Skip to content
SHEQ Control Plane Docs
Search /

Hazard & Risk Register

HIRA-style hazard identification and risk assessment — every hazard scored by likelihood and severity, with the controls in place to reduce it.

Last updated 6 September 2026 · v1

Overview

The Hazard & Risk Register is a HIRA-style (Hazard Identification and Risk Assessment) log of every identified hazard for a given activity, scored numerically so hazards can be compared and prioritised rather than just listed.

Why it matters

A hazard that's identified but not scored tends to get treated with whatever attention it happened to get when someone first noticed it, not the attention its actual risk warrants. Scoring likelihood and severity separately, then deriving a risk score and band from both, gives a consistent basis for deciding what needs a control put in place now versus what can be monitored.

How it works

Each hazard record captures the activity it relates to, a description of the hazard itself, the controls currently in place, an owner, and a review date. Likelihood and severity are each entered on a numeric scale; the register derives a risk score (likelihood × severity) and a risk band — low (score below 8), medium (8–14), or high (15 and above) — automatically, so the band is always consistent with the two inputs rather than a separately-entered judgement call that can drift out of sync with them.

This screen

The list page shows every hazard with its computed risk score/band, and can be filtered and sorted by likelihood, severity, review date, or when the record was created/updated. The detail page shows the full assessment; create and edit forms share the same fields.

Fields

  • Activity — required. The task or situation the hazard relates to (e.g. "Roof access for gutter cleaning").
  • Hazard — required. What the hazard actually is (e.g. "Fall from height").
  • Likelihood — required, numeric. How likely the hazard is to result in harm, on the register's rating scale.
  • Severity — required, numeric. How severe the harm would be if it occurred.
  • Controls — required. The controls currently in place to reduce likelihood and/or severity.
  • Owner — required. Who is responsible for this hazard assessment staying current.
  • Review date — required. When this assessment is next due to be reconsidered.

Risk score and risk band are not entered — they're computed from Likelihood × Severity every time the record is viewed, so they can never be out of sync with the two fields that produce them.

What happens next

A hazard is not automatically linked to anything else when created, but a Permit to Work issued for the activity it covers should be linked to it directly using the permit's relational picker — this is what lets a permit show, at issue time, exactly which assessed risk and controls apply to the work it authorises. A high-risk-band hazard is not blocked from any action elsewhere in the product in the current version — the band is a prioritisation signal for the people managing the register, not an automated gate.

FAQ

What are the likelihood/severity scales? Both are plain numeric fields — the register doesn't enforce a fixed rating scale (e.g. 1–5) at the data level; align on one scale within your organisation and use it consistently, since the risk-band thresholds (8 and 15) are fixed and assume a shared scale across every hazard.

Can a hazard be linked to more than one Safe Work Procedure? Yes — linking happens from the Permit to Work side (a permit references one hazard and one procedure), so any number of permits, each covering a different procedure, can reference the same hazard.