Element 05 · IOGP 510

Risk Assessment and Control

To define how risk is identified, assessed, controlled, accepted and changed — the structured discipline by which the organisation knows what could go wrong, what it has done about it, who has authority to accept what remains, and how change to any of that is governed.

"Most operators have plenty of risk assessments and very little risk control. This element demands evidence that an identified risk has a named control, an accountable owner, and a way to know if the control has degraded. If MoC is treated as paperwork to clear, the organisation has no real control over its own risk profile — which is also its own change profile."
  • ·Risk assessment methodologies (HAZID, HAZOP, HIRA, Bowtie analysis)
  • ·Risk registers (People Risk Register, Reservoir Risk Register, Supply Chain Risk Register)
  • ·Risk acceptance and authority frameworks
  • ·ALARP demonstration and barrier health (Bowtie/Barrier Engineering Input, Barrier Management Process)
  • ·Management of Change (MoC) — the process itself: design MoC, organisational MoC, technical deviation, temporary equipment
  • ·Specific scenario assessments (SIMOPS, Stress Risk Assessment, Sanctions Exposure Review)
  • →The standards against which risk is judgedE2 Policies
  • →The procedures by which a risk control is executed in the fieldE7 Procedures
  • →The verification that a risk control is workingE10 Assurance
  • →Findings that feed into MoC from monitoring and auditE9 Monitoring
IOGP 510 source content

An OMS aims to generate benefit for a company and its stakeholders while controlling its risks. It is often not possible to eliminate a risk entirely, so it is appropriate for companies to ascertain the level of residual risk acceptable to its business and stakeholders, while continuously improving controls wherever practical.

  • 1.Processes manage risks to an acceptable level: identify hazards, assess risks, implement controls/barriers.
  • 2.Document and communicate risk management for significant risks; risk acceptance approval at appropriate levels.
  • 3.Temporary/permanent changes are subject to a formal, risk-based MoC process with timeframes and actions tracked to completion.
  • 4.Maintain a culture of risk awareness — vulnerabilities, non-conformances, weak signals are recognised.