Risk & Hazard Management

Risk Tolerance and Risk Criteria: A Practical Guide to Workplace Risk Decisions

Risk tolerance and risk criteria provide a structured basis for evaluating workplace risks and deciding what action is required. Clear criteria help organizations compare assessed risks consistently, identify when further treatment is necessary and determine how remaining risk should be escalated, monitored or reviewed.

Fundamentals

What Are Risk Tolerance and Risk Criteria?

Risk criteria are the terms of reference used to evaluate the significance of risk. They provide the basis against which the results of risk analysis can be compared during risk evaluation.

Risk tolerance describes the degree or level of risk that an organization or relevant stakeholder is prepared to bear within a defined context, subject to applicable obligations and requirements.

Together, risk tolerance and risk criteria help translate risk assessment results into consistent decisions about treatment, escalation, monitoring and further action.

Purpose

Why Workplace Risk Decisions Need Defined Criteria

A risk score alone does not determine what an organization should do.

Decision-makers need criteria for interpreting the significance of the assessed risk and determining whether existing controls are sufficient or additional treatment is necessary.

Defined criteria can improve consistency by reducing dependence on individual judgment while still allowing professional judgment to address uncertainty and context.

Key Concepts

Risk Criteria, Risk Tolerance and Risk Evaluation

Risk Criteria

The terms of reference used to evaluate the significance of identified and analyzed risks.

Risk Tolerance

The organization’s or stakeholder’s readiness to bear a defined level of remaining risk within the relevant context.

Risk Evaluation

The comparison of risk analysis results with established criteria to support decisions about further action.

Risk Process

Where Risk Criteria Fit Into Risk Management

Risk criteria should be established early enough to guide the assessment and evaluation process.

Hazards are identified, risks are analyzed and the resulting information is compared with defined criteria. This evaluation supports decisions about whether further treatment, escalation, monitoring or other action is required.

The criteria should remain subject to review as organizational objectives, operating conditions and relevant requirements change.

Context

Define Risk Criteria for the Workplace Context

Risk criteria should reflect the purpose and scope of the activity being assessed.

Relevant considerations can include organizational objectives, the nature of workplace hazards, credible consequences, uncertainty, resources, stakeholder concerns and applicable legal, regulatory, contractual or other requirements.

Criteria designed for one activity or risk type should not automatically be assumed suitable for every other workplace situation.

Requirements

Risk Tolerance Does Not Override Mandatory Requirements

An organization cannot simply define a higher tolerance for risk and use that decision to disregard applicable safety obligations.

Risk criteria should account for relevant legal requirements, standards, policies, contractual obligations and other requirements that apply to the activity.

Where a mandatory requirement establishes a control or performance expectation, internal risk tolerance should be managed within that boundary.

Consequences

Define Consequence Criteria Clearly

Organizations should define how the severity of credible outcomes will be evaluated.

For occupational safety and health risks, consequence criteria may consider injury, occupational illness, exposure or other relevant forms of harm.

Categories should be sufficiently clear that assessors can distinguish between levels consistently without relying on vague descriptions.

Likelihood

Define Likelihood Criteria Consistently

Likelihood criteria should explain how the possibility or frequency of an event will be interpreted within the assessment method.

Organizations should avoid ambiguous categories that different assessors can interpret in substantially different ways.

The available evidence, exposure conditions, operating experience and uncertainty should be considered when determining likelihood.

Risk Matrix

Connect Risk Criteria With the Risk Matrix

Where an organization uses a risk matrix, the matrix should reflect defined likelihood and consequence criteria.

The resulting risk levels can then be connected to decision rules describing the expected response, such as treatment, escalation, monitoring or further analysis.

The numerical or descriptive rating should support judgment rather than substitute for understanding the hazard and control conditions.

Evaluation

Compare Risk Analysis Results With Risk Criteria

Risk evaluation involves comparing the results of analysis with established criteria to determine the significance of the risk and support decisions about further action.

This comparison can help determine whether existing controls appear sufficient, additional treatment is required or the issue needs escalation for further decision-making.

Risk evaluation should consider the quality of the information supporting the assessment and not rely mechanically on a calculated score.

Decision Rules

Define What Different Risk Levels Require

A risk classification is most useful when it is connected to meaningful action.

Organizations can define decision rules describing when work may proceed under established controls, when additional treatment is required, when management review is necessary and when work should not proceed until risk is reduced.

The response should remain proportionate to the nature and significance of the risk.

Risk Tolerance

Define Risk Tolerance Carefully

Risk tolerance should be expressed in a way that supports practical decision-making rather than as a vague statement that certain risks are acceptable.

The organization should understand the conditions, controls and assumptions on which its decision depends.

Tolerance may also differ according to the nature of the objective, consequence and uncertainty involved, subject to applicable requirements.

Serious Harm

Give High-Consequence Risks Appropriate Attention

Low estimated likelihood should not cause credible severe consequences to disappear from management attention.

For high-consequence scenarios, organizations should examine the quality and reliability of important preventive and mitigating controls as well as the assigned risk rating.

Uncertainty in the assessment should also be considered where the consequences of incorrect assumptions could be serious.

Controls

Consider Control Effectiveness in Risk Decisions

A risk assessment may depend heavily on assumptions about existing controls.

Before concluding that risk falls within defined criteria, organizations should have reasonable confidence that important controls are present, suitable and functioning as expected.

A risk rating based on controls that are unavailable or ineffective can create a misleading picture of actual workplace risk.

Residual Risk

Apply Risk Criteria to Residual Risk

After controls are implemented, the remaining risk should be evaluated using relevant criteria.

This helps determine whether additional treatment is necessary and whether the remaining risk requires particular authorization, monitoring or review.

Residual risk decisions should be based on actual control conditions rather than assuming that every planned measure performs perfectly.

Treatment

Use Risk Criteria to Guide Further Treatment

Where evaluation shows that risk requires further action, appropriate treatment should be identified and implemented.

Possible responses can include eliminating the hazard, reducing likelihood, reducing consequences, changing the activity or applying other suitable treatment options.

The treated risk should then be reassessed to determine whether the resulting risk meets the relevant decision criteria.

Escalation

Establish Risk Escalation Requirements

Organizations can define when a risk decision requires review at a higher level of authority.

Escalation may be appropriate when potential consequences are severe, controls are uncertain, important actions remain incomplete or the decision falls outside the authority of the person conducting the assessment.

Clear escalation requirements help ensure significant risk decisions reach people with appropriate authority and access to resources.

Authority

Define Who Can Make Risk Decisions

Decision authority should be proportionate to the significance of the risk.

Routine lower-level risks may be managed through normal operational processes, while significant or uncertain risks may require additional technical or management review.

Organizations should avoid systems in which people are expected to accept risks that exceed their authority or ability to control.

Uncertainty

Account for Uncertainty in Risk Evaluation

Risk assessments are based on available information, assumptions and judgment, all of which can contain uncertainty.

Uncertainty may concern exposure, likelihood, consequences, equipment condition, control effectiveness or the way work is actually performed.

Where uncertainty could materially affect the decision, it should be recognized rather than hidden behind a precise-looking risk score.

Consistency

Apply Risk Criteria Consistently

Defined criteria are valuable only when they are understood and applied with reasonable consistency.

Assessors should use the same definitions for likelihood, consequence and risk levels within the relevant assessment system.

Training, examples, multidisciplinary review and periodic calibration of assessments can help reduce inconsistent interpretation.

Professional Judgment

Do Not Let Risk Criteria Replace Judgment

Risk criteria provide structure, but they cannot capture every feature of a workplace risk.

Assessors should consider the quality of evidence, uncertainty, control dependencies, unusual operating conditions and the potential for severe consequences.

Where the calculated result conflicts with credible evidence about the hazard, the assumptions and assessment method should be examined rather than automatically accepting the score.

Communication

Communicate Risk Criteria to Decision-Makers

People responsible for assessing, supervising or authorizing work should understand how risk criteria are intended to be applied.

Communication should explain the meaning of risk categories, required actions, escalation thresholds and any important limitations of the assessment method.

This helps create a shared understanding of how risk decisions should be made across the organization.

Documentation

Record the Basis for Significant Risk Decisions

Important risk decisions should be sufficiently documented to show the assessment, relevant controls and reasoning behind the resulting action.

The risk register can provide a structured location for recording risk levels, treatments, ownership and review information.

Documentation is particularly useful where decisions depend on specific assumptions, temporary controls or future actions.

Changing Conditions

Reassess Risk When Workplace Conditions Change

A previous risk decision may no longer be valid after significant change.

Changes to equipment, materials, staffing, work methods, production conditions or critical controls can alter likelihood, consequences and the assumptions supporting the assessment.

Relevant risks should therefore be reviewed when change could materially affect their evaluation.

Incident Learning

Review Risk Criteria After Incidents and Near Misses

An incident or near miss can reveal that assumptions about likelihood, consequences or control effectiveness were incomplete.

Investigation findings should be considered when reviewing the affected risk assessment and, where appropriate, the criteria or guidance used for similar risks.

This helps ensure that operational experience improves future risk decisions.

Review

Review Risk Tolerance and Risk Criteria Periodically

Risk criteria should not be treated as permanent simply because they have been incorporated into an established risk matrix or procedure.

Organizations should review them when objectives, operations, requirements, stakeholder expectations or available knowledge change.

Review can also identify categories that are routinely misunderstood or decision rules that no longer support effective risk management.

Practical Framework

A Practical Risk Criteria and Tolerance Process

A structured approach connects organizational context with consistent workplace risk evaluation and action.

01

Define

Establish the assessment context, consequence and likelihood criteria, decision rules and relevant requirements.

02

Analyze

Understand the hazard, credible consequences, likelihood, existing controls and uncertainties affecting the risk.

03

Evaluate

Compare the analysis with defined criteria and determine whether treatment, escalation or other action is required.

04

Review

Monitor controls and assumptions, reassess residual risk and update criteria when the operating context changes.

Common Weaknesses

Common Risk Tolerance and Risk Criteria Mistakes

Treating the Score as the Decision

A calculated rating should support risk evaluation, not replace consideration of hazards, controls, uncertainty and credible consequences.

Using Vague Criteria

Ambiguous likelihood, consequence or decision categories can produce inconsistent assessments and unreliable comparisons.

Ignoring Control Condition

A risk may appear tolerable on paper while depending on controls that are degraded, unavailable or ineffective in actual work.

Key Takeaway

Risk Tolerance and Risk Criteria Support Consistent Workplace Decisions

Risk tolerance and risk criteria help organizations determine how assessed workplace risks should be interpreted and what actions should follow.

Effective criteria reflect the operating context, applicable requirements, credible consequences, likelihood, uncertainty and control effectiveness. They support professional judgment rather than replacing it and should be reviewed as workplace conditions and risk information change.

IOSHQ Knowledge Center

Explore Risk & Hazard Management Resources

Continue learning about risk criteria, risk tolerance, workplace risk assessment, risk treatment and control effectiveness through the IOSHQ Knowledge Center.

Comments are disabled