Quick Answer:
A workplace risk assessment runs in five steps: identify the hazards with the people who do the work, assess likelihood and severity, control the risk using the hierarchy of controls (eliminate first, protective equipment last), record your reasoning and actions, and review on a schedule and after changes. The template below covers what a defensible record contains.
In this article
- What Is a Workplace Risk Assessment
- The 5 Steps For Workplace Risk Assessment
- The Risk Matrix, Without The Mystique
- The Hierarchy Of Controls
- What Goes In The Template
- Psychosocial And Physical: One Process
- Who Should Do The Assessment
- From Assessment To Living Register
- Common Mistakes
- How Sentrient Helps In Workplace Risk Assessment
- Frequently Asked Questions
A workplace risk assessment is the most requested document when it comes to workplace safety and the most misunderstood.
Done properly, it is thirty minutes of structured honesty that prevents injuries and wins disputes.
Done just as paperwork, it is a form that says “low” in every box, signed by someone who never visited the work area.
With 188 Australian workers killed by traumatic work injuries in 2024, the gap between those two versions is the whole point.
This guide covers the method, the matrix, the hierarchy of controls, and a template built for a version that holds up.
Sentrient is an Australian-built GRC platform for compliance, risk and HR. See our risk management system, workplace compliance system and workplace compliance courses, all built for Australian and New Zealand workplaces.
What Is a Workplace Risk Assessment
A workplace risk assessment is a structured answer to three questions: what could cause harm, how bad and how likely is that harm, and what are we doing about it.
Under Australian WHS law the duty behind it is managing risks so far as is reasonably practicable, and the assessment is where that judgement gets made and recorded.
For plenty of specific situations, from high-risk construction work to hazardous chemicals, a documented assessment is expressly required.
The purpose shapes the quality. An assessment written to satisfy a form asks “what rating keeps this off the agenda?”.
An assessment written to manage risk asks “what would I want changed if my own family did this job?”.
Safe Work Australia recorded 146,700 serious workers’ compensation claims in 2023-24, showing what happens when paperwork-based assessments meet real workplace risks.
The 5 Steps For Workplace Risk Assessment
1. Identify the Hazards
Walk the actual work, not the procedure manual. Consult the people who do it, because they know where the shortcuts live.
Then read the data you already hold: incident and near-miss reports, maintenance logs, complaints, and absence patterns.
Hazard identification includes the psychosocial kind: workload, conduct, and isolation belong on the same list as the ladder or the forklift.
2. Assess the Risk
For each hazard, judge how likely harm is and how severe it could be, with current controls honestly accounted for.
Note who is exposed, including contractors and visitors, and whether exposure concentrates on particular roles or shifts.
Resist the pull toward “medium”: if everything is medium, nothing gets fixed first.
3. Control the Risk, in Order
Work down the hierarchy of controls, and be able to say why you stopped where you did.
Choosing training and signage over an available engineering fix is a decision you may need to defend later, so record the reasoning, not just the choice.
4. Record It
The record is the difference between having managed a risk and being able to prove it. The template section below lists the fields.
The discipline that matters: every additional control gets one owner and one date, and vague controls (“increase awareness”) should get rewritten until someone checks whether they happened.
5. Review It
On a scheduled basis, and immediately after an incident, a near miss, a change to plant, process, or people, or when there is new information about the hazard.
Reviews close the loop: did the controls happen, and did they work?
The Risk Matrix, Without The Mystique
A risk matrix combines likelihood and consequence into a rating so that priorities are consistent across assessors and time. A simple three-by-three is enough for most workplaces.
| Likelihood \ Consequence | Minor harm | Serious injury | Fatality or permanent harm |
|---|---|---|---|
| Rare | Low | Low | Medium |
| Possible | Low | Medium | High |
| Likely | Medium | High | Extreme |
Two rules keep the risk matrix honest. First, rate risks with existing controls in place, not as if no controls exist.
Second, do not lower a rating to avoid action: the rating should guide effort, not excuse inaction.
If your matrix never produces an “extreme” risk, it may reflect optimism more than the reality of your workplace.
The Hierarchy Of Controls
The hierarchy of controls is a legal expectation, not a style preference: eliminate the hazard, substitute for something safer, isolate people from it, engineer the risk down, apply administrative controls such as procedures and training, and use personal protective equipment last.
The order exists because the top controls work when people are tired, new, or distracted, and the bottom ones depend on everyone remembering everything, every shift.
The practical test when choosing controls: does this control still work on the worst plausible day? A guard does. A reminder poster does not.
What Goes In The Template
Whatever tool you use, a defensible workplace risk assessment template carries these fields.
| Field | What to write |
|---|---|
| Hazard and location | What could cause harm, and where it occurs |
| Who is exposed | Workers, contractors, visitors, and how many |
| Existing controls | What already reduces the risk, honestly stated |
| Current risk rating | Likelihood and consequence with existing controls in place |
| Additional controls | What will change, chosen down the hierarchy of controls |
| Owner and due date | One name and one date per action, not a committee |
| Residual rating | The expected rating once actions are complete |
| Consultation record | Who was consulted from the affected work group, and when |
| Assessor and date | Who ran the assessment, with competence noted where relevant |
| Review date | When it will be looked at again, and the triggers that bring it forward |
If you take one thing from the template: single owners and real dates. Risk assessments die in the gap between “we identified it” and “someone was responsible for it”.
Psychosocial And Physical: One Process
The same five steps cover psychosocial hazards: workload, role clarity, conduct, isolation, and the rest.
What changes is the evidence you read (absence data, complaints, consultation) and the controls you reach for (work design and management practice rather than guarding).
Our plain-English guide to psychosocial hazards covers the hazard list and the law. Running one process for both kinds of risk keeps the register whole and the duty visible.
Who Should Do The Assessment
The person running a workplace risk assessment needs three things: understanding of the work, access to the people who do it, and enough competence to judge the risk honestly.
Specialised hazards need specialists. Most workplace risks need a capable manager or safety lead running a structured process, with consultation that is genuine rather than ceremonial, because consultation is a WHS duty in its own right.
For those building risk assessment into their role, the skills that matter most are unglamorous: asking workers open questions, writing controls that can be verified, and following actions to completion.
Frameworks and courses help, and the risk assessments that fail rarely fail on methodology. They fail on follow-through.
From Assessment To Living Register
An assessment that ends in a folder is a snapshot. The working version feeds a risk register: every assessed risk with its rating, owner, actions, and review date in one place, connected to the incident reports that test whether controls are working.
That register is also what officers review for their due diligence, and what an auditor asks for first. Our guide to governance, risk and compliance covers how the register fits the wider picture.
Common Mistakes
- Assessing the procedure instead of the work as actually performed.
- Copying last year’s assessment forward, including the typo.
- Every risk rated medium, so nothing is ever first.
- Controls chosen from the bottom of the hierarchy because the top is inconvenient, with no recorded reasoning.
- Actions without owners, or owners without dates.
- No psychosocial hazards anywhere in the register.
How Sentrient Helps In Workplace Risk Assessment
Sentrient keeps workplace risk assessments alive after the meeting ends: a risk register with owners and review dates, actions tracked to completion, incident and hazard reports linked to the risks they test, and records retrievable in minutes for audits and reporting, with training courses to build assessor capability.
Most customers are operational within about a week, and more than 1,000 Australian organisations use Sentrient. Explore the risk management system.
See a risk register that chases its own actions.
Thirty Honest Minutes
A workplace risk assessment does not need to be long, and it must not be fictional. Walk the work, listen to the people doing it, rate honestly, control in order, write it down with owners and dates, and come back when things change.
The organisations that get hurt least are rarely the ones with the thickest risk paperwork. They are the ones whose assessments describe the workplace their workers actually recognise.
Disclaimer: This article is general information for Australian workplaces, not legal advice. Obligations differ by state, territory, industry, and company structure. Get advice on your specific circumstances from a qualified professional.
Frequently Asked Questions
1. What is a workplace risk assessment?
A structured look at what could cause harm in your work, how likely and how severe that harm could be, and what you will do about it. The output is not a form. It is a set of controls with owners and dates, and a record that shows your reasoning.
2. What are the 5 steps of a risk assessment?
Identify the hazards, assess the risks (likelihood, severity, and who is exposed), control them using the hierarchy of controls, record what you found and decided, and review on a scheduled basis and after changes or incidents.
3. Is a risk assessment a legal requirement in Australia?
WHS law requires you to manage risks so far as is reasonably practicable, and for many specific situations (high-risk work, hazardous chemicals, and others) a documented assessment is expressly required. Even where no document is mandated, the assessment is how you demonstrate the duty was met, which makes it effectively unavoidable for any hazard that matters.
4. What is a risk matrix?
A grid that combines likelihood and consequence to give each risk a rating, usually low, medium, high, or extreme. Its job is consistency and priority, so that two assessors reach similar conclusions and the worst risks get attention first. It supports judgement. It does not replace it.
5. What is the hierarchy of controls?
The legally expected order for controlling risk: eliminate the hazard first, then substitute something safer, isolate people from it, engineer the risk down, use administrative controls such as procedures and training, and rely on personal protective equipment last. The order exists because the top controls do not depend on people remembering things.
6. Who can carry out a workplace risk assessment?
Someone who understands the work, involves the people who do it, and has enough competence to judge the risk honestly. For specialised hazards (electrical, structural, complex plant) that means qualified specialists. For most workplace risks it means a capable manager or safety lead running a structured process with genuine worker consultation, which is itself a legal duty.
7. How often should risk assessments be reviewed?
On a scheduled basis, commonly annual for significant risks, and immediately after an incident or near miss, a change to equipment, process, or people, or new information about the hazard. A risk assessment with a lapsed review date reads as abandonment, not diligence.
8. What should a risk assessment template include?
The hazard and where it occurs, who is exposed, existing controls, the risk rating with them in place, additional controls required, an owner and due date for each, the residual rating, the assessor and consultation record, and the review date.
9. What is the difference between a risk assessment and a risk register?
The assessment is the exercise: examining one hazard or activity in depth. The register is the living index of all assessed risks, their ratings, owners, and review dates. Assessments feed the register. The register tells you when assessments are due again.
10. How does Sentrient help with risk assessments?
Sentrient holds a risk register with owners and review dates, links assessments to incidents and hazards reported by staff, tracks the actions that assessments generate, and keeps the records retrievable for audits, with training courses to build assessor capability. Most customers are operational within about a week.
Sources
- Safe Work Australia, Model WHS laws
- Safe Work Australia, Key Work Health and Safety Statistics Australia
- Safe Work Australia, Maximum monetary penalties under the WHS laws
- WorkSafe Victoria, Occupational Health and Safety (Psychological Health) Regulations
- WorkSafe Victoria, New regulations make psychological health a priority
