Risk you cannot see is risk you cannot manage.
A risk assessment is only worth doing if it changes what happens on the ground. Too many are written to satisfy a form, filed, and never opened again — until an incident, an audit or a tender forces the question of whether the risk was ever really understood.
We build risk assessments the other way around. Aligned to AS ISO 31000, each one gives you a clear, ranked and owned picture of exposure, with inherent and residual ratings and controls your teams can actually apply. The result is defensible on paper and useful in practice. For broader risk governance, legal registers and executive reviews, see our Risk & Compliance service.
You need us when…
- A client, tender or regulator wants a documented risk assessment
- You are introducing new plant, equipment or high-risk work
- Your existing assessments are generic, stale or unsigned
- An ISO standard requires assessed and treated risks
- Psychosocial hazards are not yet being assessed or controlled
The Five Risk Assessment Types
Different decisions need different lenses. We deliver each of the core risk assessment types — and combine them where your business needs a complete picture.
Organisational-Wide Risk Assessment
Enterprise and operational risk exposure across the whole business and every location — strategic, operational and financial risks surfaced, ranked and owned so leadership can act on what matters most.
Plant & Equipment Risk Assessment
Machinery, plant and equipment hazards assessed across guarding, isolation, pre-start and the full lifecycle — from procurement and commissioning through operation, maintenance and decommissioning.
Activity-Specific Risk Assessment
Task-level assessment at JSA and SWMS depth for specific activities and high-risk work — the hazards of a defined job broken down step by step, with controls your crews can follow.
Business Strategy Risk Assessment
Strategic, commercial and enterprise risks to your business objectives and decisions — so growth, investment and major commitments are made with exposure understood rather than assumed.
Standard-Specific Risk Assessment
Risk assessments required by a specific ISO or compliance standard — such as ISO 45001, ISO 14001, ISO 27001 or ISO 9001 — mapped to the relevant clauses so your certification holds up.
WHS & Psychosocial Risk Assessment
Workplace health and safety hazards assessed alongside psychosocial risk — workload, role clarity, exposure to trauma and workplace behaviour — using the same defensible method.
The AS ISO 31000 Risk Assessment Process
Every assessment follows the AS ISO 31000 process, with communication and consultation running throughout — so the method is consistent, repeatable and defensible whatever the scope.
Establish The Context
We define the scope, objectives, stakeholders and criteria — what we are assessing, why, and how risk will be measured.
Identify Risks
We identify the hazards, events and sources of risk relevant to the scope, drawing on your people, records and site knowledge.
Analyse
We analyse likelihood and consequence and factor in existing controls to understand each risk and how it behaves.
Evaluate
We compare each risk against your criteria and appetite to decide priorities and which risks need treatment.
Treat
We select and plan controls using the hierarchy of controls, targeting the highest residual risk first.
Monitor & Review
We set review points and monitoring so the assessment stays live — with communication and consultation throughout.
The hierarchy of controls
- Elimination — remove the hazard entirely
- Substitution — replace it with something less hazardous
- Engineering — isolate people with guarding and design
- Isolation & Administrative — procedures, permits and training
- PPE — personal protective equipment as the last line
Controls That Work Down From The Source
When we treat a risk we work down the hierarchy of controls in order of effectiveness — because a hazard removed at the source beats one managed by behaviour every time.
Most risks are treated with a practical combination of controls rather than a single measure. We document what is in place, what will be added, and who owns each control — so treatment is real and verifiable, not just a note in a spreadsheet.
Rate It Before, Rate It After.
A single risk rating hides the most important question: how much of your exposure is actually being controlled? By rating risk both before and after controls, we make control effectiveness visible — and show exactly where more is needed.
This is the difference between an assessment that looks complete and one that drives decisions. Every risk we assess carries a clear owner, so nothing sits unclaimed between teams.
How we rate each risk
- Inherent risk — the rating before any controls
- Existing controls — what is already in place
- Residual risk rating — what remains after controls
- Additional controls — treatment to close the gap
- Risk ownership — a named owner accountable for each risk
Example Risk Assessments
A look at the real, AS ISO 31000–aligned risk assessments we produce. Sample documents below — supplied by Robust HSEQ and shown for format only.
Organisational risk register — sample
Whole-of-business risk register with inherent and residual ratings. Example image to be supplied.
Plant risk assessment — sample
Machinery and equipment hazard assessment with controls. Example image to be supplied.
Activity risk assessment — sample
Task-level JSA / SWMS assessment of a specific activity. Example image to be supplied.
Strategy risk assessment — sample
Strategic and commercial risks to business objectives. Example image to be supplied.
Standard-specific assessment — sample
Risk assessment mapped to ISO standard clauses. Example image to be supplied.
WHS & psychosocial — sample
Workplace hazards including psychosocial risk. Example image to be supplied.
Your Risk Assessment Deliverables
Documented, defensible and ready to use — from the front line to the boardroom.
- A documented risk register aligned to AS ISO 31000
- Inherent and residual risk ratings for every risk
- Treatment and control plans using the hierarchy of controls
- Clear risk ownership assigned to named people
- A review schedule to keep the assessment live
- A board and executive-ready risk summary
Industries We Support
Risk assessments tailored to the hazards, plant, regulators and client expectations of your sector.
Mining
Operational and plant risk assessments for the resources sector.
MiningConstruction
Activity, JSA and SWMS assessments for head contractors and subbies.
ConstructionTelecommunications
High-risk work and activity assessments for telco contractors.
TelecommunicationsTransport & Logistics
Operational and plant risk assessments for transport operators.
Transport & LogisticsUtilities & Energy
High-assurance risk assessments for utilities and energy.
Utilities & EnergyGovernment
Risk assessments aligned to government contract requirements.
GovernmentWarehousing & Distribution
Plant and activity risk assessments for warehousing.
WarehousingManufacturing
Plant, process and activity risk assessments for manufacturers.
ManufacturingRisk Assessment FAQs
What is AS ISO 31000?
AS ISO 31000 is the Australian adoption of the international standard for risk management. It sets out principles and a process — establish the context, identify, analyse, evaluate and treat risk, with ongoing communication, consultation, monitoring and review — that gives you a consistent, defensible method for managing risk across any part of your business, rather than a one-off tick-box exercise.
What is the difference between the risk assessment types?
The types differ by scope. An organisational-wide risk assessment looks at exposure across the whole business and its locations; a plant and equipment risk assessment focuses on machinery and equipment hazards; an activity-specific assessment (JSA or SWMS level) targets a defined task or high-risk work; a business strategy risk assessment addresses strategic and commercial risks to objectives; and a standard-specific assessment covers the risks a particular ISO or compliance standard requires you to manage.
What is the difference between inherent and residual risk?
Inherent risk is the level of risk before any controls are applied. Residual risk is what remains after your existing controls are taken into account. We rate both, so you can see how effective current controls are, decide whether the residual rating sits within your risk appetite, and target additional controls where the gap is greatest.
How is the hierarchy of controls applied?
When we treat a risk we work down the hierarchy of controls in order of effectiveness — elimination first, then substitution, engineering controls, isolation and administrative controls, and finally personal protective equipment. Higher-order controls are preferred because they reduce risk at the source rather than relying on behaviour, and most risks are treated with a practical combination of controls.
Do you assess psychosocial risk?
Yes. We assess psychosocial hazards — such as workload, role clarity, exposure to trauma and workplace behaviour — alongside physical WHS hazards using the same AS ISO 31000 method, so psychosocial risk is identified, rated and controlled rather than overlooked.
Build On A Strong Foundation
Need a risk assessment that holds up?
Talk to the risk specialists businesses across Perth and WA trust. Confidential, practical and no-obligation.