Acceptable risk

Acceptable risk is the level of risk that an organization, after implementing the required preventive measures, considers tolerable based on its legal obligations, its health and safety policy, and current technical and social criteria, such that it does not require immediate additional measures beyond maintaining existing controls and periodic monitoring. It is a decision-making concept, not an absence of risk: in occupational risk prevention, the legal objective is to avoid risks and to assess and reduce those that cannot be avoided (Article 15 of Law 31/1995). Therefore, acceptability never exempts organizations from applying the hierarchy of controls nor justifies exceeding the limit values ​​or minimum requirements of the regulations. The ISO 45001 standard links it to the assessment criteria that the organization defines to determine which risks require measures.

In short

This is the level of risk that the organization considers tolerable after applying the required measures, according to legal, technical, and policy criteria, such that it only requires maintaining controls and monitoring. It is not the absence of risk, nor does it exempt the organization from the hierarchy of controls in Article 15 of Law 31/1995; no risk that violates regulations is acceptable. It is compared to the residual risk to determine measures and priorities.

Content
  1. What is acceptable risk?
  2. Criteria and methods
  3. Application in management
  4. Organizational application: how to define and apply acceptability
  5. Limits and common mistakes
  6. Practical example
  7. Regulatory and reference framework
  8. Related concepts
  9. References

A–Z dictionary →

What is acceptable risk?

No activity has zero risk. Risk assessment estimates a probability and severity for each hazard, and the organization must decide, using explicit criteria, which combinations require action, how urgently, and which can be kept under control and monitored. This boundary is the acceptable or tolerable risk. The INSST risk assessment document uses a probability and consequences matrix that classifies risk as trivial, tolerable, moderate, significant, and intolerable, and associates an action with each level: from requiring no specific action to prohibiting the work to reducing the risk.

Acceptability has three sources of criteria. The legal source establishes non-negotiable minimums: exposure limit values, safety requirements for equipment and locations, prohibitions, and distances; no risk that violates regulations is acceptable. The technical source provides methods, standards, and best practices for estimating and comparing risks, such as the principle of reducing them to the lowest reasonably achievable level. And the organizational and social source reflects company policy, consultation with representatives, and the perceptions of exposed individuals, which may demand stricter levels than those required by law.

The concept is similar to that of residual risk (the risk that remains after implementing measures), but it is not the same: residual risk is an estimated fact; acceptable risk is a criterion that is decided upon and against which the residual risk is compared. A residual risk may or may not be acceptable according to that criterion.

Criteria and methods

  • Legal compliance. Prerequisite: limit values ​​(noise, vibrations, chemical agents), minimum provisions of places and equipment, specific regulations; exceeding these makes the risk unacceptable regardless of other criteria.
  • Risk matrices. Combination of probability and severity with associated levels and actions, such as the INSST matrix or those of management standards; they require documented and consistent criteria.
  • Reasonable reduction. Principle of reducing risk to the extent reasonably practicable, weighing the safety benefit against the effort, without admitting that the cost justifies maintaining significant risks.
  • Quantitative methods. In process installations, protection layer analysis, fault trees and individual and social risk criteria that define numerical thresholds, used in major accidents.
  • Participation. Consult the worker safety representatives on the criteria and on the assessment of specific risks, in accordance with article 33 of Law 31/1995.
  • Review. The criteria are reviewed based on the evolution of knowledge, regulations, and the organization’s experience (incidents, audits).

Application in management

  • Prioritization. Comparing the assessed risk with the acceptability criterion determines the urgency and order of the measures in preventive planning.
  • Maintaining controls. An acceptable risk is acceptable as long as the measures that make it acceptable are operational: maintenance, training, supervision, and health monitoring.
  • Change management. Any change in equipment, processes, organization, or people requires a reassessment of whether the risk remains acceptable.
  • Communication. Exposed individuals must be aware of the residual risk, the measures that control it, and their role in maintaining them.
  • Record keeping. The criteria used and acceptance decisions are documented in the risk assessment to ensure traceability.

Organizational application: how to define and apply acceptability

  1. Document the acceptability criteria in the prevention plan: legal compliance as a prerequisite, matrix or assessment method, and actions associated with each level.
  2. Consult the criteria with the worker safety representatives and have them approved by management.
  3. Apply the criteria consistently in the risk assessment, recording for each risk its level, the existing measures and the decision.
  4. Plan measures for unacceptable risks in order of priority, with responsible parties and deadlines, and maintenance measures for acceptable risks.
  5. Periodically verify that the controls that support acceptability remain operational (inspections, maintenance, current training).
  6. Re-evaluate in the event of changes, incidents, or new technical or regulatory information.
  7. Review the criteria in the annual system review and in the audits.

Preventive management software allows you to parameterize the assessment matrix, apply the same criteria in all evaluations, automatically prioritize planning, and alert when a control associated with an acceptable risk is no longer valid.

Limits and common mistakes

  1. To consider acceptable a risk that does not meet legal limit values ​​or minimum requirements.
  2. Accepting risks for cost without having applied the hierarchy of controls or justified the decision.
  3. Using matrices without documented criteria or applying them differently depending on the evaluator.
  4. Forgetting that acceptability depends on controls being maintained, and not verifying their validity.
  5. Do not reassess after changes or incidents that alter the probability or severity.
  6. Deciding on acceptability without consulting representatives or informing exposed persons.

The decision on acceptability rests with the organization with the technical advice of the prevention service; this sheet is for informational purposes.

Practical example

Situation: A facility maintenance company assesses the risk of electrical contact in work on low voltage panels.

  • Initial assessment. Medium probability and extremely harmful consequences: significant risk, unacceptable; work is sometimes carried out on live equipment without proper procedures or PPE.
  • Measures. De-energised working procedure with the five golden rules, authorization of qualified workers in accordance with Royal Decree 614/2001, insulating PPE and verification of absence of voltage.
  • Residual risk. Low probability and extremely harmful consequences: moderate risk according to the matrix, acceptable with conditions: maintenance of training, supervision of permits and periodic check of measuring equipment and PPE.
  • Monitoring. Preventive observations in electrical work, annual review of authorizations and reassessment in case of changes in facilities or personnel.

Regulatory and reference framework

ISO 31000 defines risk criteria as the terms of reference against which the significance of risk is assessed; in the field of functional safety, the IEC 61508 and IEC 61511 series set tolerable risk criteria for safety systems.

Related concepts

References

  1. Official State Gazette. Law 31/1995, of November 8, on Occupational Risk Prevention. 1995, current consolidated text. Official source
  2. Official State Gazette. Royal Decree 39/1997, of January 17, Regulation of Prevention Services. 1997, current consolidated text. Official source
  3. National Institute for Occupational Safety and Health. Basic guidelines for occupational risk assessment. 2021. Official source
  4. International Organization for Standardization. ISO 45001:2018, Occupational health and safety management systems. Requirements with guidance for use. 2018. Official source
  5. Official State Gazette. Royal Decree 840/2015, of September 21, approving measures for the control of risks inherent in major accidents involving hazardous substances. 2015, current consolidated text. Official source

Editorial information

Publication date: August 30, 2026 .

Editorial Manager: Sabentis Editorial Team .

Editorial review by Pablo Rodríguez LinkedIn

Executive Vice President of the ORP International Foundation and Chief Financial Officer of Sabentis.

Request a Demo

Discover all that Sabentis can do for your organization.

Try Sabentis

request a demo
stars 5
GetApp Software Advice Capterra