Article · Risk Assessment · 19 August 2026
How to Do a Risk Assessment in the Workplace (5-Step, Practical)
A risk assessment is not a document; it is a walk, a conversation and a decision, written down. The five-step method is the sequence the UK law expects and the ISO system uses: identify the hazards, decide who might be harmed, evaluate the risks, record the findings, review them. This article walks the five steps on a real workplace — the point-of-work assessment a supervisor can do in the afternoon — and names the mistakes that make the review fail.

Step 1 — Identify the hazards
The walkover is the instrument, and it has a method: the slow walk of the workplace with the six families of hazard in mind — physical, chemical, biological, ergonomic, psychosocial, work organisation. Look at the point of work, then the interfaces: the forklift and the pedestrian, the crane and the walkway, the solvent and the ignition source.
Ask the crew the two questions the eye misses: what has nearly gone wrong here? and what are you most worried about on this shift? The near-miss history is a hazard list someone has already compiled, and the shift worry is the hazard the assessor has not seen. Read the drawings, the permits and the incident history with the same eye — the change that arrived last quarter is the hazard the old assessment does not see.
Write every hazard down as a line: the source, who is exposed, what is already in place. The hazard that is not recorded is not identified, and step 2 has nothing to work on.
Step 2 — Decide who might be harmed
The hazard is not the only thing that sets the risk; the person exposed sets it too. The same press is a different risk to the trained operator, the apprentice, the maintenance technician and the visitor. The who-might-be-harmed line includes the employees, the contractors on the site, the visitors, and the people the work affects who are not on the site — the public below the crane, the driver at the gate.
The vulnerable groups are the ones the assessment must name: the new starter, the young worker, the older worker, the pregnant worker, the disabled worker, the lone worker, the person whose first language is not the site language. The HSE expects the assessment to consider the individual — the control that protects the average worker does not always protect the one the law names.
The who-line is what turns the generic assessment into the workplace one. The "all staff" that is written on every line is the line the investigation questions: the press hurts the operator first, and the forklift hurts the pedestrian who was not on the assessment.
Step 3 — Evaluate the risks, and decide the controls
Now the score. Each hazard line goes into likelihood and consequence on the 5×5 matrix: 1 to 4 low, 5 to 9 medium (ALARP), 10 to 15 high, 16 to 25 very high. The pre-control score is what is there now; the post-control score is what the control moves it to. Write both — the residual is what the review reads, and the ALARP argument is the post-control, written down.
The controls go in the hierarchy order, and the order is the point. Eliminate the hazard where you can — the task is not done, the substance is not used. Substitute — the less hazardous substance, the lighter load. Engineer — the guard, the ventilation, the barrier, the interlock. Manage — the procedure, the training, the signage, the exclusion. PPE is the last line, not the first — the control that fails when it is forgotten, and the one the investigation finds the worker was not wearing.
The high and very high lines get the owner and the date. The control without the owner is the control that does not happen, and the control without the date is the control that is always next month. The medium lines get the ALARP decision written; the low lines get the monitor and the review.
Step 4 — Record the findings
The record is the document the law expects where the business has five or more people, and the document the client, the insurer and the investigation read. The line per hazard: the source, who is exposed, the pre-control score, the control, the post-control score, the owner, the date. The assessment that is not recorded is the assessment that did not happen — the memory is not a finding.
Keep the record where the work happens, not only in the office file. The crew at the point of work should be able to read their hazards and their controls — the assessment that is locked in the office is the assessment the crew does not know, and the crew that does not know the assessment does not work it. Brief the record at the toolbox talk, and the record becomes the method.
The point-of-work assessment is the same sequence at the task scale: the hazards of the task, the who, the score, the controls, the record — the JSA is the point-of-work risk assessment, and the task is the workplace.
Step 5 — Review, and re-assess on the change
The assessment is a living document, and the review is the step that keeps it alive. Review on the calendar — at least annually, or per the site practice — and review on the event: the incident, the near miss, the change. The MHSWR put the re-assessment on the change, not on the calendar alone: the new machine, the new product, the new shift pattern, the new layout — the hazard that arrives with the change is the one the old assessment does not see.
The review checks three things: is the record still true (the control that was in place, is it still there?), is the residual still acceptable (the ALARP argument, still the case?), and is the crew working it (the briefing, the toolbox talk, the observation). The review that finds the control has gone, or the crew does not know the record, is the review that starts the re-assessment, not the one that signs it off.
The five steps, in one line: identify the hazards on the walkover, decide who is exposed, score the risk and put the control in hierarchy order, record it where the work happens, review it on the calendar and on the change. The method is small; the discipline is the job.
The mistakes that fail the review
The assessment that fails the review fails for a small set of repeatable reasons. The generic copy: the template from the internet, the "all staff" on every line, the hazard list that does not match the site — the review reads the site and finds the document was written for another building. The consequence understated: the fall scored as 3 when the height makes it a 5, and the very high that should be a very high comes out a high.
The control before it is in place: the post-control written for the guard on order, not the open edge that is there now. The PPE as the first control: the hierarchy reversed, the last line written first. The change not re-assessed: the new machine, the new product, the new shift — the hazard that arrived with the change, and the old assessment that does not see it. The record not briefed: the document in the office file, the crew at the point of work who do not know it.
The assessment is the preparation, and the competent person is the sign-off. Where the work is high-risk, the five steps are the method the competent person walks with you — the walk, the conversation, the decision, written down. That is the practical risk assessment: the method is small, and the discipline is the job.
Hazard vs Risk: the Difference (with Examples)
The hazard is anything with the potential to cause harm — the live cable, the open edge, the chemical, the moving plant, the noise, the height. The risk is the possibility that the hazard actually causes harm, measured on the likelihood against the severity — the score on the five-by-five. The same hazard, two risks: the cable that is guarded and isolated is the low risk, the same cable that is live and open is the high risk. The assessment moves the risk; the hazard stays until it is eliminated. The difference is the one the site gets wrong most often — the "hazard" written in the risk column, the "risk" written in the hazard column — and the one the auditor finds in the first row.
Definition of a Hazard (HSE) and Definition of Risk
The HSE definition, in the plain words: a hazard is "anything which has the potential to cause harm to people" — the thing, the state, the activity that can do the harm. A risk is "the possibility that someone could be harmed as a result of a hazard, and an indication of how serious the harm could be" — the likelihood and the severity, the number on the matrix. The US says the same in other words: the hazard is the source, the risk is the probability times the consequence. The definition is the one that keeps the two columns of the assessment straight — the hazard named, the risk scored, the control against the risk.
10 Examples of Hazard and Risk (the Pairs)
The ten pairs, the way the assessment writes them: the live cable (hazard) / the electric shock (risk); the open edge at height / the fall and the fracture; the chemical on the bench / the skin and the inhalation; the noise at 90 dB / the hearing loss; the vehicle in the yard / the struck-by and the crush; the moving plant / the cut and the amputation; the hot surface / the burn; the confined space / the asphyxiation; the lone worker / the delayed rescue; the manual load / the back injury. Each pair is a row of the assessment — the hazard named, the risk scored, the control against the risk, the review on the trigger.
Which Definition Best Matches "Hazard"? (the Exam Answer)
The exam question — "which definition best matches the term hazard?" — has one right answer: anything with the potential to cause harm. The "likelihood and the severity of the injury" is the risk, not the hazard. The "situation where the harm has already occurred" is the incident, not the hazard. The hazard is the potential, before the event — and the risk assessment is the document that finds the potential and prices it, before it finds the person.
Need the sign-off, not just the article?
The article is the preparation; the sign-off is the professional. For the statutory assessments, the audits, the ISO 45001 implementation and the training that comes with them, ask Muhammad Umer — 8+ years across Iraq, KSA and Pakistan, and the programme runs through umer-hse.pro. One message gets the written scope.
Common questions
How to Do a Risk Assessment in the Workplace (5-Step, Practical) — answered
How do you do a risk assessment in the workplace?
The 5-step method: identify the hazards on the walkover (the six families, the two crew questions), decide who might be harmed, evaluate the risks on the 5×5 matrix and decide the controls in hierarchy order, record the findings where the work happens, and review on the calendar and on the change.
What are the 5 steps of risk assessment?
1 · Identify the hazards. 2 · Decide who might be harmed. 3 · Evaluate the risks and decide the controls. 4 · Record the findings. 5 · Review and update. The UK MHSWR expect the sequence; the ISO 45001 clause 6.1 works from the same logic.
What is a point-of-work risk assessment?
The risk assessment at the task scale: the hazards of the task, the who, the score, the controls, the record — the JSA is the point-of-work risk assessment. It is the same five steps applied to the job, done before the first step, signed by the crew.
Who should carry out a risk assessment?
The employer, or a competent person they appoint. The competent person is the one with the knowledge, the training and the experience of the workplace — and where the work is high-risk, the competent person is the sign-off the template is the preparation for.
How often should a risk assessment be reviewed?
At least annually, or per the site practice, and on the event: the incident, the near miss, the change. The MHSWR put the re-assessment on the change — the new machine, the new product, the new shift pattern — not on the calendar alone.
Is a risk assessment a legal requirement in the UK?
Yes, where the business has five or more people: the MHSWR 1999 require a written risk assessment, and the COSHH Regulations require the chemical version per substance. Below five, the assessment is still the duty — it is not written, but it is done.
What is the difference between a risk assessment and a hazard assessment?
There is no separate "hazard assessment" in the UK system: hazard identification is the first step of the risk assessment. The identification finds the hazards; the assessment scores the risks and decides the controls. The hazard identification is the eye; the risk assessment is the eye and the brain together.
Keep reading
Related articles
Hazard vs Risk: The Difference, Explained With Examples
Hazard vs risk, explained: what each term means in health and safety, the difference between hazard and risk w
Risk Assessment · 23 August 2026What Is Risk in Health and Safety? The Definition, the Formula, the Rating
What is risk in health and safety? The definition, the likelihood × consequence formula, the 5×5 rating bands,
Risk Assessment · 26 August 2026What Is a COSHH Risk Assessment? The Substance-by-Substance Method
What is a COSHH risk assessment? The substance-by-substance method: the exposure route, the group, the hierarc
THE HEALTH AND SAFETY is an education and knowledge network. The articles are free and open; the professional assessments and the training run through umer-hse.pro.
Safety disclaimer
The articles on this blog are practical guidance, built to the UK baseline with the US equivalents named in the text. They do not replace a competent person assessment for high-risk work, a statutory assessment, or the advice of your insurer. Where a duty has legal force — the fire risk assessment, the risk assessment, the COSHH register — the responsible person owns it. Read the article as the preparation, and take the sign-off from the competent person.
