health safety compliance15 June 2026

Health Safety Compliance: A UK Developer's Guide 2026

By Domus

You're usually not thinking about health safety compliance when a deal first looks attractive. You're looking at purchase price, planning risk, programme, abnormal costs, debt terms, and exit. Then the site moves, contractors mobilise, deliveries start arriving, and suddenly a missing induction record or an outdated scaffold inspection becomes more than a site issue. It becomes a delivery issue, a funding issue, and in the worst cases, a leadership issue.

That's the mistake I see most often in development teams. They treat safety as a contractor admin stream sitting off to one side. In practice, it sits in the middle of execution. If your records are weak, your controls are unclear, or your site team can't explain how risk is being managed today rather than last month, the project is exposed. Not just legally. Commercially.

The True Cost of a Health and Safety Surprise

A familiar scenario goes like this. The job is midway through the frame package. The programme is already tight. A site visit raises questions about scaffolding paperwork, subcontractor inductions, and whether the people on site are working to the latest approved method. None of those issues looks dramatic in isolation. Together, they signal loss of control.

That's when a “minor” compliance gap stops being minor.

Work slows immediately because managers start searching for evidence instead of managing the job. The contractor blames a subcontractor. The subcontractor says the revision was never issued. The employer's agent wants answers. The lender starts asking whether this is a one off or a sign that the wider project controls are weak. Even before any formal action, the damage is done because confidence drops.

The wider context matters. In Great Britain, the Health and Safety Executive estimated that in 2024/25 around 680,000 workers sustained a non fatal workplace injury, while 124 workers were killed in work related accidents. The same HSE linked reporting also states there were 59,219 RIDDOR reportable injuries and 4.4 million working days lost due to non fatal injuries, which shows why the issue isn't abstract for employers in property and construction supply chains (HSE statistics reported by CHAS).

Where the money starts leaking

A health and safety surprise usually hits a development in four places at once:

  • Programme pressure: Crews stand down, sequencing breaks, and follow on trades lose access.
  • Management time: Directors, PMs, and consultants spend days reconstructing decisions that should have been traceable in minutes.
  • Funding friction: A lender or monitoring surveyor doesn't just want reassurance. They want evidence.
  • Reputational drag: The market remembers which teams run controlled sites and which teams always seem to be firefighting.

Practical rule: If a site issue can't be evidenced clearly on the same day, assume it's already become a commercial problem.

The hard truth is that health safety compliance isn't a back office burden. It's one of the systems that keeps a project financeable and buildable. Teams that learn this early tend to avoid the expensive kind of surprise.

Understanding Your Core Regulatory Duties

Most developers don't need a law lecture. They need to know what the law requires them to do in practice, and where responsibility still sits with them even when consultants and contractors are appointed.

The base position is straightforward. Under the Health and Safety at Work etc. Act 1974, employers must ensure, so far as is reasonably practicable, the health, safety and welfare of employees and others affected by their work. The Management of Health and Safety at Work Regulations 1999 require suitable and sufficient risk assessments plus recorded preventive arrangements. In a development workflow, that means compliance depends on maintaining a current hazard register, linking each material risk to a control owner, and preserving an auditable trail from assessment to mitigation to review (health and safety compliance duties and risk assessment requirements).

What this means for a developer

If you're the client, you can appoint expertise. You can't appoint away accountability for making sensible arrangements.

A developer's practical duties usually include:

  • Setting the structure early: Appoint the right people before design and procurement drift too far.
  • Testing competence in a real way: Don't just collect policies. Check whether the team can manage the actual risks on your site.
  • Requiring current risk information: The hazard picture on a constrained city centre refurbishment isn't the same as a clean edge of town new build.
  • Keeping a decision trail: When a risk changes, the record should show who reviewed it, what control was chosen, and when it was communicated.

Key roles and responsibilities under CDM 2015

Role Key Responsibility
Client Make suitable arrangements for managing the project, including time and resources, and appoint the right dutyholders
Principal Designer Plan, manage, monitor and coordinate health and safety during the pre construction phase, including designing out foreseeable risk where possible
Principal Contractor Plan, manage, monitor and coordinate the construction phase, including site controls, inductions, supervision, and implementation of the construction phase plan

That table looks simple. Live projects aren't.

A common failure is assuming the Principal Designer owns all pre construction risk once appointed. They don't own your need to make sure the appointment is effective, the information is complete, and the team coordinates. The same goes for the Principal Contractor. A polished pre start meeting doesn't prove the site is under control three months later when labour has changed and the sequence has moved on.

The duty that gets missed most often

The phrase “suitable and sufficient” matters because generic paperwork won't rescue a project if it doesn't reflect the actual work. A developer refurbishing an occupied building needs very different controls from a developer building on a cleared plot. If residents, neighbours, visitors, or retained tenants can be affected, the risk management has to deal with them too.

The legal test isn't whether a file exists. It's whether the arrangements are good enough for the work being done by the people actually exposed.

That's why I push teams to think less about document collection and more about control ownership. For every material risk, someone should be named, the control should be specific, and the review point should be obvious. If those three things aren't clear, the duty hasn't really been discharged in any practical sense.

The Essential Compliance Document Toolkit

A strong compliance file isn't the thickest file. It's the one that a site manager, contractor, funder, or investigator can use.

Three documents usually tell you whether a project is effectively controlled or just heavily papered: the risk assessment, the method statement, and the construction phase plan. If any one of those is weak, the rest often collapse with it.

Risk assessments that match the job

A decent risk assessment identifies actual hazards of the task, the people exposed, the controls required, and the review trigger. A weak one uses generic wording that could apply to any site in the country.

Take façade access as an example. A suitable assessment should reflect the actual access system, the edge protection in place, weather exposure, interface with other trades, and rescue arrangements if something goes wrong. It should also be updated if the access strategy changes. Too many teams still file a standard version and move on.

Before acquisition and mobilisation, this sits alongside broader project checks. If you're already tightening your due diligence process, a structured property due diligence checklist for UK development projects helps expose where health and safety risks belong in the wider investment picture.

Method statements and RAMS that operatives can follow

Method statements should translate risk into sequence. They should answer a simple site question: how is this work meant to be done safely, in this location, with this team, using this equipment?

What doesn't work is the classic shelf document. You know the type. Dense text, copied from another job, signed by people who weren't on site when the task changed. Those documents satisfy procurement teams for about five minutes and then fail the first real test.

Good RAMS usually have these features:

  • Task specific wording: They describe the actual work package rather than a broad trade category.
  • Clear hold points: They show where work must stop until a check or approval happens.
  • Visible supervision: They identify who is responsible for briefing and enforcing the method.
  • Revision control: They make it obvious which version is current.

The construction phase plan as the live operating manual

The Construction Phase Plan should pull the project together. It's the master document that explains how the site will be run safely, how risks will be managed, how welfare and emergency arrangements work, and how information flows between parties.

The mistake developers make is treating the CPP as a mobilisation milestone rather than a live control document. If a project changes from shell only works to a more complex fit out package mix, the CPP should move with it. If site logistics tighten, if access routes change, if simultaneous operations increase, the CPP needs to reflect that reality.

A good CPP doesn't impress because it's long. It impresses because the site team can use it to make decisions on a difficult day.

When I review compliance packs, I'm not looking for elegant formatting. I'm looking for evidence that the documents connect. The risk assessment should feed the method statement. The method statement should align with supervision on site. The CPP should show how the whole system is being managed, updated, and checked.

Compliance Checkpoints Across the Development Lifecycle

Health safety compliance starts long before boots hit the ground. The strongest projects handle it as a sequence of checkpoints tied to commercial decisions, not as a construction only obligation.

A property development timeline chart outlining five key health and safety compliance checkpoints for construction projects.

Viability and acquisition

At acquisition, the question isn't “is this site compliant?” It's “what hazards are already embedded in the opportunity?”

On some sites that means asbestos, contamination, unstable structures, live services, restricted access, or neighbouring occupiers who will stay in place during works. Those aren't side notes. They affect build cost, programme logic, and whether the scheme still stacks up. Teams running better front end governance usually connect these findings to the same workflow they use for feasibility and delivery planning, which is why disciplined construction project management in the UK development cycle matters so much.

Design and pre construction

The design phase is where expensive site risk can often be reduced, transferred, or eliminated. If access for maintenance is poor, if sequencing creates unsafe trade overlap, or if temporary works are being left vague, the project is storing up trouble for later.

By pre construction, the focus shifts. Appointments need to be locked down properly. Pre construction information must be usable, not just assembled. Contractor proposals should be checked against actual site conditions, not accepted because the start date is close.

A practical way to view this phase is as a readiness test:

  • Have the key risks been identified early enough to influence design?
  • Do the appointed dutyholders understand their specific role on this project?
  • Can the contractor's planned controls withstand normal project change?

Construction and handover

Once the site is live, compliance depends on rhythm. Inductions, briefings, inspections, permit controls, supervision, and review meetings all need to happen at the pace of the job. If the programme changes weekly, risk controls need to be checked weekly or more often.

The final trap comes at handover. Teams often relax because visible construction risk is reducing. But handover is when the health and safety file, residual risk information, testing records, and operational instructions need to be complete and coherent. If they aren't, the employer inherits uncertainty that can affect occupation, facilities management, and future works.

Here's the sequence I expect teams to hold in mind throughout a live scheme:

  1. Early stage: Identify hazards that alter viability, cost, or sequencing.
  2. Design stage: Remove or reduce foreseeable risk before site teams inherit it.
  3. Mobilisation stage: Convert intent into site specific controls and clear appointments.
  4. Delivery stage: Keep records current as work packages, labour, and conditions change.
  5. Close out stage: Hand over a usable safety record, not a rushed archive.

Beyond the Checklist Common On Site Failures

I've walked onto sites with tidy folders, signed registers, and immaculate looking RAMS, then found operatives wearing the wrong PPE for the task, supervisors unclear on the latest sequence, and access routes blocked by changing logistics. That's the central weakness in a lot of health safety compliance. Paper says one thing. Site conditions say another.

Recent research is useful here because it names the barriers teams often pretend aren't structural. It found that complex incident reporting, formalistic procedures, poor interdepartmental coordination, and productivity over safety norms are statistically significant barriers to occupational safety and health outcomes (research on barriers to safety outcomes under real working pressure). That matches what experienced project teams already know. If the process is clumsy, people stop using it when the site gets busy.

A comparative infographic illustrating the disconnect between documented safety policies and actual site working conditions.

Where compliance slips in the real world

The failure points are usually ordinary rather than dramatic.

One is shelf ware RAMS. The documents exist, but the operatives doing the task haven't been properly briefed, or the method no longer reflects the workface conditions. Another is subcontractor layering. The package is let, then parts of the work are pushed down another level, and control becomes blurry. A third is programme pressure. The team knows the safe sequence, but the pressure to recover time encourages shortcuts.

You can see this clearly on jobs with frequent change in labour or method. The original plan may have been sensible. The issue is that nobody refreshed it when the reality changed.

What works better than more paperwork

If you want stronger site performance, simplify what people have to do.

  • Shorter reporting routes: If raising a concern takes too many steps, workers stay quiet.
  • Clear site ownership: One person must own each live control, not “the team” in general.
  • Briefings tied to today's work: Daily coordination beats a forgotten induction pack.
  • Visible escalation: Site managers need authority to stop a task without commercial pushback.

A lot of this comes down to whether the controls are usable under stress. Complex risk environments don't need more words. They need cleaner decisions. On high risk or legacy sites, a focused coal mine style risk assessment mindset for hidden hazards and changing conditions is often a better mental model than generic compliance language, because it forces teams to look at what can change quickly and who is exposed when it does.

If your process only works when the site is calm, it doesn't work.

The practical test is simple. Ask a supervisor what the top risks are today, what changed since yesterday, and what would stop the task. If the answer is immediate and consistent, the controls are probably alive. If the answer starts with “it should be in the folder”, they probably aren't.

Audits Record Keeping and Achieving Lender Readiness

When an auditor, monitoring surveyor, or lender reviews a project, they're not just checking whether health and safety documents exist. They're checking whether the project is being governed in a way that can withstand scrutiny.

That means records need to show action over time. Not just a risk assessment. The review of the risk assessment. Not just an appointment. Evidence that the dutyholder performed the role. Not just a site inspection. The close out of what the inspection found.

Screenshot from https://www.domusgroups.com

What lenders and auditors actually look for

In my experience, a robust evidence pack usually answers four questions quickly:

Audit question What good evidence looks like
Who owns the risk? Named dutyholders, current responsibilities, and clear reporting lines
What was identified? Project specific hazards, not generic templates
What was done about it? Actions, dates, updates, and closed loop follow up
Can the team prove control today? Current revisions, recent inspections, briefing records, and accessible files

Spreadsheets and email chains struggle here because they fragment the story. One folder holds the RAMS. Another consultant holds the review comments. The site team has a newer revision on a laptop. The project manager has a separate action tracker. When someone asks for proof, people start reconciling versions instead of producing evidence.

That's where a connected system matters. Not because software is fashionable, but because fragmented records create avoidable doubt. If a team can pull together a coherent trail from early hazard identification through to control implementation and review, lender conversations get easier and internal governance gets sharper.

A short product walkthrough helps show what a more structured workflow looks like in practice:

The standard to aim for

Lender ready compliance isn't perfection. It's traceability.

You want a system where missing evidence is visible early, ownership is obvious, and updates don't disappear into inboxes. If an underwriter or auditor asks how the project manages health and safety risk, the answer should be a coherent record, not a scramble across shared drives.

Frequently Asked Compliance Questions

Is the developer still exposed if the principal contractor is appointed?

Yes. Appointment matters, but it doesn't remove the client's duty to make suitable arrangements for managing the project. If the structure is weak, the information is incomplete, or the appointments are nominal rather than effective, the developer is still exposed.

How often should risk assessments be reviewed?

They should be reviewed whenever the work, workforce, sequence, equipment, or site conditions change in a way that affects risk. A generic annual mindset is far too passive for a live construction environment. On busy projects, the true trigger is change, not the calendar.

What does “suitable and sufficient” look like in practice?

It means the assessment fits the actual job. A document that ignores occupied areas, temporary works interfaces, delivery conflicts, or non routine tasks might look compliant in a file and still be poor in practice. The test is whether the controls are specific enough to direct safe work on that site.

Are RAMS enough to show compliance?

No. RAMS are only one part of the picture. You also need evidence that the RAMS were briefed, understood, implemented, supervised, and updated when conditions changed. If the site team can't show that chain, the paperwork is incomplete.

What usually causes the biggest compliance blind spot on multi contractor sites?

Interface risk. One contractor may have a sensible plan for its own package, but the danger appears where access routes, lifting zones, deliveries, welfare, or shared work areas overlap. Those interface points need active coordination, not just separate package documents.

What should be ready for a lender or monitoring surveyor at short notice?

Keep these current and easy to retrieve:

  • Appointments and roles: Clear dutyholder records and reporting lines.
  • Live risk information: Current hazard register, not an outdated startup version.
  • Core site documents: Relevant assessments, methods, permits, and the current CPP.
  • Action trail: Inspection findings, close out records, and evidence of follow up.
  • Handover path: A clear approach to health and safety file completion as the job progresses.

Good compliance records don't just defend the past. They prove the project is being managed properly today.

If your team is still stitching together safety evidence from separate spreadsheets, emails, and disconnected reports, Domus gives UK property developers and lenders a connected way to manage project data, due diligence, and lender ready evidence in one workflow. It helps teams keep decisions structured, risks visible, and records auditable from early appraisal through to delivery.

From Domus

Model it properly — not in a spreadsheet

Domus gives UK developers a structured platform to run development appraisals, residual land value models, planning viability assessments, and cashflow — all in one place.

About the author

Domus

Stop doing this in Excel

Domus is development appraisal software built for UK property teams — residual land value, planning viability, cashflow, and section 106, all structured and linked.