CITB Managers Risk Assessment and Method Statements 1 — Questions and Answers
Question 1: Under the Management of Health and Safety at Work Regulations 1999, when must a risk assessment be reviewed?
- Every five years automatically
- When there is reason to believe it may no longer be valid, or when a significant change in the matters it relates to has occurred (Correct answer)
- Only after an accident or near-miss
- Once per calendar year regardless of any changes
Correct answer: When there is reason to believe it may no longer be valid, or when a significant change in the matters it relates to has occurred
A risk assessment must be reviewed when there is reason to believe it is no longer valid (e.g., following an incident) or when a significant change has occurred in the work, environment, or workforce. There is no mandatory fixed review interval.
Question 2: What is the five-step approach to risk assessment recommended by the HSE?
- Plan, Do, Check, Act, Review
- Identify hazards; identify who might be harmed and how; evaluate risks and implement controls; record findings; review and update (Correct answer)
- Assess, Eliminate, Reduce, Control, Monitor
- Identify, Evaluate, Control, Record, Report
Correct answer: Identify hazards; identify who might be harmed and how; evaluate risks and implement controls; record findings; review and update
The HSE's five steps are: (1) Identify hazards; (2) Decide who might be harmed and how; (3) Evaluate risks and decide on controls; (4) Record findings and implement; (5) Review the assessment and update if necessary.
Question 3: A 'suitable and sufficient' risk assessment must:
- Be carried out only by a health and safety consultant
- Identify significant risks and introduce adequate controls proportionate to the risk — the level of detail must be appropriate to the nature and complexity of the risk (Correct answer)
- Cover every conceivable possible risk, however remote
- Be written in a specific HSE-approved format
Correct answer: Identify significant risks and introduce adequate controls proportionate to the risk — the level of detail must be appropriate to the nature and complexity of the risk
A suitable and sufficient risk assessment identifies significant risks, not trivial ones, and the controls introduced are proportionate to the risk level. The level of detail must be appropriate — more complex and higher-risk activities require more detailed assessments.
Question 4: What is the hierarchy of controls and what position does PPE occupy within it?
- PPE is first as it is most reliable
- Elimination, substitution, engineering controls, administrative controls, PPE — PPE is the last resort (Correct answer)
- PPE is second after elimination
- Elimination, PPE, engineering controls, administrative controls, substitution
Correct answer: Elimination, substitution, engineering controls, administrative controls, PPE — PPE is the last resort
The hierarchy of controls (in order of preference): (1) Eliminate the hazard; (2) Substitute a less hazardous option; (3) Engineering controls; (4) Administrative controls (procedures, training, supervision); (5) PPE as the last resort. PPE protects the worker but does not remove the hazard.
Question 5: A risk assessment identifies a high risk. What should the employer's first priority be?
- Issue PPE to workers immediately
- Eliminate the hazard entirely if reasonably practicable — if not, apply further controls to reduce the risk to an acceptable level (Correct answer)
- Write a detailed method statement and proceed
- Reduce the workforce in the area to minimise the number of people at risk
Correct answer: Eliminate the hazard entirely if reasonably practicable — if not, apply further controls to reduce the risk to an acceptable level
When a high risk is identified, the employer's first obligation is to try to eliminate the hazard (top of the hierarchy). Only if elimination is not reasonably practicable should they apply engineering controls, administrative controls, and PPE in that order.
Question 6: A risk assessment that covers a generic work activity (rather than a site-specific one) is called a:
- Dynamic risk assessment
- Generic risk assessment (GRA) — to be supplemented with site-specific adaptations (Correct answer)
- A safe system of work
- A method statement
Correct answer: Generic risk assessment (GRA) — to be supplemented with site-specific adaptations
A Generic Risk Assessment covers a standard activity as normally performed. It must be reviewed and supplemented with site-specific information before use on any particular site, as local conditions may introduce additional or different risks.
Under the Management of Health and Safety at Work Regulations 1999, when must a risk assessment be reviewed?