The first time I had to answer this question, I was three weeks into a new operations role and staring at a compliance folder my predecessor left behind. Half of it was blank. An OSHA-style checklist sat on top with no name in the “person certifying” field and no date. My manager assumed the safety consultant handled it. The consultant assumed our site supervisor handled it. The supervisor assumed the corporate handled it. Nobody had actually done the assessment, and everybody thought someone else owned it. I spent a nervous afternoon reading the regulation itself, and the answer turned out to be far simpler than the finger-pointing suggested. One party is legally on the hook, and it is not the consultant.

If you are trying to figure out who is responsible for conducting a hazard assessment, or you inherited a folder like mine, this post lays out exactly who holds the legal responsibility, who can perform the work, and how to get it done in a way that holds up. You will also see where a security-focused assessment fits alongside your safety obligations.

The Employer Holds Legal Responsibility for the Hazard Assessment

Most workplace confusion on this question comes from mixing up two different things: who does the walkthrough, and who answers to a regulator. Those are not the same, and only one of them is fixed by law.

Here’s what the regulation actually assigns:

What OSHA’s PPE standard requires

Under OSHA’s PPE standard, 29 CFR 1910.132, the employer must assess the workplace to determine whether hazards are present or likely to be present that require personal protective equipment. If they are, the employer must select the right PPE, ensure it fits each affected worker, and train employees on its use. The standard names the employer as the responsible party in plain language, and it applies whether you run a two-person shop or a large facility. This is the clearest statement of hazard assessment responsibility in federal safety law.

Why the duty of care cannot be delegated

Employers can hand off the clipboard, but they cannot hand off the liability. OSHA’s General Duty Clause, Section 5(a)(1) of the OSH Act, requires every employer to furnish a workplace free from recognized hazards likely to cause death or serious physical harm. That obligation stays with the employer even when a consultant performs the actual survey. Regulators cite the employer, not the contractor, when an assessment is missing or inadequate, which is exactly why passing the task down the chain never passes down the risk.

Who Actually Performs the Assessment

Legal responsibility sits with the employer, but the person walking the floor with a checklist is often someone else entirely. OSHA anticipates this and builds room for it into the standard.

Here’s who typically does the hands-on work:

The competent person on site

OSHA frequently points to a “competent person” as the one who carries out a hazard assessment. This is someone with the training and experience to identify existing and predictable hazards and the authority to take prompt corrective action. In practice this is often a safety manager, a supervisor, or a crew leader with the highest level of safety training on site. The title matters less than the two qualifications behind it, which are the ability to recognize the hazard and the standing to fix it.

Bringing in an outside professional

Many employers, especially smaller ones without dedicated safety staff, hire an outside professional to perform the assessment. This is fully permitted, and it often produces a more thorough result because a specialist brings fresh eyes and current regulatory knowledge. The important thing to understand is that hiring a consultant satisfies the execution, not the accountability. The employer still signs off, still keeps the records, and still answers for the corrective actions, so the outside professional works as an extension of the employer’s duty rather than a replacement for it.

How to Get a Hazard Assessment Done Right

Knowing who owns the task is only useful if the finished assessment holds up under scrutiny. A walkthrough that lives in someone’s memory is not an assessment, and it will not survive an inspection or a claim.

Here’s what a defensible assessment includes:

Document it with written certification

OSHA’s PPE standard requires written certification that the hazard assessment was performed. That certification must identify the workplace evaluated, name the person certifying that the evaluation happened, give the date or dates of the assessment, and clearly identify the document as a certification of hazard assessment. Skipping this step is the single most common failure, and it is the one my predecessor made. A verbal or undocumented assessment offers no protection, because from a regulator’s view an assessment you cannot prove is an assessment that did not happen.

Reassess when conditions change

A hazard assessment is not a one-time filing. New equipment, a new process, a facility change, a near-miss, or a workplace injury all create reasons to reassess, because each can introduce hazards the original survey never contemplated. The strongest safety programs treat assessment as ongoing rather than annual, reviewing conditions on the ground and updating the certification whenever the workplace materially changes. Building that habit keeps the paperwork current and, more importantly, keeps people safe as the environment evolves.

Where Security Risk Assessments Fit Alongside Safety

OSHA hazard assessments focus on physical safety hazards like chemical exposure, machinery, and PPE needs. They do not cover a different category of risk that many facilities face, which is the threat of theft, trespass, violence, and other security exposures. Those require their own dedicated evaluation.

Here’s how the two assessments complement each other:

Safety hazards and security threats are different evaluations

A PPE hazard assessment asks whether a worker needs gloves, eye protection, or fall protection. A security risk assessment asks a separate set of questions about access control, vulnerable entry points, lighting, patrol coverage, and the likelihood of criminal activity at your site. Both protect your people, but they draw on different expertise and different standards. Treating a safety hazard assessment as if it also covers security leaves a real gap, especially for facilities handling cash, valuable inventory, or high foot traffic.

How a professional security assessment supports your duty of care

This is where a security partner does for the threat side what a safety consultant does for the OSHA side. A professional security risk and threat assessment evaluates your property for vulnerabilities, models realistic threat scenarios, and recommends concrete measures such as officer coverage, patrol routes, and access procedures. Pairing that with your OSHA hazard assessment gives you a fuller picture of workplace risk, and it strengthens the same duty of care that regulators and courts expect employers to demonstrate. The employer still owns the responsibility, and a qualified partner makes carrying it out far more manageable.

Frequently Asked Questions

Who is legally responsible for conducting a hazard assessment?

The employer is legally responsible. Under OSHA’s PPE standard and the General Duty Clause, the employer must ensure the workplace is assessed for hazards. This responsibility cannot be transferred to another party, even when someone else performs the actual assessment.

Can an employer hire someone else to do the hazard assessment?

Yes. Employers commonly delegate the work to a competent person on staff or to an outside consultant. Delegation covers the execution only. The employer still retains legal accountability, keeps the written certification, and remains responsible for correcting identified hazards.

What is a competent person in a hazard assessment?

A competent person is someone with the training and experience to identify existing and predictable workplace hazards, and the authority to take prompt corrective action. This is often a safety manager, supervisor, or trained crew leader, though the qualifications matter more than the job title.

Does a hazard assessment need to be documented?

Yes. OSHA’s PPE standard requires written certification identifying the workplace evaluated, the person who certified the assessment, the date it was performed, and a clear label identifying it as a hazard assessment certification. An undocumented assessment provides no compliance protection.

How often should a hazard assessment be conducted?

There is no single fixed interval. An assessment should be updated whenever conditions change, including new equipment, new processes, facility changes, near-misses, or injuries. Many strong safety programs review hazards continually rather than treating the assessment as a once-a-year task.

Get Your Assessment Done With a Partner Who Understands Risk

The responsibility for a hazard assessment stays with you as the employer, but the work does not have to fall on you alone. On the safety side, a qualified competent person or consultant can carry out the walkthrough and certification. On the security side, that is where our team fits in.

Almond Tree Security Services evaluates properties across Miami-Dade, Broward, and Monroe County for security vulnerabilities and threats, then recommends practical coverage to close the gaps. If you want a clearer picture of the risks at your site, take a look at our commercial security services in South Florida and reach out whenever you would like to talk it through. No pressure either way.