top of page
Search

Risk Management That Works on Site and in Tenders

6 days ago
6 min read

A risk register completed for a tender or certification audit can look impressive and still fail the first real test: a supervisor facing an unfamiliar task, a contractor arriving without the agreed controls, or an incident that exposes a gap everyone assumed someone else owned. Effective risk management is not a document produced once a year. It is the operating discipline that makes work safer, decisions more defensible and business growth less exposed to preventable disruption.

For Australian businesses, the stakes extend beyond avoiding injuries. Weakly controlled risks can lead to project delays, environmental harm, rejected tenders, client complaints, insurance pressure and scrutiny of directors and officers. A practical system brings those exposures into view early enough to do something useful about them.

What Risk Management Must Achieve

Risk management is the structured process of identifying what could affect your objectives, assessing the likelihood and consequence, applying controls, and checking whether those controls continue to work. In a WHS setting, that means protecting workers and others from harm. Across a wider QHSE management system, it also covers quality failures, environmental impacts, supplier performance, compliance obligations and commercial commitments.

The point is not to remove every possible risk. That is rarely achievable and can make operations unworkable. The objective is to eliminate hazards where possible, reduce remaining risk so far as is reasonably practicable, and make informed decisions about the exposure the business is prepared to carry.

This distinction matters. A warehouse may accept the residual risk of forklift movements because the work cannot be done without them, but it should not accept uncontrolled pedestrian interaction, poor traffic separation or untrained operators. A manufacturer may accept a supply-chain delay as a commercial possibility, but not the absence of supplier checks for safety-critical components. Context determines the control required.

For directors and officers, the system also provides evidence of due diligence. Under Australian WHS laws, officers have positive duties to exercise due diligence in ensuring their organisation meets its health and safety obligations. A well-maintained risk process helps demonstrate that the business has identified hazards, resourced controls, received information about performance and acted when issues emerged. Paperwork alone will not establish this, but the absence of credible records makes the position harder to defend.

Start With the Work, Not the Template

Many risk assessments fail because they begin with a generic template rather than a clear understanding of how the work is actually performed. The result is familiar: broad hazards, recycled controls and risk ratings that bear little relationship to conditions on site.

A useful assessment starts by observing the task and consulting the people doing it. Map the sequence of work, including preparation, transport, handovers, cleaning, maintenance, shutdowns and abnormal events. Ask where work changes from the planned method, where people rely on experience rather than instruction, and where time pressure creates shortcuts.

This approach is especially relevant in contracting, manufacturing, port operations and security services, where changing sites, interfaces and contractors can create risks that are not visible in an office-based review. A safe work method statement may address a defined high-risk construction activity, for example, but it does not replace broader planning for traffic management, fatigue, emergency response, equipment integrity or subcontractor capability.

Consultation is not simply a legal formality. Workers, health and safety representatives, supervisors and contractors often know where controls are impractical, inconsistently applied or bypassed. Bringing that information into the assessment improves the control design and makes implementation more likely to hold.

Assess Risk Consistently, Then Apply the Right Controls

A risk matrix is useful only when people use it consistently. Before rating risk, define what likelihood and consequence mean for your business. Consider injury and illness, environmental damage, operational downtime, client impact, legal exposure and financial loss where relevant. A serious incident may have consequences well beyond an immediate injury.

Avoid treating a numerical score as the decision itself. Two risks with the same rating may require very different responses. A low-likelihood event with catastrophic potential can demand strong preventative controls, while a frequent lower-consequence issue may need closer supervision, process redesign or maintenance attention.

Control selection should follow the hierarchy of control. Elimination and substitution generally provide stronger protection than administrative measures or personal protective equipment. If workers must remember a rule perfectly for a control to work, consider whether the work can be redesigned, isolated, engineered or automated instead.

For example, requiring workers to wear hearing protection is necessary in some environments, but it is a weaker primary control than selecting quieter plant, enclosing the noise source or separating people from it. Similarly, an instruction to keep pedestrians clear of mobile plant is less dependable than physical segregation, controlled access points and a site traffic plan that reflects actual movements.

Once controls are selected, assign an owner, a due date and a verification method. “Manager to monitor” is not enough. A meaningful action identifies who will do what, by when, what resources are needed and how the business will confirm the control is operating. This is where risk registers become management tools rather than static compliance records.

Build Risk Management Into Everyday Decisions

The strongest systems do not sit separately from operations. They shape how work is quoted, planned, purchased, supervised and reviewed.

Before work starts

Risk should be considered during tender reviews, project mobilisation and job planning. Confirm the client requirements, site conditions, resources, competencies, plant, subcontractor arrangements and emergency requirements before committing to a delivery method or price. Underquoting a job and then relying on improvised controls is a common path to both commercial and safety failure.

When engaging contractors and suppliers

Contractor and supplier risk needs more than collecting certificates of currency. Assess whether the provider has the competence, licences, insurances, systems and capacity relevant to the work or product supplied. For higher-risk work, clarify responsibilities, verify critical controls before mobilisation and monitor performance during delivery.

The level of checking should reflect the risk. A low-value office supplier does not require the same scrutiny as a contractor working near live services, a labour-hire provider supplying plant operators, or an importer supplying regulated or safety-critical goods. Proportionate controls are more efficient and more credible than treating every supplier identically.

During operational change

Changes create risk quickly. New equipment, altered shifts, a different chemical, changed layout, rapid growth, client variations and new subcontractors can all invalidate an earlier assessment. A simple management-of-change process helps teams pause, assess the effect, communicate revised controls and update relevant procedures before work continues.

This is also where quality and environmental considerations should be integrated. A new cleaning chemical may affect worker exposure, waste disposal arrangements, product contamination and client specifications. One structured review is better than several disconnected forms that miss the interaction between those issues.

After incidents, near misses and audits

An incident investigation should test the system, not just the behaviour of the person closest to the event. Look for failures in planning, supervision, training, maintenance, procurement, workload, consultation and control verification. Corrective actions should address those contributing factors and be checked for effectiveness after implementation.

The same principle applies to internal audits. An audit finding is useful when it reveals whether the management system works in practice. It is less useful when it records only that a form was missing. Repeated minor non-conformities often indicate a process that is too complicated, poorly owned or disconnected from site operations.

Link Risk to ISO and Tender Requirements

Risk-based thinking is embedded in ISO 9001, ISO 45001 and ISO 14001. Certification does not require a particular risk register format, but it does require organisations to understand their context, identify relevant risks and opportunities, meet compliance obligations and evaluate whether their controls are effective.

For ISO 45001, the emphasis includes hazard identification, assessment of OH&S risks, legal requirements, worker participation and operational control. ISO 14001 requires organisations to identify environmental aspects and impacts, while ISO 9001 considers risks that could affect product and service conformity, customer satisfaction and intended quality outcomes.

A single integrated approach can reduce duplication, provided it remains usable. The risk register should connect to procedures, training, inspections, maintenance plans, emergency arrangements, corrective actions and management review. If the register identifies a critical control but no one inspects it, trains for it or measures it, the control exists only on paper.

Tender evaluators commonly look for evidence that systems are established and applied. They may ask for risk assessments, policies, incident data, worker competency arrangements, contractor controls, certifications and audit results. Businesses are in a stronger position when these records reflect actual practice and can be produced without last-minute reconstruction.

Measure Whether Controls Are Holding

Risk levels change with workloads, people, equipment and external conditions. Review is therefore not an annual administrative task. Supervisors should verify critical controls in the field, while managers should review trend data and unresolved actions at planned intervals.

Useful measures vary by business, but can include overdue corrective actions, completion of critical inspections, contractor performance, repeat incidents, training currency, environmental exceedances and audit findings. Do not rely only on injury statistics. Low incident numbers can reflect good control, under-reporting, luck or limited exposure. Leading indicators help identify weakness before someone is hurt or a client is affected.

Management review should focus on decisions. Are risk controls adequately resourced? Are recurring issues being resolved? Have legislative, client or operational changes created new obligations? Are directors receiving enough information to exercise due diligence? These questions turn review meetings into governance rather than a document sign-off.

A credible risk system should make the safe and compliant way of working easier to follow than the shortcut. When the controls fit the job, ownership is clear and leaders act on what the system reveals, risk management becomes a practical commercial asset - one that protects people, supports certification and gives clients confidence that your business can deliver.

 
 
 

Comments


bottom of page