Health Safety Compliance: A UK Developer's Guide 2026
By Domus
By Domus
You're usually not thinking about health safety compliance when a deal first looks attractive. You're looking at purchase price, planning risk, programme, abnormal costs, debt terms, and exit. Then the site moves, contractors mobilise, deliveries start arriving, and suddenly a missing induction record or an outdated scaffold inspection becomes more than a site issue. It becomes a delivery issue, a funding issue, and in the worst cases, a leadership issue.
That's the mistake I see most often in development teams. They treat safety as a contractor admin stream sitting off to one side. In practice, it sits in the middle of execution. If your records are weak, your controls are unclear, or your site team can't explain how risk is being managed today rather than last month, the project is exposed. Not just legally. Commercially.
A familiar scenario goes like this. The job is midway through the frame package. The programme is already tight. A site visit raises questions about scaffolding paperwork, subcontractor inductions, and whether the people on site are working to the latest approved method. None of those issues looks dramatic in isolation. Together, they signal loss of control.
That's when a “minor” compliance gap stops being minor.
Work slows immediately because managers start searching for evidence instead of managing the job. The contractor blames a subcontractor. The subcontractor says the revision was never issued. The employer's agent wants answers. The lender starts asking whether this is a one off or a sign that the wider project controls are weak. Even before any formal action, the damage is done because confidence drops.
The wider context matters. In Great Britain, the Health and Safety Executive estimated that in 2024/25 around 680,000 workers sustained a non fatal workplace injury, while 124 workers were killed in work related accidents. The same HSE linked reporting also states there were 59,219 RIDDOR reportable injuries and 4.4 million working days lost due to non fatal injuries, which shows why the issue isn't abstract for employers in property and construction supply chains (HSE statistics reported by CHAS).
A health and safety surprise usually hits a development in four places at once:
Practical rule: If a site issue can't be evidenced clearly on the same day, assume it's already become a commercial problem.
The hard truth is that health safety compliance isn't a back office burden. It's one of the systems that keeps a project financeable and buildable. Teams that learn this early tend to avoid the expensive kind of surprise.
Most developers don't need a law lecture. They need to know what the law requires them to do in practice, and where responsibility still sits with them even when consultants and contractors are appointed.
The base position is straightforward. Under the Health and Safety at Work etc. Act 1974, employers must ensure, so far as is reasonably practicable, the health, safety and welfare of employees and others affected by their work. The Management of Health and Safety at Work Regulations 1999 require suitable and sufficient risk assessments plus recorded preventive arrangements. In a development workflow, that means compliance depends on maintaining a current hazard register, linking each material risk to a control owner, and preserving an auditable trail from assessment to mitigation to review (health and safety compliance duties and risk assessment requirements).
If you're the client, you can appoint expertise. You can't appoint away accountability for making sensible arrangements.
A developer's practical duties usually include:
| Role | Key Responsibility |
|---|---|
| Client | Make suitable arrangements for managing the project, including time and resources, and appoint the right dutyholders |
| Principal Designer | Plan, manage, monitor and coordinate health and safety during the pre construction phase, including designing out foreseeable risk where possible |
| Principal Contractor | Plan, manage, monitor and coordinate the construction phase, including site controls, inductions, supervision, and implementation of the construction phase plan |
That table looks simple. Live projects aren't.
A common failure is assuming the Principal Designer owns all pre construction risk once appointed. They don't own your need to make sure the appointment is effective, the information is complete, and the team coordinates. The same goes for the Principal Contractor. A polished pre start meeting doesn't prove the site is under control three months later when labour has changed and the sequence has moved on.
The phrase “suitable and sufficient” matters because generic paperwork won't rescue a project if it doesn't reflect the actual work. A developer refurbishing an occupied building needs very different controls from a developer building on a cleared plot. If residents, neighbours, visitors, or retained tenants can be affected, the risk management has to deal with them too.
The legal test isn't whether a file exists. It's whether the arrangements are good enough for the work being done by the people actually exposed.
That's why I push teams to think less about document collection and more about control ownership. For every material risk, someone should be named, the control should be specific, and the review point should be obvious. If those three things aren't clear, the duty hasn't really been discharged in any practical sense.
A strong compliance file isn't the thickest file. It's the one that a site manager, contractor, funder, or investigator can use.
Three documents usually tell you whether a project is effectively controlled or just heavily papered: the risk assessment, the method statement, and the construction phase plan. If any one of those is weak, the rest often collapse with it.
A decent risk assessment identifies actual hazards of the task, the people exposed, the controls required, and the review trigger. A weak one uses generic wording that could apply to any site in the country.
Take façade access as an example. A suitable assessment should reflect the actual access system, the edge protection in place, weather exposure, interface with other trades, and rescue arrangements if something goes wrong. It should also be updated if the access strategy changes. Too many teams still file a standard version and move on.
Before acquisition and mobilisation, this sits alongside broader project checks. If you're already tightening your due diligence process, a structured property due diligence checklist for UK development projects helps expose where health and safety risks belong in the wider investment picture.
Method statements should translate risk into sequence. They should answer a simple site question: how is this work meant to be done safely, in this location, with this team, using this equipment?
What doesn't work is the classic shelf document. You know the type. Dense text, copied from another job, signed by people who weren't on site when the task changed. Those documents satisfy procurement teams for about five minutes and then fail the first real test.
Good RAMS usually have these features:
The Construction Phase Plan should pull the project together. It's the master document that explains how the site will be run safely, how risks will be managed, how welfare and emergency arrangements work, and how information flows between parties.
The mistake developers make is treating the CPP as a mobilisation milestone rather than a live control document. If a project changes from shell only works to a more complex fit out package mix, the CPP should move with it. If site logistics tighten, if access routes change, if simultaneous operations increase, the CPP needs to reflect that reality.
A good CPP doesn't impress because it's long. It impresses because the site team can use it to make decisions on a difficult day.
When I review compliance packs, I'm not looking for elegant formatting. I'm looking for evidence that the documents connect. The risk assessment should feed the method statement. The method statement should align with supervision on site. The CPP should show how the whole system is being managed, updated, and checked.
Health safety compliance starts long before boots hit the ground. The strongest projects handle it as a sequence of checkpoints tied to commercial decisions, not as a construction only obligation.

At acquisition, the question isn't “is this site compliant?” It's “what hazards are already embedded in the opportunity?”
On some sites that means asbestos, contamination, unstable structures, live services, restricted access, or neighbouring occupiers who will stay in place during works. Those aren't side notes. They affect build cost, programme logic, and whether the scheme still stacks up. Teams running better front end governance usually connect these findings to the same workflow they use for feasibility and delivery planning, which is why disciplined construction project management in the UK development cycle matters so much.
The design phase is where expensive site risk can often be reduced, transferred, or eliminated. If access for maintenance is poor, if sequencing creates unsafe trade overlap, or if temporary works are being left vague, the project is storing up trouble for later.
By pre construction, the focus shifts. Appointments need to be locked down properly. Pre construction information must be usable, not just assembled. Contractor proposals should be checked against actual site conditions, not accepted because the start date is close.
A practical way to view this phase is as a readiness test:
Once the site is live, compliance depends on rhythm. Inductions, briefings, inspections, permit controls, supervision, and review meetings all need to happen at the pace of the job. If the programme changes weekly, risk controls need to be checked weekly or more often.
The final trap comes at handover. Teams often relax because visible construction risk is reducing. But handover is when the health and safety file, residual risk information, testing records, and operational instructions need to be complete and coherent. If they aren't, the employer inherits uncertainty that can affect occupation, facilities management, and future works.
Here's the sequence I expect teams to hold in mind throughout a live scheme:
I've walked onto sites with tidy folders, signed registers, and immaculate looking RAMS, then found operatives wearing the wrong PPE for the task, supervisors unclear on the latest sequence, and access routes blocked by changing logistics. That's the central weakness in a lot of health safety compliance. Paper says one thing. Site conditions say another.
Recent research is useful here because it names the barriers teams often pretend aren't structural. It found that complex incident reporting, formalistic procedures, poor interdepartmental coordination, and productivity over safety norms are statistically significant barriers to occupational safety and health outcomes (research on barriers to safety outcomes under real working pressure). That matches what experienced project teams already know. If the process is clumsy, people stop using it when the site gets busy.

The failure points are usually ordinary rather than dramatic.
One is shelf ware RAMS. The documents exist, but the operatives doing the task haven't been properly briefed, or the method no longer reflects the workface conditions. Another is subcontractor layering. The package is let, then parts of the work are pushed down another level, and control becomes blurry. A third is programme pressure. The team knows the safe sequence, but the pressure to recover time encourages shortcuts.
You can see this clearly on jobs with frequent change in labour or method. The original plan may have been sensible. The issue is that nobody refreshed it when the reality changed.
If you want stronger site performance, simplify what people have to do.
A lot of this comes down to whether the controls are usable under stress. Complex risk environments don't need more words. They need cleaner decisions. On high risk or legacy sites, a focused coal mine style risk assessment mindset for hidden hazards and changing conditions is often a better mental model than generic compliance language, because it forces teams to look at what can change quickly and who is exposed when it does.
If your process only works when the site is calm, it doesn't work.
The practical test is simple. Ask a supervisor what the top risks are today, what changed since yesterday, and what would stop the task. If the answer is immediate and consistent, the controls are probably alive. If the answer starts with “it should be in the folder”, they probably aren't.
When an auditor, monitoring surveyor, or lender reviews a project, they're not just checking whether health and safety documents exist. They're checking whether the project is being governed in a way that can withstand scrutiny.
That means records need to show action over time. Not just a risk assessment. The review of the risk assessment. Not just an appointment. Evidence that the dutyholder performed the role. Not just a site inspection. The close out of what the inspection found.

In my experience, a robust evidence pack usually answers four questions quickly:
| Audit question | What good evidence looks like |
|---|---|
| Who owns the risk? | Named dutyholders, current responsibilities, and clear reporting lines |
| What was identified? | Project specific hazards, not generic templates |
| What was done about it? | Actions, dates, updates, and closed loop follow up |
| Can the team prove control today? | Current revisions, recent inspections, briefing records, and accessible files |
Spreadsheets and email chains struggle here because they fragment the story. One folder holds the RAMS. Another consultant holds the review comments. The site team has a newer revision on a laptop. The project manager has a separate action tracker. When someone asks for proof, people start reconciling versions instead of producing evidence.
That's where a connected system matters. Not because software is fashionable, but because fragmented records create avoidable doubt. If a team can pull together a coherent trail from early hazard identification through to control implementation and review, lender conversations get easier and internal governance gets sharper.
A short product walkthrough helps show what a more structured workflow looks like in practice:
Lender ready compliance isn't perfection. It's traceability.
You want a system where missing evidence is visible early, ownership is obvious, and updates don't disappear into inboxes. If an underwriter or auditor asks how the project manages health and safety risk, the answer should be a coherent record, not a scramble across shared drives.
Yes. Appointment matters, but it doesn't remove the client's duty to make suitable arrangements for managing the project. If the structure is weak, the information is incomplete, or the appointments are nominal rather than effective, the developer is still exposed.
They should be reviewed whenever the work, workforce, sequence, equipment, or site conditions change in a way that affects risk. A generic annual mindset is far too passive for a live construction environment. On busy projects, the true trigger is change, not the calendar.
It means the assessment fits the actual job. A document that ignores occupied areas, temporary works interfaces, delivery conflicts, or non routine tasks might look compliant in a file and still be poor in practice. The test is whether the controls are specific enough to direct safe work on that site.
No. RAMS are only one part of the picture. You also need evidence that the RAMS were briefed, understood, implemented, supervised, and updated when conditions changed. If the site team can't show that chain, the paperwork is incomplete.
Interface risk. One contractor may have a sensible plan for its own package, but the danger appears where access routes, lifting zones, deliveries, welfare, or shared work areas overlap. Those interface points need active coordination, not just separate package documents.
Keep these current and easy to retrieve:
Good compliance records don't just defend the past. They prove the project is being managed properly today.
If your team is still stitching together safety evidence from separate spreadsheets, emails, and disconnected reports, Domus gives UK property developers and lenders a connected way to manage project data, due diligence, and lender ready evidence in one workflow. It helps teams keep decisions structured, risks visible, and records auditable from early appraisal through to delivery.
From Domus
Domus gives UK developers a structured platform to run development appraisals, residual land value models, planning viability assessments, and cashflow — all in one place.
Domus