mail@mabbaz.com Abu Dhabi, UAE

HSE · Risk Management · Facility Operations

HIRA: Hazard Identification and Risk Assessment

HIRA joins two different intellectual tasks under one name, on purpose. This guide explains what the term means, why identification and assessment are deliberately bolted together, where HIRA sits organisationally against a job safety analysis or a permit risk assessment, and the specific places where the join between the two halves quietly breaks.

Muhammad Abbas September 27, 2026 ~16 min read

In occupational health and safety, HIRA stands for Hazard Identification and Risk Assessment, and that is what this article is about. The acronym is used for other things in other fields, so if you arrived looking for one of those, this is not the page you want. If you are here for the safety meaning, the useful question is not what the four letters expand to. It is why two separate activities were given one joined-up name, and what goes wrong when organisations keep the name but stop doing both halves.

The message up front: HIRA is a framing that insists on the whole chain, from finding a hazard through to a rated risk with a named owner and a control. Identification without assessment produces a register nobody prioritises. Assessment without proper identification rates an incomplete list with impressive confidence. Joining them in one named exercise is meant to stop either happening alone. In many organisations, though, HIRA has become the name of a spreadsheet rather than the name of a practice.

This is a general explanation of how the combined exercise is structured and governed. A HIRA for a real site must be carried out by people competent in the work and the hazards involved, against the legal framework that applies in your own jurisdiction.

1. What HIRA means, and what it is not

Hazard Identification and Risk Assessment. Two verbs, two outputs. Hazard identification asks what in this workplace, process or activity has the potential to cause harm. Risk assessment asks, for each of those, how likely harm is, how severe it would be, what already controls it, and therefore what priority it deserves and what else needs doing.

It is worth being plain about the status of the term. HIRA is not defined by a numbered international standard. It is a widely used practitioner framing, common across the Gulf, South Asia, and the parts of the world where management-system language dominates safety practice. You will not find a clause that says "the organisation shall conduct a HIRA". What you will find are duties and requirements that describe the same work under different words: a general duty to assess risk in a national legal framework, and requirements in a management-system standard to identify hazards and assess occupational health and safety risks. The acronym is the industry's shorthand for satisfying those, not a standard in its own right.

That matters practically, because nobody can tell you what a HIRA must contain by quoting a standard number at you. What an organisation must do is set by its own jurisdiction and by whatever management system it has committed to. The structure below is what competent practice looks like, not a compliance checklist. If the hazard-versus-risk distinction is not yet solid for you, that is the foundation everything else rests on: see hazard vs risk, and what HSE means for the surrounding territory.

2. Why the two halves are deliberately joined

This is the part most explanations skip, and it is the whole reason the acronym exists.

Identification and assessment are different intellectual tasks with different failure modes. Identification is divergent work. It rewards breadth, imagination, awkward questions, and people who have actually done the job at three in the morning when the normal method did not work. Its failure mode is omission: you simply do not think of the thing that later hurts someone, and nothing in your process tells you it is missing, because an absent hazard leaves no trace on the page.

Assessment is convergent work. It rewards consistency, calibration, evidence, and the discipline to rate two similar situations the same way. Its failure mode is false confidence: a neat, internally consistent set of ratings that looks authoritative and is entirely correct about the wrong list.

Each half fails silently on its own. Assessment done without proper identification rates an incomplete list, and the polish of the output actively hides the gap. Identification done without assessment produces a long, flat inventory in which everything is a hazard and therefore nothing is a priority, which is the register that gets printed, filed and never consulted. Bolting them together under one name is a structural fix for two problems that do not announce themselves.

The point of the joined name

HIRA is a commitment to the whole chain: hazard, risk, control, owner, date, evidence. The moment an organisation can do one half and still say it has "done its HIRA", the framing has stopped working and only the filename survives.

The honest observation from advisory work: in a great many organisations HIRA has become the name of a spreadsheet. There is a file, it has the right columns, it is produced when an auditor asks, and the people planning next week's work have never opened it. That is not a HIRA. That is a document about a HIRA that nobody performs.

This article deliberately does not re-teach either half. Identification methods are covered in full in hazard identification methods and process, and the assessment process end to end is covered in the risk assessment guide. Read those for the how. What follows is the integration, the governance, and the organisational view, which is what HIRA as a combined exercise actually adds.

3. Where HIRA sits: the layers of assessment

Readers genuinely do not know how HIRA, a general risk assessment, a job safety analysis and a permit risk assessment relate to one another, and no wonder: the words overlap and different organisations use them differently. The clean way to think about it is by time horizon and the decision each layer serves.

HIRA is typically a standing exercise at organisational, facility, process or asset-group level. It produces and maintains a risk register. It is not about a job. It is about a place and the activities that happen there, over a horizon of months and years, and it exists to inform programmes, resourcing, design and capital decisions. A JSA is the opposite end: task level, specific crew, specific shift, and its job is to tell the people about to start work what will hurt them in the next few hours.

Those are different products for different customers, and trying to make one do the other job is the most common conceptual error in this space. A facility HIRA cannot brief a crew, and a JSA cannot tell a board where next year's safety capital should go.

Layer Typical scope Time horizon Decision it serves Typical owner
HIRA Site, facility, process, or asset group and its activities Months to years, maintained continuously Programmes, budgets, resourcing, design change, training strategy, insurance and assurance Line management for the area, supported by the safety function
General risk assessment A defined activity or hazard class across the organisation, for example manual handling or a substance group Weeks to years Standard method statements, control specifications, what the rule for this activity should be Activity or discipline owner
JSA One task, broken into steps The job, typically hours to days How this crew does this task safely today, and what they need in hand before starting Supervisor and the crew doing the work
Permit risk assessment One high-hazard job at one location at one time, under a permit The permit validity window Whether this specific job may proceed now, under what isolations and conditions, and who may authorise it Permit issuer and authorising authority
Dynamic assessment Conditions as found at the workface Minutes Proceed, adapt, or stop the job The person doing the work

The layers should feed each other. A HIRA that identifies a confined-space hazard class at a site should be why a permit regime exists for those spaces at all; the permit then handles the specific instance. A recurring finding in JSAs, or a pattern in near miss reports, should push upward into the HIRA as evidence that a hazard was under-rated or missing. When the layers are disconnected, the bottom layers absorb risk the top layer should have designed out, which is a slow, quiet transfer of burden onto the people at the workface.

For the task layer in detail, see the JSA guide, and for the permit layer, the permit to work guide. Worth noting on permits: no international standard specifies a permit-to-work system. The widely used reference is Great Britain's HSE guidance HSG250 (2005), written for the petroleum, chemical and allied industries, and it is guidance, not law, creating no duties of its own.

4. How the combined exercise is organised

Six things have to be got right for a HIRA to function as a practice rather than a document. Note that steps three, four and five are exactly the points where the sibling articles carry the depth, and I defer to them rather than repeating.

Define the scope and the boundary. Is this HIRA for a site, a building, a process, an activity, or an asset group? Where does it stop? A poorly drawn boundary is the most common structural flaw I encounter, and it fails in both directions. Drawn too wide and the exercise becomes a shallow sweep of everything with the depth of a poster. Drawn too narrow and hazards live in the seams: the loading bay that belongs to logistics in one register and to facilities in another, the rooftop plant that the building HIRA treats as someone else's equipment, the contractor compound nobody owns. Write the boundary down explicitly, including what is deliberately excluded and where that exclusion is covered instead.

Assemble the right people. You need a mix of deep knowledge of how the work is actually done and genuine independence from it. People who do the job know the workarounds, the shortcuts, the thing that always jams. People from outside ask why, and are willing to record an answer that is inconvenient. Either group alone produces a predictable distortion: insiders normalise what they live with, outsiders miss what is never written down. Include the maintenance function, include contractors where they do the work, and include someone with authority to commit resources, because a register full of actions nobody can fund is a wish list.

Work through identification using structured prompts. Free-form brainstorming under-performs a structured sweep. Use energy types, activity walkthroughs, hazard checklists appropriate to the industry, maintenance and incident history, and a structured technique where the risk warrants it. IEC 31010:2019 "Risk management - Risk assessment techniques" is the catalogue of recognised techniques and is the right reference when you need to choose a method deliberately. The depth on methods belongs to the identification article.

Assess what was found. Apply a consistent approach to consequence, likelihood and existing controls, and record the reasoning rather than only the result. Rating mechanics, matrix design and the traps in scoring belong to the risk matrix article. I publish no scale or band descriptors here on purpose: yours should be the one your organisation has calibrated and can apply consistently, not one borrowed from an article.

Determine controls through the hierarchy. Work down from elimination rather than starting at personal protective equipment, which is where tired assessments tend to land. The hierarchy of controls is a principle rather than a standalone standard: it is required by ISO 45001:2018 at clause 8.1.2 and by ANSI/ASSP Z10.0-2019 (United States) at section 8.4, and described by NIOSH (United States) on a free public page. NIOSH is a research body with no regulatory power, which is worth knowing when someone cites it as though it were enforcement. The depth is in the hierarchy of controls guide.

Assign ownership and dates, and record the reasoning. Every action gets a named individual, not a department, and a date. And the record must preserve why, not only what: why this consequence was judged credible, what control was assumed to be working, what was considered and ruled out. Ratings without rationale cannot be reviewed by anyone who was not in the room, which means at the next review they are either accepted on faith or redone from scratch.

5. The register as a living artefact

The output of a HIRA is a risk register, and registers divide sharply into the ones that do work and the ones that exist.

A useful register has traceability running all the way through: from the hazard, to the risk, to the control relied upon, to the person who owns it, to the evidence that it is in place and working. You can start at any point in that chain and walk it in either direction. Ask "what are we relying on to stop this" and get an answer. Ask "if this inspection stopped happening, what becomes unmanaged" and get an answer. That bidirectional traceability is what turns a list into a management tool.

A dead register has recognisable symptoms. It is updated once a year, shortly before an audit. Ratings carry no rationale. Actions have owners but no dates, or dates long past with no closure. Controls are named generically, so "training" appears as a control with no indication of what training, for whom, refreshed how. And the decisive symptom: nobody consults it when planning work.

The practical test of whether a HIRA is real

Can someone planning a job find the relevant entry, and does it tell them something they did not already know? If the answer to the first is no, the register is not accessible. If the answer to the second is no, the register is not adding knowledge, only recording it. A real HIRA passes both.

That test is deliberately harsh, and it is the one I would apply before any audit-readiness check. Compliance can be achieved by a well-formatted document. Usefulness cannot.

On tooling: the register can live in a spreadsheet, a safety module or a maintenance system, and the format matters far less than the discipline around it. What a system genuinely adds is linkage, connecting an entry to the assets it concerns, the permits and work orders that touch it, and the evidence of controls being executed. That is hard to maintain by hand at scale, and it is no substitute for anyone doing the thinking.

6. Review and re-assessment triggers

A HIRA is not valid because it was done. It is valid because nothing material has changed since, and because it is still being revisited. The triggers below should each cause something specific to be re-examined rather than a blanket re-run of the whole register, which is how reviews become box-ticking.

Deliberately absent from this article: any review frequency. Periodic review is a real trigger and you should have a defined cycle, but the interval is set by your legal framework and by the risk involved in your own jurisdiction, and a number published here would be worse than useless.

Trigger What it should cause to be re-examined
Change of process or method of work Identification for the changed activity from scratch, plus any entry whose control depended on the old method
New, modified or removed equipment Hazards introduced by the new asset, and any hazard previously controlled by the asset removed
New or changed substance Exposure routes, storage, incompatibilities, emergency response, and the controls the previous substance justified
Change of people, competence or contractor Every entry where the control is administrative or depends on skill, supervision or familiarity
Change of layout, occupancy or use Access and egress, segregation and separation distances, traffic interaction, and any control that assumed the old geometry
Change in law or applicable standard Whether existing controls still satisfy the duty, and whether newly-named hazards are in the register at all
Incident or near miss Whether the hazard was in the register, whether it was rated realistically, and whether the control existed and failed or never existed
A control found not to work The rating of every entry relying on that control, since the residual risk was calculated on a false premise
Defined periodic cycle Whether the boundary is still right, whether identification has been repeated and not only ratings refreshed, and whether overdue actions are real

The incident trigger is the one to treat most seriously, because it is diagnostic. If the hazard was not in the register, you have an identification problem. If it was there but rated low, you have a calibration problem. If it was rated correctly and the control did not hold, you have an execution problem. Three very different fixes, and incident investigation is where that distinction gets drawn properly.

7. Where the join between the two halves breaks

This is the honest core of the article. HIRA's whole value is the joining, and the joining is exactly what decays first. Five failure patterns, in roughly the order I encounter them.

Identification is done once and never repeated. The thorough exercise happens at the start, often with external help and real rigour. Then the review cycle begins, and what gets reviewed is the ratings. The hazard list is treated as settled. Meanwhile the plant changes: equipment is added, a process is modified, a wall goes up, a contractor takes over a scope. The register ages against a facility that moved, and it ages invisibly, because everything in it is still being diligently re-rated. This is the single most damaging pattern, and it is very hard to see from inside.

New hazards enter only through incidents. The consequence of the above. If identification is not repeated, the only mechanism that adds a hazard to the register is something going wrong. The organisation is then learning from harm rather than from foresight, which is precisely the inversion the whole discipline exists to prevent. A useful diagnostic: look at your register's recent additions and ask what prompted each one. If the honest answer is mostly "an incident", identification has stopped.

The assessment step quietly drops what is hard to rate. Hazards that resist the scoring method tend to fall out between the two halves. Long-latency health hazards, where consequence is real but diffuse and delayed. Psychosocial risk, which the method often has no vocabulary for; ISO 45003:2021 exists as guidance on managing psychosocial risk, and it is guidance rather than a certifiable standard, but a register with no psychosocial entries at all is usually a method limitation rather than a finding. Low-likelihood high-consequence scenarios, which a matrix built for routine risk handles badly. Cumulative hazards that only matter in combination. These get identified, prove awkward to assess, and silently do not make the register. Nobody decided to omit them.

Ratings get adjusted instead of controls being improved. A high residual risk demands action, budget and attention, and the path of least resistance is to revisit the likelihood judgement until the number sits in a tolerable band. This is rarely cynical; it presents as reasonable argument: we have never had one, the operators are experienced, the procedure covers it. The effect is that the register drifts toward comfort and the organisation optimises the document rather than the risk. The tell is residual ratings clustering just below whatever threshold triggers escalation.

Ownership sits with a function that does not control the work. The register is owned, maintained and defended by the safety function, which has no authority over budgets, schedules or engineering change. So the identification and assessment are competent and nothing moves, because the people who could move it regard the register as someone else's paperwork. Line ownership of the register, with the safety function as the technical support and the challenge, is the arrangement I would advise every time. It is also the hardest thing on this list to change, because it is an organisational question rather than a safety one.

What HIRA cannot do

A HIRA cannot make anyone safer by itself. It is an analysis and a record, and everything that actually reduces risk happens afterwards, in engineering change, procurement, scheduling, training and supervision. An organisation can hold a thorough, current, well-governed register and still hurt people, if nothing downstream of the register has the authority or the budget to act. Judge a HIRA programme by what changed, not by the quality of the document.

8. HIRA and the maintenance function

Maintenance and cleaning activities are systematically under-represented in facility-level HIRAs, and the reason is structural rather than careless.

A facility HIRA is typically built around normal operation. The walkthrough happens during the working day, the people consulted are the people who run the place, and the hazards that present themselves are the hazards of the place functioning as intended: occupancy, traffic, the visible plant, the routine activity. Maintenance, by definition, is what happens when the normal state is suspended. Guards come off, isolations go on, and people go into ceiling voids, plant rooms, lift shafts, roof plant and pits that nobody enters during normal operation. Cleaning happens at night, often by a contractor, often unwitnessed by anyone who contributes to the register. None of that shows up on a daytime walkthrough, so none of it enters identification.

The result is a register that describes the building in use and is close to silent about the building being worked on, which is when much of the serious harm in facilities actually occurs. If you audit one thing in an existing HIRA, audit this. Count the entries that concern maintenance, cleaning, shutdown, commissioning and abnormal states. The count is usually low enough to be conclusive on its own.

The input nobody uses

Maintenance history is one of the richest and least-used inputs to hazard identification. Years of work orders record which assets fail, how they fail, what conditions technicians found, what needed isolating, what went wrong mid-job and what had to be improvised. That is empirical evidence of hazards at the exact moments they are most present. It sits in the maintenance system, and the HIRA team rarely asks for it.

The practical fix has three parts. Bring maintenance and cleaning representation into the HIRA team, including contractor supervision where contractors do the work. Extract failure and intervention history from the maintenance system as a structured input to identification rather than relying on memory. And treat criticality work you have already done as a starting point for consequence judgements, since it encodes much the same thinking. On those: facilities maintenance management covers the function, asset criticality classification covers the consequence framing, and permit to work integration with a maintenance system covers connecting the permit layer to the work itself.

9. HIRA and the management system

Worth being accurate here, because this is where overclaiming is common.

ISO 45001:2018, "Occupational health and safety management systems - Requirements with guidance for use", is the international management-system standard for occupational health and safety, and it is certifiable. Cite it as amended: ISO 45001:2018/Amd 1:2024, which added climate-action wording. It requires an organisation to have processes for identifying hazards and assessing occupational health and safety risks, and it requires controls to be determined according to the hierarchy at clause 8.1.2. It replaced OHSAS 18001:2007, which was a BSI-led consortium standard rather than an ISO standard and was withdrawn in March 2021 after a three-year migration. What ISO 45001 does not do is define HIRA, mandate the acronym, prescribe a rating scale, or specify a register format. It requires the capability and leaves the method to you.

ISO 31000:2018, "Risk management - Guidelines", is the enterprise risk-management reference. It is guidance and not certifiable: it contains no auditable requirements, so there is no accredited ISO 31000 certification for an organisation. It is useful for vocabulary and for framing risk governance, which is where a safety register should connect to the organisation's wider risk picture. It is currently under revision.

IEC 31010:2019, "Risk management - Risk assessment techniques", is the catalogue of assessment techniques. Note the designation: it is IEC 31010, not "ISO 31010" and not "ISO/IEC 31010". Only the withdrawn 2009 edition carried the dual prefix.

ISO 45003:2021 gives guidelines on psychosocial risk within an occupational health and safety management system. Guidance, not certifiable, and free to read on the ISO site.

On legal duties, and this is where jurisdiction has to be attached to every claim. In Great Britain, the general duty to assess risk sits in the Management of Health and Safety at Work Regulations 1999 (SI 1999/3242) at Regulation 3, under the Health and Safety at Work etc. Act 1974 (c. 37). Northern Ireland operates separate instruments with different years. In the United States, there is no general federal requirement for a written hazard analysis; the closest thing in general industry is the written hazard assessment and certification required by 29 CFR 1910.132(d), and separately 29 CFR 1910.119(e) requires a process hazard analysis for covered process-safety processes. Those are federal, and State Plan states may differ. In the United Arab Emirates, occupational safety duties sit in Federal Decree-Law No. 33 of 2021 on the Regulation of Employment Relationships, administered by MOHRE, with the occupational safety and health duties in Article 13, and in Abu Dhabi the applicable framework is ADOSH-SF, the Abu Dhabi Occupational Safety and Health System Framework, Version 4.0, administered by the Abu Dhabi Public Health Centre. Note plainly that United States OSHA regulations and Great Britain's HSE law have no legal force in the UAE; they are voluntary benchmarks there, and ISO 45001 is the usual international reference, but the binding law is the federal decree-law and the emirate framework.

The summary position: HIRA is not a standard, it is the practice that a management system requires and that a jurisdiction's law obliges in its own words. Do not let anyone tell you a number defines it.

Primary sources: ISO , IEC , HSE, Great Britain , OSHA, United States , NIOSH, United States .

The idea to walk away with

HIRA is a name for insisting on the whole chain. Two tasks with different failure modes, tied together so that neither can be quietly skipped, producing a maintained register that informs decisions at the programme and design level, above the task-level work that a JSA and a permit do. That is the entire concept, and the acronym is doing nothing more than holding the two halves in the same sentence.

Which is why the diagnosis, when a HIRA is not working, is usually about the join rather than about either half. The identification was competent and stopped. The assessment is diligent and is re-rating an ageing list. The register is well kept and unread. Look at the join first.

Final thoughts

If you inherit a HIRA and want to know within an hour whether it is real, ask four questions. When was identification last repeated, as distinct from ratings last reviewed? How many entries concern maintenance, cleaning or abnormal states? Who owns the register, and do they control any budget? And can a planner find the relevant entry and learn something from it? Those four will tell you more than reading the whole document.

And if you are building one from scratch, spend the disproportionate effort on the boundary and on the team. Most structural problems in a risk register trace back to a boundary drawn for organisational convenience, or a team assembled from whoever was available. The method can be corrected later. Those two are hard to fix once the register exists and people believe it.

Disclosure

Alongside advisory work I also build a CMMS and CAFM platform, so I have a commercial interest in this category. Nothing above is a recommendation for it, and no vendor named here has paid for inclusion or had any editorial input. Weigh the analysis accordingly.

Reviewing a risk register that nobody reads?

Independent advisory on connecting hazard and risk registers to the maintenance and permit workflows where the work actually happens, including maintenance history as an identification input. 22+ years across utilities, oil and gas, manufacturing, government and facility operations.

Book a conversation

Related reading: Hazard identification methods and process, Risk assessment: a complete guide, Risk assessment matrix, Hierarchy of controls, Hazard vs risk, Job safety analysis (JSA), Permit to work, Incident investigation, Near miss reporting, What is HSE, Facilities maintenance management, Asset criticality classification.

Muhammad Abbas

CMMS / CAFM Manager & Independent Advisor · 22+ years across enterprise CMMS, EAM, CAFM and ERP implementations in utilities, oil and gas, manufacturing, government and facility operations.

Work with me
MAbbaz.com
© MAbbaz.com