South African workplace team completing a task-based risk assessment before work starts

A practical risk assessment should connect tasks, hazards, controls, registers and accountability.

Many companies can list the 5 steps of a risk assessment, but still struggle to control risk in the workplace.

That is because a risk assessment is not powerful because it exists on paper. It becomes powerful when it changes how work is planned, controlled, supervised, inspected and improved.

In South Africa, employers must provide and maintain a working environment that is safe and without risk to health as far as reasonably practicable. A risk assessment supports this duty by helping the employer identify hazards, understand risk, decide on controls, communicate those controls and monitor whether they are working.

The common 5-step risk assessment method is useful because it gives structure: identify hazards, decide who may be harmed, evaluate the risks, record and implement the findings, and review the assessment.

But here is the SafetyWallet platform perspective: a risk assessment should not end with a completed form. It should create a line of control from the task being performed to the control measures required, the registers that must be maintained, the inspections that must be completed, the evidence that must be captured and the people accountable for keeping the workplace safe.

Need help understanding whether your risk assessments are actually controlling workplace risk? Explore SafetyWallet's practical health and safety risk assessments support.

Short Answer: What Are the 5 Steps of a Risk Assessment?

The 5 steps of a risk assessment are:

  1. Identify the hazards.
  2. Decide who may be harmed and how.
  3. Evaluate the risks and decide on control measures.
  4. Record the findings and implement the controls.
  5. Review the assessment and update it when work, people, equipment or conditions change.

In a South African workplace, these steps should be connected to a practical health and safety management system. That means every hazard must lead to a control, every control must be registered, every register must be monitored, and every finding must create accountability and continuous improvement.

Why the 5 Steps Alone Are Not Enough

The 5 steps are a good starting point, but many workplaces fail after the assessment is completed.

The real problem is not always that the employer does not know the steps. The problem is often that the risk assessment is disconnected from daily work.

  • A warehouse identifies forklift hazards, but daily pre-use inspections are not completed.
  • A school identifies fire evacuation risks, but emergency drills are not recorded.
  • A workshop identifies machine guarding risks, but corrective actions remain overdue.
  • A construction contractor identifies working-at-height risks, but harness inspections are not monitored.
  • A retail site identifies manual handling risks, but staff are not trained on safe lifting practices.

This is why SafetyWallet approaches health and safety risk assessments as part of a practical control system, not as a once-off document exercise. The logic is simple:

RiskControlRegisterMonitoringAccountabilityContinuous Improvement

If a risk assessment does not create this chain, it may look complete but still fail to protect people.

Risk assessment process from task hazard risk control register monitoring accountability and continuous improvement

Risk assessment becomes useful when every risk leads to control, monitoring and improvement.

South African Context: Risk Assessment Is a Practical Duty, Not a Filing Exercise

In South Africa, risk assessment supports the employer's duty to provide and maintain a working environment that is safe and without risk, as far as reasonably practicable.

This does not mean every risk can be removed completely. It means employers must actively identify hazards, understand who may be harmed, put reasonable controls in place, communicate those controls, monitor whether they are working and improve them when necessary.

That is where health and safety compliance in South Africa becomes practical. A Department of Employment and Labour inspection, a client audit, an ISO 45001 audit or an internal management review will not only ask whether a risk assessment exists. The real question is whether the assessment is alive in the workplace.

Can the employer show:

  • What tasks were assessed?
  • What hazards were identified?
  • What control measures were selected?
  • Who is responsible for those controls?
  • Which registers support the controls?
  • Which inspections verify that the controls are still working?
  • What evidence proves follow-through?
  • What corrective actions were raised and closed?
  • What has changed since the assessment was last reviewed?

That is the difference between a risk assessment file and a risk-based health and safety management system.

Five steps of a risk assessment infographic identify hazards decide who may be harmed evaluate risks record findings and review assessment

The five steps must be applied to real tasks, not generic workplace categories.

Step 1: Identify the Hazards

Hazard identification is the foundation of the risk assessment. A hazard is anything with the potential to cause harm, damage, injury, illness or loss.

In a practical workplace, hazards should not be identified only by walking around with a checklist. They should be identified by understanding the task.

For example, "working in a warehouse" is too broad. A task-based approach asks:

  • What is the person actually doing?
  • What equipment are they using?
  • What materials are being handled?
  • What environment are they working in?
  • What can go wrong during this specific activity?
  • What routine and non-routine work is involved?

A task-based risk assessment might separate warehouse work into tasks such as loading vehicles, operating forklifts, stacking pallets, picking stock, charging batteries, handling damaged goods, cleaning spills and working near pedestrians.

Each task has different hazards. Forklift movement, unstable stacking, blocked emergency routes, manual handling, battery acid, poor housekeeping and pedestrian interaction all require different controls.

This is why generic risk assessments often fail. They identify broad hazards but do not connect them to actual work.

Step 2: Decide Who May Be Harmed and How

The second step is to identify who may be affected by the hazard.

This includes more than the employee performing the task. In South African workplaces, affected people may include permanent employees, temporary employees, contractors, visitors, delivery drivers, cleaners, security personnel, maintenance teams, clients, learners, students and members of the public.

The "how" is just as important as the "who".

For example, a wet floor does not only create a slipping risk for the cleaner. It may affect employees walking through the area, visitors entering reception, contractors carrying tools or customers moving through a retail space.

Good risk assessment does not assume everyone understands the workplace in the same way.

Step 3: Evaluate the Risk and Decide on Control Measures

Once hazards and affected persons have been identified, the risk must be evaluated. This usually means considering the likelihood of harm occurring, the severity of possible harm, the existing controls already in place, the additional controls required, the responsible person and the timeframe for action.

The most important part of this step is not the risk rating. It is the control measure.

A risk rating without a control measure does not make people safer.

For example, forklift risks should not be controlled only by telling people to be careful. Better controls may include a traffic plan, pedestrian walkways, trained operators, pre-use checklists, speed control and supervision. Grinder risks should not be controlled only by PPE. Better controls include correct disc selection, guarding, pre-use inspection, operator competence, a face shield and an exclusion zone.

The hierarchy of control should guide decision-making. Elimination and substitution are stronger than relying only on personal protective equipment. PPE may still be necessary, but it should not become the first and only control when better controls are reasonably practicable.

This is where the SafetyWallet Triple P approach becomes useful. Policies, Procedures and Practices create the standard, explain the implementation steps and define how the task must be performed safely.

Step 4: Record the Findings and Implement the Controls

Recording the risk assessment is not just an administrative step. It is where accountability starts.

A proper risk assessment record should show the task assessed, hazards identified, who may be harmed, risk rating, existing controls, additional controls, responsible persons, target dates, supporting registers, required training, required inspections, evidence needed and the review date.

This is where many organisations become weak. They record the risk assessment but do not implement the control measures properly.

A control measure should not disappear into a PDF. It should become part of the management system.

  • Fire extinguishers identified as a control should link to a fire equipment register and inspection schedule.
  • First aid as a control should link to first aid box inspections, trained first aiders and appointment records.
  • Machine guarding as a control should link to inspection checklists and corrective actions.
  • PPE as a control should link to issue records, training and condition checks.
  • Emergency evacuation as a control should link to drills, plans, appointees and training evidence.

This is why OHS Online is important. It helps move the risk assessment from a document into registers, inspections, reminders, corrective actions and evidence.

Software gives visibility, but visibility is not the same as control. A dashboard can show overdue inspections, but someone still needs to inspect. A register can show missing evidence, but someone still needs to upload and verify it. A risk assessment can identify hazards, but controls must still be implemented. A policy can exist, but people must still understand and follow it. A consultant can assist, but the client must still build internal ownership.

Digital risk register dashboard linking hazards controls inspections corrective actions and accountability

OHS Online helps connect risk assessments to registers, inspections, evidence and corrective actions.

Step 5: Review the Assessment and Update It When Necessary

A risk assessment must be reviewed because work changes.

The review should not only happen because a calendar reminder says "annual review". It should also happen when something meaningful changes, such as a new process, new equipment, new chemicals, a workplace incident, a near miss, a change in layout, a new contractor activity, new legislation or client requirements, repeated inspection findings, employee feedback or ineffective controls.

The review should ask one key question: Are the control measures still working in the real workplace?

This is where monitoring matters. If the risk assessment says the control is "daily forklift inspection", but the inspection register shows gaps, the risk assessment is not being lived. If the assessment says employees must follow a safe work procedure, but observations show shortcuts, the issue may be behaviour, training, supervision, workload or belief.

This is where SafetyWallet connects risk assessment with behaviour based safety. The visible unsafe act may be the fruit, but the root may sit deeper in knowledge, perception, values, identity or ownership.

The SafetyWallet Risk Assessment Method: From Risk to Ownership

SafetyWallet's view is that a strong risk assessment should follow this practical flow:

RiskControlRegisterMonitoringAccountabilityContinuous Improvement

Where behaviour and culture are involved, the deeper layer becomes:

RiskControlRegisterObservationTraitValueIdentityOwnership

This matters because many workplace risks repeat themselves even after training. If an employee repeatedly bypasses a procedure, the answer is not always "discipline them". The organisation first needs to ask whether the control was clear, whether the employee was trained, whether the right equipment was available, whether supervision was active, whether production pressure influenced the behaviour, and whether the person understands the reason behind the rule.

This is where MES, SafetyWallet's Mindset Evaluation Schema, supports the behaviour and culture layer. It helps organisations move beyond "unsafe act observed" toward understanding what may be influencing the behaviour.

What We See Repeatedly in South African Workplaces

  • Many companies have documents, but the documents do not drive daily action.
  • Health and Safety representatives are appointed, but they are not always confident about what to inspect, what to record or how to escalate issues.
  • Risk assessments are completed once, but they are not always connected to SOPs, registers, inspections or control measure verification.
  • Inspections are scheduled, but evidence and follow-through are weak.
  • Consultants can help, but over-reliance on consultants can prevent internal ownership.
  • Behaviour problems are visible, but the deeper belief, trait and value layer is not always coached.
  • Management wants compliance, but it needs visibility, accountability and a practical rhythm.

This is the gap the SafetyWallet platform is designed to close, connecting software, structure, support, education and behaviour.

Practical Example: Task-Based Risk Assessment for a Workshop

Take a simple workshop example: using an angle grinder.

A generic assessment may say: Hazard: grinder. Risk: injury. Control: wear PPE. That is not enough.

A task-based risk assessment should go deeper:

Element Detail
Task Cutting steel with an angle grinder
Hazard Rotating disc, sparks, noise, flying particles, electrical cable and hot metal
Risk Eye injury, burns, hearing damage, disc failure, electric shock and fire
Persons affected Operator, assistant, nearby employees and visitors
Existing controls Trained operator, grinder guard, correct disc, PPE and fire extinguisher nearby
Additional controls Pre-use inspection, spark direction control, hot work control where required, exclusion zone and cable inspection
Register link Portable electrical equipment register, PPE issue register and fire equipment register
Inspection link Tool inspection checklist and housekeeping inspection
Training link Grinder safety, PPE use and fire response
Monitoring Supervisor observation and JSO / control measure verification
Accountability Operator, supervisor and Health and Safety representative
Review trigger Incident, damaged disc, new grinder, repeated unsafe use or changed work area

This is what separates paperwork from control.

Software Only vs Consultant Only vs The SafetyWallet Model

Approach What it solves What it often misses Best use Long-term result
Software only Visibility, dashboards, reminders and storage Behaviour, ownership and implementation discipline Businesses with strong internal capacity Good data, weak action if people do not follow through
Consultant only Expert assessment, audits and implementation input Internal ownership if the client becomes dependent Specialist support or capacity gaps Dependency risk if knowledge does not transfer
Safety file / document approach Documents, risk assessments and basic evidence Live registers, monitoring, verification and behaviour Immediate compliance requirement A document that may not drive daily work
SafetyWallet model Software, structure, support, risk, controls, behaviour and accountability Requires client participation and management ownership Businesses wanting sustainable control A living system with registers, monitoring, evidence and improvement

How SafetyWallet Supports Risk Assessment in Practice

SafetyWallet helps organisations move from a risk assessment document to a working control system.

  • Through task-based risk assessments, the organisation identifies the work being performed, the hazards linked to that work, the risks created and the control measures required.
  • Through OHS Online, those controls can be connected to registers, inspections, corrective actions and evidence.
  • Through Policies, Procedures and Practices, the organisation can align structure to actual risks rather than generic documents.
  • Through a practical health and safety management system, management can create rhythm: plan, do, check, act, review and improve.
  • Through MES and behaviour based safety, the organisation can address repeated unsafe behaviour more intelligently.
  • Through expert health and safety support, clients can access practical help where capacity or implementation support is needed.
  • Through ISO 45001 support in South Africa, companies can align risk assessment, controls, evidence and improvement with recognised occupational Health and Safety management principles.

SafetyWallet does not remove the employer's responsibility. It helps the employer see, structure, manage and improve that responsibility.

Build task-based risk assessments that link hazards, controls, registers, inspections and accountability in one system.

Visit the Health and Safety Risk Assessment page →

What Makes a Risk Assessment Good?

A good risk assessment is not the longest document. It is the one that helps people control real risk.

A strong risk assessment should be:

  • Task-based and practical
  • Site-specific and understandable
  • Linked to control measures, registers and inspections
  • Reviewed when things change
  • Supported by evidence
  • Owned by management and employees
  • Useful during daily work, not only during audits

The best test is simple: Can a supervisor, Health and Safety representative or employee use the risk assessment to understand what must be controlled today?

If the answer is yes, the assessment is useful. If the answer is no, it may only be a compliance document.

Common Mistakes in Workplace Risk Assessments

Mistake 1: The assessment is too generic

A generic assessment may mention "slips, trips and falls" but not explain where, why, who is exposed and what control applies.

Mistake 2: Controls are vague

Controls such as "be careful", "use PPE" or "follow procedure" are not strong enough on their own. Controls should be specific and verifiable.

Mistake 3: The assessment is not linked to registers

If first aid, fire equipment, PPE, training, machinery, ladders or chemicals are controls, they must be managed through registers.

Mistake 4: No one owns the action

A control without an accountable person often becomes an intention, not an action.

Mistake 5: Reviews are only annual

Risk changes when work changes. Waiting a full year can leave new risks unmanaged.

Mistake 6: Behaviour is ignored

If people repeatedly do not follow the control, the organisation must understand why. That may involve training, supervision, workload, belief, culture or accountability.

The Better Way: Build a Risk Assessment That Controls the Task

A better risk assessment should answer these questions:

  1. What task is being performed?
  2. What can harm people, equipment or the environment?
  3. Who can be harmed and how?
  4. What is already in place?
  5. What additional controls are required?
  6. Which registers must support the control?
  7. Which inspections must verify the control?
  8. Who owns the action?
  9. What evidence must be available?
  10. When must the assessment be reviewed?

This creates a direct bridge from risk assessment to operational control.

South African workers leaving the workplace safely after completing their shift

The purpose of risk assessment is not paperwork. It is making sure people return home healthy and safe.

Conclusion: The 5 Steps Are the Start, Not the System

The 5 steps of a risk assessment are important. They help employers identify hazards, assess risk, select controls, record findings and review the assessment.

But the real value sits in what happens next.

A completed risk assessment does not automatically make a workplace safe. Control measures must be implemented. Registers must be maintained. Inspections must be completed. Evidence must be uploaded. Corrective actions must be closed. Employees must understand the controls. Supervisors must monitor the work. Management must review the results.

That is how risk assessment becomes control.

The SafetyWallet platform purpose is clear: we believe in making sure your loved ones return home healthy and safe after work.

The stronger your risk assessment process, the stronger your ability to protect people, prove control and build ownership.

Ready to turn your risk assessments into practical workplace control? Talk to the SafetyWallet team about building task-based risk assessments that link hazards, controls, registers, inspections and accountability in one system.