What Is Risk Identification

Photo of author
Written By Chris Ekai

What Is Risk Identification

What is risk identification? It is the step in the risk management process where an organization finds, recognizes, and describes the risks that could stop it, or help it, reach its objectives. The output is a written list of risks, each stated as a cause, an event, and a consequence, ready for analysis and treatment.

Shortly before dawn on September 29, 2024, firefighters reached Bio-Lab’s Plant 12 warehouse in Conyers, Georgia, where a corroded sprinkler head had been dripping onto pallets of pool-treatment chemicals. The US Chemical Safety Board’s final report, released July 21, 2026, found nearly 14 million pounds of reactive oxidizers in a building permitted in 2019 for 6.2 million.

The toxic plume that followed forced 17,000 people to evacuate and put up to 90,000 Atlanta-area residents under a shelter-in-place order. Inspections in 2021 and 2022 had found more than 500 corroded sprinkler heads, and a December 2023 inspection found 1,100 more. Bio-Lab kept repairing parts after they leaked.

What Is Risk Identification: The Practitioner’s Cheat Sheet
Risk identification is the step in which an organization finds, recognizes, and describes the risks that could help or prevent it reaching its objectives (ISO 31000:2018, clause 6.4.2). It produces a described list; rating and treatment come later.
The Bio-Lab Conyers fire of September 29, 2024 forced 17,000 evacuations and a shelter-in-place order for up to 90,000 people. The CSB’s July 2026 final report named identification of storage hazards as one of five safety issues.
Six steps cover the job: fix the scope, collect existing evidence, inspect and interview, apply a structured technique, write each risk as cause, event, and consequence, then record and validate it in the register.
IEC 31010:2019 describes 31 techniques. A randomized 2023 study found a business-process walk-through surfaced 5.93 risks per person against 2.46 with no method at all.
Only 20 percent of 860 senior risk leaders are confident they can verify a new risk at speed, and 57 percent say new risks appear faster than they can manage them (International SOS Risk Outlook 2026).
Rerun the exercise on a fixed cycle and on triggers: a new process, a near miss, a supplier change, an inspection finding, or a regulatory change. Corroded sprinkler heads were a trigger nobody logged.

 

CSB Chairperson Steve Owens called the conditions completely unacceptable and listed identification of storage hazards among five safety issues. The company had never been required to run a formal hazard review, because the chemicals sat outside OSHA’s process safety rule and EPA’s Risk Management Program. That gap is what risk identification exists to close.

What Is Risk Identification? The Definition Standards Use

ISO 31000:2018 defines the purpose of risk identification in clause 6.4.2: to find, recognize, and describe risks that might help or prevent an organization achieving its objectives. The wording does two jobs. It covers upside as well as downside, and it stops at description, before any rating of likelihood or consequence.

The same clause lists what to look for: sources of risk, causes and events, threats and opportunities, vulnerabilities and capabilities, changes in context, and indicators of emerging risk. A search that covers only the first two items will miss most of what later becomes an incident. Our ISO 31000 overview walks the full clause structure.

Term What it means How it appeared at Conyers
Hazard A source with the potential to cause harm About 14 million pounds of trichloroisocyanuric acid, a water-reactive oxidizer
Risk The effect of uncertainty on objectives, described by cause, event, and consequence A corroded sprinkler leaks onto the oxidizer, starting a reaction, fire, and toxic plume
Event An occurrence or change in circumstances A sprinkler component fails inside Plant 12
Consequence The outcome of an event on objectives 17,000 evacuated, 90,000 sheltered, plant closed May 2025
Control A measure that maintains or modifies risk Corrosion-resistant heads, segregated storage, quantity limits

Practitioners use hazard identification and risk identification as one phrase, but they are not the same job. Hazard identification lists sources of harm, the habit that OSHA’s recommended practices describe, and the hazard versus risk explainer covers the distinction. Risk identification also asks how a source could combine with an event to reach an objective, the wider ISO 31000 habit.

Stage Question it answers Output ISO 31000 clause
Risk identification What could happen, why, and with what effect? Described list of risks with sources and owners 6.4.2
Risk analysis How likely is each risk and how severe would it be? Likelihood and consequence estimates, often on a matrix 6.4.3
Risk evaluation Which risks exceed our criteria and need action? Prioritized list with treatment decisions 6.4.4
Risk treatment What do we do about each risk we accept, avoid, share, or reduce? Treatment plans and controls 6.5

The stages that follow identification have their own guides here: how to conduct risk analysis, the risk matrix template for rating entries, and the risk response options applied at treatment. This article stays on the first stage, the one most teams shorten, because a risk left off the list gets no rating and no treatment.

Why Finding Risks Early Decides the Rest of the Process

The case for spending time on identification rests on one dependency: every later step works only on the risks already written down. International SOS surveyed 860 senior risk decision makers for its Risk Outlook 2026 and found 57 percent believe new risks emerge faster than they can manage them, according to ASIS International’s summary of the report.

What Is Risk Identification

Figure 1. Four findings from the International SOS Risk Outlook 2026, each pointing at how fast a new risk is found and verified.

The same survey found 80 percent believe early detection is a competitive advantage, but only 20 percent are confident they can verify a new risk at speed. Some 74 percent said the decision window is shrinking. Those three numbers describe an identification gap, not a treatment gap, and treatment budgets cannot close it.

The human cost of missed hazards is counted every year. The Bureau of Labor Statistics recorded 5,070 fatal work injuries in 2024, published February 19, 2026, at a rate of 3.3 per 100,000 full-time workers. Transportation incidents caused 1,937 of those deaths, violence 733, and exposure to harmful substances 687, per the National Safety Council’s summary.

The PEMEX Deer Park release shows how a single unidentified hazard ends. On October 10, 2024, workers removed an isolation blind from the wrong piping and released hydrogen sulfide, killing two and injuring 13. The CSB’s February 23, 2026 report found workers had not received instructions defining the hazards before the job began.

Incident Date What was never identified Consequence
Bio-Lab Conyers, Georgia September 29, 2024 Sprinkler corrosion as an ignition path for water-reactive oxidizers; storage quantity double the permitted design 17,000 evacuated, 90,000 sheltered, site closed May 15, 2025
PEMEX Deer Park, Texas October 10, 2024 Which line was live; hazards of the isolated unit were not briefed to the crew 2 deaths, 13 injuries, final report February 23, 2026
Bio-Lab group sites, 2004 to 2024 Multiple Repeated off-gassing events treated as normal and not carried into a company-wide register Lessons not applied across facilities, per the CSB

Boards see the same dependency in enterprise terms. The CAS and SOA surveyed 350 risk professionals in January 2026 and found financial volatility, geoeconomic shifts, and extreme weather as the top near-term risks. Each entered a register somewhere because someone ran a structured risk identification search for it, which is what a risk management program exists to make routine.

The Six-Step Process From Context to Register

ISO 31000 places identification after scope, context, and criteria, and OSHA’s Recommended Practices for Safety and Health Programs break the hazard half into six action items. Combining the two gives a six-step routine any team can run. The first step in the risk management process, explained elsewhere on this site, is why context comes before the search.

Step What you do Evidence it produces Reference
1. Fix scope and criteria Name the objective, boundary, time horizon, and who owns the output Signed scope note ISO 31000 clause 6.3
2. Collect existing evidence Pull incident reports, inspection findings, Safety Data Sheets, audit logs, and near-miss records Evidence index with dates OSHA action item 1
3. Inspect and interview Walk the site or process, talk to operators, and review nonroutine and emergency tasks Inspection notes and interview log OSHA action items 2, 3, and 5
4. Apply a structured technique Run a checklist, HAZOP, FMEA, or bow-tie against each process step Completed technique worksheet IEC 31010 Annex B
5. Write the risk statement Cause, event, consequence, plus source of evidence and owner Draft register entries ISO 31000 clause 6.4.2
6. Record and validate Enter, remove duplicates, challenge, sign, and set the review date Register version and sign-off ISO 31000 clause 6.7

Step two is where most teams underinvest. OSHA’s first action item is to collect existing information: Safety Data Sheets, inspection reports, injury and near-miss records, and external sources such as NIOSH bulletins, and the risk management process post lists the same inputs for enterprise use. Bio-Lab held two sprinkler inspection reports that named the failure that started the fire.

Before any risk identification workshop, the facilitator should have the evidence below on the table. In our experience that evidence is what separates a two-hour session that finds thirty risks from one that finds eight, because participants react to documents faster than they react to open questions.

  • Incident, injury, and near-miss records for the past three years
  • Inspection and audit findings, including every open corrective action
  • Safety Data Sheets, equipment manuals, and permit or license conditions
  • Process maps, work instructions, and the current risk register
  • Supplier, contractor, and change-of-ownership records since the last review
  • Regulator bulletins and industry incident reports for the sector

Step three follows OSHA’s inspection items and adds interviews, because operators know which alarms get silenced; our hazard identification and analysis guide covers the walk-through. NIST SP 800-30 gives the cyber version: identify threat sources, threat events, vulnerabilities, and predisposing conditions before any likelihood is scored. The two frameworks differ in vocabulary and agree on order.

Steps five and six are covered in the final step in the risk identification process, which shows the register anatomy and the validation checklist, and in the key elements of a risk register. Keep the two halves apart. A workshop that rates risks while it is still finding them will stop finding once the first red rating appears.

Risk Identification Techniques and When Each One Fits

IEC 31010:2019 describes 31 techniques across the risk assessment process, and its Annex B groups the ones used to identify risk. They include brainstorming, checklists and taxonomies, Delphi, structured interviews, surveys, HAZOP, structured what-if (SWIFT), FMEA, and scenario analysis. No single technique covers every source, so the choice of risk identification technique depends on what you expect to find.

Technique Finds most in Weakness Usual owner
Brainstorming New projects, novel processes, early strategy Loud voices dominate; no completeness check Project or risk lead
Checklist or taxonomy Repeat operations with a known hazard history Finds only what the list already names Safety or compliance officer
Structured interview or Delphi Expert judgement on rare or emerging risks Slow; depends on who is asked Risk function
HAZOP Continuous process plants, piping, reactive storage Resource-heavy; needs current drawings Process engineer
FMEA Equipment, product design, maintenance regimes Component focus can miss system interactions Reliability engineer
Bow-tie One major hazard with many causes and outcomes One hazard per diagram Safety lead
Scenario or PESTLE Strategic, regulatory, and market sources Abstract unless tied to a real process Executive team
Business-process walk-through Administrative and service operations Requires an accurate process map Process owner

Structure changes the count. Kountur and Sari randomized 86 participants across three methods in a 2023 study published in Humanities and Social Sciences Communications. Those given a business-process walk-through found 5.93 risks on average, those given a work breakdown structure found 3.14, and those given no method found 2.46.

What Is Risk Identification

Figure 2. Mean risks identified per participant by method, from Kountur and Sari (2023).

The lesson for a workshop is to hand people a map of the process before asking what could go wrong. Our risk identification tools and techniques post gives templates for each method, and the bow-tie analysis example shows how one hazard becomes a diagram of causes and consequences. Scenario-based assessment handles the sources a checklist cannot name yet.

Safety and project teams have their own reference lists. OSHA’s Job Hazard Analysis booklet breaks a task into steps and asks what could go wrong at each one, and PMI’s risk identification guidance ties the techniques to project phases. Cyber teams use MITRE ATT&CK as a threat catalogue and CISA’s sector profiles for the 16 critical infrastructure sectors.

Sources of Risk Across Safety, Operations, Cyber, and Strategy

A search that stays inside one department finds one department’s risks. COSO’s 2017 ERM framework places identification in its Performance component under Principle 10, and expects the search to cover strategy, operations, reporting, and compliance objectives together, as NC State’s ERM Initiative explains. The table maps the main source categories to the reference that governs each.

Source category Examples Where the evidence sits Governing reference
Physical and chemical hazards Falls, energy release, reactive storage, toxic exposure Inspection reports, SDS, injury logs OSHA standards, NFPA 400, EPA RMP
Process and operational Equipment failure, procedure gaps, single points of failure Maintenance records, near-miss reports, process maps IEC 31010, ISO 31000
Cyber and information Credential theft, ransomware, misconfiguration, insider misuse Logs, vulnerability scans, access reviews NIST SP 800-30, MITRE ATT&CK
Supplier and third party Sole-source parts, contractor competence, ownership change Contracts, audits, financial checks ISO 31000, COSO ERM
Financial and market Volatility, credit, liquidity, currency Treasury reports, covenant tests CAS/SOA survey categories, COSO ERM
Strategic, regulatory, reputational Rule changes, product recalls, public incidents Regulator bulletins, media monitoring, board papers COSO ERM Principle 10, PESTLE

Safety hazards remain the most cited category in US enforcement, and our workplace safety risk management post covers the program side. OSHA’s final FY2025 data, published April 29, 2026 by Safety+Health, shows 6,992 fall-protection citations and 3,010 hazard-communication citations. Each was a hazard an employer could have found with the six risk identification steps above.

What Is Risk Identification

Figure 3. OSHA’s ten most cited standards in FY2025, from the final data published April 29, 2026.

The operational risk examples post lists failure modes by function, and the PESTLE comparison covers the external scan for strategic and regulatory sources. Product and pharmaceutical teams use ICH Q9(R1), adopted by FDA, which names hazard identification as the first activity of risk assessment. Small businesses can start from Ready.gov’s risk assessment page.

Reactive chemicals show why boundaries matter. The Conyers warehouse sat outside OSHA process safety management and EPA’s Risk Management Program, so no rule forced a hazard review. The CSB has renewed a 2002 recommendation asking both agencies to cover reactive hazards, and NFPA 400 is being revised; the types of risk assessment guide shows the assessment each category needs.

A Worked Example: Turning the Bio-Lab Findings Into Register Entries

The CSB report reads as a completed identification exercise, run after the fact. Its five safety issues were run to failure, identification of storage hazards, risk management and oversight, industry guidance for pool-treatment chemicals, and regulatory coverage of reactive hazards. Each converts into a register entry a warehouse operator could have written in 2023.

What Is Risk Identification

Figure 4. The Conyers timeline as the CSB reconstructed it from Bio-Lab’s own inspection records.

Register field Entry 1: sprinkler leak Entry 2: storage quantity Entry 3: normalized off-gassing
Cause Corrosion of sprinkler heads and fittings above oxidizer storage Inventory held above the 6.2 million pound permit basis, sacks stacked high Small reaction events treated as routine, not investigated
Event Water leaks onto trichloroisocyanuric acid A reaction that responders cannot reach or isolate A larger reaction that staff assume is another routine event
Consequence Exothermic reaction, fire, chlorine and hydrogen chloride plume Loss of the warehouse, community evacuation, regulatory action Delayed response, escalation to a site-wide fire
Evidence source 2021, 2022, and December 2023 sprinkler inspections Permit file versus inventory system Near-miss log; incidents at group sites 2004 to 2024
Owner Site engineering manager Warehouse operations manager Site leader and corporate EHS
Existing control at the time Repair after leak; partial replacement in the bunker only None recorded None recorded

Entry one existed as evidence by 2022, when two inspections named the corroded heads and the company replaced only those in the bunker. Written as a risk statement with the December 2023 count attached, it would have reached the site leader as a red item with a deadline. Our control measure guide shows how to record the control.

Quantity is the second entry. The 2019 permit anticipated 6.2 million pounds, but the warehouse held nearly 14 million in about 5,000 sacks of 2,205 to 2,805 pounds each.

Some were stacked so that responders could not reach the first reaction, and a quarterly inventory-versus-permit check, with the result recorded against the risk controls, is the whole treatment.

The third entry is cultural, and the hardest to write down. The GPB report on the findings notes the CSB described smaller off-gassing events as normalized at the plant, and cited incidents at Bio-Lab sites between 2004 and 2024 whose lessons were not applied company-wide. The risk culture post explains how to turn near misses into register inputs.

How Often to Repeat the Search and What Triggers a Rerun

ISO 31000 clause 6.6 requires monitoring and review of the whole process, and OSHA’s hazard identification element asks for initial and periodic inspections plus investigation of every incident. Neither names a calendar interval, so we set one by exposure. The cadence table is the one we use with clients, and the risk management lifecycle post explains where each review sits.

Exposure profile Full re-identification Partial refresh Example
High-hazard process (PSM, reactive storage, high voltage) Annual full review; process hazard analysis at least every five years Monthly walk-through with the inspection log Chemical warehouse, refinery, utility substation
Standard operations Annual Quarterly register review by owners Distribution center, hospital, campus
Projects At each phase gate Fortnightly risk meeting Construction, IT programs, product launches
Enterprise strategic Annual, aligned with the strategy cycle Quarterly board update Corporate ERM register

Between scheduled reviews, any of the events below should trigger a rerun of risk identification on the affected scope. The rerun does not need a full workshop. A one-page addendum to the register, signed by the owner and dated, keeps the evidence trail intact and takes an afternoon.

  • A new process, product, material, or piece of equipment enters service
  • An incident, a near miss, or an inspection finding, internal or external
  • A supplier, contractor, or ownership change on a critical activity
  • A regulatory change, a revised standard, or a new enforcement priority
  • An audit, insurance survey, or regulator visit raises a finding
  • A staffing change in a safety-critical or control-owner role

Key risk indicators cover the months between reviews. The KRI examples post shows how a count of open corrective actions or overdue inspections becomes an early signal. At Conyers, the number of corroded sprinkler heads was a ready-made indicator that nobody was tracking as one, even though it was counted three times.

Document every rerun. The risk register template and guide shows how to keep version history so an auditor or investigator can see when a risk was first found and what changed, and the how to identify risks post gives the field-level checklist. The CSB built its timeline from Bio-Lab’s own inspections: the records existed, the risk identification step did not.

Risk Identification: Your Questions Answered

What is risk identification in simple terms?

Risk identification is the act of finding and writing down what could go wrong, or unexpectedly right, before it happens. ISO 31000 describes it as finding, recognizing, and describing risks against objectives. The output is a list of statements, each with a cause, an event, and a consequence, ready for the five risk management steps that follow.

What is the difference between risk identification and risk assessment?

Risk identification is the first stage of risk assessment. Assessment also includes analysis, where likelihood and consequence are estimated, and evaluation, where the result is compared with criteria. Our risk assessment versus risk management post separates the terms further, and the risk assessment pillar guide covers all three stages in order.

What are the main risk identification techniques?

IEC 31010:2019 lists brainstorming, checklists, Delphi, structured interviews, surveys, HAZOP, SWIFT, FMEA, and scenario analysis among techniques used to identify risk. Structured methods find more: a 2023 randomized study measured 5.93 risks per person with a process walk-through against 2.46 with none. The risk management techniques post covers what happens after the list exists.

Who is responsible for risk identification?

The owner of the objective owns risk identification for it. OSHA places the duty on the employer with worker participation, ISO 31000 expects people with appropriate knowledge to take part, and COSO assigns it to management within the Performance component. The risk function runs the workshop and challenges the list, while each entry carries an owner outside the risk team.

How often should risk identification be done?

Run a full risk identification exercise at least annually and a partial refresh quarterly. Rerun it on any trigger: a new process, an incident or near miss, a supplier or ownership change, a regulatory change, or an audit finding. High-hazard processes covered by OSHA’s process safety management standard need a process hazard analysis revalidated at least every five years.

Is risk identification a legal requirement in the United States?

For workplace hazards, in effect, yes. The OSH Act’s general duty clause requires employers to keep workplaces free of recognized hazards, OSHA standards such as PSM require formal hazard analysis, and EPA’s Risk Management Program requires hazard assessments at covered facilities. Outside those rules, identification is a duty of care and a governance expectation from boards, lenders, and insurers.

What does a good risk identification output look like?

Good risk identification output is a register entry with a cause, an event, a consequence, supporting evidence, a named owner, and the existing control. If a reader cannot tell from the entry what would happen and why, it is still a topic and needs rewriting. The hazard and risk assessment definitions post shows worked entries for safety hazards.

Where the Search for Risks Breaks Down

The failure patterns below come from CSB investigation reports, OSHA’s citation data, and the register reviews we run for clients. Most appear in the Conyers record in some form. None of the fixes needs capital spending; nearly all are a change to a procedure, a form, or a meeting agenda.

Failure What it looks like Fix
Rating while finding The workshop scores the first three risks and never reaches the tenth Finish the list before the matrix comes out
Evidence left in the drawer Inspection reports name a failure that the register never mentions Step two before step three: index every report and open finding
Scope drawn by department Safety finds hazards, IT finds threats, nobody finds the interaction One register, COSO’s four objective categories, cross-functional workshop
Checklist as ceiling The list finds only what last year’s list named Pair a checklist with a walk-through or HAZOP each cycle
Topics instead of risks Register rows read as single words such as corrosion or cyber Enforce cause, event, consequence in every entry
Normalized deviation Small events become routine and stop reaching the log Near-miss reporting with a monthly count as a KRI
No rerun trigger The register is refreshed on the anniversary and nowhere else Publish the trigger list and assign a rerun owner

The Regulatory and Technology Horizon

Regulatory coverage of reactive chemicals is the first change due before 2027. The CSB has renewed its 2002 recommendation that OSHA and EPA extend process safety and Risk Management Program coverage, and NFPA 400 is under revision on hazard classification and oxidizer corrosion. Any warehouse holding pool chemicals should identify against the draft now.

AI enters the exercise as a search tool. The CAS and SOA survey ranks adverse AI outcomes among the top five near-term risks, and International SOS found only 6 percent of leaders see AI as important for risk management. Use it to draft checklists from incident databases, and keep a person accountable for every entry that reaches the register.

Expect boards to ask for identification evidence alongside the ratings. Audit committees now want the date each risk was first found and the inspection or interview it came from. Build the register so that question takes one click to answer, and the annual review becomes a comparison of two dated lists.

If your register was last rebuilt from a brainstorm, send us the register and two years of inspection reports. We run the six steps against them, using ISO 31000 and IEC 31010 as the reference, and hand back the risks the brainstorm missed, sorted by source category, with a rerun calendar and a named owner for each.

The services page sets out what an identification review covers, and the contact page is the quickest route to a quote; we reply within five working days. A corroded sprinkler head costs a few dollars to log as a risk. Bio-Lab found out what it costs to leave it off the list.