What is the difference between a risk assessment and a risk analysis under GPSR?

Under the General Product Safety Regulation (EU) 2023/988 (GPSR), a risk analysis is the step in which you identify hazards and estimate the level of risk, usually by combining severity and probability. A risk assessment is broader: it includes the analysis, plus judging whether the risk is acceptable and deciding how to reduce it. Below are the practical differences, what to document, and how to keep it ready for market surveillance checks.

What is a risk analysis under the GPSR?

A risk analysis under the GPSR is the structured work of identifying hazards and estimating the risk for each hazard, typically by considering the severity of harm and the likelihood of occurrence. It is the “what can go wrong, how bad would it be, and how likely is it?” part of your product safety work, and it should be documented in your technical documentation.

Typical inputs for a GPSR risk analysis include:

  • Intended use and conditions of use (environment, duration, user interaction).
  • Reasonably foreseeable misuse (common user mistakes, predictable behavior).
  • User groups, including vulnerable consumers where relevant (for example, children or older users).
  • Product lifecycle stages: transport, installation, normal use, maintenance, and end of life.

The GPSR does not prescribe one mandatory method or a single required risk matrix. What matters is that your approach is logical, repeatable, and produces a clear record that supports the general safety requirement.

What is a risk assessment under the GPSR?

A risk assessment under the GPSR is the broader process that includes the risk analysis, plus risk evaluation and risk-reduction decisions. After you estimate risks, you decide whether each risk is acceptable for the product as placed on the market. You then select and implement measures to reduce risk, and you confirm that the remaining (residual) risk is acceptable.

In practice, a GPSR-aligned risk assessment usually documents:

  • Risk acceptability criteria (how you decide what is “acceptable and compatible” with intended use).
  • Risk control measures, such as design changes, protective features, or software controls.
  • Warnings and instructions, including language and placement considerations.
  • Verification and validation evidence (for example, testing, inspections, or checks against standards).
  • Residual risk and any user information needed to manage it.

This connects directly to the GPSR rule that only safe products may be placed or made available on the EU market, and to the expectation that technical documentation is available when market surveillance authorities request it.

How do you document and maintain GPSR risk work for compliance?

To document GPSR risk work, keep a clear, retrievable file that shows hazards, risk ratings, decisions, and evidence, and keep it updated as the product and real-world use evolve. The goal is not paperwork for its own sake; it is being able to demonstrate, quickly, why you consider the product safe under normal and reasonably foreseeable conditions.

Practical documentation checklist

  • A hazard list covering mechanical, electrical, thermal, chemical, choking, strangulation, cybersecurity, and other relevant hazard types.
  • Your risk rating method and rationale (for example, how you define severity and probability levels).
  • Chosen risk controls, with traceability to requirements, drawings, software versions, or supplier changes.
  • Test reports and standards used to support safety arguments (European standards can support a presumption of safety when applicable).
  • Residual risk statements, plus warnings and instructions that address remaining risks.

When to review and update

  • Customer complaints and safety-related feedback.
  • Accidents, near misses, or field safety observations.
  • Design, material, supplier, or manufacturing process changes.
  • New information, such as updated standards or newly identified hazards for similar products.

Many companies align their approach with ISO 12100 (machinery risk assessment principles) or ISO 14971 (medical device risk management principles) because they are structured and auditable, but the GPSR is broad in scope, so you should adapt the method to the product and its risks.

How EARP helps with GPSR risk assessment and risk analysis

We help you turn GPSR risk analysis and risk assessment work into a compliance-ready documentation set that is organized, complete, and easy to provide to authorities when requested. Our support focuses on practical workflows that reduce delays and confusion for non-EU manufacturers and online sellers.

  • Document presence and completeness checks for your GPSR technical file, including risk documentation.
  • Structured guidance on what to include so your risk work is clear, consistent, and retrievable.
  • Technical documentation storage and controlled access, supporting readiness for authority requests.
  • EU Responsible Person and Authorized Representative role support aligned with your product and supply chain setup.

See our services for details, or contact us to discuss what you sell and what documentation you already have.

Related Articles

Ready to get in touch?

For guidance specific to your products and target markets, contact our team.

Lets Get Started

There’s no time to waste. Talk to the experts at EARP and know that you have 25 years of experience at your disposal. You deserve to focus on your products. Let us take care of your regulatory representation in the large and lucrative European market.