I’ve made some assumptions in this chapter:
In return, although this chapter includes example risk grids, please don’t assume they are ready-to-use templates. This chapter offers guidance that enables you to develop ways of documenting risk assessments suited to your organisation’s activities.
When risk assessments are long, complicated tables of text and numbers, it can be difficult to see who needs to do what. Too often, the risk assessment document is merely a passport, not a tool for reducing risk.
In a remote warehouse, I spotted a step ladder underneath a loft hatch. The top platform of the ladder was about 1.5 metres from the loft hatch. A worker from a major national provider of fire safety and security solutions was alone in the roof space installing smoke detectors. The only way he could have accessed the loft would have been to stand on the platform and pull himself up into the loft using his arms. The loft itself was hot and airless, and he had a radio on so loudly he couldn’t hear me when I called up to him. Apart from my unexpected appearance in the warehouse, no one else was about. Had he been overcome by the heat, or fallen from the ladder, it could have been hours before anyone realised.
I asked the site manager if the contractor had provided a risk assessment for the work. She handed me a thick document, with around 200 pages of tables and lists. “Which bit applies to the job he’s doing?” I asked. She didn’t know.
When the contractor re-appeared I asked him the same question. “How should I know? I don’t do the risk assessments!” The pack of assessments was merely his ticket to get on site. After some perusal, it became apparent there wasn’t even a generic risk assessment for the job he was doing, let alone a site-specific one taking account of lone-working in a hot roof space without a suitable means of access. Since he hadn’t looked at the assessments, even if there had been an appropriate one, he wouldn’t have been alerted to any additional controls needed. I worked with the contractor and the facilities manager to agree some controls for the work, including a longer ladder to access the loft, and checks by the facilities manager every 30 minutes.
In this case no one was harmed. For a lorry driver working for a contract haulier, the failure to communicate and monitor significant controls led to his death
As quoted in Chapter 13, the legal requirement of the Management of Health and Safety at Work Regulations (3(6)) is only to record the significant findings of the assessment and those identified as being especially at risk. The law does not require matrices, scoring systems or elaborate forms – just that you record “significant findings”.
In Chapter 13 we looked at the three items the current HSE guidance lists for Step 4. These are a paraphrase of the 2014 version of INDG 163, which included further advice about simplicity and communication:
Any record produced should be simple and focused on controls… Any paperwork you produce should help you to communicate and manage the risks in your business. For most people this does not need to be a big exercise – just note the main points down about the significant risks and what you concluded… When writing down your results keep it simple.
If you created a template directly from the advice for step 4 on the HSE website (2025) it might look like Figure 16.1.
| Hazards (things that may cause harm) | Who might be harmed and how | What you are doing to control the risks |
|---|---|---|
| .. | .. | .. |
This would be supported by action tracking and monitoring systems to ensure the controls were in place and effective.
In chapter 2 I emphasised the need to be clear about what you are risk assessing, using the example of “changing a fuse.” Had the scope been documented more clearly, workers would have realised there wasn’t a risk assessment for the types of fuses they changed.
Without a clear definition of the scope it is easy to omit an area of operations (such as maintenance) or a group of people (such as contractors) from your risk assessments. If you miss people or locations or task steps, you will miss hazards. Without a scope you might include hazards that aren’t relevant, making the document hard to read and understand.
A clear scope statement will also show you when you can apply one risk assessment to another process, or to what extent a generic risk assessment can be applied to a specific site. For example, the case against Stagecoach Devon Limited in 2022 focussed on the application of a generic risk assessment for bus depots, which didn’t take account of the individual hazards at each bus station. Had the scope been clear that it applied only to bus stations designed such that buses rarely reversed, it would have been transparent that the informal activities of one driver acting as banksman for another bus driver had not been risk assessed.
Your risk assessment should have a consistent place for people to document the scope. Many risk assessments I have reviewed have nothing more than a title, and even then, I’ve seen some where the title has been left as “Risk assessment template”.
One option is to provide a large box on a form (or with an online system, a box that expands to the size needed). You could provide guidance on how to write the scope, suggesting the types of things to include.
An alternative is to provide multiple fields to complete to describe the scope, such as:
If you provide multiple fields, some of them might be left empty if they don’t apply. Some online systems can support this by tailoring the form as you answer initial questions about the scope.
If you are writing the risk assessment for a process that has been defined in a procedure or method statement, you can simplify the scope statement by referring to that document. Provide a link if doing this online, and tell people how to find the document if not. Make sure the reference is exact – as with our previous example “see the latest task description on fuses” would be less helpful than “see task document T045: Changing fuses in distribution boards, version 01.04.2024”
The next five sections are organised according to the five steps to risk assessment that we started this book with. In each section I consider how the documenting of the risk assessment supports that step.
If the column is labelled “hazard” make sure that what you put in that column is a hazard, that is, the thing or the activity with the potential to cause harm.
As explained in Chapter 1, many things get documented in the hazard column that aren’t hazards. As a reminder:
If the hazard is an activity such as “driving for work” or “working at height” can you be more specific about what sort of driving, or the equipment being used for working at height? These activities might need to be divided into sub-tasks, with the hazards associated with each stage being considered, as explained in Chapter 2.
The Regulations and the HSE guidance are clear that the requirement is only to document significant findings, including any people who might be especially at risk. Therefore, if you consider a hazard and determine there is no significant risk to anyone, you don’t need to document it in the risk assessment. Instead, use the documents described in Chapter 14 such as a risk register, an inventory and a checklist to show you considered all the hazards.
However, sometimes I am asked to carry out a risk assessment when I have no influence over higher level documents, and I know I might not be around to review the risk assessment. In this case I might include some hazards that are not significant within the scope of the defined risk assessment, but that I want to show I considered – and I want to nudge future assessors to review them.
Next to each of these I might comment “no significant sources of noise (etc) currently identified.” This also indicates to whoever reviews the risk assessment next time that these hazards should be reconsidered. Perhaps stress or noise have become issues, or the controls that prevented trip hazards have been removed. Documenting the apparently ‘trivial’ hazard provides a reminder to a future assessor to keep their eye on this hazard.
If there isn’t a risk register, you are likely to keep hazards which are non-significant because of current controls in the risk assessment. For example, you replaced bleach with a gentle soap and need somewhere to remind procurement not to buy bleach again.
But, where you have a risk register, keep your risk assessments free of hazards which are not significant.
The 2014 version of INDG 163 included the following advice, which I’ve rarely followed:
If your risk assessment identifies a number of hazards, you need to put them in order of importance and address the most serious risks first.
While I agree that you need to address the most serious hazards (highest risk) hazards urgently, this doesn’t mean it’s always logical to list them first, nor even to manage them first. As we saw in Chapter 11 you might be able to apply less effective controls in the short term, while more effective controls might take time to put in place.
If a risk assessment is being used alongside a task, hazards are likely to be listed in the order they need to be considered during the task. Listing the most serious hazards first would presumably mean rearranging them once you have completed step 3, and assessed the risk, and then re-arranging them once you’d mitigated the risk for some hazards. It’s hard to believe the HSE ever intended us to do this.
Ask yourself:
When might it be useful to list hazards in order of risk?
In Chapter 8 I advised you only to use numbers for something that can be measured. If you have measured something, you might need extra columns. For example:
The scope should document the conditions under which data was collected, the assumptions made, and any standards or limits against which the date needs to be compared.
If there aren’t any measures, you might need only one “harm statement” column, provided you have trained people how to write these, and include examples in your risk assessment management plan.
As we saw in Chapter 8 a single hazard “driving for work” could have four (or more) harm statements, so the layout of your risk assessment template needs to take this into account. If you’re using Excel, this might mean repeating the same hazard four times; if you have a database, you’ll need to define a 1:n relationship between the hazard and the harm statements.
The first two columns of the risk assessment might look likes Figure 16.2
| Hazard | Harm statement |
|---|---|
| Driving for work | If a driver is involved in a motorway accident there could be multiple fatalities, including the death of our employee. |
| If a driver is shunted by another vehicle, or shunts another vehicle, they could suffer whiplash. | |
| If our drivers spend long hours driving without a rest they can suffer from musculoskeletal pain which might lead to time off work. | |
| If a car hit a pedestrian, the pedestrian could be seriously injured or killed. Our employee could suffer whiplash, and psychological harm. | |
| Handling deliveries | If a driver tries to move too many items in one go, they could suffer a musculoskeletal injury |
| If a driver drops one of the deliveries, they could injure their own feet or those of a bystander. | |
| If deliveries are made in poor weather or on uneven ground, a worker could fall while carrying items, causing sprains or bruising. | |
| If items are carried in a way that blocks the driver’s visibility, they could collide with another person or object, leading to impact injuries for the driver or other person. |
From the harm statements you can identify the factors that impact the risk – and this will tell you how to control the hazards.
Note that in Figure 16.2 I have incorporated the “who might be harmed” into the assessment column. You could describe the audience who could be harmed in the scope statement (especially for individual risk assessments, such as for a pregnant or young worker). The scope provides a prompt then to question if all reasonably foreseeable harms have been considered.
It should be possible for someone to pick up a risk assessment and know what the expected standard is for each control (or where to find the standard). Some controls will be immediate barriers to the hazard – such as wearing PPE or using a handling aid for a heavier load. Other controls are how you make sure the immediate barriers are effective, such as checking the PPE for damage, or inspecting a handling aid.
Either way, it needs to be clear:
What should be clear from Chapter 15 is that having multiple columns where it is not clear which controls are already in place, and which are aspirational, is not the basis for a suitable and sufficient risk assessment.
Referring to other documents, such as those described in Chapter 14, will save you time, reduce repetition and promote consistency. As noted in Chapter 13 the old ACOP covering risk assessment (L21) encouraged the use of other documents, including existing procedures.
Too often I’ve seen controls which state “all staff are trained” or “everyone knows what to do” or even “common sense”. If something is important enough to be documented as a control, there needs to be a process that makes sure it happens. If your assessments are audited, you will need evidence, such as a training syllabus to support a claim that “all staff are trained.”
A catering risk assessment might identify several types of bacteria and multiple contamination routes. Some assessors document vague controls like “good hygiene,” while others repeat the same precautions – hand washing, storage temperatures, segregation rules – on every row. That’s inefficient and it’s hard to maintain.
Instead, refer to other well-written and accessible documents which include the precautions needed (such as hand washing). You could list method statements, training records and other documents separately, or refer to a top-level management plan. For example, suppose you have written multiple harm statements relating to musculoskeletal injuries. You’ve worked through the hierarchy and decided you still need manual handling training as a control. You’ve created a syllabus for course that tackles all relevant handling scenarios. You set up an item in your training log, showing who needs this training and when. You link both of these into a Manual handling management plan which describes objectives, assessment criteria, responsibilities and requirements for refreshers. Now, the control in your risk assessment can state simply “L013 Manual handling management plan, 1.4.2024”.
Since workers are unlikely to refer to the method statements every time they do a job, this approach only works if the procedures described are practical, tested, trained, understood and embedded in practice. Where documents are referred to in a risk assessment, make sure that document covers the point you are relying on.
Let’s assume you’ve used harm statements as we did in Figure 16.2, and that we have other documents such as method statements that we know are tested, reviewed and monitored.
We can document controls for each harm as shown in Figure 16.3. If you think that’s overly simple, go back to the example in Figure 16.1 which directly maps the HSE requirements for recording the significant findings in a risk assessment.
While this format makes it is straightforward to document appropriate controls for each harm statement, you’ll notice that some harms need more than one control, and some controls might apply to more than one harm statement.
While this risk assessment is tidier than many, and will provide the ability to audit other documents against the criteria set in the risk assessment, it is overly wordy as a document for doing the job on the day, and hence you are likely to need another document, based on the risk assessment, containing only the on-the-day tasks.
| Hazard | Harm statement | Controls |
|---|---|---|
| Driving for work | If a driver is involved in a motorway accident there could be multiple fatalities, including the death of our employee. | Permit to drive scheme assesses competence of drivers, including understanding the need to maintain distance from other vehicles. DW 0301 Driver training, 29.4.2025 CK 0561 Vehicle check schedule, 1.4.2025 |
| If a driver is shunted by another vehicle, or shunts another vehicle, they could suffer whiplash. | ||
| If our drivers spend long hours driving without a rest they can suffer from musculoskeletal pain which might lead to time off work. | Seat ergonomics is considered in procurement of vehicles Drivers are shown how to adjust seats DW 0301 Driver training, 29.4.2025 Journeys are planned to avoid long hours of driving without a rest |
|
| If a car hit a pedestrian, the pedestrian could be seriously injured or killed. Our employee could suffer whiplash, and psychological harm. | Procurement do not allow vehicles with bull bars or similar at the front. DW 0301 Driver training, 29.4.2025 CK 0561 Vehicle check schedule, 1.4.2025 |
|
| Handling deliveries | If a driver tries to move too many items in one go, they could suffer a musculoskeletal injury | Drivers are provided with a trolley and have been shown how to use it. L013 Manual handling management plan, 1.4.2024 |
| If a driver drops one of the deliveries, they could injure their own feet or those of a bystander. | ||
| If deliveries are made in poor weather or on uneven ground, a worker could fall while carrying items, causing sprains or bruising. | Trolleys provided have all weather wheels and are checked weekly by maintenance as per PPM 8975 L013 Manual handling management plan, 1.4.2024 |
|
| If items are carried in a way that blocks the driver’s visibility, they could collide with another person or object, leading to impact injuries for the driver or other person. | Maintaining visibility while carrying is covered on training course L013 Manual handling management plan, 1.4.2024 |
The five steps to risk assessment should not dictate how you document the significant findings of your risk assessment.
If you want people to refer to the risk assessment when they do a job, make it easy for them to find which controls they are responsible for on that day. Where a risk assessment is for an activity, I prefer to split the controls into two columns:
In Chapter 15 we looked at a variant of this. Figure 16.4 illustrates a simplified version, without numbers, using the controls suggested in Figure 16.3 for the driving element of the task.
| Hazard | Harm statement | Controls in advance | Controls on the day |
|---|---|---|---|
| Driving for work | If a driver is involved in a motorway accident there could be multiple fatalities, including the death of our employee. | Permit to drive scheme assesses competence of drivers, including understanding the need to maintain distance from other vehicles. DW 0301 Driver training, 29.4.2025 | Carry out vehicle checks as per CK 0561 Vehicle check schedule, 1.4.2025 Maintain distance from vehicles in front as per your training. |
| If a driver is shunted by another vehicle, or shunts another vehicle, they could suffer whiplash. | |||
| If our drivers spend long hours driving without a rest they can suffer from musculoskeletal pain which might lead to time off work. | Seat ergonomics is considered in procurement of vehicles Drivers are shown how to adjust seats in training. DW 0301 Driver training, 29.4.2025 Journeys are planned to avoid long hours of driving without a rest | Plan your route, including your first stop where the journey is likely to be longer than two hours Check your seat adjustment for comfort and visibility before starting your journey. |
|
| If a car hit a pedestrian, the pedestrian could be seriously injured or killed. Our employee could suffer whiplash, and psychological harm. | Procurement do not allow vehicles with bull bars or similar at the front. DW 0301 Driver training, 29.4.2025 | Carry out vehicle checks as per CK 0561 Vehicle check schedule, 1.4.2025 Stay below speed limits, and reduce speed further in built up areas, where there are many parked vehicles and near schools or parks |
Ask yourself:
Looking at what I’ve done with driving, do the same for the handling controls. Feel free to add any additional controls you can think of. Figure 16.5 provides a template you can use. Compare your thoughts with the version in the Appendix – you might have ideas that I’ve left out. If you want extra practice, apply the same process to the five-column example in Figure 15.5 in Chapter 15 for the warehouse controls.
| Hazard | Harm statement | Controls in advance | Controls on the day |
|---|---|---|---|
| Handling deliveries | If a driver tries to move too many items in one go, they could suffer a musculoskeletal injury | ||
| If a driver drops one of the deliveries, they could injure their own feet or those of a bystander. | |||
| If deliveries are made in poor weather or on uneven ground, a worker could fall while carrying items, causing sprains or bruising. | |||
| If items are carried in a way that blocks the driver’s visibility, they could collide with another person or object, leading to impact injuries for the driver or other person. |
If you document “Controls on the day” separately from the background controls, it will be simpler to create method statements, procedures, checklists of permits, or to confirm consistency between these procedural documents and risk assessments.
Figure 16.6 shows some examples of controls as I’ve seen them in typical risk assessments, with some preferred alternatives along with the principle the alternative demonstrates. [n] indicates where a document reference would be provided.
| Example | Preferred | Principle |
|---|---|---|
| Checks will be made of the safety of the equipment | Electrical checks will be as per [n] The supervisor will make 3-monthly checks of equipment listed on the high-risk inventory [n] as per PPM [n] Staff using equipment will make pre-use visual and functional checks as per training doc [n]. | Make it clear who will do what – choose a language style and stick to it eg “Supervisor will…” (future tense) or “Manager does.. (present tense)“ There might be circumstances where you say “You will…” but 3rd person is advised against eg “a miracle will occur” |
| Staff should not walk near the production line to get to the stores | When walking to stores, staff should take the route via the corridor. Induction training [n] | Tell people what to do, rather than what not to do |
| Always ensure people wear suitable footwear | Induction [n] includes staff instruction to wear the safety footwear provided OR Induction [n] includes staff instruction to wear shoes, trainers or boots with closed in toes and heels AND Supervisor makes daily checks that appropriate footwear is being worn and provides feedback. | Be specific and realistic |
| Visitors will behave sensibly and safely when on the premises | Host will provide visitors with information about behaviours expected on site, including any out-of-bounds areas. Induction [n] | Document the things your organisation will do, not what you expect others outside your control to do |
| Managers should undertake the appropriate risk assessments for the task | Managers should assess the risk of the task, and document the findings. Training [n]; Template [n] | Use unambiguous language |
Make sure you have a document naming and management system in place, so that everyone knows how to find the most recent version of anything. If a risk assessment relies on a work procedure for the scope, and a training document for a control, a review needs to be triggered when any of these documents are updated. If a risk assessment refers to another document multiple times it can be easier to include a list of references at the end of the assessment, so each reference only needs updating once when it changes.
With our example in Figure 16.3, we could just have used the short code for the documents like “DW0301” or even an index number, and then list references at the end:
In Chapter 13, we quoted the now withdrawn 2013 HSE ACoP on risk assessment (L21), which made it clear that a risk assessment record needs to be:
Paper documents in the health and safety manager’s office are not widely accessible. Most organisations now create their risk assessments and other safety documentation in commonly available software – such as Microsoft Word or Excel. Many even store these documents on a shared cloud-based server – such as OneDrive (via SharePoint or Teams), Google drive or a proprietary Intranet. Without structure, even online storage can get overwhelming. How quickly could you find the latest version of the specific risk assessment for a task if an inspector comes calling?
Other uses of technology include:
AI technologies are increasingly being adopted in health and safety systems. Another book could be written on this, but the HSE survey results in 2025 provided a useful way of grouping AI use for our context. In Box 16.1 I’ve provided summaries under their headings.
Chapter 17 will discuss issues around reviewing controls. But as this chapter is about creating the templates for recording your risk assessment, we have to leap ahead a little.
While I’ve argued against tracking your “to do” list inside the risk assessment document, you might need that extra “responsibility” column to support the review process. For ongoing tasks, this is not a job that can ever be signed off as done for ever, but it can be useful to document who will do what as part of the review. Figure 16.7 illustrates one way of doing this. As with Figure 16.6 [n] indicates where you might need to include a reference to another document.
| Hazard | Harm | Controls | Responsibility |
|---|---|---|---|
| Moving parts of machinery | Contact with moving parts during operations could result in amputations to operational or cleaning staff | All items in machinery inventory [ref 1] are subject to PUWER inspection [n] on installation, and on monthly checks [n] PUWER inspection [n] includes checks of emergency stop button availability. | Engineering manager reports on inspections and checks to quarterly safety meeting [n] |
| Contact with moving parts during maintenance could result in amputations to maintenance staff | LOTO [n] for all maintenance on machinery. PUWER inspection [n] includes checks of interlocks. | Maintenance supervisor checks all maintenance staff understand and use LOTO [n] | |
| Fire in boiler room | Spread of fire from the boiler room into the office could result in people becoming unconscious through smoke inhalation and being unable to evacuate, or slower to evacuate. | Sign on the door reminds people to close it | Facilities manager checks the signs on the monthly safety tour |
| Door has automatic closing mechanism | Facilities manager checks the mechanism on the monthly safety tour | ||
| Staff are reminded not to wedge or prop the door open | Annual refresher e-learning includes compulsory question on doors. Training manager assesses responses and provides feedback on completion. |
Having looked at some of the problems of typical templates used widely by organisations in Chapter 15, this chapter has provided some practical ideas on how to document the significant findings of your risk assessments, in a way that makes it easier to use those assessments as a working tool. In Chapter 17 we’ll look at the last step in the risk assessment process, reviewing the risk assessment, including checking that the controls are working.
You can use the Contact form to send me feedback. If you’d like to receive an email when I add or update a chapter, please subscribe to my ‘book club’
Alternatively, go back to the book contents page
Appendix 1: Case studies by year
Appendix 2: Answers to questons posed in each chapter
Appendix 3: Lost HSE references