Why the process of assessing risks matters.
Every so often, we see posts on social media from adventure activity providers asking for a risk assessment for a particular activity.
From time to time, we also receive paperwork that includes risk assessment documents clearly originating from another organisation. We have also encountered risk assessment documents that appear to have followed an individual from one employer to the next.
Most outdoor professionals have probably experienced some version of this. Perhaps you’ve downloaded a document shared by a colleague or, more recently, considered asking AI to create a starting point for you to proof read.
At first glance, this might seem like a question of administration and time management efficiency. Why start from a blank page when someone has already done the work?
However, we believe this perspective misses a much more important point.
The issue is not whether a risk assessment document can be shared. The issue is whether the risks themselves have been assessed.
“A risk assessment document is evidence that someone, somewhere, assessed a risk. It may not be evidence that you have.”
The value is in the process – not the paperwork
A ‘risk assessment’ is not the document itself. The document is simply a record of the process undertaken to identify how people may be harmed and determine what measures are needed to manage those risks.
You might carefully review and edit a document before using it. You might update names, locations and operating procedures. However, editing an existing document is not the same as undertaking your own assessment of the risks.
That process involves observing activities, understanding participants, considering environments, evaluating staff competence, discussing potential hazards, and determining what controls are appropriate. It requires critical thinking, professional judgement and a detailed understanding of how activities are delivered in practice.
When a document is simply adopt from elsewhere—whether downloaded from the internet, borrowed from another provider, inherited from a previous employer, or generated by artificial intelligence— there is a risk that this process is bypassed entirely.
Why one size rarely fits all
There are many reasons why an assessment of risk undertaken by others may not be sufficient for your circumstances.
Even when two organisations appear to deliver similar activities, there can be significant differences in:
- The activities being delivered
- The operating venues and environments being used
- The experience, qualifications and competence of staff
- The aims and objectives of the session
- The age, ability, experience and specific needs of participants
- The equipment being used
- Supervision models
- Organisational systems, operating practices and culture
Unless you deliver activities in exactly the same way, with the same staff, in the same venues, with the same participants, and with the same objectives, important differences will exist.
Those differences may affect both the hazards present and the controls required to manage them effectively.
The question is not whether the document looks credible. The question is whether the thinking behind it has actually taken place within your organisation.
Providers often develop their own approaches, systems and ways of delivering activities. It is not uncommon to hear someone say
“We don’t do things the same as everyone else – we’re different.”
For many organisations that uniqueness is a source of pride. It reflects their values, operating style, staff team, client groups, and approach to delivering high-quality experiences.
However, that same uniqueness is also highly relevant when assessing and managing risks.
If your organisation genuinely operates differently from others, it follows that the risks you face, and the most appropriate ways of controlling them, may also differ. Control measures that are effective in one setting may be unnecessary, impractical or insufficient in another.
This is one of the reasons why risk assessment cannot simply be copied from elsewhere. The more distinctive your operation, the greater the importance of understanding and evaluating risks within the context of your own activities, environments, staff and participants.
A simple outdoor analogy
Few experienced expedition leaders, paddlers or climbers would be comfortable with allowing somebody else to pack their rucksack for a multi-day trip, choose their line down a rapid, or rack their gear before a lead climb.
The decisions we make in these situations are based on a personal assessment of the risks involved. They take account of the environment, our skills, experience, preferences, competence, objectives and appetite for risk.
“So why would you rely solely on someone else’s assessment of the risks associated with the activities you provide? Someone who may know little or even nothing about what you do, how you do it, where you do it, or why.”
Nobody is likely to understand your activities, participants, venues and operating practices better than you. You might seek specialist advice, external expertise or engage others with specific skills to assist you, but your own understanding of your provision remains a critical part of assessing the risks and identifying sensible measures to manage them.
Why this matters
When Adventure RMS inspectors review an organisation’s arrangements, our focus is not on whether a risk assessment document exists.
What really matters is whether the provider has undertaken a suitable and sufficient assessment of the risks arising from its activities, working out how individuals might be harmed, and identified appropriate measures to manage them.
This distinction is important
A document borrowed from another organisation, or one generated by artificial intelligence, is not evidence that a provider has assessed its own risks.
Both the Health and Safety at Work Act 1974 (HASAWA 1974) and the Adventure Activities Licensing Regulations 2004 (AALR 2004) require providers to undertake a suitable and sufficient assessment of the risks and identified control measures to manage these. That responsibility remains with the provider and cannot simply be delegated to others.
Where documents appear to have been adopted wholesale from elsewhere, inspectors are often left with questions, rather than answers and useful evidence. In such circumstances, further evidence may be required to demonstrate that the provider has fully engaged with the process of understanding and managing the risks created by its own activities.
A final thought
Good risk assessment emerges from observation, discussion, experience and professional judgement. It is the product of carefully considering how people might be harmed, what controls are required, and how those controls will work in practice.
Templates, examples and shared practice can all be useful. They can stimulate thinking, prompt discussion and provide useful reference material. Used well, they can help organisations develop and refine their own approach to managing risk.
What they cannot do is replace the process itself.
The most effective risk assessment documents are the ones that demonstrate a genuine consideration of the activities being delivered, the people involved and the measures needed to keep them safe.
Because ultimately, the value is not in having a risk assessment document. The value lies in assessing the risk.
Scan to read online

