more people you must record your significant findings: the hazards, who might be harmed and how, and what you are doing to control the risks. Below that threshold the recording duty does not bite, and almost every firm should record anyway, because the alternative is that the assessment lives in one person's head and leaves with them. The threshold is about the law, not about whether writing it down is sensible.

Reviewing is the step that gets dropped, and the reason is structural

Steps one to four happen in a burst, usually when something forces them: a client asks, a tender needs them, an incident happens. Step five is a recurring obligation attached to nothing. Nobody schedules a review of a document that has no date on it, and so the set silently ages until a change makes one of them wrong. The fix is not discipline, it is putting the review date on the record so the month's work is a list rather than a memory.

What the five steps cost, in your firm

The honest way to plan a set of assessments is to price all five before writing any. The free risk assessment form worksheet on this site takes your activities split by effort, the minutes each takes, your review cycle, the assessments a change forces out of cycle and the people every change has to reach, and returns the hours and the money for the first pass and for each year after it. Most firms find the first pass is the small number.

Questions people ask about 5 steps to risk assessment

How many steps are there in the risk assessment process?

Five, in the regulator's current framing: identify the hazards, assess the risks, control the risks, record your findings, review the controls. Older material and some training courses describe the same work as five steps in slightly different words, and one or two vendors sell a six-step or seven-step version. The number is a teaching device; the duty is to assess suitably and sufficiently and to review when it is no longer valid.

How do you write a risk assessment?

Take one activity at a time rather than a department. Say what could go wrong and to whom, state what you already do about it honestly rather than aspirationally, add the further actions with a named owner and a date, and sign and date it. If you cannot name the person who will do the further action, you have written a wish rather than an assessment.

When does a risk assessment have to be reviewed?

When it is no longer valid or there has been a significant change in the work it covers, and in practice on a cycle as well, so that the ones nothing has happened to still get looked at. The cycle is a floor rather than the rule: a change to the process, the substance, the equipment or the people is the real trigger and it does not wait for your anniversary.

Sources

Related answers

Start Coshhvo ProKeep the file in Coshhvo