Types of Risk Assessment: Methods, Tools, and When to Use Each
By Mehreen Iqbal
| 3 Sep 2026
A clear breakdown of risk assessment types by approach, workplace context, and specific method, with a comparison table and guidance on choosing one.
A clear breakdown of risk assessment types by approach, workplace context, and specific method, with a comparison table and guidance on choosing one.

Search "types of risk assessment" and the answer changes depending on which article you land on: three types, five, six, nine, sometimes ten. None of these sources are wrong exactly; they're just counting different things under the same word.

In this article, we sort risk assessment into the five categories that actually matter: by analytical approach, by workplace context, by legal trigger, by specific tool or method, and by the type of risk itself. Then we'll explain why the count depends entirely on which of those five you're asking about.

Key takeaways

  • Risk assessment types split into five distinct categories: analytical approach (qualitative, quantitative, semi-quantitative), workplace context (generic, site-specific, dynamic), legal trigger (fire, COSHH, DSE, manual handling, and others), named tools or methods (HAZOP, FMEA, Bowtie, and others), and the type of risk being assessed (safety, financial, operational, and more).
  • The "how many types" confusion exists because different sources count within different categories without saying so.
  • No regulatory framework mandates one specific method. The UK's Management of Health and Safety at Work Regulations 1999 (reg 3) and US OSHA regulations both require a risk assessment to happen, not a particular technique for doing it. ISO 31000 sits alongside these as voluntary international guidance, not a regulation, and it's method-neutral for the same underlying reason.
  • A risk matrix is a tool that supports a qualitative or semi-quantitative approach, not a separate type sitting alongside them.
  • Choosing the right method depends on the hazard's severity, the data actually available, and who needs to understand the result.

What Is a Risk Assessment?

What Is a Risk Assessment?

A risk assessment is a structured process for identifying hazards and evaluating how likely they are to cause harm, along with how severe that harm would be. It also involves deciding what controls reduce that risk to an acceptable level.

ISO 31000 frames this as three linked steps: risk identification, risk analysis, and risk evaluation. Every method covered in this article is a different way of carrying out that same underlying process, not a competing definition of what a risk assessment actually is.

How Many Types of Risk Assessment Are There?

There's no single correct number, but there is a highest-authority answer. IEC 31010:2019, the international standard that catalogues risk assessment techniques as a companion to ISO 31000, lists 41 distinct techniques in its Annex, ranging from simple checklists to full quantitative modeling.

Most sources answering this question aren't citing that standard, though; they're citing a much smaller subset filtered through whichever lens they happen to be using.

Sources citing "3 types" are almost always describing an analytical approach: qualitative, quantitative, and semi-quantitative.

Sources citing "5" or "6" typically add workplace context on top of that: generic, site-specific, and dynamic assessments.

Sources citing "9" or "10" have usually stopped talking about types altogether and started listing named tools, a small slice of IEC 31010's actual 41.

A smaller set of sources, mostly from enterprise risk management rather than workplace safety, count by risk type instead: financial, operational, compliance, reputational, and safety, a framework that has almost nothing to do with the other three and shouldn't be mixed into the same list.

UK-focused sources sometimes add a fifth category entirely, listing assessments by the specific regulation that triggers them, fire, COSHH, DSE, manual handling, and others, which is really a legal compliance checklist rather than a method or approach at all.

None of these lists is measuring the same thing, which is why they don't agree. We keep all five categories separate rather than collapsing them into one master list. That's because a risk matrix and a quantitative approach aren't actually competing options. One is a tool, and the other is a category that tool can support.

Types of Risk Assessment by Approach

Type Produces Data Needed Best For Effort Typical Owner
Qualitative Descriptive rating (high/medium/low) Expert judgment, minimal data Routine workplace hazards Low Supervisor, safety officer
Quantitative Numerical probability and consequence values Historical, statistical, or modeled data Major hazard, high-consequence work High Risk engineer, specialist team
Semi-Quantitative Hybrid score blending judgment and data Partial data plus expert input Situations with incomplete data Medium Safety or risk manager

Qualitative Risk Assessment

A qualitative assessment rates risk using descriptive categories, like high, medium, or low, based on expert judgment rather than measured data.

It's the fastest approach available, and the one most workplaces use for routine hazards, since it doesn't require statistical evidence to produce a usable result.

The tradeoff is subjectivity: two assessors can rate the same hazard differently, and the result carries no numerical precision.

Quantitative Risk Assessment

A quantitative assessment assigns actual numbers, probabilities, frequencies, and financial impact to both likelihood and consequence.

This approach demands real data: historical incident records, failure rates, or engineering models, which makes it far more resource-intensive than a qualitative rating.

It earns that cost in high-consequence industries like oil and gas or nuclear power, where a wrong qualitative guess carries catastrophic stakes.

Semi-Quantitative Risk Assessment

A semi-quantitative assessment sits between the two, assigning numerical scores to likelihood and severity without the full statistical rigor a true quantitative model requires. A standard risk matrix that multiplies a likelihood score by a severity score is a common example.

Chemical-specific tools often work this way too: SDS Manager's chemical risk assessment feature scores a substance's risk both before and after controls are applied, a semi-quantitative approach since it uses a numbered scale rather than full statistical modeling.

This approach exists because pure qualitative judgment is often too vague and full quantitative analysis is often too expensive or data-starved, so most real-world risk assessments actually land somewhere in this middle category.

Types of Risk Assessment by Workplace Context

Type Produces Data Needed Best For Effort Typical Owner
Generic Reusable assessment for a common task Task knowledge, no site visit required Repeated tasks across multiple sites Low Corporate safety team
Site-Specific Assessment tailored to one location's actual conditions Site walkthrough, local hazard data Unique or high-risk locations Medium Site supervisor
Dynamic Real-time judgment as conditions change On-the-spot observation Emergency response, changing conditions Low (per instance) Frontline worker, first responder

Generic Risk Assessment

A generic risk assessment covers a task or hazard that repeats across multiple locations in largely the same way. Manual handling or working with a specific piece of standard equipment are common examples.

It's written once and reused, which makes it efficient but only appropriate when the underlying conditions genuinely don't change from site to site.

Site-Specific Risk Assessment

A site-specific assessment is built around the actual conditions of one particular location. It accounts for hazards a generic template wouldn't capture, like a specific building's layout or a site's unique environmental exposure.

This type requires an actual site visit or detailed local knowledge, and it's the correct choice whenever a generic assessment would miss something material to that location.

Dynamic Risk Assessment

A dynamic risk assessment happens continuously, in real time, as conditions change. It's most common among emergency responders and workers facing rapidly evolving situations.

There's no written document produced in the moment; it's a trained judgment process applied on the spot. This type only works when the person making the assessment has enough experience and training to do it reliably without the structure a written assessment normally provides.

Types of Risk Assessment by Risk Type

Risk Type Covers Commonly Used Methods
Safety Harm to people, workers, contractors, or the public Risk matrix, HAZOP, JHA, and most other methods in this article
Financial Exposure to monetary loss Quantitative analysis, Monte Carlo simulation
Operational Loss from internal process failure FMEA
Compliance Breach of a legal or regulatory requirement Gap analysis, often paired with a safety risk assessment
Reputational Damage to trust or public standing Qualitative assessment, by necessity

Safety Risk Assessment

Covers harm to people, whether workers, contractors, or the public, and is what most of this article has focused on so far.

Every method already covered, from a simple risk matrix through to HAZOP, can be applied here.

Financial Risk Assessment

Covers exposure to monetary loss, from a specific project's cost overrun risk to an organization's broader credit or market exposure.

This is where quantitative methods and Monte Carlo simulation see the heaviest use, since financial risk usually comes with genuine historical data to model against.

Operational Risk Assessment

Covers the risk of loss from internal process failure, whether that's a system outage, a supply chain disruption, or human error in a routine procedure.

FMEA is particularly common here, since it's built around exactly this question: how could a process or component fail.

Compliance Risk Assessment

Covers the risk of breaching a legal or regulatory requirement, which carries its own consequences separate from any safety or financial harm involved.

A gap analysis against a specific regulation is the most common tool here, often run alongside a safety risk assessment covering the same activity.

Reputational Risk Assessment

Covers damage to trust or public standing, which is harder to quantify than the other four types but no less damaging.

This type is qualitative by necessity most of the time, since there's rarely reliable data to model reputational damage numerically before it happens.

Types of Risk Assessment by Legal Trigger

Assessment UK Regulation Applies When
Fire risk assessment Regulatory Reform (Fire Safety) Order 2005 All non-domestic premises; must be done by a "competent person"
COSHH assessment Control of Substances Hazardous to Health Regulations 2002 Hazardous substances present (chemicals, dusts, fumes, biological agents); excludes asbestos, lead, radioactive substances
DSE assessment Health and Safety (Display Screen Equipment) Regulations 1992 Prolonged use of a computer or screen
Manual handling assessment Manual Handling Operations Regulations 1992 Lifting, carrying, pushing, or pulling creates injury risk
Noise assessment Control of Noise at Work Regulations 2005 High decibel exposure
Vibration assessment Control of Vibration at Work Regulations 2005 Hand-arm or whole-body vibration exposure
Asbestos assessment Control of Asbestos Regulations 2012 Kept separate from COSHH entirely
Vulnerable-group assessment MHSWR 1999 (young workers, new/expectant mothers); general duty (lone workers) Employing young workers, new or expectant mothers, or lone workers

Several risk assessments exist not because of scope or method, but because a specific UK regulation names them directly.

A general workplace risk assessment under MHSWR 1999 doesn't satisfy these; each one has its own separate legal requirement.

  • Fire risk assessment — required under the Regulatory Reform (Fire Safety) Order 2005 for all non-domestic premises, and must be carried out by a "competent person."
  • COSHH assessment — required under the Control of Substances Hazardous to Health Regulations 2002 wherever hazardous substances, including chemicals, dusts, fumes, or biological agents, are present. COSHH does not cover asbestos, lead, or radioactive substances, since each of those has its own separate regime.
  • DSE assessment — required under the Health and Safety (Display Screen Equipment) Regulations 1992 for employees whose work involves prolonged use of a computer or other screen.
  • Manual handling assessment — required under the Manual Handling Operations Regulations 1992 wherever lifting, carrying, pushing, or pulling a load creates a risk of injury.
  • Noise assessment — required under the Control of Noise at Work Regulations 2005 in environments with high decibel exposure.
  • Vibration assessment — required under the Control of Vibration at Work Regulations 2005 where tools or equipment expose workers to hand-arm or whole-body vibration.
  • Asbestos assessment — required under the Control of Asbestos Regulations 2012, kept entirely separate from COSHH.
  • Vulnerable-group assessments — young workers and new or expectant mothers each carry their own specific assessment duty under MHSWR 1999, while lone workers are covered by the general risk assessment duty rather than a dedicated regulation of their own.

This category is UK-specific by nature, since it's built around named UK regulations.

Other jurisdictions impose comparable hazard-specific duties under their own regulations, OSHA's asbestos standard (29 CFR 1926.1101) or noise standard (29 CFR 1910.95) work the same way structurally, just under different names and numbers.

Types of Risk Assessment Tools and Methods

Method Produces Data Needed Best For Effort Typical Owner
Risk Matrix Priority score from likelihood × severity Estimated likelihood and severity Quick prioritization across many hazards Low Anyone trained in its use
JHA Step-by-step hazard and control list Task breakdown Task-specific hazard identification Medium Supervisor with worker input
HAZOP Deviation list with causes and consequences Process design documentation, team expertise Process industry hazard identification High Process safety engineer, team
FMEA Ranked list of failure modes Component or process knowledge Equipment and process reliability High Reliability or engineering team
Fault Tree Analysis Logic tree tracing root causes of a top event Failure data, engineering knowledge Root-cause analysis of a specific failure High Reliability engineer
What-If / Checklist List of scenarios or compliance gaps Team brainstorming or a standard checklist Early-stage or simple hazard identification Low Any team member
Bowtie Visual map of threats, controls, and consequences Identified top event and existing controls Communicating risk to non-specialists Medium Risk or safety manager
Event Tree Analysis Branching outcomes following an initiating event Probability data for each branch Modeling consequences of an incident High Process safety specialist
Monte Carlo Simulation Probability distribution from repeated random sampling Statistical model, computing resources Complex systems with many uncertain variables High Data or risk analyst
LOPA Count of independent protection layers against a scenario Identified scenario, known safeguards Verifying whether existing safeguards are sufficient Medium-High Process safety engineer
Preliminary Hazard Analysis Early-stage ranked list of hazards Conceptual design information Early project or design-phase screening Low-Medium Project or design engineer

Risk Matrix

Risk Matrix

Arisk matrix plots likelihood against severity on a grid, producing a priority score that's easy to read and communicate.

It's the most widely used tool across ordinary workplace risk assessment, precisely because it turns subjective judgment into something structured without requiring real statistical data. Most modern platforms include configurable risk matrices with visual heat maps as a standard feature.

Job Hazard Analysis (JHA)

A JHA, also called a JSA, breaks a specific task into its individual steps and identifies the hazards and controls at each one. Job safety analysis covers this process in more depth for a US audience specifically.

Because it's built step by step, it catches hazards a broader, whole-task assessment tends to miss, and it works best when the workers who actually perform the task are involved in writing it.

In the UK, this same document is typically called a COSHH assessment instead, though it follows the same underlying logic. A JHA form template covers the standard structure.

HAZOP (Hazard and Operability Study)

HAZOP is a structured, team-based technique used mainly in process industries, examining a system for deviations from its intended design using guide words like "more of," "less of," and "none." It's one of the methodologies OSHA specifically accepts for process hazard analysis, covered in more depth in this PHA guide.

FMEA (Failure Modes and Effects Analysis)

FMEA identifies how a component, product, or process could fail, then ranks each failure mode by severity, likelihood of occurrence, and how easily it would be detected.

Multiplying those three factors produces a risk priority number, letting an engineering team focus attention on the failure modes that score highest. It's another PHA methodology, alongside HAZOP and Fault Tree Analysis.

Fault Tree Analysis (FTA)

Fault Tree Analysis

FTA works backward from a single undesired top event, using a logic tree to trace every combination of underlying causes that could lead to it.

This deductive, top-down structure makes it a strong tool for root-cause analysis, particularly when a failure could result from several different combinations of contributing factors. It's one of the OSHA-accepted methods for process hazard analysis.

What-If Analysis and Checklist Analysis

A what-if analysis is an unstructured brainstorming exercise built around the simple question "what if this happens?", applied to a process or task by a team familiar with it.

Checklist analysis is more rigid, comparing a process or site against a predetermined list of known hazards or compliance requirements.

Both are low-effort methods, and both appear among the accepted PHA methods best suited to early-stage identification rather than final risk decisions on their own.

Bowtie Analysis

Bowtie Analysis

A Bowtie diagram visually maps a single top event, showing the threats that could cause it on one side and the potential consequences on the other, with the specific controls (barriers) sitting between each threat or consequence and the event itself.

Its real strength is communication: a Bowtie diagram explains a complex risk to a non-specialist far more clearly than a HAZOP worksheet or a fault tree would, which makes it a common choice when a risk needs to be presented to leadership rather than just documented for a technical team.

Event Tree Analysis (ETA)

ETA works in the opposite direction from FTA, starting from an initiating event and branching forward through the possible sequences of success or failure in the safety systems meant to respond to it.

This forward-looking structure makes it useful for modeling how bad a given incident could actually become, rather than tracing what caused it in the first place.

ETA and FTA are frequently used together, one tracing backward to causes, the other forward to consequences, around the same central event.

Monte Carlo Simulation

Monte Carlo simulation runs a model thousands of times with randomly varied inputs to generate a probability distribution of possible outcomes, rather than a single estimated number.

It's the method of choice when a system has too many uncertain variables interacting for a simple calculation to capture, such as project cost overrun risk or complex financial exposure.

The tradeoff is that it requires genuine computing resources and a defensible underlying model, since a poorly built model produces a precise-looking distribution around the wrong answer.

LOPA (Layer of Protection Analysis)

LOPA takes a specific hazardous scenario and counts the independent layers of protection standing between that scenario and a serious consequence, such as a safety instrumented system, a relief valve, and an operator response, each counted separately.

It sits between qualitative and fully quantitative analysis, since it uses order-of-magnitude estimates rather than precise statistical modeling.

LOPA is commonly used after a HAZOP identifies a scenario, as a faster way to check whether existing safeguards are actually adequate before committing to a full quantitative risk assessment.

Preliminary Hazard Analysis

Preliminary hazard analysis is a coarse, early-stage screening technique applied when a project or design is still conceptual and detailed information isn't available yet.

It ranks hazards broadly, by category and rough severity, to identify which ones need deeper analysis once the design matures.

This makes it a starting point rather than a final answer, useful for catching major hazards early enough that they can still be designed out cheaply, before a more detailed method like HAZOP or FMEA gets applied later in the project.

How Do You Choose the Right Type of Risk Assessment?

choosing-risk-assessment-method-flowchart

The choice comes down to a handful of practical factors rather than one universal best answer, and in the UK, one legal concept sits underneath most of them: ALARP.

ALARP (As Low As Reasonably Practicable), sometimes written as SFAIRP (So Far As Is Reasonably Practicable), reflects the "reasonably practicable" standard used throughout UK health and safety law.

It divides risk into three bands: unacceptable risk, which must be reduced regardless of cost; broadly acceptable risk, which needs no further action; and a middle "tolerable" region, where risk must be reduced unless the cost of doing so is grossly disproportionate to the benefit.

This middle band is where the choice of assessment method actually matters. A risk that's clearly broadly acceptable rarely needs more than a qualitative judgment.

A risk sitting in the tolerable band, close to the unacceptable boundary, is exactly where a more rigorous semi-quantitative or quantitative method earns its cost, since demonstrating ALARP convincingly at that level usually requires more than a subjective rating.

Factor Points toward qualitative / risk matrix Points toward quantitative / rigorous method
Hazard severity Low to moderate consequence High or catastrophic consequence
Position in the ALARP framework Broadly acceptable risk Tolerable risk near the unacceptable boundary
Data availability Little or no reliable data Real historical, engineering, or statistical data exists
Regulatory requirement No specific technique named Sector rules reference HAZOP, LOPA, or similar directly
Audience Frontline team, routine decision Leadership, regulator, or external stakeholder needs justification
Available resources Limited time, no specialist team Time and technical expertise available

Is a Specific Risk Assessment Method Legally Required?

No, not the specific method. Major frameworks, ISO 31000, the UK's Management of Health and Safety at Work Regulations 1999 (regulation 3), the EU's Framework Directive 89/391/EEC, and US OSHA regulations, all require that a risk assessment take place and that identified risks get controlled.

None of them mandate qualitative over quantitative, or a risk matrix over a HAZOP.

The exception sits at the industry level: OSHA's Process Safety Management standard specifically names six methodologies at 29 CFR 1910.119(e)(2), What-If, Checklist, What-If/Checklist as its own distinct listed method, HAZOP, FMEA, and Fault Tree Analysis, plus a seventh catch-all allowing "an appropriate equivalent methodology," even though the general legal duty itself stays method-neutral outside that specific context.

Types of Risk Assessment Come Down to Matching Method to Risk

The type of risk assessment that matters isn't the one with the most rigorous-sounding name; it's the one that actually matches the hazard being assessed.

A routine task rarely needs a fault tree, and a major hazard process rarely gets adequately covered by a five-minute qualitative guess. Understanding which category a method belongs to, such as approach, context, or specific tool, makes it possible to combine them deliberately. Otherwise, the whole list ends up treated as interchangeable options for the same job.

Understanding which category a method belongs to, approach, context, legal trigger, risk type, or specific tool, makes it possible to combine them deliberately instead of treating the whole list as interchangeable options for the same job.

Frequently Asked Questions

What Is the Difference Between Qualitative and Quantitative Risk Assessment?

The difference is what kind of output each one produces. Qualitative assessment uses descriptive ratings based on judgment, while quantitative assessment assigns actual numerical probabilities and consequences based on real data.

What Is the Most Commonly Used Risk Assessment Method?

The risk matrix is the most commonly used method across general workplace risk assessment. It's fast, requires no specialized data, and produces a result that's easy for most people to interpret.

Is a Risk Matrix a Type of Risk Assessment or a Tool?

A risk matrix is a tool, not a separate type sitting alongside qualitative or quantitative assessment. It's typically used to support a qualitative or semi-quantitative approach, not as its own standalone category.

Is a COSHH Assessment Different From a General Risk Assessment?

Yes, a COSHH assessment is legally distinct from a general workplace risk assessment, even though both may cover the same activity. A general risk assessment under MHSWR 1999 looks at the task as a whole, while COSHH specifically requires its own separate assessment covering the substance itself, the route of exposure, the likely health effects, and the control measures in place. Completing a general risk assessment doesn't satisfy the COSHH duty on its own, and the reverse is also true.

Can You Combine Different Risk Assessment Methods?

Yes, and doing so is common practice rather than an exception. A qualitative risk matrix might flag a hazard as high priority, which then triggers a more detailed quantitative or HAZOP-style analysis for that specific risk alone.

What Is Residual Risk?

Residual risk is the risk that remains after controls have been applied, as distinct from inherent risk, which is the level of risk before any controls exist. Risk management platforms that score both inherent and residual risk separately make it possible to see exactly how much a given control actually reduced the risk, rather than just recording a single final number.

Who Is Responsible for Carrying Out a Risk Assessment?

Overall responsibility for risk assessment sits with the employer, who must ensure it's done properly even if the task itself is delegated. An employer can hand the actual work to a safety officer, occupational health specialist, or supervisor, but the underlying legal responsibility for making sure it happens correctly stays with the employer regardless of who performs it.

How Often Should a Risk Assessment Be Reviewed?

A risk assessment should be reviewed whenever the task, equipment, or environment it covers changes, and periodically even if nothing obvious has changed, since overlooked drift is common. Some frameworks set a specific interval: OSHA's Process Safety Management standard, for instance, requires a process hazard analysis to be revalidated at least every five years, even though a full redo isn't always necessary at that point.

Mehreen Iqbal

Mehreen Iqbal LinkedIn

Started with a Bachelors in Microbiology, then a Masters in Public Health; Currently a Workplace Safety Expert.