Principle

Lightning risk assessment review and sign off: the engineer signs, a reviewer checks

A risk figure carries a name. The engineer who prepared it answers for it, and a second competent person checks it before anyone relies on it. This piece explains why that split matters and how Lumex records each step.

A lightning bolt striking behind an industrial building, the exposure a lightning risk assessment quantifies

In a sound lightning risk assessment review and sign off, the engineer who prepares the figures owns them, and a second competent person checks them before anyone relies on them.

A risk assessment under IEC 62305-2:2024, the Annex L method of NFPA 780-2026 or AS 1768:2021 ends in a verdict: protection is needed, or it is not, and if it is, which measures bring the risk down far enough. That verdict decides money, design and liability. It is only as good as the inputs behind it, and the person least able to see a wrong input is the person who typed it.

So the work splits in two. The engineer prepares the assessment and puts their name to the figures. A reviewer checks it and records a decision. Neither job replaces the other. This piece sets out what each person does, what a reviewer should look at, what must stay fixed while they look, and what the record of the decision has to hold. It sits beside a companion principle, that every figure must be traceable and reproducible, because a reviewer can only check a number that can be followed back to its inputs.

Why two people

Why the person who prepares a risk figure should not be the only one to check it

The risk methods are long chains. A structure's dimensions become a collection area, the collection area and the lightning density become a count of dangerous events, and that count meets a probability and a loss to give each risk component. One wrong input travels the whole chain and lands in the verdict looking exactly like a right one. The arithmetic will be perfect. The answer will still be wrong.

The engineer who entered that input reads it the way they meant it, not the way they typed it. A second person reads it cold. They compare the length on the screen with the length on the drawing, the occupancy with the brief, the service lines with the site. That is the whole value of review: a fresh reader at the point where errors enter, before the figures leave the firm.

Signing and checking are different acts. The engineer signs to say the figures are theirs and they stand behind them. The reviewer checks to say a second competent person looked and agreed. A report that has only one of the two has half the assurance a client thinks it has.


Roles

Who does what in a Lumex workspace

Lumex gives each member of a firm's workspace one of five roles. The split between preparing and deciding is built into them.

Role What it can do with an assessment
EngineerCreates and edits assessments, opens the calculation working behind every figure, submits a report for review, generates it and, once it is approved, sends it to a client
ReviewerWorks the approvals queue: takes a report into review, then approves it, requests changes or rejects it. Generates reports. Cannot edit an assessment
AdminEverything an Engineer and a Reviewer can do, plus running the workspace and its team
Field SurveyorCollects site data in the field. Cannot submit or decide
ViewerReads projects, assessments and reports. Cannot change an assessment or decide on a report

A Reviewer is assigned to a project, and their queue shows the reports for the projects they review. A Reviewer cannot change the inputs they are judging, which keeps the two jobs apart: if something is wrong, they send it back with a note, and the engineer fixes it.

The check

What a reviewer should look at before approving

A reviewer is not there to redo the arithmetic. The method does that the same way every time. They are there to check what went into it.

The structure is the real one

Dimensions, height, location and the services that enter the building match the drawings and the site. The lightning density used and where it came from are stated. Most wrong verdicts start here.

The right standard and edition

The project specification names a standard. The report must apply that one, in the edition it names. Under NFPA 780-2026 Annex L the owner or the authority having jurisdiction may set other tolerable values (L.6.2), so any change has a source.

The verdict follows

The occupancy, the loss values and the protection already in place reflect the brief. The engineer's written assumptions are reasonable. The verdict and any proposed measures follow from the figures, and nothing is claimed that the figures do not show.

Holding still

What is locked while a report is reviewed and after it is decided

A review means nothing if the figures can move while the reviewer reads them, or after they approve. So in Lumex, once the engineer submits a report for review, its inputs cannot be edited and its figures cannot be recomputed. The same lock holds once the report is approved or rejected. The approved figures are the figures that were checked.

Decisions can still be corrected, but in the open. A reviewer can undo an approval, a rejection or a request for changes. That reopens the review as a new cycle, and the earlier decision stays in the history rather than being erased. A rejected report cannot simply be submitted again. The one thing that stays editable is the next review date, because it is a reminder about the record, not a change to what the record says.

Independence

A reviewer never approves their own work

The check only works if the checker is someone else. Lumex enforces that for reviewers, and lets a firm extend it to everyone.

A reviewer cannot approve their own report

A Reviewer cannot approve or reject a report they created or submitted. When a decision is undone, the original submitter is carried onto the new review cycle, so reversing a decision does not let a reviewer who submitted the report decide on it.

A setting for a strict two-person rule

By default an Admin can decide any report, their own included, which suits a one-person practice, and the PDF then says one person prepared and approved it. A workspace that switches on independent review blocks every role, Admin included, from approving, rejecting or requesting changes on a report they created or submitted. It needs at least two members to switch on.

The record

What the record of a sign off should hold

When a verdict is questioned months later, the first questions are who prepared it, who checked it, what they said and when. A record that answers all four, for every round, is what turns a review from a habit into evidence.

Lumex keeps every review cycle of an assessment, oldest first: who submitted it and when, the note they sent with it, who decided, the decision, the reviewer's note and the time. The report screen in the portal lists the engineer, the reviewer and both dates beside the report itself. The workspace activity feed records each submission and decision. A report still waiting six days after submission prompts an email to the person who submitted it, so a review nobody picked up does not go quiet.

The downloaded PDF names the standard and edition on its cover. Its sign off page names who prepared the report and who approved it, with the approval date, or says it is not yet approved. Blank lines for the date, place, signature and stamp follow, to be completed by hand. The full history of every cycle lives in the portal record.

Where Lumex fits

The method computes, people decide

Lumex does the part a machine should do. Voltrace, its calculation engine, computes the risk by the method of the standard you choose and shows the working behind every figure. It does not decide whether the inputs describe your building, and it does not certify a structure. That judgement stays with the engineer who prepares the assessment and the reviewer who checks it. Lumex gives them the steps, the lock and the record. No report goes to a client before it is approved. Switch on independent review to make the approver a different person every time.

Read more on the companion principles: why every figure must be traceable and reproducible, why every figure names the edition it was computed on, why the activity record is only added to and why the assessment is independent of protection products. For what a finished report should contain, see audit-ready lightning risk reports. For the methods themselves, see the standards Lumex supports, and for the product, the platform.

FAQs

Questions answered

Who should sign off a lightning risk assessment?

A competent person other than the one who prepared it. The engineer who entered the inputs and ran the method owns the figures and submits them. A reviewer with the same competence then checks the inputs, the standard and edition applied and the verdict, and approves, sends back or rejects the report. One person doing both jobs removes the only check that catches a wrong input before a client relies on it.

What does a reviewer check in a lightning risk assessment?

The reviewer checks that the inputs describe the real structure, that the right standard and edition were applied, and that the verdict follows from both. That means dimensions and services against the drawings, the occupancy and loss values against the brief, the lightning density source, any tolerable value the owner or authority changed, and the assumptions the engineer wrote down. A reviewer does not redo the arithmetic by hand. They check what went into it.

Can an engineer approve their own risk assessment in Lumex?

A Reviewer cannot approve or reject a report they created or submitted. An Admin can, unless the workspace turns on the setting that requires independent review, which then blocks every role, Admin included, from deciding on their own work. Firms that want a strict two-person rule should switch that setting on. A workspace with one member cannot, because nobody else could approve. Lumex records who submitted and who decided in either case, so the record shows when one person did both.

Can a lightning risk assessment be changed after it is approved?

Not in Lumex. From the moment the engineer submits a report for review, and after it is approved or rejected, its inputs and figures cannot be edited or recomputed. To change an approved report, a reviewer undoes the decision, which reopens the review and keeps the earlier decision in the history, and then sends it back to the engineer for changes. The next review date stays editable throughout, because it schedules a future check rather than changing what the report says.

What happens when a reviewer requests changes?

The report goes back to the engineer with the reviewer's note, and its inputs open for editing again. The engineer makes the changes and submits it once more, which starts a new review cycle. Lumex keeps every cycle, so the history shows each round of changes, who asked for them, what they said and when. The approvals queue also counts how many revision rounds an assessment has been through.

Does the report itself show who reviewed it?

Yes. The PDF's sign off page names the engineer who prepared it and the person who approved it, with the approval date. When one person did both, it says the report was prepared and approved by that person. A report not yet approved says so. The page still ends with blank date, place, signature and stamp lines to complete by hand. The report screen in the portal shows the same names and links to the full review history.

Can a report go to a client before it is approved?

No. Lumex sends a report to a client only after it is approved, whichever review setting the workspace uses. Until then, the engineer can still download and read it inside the firm.

What Lumex does, and what stays with you

Lumex computes the method of the standard you choose, IEC 62305-2:2024, AS 1768:2021 or NFPA 780-2026, and shows the working. It does not certify a structure. You may not issue or submit a Lumex output until a competent person, qualified where the structure is located, has reviewed the inputs and the result and signed it.

The tolerable risk in IEC 62305-2 is not a fixed constant. Clause 7.3 NOTE 1 gives RT = 1 × 10⁻⁵ per year as a representative value of tolerable risk and adds that another value may be set once the case has been investigated in detail. Printed p.12 then lets national or local regulations fix RT, the tolerable frequency of damage FT, and the Annex A, B, C and E calculation rules and parameter values. Every IEC 62305-2 assessment in Lumex states the jurisdiction it was computed under and the values that applied.

Get started today

Every review decision recorded with a name, a note and a time, not lost in an email thread