Home Events Risk Assessments — plan safer excursions …

Risk Assessments — plan safer excursions and events

By mario· Aug 31, 2026 · Events

Every excursion, camp and incursion needs a documented risk assessment before it runs — every Australian state and territory requires one, and they all ask for the same things: what the activity is, who is supervising, what could go wrong, what you will do about it, and what the plan is if something goes wrong anyway.

PortalHQ now builds that document into Event Planner. When an event’s type requires a risk assessment, the event cannot be approved until the assessment is complete — and the person filling it in gets a structured form rather than a blank page: activity and venue details, staffing and supervision, transport legs, a proper risk register with calculated ratings, and an emergency management plan. The field set follows the Victorian ERREMP, the Queensland CARA planner and the NSW excursions policy, which all sit on the AS/NZS ISO 31000 standard, so what you produce here lines up with what your jurisdiction expects.

This guide covers turning the feature on, configuring it for your event types, filling in an assessment, getting it approved, and what it gives you on the day of the activity.

Before you start

  • Risk assessments are off by default. A portal admin needs to switch them on for your school (see the next section).
  • The feature lives inside Event Planner, so it only applies to events — there is one risk assessment per event, and it is created from the event itself.
  • Risk assessments are staff-only. Parents and students never see them (parents see only the consent slip, if you send one).
  • If you want parent consent notes generated from the assessment, you’ll need a Slip Form built in the form builder first — more on that below.

Setting it up (portal admins)

1. Turn it on for the school

Go to Settings → School Settings and enable Risk assessments (you’ll find it in the Staff and Student Links column). This adds a Risk Assessments entry to the Events menu in the sidebar and activates everything described in this guide.

2. Tell PortalHQ which event types need one

Not every event needs a risk assessment — a staff meeting doesn’t, a three-day camp certainly does. This is controlled per event type.

Go to Event Planner → Types, open an event type, and find the Risk assessment section. There are three settings:

Setting What it does
Requires risk assessment Events of this type cannot be approved until their risk assessment is complete. This is the master switch — without it, events of this type are entirely unaffected.
Risk assessment sections Which sections staff fill in for events of this type. Four sections are always shown — Activity, Staffing and supervision, Risk register and Emergency plan — and are marked “(always shown)”. The optional ones are Transport, Students and medical and School questions. Leaving everything ticked keeps the full form.
Parent consent form The slip form used for the parent consent note on events of this type. Only forms whose type is Slip Form appear here; leave it as “No consent form” if you don’t want consent handled through PortalHQ for this type.

If the picker shows no forms, your school doesn’t have a Slip Form yet: open (or create) a form in the form builder, go to its Properties tab, and set Form type to “Slips Form”.

A sensible starting point: switch on Requires risk assessment for your excursion and camp types, leave all sections enabled for camps, and drop the Transport section from incursion types where nobody leaves the grounds.

Tip: if you open an event type’s Risk assessment section before enabling the school setting, you’ll see a note that risk assessments are switched off for the school and nothing there takes effect yet. Turn the school setting on first.

3. Add your school’s own questions (optional)

If your school’s template asks something the standard form doesn’t — a diocesan approval number, a sun-safety declaration — you can add your own fields without losing the standard structure.

Go to Event Planner → Additional Fields, create a field as usual, and set its Section to Risk assessment (rather than “Event request”). It will appear in a School questions section at the bottom of every risk assessment, and its answers are saved with the assessment.

Starting a risk assessment

Once your event type is configured, the workflow starts from the event itself:

  1. Create your event as normal in Event Planner.
  2. On the event’s summary page you’ll see a Risk assessment card. It shows Start if no assessment exists yet, or Open if one does.
  3. Click Start. The assessment is created immediately and pre-filled from the event — the activity description comes from the event description, the venue from the event location, the staff in charge from the event owner, and the excursion duration is guessed from the event dates (a same-day event becomes a Day excursion, one night becomes Overnight, longer becomes Multi-day camp). Check the pre-filled values rather than trusting them; they’re a head start, not an answer.

You can also reach existing assessments from the sidebar under Events → Risk Assessments, which lists every assessment you’re allowed to see.

At the top of the assessment you’ll find a summary strip showing the Status (Draft, Submitted for approval, or Approved), the Highest residual risk across your register, and the Version. Below that, a row of section chips shows which sections are done and which are still outstanding — click a chip to jump to that section.

Working through the sections

The assessment is one long form of tiles. You can fill it in over several sittings — the save bar at the bottom tells you how many sections are still outstanding, and Save risk assessment keeps everything as a draft until you’re ready.

Activity

What is being run, where, and why. Alongside the description and venue details (including a venue contact), two fields matter more than they look:

  • Educational purpose — the curriculum link or educational rationale for the activity. Every state policy asks for this, and approvers read it first.
  • External provider — if a third party runs the activity (a ropes course, a surf school), record them here, and tick the box confirming they supplied their own risk assessment, insurance and accreditation.

Staffing and supervision

Who is in charge, and who is supervising:

  • Staff in charge — the teacher in charge; must be a registered teacher — plus their mobile and a second-in-charge.
  • Supervision ratio — your planned staff-to-student ratio, for example 1:15.
  • First aid staff — pick the staff on the activity who hold a current first aid qualification, and confirm a first aid kit is carried.
  • Volunteers — how many, with a Volunteer WWCC verified confirmation that all volunteers hold a current Working With Children Check.
  • Staff training notes — anything specific, for example anaphylaxis or asthma management training.

Transport

Each leg of the journey there and back gets its own row — a camp routinely mixes a chartered bus with a walk and a ferry, and each leg has its own risks. Click Add transport leg and record the mode (walking, chartered bus, school bus, public transport, private vehicle, air travel, water vessel or other), the operator and their accreditation number where relevant, departure and return points and times, and the supervision arrangements during travel, including your headcount procedure.

Risk register

This is the heart of the assessment: hazards, their controls, and the risk left over. Click Add hazard for each row and record:

  • Category — Transport and travel, Venue and facilities, Activity and equipment, Environment and weather, People and supervision, Medical and first aid, Food and catering, Child safety, or Other.
  • The hazard — what it is, and how it could cause harm — and who is at risk.
  • Inherent likelihood and inherent consequence — how likely, and how bad, before you do anything about it.
  • Controls — the control measures you will put in place. This is required: a hazard without controls won’t save.
  • Control hierarchy — where your main control sits on the standard hierarchy: Eliminate, Substitute, Isolate, Engineering / redesign, Administrative, or Personal protective equipment.
  • Residual likelihood and residual consequence — how likely, and how bad, with your controls in place.
  • A responsible person and a due by date, so each control has an owner.

You never type a risk rating — see the next section.

Emergency plan

What happens if something goes wrong: the nearest medical facility with its address and phone number, your school emergency contact and after-hours contact, communication arrangements (mobile coverage, radios or satellite phone), rescue, resuscitation and first aid procedures, what would cause the activity to be cancelled, recalled or altered — and who decides — and your missing-student procedure.

School questions

Any extra questions your school has added appear here (see Setting it up, step 3).

How risk ratings work

Ratings in the register are calculated, never typed. For each hazard you choose a likelihood (Rare, Unlikely, Possible, Likely, Almost certain) and a consequence (Insignificant, Minor, Moderate, Major, Catastrophic), and PortalHQ derives the rating from the standard 5×5 matrix — so nobody can record a rating the matrix wouldn’t produce.

Insignificant Minor Moderate Major Catastrophic
Almost certain Medium High High Extreme Extreme
Likely Medium Medium High High Extreme
Possible Low Medium Medium High Extreme
Unlikely Low Low Medium Medium High
Rare Low Low Low Medium High

Each hazard shows two rating pills: the inherent rating (before controls) and the residual rating (after controls). Until you’ve picked both a likelihood and a consequence, the rating reads “Not rated yet”.

The residual rating is the one that matters. If a hazard’s residual rating is High or Extreme, the assessment flags it — “Reduce this before the activity runs.” — and the highest residual rating across the whole register is rolled up into the summary strip, the event’s risk assessment card, and the register listing, so it’s visible everywhere without opening the assessment.

Copying the risk register from a previous event

The Year 5 camp runs every year, and so do its hazards. Rather than rebuilding the register, click Copy from another event on the Risk register tile. A dialog lets you search earlier assessments at your school — each option shows the event, its date and how many hazards it holds — and Copy risk register brings the hazard rows across.

A few things to know:

  • Rows are copies — editing them here won’t change the original, and anything already in your register is kept.
  • Only the hazard rows come across. The responsible person and due-by date don’t, because they belong to this year’s activity — assign them fresh.
  • The button only appears once your school has at least one other assessment to copy from. (A hazard library is on the roadmap; for now, copying from last year’s event is the intended shortcut.)

Submitting and approval

What counts as complete

The save bar tracks completeness for you, but for reference, a section is complete when:

Section Complete when
Activity Activity description and educational purpose are filled in
Staffing and supervision Staff in charge and supervision ratio are set
Transport At least one transport leg is recorded
Risk register At least one hazard is recorded
Emergency plan Emergency procedures and nearest medical facility are filled in

(Students and medical, and School questions, don’t gate anything.)

Submit for approval

Once every section is complete, a Ready for approval bar appears with a Submit for approval button. Submitting is your explicit “I’m finished” signal: it records who submitted and when, sets the status to Submitted for approval, and — if the event is still a draft — moves the event into the approvers’ queue and emails the first approval group. An event already partway through its approval chain is left where it is, so submitting never undoes progress the approvers have already made.

You can still edit the assessment after submitting.

Approval

Approval happens through the event’s existing approval chain — there is no separate risk assessment approval. Two things change for approvers:

  • Approvers can open and read the risk assessment from the event, but they can’t edit it. Approvers read; the event’s staff write. Send-backs work the way they always have — More info needed returns the event to its author with a note.
  • If the event type requires a risk assessment and it isn’t complete, the approve screen shows a Risk assessment not complete blocker naming exactly which sections are outstanding, with a link to open the assessment, and the approve button is disabled until it’s done.

When the final approval on the event lands, the risk assessment is automatically marked Approved — no extra step.

Editing after approval

If you edit an approved assessment, PortalHQ treats it the way it treats moving an approved event’s start time: the assessment’s version bumps (v1 becomes v2), its status returns to Draft, and the event returns to draft with its approvals cleared, so it goes through the chain again. The event page tells everyone why: “The risk assessment changed after approval, so this event has been returned to draft and needs approving again.”

A version bump also re-prompts staff acknowledgement (below) — anyone who acknowledged v1 is asked to read and acknowledge v2.

On the day

Below the form, an On the day area holds the three things you’ll actually reach for as the activity approaches.

Students and medical alerts

If the Students and medical section is enabled, the assessment shows a live panel of the students on the event with their medical alerts (severe conditions flagged), student flags, NCCD adjustments and emergency contacts. It’s generated fresh every time you view or print — medical data is never copied onto the assessment, so it can’t go stale.

Two things to know:

  • The panel needs named students on the event. If the event only records student numbers and year groups, add the actual students under People, Classes and Groups on the event.
  • Coverage depends on your student information system. Stored medical conditions are currently synced for TASS schools only. If your school runs Sentral, Compass, Synergetic, Edumate, Engage, Wonde, Maze or PowerSchool, the panel shows student flags and adjustment records but tells you plainly that condition, allergy and medication details aren’t available — check them in your SIS before the activity runs. The panel will never show an empty list that could be misread as “no alerts”.

The medical panel is visible only to staff on the event, its approvers, medical admins and portal admins.

If the event type has a Parent consent form attached, the assessment’s Parent consent tile offers Create the consent slip. One click builds a slip named Permission note: (your event’s title), addressed to the event’s participants, due three days before the event, and pre-filled from the event’s permission-note fields (intro, location, departure, transport, return, dress and additional requirements).

From then on the tile tracks returns — “3 of 25 consent notes returned” — and lists exactly which students are still outstanding, both here and in the printed pack.

Staff acknowledgement

Approval and acknowledgement are different things, and every state policy requires both: approvers sign the activity off, and the staff actually running it confirm they’ve read the risk assessment and the emergency procedures. They are rarely the same people.

The Staff acknowledgement tile lists everyone expected to acknowledge — the staff involved on the event plus the staff in charge — split into Acknowledged and Still to read it. Each supervising staff member opens the assessment and clicks I have read this risk assessment. Acknowledgements are per version, so if the assessment changes after approval, everyone is asked again.

Print excursion pack (top of the assessment, or Print on the event’s risk assessment card) produces a single PDF to carry on the day: the full assessment, the risk register, the transport plan, the emergency plan, the participant list with medical alerts and emergency contacts, and the sign-off state — who approved, who has acknowledged.

The pack contains student medical information, so it’s stamped with a generation time and a confidentiality footer. Treat it accordingly: carry it only for the duration of the activity, and dispose of it securely afterwards.

The register

Events → Risk Assessments in the sidebar opens the register — every assessment on record, for compliance review. Filter by Status or by Highest residual risk; each row shows the event, its date, the status, the highest residual rating and the hazard count, plus how many sections are still outstanding and a “Reduce before the activity runs” flag where a residual risk is still High or Extreme — so a compliance reviewer can triage the list without opening each one.

Portal admins see every assessment at the school. Other staff see only the assessments for events they created, own, co-own or are listed on.

Who can do what

Action Who
View an assessment Portal admins; staff attached to the event (creator, owner, co-owner, staff involved, additional staff); approvers whose group is still due to approve it
Edit an assessment The same, minus approvers
Approve The event’s approval chain, exactly as before
See the medical panel Anyone who can view, plus medical admins
The register Portal admins see everything; other staff see their own events only

Risk assessments are staff-only throughout — parents and students have no access.

Troubleshooting

There’s no Risk assessment card on my event. Three switches sit in front of it: the school setting (Settings → School Settings → Risk assessments), the event type’s Requires risk assessment flag, and your own access to the event. If the event’s type doesn’t require an assessment, no card appears — that’s by design.

The event type page says risk assessments are switched off for this school. A portal admin needs to enable them under School Settings first; the event type settings do nothing until then.

I can’t submit for approval. Submitting is only offered when every enabled section is complete — the save bar and the section chips show what’s outstanding. Check the completeness table above; the usual culprits are a missing educational purpose or an empty risk register.

A hazard row won’t save. Every hazard needs its control measures described — a hazard without controls isn’t a risk assessment, it’s a worry list. Fill in the controls and save again.

The Copy from another event button is missing. It only appears once your school has another assessment to copy from. The first assessment at a school is always built by hand.

Medical conditions aren’t showing on the panel. Either the event has no named students yet (add them under People, Classes and Groups), or your school’s SIS doesn’t sync medical conditions to PortalHQ — currently only TASS schools do, and the panel says so explicitly. Check your SIS before the activity runs.

My approved event went back to draft. Someone edited the risk assessment after approval. That’s deliberate: the approvers signed off a specific plan, so a changed plan needs their sign-off again. The assessment’s version number will have bumped, and supervising staff will be asked to acknowledge the new version.

The parent consent tile says no consent form is configured. Attach a Parent consent form to the event type under Event Planner → Types. If no forms are offered there, build one in the form builder and set its Form type to “Slips Form” on the Properties tab.