The Safer Choice

Early versions of the five steps included assessing the level of risk as part of step 3:

Evaluate the risks and decide whether the existing precautions are adequate or whether more should be done. (INDG 163, 1998, 1st edition).

Evaluate the risks and decide on precautions (INDG 163, 2006, 2nd edition and 2011, 3rd edition).

Evaluate the risks. (INDG 163, 2014, 4th edition)

It was clear from the editions up to 2011 that the HSE saw this as two steps, and there was an implication that the steps were carried out in this order: evaluate (or assess) the risks, and then decide on the precautions (controls). The 2014 version omits the need to control risk from any of the headings – criticism the HSE presumably took on board for their next version. In 2019, having combined the first two steps into one as explained in Chapter 4, the original step 3 was split into two steps:

  • Step 2: Assess the risk
  • Step 3: Control the risk

How then do we assess the risk?

5.2 SFAIRP and ALARP

So Far As Is Reasonably Practicable (SFAIRP) and As Low As Reasonably Practicable (ALARP) form the basis of understanding what it means to “assess” the risk. See the box for an explanation if you aren’t familiar with the terms. We’ll look at the term again in Chapter 11 in the context of controlling risk.

Box 5.1: SFAIRP and ALARP

The HSE regards ALARP and SFAIRP as equivalent, so you need to be familiar with both terms, and in particular the shared concept of what is “reasonably practicable”.

SFAIRP: Sections 2 and 3 of the Health and Safety at Work Act require employers and the self-employed to ensure the health and safety of employees and others “so far as is reasonably practicable”. As such, this relates to the control of risk.

ALARP: For example, the Provision and Use of Work Equipment Regulations (PUWER) while using SFAIRP as above, also require features and equipment to reduce “to as low as is reasonably practicable” the risk to safety of mobile work equipment and the risk of fork-lift trucks overturning. As such, this appears to relate more to the assessment of risk once controls are in place.

In Reclaiming health and safety for all (2011), Professor Loftstedt noted “overwhelming” support for SFAIRP, because it allows risks to be managed in a proportionate way. However, he also noted that there was “general confusion” over what it means in practice.

5.3 Reasonably Practicable

The definition of “reasonably practicable” comes from the Court of Appeal judgement in the case Edwards v. National Coal Board (1949). Lord Justice Asquith explained:

‘Reasonably practicable’ is a narrower term than ‘physically possible’ … the quantum of risk is placed on one scale and the sacrifice involved in the measures necessary for averting the risk (whether in money, time or trouble) is placed in the other, and that, if it be shown that there is a gross disproportion between them – the risk being insignificant in relation to the sacrifice – the defendants discharge the onus on them.

This is not a simple cost-benefit analysis – as Figure 5.1 shows, the scales do not balance. The owner of the risk (the duty holder) needs to show that there is “a gross disproportion” between the risk and the cost of avoiding a harmful outcome. Lord Justice Asquith didn’t say “if it costs a bit more to avert the risk than you think it’s worth..” He placed the onus on the employer to protect, unless the cost, time and effort is grossly disproportionate. We will look at what “grossly disproportionate” means in more detail in Chapter 12.

Figure 5.1: Deciding what is reasonably practicable using scales

Scales with money time trouble on left and risk on right with reasonably practicable across the top

However, what is considered “reasonably practicable” by the courts is rarely assessed by such a cost benefit analysis. In the first place, you must comply with the law whether you regard it as practicable or not. If you can’t afford to apply the law, you can’t operate your business. If you’ve identified that a hazard is relevant to your organisation, there are some controls required by law, regardless of your personal assessment of the risk or the risk benefit. For example:

  • If you have asbestos in a property, you must have an asbestos management survey to show the location and status of the asbestos. Even if it turns out to be very low risk (in excellent condition in a basement no one ever uses).
  • If your workplace is noisy, there are levels of noise you must not exceed.
  • If you have toilets, it must be possible to ventilate the facilities.

Secondly, if there is guidance available (from the HSE, from industry bodies) then if you choose not to follow the guidance and an accident happens, the burden of proof is on you to prove it wasn’t practicable to follow the guidance. For example, INDG 199 provides advice on how to use a ‘banksman’ when it is not possible to avoid reversing a vehicle. If a vehicle is reversed on your premises and you didn’t attempt to eliminate reversing, or consider the advice on banksmen, you will have a hard time showing you did everything reasonably practicable.

Chapter 6 provides examples of law you must follow and guidance you must consider, regardless of your assessment of the risk.

5.4 Assessment and control are not discrete steps

Although the HSE separated assessment and control, the description of the “assessment” step from the HSE suggests that the authors don’t see a clear division between assessment and control.

Ask yourself:

Read this description and each bullet from the HSE description of Step 2: Assess the risk.

Once you have identified the hazards, decide how likely it is that someone could be harmed and how serious it could be. This is assessing the level of risk. Decide:

    • Who might be harmed and how
    • What you’re already doing to control the risks
    • What further action you need to take to control the risks
    • Who needs to carry out the action
    • When the action is needed by

Which steps does each bullet relate to? Are any unambiguously about “assessing the level of risk”?

Let’s review these bullets.

‘Who might be harmed and how’ was something we already considered in Step 1 – we had to do that to identify our list of hazards. The remaining four steps all seem to be related to control rather than assessment. The only bit of this step that sounds like it is entirely assessment is in the introductory sentence ‘decide how likely… and how serious’.
Whether expressed as two steps, or as a single step with two components, I don’t think the HSE ever intended that the processes should be discrete.

In the original ACoP for MHSW regs (L21, withdrawn in 2013) there is advice that:

In some cases employers may make a first rough assessment, to eliminate from consideration those risks on which no further action is needed. This should also show where a fuller assessment is needed, if appropriate, using more sophisticated techniques.

Just as I argued that identifying a hazard, and identifying who could be harmed are not discrete steps, so it should be clear that assessment is not a separate, one-off activity.

So, a key take away from this chapter needs to be this: 

You assess at every step

When I first learned about the process, it bothered me that it is called “risk assessment”, rather than “risk management.” The purpose of the process is after all not merely to assess the risk, so we know how dangerous or safe something is, but to manage the risk down to an acceptable level. But assessment comes into every step, as I’ve attempted to show in Figure 5.2:

  • To identify something as a hazard, you assess if there is a significant risk. If the risk is trivial, you dismiss the candidate hazard. You decided that walking across the car park was unlikely to lead to an alien invasion, but that it could result in a trip on the curve, or a collision with a vehicle.
  • In considering who can be harmed, you assess the risk to different types of people.
  • In deciding if more controls are needed, you assess what you think the risk is with and without those controls. Every control you might add involves a further assessment of the risk, even if you are not consciously doing this.
  • In deciding what to document, you consider the risk of not writing something down.
  • In reviewing the risk assessment, and the controls, you are re-assessing the risk, and should be asking ‘does my original assessment of the risk need to be adjusted?’

Risk assessment is an iterative process, with new hazards identified when you consider who could be harmed, and other hazards dismissed once you assess the risks. Whether shown as one or two steps, this was always going to be an oversimplification of a complex process.

Figure 5.2: The iterative nature of assessment

Flowchart

Ask yourself:

Look again at the scales in Figure 5.1. How do the steps of “assess the risk” and “control the risk” map onto these scales?

On the left side of the scales, we can list some possible controls, and estimate the financial cost, the time required, and the trouble needed for each possible control.

On the right side of the scales we must assess the risk before a control, choose a control, then reassess the risk. To apply the scales literally, you would need to compare the change in risk from each possible control, and every combination of controls, to determine practicability. This is not what happens.

5.5 How can it be better?

The next few chapters are organised around a simplification of the iterative process described in this chapter:

Chapter 6: The mandatory controls which must be in place, regardless of your evaluation or assessment of the risk.

Chapter 7a: The theory of risk assessment, probability and numbers

Chapter 7b: What’s wrong with risk assessment (mostly a critique of the use of risk matrices)

Chapters 8, 9 and 10: How to assess the risk (with the knowledge that you will already have some controls in place, but might need more).

For well understood hazards, you might not need complex assessments. You know what you need to do, and if it is straightforward to make things safer, you should do so. The benefit of your risk assessment will come from your controls, which we look at in Chapter 6 and Chapter 11.

You can use the Contact form to send me feedback. If you’d like to receive an email when I add or update a chapter, please subscribe to my ‘book club’

Alternatively, go back to the book contents page

Appendix 1: Case studies by year

Appendix 2: Answers to questons posed in each chapter

Appendix 3: Lost HSE references