Risk assessment vs risk management vs health and safety

Residential Security Handbook 2021: Secure Living Residential Estate (Industry), Security Services & Risk Management, Products & Solutions

Risk management and a security risk assessment are often seen as the same thing, when in fact, they are two vastly different things. The security risk assessor’s question is not if you have security, but rather if you have a security risk assessment. The general perception is that a security risk assessment and security is the same thing, however, these two concepts are two very different things, related, but different.


Andre Mundell.

We believe that the risks need to be identified first before any management can take place. Security risk assessments specialise in the identification of security risks. The best way to describe a security risk assessment is as a ‘crime fighting tool’ and it only works if it is done independently. This consists of finding the security risks that provide opportunities for crime.

When conducting a security risk assessment, the assessor looks at outer crime as well as inner crime. Most people only look at outer crime and do not consider inner crime to be a concerning factor. In most cases, it is the inner crime factor that brings estates and companies to their knees.

A security risk assessment is an in-depth investigation into your current security measures to establish if there are any risks. When the risks are identified, the assessor finds suitable, risk-specific solutions to eliminate these risks. Some risks cannot be covered by security hardware; however, the assessor provides ample advice in the security plan that will eliminate these risks by means of processes, protocols and the application of security knowledge and understanding.


Once all the risks are identified and the assessor has found suitable solutions to eliminate the risks, he/she compiles all the information into a document that gets handed over to the client. When a security risk assessment report is read and understood, the risk manager can take over as he now knows and understands what the risks are and will be able to manage these risks in accordance with the security risk assessment.

Working under the risk manager, you will usually find a security manager, health and safety manager, building manager, and sometimes an asset manager.

When it comes to health and safety, we are dealing with the ‘probability’ or ‘likelihood’ of something, like an accident. A security risk assessment, on the other hand, looks at the opportunities for crime and when specific risks are identified, measures are put in place to manage these risks.

Keep in mind that the Health and Safety Act states that the business/company must ensure that no harm comes to employees or visitors. When this is interpreted correctly, the protection of employees and visitors includes security and crime as well. In South Africa, health and safety is governed by the law which means that it will automatically come first and take up most of the time and focus. Physical security is almost always neglected and left behind.

Neither of these aspects, whether it is risk management, health and safety, or physical security, are more important than the other. They are not the same, in fact, they are vastly different and should all be managed accordingly. In addition, health and safety, risk management and physical security must be managed by separate individuals and not one person alone.

If security is not managed as it should be, and the risks are not identified, the door is wide open for crime.


Credit(s)




Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

Understanding the Shared Responsibility Model
Infrastructure Security Services & Risk Management
While the cloud can certainly be a growth enabler in many ways, it can also introduce new security risks. Companies want to have a clear understanding of where their security duties end and where their cloud service provider’s begin.

Read more...
Cloud security in visitor management and access control
SA Technologies Access Control & Identity Management Infrastructure Residential Estate (Industry) Commercial (Industry)
Cloud has become the default platform for modern security operations, from visitor management portals and remote access control to incident logging, reporting, analytics, and integrations. But “in the cloud” does not mean “someone else is securing it for us”.

Read more...
Centurion raises the bar at HomeSec Expo
Centurion Systems News & Events Access Control & Identity Management Residential Estate (Industry) Smart Home Automation Commercial (Industry)
Centurion Systems unveiled its latest product lines at HomeSec Expo 2026, introducing SMART+, a simpler way for installers and end users to manage their Centurion installations - as well as a few new products.

Read more...
SMARTpod talks about HomeSec Expo 2026
SMART Security Solutions Technews Publishing News & Events Residential Estate (Industry) Videos
SMARTpod, the podcast from SMART Security Solutions, finds out more about the upcoming HomeSec Expo happening at Gallagher Estate on 4 & 5 March 2026.

Read more...
“This Is Theft!” SASA slams Mafoko Security
News & Events Security Services & Risk Management Associations
The Security Association of South Africa (SASA) has issued a stark warning that the long-running Mafoko Security Patrols scandal is no longer an isolated case of employer misconduct, but evidence of a systemic failure in South Africa’s regulatory and governance structures.

Read more...
Bringing fire safety closer to home
SafeQuip Fire & Safety Products & Solutions Smart Home Automation
SafeQuip’s latest product launch introduces two compact, disposable fire extinguishers for everyday use, one suitable for Class A, B, and C fires, the other rated for Class A, B and F fires.

Read more...
Making a mesh for security
Information Security Security Services & Risk Management
Credential-based attacks have reached epidemic levels. For African CISOs in particular, the message is clear: identity is now the perimeter, and defences must reflect that reality with coherence and context.

Read more...
From surveillance to insight across Africa
neaMetrics TRASSIR - neaMetrics Distribution Access Control & Identity Management Surveillance Products & Solutions
TRASSIR is a global developer of intelligent video management and analytics solutions, delivering AI-driven platforms that enable organisations to monitor, analyse, and respond to events across complex physical environments.

Read more...
From friction to trust
Information Security Security Services & Risk Management Financial (Industry)
Historically, fraud prevention has been viewed as a trade-off between robust security and a seamless customer journey, with security often prevailing. However, this can impair business functionality or complicate the customer journey with multiple logins and authentication steps.

Read more...
Security ready to move out of the basement
AI & Data Analytics Security Services & Risk Management
Panaseer believes that in 2026, a board member at a major corporation will lose their job amid rising breaches and legal scrutiny, as organisations recognise that cyber risk is a business risk that CISOs cannot shoulder alone.

Read more...










While every effort has been made to ensure the accuracy of the information contained herein, the publisher and its agents cannot be held responsible for any errors contained, or any loss incurred as a result. Articles published do not necessarily reflect the views of the publishers. The editor reserves the right to alter or cut copy. Articles submitted are deemed to have been cleared for publication. Advertisements and company contact details are published as provided by the advertiser. Technews Publishing (Pty) Ltd cannot be held responsible for the accuracy or veracity of supplied material.




© Technews Publishing (Pty) Ltd. | All Rights Reserved.