Leaders: 7-Step Risk Assessment Process Mapped to ISO, NIST, OSHA

September 26, 2026•15 min read

Seven-stage risk assessment process illustration

A risk assessment is an iterative, documented process that identifies hazards, scores their likelihood and consequence, and prescribes prioritized controls to reduce harm and inform management decisions. It follows the logic embedded in ISO 31000, the NIST Risk Management Framework, and OSHA’s hierarchy of controls. PROJECT-JTH applies this same structure when conducting external technical risk reviews for organizations that need a defensible, repeatable process rather than a one-time checklist.


TL;DR:

  • Conducting a thorough risk assessment requires all seven stages, especially proper scoping and documentation, to avoid gaps during audits or incidents.

  • Hazard identification must include records review, floor inspections, incident investigations, nonroutine scenarios, and input from vendors and workers to reveal blind spots.

  • Risk scoring should match the hazard’s severity and likelihood, with different rigor levels (qualitative, semi-quantitative, quantitative) applied based on the risk’s stakes.

  • Controls should follow OSHA’s hierarchy, prioritizing elimination, substitution, and engineering solutions over administrative measures and PPE, which are less reliable long-term.

  • External risk reviews can generate prioritized risk registers and concrete action plans, often revealing hazards internal teams overlook after months of familiarity.


PROJECT-JTH

Bring Clarity to Your Risk Program

PROJECT-JTH provides technical advisory services for organizations seeking clearer, more repeatable risk and operational decisions under pressure.

Explore PROJECT-JTH

Table of Contents

What Are the Steps in a Risk Assessment Process?

The standard risk assessment process moves through seven stages, each building on the one before it. Skipping a stage, especially scoping or documentation, tends to produce a program that looks thorough on paper but fails during an audit or an actual incident.

Here is the sequence most safety and IT risk frameworks converge on:

  • Define scope and context. Decide what operations, systems, or facilities are in play and who owns the outcome. ISO 31000 treats this step as foundational, insisting that risk criteria be tailored to the organization’s own objectives rather than borrowed wholesale from a template.

  • Identify hazards. Gather every plausible source of harm, including the ones nobody has reported yet.

  • Analyze and assess. Rate each hazard by likelihood and consequence to produce a risk score.

  • Evaluate and prioritize. Rank risks so limited time and budget go to the highest-consequence items first.

  • Select and implement controls. Apply the hierarchy of controls, starting with elimination where feasible.

  • Record and report. Document the decision trail, not just the final control.

  • Review and monitor. Reassess on a schedule and whenever conditions change.

This cycle never really closes. A new supplier, a modified process line, or a software migration can reopen any stage without warning, which is why NIST frames its own seven-step Risk Management Framework (Prepare, Categorize, Select, Implement, Assess, Authorize, Monitor) as a loop rather than a line. Organizations that treat risk assessment as a single event, rather than a maintained system, are the ones that get surprised.

How Do You Identify Hazards Before They Cause Harm?

Hazard identification fails most often not from a lack of effort but from a narrow field of vision. Teams inspect the obvious equipment and skip the maintenance window, the vendor’s forklift route, or the software patch that changes a data flow nobody flagged. OSHA’s guidance on hazard identification lays out a wider net than most internal checklists capture.

Here is a practical sequence for building that wider net:

  1. Pull existing records first. Incident reports, near-miss logs, workers’ compensation claims, and prior audit findings usually contain patterns nobody has connected yet.

  2. Walk the floor with fresh eyes. Scheduled inspections catch drift. Conditions that were compliant a year ago often are not compliant today.

  3. Investigate incidents and near-misses as they happen. A near-miss investigated within 48 hours yields sharper detail than one reconstructed from memory a month later.

  4. Flag nonroutine and emergency scenarios separately. Startup, shutdown, cleaning, and maintenance windows carry a disproportionate share of severe incidents because they fall outside normal supervision and routine.

  5. Bring in supplier and contractor input. Outside vendors often see conditions your own staff have stopped noticing.

  6. Interview the people doing the work. Front-line workers routinely know about a workaround or a shortcut that never made it into a procedure manual.

Cross-functional involvement matters here, not as a courtesy but as a coverage strategy. A safety manager, an IT lead, a facilities supervisor, and a line worker will each spot different hazards in the same physical space, and a plan built by only one of them will always have blind spots.

Pro Tip: Schedule a short hazard walk-through specifically for nonroutine tasks, separate from your regular inspection. Startup and shutdown procedures deserve their own review because they almost never look like the “normal” version of the job.

How Do You Score and Prioritize Risks?

Risk scoring converts a hazard into a number you can act on, typically by multiplying a likelihood rating by a consequence rating. A five-point scale on each axis is common: likelihood ranges from rare to almost certain, and consequence ranges from negligible to catastrophic. Multiply the two, and a hazard scoring 4 for likelihood and 5 for consequence lands at 20, well above one scoring 2 and 2 for a total of 4.

Three levels of rigor apply depending on the stakes involved:

  • Qualitative assessment works for lower-stakes or early-stage reviews, using descriptive labels like “low,” “moderate,” and “high” without forcing numbers onto judgment calls that don’t need them.

  • Semi-quantitative assessment applies numeric scales (the classic likelihood times consequence matrix) to enable comparison across many hazards at once.

  • Quantitative assessment uses hard data, failure rates, financial exposure, or modeled probabilities, reserved for high-consequence decisions like capital equipment investment or regulatory exposure.

ISO 31000 frames this entire stage as risk analysis feeding into risk evaluation, and it stresses that criteria should reflect the organization’s actual risk appetite rather than a generic scale imported from another industry.

The distinction between inherent and residual risk is where many assessments quietly lose credibility. Inherent risk is the hazard’s severity before any controls exist. Residual risk is what remains after controls are applied, and it should be lower, but only if the controls actually work as designed. A control that exists on paper but isn’t inspected or maintained does not reduce residual risk; it just creates the appearance of reduction. Document control effectiveness explicitly rather than assuming a control’s presence equals a control’s performance.

Illustration showing risk reduction through verified controls

How Do You Choose the Right Risk Controls?

Once a hazard is scored, the next decision is which control to apply, and the hierarchy of controls settles that question in order of reliability rather than convenience. OSHA ranks controls from most to least effective: elimination, substitution, engineering controls, administrative controls, and personal protective equipment. The logic is straightforward. A control that physically removes a hazard doesn’t depend on a worker remembering a rule or wearing equipment correctly every single time.

  • Elimination removes the hazard entirely, such as discontinuing a dangerous process step.

  • Substitution swaps in a less hazardous material or method.

  • Engineering controls isolate people from the hazard through design, guarding, or ventilation.

  • Administrative controls change how people work through training, signage, and procedures.

  • PPE protects the individual worker but does nothing to reduce the hazard itself.

Administrative controls and PPE sit at the bottom for a reason: both rely on consistent human behavior under pressure, and pressure is exactly when compliance slips. Engineering controls, once installed, work even when nobody is watching.

Feasibility still matters. An engineering fix that costs six months and a capital request cannot be the only answer to a hazard that’s active today, which is why interim “worst-first” measures deserve serious weight while a permanent solution moves through budgeting and installation. Address the highest-consequence exposure with a temporary administrative control or PPE now, then track the permanent fix on a firm deadline rather than letting the interim measure quietly become permanent by default.

Pro Tip: Every engineering control needs a maintenance schedule from day one. A guard rail that’s never inspected or a ventilation system nobody services degrades silently, and the risk it was supposed to eliminate creeps back without anyone noticing until an incident forces the question.

Which Tools Work Best for Different Risk Scenarios?

Different situations call for different tools, and picking the wrong one either wastes time on overkill analysis or misses risk that a simpler method would have caught.

  • Risk matrix. A five-by-five likelihood/consequence grid is the workhorse for most operational risk screening, fast to build and easy for non-specialists to read.

  • Job Hazard Analysis (JHA). Breaks a specific task into steps, hazards per step, and controls per hazard, ideal for high-risk or nonroutine jobs.

  • Failure Mode and Effects Analysis (FMEA). Escalate here when a system has many interacting failure points, common in manufacturing lines or safety-critical equipment, where a matrix alone can’t capture cascading failure paths.

  • Bowtie analysis. Maps causes on one side and consequences on the other around a central hazard event, useful for visualizing multiple barriers and where each one could fail.

  • Quantitative modeling. Reserved for major capital decisions or regulatory filings where financial exposure or probability data justifies the added rigor.

A basic risk matrix example: a hazard rated “likely” (4) with “major” consequence (4) scores 16, landing in the highest priority band on most five-by-five scales, while “unlikely” (2) with “minor” consequence (2) scores 4, landing near the bottom. The matrix’s limit is that it flattens nuance into a single number. Two hazards scoring 16 can carry very different risk profiles, so treat the matrix as a triage tool, not the final word on resource allocation.

What Documentation Does a Risk Assessment Require?

A risk assessment that lives only in someone’s memory isn’t a risk assessment; it’s an opinion with no audit trail. The 2025 GAO Green Book revisions reinforce this directly, requiring organizations to document both periodic and ongoing risk assessment results and to maintain a defined process for responding to significant changes so controls can adapt quickly.

A risk register should capture, at minimum:

  • Hazard description and the activity or system it’s tied to

  • Who or what is exposed (workers, data, equipment, the public)

  • Inherent risk rating and residual risk rating after controls

  • Selected controls, mapped to the hierarchy of controls

  • Assigned owner and implementation timeline

  • Verification method and next review date

Here’s how that translates into an actual register row:

Hazard

Inherent Risk

Control

Owner

Review Date

Unguarded conveyor pinch point

20 (High)

Fixed guarding installed

Facilities Lead

Quarterly

Legacy server missing patches

16 (High)

Patch cycle + monitoring

IT Systems Manager

Monthly

NIST’s RMF echoes the same principle for information systems, treating documentation as a living artifact updated through the Monitor step rather than a report filed once and forgotten.

How Often Should Risk Controls Be Reviewed?

Reviews need both a calendar and a trigger list. Set a baseline cadence, quarterly for high-risk items and annually for lower-risk ones, but treat any of the following as an automatic reassessment trigger regardless of where you are in that cycle:

  • A recorded incident or near-miss

  • A process, equipment, or software change

  • New technology introduced into the workflow

  • Personnel turnover in a safety-critical role

Continuous monitoring closes the loop between review and action. NIST’s guidance on the Monitor step recommends defining what gets monitored, how often, and who receives the reporting, principles that transfer cleanly from IT systems to physical safety programs. Feed every review outcome back into the risk register so governance always reflects current conditions, not last year’s snapshot.

What Should Leaders Do First to Strengthen Risk Assessment?

Momentum matters more than perfection when starting or rebuilding a program. Work through this sequence rather than trying to fix everything simultaneously.

  1. Assign one accountable owner for the overall assessment, even if multiple departments contribute data.

  2. Define scope in writing before collecting a single data point, so the effort doesn’t sprawl.

  3. Pull existing records (incidents, inspections, audits) to establish a baseline instead of starting from a blank page.

  4. Run a focused JHA on your three highest-suspected-risk activities first.

  5. Score and rank what you find using a consistent matrix.

  6. Assign controls with named owners and firm deadlines, not open-ended commitments.

  7. Log everything in a risk register from the first day, not after the fact.

  8. Set review dates on the calendar immediately, before the initial urgency fades.

Budget discipline follows the hierarchy of controls: engineering fixes cost more upfront but eliminate recurring administrative and PPE expenses over time. A single well-placed guard or a ventilation upgrade often pays back faster than years of replacement PPE and retraining cycles for the same hazard.

Pro Tip: If budget forces a choice, fund the engineering control for your highest-scoring hazard first, even if it means delaying lower-priority items. A permanent fix on your worst risk beats administrative patches spread thin across five moderate ones.

What Does an External Technical Risk Review Deliver?

An outside review often surfaces what internal teams stop seeing after months of familiarity. PROJECT-JTH’s Technical Systems & Risk Review walks through the same process outlined above, hazard identification, scoring, and control mapping, applied to technical infrastructure and operational systems.

Typical deliverables include a prioritized risk register, an implementation roadmap tied to the hierarchy of controls, and a governance checklist your team can maintain going forward. For organizations already tracking production records or contract-based work, Project Relay can house that risk register alongside existing documentation instead of scattering it across separate spreadsheets. The engagement works alongside your internal team, not around it, and ends with concrete next steps rather than a binder nobody reopens.

Where Risk Programs Quietly Fail

The failures that matter most rarely announce themselves. Controls get installed once and never inspected again. Nonroutine tasks stay off the register entirely. Ownership gets assigned to a title instead of a person, which means it belongs to no one. Fixing this takes documented ownership and small, prioritized engineering investments made consistently, not a bigger binder.

— Jesse Hart

How PROJECT-JTH Supports Your Risk Program

PROJECT-JTH gives organizations a technical review that turns scattered hazard knowledge into a documented, prioritized system, without the overhead of building an internal risk function from scratch.

PROJECT-JTH

A Technical Systems & Risk Review produces the exact artifact this article describes: a scored risk register with named owners and control recommendations mapped to the hierarchy of controls, delivered by people who work through Linux infrastructure and security remediation daily rather than generic checklists. Infrastructure Automation & Ansible Review is available for teams whose risk exposure runs through automated deployment pipelines. For maintaining the register itself, Project Relay organizes production records and control documentation in one place at $49 per month, so review dates and ownership don’t quietly slip through a shared drive. Leadership teams that need their people communicating clearly under pressure during an incident, not just documenting one after the fact, can also look at PROJECT-JTH’s coaching and workshop offerings under the Solo, Team, and Practice plans. Reach out through the technical consulting page to scope a review against your current systems and get a direct quote.

Where to Verify Risk Assessment Standards

Match the source to the audience: safety teams should reference OSHA’s hazard identification guidance, IT teams the NIST RMF, enterprise risk owners ISO 31000, and governance staff the GAO Green Book.

Sources

FAQ

What Is the Difference Between a Risk Assessment and a Risk Management Framework?

A risk assessment is the identify, analyze, and evaluate stage; a framework like NIST’s RMF wraps that assessment into a larger cycle including control selection, authorization, and ongoing monitoring. The assessment feeds the framework rather than replacing it.

How Often Should a Risk Assessment Be Updated?

Set a routine cadence, often quarterly for high-risk areas and annually for lower-risk ones, but always reassess immediately after an incident, a process change, or new equipment or technology. Waiting for the calendar date when conditions have already changed defeats the purpose of the schedule.

Should Small Organizations Use the Same Process as Large Enterprises?

Yes, scaled to fit. A small operation can run the same identify, assess, control, document, and review cycle with a simpler risk matrix and fewer stakeholders, while ISO 31000 explicitly supports tailoring risk criteria to the organization’s own context and objectives rather than a fixed enterprise template.

What Should Go in a Risk Register Besides the Hazard Itself?

At minimum, include who or what is at risk, the inherent and residual risk ratings, the selected control mapped to the hierarchy of controls, an assigned owner, an implementation timeline, and a scheduled review date. The GAO Green Book treats this level of documentation as a baseline governance expectation, not an optional extra.

Can an Outside Consultant Run Our Risk Assessment?

Yes. External reviewers often catch hazards internal teams have stopped noticing, and PROJECT-JTH’s Technical Systems & Risk Review delivers a prioritized risk register and implementation roadmap that plugs into your existing safety or IT governance process rather than replacing it.

Back to Blog

Put It Into Practice

Find Your Next Clear Step.

Need help with a technical challenge or a leadership event? Tell Jesse what you are working through and start a practical conversation.

Start a Conversation

PROJECT-JTH LLC · Hoover, Alabama
Calmer Leadership. Better Systems. Practical Tools.

Home   /   Contact