Risk and threat assessment
A risk assessment is only worth its cost if somebody can act on it. Almost everyone who asks us intends to go anyway. Our job is therefore not to talk you out of it but to find the version that holds: this route, this timing, this local partner, this measure now and that one once an indicator moves. The decision itself stays with you.
What the work covers
Country and area assessments for a specific operation, rather than a subscription feed rewritten with your logo on it. Site security surveys, on the ground, with photographs and a fix list ordered by what actually reduces exposure. Threat assessments where a named person or group is the concern. Security program design for organizations that have grown past ad hoc measures. Audits, including of providers already engaged.
We write the assumptions down. Every assessment states what we could not verify, what would change the conclusion, and when it should be reviewed. An assessment that reads as certain about a place where certainty is not available is the most common failure in this field.
We make it work
Almost everyone who asks us intends to travel anyway. So our job is not to talk you out of it but to find the version that works, meaning this route, this window, this local partner, this precaution. In the large majority of cases there is one. Where we do advise against it, that goes in writing with the reasoning and with what would have to be different for it to hold.
The decision is yours. We advise, and it belongs to the person who answers for it.
For that to work the assessment has to do two things. It has to be solid enough for a decision to rest on. And it has to be written so that the basis for that decision can still be reconstructed later, including when the situation afterwards went another way.
Who delivers on the ground
This capability is advisory end to end, so there is nothing to divide up. The assessment, the survey and the report are ours. Where a site visit needs local access, transport or a fixer, a local intermediary who opens doors, that is arranged locally and named in the report, including anything that access constraint kept us from seeing.
Sources are cited. Where a conclusion rests on our own observation rather than a document, we say that too, because the two carry different weight when your board reads it.
Standards we work to
Questions we get asked
How is this different from a country risk subscription?
A subscription tells you the country rating. It does not know that your site sits on the wrong side of a river with two bridges, that your staff are hired mainly from one community in a place where that matters, or that your evacuation plan assumes an airport that closes at dusk. Assessment is the work of connecting the general picture to your specific exposure.
Will you tell us not to go?
It happens, but rarely, and it is not the point of the exercise. In most cases an operation in a difficult place is workable once the route, the timing or the local partner changes. When we do advise against it, we say so in writing with the reasoning, and we say what would have to be true for it to work.
How long does an assessment hold?
That depends on the context, not on the calendar. A site assessment in a stable country can hold for two years. A picture of a region in active escalation is out of date within weeks. So every assessment names the indicators we watch and the change that triggers a re-assessment. If you keep us on, we come back to you when one of them moves.
Can you take over our statutory risk assessment?
Under sections 5 and 13 of the German Occupational Safety Act (ArbSchG), the duty sits with the employer and cannot be delegated away. We are not your appointed safety officer, but we are qualified to produce the assessment itself, and the NEBOSH International General Certificate is the evidence for that. What we mainly supply is the part an in-house safety officer rarely covers: the exposure of your people abroad, by destination, travel profile and type of deployment, in a form your safety officer can adopt and sign.
The legal basis is section 13(2) ArbSchG, under which an employer may appoint reliable and competent persons in writing to carry out duties under the act on their own responsibility. A formally appointed safety specialist is not required for that, because the role under section 6 ASiG is advisory rather than an execution monopoly. What counts is competence for that specific work area. Overall responsibility stays with the employer, who still owes careful selection and supervision of whoever is appointed, and the separate duty to appoint a safety specialist under the ASiG is unaffected. That is why we write the assessment so your management can check it and sign it.
Many miss one part. Under section 8 of the ArbSchG the assessment does not stop at your own payroll. Where people employed by different companies work together, the hazards have to be communicated both ways and the measures coordinated, and you have to satisfy yourself that the contractor has instructed its people.
Can you audit a provider we already use?
Yes, and it is one of the more common requests. We assess against the contract you signed and the standard the work actually needs, which are frequently not the same document.
What does the documentation do for us if something happens anyway?
No program takes risk to zero, and anyone promising that is selling something else. What can be shaped is the question asked after an incident. Did the organization recognize what was recognizable, and did it do what the accepted standard required?
That question is not answered afterwards. It is answered out of the paperwork that already existed. So we work along named standards, ISO 31000 and ISO 31030, the ArbSchG and DGUV Vorschrift 1, and every report states what a finding rests on, what stayed unverified, and when it has to be reviewed. What comes out is a traceable line from assessment to decision to measure.
We are not a law firm and we do not give legal advice. What we supply is evidence that the work was done with care, in a form your counsel and your insurer can read.
Other capabilities
Travel risk management and duty of care
Travel risk programs built to ISO 31030, thresholds through escalation.
Learn moreProtective services and close protection
Protective concepts, advance work and command, low profile by design.
Learn moreCrisis and emergency management
Crisis structures with named roles, exercised before handover.
Learn moreTalk it through first
Every engagement starts with a confidential conversation, and it is free. Describe the operation and the concern. We will tell you honestly whether this is the right capability, another one, or nothing at all.
enquiries@foxpedition.com