Why every good management plan starts with a risk assessment
- Karen Pither

- 2 days ago
- 2 min read
Whether it's drinking water, environment, ESG, safety or quality, I'm often asked what makes a management plan work. My answer is always the same: the risk assessment. It's not a chapter you write to satisfy an auditor — it's the engine that drives the whole plan. Get it right, and everything else follows: what you monitor, what you document, where you spend, and what you fix first.
A plan built on risk fits your operation
Template plans describe a generic organisation. A risk-based plan describes yours. When you systematically work through what could go wrong — in your catchment, your workshop, your supply chain — the plan that emerges deals with your actual hazards, at the scale of your actual business. That's why regulators and certification bodies across water, environment, safety and quality all ask for the same thing: show me your risks, then show me how your plan controls them.
The inputs decide whether it's evidence or opinion
A risk assessment is only as good as what you feed it. Done around a table in an afternoon with no data, it captures opinions and assumptions — and it will confidently rate the wrong things. The inputs are vital: monitoring results, incident and near-miss records, maintenance history, inspection and audit findings, customer complaints, industry guidance. Wherever possible, quantify the actual risk from evidence rather than accepting the assumed one.
Here's a hypothetical example of why that matters. A water supply team rates turbidity after heavy rain as their number one risk — everyone remembers the storm three years ago. But five years of raw water data shows the treatment barrier has handled every rain event comfortably, while chlorine residuals in the far end of the network have been quietly declining for eighteen months. The evidence flips the priorities: the feared risk is well controlled, and the neglected one is the real threat. Opinion would have spent the budget in the wrong place.
The results should drive action — not sit in a register
The other half of the value comes after the assessment. The risk ratings are your prioritisation tool: highest risks get attention, resources and deadlines first; lower risks get proportionate controls and scheduled review. That becomes your improvement plan — a ranked, defensible program of action you can put in front of a board, a regulator or a certification auditor and justify line by line. It also makes budget conversations easier: you're no longer arguing for "more money for compliance", you're showing exactly which risk each dollar reduces.
Then the cycle continues. Every audit finding, incident and new piece of monitoring data is fresh evidence — feed it back in, reassess, and re-prioritise. That's what continuous improvement actually looks like: not a slogan, a loop.
The same logic, whatever the discipline
Catchment to tap, site to supply chain, workshop floor to boardroom — the method doesn't change. Identify the hazards, assess them on evidence, control the biggest ones first, and keep the loop turning.
If your plan was built from a template — or your risk register hasn't changed since it was written — a risk assessment refresh is the single most valuable thing you can do for it.
Get in touch
Comments