Risk Assessment
12 minutes


Structured Assessment Logic (SAL) – Your Roadmap for Compliance
Cross-Cutting Fundamentals
Preliminary note: The risk assessment is primarily a process that accompanies the design and engineering of a product. It is important to distinguish between the risk assessment as a process and the documented “risk assessment” that forms part of the technical documentation (see for the technical documentation, Blue Guide, section 4.3).
Experienced designers carry out substantial parts of the risk assessment implicitly, drawing on their knowledge of standardized or typical hazards, hazardous situations and hazardous events (see, for example, Annex B of EN ISO 12100 or Annex A of CENELEC Guide 32). In electromagnetic risk assessment, a comparable approach is followed by considering standardized, or typified, electromagnetic phenomena (e.g. Annex 3 of the EMCD Guide), which provide guidance on identifying the disturbances to be assessed.
Designers intuitively discard hazards or phenomena that are clearly irrelevant to the product and focus on those that are genuinely pertinent. It is therefore not required that every conceivable hazard, hazardous situation, hazardous event, or electromagnetic phenomenon be formally listed and assessed, for example by means of a checklist, merely to record its absence of relevance.
Instead, the designer proceeds through an informed and experience-based preselection. This preselection does not need to be documented. Only the assessment of relevant hazards or phenomena - i.e. those identified as present or reasonably associated with the product and supported by sufficiently concrete indications - needs to be recorded.
Key Definitions
Harm: Injury or damage to the protected public interest.
Public Interest: The interest that the legal act requiring a risk assessment seeks to protect, e.g., health and physical integrity or electromagnetic compatibility
Hazard: A potential source of harm, describing the cause of the harm. In electromagnetic risk assessment, a hazard corresponds to an emission or immunity phenomenon that is capable of causing harm (for example, by disturbing equipment, degrading performance, or leading to unsafe system behaviour).
Hazardous Event: An event that can cause harm, i.e. a situation in which a hazard actually manifests itself and may lead to damage or injury.
In electromagnetic risk assessment, a hazardous event corresponds to the operation of equipment in which the public interest is exposed to at least one electromagnetic hazard.
Hazardous situation: Circumstances in which the public interest is exposed to at least one hazard.
Risk: Combination of the probability of occurrence of harm and the severity of the harm in such manner that it describes the results of the risk estimation (ex. low, middle, high risk).
Risk estimation: Determination of the probable severity of harm and the probability of occurrence of that severity of harm.
Relevant hazard: Hazard which is identified as being present at, or associated with, the product, i.e. established facts, giving sufficiently concrete evidence for a hazard and on the basis of which the hazardous situation is analysed and the risk assessment performed.
Significant Hazard: A relevant hazard requiring specific action to eliminate or reduce risk.
Tolerable Risk: A risk accepted within a given context based on the current values of society. Legally, this assumes either:
The original risk assessment indicates negligible risk.
Risk reduction measures meet the state of the art (“adequate risk reduction”).
Risk Assessment Process
Note: The following presentation is intentionally simplified for illustrative purposes and focuses on the core strctural elements.
The risk assessment can be carried out using various methods (risk matrix, risk graph, numerical scoring, etc.) and generally follows three main steps: Hazard Identification, Risk Estimation, and Risk Evaluation - these first three steps constitute the risk assessment proper - followed by a fourth step, Risk Reduction.
Start
↓
Hazard identification (1st step)
Identify hazards considering intended and reasonably foreseeable uses.
Presence of relevant hazard?
No → Product deemed legally safe (no intolerable risk)
↓ Yes
Hazard-specific analysis for each identified hazard.
Presence and application of a group, generic, product, or performance standard (for definitions, see e.g., CEN Guide 414, Sections 3.2 and 3.3; ISO/IEC Guide 51, Section 7.1; CENELEC Guide 24) that addresses the relevant hazard:
Yes → The product can be considered safe with respect to the relevant hazard (i.e., no intolerable risks remain).
↓ No
Risk estimation (2nd step)
Determine severity of harm and probability of occurrence.
Risk evaluation (3rd step)
Significant hazard?
No → Product deemed safe.
↓ Yes
Risk reduction (4th step)
Are risk reduction measures sufficient?
Yes → Reassess to ensure no new hazards or increased risks considering the risk reduction measures taken.
No →Additional measures required.
The following provides a cross-methodological guidance for conducting the various steps of a risk assessment (basic model). For each step, this guidance describes the fundamental method. The approaches presented in legal texts, engineering literature, and standardization documents reflect these basic methods.
Note: The realities of engineering practice are too diverse to be fully captured by a universally binding, legally enforceable procedure for performing a risk assessment. Representations in legal and engineering literature or in standards should therefore be understood as non-binding recommendations. They do not prescribe a procedure required by law, nor do they define a legally mandated process. What is essential is that a risk assessment is actually performed and documented. The methods manufacturers use to carry it out are not determined by law. Techniques developed in engineering practice or theorized in engineering sciences—especially risk evaluation methods—belong to applied science. The focus is on solving a practical task, rather than fulfilling a purely legal requirement. There is no single “correct” method; the various approaches should be seen as proposed solutions.
1. Hazard Identification
Consider the limits of the product:
Use: Operating modes, interventions, user expertise, variants, voltage and frequency of the power supply.
Space: Movement, installation/maintenance space, interfaces, electromagnetic environment.
Time: Product/component lifetime, maintenance intervals.
Other: Material properties, interactions, environmental conditions, housekeeping.
Analyze product life phases (systematic identification of possible hazards, hazardous situations, and hazardous events throughout all stages of the product life cycle):
Transport, assembly, installation, commissioning, use, decommissioning, disposal.
Identify hazards (produce a list of hazards, hazardous situations, and hazardous events to describe possible accident scenarios and how/when they could lead to harm), considering:
Tasks: Setting, testing, programming, maintenance, cleaning, emergency stops, etc.
Product states: Normal operation, malfunction, external disturbances, design deficiencies.
User behavior: Loss of control, reflex actions, inattention, pressure to maintain operation, specific populations (children, disabled).
Note on electromagnetic risk assessment – aspects to be considered when carrying out an EMC risk assessment:
Within an electromagnetic risk assessment, the “hazards” are electromagnetic phenomena relating both to emission and to immunity. These phenomena have to be identified and assessed with regard to the limits, intended use and reasonably foreseeable use of the equipment in order to determine their relevance.
Emission phenomena
The electromagnetic disturbances generated by the equipment, as well as their intensity (disturbance level), originate from the components, assemblies and functional units of the equipment. They are largely determined by the technical realization, such as:
circuit-board layout,
cabling and routing,
housing material and shielding concept,
arrangement and interaction of components and cables.
Those emission phenomena must be considered which, with a certain degree of probability, may impair the intended operation of radio and telecommunications equipment or other apparatus.
Immunity phenomena
When analysing immunity, both of the following must be taken into account:
the electromagnetic phenomena present in the intended operational environment, and
the susceptibility thresholds of the incorporated components, assemblies and functional units.
Standards describing electromagnetic environments provide guidance on the types of disturbances to be expected in different locations (e.g. residential, industrial or mixed environments) and help to define representative test phenomena and levels.
Guidance on the systematic identification of electromagnetic phenomena to be assessed is provided, for example, in Annex 3 of the Guide for the EMCD.
2. Risk estimation
In the second step, the manufacturer evaluates the risks associated with the relevant hazards, generally expressed as a level, index, score, or descriptive classification. If a group, product, or performance standard fully addresses the relevant hazard, it can be assumed that sufficient risk reduction according to the state of the art has been achieved, making the risk tolerable. In such cases, further actions for risk estimation (Step 2) and risk evaluation (Step 3) are not required.
There are many approaches to risk estimation, ranging from simple qualitative methods to detailed quantitative analyses. The best-known methods include risk matrices, risk graphs, and numerical scoring. While ISO/TR 14121-2 Section 5.4 focuses on machinery, these methods are generally applicable across other sectors (low-voltage equipment, pressure equipment, EMC, etc.).
Note: Every relevant hazard identified in Step 1 must be assessed, except those fully covered by an applicable standard.
Risk estimation typically proceeds in three sub-steps:
Severity of harm
Probability of occurrence of harm
Derivation of the overall risk level
2.1. Severity of harm
The starting point is the hazardous event, i.e., the potential harm-causing event. The assessor anticipates an injury scenario, describing step by step how the hazard could lead to harm to the public interest. Depending on the method chosen, severity can be expressed differently:
Risk matrices
Rsik graph
Numerical scoring
2.1.1 Risk matrices
Severity is expressed as an index (e.g., 1–6 or A–D) or qualitatively (e.g., low, medium, high). Each hazard can result in multiple severities, but the worst credible severity should be considered.
Example qualitative levels of severity:
Catastrophic: Very serious or irreversible injury
Serious: Long-lasting severe injury
Moderate: Significant or reversible injury of medium or short duration
Minor: Slight or reversible injury of short or medium duration
Table 1 – Risk matrix (example)
Probability of occurrence of harm | Severity of harm | |||
catastrophic | serious | Medium | minor | |
very likely | high | high | high | medium |
likely | high | high | medium | low |
unlikely | medium | medium | low | negligible |
remote | low | low | negligible | negligible |
2.1.2 Risk graph
Based on decision trees; severity expressed as S1, S2, etc.
S1: Slight injury (usually reversible)
S2: Serious injury (usually irreversible)
Figure 1 – Example risk graph with risk indices 1 to 6

2.1.3 Numerical scoring
Severity is assigned a numerical value (Severity Score, SS) across four classes:
Catastrophic: SS = 100
Serious: 99 ≥ SS ≥ 90
Moderate: 89 ≥ SS ≥ 30
Minor: 29 ≥ SS ≥ 0
2.2. Probability of occurrence of harm
2.2.1 Assessment of Probability of Harm
After estimating the severity of harm, the next step is to assess the probability of harm.
Unless empirical data are available - which is rare - the estimation of probability is generally subjective. Consulting with knowledgeable personnel or using brainstorming sessions is therefore highly recommended.
The probability of occurrence is typically considered as a function of three sub-factors:
Exposure to the hazard - How often the public interest is exposed to the hazardous situation. This requires analysis of all modes of operation and work methods.
Occurrence of the hazardous event - How often and with what probability the hazardous event occurs. Criteria include:
Reliability data of components and systems (e.g., component failures, power disturbances, environmental effects, electromagnetic phenomena, vibrations)
Accident histories and experiences from risk reduction applied to similar equipment
Ability to limit harm - The ability of persons exposed to recognize risks and prevent or limit harm, depending on their training, knowledge, and experience. Considerations include:
User type: skilled, unskilled, unmanned
Human reaction ability: possible, possible under certain conditions, impossible (e.g., reflexes, agility, escape possibilities)
Risk awareness: via general information, direct observation, warning signs, and indicators*
Speed of harm: sudden, fast, slow
*Note: According to the “3-step method,” warnings, signs, and information cannot replace inherently safe design or technical protective measures if these are available according to the state of the art.
2.2.2. Expression of the probability of occurrence of harm
Risk matrices: Various scales are used to assess probability. Typical qualitative examples:
Very likely: near certain
Likely: can occur
Unlikely: not likely
Remote: almost zero
Risk graphs: The probability is derived from the combination of:
Frequency/duration of exposure (F):
F1: seldom or short exposure
F2: frequent or long exposure
Occurrence of the hazardous event (O):
O1: Low – proven, mature technology
O2: Medium – occasional occurrence, less proven technology
O3: High – frequent occurrence, recent failures observed
Avoidance (A):
A1: possible under some conditions – user can recognize and respond
A2: impossible – harm occurs too quickly, lack of risk awareness
Numerical scoring: Probability is assigned a Probability Score (PS):
Very likely: PS = 100
Likely: 99 ≥ PS ≥ 70
Unlikely: 69 ≥ PS ≥ 30
Remote: 29 ≥ PS ≥ 0
2.3 Risk level
Once severity and probability have been assessed, they are combined to derive the overall risk level:
Risk matrices: Combine severity and probability (e.g., “catastrophic” + “likely” → high risk)
Risk graphs: Risk indices:
1–2 = low risk
3–4 = medium risk
5–6 = high risk
Numerical scoring: Risk Score (RS) = PS + SS (Probability Score + Severity Score). The RS is then interpreted according to predefined ranges (see Table 2).
Table 2 – Risk score and risk level
- | high | ≥ 160 |
159 ≥ | medium | ≥ 120 |
119 ≥ | low | ≥ 90 |
89 ≥ | negligible | ≥ 0 |
3. Risk evaluation
After risk estimation, risk evaluation determines whether risk reduction is required, i.e., whether a relevant hazard qualifies as a significant hazard. If risk reduction measures have already been implemented, it must be checked whether they:
Achieve the required risk reduction, and
Do so without introducing new hazards or increasing other risks.
The risk level from Step 2 provides an initial indication of risk magnitude. Society tolerates low risks more readily than high or severe risks. Nevertheless, even low risks should be reduced where economically feasible (As Low As Reasonably Practicable – ALARP).
The required level of protection to meet legal design requirements corresponds to the state of the art. Residual risk is considered tolerable when implemented risk reduction measures meet the state of the art or provide an equivalent level of protection.
An integral part of the state-of-the-art concept is the cross-sectoral hierarchy of measures defined in the 3-step method. In short, the technical state determines what protection is owed.
4. Risk Reduction
Following risk evaluation, risk reduction addresses the findings of the risk assessment. The goal is to eliminate hazards or reduce one or both elements that determine risk:
Severity of harm
Probability of occurrence
Measures should be applied according to the 3-step method in priority order:
Inherently safe design measures - e.g., safer / EMC design measures, substitution of hazardous materials, ergonomic principles, shielding, filtering, earth or local separation.
Technical protective measures - adequately reduce risk for intended use and are appropriate for the application.
Information for use – only when steps 1 and 2 are impracticable; includes warnings, instructions, and residual risk notices.
After implementing protective measures, the risk assessment should be repeated to verify that no new hazards have been introduced and that existing risks have not increased (risk assessment iteration).
5. Final Notes
Legal perspective: Risk assessment is part of the conformity assessment procedure. The risk assessment document proves the product meets essential/general safety/EMC requirements and is a mandatory part of technical documentation. Without it, the product is formally non-compliant.
Adequacy: The technical documentation must allow assessment of product conformity and include a sufficient risk analysis and evaluation. A risk assessment is adequate if, together with the full technical documentation, it demonstrates conformity.
Use of harmonised standards: Risk assessment is still required even if harmonised standards are applied. Only Steps 2 and 3 (risk estimation and evaluation) may be omitted if the relevant hazard is fully covered by a standard.
Documentation: The risk assessment record should demonstrate the procedure and results, including:
· Product specifications, limits, intended use
· Assumptions (loads, strengths, safety factors)
· Relevant hazards, hazardous situations, and events
· Basis for risk assessment, data and sources (e.g., accident histories, experience)
· Data uncertainty and its impact
· Protective measures implemented and their objectives