What a modern risk assessment really needs to do
A risk assessment is a structured process for identifying potential hazards, evaluating their likelihood and consequence, and determining appropriate responses. Risk analysis sits within that process as the step where you quantify or qualitatively evaluate each risk. Both feed into the broader discipline of risk management, which involves identifying hazards, analysing risks, and implementing controls to protect people, assets, and operations.
At Resilient Services, we work with Australian organisations in energy, water, ports, transport, mining, and government sectors where risk assessments are mandatory under WHS laws, ISO standards, and the Security of Critical Infrastructure (SOCI) Act. In these environments, risk assessments are a proactive tool to identify threats and implement controls before harm occurs.
There are important distinctions between assessment types. Workplace health and safety risk assessments focus on injury and illness to workers. A public health risk assessment evaluates community-level exposure to contaminants. Enterprise risk assessments capture strategic, cyber, and operational risks that threaten service delivery.
Consider a water utility assessing hazardous chemicals in its treatment plants: chlorine gas leaks, storage failures, worker exposure. Or a port operator analysing the potential impact of berth closures from storms, cyberattacks, or supply chain disruption. Both scenarios demand more than a checkbox exercise.
This article sets out the key steps, practical examples, and tools, including our AI incident response assistant BRUCE, that move risk assessments from compliance burden to genuine resilience.
A step-by-step risk assessment process for Australian workplaces
In regulated Australian environments, a formal risk assessment must be repeatable, documented, and aligned with recognised standards. The core steps in a risk assessment include identifying, analysing, evaluating, and treating risks across four steps that form a continuous cycle.
The assessment process begins when you identify hazards across your operations. Physical safety hazards include plant, machinery, and working at heights. Hazardous chemicals present exposure risks in treatment, storage, and handling. Psychosocial risks, now mandated across all jurisdictions, encompass workload, bullying, and remote-work stress. Critical infrastructure dependencies such as power supply, IT systems, and SCADA networks add another layer of multiple hazards that many organisations underestimate.
Next, you assess each risk by evaluating likelihood and consequence. A standard 5Ă—5 risk matrix rates likelihood from “rare” to “almost certain” and consequence from “insignificant” to “catastrophic.” Risk assessments identify hazards and assess risk levels for both acute events like a chemical spill or injury and chronic impacts such as noise exposure or fatigue.

You then implement control measures using the hierarchy of controls: eliminate the hazard, substitute it, isolate it, apply engineering controls, introduce administrative controls, and deploy personal protective equipment as a last resort. Controls must be embedded into procedures, training, and maintenance schedules rather than existing only on paper.
Finally, you review. A risk assessment should be reviewed when conditions change: after incidents or near misses, when new plant or processes arrive, following regulatory changes, or after emergency exercises. Regularly monitoring and reviewing risks is essential for successful risk management. We align this process with ISO 31000 for risk management and ISO 22301 for business continuity when designing client frameworks.
Legal and standards context: why risk assessment is non-negotiable
Risk assessments are necessary for ensuring legal and regulatory compliance across every Australian jurisdiction. Under the Model WHS Act and Regulations, a person conducting a business or undertaking (PCBU) must identify foreseeable hazards, assess WHS risks, and implement control measures so far as is reasonably practicable. Regulations 34–36 specifically mandate hazard identification, risk management, and the hierarchy of controls.
Sector-specific obligations add further requirements. Under the SOCI Act, responsible entities for critical infrastructure assets must maintain a written Critical Infrastructure Risk Management Program (CIRMP) covering hazard vectors including physical, cyber, supply chain, and personnel threats. The Enhanced CIRMP requirements commenced 10 June 2026, raising the bar further. Internationally, even legislation like the Safe Drinking Water Act of 1974 requires risk assessments for water quality, illustrating how deeply embedded these obligations are worldwide.
Risk assessments must comply with local regulations and standards, and ISO standards guide risk assessments in business continuity planning. ISO 22301 structures business continuity management, ISO 45001 governs occupational health and safety systems, and ISO 31000 provides the overarching risk management process. Together, they shape how regulated organisations document, own, and review their risk assessments.
In practice, regulators expect evidence. When a power utility faces an external audit, inspectors look for documented risk registers, defined control ownership, and review schedules. Resilient Services helps clients map existing processes to these standards and rectify gaps before regulators find them.
Types of risk assessments: WHS, health, and enterprise risk
Not all risk assessments serve the same purpose, and understanding the distinctions prevents critical gaps.
Workplace health and safety risk assessments focus on direct harm to workers and contractors. They cover manual tasks, confined spaces, noise exposure, heat stress, and handling of chemicals. These assessments address both acute injury and chronic illness, including psychosocial hazards. With mental health claims now accounting for 12% of serious workers’ compensation claims and a median absence of 35.7 weeks, psychosocial risk can no longer be treated as secondary.
A human health risk assessment operates in a different domain. Health risk assessments evaluate community impacts from land use changes, industrial emissions, or contamination. Environmental risk assessment assesses chemical effects on ecosystems, while biodiversity risk assessments evaluate extinction risks for species, both of which may be required alongside health assessments for major projects.
Enterprise risk assessments capture strategic, financial, cyber, and operational risks on a corporate risk register. They allow leadership to manage risk across the entire organisation, linking departmental findings to board-level decision-making.
Systems risk assessment evaluates complex mechanical and biological systems, which is particularly relevant in sectors like water and energy where interdependencies between physical plant, digital control systems, and supply chains create compounding risk. At Resilient Services, we specialise in critical infrastructure dependency analyses, emergency management risks from bushfire, flood, and cyclone, and crisis management risks including reputation and regulatory sanctions. The key is ensuring these assessment types connect: health and safety findings feed into business continuity and crisis plans rather than sitting in silos.
How to identify hazards and “identified risks” in complex operations
Hazard identification is often the weakest step in the risk management process. In large utilities, ports, and government agencies with diverse activities, identification tends to be reactive, triggered only after an incident rather than systematically uncovering what could go wrong. Proactive problem solving shifts organisations from reactive to proactive risk management.
At Resilient Services, we use several practical methods. Site walkthroughs and task-level observations, for example, watching how maintenance crews access high-voltage switchgear or how mobile plant operates near pedestrian zones, reveal hazards that documents alone miss. We conduct structured document reviews of incident logs, near-miss records, maintenance histories, and audit findings. Facilitated workshops with frontline staff and supervisors draw out tacit knowledge and real-world conditions that formal procedures may not capture.
Specific hazard categories for Australian clients include hazardous chemicals in water treatment plants (chlorine, fluoride, algicides), mobile plant interactions at ports and mine sites, lone and remote work across dispersed assets, cybersecurity vulnerabilities in operational technology and SCADA systems, and climate-related hazards such as heatwaves, bushfire smoke, and coastal inundation.
Risk assessments help identify hazards that could harm employees or operations, and potential harm to people. Reviewing incident and ned regulator notifications uncovers less obvious new hazards that routine inspections may overlook. The importance of participation and consultation with workers, contractors, and health and safety representatives cannot be overstated, as safety representatives capture how tasks are actually performed, including informal shortcuts.
We convert this information directly into structured identified risks in the organisation’s risk register, using agreed descriptors: hazard name, cause, potential consequences, who is exposed, existing controls, risk owner, and review date. Avoiding common risk assessment mistakes at this stage saves significant effort downstream.
Risk analysis and evaluation: likelihood, consequence and tolerability
Once hazards are documented, the next challenge is turning qualitative observations into consistent risk ratings that support decision-making. Risk assessments support better decision-making by evaluating potential risks before action, but only if the evaluation methodology is robust.
A standard risk assessment tool is the 5Ă—5 matrix, rating likelihood from “rare” to “almost certain” and consequence from “insignificant” to “catastrophic.” Each intersection produces a risk level. For the outcome to be meaningful, definitions must be calibrated to the organisation’s context. “Major consequence” might mean a hospitalisation in a WHS assessment or lost production exceeding 10% in an operational assessment. Organisations prioritise risks based on severity to address the most critical threats first.
For public health risk assessments and environmental exposure scenarios, quantitative methods are often required. Quantitative risk assessment uses annualised loss expectancy calculations to translate probabilities and financial impacts into comparable figures. Exposure assessment models estimate concentration, duration, and frequency of contact with contaminants, then map these against dose-response data to characterise risk.

Consider a concrete example: assessing the risk of a chlorine gas release at a water treatment plant. Likelihood depends on handling frequency, storage condition, and control system reliability. The consequence includes worker exposure, community health risks, regulatory penalties, and reputational damage. By applying the matrix and quantitative exposure limits for chlorine breathing zones, analysts can determine which controls bring the risk to a tolerable level.
Evaluating tolerability draws on criteria such as “as low as reasonably practicable” (ALARP), the organisation’s risk appetite, and statutory limits for noise, chemical exposure, or other standards. We help clients standardise scoring scales across WHS, operational, and continuity risks so that managers and leadership can compare and prioritise effectively across the entire risk landscape.
Designing and prioritising control measures that actually work
A risk assessment must lead to tangible control measures, not just a completed form. Without action, even the most thorough evaluation delivers zero risk reduction. Effective risk assessments protect workers from injury and ensure business continuity only when controls are actually implemented.
The hierarchy of controls prioritises elimination of hazards first. In high-risk industries, higher-order controls are non-negotiable. Elimination removes the hazard entirely. Substitution replaces it with something less dangerous, for example substituting chlorine gas with sodium hypochlorite in water treatment. Engineering controls physically reduce exposure: automating valve operations removes workers from hazardous zones, while interlocks on conveyor systems prevent operation when guards are removed. Each of these measures delivers more reliable protection than relying on human behaviour alone.
Administrative controls such as standard operating procedures, permits to work for confined space or live electrical activities, and structured training programmes provide important layers of defence. However, they should support engineering controls, not replace them. Control measures include avoiding, mitigating, transferring, or accepting risks, and the selection must be documented with clear rationale.
Personal protective equipment, whether respiratory protection during asbestos removal or hearing protection in turbine halls, must be the last line of defence. PPE depends entirely on correct use, fit, and maintenance, making it the weakest link when used in isolation to reduce exposure.
At Resilient Services, we support clients to develop costed action plans with assigned control owners, deadlines, and integration into maintenance, inspection, and competency frameworks. We help build risk management plans where every control is tracked, reviewed, and updated based on its effectiveness.
“Reasonably practicable” and cost-benefit in Australian WHS law
Under Australian WHS legislation, duty holders must implement control measures “so far as is reasonably practicable.” This legal concept requires weighing several factors before you decide on a course of action.
The factors include:
The likelihood of the risk occurring
The degree of potential harm or severity of the consequence
What the person conducting the business knows, or ought reasonably to know, about the hazard
The availability and suitability of ways to eliminate or minimise risks
The cost of those measures relative to the risk reduction achieved
Cost can only be a deciding factor where it is grossly disproportionate to the reduction in risk. You cannot defer critical life-safety upgrades solely on budget grounds if the hazard is severe and the controls are available. Regulators and courts expect documentation showing why certain control measures were or were not implemented, particularly in high-consequence environments.
For example, consider a regional council operating an ageing chlorine dosing system. Retrofitting the existing pumps may partially reduce risks at modest cost. Full system replacement may eliminate the hazard but at significantly greater expense. If the residual risk after retrofitting remains high and the consequence is potentially catastrophic, the “reasonably practicable” test likely favours replacement, and the decision must be recorded with supporting data and evaluation.
Resilient Services helps leadership teams evidence these decisions during regulator investigations, board-level reviews, or crisis management situations by preparing structured documentation of alternatives considered, cost estimates, risk reduction achieved, and residual risk accepted.
Risk assessment tools, templates and digital risk registers
Consistent tools significantly improve the quality and repeatability of risk assessments across large organisations. Without standardisation, identical hazards at different sites can receive wildly different ratings, undermining both credibility and compliance.
Common risk assessment tools include task-based templates for activities like confined space entry, working at heights, and hazardous chemical handling. Hazard-specific forms prompt users to document the hazard, existing controls, residual risk, control owner, and review date. Dynamic risk assessment checklists for field crews enable rapid pre-task hazard checks during changing conditions. Dynamic risk assessment is continuous during rapidly changing emergencies and adapts to rapidly changing emergencies, making it essential for operational teams responding to unplanned emergencies or security incidents.
Centralised digital risk registers aggregate identified risks, control measures, residual ratings, and review schedules across departments and assets. They provide audit trails showing when risk entries were created, updated, or reviewed, which is critical evidence for regulators.
AI-enabled tools like BRUCE, our incident response assistant, support real-time risk assessment during emergencies. BRUCE can integrate situational inputs, surface relevant existing risk entries, suggest control options, and assist with communication protocols during an unfolding incident.
When selecting software, organisations should assess alignment with ISO 31000 and ISO 22301, integration with incident management and maintenance systems, audit trail capability, and user-friendliness for both field staff and executives. A utility or port operator with multiple sites, for example, can standardise templates so that WHS and SOCI Act risk assessments use identical rating scales, enabling aggregated dashboards that give leadership a genuine whole-of-organisation risk picture.
Integrating risk assessments with business continuity and emergency management
Isolated risk assessments are less valuable than those embedded in business continuity, emergency, and crisis management planning. A risk assessment that identifies a vulnerability but sits disconnected from response plans creates a false sense of security.
High-rated risks from departmental assessments should feed directly into enterprise-level risk registers and business impact analyses. These analyses determine which functions and assets are critical, what downtime is tolerable, and which dependencies could cascade into broader failures. Risk assessment findings shape recovery strategies: alternate suppliers, backup power sources, manual workarounds for digital system outages.
Scenario-based risk assessments drive emergency response planning. For example, assessing the risk of a major substation failure during a prolonged heatwave combines likelihood data (increased load, overheating components) with consequence analysis (prolonged outage, health impacts on vulnerable populations, reputational damage). That assessment then informs evacuation procedures, load-shedding protocols, alternate supply strategies, and communication plans.

We routinely use risk assessment outputs to design and run emergency exercises. A simulated chemical spill at a water treatment plant, for instance, tests whether the emergency response plan, business continuity arrangements, community notification protocols, and crew rotation procedures all function under pressure. The exercise itself becomes a review mechanism, generating lessons that update identified risks and improve control measures.
This integration is what transforms compliance into genuine organisational resilience. When effective strategies for risk treatment, continuity, crisis communication, and after-action review are connected, the organisation absorbs disruption faster, recovers more reliably, and maintains stakeholder trust.
Health risk assessment and public health considerations for major projects
A formal health risk assessment is required in Australia when industrial developments, waste facilities, or major transport corridors may affect community health. Health risk assessments evaluate community health impacts from developments and assess impacts on existing communities, making them essential for planning approvals and licence conditions.
The framework includes hazard assessment and risk characterisation as core components. In accessible terms, the process involves identifying contaminants of concern (particulates, NOx, PFAS, bioaerosols), conducting an exposure assessment to determine who is exposed, at what levels, and for how long, and then characterising the risk by comparing modelled exposure against health-based thresholds. Health risk assessments are based on group impacts, not individuals, focusing on population-level outcomes such as increased respiratory illness rates over decades.
They assess potential health risks from environmental hazards across affected communities. Consider a port expansion where diesel exhaust and ship emissions could affect a nearby suburb. Modelling the dispersion of particulate matter, estimating the increase in respiratory hospital admissions over years, and assessing noise impacts provides the data that planning authorities and communities need.
Health risk assessments inform decision-making by shaping buffer zones, emissions limits, operating hours, and community consultation requirements. Health risk assessments also evaluate community impacts from land use changes such as rezoning industrial or residential boundaries.
Resilient Services translates technical findings into practical risk management actions. We help project sponsors interpret exposure data, estimate risk reduction from various mitigation options, engage communities, and ensure that project-level public health risks are visible on the enterprise risk register alongside other benefits of a fully integrated approach.
Making risk assessment a living process: training, culture and continual improvement
Risk assessments that sit in drawers or buried on shared drives protect nobody. To reduce risks in practice, assessments must be refreshed, actively used, and owned by people who understand them.
Training and competency development are foundational. Supervisors, health and safety representatives, and control room operators need the skills to conduct and update assessments confidently, not just fill in forms. Training should cover hazard identification techniques, the hierarchy of controls, use of the organisation’s risk assessment tool, and how to provide feedback on whether controls are working in the field. Competency must be evaluated through audits and practical review, not assumed.
Dynamic risk assessment plays a critical role in rapidly changing situations. During bushfire responses, flood events, or unplanned outages, conditions shift faster than any static document can capture. Dynamic assessments complement the formal risk assessment by enabling field crews to reassess hazards in real time and adjust controls immediately, a capability that directly supports emergency management outcomes.
Learning loops close the cycle. Incident investigations, near-miss reports, emergency exercises, and external audits should all trigger updates to the risk register and improvements to control measures. Every incident is data. Every near miss is a preview of what could escalate.
One of our clients, a large utility that previously assessed risk only during capital projects, shifted to an integrated cyclical programme: annual full risk register reviews at every site, quarterly hazard walkthroughs, incident-triggered control reviews, and monthly leadership dashboards. The result was the identification of previously undetected risks including remote-work exposure and supplier failure, improved response times, and reduced incident frequency.
The difference between a compliant organisation and a resilient one is whether its risk assessments drive action or gather dust. If you are ready to benchmark your current approach and identify priority improvements, we invite you to book a free 30-minute business resilience assessment with Resilient Services. We will review where your risk assessment process stands, where gaps exist, and what practical steps will build lasting resilience for your organisation.