SERIOUS INCIDENT RESPONSE

Protect people. Preserve the scene. Secure the evidence.

CALL +27 81 324 3666
Risk10 MINUTE READ24 LAW BRIEFING

When a Risk Assessment Needs to Be Reviewed

The change, incident, performance and time-based triggers that should cause an organisation to revisit a workplace risk assessment.

LAW SYSTEM EVIDENCE CONTROL

01 / WHY THIS MATTERS THE QUESTION BEHIND THE QUESTION

When a Risk Assessment Needs to Be Reviewed

A risk assessment is a decision made with the information available at a point in time. When the work, people, equipment, environment or knowledge changes, the decision may no longer be reliable. An annual review date is useful administration, but it is not the only trigger.

The strongest systems identify review triggers in advance and make them part of management of change. This prevents teams from continuing under controls designed for yesterday’s conditions.

THE 24 LAW LENSA document is only useful when it changes a decision, a control or the quality of evidence.

03 / SYSTEM LENS FROM WORDS TO WORK

The system behind the document.

Triggers include new plant or substances, changed design or method, different contractors, temporary work, staffing or shift changes, deteriorating equipment, unusual weather, complaints, exposure results, near misses, audit findings and legal updates. Cumulative small changes can be as important as one major project.

Review does not always require starting over. The assessor should define what changed, which assumptions are affected, whether existing controls remain effective and who must be consulted or retrained.

01DUTYWhat must be achieved?
02OWNERWho has authority?
03CONTROLWhat changes exposure?
04EVIDENCEHow can it be proved?

04 / PRACTICAL METHOD A SEQUENCE MANAGEMENT CAN USE

Seven moves from uncertainty to control.

  1. 01

    List mandatory and organisation-specific review triggers

  2. 02

    Create a management-of-change screening question

  3. 03

    Pause work when a critical assumption no longer holds

  4. 04

    Consult workers and specialists closest to the change

  5. 05

    Reassess severity, likelihood and control effectiveness

  6. 06

    Update methods, training and permits

  7. 07

    Verify the revised control in operation

The sequence should be adapted to the organisation and repeated when people, scope, law, equipment or risk changes. Implementation is stronger when the responsible person is involved in designing the control rather than merely receiving the final document.

Implementation commentary

Begin by treating list mandatory and organisation-specific review triggers, create a management-of-change screening question and pause work when a critical assumption no longer holds as connected decisions. The output of one step should become the input to the next. If teams complete them independently, different assumptions can survive inside the same system and later appear as a supervision, contract or compliance gap.

Ownership must follow authority. The person named against an action needs access to the information, budget, people and decision rights necessary to perform it. Where approval sits elsewhere, the escalation route and response time should be defined. This matters particularly when the risk crosses departments, contractors, legal entities or national borders.

Finally, implementation should be tested under normal work, change and pressure. A process that works only during a scheduled audit is not reliable. Sample recent decisions, speak to the people expected to use the control and test whether the records tell the same story as the operating environment.

05 / EVIDENCE WHAT A DEFENSIBLE FILE SHOULD SHOW

Evidence is the memory of the system.

Evidence should be proportionate, authentic and connected to the decision it supports. Six useful evidence classes for this topic are:

01Trigger and change recordIt should identify the decision, responsible person, date and approved basis instead of existing as an isolated attachment.
02Revised assessment with version controlIt should be current, attributable and capable of being checked against what people actually do in the workplace or transaction.
03Consultation notesIt should show the control before the problem, not only the paperwork produced after a complaint, audit or incident.
04Updated method or procedureIt should preserve version history so management can establish what applied at the relevant time and what later changed.
05Briefing and competency evidenceIt should connect the person performing the work with the instruction, authority, competence or approval relied upon.
06Post-change verificationIt should demonstrate verification: who checked effectiveness, what they observed and how remaining weakness was escalated.

Quantity is not the objective. A smaller body of reliable, connected evidence is more valuable than a large file of unsigned, duplicated or untested material. Retention periods, confidentiality, access and cross-border transfer should be considered where personal, commercially sensitive or legally significant information is involved.

06 / FAILURE PATTERNS WHERE GOOD INTENTIONS COLLAPSE

Common mistakes worth finding early.

  • ×
    Reviewing only once a yearThis creates confidence without a reliable basis and can conceal the point where responsibility or control becomes unclear.
  • ×
    Changing scores without changing controlsThe weakness usually appears during change or pressure, when the team needs a decision rule and finds only a generic document.
  • ×
    Failing to involve the workforceIt separates management’s record from operating reality, leaving the organisation unable to prove that the intended safeguard worked.
  • ×
    Ignoring temporary conditionsIt often transfers uncertainty to the person with the least authority to resolve it and allows the underlying condition to remain.
  • ×
    No link to training or proceduresThe apparent short-term convenience produces greater delay when customers, employees, auditors or regulators later test the arrangement.
  • ×
    Approving change after implementationRepeated tolerance can normalise the gap until a serious event, dispute or enforcement process makes the consequence visible.

A repeated weakness should be treated as information about the management system. Correcting the individual document without understanding the conditions that produced it usually guarantees recurrence.

07 / MANAGEMENT TEST QUESTIONS FOR THE DECISION ROOM

Five questions that expose whether the system is real.

  1. 01
    Who has the authority and resources to list mandatory and organisation-specific review triggers, and where is that responsibility recorded?

    Ask for the evidence, then test it against a recent real example. A confident verbal answer is useful context, but the organisation should be able to demonstrate the decision, control and follow-up without reconstructing them for the meeting.

  2. 02
    What would trigger and change record prove to an independent reader who was not present when the decision was made?

    Ask for the evidence, then test it against a recent real example. A confident verbal answer is useful context, but the organisation should be able to demonstrate the decision, control and follow-up without reconstructing them for the meeting.

  3. 03
    How would management detect that “reviewing only once a year” was beginning to occur before the outcome became serious?

    Ask for the evidence, then test it against a recent real example. A confident verbal answer is useful context, but the organisation should be able to demonstrate the decision, control and follow-up without reconstructing them for the meeting.

  4. 04
    Which operational, legal or contractual change would require this system to be reviewed rather than carried forward unchanged?

    Ask for the evidence, then test it against a recent real example. A confident verbal answer is useful context, but the organisation should be able to demonstrate the decision, control and follow-up without reconstructing them for the meeting.

  5. 05
    When the control is marked complete, who will verify that verify the revised control in operation has actually happened in practice?

    Ask for the evidence, then test it against a recent real example. A confident verbal answer is useful context, but the organisation should be able to demonstrate the decision, control and follow-up without reconstructing them for the meeting.

The purpose of these questions is not to create another audit ritual. They help leadership identify where the organisation depends on assumption, memory or one indispensable person. That dependency should be converted into a shared, documented and reviewable control.

08 / MANAGEMENT CONCLUSION THE SENTENCE TO TAKE INTO THE MEETING

Review the assessment whenever the basis of the original decision changes—not merely when the calendar tells you to open the document.
RELATED 24 LAW CAPABILITYExplore risk-assessment support
Follow this path
Legal references and reading points

The application of law depends on the facts and jurisdiction. Useful official starting points include:

General information only. This article does not create a professional mandate and should not be relied on as matter-specific legal advice.