The question nobody gives a clean answer on
I've had this argument more times than I can count — with colleagues, with clients, and recently with someone who has been doing exactly this job for as long as I have.
The question is simple enough: in a risk assessment, can severity actually change once you've introduced control measures?
Most practitioners have a view. The problem is those views don't always agree — even among people with NEBOSH, IOSH, and RoSPA credentials. Even government guidance isn't explicit. And, interestingly, two major AI systems gave me two different answers when I put the question to them directly.
So let's work through it properly.
The "severity is fixed" argument
There's a well-established school of thought that says severity should never change — or at least, should rarely change — once control measures are introduced.
The logic runs like this: severity represents the worst-case consequence of the hazard. If someone falls from a roof, the potential outcome is death. A control measure doesn't change what the hazard could do to someone; it changes the probability of it happening. So only likelihood moves, not severity.
Under this view, if your controls are so effective that the outcome of an event would genuinely be different, you're essentially dealing with a different scenario — and you should write a fresh risk assessment rather than adjusting severity downward on the original one.
This is the position taught in many training programmes, and it has the merit of keeping risk assessments conservative and consistent.
The case for severity moving
I don't accept that severity is always fixed. Not completely, anyway.
Here's a straightforward example. A worker is operating at height. Without controls, a fall from 6 metres onto a hard surface is likely to be fatal or cause life-changing injury. You then install a safety net beneath the working area.
If that worker falls — and the fall still happens, the event still occurs — they land in a net rather than on concrete. The outcome is meaningfully different. They may still be injured. But the severity of that injury is substantially lower than it would have been.
That isn't a change in likelihood. The fall happened. The event occurred. That's a reduction in severity.
The counterargument, fairly, is that you should have installed restraints to prevent the fall rather than a net to catch it. True — and under the hierarchy of controls, that's the right approach. But that doesn't undermine the principle. Some controls are designed precisely to reduce the consequence of an event, not its probability. Safety nets, impact-absorbing PPE, secondary containment, emergency response systems — these are mitigation controls, and they affect the outcome, not the odds.
What the guidance actually says
I've looked at IOSH, RoSPA, and IIRSM on this. None of them give a definitive clean answer.
What is notable is that the GOV.UK JSP375 safety framework (updated June 2025) explicitly states that control measures "can also reduce the severity of exposure to a hazard." That's government safety guidance directly acknowledging that severity is not always fixed — it can be reduced by the right controls.
This matters. Because if the official position were that severity is always fixed, that's not what the guidance says.
The useful distinction: prevention vs mitigation
The most helpful way I've found to think about this is to separate two types of controls:
Prevention controls reduce the probability that the harmful event occurs at all. A guardrail stops someone falling. A lockout/tagout procedure stops a machine being energised while someone works on it. An interlock prevents a door opening while a process is running. These controls reduce likelihood.
Mitigation controls reduce the consequence if the event does occur. A safety net catches a falling worker. Cut-resistant gloves reduce the severity of a laceration. A sprinkler system limits the spread of fire. An emergency response plan shortens the time between incident and medical attention. These controls reduce severity.
In practice, many controls do both. But thinking about which category a control primarily falls into helps clarify whether it's right to adjust likelihood, severity, or both on your residual risk score.
Does it matter in practice?
Yes, for two reasons.
First, accuracy. A risk assessment that records the same severity score before and after the installation of a safety net isn't accurately reflecting the residual risk. That has real implications when deciding whether the risk is tolerable, or what further action is needed.
Second, proportionality. If severity can only ever stay the same or be reassessed from scratch, you end up with risk assessments that don't genuinely reflect the state of controls on the ground. The document stops being a useful tool and starts being a compliance tick-box.
The whole point of a residual risk score is to show what the risk looks like after controls. If mitigation controls genuinely change the outcome of an event, that should be reflected.
What do you think?
This is a genuine debate. I'd be interested to hear how other practitioners handle it — not what the textbook says, but what actually happens when you're sitting in front of a risk matrix.
Do you treat severity as fixed? Do you allow it to drop where a control clearly changes the outcome? And does the type of control matter in your approach?
If you want more of this kind of thing in your inbox, the SafeCompli mailing list is at safecompli.co.uk/subscribe.
You can also try RiskCompli free — no card needed — at riskcompli.safecompli.co.uk.
