The problem

Risk assessment teams often inherit a method rather than choose one. A site uses a 5×5 matrix because it always has; a client asks for Fine-Kinney; an engineering team uses FMEA for equipment. Over time the same organisation may hold assessments built on different scales, with different definitions and different thresholds, and nobody is quite sure how a "high" in one compares with a "high" in another.

The opposite problem also occurs: a single method is applied to everything, including work it was never designed for.

Why it matters

A risk score is only meaningful within its method. A rating of 12 on a 5×5 matrix, a Fine-Kinney score of 200 and an RPN of 120 are not comparable numbers. Each depends on its own scales, its own definitions and its own action thresholds.

When methods are mixed carelessly, or their definitions change after assessments have been made, three things go wrong. Priorities become inconsistent. Historical assessments become hard to interpret. And reviewers lose confidence in the scores, which pushes decisions back towards intuition.

A practical approach

Start by understanding what each method is designed to do.

Risk matrix. A matrix combines likelihood and consequence on defined scales, typically 3×3 to 7×7. It is quick to use, easy to communicate and suits most task and workplace assessments. Smaller matrices are simple but coarse; larger matrices give more resolution at the cost of more careful definitions. Consequences can be rated separately for people, the environment, assets and reputation, which makes the assessment more transparent.

Fine-Kinney. Fine-Kinney calculates risk as the product of probability, exposure (how often people are exposed to the hazard) and consequence. Including exposure explicitly is useful where the frequency of a task or presence in an area varies widely, for example in routine operational activities.

FMEA and RPN. Failure Mode and Effects Analysis looks at how a component, process or design can fail. The Risk Priority Number multiplies severity, occurrence and detection. Detection, meaning how likely it is that the failure is found before it causes harm, makes FMEA particularly suited to equipment, process and design reviews by engineering, quality and reliability teams.

No method is automatically superior. A good choice depends on the type of assessment, the people doing it, what the results will be used for and what the organisation or its clients require.

Once a method is chosen, consistency matters more than sophistication:

  • Use the same scales and definitions throughout an assessment.

  • Keep a record of which methodology, and which version of it, an assessment used.

  • Do not change definitions underneath existing assessments; create a new revision instead.

  • Agree what each risk level means in practice, including what action it requires.

It also helps to separate three views of risk that are often blurred: the current risk with existing controls, the target residual risk expected once planned controls are in place, and the verified residual risk confirmed after those controls have been implemented and checked. Why that last distinction matters is explained in Target Residual Risk Is Not Verified Residual Risk.

What a good system should provide

A good risk assessment tool should support more than one method without mixing them. It should:

  • Offer the methods the organisation actually uses, each with its own scales and calculations.

  • Store the methodology settings with each assessment revision, so past results remain interpretable.

  • Distinguish current, target and verified residual risk.

  • Keep previous revisions read-only, with a summary of what changed.

  • Produce a report that shows the method used, the ratings and the sign-off.

For field work, it also matters whether the tool works without connectivity. Assessments are often made where the signal is weakest.

How Sospita Risk Assessment addresses it

Sospita Risk Assessment is a local-first mobile app for iOS and Android, designed for HSE professionals and engineering teams. It works offline and does not require an account; assessment data stays on the device unless the user shares it.

The app supports three methodologies: a risk matrix with consequence ratings for People, Environment, Asset and Reputation; Fine-Kinney; and FMEA with RPN. The free version includes a 3×3 matrix, standard Fine-Kinney and standard FMEA. The Pro plan adds 4×4 to 7×7 matrices and custom matrix, Fine-Kinney and FMEA definitions.

Each assessment revision keeps a snapshot of its methodology, so a historical report reproduces the method that was actually used. Assessments record current, target and verified residual risk separately; verified residual risk can only be recorded once every active action has been completed and verified. Revisions include change summaries, and assessments can be signed as Prepared, Checked and Approved before a PDF report is produced.

Limitations and human responsibility

Software can apply a method consistently. It cannot choose the right method for you or make the ratings correct.

The quality of an assessment still depends on the people involved: their understanding of the work, the hazards identified, the honesty of the likelihood and consequence judgements, and the review by someone competent. A precise number from a poorly understood task is still a poor assessment.

Method choice may also be constrained by legislation, client requirements or internal standards. Check those first, then use the tool to apply the chosen method consistently.