Search any safety forum and you'll find the same argument running for years: is a JSA different from a JHA? Do we need a risk assessment if we already have JSAs? Is one of them "the OSHA one"?
Let's settle it up front:
JSA and JHA are the same document. A Job Safety Analysis and a Job Hazard Analysis are two names for one method: break a task into steps, identify the hazards at each step, and define the controls. OSHA uses "job hazard analysis" in its official guidance (Publication 3071). Much of industry, especially construction and oil and gas, says "JSA." The structure, purpose, and output are identical. If your site argues about which term to use, you are having a branding discussion, not a safety discussion.
A risk assessment is a different tool. It shares DNA with the JSA (identify hazards, apply controls) but differs in scope, method, and where it sits in your safety management system. That difference is worth understanding, because the two documents answer different questions.
What a JSA/JHA does
A JSA is task-level and worker-facing. It answers the question: what could hurt someone doing this specific job, and what are we doing about it at each step?
Its defining features:
- Scope: one task. Changing a pump seal, unloading a tanker, clearing a conveyor jam. Not the whole plant.
- Structure: sequential steps. The job is broken into roughly 10 to 15 steps, with hazards and controls listed against each one.
- No formal risk scoring. A classic US-style JSA doesn't rate likelihood or severity. It identifies the hazard and states the control. The judgment about acceptability is embedded in the hierarchy of controls, not in a number.
- Audience: the crew. A good JSA is reviewed at the job, signed by the workers, and lives where the work happens. In the US, the JSA earns its keep against specific obligations: the General Duty Clause requires employers to identify and control recognized hazards, 29 CFR 1926.21(b)(2) requires hazard instruction in construction, and 29 CFR 1910.132(d) requires a written, certified PPE hazard assessment. A signed JSA is the working evidence for all three.
What a risk assessment does
A risk assessment is broader and management-facing. It answers a different question: of all the hazards we face, which ones matter most, and is our residual risk acceptable?
Its defining features:
- Scope: a process, area, project, or whole site. A risk assessment can cover an entire facility, a department, or a project phase. It captures hazards a task-level JSA never sees: extreme weather, plant-wide traffic, workplace stress, slips and trips in common areas.
- Formal risk scoring. The signature element is the risk matrix. Likelihood is scored against severity, commonly on a 5x5 grid producing a rating from 1 to 25, and hazards are ranked so resources go to the biggest exposures first. Scoring is typically done twice: once for the raw hazard, and again for residual risk after controls.
- Management sign-off. Risk assessments feed prioritization decisions, budgets, and audits. They are reviewed and approved above the crew level.
- Regulatory home: management system standards and non-US law. ISO 45001 (clause 6.1.2) requires a systematic process for hazard identification and risk assessment. UK law requires documented risk assessments outright. Many multinationals and Gulf-region regulators require the same under the banner of HIRA (Hazard Identification and Risk Assessment). US OSHA, by contrast, never mandates a scored risk matrix. It requires hazard assessment and control, and accepts any consistent, documented approach. That last point explains most of the confusion. A US plant can be fully OSHA-compliant with JSAs and no risk matrix in sight. The same plant, once it pursues ISO 45001 certification or gets bought by a European parent, suddenly needs formal risk assessments too. Neither document replaced the other. They were never doing the same job.
The relationship: one feeds the other
The cleanest way to think about it:
- The risk assessment is the map. It surveys everything, scores it, and tells you where the danger concentrates.
- The JSA is the street view. It zooms into one high-risk task from that map and works out, step by step, how the crew does it safely today. They connect in both directions. Your risk assessment tells you which tasks deserve a JSA first: start with the red squares on the matrix. And your JSAs feed the risk assessment: ISO 45001 guidance explicitly treats existing JHAs/JSAs as inputs to the site-wide risk picture. A near miss captured on a JSA review should move a score on the risk register. A re-scored risk should trigger a JSA update.
When the two documents live in separate binders and never touch, that loop breaks. The risk register describes a site from two years ago, and the JSAs protect against hazards nobody has ranked.
Which one do you need?
You need a JSA/JHA when:
-
A specific task has injury or near-miss history
-
One error in the task could cause serious injury or death
-
The task is new, changed, or non-routine
-
You need documented evidence of hazard instruction and PPE assessment for a task You need a risk assessment when:
-
You're pursuing or maintaining ISO 45001 certification
-
You operate under UK, EU, Gulf-region, or other legislation that mandates documented risk assessment
-
A client or parent company requires scored risk documentation (common in oil and gas, energy, and federal contracting)
-
You need to prioritize: too many hazards, finite budget, and a decision to make about where controls go first In practice, mature safety programs run both. The risk assessment sets priorities at the site level; JSAs control the work at the task level. Small US operations often start with JSAs alone, and that's a legitimate starting point. But the moment you're comparing hazards against each other to decide where to spend, you're doing risk assessment whether you've written it down or not. Writing it down is the part that survives an audit.
A quick word on the cousins
Two related terms you'll meet in the wild:
- AHA (Activity Hazard Analysis): the federal-contracting version of a JSA, required on US Army Corps of Engineers projects under EM 385-1-1. It's a JSA plus formal risk codes, equipment and training requirements, and government approval workflow. If you work USACE contracts, this is its own topic.
- HIRA: the term for systematic hazard identification and risk assessment used under ISO 45001 and across the Gulf and South Asia. Functionally, it's what this article calls a risk assessment.
The real problem isn't terminology
Whatever you call the documents, they fail the same way: written once, filed, and never revisited. The JSA that doesn't reflect the current equipment. The risk register with scores nobody has challenged since the audit. The review date that passed silently eight months ago.
Keeping the two connected, current, and signed is a version-control problem more than a safety-knowledge problem, and it's exactly where paper systems quietly fall apart.
Start with the task level: our free one-page JSA/JHA template follows the OSHA 3071 method, includes the written PPE hazard assessment certification most templates miss, and comes with a one-page completion guide.
Download the free JSA/JHA template →
And when you need JSAs, risk registers, permits, and lockout procedures talking to each other instead of living in separate binders, that's what Zentri does.
