Skip to main content
Category: Incident & Remediation

Risk Mitigation Hierarchy

Also known as: Mitigation Hierarchy, Hierarchy of Controls
Simply put

A risk mitigation hierarchy is a ranked set of steps for dealing with potential harms, ordered from most to least preferable. The general idea is that you should first try to prevent a harm entirely, then reduce whatever harm remains, and only turn to lower-ranked options like repairing damage or compensating for it as a last resort. The specific steps and terminology differ depending on the field in which the hierarchy is applied.

Formal definition

A risk mitigation hierarchy is a sequenced, priority-ordered framework that ranks intervention options according to their effectiveness at avoiding or reducing an adverse impact, with higher-ranked actions preferred and applied before lower-ranked ones. The concept is field-specific rather than a single unified schema: in biodiversity and environmental impact contexts it is commonly expressed as avoid → minimize (reduce) → restore/rehabilitate → offset or compensate (as attested in Sources 1, 2, 3, and 5), while in occupational safety it appears as a hierarchy of controls that ranks safeguards from most to least effective (Source 4). The evidence provided does not document a single cross-domain hierarchy, and the sources here do not attest to risk-treatment options such as transfer/sharing or acceptance/retention as tiers of a mitigation hierarchy; those terms belong to distinct enterprise risk-treatment frameworks and should not be merged into these hierarchies. As applied, the hierarchy is a decision-ordering tool that reduces or manages residual impact; it does not by itself guarantee elimination of harm. Out of scope for this entry: the applicability of any specific hierarchy to AI or model risk contexts, which is not supported by the cited evidence.

Why it matters

The risk mitigation hierarchy matters because it changes how organizations prioritize interventions: it establishes that preventing a harm outright is preferable to reducing, repairing, or compensating for it after the fact. This ordering discourages the common tendency to treat compensation or offsetting as an equivalent substitute for avoidance, and instead frames those lower-ranked options as measures of last resort. In biodiversity and environmental impact assessment, the hierarchy is described as a widely used good-practice framework that guides users toward limiting negative impacts as far as possible before turning to restoration or offsetting (Sources 1, 3, 5).

The hierarchy also functions as a defensible decision-ordering tool. In occupational safety, for example, controls are explicitly ranked from most to least effective so that safeguards are selected in a principled sequence rather than by convenience (Source 4). This ranking gives reviewers, lenders, and regulators a shared logic against which to evaluate whether an actor genuinely attempted higher-ranked options before defaulting to lower-ranked ones.

At the same time, the concept can be misapplied when treated as a single universal schema. The evidence here documents field-specific hierarchies—an environmental sequence of avoid → minimize/mitigate → restore/rehabilitate → offset or compensate, and a separate occupational-safety hierarchy of controls—not one cross-domain framework. Applying the hierarchy also reduces or manages residual impact; it does not by itself guarantee that harm is eliminated. Practitioners who treat the hierarchy as a guarantee of elimination, or who blur it with enterprise risk-treatment options such as transfer or acceptance, overstate what these frameworks support.

Who it's relevant to

Environmental and biodiversity practitioners
Those conducting environmental impact assessments or biodiversity planning use the mitigation hierarchy as a good-practice framework to prioritize avoidance and minimization of impacts before restoration, and to treat offsetting or compensation as measures of last resort (Sources 1, 3, 5).
Occupational safety professionals
Safety practitioners apply the hierarchy of controls to identify and rank safeguards from most to least effective when protecting workers from hazards, selecting the more effective controls first (Source 4).
Regulators and lenders
Regulatory reviewers and lenders can use the hierarchy as a shared logic to evaluate whether an actor demonstrably pursued higher-ranked options before defaulting to lower-ranked ones, as reflected in guidance describing the hierarchy as a tool to limit environmental damage from development actions (Sources 3, 5).
AI governance and model risk professionals (with caution)
Readers working in AI governance or model risk management should note that the cited evidence does not document application of these field-specific hierarchies to AI or model risk. Treating the environmental or occupational-safety hierarchy as directly transferable to AI contexts is out of scope for this entry and unsupported by the sources here.

Inside Risk Mitigation Hierarchy

Ordered preference structure
A risk mitigation hierarchy is defined by its ordering: measures are applied in a preferred sequence, with more effective or more fundamental measures attempted before less effective ones. The defining feature is the priority ordering, not merely the presence of a set of options.
Elimination and prevention at source (highest tier)
In many hierarchies, the most preferred step is to remove or prevent the source of the risk entirely rather than to manage its consequences. In occupational safety framings this is typically expressed as elimination, followed by substitution; in some environmental framings the analogous first step is avoidance.
Reduction and control steps (middle tiers)
Where a risk cannot be eliminated or avoided, the hierarchy typically calls for reducing or controlling it. In occupational-safety hierarchies of controls this commonly includes engineering controls followed by administrative controls; the ordering reflects a general preference for controls that do not rely on individual behavior.
Residual-risk controls (lowest tier)
The least preferred measures are those applied last and often relied upon to address risk that remains after higher-tier measures. In occupational-safety framings, personal protective equipment (PPE) is commonly placed at the bottom of the hierarchy for this reason.
Restoration and compensation steps (environmental framings)
In biodiversity and environmental impact contexts, the hierarchy is commonly framed differently, as avoidance, then minimisation, then restoration, and finally offsetting or compensation for residual impacts. This is a distinct hierarchy from occupational-safety hierarchies of controls and should not be merged with it.
Context-specific scope
The term 'risk mitigation hierarchy' does not refer to a single universal ordering. Its exact tiers depend on the domain (for example occupational health and safety versus biodiversity and environmental impact), and the tiers, labels, and preferred sequence differ accordingly.

Common questions

Answers to the questions practitioners most commonly ask about Risk Mitigation Hierarchy.

Is 'transfer' or 'acceptance' of risk part of the risk mitigation hierarchy?
Not typically. As commonly defined, a mitigation hierarchy refers to an ordered preference among ways to reduce a hazard or impact—for example, the occupational safety hierarchy of controls (elimination, substitution, engineering controls, administrative controls, personal protective equipment) or the biodiversity mitigation hierarchy (avoid, minimize, restore, offset or compensate). Risk transfer (such as sharing risk through insurance or contracts) and risk acceptance (retention) are risk-treatment options that appear in broader risk-management frameworks such as ISO 31000, but they are not steps within the recognized mitigation hierarchies. Treating them as tiers of a mitigation hierarchy conflates two distinct frameworks.
Is there a single, universally accepted 'avoid–reduce–transfer–accept' mitigation hierarchy?
No. There is no single documented hierarchy of that form. Different domains use different ordered hierarchies: occupational safety uses elimination through personal protective equipment, and biodiversity practice uses avoid through offset or compensate. A generic 'avoid–reduce–transfer–accept' sequence blends mitigation-hierarchy language with the broader treatment options found in general risk-management standards, and should not be presented as a commonly accepted unified hierarchy.
How do you determine which mitigation hierarchy applies to a given AI system or program?
Selection typically depends on the domain and the nature of the harm being addressed. Where a recognized domain-specific hierarchy exists, practitioners generally apply that hierarchy within its intended scope rather than importing an unrelated one. Because the term is used differently across fields, it is worth confirming which framework a policy, contract, or regulator is referencing before applying an ordered preference among controls.
What is the practical rationale for ordering controls in a hierarchy?
The ordering generally reflects a preference for measures that address a hazard at its source over measures that depend on ongoing behavior or protective equipment. Higher-ranked options are typically favored because they reduce reliance on human compliance, though implementation feasibility, cost, and context influence which control is actually adopted.
How does a mitigation hierarchy relate to broader risk-treatment decisions like transfer or acceptance?
A mitigation hierarchy addresses how to reduce a specific hazard or impact, while broader risk-treatment frameworks additionally cover options such as sharing risk or retaining it. In practice a program may apply a mitigation hierarchy to reduce a risk and then, separately, make a treatment decision about any residual risk. Keeping these two steps distinct helps avoid mislabeling a treatment choice as a tier of the hierarchy.
What should be documented when applying a mitigation hierarchy?
Documentation commonly records which hierarchy framework was used, why higher-ranked options were or were not feasible, and the controls ultimately selected at each level considered. Recording the rationale for moving down the hierarchy supports later review, though specific documentation requirements vary by domain and by the standard or policy being followed.

Common misconceptions

There is one universally accepted risk mitigation hierarchy that applies across all domains.
Different fields use different hierarchies. Occupational-safety practice commonly uses a hierarchy of controls (elimination, substitution, engineering, administrative, PPE), while biodiversity and environmental impact practice commonly uses avoid, minimise, restore, and offset/compensate. These are distinct frameworks with different tiers, and applying one to the other's domain can be inappropriate.
Transfer (sharing) and acceptance (retention) of risk are standard tiers within these mitigation hierarchies.
Transfer and acceptance appear as risk-treatment options in general risk management approaches, but they are not documented tiers of the occupational-safety hierarchy of controls or the biodiversity mitigation hierarchy. Presenting them as tiers of a mitigation hierarchy conflates separate frameworks.
Following a mitigation hierarchy eliminates the underlying risk.
A mitigation hierarchy is a structured approach for reducing and managing risk in an ordered sequence. Lower tiers, such as PPE in safety framings or offsetting in environmental framings, exist precisely because residual risk or residual impact typically remains after higher-tier measures. The hierarchy reduces and manages risk rather than guaranteeing its removal.

Best practices

Identify which domain-specific hierarchy applies before selecting measures, and use the ordering and terminology recognized in that domain rather than a generic composite sequence.
Attempt higher-tier measures first, such as elimination or avoidance, and document why they were rejected before relying on lower-tier measures such as PPE or offsetting.
Keep the hierarchy distinct from general risk-treatment options like transfer and acceptance; if those options are used, treat and label them separately rather than inserting them as tiers of the hierarchy.
Recognize that lower-tier measures address residual risk or residual impact, and monitor whether that residual level is acceptable rather than assuming the risk has been removed.
State the scope and limitations of the chosen hierarchy explicitly, including that it is domain-specific and not a single universal ordering, when communicating decisions to stakeholders.