A risk assessment is not about predicting the future. The purpose is far more practical: writing down what could go wrong, judging how serious it would be, and acting on it before it turns into a non-conformance, a delay or a cost nobody budgeted for.
Below we cover what a risk assessment actually is, how it is carried out in practice, what the regulations require, and why it is often the least visible risk that ends up costing the most.
What is a risk assessment?
Put simply, a risk assessment is the work of mapping what could go wrong in a project, then ranking it by how likely and how serious it is.
The assessment is the starting point for everything else in the risk work. Skip it, and the measures you take quickly become arbitrary, simply because nobody really knows where the effort is needed most.
The steps in a risk assessment
In practice the work follows four steps, and they repeat for as long as the project runs.
It is usually the fourth step that fails. An assessment that ends up in a drawer after the kick-off meeting governs nothing. It only records that somebody once had the thought.
What the regulations require
Risk assessment is not optional in Norwegian construction projects. The Building Owners’ Regulations place the responsibility on the builder to ensure that the risk conditions are assessed and that a written SHA plan is in place before work on the construction site begins.
The plan must be based on assessments made by the builder in the planning phase, and by the designers during the design process. The focus is therefore on the early stages, long before the first shovel is turned.
Safety, health and the working environment are, however, only one part of the picture. A real risk assessment must encompass a broader scope than that.
Need help with safety plans and documentation? Book a demo →
The five areas a risk assessment should cover
Risk in construction rarely arrives alone. It tends to show up in five forms that are closely connected.
The risk most assessments forget
The first four points normally make it onto the agenda. The fifth, documentation and compliance, tends to sit outside the assessment until something goes wrong.
A typical project today handles thousands of product, chemical and sustainability documents, and the requirements keep multiplying. REACH governs the chemicals, the Construction Products Regulation (CPR) sets requirements for declarations of performance, and the incoming Digital Product Passport (DPP) is designed to make products traceable. On top of that, certifications such as BREEAM and the Nordic Swan Ecolabel require evidence that hazardous substances have genuinely been kept out.
All of this can be managed. The condition is that documentation is structured and traceable from the outset, rather than being rushed together in the weeks before handover.
Control over documentation means lower risk
The difference lies in whether you react to deviations after they have occurred, or prevent them in the first place. When the status of the documentation is visible at all times, compliance ceases to be something to be feared, and becomes part of the daily control.
This is exactly what Cobuilder is made for. Product data, documentation and requirements management are collected in one place.
Seltor achieved 99% documentation quality, because requirements and documentation were followed up systematically throughout the entire process instead of collected at the very end.

