Who Should Perform a Risk Assessment? Roles, Responsibilities and Legal Requirements

Responsibility for arranging and overseeing a risk assessment sits with the person or organisation controlling the workplace, such as an employer, proprietor, facility manager or designated duty-holder. Competent safety officers and EHS teams typically manage methodology, specialist checks and consistency. Line managers implement controls and maintain day-to-day compliance. Workers and safety representatives contribute hazard reports. External consultants may be engaged for independence or specialist skills. Further sections outline practical checklists, triggers, procurement and documentation to guide action.

Key Takeaways

  • The duty to perform risk assessments lies with the person or organisation controlling the workplace, typically the employer, proprietor, or facility manager.
  • Competent individuals with relevant technical knowledge and experience should conduct assessments, matched to the specific hazards and context.
  • Safety officers and EHS teams coordinate, standardise methodology, and provide specialist assessments and documented recommendations.
  • Line managers must implement, monitor, and maintain controls, with support from worker involvement and safety representatives.
  • External consultants may be procured for independence, specialist skills, or scale, with clear contracts, evidence of competence, and audit trails.

Who Legally Must Arrange a Risk Assessment?

Who is legally required to arrange a risk assessment depends on the jurisdiction and the specific regulatory framework governing the activity or premises; typically, the duty falls on the person or organisation that controls the workplace, premises, operation, or service provision. Responsibility commonly rests with employers, proprietors, facility managers, or contractors who have authority over work environments and activities.

 Regulators often specify duty-holders for particular sectors such as building owners for structural risks, employers for occupational hazards, and event organisers for temporary gatherings. In multi-party settings, legal duties can be shared or allocated by contract, but statutory obligations frequently remain non-delegable, leaving ultimate accountability with the controlling party. Where vulnerable populations are present, heightened obligations may apply.

What Are the Five Steps to Risk Assessment and Why Do They Matter? Compliance usually requires documented assessments, periodic review, and corrective action plans.

Failure to arrange required assessments can trigger enforcement actions, civil liability, or criminal penalties, depending on statutory remedies and the severity of omissions.

Quick Decision Checklist: Who Should Do a Risk Assessment (Five-Step)

Having clarified legal duty-holders, attention turns to a practical five-step checklist for deciding who should carry out a risk assessment. Step 1: Identify the scope, determine the premises, activities and people affected to gauge required expertise. Step 2: Match competence, select someone with relevant technical knowledge, training and experience; use external specialists when complexity exceeds in-house capability. Step 3: Check authority to ensure the chosen person can access the necessary information, make observations, and recommend controls, and that management will act on the findings. Step 4: Verify availability and impartiality, confirm the time allocation for a thorough process, and avoid appointing someone with conflicts of interest that could bias hazard identification or evaluation. Step 5: Confirm documentation and follow-up responsibility, assign who will record the assessment, communicate results and monitor implementation of controls. Applying this checklist produces a defensible, efficient allocation of responsibility while aligning legal duties, practical competence and organisational accountability.

When to Create or Update a Risk Assessment (Triggers & Timing) / Who Should Perform a Risk Assessment

When to Create or Update a Risk Assessment (Triggers & Timing)

Several clear triggers should prompt the creation or review of a risk assessment to confirm it remains accurate and effective. Changes in operations, new equipment, or altered processes can introduce hazards requiring reassessment. Regulatory updates, incident reports, and near misses similarly necessitate prompt review to close gaps. Periodic scheduled reviews confirm ongoing relevance, especially where work patterns or personnel turnover are frequent.

TriggerExampleRecommended Timing
Operational changeNew machinery or processBefore use
Incident or near missInjury or close-callImmediately after the investigation
Regulatory changeNew legal requirementWithin the compliance deadline
Routine reviewAnnual or role changeAt a set interval or on staff turnover

Decision-makers should document the trigger, scope, responsible person, and completion date. Timely updates maintain legal compliance and practical controls, reducing the likelihood of recurrence and supporting informed, defensible safety decisions. If you need the details, read our blog post When Is a Risk Assessment Necessary? A Clear Guide for UK Properties.

Safety Officers & EHS Teams: Risk Assessment Responsibilities

Many organizations assign clear responsibility for managing risk assessments to dedicated safety officers or Environmental, Health, and Safety (EHS) teams, who coordinate hazard identification, evaluate risk levels, and confirm controls are implemented and maintained. These professionals design and maintain the assessment framework, select appropriate methodologies, and ensure consistency across sites and activities. They compile data, conduct specialist assessments for complex hazards, and translate technical findings into actionable recommendations. EHS teams oversee training, provide tools and templates, and support line managers in applying controls without assuming operational decision-making. They also track corrective actions, audit compliance, and update assessments after incidents, regulatory changes, or process modifications. Where statutory reporting or formal certification is required, safety officers liaise with regulators and external auditors. Their role includes documenting the rationale for risk ratings and control selection to create an auditable record. By centralising expertise and quality assurance, safety officers and EHS teams reinforce systematic, legally defensible risk-assessment practices while enabling operational staff to implement day-to-day controls.

Line Managers: Day-to-Day Accountability and Required Actions

Line managers translate policy into practice by implementing and maintaining risk controls within their teams, ensuring daily activities comply with assessed hazards and prescribed safeguards. They are accountable for operationalising assessments: reviewing risk registers, assigning corrective actions, and verifying that controls remain effective during routine work. Line managers schedule and document inspections, escalate unresolved risks, and coordinate with EHS teams to update mitigation measures when processes or exposures change.

  • Conduct regular workplace checks and confirm that control measures function as intended.
  • Assign and monitor completion of corrective actions identified in risk assessments.
  • Maintain records of inspections, training, and incidents relevant to team activities.
  • Escalate complex risk to EHS specialists and enforce temporary controls until resolved.

Workers & Safety Reps: Participation, Reporting and Competency

Effective risk management relies on workers and safety representatives actively participating in risk  identification, reporting unsafe conditions, and demonstrating competency in required controls and procedures. Workers contribute practical knowledge of tasks, equipment, and workarounds; their observations enable timely identification of danger and verification of control effectiveness. Safety representatives act as intermediaries, consolidating workers’ concerns, raising systemic issues with management, and ensuring follow-up on corrective actions. Both roles require clear reporting channels, protection from reprisal, and understanding of incident classification to guarantee consistent documentation. Competency encompasses awareness of relevant risks, training on control measures, and the ability to apply procedures correctly under routine and non-routine conditions. 

Employers must provide accessible training, refresher updates, and opportunities for workers to practice risk controls. Regular participation in risk assessments, toolbox talks, and the review of procedures strengthens collective ownership of safety. Practical expectations focus on active observation, prompt reporting, cooperative engagement in mitigation, and demonstrable skill in executing prescribed safety measures.

When to Hire External Risk Assessment Consultants and What to Expect / Who Should Perform a Risk Assessment

When to Hire External Risk Assessment Consultants and What to Expect

When should an organisation engage external risk assessment consultants? External consultants are appropriate when internal capacity, objectivity, or specialised expertise is insufficient. They supplement in-house teams for complex hazards, regulatory change, mergers, or when independent verification is required.

External consultants typically provide disciplined scoping, hazard identification, quantitative analysis, and practical recommendations. Engagements vary from advisory reviews to full assessments and may include training or implementation support. Expectations should be set up front regarding deliverables, timelines, and confidentiality.

  • Independent perspective to reduce bias and validate internal findings
  • Access to specialised methodologies, tools, or sector-specific experience
  • Scalability for large projects, urgent assessments, or regulatory responses
  • Clear contractual terms covering scope, deliverables, liability, and fees

Procurement should emphasise demonstrable competence, references, and alignment with organisational objectives. Costs and timelines should be balanced against risk exposure and legal obligations. Effective engagements result in actionable controls, transparent assumptions, and measurable follow-up plans.

How to Document Responsibility: Sign-Offs, Evidence and Audit Trails

A clear record of responsibility anchors risk assessment outcomes to specific individuals and decisions: sign-offs, supporting evidence, and audit trails together create traceable accountability from scoping through implementation. Documentation should record who approved each stage, the basis for decisions, timestamps, and any delegation. Sign-off templates and version-controlled records minimise ambiguity: names, roles, dates, and concise statements of acceptance or rejection establish authority.

Supporting evidence links conclusions to data risk matrices, meeting minutes, test results, and correspondence each referenced in the main report. Audit trails capture changes: who edited what, why, and when, preserving rationale for revisions and enabling retrospective review. Confidentiality and retention policies govern access and storage, balancing transparency with legal protection.

Consistent naming conventions, central repositories, and periodic audits reinforce integrity. Clear escalation paths and documented handoffs guarantee that responsibility survives staff turnover. Together, these practices make responsibility verifiable, enforceable, and defensible in operational and legal contexts.   

Frequently Asked Questions

How Much Does a Professional Risk Assessment Typically Cost?

Costs typically range from $1,000 to $50,000 depending on scope, complexity, industry, and deliverables. The assessor’s experience, required testing, travel, and regulatory requirements also influence pricing, with larger enterprises paying more.

Can Risk Assessments Be Automated With Software Tools?

Yes, risk assessments can be automated with software tools that streamline data collection, scoring, and reporting; however, human oversight remains necessary for context, judgment, interpretation, and compliance with legal or organisational requirements.

Are Risk Assessment Results Admissible in Court?

Yes. Courts may admit risk assessment results as evidence, subject to the relevance, reliability, and hearsay rules; admissibility depends on the methodology, expert testimony, documentation, and jurisdictional standards, so the results often require corroboration and expert validation.

How Long Does a Comprehensive Workplace Risk Assessment Take?

A thorough workplace risk assessment typically takes from one day to several weeks, depending on the workplace’s size, complexity, hazards, data availability, and stakeholder engagement; larger or high-risk environments often require more time for meticulous inspection, analysis, and reporting.

Do Insurers Require Specific Risk Assessment Formats or Standards?

Insurers sometimes mandate specific risk assessment formats or standards, often referencing ISO, national regulations, or industry codes; they typically accept equivalent evidence if documentation demonstrates a comparable scope, methodology, and mitigation actions to the insurer’s requirements.

Conclusion

Determining who should perform a risk assessment hinges on legal duties, organisational structure and the nature of hazards. Employers ultimately must guarantee assessments occur, delegating tasks to competent safety officers, EHS teams or trained line managers, with workers and safety representatives participating. External consultants may be engaged for specialist risks. Clear documentation, sign-offs and audit trails establish accountability and evidence of compliance. Regular review and updates guarantee assessments remain valid, proportionate and legally defensible.

Share this :
Picture of Landlord Certifications Editors
Landlord Certifications Editors

LSE Editors are a team of property safety specialists at Landlord Certifications, dedicated to helping landlords stay compliant with UK regulations. With years of hands-on experience in gas safety, EICRs, fire risk assessments, and HMO compliance, they provide practical insights and up-to-date guidance to keep both properties and tenants safe.

Leave a Reply

Your email address will not be published. Required fields are marked *