Skip to content
All safety questions
Asked by a personGeneral — US and Canadaen-CA

Write a risk assessment for It risk register

A person submitted this question to Rosie's free generator. The asker's identity is neither imported nor published.

Rosie's answer

Published by SALUS

IT Risk Register Risk Assessment for Information Security and Operational Risk Management =========================================================================================

Assessment Date: \[DATE]

Assessor: \[ASSESSOR NAME]

Department/Area: \[DEPARTMENT/AREA]

Review Date: \[REVIEW DATE]

1\. Assessment Scope


This risk assessment covers the identification, evaluation, and control of information security and operational risks associated with the operation, administration, support, and use of IT systems, networks, applications, endpoints, cloud services, data repositories, and related business processes. The scope includes routine operations, non-routine activities such as maintenance, patching, backups, incident response, system changes, and recovery activities, as well as foreseeable abnormal conditions such as cyber incidents, service outages, power loss, remote access failures, and extreme workload periods. It applies to employees, contractors, service providers, and other authorized users who access or support IT assets, and it considers impacts to business operations, data confidentiality, integrity, availability, and regulatory compliance. Exclusions from this assessment are physical workplace hazards unrelated to IT operations, product development risk outside operational deployment, and legal or contractual matters that do not directly affect information security or operational risk controls. [2] [5] [4]

2\. Risk Assessment Methodology


This assessment uses a structured qualitative risk assessment approach consistent with hazard identification, risk analysis, risk evaluation, and risk control principles. Hazards were identified by considering the full lifecycle of IT activities, routine and non-routine tasks, foreseeable abnormal conditions, affected stakeholders, and relevant compliance obligations. Each hazard was evaluated using a 5x5-style qualitative matrix based on likelihood and severity, with risk ratings expressed as Low, Medium, High, or Extreme. Controls were selected using the hierarchy of controls, prioritizing elimination and substitution where feasible, followed by engineering controls, administrative controls, and personal protective equipment where applicable. Residual risk was estimated after controls were applied to determine whether additional action is required and whether the remaining risk is acceptable for ongoing operations. [7] [9] [10]

3\. Risk Matrix Reference


The following matrix is used to evaluate risk levels based on likelihood and severity:

Likelihood

| Rare | Unlikely | Possible | Likely | Almost Certain | | Severity | Catastrophic | Low | Low | Low | Medium | Medium | | Major | Low | Low | Medium | Medium | High | | Moderate | Low | Medium | Medium | High | High | | Minor | Medium | Medium | High | High | Extreme | | Negligible | Medium | High | High | Extreme | Extreme |

4\. Hazard Identification and Risk Evaluation


1\. Unauthorized access to systems, applications, or data through weak authentication, credential theft, phishing, or account compromise.

Potential Consequences: Confidential information may be exposed, altered, or deleted; attackers may gain persistence in the environment; business operations may be disrupted; regulatory breaches and reputational damage may occur. [7] [6] [11]

Affected Persons: Employees, contractors, customers, business partners, IT administrators, and the organization as a whole.

Initial Risk Assessment
LikelihoodSeverityRisk Rating
LikelyMajorExtreme
Control Measures
  • Eliminate unnecessary accounts, shared credentials, and dormant access paths.
  • Substitute legacy authentication methods with phishing-resistant multi-factor authentication and strong identity governance.
  • Implement engineering controls such as MFA, privileged access management, conditional access, password vaulting, and session timeout controls.
  • Apply administrative controls including access reviews, least-privilege provisioning, security awareness training, phishing simulations, and formal joiner-mover-leaver procedures.
  • Use secure tokens or hardware authenticators for privileged users where appropriate.
Residual Risk Assessment
LikelihoodSeverityRisk Rating
UnlikelyMajorHigh

2\. Malware, ransomware, or other malicious code introduced through email, web browsing, removable media, or compromised software supply chains.

Potential Consequences: Systems may be encrypted, corrupted, or rendered unavailable; data loss may occur; recovery costs and downtime may be significant; critical services may be interrupted.

Affected Persons: All users of IT systems, operational teams, customers relying on services, and IT support personnel.

Initial Risk Assessment
LikelihoodSeverityRisk Rating
LikelyCatastrophicExtreme
Control Measures
  • Eliminate unsupported software and unauthorized removable media use.
  • Substitute high-risk manual file transfer methods with managed secure file transfer and approved collaboration platforms.
  • Deploy engineering controls including endpoint detection and response, email filtering, application allowlisting, network segmentation, immutable backups, and malware scanning.
  • Use administrative controls such as patch management, backup testing, incident response playbooks, and user training on suspicious attachments and links.
  • Apply restricted administrative access and hardened privileged workstations.
Residual Risk Assessment
LikelihoodSeverityRisk Rating
PossibleMajorHigh

3\. Data loss, corruption, or unauthorized modification caused by system failure, human error, poor change control, or inadequate backup and recovery processes.

Potential Consequences: Records may be incomplete or inaccurate; services may be interrupted; financial, legal, and operational decisions may be based on incorrect information; recovery may be delayed.

Affected Persons: Business users, IT operations staff, management, auditors, and external stakeholders dependent on accurate records.

Initial Risk Assessment
LikelihoodSeverityRisk Rating
PossibleMajorHigh
Control Measures
  • Eliminate single points of failure where feasible through redundancy and resilient architecture.
  • Substitute manual, error-prone deployment methods with automated, version-controlled change and release processes.
  • Implement engineering controls such as backup automation, replication, integrity checks, access logging, and configuration management tools.
  • Apply administrative controls including change approval, segregation of duties, backup retention rules, restore testing, and data validation procedures.
  • Restrict privileged actions to authorized personnel and require dual review for high-risk changes.
Residual Risk Assessment
LikelihoodSeverityRisk Rating
UnlikelyMajorHigh

4\. Unplanned service outage or degraded availability due to infrastructure failure, cloud provider disruption, network interruption, or capacity exhaustion.

Potential Consequences: Users may be unable to access critical applications or data; service-level commitments may be missed; operational delays and financial losses may occur; emergency processes may be affected.

Affected Persons: Employees, customers, suppliers, IT support teams, and business continuity stakeholders.

Initial Risk Assessment
LikelihoodSeverityRisk Rating
PossibleMajorHigh
Control Measures
  • Eliminate avoidable dependencies on single systems or single providers where practical.
  • Substitute fragile manual recovery arrangements with tested business continuity and disaster recovery solutions.
  • Use engineering controls such as redundancy, failover, load balancing, monitoring, capacity management, and geographically separated backups.
  • Apply administrative controls including service continuity planning, escalation procedures, maintenance windows, and recovery time objective tracking.
  • Maintain secure remote access and emergency communication procedures for continuity events.
Residual Risk Assessment
LikelihoodSeverityRisk Rating
UnlikelyMajorHigh

5\. Misconfiguration of cloud services, firewalls, identity settings, storage permissions, or network controls leading to exposure of systems or data.

Potential Consequences: Sensitive data may be publicly exposed; unauthorized access may occur; compliance failures and incident response costs may increase.

Affected Persons: Data subjects, system users, administrators, and the organization.

Initial Risk Assessment
LikelihoodSeverityRisk Rating
LikelyMajorExtreme
Control Measures
  • Eliminate manual configuration drift through infrastructure-as-code and standardized secure baselines.
  • Substitute ad hoc configuration changes with approved templates and hardened reference architectures.
  • Implement engineering controls such as configuration monitoring, policy-as-code, secure defaults, and automated drift detection.
  • Apply administrative controls including peer review, change authorization, cloud security standards, and periodic configuration audits.
  • Limit administrative privileges and require just-in-time access for sensitive changes.
Residual Risk Assessment
LikelihoodSeverityRisk Rating
PossibleMajorHigh

6\. Insider threat, whether malicious or accidental, including misuse of access, data exfiltration, or unsafe handling of sensitive information.

Potential Consequences: Confidential data may be disclosed, altered, or destroyed; fraud may occur; trust and compliance may be compromised.

Affected Persons: Employees, contractors, customers, and the organization.

Initial Risk Assessment
LikelihoodSeverityRisk Rating
PossibleMajorHigh
Control Measures
  • Eliminate unnecessary access to sensitive data and systems.
  • Substitute broad access models with role-based access and data minimization.
  • Implement engineering controls such as logging, data loss prevention, privileged session recording, and segregation of duties.
  • Apply administrative controls including background screening where permitted, acceptable use rules, confidentiality obligations, monitoring, and disciplinary procedures.
  • Use targeted awareness training for handling sensitive data and reporting suspicious behavior.
Residual Risk Assessment
LikelihoodSeverityRisk Rating
UnlikelyMajorHigh

7\. Third-party and supply chain risk arising from vendors, managed service providers, software suppliers, or outsourced support with inadequate security or resilience.

Potential Consequences: Compromised suppliers may introduce malware, data exposure, service disruption, or compliance failures into the organization.

Affected Persons: Internal users, customers, business partners, procurement teams, and IT operations.

Initial Risk Assessment
LikelihoodSeverityRisk Rating
PossibleMajorHigh
Control Measures
  • Eliminate unnecessary third-party connections and unused integrations.
  • Substitute high-risk suppliers with vendors that meet defined security and resilience requirements where feasible.
  • Implement engineering controls such as network segmentation, API security controls, vendor access restrictions, and monitoring of third-party activity.
  • Apply administrative controls including due diligence, contractual security clauses, right-to-audit provisions, periodic reassessment, and offboarding procedures.
  • Require vendors to report incidents promptly and maintain minimum security standards aligned to organizational policy.
Residual Risk Assessment
LikelihoodSeverityRisk Rating
UnlikelyMajorHigh

8\. Non-compliance with information security, privacy, operational resilience, record retention, and sector-specific regulatory requirements.

Potential Consequences: The organization may face legal penalties, enforcement action, contractual breach, audit findings, loss of customer confidence, and mandatory remediation costs.

Affected Persons: The organization, compliance teams, management, customers, and regulated stakeholders.

Initial Risk Assessment
LikelihoodSeverityRisk Rating
PossibleMajorHigh
Control Measures
  • Eliminate undocumented or uncontrolled processes that cannot demonstrate compliance.
  • Substitute informal compliance tracking with a formal control register and evidence repository.
  • Implement engineering controls such as centralized logging, retention controls, access records, and automated compliance reporting where possible.
  • Apply administrative controls including policy management, legal and regulatory review, internal audits, corrective action tracking, and management sign-off.
  • Maintain staff training on applicable standards, privacy obligations, and incident reporting requirements.
Residual Risk Assessment
LikelihoodSeverityRisk Rating
UnlikelyMajorHigh

9\. Human error during routine support, maintenance, patching, backup restoration, or emergency recovery activities.

Potential Consequences: Incorrect changes may cause outages, data loss, security gaps, or prolonged recovery times; errors may propagate across systems.

Affected Persons: IT administrators, support staff, business users, and dependent services.

Initial Risk Assessment
LikelihoodSeverityRisk Rating
LikelyModerateHigh
Control Measures
  • Eliminate unnecessary manual steps through automation and standard operating procedures.
  • Substitute high-risk ad hoc work with scripted, tested, and peer-reviewed procedures.
  • Implement engineering controls such as change validation, rollback capability, backup verification, and environment separation.
  • Apply administrative controls including competency checks, pre-task briefings, checklists, peer review, and post-change verification.
  • Restrict elevated access during maintenance to approved windows and authorized personnel only.
Residual Risk Assessment
LikelihoodSeverityRisk Rating
PossibleModerateMedium

5\. General Control Measures


  • Maintain a formal information security governance framework with documented policies, standards, procedures, and assigned responsibilities.

Use a control register to map risks to controls, owners, review dates, and evidence of implementation. Ensure policies cover access control, change management, incident response, backup, logging, vendor management, and acceptable use. [1] [12]

  • Apply least privilege and segregation of duties across all critical systems and administrative functions.

Review privileged access regularly, remove unnecessary rights promptly, and separate development, testing, approval, and production support duties where feasible.

  • Implement layered technical safeguards for prevention, detection, and recovery.

Use secure configuration baselines, patching, endpoint protection, network segmentation, logging, monitoring, backup, and tested restoration capabilities.

  • Require structured change management for all material system, configuration, and process changes.

Assess risk before changes, obtain approvals, test changes in non-production environments, define rollback plans, and verify outcomes after implementation.

  • Promote security awareness and reporting culture across the organization.

Train users to recognize phishing, social engineering, suspicious activity, and data handling requirements, and ensure incidents and near misses are reported promptly.

6\. Emergency Preparedness


  • Maintain an incident response plan for cyber events that defines triage, containment, eradication, recovery, communications, evidence preservation, and escalation criteria. The plan should include ransomware, account compromise, data breach, and malware scenarios. [4]

[7]

  • Maintain tested backup restoration and disaster recovery procedures with defined recovery time objectives and recovery point objectives for critical systems. Restoration tests should confirm that backups are usable and that critical services can be recovered within acceptable timeframes. [4]
  • Establish outage communication procedures for internal users, customers, vendors, and management so that service interruptions, expected restoration times, and workarounds are communicated quickly and consistently.
  • Define escalation paths for suspected privacy breaches, regulatory non-compliance, and third-party incidents so that legal, compliance, security, and operational leaders are notified without delay.
  • Prepare contingency arrangements for remote work, alternate access, and manual fallback processes where business operations must continue during system unavailability or security containment actions.

7\. Training Requirements


  • Cybersecurity Awareness Training: All users should receive training on phishing recognition, password hygiene, multi-factor authentication, safe browsing, suspicious attachments, social engineering, and prompt incident reporting. Training should be refreshed regularly and reinforced with simulated phishing exercises.
    • Recognize and report suspicious emails and messages.
    • Protect credentials and never share authentication factors.
    • Verify requests for sensitive actions through trusted channels.
  • Privileged User and Administrator Training: Administrators and support personnel should be trained on secure configuration, privileged access handling, logging, change control, backup verification, and recovery procedures. Training should emphasize the consequences of misconfiguration and the need for peer review and rollback planning.
    • Use approved administrative tools and hardened workstations.
    • Follow change approval and testing requirements.
    • Document and verify all high-risk actions.
  • Incident Response and Escalation Training: Relevant staff should be trained to recognize cyber incidents, preserve evidence, isolate affected systems, notify the correct stakeholders, and follow the incident response plan. Training should include ransomware, data breach, and service outage scenarios.
    • Know containment steps for compromised accounts or devices.
    • Preserve logs and evidence for investigation.
    • Escalate incidents according to severity thresholds.
  • Data Protection and Compliance Training: Employees who handle sensitive or regulated information should be trained on data classification, retention, privacy obligations, secure sharing, and recordkeeping requirements. Training should reflect applicable legal, contractual, and organizational standards.
    • Handle sensitive data only for authorized purposes.
    • Store records in approved systems with retention controls.
    • Report suspected compliance gaps immediately.
  • Change Management and Recovery Training: Personnel involved in maintenance, patching, deployment, and recovery should be trained on change planning, testing, rollback, restoration, and post-change validation. This reduces the likelihood of outages and data loss during operational changes.
    • Use checklists for critical changes.
    • Confirm backups before major changes.
    • Validate system health after implementation.

8\. Monitoring and Review


Review Frequency: Annually and after any significant incident, major system change, regulatory change, or control failure.

Monitoring TypeFrequencyResponsible PartyDescription
Regular InspectionDaily or continuous for critical systemsIT operations and security monitoring teamMonitor security alerts, authentication anomalies, endpoint detections, backup status, and service availability to identify active threats or control failures early. [1]
Access ReviewMonthly for privileged access; quarterly for standard accessSystem owners and information security managementReview user accounts, privileged roles, dormant accounts, and third-party access to confirm access remains appropriate and promptly remove unnecessary permissions. [1]
Control Effectiveness ReviewMonthly or after significant changesIT governance, risk, and compliance functionVerify that key controls such as patching, logging, backup restoration, MFA, and change approvals are operating as intended and producing evidence of effectiveness.
AuditAt least annually and after major incidentsInternal audit, compliance, or designated independent reviewerAssess whether the risk register, control framework, and evidence support compliance with internal policies, legal obligations, and applicable standards.
Incident Trend AnalysisQuarterlySecurity operations and risk managementAnalyze incidents, near misses, phishing reports, outages, and recovery performance to identify recurring weaknesses, emerging threats, and opportunities for improvement.

9\. Special Circumstances


  • Remote work and off-site access increase exposure to phishing, insecure networks, lost devices, and reduced supervision. Additional controls such as VPN, MFA, device encryption, and secure remote support are required. [3]
  • Night work, reduced staffing, and on-call operations can increase the likelihood of human error and delayed escalation. Enhanced handover, escalation, and monitoring arrangements should be used during these periods.
  • Lone work by administrators or support staff during maintenance or recovery increases the impact of mistakes and delays in assistance. High-risk tasks should use buddy checks, remote oversight, or scheduled support coverage. [8]
  • Extreme weather, power outages, and utility disruptions can affect connectivity, cooling, backup power, and recovery capability. Continuity plans should address generator use, UPS capacity, and alternate communications. [4]
  • Major change windows, incident response periods, and peak business cycles can elevate operational risk due to time pressure and workload. Additional approvals, staffing, and rollback readiness should be applied.

Approval and Sign-off


This risk assessment has been reviewed and approved by:

Assessor: _________________________ Date: __________

Manager/Supervisor: _________________________ Date: __________

Safety Representative: _________________________ Date: __________

This risk assessment must be reviewed annually and after any significant incident, major system change, regulatory change, or control failure. or when significant changes occur.

Safety powered by SALUS

12 source record(s)

Sources used for this answer

[1] Hazard and Risk - Risk Assessment

Page 8

Open source document

Source excerpt

# How is a risk assessment done? (cont.) ## How do you know if the hazard will cause harm (poses a risk)? (cont.) - The number of people that could be impacted. - Working alone or in a remote area. ## How are risks ranked or prioritized? Ranking or prioritizing hazards is one way to help determine which hazards are the most serious and, thus, which to control first. Priority is usually established by taking into account the probability of employee exposure to the hazard and the potential severity of an incident, injury or illness associated with the hazard. By assigning a priority to the hazards based on the risks, you are creating a ranking or an action list. Risk assessments with clearly defined parameters for probability and severity will make it easier to determine which hazards should be addressed first. ## What risk assessment methods should be used? Numerous methods exist to analyze risk, and the method used will depend on many factors, including the experience level of the risk assessment team, the scope, the data available, and the level of detail required to adequately understand the risks. There is no one simple or single way to determine the level of risk. Nor will a single method apply in all situations. The organization has to determine which method will work best for each situation. Ranking hazards requires knowledge of workplace activities, the urgency of situations, and, most importantly, objective judgment. For simple or less complex situations, an assessment can literally be a discussion or brainstorming session based on knowledge and experience. In some cases, checklists or a risk matrix can be helpful. For more complex situations, a team of knowledgeable personnel who are familiar with the work and risk assessment methodologies is usually necessary. Depending on the circumstances or situation being assessed, the legislation may specify how the risk assessment needs to be done, including what personnel need to be involved. Depending on t

[2] Hazard and Risk - Sample Risk Assessment Form

Page 1

Open source document

Source excerpt

CCOHS CCHST Canadian Centre for Occupational Health and Safety Centre canadien d'hygiène et de sécurité au travail Hazard and Risk # Hazard and Risk - Sample Risk Assessment Form On this page How can risks be assessed? What is a sample risk assessment form? Is there a procedure for assessing risks? ## How can risks be assessed? After hazards are identified, the risks associated with those hazards should be systematically reviewed to ensure those things, activities, situations, processes, tasks, etc. that cause harm to people or property are controlled. One way to ensure that all risks are evaluated in the same way is to use a risk assessment form. This procedure should be carried out by someone who is experienced and fully familiar with the activity (e.g., a "competent person"). Please note: see the OSH Answers Risk Assessment for more information about risk assessments in general, and how to rank hazards. ## Is there a procedure for assessing risks? There is no one way to assess risks, and there are many risk assessment tools and techniques that can be used. Choose the method that best matches your situation. In all cases, the risk assessment should be completed for any activity, task, etc. before the activity begins. <table><tr><th>Step</th><th>Action</th><th>Deliverable</th></tr><tr><td>1</td><td>Identify hazards and their potential for causing harm.</td><td>An inventory of hazards.</td></tr><tr><td>2</td><td>Assess the risk of each hazard and rank hazards by priority (consider the probability of harm and severity of harm).</td><td>A ranked list of hazards. This list will be useful in planning further action.</td></tr><tr><td>3</td><td>Determine hazard control measures.</td><td>1. A record of hazard control measures at various locations. 2. Evaluation of the adequacy of hazard control measures. Consider the hierarchy of controls, and controls required or recommended by legislation, standards, good practices, or organizational policies.</td></tr><tr><

[3] Hazard and Risk - Risk Assessment

Page 12

Open source document

Source excerpt

# How is a risk assessment done? (cont.) ## Field-level Risk Assessment (cont.) The purpose of a field-level risk assessment is to identify, assess, and manage hazards and risks in real-time or on-site as work progresses, with a focus on ensuring the safety of workers. Field- level risk assessments are often completed in addition to formal risk assessments that have already been done before that specific day. Field-level risk assessments can also supplement safety meetings with teams as you work together through a common task, highlighting hazards and control measures that are currently in place. It can also be a good opportunity to brainstorm additional controls or better ways to complete the task. These risk assessments can help continue the safety conversation and avoid complacency. Similar to other risk assessments, each step of the task should be written down and hazards identified. The risk of each hazard can then be assessed based on the likelihood and severity of harm. Then, the team will determine if the current controls in place are adequate, or if further measures are needed prior to work beginning. An example of a table that may assist with a field- level risk assessment is shown in Table 4. Risk matrices similar to those in Table 2 or Table 3 can also be used to assess the risk for each hazard. Table 4: Field-level risk assessment Job or work activity being assessed: <table><tr><th>Step/task description</th><th>Hazards</th><th>Risk</th><th>Priority</th><th>Current controls</th><th>Recommended controls</th></tr><tr><td></td><td></td><td></td><td></td><td></td><td></td></tr><tr><td></td><td></td><td></td><td></td><td></td><td></td></tr></table> ## What are methods of hazard control? Once you have established the priorities, the organization can decide on ways to control each specific hazard. Hazard control methods are often grouped into the following categories: - Elimination. - Substitution. - Engineering controls. - Administrative controls.

[4] Hazard and Risk - Risk Assessment

Page 1

Open source document

Source excerpt

CCOHS CCHST Canadian Centre for Occupational Health and Safety Centre canadien d'hygiène et de sécurité au travail Hazard and Risk # Hazard and Risk - Risk Assessment ## On this page What is a risk assessment? Why is risk assessment important? What is the goal of risk assessment? When should a risk assessment be done? How do you plan for a risk assessment? How is a risk assessment done? How are the hazards identified? How do you know if the hazard will cause harm (poses a risk)? How are risks ranked or prioritized? What risk assessment methods should be used? What are methods of hazard control? Why is it important to review and monitor the assessments? What documentation should be done for a risk assessment? ## What is a risk assessment? Risk assessment is a term used to describe the overall process or method where of identifying hazards, assessing the risk of hazards, and prioritizing hazards associated with a specific activity, task, or job. It considers the probability or likelihood of harm from exposure and the potential consequence or severity of harm from exposure to a hazard. A risk assessment is a thorough look at your workplace to identify those things, situations, processes, etc. that may cause harm, particularly to people. After the identification of a hazard, it should be reviewed to determine how likely and severe the potential harm is. When this determination is made, you can decide what measures should be in place to effectively eliminate or control the harm from happening (hazard control). Some important terms related to risk assessments include: Hazard - a potential source of injury, adverse health effect, or damage to people, structures, equipment, or the environment. A common way to classify hazards is to categorize them as biological, chemical, ergonomic, physical, psychosocial, and safety hazards. Hazard identification - the process of finding, listing, and characterizing hazards. Hazard and Risk - Risk Assessment CCOHS

[5] Hazard and Risk - Hierarchy of Controls

Page 2

Open source document

Source excerpt

# Hierarchy of Controls Most effective ELIMINATION SUBSTITUTION ENGINEERING CONTROLS ADMINISTRATIVE CONTROLS PPE Least effective Figure 1: Hierarchy of Control Some sources may use a variation of this hierarchy of controls. For example, the CSA Standard 1002-12 (R2022): Occupational health and safety — Hazard identification and elimination and risk assessment and control includes a layer called "systems that increase awareness of potential hazards". For example, visual or audible alarms or warning signs. This systems layer is placed in between engineering controls and administrative controls. Regardless of the number of layers included, the hierarchy should be considered in the order presented (it is always best to try to eliminate the hazard first, etc.). What is meant by elimination? Hazard and Risk - Hierarchy of Controls CCOHS

[6] Hazard and Risk - Risk Assessment

Page 3

Open source document

Source excerpt

# Hazard and Risk - Risk Assessment (cont.) ## What is the goal of risk assessment? (cont.) a. What can happen, and under what circumstances? b. What are the possible consequences? C. How likely are the possible consequences to occur? d. How severe are the possible consequences? e. Has an adequate level of risk reduction been achieved, or is further action required? ## When should a risk assessment be done? There may be many reasons a risk assessment is needed, including: - Before new processes or activities are introduced. - Before changes are introduced to existing processes or activities, including when products, machinery, tools, or equipment change. - When new information concerning harm becomes available. - When hazards are identified. - Before working in a new environment. - When new information on hazard controls or good practices becomes available. - Before performing maintenance or commissioning of equipment - Before completing routine or non-routine tasks. - When the legislation requires a risk assessment to be done. ## How do you plan for a risk assessment? In general, determine: - What the scope of your risk assessment will be (e.g., be specific about what you are assessing such as the lifetime of the product, the physical area where the work activity takes place, or the types of hazards). - The resources needed (e.g., training a team of individuals to carry out the assessment, the types of information sources, etc.). - What type of risk analysis measures will be used (e.g., how exact the scale or parameters need to be in order to provide the most relevant evaluation)? - Who are the stakeholders involved (e.g., manager, supervisors, workers, worker representatives, suppliers, etc.). - What relevant laws, regulations, codes, or standards may apply in your jurisdiction, as well as organizational policies and procedures? Hazard and Risk - Risk Assessment CCOHS

[7] Hazard and Risk - Risk Assessment

Page 7

Open source document

Source excerpt

# How is a risk assessment done? (cont.) ## How are the hazards identified? (cont.) Hazard mapping is a method of hazard identification that is performed by employees themselves. All of the employees from a work area, including supervisors and managers, get together and mark hazard locations on the building's floor plan. Later, the group discusses how to control these hazards and which ones should be dealt with first. This approach makes use of employees' knowledge and experience, empowers employees, and encourages involvement and cooperation. More information is also available in the OSH Answers on Hazard Identification. ## How do you know if the hazard will cause harm (poses a risk)? Each hazard should be studied to determine its level of risk. Understanding how likely it is that a hazard will cause harm and how severe that harm could be. To research the hazard, you can look at: - Product information and the manufacturer documentation. - Past experience (knowledge from workers, etc.). - Legislated requirements and applicable standards. - Industry codes of practice and good practices. - Health and safety material about the hazard, such as safety data sheets (SDSs), research studies, or other manufacturer information. - Information from reputable organizations. - Results of testing (atmospheric or air sampling of the workplace, biological swabs, etc.). - The expertise of an occupational health and safety professional or other technical experts. - Information about previous injuries, illnesses, near misses, incident reports, etc. - Observation of the process or task. Remember to include factors that contribute to the level of risk, such as: - The work environment (layout, condition, weather, etc.). - The procedures for performing a task. - The range of foreseeable conditions. - The way the source may cause harm (e.g., inhalation, ingestion, etc.). - How often and how much a person will be exposed. - The interaction, capability, skill, and ex

[8] Hazard and Risk - Risk Assessment

Page 11

Open source document

Source excerpt

# How is a risk assessment done? (cont.) ## Semi-quantitative Methods (cont.) <table><tr><th></th><th>Negligible Severity (1)</th><th>Minor Severity (2)</th><th>Moderate Severity (3)</th><th>Major Severity (4)</th><th>Catastrophic Severity (5)</th></tr><tr><td>Rare Probability (1)</td><td>Low (1)</td><td>Low (2)</td><td>Low (3)</td><td>Moderate (4)</td><td>Moderate (5)</td></tr><tr><td>Unlikely Probability (2)</td><td>Low (2)</td><td>Moderate (4)</td><td>Moderate (6)</td><td>High (8)</td><td>High (10)</td></tr><tr><td>Possible Probability (3)</td><td>Low (3)</td><td>Moderate (6)</td><td>High (9)</td><td>High (12)</td><td>Extreme (15)</td></tr><tr><td>Likely Probability (4)</td><td>Moderate (4)</td><td>High (8)</td><td>High (12)</td><td>Extreme (16)</td><td>Extreme (20)</td></tr><tr><td>Almost Certain Probability (5)</td><td>Moderate (5)</td><td>High (10)</td><td>Extreme (15)</td><td>Extreme (20)</td><td>Extreme (25)</td></tr></table> When using this method, it is important to clearly define the parameters for assigning scores for severity and probability, so all team members understand the scoring criteria. Using Table 3, a hazard assigned as having an unlikely probability of occurring (probability score of 2) and minor severity (severity score of 2) is a moderate riskwith a risk rating score of 4. Remember! Risk = probability X severity. The qualitative and semi-quantitative risk matrices above are just a couple of examples. These matrices can be customized to further refine risk by considering more detailed criteria for probability and severity. Quantitative methods are also sometimes used, which calculate risk based on data collected over a period of time or multiple situations. Examples include failure mode and effects analysis (FMEA) and decision tree analysis (these methods are not covered in this fact sheet). ## Field-level Risk Assessment A field-level risk assessment (FLRA) is another method that is commonly used in industries and wor

[9] Hazard and Risk - Risk Assessment

Page 2

Open source document

Source excerpt

# Hazard and Risk - Risk Assessment (cont.) ## What is a risk assessment? (cont.) Risk - the combination of probability and severity that a person will be harmed or experience an adverse health effect if exposed to a hazard. Risk can also be applied to situations with property or equipment damage, or harmful effects on the environment. Probability - the extent to which an event is likely to occur. The probability of harm may also be referenced as the likelihood of harm. Severity - the seriousness of an incident, injury, or illness. Severity, or consequence, describes the highest level of damage possible from a hazard and is often described in terms such as catastrophic, critical, moderate, minor, or negligible. In general, risk can be expressed as: Risk = probability X severity Hazard control - control measure(s) and action(s) taken to reduce the risk of a hazard based on the risk assessment. Hazard control should also include monitoring, re- evaluation, and compliance with decisions (the term "controls" or "control measures" are also used and have the same meaning). Recommending or determining hazard controls may be incorporated into the risk assessment process, or completed separately following a risk assessment. For definitions and more information about what hazards and risks are, please see the OSH Answers document Hazard and Risk. ## Why is risk assessment important? Risk assessments are very important as they form an integral part of an occupational health and safety management plan. They help to: - Create awareness of hazards and risks. - Identify who may be at risk (e.g., workers, cleaners, visitors, contractors, the public, etc.). - Determine whether a control program is required for a particular hazard. - Determine if existing control measures are adequate or if more should be done. Prevent injuries - or illnesses, especially when done at the design or planning stage. - Prioritize hazards and control measures. - Meet legal requirements

[10] Hazard and Risk - Hazard Identification

Page 3

Open source document

Source excerpt

# Hazard and Risk - Hazard Identification (cont.) ## How are hazards identified? (cont.) - Job descriptions and demands analysis - Job safety analysis - Incident investigations - Documents and records - Hazard reporting by employees - Hazard mapping To be sure that all hazards are found: - Look at all aspects of the work and include non-routine activities such as maintenance, repair, or cleaning. - Look at the physical work environment, equipment, materials, products, etc. that are used. - Include the various steps that make up a task or activity. - Look at injury and incident records. - Talk to the workers: they know their job and its hazards best. - Include all shifts and people who work off-site, either at home, on other job sites, drivers, teleworkers, or with clients. - Look at the way the work is organized or done by different individuals (including the experience of people doing the work, systems being used, if alternate methods are being used, etc.). - Look at foreseeable unusual conditions (for example, possible impact on hazard control procedures that may be unavailable in an emergency situation, power outage, etc.). - Determine whether a product, machine, or equipment can be intentionally or unintentionally changed (such as a safety guard that could be removed). - Review all of the phases of the lifecycle of processes, products, and services (such as design, transportation, construction, dismantling, and disposal). - Examine risks to visitors or the public. - Consider the groups of people that may have a different level of risk, such as young or inexperienced workers, persons with disabilities, or new or expectant mothers. - Consider the psychosocial aspects of the job and the hazards that could be created. ## What types of hazards are there? A common way to classify hazards is by category: Hazard and Risk - Hazard Identification CCOHS

[11] Hazard and Risk - Risk Assessment

Page 4

Open source document

Source excerpt

# How is a risk assessment done? In general, to do an assessment, you should: 1. Assemble a risk assessment team. Assessments should be done by a competent person or team of individuals who have a good working knowledge of the situation being studied. Include the supervisors and workers who work with the process under review on the team or as sources of information, as these individuals are the most familiar with the operation. The health and safety committee or representative should also be consulted. 2. Select the job or process to assess. Refer to the above section, "When should a risk assessment be done", to help prioritize your assessments. Ideally, risk assessments should be done for all jobs. Jobs or tasks with higher injury and illness rates, worker concerns, and other factors should be considered first. 3. Break down the job or process into tasks. Divide the job or process into tasks or basic steps to better understand the hazards. 4. Identify the hazards of each task. After the basic steps or tasks have been recorded, identify the hazards of each step or task. List the hazards based on observations and inspections, previous causes of incidents and injuries, feedback from workers and supervisors directly involved in the task, and other considerations. 5. Assess the risk of each hazard. For each hazard, determine the likelihood of harm, such as an injury or illness occurring, and its severity. Use a risk assessment method appropriate for your workplace (see further below for details on risk assessment methods). Consider normal operational situations as well as non-standard events such as maintenance, shutdowns, power outages, emergencies, extreme weather, etc. Review all available health and safety information about the hazard, such as Safety Data Sheet (SDS), manufacturer's literature, information from reputable organizations, results of testing, workplace inspection reports, records of workplace incidents (accidents), including information about the

[12] Hazard and Risk - Risk Assessment

Page 13

Open source document

Source excerpt

# Why is it important to review and monitor the assessments? It is important to know if your risk assessment was complete and accurate. It is also essential to be sure that any changes in the workplace have not introduced new hazards or changed hazards that were once ranked as lower priorities to higher priorities. It is good practice to review your assessment on a regular basis to make sure your control methods are effective. ## What documentation should be done for a risk assessment? It is very important to keep records of your assessment and any control actions taken. You may be required to store assessments for a specific number of years. Check for local requirements in your jurisdiction. The level of documentation or record keeping will depend on: - Level of risk involved. - Legislated requirements. - Requirements of any management systems that may be in place. Your records should show that you: - Conducted a good hazard review. - Determined the risks of those hazards. - Implemented control measures suitable for the risk. - Reviewed and monitored all hazards in the workplace. Fact sheet last revised: 2025-03-12 ## Disclaimer Although every effort is made to ensure the accuracy, currency and completeness of the information, CCOHS does not guarantee, warrant, represent or undertake that the information provided is correct, accurate or current. CCOHS is not liable for any loss, claim, or demand arising directly or indirectly from any use or reliance upon the information. Hazard and Risk - Risk Assessment CCOHS

Related Q&A

Keep exploring.

Human questionGeneral

Lifting

Toolbox Talk: Safe Lifting Practices *Date:** [DATE] *Duration:** [DURATION] minutes *Presenter:** [PRESENTER NAME] *Location:** [LOCATION] Objective The objective of this toolbox talk is to educate participants on safe lifting practices to prevent injuries and ensure compliance with safety regulations. By the end of

Read the thread
Human questionGeneral

spray fireproofing

\[PRE TASK PLAN TITLE] ====================== *Project:** \[PROJECT NAME] *Date:** 2025-08-27 *Location:** \[LOCATION] *Supervisor:** \[SUPERVISOR NAME] Task Overview This pre-task plan outlines the safety guidelines for the application of spray-applied fireproofing materials, including application procedures, hazard

Read the thread
Human questionGeneral

use a single line drawing to identify lock out points

Creating Single-Line Diagrams for Lockout/Tagout (LOTO) ======================================================== *Date:** 2026-01-03 *Duration:** \[DURATION] minutes *Presenter:** \[PRESENTER NAME] *Location:** \[LOCATION] Objective To understand how to create and use single-line diagrams for effective energy isolation

Read the thread
Human questionGeneral

Evaluating risk

Toolbox Talk: Evaluating Risk *Date:** [DATE] *Duration:** [DURATION] minutes *Presenter:** [PRESENTER NAME] *Location:** [LOCATION] Objective The objective of this toolbox talk is to educate participants on the importance of evaluating risks in the workplace, particularly when dealing with hazardous chemicals and

Read the thread
Human questionGeneral

Safety procedure for installing sheaves on an elevator

Safe Work Procedure: Installing Sheaves on an Elevator Document Number: [SWP-NUMBER] Revision Date: [DATE] Next Review Date: [NEXT REVIEW DATE] Department: [DEPARTMENT NAME] 1. Scope This Safe Work Procedure (SWP) outlines the necessary safety precautions and procedures to be followed when installing sheaves on an

Read the thread
Discussion thread

Add your experience.

Community answers can add practical context. They are moderated, but they are not SALUS-reviewed safety guidance.

New contributions are temporarily closed while the moderation queue is configured.

Community answers(0)

No community answers have been approved yet.

Comments on Rosie's answer(0)

No comments have been approved yet.

Ready to put operational safety to work?

Join 400K users across 150K sites already on SALUS.

No commitment · 30-minute personalized walkthrough