Capptions
Back to blog

What Is Risk Assessment? A Guide for Seveso and BRZO Sites

July 8, 2026

Risk assessment is the process of identifying what can go wrong, estimating how likely it is and how bad the consequences would be, and deciding what controls are needed to keep that risk acceptable. In general industry, that definition covers everything from a wet floor to a forklift collision.

For a Seveso or BRZO-classified site, the definition doesn't change, but the scale does. Risk assessment there isn't a workplace-safety exercise you file away - it's a legal input into your safety report and your major accident prevention policy (MAPP). Get it wrong, or let it go stale, and the gap shows up not in an incident report but in a scenario nobody planned for.

This article covers what risk assessment means specifically in a major-hazard context: how it differs from routine workplace risk assessment, which methodologies apply, how it connects to your veiligheidsbeheersysteem (VBS), and what triggers a review.

Risk Assessment vs. Major-Accident Risk Assessment

Most risk assessments deal with routine workplace risk: a spill, a fall, an ergonomic strain, a near-miss on the shop floor. The consequences are typically contained to the immediate area and the people working in it.

Major-accident risk assessment asks a different question: what could happen if a loss of containment, runaway reaction, fire, or explosion involving a dangerous substance escalates beyond normal control - potentially affecting multiple installations on site, neighboring facilities, or the surrounding community?

The distinction matters because it changes what you're assessing for:

  • Routine risk assessment asks: could this task hurt the person doing it?
  • Major-accident risk assessment asks: could this failure mode lead to an uncontrolled release of hazardous substances with off-site consequences?

A pump seal failure is a routine maintenance risk in most contexts. On a site handling a Seveso-threshold quantity of a flammable or toxic substance, the same failure mode is also a potential initiating event for a major accident scenario, and it needs to be evaluated as one - with its own likelihood, consequence, and barrier analysis.

Both types of assessment matter. But only major-accident risk assessment satisfies the Seveso Directive's requirement to identify and evaluate major hazards.

Where Risk Assessment Sits in the VBS

Under the Seveso Directive (and its national implementations, including BRZO in the Netherlands), operators of upper-tier establishments must maintain a veiligheidsbeheersysteem - a safety management system covering the full set of elements in Annex III.

One of those elements is "identification and evaluation of major hazards." In practice, this element has two parts that get grouped together but are distinct steps:

  1. Gevarenidentificatie (hazard identification): systematically finding the ways a major accident could originate - which substances, which process conditions, which equipment failures or human errors could initiate a loss of containment or uncontrolled reaction.
  2. Risk assessment: for each identified hazard, estimating the likelihood and severity of the resulting scenario, and determining what safeguards (technical, procedural, organizational) reduce the risk to an acceptable level.

You can't do the second without the first. Hazard identification produces the list of "what could happen"; risk assessment turns that list into a ranked, evidenced picture of which scenarios matter most and what stands between them and an actual major accident.

This is also where the VBS element stops being paperwork and starts driving decisions: it feeds directly into the safety report and the MAPP, and it's the basis auditors and regulators use to test whether an operator actually understands its own hazards - not just documented them.

Common Methodologies

No single method covers every situation. Most Seveso sites use a combination, matched to the complexity of the process and the stage of the plant lifecycle.

HAZOP (Hazard and Operability Study) A structured, team-based review of a process design or procedure, using guide words (more, less, no, reverse, other than, etc.) applied to process parameters (flow, pressure, temperature, level) at each node of the system. HAZOP is the standard method for identifying deviations from design intent that could lead to a major accident, and it's typically expected for new processes or significant modifications.

What-If Analysis A less formal, more flexible technique where a multidisciplinary team asks "what if" questions about a process, operation, or procedure and evaluates the consequences. What-If is often used for simpler processes, for revalidating existing HAZOPs, or as a complement to more structured methods.

Bow-Tie Analysis A visual method that maps a specific major-accident scenario (the "top event," e.g., loss of containment of a hazardous substance) with its causes on one side and its consequences on the other, showing the preventive barriers (stopping the cause) and mitigative barriers (limiting the consequence) in between. Bow-tie is particularly useful for communicating barrier management - showing which safeguards are in place, who owns them, and where the gaps are - and is widely used to link risk assessment findings to the safety report's barrier descriptions.

Other methods you may encounter or need depending on the hazard type include Fault Tree Analysis (probability-focused, working backward from a top event), Event Tree Analysis (working forward from an initiating event to possible outcomes), and Layer of Protection Analysis (LOPA), which quantifies whether independent protection layers reduce risk sufficiently.

The choice of method - and the justification for it - is something inspectors will ask about. "We did a HAZOP once" is not the same as demonstrating the method fits the hazard and the assessment is current.

From Risk Assessment to Safety Report and MAPP

Risk assessment isn't an end product. It's an input that has to show up, traceably, in two places:

The safety report (required for upper-tier establishments) must demonstrate that major hazards have been identified and that measures are in place to prevent accidents and limit their consequences. The scenarios, likelihoods, and barriers identified in your risk assessment are the evidence base for that demonstration - a safety report that asserts control measures without a traceable risk assessment behind them won't hold up to scrutiny.

The MAPP sets out the operator's overall aims and principles of action for controlling major-accident hazards. Risk assessment findings inform what the MAPP actually commits the organization to: which risk-reduction measures are prioritized, what resources are allocated, and how the safety management system elements are structured to address the hazards that were found.

If the connection between "what our risk assessment found" and "what our safety report and MAPP say we do about it" isn't traceable, that disconnect is exactly what a regulator or auditor will probe.

What Counts as a Major-Accident Scenario

Not every deviation is a major-accident scenario, and treating every risk assessment finding as one dilutes the ones that matter. A scenario generally qualifies as major-accident-relevant when it involves:

  • A dangerous substance present at or above Seveso threshold quantities
  • A credible pathway to loss of containment, fire, explosion, or toxic release
  • Potential consequences that extend beyond immediate task-level harm - to other parts of the installation, neighboring sites, or off-site receptors (people, environment)

A contractor tripping over a hose is a routine safety risk. A hose failure that releases a flammable substance near an ignition source, with a plausible escalation path to a tank farm, is a major-accident scenario - even if, in this instance, nothing happened. The assessment has to be done on the basis of what could happen, not just what has happened.

Review Triggers: Keeping Risk Assessment Current

A risk assessment is only as good as its last update. Seveso/BRZO frameworks expect risk assessment to be a living process, not a document produced once for the safety report and left alone. Common triggers for review include:

  • Process changes: modifications to equipment, control systems, operating parameters, or procedures that could alter the failure modes or consequences already assessed
  • New or changed substances: introducing a new dangerous substance, changing quantities, or changing storage/handling conditions
  • Incidents and near-misses: any event that reveals a scenario, cause, or consequence pathway the existing assessment didn't anticipate - including near-misses, not just actual losses of containment
  • Organizational changes: changes to staffing, contractor arrangements, or maintenance regimes that affect the human and procedural barriers the assessment relied on
  • Periodic review: even without a specific trigger, assessments need scheduled revalidation, since equipment ages, procedures drift, and assumptions made years ago may no longer hold

Each of these triggers should map to a defined action in your management-of-change process: who re-evaluates the risk assessment, on what timeline, and how the outcome feeds back into the safety report and MAPP if it changes the picture.

The Practical Takeaway

For a Seveso-classified operator, risk assessment is not a generic safety exercise - it's the analytical core of the "identification and evaluation of major hazards" element of your VBS, and the evidence base for your safety report and MAPP. Getting the methodology right (HAZOP, What-If, bow-tie, or a combination) matters less than getting the discipline right: identifying hazards systematically, distinguishing major-accident scenarios from routine risk, keeping the assessment traceable to your safety documentation, and reviewing it whenever the process, substances, or incident history change.