Risks module overview
The Risks module in CalmCompliance helps you assess risks, log hazards, and keep specialist registers in one connected system. You build risk assessments with AI-suggested hazards, link them to locations and assets, manage hazardous materials with QR codes, and run everything through approval and review cycles so the full picture stays current and defensible.
What the Risks module covers
The module is not limited to document-style assessments. It treats hazards, controls, and specialist registers as first-class records tied to real places in your organisation.
Risk assessments β records that capture how you manage risk at a site. Structured assessments hold sections, hazards, and matrix scores. PDF assessments keep one uploaded PDF as the authoritative content and do not use sections, hazards, or scores. You can create structured assessments from scratch, from a reusable template, with AI Extract From PDF into structured content, or as a dynamic on-the-fly assessment, and you can create PDF assessments with Upload PDF as Assessment. See Create a risk assessment.
Hazard registers β structured assessments use Matrix Sections to score each hazard for severity and likelihood. Risk Register sections record hazards with a description and optional controls, without scoring. An assessment can contain multiple Matrix Sections so you can group hazards by topic, location, or activity. Each hazard has a stable link that survives republishing. See View and edit a risk assessment item.
Specialist registers β first-class records for things like hazardous materials, each with its own QR code so anyone can scan and open the full record and attached safety data sheets. See Add hazardous material sections to a risk assessment and Add an image gallery to a risk assessment for how linked records fit into assessments.
Controls and actions β each risk item documents existing controls and planned mitigation controls. You can create follow-up tasks directly from a hazard to assign work and track completion. See Add controls and actions to a risk assessment.
Connected locations and assets β assessments and hazards are linked to locations and assets so risk is not an abstract document but something attached to a real place.
AI assistance
AI suggests hazards and risk items as you build a structured assessment, so you are less likely to miss a scenario. AI Extract From PDF reads a risk register PDF and populates structured hazards for you to review. That path does not create a PDF assessment and does not keep the source file as assessment content. Upload PDF as Assessment is separate: it retains the uploaded PDF as the assessment content with no hazard extraction. AI suggestions are a prompt, not a decision β you choose what is relevant and retain human judgement on every line.
Scoring and matrices
On structured assessments, risk items are scored against a configurable matrix. You can choose a 3Γ3, 4Γ4, 5Γ5, or custom matrix to match your organisationβs risk framework. The assessment page rolls up scores across all Matrix Sections so you can see the highest-priority items quickly. Risk Register hazards are unscored and do not contribute to risk bands, score statistics, or score-based summary widgets.
PDF assessments are unscored. They appear under Unscored in risk insights rather than as zero-risk assessments, and the Risk Assessments list can filter by Content Type (All Content Types, Structured, or PDF).
Approvals, reviews, and distribution
Risk assessments support multi-stage approval workflows. You can set an approval workflow and review schedule on each assessment so the right people sign off before it goes live, and it comes back for review on a schedule. Distribution sends assessments to the people who need to see them, with every step recorded for the audit trail. See Set up approvals and review policies for risk assessments.
Drafts, publishing, and versions
You work on an editable draft, then publish when the assessment is ready. Published and historical versions are read-only, which protects the audit trail. You can publish with an optional effective date and expiry date to control when a version is current. For how versioning affects editing, see Working with risk assessment versions.
Roles and permissions
Risks uses three module roles: Member, Manager, and Admin. Unlike most modules, Members can create and edit risk assessments directly. Managers can also create templates, approve assessments, export and distribute, manage hazardous materials, and access dashboards. Admins add the ability to delete risk content and cancel distributions. Roles are assigned per site in Settings > User Management. For the full permission table, see Risks roles and access.
Child-site inheritance
When cascade is available, open child sites can inherit eligible Risks content from ancestor sites. Ordinary assessments use category and site share-down settings; templates, risk sets, hazardous materials, and equipment profiles use per-record Share with Child Sites. Inherited records are read-only in the child site. See Share risks content with child sites and Cascade Mode for sites.
How Risks fits into the platform
Risk assessments and hazards connect to the rest of CalmCompliance. They are linked to locations and assets, can reference published documents from the document library, feed into Distribution & Reviews for scheduled read-and-sign cycles, and appear as evidence in Standards when proving a requirement is met site by site. Everything shares one system, so the risk picture stays joined up with the places, people, and documents it concerns.
Read next
Create a risk assessment β step-by-step guide to building your first assessment.
Add controls and actions to a risk assessment β how to add hazards, controls, and follow-up tasks.
View and edit a risk assessment item β how to open and manage individual hazards.
Work with risk assessment sections β how to add, reorder, and remove sections.
Set up approvals and review policies for risk assessments β how to configure approval workflows and scheduled reviews.
Export or download a risk assessment β how to export structured assessments or download a PDF assessment.