Ask ten people on a site walk to tell you the difference between a hazard and a risk and you will get three confident answers, four approximations and three shrugs. It rarely seems to matter. Then you read the risk assessment that same team produced, and it matters enormously: the hazard column contains things like "injury to operative", the risk column contains things like "working at height", and the control column contains a training course aimed at neither. Nobody in that room was careless. They just never had the distinction explained in a way that showed them what it is for.
The message up front: a hazard is a source of potential harm, and it exists whether or not anybody is near it. Risk is the combination of how likely that harm is and how severe it would be, and it only exists in a situation, with exposure and controls in it. The practical consequence is the whole point: you can eliminate or substitute a hazard, but you can only ever reduce a risk. That single asymmetry is why the hierarchy of controls puts elimination at the top, and why an assessment that muddles the two ends up pointing its controls at the wrong thing.
1. The two ideas, stated plainly
A hazard is a source of potential harm. It is a property of a thing, a substance, an energy, a process or a situation. Mains voltage is a hazard. A rotating shaft is a hazard. A solvent that damages the liver is a hazard. A four-metre drop is a hazard. A bullying management culture is a hazard. In each case the harm-causing potential is intrinsic: the voltage does not become less able to kill you because the panel door is locked, and the drop does not get shorter because you fitted a guardrail. Lock the door and fit the rail and the hazard is exactly what it was. Something else changed.
That something else is risk. Risk is the combination of the likelihood that the hazard actually causes harm and the severity of that harm if it does. It is not a property of the thing. It is a property of the whole situation: who is exposed, how often, for how long, under what conditions, with what controls in place, and how competent and predictable those people and controls are. Change any of those and you have changed the risk without touching the hazard.
The test I use when reviewing an assessment is a single question: could this entry exist in an empty building at 3am? If yes, it is a hazard. Mains voltage in a distribution board exists at 3am with nobody in the building. The risk of electrocution does not, because there is no exposure. Hazards persist; risk is contingent.
This vocabulary is not folklore. It is formalised in the risk management and occupational health and safety standards that most organisations work to, principally ISO 45001:2018 "Occupational health and safety management systems", as amended by Amd 1:2024, which is the certifiable OH&S management system standard, and ISO 31000:2018 "Risk management", which is worth naming carefully: ISO 31000 is guidance and is not certifiable. There are no auditable requirements in it, so there is no accredited ISO 31000 certification for an organisation, whatever anyone selling one implies. Its companion for technique selection is IEC 31010:2019 "Risk management. Risk assessment techniques", and note the prefix: it is IEC 31010, not ISO 31010. I am naming these as the places the vocabulary is formalised rather than quoting them, because the text is paywalled and paraphrasing normative wording from memory is how bad citations get born.
2. The contrast across the dimensions that matter
Definitions stated side by side do more work than definitions stated in sequence. This is the table I put on the whiteboard before running any risk assessment workshop.
| Dimension | Hazard | Risk |
|---|---|---|
| What it is | A source of potential harm | The combination of likelihood of harm and severity of that harm |
| Where it lives | In the thing, substance, energy, process or situation | In the situation as a whole, including people and controls |
| Needs exposure? | No. It exists with nobody present | Yes. No exposure pathway means no risk, however severe the hazard |
| Affected by controls? | Only by removal or substitution. Guarding does not change it | Yes. Every control acts on likelihood, severity or both |
| How it is expressed | A noun. "Compressed gas cylinder", "chlorine", "unguarded nip point" | A judgement or a rating, qualitative or scored, always about a specific harm |
| What you can do to it | Eliminate it, substitute it for a less harmful one, or accept that it stays | Reduce it. You cannot eliminate risk while the hazard and any exposure remain |
| Where it appears in the process | Step one: hazard identification | Step two onward: risk evaluation, control, review |
| Stability over time | Largely fixed unless the design or the substance changes | Moves constantly with staffing, workload, weather, competence, control condition |
| Typical assessment error | Listing a consequence ("burns") in the hazard column | Rating a hazard instead of a specific harm pathway |
Read down the "Affected by controls?" row and the "What you can do to it" row together, because those two are where the distinction stops being semantic and starts changing decisions.
3. You eliminate hazards. You only reduce risk.
This is the consequence that readers actually need, and it is the reason the terminology is worth getting right.
Because a hazard is intrinsic, there are only two ways to act on the hazard itself: take it away, or swap it for something with less harmful potential. Remove the need to work at height by assembling at ground level and the fall hazard is gone, not controlled, gone. Replace a solvent-based adhesive with a water-based one and the toxicity hazard has been substituted, not managed. In both cases you have not reduced a risk, you have removed the thing the risk was about, and the risk goes to zero as a side effect.
Everything else on the control list works on risk, not hazard. Guarding, interlocks, local exhaust ventilation, isolation, permits, safe systems of work, supervision, training, signage, respiratory protection: all of them leave the hazard exactly as harmful as it was and act instead on likelihood, on severity, or on the exposure pathway between the hazard and the person. That is legitimate and often unavoidable work. But it is a different kind of intervention, and it has a different failure mode. A hazard that has been eliminated cannot come back through inattention. A risk that has been reduced by a control can climb straight back the moment the control degrades, the guard is defeated, the extraction fan fails, the trained operator leaves or the permit becomes a signature ritual.
Why the hierarchy is ordered the way it is
The hierarchy of controls is not a preference list somebody arranged for neatness. It is ordered by how much it depends on human behaviour holding up over time. Elimination and substitution act on the hazard and stay done. Engineering controls act on the risk but stay in place without anyone deciding each morning to comply. Administrative controls and personal protective equipment act on the risk and depend on a person doing the right thing every single time. Understanding hazard against risk is what makes that ordering obvious rather than arbitrary. The hierarchy is required by ISO 45001:2018 clause 8.1.2 and described on a free public page by NIOSH in the United States. It is a principle, not a standard in its own right, and US OSHA does not codify the term in any regulation.
The full ordering, its tiers, where reorganisation of work sits and how to apply it properly belongs to the hierarchy of controls guide. I am only making the linguistic point here: if your team cannot separate hazard from risk, they will reach for the bottom of the hierarchy by default, because administrative controls and PPE are the natural answers to "how do we make this safer" while elimination is the answer to a question about the hazard that nobody asked.
4. Worked contrasts: same hazard, very different risk
Abstraction is where this distinction goes to die, so here are illustrative scenarios. These are my own hypotheticals, deliberately simplified to isolate one variable at a time, and the ratings are descriptive words rather than scores because a numeric scale presented as authoritative would be its own kind of error.
| Hypothetical scenario | Hazard (unchanged) | What differs | Risk of harm |
|---|---|---|---|
| A1. Sealed drum of concentrated acid in a locked, bunded, ventilated store; opened twice a year by a trained chemist in full PPE | Corrosive substance | Baseline: rare exposure, competent person, engineered containment | Low |
| A2. The same drum, decanted by hand into open buckets twice a shift in a corridor, no extraction, no face protection | Corrosive substance (identical) | Exposure frequency, no containment, no barrier between person and hazard | High |
| A3. The same drum, in a store that was decommissioned and is now permanently sealed with no access and no work activity | Corrosive substance (identical) | No exposure pathway at all | Negligible while that remains true |
| B1. 11 kV switchgear in a locked substation, worked on only under isolation and permit by an authorised person | High-voltage electrical energy | Isolation, access control, competence, permit | Low |
| B2. The same switchgear with a door lock that has been broken for a month and a cleaning contractor storing equipment inside | High-voltage electrical energy (identical) | Control has degraded; an untrained group is now exposed | High |
| C. A severe hazard with almost no risk: a large sealed radioactive source in a shielded, interlocked enclosure with no one entering during operation | Ionising radiation, very high harm potential | Severity extreme, likelihood of exposure engineered close to zero | Low, entirely dependent on the interlock and shielding staying intact |
| D. A mild hazard with high risk: a shallow water spill on a polished floor at the head of a stair used by 400 people an hour, unmopped and unsigned | Slip hazard, modest harm potential per event | Severity moderate, likelihood very high, and the stair raises the credible worst case | High |
Rows A1 to A3 are the core lesson: one hazard, three risk levels, and nothing about the acid changed. Rows C and D are the lesson people find harder, because they break the instinct that dangerous-sounding things carry high risk and mundane things carry low risk. In real portfolios it is overwhelmingly the mundane hazards with heavy exposure that produce the injuries, while the dramatic hazards sit behind engineering that works. Which is exactly why the next point needs making.
5. "High hazard" and "high risk" are not synonyms
These two phrases get used interchangeably in toolbox talks, method statements and permits, and the sloppiness has consequences.
High hazard properly describes severity of potential harm: the hazard could kill or cause serious irreversible harm if it were realised. Confined space atmospheres, high-voltage energy, stored pressure, work at height, toxic gas. High risk describes a situation where harm is judged likely enough and severe enough, given the exposure and the controls, to demand action now. A high-hazard activity that is well engineered and tightly permitted can legitimately be a lower-risk activity than a low-hazard task performed constantly with no controls at all.
Where I see the confusion cause real trouble:
- Permit systems keyed to the wrong word. If a permit regime is triggered by hazard severity alone, it captures every confined space entry, including well-controlled routine ones, and misses the sustained high-exposure work that actually generates injuries. If it is triggered by risk rating alone, then a control being applied well drops the rating and quietly drops the permit, which is the wrong direction entirely. Sound practice is to trigger the permit on the hazard class, because the hazard does not improve, and use the risk assessment to decide the precautions written on it. That is the logic behind the way permit workflows are usually structured, including when they are automated inside a maintenance system, and it is covered in the permit to work integration guide.
- Prioritisation by the wrong dimension. Teams that equate the terms rank their action plan by how frightening the hazard sounds, so the shielded source gets the attention and the stairwell does not. Ranking by risk fixes this, and ranking by risk requires being able to tell the two apart.
- Complacency after a rating drop. When people believe reducing risk has dealt with the hazard, control verification loses its urgency. The guard becomes something that was fixed once rather than something that must still be there next year. Scenario B2 above is this failure in miniature.
- Contractor briefings that describe the wrong thing. "This is a high-risk site" tells an incoming contractor nothing actionable. "This site has live high-voltage distribution, confined spaces and overhead lifting, and here are the controls each one sits behind" tells them what to prepare for.
6. Where each term sits in the assessment process
The process has an order, and the order is not cosmetic. You identify hazards first, then evaluate the risk arising from each. In Great Britain the duty to carry out a suitable and sufficient assessment of risk sits in Regulation 3 of the Management of Health and Safety at Work Regulations 1999 (SI 1999/3242). Note the jurisdiction: that is Great Britain, Northern Ireland has separate legislation, and neither has legal force in the Gulf, where the binding instruments are national and emirate-level. I am naming it because it is the clearest statutory illustration that the duty is expressed as an assessment of risk, which presupposes that hazards were identified first. That is the only jurisdictional qualification I will make here: the concepts below travel, the legal duties do not, and you should confirm what applies where you operate and work within your own competence.
Sequenced, the distinction maps onto the process like this:
- Identify hazards. Walk the area, read the safety data sheets, study the task, interview the people doing it, look at the incident and near-miss history. Output: a list of sources of potential harm. No ratings yet. The methods for doing this properly, and how to avoid the classic blind spots, are the subject of the hazard identification guide.
- Identify who could be harmed and how. This is the exposure step, and it is the bridge from hazard to risk. It is also the step most commonly skipped, which is why so many assessments jump from a hazard straight to a score with no stated harm pathway.
- Evaluate the risk. For each credible harm pathway, judge likelihood and severity with existing controls taken into account. How to structure that judgement, and the honest limits of scoring it, belong to the risk assessment matrix guide.
- Decide and record controls. Applied in hierarchy order, starting with whether the hazard can go away entirely.
- Record, communicate, review. Review is triggered by change, and the changes that matter most are the ones that move exposure or degrade controls, because those move risk without touching the hazard.
The full process, with worked examples end to end, is the complete risk assessment guide, and both sit under the broader what is HSE overview. What I want to flag is the specific failure that conflating the terms produces.
The tell-tale broken assessment
An assessment that conflates the two ends up rating risks it never identified hazards for. You see a row that reads: hazard, "slips and trips"; risk, "medium"; control, "good housekeeping". Nothing in that row names a source of harm, nobody has said what the harm is or who is exposed, and the control cannot be verified because there is no stated condition it is supposed to address. Reviewers sign it because it looks like the template. The assessment is complete, auditable, and tells no one anything. This is the single most common defect I encounter, and it is a vocabulary problem wearing a paperwork costume.
7. The related words people mix in, and where each fits
Hazard and risk do not sit alone. Five other terms get folded into the same conversation, and placing them correctly makes the original distinction easier to hold.
- Harm is the actual injury, illness, damage or loss. It is what the hazard is capable of causing and what the risk is the chance of. "Burns", "hearing loss" and "fatality" are harms, which is why they are wrong in a hazard column.
- Consequence is the harm plus everything downstream of it: the injury, the lost production, the environmental release, the reputational damage. Consequence is the severity half of risk.
- Likelihood is the chance that the harm occurs in a stated period or per exposure. It is the other half of risk. It is not the same as frequency of the task, though frequency drives it, and it is not the same as how often the hazard is present.
- Exposure is the contact, or possible contact, between the person and the hazard: who, how close, how often, how long, in what conditions. Exposure is the mechanism by which a hazard becomes a risk, and it is the variable most controls actually attack.
- Hazardous event is the distinction worth spending a moment on. A hazard is the source. A hazardous event is the occurrence in which the hazard is released or contacted: the fall, the arc flash, the spill, the ignition, the unexpected start-up. The hazard is the stored energy in a raised load; the hazardous event is the load dropping. Many risk assessments are much clearer once the event is written down explicitly, because the event is what controls are designed to prevent, and separating prevention of the event from mitigation of its consequences is often the most useful thing an assessment does. If your work touches machinery specifically, this event-centred framing is how machinery risk is conventionally handled, and the relevant reference is ISO 12100:2010 "Safety of machinery. General principles for design. Risk assessment and risk reduction", which consolidated and replaced ISO 12100-1:2003, ISO 12100-2:2003 and ISO 14121-1:2007, and is currently under revision.
There is a neighbouring distinction that trips up the same people for the same reason: unsafe act against unsafe condition. A condition is closer to a hazard, an act is closer to an exposure decision, and conflating those two produces investigations that blame individuals for situations.
8. Inherent and residual risk: the consequence of risk depending on controls
If risk is a function of the controls in place, then the same hazard has more than one honest risk rating depending on which controls you count. That is not a flaw in the concept, it is a direct consequence of it, and it produces two terms that are worth using deliberately.
Inherent risk is the risk before the controls under consideration are applied, or with only the design and the nature of the work counted. Some organisations call it initial, gross or unmitigated risk. Residual risk is the risk that remains once the controls are in place and working as designed. The gap between them is the claimed value of the control set, and writing both down is what makes that claim visible and challengeable.
The failure I see repeatedly is an assessment that records one and then acts as though it were the other, in both directions:
- Recording residual risk and treating it as the real state of affairs. The assessment shows "low" everywhere because every row assumes the extraction is running, the guard is fitted, the permit is honoured and the operator is trained. Nobody has verified any of that recently. The rating describes a designed world, not the site as it stands, and the register becomes a record of intentions.
- Recording inherent risk and planning against it. Everything reads "high", so nothing is prioritised, and the assessment loses its ability to direct attention. Teams then stop reading it, which is worse than not having it.
- Recording both but never reviewing whether the gap is still real. This is the most insidious version. The numbers were right the day they were written. Two years later the extraction has lost capacity, the interlock has been bypassed for a changeover and never restored, and two of the three trained operators have left. The hazard has not changed at all. The residual risk has quietly climbed back toward inherent, and the document still says low.
Where the distinction is genuinely unhelpful
I am not going to pretend the terminology solves everything. Two honest limitations. First, inherent risk is partly arbitrary: which controls you strip out to calculate it is a judgement call, and two competent assessors will produce different inherent ratings for the same task, so comparing inherent scores across teams or sites is close to meaningless. Second, some hazards are so entangled with the design that separating hazard from control is artificial. Ask whether a pressure vessel's wall thickness is part of the hazard or part of the control and you will get a philosophy seminar rather than an answer. In those cases stop arguing about categories, write down the hazardous event you are trying to prevent, and control that. The vocabulary is a tool for clear thinking. When it stops helping you think, put it down.
A related observation from asset-heavy environments: residual risk depends on control condition, and control condition is a maintenance question. The interlock, the guard, the extraction fan, the relief valve and the gas detector are all assets with a failure mode and a maintenance regime. If safety-critical controls are not identified as such in the asset register and prioritised accordingly, residual risk drifts without anybody deciding to let it. That intersection is one of the more useful applications of asset criticality classification: criticality driven by the consequence of the control failing, not by replacement cost.
9. Why this is practical rather than pedantic
There is a fair objection to everything above: does it actually matter, if the team knows the work and applies sensible controls? Plenty of safe sites are run by people who use the words loosely.
It matters for a specific and non-pedantic reason. The distinction is the mechanism by which an assessment connects a control to a thing the control is supposed to act on. When hazard and risk are clear, every control in the document has a traceable job: this one removes that hazard, this one interrupts that exposure pathway, this one reduces the severity of that event if it happens. Each of those claims can be tested, verified and audited, and when one degrades you can see what it was holding up.
When the terms are blurred, that traceability is gone. Controls end up attached to vague nouns, so nobody can say what a control is for, whether it is working, or what would happen if it stopped. The document still exists and still gets signed. But it has stopped being an instrument for managing anything and become a record that a meeting happened. That is the actual cost, and it is why I spend the first twenty minutes of a risk assessment workshop on vocabulary that everyone in the room believes they already understand.
The other practical payoff is that clear language surfaces elimination. Teams that habitually separate hazard from risk ask "can this hazard go away" as a matter of course, because the question is built into the vocabulary they are using. Teams that do not, ask "how do we make this safer", and that question almost always returns a procedure and some PPE. Over years, across hundreds of assessments, that difference in habitual question is worth more than any scoring refinement.
The idea to walk away with
A hazard is a source of potential harm and it exists whether or not anyone is exposed to it. Risk is the combination of how likely that harm is and how severe it would be, and it exists only in a situation that includes exposure and controls. From that one distinction everything practical follows: you eliminate or substitute hazards and you reduce risks, which is why the hierarchy of controls is ordered as it is; the same hazard can carry wildly different risk depending on exposure; a severe hazard can carry negligible risk and a mild one high risk; hazards are identified before risks are evaluated; and risk ratings are always relative to a set of controls, which is why inherent and residual are different numbers and why recording one while acting on the other is a real and common failure.
If you want one diagnostic, use this: pick any row of your current risk assessment and ask whether the hazard column names something that would still be there in an empty building. If it does not, the row is describing a consequence or a task, not a hazard, and whatever the risk column says next to it is an assessment of nothing in particular.
Final thoughts
The reason this question keeps getting asked is that it feels too simple to be worth a proper answer, so it usually receives a one-line one, and the one-line answer does not carry the consequence. The consequence is what changes behaviour: hazards can be removed, risks can only be reduced, and an assessment that cannot tell the two apart will aim its controls at whichever of them the author happened to be thinking about.
None of this requires a new template or a better scoring scale. It requires a team that can say, out loud, what the source of harm is, who is exposed to it, what event you are trying to prevent, and which control is doing which job. Get that far and the paperwork mostly writes itself and, more importantly, becomes worth reading. Whatever framework, standard or software you use to record it, the vocabulary is what makes the record mean something, and no system will supply it for you.
Disclosure
Alongside advisory work I also build a CMMS and CAFM platform, so I have a commercial interest in this category. Nothing above is a recommendation for it, and no vendor named here has paid for inclusion or had any editorial input. Weigh the analysis accordingly.
Risk assessments that nobody reads?
Independent advisory on hazard identification, risk assessment structure, control verification and how safety-critical controls are tracked in the systems that already hold your asset and work data. 22+ years across utilities, oil and gas, manufacturing, government and facility operations.
Book a conversationRelated reading: What is HSE, Risk assessment: complete guide with examples, Hierarchy of controls, Hazard identification methods, Risk assessment matrix, Unsafe act vs unsafe condition.
Primary sources: UK HSE , Management of Health and Safety at Work Regulations 1999 , ISO , NIOSH .
Muhammad Abbas
CMMS / CAFM Manager & Independent Advisor · 22+ years across enterprise CMMS, EAM, CAFM and ERP implementations in utilities, oil and gas, manufacturing, government and facility operations.
Work with me