You should read ‘documenting’ as a shorthand for ‘communicating in a demonstrable way.’ So, if you videoed yourself giving a briefing to workers, you could consider those controls as ‘documented’ (although you might also need to demonstrate that it was reasonable to expect the workers to understand and remember what needed to be done on the basis of that verbal briefing).
At the start of Chapter 13, I spelled out the legal requirement to record “significant findings”. At the end of that chapter I concluded this includes relevant hazards, who might be harmed and how and what you are doing to control risk. One way to determine what is significant is to think about your position If there was an accident, and someone was hurt. If writing something down and communicating it would have prevented that harm, it was significant, and you should have documented (and communicated) it.
In Chapter 13 we saw that in the past, the HSE was clear that significant findings can be recorded using existing documents, including guidance, policy, arrangements, procedures and records. The HSE myth-buster series tried to combat the safety clutter that risk assessments sometimes create, stating:
Carrying out a risk assessment should be straightforward. It’s about focusing on real risks and hazards that cause real harm and, more importantly, taking action to control them.
So risk assessments should be fit for purpose and acted upon. OK, if you’re running an oil refinery you’re going to need a fair amount of paperwork. But for most, bullet points work very well indeed.
Following the advice in this chapter will allow you to throw away unwieldy risk assessment tables, full of numbers and duplicated controls, some of which are imaginary rather than actually in place, and create simple records that people will use to reduce risk.
A ‘document’ no longer refers to the dog-eared pile of paper, or to the dusty, unread folder on a shelf, but to any form of information provided in the workplace.
Finding the right paper document is a chore. Searching through an Intranet has replaced this for many workers, inheriting some of the problems of out-of-date documents being more accessible than current ones. Better systems use mobile devices such as tablets to display instructions as needed. Some devices can read instructions aloud, with voice activation of the next instruction – handy when the user’s hands are busy elsewhere. Barcodes on machinery can be used to quickly locate the correct instructions or inspection checklist, or increasingly, location-aware devices will know what is needed. Heads up displays on augmented reality headsets show what needs to be done, with instructions overlaid on the equipment the user is working on.
Other documents might be paper-based, but not on A4 paper in a ring binder. An organisation can document its safety system in many ways: A poster on a wall, a laminated card in a vehicle, some emergency instructions on the back of a pass card.
In this chapter, ‘document’ could refer to any of these examples.
To keep your risk assessments simple, you might need:
You probably have some or all of these documents, although you might name and group them in a different way. That’s fine – there is no need to rename your documents to match these categories. But for each category, consider which of your documents match the descriptions, and whether there are any gaps. And make sure your documents support your risk assessments, and are influenced by those risk assessments.
Ask yourself:
What advantages can you see to documenting your findings outside the risk assessment table? Think of at least three before you carry on reading (or create a list as you read through the chapter).
A risk register provides a central overview of organisational risk management and helps to prioritise resources by focusing on high-risk hazards. The register is a useful reference point for reviewing hazards and monitoring changes in associated risks over time.
The MHSW regs do not state a requirement for a risk register, only that significant findings need to be documented. Is it a significant finding that there is no asbestos, no lift and no gas? More complex still is where a hazard exists, but with a risk you consider insignificant. There are stairs, but the risk of walking up and down them is no higher than for someone in their own home (unless you are painting the ceiling above the stairs, or you have to carry a load up the stairs). There is hot coffee, but adults face the same risk in their own kitchen.
But there is a catch-22 inherent in the way the law is written and interpreted in court.
If I don’t write something down because I think it is insignificant and an accident arises from that hazard, how do I prove that I did consider it? If I write down everything I’ve considered on a risk assessment, it will be bulky and unusable as an everyday tool.
The risk register overcomes the problem of where to document that a hazard is insignificant. List asbestos on your risk register, and if you can state that all your buildings are clear of asbestos, you know that this is currently an insignificant risk for your organisation. But if you move premises (or inherit an old fire-proof safe or filing cabinet) you know to ask about asbestos.
In 2023 Morrisons were found guilty of four charges, including failing to carry out a suitable and sufficient risk assessment. An employee died, most likely after falling on the stairs while having a seizure. He was known to have epilepsy, and his employer had agreed to make several adjustments, such as moving his locker downstairs to reduce the number of times he needed to go up and down the stairs. This hadn’t happened by the time he was found unconscious by a colleague at the foot of the stairs. Fighting a fine of £3.5 million, Morrisons appealed, arguing that stairs are not a ‘relevant work risk’ but a hazard of ’everyday life’. If you required delivery drivers to carry furniture up some stairs in customer premises, then using stairs would be a ‘relevant work risk.’ But Morrisons considered that using stairs to access a locker during a break was not.
Now imagine an organisation like Morrisons which has ‘stairs’ on its risk register, with a comment that currently no significant risks have been identified around the use of stairs. At the point that particular needs are identified, albeit for one individual, the risk register could be updated to show that stairs need to be considered as part of individual risk assessments.
If you’re not sure what to include on your risk register, see the topics listed on the HSE website. While not all topics are hazards – some are outcomes, such as back pain – the list is a useful starting point. You don’t need to record hazards that are always going to be irrelevant. Abrasive wheels and metalworking fluids are never going to be an issue in an office. But lead, asbestos and radiation (in the form of radon gas) could be, depending on the location and age of the building. If they are not an issue, include them on the register to show you checked for the absence of lead and asbestos, and you did a postcode check for radon.
Where you eliminate a hazard through your risk assessment process, make sure this is reflected in the risk register. Let’s say you have indicated on the risk register that diesel fumes are a problem because you have a fleet of vehicles coming in and out of a work location. Previously, your risk assessment documented controls such as maintenance, and instructions not to leave engines running. You have just replaced the last diesel vehicle with an electric vehicle. Update the risk register to explain why you no longer need diesel controls on your risk assessment, and update the register in relation to new hazards introduced by electric vehicles.
Most risk registers have a risk rating by each hazard topic. As with risk assessments, don’t let these ratings become more important than identifying and fixing the hazards. You could use a similar matrix to the one for risk assessments, but think first about the likely outcomes. Three outcomes are usually enough:
If you have multiple sites, you could add extra columns to provide a summary for each site. For example, showing asbestos but no vehicles at one site, and vehicles but no asbestos at another.
An action tracker is a sophisticated ‘to do’ list.
By having an action tracker you can keep all of the ‘to do’ items off the risk assessment. The risk assessment will instead be an accurate record of your assessment of the risk at the time of the assessment. Having all the actions from all the risk assessments (and from incident investigations, safety meetings, hazard reporting, inspections and so on) in one place has many other benefits:
Typically, many people still use Excel for this, setting up tables and using colours to highlight the importance of the action. Advanced Excel users will apply conditional formatting to show just how far past the initial deadline each action is. While Excel is a bit more sophisticated than the post-it on your screen, it is less visible. Once you close the file, it doesn’t remind you what needs to be done.
As well as being a record of actions, a more useful action tracker will send notifications to people about their actions, with reminders sent periodically until they close out the action. It will escalate actions if the original responsible person doesn’t respond in time. It will insist that you assign a responsible person for each action (ideally, making you select from a list of people already registered in the system).
As far as possible, your action tracking system should tie in with systems you use for other aspects of work – for example, if you use Trello for project management, add a board for tracking safety actions; Google and Microsoft have planning options if you’re already invested in either of these; or you might have an action tracking system in another department, like marketing, sales or production.
While the action tracker is a ‘to do’ list, the inventory is a list without defined actions, although actions can be applied to the items in an inventory. Each inventory normally contains items of a similar kind.
Ask yourself:
Without a list of hazardous substances, how do you know you’ve assessed the harmful effect of all hazardous substances?
Without a list of equipment, how do you know you’ve done PUWER inspections of all the equipment?
Without a list of locations, how do you know you’ve covered every room?
Each of these lists is an inventory. The benefits of an inventory are:
When you have a ‘to do’ list that applies to multiple items, you might need an inventory to apply it to.
I talked about inventories in Chapter 2, providing an example of an equipment inventory.
Once you have your inventory, record information on it that would otherwise make a risk assessment too complicated. Next to each item in the inventory make a note about whether the item requires a more detailed risk assessment, inspection or other process, and provide a link or reference to that detail. Some items on your hazardous substances list can be identified as covered by a general requirement to wear gloves, store substances away from children and wash your hands before eating. Other substances might need more detailed information about further PPE, and disposal or spillage instructions.
Inventories can also be used on a larger scale. You can list all the locations in a workplace, and record whether each location is covered by a general site-wide risk assessment, or whether it has a more detailed risk assessment to cover the hazards. For example, office and reception areas might be covered by a site-wide risk assessment, but a workshop might need a location-specific approach. Some locations might have additional equipment-based or task-based risk assessments.
Location-based inventories might be for specific hazards. The asbestos register is a common example of this, where every area checked is listed, even if the result is no asbestos found. Importantly, the asbestos register lists any areas that haven’t been checked. A confined-space register will indicate all areas that are (or could be) confined-spaces, and the controls needed in each location, for example if a permit is required.
Inventories do need to be ‘reasonable’. If you have four trees in your grounds, you should list each one, with details of when it was last inspected and the conclusion. If you have four thousand trees, you could instead zone them according to accessibility, and record details for each zone.
Ask yourself:
For what other topics or location types might you produce an inventory? I’ve made a few further suggestions in Appendix 2.
A read only task document or procedure here refers to any document that describes how something needs to be done, without requiring anything to be written down during the performance of that task. For most organisations, this is likely to be the largest category of documents.
The Safety II and Safety Differently movements have been interpreted by some as a move away from written procedures, towards giving people freedom and autonomy to do the right thing. While there are contexts in which this might be a positive approach, accidents and legal cases demonstrate that procedures are needed to draw together all the information people need to stay safe.
Some historical cases will demonstrate this (see more details of these cases in Appendix 1).
In General Cleaning Contractors v Christmas (1953) and Drummond v British Building Cleaners Ltd (1954), Mr Christmas and Mr Drummond were both experienced window cleaners. When they fell off their respective windowsills, the employers defended by explaining their expectation that the window cleaners would be able to devise their own safe procedures. However, the courts disagreed. Standing on a windowsill is clearly dangerous. In both cases, as part of their defence, the employers suggested methods of work that would have reduced risk. The prosecution were able to argue that given there were safer methods, the employers should have described these for the workers. One judge concluded: “it is the duty of an employer to give such general safety instructions as a reasonably careful employer who has considered the problem presented by the work would give to his workmen.”
The second case makes a further point about procedures. Mr Drummond had been supplied with a safety belt, with the intention that it could be attached to an eye-bolt or hook. The building didn’t have any such attachment point, but the employer argued that he could have hitched it to the transom (horizontal beam) above the sash window. The court ruled that if this was an option, the employer should have made that clear to the employee.
These rulings are quoted in more recent cases, confirming that the 1974 and 1999 legislation did not overturn these conclusions. In Durnan Barnes v Stockton-On-Tees Borough Council (1997) a swimming pool attendant slipped while tidying away a wet inflatable slide. Had the task been carried out in a different order, it was unlikely he would have fallen. The employer had relied in this case on the fact that the task had been carried out without incident for many years. The court concluded that regardless of history, employers must point out hazards to employees, and lay out a safe method to prevent the harm being realised.
Examples include:
Some task documents will refer to safety critical tasks, such as how to isolate machinery for maintenance. They can describe routine tasks such as maintenance, reactive tasks such as responding to breakdowns, and emergency responses such as responding to a chemical spill or evacuating a building.
Procedures also cover safety adjacent processes, such as how to assess and deliver training needs, or how to report a near miss. Think about how often ‘competence’ or ‘training’ appear in the control column. I’ve even seen ‘staff know what to do’. The detail about how training needs are identified, met and ensured is best documented in a separate document, and referred to unambiguously in the risk assessment.
What these documents have in common is that they (should):
Some commercial websites and safety training courses will tell you that a method statement is just another name for a safe system of work (SSoW). If you consider the legislation, I argue these are not the same.
Section 2.2(2) of the Health and Safety at Work Act requires that an employer provides:
systems of work that are, so far as is reasonably practicable, safe and without risks to health
Those ‘systems of work’ are what I would describe as, desirably, ‘safe systems of work’.
For example, a method statement for changing a light bulb could explain how to determine a safe means of access (selection of an appropriate ladder), how to transport and check the ladder and its set-up, how to isolate the power, how to carry the lightbulb up the ladder, and what to do with the old lightbulb.
The method statement would be unwieldy if it also described the procurement process for the ladder, the arrangements for periodic EICR (electrical installation condition report, or fixed wiring checks), the checklist used for six-monthly ladder inspections, and the syllabus for training the person changing the lightbulb. The individual method statement for changing the lightbulb is one part of the total SSoW, but the SSoW includes other documents, the tools, the environment and even the other workers.
Safe systems of work are a legal requirement. It is not a legal requirement to provide a method statement for any particular task, provided you can show that without the method statement, the ‘system of work’ is without risk to health or safety (SFAIRP). For example, a desk worker doesn’t need a method statement to sit down on a chair and switch on a computer, but they should be able to do so without the chair collapsing or the computer giving them an electric shock.
Since this book is about risk assessment, not procedures, I’ll limit myself to a few principles:
One task – one procedure. The familiar “RAMS” commonly provided by contractors separate the Risk Assessment from the Method Statement, such that in following the method statement the user is expected to (and rarely does) refer back to the risk assessment. To reduce the likelihood of missing something, include the safety steps within the method statement. What might go wrong, for example, if the method statement that tells you to open the cover of the equipment to change a component, while the instruction to isolate and lock out is left to the risk assessment?
Visual. Consider alternative ways of showing a procedure, other than a page of text. Most people hate reading procedures. Numbered steps are a good starting point, but sometimes a table or a flowchart, or a labelled diagram is a better approach.
Who does what. There are two successful approaches to this, but don’t mix up both approaches in one procedure. If the procedure will be read by just one person at a time, you can write in the first person. If two or more people will be involved, state clearly who will do what. Table 14.1 gives examples of this.
In order. If there are steps that need to be done in order, write them down in that order. Obvious? You’d think, and yet I have come across procedures where at the end of the procedure after the tenth instruction there is some warning like “if after step 2 the red light remains on, on no account proceed to step 3.” If there is a warning you need to know about at step 2, put it there.
Use positive language. Focus on what people should do rather than what they shouldn’t do.
Options. Think about British Building Cleaners Ltd. Would it be easier to provide one procedure with some options, or multiple procedures, depending on the situation? This is a judgement you have to make each time – when are there so many options that this deserves a different procedure? If there are two procedures for the same activity, depending on circumstances, how will the worker know which one applies? This is another situation where you need a clear scope statement.
| Principle | Poorly expressed step | Option 1: First person | Option 2: Role-based |
|---|---|---|---|
| Who does what | The fuseboard should be isolated and the lockout key held securely | You must check that the fuseboard has been isolated and that you have the lockout key under your control | The electrician will isolate the fuseboard. The technician will place a lockout device on the isolation and keep the lockout key under their control. |
| In order | Before opening the cover check that the power has been isolated | You should: • check that the power has been isolated • open the cover | The technician will: • check that the power has been isolated • open the cover |
| Use positive language | Do not open the cover if the power has not been isolated. | ||
| Make options and exceptions clear | You should be able to use your lockout device on the fuseboard. | Attach your lockout device to the circuit. If your lockout device does not fit, ask the electrician for an alternative. You should start only when you see a suitable lock out device fitted and you have the key. | The technician will: • Attach a lockout device to the circuit. • If this is not possible, the technician will ask the electrician for an alternative. • The electrician will provide an alternative, and show the technician when it is fitted. • The technician will take charge of the key. |
Keep it simple. I’ve seen method statement templates with so many sections (equipment, method, PPE, issues, and so on) that procedures have more ‘not applicable’ sections than completed ones. A template is useful to help you create the procedure, but then delete everything the user doesn’t need to read. Legislation for example can be in contract documentation, policies and management plans, but it is not needed on a “how to do this job” document.
A read-write (task) document provides somewhere for someone to record actions that have been taken. The confirmation might be a tick, a selection from multiple choices, a reading (such as a temperature or pressure), a free text entry or a signature to acknowledge responsibility for a check. Some checklists might require you to add a photograph – for example, showing that equipment is available, or that a worksite has been made safe.
If a control in a risk assessment states that something must be inspected, or checked, there should be a process in place for making sure the inspection or check happens. For example, if a work at height risk assessment states a control is an annual ladder inspection, there should be a checklist stating what is to be inspected, such as rungs (or steps) and feet.
While some checklists might be read only – for example, pre-inspection checks made as part of a method statement before using equipment – others require some form of written confirmation. As with the use of the word ‘document’, ‘written confirmation’ might be pen and paper, but is more likely to be typing or clicking on a checklist presented on a mobile device.
You can source your read-write documents from different places:
Some documents will be used in full each time a task is done – for example, a pre-start up checklist for machinery. Others will be updated as something changes. For example, a training log with a list of employee names might only need one person’s record to be updated if they are the only person trained.
A permit to work is a type of checklist, in that it is a read/ write document. The purpose of a permit is to provide checkpoints where someone other than the person performing the task confirms that defined controls are in place. This could be making sure that power is isolated before a hatch on equipment is opened, or that rescue equipment and personnel are in place before someone enters a confined space. A permit might also specify checks to be signed off when a task is complete, such as a hot work fire watch, and removing smoke heads after dusty work.
Some of the rules for procedures also apply to checklists. If a procedural item is “Confirm all pressure readings are in the green zone” the user should not proceed until they are; if this is an item in a checklist, how does the user report which readings are in the green zone, and which aren’t? Depending on the purpose of the checklist, you could have a separate item reporting on each pressure reading, or a free text field for reporting any readings which are abnormal.
Checklists should follow a natural order for making checks – for example, asking about fire doors in one location before moving onto the next. This is even more important for some electronic checklists if jumping ahead to a later question isn’t supported.
An advantage of electronic checklists is that if written well, they can branch. If you answer ‘no’ to ‘Does the site have a gas supply?’ you can move to the next section; if yes, further questions about gas can be presented.
There is a clear link here between your inventories and the checklists:
In some cases your inventory and your checklist might be the same document, provided you keep it up to date.
Technology can take over some of the heavy lifting for checks. For example, rather than having to test the temperature of a fridge regularly, a fridge temperature alarm can alert you when the temperature is out of range. Note that the technology itself might need some form of checking or calibration.
A management plan defines goals and responsibilities, normally for a specific hazard topic such as fire, asbestos, legionella or work at height. Some management plans focus on a process for managing safety, such as permit-to-work or training.
For example, a fire management plan will describe the fire strategy for a building, the alarm systems in place, the emergency lighting available and might show escape routes under different circumstances. It can describe the regime for testing extinguishers, alarms, call points and lighting, with responsibilities and timescales. It should include information about training provided – to all staff, to fire wardens or marshals, and to people in specialist roles. Having all this in the management plan means the fire risk assessment can be kept free of the detail, and makes updates easier.
UK health and safety legislation does not mention ‘management plans.’ However, Regulation 4 of the Control of Asbestos Regulations 2012 (CAR 2012), titled ‘Duty to manage asbestos in non-domestic premises’ refers to a ‘plan.’ Where asbestos is (or could be) present, 4(8) requires the dutyholder to ‘ensure that a written plan identifying those parts of the premises concerned is prepared’, and ‘the measures which are to be taken for managing the risk are specified in the written plan.’
Regulation 4(9) provides more details of ‘the measures to be specified in the plan’ including how you will monitor the condition of ACM and how information will be shared with workers and the emergency services. 4(10) explains the duty to review and revise the plan.
Since this is a ‘plan’ for the duty to manage, it is not surprising that the ACoP for CAR 2012 (L143) refers to a “management plan.” Sections 129 – 134 provide more detail of what the regulator expects to see in a management plan for asbestos. For example, the rules about how the register will be used to prevent asbestos being disturbed by workers or contractors. Your asbestos management plan (AMP) can set these out clearly, with information about how your organisation will make sure that workers and contractors understand what needs to be done. It might take two or three pages to describe this well, particularly if you include a flow chart or table to make the process clearer.
While following an ACoP is not a legal requirement, if you don’t follow it and someone is harmed, you will have to prove you did something of at least equal value – in other words, many professionals treat ACoP clauses as law.
Ask yourself:
How would you include all this information in a risk assessment if you didn’t have a management plan?
To include that information in every risk assessment would make an otherwise simple risk assessment lengthy, such that specific controls for a task might be missed.
Helpfully, the HSE provide a template Asbestos Management Plan on their website. The high-level headings are:
Table 14.2 gives examples of other requirements where a document equivalent to a management plan would support compliance.
| Legislation | Reference | Quote |
|---|---|---|
| Management of Health and Safety at Work Regulations 1999 | Reg 5(1)(2) | “Every employer shall make and give effect to such arrangements as are appropriate… for the effective planning, organisation, control, monitoring and review of the preventive and protective measures. Where the employer employs five or more employees, he shall record the arrangements.” |
| Regulatory Reform (Fire Safety) Order 2005 – updated by the Building Safety Act 2022 s156. See The Fire Safety (England) Regulations 2022 for additional details required in high-rise residential building | Article 11 | Fire safety arrangements “The responsible person must make and give effect to such arrangements as are appropriate … for the effective planning, organisation, control, monitoring and review of the preventive and protective measures. The responsible person must record the arrangements.” This applies regardless of the size of organisation. |
| Construction (Design and Management) Regulations 2015 | Reg 12(1)(2) | “..before setting up a construction site, the principal contractor must draw up a construction phase plan.. The construction phase plan must set out the health and safety arrangements and site rules..” |
| Legionnaires’ disease. The control of legionella bacteria in water systems: ACoP and guidance (L8) | ACoP paras 58 – 64 | Where the risk can’t otherwise be avoided “… there should be a written scheme for controlling the risk from exposure that should be properly implemented and managed. The written scheme should specify measures to take to ensure that it remains effective.” |
Once you realise that a “construction phase plan”, a “written scheme” and “fire safety arrangements” are types of management plans, it becomes easier to produce consistent documents in your organisation, which people will find easier to navigate. Whatever you call it, a management plan will help you to meet the requirements, without overloading your risk assessment documents.
Allows for more detail
Grid-based risk assessments often suffer from a lack of detail in describing controls. For example, a risk assessment of multiple tasks in a warehouse might have ‘training’ as a control, or perhaps ‘manual handling training’ and ‘forklift truck training.’ But how much training, and how do you control the quality of that training? You could expand the explanation to explain ‘manual handling that covers identifying the hazards around tasks, individual susceptibilities, load issues…. ‘ etc, etc but risk assessment templates rarely allow for this.
A similar issue arises with the ‘person responsible’ column of the risk assessment. Several people might be involved in different aspects of the action, or different people involved under different circumstances. A management plan allows you to explain this.
Avoids duplication
Let’s assume you have crammed more detail about the training requirement (or the monitoring, cleaning, inspection or other requirement) into the risk assessment.
Then you need the same control on another page. Do you repeat the description? Or write ‘manual handling training as specified on page 2’? And then, when the earlier task is removed, the description of what is included in manual handling training is lost.
The competency section of the management plan explains what competencies are required for different roles, how training will be provided and how skills and knowledge will be assessed. Similarly, arrangements for monitoring, cleaning, inspection or any other repeated task can be specified once in the management plan.
Easier update
You might have several similar risk assessments tailored for different instances. For example, a bus company provides a template risk assessment for bus stations. Each depot manager reviews the assessment with local staff representatives and tailors it to take account of layout, hours of operation and timetables. All bus depots use the same facilities company. The process for identifying a repair, contacting the facilities company, hosting the technician and so on is described in the generic risk assessment, and therefore copied across to all the local assessments.
Then the bus company changes its facilities provider, and there is a new system for arranging work. Each local assessment needs to be updated. If the process was described in a management plan, and referred to in the risk assessment, it need only be updated in one place.
Gap analysis
A management plan can help to identify gaps or errors in a risk assessment:
• The person assigned to carry out the action might not have the authority to make sure it happens.
• Controls documented in the risk assessment might be ambiguous or vague, eg ‘cleaning’, ‘training’ or ‘competency’.
• You might not have included monitoring controls – eg a control is to maintain pressure at a stated level, but no one checks the pressure reading.
• Since a standard risk assessment doesn’t include a “communicate the findings” step, you might not have thought through how you will make sure that everyone who needs to, knows what to do.
• The review period on the risk assessment might be more or less often than necessary – the management plan prompts you to think about how often and under what circumstances a review is needed.
Enables simpler risk assessments
Along with the other documents suggested in this chapter, a good management plan will make risk assessments a lot simpler. The fire risk assessment you show to office staff doesn’t need to include the detail of how and when the facilities staff will check, monitor and service all the detection and alarm systems, fire curtains and emergency exits.
The risk assessment for manual handling tasks can focus on when to use a trolley, where to store things, and when to lift with other people. The detail of how and when the trolleys and storage units are checked can be in the maintenance area of the management plan.
COSHH assessments used by workers can focus on practical instructions, such as handling procedures and the PPE required. Details of measures taken to substitute for less hazardous substances in procurement and the management of the supplier’s safety data sheets can be explained in the management plan.
A risk assessment for employees working near forklifts or delivery trucks can emphasise the use of safe pedestrian routes and designated crossing points, and requirements for high-visibility clothing. It doesn’t need to delve into the frequency and process of vehicle maintenance checks or driver competence assessments.
Creating a risk register will help you to identify which systems of controls might need a management plan. If you have management plans based on hazards (eg asbestos or work at height) and on topics (eg contractors or training) be careful not to duplicate the effort. For example, the asbestos management plan might need to refer to the contractor management plan for how to select contractors, or the contractor management plan might point to the asbestos management plan where there are different rules for contractors working with asbestos.
Answer these questions to help you decide when to have a management plan:
The management plan for a construction project is very different from a fire safety management plan or a confined space management plan. But there are some things that should always be documented:
A policy statement that summarises the organisation’s approach to the topic. For example “We will comply with the regulations on topic X by following the guidance in document Y. Over time we intend to reduce / eliminate the hazard by doing Z.” This section also makes clear, in a qualitative way, the organisation’s tolerance of risk. As a roofing contractor, you want to eliminate exposure to asbestos and diesel, but accept that work at height is inevitable.
Responsibilities. Organisations differ on whether this should have named people, or a job title. Whichever approach is taken, this section must leave people in no doubt as to who is responsible for what. This can be done in a hierarchical way. For example:
How it’s done (and how it’s done safely). This is a more detailed explanation which expands on the approach to explain what technical and human systems are in place to manage safety around the topic. This can provide references to manuals, procedures, checklists and risk assessments.
How it’s reviewed. It should be clear how the processes outlined are checked, and how any feedback is used to improve the process.
You can have individual management plans for each hazard topic, but there will be some duplication between these management plans. For example, the same team might be responsible for maintaining a list of documents and chasing people to review them periodically, or the process for first-aid will be the same in each plan. You could have a super management plan which provides all the general information, and references topic-specific plans (asbestos, legionella, fire) for the detail which applies only to that topic. Many organisations refer to this document as the health and safety policy document, but the policy should only be one or two pages in that document, with the rest of the document focussed on how to manage risk.
Too often, the risk assessment is expected to do everything. But there are other documents in your health and safety library that are better suited to some of those responsibilities. Table 14.3 summarises the documents we’ve discussed in this chapter.
| Document Type | Purpose | Content | When to use | Advantages |
|---|---|---|---|---|
| Risk Register | Central overview of hazards, their associated risks, and controls. | List of hazards, risk ratings, controls, and review dates. | When multiple hazards need to be tracked and prioritised over time. | Offers an organisational overview, supports prioritisation and monitoring of changes. |
| Action tracker | Tracks the progress and completion of corrective or preventive actions for hazards – a ‘to do’ list. | List of actions, assigned responsibilities, deadlines, and completion status. | When further actions, such as checks or maintenance, are required to address hazards or implement improvements. | Ensures accountability, demonstrates due diligence, and prevents actions from being overlooked. |
| Inventory | Tracks physical assets, especially hazardous substances, equipment, or tools. Controls can be applied to all items in an inventory to ensure completeness. | List of items, quantities, locations, and associated risks or maintenance needs. | When managing hazardous materials, equipment, or PPE, or ensuring compliance with regulations like COSHH. | Prevents shortages, improves organisation, and identifies high-risk items needing attention. |
| Task docs: read only eg method statements, procedures | Detailed step-by-step guide for safely completing a specific task or activity. | Instructions, roles, PPE, and necessary tools or equipment. | When tasks involve specific, high-risk steps or require precise adherence to ensure safety. | Provides clarity, reduces errors, and ensures tasks are performed consistently and safely. |
| Task docs: read-write eg permits, legionella temperature records | Routine tool for checking status, checking the status of hazards or ensuring compliance. | List of checkpoints for inspecting key controls, equipment, or processes. | When key steps in a process need to be monitored or confirmed to control hazards. | Provides assurance that critical steps have occurred and provides data on systems for further action. |
| Management Plan | Long-term strategy for managing hazards across multiple teams, sites, or over time. | Vision, objectives, roles, responsibilities, and phased actions for managing hazards. | When hazards need long-term reduction, involve multiple teams, span sites, or require ongoing monitoring. | Ensures consistency especially during updates, provides greater detail without duplication, and integrates hazard controls into broader systems. |
In section 14.4 I asked you to think of at least three advantages to documenting your findings outside the risk assessment table. Here are a few:
In Chapter 15 we’ll look at some of the problems that occur when, rather than using other documents, too much is put on a single risk assessment document. Alternatively, skip straight to Chapter 16, where we look at better ways of documenting the risk assessment findings, with the assumption that the documents in Table 14.3 will be part of the system.
You can use the Contact form to send me feedback. If you’d like to receive an email when I add or update a chapter, please subscribe to my ‘book club’
Alternatively, go back to the book contents page
Appendix 1: Case studies by year
Appendix 2: Answers to questons posed in each chapter
Appendix 3: Lost HSE references