← All policies Policy

Risk assessment framework

In force from 3/12/2025 · Next review 3/12/2026

1. Purpose of the Framework

This Risk Assessment Framework outlines how Kinect CIC identifies, evaluates, manages, and monitors risks across all areas of service delivery, including work with families, adults, children, communities, staff, and partners.

The framework ensures that: - Risks are identified early and managed proportionately.

Staff understand their responsibilities for risk management.

Risk assessments follow a consistent structure across all programmes.

Controls and mitigation strategies are applied effectively.

The organisation meets legal and statutory requirements.

Service users and staff remain safe.

This framework applies to all operational environments, including centres, community venues, outreach settings, online delivery, home visits, sports/physical activities, and one-to-one sessions.

This framework complies with relevant legislation and guidance, including: - Health and Safety at Work etc. Act 1974

Management of Health and Safety at Work Regulations 1999

Reporting of Injuries, Diseases and Dangerous Occurrences Regulations (RIDDOR) 2013

Fire Safety Order 2005

Equality Act 2010

Safeguarding legislation for adults and children (Care Act 2014, Children Act 1989 & 2004)

Data Protection legislation (GDPR & DPA 2018) where risk relates to information security

3. Risk Management Principles

Kinect CIC’s approach is based on the following principles:

3.1 Prevention First

Proactively identify and reduce risks before harm occurs.

3.2 Proportionality

Risk controls should be reasonable, balanced, and practical.

3.3 Shared Responsibility

All staff and volunteers contribute to a safe culture.

3.4 Person-Centred and Family-Centred Practice

Risk management must consider the needs, vulnerabilities, and strengths of service users.

3.5 Dynamic and Ongoing Assessment

Risks change—continuous monitoring is required.

3.6 Transparency and Accountability

Risk decisions are recorded, reviewed, and communicated appropriately.

4. Types of Organisational Risk

Kinect CIC’s risk assessments cover the following categories:

4.1 Safeguarding Risks

  • Harm to children, adults, or families
  • Domestic abuse, exploitation, or neglect
  • Online safety concerns

4.2 Operational Risks

  • Inadequate staffing or supervision
  • Unsafe environments or equipment
  • Lone working
  • Community outreach risks

4.3 Health & Safety Risks

  • Accidents or injuries
  • Fire safety
  • Manual handling
  • Hazardous substances

4.4 Financial & Governance Risks

  • Fraud, financial mismanagement
  • Misuse of grant or restricted funds
  • Loss of income streams

4.5 Information & Data Security Risks

  • Data breaches
  • Insecure storage or transfer of information
  • Cybersecurity threats

4.6 Reputational Risks

  • Complaints or negative publicity
  • Staff misconduct
  • Poor-quality service delivery

4.7 Environmental & External Risks

  • Changes in policy or legislation
  • Local community challenges
  • Partner agency issues

5. Risk Assessment Structure

All Kinect CIC risk assessments must include the following elements:

5.1 Hazard Identification

Identify anything that could cause harm. Examples: unsafe flooring, lone working, challenging behaviour, IT failures.

5.2 Who Might Be Harmed?

Consider:

  • Adults
  • Children and young people
  • Families
  • Staff and volunteers
  • Contractors
  • Visitors

5.3 Risk Evaluation

Assess likelihood and severity using the Kinect CIC risk matrix (below).

5.4 Control Measures

Existing measures + additional actions required.

5.5 Residual Risk Level

The risk rating after controls are applied.

5.6 Person Responsible & Timescale

Who will implement actions and by when?

5.7 Review Frequency

Risk assessments must be reviewed regularly and updated when circumstances change.

6. Risk Rating Matrix

Likelihood Scale

1 – Rare 2 – Unlikely 3 – Possible 4 – Likely 5 – Almost Certain

Severity Scale

1 – Minor harm 2 – Moderate harm 3 – Significant injury 4 – Major injury/permanent harm 5 – Fatal/critical injury

Risk Rating = Likelihood × Severity

Risk ScoreLevelAction Required
1–5LowAcceptable with routine controls
6–12MediumAdditional controls required; monitor closely
15–25HighImmediate action required; consider suspending activity

7. Dynamic Risk Assessment

Staff must be able to identify and respond to risks in real time, especially during:

  • Home visits
  • Outreach in the community
  • Sports/physical activities
  • One-to-one sessions
  • Work with families experiencing conflict or stress

Dynamic assessment includes:

  • Observing behaviours and environment
  • Identifying escalating or new risks
  • Adapting actions accordingly
  • Seeking support from managers or safeguarding leads

Staff should always prioritise personal safety and the safety of service users.

8. Lone Working Risk Measures

Lone working requires additional precautions:

Staff must sign in/out of visits

A colleague must be aware of location and expected return time

Mobile phone must be charged and accessible

Visits should not proceed if risks are too high

A lone working risk assessment must be completed for relevant roles.

9. Home Visit & Community Outreach Risks

Risk assessments must consider: - Unknown adults at the address

  • History of violence or aggression
  • Pets or environmental hazards
  • Signs of distress, conflict, or unsafe conditions
  • Exit routes and staff safety
  • Confidentiality and privacy issues

Staff must report concerns immediately to managers or safeguarding leads.

10. Activity-Specific Risk Assessments

The following activities must have tailored risk assessments:

  • Family workshops
  • Group sessions
  • Outdoor or physical activities
  • Educational sessions
  • Trips or events

Work with vulnerable or high-risk individuals

Templates will be provided for consistency across the organisation.

11. Risk Escalation Procedure

If a risk is identified that cannot be controlled safely:

1. Stop the activity if necessary 2. Inform a manager immediately 3. Record the concern 4. Review the risk assessment 5. Implement further controls before resuming

High or repeated risks must be escalated to senior leadership and, where relevant, safeguarding teams.

12. Monitoring, Review & Governance

Kinect CIC will:

  • Review all risk assessments at least annually
  • Review them earlier if incidents occur or environments change
  • Conduct regular audits of risk management practice
  • Analyse patterns and trends in incident reports
  • Report risk-related issues to the Board quarterly

The Board holds ultimate accountability for risk governance.

13. Staff Training

All staff will receive training in:

  • Risk awareness
  • Completing risk assessments
  • Dynamic risk assessment techniques
  • Lone working protocols
  • Health & Safety procedures
  • Safeguarding (adult and child)

Ongoing refresher training is mandatory.

14. Templates and Tools

Kinect CIC will maintain and provide:

  • General Risk Assessment Template
  • Dynamic Risk Assessment Checklist
  • Lone Working Risk Assessment Template
  • Home Visit Risk Assessment Template
  • Activity-Specific Risk Assessment Templates

Staff must use the correct template for their activity.

15. Policy Review

This framework will be reviewed annually or sooner if:

Legislation changes

New risks emerge

Incidents highlight gaps or weaknesses

Approval

Signature (Directors):

Date: _________________________

Questions about this policy? Email contact@kinectcommunity.org.