How to Draft Risk Assessments With AI and What a Human Must Check

Coding Liquids tutorial cover featuring Sagnik Bhattacharya for How to Draft Risk Assessments With AI and What a Human Must Check.
Coding Liquids tutorial cover featuring Sagnik Bhattacharya for How to Draft Risk Assessments With AI and What a Human Must Check.

Yes. Give AI the real facts of the job, the site and your template, and it drafts hazards, who could be harmed and sensible controls in minutes. A competent person who knows the work must then check that every hazard is real and none is missing, each control exists, the ratings are honest, and it's signed, shared and reviewed.

The responsibility never moves to the AI. What it produces is a well-organised guess based on typical jobs of that kind, and the most dangerous thing on a particular site is often the one fact nobody typed in. The most common failure isn't a missing hazard, though. It's a plausible control the team doesn't actually have, written down confidently enough that everyone assumes someone arranged it.

Follow me on Instagram@sagnikteaches

What AI drafts well, and what it can't know

AI is good atAI can't know
Listing the typical hazards of a task typeWhat is on this particular site today
Suggesting controls in a sensible orderWhich equipment, training and people you actually have
Formatting everything into your templateYour near misses and what went wrong last time
Applying a rating matrix consistently, if told howWhether a control is practical for this team on this day
Turning rough notes into clear instructionsWhat the law requires where you operate
Spotting gaps between an incident log and an assessmentWho has read and understood the assessment

The left column saves an hour or two of writing per assessment. The right column is the human review, and it can't be skipped or shortened just because the draft looks professional.

Connect on LinkedInSagnik Bhattacharya

Give it the facts it can't guess: a filled-in site brief

The quality of the draft depends almost entirely on the brief. The running example is an illustrative engineering consultancy sending two engineers to log trial pits and a borehole on a disused industrial site, with a hired excavator and operator. Before drafting anything, the project lead fills in a short brief:

Subscribe on YouTube@codingliquids
SITE BRIEF - for risk assessment drafting
Task: log 8 trial pits (excavator, max 3 m deep) and supervise
  1 cable-percussion borehole. 3 days.
Team: 2 engineers (one 2 years' experience, one graduate in
  first month), 1 excavator operator (hired, with own machine),
  drilling crew of 2 (subcontractor).
Site: former engineering works, closed 15 years. Fenced but
  fence damaged on north side; signs of trespass.
  One derelict single-storey building, corrugated roof sheets,
  age unknown. Old concrete slabs, possible buried tanks.
  Nearest hospital 25 minutes. Mobile signal weak at rear.
Known services: utility records requested, electricity record
  shows a cable along the east boundary. Others not received yet.
Ground: desk study notes possible hydrocarbon contamination
  near former tank area.
Equipment we have: cable and pipe locator, first aid kit,
  PPE (hard hats, boots, hi-vis, gloves, glasses), 1 lone-worker
  app. We do NOT own a gas monitor.
Weather: forecast rain on day 2.
Our template: attached (hazard / who / controls / L / S / risk
  / residual L / S / risk / action owner).

Three lines in that brief change the assessment completely: the derelict building with roof sheets of unknown age (possible asbestos), the missing utility records, and "we do NOT own a gas monitor". Without them, the AI produces a competent generic assessment for trial pitting, which is precisely the problem.

The drafting prompt and a sample of what comes back

Using the site brief and template attached, draft a risk
assessment for this task.
- List hazards specific to this site first, then general
  trial-pitting and drilling hazards.
- For each: who could be harmed and how; controls in order of
  the hierarchy (eliminate, substitute, engineer, organise,
  PPE); likelihood and severity scores on the 1-5 scales in the
  template, before and after controls.
- Only include controls using equipment and people listed in
  the brief. If a control needs something we don't have, write
  "NEEDS: [item]" instead of assuming it.
- Do not cite laws or regulations.
- End with a list of questions I need to answer before this
  assessment can be finalised.

An illustrative excerpt of the draft:

HazardWho / howControlsBeforeAfter
Striking a buried electricity cable while excavatingOperator, engineers: electric shock, burnsDo not dig until all utility records received; scan every pit location with the cable and pipe locator; mark and keep pits clear of the east boundary cable; hand-dig the first part of each pit where services are suspected3 × 5 = 151 × 5 = 5
Disturbing asbestos in derelict buildingEngineers, operator, trespassers: inhaling fibresNo entry to the building; no pits within the exclusion distance set by the project lead; NEEDS: asbestos survey or specialist advice if work near the building is unavoidable3 × 5 = 151 × 5 = 5
Ground gases or vapours in pits near former tanksEngineers logging at pit edgeLog from the pit edge only, never enter a pit; NEEDS: gas monitor for pits in the tank area3 × 4 = 122 × 4 = 8
Falling into an open pitEngineers, trespassersBackfill each pit before leaving it; barrier around any pit left open while logging; nobody works within a metre of the edge unless essential3 × 4 = 121 × 4 = 4

The draft ended with seven questions, including "What is the exclusion distance from the derelict building?", "Who is the site contact if the excavator operator is injured?" and "Is the graduate engineer permitted to supervise the drilling crew alone?" Those questions are often the most useful part of the draft, because they are the decisions a busy project lead forgets to make.

The human check: twelve questions before anyone signs

The reviewer should be someone competent in the task, which usually means someone who has done this kind of work, knows the team and has seen the site or its photographs. Work through these in order.

Is it this job, on this site?

  1. Does every hazard exist here? Delete anything imported from a typical job that doesn't apply. A hazard list padded with irrelevant items trains people to skim.
  2. Is anything missing? Walk through the day in your head: arrival, parking, access, each task, breaks, weather, leaving. In the example, the reviewer added "reversing excavator near people logging samples", which the draft had folded into a general "plant movement" line.
  3. Are the site-specific facts right? Distances, depths, dates, the location of the cable. AI transcribes well but occasionally swaps numbers between lines.

Do the controls exist and work?

  1. Is every piece of equipment named in a control actually available on the day? Every "NEEDS" item must be resolved, bought, hired or the task changed, before the assessment is final.
  2. Is every control practical? "Hand-dig every pit to full depth" is safe and impossible in three days. A control nobody will follow is worse than an honest gap.
  3. Are controls specific enough to act on? "Take care near the pit" is not a control. "Barrier at 1 m from any open pit" is.
  4. Is the order of controls right? Removing or avoiding the hazard comes before PPE. If the only control for a serious hazard is gloves and glasses, look again.

Are the ratings honest?

  1. Does each score follow your matrix definitions, not a gut feeling? Ask "which definition does a 3 match?" for a few lines.
  2. Does every drop from before to after have a control that explains it? Severity rarely falls; if a line shows severity dropping from 5 to 2, check the reasoning.

Have the people seen it?

  1. Does it say who does what? Every action needs an owner and a date.
  2. Is there an emergency plan? Nearest hospital, how to call for help with weak signal, who holds the first aid kit, how the lone-worker app is used.
  3. How will the team be briefed? A signed sheet at a site briefing, with the assessment walked through, not emailed and assumed read. Record who reviewed and signed it, with the date.

For more on building review steps that don't become rubber stamps, see setting up human review for AI work.

Errors that keep turning up in AI-drafted assessments

Controls that assume kit you don't own. Before the "only use equipment in the brief" instruction was added, the consultancy's first draft listed "continuous gas monitoring by the logging engineer" as a control. The firm owned no gas monitor. Had the draft been signed as written, the record would show a control that never existed, which is worse than no record at all if something goes wrong.

Confident legal references. Asked to "include the relevant regulations", an AI will usually oblige, sometimes citing rules from another country, a superseded version, or a standard that doesn't exist in that form. This is one of the ways AI hallucinations reach business documents. Tell it not to cite law, and add verified references yourself if your template needs them.

The copied site. A draft built from last month's assessment as an example kept a hazard for "working near the river bank" on a site with no river. Harmless in itself, but it shows nobody read the document properly, and a reviewer who spots one of these should read everything else more slowly.

Residual risk that falls for no reason. One line in an early draft rated manual handling of core boxes at 4 × 3 before controls and 1 × 3 after, with "use correct lifting technique" as the only control. Technique training doesn't make a 25 kg box four times less likely to hurt someone's back. Two-person lifts and a trolley would.

Wishes written as controls. "Remain vigilant", "be aware of surroundings", "exercise caution". Ask the AI to rewrite any control that doesn't describe a physical thing, a named person's action or a rule with a number in it.

Rewriting vague controls: four before-and-after examples

Once the draft is reviewed, a second prompt tidies the wording: "Rewrite each control so it names a physical measure, a person's action or a rule with a number. Keep the meaning; flag any control you can't make specific." Illustrative results from the consultancy's assessment:

BeforeAfter
Be aware of plant movementsBanksman present whenever anyone is within the excavator's swing or reversing area; engineers bag samples at least 5 m from the machine
Take care in wet weatherIf rain makes pit sides unstable, the senior engineer stops pitting; no logging within 1 m of a wet pit edge
Maintain communicationCheck in via the lone-worker app at 10:00, 13:00 and on leaving; office calls if a check-in is 30 minutes late
Use appropriate PPEHard hat, boots, hi-vis, gloves and glasses at all times outside the vehicle; disposable coveralls for pits in the former tank area

The numbers in the right-hand column came from the reviewer, not the AI. When the AI doesn't know the right distance or time, the useful response is a flag ("distance needed"), and the rewrite prompt should ask for exactly that rather than a guess.

On timing: for this assessment the brief took about 20 minutes, the draft under five, and the review and rewrites about 40 minutes with the second engineer. Writing the same document from a blank template usually took the project lead two to three hours, much of it formatting. The saved time is best spent on the review and the site briefing, which are the parts that actually keep people safe.

Rating risk the same way every time

AI applies a matrix consistently only if you define it. A common layout multiplies likelihood (1 to 5) by severity (1 to 5):

ScoreLikelihoodSeverity
1Very unlikely: hard to imagine it happening on this jobMinor: first aid only
2Unlikely: could happen, but only if several things go wrongInjury needing medical treatment, back at work within days
3Possible: has happened on similar jobsInjury causing more than a week off work
4Likely: would be expected without controlsSerious or permanent injury
5Very likely: almost certain without controlsFatal, or harm to several people

Then set bands: 1 to 4 low (proceed), 5 to 9 medium (proceed with the controls in place and reviewed), 10 to 16 high (senior sign-off before work starts), 20 to 25 very high (do not start). Paste these definitions into every drafting prompt and ask for likelihood and severity as separate numbers, not just the product, so a reviewer can challenge each one. Your firm may use a different matrix; the point is that the AI uses yours, word for word.

Keeping assessments alive after the first draft

An assessment written once and filed is a record of intentions. Reviews should happen when the work changes, after any incident or near miss, when someone new joins the team, and on a fixed date as a backstop. AI makes the incident-driven review quick:

Here is our current risk assessment for trial pitting and our
near-miss and incident log for the last 12 months. For each log
entry, say whether the assessment already covers the hazard and
whether the control listed would have prevented it. List any
log entries the assessment doesn't cover, and draft a new line
for each in our template format, marked DRAFT for review.

In the consultancy's log, a near miss had been recorded in the spring: an excavator reversed within two metres of an engineer bagging samples. The assessment covered "plant movement" generally but had no control for it. The AI's suggested line added a banksman (a person guiding the machine) whenever anyone works within the swing and reversing area, and a rule that samples are bagged away from the machine, not beside the pit. The reviewer kept the second control, adjusted the first to match how the hired operators actually work, and briefed both at the next site start. Put the review dates on a compliance calendar so they don't depend on memory.

The same approach in an office-based firm and a recruitment agency

A law firm's home visits. An illustrative law firm whose private client team visits elderly clients at home to take will instructions has a real, if lower-level, set of hazards: lone working in unfamiliar homes, driving, occasional aggressive relatives, pets, trip hazards, and carrying confidential papers. The brief for the AI is short (who visits, how often, what they carry, how they check in) and the human check focuses on the check-in routine: who notices when a solicitor hasn't called in by the agreed time, and what they do.

A recruitment agency's pre-placement site check. An illustrative agency placing temps in warehouses gathers information from each new client before the first placement: the tasks, the equipment temps will use, the induction and the PPE provided. AI can turn a consultant's site-visit notes into a structured checklist and list the questions still unanswered, such as who trains temps on the pallet trucks and whether night shifts have a first aider. The duties on agencies and the businesses that hire their workers vary, so the human check here includes confirming what your contracts and local rules say about who assesses what.

When a draft isn't enough and you need an adviser

AI plus a competent reviewer is a sound way to handle routine assessments. Bring in a qualified health and safety adviser when the work involves high-hazard activities (confined spaces, work at height beyond simple ladders, hazardous substances, demolition, work near live traffic or rail), when you're doing a task for the first time, after a serious incident, or when you're not sure what your local law requires you to record. An adviser can also review your template and matrix once, which makes every AI draft built on them better.

Keep personal details out of general-purpose tools. An assessment for a named employee's health condition or pregnancy contains sensitive personal information; either use a business plan that doesn't train on your content, or describe the needs without the name. And if you're also writing the policy that sits above these assessments, writing a health and safety policy with AI covers what to check there.

Risk assessment and AI: what people ask next

Who is legally responsible if an AI-drafted risk assessment is wrong?

The employer or business, exactly as if a person had drafted it. Using AI doesn't transfer any duty. That's why a named, competent person should review, amend and sign every assessment, and why the record should show who reviewed it and when. If you're unsure what your local rules require, ask a qualified health and safety adviser.

Can I use a free AI account to draft risk assessments?

For generic tasks with no personal or client details, the risk is low, but switch off model training in the privacy settings. For anything naming staff, clients, sites or health conditions, use a business plan that doesn't train on your content by default, or remove the identifying details before you paste anything in.

How often should risk assessments be reviewed?

Whenever something significant changes: a new task, new equipment, a new site, a new member of staff with different needs, or an incident or near miss. Many firms also set an annual review date as a backstop. AI helps by comparing your incident log with the assessment and listing the hazards that aren't covered.

Does AI know my local health and safety law?

Not reliably. It will often cite regulations or standards with confidence, sometimes from another country or an older version. Treat any legal reference in a draft as unverified until you've checked it yourself or with an adviser, and delete references you can't confirm rather than leaving them in.

Further reads

Sources: general risk assessment method (identify hazards, who may be harmed, evaluate and control, record, review), the hierarchy of controls and the common 5x5 likelihood-severity matrix, as used in standard health and safety practice. Plan privacy defaults from the vendors' business plan pages.

Want AI-drafted risk assessments your team can trust?

On a 1:1 call we'll look at the assessments you write most often, build a site brief and prompt around your own template, and set up a review step so nothing unchecked reaches a site.

Book a 1:1 call with me