Risk assessment vs risk management vs health and safety

Residential Security Handbook 2021: Secure Living Residential Estate (Industry), Security Services & Risk Management, Products & Solutions

Risk management and a security risk assessment are often seen as the same thing, when in fact, they are two vastly different things. The security risk assessor’s question is not if you have security, but rather if you have a security risk assessment. The general perception is that a security risk assessment and security is the same thing, however, these two concepts are two very different things, related, but different.


Andre Mundell.

We believe that the risks need to be identified first before any management can take place. Security risk assessments specialise in the identification of security risks. The best way to describe a security risk assessment is as a ‘crime fighting tool’ and it only works if it is done independently. This consists of finding the security risks that provide opportunities for crime.

When conducting a security risk assessment, the assessor looks at outer crime as well as inner crime. Most people only look at outer crime and do not consider inner crime to be a concerning factor. In most cases, it is the inner crime factor that brings estates and companies to their knees.

A security risk assessment is an in-depth investigation into your current security measures to establish if there are any risks. When the risks are identified, the assessor finds suitable, risk-specific solutions to eliminate these risks. Some risks cannot be covered by security hardware; however, the assessor provides ample advice in the security plan that will eliminate these risks by means of processes, protocols and the application of security knowledge and understanding.


Once all the risks are identified and the assessor has found suitable solutions to eliminate the risks, he/she compiles all the information into a document that gets handed over to the client. When a security risk assessment report is read and understood, the risk manager can take over as he now knows and understands what the risks are and will be able to manage these risks in accordance with the security risk assessment.

Working under the risk manager, you will usually find a security manager, health and safety manager, building manager, and sometimes an asset manager.

When it comes to health and safety, we are dealing with the ‘probability’ or ‘likelihood’ of something, like an accident. A security risk assessment, on the other hand, looks at the opportunities for crime and when specific risks are identified, measures are put in place to manage these risks.

Keep in mind that the Health and Safety Act states that the business/company must ensure that no harm comes to employees or visitors. When this is interpreted correctly, the protection of employees and visitors includes security and crime as well. In South Africa, health and safety is governed by the law which means that it will automatically come first and take up most of the time and focus. Physical security is almost always neglected and left behind.

Neither of these aspects, whether it is risk management, health and safety, or physical security, are more important than the other. They are not the same, in fact, they are vastly different and should all be managed accordingly. In addition, health and safety, risk management and physical security must be managed by separate individuals and not one person alone.

If security is not managed as it should be, and the risks are not identified, the door is wide open for crime.


Credit(s)




Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

Powering business resilience and field operations
Infrastructure Products & Solutions
[Sponsored] The Anker 757 Portable Power Station emerges as a strategic asset for businesses looking to overcome power instability and the demand for operational efficiency in remote and field-based environments.

Read more...
Deception technology crucial to unmasking data theft
Information Security Security Services & Risk Management
The ‘silent theft’ of data is an increasingly prevalent cyber threat to businesses, driving the ongoing leakage of personal information in the public domain through undetected attacks that cannot even be policed by data privacy legislation.

Read more...
Proactive strategies against payment fraud
Financial (Industry) Security Services & Risk Management
Amid a spate of high-profile payment fraud cases in South Africa, the need for robust fraud payment prevention measures has never been more apparent, says Ryan Mer, CEO of eftsure Africa.

Read more...
Eight MP dome for harsh environments
Axis Communications SA Surveillance Products & Solutions
Axis Communications announced a marine-grade stainless steel camera that offers performance in harsh environments. Enclosed in an electropolished stainless steel casing, it can withstand the corrosive effects of seawater and cleaning chemicals.

Read more...
How to prevent and survive fires
Fire & Safety Security Services & Risk Management
Since its launch in August 2023, Fidelity SecureFire, a division of the Fidelity Services Group, has been making significant strides in revolutionising fire response services in South Africa.

Read more...
A long career in mining security
Technews Publishing Editor's Choice Security Services & Risk Management Mining (Industry)
Nash Lutchman recently retired from a security and law enforcement career, initially as a police officer, and for the past 16 years as a leader of risk and security operations in the mining industry.

Read more...
Risk management: There's an app for that
Editor's Choice News & Events Security Services & Risk Management
Zulu Consulting has streamlined the corporate risk management process with the launch of Risk-IO, a web-based app designed to consolidate and guide risk managers through the process, monitoring progress as one proceeds.

Read more...
Integrated information platform for risk management
Editor's Choice News & Events Security Services & Risk Management
Online Intelligence recently launched version 7 of its CiiMS risk and security platform. Speaking to SMART Security Solutions after the launch event, the company’s Arnold van den Bout described the enhancements in version 7.

Read more...
Global Identity Fraud Report revealing eight-month ‘mega-attack’
Editor's Choice Security Services & Risk Management
AU10TIX recently released its Q4 Global Identity Fraud Report, with the research identifying two never-before-seen attack patterns, with the worst case involving 22 000+ AI-generated variations of a single U.S. passport.

Read more...
Linking of security officers by security businesses
PSiRA (Private Security Ind. Regulatory Authority) News & Events Security Services & Risk Management
[Sponsored] By law, all security businesses are required to declare their employees to PSiRA so that they can be accounted for administratively. Failure to link employees by security businesses is a contravention of the Code of Conduct and a criminal offence.

Read more...