Search "risk assessment template UK" and you'll get a thousand blank grids: hazard, who's at risk, controls, risk rating, done. Download one and you quickly hit the real problem — the template doesn't tell you what to write. A blank table is not a risk assessment any more than a blank invoice is a payment.
This guide breaks down what a genuinely useful UK risk assessment template contains, why each field matters, and where most SME contractors come unstuck.
What the law actually requires
Under the Management of Health and Safety at Work Regulations 1999, every employer must make a "suitable and sufficient" assessment of the risks to employees and anyone else affected by the work. There is no legally required template — but there is a legally required standard. "Suitable and sufficient" means the assessment is proportionate to the risk, identifies the significant hazards, and records the conclusions where you employ five or more people.
In practice, principal contractors, PQQ assessors and insurers all judge your assessment against the same unwritten checklist. A good template is simply one that forces you to answer every question on that checklist.
The fields a good template forces you to complete
- The actual activity — not "construction work" but "laying 150mm drainage at 1.4m depth, two live services crossing the run." Generic activity descriptions produce generic, worthless assessments.
- Specific hazards — separated out, not lumped together. "Working at height" and "fragile roof surface" are two different hazards with two different control sets.
- Who is at risk — operatives, other trades, the public, visitors. This drives which controls are actually adequate.
- Existing controls and further controls — what's already in place versus what you'll add. Assessors look for this split because it shows you've thought about the gap.
- Initial and residual risk rating — likelihood × severity before and after controls. A single rating with no "after" column tells the reader nothing about whether your controls work.
- Legislation and guidance references — the specific regulation or HSE guidance each control answers to (CDM 2015, WAHR 2005, COSHH, PUWER, HSG47). This is what separates a competent document from a checklist.
- Responsible person and review date — who owns it and when it gets revisited.
The three mistakes that fail a risk assessment
1. Copy-paste hazards that don't match the job
The fastest way to fail a pre-start audit is a hazard list that clearly came from another job. If your drainage assessment mentions "hot works" and there are no hot works on site, the reviewer stops trusting the whole document.
2. No residual risk, or residual risk that never drops
If every line is "High" before and after controls, your controls aren't controlling anything. If everything magically becomes "Low," you're overclaiming. Honest, proportionate scoring is what competent reviewers reward.
3. Controls with no legal anchor
"Wear PPE" is not a control — it's the last line of the hierarchy. A strong assessment shows you've worked down the hierarchy of control (eliminate, substitute, engineer, administrate, PPE) and cites the regulation behind each step.
Template vs. tool
A blank template hands you the grid and leaves the hard part — knowing what to write — entirely to you. That's fine if you're a safety professional. If you're a contractor trying to get a document out before tomorrow's start, it's the reason risk assessments get rushed, copied, or skipped.
This is exactly why we built RiskCompli. You describe the job in plain English; it drafts the hazards, persons at risk, existing and further controls, risk ratings and the legislation references for your specific trade — then runs 13 quality checks before you export. You still review and sign it as the competent person, but you start from a real draft, not a blank grid.
RiskCompli is a sub-brand of SafeCompli, the UK safety consultancy that spends every week fixing rejected risk assessments for SME contractors. For more free guidance on UK health and safety law, see the SafeCompli Insights library.
