Insight · Occupational risks

DUERP: from risk assessment to a single document that lives.

The DUERP is the single occupational risk-assessment document every French employer must keep, from the first employee. In many companies it is written once, filed in a binder, and pulled out the day before an inspection. Yet the obligation is manageable in-house, with method. Here is how to structure the approach, from work unit to action plan.

The symptom

A document written for the inspector, not for prevention

The scene is familiar. The document exists, often drafted by a contractor three years ago from a generic sector template. The work units no longer match the actual organisation. Risks are rated on a scale no one can explain anymore. The action plan, when there is one, lives in another file, with no link to the risks that triggered it.

The result: every yearly update starts from scratch. The exercise costs time, produces nothing for the field, and protects the employer poorly. Because after an accident, an outdated document disconnected from reality turns against the company: it proves the risk was identified and nothing followed.

The remedy fits in one sentence: an assessment per work unit, a common rating grid, an action plan tied to the risks, dated versions.

The framework

What the obligation says

The foundation has been in place since 2001: every employer assesses occupational risks and records the results in a single document, from the first employee. The French law of 2 August 2021 tightened the framework. Updates are at least yearly from eleven employees, and required at every significant reorganisation or new information on a risk. Successive versions are kept for at least forty years, available to workers and former workers. From fifty employees, the assessment feeds a yearly prevention programme.

Since late June 2026, the risk has changed in nature. The French law of 25 June 2026 on fraud control allows the administration, on a report from the labour inspectorate, to impose an administrative fine when the document is missing: up to 4,000 euros per employee concerned, the cap doubled if the breach recurs within two years. Without going before a judge.

In other words: the document must exist, live, and leave a dated trail. Three requirements the method below covers.

The method

The assessment in five steps

The same approach whatever the company size. What changes is the number of units, not the method.

01

Split the company into work units

A work unit is not the org chart: it is a group of employees exposed to the same risks under comparable conditions. A workshop, a warehouse, the administrative functions, the travelling sales force.

  • A split by exposure, not by department
  • Few units beat too many
  • Revisit the split when the organisation changes
02

Identify hazardous situations

Unit by unit, describe what can cause harm: manual handling, falls from height, noise, chemicals, screen work, road risk, psychosocial risks. The right level of detail is the field's.

  • An observable situation, not an abstract category
  • The unit's employees describe it, they know
  • Nothing gets invented behind a desk
03

Rate each risk on a common grid

Two axes are enough: the severity of the potential harm and the likelihood of occurrence. Crossing them yields a criticality, from low to critical, which ranks the risks by priority.

  • The same scale everywhere, applied the same way
  • The grid explained and illustrated with examples
  • Priorities comparable across units, hence decidable
04

Tie every risk to an action plan

A rated risk with no action attached is an observation, not prevention. Every action has a named owner, a unit, a deadline and a status. Deal with the critical first, schedule the rest.

  • The risk-action link, backbone of the file
  • An owner, a deadline, a status
  • An overdue action must be visible
05

Generate the single document, and keep it

The single document is only the dated snapshot of the approach: company, headcount, risks by level, most critical risks, action plan. If the assessment is kept as you go, the yearly update becomes an edition, not a reconstruction.

  • Every version dated and archived
  • Forty years of retention: the law requires it
  • A clean export, ready for inspection
The pitfalls

Four ways to fail your risk assessment

01

The purchased document

A DUERP copied from a sector template, without a site visit, is spotted immediately, by the inspectorate as by the judge. Outsourcing can help with method, never replace knowledge of the job.

02

Variable-geometry rating

When each unit manager rates by personal sensitivity, priorities lose all meaning: the careful workshop looks riskier than the careless warehouse. The common grid, explained, is the real deliverable of the exercise.

03

The orphan action plan

Actions listed in a separate file, with no link to the risks, no owner, no deadline, die within three months. The risk-action link is what holds the whole thing together.

04

The big-bang update

Starting from scratch every year guarantees the exercise stays a chore. Good practice is the opposite: a living document, revised as things change, whose yearly version is just a freeze frame.

The tool

The approach, tooled

Everything above fits in a disciplined frame. We tooled it: work units, severity-by-likelihood rating on a common grid, an action plan tied to the risks, and the single document generated as a PDF. The approach remains yours: describe the field before tooling, as our method has it.

KEYSTONE APPLICATION

Clavis: the single document generated from the assessment

Work units, common rating grid, action plan tied to risks, PDF export of the full document. Free, in the browser, no data sent.

A risk assessment to build or to put back on its feet?

Let's start from your work units, not from a generic template.

Let's talk