A Risk Assessment Is Only As Current As Its Last Reconciliation
The value of a machine risk assessment is set by when it was last reconciled against the equipment as it actually runs today, not by the fact that a document exists in the file.
There is a document in a folder somewhere that proves your machine is safe. It has a revision number, an approval signature, a hazard table, and a date. The date is the only part that matters, and it is the part nobody reads.
A machine risk assessment is a photograph. It captures the hazards, the estimated risk, and the chosen protective measures for a machine in a particular state at a particular moment. Photographs are useful. But a photograph of a machine from two line changes ago is not a control over the machine running now. It is a record of a machine that no longer exists.
What the standard is and is not
In the international framework, machine risk assessment is governed by ISO 12100, the type-A standard that specifies the terminology, principles, and methodology for risk assessment and risk reduction in the design of machinery. It is the backbone document. It tells you how to identify hazards, estimate and evaluate risk, and reduce it through inherently safe design, safeguarding, and information for use.
Read the standard closely and you find something the filing cabinet ignores. ISO 12100 frames risk assessment across the relevant phases of the machine life cycle, and it treats risk reduction as an iterative process. The published methodology is a loop, not a line: assess, reduce, then reassess whether the measures introduced new hazards or left residual risk, and repeat. The standard also asks for documentation and verification of that process. Nothing in that model supports the idea that an assessment is finished when it is signed. The signature closes one pass of the loop. It does not close the loop.
So the standard itself is on the side of the argument here. A compliant risk assessment is not a document you produced. It is a process you keep current. The moment the machine changes and the assessment does not, you are compliant on paper and blind in practice.
How a live control becomes a dead file
Machines do not hold still. A guard interlock gets bypassed for a maintenance run and the bypass becomes semi-permanent. A robot cell gains a second infeed. Cycle rates climb after a productivity project. An operator invents a faster way to clear a jam that the original assessment never imagined, because the original assessment was written before the jam pattern existed. Each of these is a change to the hazard picture. None of them updates the document, because the document lives in a different building from the machine.
This is where the compliance-is-not-safety spine cuts hardest. The assessment on file can be immaculate, thorough, well-reasoned, correctly referencing the hierarchy of controls, and still describe a machine that stopped existing the day the line was reconfigured. An auditor pulls the file, sees a signed and dated assessment, and moves on. The auditor has verified that a document exists. Whether that document describes the equipment in front of it is a separate question, and it is almost never the question that gets asked.
The failure is quiet because nothing announces it. A missing guard triggers an alarm. A stale risk assessment triggers nothing. It sits in the file radiating false confidence, and the gap between the paper machine and the real machine widens with every undocumented change until an operator’s hand finds the difference.
Reconciliation test
Pull the risk assessment for your highest-hazard machine and stand in front of the actual equipment with it. Compare the guarding, the interlocks, the access points, and the operating tasks line by line against what the paper says. Then ask the one question that sets the document's real value: does the last-reviewed date fall before or after the most recent physical or operational change to this machine? If the machine changed after the assessment was signed, the assessment is describing a machine you no longer run.
What actually works
The fix is not more assessments. It is tying the assessment to the events that make it stale.
Trigger reassessment on change, not on the calendar. An annual review cycle will miss a modification made in March and catch it eleven months late, if at all. The reliable trigger is the change itself. Any physical modification, control-system change, new task, or discovered near-miss should force a reconciliation of the assessment before the machine returns to normal production. Management-of-change and risk assessment should be the same conversation, not two systems that never meet.
Make the last-reviewed date a visible operating parameter, not a document property. If the reconciliation date is buried in a header nobody opens, it cannot do its job. Surfacing it, so anyone can see when the assessment was last checked against reality, turns a dead field into a live signal.
Reconcile against the machine, never against the previous document. A review that only re-reads the last assessment inherits all of its blind spots. The only reconciliation worth doing walks the equipment and the tasks as they are performed today, including the workarounds operators have quietly adopted, because those workarounds are the hazards the original document could not have known about.
The existence of a risk assessment tells you almost nothing. A thick, signed, beautifully formatted assessment for a machine that was rebuilt last quarter is more dangerous than a rough one that was reconciled yesterday, because the thick one invites you to stop looking. The question is never whether the assessment exists. It is whether it still describes the machine, and the date is where you find out.