Element 06 · EI PSM

Hazard identification and risk assessment

A fundamental requirement of any HS&E and PSMS is the identification and assessment of risk.

"Management must ensure that a comprehensive risk assessment process systematically identifies, assesses and appropriately manages the risks arising from the organisation's operations."

Hazard identification and risk assessment is one method applied to many kinds of risk. Enterprise, financial, credit, cyber, financial-crime and personal-security risks follow the same logic: identify, assess, control, review. They belong in the same risk framework so the board sees one risk picture rather than several that are never compared.

Brings in
Enterprise and financial reporting riskCounterparty credit riskCyber and information security riskFinancial crime riskPersonal and travel security
Placed here by this reading (3)
  • 6.1A structured process is applied to identify the hazards and ensure that the risks arising from the organisation's assets and operations are systematically assessed.
  • 6.2Risk control measures are identified and implemented, using the hierarchy of control, to manage the identified risks to a tolerable level.
  • 6.3The tolerable level of risk is defined for all risks (to human health & safety, environmental impact, asset and financial loss), and is consistently understood and applied throughout the organisation.
  • 6.4Risk assessments are conducted for: ongoing operations; hazardous materials; new projects; products and services; and all changes.
  • 6.5Risk assessments consider risk to: health and safety of workers, contractors and members of the public; occupied buildings; environment (the impacts of hazardous releases and from mitigatory actions); reputation; asset integrity; business interruption; physical and cyber security; and third-party assets.
  • 6.6Risk assessments consider human and organisational factors, particularly as contributory factors in major accident scenarios.
  • 6.7Risk assessments consider the threats of natural hazards, including extreme weather events and the effects of climate change.
  • 6.8Risk assessments are carried out by competent personnel with appropriate independence.
  • 6.9Risk assessments take into account learnings from incidents from both inside and outside the organisation.
  • 6.10Completed risk assessments are reviewed, approved and accepted by specific levels of management appropriate to the magnitude of the risk, and any decisions are clearly documented.
  • 6.11All stakeholders are kept informed about the risk assessment process and results.
  • 6.12The status of risk control measures is reviewed at regular intervals by specified levels of management to ensure risk assessment recommendations are resolved in a timely manner.
  • 6.13The implementation of mitigation recommendations for the top HS&E and process safety risks is reviewed regularly by specified levels of management.
  • 6.14Risk assessments are updated as changes occur and reviewed and updated at a defined appropriate frequency.
  • 6.15Arrangements for hazard identification and risk assessment are understood and followed; understanding of arrangements, and compliance with them, are regularly tested.
  • 6.16Compliance and performance trends are reviewed by specified levels of management.