QEHS EthosEHS Ethos

Risk

Risk

The combination of likelihood and consequence of harm from a hazard.

Last reviewed 3 July 2026

ISO 31000 defines risk as the effect of uncertainty on objectives. In QEHS practice it is calculated as Likelihood × Consequence, often on a 5×5 matrix with named thresholds — Low, Medium, High, Critical — that map to a control expectation and a response time. The matrix is not the analysis; it is the summary of an analysis that already identified the hazard, the exposure, and the existing controls.

The two failure modes of a risk matrix are over-grading and complacency. Over-grading — calling everything High — trains reviewers to ignore the threshold, and the matrix stops driving action. Complacency — accepting a High because it has been High for years — lets a residual risk sit because no one re-rates it after a control changes. A defensible risk register re-rates on a schedule, ties each rating to a named control, and treats a rating change as a trigger for management of change rather than a paperwork edit. See hazard, risk register, and bowtie.

Risk · Glossary | QEHS Ethos