Risk Management

Hazard vs Risk Explained: Four Distinctions That Change the Decision

Hazard is a source of potential harm, while risk describes the likelihood and consequence of harm in a defined exposure. This glossary explains four distinctions that prevent risk assessments from becoming labels and helps leaders choose controls, owners, and escalation rules.

By 6 min read
risk management scene on hazard vs risk explained four distinctions that change the decision — Hazard vs Risk Explained: Four

Key takeaways

  1. 01Define the hazard before estimating risk, because a vague source of harm produces a vague control plan.
  2. 02Separate exposure from hazard, since a dangerous energy source may exist without being active in every task.
  3. 03Describe risk with scenario, consequence, likelihood, and control assumptions instead of relying on a color alone.
  4. 04Choose controls that change the exposure pathway, then assign an owner who can verify the control under real work conditions.
  5. 05Use the four distinctions in the next risk review and keep the final decision close to the work, because safety is about coming home.

F7 glossary for supervisors, EHS managers, and risk owners

A hazard is not the same thing as risk, and treating the terms as interchangeable makes controls harder to choose. This explainer separates 4 practical distinctions that help a supervisor decide whether the work can proceed, what must change, and who has authority to accept the remaining exposure.

A hazard is a source or situation with the potential to cause harm, while risk describes the likelihood and consequence of that harm within a defined exposure. The hazard may remain present when the risk changes, because people, task conditions, time, and controls alter the pathway to the unwanted event.

What is a hazard?

A hazard is the source of potential harm, such as energy, a substance, a vehicle movement, a biological agent, or a work condition that can affect health and safety. The label becomes useful only when it identifies what can cause harm and how that harm could occur. “Unsafe work” is too broad to guide a control. “Uncontrolled line pressure during maintenance” gives the team a source, a task, and a possible pathway.

ISO 45001 frames hazard identification as part of the operational process used to control occupational health and safety risks. ISO describes the standard through its official standard page. The distinction is important because a hazard register that only lists nouns can appear complete while leaving the exposure mechanism undefined.

Andreza Araujo's book Safety Culture: From Theory to Practice is useful here because it connects safety culture to the decisions and routines that operate under pressure. A hazard becomes a management concern when the organization knows what can cause harm but has not made the control path dependable.

What is risk?

Risk is the possibility of harm in a specific scenario, described through likelihood, consequence, exposure, and control assumptions. The same hazard can create different levels of risk depending on whether a person is present, how long exposure lasts, how much energy is available, and whether the required barrier is reliable.

Health and Safety Executive guidance explains risk assessment as a process of identifying hazards, deciding who may be harmed, evaluating risk, recording findings, and reviewing controls. HSE sets out those steps in its risk-management guidance.

The practical trap is to write “high risk” without naming the event. High risk of what, for whom, under which conditions, and despite which controls? A decision cannot be tested when the scenario is missing. Risk language should make the unwanted event easier to imagine, verify, and prevent. The related guide on risk acceptance decision authority shows how ownership changes the next step.

Four distinctions that change the decision

Hazard and risk become operationally clear when the team separates source from exposure, possibility from scenario, inherent from residual conditions, and score from decision authority. These distinctions prevent a risk assessment from becoming a color assignment that no one can challenge when the work changes.

1. Source is not exposure

A hazard can be present without active exposure. Stored electrical energy exists in equipment, but a verified isolation can remove the worker's exposure pathway for a defined task. A chemical in a closed system remains a hazard, while the risk changes when containment, ventilation, and access conditions are different.

Ask what connects the person to the source. The answer may be contact, inhalation, engulfment, collision, heat transfer, noise, repetition, or a psychosocial work condition. NIOSH explains the value of identifying the source and the route of exposure in its workplace health-evaluation resources.

Supervisors can test this distinction by asking whether the control blocks the source, the route, the person, or only the person's attention. A warning sign may improve recognition, but it does not remove stored energy. The control decision should match the pathway that creates the exposure.

2. Possibility is not a scenario

Possibility is a broad statement that harm could occur. A scenario explains how the event could unfold, who is exposed, what control is expected to work, and what consequence follows if the control fails. “Fall from height” is a hazard outcome. “Worker crosses an unprotected edge during tool retrieval because the access route is blocked” is a scenario that can be examined.

The difference matters because vague scenarios invite generic controls. Once the sequence is visible, the team can test whether redesign, guarding, access planning, or supervision changes the path before relying on a warning or a personal protective measure.

Andreza Araujo has spent 25+ years in multinational EHS leadership, and her published work repeatedly treats safety decisions as evidence questions. The useful question is not whether the form contains a risk score. It is whether the scenario is concrete enough for someone to prove that the control works.

3. Inherent is not residual

Inherent risk describes the exposure before selected controls are credited, while residual risk describes what remains after the controls are assumed to operate. The distinction is valuable only when the control assumptions are explicit and testable.

A risk assessment that reduces a score because a permit, procedure, or training record exists may be crediting paperwork rather than protection. OSHA's incidence and recordkeeping guidance illustrates a broader principle that definitions and evidence rules matter when organizations compare safety information.

Use separate fields for the source, the credible event, the inherent exposure, each credited control, the residual condition, and the verification method. If the residual rating depends on a control that is not available at the point of work, the assessment is optimistic by design.

4. A score is not decision authority

A risk score summarizes a judgment; it does not decide who may authorize the work. A supervisor may be able to apply a standard control, while a plant manager or technical authority may need to approve a temporary deviation, a missing barrier, or a residual exposure above the local threshold.

Risk appetite and acceptance authority should be connected to consequence, uncertainty, and control reliability. A low numerical likelihood should not silence a credible high-consequence scenario when the evidence is weak. The organization needs a rule for escalation, not only a number for classification.

Andreza Araujo's leadership approach keeps responsibility visible by linking the decision to the role that controls resources, sequence, design, and stop-work authority. If the person completing the form cannot change the condition, the form has documented a concern but not assigned ownership.

How to differentiate the terms in practice

Use a short four-question test to distinguish hazard from risk before the team chooses a control or accepts residual exposure. The test should be applied to the task as planned and repeated when the work, people, equipment, or environment changes.

QuestionHazard answerRisk answerDecision implication
What can cause harm?Source of energy, substance, condition, or behaviorCredible unwanted eventDefine the scenario
Who or what can be exposed?Potentially affected people, equipment, or environmentPeople exposed under the task conditionsSet boundaries and timing
What keeps exposure from occurring?Required barrier or design featureControl that is available and effectiveVerify before crediting
Who decides when conditions change?Role that owns the source or systemRole with authority over residual exposureEscalate beyond local authority

The table does not replace a formal method. It improves the conversation before the method is applied, which is often where a weak assessment first loses the connection to the work. When residual exposure remains, the companion explainer on residual-risk acceptance conditions helps keep the approval boundary visible.

When should a risk assessment be reopened?

Reopen the assessment when the scenario, exposure, control, or decision authority changes. A new contractor, a different material, a temporary bypass, a changed sequence, a failed barrier, or an unexpected workload can invalidate the original assumptions even when the task name remains the same.

ISO 45001 expects organizations to manage operational changes and control risks associated with those changes. The review should record what changed, what new event is credible, which control must be added or strengthened, and who can authorize the next step.

NIOSH's workplace evaluation resources reinforce the value of examining actual conditions rather than relying only on a written description. The field check should be proportionate to the consequence, but it should occur before the team treats the revised risk as acceptable. For a related control-evidence perspective, read Control Reliability Explained.

What should the reader do differently?

Before the next job starts, write the hazard as a source, write the risk as a scenario, list the control assumptions, and name the person who can change the exposure. Those four actions make the assessment easier to challenge and easier to verify.

For the next review, ask the team to identify one control that changes the exposure pathway rather than merely reminding people to be careful. Then define the evidence that will show the control worked under the conditions that matter. This creates a small but meaningful bridge between risk assessment and field leadership.

Conclusion: keep the terms connected to action

Hazard names the source of potential harm, while risk describes the possibility and consequence of harm in a defined exposure. The difference matters because leaders cannot choose a dependable control or assign credible authority when the source, scenario, and assumptions remain blended together.

If you want to strengthen that decision discipline, explore Andreza Araujo's work at Andreza Araujo. The goal is not a more impressive risk register. It is a clearer decision that keeps people protected when work conditions change.

Topics risk-management hazard-identification risk-assessment hierarchy-of-controls ehs-manager supervisor decision-quality

Frequently asked questions

What is the difference between a hazard and a risk?
A hazard is a source, situation, or act with the potential to cause injury or ill health. Risk describes the combination of the likelihood of an unwanted event and the severity of its consequence within a defined exposure. A chemical, stored energy source, vehicle movement, or workload condition can be a hazard. The risk changes when people, time, controls, and exposure conditions change.
Can a hazard exist without risk?
A hazard can exist even when no person is currently exposed to it, so the immediate risk may be low or absent for that task. The hazard has not disappeared. A locked and isolated energy source remains a hazard, while effective isolation changes the exposure scenario. Risk assessment should therefore describe who can be exposed, how exposure could occur, and which assumptions keep that path closed.
How do you assess risk after identifying a hazard?
Describe the credible unwanted event, identify who or what can be exposed, estimate consequence and likelihood using a defined method, and document the controls that are actually available. Then test whether the controls change the scenario. A risk matrix can organize a discussion, but it cannot replace field verification, technical judgment, or a decision owner.
Why do risk matrices sometimes give false confidence?
Risk matrices can give false confidence when teams debate a color without agreeing on the scenario, when numerical bands appear more precise than the evidence allows, or when a low score is used to approve weak controls. The matrix is a communication aid. It should not conceal uncertainty, serious-injury potential, control failure, or the authority required to stop work.
What should a supervisor do when the risk changes during work?
The supervisor should pause the task when the original assumptions no longer hold, reassess the changed exposure, confirm the required control, and escalate when the decision exceeds the supervisor's authority. The record should capture what changed, who decided the next step, and how the control will be verified before work resumes.

About the author

Andreza Araújo

Safety Culture Expert | Senior EHS Executive

Andreza Araújo is a safety culture expert and senior EHS executive with more than 25 years of experience in environment, health and safety. She is a Civil Engineer and Occupational Safety Engineer from Unicamp, holds a Master's degree in Environmental Diplomacy from the University of Geneva, and completed sustainability studies at IMD Switzerland. Andreza has served in Global Head of EHS roles in Fortune 500 environments, leading cultural transformation programs across multinational operations. She has represented Brazil as a speaker at the United Nations in Paris and has spoken at the International Labour Organization in Turin. She is the author of more than 16 books on safety culture in Portuguese, Spanish, English and German. Her work has earned more than 10 EHS awards, including two recognitions from Indra Nooyi, former PepsiCo CEO.

  • Civil & Safety Engineer (Unicamp)
  • M.A. Environmental Diplomacy (University of Geneva)
  • Sustainability Cert (IMD Switzerland)
  • People Management & Coaching (Ohio University)
  • UN Paris speaker representative for Brazil
  • ILO Turin speaker
  • LinkedIn Top Voice
  • Indra Nooyi PepsiCo CEO recognition (2x)

Documentaries

Watch Andreza's documentaries

Three productions on safety culture, organizational failure and the human lessons behind major disasters.

Podcasts

Listen to Andreza's podcasts

She hosts three shows on safety leadership, EHS and organizational culture, in English and Portuguese.

Summarize with AI