Is a 22 Page Risk Assessment Suitable?
Long risk assessments often feel safer to write and but can be useless on site. Here is why simplicity is how makes a risk assessment suitable and sufficient, and how to cut yours back without losing anything that matters.
R1SK Team
6 min read
Ask someone on site what the controls are for the job they are about to start. If the answer is "it'll be in the risk assessment somewhere", the risk assessment has already failed.
I have lost count of the documents I have read that run to twenty pages, cite half a dozen regulations, carry a colour-coded matrix nobody can explain, and still do not tell a supervisor what to do differently on a wet Tuesday morning. They exist. They are signed. They are filed. And the person exposed to the hazard has never opened one.
Length is not Always Evidence of Effort
There is a habit in industry of treating page count as proof that you took the risk seriously. It is an understandable instinct. A thick document looks defensible. It feels like it would hold up if something went wrong and someone came asking questions.
It usually does the opposite. A twenty-page assessment that nobody has read gives you a paper trail showing you identified a hazard and then failed to communicate the control. That is a worse position than a one-page document that everyone on the team can recite.
The HSE has never asked for length. Their guidance on managing risk sets out three things: identify what could cause injury or illness, decide how likely harm is and how serious, and take action to remove the hazard or control the risk. Their own downloadable template has five columns. Five. It asks who might be harmed and how, what you are already doing, what more you need to do, who is doing it and by when.
That is the whole job. Everything past it is either genuinely necessary for a complex or high-hazard activity, or it is padding.
Where Padding Comes From
Bloat rarely arrives on purpose. It creeps in:
- Copy-paste from the last job. The previous assessment had a section on confined spaces, so this one does too, even though there is no confined space within a mile of the site.
- Generic hazard libraries. Somebody imports every plausible hazard for the work type and then cannot bring themselves to delete any of them.
- Writing for the wrong reader. The document gets drafted as though an inspector is the audience, when the audience is the operative holding the tool.
- Nobody owns the deletions. Adding a line feels safe. Removing one feels like exposure. So the document only ever grows.
The result is an assessment where the two controls that actually keep someone safe are buried between forty that do not apply.
If a control matters, it should be impossible to miss. Burying it in generic content is a way of hiding it in plain sight.
Suitable and Sufficient is a Test of Use, Not of Volume
"Suitable and sufficient" gets quoted a lot and interrogated rarely. Strip the phrasing back and it is asking whether the assessment does its job in the real world. Have you found the significant risks — the ones that will actually hurt someone, not the theoretical ones? Are the controls proportionate to the work? Are they controls someone can actually apply on site, with the kit and the time they have?
A generic assessment fails that test even when it is long, because it was never about this job. This is exactly why the HSE tells you plainly not to copy one of their worked examples and drop your company name on it. A borrowed document does not protect anybody.
Length has nothing to do with it. A short assessment that names three real hazards and three controls people follow is suitable and sufficient. A long one that names thirty hazards and controls nobody reads is not.
The Test That Counts
Here is the one I use. Walk up to the person doing the work and ask them what the main risks are and what they are doing about them. Do not let them look anything up.
If they can tell you, the assessment is working, whatever it looks like on paper. If they cannot, nothing else about the document matters. Not the version control, not the matrix, not the signature at the bottom. The assessment exists to change what happens on site, and it clearly has not.
That test also tells you where the fix goes. Most of the time the problem is not that the assessor missed a hazard. It is that the assessment was never written to be read by the people it protects.
Simple is Not Necessarily Thin
Worth being clear here, because this argument gets misused. Cutting an assessment back is not the same as cutting corners.
A confined-space entry, a lift plan, a job involving live electrical work — these need detail, and the detail earns its place. Simplicity means every line is there for a reason and a competent person can act on it. It does not mean skipping the hard thinking. The hard thinking is what lets you be brief: you only know which twenty-five hazards to leave out once you have properly worked out which five matter.
Complexity is often the tell that the thinking has not been done. When you are not sure what really matters, listing everything feels like the safe option.
Cutting one back
If you want to test this on a document you already have, try the following.
- Read it as the operative. Not as the author. Would you know what to do differently after reading it?
- Delete anything that is not about this job. Hazards that are not present. Controls for equipment nobody is using. Regulatory quotes that tell nobody what to do.
- Turn every control into an instruction. "Ensure adequate segregation" is not a control. "Barrier the excavation edge to two metres, checked at the start of each shift" is.
- Name who does it and when. A control with no owner is an intention.
- Get it in front of the crew before the job, not after. A briefing where people can push back is worth more than a signature sheet.
- Check it after a fortnight. Ask the crew what the controls are. Their answer is your review.
Most documents lose half their length to step two alone, and get better for it.
The point
A risk assessment is a communication tool that happens to have a legal function, not a legal document that happens to communicate. Once you look at it that way, simplicity stops being a nice-to-have and starts being the thing that determines whether it works.
Write it for the person holding the tool. If they understand it and follow it, the assessment has done what it was always meant to do.
If you want to see how we approach this, our risk assessment tool is built around exactly this principle — clear, usable assessments that people actually read. Or get in touch and we will talk it through.