Tools · ISO 45001
Choose your scale, rate the risk before controls, then after. The gap between the two is the first thing an auditor looks at.
The scores you enter stay in your browser: nothing is transmitted or stored. The rating of a site's hazards is sensitive information.
The standard imposes none. Choose the one you already use, and keep the same one everywhere.
Choose a severity and a likelihood to get a rating.
Your matrix
| 5 | 5 | 10 | 15 | 20 | 25 |
|---|---|---|---|---|---|
| 4 | 4 | 8 | 12 | 16 | 20 |
| 3 | 3 | 6 | 9 | 12 | 15 |
| 2 | 2 | 4 | 6 | 8 | 10 |
| 1 | 1 | 2 | 3 | 4 | 5 |
| 1 | 2 | 3 | 4 | 5 |
Severity in rows, likelihood in columns. The outlined cell is your rating.
The priority bands are a reading convention computed from your maximum, not a normative threshold.
HEMC
OH&S risk rating: severity and likelihood matrix
Indicative value. None of the standards cited imposes a threshold or a calculation method: the method used, the boundary and the source of the data must be stated beside the result.
ISO 45001 requires the organization to establish its own risk assessment criteria, in clause 6.1.2. It imposes no matrix, no scale and no threshold: a three by three and a five by five matrix are equally acceptable. What gets audited is therefore not the choice of scale, but the fact that it is defined, documented and applied consistently. The colour bands shown here are a reading convention computed as a proportion of your own maximum; they help you order an action plan, they do not replace the criteria you must write.
Set the scale once and for all
Three by three is enough for a small site, five by five discriminates better when risks are numerous. The choice matters less than sticking to it: two ratings on two scales cannot be compared.
Rate the severity
Rate the most severe plausible harm, neither the worst imaginable nor the most common. A crushed hand and a superficial cut are not rated at the same level even when the hazard is the same.
Rate the likelihood
It accounts for real exposure: duration of the task, number of people involved, frequency of the operation. A yearly operation and a daily one do not carry the same likelihood.
Rate the initial risk, excluding existing controls
This is the step most often skipped. Rating straight away with existing protections in place makes it impossible to demonstrate their effect, and deprives the organization of its best argument in an audit.
Rate the residual risk after controls
The score only drops if a genuinely implemented control justifies it. An intention, a planned action or an approved budget do not reduce a risk.
Sources and verification
Values and definitions verified on 2026-09-02.
Indicative result. It helps you position yourself; it replaces neither a specialist's analysis nor the reporting obligations that apply to your activity.
A rating places a risk, it does not tell you whether the system that produced it holds up. The two resources below cover the requirements around risk assessment.
Risk assessment is rarely a standalone exercise: our QHSE expertise describes how it fits with the rest of the management system. See this expertise
The ISO 45001 self-assessment checklist covers the requirements of clauses 4 to 10, including hazard identification and risk assessment.
View the checklistThe ISO 45001 toolkit contains the system files, including the hazard identification procedure and the risk assessment register.
View the toolkitOnline version
The ISO 45001 workbook you have here also exists as an online audit, with 57 control points, a rate that updates as you go and a history of your passes. It is not the same document, it is the same standard tooled differently.
NormePulse is published by HEM Consulting. The trial commits you to nothing and asks for no payment method.