NEBOSH Risk Assessment 3 — Questions and Answers
Question 1: What is the purpose of a 'risk register' in an organization?
- A centralized record of all identified risks, their ratings, assigned owners, control measures, and review status — used to manage and monitor organizational risks systematically (Correct answer)
- A list of accidents that have occurred
- A document completed only during annual safety audits
- A register of workers who have reported hazards
Correct answer: A centralized record of all identified risks, their ratings, assigned owners, control measures, and review status — used to manage and monitor organizational risks systematically
A risk register captures all significant identified risks (occupational H&S, environmental, business, regulatory), their likelihood and consequence ratings, the control measures in place, residual risk rating, who is responsible for each risk, and when each will be reviewed. It provides management visibility and enables prioritization of risk control resources.
Question 2: Why is 'consultation' with workers important in risk assessment?
- Workers have first-hand knowledge of actual hazards and working conditions; consultation improves quality of assessment and increases worker compliance with controls (Correct answer)
- Consultation is a legal formality only — workers add no value
- Consultation slows down the assessment process without benefit
- Only senior workers should be consulted
Correct answer: Workers have first-hand knowledge of actual hazards and working conditions; consultation improves quality of assessment and increases worker compliance with controls
Workers performing a task daily observe hazards that managers and safety officers may not notice. They can identify practical problems with proposed controls. Worker consultation is also legally required under most H&S legislation (including UAE and Saudi regulations implementing ILO principles) and produces more practical, accepted, and effective risk assessments.
Question 3: What does 'tolerable risk' mean in risk assessment terminology?
- Risk that has been reduced to as low as reasonably practicable and is accepted because it would cost a grossly disproportionate amount to reduce further — it does not mean the risk is ignored (Correct answer)
- Acceptable risk requires no further control at any level
- Tolerable risk means the risk is eliminated
- Only regulators define tolerable risk levels
Correct answer: Risk that has been reduced to as low as reasonably practicable and is accepted because it would cost a grossly disproportionate amount to reduce further — it does not mean the risk is ignored
The ALARP (As Low As Reasonably Practicable) framework distinguishes: broadly acceptable risk (very low, minimal control needed), tolerable risk (significant but justifiable benefit; must be ALARP), and unacceptable risk (too high under any circumstances). Tolerable risk must still be managed to ALARP — it is not ignored.
Question 4: What is the difference between 'quantitative' and 'qualitative' risk assessment?
- Qualitative RA uses descriptive ratings (low/medium/high) and expert judgment; quantitative RA uses numerical probability and consequence data to produce numerical risk values (Correct answer)
- They produce the same results by different methods
- Quantitative RA is always more accurate
- Qualitative RA is only used for simple tasks
Correct answer: Qualitative RA uses descriptive ratings (low/medium/high) and expert judgment; quantitative RA uses numerical probability and consequence data to produce numerical risk values
Qualitative risk assessment (most common in occupational H&S) uses descriptive judgments — likelihood and severity rated as low/medium/high with a risk matrix. Quantitative RA (used in major hazard industries — oil/gas, nuclear, chemical plants) uses statistical failure rate data, fault tree analysis, and numerical risk values (e.g., 10⁻⁶ per year). Gulf petrochemical QRA is regulatory requirement.
Question 5: What is a 'significant finding' in a risk assessment and what must be recorded about it?
- A hazard that poses a real (not trivial) risk — records must include: hazard, who is at risk, existing controls, further actions required, and person responsible and timescale (Correct answer)
- Only the hazard description needs recording
- Only fatal risks are significant findings
- Records need not be kept for risks with existing controls
Correct answer: A hazard that poses a real (not trivial) risk — records must include: hazard, who is at risk, existing controls, further actions required, and person responsible and timescale
Significant findings are those where meaningful risk exists after considering the hazard and who could be harmed. The record must show: what the hazard is, who is at risk, what controls are already in place, what further action is needed, who is responsible, and by when. This constitutes a legally defensible record of compliance.
Question 6: Under what circumstances can informal (unrecorded) risk assessment be acceptable?
- For very low-risk activities with obvious, widely understood hazards and standard controls — formal written records are legally required when significant risks exist or for organizations with 5+ employees (Correct answer)
- Formal records are never needed
- Only large organizations need written records
- Written records are always optional
Correct answer: For very low-risk activities with obvious, widely understood hazards and standard controls — formal written records are legally required when significant risks exist or for organizations with 5+ employees
Trivial risks with obvious controls (crossing a car park, making a cup of tea) may not require formal written records. However, for significant risks, non-routine work, complex environments, vulnerable workers, high-severity potential, or when legally required (5+ employees in UK/equivalent), formal written risk assessments are mandatory.
What is the purpose of a 'risk register' in an organization?