Quick Summary: A risk register is a central document for managing workplace hazards. It lists potential dangers, analyzes their impact, and outlines actions to ensure safety. Key components include hazard identification, risk ratings (likelihood and consequence), control measures, designated risk owners, and review dates. It is a foundational tool for proactive safety management and essential for achieving ISO 45001 certification.

At its core, understanding what is included in a risk register is about telling a clear story for each identified hazard. It's the central document for your Occupational Health and Safety (OHS) management system. You get a snapshot of the hazard itself, the potential consequences if something goes wrong, a rating of its likelihood and severity, and a breakdown of the control measures you have in place.

The Foundation of Proactive Safety Management

Don't think of a risk register as just another compliance document gathering dust. It's more like a pilot's pre-flight checklist. Before a plane ever leaves the tarmac, the crew meticulously runs through every potential issue—from the engine status to the weather forecast—to ensure the journey is safe. That’s exactly what a risk register does for your business; it lets you systematically identify, analyse, and control workplace hazards before they turn into incidents. This shift from reacting to preventing is the very heart of modern safety management.

This isn't just a "nice-to-have," especially for businesses in high-risk industries like construction, manufacturing, or field services. It's a non-negotiable tool that provides a clear, documented trail of how you’re meeting your safety obligations. This is about more than just preventing injuries; it’s about building a resilient, trustworthy, and professional operation.

Why It’s a Non-Negotiable Tool

A well-maintained risk register is absolutely fundamental to achieving and keeping your ISO 45001 certification. The standard is very clear: it requires organisations to have a solid process for identifying hazards and assessing OHS risks and opportunities. Your risk register is the primary evidence you'll present to show you’re meeting this critical requirement. It proves to auditors, clients, and regulators that you have a structured, intelligent system in place.

Without one, you're always on the back foot, simply reacting to problems as they happen. A dynamic, well-used register flips the script and allows you to:

  • Prioritise your resources by focusing time and money on the most significant risks first.
  • Assign clear ownership for managing specific hazards, which drives accountability.
  • Track the effectiveness of your safety controls over time to see what’s working and what isn’t.
  • Build a safety-conscious culture where everyone understands their role in managing risk.

Ultimately, understanding what goes into a risk register and keeping it up to date helps you navigate any potential turbulence—from workplace incidents to regulatory penalties—ensuring a safer, more efficient, and more successful operation.

The Core Components Every Risk Register Must Include

Alright, let's move past the theory and get practical. A truly useful risk register isn't just a tick-the-box exercise; it's a dynamic tool built from a handful of essential components. Each field, or column, in your register has a specific job to do, and together, they paint a clear picture of your workplace safety landscape.

Understanding what is included in a risk register is your first step. It’s what turns a static document into a living, breathing part of your safety management system.

The whole process really boils down to three key stages: identifying the hazard, analysing its potential harm, and then doing something about it (mitigation). This is the fundamental loop that keeps your workplace safe.

A concept map illustrates the OHS Risk Register process, connecting identify, analyze, and mitigate steps.

As you can see, one step naturally flows into the next. This logical progression is what ensures no hazard gets missed or left to chance. Now, let’s break down the specific fields that make this process come to life.

Hazard Identification And Description

This is ground zero. You can't manage a risk you haven't seen, so the first column is all about clearly describing the hazard. Generic entries like "workshop danger" or "machine risk" are completely useless here. You need to be specific.

For instance, instead of just writing "forklift," describe the actual problem: "Unsafe operation of forklift in a shared pedestrian walkway." See the difference? That single sentence gives us context, pinpointing the unsafe action, the equipment involved, and the specific location where it’s a problem.

Risk Analysis: Likelihood And Consequence

Once you’ve identified a hazard, you need to figure out how big of a problem it really is. This is where you analyse the risk, and it usually comes down to two simple questions:

  • Likelihood: How likely is it that something will go wrong? We often rate this on a scale, say 1 (Rare) to 5 (Almost Certain).
  • Consequence (or Severity): If it does go wrong, how bad will it be? Again, a simple scale works best, like 1 (Minor First Aid) up to 5 (Fatality).

Multiply those two numbers together, and you get your initial risk rating. This simple score is incredibly powerful—it instantly tells you which hazards are ticking time bombs and need your immediate attention.

A common mistake is to over-engineer the scoring. A simple 5×5 matrix that everyone understands and uses consistently is far more effective than a complex system that just gathers dust.

Control Measures And Risk Owner

This is where the register stops being a list and becomes an action plan. For every hazard you’ve identified, you need to document what you’re already doing to control it. These are your control measures—things like guard rails, lockout-tagout procedures, mandatory PPE, or specific training programs.

Just as importantly, every risk needs an owner. This isn't a department; it's a person. Assigning a name creates real accountability and makes it crystal clear who is responsible for ensuring the controls are working. For a more detailed walkthrough, our guide on how to create a risk register takes you through the nuts and bolts.

Status And Action Plan

Your risk register should never be static. The status column is what keeps it alive, showing whether a risk is 'Open', 'Under Review', or 'Closed'. This gives you a quick, at-a-glance dashboard of your safety efforts.

For any risk that isn't closed, the action plan column is your roadmap. It should spell out exactly what needs to be done, who is going to do it, and by when. This is precisely what auditors want to see—not just a list of problems, but clear evidence that you have a plan to fix them. While the context here is OHS, the core principles of managing threats are universal, as detailed in resources like this Microsoft 365 Security Risk Management Guide, which offers insights applicable to any risk management process.

To tie this all together, here's a quick summary of the essential fields your register should have.

ComponentPurpose and Description
Hazard DescriptionA specific, clear statement identifying the potential source of harm. Avoid vague terms.
ConsequencesWhat could happen if the hazard is realised? Describe the potential injuries or health effects.
LikelihoodThe probability of an incident occurring. Typically rated on a numerical scale (e.g., 1-5 from Rare to Almost Certain).
SeverityThe seriousness of the potential outcome if an incident occurs. Also rated on a scale (e.g., 1-5 from Minor Injury to Fatality).
Risk RatingThe calculated score (Likelihood x Severity) that determines the priority level of the risk.
Current ControlsThe existing measures in place to mitigate the risk (e.g., PPE, guarding, procedures).
Risk OwnerThe specific person accountable for managing the risk and ensuring controls are effective.
StatusThe current state of the risk (e.g., Open, Under Review, Closed). Provides a quick progress check.
Action PlanThe detailed steps required to further reduce the risk, including who is responsible and the deadline.
Residual RiskThe risk level after new controls have been implemented. This shows the effectiveness of your actions.
Review Dates & HistoryA log of when the risk was last reviewed and any changes made. This is critical for demonstrating ongoing management and is a key requirement for ISO 45001.

These components form the foundation of a risk register that not only satisfies auditors but actively helps you create a safer workplace.

Real-World Examples from Australian Industries

Theory is a great starting point, but the true value of a risk register really clicks when you see it in action. To get a practical handle on what is included in a risk register, let’s walk through some real-world scenarios from Aussie industries where safety isn't just a policy—it's everything. These examples show how a simple document can prevent serious harm.

The statistics from Safe Work Australia paint a sobering picture. Between 2013 and 2023, more than 1,850 workers lost their lives in traumatic incidents on the job. The manufacturing and construction sectors were hit particularly hard, making up a combined 45% of these devastating fatalities. You can dig deeper into these numbers over at the official Safe Work Australia data portal.

A construction worker in a hard hat and high-vis vest uses a tablet on an industry job site.

This data isn't just a number; it's a powerful reminder of why getting risk management right is absolutely non-negotiable.

Construction Site: Working at Heights

Working at heights is a daily reality on most building sites, and it's a textbook example of a high-stakes hazard. Here’s how a site manager might break it down in their risk register.

  • Hazard Identification: "Working on an unprotected edge of a second-storey building slab to install framework." Notice how specific that is. It’s not just "working at height"; it details the task, the location, and the precise danger.
  • Risk Analysis: A fall is maybe 'Possible' (3/5), but the outcome is 'Catastrophic' (5/5). Multiplying those gives you an initial risk rating of 15 (Extreme). That score is an immediate red flag—an unacceptable risk that needs to be dealt with before anyone goes near that edge.
  • Control Measures: The register would list the standard stuff, like mandatory site inductions and wearing a fall arrest harness. But that high score tells us it's not enough.
  • Action Plan: This is where the real work happens. "Install temporary edge protection (guardrails) along all open edges before framing work commences. Action by: Site Supervisor. Due Date: [Date]."
  • Residual Risk: With the guardrails installed and checked, the likelihood of a fall plummets to 'Rare' (1/5). Now, the residual risk score is just 5 (Low). Work can now proceed safely.

Manufacturing Plant: Machine Entanglement

Step into any manufacturing plant, and you'll see people working with and around machinery. It's a constant dance between productivity and risk.

A great risk register entry doesn't just say a machine is dangerous. It pinpoints the specific human interaction that creates the risk. That level of detail is what makes your controls truly effective.

Let's think about a common scenario involving a conveyor belt system.

  • Hazard Identification: "Operator cleaning debris from a moving conveyor belt, creating a risk of hand or clothing entanglement."
  • Risk Analysis: If there are no clear rules, an incident is 'Likely' (4/5) and the consequence 'Major' (4/5). That puts the risk rating at 16 (Extreme).
  • Control Measures: Maybe there’s a basic safety sign, but that’s it. The action plan here is to implement a formal lockout-tagout (LOTO) procedure. This ensures the machine is fully de-energised and physically locked before anyone attempts to clean it.
  • Risk Owner: The Production Manager is assigned ownership. It's their job to make sure everyone is trained on the LOTO system and that it's being used correctly every single time.
  • Residual Risk: With a strictly enforced LOTO system in place, the likelihood of entanglement becomes 'Rare' (1/5), which drops the residual risk down to 4 (Low).

While these examples cover common ground, the same principles apply everywhere. For those in more specialised fields, our guide on creating a risk register for mining and quarrying offers more targeted insights.

Integrating Modern Threats into Your Register

A truly effective risk register goes beyond just ticking boxes for physical hazards like slippery floors or unguarded machinery. To keep your business safe and resilient today, your register needs to tackle the modern threats that can just as easily shut you down—think cybersecurity and workforce challenges. Knowing what is included in a risk register now means taking a much broader view of potential harm.

Imagine this: a ransomware attack locks you out of your entire safety management system. Suddenly, all your Safe Work Method Statements (SWMS), incident reports, and worker training records are gone. This isn't just an IT headache; it's a massive OHS failure waiting to happen, leaving you unable to manage safety on site or protect sensitive employee data.

The same goes for people problems. High staff turnover, skills shortages, or shoddy training aren't just HR issues; they are serious operational risks. A team of new or inexperienced people is far more likely to miss a critical safety check or make a costly mistake.

Expanding Your View of Cybersecurity Risks

Cyber threats are no longer a side issue for Australian businesses; they're a direct hit to the bottom line and operational safety. According to the Office of the Australian Information Commissioner (OAIC), there were a staggering 1,113 notifiable data breaches in the year leading up to June 2024. That’s a 25% jump from the year before and the highest number recorded since the scheme kicked off in 2018.

This data highlights why cybersecurity can't be kept in a separate box from OHS. It's a direct threat to your ability to operate and keep your safety data intact.

So, how do you get this into your register? Start adding entries that look something like this:

  • Hazard: Ransomware attack on our cloud-based safety management system.
  • Consequence: Can't access safety procedures, incident logs, or worker certifications. This could lead to non-compliant work and a serious injury.
  • Control: Regular offline backups of all critical data, multi-factor authentication for all users, and ongoing cyber awareness training for staff.

Addressing Workforce and Human Capital Risks

A stable team is one of your best safety assets. When you have high staff turnover, you're stuck in a constant loop of training new people, which drains your business of deep-seated knowledge and makes mistakes more likely.

A stable, well-trained workforce is one of your most effective safety controls. When people know their jobs, their equipment, and each other, they are better equipped to identify and manage hazards proactively.

Think about adding these kinds of risks to your register:

  • Hazard: Critical skills shortage for specialised machinery operators.
  • Consequence: Unqualified staff trying to handle complex tasks, potentially leading to equipment damage or a severe injury.
  • Control: Create a documented succession plan, invest in cross-training programs, and maybe even partner with local TAFEs to build a pipeline of talent.

A huge part of managing these people-related threats is putting solid employee retention strategies in place. This helps you hang on to valuable knowledge and maintain consistent safety practices. By treating these modern challenges with the same seriousness as traditional physical hazards, you build a much stronger, more resilient business.

Getting Your Risk Register Ready for Audits and Certification

Putting together a risk register is one thing, but using it to sail through an audit is where the rubber really hits the road. Whether you're facing an internal spot-check or the scrutiny of an ISO 45001 certification audit, your register is the star witness for your safety management system. It tells the complete story of how you handle occupational health and safety (OHS).

Auditors are sharp; they can spot a token effort a mile away. They're looking for a 'living' document—one that’s clearly part of your day-to-day operations, not a dusty spreadsheet that was hastily updated the night before they arrived. That’s an immediate red flag.

Two professionals in safety vests collaboratively reviewing documents and a laptop, ready for an audit.

What they're after is clear, documented proof that your safety processes are working exactly as you say they are.

What Auditors Look For

When an auditor reviews your risk register, they’re not just ticking boxes. They’re looking for a clear, logical story. They want to see that you have a robust, closed-loop system where risks are spotted, managed, and constantly re-evaluated.

Here’s a quick checklist of what will be on their radar:

  • A Systematic Process: Is there a consistent method? They'll check that you're methodically identifying hazards, analysing the risk, and putting appropriate controls in place for each one.
  • Clear Assignment of Responsibilities: Every serious risk needs a named risk owner. This isn't just about passing the buck; it proves accountability, which is a cornerstone of ISO 45001.
  • Completed Actions: A long list of overdue tasks on your action plan is a sign of a failing system. Auditors need to see evidence that you actually follow through and close things out.
  • A History of Regular Reviews: That review history column is more important than you think. It's the proof that safety management is an ongoing conversation in your business, not a one-and-done task.

Your risk register is more than a list of what could go wrong. To an auditor, it’s a detailed record of your commitment to preventing it. It should tell a story of continuous improvement, not just compliance.

Presenting Your Register Effectively

To really nail the audit, you need to show how your risk register connects with everything else you do. Think of it as the central hub of your OHS system. For example, if a safety incident occurred, an auditor will look for a corresponding update in the register. Did you review the risk? Did you add new controls as a result?

Showing this connectivity proves your safety management is a cohesive ecosystem, not just a bunch of standalone documents. It also shows you’re thinking about modern-day issues. For instance, workforce stability is a huge one right now. Aon's recent survey flagged the failure to attract and retain top talent as a major risk for Australian businesses, which has a direct knock-on effect on safety and operations. You can dig into the complete findings about Australian business risks to see just how interconnected these challenges are.

Ultimately, a well-kept register is your best friend for achieving certification and, more importantly, for building a genuinely safer workplace. It shifts the focus from "what is included in a risk register?" to "how does our risk register actively drive our safety culture?".

Common Questions About Building a Risk Register

Even with a great template in hand, putting theory into practice always throws up a few questions. Building your first risk register can feel a bit intimidating, so we’ve pulled together answers to the queries we hear most often from our clients. The idea is to tackle these common sticking points head-on, giving you the confidence to build a tool that’s not just compliant, but genuinely useful.

After all, getting these details right is crucial for creating a document that will stand up to the scrutiny of an ISO 45001 audit.

How Often Should I Review My Risk Register?

There isn't a single "correct" answer here; the right frequency really depends on your operational rhythm and risk level. That said, a good rule of thumb is to schedule a formal review at least annually.

For businesses with higher-risk activities, like in construction or manufacturing, a quarterly or even monthly review makes a lot more sense. But more importantly, you need to treat your risk register as a living document. It should be updated immediately whenever:

  • An incident or a near-miss happens on site.
  • New machinery, processes, or chemicals are introduced.
  • There are significant changes to Australian WHS legislation.

Auditors won't just check your review schedule; they'll want to see real evidence that you're actually following it.

What Is the Difference Between a Hazard and a Risk?

This is one of the most fundamental concepts in OHS, and it's essential to get it straight. The easiest way to think about it is like this:

A hazard is the thing that has the potential to cause harm. A risk is the chance of that harm actually happening, combined with how bad it would be.

So, a wet floor is a hazard. The risk is someone slipping, falling, and breaking their arm. The whole point of your register is to identify the hazards, then analyse the related risks to figure out which ones need your attention first.

Can I Just Use an Excel Spreadsheet?

Absolutely. For most small to medium-sized Australian businesses, a well-structured Excel or CSV file is a perfectly practical and compliant tool. The software you use is far less important than the quality of the information you put into it and the consistency of your process.

As long as your spreadsheet contains all the core components we’ve discussed—covering everything from hazard identification to review history—is easy to read, and is accessible to the right people, it will definitely meet ISO 45001 standards.


At ISO45001 Consulting, we help Australian businesses move beyond templates to build safety systems that actually work. If you need expert guidance to prepare for your certification audit, contact us to see how we can help you achieve a 100% success rate.