Learning how to create a risk register is a fundamental process for ensuring workplace safety and achieving ISO 45001 compliance. It involves three core steps: first, you identify potential workplace hazards; then, you analyze their likelihood and potential impact; and finally, you plan a response to control them. This essential document serves as a central log for all identified risks, ensuring your team is prepared, your operations are secure, and you meet your compliance obligations.
Your Blueprint for an Auditor-Ready Risk Register
For any Australian SME aiming for ISO 45001 compliance, a solid risk register is the absolute cornerstone of your safety management system. Forget thinking of it as just more paperwork. This is a dynamic risk management tool designed to actively improve workplace safety and, crucially, satisfy auditors.
A well-constructed register is your key to creating a safer work environment, cutting down on incidents, and proving you have the robust systems needed to win those competitive tenders.
The whole idea behind risk management is a cycle of identifying, analyzing, and controlling risks, as you can see below.

This simple flow highlights that the register is meant to be a living document, not something you create once and file away. This guide will give you a practical, no-nonsense approach to building one that actually works for your business.
Before we get into the step-by-step process, it helps to know what a finished risk register should contain. These are the non-negotiable columns you'll need to satisfy an ISO 45001 auditor.
Essential Components of an ISO 45001 Risk Register
| Component | Purpose | Example |
|---|---|---|
| Hazard Identification | Describes the potential source of harm. | Working at heights on a scaffold. |
| Risk Description | Explains the specific unwanted event that could occur. | A worker falling from the scaffold due to instability. |
| Risk Analysis | Assesses the likelihood and consequence of the risk. | Likelihood: Possible; Consequence: Major Injury. |
| Risk Rating | Assigns a score (e.g., High, Medium, Low) based on the analysis. | High Risk (15). |
| Existing Controls | Lists the current safety measures in place. | Mandatory harness use; daily scaffold inspections. |
| Residual Risk | Re-evaluates the risk rating with existing controls applied. | Medium Risk (9). |
| Additional Controls | Outlines new actions needed to further reduce the risk. | Install toe boards; provide refresher training. |
| Risk Owner | Assigns responsibility for managing the risk to a specific person. | Site Supervisor. |
| Review Date | Sets a schedule for re-assessing the risk and controls. | 12/06/2025 |
Having these components clearly laid out is what transforms a simple list into a powerful management tool that demonstrates true compliance.
The Business Case for a Solid Risk Register
The safety landscape in Australia makes a compelling case for getting this right. In 2024 alone, there were 146,700 serious workers' compensation claims, with the total cost tipping towards AUD $6 billion a year. For a small or mid-sized business, those numbers are a stark reminder of why a risk register is so critical for the systematic documentation and control monitoring that ISO 45001 demands.
In fact, organisations that properly integrate these programs have seen up to a 45% reduction in their incident costs. It's not just a compliance exercise; it's a smart business decision.
Getting Proactive, Not Reactive
A good risk register shifts your business from a reactive mode—fixing problems after someone gets hurt—to a proactive one where you anticipate and manage issues before they happen. This change in mindset is fundamental to building a strong safety culture.
The benefits quickly become obvious and directly affect your bottom line:
- Improved Safety: When you systematically look for hazards, you naturally have fewer incidents.
- Demonstrated Due Diligence: A detailed register is concrete proof for auditors and regulators that you take safety seriously.
- Smarter Decisions: With a clear view of potential threats, management can allocate time and money where they're needed most.
- A Real Competitive Edge: Having robust safety systems, like those required for ISO 45001 certification, is often a deal-breaker for winning major contracts.
To make sure your risk register is truly 'auditor-ready,' it’s helpful to get familiar with the kinds of documentation and checklists used in official reviews, like the examples found in effective compliance audit forms. This guide will walk you through building a register that becomes the powerful, central hub of your entire safety management system.
Defining Your Scope and Identifying Workplace Hazards
Before you can even think about listing risks, you need to draw a clear line in the sand. This first step—defining your scope—is all about setting practical boundaries for your risk register. For any small or medium-sized business, this is non-negotiable if you want to keep the task manageable.
So, what does that actually mean? It means answering some simple but critical questions. Are we just looking at the workshop floor, or are we including the admin office too? Does this cover our subcontractors, or only our direct employees? Getting these parameters sorted from the get-go stops the whole process from spiralling out of control and keeps your focus sharp.
Setting Realistic Boundaries for Your Register
For most Australian SMEs, a realistic scope means starting where the biggest dangers lie. If you're in manufacturing, your focus might initially be on plant operation and manual handling. A construction company, on the other hand, would naturally gravitate towards high-risk work like scaffolding, excavation, or electricals.
It’s far better to build a detailed, rock-solid register for one high-risk area than a flimsy, superficial one that tries to cover everything at once. You can always expand your scope later as you get more comfortable with the process. In many ways, these initial steps of defining your scope and identifying hazards mirror the principles of due diligence, as you're doing your homework before jumping in.
With your boundaries firmly in place, the real work begins: hazard identification. This isn't a job for one person sitting alone in an office. It has to be a team effort, bringing in the very people who face these risks day in and day out.
Practical Techniques for Hazard Identification
To build a list of hazards that actually means something, you need to actively go looking for them. Guesswork is a recipe for disaster and will leave dangerous gaps in your safety net. The best approach is to use a few different methods to uncover both the obvious dangers and the ones lurking just beneath the surface.
Some of the most effective ways to do this are:
- Workplace Inspections: Get out there and walk the floor. Do it regularly—whether it’s on the construction site, in the factory, or through the office—with the sole purpose of spotting potential trouble. Look for things like trailing cables, unguarded machinery, poor lighting, or dodgy storage.
- Consulting Your Team: Your workers are your best source of information. They have intimate, firsthand knowledge of the risks they face. Run a toolbox talk, a dedicated workshop, or even just have informal chats. Ask them what worries them; they’ll be the ones who know about all the near misses that never made it into a formal report.
- Analysing Past Incidents: Your own history is a powerful teacher. Dig into your records of past injuries, illnesses, and near-miss reports. This is a goldmine of data that points directly to hazards that have already caused harm or have the clear potential to.
- Reviewing Official Documentation: Don't forget the paperwork. Go through your Safe Work Method Statements (SWMS), the Safety Data Sheets (SDS) for any chemicals you use, and the manufacturer’s operating manuals for equipment. These documents are legally required for a reason and often spell out the potential hazards.
Remember, a hazard isn't just a catastrophic event. It's anything with the potential to cause harm. This could be a repetitive task causing strain injuries over time or a noisy environment that could lead to gradual hearing loss. You have to think broadly.
Moving Beyond Generic Risks
It's tempting to just jot down "slips, trips, and falls" and call it a day, but a genuinely useful risk register goes deeper. The aim is to pinpoint the specific, operational hazards that are unique to your business. If you're new to this, our guide on what is a risk register is a great place to start.
Let’s look at some real-world examples for Aussie SMEs that show the difference:
- Construction: Instead of a generic "working at heights," be specific: "Unsecured voids on the second-floor slab during formwork stripping."
- Manufacturing: Don't just write "manual handling." Get to the root of it: "Repetitive lifting of 15kg boxes from floor level to shoulder height at the packing station."
- Office Environment: Move beyond "ergonomics." Identify the real problem: "Prolonged use of non-adjustable seating leading to potential musculoskeletal disorders for the customer service team."
This level of detail is what elevates your risk register from a tick-a-box compliance document to a powerful, practical tool for making your workplace safer. It lays the groundwork for a much more accurate and meaningful risk assessment, which is where we're headed next.
Getting to Grips with Risk Assessment and the Risk Matrix
Okay, so you’ve got your list of hazards. That’s a great start. But a list is just a list until you figure out which items can cause real trouble. This is where risk assessment comes in – it’s the process of turning that long list into a smart, prioritised action plan.
We're not just guessing here. For every single hazard you've identified, you need to analyse two simple things: how likely is it to actually happen, and if it does, how severe would the outcome be?
By scoring each hazard, you can finally see where to focus your limited resources. It’s all about putting your time, money, and effort into fixing the biggest problems first. The aim is to create a straightforward rating system that anyone in the business can pick up and use consistently.

This entire process leads us to one of the most practical tools in the safety world: the risk matrix.
Defining Likelihood and Severity
First things first, you need to define what "likely" and "severe" actually mean in your workplace. Vague terms won't cut it. The key is to create a simple scale with clear descriptions that make sense for your operations. For most Australian SMEs, a 5-point scale for each is the sweet spot – detailed enough to be useful, simple enough to be used.
Likelihood Ratings (How often could this happen?)
- (5) Almost Certain: You'd expect this to happen pretty much all the time (e.g., daily or weekly).
- (4) Likely: Will probably happen at some point (e.g., maybe monthly).
- (3) Possible: Could happen, but it’s not a regular thing (e.g., once or twice a year).
- (2) Unlikely: You wouldn't expect it, but it could happen (e.g., once every few years).
- (1) Rare: Would only happen in really unusual circumstances (e.g., it’s never happened but is theoretically possible).
Severity Ratings (How bad would it be?)
- (5) Catastrophic: Results in a death or a permanent, life-changing disability.
- (4) Major: A serious, irreversible injury or illness that needs major medical help.
- (3) Moderate: Someone needs medical treatment, but they'll recover (think stitches or a broken bone).
- (2) Minor: A simple first-aid job will do (like for cuts and bruises).
- (1) Insignificant: No real injury, or so minor it doesn't even need a plaster.
Having these definitions written down is crucial. It stops the assessment from being a matter of opinion and ensures that if two people assess the same risk, they’ll land on a similar rating.
Building Your Risk Matrix
A risk matrix is just a grid that maps your likelihood scores against your severity scores. Where they intersect, you get a final risk score. This score is then assigned a priority level – Low, Medium, High, or Extreme. It’s a brilliant visual tool that instantly shows you what needs fixing now.
To get the score, you just multiply the likelihood rating (1-5) by the severity rating (1-5). This gives you a number between 1 and 25, making it easy to rank your risks objectively.
The real magic of a risk matrix is how clear it is. A quick glance shows you exactly where the danger zones are. Management can see the red and orange squares and know immediately where the biggest threats are, without having to wade through a massive report.
Here’s a common 5×5 risk matrix you can use as a starting point. Feel free to adjust the scores and colours to match what your business considers an acceptable level of risk.
Example Risk Matrix (5×5)
The table below shows how a likelihood score (from 1 to 5) and a severity score (from 1 to 5) are multiplied to produce a risk rating. This rating then corresponds to a colour-coded priority level.
| Likelihood ↓ / Severity → | (1) Insignificant | (2) Minor | (3) Moderate | (4) Major | (5) Catastrophic |
|---|---|---|---|---|---|
| (5) Almost Certain | Med (5) | High (10) | Extreme (15) | Extreme (20) | Extreme (25) |
| (4) Likely | Med (4) | Med (8) | High (12) | Extreme (16) | Extreme (20) |
| (3) Possible | Low (3) | Med (6) | High (9) | High (12) | Extreme (15) |
| (2) Unlikely | Low (2) | Low (4) | Med (6) | Med (8) | High (10) |
| (1) Rare | Low (1) | Low (2) | Low (3) | Med (4) | Med (5) |
Based on the scores in the table, you can set action levels for your team to follow.
Risk Priority Levels:
- Extreme (15-25): Stop work. This is an intolerable risk and must be dealt with before anyone continues.
- High (9-14): Urgent action required. Senior management needs to be involved.
- Medium (4-8): Needs to be managed. You'll need specific controls and procedures in place.
- Low (1-3): Generally acceptable. Manage through routine day-to-day procedures.
Putting it into Practice: A Real-World Scenario
Let's walk through an example using one of our previously identified hazards: "Repetitive lifting of 15kg boxes from floor level to shoulder height at the packing station."
Assess Likelihood: This task happens all day, every day, with multiple staff. Based on our scale, the chance of a strain injury happening eventually is high. We’ll call it (4) Likely.
Assess Severity: A serious back injury, like a herniated disc, could mean significant time off work and extensive medical treatment. It's not catastrophic, but it's serious. We'll rate the severity as (3) Moderate.
Calculate the Risk Rating: Now, we just multiply the two numbers: Likelihood (4) x Severity (3) = a risk score of 12.
Find it on the Matrix: A score of 12 on our example matrix lands squarely in the High risk category.
Just like that, this simple process has shown us that this manual handling task is a major priority. It’s a problem we need to solve with proper controls before it leads to a painful and expensive injury. This initial rating is what we call the inherent risk—the risk as it stands before we've done anything to fix it. The next step is to figure out what we’re going to do about it.
Implementing Controls and Evaluating Residual Risk
A risk assessment is pretty useless without a solid action plan. Once you've figured out what could go wrong and how bad it could be, the real work begins: deciding what you’re going to do about it. This is where controls come in – the practical steps you take to dial down the likelihood or severity of an incident. This is the part that transforms your risk register from a static document into a living, breathing safety tool.

The approach championed by both ISO 45001 and local Australian WHS regulators isn't about just picking any solution. It's a structured method called the hierarchy of controls. Think of it as a pyramid for safety solutions, where you always start at the top with the most effective measures and only move down when the higher-level options aren't reasonably practicable.
Understanding the Hierarchy of Controls
This framework gives you a clear roadmap for tackling hazards, pushing you to choose robust, reliable solutions over quick fixes. It’s broken down into five levels, with each level being less effective than the one above it.
- Elimination: The gold standard. This means getting rid of the hazard entirely. No hazard, no risk. Simple as that.
- Substitution: The next best thing. Can you swap out a hazardous chemical, a noisy piece of equipment, or a dangerous process for a safer one that still gets the job done?
- Engineering Controls: These are physical changes you make to the workplace to put a barrier between people and the hazard. Think machine guards, local exhaust ventilation, or sound-proof enclosures.
- Administrative Controls: This involves changing the way people work. We're talking about safe work procedures, specific training, warning signs, and job rotation. These rely heavily on people doing the right thing.
- Personal Protective Equipment (PPE): Your last resort. This is stuff like hard hats, safety glasses, and gloves. It protects the person, but it does absolutely nothing to fix the actual hazard.
A key takeaway here is to always aim as high up the hierarchy as you can. An over-reliance on PPE is a massive red flag for any auditor and usually points to a weak safety culture.
Let's go back to our earlier example: "Repetitive lifting of 15kg boxes from floor level to shoulder height at the packing station," which we rated as a High risk with a score of 12.
Applying the hierarchy might look something like this:
- Elimination: Could we automate the whole task? A packing machine would mean nobody lifts a single box, completely eliminating the manual handling hazard.
- Substitution: What if we switched to smaller 5kg boxes instead of 15kg ones? This substitutes the hazardous lift with a far more manageable one.
- Engineering Controls: Maybe we could install a vacuum lifter or a height-adjustable scissor lift table. This way, workers are guiding the load, not bearing its full weight.
- Administrative Controls: Could we introduce a two-person lift policy, rotate staff through different tasks to avoid repetitive strain, and provide targeted manual handling training?
- PPE: Honestly, for a musculoskeletal hazard like this, PPE such as back braces is generally not considered an effective control.
Documenting Controls and Finding the Residual Risk
Once you've landed on the best controls for the job, get them documented in your risk register. It’s really important to separate what you’re already doing (existing controls) from what you plan to do (additional controls).
But you're not done yet. After figuring out your controls, you have to reassess the risk with those measures in place. This new rating is called the residual risk—it's the level of risk that's left over after your safety solutions are up and running.
Let's stick with our lifting example. Say we decided to install a scissor lift table (a solid engineering control). Now we go back to our risk matrix for a re-evaluation:
- New Likelihood: With the scissor lift doing the heavy work, the physical strain is dramatically lower. The chance of a serious injury is now way down. We might confidently re-rate it from a (4) Likely to a (2) Unlikely.
- New Severity: If an injury were to somehow still happen, its potential severity hasn't really changed. A back strain is a back strain. So we’ll keep Severity at (3) Moderate.
Now, we calculate our new score: New Likelihood (2) x Severity (3) = 6.
A quick glance at our risk matrix shows a score of 6 is a Medium risk. Just like that, we’ve effectively reduced the risk from High (12) to Medium (6). Writing this whole thought process down in the register gives a clear, defensible record that proves you have a systematic and effective way of managing safety in your business.
Maintaining Your Risk Register: Ownership and Reviews
Right, you've built your risk register. That's a fantastic start, but let's be honest—its real value isn't in the creation, it's in the follow-through. A register that just sits on a server is nothing more than a snapshot in time. It becomes stale, fast.
To turn that document into a living, breathing safety tool that will actually impress an ISO 45001 auditor, you need two things: clear ownership and a rock-solid maintenance schedule.
Without someone accountable, even the most brilliant plans fizzle out. That's why every single risk you've listed needs a designated Risk Owner.
Who Exactly is a Risk Owner?
A Risk Owner is the go-to person for a specific risk. This isn't just a name in a spreadsheet; it’s an active, hands-on role. Their job is to keep a close eye on that risk, make sure the controls you've all agreed on are actually working, and push for any new actions needed to keep your team safe.
Picking the right person is crucial. You need someone with the authority and the on-the-ground knowledge to make things happen.
A Risk Owner is expected to:
- Keep an eye on controls: Are the machine guards still in place and maintained? Are people actually following the safe work procedure? Is the right PPE being worn?
- Flag any changes: If a control measure fails or a new wrinkle to the hazard pops up, they need to raise the alarm with management.
- Drive new actions: If the team decides a new control is needed, the Risk Owner leads the charge to get it implemented.
- Talk to the team: They make sure the workers doing the task truly understand the risks and why the control measures are so important.
In a typical SME, this is often a site supervisor, a leading hand, or an operations manager—someone who sees the day-to-day reality of the work.
When you assign ownership, you transform a passive document into an active management system. It builds a culture of accountability where key risks have a dedicated champion, making sure nothing gets ignored.
Setting Up a Realistic Review Schedule
Your risk register isn't a "set and forget" exercise. Workplaces change, and ISO 45001 demands that your risk management keeps pace. New gear, different procedures, and updates to Australian WHS laws mean a static register is a liability.
For most businesses, a two-tiered approach to reviews works best.
- The Annual Check-up: At a minimum, you should do a full, top-to-bottom review of the entire risk register once a year. It’s a good idea to tie this into your broader management review meetings to ensure nothing falls through the cracks.
- Trigger-Based Reviews: More importantly, you need to review specific parts of the register immediately after certain things happen. Think of these events as your safety early warning system.
Key Triggers That Demand an Immediate Review
Some events make your current risk assessments instantly out of date. You can’t wait for the annual review when safety is on the line.
Get ready to pull out the register when:
- An incident happens: After any injury or even a close call, you have to dissect the related risk assessment to figure out where the controls went wrong.
- New equipment arrives: A new machine brings new hazards. These must be assessed before it gets used.
- You change how you work: Altering a process can create completely new risks or make your old controls useless.
- The law changes: Australian WHS legislation gets updated. Your register must reflect your current legal duties.
- Your team raises a concern: If a worker or your safety committee spots a new hazard or a problem with a control, that’s your cue to review it.
This dynamic approach is what keeps your risk management relevant. It’s not just busywork, either. We see a direct link between this kind of systematic practice and better business outcomes in Australia. Companies with strong risk management programs often see 23% fewer financial losses from operational incidents, and those who regularly review their assessments achieve 40% better outcomes. You can dig deeper into the numbers by exploring the latest research on digital risk register effectiveness.
Don’t Forget the Paper Trail
Finally, proper record-keeping is non-negotiable for an audit. You have to be able to prove you’re actively managing your risks. Whether you’re using a simple spreadsheet or dedicated software, version control is your best mate.
When you update a risk, don't just type over the old text. Archive the old version and create a new one, making a note of the date and why it was changed. This creates a crystal-clear audit trail that shows how your understanding and management of a risk have evolved over time.
For an auditor, this documented history isn't just paperwork; it's solid proof of your commitment to continuous improvement—a cornerstone of the ISO 45001 standard.
Answering Your Top Questions About Risk Registers
Even with the best intentions, building your first risk register can feel a bit daunting. A few common questions always seem to pop up, especially for businesses getting their heads around ISO 45001 compliance for the first time.
Let's tackle some of the most frequent queries we hear from Australian SMEs. Getting these details right is the key to creating a document that’s genuinely useful on the workshop floor and ticks all the boxes for an auditor.
How Detailed Does My Risk Register Need To Be for an ISO 45001 Audit?
This is a brilliant question because it cuts right to the chase. Your risk register needs enough detail to show you have a proper, systematic process, but it definitely shouldn't be an encyclopedia of every tiny thing that could go wrong. The goal is clarity, not complexity.
An auditor wants to see a ‘living document’ that reflects what actually happens in your business, not just a generic template you’ve pulled off the internet. For an Aussie SME, that means linking risks directly to specific tasks, pieces of equipment, or roles within your company.
To hit the mark, make sure your register clearly shows you've:
- Identified specific Occupational Health and Safety (OHS) hazards.
- Assessed the risks that come with them using a consistent method.
- Put controls in place based on the hierarchy of controls.
- Got a clear plan for checking if those controls are actually working.
In my experience, auditors will scan for things like specific hazard descriptions, clear risk ratings (both before and after controls), the names of risk owners, and documented review dates. If those key pieces are there and they’re specific to your operations, you’re in a great position.
What’s the Difference Between a Hazard and a Risk?
Nailing this distinction is fundamental. It's one of those things that, once you get it, makes the whole process click into place. The two terms are linked, but they mean very different things, and using them correctly shows you genuinely understand the safety process.
A hazard is anything with the potential to cause harm. Think of it as the source of the danger. A risk is the likelihood that the hazard will actually cause harm, combined with how bad that harm could be (severity).
Let’s use a classic workshop example to make it crystal clear:
- The Hazard: An electrical cord from a power tool is stretched across a main walkway.
- The Risk: The chance that a worker will trip over that cord (likelihood) and suffer anything from a minor bruise to a sprained ankle or even a serious fracture (severity).
Your register needs to first identify the hazard (the cord itself), and then separately analyse the risk it creates (the chance of a trip and injury). This separation is crucial because it ensures you're focused on fixing the root cause, not just reacting to the potential outcome.
Can I Just Use an Excel Spreadsheet for My Risk Register?
Yes, absolutely. For the vast majority of Australian SMEs, a well-structured spreadsheet is a fantastic and completely acceptable tool for managing your risks. It’s cheap, everyone knows how to use it, and you can customise it to perfectly fit your business.
Honestly, the tool you use is far less important than the quality of the information you put into it. While there’s some fancy WHS software out there with all the bells and whistles, a comprehensive and regularly updated spreadsheet is more than enough to meet ISO 45001 requirements.
The trick is to ensure your spreadsheet has all the essential columns we've talked about:
- A unique ID for tracking each hazard
- Clear descriptions of the hazard and the risk
- Your risk analysis (likelihood and severity scores)
- The initial risk rating
- The control measures you have (and plan to add)
- The residual risk rating (after controls)
- A named Risk Owner
- The status and planned review dates
As long as those components are there and you're actively keeping it up to date, a spreadsheet is an excellent choice.
How Often Should We Formally Review Our Entire Risk Register?
This gets to the heart of the "living document" idea in ISO 45001. A risk register gathering dust in a folder is a compliance problem, but more importantly, it's a safety failure. The best approach is to have two types of reviews.
First, you should plan a formal, top-to-bottom review of your entire risk register at least once a year. Many businesses tie this into their annual management review process. It’s your chance to step back, take a high-level look, and make sure the register still makes sense for your business and its goals.
Second—and arguably more important—is treating it as a dynamic document that gets updated whenever things change. A review of specific sections should be immediately triggered by certain events, such as:
- After a workplace incident or a serious near-miss.
- When you bring in new machinery, equipment, or chemicals.
- If you change a work process or standard operating procedure.
- When there are updates to Australian WHS legislation or codes of practice.
- If a new hazard is identified through worker consultation or a safety inspection.
This two-pronged approach—combining event-triggered updates with a full annual review—is what keeps your risk register relevant, accurate, and powerful enough to actually protect your people.
Navigating ISO 45001 and building a risk register that works can be a tough gig. At ISO45001 Consulting, we specialise in taking the guesswork out of the process for Australian SMEs. Our team works alongside you to develop practical, compliant safety systems that fit your business, ensuring you are not just auditor-ready, but genuinely safer. Let us help you achieve certification and win more tenders.

Recent Comments