Skip to main content

Conducting a risk assessment

A risk assessment in ReFresh follows the Code of Practice cycle: identify, assess, control, review. You rate a hazard's risk before controls (inherent) and after controls (residual), then move it through a defined lifecycle.

Written by Taylor Laing

Where assessments live

Risk assessments are managed from the Risk Register (admin sidebar → Risks). From there you can open an existing risk to assess it, or create a new one. See Using the risk register.

Creating and setting up a risk

You can create a risk in three ways:

  • Adopt a scenario from the scenario library, which arrives pre-populated and ready to assess; see Adopting risks from the scenario library

  • Activate a framework, which seeds its required risks into your register

  • Create a custom risk from scratch

New custom risks are taken through a short Set Up wizard before assessment. It has three steps:

  1. Identify: name, short description, description, hazard categories, and owner.

  2. Scope and Schedule: confirm the scope on the group tree and record the workers exposed (a prioritisation signal that does not change the rating); set a Review Frequency (As needed, Daily, Monthly, Quarterly, or Yearly) with a note on why; and pick a Target Hierarchy level (Elimination, Substitution, Engineering, Administrative, or Personal).

  3. Confirm and Save: review a summary, then choose what happens when you save: keep it as a draft, mark it as Identified, or start the assessment straight away.

Assessing the risk

Assessment happens in the Assess wizard, which scores the risk against a matrix of likelihood and consequence. It runs as two separate passes, each with the same two steps (an exposure step then Confirm and Save):

  1. Inherent Exposure → Confirm and Save

  2. (link your controls) then Residual Exposure → Confirm and Save

Between the two passes the app prompts you to link the controls that are in place before you rate residual exposure.

Likelihood

Likelihood is derived, not picked directly. You choose how often and how long people are exposed, and ReFresh calculates the likelihood from them:

  • Frequency (required): Rare, Occasional, Regular, Frequent, Constant

  • Duration (optional): Minimal, Short Term, Medium Term, Long Term, Ongoing

The derived likelihood is displayed with its own vocabulary: Almost impossible, Unlikely, Possible, Likely, Almost certain.

Why Duration is optional: Whether Duration appears at all is a tenant setting. Under Settings → Company, the 3-Axis Risk Rating toggle switches between the Comcare-aligned three-axis model (Duration by Frequency by Severity) and a two-axis model (Frequency by Severity). When it is off, the Duration input disappears across the assess wizard and the rating maths, and likelihood is derived from Frequency alone. See Company settings and global configuration.

Consequence

Consequence is set by Severity, the severity of harm if the hazard is realised: Insignificant, Minor, Moderate, Major, Catastrophic.

The matrix and rating bands

Likelihood and consequence combine on a 5×5 risk matrix, Likelihood (vertical axis) by Consequence (horizontal axis), to produce an overall rating. The result falls into one of four rating bands, each with its own colour: Low (green), Medium (amber), High (orange), Critical (red). A "How this rating is calculated" panel explains each result in plain language; for the full breakdown of how likelihood is derived and how the bands are set, see How risk ratings are calculated.

Inherent vs residual

You rate the risk twice, on separate inputs. Each pass has its own full frequency/duration/severity inputs and its own derived rating:

  • Inherent risk: the risk before any controls are applied.

  • Residual risk: the risk that remains after your controls are in place, rated on the same matrix.

Residual is soft-gated: after you set inherent, the app prompts you to link controls before rating residual, but you can proceed without them (it warns you're rating a hypothesis). Both ratings then appear on the Risk Register as the Inherent and Residual columns.

Treatment

Choose how you'll respond to the risk: Accept, Mitigate, Transfer, or Avoid. The treatment you pick guides the controls and tasks you attach, and is set when the risk moves into the Treating stage.

Status lifecycle

As you work a risk, it moves through a lifecycle. The status stepper shows six stages: Draft → Identified → Assessing → Treating → Monitoring → Closed. (Behind the scenes the status can also be Accepted or Archived, which the six-stage stepper rolls up.)

Save your changes to advance the assessment; the risk's status updates accordingly.

Where you can assess

Risks are scoped to a level of your organisation using the group tree in the Set Up wizard:

  • Whole organisation: the recommended starting point for a first assessment

  • Group-specific: a particular team, site, or division

Group-scoped risks roll up into the organisation-wide register.

Linking to controls, consultation, and evidence

A risk assessment is the structured starting point. As you work it, link the risk to:

  • Controls that mitigate it

  • Consultations that informed the assessment

  • Incidents that materialised from the risk

  • Evidence (Records) that supports the rating

These links surface in the risk's detail view and feed your audit trail.

Did this answer your question?