mail@mabbaz.com Abu Dhabi, UAE

Risk Assessment · HSE · Maintenance Safety

Risk Assessment: A Complete Guide With Examples

A risk assessment is not a form. It is a decision about what you are going to change before the work starts. This is the complete process, step by step, with a worked maintenance example, the jurisdictional legal position set out honestly, and a frank account of why so many assessments produce paperwork and no change in how the job is actually done.

Muhammad Abbas September 27, 2026 ~22 min read

Risk assessments across utilities, oil and gas, manufacturing and facility operations divide into two recognisable kinds, and it usually takes about thirty seconds of reading to tell whether the person who wrote one had ever stood next to the job. The good ones are specific, slightly awkward, and contain at least one control that clearly cost somebody an argument. The bad ones are fluent, generic, complete, and changed nothing. Both get filed; only one protects anyone.

The message up front: the output of a risk assessment is a decision about controls, not a document. If you can complete an assessment and nothing about the job changes, no control added, no method altered, no extra person or equipment brought in, then either the job was already adequately controlled and you can say exactly which existing controls do that, or you have not really assessed it. The most common failure mode in this discipline is producing the paperwork and changing nothing.

One qualification, placed here once. I am an enterprise systems and maintenance management practitioner, not a chartered safety professional or a lawyer, and this guide states jurisdiction every time law is mentioned because safety law is national and does not travel. For a binding view on your own duties, and for specialist risk such as confined spaces, explosive atmospheres, asbestos or radiation, use a competent person qualified in your jurisdiction. Competence is the load-bearing concept in every framework below, and no article makes anyone competent.

1. What a risk assessment is actually for

Strip away the templates and the assessment answers four questions before someone gets hurt. What could go wrong here. Who would be harmed, and how. Given what we already have in place, how likely and how bad is that. And what will we do about it that we are not doing now. Everything else, the numbering, the scoring, the sign-off boxes, exists to make those four answers traceable.

That framing has a consequence people resist: the assessment is a planning activity, not a compliance one. It belongs where the method of work is still changeable, before the job is scoped, priced, scheduled and manned. One produced the morning of the work, with the crew on site and the shutdown window fixed, cannot recommend anything that costs time or money. It will recommend awareness, care and PPE, the pattern you see in the weakest assessments in circulation. It follows that it is only useful if it connects to what actually governs the work: the work instruction, the isolation certificate, the permit, the toolbox talk. A control that appears nowhere in the documents the technician holds has not controlled anything. It has documented an intention. If the hazard and risk distinction is at all fuzzy, start with hazard versus risk, and for where this sits in the wider discipline, the HSE overview pillar.

The test I apply to any assessment handed to me

Name one thing about how this job will be done that is different because this assessment exists. If the answer is nothing, and the job was not already demonstrably well controlled, the assessment is decoration.

This is where published advice quietly misleads people, usually by taking a British duty and presenting it as universal. The three positions below are genuinely different from each other.

Great Britain. The duty is explicit: Regulation 3 of the Management of Health and Safety at Work Regulations 1999 (SI 1999/3242), made under the Health and Safety at Work etc. Act 1974. The statutory standard applied to the assessment is that it must be suitable and sufficient, which is the test an inspector or a court actually applies: not whether a document exists, but whether the assessment was adequate for the risk. Note the geography. These are Great Britain instruments. Northern Ireland has separate legislation, with its own instrument numbers and in several cases different years, so a Northern Ireland duty should never be cited using a Great Britain SI number. Sector regulations covering work equipment, lifting, hazardous substances and construction add their own requirements.

Federal United States. There is no single OSHA risk-assessment regulation, and no federal equivalent of the British general duty to assess and record risk across all work activities. That is a difference in legal architecture, not a gap in the reader's knowledge. Where written analysis is mandated federally, the two citations to know are 29 CFR 1910.132(d), the hazard assessment for PPE selection, which requires a written certification identifying the workplace assessed, the person certifying it and the date; and 29 CFR 1910.119(e), process hazard analysis under Process Safety Management, which requires a named methodology and revalidation at least every five years. State Plan states may impose more. Anyone telling you OSHA requires a general workplace risk assessment in the British sense is describing a rule that does not exist.

United Arab Emirates. The binding instrument is Federal Decree-Law No. 33 of 2021 on the regulation of employment relationships, administered by MOHRE, with occupational safety and health duties in Article 13, and emirate frameworks on top. Worth stating plainly: US OSHA regulations and UK HSE law have no legal force in the UAE. They are voluntary benchmarks, often written into contracts, but not the law there.

Voluntary standards, all jurisdictions. ISO 31000:2018, "Risk management - Guidelines", is the general framework. It is guidance and it is not certifiable: no auditable requirements, therefore no accredited ISO 31000 certification for an organisation, and anyone offering one is selling individual training or nothing. Its technique companion is IEC 31010:2019, "Risk management - Risk assessment techniques". Get the prefix right: it is IEC 31010, not "ISO 31010". ISO 45001:2018 (as amended by Amd 1:2024) is the certifiable occupational health and safety management system standard, and it is what requires the hierarchy of controls, at clause 8.1.2. For machinery, ISO 12100:2010, "Safety of machinery - General principles for design - Risk assessment and risk reduction", consolidated and replaced ISO 12100-1:2003, ISO 12100-2:2003 and ISO 14121-1:2007, and is under revision. None of these is law anywhere by itself; they bind through contract, certification scope, and being a yardstick a court may treat as reasonable practice. One further correction: bowtie analysis is not a standard but a 2018 CCPS and Energy Institute concept book, and while it appears as a listed technique in IEC 31010:2019, there is no "bowtie standard" to comply with.

Primary sources: MHSWR 1999 on legislation.gov.uk , HSE , OSHA , ISO , NIOSH .

3. Scope definition, where most assessments go wrong

If I could change one thing about how risk assessment is taught, it would be to spend far more time on scope and far less on scoring. Scope determines whether the assessment can possibly be useful, and it is decided in the first two minutes, usually without anyone noticing a decision was made.

Too broad and you get wallpaper. "Maintenance activities, Building B" produces an assessment listing slips, trips, manual handling, electricity, working at height and hand tools, controlled by training, PPE, good housekeeping and competent persons. Every word is true. None of it helps anybody do anything differently, because it is not about any actual task. These feel efficient because one document covers a lot of ground, which is why they multiply, and they are the largest category of useless safety paperwork I encounter.

Too narrow and you miss the interactions. Replacing a valve actuator, assessed as a standalone mechanical task, looks modest. Replacing it while the adjacent line is being hydrotested, on a grated floor above another crew, with a temporary scaffold in the access route, is a different job. Simultaneous operations, shared access and the effect of one crew's isolation on another's equipment are what narrow scoping hides.

The scope that works sits at the level of an identifiable task, on identifiable equipment, in an identifiable location and operating context, with the boundaries named: "Replacement of the failed drive coupling on chilled water pump CHWP-03, plant room 2, with the pump isolated electrically and mechanically and duty transferred to CHWP-04. Includes isolation, guard removal, coupling removal and refit, alignment and function test. Excludes electrical panel work inside the starter, covered separately, and excludes any work requiring entry into the tank pit."

The exclusions are the part people skip and the part that prevents the most harm, because an unstated exclusion becomes an assumed inclusion at the worst possible moment. If the boundary is going to be crossed during the work, that is a trigger to stop and reassess, not a judgement call for the technician standing there at four in the afternoon.

The honest cost of scoping properly

Task-level scoping means more assessments, not fewer, and maintaining them as equipment and methods change. Organisations that adopt it without retiring their broad-scope wallpaper end up with both, which is worse than either. It is a decision to carry more administrative load in exchange for assessments that bear on the work, and it only pays if you delete what it replaces.

4. Who should do it, and who should not

The legally significant answer is a competent person, with competence judged against the risk assessed. The practically significant answer is narrower: the person who will actually do the work must be involved, because they are the only one who knows the real method.

This is not a participation nicety. There is commonly a gap between the documented method and the executed one, rarely because anyone is being cavalier. The documented method assumes the isolation point is accessible; the technician knows you reach over the pipe rack to get to it. It says lift the cover; the technician knows the cover has been seized since the last overhaul and comes off with a bar. It assumes two people; the technician knows the second is on another job by nine o'clock. Those gaps are where the actual risk lives, and none appears in an assessment written by someone who has not seen the task.

Hence a known failure mode worth naming: the remotely written assessment. Someone in an office, working from an equipment list and a template library, produces a technically literate assessment for a task they have never observed, in a plant room whose access constraints they cannot know. It reads more professionally than one written by the crew and cites more standards. It is also wrong in the specific ways that matter, and wrong invisibly, because nothing reveals that the author was never there.

The workable composition is small: the crew, the supervisor or planner who owns the method and can authorise a change to it, safety or engineering input where the risk is specialist, and the operations representative when live plant is affected. Anyone who can neither describe the work accurately nor change how it is done is an audience, not a participant. And if the process has no route to approve a control that costs money or time, it is not an assessment process: the most valuable outputs are often expensive, a different tool, a shutdown rather than live work, a design change so the job never needs doing this way again.

5. The steps, done properly

What separates a real assessment from a completed form is not the steps but the honesty applied within each.

  • Step 1: define the scope and activity precisely. Task, asset, location, operating state, included and excluded steps. Section 3, and the step most often skipped.
  • Step 2: identify the hazards, including who might be harmed and how. Not just "electricity" but who is exposed, in which step, by what mechanism. Include people not doing the work: other crews, operators, contractors.
  • Step 3: evaluate the risk with existing controls in place. The guards, interlocks, procedures, training and permits you genuinely have, not the ones a management system document describes.
  • Step 4: decide additional controls using the hierarchy. Work down from elimination rather than starting at PPE and rationalising backwards. Each control gets an owner and a date.
  • Step 5: record the significant findings. Significant, not exhaustive. Section 11.
  • Step 6: implement. The step that gets dropped. The controls have to reach the documents that govern the work and the heads of the people doing it. Until then the assessment has had no effect on anything.
  • Step 7: review. On defined triggers, not a vague intention. Section 12.

Steps 2, 3 and 4 each have a discipline behind them that this guide deliberately does not absorb. Identification techniques, from walkthrough and task observation up to the structured methods catalogued in IEC 31010:2019, are in hazard identification methods and process. Task-step decomposition is in the job safety analysis guide. Scoring and matrices belong to risk assessment matrix: how to calculate risk, and the control hierarchy to the hierarchy of controls guide.

6. Evaluating risk without pretending to precision

Evaluation supports two decisions: is this tolerable as it stands, and if not, what gets attention first. It is a prioritisation instrument and a fairly coarse one. The standard approach combines how likely the harm is with how severe it would be. The mechanics, including matrix sizing, scale wording and the awkward high-severity low-likelihood corner, belong to the risk matrix guide, and I defer to it entirely. I am also not publishing a scale or matrix here, because one lifted from a web page and applied to an unfamiliar operation is worse than none: organisations calibrate their own severity and likelihood definitions against their own tolerability criteria, and a borrowed scale produces numbers with no meaning.

Three places where honesty has to go. The number is an ordering device, not a measurement, so averaging scores or setting a target for them attributes a precision they do not have, and that commonly produces perverse behaviour where scores drift downward over reporting periods while nothing about the work changes. The evaluation must be of the real current state; scoring against the controls you are about to recommend produces an assessment where everything is already acceptable and nothing needs doing. And a residual rating is a forecast, true only once the controls are in place: recording a low residual rating for controls not yet implemented is one of the commonest ways an assessment becomes actively misleading.

7. Deciding controls: the hierarchy in one page

The hierarchy of controls is the discipline that stops assessment defaulting to PPE. It is a principle rather than a standard: no body issues it standalone. It is required by ISO 45001:2018 at clause 8.1.2 and described by NIOSH on a freely available public page, the origin of the inverted triangle everyone draws. US OSHA does not define it in any regulation, so "as defined by OSHA" is wrong. The ordering runs from eliminating the hazard, through substitution and engineering controls, then administrative controls including procedure and training, and finally PPE. ISO groups reorganisation of work with the engineering tier, so the ISO list is not quite identical to the NIOSH one, which matters if you are writing a procedure citing either.

The discipline it enforces is one question asked in order. Can this job be designed out? Can the hazardous element be substituted? Can it be engineered, guarded, isolated, interlocked, ventilated, restrained? Only when those are genuinely exhausted do you reach procedure, permit, training and supervision, and only then PPE. Most assessments arrive at the answer before asking the questions, which is how elimination options go unconsidered because nobody said them out loud.

On maintenance work the top of the hierarchy is often unavailable in the short term: you cannot eliminate the need to open the machine to repair it. Record that elimination was considered and why it was rejected, then feed recurring cases into design and capital planning, because a job assessed as high risk every single time is telling you something about the equipment rather than the crew. Depth on all five levels is in the hierarchy of controls guide.

8. Generic, task-specific and dynamic assessment

Three legitimate forms, each routinely abused. The abuse is rarely deliberate: it is one form stretched to cover work it was never suitable for, because it is the form that already exists.

Type When it is appropriate When it is an abuse of the form
Generic
One assessment covering a repeated standard task across similar situations
A genuinely standardised, repeated task with consistent equipment, method and environment. Routine filter changes on an identical air handling unit fleet, standard lamp replacement at low level, scheduled meter readings. Sensible, proportionate and avoids rewriting the same document weekly. Applied to a non-standard job because a generic assessment already existed for something that sounds similar. Also abused when it is never validated against the actual site, or when nobody checks that this particular instance really does match the standard conditions it assumes.
Task-specific
Written for one job, one asset, one occasion
Non-routine work, first-time work, work on unfamiliar or degraded equipment, work where the method had to be improvised, work with simultaneous operations, and anything where the generic assessment's assumptions do not hold. This is the default for corrective and project maintenance. Produced by editing the asset name in a previous assessment and changing nothing else. That is a generic assessment wearing a task-specific label, and it carries the false credibility of looking bespoke.
Dynamic
Continuous on-the-spot reassessment by competent people as conditions change
A real discipline in its own right. Appropriate for emergency response, fault-finding where the next step depends on what you find, and rapidly changing environments. It requires trained, competent, authorised people, clear stop authority, and a mechanism to capture what was decided. Invoked as a reason not to have assessed planned work at all. "We do dynamic assessment" offered in place of any prior assessment of a foreseeable, plannable task is one of the most common misuses, and it is usually a resourcing problem being described as a methodology.

Most maintenance operations need all three. The governance question is not which one you use but who has authority to escalate from generic to task-specific when the job does not match the document. That route should be explicit and easy to use, because a technician who has to justify asking for a proper assessment will stop asking. On a related confusion in contractor-heavy environments, the assessment and the method statement are different documents doing different jobs: see risk assessment versus method statement.

9. The maintenance problem nobody puts firmly enough

Maintenance work routinely requires defeating the very controls that make normal operation safe. That is not an edge case, it is the ordinary condition of the work. Guards come off because you cannot reach the coupling with them on. Interlocks are bypassed because you cannot observe the fault with the door closed. Equipment is deliberately energised during fault-finding because a dead circuit tells you nothing about an intermittent fault. Enclosures are opened, covers removed, barriers taken down, pressure systems broken into. Every one of those actions removes a control the production risk assessment counted as present.

Therefore: a production or operational risk assessment does not cover maintenance on the same equipment. It cannot, because its whole evaluation assumed the guards were fitted, the enclosure closed and the system in its designed state. The moment the fitter removes the guard, the assessment governing that area describes a machine that no longer exists. I say this firmly because accepting an operational assessment as maintenance coverage is widespread, administratively convenient, and one of the more reliable routes to serious harm in an otherwise well-run plant.

Three corollaries. Isolation and energy control is the load-bearing control, not a paragraph, and where it cannot be fully achieved, during live fault-finding for instance, that must be controlled specifically rather than covered by a general statement about competence. Reinstatement belongs in the scope: guards refitted, interlocks proven, machine formally returned to service, because work left half-reinstated at shift handover is a hazard created by the maintenance process itself. And the assessment has to cover the function test, the moment the equipment is deliberately made live with people close to it, frequently the highest-risk step and frequently the one nobody assessed.

This is also why permits and assessments must be connected rather than parallel. The permit enforces the controls the assessment decided on, at the moment of the work, with named people accepting them. An assessment with no route into the permit is half of a control that does not close. See the permit to work guide, and for the systems linkage, permit to work integration with CMMS.

The question that exposes this in about a minute

Take any machine with a risk assessment covering its operation. Ask which assessment covers maintenance of that machine with the guard removed. If the answer is the same document, or a shrug, you have found a real gap and not a paperwork one.

10. A worked example, clearly hypothetical

The example below is invented for illustration and describes no real site, client or incident. Hypothetical task: replace the failed flexible drive coupling on chilled water pump CHWP-03, plant room 2, second floor. Duty transferred to CHWP-04, pump isolated electrically at the local starter and mechanically by locking the suction and discharge valves closed. Scope covers isolation, guard removal, coupling replacement, alignment check, guard refit and function test, and excludes work inside the starter enclosure. Assumed conditions: corroded guard fasteners, a warm plant room, and an access route between pump and wall about 700mm wide with a floor gully across it.

Step Hazard, who is harmed and how Existing controls in place today Additional controls decided (hierarchy level) Owner
Duty transfer and isolation Unexpected start-up. Both technicians: crush and entanglement injury to hands and arms if the pump starts with the coupling exposed. BMS auto-changeover could command a start. Lockable local starter isolator. Padlocks and tags issued. Isolation certificate required by site procedure. Disable the BMS auto-changeover for CHWP-03 and confirm in writing with the shift representative before isolation, not after (engineering / administrative). Prove dead at the motor terminals, not only at the isolator (administrative). Operations countersigns the isolation. Supervisor
Coupling guard removal Corroded fasteners. Technician removing the guard: hand laceration from slipping tool and cut edges; eye injury from corrosion debris; strain from applying force in a confined stance. Cut-resistant gloves and safety glasses issued as standard for mechanical work. Penetrating lubricant applied and left the shift before, so the fasteners are not fought cold (substitution of method). Correct-fit socket set brought to the job rather than an adjustable spanner (engineering). If a fastener shears, stop and raise it, do not improvise a cut (administrative, with explicit stop authority for the technician). Technicians
Draining and residual water Warm water release on breaking the coupling housing area, and standing water on the plant room floor. Both technicians and anyone entering: scald risk and slip risk. Floor gully increases the slip and trip consequence. Suction and discharge valves locked closed. Plant room floor drains to gully. Confirm the line is vented and drained before work, with the vent point identified in the work instruction (engineering). Absorbent mat placed over the gully crossing and the immediate work area (engineering). Work area barriered so nobody walks the route while it is wet (engineering). Technicians
Coupling handling in a 700mm access Manual handling in a restricted stance with an awkward load at low level. Technician lifting: back and shoulder strain; dropped component causing foot injury to either technician. Manual handling training current for both technicians. Safety footwear. Two-person lift specified for the coupling half, with the lift position agreed before starting (administrative). Component staged on a low trolley at the pump rather than carried across the room (engineering). Access route cleared of stored spares before the job, which is a pre-start check not a during-job one (engineering). Supervisor
Hot plant room environment Heat stress during extended work in a warm plant room with PPE. Both technicians: fatigue, reduced concentration, and the secondary risk of a fatigue-driven error on the alignment or the reinstatement. Drinking water available on the floor. Work generally scheduled in the morning. Portable ventilation positioned for the duration (engineering). Defined rest breaks out of the plant room, scheduled rather than taken if convenient (administrative). Job planned for the cooler part of the shift and not compressed to fit a late window (administrative). Supervisor
Reinstatement and function test Guard not refitted, or refitted incorrectly, with the machine returned to service. Anyone in the plant room afterwards: entanglement. During the test itself, both technicians are close to rotating equipment being deliberately energised. Work order requires reinstatement sign-off. Test normally witnessed by the technician. Guard refit and fastener torque confirmed as a named line item before the isolation is removed, not after (administrative). Function test run with both technicians clear of the coupling and one at the isolator with the ability to stop it (engineering and administrative). No partial reinstatement across a shift handover: if the job is not complete, the isolation stays on and the state is formally handed over (administrative). Supervisor

Two features are deliberate. There are no risk scores, partly because scoring belongs to the matrix guide and partly to show the useful content survives without them. Second, several controls are changes to planning and sequencing rather than equipment, which is what a remotely written assessment rarely produces.

11. Recording the significant findings

In the Great Britain framework the recording obligation is expressed in terms of significant findings, and that word is doing real work. It is not licence to record less than you should: the record should contain the significant hazards, the conclusions about who is at risk and how, the existing and additional controls, and enough reasoning that a competent reader can follow why. It is not a requirement to catalogue every trivial hazard of ordinary life, and assessments that do so bury their own findings.

A record that works has a few unglamorous properties. It is short enough that the crew will read it, a page or two rather than fourteen, and specific enough that a reader can tell it was written about this asset and this method. It names controls in terms someone can comply with, so "secure the access route" becomes "barrier the route from the door to the pump and place a mat over the gully". It records who was involved, which is both a competence record and a check on whether the crew were there. And it carries a date and version.

The property most often missing is the link to the document that governs the work. The assessment should reference the work order or instruction, and where a permit applies, the permit should reference the assessment. Without that it lives in a parallel filing system and nobody reads it at the point of use. Where a maintenance management system holds the work order, referencing the assessment against that record achieves it mechanically, but the tool is not the point: a folder on a shared drive works if the work order tells you which file to open. For the wider workflow picture see the facilities maintenance management guide and what is a CMMS.

The recording question has a different shape in the federal United States, where 29 CFR 1910.132(d) requires a written certification naming the workplace, the certifying person and the date, and 29 CFR 1910.119(e) requires a named methodology and revalidation at least every five years for covered processes. Both sit inside specific scopes. Do not generalise either into a universal recording rule.

12. Review triggers that actually fire

An assessment is a statement about a particular set of conditions, so it expires when those change. "Review annually" as the only trigger is weak, because what invalidates an assessment does not wait for the anniversary. The triggers that matter:

  • Change of method. A different sequence, tool, access arrangement or isolation point. If the method changed, the assessment describes a job nobody is doing.
  • Change of equipment. New or modified plant, a replacement unit with different guarding, a control upgrade that alters how the machine can start. Also deterioration, which is a change of equipment even though nothing was replaced.
  • Change of people or of operating context. New or less experienced staff, a smaller crew, a contractor doing work that used to be in-house, adjacent construction, simultaneous operations, seasonal heat, a shared access route. An assessment that assumed a two-person crew is invalid when one person is sent.
  • After an incident or near miss, including one elsewhere on a similar task or asset. A near miss is the cheapest review trigger you will ever get and the most frequently wasted.
  • When the crew says it does not match. The most valuable trigger and the one most often absent from procedures. That is a review trigger, not a training issue.
  • A defined period, as a backstop so nothing drifts indefinitely. If the periodic review is the only trigger that ever fires, the others are not working.

A review is not automatically a rewrite. "Checked, still valid, conditions unchanged, dated and initialled" is legitimate, provided somebody actually checked. What makes it worthless is a batch of assessments re-dated in an afternoon to clear an audit finding.

13. The honest failure modes

These are the patterns that make risk assessment disliked by the people it is supposed to protect, and all of them are within the organisation's control.

  • Copy-paste assessments. The template library becomes the assessment. The asset name changes, the hazards do not, and nobody notices the document describes a pump on the ground floor with clear access rather than the one wedged against a wall upstairs.
  • Assessments written to satisfy an audit. The audience becomes the auditor rather than the crew, and usefulness at the point of work falls as audit performance rises. You spot these because they are written in a register no technician would use.
  • Controls listed that do not exist in practice. The most dangerous one, because it produces a false picture of safety: a guard missing for two years, a defeated interlock, a procedure nobody was trained on, a permit signed retrospectively. If the control is listed and absent, the residual rating is fiction. Verifying that listed controls physically exist is the highest-value check you can run over an existing assessment library.
  • No link to the work instruction or the permit. The assessment never reaches the job, so compliance depends on memory and goodwill.
  • Scoring as the activity, and no feedback into design. Effort spent making the numbers consistent rather than the controls right, and the same task assessed as high risk fifty times with nobody asking whether the equipment should change. The assessment library is a record of recurring problems and almost nobody reads it as one.
What risk assessment cannot do

It will not compensate for inadequate resourcing, equipment beyond economic repair, or a schedule that does not permit the work to be done properly. An assessment can identify that the job needs two people, a platform and four hours. It cannot conjure them. Where the organisation will not supply the controls identified, the assessment becomes a documented record of a known, unmitigated risk, which is a worse position than not having assessed it. The honest response then is to escalate or not do the work, not to soften the assessment until it fits the resources available. Quietly downgrading findings to match what is affordable is the most corrosive thing that happens to this process.

The idea to walk away with

A risk assessment is a decision about controls, recorded. Everything that makes it work follows from taking that seriously: scope it at the level of an actual task, involve the people who know the real method, evaluate against the controls you genuinely have, work down the hierarchy rather than arriving at PPE and rationalising backwards, record the significant findings in language the crew will use, connect the record to the work instruction and the permit, and review on triggers that actually fire. And for maintenance, the one point I would most want remembered: maintenance defeats the controls that make normal operation safe. That is the nature of the work, not a lapse in it. An operational risk assessment therefore cannot cover maintenance on the same equipment, and treating it as though it can is a widespread, administratively convenient and genuinely dangerous shortcut.

Final thoughts

Risk assessment has a poor reputation among the people who do the work, and it is not because the method is wrong. The method is sound and decades old. The reputation comes from paperwork produced for auditors by people who were not there, listing controls that do not exist, reaching a residual rating decided before the analysis started, and filed where the crew will never look. When technicians dismiss it as a tick-box exercise, they are usually describing something they have seen accurately.

The repair is not a better template but a change in what the process is for. If the assessment has the authority to change the job, involves the people who will do it, and ends up in the technician's hand rather than in a folder, it becomes something people use because it makes the work go better and not only safer. That version costs more time up front and occasionally forces an uncomfortable conversation about resources. It is also the only version that does anything. If you audit one thing in your own library this month, audit whether the controls it lists physically exist.

Disclosure

Alongside advisory work I also build a CMMS and CAFM platform, so I have a commercial interest in this category. Nothing above is a recommendation for it, and no vendor named here has paid for inclusion or had any editorial input. Weigh the analysis accordingly.

Risk assessments that nobody reads?

Independent advisory on connecting risk assessment to work instructions, permits and maintenance workflow, so that decided controls actually reach the job. 22+ years across utilities, oil and gas, manufacturing, government and facility operations.

Book a conversation

Related reading: What is HSE?, Risk assessment matrix: how to calculate risk, Hazard vs risk, Hazard identification methods, Hierarchy of controls, Job safety analysis (JSA), Permit to work, Risk assessment vs method statement, PTW integration with CMMS, Facilities maintenance management.

Muhammad Abbas

CMMS / CAFM Manager & Independent Advisor · 22+ years across enterprise CMMS, EAM, CAFM and ERP implementations in utilities, oil and gas, manufacturing, government and facility operations.

Work with me
MAbbaz.com
© MAbbaz.com