After a workplace risk assessment, most teams file the record, assign the control actions and set a review date. The step they skip is testing the assumptions underneath each likelihood and severity rating, the ones that decide whether a hazard lands in the green or the red.

A workplace risk assessment is an employer's structured check of what could harm people at work, how likely and severe that harm is, and which controls reduce it.

The standard next step after a workplace risk assessment

Regulators broadly agree on what comes next. The UK Health and Safety Executive sets out five steps to manage risk: identify hazards, assess the risks, control the risks, record the findings, review the controls. An employer with five or more people must record the significant findings, including the hazards, who might be harmed and how, and what is being done to control the risks.

Safe Work Australia's model Code of Practice on managing work health and safety risks follows the same arc and ends with reviewing control measures to confirm they are working as planned. In the United States, OSHA's recommended practices on hazard identification and assessment ask employers to determine the severity and likelihood of incidents for each hazard, then use that information to prioritise corrective action.

What to do after a workplace risk assessment: test the assumptions behind each rating before implementing controls
The usual question after a workplace risk assessment asks which hazards to control first. The better one asks which ratings rest on assumptions nobody has verified.Click to expand

So the standard next step is implementation. Each rated hazard gets a control, chosen as high on the hierarchy of control as is reasonably practicable: eliminate the hazard, substitute, isolate or engineer it out, then fall back on administrative controls and personal protective equipment. Actions get owners and due dates. The highest ratings go first. The risk assessment process then loops through periodic review, usually prompted by a date on the calendar, an incident, or a change in the work.

Across the wider discipline of risk assessment, this is the settled sequence. Rate, control, record, review. What the sequence treats as finished is the rating itself. Once a hazard has a likelihood and a severity, the conversation moves to controls, not to whether the numbers were right.

What that step adds

Implementation is where a risk assessment stops being paperwork. A hazard identified and rated but never controlled protects nobody. The standard step forces the question from "what could go wrong" to "what will be done about it, by whom, by when."

The hierarchy of control earns its place here. It pushes employers toward controls that remove the hazard rather than controls that depend on people behaving perfectly. A fixed guard on a machine outlasts a warning sign. A substituted solvent outlasts a respirator policy. That ordering is one of the most useful ideas in occupational safety, and it only operates at the implementation stage. It is also what a certifier checks, which is why a clean result after an ISO 45001 audit says the controls fit the listed hazards, not that the list was right.

The record matters too. A written assessment gives inspectors, workers and managers a shared reference. It shows what the employer knew, when it knew it, and what it chose to do. When something changes, the record is the baseline the change gets measured against. Unlike a risk register that sits apart from any decision, a workplace assessment is usually tied to a specific task, area or piece of plant, which keeps it close to the work.

Review closes the loop. HSE lists the prompts: controls that may no longer be effective, changes to staff, processes, substances or equipment, and workers reporting problems, accidents or near misses. Each prompt is a sensible reason to look again. None of them asks whether the original rating rested on something that was never true.

Rewrite the risk rating your controls lean on hardest as a claim and test it before the assessment is signed off and filed. Start the Walk →

Where the standard playbook breaks down

A likelihood and severity rating is a compressed argument. The same flaw runs through formal risk evaluation, where criteria inherited from last year's thresholds go untested against current conditions. Behind "low likelihood" sits a claim about how often people are exposed, how the hazard behaves, and whether the controls will hold. Cox (2008) showed that risk matrices can give identical ratings to quantitatively very different risks, and can rate a smaller risk above a larger one. The grid hides the argument, a flaw that runs through risk practice well beyond workplace safety and the reason alternatives to the risk matrix start by making the reasoning visible.

The BP Texas City refinery explosion of 23 March 2005 shows what this looks like on a real site. Fifteen contract workers were killed and 180 people were injured. According to the US Chemical Safety Board's final investigation report, all 15 fatalities occurred in or around temporary trailers that BP had sited as close as 121 feet from the isomerization unit's blowdown drum.

The trailers sat inside an assessment process. The refinery's management-of-change procedure required a hazard analysis for newly sited structures, and a checklist sent any trailer within 350 feet of a process unit on to a building siting analysis using the refinery's siting workbook, which broadly followed API Recommended Practice 752. In September 2004 the checklist correctly flagged the double-wide trailer. None of the team had been trained to use the workbook. In place of the analysis, they attached a drawing of the trailer's interior and measured its distance from a catalyst warehouse. Nine more trailers went into the same area in early 2005 without any management-of-change review, so the combined occupancy of the cluster was never considered.

Beneath the procedure sat assumptions nobody tested. Under BP's siting policy, short-duration turnaround trailers were considered to pose little or no danger to occupants. Occupancy was normally judged as an annual average, which the CSB called inappropriate for trailers occupied for only several months of a turnaround. The vulnerability data came mostly from conventional buildings, and under-predicted how trailers respond to a vapour cloud explosion. A September 2004 email forwarded from BP's Whiting refinery flagged both limits. They were dismissed because the checklist called for 350 feet, a distance at which fatality risk was judged extremely low. The 350-foot line triggered an analysis. It never stopped a trailer being placed closer.

On a generic likelihood and severity grid, illustrative rather than a reconstruction of BP's method, the pattern looks like this.

Lower severityHigher severity
Higher likelihoodRoutine exposures managed by procedure and supervisionControl before anyone occupies the area
Lower likelihoodRare, minor harms: record and monitorOccupied trailer near a process unit, rated on annual average occupancy → moves when assumptions tested

Replace the annual average with the people actually inside during a turnaround, and replace conventional-building vulnerability with data for trailers, and the same hazard climbs into the top right. The Texas City trailers did not lack a risk assessment process. They lacked a test of the assumptions that process ran on. What looked like a measured risk was closer to an uncertainty nobody had named.

The step to take first

Before implementing controls, test the assumptions each rating and each control depends on. This does not replace the hierarchy of control or the review cycle. It sits between the rating and the action plan.

A five-step decision method gives the check a shape. Frame the decision: what the assessment is for and what the employer is trying to protect. Treat the hazards, ratings and proposed controls as tentative elements, provisional rather than final. Surface the assumptions each one rests on: who is exposed and for how long, how the hazard behaves at its worst, whether the control works under real conditions. Decide whether there is sufficient certainty to proceed, or whether a specific assumption needs testing first. Then implement and monitor, with monitoring aimed at the assumptions most likely to fail.

The third step does the work. A rating is a conclusion drawn from premises, and the premises belong on the page next to it. "Low likelihood" becomes "low likelihood, assuming an average of five people present." Written that way, the flaw in a siting decision like Texas City is visible before anyone moves in. A clinical risk assessment completed on the ward hides the same kind of premise when it is used to approve a discharge, as does a structural risk assessment used to defer a repair. Residual-risk entries in a CDM risk assessment carry that kind of premise from the design office to site. The same discipline applies to assumptions in any decision, not only safety ones.

Assumptions behind workplace risk assessment ratings and controls
Hazards were identified by inspecting the work area and asking the people who do the work
Exposure reflects peak occupancy, not an annual average
The severity rating holds for the worst credible event, not the typical one
The people applying each control have been trained to apply it
People or equipment added after the assessment will trigger a new one

The controls still get implemented. The record still gets filed. The difference is that the employer knows which ratings rest on evidence and which rest on a convenient average. That knowledge is what turns a review date into an actual review.

You could close this tab and carry that decision into another week.

Work through your decision

No sign-up. Just pick your decision and start.


Grant Purdy is the co-author, with Roger Estall, of Deciding (2020), and the architect of the Universal Decision-Making Method.