Risk Tolerance and Risk Criteria: A Practical Guide to Workplace Risk Decisions
Risk tolerance and risk criteria provide a structured basis for evaluating workplace risks and deciding what action is required. Clear criteria help organizations compare assessed risks consistently, identify when further treatment is necessary and determine how remaining risk should be escalated, monitored or reviewed.
What Are Risk Tolerance and Risk Criteria?
Risk criteria are the terms of reference used to evaluate the significance of risk. They provide the basis against which the results of risk analysis can be compared during risk evaluation.
Risk tolerance describes the degree or level of risk that an organization or relevant stakeholder is prepared to bear within a defined context, subject to applicable obligations and requirements.
Together, risk tolerance and risk criteria help translate risk assessment results into consistent decisions about treatment, escalation, monitoring and further action.
Why Workplace Risk Decisions Need Defined Criteria
A risk score alone does not determine what an organization should do.
Decision-makers need criteria for interpreting the significance of the assessed risk and determining whether existing controls are sufficient or additional treatment is necessary.
Defined criteria can improve consistency by reducing dependence on individual judgment while still allowing professional judgment to address uncertainty and context.
Risk Criteria, Risk Tolerance and Risk Evaluation
Risk Criteria
The terms of reference used to evaluate the significance of identified and analyzed risks.
Risk Tolerance
The organization’s or stakeholder’s readiness to bear a defined level of remaining risk within the relevant context.
Risk Evaluation
The comparison of risk analysis results with established criteria to support decisions about further action.
Where Risk Criteria Fit Into Risk Management
Risk criteria should be established early enough to guide the assessment and evaluation process.
Hazards are identified, risks are analyzed and the resulting information is compared with defined criteria. This evaluation supports decisions about whether further treatment, escalation, monitoring or other action is required.
The criteria should remain subject to review as organizational objectives, operating conditions and relevant requirements change.
Define Risk Criteria for the Workplace Context
Risk criteria should reflect the purpose and scope of the activity being assessed.
Relevant considerations can include organizational objectives, the nature of workplace hazards, credible consequences, uncertainty, resources, stakeholder concerns and applicable legal, regulatory, contractual or other requirements.
Criteria designed for one activity or risk type should not automatically be assumed suitable for every other workplace situation.
Risk Tolerance Does Not Override Mandatory Requirements
An organization cannot simply define a higher tolerance for risk and use that decision to disregard applicable safety obligations.
Risk criteria should account for relevant legal requirements, standards, policies, contractual obligations and other requirements that apply to the activity.
Where a mandatory requirement establishes a control or performance expectation, internal risk tolerance should be managed within that boundary.
Define Consequence Criteria Clearly
Organizations should define how the severity of credible outcomes will be evaluated.
For occupational safety and health risks, consequence criteria may consider injury, occupational illness, exposure or other relevant forms of harm.
Categories should be sufficiently clear that assessors can distinguish between levels consistently without relying on vague descriptions.
Define Likelihood Criteria Consistently
Likelihood criteria should explain how the possibility or frequency of an event will be interpreted within the assessment method.
Organizations should avoid ambiguous categories that different assessors can interpret in substantially different ways.
The available evidence, exposure conditions, operating experience and uncertainty should be considered when determining likelihood.
Connect Risk Criteria With the Risk Matrix
Where an organization uses a risk matrix, the matrix should reflect defined likelihood and consequence criteria.
The resulting risk levels can then be connected to decision rules describing the expected response, such as treatment, escalation, monitoring or further analysis.
The numerical or descriptive rating should support judgment rather than substitute for understanding the hazard and control conditions.
Compare Risk Analysis Results With Risk Criteria
Risk evaluation involves comparing the results of analysis with established criteria to determine the significance of the risk and support decisions about further action.
This comparison can help determine whether existing controls appear sufficient, additional treatment is required or the issue needs escalation for further decision-making.
Risk evaluation should consider the quality of the information supporting the assessment and not rely mechanically on a calculated score.
Define What Different Risk Levels Require
A risk classification is most useful when it is connected to meaningful action.
Organizations can define decision rules describing when work may proceed under established controls, when additional treatment is required, when management review is necessary and when work should not proceed until risk is reduced.
The response should remain proportionate to the nature and significance of the risk.
Define Risk Tolerance Carefully
Risk tolerance should be expressed in a way that supports practical decision-making rather than as a vague statement that certain risks are acceptable.
The organization should understand the conditions, controls and assumptions on which its decision depends.
Tolerance may also differ according to the nature of the objective, consequence and uncertainty involved, subject to applicable requirements.
Give High-Consequence Risks Appropriate Attention
Low estimated likelihood should not cause credible severe consequences to disappear from management attention.
For high-consequence scenarios, organizations should examine the quality and reliability of important preventive and mitigating controls as well as the assigned risk rating.
Uncertainty in the assessment should also be considered where the consequences of incorrect assumptions could be serious.
Consider Control Effectiveness in Risk Decisions
A risk assessment may depend heavily on assumptions about existing controls.
Before concluding that risk falls within defined criteria, organizations should have reasonable confidence that important controls are present, suitable and functioning as expected.
A risk rating based on controls that are unavailable or ineffective can create a misleading picture of actual workplace risk.
Apply Risk Criteria to Residual Risk
After controls are implemented, the remaining risk should be evaluated using relevant criteria.
This helps determine whether additional treatment is necessary and whether the remaining risk requires particular authorization, monitoring or review.
Residual risk decisions should be based on actual control conditions rather than assuming that every planned measure performs perfectly.
Use Risk Criteria to Guide Further Treatment
Where evaluation shows that risk requires further action, appropriate treatment should be identified and implemented.
Possible responses can include eliminating the hazard, reducing likelihood, reducing consequences, changing the activity or applying other suitable treatment options.
The treated risk should then be reassessed to determine whether the resulting risk meets the relevant decision criteria.
Establish Risk Escalation Requirements
Organizations can define when a risk decision requires review at a higher level of authority.
Escalation may be appropriate when potential consequences are severe, controls are uncertain, important actions remain incomplete or the decision falls outside the authority of the person conducting the assessment.
Clear escalation requirements help ensure significant risk decisions reach people with appropriate authority and access to resources.
Define Who Can Make Risk Decisions
Decision authority should be proportionate to the significance of the risk.
Routine lower-level risks may be managed through normal operational processes, while significant or uncertain risks may require additional technical or management review.
Organizations should avoid systems in which people are expected to accept risks that exceed their authority or ability to control.
Account for Uncertainty in Risk Evaluation
Risk assessments are based on available information, assumptions and judgment, all of which can contain uncertainty.
Uncertainty may concern exposure, likelihood, consequences, equipment condition, control effectiveness or the way work is actually performed.
Where uncertainty could materially affect the decision, it should be recognized rather than hidden behind a precise-looking risk score.
Apply Risk Criteria Consistently
Defined criteria are valuable only when they are understood and applied with reasonable consistency.
Assessors should use the same definitions for likelihood, consequence and risk levels within the relevant assessment system.
Training, examples, multidisciplinary review and periodic calibration of assessments can help reduce inconsistent interpretation.
Do Not Let Risk Criteria Replace Judgment
Risk criteria provide structure, but they cannot capture every feature of a workplace risk.
Assessors should consider the quality of evidence, uncertainty, control dependencies, unusual operating conditions and the potential for severe consequences.
Where the calculated result conflicts with credible evidence about the hazard, the assumptions and assessment method should be examined rather than automatically accepting the score.
Communicate Risk Criteria to Decision-Makers
People responsible for assessing, supervising or authorizing work should understand how risk criteria are intended to be applied.
Communication should explain the meaning of risk categories, required actions, escalation thresholds and any important limitations of the assessment method.
This helps create a shared understanding of how risk decisions should be made across the organization.
Record the Basis for Significant Risk Decisions
Important risk decisions should be sufficiently documented to show the assessment, relevant controls and reasoning behind the resulting action.
The risk register can provide a structured location for recording risk levels, treatments, ownership and review information.
Documentation is particularly useful where decisions depend on specific assumptions, temporary controls or future actions.
Reassess Risk When Workplace Conditions Change
A previous risk decision may no longer be valid after significant change.
Changes to equipment, materials, staffing, work methods, production conditions or critical controls can alter likelihood, consequences and the assumptions supporting the assessment.
Relevant risks should therefore be reviewed when change could materially affect their evaluation.
Review Risk Criteria After Incidents and Near Misses
An incident or near miss can reveal that assumptions about likelihood, consequences or control effectiveness were incomplete.
Investigation findings should be considered when reviewing the affected risk assessment and, where appropriate, the criteria or guidance used for similar risks.
This helps ensure that operational experience improves future risk decisions.
Review Risk Tolerance and Risk Criteria Periodically
Risk criteria should not be treated as permanent simply because they have been incorporated into an established risk matrix or procedure.
Organizations should review them when objectives, operations, requirements, stakeholder expectations or available knowledge change.
Review can also identify categories that are routinely misunderstood or decision rules that no longer support effective risk management.
A Practical Risk Criteria and Tolerance Process
A structured approach connects organizational context with consistent workplace risk evaluation and action.
Define
Establish the assessment context, consequence and likelihood criteria, decision rules and relevant requirements.
Analyze
Understand the hazard, credible consequences, likelihood, existing controls and uncertainties affecting the risk.
Evaluate
Compare the analysis with defined criteria and determine whether treatment, escalation or other action is required.
Review
Monitor controls and assumptions, reassess residual risk and update criteria when the operating context changes.
Common Risk Tolerance and Risk Criteria Mistakes
Treating the Score as the Decision
A calculated rating should support risk evaluation, not replace consideration of hazards, controls, uncertainty and credible consequences.
Using Vague Criteria
Ambiguous likelihood, consequence or decision categories can produce inconsistent assessments and unreliable comparisons.
Ignoring Control Condition
A risk may appear tolerable on paper while depending on controls that are degraded, unavailable or ineffective in actual work.
Risk Tolerance and Risk Criteria Support Consistent Workplace Decisions
Risk tolerance and risk criteria help organizations determine how assessed workplace risks should be interpreted and what actions should follow.
Effective criteria reflect the operating context, applicable requirements, credible consequences, likelihood, uncertainty and control effectiveness. They support professional judgment rather than replacing it and should be reviewed as workplace conditions and risk information change.
Explore Risk & Hazard Management Resources
Continue learning about risk criteria, risk tolerance, workplace risk assessment, risk treatment and control effectiveness through the IOSHQ Knowledge Center.
