Risk assessment

Risk assessment is the process of estimating the magnitude of unavoidable risks and obtaining the information necessary to decide on preventive measures and their priority. It is a means to act and review working conditions, not a static document or an end in itself.

In short

Risk assessment identifies what can cause harm, determines who may be exposed, and evaluates the risk to decide on controls. Risk assessment should reflect actual work, document its criteria, and be reviewed when conditions change, harm occurs, or measures prove insufficient.

Content
  1. What is risk assessment?
  2. Differences between identifying hazards, assessing and planning
  3. When should it be performed and reviewed?
  4. How to do it step by step
  5. Methods, competence and participation
  6. Practical example
  7. Documentation and traceability
  8. Regulatory framework
  9. Related concepts
  10. On the blog
  11. References

A–Z dictionary →

What is risk assessment?

Article 3 of the Regulations for Prevention Services defines it as the process of estimating the magnitude of risks that could not be avoided. The information obtained allows for a decision to be made regarding whether measures are needed and, if so, which ones. The INSST emphasizes that the assessment is a means to make decisions and improve working conditions , not merely a document for its own purposes.

Your unit of analysis can be a job, task, process, location, piece of equipment, or situation, depending on how the exposure occurs. You must consider routine and non-routine work, maintenance, foreseeable emergencies, and variations. Include all potentially exposed individuals and pay attention to those who are especially sensitive due to their personal characteristics or known biological condition.

Differences between identifying hazards, assessing and planning

Identifying hazards means recognizing sources, situations, or actions capable of causing harm. Assessing risks links these hazards to exposure, probability, consequences, and existing controls to estimate the magnitude and make decisions. Planning preventive activities translates the results into measures, priorities, responsibilities, resources, and timelines. These are connected but not interchangeable stages.

A list of hazards without assessment makes prioritization impossible; a matrix without metrics is ineffective; and planning disconnected from assessment can address secondary problems. Nor should assessment be confused with measurement. Measurements are necessary when the nature of the risk demands it, but they always require strategy, methodology, and interpretation. In other cases, observation, interviews, documentation, and appropriate qualitative or semi-quantitative methods are used.

When should it be performed and reviewed?

The company conducts an initial risk assessment, taking into account the company’s activities, job positions, and personnel. This assessment is updated when equipment, substances, technology, locations, organizational structure, or conditions change; when a new employee is hired whose known characteristics make them particularly vulnerable; and when regulations or evidence indicate new risks. It is also reviewed when injuries occur, when health checks reveal potential hazards, or when existing measures may be inadequate.

The review does not always require redoing the entire document; it should address the affected part and verify its relationship with the rest of the system. A review schedule can be agreed upon between the company and employee representatives, taking into account the anticipated deterioration of the process elements. In any case, a scheduled date never justifies waiting when a change or sign of damage occurs.

How to do it step by step

A rigorous sequence is:

  1. Define scope, tasks, people and conditions, gathering reliable information.
  2. Identify hazards and existing controls through observation and participation.
  3. Determine who may be harmed, how, and for how long.
  4. Select the appropriate method; take measurements when necessary.
  5. Estimate the risk by combining the available information and its uncertainties.
  6. Compare with legal requirements, values ​​or technical criteria and decide on acceptability.
  7. Propose measures according to the preventive hierarchy and prioritize them.
  8. Document results, those responsible, and the rationale for the decision.
  9. Verify effectiveness and set review conditions.

If there is any doubt, the Regulation requires that the most favorable preventive measures be adopted from a prevention point of view.

Methods, competence and participation

The method must inspire confidence in the result and be appropriate for the risk. General methods can be used for an initial assessment, and specific methods for noise, chemicals, ergonomics, psychosocial factors, or other agents. Where specific regulations exist, their procedures are followed; in their absence or as a supplement, standards, INSST guidelines, competent bodies, or recognized professional methods are used.

The assessment is conducted by personnel with the appropriate preventative skills for its complexity. The company consults with employees about the procedure and gathers their knowledge of deviations, peak periods, maintenance, and non-prescribed work. This participation does not replace technical expertise, but it prevents the analysis from merely describing the theoretical process. Assumptions, limitations, and missing data must be declared so that the decision can be reviewed.

Practical example

A new loading area with forklifts and pedestrian access is being implemented in a warehouse. The assessment examines routes, intersections, visibility, speeds, lighting, peak activity, battery charging, and non-routine tasks. It includes external carriers and cleaning duties, not just regular operators. Previous incidents and staff experience reveal a blind intersection that the plan did not show as a problem.

Distributing vests as the sole response is not the priority. Traffic flows are redesigned to separate people and vehicles, intersections are eliminated, barriers and access controls are installed, and speed limits are imposed. Signage, regulations, training, and high visibility complement these measures. Observations, speeds, and incidents are then reviewed, and the assessment is revised if the distribution or volume of traffic changes.

Documentation and traceability

The documentation identifies the position or situation, existing risks, people affected, outcome, appropriate measures, and criteria and methods used. When measurements have been taken, it retains the information necessary to interpret their validity. It should allow for understanding why a decision was made and subsequently verifying whether it was implemented and effective. A number in a matrix without context does not provide that traceability.

Digital tools can facilitate versioning, assignment, and tracking, but they do not guarantee quality. A copied, generic, or closed assessment without feedback is not improved simply by being on a platform. Changes must be linked to closing measures and evidence. Personal and health data are handled with appropriate safeguards; the preventative document uses only the necessary information without disclosing individual diagnoses.

Regulatory framework

Law 31/1995 mandates an initial assessment and, based on its results, the planning of preventive measures. Royal Decree 39/1997 details the definition, content, procedure, review, and documentation in Articles 3 to 7. Specific regulations detail assessments for certain agents, equipment, or activities.

Framework Directive 89/391/EEC establishes the general approach to prevention and assessment in the European Union. EU-OSHA maintains OiRA, a platform for creating sector-specific tools that guide micro and small businesses through the process and planning. OiRA can facilitate the work, but the obligation and suitability to the context rest with each organization. Assessment retains its value when it leads to concrete actions and continuous improvement.

Related concepts

  • Hazard .Expand on this aspect within the management of occupational safety and health.
  • Occupational risk .Expand on this aspect within the management of occupational safety and health.
  • Preventive and control measures .Expand on this aspect within the management of occupational safety and health.
  • Occupational risk prevention management .Expand on this aspect within the management of occupational safety and health.
  • IPER .Expand on this aspect within the management of occupational safety and health.
  • Traceability in OSH .Expand on this aspect within the management of occupational safety and health.

On the blog

References

  1. Official State Gazette. Law 31/1995, of November 8, on Occupational Risk Prevention. 1995. Official Source
  2. Official State Gazette. Royal Decree 39/1997, of January 17, Regulation of Prevention Services. 1997. Official Source
  3. National Institute for Occupational Safety and Health. Basic guidelines for occupational risk assessment. 2021. Official source
  4. European Union. Directive 89/391/EEC on the safety and health of workers. 1989. Official source
  5. European Agency for Safety and Health at Work. OiRA: free and simple workplace risk assessment tools. 2026. Official source

Editorial information

Publication date: August 29, 2026 .

Editorial Manager: Sabentis Editorial Team .

Editorial review by Pablo Rodríguez LinkedIn

Executive Vice President of the ORP International Foundation and Chief Financial Officer of Sabentis.

Request a Demo

Discover all that Sabentis can do for your organization.

Try Sabentis

request a demo
stars 5
GetApp Software Advice Capterra