2.8 Risk and Risk Assessment
2.8.1 Understand how risk is assessed using a five-by-five matrix
Risk, Likelihood, and Severity
Risk is assessed by considering both the likelihood that an event will occur
and the severity of the consequences if it does occur.
These are combined using a five-by-five risk assessment matrix.
Likelihood Levels
- Improbable – very unlikely to occur
- Remote – unlikely but possible
- Occasional – may occur from time to time
- Probable – likely to occur
- Frequent – expected to occur regularly
Severity Levels
- Negligible – minimal impact or inconvenience
- Marginal – minor injury or damage
- Moderate – noticeable injury or service disruption
- Critical – serious injury or major disruption
- Catastrophic – severe injury, loss of life or total system failure
2.8.2 Be able to interpret and create a risk assessment matrix
Risk Assessment Matrix
A risk assessment matrix combines likelihood and severity scores
to calculate an overall risk level. This helps prioritise risks
and decide which require immediate action or further control measures.
2.8.3 Understand the purpose of risk assessment documentation
Purpose of Risk Assessment Documentation
Risk assessment documentation is used to:
- Ensure continuity of service
- Protect the health and safety of people
- Ensure compliance with legal and regulatory requirements
2.8.4 Understand the contents of risk assessment documentation
Risk Assessment Documentation Elements
A risk assessment document should include:
- A description of the risk
- Who or what might be harmed or damaged
- How the harm or damage might occur
- Mitigation measures already in place
- Details of additional mitigation required
- Who is responsible for implementing mitigation
- The due date for completion
2.8.5 Be able to interpret and create risk assessment documentation
Interpreting and Creating Risk Assessments
Interpreting a risk assessment involves reviewing identified risks,
understanding the mitigation measures, and checking responsibilities
and deadlines. Creating risk assessment documentation requires clearly
identifying risks and recording appropriate control measures.