Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

ISO 45001 Risk Assessment — guide from Governance Docs

ISO 45001 Risk Assessment: Hazard Identification That Holds Up

ISO 45001 risk assessment is the engine of the standard. Clause 6.1.2 requires a
process for hazard identification and assessment of OH&S risks, and clause 8.1.2 governs what you
do about them. This guide covers what the process must contain, how to document the method, and the
mistakes that turn a risk register into an audit finding.

ISO 45001 risk assessment asks for two things, not one

Clause 6.1.2 splits into hazard identification and the assessment of risks, and it is worth
keeping them separate in your own process. Hazard identification is ongoing and proactive: it must
take account of routine and non-routine activities, human factors, past incidents, changes in the
organisation, emergency situations, and the people who have access to the workplace — including
contractors and visitors. Assessment is what you then do with each hazard.

The documented deliverable is the methodology, not just the register. The standard
requires you to maintain documented information on the methodology and criteria for the assessment of
OH&S risks. Most organisations produce a populated spreadsheet and no written method, then cannot
explain at audit why a given hazard scored what it scored. That gap is the most common finding in this
area, and it is entirely avoidable.

What an ISO 45001 risk assessment must record

  • Activity or area, and whether it is routine or non-routine.
  • Hazard — the thing with potential to cause harm, stated specifically.
    “Working at height” is a category; “unprotected leading edge on mezzanine during stock picking” is a
    hazard.
  • Who might be harmed, explicitly including contractors, visitors, and anyone
    outside the organisation affected by the work.
  • Existing controls already in place.
  • Severity and likelihood, scored against criteria defined in advance in the
    documented methodology.
  • Risk rating and acceptability against a stated threshold.
  • Additional controls, each tagged with its level in the hierarchy.
  • Residual risk, and whether the control introduced any new hazard.
  • Owner, target date and verification that the control was implemented and works.
  • Review trigger — the date or the event that forces reassessment.

The hierarchy of controls is a requirement, not advice

Clause 8.1.2 requires elimination of hazards and reduction of OH&S risks using a hierarchy,
in this order: eliminate the hazard; substitute with less hazardous processes, operations,
materials or equipment; use engineering controls and reorganization of work; use administrative
controls including training; use adequate personal protective equipment.
Each level is less
effective than the one above it, and you move down only where the higher level is not reasonably
practicable.

This is where an ISO 45001 risk assessment most often falls down. A register where nearly every
control is training, signage, a permit or PPE is not evidence of the hierarchy being applied —
it is evidence of the bottom two rungs being applied by default. Auditors read the control column for
exactly this pattern. Record which level each control sits at, and where you rejected a higher level,
record why.

A risk assessment method and register that already fit clause 6.1.2.

The ISO 45001 Toolkit includes the documented risk assessment methodology, a hazard identification and risk register workbook with hierarchy-of-controls tagging, and the change-management form that keeps it current.

Explore the ISO 45001 Toolkit →

Where an ISO 45001 risk assessment must connect

An ISO 45001 risk assessment is not a standalone document, and auditors test the joins. Its
outputs set your operational controls under 8.1, drive the objectives you set under 6.2, determine
what emergency scenarios you plan for under 8.2, shape the competence requirements under 7.2, and
must be revisited when incidents are investigated under 10.2. If a serious incident is investigated
and the register is never updated, the loop the standard is built around is broken.

Clause 8.1.3 adds management of change to the ISO 45001 risk assessment cycle: risks arising from new processes, new equipment, new
premises or new legal requirements must be assessed before the change, not after the first
near miss.

Psychosocial risk is in scope

Hazards under ISO 45001 are not only physical. Clause 6.1.2.1 requires human factors and work
organisation to be considered, which brings workload, working hours, bullying and harassment into
scope. ISO published ISO 45003:2021
as guidance for managing psychosocial risk within an ISO 45001 system. It is guidance, not a
certifiable standard, but registers that contain no psychosocial hazards at all increasingly attract
questions — and in several jurisdictions the law has moved ahead of the register.

Keep ISO 45001 risk assessment scoring defensible, not elaborate

For ISO 45001 risk assessment, a five-by-five severity and likelihood matrix is conventional and sufficient. What matters is that
the scales are defined in advance in your methodology, applied consistently by people trained to use
them, and that the acceptability boundary is stated. An intricate scheme applied inconsistently is
weaker than a simple one applied well — and if no hazard in the register ever scored
unacceptable before controls, expect that to be probed.

References

More on ISO 45001

All of these are covered by the ISO 45001 Toolkit. To score where you stand first, use the ISO 45001 Assessment Tool, or browse the free ISO templates.

Stay Compliance-Ready

Get compliance tips, new toolkit releases, and standard updates in your inbox.

We don’t spam! Read our privacy policy for more info.