Introduction
Non-profit organisations implement programmes in a wide range of environments, from offices and community centres to field visits, distribution activities and humanitarian response settings. As these environments vary, so do the risks faced by staff, volunteers and beneficiaries.
For this reason, Health, Safety and Security (HSS) should not be treated as a set of instructions used only when an incident occurs. It should be understood as a system that begins before an activity is implemented and continues throughout implementation and afterwards.
The basic principle is straightforward:
Identify Hazards → Assess Risks → Establish Controls → Monitor Conditions → Prepare for Emergencies → Report, Learn and Improve
A safe organisation is not necessarily one that has never recorded an incident. It is one that understands its risks, works to prevent harm before it occurs, can respond when circumstances change, and learns from incidents and near misses when they happen.
This article develops the original content on health, safety and security, with greater emphasis on risk assessment, preventive controls, emergency preparedness, beneficiary protection, incident reporting and organisational learning.
First: What Do We Mean by Health, Safety and Security?
Although these three concepts are closely related, each has a distinct scope.
Health
Health focuses on protecting people's physical and psychological well-being and reducing exposure to illness, fatigue and work-related health risks.
This may include healthy working conditions, access to drinking water and sanitation facilities, fatigue management, and attention to the psychological well-being of staff and volunteers.
Safety
Safety focuses on preventing accidents and injuries arising from activities, equipment, locations or working conditions.
Examples include site safety, proper use of equipment, crowd management, emergency exits, and prevention of falls and fires.
Security
Security focuses on protecting people, property and information from threats that may affect their safety or the continuity of a project.
This may include security context assessment, access control, movement and travel procedures, communication with field teams, protection of equipment and information, and procedures for responding to security incidents.
These elements are most effective when they operate as one integrated system connected to project risk management.
Second: Hazard or Risk? The Difference Matters
Before assessing risks, it is important to distinguish between two concepts:
Hazard
A source or situation with the potential to cause injury or harm.
Risk
The likelihood and severity of harm occurring as a result of exposure to a hazard.
A simple example:
Hazard: A wet floor at the entrance to a distribution centre.
Risk: A beneficiary may slip, fall and be injured.
The process should therefore not begin only by asking:
What risks exist?
It should also ask:
What are the sources of harm? Who could be harmed? And how could that harm occur?
Third: Risk Assessment Before an Activity Begins
Effective protection begins before the first beneficiary or volunteer arrives at the activity site.
A Risk Assessment should ideally connect:
Activity → Hazard → Who May Be Harmed → Likelihood → Severity → Existing Controls → Additional Controls → Responsible Person → Residual Risk
Suppose an organisation is planning a large aid distribution event.
One potential hazard may be:
Hazard: Severe crowding at the entrance.
Who may be harmed?
Beneficiaries, particularly children, older people and persons with disabilities, as well as staff and volunteers.
Potential harm:
Crowd crush, falls, injuries or disruption of the distribution process.
Controls may include:
Staggered Attendance Times → Capacity Limits → Separate Entry and Exit Routes → Queue Management → Crowd Management Staff → Monitoring Crowd Density
Risk assessment then becomes a decision-making tool rather than an administrative formality.
Fourth: Do Not Start With PPE — Use the Hierarchy of Controls
When a hazard is identified, the first response should not always be:
We need protective equipment.
A professional approach known as the Hierarchy of Controls helps organisations select more effective preventive measures:
Elimination → Substitution → Engineering Controls → Administrative Controls → Personal Protective Equipment (PPE)
Elimination
Can the hazard be removed entirely?
Substitution
Can the activity, material or method be replaced with a safer alternative?
Engineering Controls
Can people be physically separated from the hazard, or can the environment be modified to reduce exposure?
Administrative Controls
These include procedures, instructions, capacity limits, shift arrangements, training and supervision.
Personal Protective Equipment (PPE)
PPE should be used where appropriate as part of controlling a hazard, rather than as a substitute for eliminating or reducing the hazard where that is reasonably possible.
The principle is:
Control the hazard at its source before relying on individual behaviour to protect people from it.
Fifth: The Project Health, Safety and Security Plan
Once risks have been assessed, the findings should be translated into a practical plan proportionate to the project's size, nature and level of risk.
The plan may include:
- Roles, responsibilities and authority.
- Key risks and approved controls.
- Instructions for higher-risk activities where applicable.
- Training requirements.
- First-aid arrangements.
- Emergency communication procedures.
- Evacuation and assembly points.
- Incident and near-miss reporting.
- Site security and access procedures.
- Review and update mechanisms.
The plan should not operate separately from project management. Safety requirements may affect the location, budget, resources, schedule and method of implementation.
Sixth: Risks Do Not Remain Static During Implementation
A site assessment may be appropriate in the morning, while conditions may change significantly later in the day.
Attendance may unexpectedly increase, weather conditions may deteriorate, an emergency exit may become unavailable, the security context may change, or a new hazard may emerge.
Some activities therefore require a Dynamic Risk Assessment during implementation:
What Has Changed? → Has the Risk Level Changed? → Are Existing Controls Still Adequate? → Should We Continue, Modify or Stop the Activity?
This introduces an important principle:
Stop-Work Authority
The organisation should define when an activity can be stopped because the risk has become unacceptable, who has the authority to make that decision, how escalation takes place, and who approves the resumption of work.
Completing an activity should never take priority over people's safety.
Seventh: Emergency Preparedness — What If Prevention Fails?
Even with effective controls, not every incident can be prevented.
Organisations therefore need Emergency Preparedness and Response arrangements proportionate to the risks they face.
The team should know:
What constitutes an emergency?
Who leads the response?
Who contacts whom?
How will evacuation take place?
Where are the assembly points?
Where is first-aid equipment located?
How will people who may require additional assistance be supported?
How will the incident be escalated and communicated to the relevant authorities where necessary?
Having a plan in a file is not enough.
For activities where it is appropriate, emergency drills help test whether the plan actually works.
Eighth: Training Should Match the Role and the Risk
Not every employee requires the same training.
Training should reflect the person's responsibilities and level of exposure.
A field worker may require different knowledge from an office employee, while the person responsible for a major event will require different competencies from a volunteer supporting an activity for only a few hours.
Depending on the role, training may cover:
- Hazard identification and reporting.
- Project-specific health, safety and security procedures.
- Safe use of equipment.
- Emergency response.
- First aid for appropriately designated and trained personnel.
- Crowd management.
- Security and field communication procedures.
- Supervisory responsibilities during incidents.
New staff and volunteers should receive an appropriate Safety Induction before being assigned duties that may expose them or others to risk.
Ninth: Beneficiary Protection Is an Essential Part of Planning
An organisation's responsibility does not end with its staff.
Activities should be designed with the safety of beneficiaries in mind, particularly people who may be more vulnerable to harm.
This may include:
- Safe sites and facilities.
- Appropriate attendance and capacity management.
- Organised entry and exit.
- Appropriate accessibility.
- Consideration for children, older people and persons with disabilities.
- Adequate supervision according to the nature of the activity.
- Protection of privacy and dignity.
- Clear channels for reporting safety concerns.
It is also important to distinguish between Health, Safety and Security and Safeguarding.
The two areas overlap, particularly in protecting children and people at greater risk, but HSS does not replace a dedicated Safeguarding system designed to prevent and respond to exploitation, abuse, harassment, neglect and other protection concerns.
Tenth: Mental Health and Fatigue Are Part of Safety
Not every hazard is visible.
Long working hours, repeated exposure to difficult humanitarian situations, emergency pressure and insufficient rest may affect psychological well-being, concentration and decision-making.
Organisations should therefore consider factors such as:
- Workloads.
- Working hours and rest periods.
- Signs of fatigue.
- Repeated exposure to distressing situations.
- Supportive team environments.
- Access to appropriate support when needed.
This is not only about employee well-being. Fatigue can also contribute to errors in judgement, implementation and safety.
Eleventh: Incidents and Near Misses — Learn Before the Error Is Repeated
Not every dangerous event results in an injury.
Suppose a heavy object falls beside a volunteer without hitting them.
It may appear that:
Nothing happened.
But this is an important Near Miss, because the same circumstances could have resulted in a serious injury.
Reporting systems should therefore extend beyond injuries to include:
Incident + Near Miss + Unsafe Condition
followed by:
Report → Immediate Response → Investigation → Root Cause → Corrective Action → Verification → Learning
The purpose of an investigation should not simply be to determine:
Who made the mistake?
The more important question is:
Why did the system allow this to happen, and how can we prevent it from happening again?
Staff should therefore be encouraged to report concerns and incidents professionally and in good faith, without creating a culture that drives people to conceal errors or hazards.
Twelfth: How Should HSS Performance Be Measured?
Counting incidents alone is not enough.
It is useful to distinguish between two categories of indicators:
Lagging Indicators
These describe what has already happened, such as:
- Number of incidents.
- Number of injuries.
- Incident frequency.
- Lost workdays due to injury where this is an appropriate measure.
Leading Indicators
These measure actions that help prevent incidents, such as:
- Percentage of activities preceded by a Risk Assessment.
- Percentage of staff who completed required training.
- Number of reported Near Misses.
- Percentage of corrective actions closed on time.
- Percentage of planned site inspections completed.
- Percentage of planned emergency drills completed.
One important caution applies:
A low number of incidents alone does not prove that the safety system is effective.
Incident numbers may be low because risks are well controlled, or because staff are not reporting them.
Indicators should therefore be interpreted together.
Thirteenth: Who Is Responsible?
Health, safety and security are shared responsibilities, but accountability must remain clearly defined.
The Board oversees the framework, policies and significant risks at the appropriate level.
Executive Management provides resources and ensures implementation and performance monitoring.
Project Managers integrate HSS requirements into planning, budgets and implementation.
Field Supervisors monitor actual conditions, implement controls and respond to changing circumstances.
Staff and Volunteers follow procedures and report hazards, incidents and near misses.
Saying:
Safety is everyone's responsibility
should not mean that responsibility becomes unclear.
Each person should know what is expected of them, what decisions they are authorised to make, and when escalation is required.
Fourteenth: How Can a Donor Know That the System Actually Works?
Having a Health & Safety Policy is important, but it does not by itself demonstrate implementation.
Institutional evidence may include:
Policy → Risk Assessments → HSS Plans → Training Records → Emergency Plans → Inspection Records → Incident & Near-Miss Reports → Corrective Actions → Management Reviews → Evidence of Improvement
One of the strongest readiness tests is:
Show us the most recent significant incident or Near Miss.
Then ask:
How was it reported?
How did the organisation respond?
Was it investigated?
What was the Root Cause?
What Corrective Actions were identified?
Who was responsible for them?
Were they closed?
Was the Risk Assessment or relevant procedure updated afterwards?
This test reveals the difference between an organisation that has safety documentation and one that has a safety system that operates and learns.
Fifteenth: Health, Safety, Security and Institutional Governance
HSS should not operate separately from the organisation's other management systems.
Significant health, safety and security risks should, where appropriate, appear in the institutional Risk Register, with relevant information reaching executive management and the Board.
Findings from incidents and reviews should also influence:
Policies → Procedures → Training → Project Design → Budgets → Controls → Future Decisions
This is consistent with the general logic of occupational health and safety management systems such as ISO 45001, which emphasises leadership and worker participation, hazard identification and risk assessment, operational controls, emergency preparedness, performance evaluation and continual improvement.
Reference standard: ISO 45001 — Occupational Health and Safety Management Systems
Before Moving to the Next Article...
An organisation can begin by reviewing a limited set of practical questions:
✓ Have we identified the Hazards associated with our main activities?
✓ Do significant-risk activities undergo Risk Assessments before implementation?
✓ Do we use the Hierarchy of Controls when selecting preventive measures?
✓ Does the team know when an activity should be modified or stopped?
✓ Are Emergency Plans proportionate to the actual risks?
✓ Do staff and volunteers receive training appropriate to their roles?
✓ Do our procedures address beneficiary safety and people at greater risk?
✓ Do we distinguish between HSS and Safeguarding while connecting them where appropriate?
✓ Do we report Near Misses as well as injuries?
✓ Do we investigate the Root Causes of incidents?
✓ Do we monitor the closure of Corrective Actions?
✓ Do we use both Leading and Lagging Indicators?
✓ Are significant risks escalated to management and the Board?
✓ Can we demonstrate that an incident or Near Miss resulted in an actual improvement?
Conclusion
Health, safety and security are not a set of instructions added to a project after it has been designed. They are part of how a project should be planned, implemented and reviewed from the outset.
An effective system begins by identifying hazards, assessing risks, selecting appropriate controls, training people, monitoring changing conditions, preparing for emergencies, and giving teams the authority to stop when conditions become unsafe.
When an incident occurs—or nearly occurs—the organisation's responsibility does not end with addressing the immediate consequence. Another process begins: understanding the cause, correcting the weakness, updating procedures, and preventing recurrence.
The real test of institutional maturity is therefore not:
How many incidents have we had?
but rather:
Do we know where harm could occur, do we act before it happens, and do we learn when experience reveals that our system needs improvement?
At that point, health, safety and security become more than an administrative requirement or donor condition. They become part of the organisation's responsibility toward people and the quality with which it delivers its mission.