Compliance
RAMS Explained: Risk Assessments and Method Statements for UK Sites
On any UK construction site, "have you got the RAMS?" is one of the first questions a principal contractor will ask before your team sets foot on the job. Yet RAMS is one of the most misused acronyms in the industry — treated as a single form to be downloaded, signed and filed, rather than the two distinct safety documents it actually is. This guide sets out what a risk assessment and a method statement each do, when the law requires them, and how to keep them from going stale.
What does RAMS stand for?
RAMS stands for Risk Assessment and Method Statement — two documents that almost always travel together, and are often bound into one. They answer two different questions about a task:
- The risk assessment asks *what could go wrong, and how bad could it be?* It identifies the hazards, judges the risk, and sets the control measures that bring that risk down to an acceptable level.
- The method statement asks *so how do we do this safely, step by step?* It describes the safe system of work — the sequence, the equipment, the people, the controls — that puts the risk assessment into practice on the ground.
Get the distinction and the whole thing makes sense: the risk assessment is the thinking, the method statement is the doing. One without the other is half a document.
Are RAMS a legal requirement?
"RAMS" as a single named document is an industry convention, not a phrase you'll find in a statute. But the two duties underneath it are firmly in law:
- Risk assessment is required by regulation 3 of the Management of Health and Safety at Work Regulations 1999. Every employer must assess the risks to workers and anyone else affected by the work. If you employ five or more people, the significant findings must be recorded.
- Method statements are not named in law, but on construction work regulation 13 of CDM 2015 requires contractors to plan, manage and monitor their work so it is carried out without risks to health and safety, so far as is reasonably practicable — and a written method statement is the recognised way to show you have done that for a high-risk task.
The practical reality
Whatever the letter of the law, no principal contractor will let a subcontractor start high-risk work without approved RAMS. For work at height, excavation, lifting, hot works or confined spaces, they are effectively mandatory — the ticket onto the site.
How to write a risk assessment: the five steps
The HSE's long-standing approach breaks a risk assessment into five plain steps:
- Identify the hazards — walk the task and the site, and be honest about what could cause harm: the edge, the dust, the moving plant, the buried service.
- Decide who might be harmed and how — your own crew, other trades, the public, lone workers, young or new workers.
- Evaluate the risks and decide on controls — follow the hierarchy: eliminate the hazard if you can, then reduce, isolate and control, with PPE as the last line, not the first.
- Record your significant findings — write down the hazards, who is at risk, and the controls. If you have five or more employees this is a legal duty, not an option.
- Review and update — a risk assessment is not a document you write once. Revisit it when the work changes, when something goes wrong, or when a near miss tells you a control isn't holding.
What a good method statement contains
A method statement should let someone who wasn't in the planning meeting carry out the task safely. In practice that means:
- The task and its sequence — a clear, step-by-step description of the work, in the order it happens.
- Who does what — roles, responsibilities, and the competence or training each step requires.
- Plant, equipment and materials — what is used, and the safety checks it needs before use.
- The control measures from the risk assessment — carried through into the actual method, not left behind on the other document.
- Emergency arrangements — what happens if it goes wrong: rescue, first aid, who to call.
The RAMS problem nobody talks about
The failure mode of RAMS is not writing them — it is what happens after. A method statement approved in an office, printed, signed at induction and never looked at again is a document that protects a filing cabinet, not a worker. The site changes, a new hazard appears, an incident happens — and the RAMS says none of it.
The regulations are clear that a risk assessment must be reviewed when circumstances change or when there is reason to think it is no longer valid. The single strongest reason to think that is your own incident and near-miss data. If workers keep reporting near misses around a task your RAMS calls "low risk", the document is wrong and the reports are right. A toolbox talk is how you brief the RAMS to the crew; an incident report is how the crew tells you the RAMS needs updating.
Keep RAMS alive
Treat your RAMS as a living control, not a one-off admission ticket. Every incident and near miss your teams report is feedback on whether the controls are working — feed it straight back into the assessment, and the document starts protecting people instead of paperwork.
That feedback loop is exactly what jobsafe is built to power. Workers capture incidents and near misses in seconds from the phone in their pocket — with photos, location and time attached — and a live dashboard shows you where reports cluster, so you know which RAMS to revisit before the next job, not after the next injury. See how reporting works, or call us on 0333 8000 883.