Write a risk assessment for Staff working without site specific dbs
Risk Assessment for Staff Working Without Site-Specific DBS Checks
Assessment Date: [DATE]
Assessor: [ASSESSOR NAME]
Department/Area: [DEPARTMENT/AREA]
Review Date: [REVIEW DATE]
1. Assessment Scope
This assessment covers the safeguarding, legal, regulatory, and duty-of-care risks associated with staff undertaking work that brings them into contact with children, young people, or vulnerable adults without site-specific DBS checks in place. It applies to direct service delivery, supervised and unsupervised contact, home visits, off-site work, lone working, temporary assignments, and any situation where staff may have access to vulnerable persons or sensitive environments. The assessment includes pre-deployment screening, supervision arrangements, safer recruitment controls, escalation and reporting pathways, and operational controls needed to reduce the likelihood of harm. It excludes clinical decision-making, criminal investigations, and any safeguarding case management beyond the workplace control measures described here.
2. Risk Assessment Methodology
This assessment uses a qualitative risk assessment approach consistent with a task-based hazard analysis. Hazards are identified by reviewing the work activity, the people involved, foreseeable unusual conditions, and the potential for harm to vulnerable persons and staff. Each hazard is evaluated using a 5x5-style qualitative matrix based on likelihood and severity, then prioritized for control. Controls are selected using the hierarchy of controls: elimination, substitution, engineering controls, administrative controls, and PPE where relevant. The assessment should be treated as a living document and updated when work conditions, staffing, supervision, or safeguarding arrangements change.
3. Risk Matrix Reference
The following matrix is used to evaluate risk levels based on likelihood and severity:
| Likelihood | ||||||
|---|---|---|---|---|---|---|
| Rare | Unlikely | Possible | Likely | Almost Certain | ||
| Severity | Catastrophic | Low | Low | Low | Low | Medium |
| Major | Low | Low | Medium | Medium | High | |
| Moderate | Low | Medium | Medium | High | High | |
| Minor | Medium | Medium | High | High | Extreme | |
| Negligible | Medium | High | High | Extreme | Extreme |
4. Hazard Identification and Risk Evaluation
1. Staff may have unsupervised or inadequately supervised contact with vulnerable persons because site-specific DBS checks have not been completed before deployment.
Potential Consequences: A person who has not been appropriately screened may pose a safeguarding risk, including inappropriate conduct, boundary violations, exploitation, grooming, neglect of duty, or abuse. Vulnerable persons may be placed at risk of physical, emotional, or sexual harm, and the organization may fail in its duty of care.
Affected Persons: Children, young people, vulnerable adults, staff, visitors, and the organization.
Initial Risk Assessment
| Likelihood | Severity | Risk Rating |
|---|---|---|
| Possible | Catastrophic | Extreme |
Control Measures
- Eliminate unscreened contact by preventing deployment to any role involving regulated or vulnerable-person contact until the required DBS and safeguarding checks are complete.
- Substitute the task with alternative duties that do not involve direct contact with vulnerable persons, such as back-office, remote, or non-client-facing work.
- Implement engineering-style access controls such as restricted access areas, sign-in systems, and controlled entry to vulnerable-person settings.
- Apply administrative controls including safer recruitment checks, role-specific risk screening, written supervision plans, and clear escalation rules for any unscreened assignment.
- Require continuous line-of-sight supervision for any temporary transitional period where contact cannot be fully avoided, with immediate removal from the task if supervision cannot be maintained.
Residual Risk Assessment
| Likelihood | Severity | Risk Rating |
|---|---|---|
| Rare | Major | Medium |
2. Failure to comply with legal, regulatory, contractual, or organizational safeguarding requirements when staff are assigned without site-specific DBS clearance.
Potential Consequences: The organization may breach safeguarding policy, contractual obligations, licensing conditions, or statutory expectations. This can lead to enforcement action, loss of service contracts, reputational damage, civil claims, disciplinary action, and increased exposure to safeguarding incidents.
Affected Persons: Organization, managers, staff, service users, commissioners, and the public.
Initial Risk Assessment
| Likelihood | Severity | Risk Rating |
|---|---|---|
| Likely | Major | High |
Control Measures
- Eliminate non-compliant deployment by making DBS clearance a mandatory precondition for any role requiring it.
- Use administrative controls such as a documented compliance checklist, pre-start authorization, and manager sign-off before any placement begins.
- Assign a competent safeguarding lead to verify screening status, role suitability, and any restrictions before work starts.
- Maintain records of checks, decisions, exceptions, and review dates to demonstrate due diligence and traceability.
- Suspend work immediately if compliance status is unclear or expired, and escalate to senior management and safeguarding leads.
Residual Risk Assessment
| Likelihood | Severity | Risk Rating |
|---|---|---|
| Unlikely | Major | Medium |
3. Inadequate supervision of staff who have not been site-cleared or who are new to the setting, increasing the chance of unsafe decisions or missed safeguarding concerns.
Potential Consequences: Staff may fail to recognize warning signs, respond incorrectly to disclosures, or act outside their competence. Vulnerable persons may not receive timely protection, and unsafe practice may continue unchecked.
Affected Persons: Vulnerable persons, staff, supervisors, and the organization.
Initial Risk Assessment
| Likelihood | Severity | Risk Rating |
|---|---|---|
| Likely | Major | High |
Control Measures
- Eliminate lone or unsupervised work for staff awaiting clearance in safeguarding-sensitive environments.
- Provide a named supervisor or mentor with clear responsibility for oversight, observation, and intervention.
- Use administrative controls such as induction, task limitation, competency checks, and documented supervision frequency.
- Schedule higher-risk interactions only when an experienced cleared worker is present and able to intervene immediately.
- Review supervision effectiveness regularly and increase oversight if concerns, incidents, or uncertainty arise.
Residual Risk Assessment
| Likelihood | Severity | Risk Rating |
|---|---|---|
| Unlikely | Moderate | Medium |
4. Staff may not recognize safeguarding indicators, disclosure protocols, or boundaries because they have not received adequate role-specific safeguarding training.
Potential Consequences: Warning signs of abuse, neglect, exploitation, or coercion may be missed. Disclosures may be mishandled, records may be incomplete, and vulnerable persons may remain at risk for longer periods.
Affected Persons: Vulnerable persons, staff, safeguarding leads, and the organization.
Initial Risk Assessment
| Likelihood | Severity | Risk Rating |
|---|---|---|
| Possible | Major | High |
Control Measures
- Eliminate task allocation until mandatory safeguarding training is completed and understood.
- Provide structured induction covering safeguarding principles, professional boundaries, disclosure handling, reporting routes, and escalation thresholds.
- Use competency-based assessment rather than attendance-only training to confirm understanding.
- Issue concise reference materials and decision aids for use during live work.
- Refresh training at defined intervals and after any safeguarding incident or policy change.
Residual Risk Assessment
| Likelihood | Severity | Risk Rating |
|---|---|---|
| Unlikely | Moderate | Medium |
5. Poor recruitment and vetting processes may allow unsuitable individuals into roles involving vulnerable persons, especially where site-specific DBS checks are missing or delayed.
Potential Consequences: Individuals with undisclosed histories, poor conduct, or unsuitable attitudes may gain access to vulnerable persons. This increases the likelihood of abuse, misconduct, boundary breaches, and organizational liability.
Affected Persons: Vulnerable persons, recruitment staff, managers, and the organization.
Initial Risk Assessment
| Likelihood | Severity | Risk Rating |
|---|---|---|
| Possible | Catastrophic | Extreme |
Control Measures
- Eliminate unsafe appointments by requiring completion of safer recruitment checks before any unsupervised or direct-contact work.
- Use structured recruitment controls including identity verification, references, role suitability review, and safeguarding declarations.
- Apply a formal exception process for any temporary deployment, with senior approval and documented compensating controls.
- Ensure recruitment panels include personnel trained in safeguarding and safer recruitment principles.
- Audit recruitment files to confirm that screening, verification, and authorization steps are consistently completed.
Residual Risk Assessment
| Likelihood | Severity | Risk Rating |
|---|---|---|
| Rare | Major | Medium |
6. Lone working or remote working without site-specific DBS clearance may prevent timely intervention if a safeguarding concern, allegation, or emergency occurs.
Potential Consequences: A staff member may be unable to summon help, report a concern promptly, or protect a vulnerable person from immediate harm. Delayed response can worsen harm and complicate incident management.
Affected Persons: Staff, vulnerable persons, supervisors, and emergency responders.
Initial Risk Assessment
| Likelihood | Severity | Risk Rating |
|---|---|---|
| Possible | Major | High |
Control Measures
- Eliminate lone working in safeguarding-sensitive settings where direct contact is required and clearance is incomplete.
- Use a check-in/check-out system, scheduled contact points, and escalation triggers for missed contact.
- Provide reliable communication equipment and backup communication methods.
- Schedule work so that higher-risk tasks occur only when another cleared worker is present.
- Prohibit lone work where immediate safeguarding intervention may be needed and where response time would be unacceptable.
Residual Risk Assessment
| Likelihood | Severity | Risk Rating |
|---|---|---|
| Unlikely | Moderate | Medium |
7. Boundary violations, inappropriate relationships, or misuse of authority may occur where staff interact with vulnerable persons without proper screening, supervision, or conduct controls.
Potential Consequences: Vulnerable persons may experience emotional harm, coercion, grooming, exploitation, or loss of trust. The organization may face complaints, investigations, and long-term reputational damage.
Affected Persons: Vulnerable persons, staff, families, and the organization.
Initial Risk Assessment
| Likelihood | Severity | Risk Rating |
|---|---|---|
| Possible | Catastrophic | Extreme |
Control Measures
- Eliminate opportunities for unsupervised private contact where possible.
- Set clear professional boundaries, communication rules, and acceptable conduct standards.
- Use administrative controls such as code-of-conduct briefings, two-person working for sensitive interactions, and documented visit plans.
- Monitor interactions through supervision, spot checks, and review of concerns or complaints.
- Remove staff immediately from duties if boundary concerns arise pending investigation.
Residual Risk Assessment
| Likelihood | Severity | Risk Rating |
|---|---|---|
| Rare | Major | Medium |
8. Failure to protect confidential information and personal data during work with vulnerable persons, especially where staff have not been fully vetted or trained.
Potential Consequences: Sensitive information may be disclosed inappropriately, increasing the risk of exploitation, identity misuse, distress, or safeguarding compromise. The organization may also breach confidentiality and data protection obligations.
Affected Persons: Vulnerable persons, staff, families, and the organization.
Initial Risk Assessment
| Likelihood | Severity | Risk Rating |
|---|---|---|
| Possible | Major | High |
Control Measures
- Eliminate unnecessary access to sensitive records and limit access on a need-to-know basis.
- Use role-based permissions, secure storage, and controlled information-sharing procedures.
- Provide administrative controls for confidentiality, record handling, and secure communication.
- Train staff on privacy, information governance, and safeguarding-related record keeping.
- Audit access logs and investigate any unusual access or disclosure promptly.
Residual Risk Assessment
| Likelihood | Severity | Risk Rating |
|---|---|---|
| Unlikely | Moderate | Medium |
5. General Control Measures
- Implement a formal pre-deployment authorization process that confirms DBS status, role suitability, safeguarding training, references, and supervision arrangements before any contact with vulnerable persons.
No staff member should begin direct-contact work until the responsible manager and safeguarding lead have confirmed that all required checks and controls are in place.
- Use a safer recruitment framework for all roles involving vulnerable persons.
Include identity verification, reference checks, role-specific screening, interview questions on safeguarding, and documented decision-making for appointments and temporary cover.
- Apply a clear supervision and escalation structure for any staff member awaiting clearance or working in a transitional capacity.
Define who supervises, how often contact occurs, what tasks are prohibited, and when the person must be removed from the setting.
- Maintain a safeguarding culture that encourages reporting of concerns, near misses, boundary issues, and policy breaches without delay.
Ensure staff know how to report concerns, who receives them, and how urgent concerns are escalated outside normal working hours.
- Keep records of screening, training, supervision, incidents, and review actions to demonstrate compliance and support continuous improvement.
Records should be current, accessible to authorized personnel, and reviewed after incidents or changes in role or setting.
6. Emergency Preparedness
- Establish a safeguarding escalation procedure for disclosures, allegations, suspected abuse, or immediate risk to a vulnerable person. Staff must know who to contact, how to preserve evidence, and when to involve emergency services or external safeguarding authorities.
- Create a rapid removal and substitution process so that any staff member whose screening status is unresolved, expired, or questioned can be withdrawn from direct-contact duties immediately without disrupting protection arrangements.
- Maintain an out-of-hours contact tree for supervisors, safeguarding leads, and emergency responders so concerns can be escalated promptly when incidents occur outside normal working hours.
- Ensure staff know how to respond if a vulnerable person is at immediate risk, including maintaining personal safety, summoning assistance, and following local emergency procedures without attempting unsafe intervention.
- Test communication and escalation arrangements periodically, including backup methods for lone or remote work, to confirm that urgent safeguarding alerts can be delivered and received reliably.
7. Training Requirements
- Safeguarding Awareness Training: All staff who may come into contact with vulnerable persons must receive role-specific safeguarding training before deployment. Training should cover signs of abuse and neglect, professional boundaries, disclosure handling, reporting routes, confidentiality, and the duty to act on concerns immediately.
- Recognize indicators of abuse, neglect, exploitation, and grooming.
- Respond appropriately to disclosures without leading questions.
- Escalate concerns through the correct internal and external channels.
- Understand the limits of the role and when to seek supervision.
- Safer Recruitment and Vetting Training: Managers and recruiters involved in appointments must be trained in safer recruitment principles so they can identify unsuitable candidates, verify screening requirements, and document decisions consistently. This is essential where site-specific DBS checks are required before contact with vulnerable persons.
- Verify identity and references before appointment.
- Confirm role-specific screening requirements.
- Use structured interview and selection methods.
- Record exceptions and approvals formally.
- Supervision and Boundary Management Training: Supervisors and frontline staff must understand how to maintain professional boundaries, manage one-to-one interactions safely, and recognize when supervision levels must increase. Training should emphasize that unsupervised contact is not permitted until clearance and competence requirements are met.
- Maintain appropriate physical and emotional boundaries.
- Avoid private or isolated interactions unless authorized and controlled.
- Use two-person working where risk is elevated.
- Report boundary concerns immediately.
- Information Governance and Confidentiality Training: Staff must be trained to handle personal and sensitive information securely, especially when working with vulnerable persons. Training should cover secure record keeping, need-to-know access, approved communication methods, and the consequences of inappropriate disclosure.
- Store records securely and access them only when authorized.
- Use approved channels for sharing sensitive information.
- Avoid discussing cases in public or informal settings.
- Report suspected data breaches promptly.
- Lone Working and Emergency Communication Training: Where lone or remote work is permitted, staff must be trained in check-in procedures, emergency alerting, backup communication methods, and the circumstances in which lone work must stop. This is particularly important when safeguarding concerns could arise unexpectedly.
- Follow scheduled check-in and check-out procedures.
- Use communication devices correctly and test them before work.
- Stop work and escalate if contact is lost or risk increases.
- Know when lone work is prohibited.
8. Monitoring and Review
Review Frequency: Annually and immediately after any safeguarding incident, complaint, change in role, change in legislation, or significant change in supervision or service delivery.
| Monitoring Type | Frequency | Responsible Party | Description |
|---|---|---|---|
| Pre-Deployment Compliance Check | Before each assignment or placement | Line manager or safeguarding lead | Confirm that DBS status, role suitability, training completion, supervision arrangements, and any restrictions are in place before the staff member begins work with vulnerable persons. |
| Supervision Review | Weekly for new or transitional staff; monthly thereafter or more often if risk increases | Named supervisor | Review the quality of supervision, any concerns raised, adherence to boundaries, and whether the current level of oversight remains adequate for the role and setting. |
| Safeguarding Incident and Near-Miss Review | After every incident, allegation, disclosure, or near miss | Safeguarding lead with manager input | Investigate what happened, whether controls failed, whether immediate protection measures were effective, and what corrective actions are required to prevent recurrence. |
| Recruitment File Audit | Quarterly | HR or compliance lead | Check that safer recruitment records, screening evidence, approvals, and exception decisions are complete, current, and traceable for all relevant staff. |
| Safeguarding Control Effectiveness Review | Annually and after any significant change in service model, legislation, or incident trend | Senior management and safeguarding lead | Assess whether the overall control framework remains effective, whether supervision and training are sufficient, and whether any roles should be redesigned to eliminate unscreened contact. |
9. Special Circumstances
- New starters, temporary staff, and inexperienced workers require enhanced supervision because they may be less familiar with safeguarding expectations, reporting routes, and professional boundaries.
- Lone working, remote work, or work outside normal hours increases risk because timely intervention and supervision may not be available if a safeguarding concern arises.
- High-pressure, fast-paced, or emotionally charged environments can reduce judgment and increase the likelihood of boundary errors or missed warning signs.
- Any change in location, client group, task, or staffing arrangement should trigger a fresh risk review because the safeguarding profile may change materially.
- Where vulnerable persons have additional communication, cognitive, or physical needs, controls should be strengthened to ensure they can be protected and heard appropriately.
Approval and Sign-off
This risk assessment has been reviewed and approved by:
Assessor: _________________________ Date: __________
Manager/Supervisor: _________________________ Date: __________
Safety Representative: _________________________ Date: __________
This risk assessment must be reviewed annually and immediately after any safeguarding incident, complaint, change in role, change in legislation, or significant change in supervision or service delivery. or when significant changes occur.
Safety powered by SALUS
Important Safety Note:
Always verify safety information with your organization's specific guidelines and local regulations.