"Risk you haven't assessed is risk you've accepted by default."
Legal and Regulatory Compliance in Risk Assessment
Professor Sele: Risk assessment is not only a professional best practice — it is a legal requirement in many contexts. This module covers the legal landscape that frames ESRA in Liberia and the consequences of failing to comply with it.
Section 1 — Legal Duty to Assess Risk
In Liberia and across most jurisdictions, employers have a legal duty of care to take reasonable steps to protect employees, contractors, and visitors from foreseeable harm. A documented risk assessment is the primary evidence that this duty has been exercised. Without it, an organisation facing a harm-related legal claim is significantly exposed.
For SafeHaven, conducting a thorough ESRA for clients is both a service and a legal protection — for the client and for SafeHaven itself.
Section 2 — Regulatory Compliance Considerations
Depending on the client's sector, additional regulatory requirements may apply: Mining and extractives (international operators typically require security risk assessments aligned with the Voluntary Principles on Security and Human Rights, VPSHR); Humanitarian operations (UN and major NGO operators require assessments aligned with the UNDSS Security Risk Management Model); Banking and financial services (Central Bank of Liberia regulations on operational risk management); and Government contracts (specific security standards defined in the contract and in Liberian public procurement regulations).
The assessor must understand which regulatory framework applies to each client before beginning the assessment.
Section 3 — Data Protection in ESRA
The ESRA process collects significant personal data — interview responses, incident records involving named individuals, personnel risk assessments. This data must be collected with informed consent where required, stored securely with access limited to authorised personnel, used only for the purposes of the assessment, retained only as long as necessary, and anonymised in the final report where individual identification is not required.
Section 4 — The Assessor's Legal Liability
A risk assessment that is conducted negligently — missing obvious risks, using inadequate methodology, producing recommendations that create new hazards — can expose the assessor to professional and legal liability. SafeHaven manages this through adherence to documented methodology, peer review of assessments before delivery, professional indemnity insurance, and clear scope of work agreements with clients.
- •Employers have a legal duty of care — a documented ESRA is the primary evidence of compliance
- •Regulatory frameworks vary by sector: VPSHR for extractives, UNDSS for humanitarian, Central Bank for financial services
- •Personal data collected during ESRA must be handled with full data protection compliance
- •A negligently conducted assessment creates legal liability for the assessor and SafeHaven
- •Peer review all assessments before delivery — methodology errors must be caught internally
"A client in the mining sector was preparing for an audit by their international parent company. The parent required a security risk assessment aligned with the Voluntary Principles on Security and Human Rights — a specific international framework I hadn't worked with before. I could have conducted a standard ESRA and hoped the client didn't notice. Instead I spent three days studying the VPSHR framework before beginning the assessment. The audit passed. The client renewed the contract for three years. Knowing which framework applies is as important as knowing how to assess."
An ESRA should be updated: