Most risk assessments dont fail because people dont care. They fail because theyre:
– too complicated
– too generic
– done once and forgotten
A risk assessment should be a working tool something that helps you prevent problems, prove control to clients/auditors, and make better decisions.
Heres a practical method that works for busy SMEs.
What a risk assessment is (in plain English)
Its a simple way to answer:
– What could go wrong?
– How bad would it be?
– How likely is it?
– What are we doing to control it?
– What else do we need to do?
The 5-step method (copy/paste)
Step 1: Define the scope
Be specific. Write one sentence:
– Risk assessment for: [process/site/activity]
– Applies to: [team/locations]
– Reviewed: [date]
Step 2: Identify real risks (not generic fluff)
Use three prompts:
– People: competence, fatigue, supervision, contractors
– Process: steps that fail, handovers, approvals, changes
– Proof: evidence, records, traceability, version control
Keep it real. If its never happened and cant happen, dont include it.
Step 3: Score it simply
Dont overthink it. Use a simple 15 scale for:
– Likelihood (1 rare 5 frequent)
– Impact (1 minor 5 severe)
Then calculate:
Likelihood d7 Impact = Risk score
Example:
Likelihood 4 d7 Impact 3 = 12 (needs action)
Step 4: List your current controls
This is where you show youre in control. Controls might include:
– training/competence checks
– supervision
– maintenance/calibration
– document control
– inspections
– supplier approval
Step 5: Add actions that actually reduce risk
If the score is high, add an action that changes the reality not just a note. Every action needs:
– owner
– due date
– evidence required
Examples of good actions:
– Introduce pre-start checklist and store completed records in [folder]
– Train team on procedure v3 and record sign-offs
– Add monthly inspection log and review in management review
The bit most businesses miss: keep it live
A risk assessment isnt a one-off. Update it when:
– you win a new contract
– you add a new site
– you change suppliers/subcontractors
– you introduce new equipment
– you have an incident/complaint
Quick rule: If the business changes, the risk register changes.
Common mistakes that get flagged in audits
– generic risks copied from the internet
– no owners/dates on actions
– actions listed but not completed
– no review dates
– risk assessment exists but doesnt match reality
A simple risk register structure
Use columns like:
– Activity/process
– Hazard/risk
– Who it affects
– Likelihood
– Impact
– Score
– Current controls
– Further actions
– Owner
– Due date
– Status
– Review date
How CAW helps
We build practical, audit-ready systems including risk registers that are simple, live, and actually used.
CTA
If you want the risk assessment template we use with clients, message us and well send it over.

Leave a comment