AI & MCP Integration

Give your risk register a voice.

Your risk register sits at the centre of your HSE system. With MCP, it stops being a static document and becomes a live intelligence hub — connected to legislation, guidance, procedures, and verification.

The HSE waterfall — legislation flows down through regulations, ACOPs, GPGs, industry guidance, and company systems into the risk register, and AI connects the register bidirectionally to procedures and verification.

The HSE waterfall — and where the risk register fits.

The problem

The waterfall is only as strong as its weakest connection.

In every effective HSE system, guidance flows downward. It starts with the Health and Safety at Work Act, moves into regulations, then Approved Codes of Practice, Good Practice Guidelines, industry guidance, company systems — and finally into the risk register and the operational documents that shape work on the ground.

At the bottom of that waterfall sits the risk register. It is where the legal framework meets operational reality.

The challenge has always been consistency. Even when the source material is sound, gaps develop. Controls that appear in the register do not always appear in procedures. Procedures drift away from the register. Verification activities focus on what is easy to check rather than what matters most.

The HSE waterfall

  1. 1
    Health and Safety at Work Act
  2. 2
    Regulations
  3. 3
    Approved Codes of Practice
  4. 4
    Good Practice Guidelines
  5. 5
    Industry guidance
  6. 6
    Company HSE systems
  7. 7
    Risk register← you are here
  8. 8
    SOPs, TAs, JSAs, and SWMS
  9. 9
    Work execution and verification
The knowledge burden

The volume of knowledge is itself a system risk.

To develop sound risks, controls, procedures, and verification activities, a business must draw on a substantial body of knowledge. In higher-risk industries, it is not realistic to expect one person to hold all that information consistently, connect it across every document, and apply it evenly across the system.

This is where risk develops — not because people do not care or are not competent, but because the volume of relevant material is large, scattered, and constantly changing.

When grounded in the right legal, regulatory, industry, and company source material, AI can ingest, organise, compare, and surface relevant information far more quickly than a manual review process alone. That does not remove the need for human expertise. It supports it.

Knowledge a business must draw on

  • Health and Safety at Work Act
  • Regulations
  • Approved Codes of Practice (ACOPs)
  • Good Practice Guidelines (GPGs)
  • Industry manuals and reference documents
  • Manufacturer and equipment guidance
  • Training and competency requirements
  • Company HSE manuals and systems
  • Incident learnings and near-miss history
  • Site-specific conditions
What changes with MCP

The waterfall becomes bidirectional.

When a risk register is connected through MCP to an AI system grounded in legislation, regulations, ACOPs, GPGs, and industry guidance, the register becomes far more useful. Instead of sitting in isolation, each risk can be reviewed in the context of the company's actual work, actual procedures, and actual control framework.

Information from SOPs, TAs, JSAs, SWMS, verification records, and field observations can be reviewed and returned to the register — so it evolves based on actual work, not just periodic desktop review.

Your AI can help test whether:

Check whether controls in the register appear in SOPs, JSAs, and SWMS
Identify where operational documents do not reflect the seriousness of a risk
Surface patterns from field documents and verification records
Flag where training content does not support the controls relied upon
Compare your controls against WorkSafe prosecution outcomes
Highlight where guidance has changed and the register may not reflect it
Human in the middle

AI surfaces gaps. A competent person decides.

AI should support the system, not become the system. Where AI identifies a possible gap, inconsistency, or missed control, a competent human must sit in the middle of that process. The role of the AI is to surface issues and present relevant guidance. The role of the human is to review, assess, and decide what should change.

This is built into how Risk3y works. The MCP tools include risk_change_proposal and risk_propose_controls — proposal-only tools that bring an issue forward with supporting context, but require human approval before anything in the register changes.

Human accountability stays where it belongs.

A person must still determine:

  • Whether the identified gap is real in the company context
  • Whether a suggested change is valid and proportionate
  • Whether wording, controls, or risk ratings should be amended
  • Whether a proposed update should be approved and implemented
Getting started

Connected in minutes, not months.

Works with Claude, GPT, Cursor, and any MCP-compatible AI tool. Bring your own AI — Risk3y gives it structured, permission-aware access to your register.

01

Generate a scoped token

Create an MCP client in your Risk3y admin panel. Choose read-only access for analysis and insights, or read-write for AI-assisted updates — all scoped to your account only.

02

Point your AI at the MCP server

Add the Risk3y MCP server URL and your token to your AI client (Claude, GPT, Cursor, or any MCP-compatible tool). Takes about two minutes.

03

Start querying your register

Your AI can now search risks, read controls and reviews, generate summary reports, and propose changes — all within your account, with a full audit trail of every action.

Give your risk register a voice.

14-day free trial. No credit card required. MCP access included in all paid plans.

Get started for free →

Risk3y is an MCP-enabled risk register designed for health and safety teams, HSE consultants, and operations managers in higher-risk industries — including cranes, lifting and rigging, precast concrete, working at heights, and construction. Connect Claude, GPT, or any MCP-compatible AI tool to your risk register, SOPs, JSAs, and SWMS. Give your AI safe, structured, permission-aware access to your HSE data while keeping human judgement at the centre of every update.