Most risk assessments dont fail because people dont care. They fail because theyre:
– too complicated
– too generic
– done once and forgotten

A risk assessment should be a working tool something that helps you prevent problems, prove control to clients/auditors, and make better decisions.

Heres a practical method that works for busy SMEs.

What a risk assessment is (in plain English)
Its a simple way to answer:
– What could go wrong?
– How bad would it be?
– How likely is it?
– What are we doing to control it?
– What else do we need to do?

The 5-step method (copy/paste)
Step 1: Define the scope
Be specific. Write one sentence:
– Risk assessment for: [process/site/activity]
– Applies to: [team/locations]
– Reviewed: [date]

Step 2: Identify real risks (not generic fluff)
Use three prompts:
– People: competence, fatigue, supervision, contractors
– Process: steps that fail, handovers, approvals, changes
– Proof: evidence, records, traceability, version control

Keep it real. If its never happened and cant happen, dont include it.

Step 3: Score it simply
Dont overthink it. Use a simple 15 scale for:
– Likelihood (1 rare 5 frequent)
– Impact (1 minor 5 severe)

Then calculate:
Likelihood d7 Impact = Risk score

Example:
Likelihood 4 d7 Impact 3 = 12 (needs action)

Step 4: List your current controls
This is where you show youre in control. Controls might include:
– training/competence checks
– supervision
– maintenance/calibration
– document control
– inspections
– supplier approval

Step 5: Add actions that actually reduce risk
If the score is high, add an action that changes the reality not just a note. Every action needs:
– owner
– due date
– evidence required

Examples of good actions:
– Introduce pre-start checklist and store completed records in [folder]
– Train team on procedure v3 and record sign-offs
– Add monthly inspection log and review in management review

The bit most businesses miss: keep it live
A risk assessment isnt a one-off. Update it when:
– you win a new contract
– you add a new site
– you change suppliers/subcontractors
– you introduce new equipment
– you have an incident/complaint

Quick rule: If the business changes, the risk register changes.

Common mistakes that get flagged in audits
– generic risks copied from the internet
– no owners/dates on actions
– actions listed but not completed
– no review dates
– risk assessment exists but doesnt match reality

A simple risk register structure
Use columns like:
– Activity/process
– Hazard/risk
– Who it affects
– Likelihood
– Impact
– Score
– Current controls
– Further actions
– Owner
– Due date
– Status
– Review date

How CAW helps
We build practical, audit-ready systems including risk registers that are simple, live, and actually used.

CTA
If you want the risk assessment template we use with clients, message us and well send it over.

Leave a comment

I’m Craig

Meet Craig Willetts

Welcome to the ISO and Compliance Blog, I have spent over 20 years in compliance specialising in accreditation and business growth, I own a number of compliance related businesses including CAW Consultancy, Global ISO Services, CAW Digital, Screen my staff and fusion consultancy worldwide and this blog is designed to help SME’s on their journey to top notch compliance, any questions feel free to drop me an email at Craig@CAWConsultancy.co.uk

Let’s connect