Frequently asked questions
Let us have your feedback
As part of the evaluation of the risk assessment guidance we would like to know more about visitors to these webpages. Please help us by following the link below and answering some quick questions.
Definitions
- What is a hazard?
- What is risk?
- What is risk management?
- What is risk assessment?
- What do 'ALARP' and'SFAIRP' mean?
- What does 'reasonably practicable' mean?
Risk assessment
- Why is risk assessment important?
- How do I do a risk assessment?
- Is HSE's five steps to risk assessment the only acceptable method?
- Who do I involve in a risk assessment?
- What things do I have to include in a risk-assessment record?
- When do I need to do a risk assessment?
- When should I review my risk assessments?
- What do you mean by 'good practice' and how do I find it?
- What do I have to do in terms of fire safety?
Sensible risk management
- Do I need to get consultants in to do my risk assessment?
- Do I have to record the findings of the risk assessment? If so, why? Isn’t that just bureaucracy?
- Is there a specific form/format that I have to use to record a risk assessment?
- Isn’t risk assessment nonsense? My employees are adults and can look after themselves.
- Doesn’t risk assessment just lead to more and more safety measures most of which aren’t necessary?
- Is HSE too risk averse?
Precautionary principle
Definitions
What is a hazard?
A hazard is anything with the potential to cause harm e.g. working at height on scaffolding.
What is risk?
A risk is the likelihood that a hazard will cause a specified harm to someone or something, eg if there are no guard rails on the scaffolding it is likely that a construction worker will fall and break a bone.
What is risk management?
Risk management is a process that involves assessing the risks that arise in your workplace, putting sensible health and safety measures in place to control them and then making sure they work in practice.
What is risk assessment?
A risk assessment is nothing more than a careful examination of what, in your work, could cause harm to people, so that you can weigh up whether you have taken enough precautions or should do more to prevent harm.
What do 'ALARP' and 'SFAIRP' mean?
You may come across these abbreviations. ALARP stands for 'as low as reasonably practicable' and SFAIRP stands for 'so far as is reasonably practicable'. In essence, these are the same; however, SFAIRP is the term most often used in the Health and Safety at Work etc Act and in Regulations, and; ALARP is the term used by risk practitioners.
What does 'reasonably practicable' mean?
This means that you have to take action to control the health and safety risks in your workplace except where the cost (in terms of time and effort as well as money) of doing so is 'grossly disproportionate' to the reduction in the risk. You can work this out for yourself, or you can simply apply accepted good practice.
Risk assessment
Why is risk assessment important?
Managing health and safety risks puts you in control since it leaves your business less open to chance. A risk assessment helps to prevent accidents and ill health to you, your workers and members of the public. Accidents and ill health can ruin lives and harm your business too if output is lost, equipment is damaged, insurance costs increase or you have to go to court. You are legally required to assess the risks in your workplace so that you can put in place a plan to control the risks.
How do I do a risk assessment?
Download the Risk Assessment and Policy Template. This template brings together your risk assessment, health and safety policy and record of health and safety arrangements into one document to help get you started and save you time. If you already have a policy, you may choose to simply complete the risk assessment part of the template. Use the example risk assessments as a guide for completing the template, adapting it for your own workplace. We also have the Five Steps to Risk Assessment leaflet that you can use, if you wish. This is not the only way to do a risk assessment, there are other methods that work well, particularly for more complex risks and circumstances. However, we believe this method is the most straightforward for most organisations.
Should you decide to complete the health and safety policy part of the template, we have an example health and safety policy that you can use as a guide.
Is HSE’s five steps to risk assessment the only acceptable method?
No. We believe ‘Five steps to risk assessment’ provides a straightforward method, but it’s certainly not the only acceptable way.
A number of alternatives exist. Most follow the same format as that in Five Steps to Risk Assessment.
- Identify the hazards.
- Decide who might be harmed and how.
- Evaluate the risks and decide on precautions.
- Record your findings and implement them.
- Review your risk assessment.
Other methods tend to differ at the ‘evaluate the risks’ stage. Here, we suggest comparing your control measures with good practice to assess whether more needs to be done. But, another common and very effective method involves working out a risk level by categorising the likelihood of the harm and the potential severity of harm and then plotting these two risk-determining factors against each other in a risk matrix (see below). The risk level determines which risks should be tackled first. As with any other method of risk assessment, you should not overcomplicate the process, eg by having too many categories.

Using a matrix can be very helpful for prioritising actions. It is suitable for very many assessments but particularly lends itself to more complex situations. However, it does require a fair degree of expertise and experience to judge the likelihood of harm accurately. Getting this wrong could result in applying unnecessary controls or failing to take important ones. People working full time in health and safety often use a version of this method. It provides a good alternative to the 'good practice' approach in Five Steps To Risk Assessment.
Who do I involve in a risk assessment?
Make sure that you involve employees and safety representatives when carrying out the assessment. For advice on how to do this please visit HSE’s Worker Involvement web pages. Remember to speak to workers who may have particular requirements, eg new and young workers, new or expectant mothers and people with disabilities.
What things do I have to include in a risk-assessment record?
In your risk assessment, you need to be able to show that:
- a proper check of the hazards was made;
- you asked who might be affected;
- you dealt with all the obvious significant hazards, taking into account the number of people who could be involved;
- the precautions are reasonable, and the remaining risk is low; and
- you involved your staff or their representatives in the process.
When do I need to do a risk assessment?
You should carry out an assessment before you do the work that gives rise to the risk, and review it as necessary.
When should I review my risk assessments?
Few workplaces stay the same. Sooner or later, you will bring in new equipment, substances and procedures, and that could lead to new hazards. Therefore, you will need to review where you are, every year or so, to make sure you are still improving, or at least not sliding back.
During the year, if there is a significant change, don't wait, check your risk assessment and where necessary, amend it. It is best to think about the risk assessment when you're planning your change – that way you leave yourself more flexibility.
See Step 5 of "Five Steps to Risk Assessment"
What do you mean by 'good practice' and how do I find it?
Good practice refers to practices that have been acknowledged by HSE or local authorities as representing standards of compliance with the law. It doesn’t mean ‘custom and practice’ necessarily – that can be poor practice. There are many sources of good practice and HSE works with industries to produce good practice guidance – HSE’s website, HSE Infoline and Workplace Health Connect can all help.
What do I have to do in terms of fire safety?
Under the Regulatory Reform (Fire Safety) Order 2005, a responsible person (usually the employer, owner or occupier) must carry out a fire safety risk assessment and put measures in place that adequately protect in the event of a fire. More information and guidance on how to comply with the law can be found at www.communities.gov.uk/firesafety.
Sensible risk management
Do I need to get consultants in to do my risk assessment?
In most cases, this is not necessary. Risk assessment is a straightforward process that most people can do, given a little time and effort. You will probably need help if you have particularly hazardous or complex processes, but for the majority of organisations, you or a competent member of staff should be able to complete a satisfactory assessment. HSE’s Risk Assessment and Policy Template, Example Risk Assessments and Five Steps to Risk Assessment leaflet can help.
Just use your common sense. You don’t need an electrician to rewire a plug, but most people would need one to rewire their house. It’s the same with risk assessment.
Do I have to record the findings of the risk assessment? If so, why? Isn’t that just bureaucracy?
Health and safety law requires that you keep a record of the significant findings of your assessment if you employ five or more people. It makes sense to keep a record of the assessment so that when you come to review it, you can check back to see if anything has changed. It is also useful to keep a record so that you can share the findings with your staff. Finally, it proves that you have carried out the process if a health and safety inspector asks about it.
Is there a specific form/format that I have to use to record a risk assessment?
No. However, there is a Risk Assessment and Policy Template and a number of example risk assessments that may help. We also have the Five Steps to Risk Assessment leaflet that you can use, if you wish. You can record the assessment in any convenient way.
Isn’t risk assessment nonsense? My employees are adults and can look after themselves.
All workers are entitled to work in environments where risks to their health and safety are properly controlled. Under health and safety law, the primary responsibility for this is down to employers. Doing a risk assessment is the key to preventing accidents and ill-health to you, your workers and members of the public. Accidents and ill health can ruin lives and harm your business too if output is lost, equipment is damaged, insurance costs increase or you have to go to court.
However, workers also have a duty to take care of their own health and safety and that of others who may be affected by their actions. Health and safety legislation, therefore, requires employers and workers to co-operate. Involving workers and their representatives in your risk assessment is one of the best ways of doing this. For more information, visit HSE’s Worker Involvement pages.
Doesn’t risk assessment just lead to more and more safety measures - most of which aren’t necessary?
No. When done properly, it should identify the measures that are needed to reduce the risk as low as 'reasonably practicable' and not further. It is important to remember that risk assessment can show that a process is safe enough with the measures you already have in place, and no more need be done.
Is HSE too risk averse?
We don’t think so. Our approach is to seek a balance between the unachievable aim of absolute safety and the kind of poor management of risks that damages lives and the economy. In a nutshell: risk management, not risk elimination. For more information about this, read our Principles of Sensible Risk Management. We consult widely on our proposals and we listen carefully to those who have views different from our own.
Precautionary principle
What is the precautionary principle?
The precautionary principle should be applied only in very particular circumstances. It is highly unlikely to be relevant to your work.
The precautionary principle says that where you have good reason to believe that something might cause harm but there isn’t enough scientific knowledge to carry out a full risk assessment, this should not be used as an excuse to do nothing to prevent harm. The precautionary principle is, therefore, applied to a few new hazards until enough is learned about the risks they present. It should not be applied to well-known hazards where the broad level of risk has been established.

