Health And Safety Policy Risk Assessment Template for the United States

Generate a bespoke document

What is a Health And Safety Policy Risk Assessment?

The Health And Safety Policy Risk Assessment is a crucial document required under U.S. workplace safety regulations, particularly OSHA standards. It serves as both a legal compliance tool and a practical guide for maintaining workplace safety. Organizations should conduct this assessment when establishing operations, implementing significant changes, or periodically reviewing their safety measures. The document encompasses hazard identification, risk evaluation, control measures, and compliance requirements specific to the organization's activities and industry sector.

Frequently Asked Questions

Is a Health and Safety Policy Risk Assessment legally required by OSHA in the United States?

Yes, Health and Safety Policy Risk Assessments are legally mandatory under OSHA standards and the Occupational Safety and Health Act of 1970. All employers with one or more employees must conduct systematic workplace hazard identification and risk evaluation. Failure to maintain proper risk assessments can result in OSHA citations, fines, and potential legal liability for workplace injuries.

Can OSHA fine my company for not having a complete Health and Safety Risk Assessment?

Yes, OSHA can issue citations and impose fines ranging from $15,625 to $156,259 per violation for missing or inadequate risk assessments. Under the General Duty Clause of the OSH Act, employers must provide a workplace "free from recognized hazards." Incomplete risk assessments demonstrate failure to identify and address known workplace dangers, making companies liable for both OSHA penalties and potential worker compensation claims.

How often must I update my workplace risk assessment to stay OSHA compliant?

OSHA requires risk assessments to be reviewed and updated whenever workplace conditions change, new equipment is introduced, or after any workplace incident or near-miss. At minimum, conduct annual reviews to ensure continued compliance. Major changes like facility renovations, new chemical introductions, or equipment modifications trigger immediate assessment updates under federal safety regulations.

How is a Health and Safety Policy Risk Assessment different from an OSHA 300 injury log?

A Health and Safety Policy Risk Assessment is a proactive document that identifies potential workplace hazards before incidents occur, while the OSHA 300 log records actual workplace injuries and illnesses after they happen. The risk assessment focuses on prevention and hazard mitigation strategies, whereas the 300 log serves as a reactive recordkeeping requirement for tracking workplace safety performance and identifying injury patterns.

How long does it typically take to complete a comprehensive workplace risk assessment?

A thorough Health and Safety Policy Risk Assessment typically takes 1-4 weeks depending on workplace size and complexity. Small offices may complete assessments in 2-3 days, while manufacturing facilities or multi-location businesses can require several weeks. The process includes physical workplace inspections, employee interviews, documentation review, and development of hazard control measures.

Can employees sue if my risk assessment missed a workplace hazard that caused injury?

Yes, inadequate risk assessments can expose employers to personal injury lawsuits and increased workers' compensation claims. Courts may find employers negligent if they failed to identify "reasonably foreseeable" workplace hazards through proper risk assessment procedures. A comprehensive, regularly updated risk assessment demonstrates due diligence and can provide legal protection against negligence claims.

Why do most companies fail OSHA inspections related to risk assessment documentation?

Common failures include conducting generic assessments without workplace-specific hazard identification, failing to involve employees in the assessment process, and not updating assessments after workplace changes. Many companies also neglect to document hazard control measures or fail to train employees on identified risks. OSHA expects detailed, current documentation that demonstrates active hazard management, not just paperwork compliance.

Reviewed by

Swetha Meenal

Legal Engineer, GenieAI

Swetha Meenal profile photo

A lawyer, legal researcher and legal tech founder, Swetha has built AI products deployed inside Tier 1 firms and enterprises. She ensures GenieAI's alignment with the latest regulation and executes testing on the legal robustness of Genie output.

Reviewed by

Imad Mohammed Nazar

Legal Engineer, GenieAI

Imad Mohammed Nazar profile photo

A Skadden-trained M&A lawyer, Imad advised on cross-border transactions and contractual risk before moving into legal AI. He reviews GenieAI's output for compliance and enforceability across our 150+ supported jurisdictions, as well as facilitating external benchmarking.

Jurisdiction

United States

Publisher

GenieAI

Sector

Business

Cost

Free to use

Last updated

About the Health And Safety Policy Risk Assessment

A Health And Safety Policy Risk Assessment is your organization's systematic evaluation of workplace hazards and safety risks, required under OSHA regulations to ensure federal compliance and employee protection. This document identifies potential dangers, evaluates their likelihood and severity, and establishes control measures to maintain a safe working environment.

When do you need this document?

You need this assessment when establishing new operations, implementing significant workplace changes, or conducting periodic safety reviews. OSHA requires employers to identify and assess workplace hazards as part of their General Duty Clause obligations. Manufacturing facilities must complete assessments before equipment installation, while office environments need evaluations when relocating or restructuring workspaces. Healthcare facilities require specialized assessments covering biological hazards and patient safety protocols. Construction companies need site-specific assessments before project commencement, and retail establishments must evaluate customer and employee safety risks.

Key legal considerations

Your risk assessment must comply with OSHA's hazard identification and evaluation requirements, documenting both existing and potential workplace dangers. The methodology section should detail your systematic approach to risk evaluation, ensuring consistency and thoroughness. Risk evaluation matrices must accurately reflect likelihood and severity ratings, supporting your control measure decisions. Control measures should address engineering controls, administrative procedures, and personal protective equipment in order of effectiveness. Documentation requirements include maintaining records of assessments, updates, and employee training related to identified hazards. Employee involvement provisions must demonstrate worker participation in hazard identification and assessment processes.

Legal requirements in United States

Under OSHA 1970, employers must provide workplaces free from recognized hazards and comply with specific safety standards applicable to their industry. Your assessment must address General Duty Clause requirements and industry-specific OSHA standards relevant to your operations. ADA compliance considerations include ensuring safety measures accommodate employees with disabilities and don't create discriminatory barriers. EPA regulations apply when your workplace involves hazardous materials, requiring integration of environmental safety requirements into your risk assessment. NFPA standards govern fire safety requirements, mandating specific assessments for fire prevention and emergency response procedures. State-specific OSHA programs may impose additional requirements beyond federal standards, particularly in states operating their own occupational safety programs. Regular updates are required when workplace conditions change, new hazards emerge, or incidents occur that reveal assessment gaps.

GOVERNING LAW

Applicable law

This Health And Safety Policy Risk Assessment is drafted to comply with United States law. Key legislation includes:

OSHA 1970: Primary federal law governing occupational health and safety in private sector and federal government. Includes General Duty Clause, industry-specific standards, and recordkeeping requirements.

Americans with Disabilities Act (ADA): Federal law requiring workplace accessibility and reasonable accommodations for employees with disabilities in the context of health and safety.

Family and Medical Leave Act (FMLA): Federal legislation covering medical leave provisions and return to work considerations in relation to health and safety policies.

EPA Regulations: Environmental Protection Agency standards governing hazardous materials handling and environmental safety requirements in the workplace.

NFPA Standards: National Fire Protection Association standards setting requirements for fire safety and prevention in workplace environments.

State OSHA Programs: State-specific occupational safety and health programs that may have additional or more stringent requirements than federal OSHA.

State Workers' Compensation: State-level regulations governing workplace injury compensation and related safety requirements.

Local Building Codes: Municipal and state-specific building safety codes that impact workplace health and safety requirements.

HIPAA: Healthcare-specific regulations that may apply to health and safety policies in medical settings or when handling medical information.

Industry-Specific Standards: Specialized safety regulations for specific industries including construction, manufacturing, chemical handling, and food safety sectors.

Genie's Security Promise

Genie is the safest place to draft. Here's how we prioritise your privacy and security.

Your data is private:

We do not train on your data; Genie's AI improves independently

All data stored on Genie is private to your organisation

Your documents are protected:

Your documents are protected by ultra-secure 256-bit encryption

We are ISO27001 certified, so your data is secure

Organizational security:

You retain IP ownership of your documents and their information

You have full control over your data and who gets to see it