Risk Assessment Is an Art Disguised as a Spreadsheet

Every operation I walk into has a risk assessment. Usually several. There is a job hazard analysis binder, a five-by-five matrix on a poster in the conference room, a spreadsheet somebody built for the ISO audit, and a machine risk assessment the integrator delivered with the last capital project. Most of them agree with each other. Almost none of them predicted the last serious injury.

That is not a coincidence, and it is not a failure of effort. It is a failure of understanding what a risk assessment is. Most organizations treat it as a science, meaning a calculation that produces a number, and they invest in making the calculation more sophisticated. The truth is that risk assessment is an art that borrows the clothing of science. The matrix is real, the math is real, the standards are real, and none of it is worth anything without the judgment of the person doing it. If you want assessments that actually change what happens on the floor, you need to understand where the science ends and the art begins, and you need to invest in the art.

The science, and what it is good for

Let me give the scientific side its due, because it matters.

ISO 12100 and ANSI B11.0 define a disciplined process: identify the tasks, identify the hazards associated with each task, estimate the risk from severity and probability, evaluate whether the risk is tolerable, reduce it through the hierarchy of controls, and verify the result. ISO 31000 provides the enterprise framework. The severity-probability matrix converts qualitative judgment into a ranking. Layer-of-protection analysis and quantitative risk assessment, used in the process safety world, take it further by assigning numerical failure rates to safeguards and calculating the residual risk against a target.

These tools do three things well. They force completeness: a task-based approach makes you consider the jam clearing and the changeover, not just normal operation. They create a shared language so that a plant manager, a maintenance lead, and an operator are arguing about the same thing. And they produce a defensible record that shows the organization considered the hazard and made a decision. That record is what an OSHA compliance officer, a carrier, or a plaintiff’s expert will ask for, and its absence is its own kind of finding.

What the tools do not do is generate the inputs. Every cell in that matrix is a judgment. Severity: what is the worst credible outcome? Probability: how often is a person exposed, and how likely is the harm when they are? The matrix cannot answer those. A person answers them, and the quality of the assessment is entirely the quality of that person’s judgment.

Where the art begins

Here is what I have learned about the judgment layer, from doing this work in operations ranging from a 30-person shop to global manufacturing.

Severity is systematically underestimated by people who have not seen the injury. An engineer who has never attended an amputation investigation rates a pinch point as “moderate.” An operator who watched a coworker lose three fingers rates it correctly. The single most valuable input to a risk assessment is someone in the room who has seen what the hazard actually does to a human body. You cannot get that from a table.

Probability is systematically overestimated for the hazard everyone talks about and underestimated for the one nobody does. The forklift gets a high probability score because there was a near miss last month. The energized panel that has been open for six years gets a low one because nothing has happened. This is exactly backward. Exposure frequency, not incident history, drives probability, and the hazard with no history is often the one with the most exposure and the least attention.

The assessment is only as good as the task list. Most assessments cover normal operation. Injuries happen during abnormal operation: the jam, the changeover, the startup after maintenance, the “just reach in for a second.” A risk assessment that does not include the tasks people actually do, including the ones they are not supposed to do, is assessing a fictional operation. Finding those tasks requires going to the floor, watching, and asking the question the operator will only answer if they trust you: “What do you do when it jams?”

The credible worst case requires imagination disciplined by experience. A spreadsheet cannot tell you that the lithium battery room next to the loading dock creates an exposure for the truck driver. A person who has investigated a thermal runaway can. The value of a senior assessor is a mental library of ways things have gone wrong, applied to a situation that has not gone wrong yet.

Tolerability is a values decision, not a calculation. The matrix tells you a risk is “medium.” Whether medium is acceptable depends on what the organization is willing to live with, and that is a leadership decision that most organizations have never explicitly made. When it has not been made, the assessment defaults to whatever keeps the project on schedule.

The failure modes I see most

The first is the assessment as artifact. It was done for the audit, it lives in a drawer, and no one on the floor has read it. The tell is that the controls listed in the assessment do not match the controls actually in place. This is the majority case.

The second is sophistication as a substitute for judgment. An organization gets burned by a bad assessment and responds by buying software, adding decimal places, and moving from a five-by-five to a quantitative model. The inputs are still guesses, but now they are guesses with three significant figures, and the false precision makes the output harder to argue with. I have seen LOPA studies that were beautifully executed on a hazard scenario that was not the one that actually hurt someone.

The third is the assessment as a compliance-avoidance exercise. The purpose becomes documenting that the risk is acceptable rather than determining whether it is. The severity gets rounded down, the existing controls get rounded up, and the residual risk lands neatly in the green. Everybody signs. The process has been inverted.

The fourth is the one-time assessment. The machine was assessed at installation. Then the guarding was modified, the process changed, the product changed, the operator changed, and the scanner field was adjusted. The assessment describes a machine that no longer exists. Risk is a property of a moment, and an assessment that is not tied to change management is a photograph of the past.

What good actually looks like

A risk assessment that changes outcomes has a few characteristics, and none of them are about the template.

It is done at the point of work, with the people who do the work, and it covers the tasks they actually perform, including the abnormal ones. It is led by someone who has seen the consequences and can calibrate the severity honestly. It treats the matrix as a communication tool, not an oracle, and it argues about the inputs out loud. It results in specific control decisions with owners and dates, following the hierarchy of controls, not a list of “training” and “awareness” line items. It defines what “acceptable” means before the assessment starts, as a leadership statement, so the answer cannot be reverse-engineered from the schedule. And it is tied to change management, so that any modification to the equipment, the process, or the people triggers a review.

Most of that is discipline rather than expertise. The one piece that is expertise is the calibration: the ability to look at a hazard and know, from experience, what it does and how often, and to say so when the room wants a different answer. That is what a senior EHS professional brings to a risk assessment that a template cannot, and it is the reason a two-hour walkthrough with the right person can produce a better register than a two-month software project with the wrong one.

Consistency is the whole game

There is one more thing, and it is the thing that separates the organizations that get real value from risk assessment from the ones that do not. It is not the quality of any single assessment. It is the consistency of the practice.

An organization that assesses risk the same way, with the same calibration, on every machine, every project, and every change, builds something a single assessment cannot: a comparable picture of risk across the operation. That picture is what lets you prioritize capital, defend a decision to a carrier, and tell a board where the money should go. It is also the foundation of a safety culture, because when people see that hazards are evaluated honestly and consistently, and that the answers lead to action, they start reporting the ones they used to hide.

Consistency is hard, and it is hard for a boring reason: it requires the same senior judgment to be present every time, and most organizations do not have that person, or have them too busy to show up. That is the problem I built my practice to solve. A consistent, calibrated assessment process, owned by someone who has seen enough to get the severity right, and applied on a rhythm rather than on a crisis, is one of the highest-leverage things an operation can buy. It is also one of the cheapest, if you buy the judgment rather than the software. It is the first thing I build inside every 30-Day Baseline, because everything else in a safety program depends on getting this right.

Key takeaways

  • The matrix is a communication tool, not an oracle — ISO 12100, ANSI B11.0, and quantitative methods structure the conversation, but every input is a human judgment.
  • Calibration is the scarce ingredient — severity is underestimated by people who have not seen the injury, and probability is driven by exposure frequency, not incident history.
  • Assess the tasks people actually do — the jam, the changeover, the reach-in — not a fictional normal operation.
  • Define acceptable before you start — tolerability is a leadership values decision; without it, the assessment defaults to whatever keeps the schedule.
  • Consistency beats sophistication — the same calibrated judgment applied on a rhythm, tied to change management, produces a comparable risk picture that drives capital, insurance, and culture.

Related reading: Machine Guarding Is About to Stop Being a Fence · When the Hazard Moves: Safety Management for Autonomous Work

more insights

Machine Guarding Is About to Stop Being a Fence — FractionalEHS

Machine Guarding Is About to Stop Being a Fence

OSHA’s 1910.212 hasn’t changed since 1971. The machines have. Safety-rated sensing, ISO 13849 performance levels, and ISO 10218:2025 are turning the guard into a decision instead of an object — and most guarding programs aren’t built for it.

Read more >