The Most Expensive Risk Assessments Are the Ones Nobody Values

Most organisations I work with have risk assessments.

Some have hundreds of them.

They’re sitting in folders, on shared drives, buried somewhere in a management system or, increasingly, saved on SharePoint.

They have titles, dates, risk ratings, control measures and the name of whoever completed them. On paper, everything can look reassuringly organised.

But if I was sitting in your boardroom, I wouldn’t be particularly interested in how many risk assessments you have.

I’d want to know something else.

Do the people actually doing the work know what those risk assessments say?

That question usually tells me far more about how risk is being managed in an organisation.

Because having a risk assessment and managing the risk are two very different things.

And one of the most expensive risk assessments you can have is the one somebody spent hours writing, somebody else approved, somebody uploaded to SharePoint…

…and everybody then forgot about.

When completing the document becomes the objective

Let’s strip risk assessment back to what it’s actually for.

It isn’t about producing a document.

It’s about understanding how somebody could get hurt and working out what you’re going to do to stop that happening.

The document is the record of that thinking.

Simple enough.

But somewhere along the way, that can get turned on its head.

Has the risk assessment been completed? Yes.

Has it been signed? Yes.

Is it saved in the right place? Yes.

Is it within its review date? Yes.

Great. Next item on the agenda.

Except I still don’t know whether the risk is being controlled.

And neither do you.

A beautifully written risk assessment sitting unread on SharePoint isn’t controlling anything.

It’s storing information.

That’s an important distinction for leaders because a dashboard showing 98% of risk assessments “in date” can look fantastic.

But 98% of what?

Documents?

Or risks actually being managed?

They aren’t necessarily the same thing.

The people doing the job need to be part of this

One of the most common weaknesses I come across isn’t an absence of risk assessments.

It’s a disconnect between the assessment and the people whose work it is supposed to influence.

The assessment might identify perfectly sensible controls.

The manager understands them.

The H&S Adviser has reviewed them.

Everyone is happy.

Then I speak to the person actually doing the job.

They’ve never seen it.

They weren’t involved in writing it, despite potentially knowing that activity better than anyone else in the organisation.

Nobody has talked them through the significant findings.

Nobody has explained why particular controls matter.

They’ve learned the job from somebody who learned it from somebody else.

Or, over time, they’ve simply found their own way of doing it.

Now we have a problem.

People cannot follow controls they don’t know exist.

And this is where I think we sometimes make communication far more complicated, or far more superficial, than it needs to be.

Uploading a risk assessment to SharePoint doesn’t mean you’ve communicated it. I promise you, your employees will not voluntarily read it.

Emailing somebody a 12-page document doesn’t necessarily mean you’ve communicated it either.

And a tick box saying “I confirm I have read and understood this document” might give you a record, but it doesn’t automatically give you understanding.

Sometimes what is needed is simply a proper conversation.

Other times it might be instruction, practical training, a demonstration, competency assessment or supervision.

It depends on the risk.

The important question is not: “Did we make the document available?”

It’s: “Do our people understand what they need to do to keep themselves and others safe?”

That’s the outcome we’re actually interested in.

Then the real world gets involved

Even if your risk assessment was excellent when somebody wrote it, there’s another problem.

Businesses change.

Equipment changes. Processes change. People change. Staffing levels change. Production pressures change.

New substances arrive.

Contractors turn up.

Someone buys a new piece of machinery.

Vehicles change.

Technology changes.

And people find quicker ways of doing things. Sometimes those ways are better. Sometimes they’re not.

Meanwhile, the risk assessment can sit happily in SharePoint completely oblivious to all of it.

This is why I’ve never been particularly impressed by a tracker telling me that every risk assessment has an annual review date.

That’s useful administration.

But if the activity changed significantly six months ago, telling me the assessment isn’t due for review for another six months rather misses the point.

You’re managing today’s work using yesterday’s assumptions.

This is also why I put so much value on getting away from the desk and actually looking at the work.

I’ve reviewed plenty of documentation over the years that looked absolutely fine when I read it in an office.

Then I’ve gone out, spoken to the people doing the job and watched the activity.

And suddenly the picture is very different.

Sometimes it’s a small difference.

Sometimes you wonder whether the risk assessment and the activity you’re watching are even describing the same job.

That gap between work as imagined and work as performed is where leaders need to pay attention.

Because that’s where false assurance starts.

So what exactly is the board being assured about?

Imagine you’re sitting in a board meeting, and the H&S report says: “Risk assessments are in place for all significant activities.”

Sounds good, doesn’t it?

But I’d be asking: “Okay. And how do we know they’re being followed?”

That’s where the conversation gets more interesting.

Because knowing the assessments exist doesn’t tell you whether they’re suitable and sufficient.

It doesn’t tell you whether they reflect what people are doing today.

It doesn’t tell you whether employees know what the controls are.

It doesn’t tell you whether managers reinforce them.

It doesn’t tell you whether people are competent to implement them.

And it certainly doesn’t tell you what happens at 4pm on a Friday when the manager isn’t standing there, and everyone wants to get finished and go home.

That’s the information leadership actually needs.

The board doesn’t need assurance that risk assessments exist.

It needs assurance that risks are being controlled.

Those are very different things.

The risk assessment is only one part of the system

This is why I never look at risk assessment as a standalone compliance activity.

It belongs inside a management system.

In simple terms, that system should do something like this:

Identify → Assess → Control → Communicate → Train → Implement → Observe → Review → Improve.

Miss one of those stages and you can undermine everything that came before it.

You can identify the right risk and choose excellent controls, but if nobody communicates them, you’ve achieved very little.

You can communicate them, but if somebody needs training to implement them and doesn’t receive it, you still have a problem.

You can train everyone perfectly, but if nobody ever checks what’s happening afterwards, shortcuts and workarounds can gradually become “the way we do things here”.

And if nobody feeds that information back upwards, the board can continue receiving green dashboards while something very different is happening on the ground.

That’s why the risk assessment isn’t the end product.

Controlled work is the end product.

And this isn’t unique to health and safety.

You can have an excellent HR procedure that managers don’t follow.

Occupational Health can make perfectly reasonable recommendations that never make their way into operational decisions.

Finance can put controls in place that people routinely work around.

Your insurer can expect certain risk controls that nobody has translated into day-to-day operations.

You can have beautifully written governance policies that bear very little resemblance to how decisions are actually made.

The same principle runs through all of them.

There is a big difference between having a system and having a system that works.

Nobody cares about the paperwork until something happens

This is often when the value, or weakness, of all this becomes painfully obvious.

Most documentation can sit in the background while everything is going well.

Then somebody gets seriously hurt.

There’s a fire.

A significant claim lands.

The regulator arrives.

And suddenly that risk assessment nobody has looked at for nine months becomes a very popular document.

Now we’re asking different questions.

What did you know about the risk?

What controls had you identified?

Were they actually implemented?

Were employees told about them?

How were they trained?

Did anybody check they were being followed?

Did managers know people were doing something differently?

Had the activity changed since the assessment was written?

What did you do about it?

And, one of my all-time favourites…

How can you prove that?

At this point, simply producing the risk assessment doesn’t necessarily solve the problem.

In fact, if the document says you should have been doing A, B and C and the investigation discovers nobody was doing A, B or C, you’ve potentially created another question entirely.

After an incident, the important question isn’t: “Did you have a risk assessment?”

It’s: “Can you demonstrate that this is how the work was actually managed?”

There can be an insurance dimension to this as well.

If your documentation describes controls that supposedly exist but an investigation finds something very different happening in practice, that discrepancy can become important when insurers start looking at a claim.

I’ve covered that issue in more detail in my blog, “Will Your Insurers Pay Out? How Poor Safety Documentation Can Put Corporate Insurance Cover at Risk”, which is available on the website: Will Your Insurers Pay Out? How Poor Safety Documentation Can Put Corporate Insurance Cover at Risk. – accuSafe

But the principle is the same whether we’re talking about an insurer, regulator, solicitor or client.

Your documentation is valuable when it is evidence of a functioning system.

It becomes far less valuable when it is being used instead of one.

So, as a leader, how do you know?

This brings us back to the question behind this whole series:

How do I know what’s really happening in my organisation when I’m not there?

You don’t do it by personally reading 300 risk assessments.

Please don’t. That’s not your job.

Your job is to make sure you have enough oversight to know whether the system underneath you is working.

So ask better questions.

Instead of: “How many risk assessments are overdue?”

Try: “How do our managers know the controls are actually being followed?”

Ask how employees are involved in developing assessments.

Ask employees themselves how they know what the controls are.

Ask when somebody last went out to observe the activity against the assessment.

Ask what happens when an employee says, “That control doesn’t actually work.”

Ask what triggers a review when something changes.

Ask how you know someone is competent where your controls rely on them performing a task correctly.

And every now and again, get out of the boardroom and have a look yourself.

Not because you’re trying to catch somebody out.

Because sometimes ten minutes talking to the person doing the job will tell you more about the effectiveness of your management system than ten pages of KPI data.

Dashboards matter. Audits matter. Reports matter.

But they are representations of your organisation.

They are not your organisation.

The further leadership gets from operational reality, the easier it becomes for paperwork to create an illusion of control.

And that’s really what good governance is trying to prevent.

Good governance closes the distance between what leaders believe is happening and what people are actually doing.

So don’t create more risk assessments for the sake of having more risk assessments.

Create better ones.

Involve the people who understand the work.

Communicate what matters.

Train people where necessary.

Check what’s actually happening.

And when reality changes, change the assessment with it.

Because the value of a risk assessment isn’t measured by how impressive the document looks. If only it were that simple.

It’s measured by whether it changes what somebody does when they go to work.

One Question for Leaders

If you picked one significant risk in your organisation today and spoke directly to the people exposed to it, would their description of how they control that risk match what your risk assessment says?

If you don’t know, there’s your starting point.

And next week, we’re going to take this one stage further.

Because communicating the risk assessment is only part of the answer.

You can identify the right controls. You can explain them to your people. You can send them on the right training course and come away with a folder full of certificates.

But what does that actually prove?

It proves they attended the training.

It doesn’t necessarily prove they understood it, can apply it or are doing anything differently as a result.

And if your management system relies on people being competent to control significant risks, that’s quite an important distinction.

Next week: When Training Becomes a Tick Box. Why certificates don’t demonstrate competence, attendance doesn’t prove understanding, and what leaders should be asking for instead.

Share it :

Leave a Reply

Your email address will not be published. Required fields are marked *

Latest Post

Need Help?

Lorem ipsum dolor sit amet consectetur adipiscing elit dolor