ISO 45001 Risk Assessment Template – What It Should Actually Include

When people search for an ISO 45001 risk assessment template, they are usually looking for something more structured than a basic health and safety risk assessment.

They may already have risk assessments for individual activities, machinery or workplaces, but they want to know whether those records are enough for an ISO 45001 occupational health and safety management system.

The answer depends less on the appearance of the document and more on what the assessment actually does.

ISO 45001 places hazard identification and the assessment of occupational health and safety risks at the centre of the management system. The aim is not simply to produce a folder of completed risk assessments. It is to understand where workers could be harmed, decide how those risks should be controlled and make sure those controls remain effective.

A good ISO 45001 risk assessment template should therefore help you move logically from identifying a hazard to deciding what needs to be done about it.

What should an ISO 45001 risk assessment template include?

At its simplest, the template should allow you to identify the activity or area being assessed, describe the hazard, identify who could be affected and consider the potential consequences.

It should then provide a consistent method for assessing the level of risk.

Many organisations use a likelihood and severity scoring system. For example, likelihood may be rated from one to five and severity from one to five, producing an overall risk score. The exact scoring method is less important than making sure it is understood and applied consistently.

Example roles and responsibilities template image showing senior management, QMS manager, line managers and employees with assigned management system duties.

It should then provide a consistent method for assessing the level of risk.

Many organisations use a likelihood and severity scoring system. For example, likelihood may be rated from one to five and severity from one to five, producing an overall risk score. The exact scoring method is less important than making sure it is understood and applied consistently.

The assessment should also identify the controls already in place.

This is important because you are not normally assessing a workplace as though no controls exist. Guards, training, supervision, inspection, maintenance, safe systems of work, personal protective equipment and other measures may already reduce the risk.

The next question is whether those controls are enough.

Where further action is needed, the assessment should record what needs to happen, who is responsible and when the action should be completed.

A useful template will normally finish with the residual risk after additional controls have been introduced and a review date so the assessment does not simply disappear into a file.

Hazard identification comes before risk scoring

One of the most common mistakes is concentrating heavily on the numbers while giving too little attention to the hazards themselves.

For a workshop, obvious hazards might include machinery, manual handling, noise, vehicles, electricity or hazardous substances.

For an office-based business, the risks may look very different. They could include display screen work, slips and trips, lone working, stress, workstation problems, fire, driving or visits to customer premises.

For field-based employees, hazards might include unfamiliar locations, travelling, working around members of the public, weather conditions, contractors or working alone.

ISO 45001 is intended to be applicable across different types of organisation, so hazard identification needs to reflect how the business actually operates rather than relying on a generic list.

Do not forget routine and non-routine activities

Another weakness is assessing only normal day-to-day work.

A useful risk assessment process should also consider situations that happen less frequently.

Maintenance, cleaning, equipment breakdowns, deliveries, emergency situations, temporary work, unusual customer requirements and changes to normal staffing arrangements can all create different risks.

A machine may be relatively safe during ordinary operation but present very different hazards while being cleaned or maintained.

A site may be well controlled during normal working hours but operate differently when contractors arrive or employees work outside normal hours.

Thinking about non-routine activities makes the assessment much more realistic.

Who could actually be affected?

Risk assessments should not become so focused on the task that the people exposed to the risk are forgotten.

Workers carrying out the activity are an obvious group, but they may not be the only people affected.

Other employees, contractors, visitors, customers, delivery drivers and members of the public may also need to be considered.

There may also be individuals or groups who require particular attention because of the circumstances of the work.

The important point is not to create a generic list that appears on every assessment. It is to think about who could genuinely be affected by the hazard being assessed.

ISO 45001 also places considerable emphasis on consultation and participation of workers within the OH&S management system. In practice, the people carrying out the work can often identify hazards and weaknesses in controls that are not obvious from a desk-based assessment.

Existing controls versus further controls

A good ISO 45001 risk assessment template should make a clear distinction between controls already operating and additional action that is required.

For example, a warehouse may identify the movement of forklift trucks as a hazard.

Existing controls might include trained drivers, marked pedestrian routes, speed limits and vehicle inspections.

The assessment may still identify improvements, such as installing additional barriers at a crossing point or changing the layout around a loading area.

Recording both gives a much clearer picture.

It shows what the organisation already relies upon to control the risk and what further improvement has been identified.

It also makes future review easier because you can check whether the additional controls were actually implemented.

Think about the hierarchy of controls

When further action is needed, the first response should not automatically be to provide more training or personal protective equipment.

A stronger approach is to consider whether the hazard can be eliminated completely.

If that is not possible, consider whether the activity, equipment or substance can be replaced with something safer, whether engineering or physical controls can reduce exposure, and whether changes to working arrangements are needed.

Administrative measures such as procedures, training and supervision can then support those controls, with personal protective equipment used where appropriate.

This encourages organisations to deal with the hazard itself rather than relying entirely on people remembering to behave safely.

One of the clearest signs of a weak system is a large collection of risk assessments containing actions that nobody tracks. If an assessment identifies the need for a new guard, revised procedure, improved signage, additional inspection or training, this should have an owner and a target date.

If you want a complete, working system rather than disconnected templates

This is where organisations often discover that the risk assessment is only one part of the wider picture.

Hazards connect to operational controls, competence, consultation, emergency arrangements, incident reporting, objectives, legal requirements, internal audits and management review.

That is why building ISO 45001 from disconnected health and safety documents can quickly become difficult to manage.

The Compliance Companion provides a structured ISO 45001 management system that brings the templates, procedures and supporting records together so they can be adapted around the way your organisation actually works.

Instead of treating the risk assessment as an isolated form, it becomes part of a wider system for identifying hazards, controlling risks and monitoring whether those controls continue to work.