Services A-Z     Pricing

Workplace risk assessments: understanding legal duties under the Management of Health and Safety at Work Regulations 1999

18 August 2025

Ensuring the safety and health of employees is a cornerstone of responsible business practice in the UK. At the heart of this responsibility lies the legal requirement to carry out workplace risk assessments - a duty enshrined in the Management of Health and Safety at Work Regulations 1999 (MHSWR). This article sets out the legal framework surrounding risk assessments, outlines practical steps for compliance, and includes expert insights from Andrew Sanderson of Kingsley Napley and Craig Lydiate of Eighty20 Risk Systems.


The legal framework: what the law requires
 

The MHSWR 1999, made under the Health and Safety at Work etc. Act 1974, places a duty on employers to assess the risks to the health and safety of employees and others affected by their work activities.

Key legal duties include:
 

  • Regulation 3: Requires every employer to make a "suitable and sufficient" assessment of the risks to employees and others.
  • Regulation 5: Requires employers to make appropriate health and safety arrangements based on the outcomes of the risk assessment.
  • Regulation 7: Requires the appointment of competent persons to assist in undertaking protective and preventive measures.
  • Regulation 10: Mandates employers to provide comprehensible and relevant information on risks and preventive measures.

Employers with five or more employees must record the significant findings of their risk assessments and any groups of employees especially at risk (e.g. young workers, pregnant workers, disabled persons).

Hazard identification and control measures
 

Risk assessment is a five-step process that focuses on systematically managing workplace hazards:

  1. Identify hazards: What in your workplace could cause harm?
  2. Decide who might be harmed and how: Employees, contractors, visitors, the public.
  3. Evaluate risks and decide on precautions: What is the likelihood and severity of harm? What control measures are already in place, and what further steps are needed?
  4. Record findings and implement them: If employing five or more people, maintain written documentation.
  5. Review and update regularly: Risk assessments must be reviewed if there is reason to believe they are no longer valid, or if there has been a significant change.

According to Craig Lydiate, Director at Eighty20 Risk Systems, "Too often we see organisations treat risk assessments as a ‘tick-box’ exercise. But the most effective assessments are dynamic—they reflect operational changes, seasonal work patterns, and new technologies. Risk management must be a living process.”

The role of training
 

To be effective, risk assessments require competent persons - those with the necessary training, experience, and knowledge. Training should focus on:

  • Recognising workplace hazards.
  • Applying appropriate control measures.
  • Understanding legal obligations.
  • Documenting and reviewing assessments effectively.

Craig Lydiate adds "Empowering staff through targeted training not only enhances safety but creates a culture where risk awareness is second nature. This is what drives real change on the ground.”

Practical tips for compliance
 

  1. Appoint a competent person: Whether internal or outsourced, ensure that someone with the right level of competence takes charge of the process. 
  2. Use sector-specific templates: While templates are not a substitute for critical thinking, industry-specific formats (such as from the HSE) can guide your approach. Eighty20’s E20 platform helps to design and deliver consistent standards.
  3. Embed risk assessment in planning: Don’t conduct assessments retrospectively. Integrate them into project planning, procurement, and policy development.
  4. Communicate outcomes: Make sure findings are shared with staff through training, briefings, signage, and digital platforms.
  5. Audit and monitor: Schedule regular audits of risk assessments and ensure implementation of control measures.

According to Andrew Sanderson, a health and safety specialist at Kingsley Napley LLP "Legal compliance is not just about avoiding enforcement - it’s about ensuring that risk is proportionately and demonstrably managed. Failure to undertake adequate risk assessments can expose employers to criminal liability, civil claims, and reputational harm.”

Enforcement and penalties
 

The Health and Safety Executive (HSE) and local authorities are responsible for enforcing the MHSWR. They have broad powers to:

  • Enter and inspect premises.
  • Issue Improvement Notices or Prohibition Notices.
  • Prosecute individuals or organisations under the Health and Safety at Work etc. Act 1974.

Penalties for non-compliance include unlimited fines and, in serious cases, imprisonment for responsible persons.

Andrew Sanderson warns "We are increasingly seeing the HSE taking a more assertive approach to enforcement, especially where there is a pattern of neglect or where vulnerable groups are affected. The courts have also shown little leniency for businesses that fail in their risk assessment duties.”

Final thoughts
 

A well-executed risk assessment is not just a legal requirement - it is a vital tool in protecting your workforce, ensuring productivity, and maintaining your organisation’s integrity.

Employers should view the MHSWR not as an administrative burden but as a structured framework to prevent harm before it occurs.

As Craig Lydiate aptly concludes "Good risk assessment isn’t just about compliance - it’s about leadership. It’s about sending the message that people’s safety comes first.”

About the authors

Andrew Sanderson specialises in the transport sector, with particular expertise in road transport matters including Public Inquiries before the Traffic Commissioners and Transport Appeal Tribunal, defending road transport prosecutions in the Magistrates’ and Crown Court, health and safety, corporate manslaughter, and Coroners’ Inquests.

Craig Lydiate is the Managing Director at Eighty20 Risk Systems, a web-based H&S Software supplier, providing our award winning E20 platform to all sectors of the economy, from manufacturing and construction firms to housing groups and charitable bodies.

 


Latest blogs & news

Sanctions regimes: what law firms need to know

During this year’s London International Disputes Week (LIDW), we explored how sanctions regimes are affecting the UK and offshore landscape. 

The "Inequality of Arms" Problem: AI-Assisted Complaints and Representations

One of the more immediate challenges facing regulators is not the use of AI by regulated professionals, but the increasing use of AI-generated advocacy by all participants in the regulatory process.

Press Round-Up: Regulatory and Professional Discipline – May 2026

Here is the Press Round-Up: Regulatory and Professional Discipline – May 2026

The FRC's revised Audit Enforcement Procedure: what the reforms mean for auditors and firms

The Financial Reporting Council (FRC) has now published its final reforms to the Audit Enforcement Procedure (AEP) following its consultation launched last year. With the revised AEP coming into force on 1 July 2026, we look at the new routes to resolution being introduced, how they differ from the FRC’s initial proposals and what this means for auditors and audit firms.

 

Artificial intelligence in regulatory tribunals: key principles from guidance for judicial office holders

Artificial intelligence tools continue to develop at pace, reshaping how legal practice is conducted. These technologies are now being used across the legal landscape - by legal representatives preparing submissions, by self-represented litigants seeking guidance, and increasingly by courts and tribunals seeking to manage caseloads more efficiently.

AI in the Courtroom

In this blog series we have been examining the growing use of Artificial Intelligence (AI) within regulatory investigations and proceedings and the benefits and pitfalls of this emerging technology.

In this blog, we consider how AI is being used in courts and tribunals by both legal representatives and litigants in person. Over the last 12 months, there has been a developing body of judgments handed down where the use of AI has been referenced as creating an issue in the hearing. These cases typically involve written submissions that have been provided to the court, by both legal qualified representatives and by litigants in person. We summarise some of these cases within this blog and reflect on the lessons learnt.

Professional behaviour and the junior accountant: understanding your personal obligations

As a junior accountant, you are likely already comfortable with the core technical principles that support your role. Much of your day‑to‑day work is shaped by financial reporting obligations and the need to comply with accounting standards. These are the expectations most junior accountants encounter early on, and many develop a practical understanding of them as they begin their careers.

Opportunities for Regulators in the Age of AI

The rapid expansion in Artificial Intelligence (AI) capabilities and products has invited individuals and organisations to consider how such capabilities could be harnessed in their professional spheres.

Professional regulatory bodies are engaging with the conversation about the use of AI by their registered members and publishing guidance for their use – for example, recent guidance by the Financial Reporting Council, the General Medical Council and the General Osteopathic Council

However, what role could AI play in the day-to-day aspects of the regulator’s operational activities?

Growing Risks for Regulators in the Age of AI

The rise of Artificial Intelligence (AI) has unlocked extraordinary capabilities across every sector, including in the legal and regulatory sphere. But with that transformation, which is progressing at lightning-quick speed, comes an equally dramatic rise in risks for regulators. Whether overseeing healthcare, education, finance, legal services or other areas of professional standards, regulators are feeling the pressure where the rise in instant-access and quick thinking AI is making it easier than ever for complaints, reports and responses to be generated and submitted. And the pace is only accelerating.

Why getting the burden of proof right is non-negotiable

In a judgment handed down on 13 May 2026, Mrs Justice Collins Rice allowed a nurse's appeal against an NMC fitness to practise decision, finding that serious and pervasive procedural irregularity had rendered the Panel's findings unsafe. The case is a reminder that reaching a conclusion is not enough: the route to that conclusion must itself be legally coherent and demonstrably fair. 

Changes to the ICAS Code of Ethics – what do the changes mean for ICAS members

For many chartered accountants, the ethical obligations that come with membership have traditionally been understood through the lens of financial propriety. The issues that have historically dominated the conversation around professional ethics in the accountancy sector have been conflicts of interest, independence, or objectivity in client work.

World Day for Safety and Health at Work 2026: Psychosocial Risk and the Evolving Workplace

Today is World Day for Safety and Health at Work. The theme for 2026 – "Let's ensure a healthy psychosocial working environment" – offers a valuable opportunity to reflect on the evolving definition of workplace safety and the changing risk landscape facing employers.

Navigating Generative and Agentic AI: The FRC’s Latest Expectations for Auditors

The use of generative and agentic AI in audit is increasing rapidly as accountancy firms seek to improve efficiencies in audit engagements. The development of regulatory guidance has however largely trailed behind the pace of innovation, with little formal guidance on this topic issued since last July when the FRC published its “landmark” guidance on AI in audit. That guidance was an important first step in providing a “coherent approach” to AI deployment, and provided insight into the documentation requirements for AI tool development that the FRC expected to see.  

GDC launches new Fitness to Practise Consultation: Advancing fairness, transparency and professional confidence

On 31 March 2026, the General Dental Council (GDC) unveiled on of its most substantial regulatory reviews in recent years: a 12-week public consultation  aimed at overhauling key element of its Fitness to Practise (FtP) framework. This initiative marks a critical milestone in the regulator’s ongoing commitment to improving fairness, reducing professional fear and reinforcing public trust in dental regulation.

The consultation is open until 18 June 2026 and seeks stakeholder views on proposed updates to guidance of case examiners and its undertakings bank. This is a shift toward a more consistent, transparent and compassionate approach to FtP decision-making.

Press Round-Up: Regulatory and Professional Discipline – March 2026

In this blog, we have provided a press round-up in the Regulatory and Professional Discipline – March 2026

Mazur & others v CILEX & others

The Court of Appeal has now handed down judgment in Julia Mazur & others v CILEX & others [2026] EWCA Civ 369 (the “Judgment”) providing welcome clarity on the conduct of litigation as a reserved legal activity.

Sanctions Guidance is not a score sheet – Court of Appeal findings from GMC v Gilbert & PSA

In a judgment handed down on 6 February 2026, the Court of Appeal (CoA) dismissed appeals by both the General Medical Council (GMC) and the Professional Standards Authority (PSA) to overturn the decision to suspend, rather than erase, a consultant surgeon from the medical register.

The judgment arrives at an interesting moment. In November 2025, the Medical Practitioners Tribunal Service (MPTS) introduced new Sanctions Guidance based on bandings structured around low, medium and high-risk levels, replacing the previous approach that required tribunals to start with the least restrictive sanction. The Court’s findings in Dr Gilbert’s matter should now influence how this guidance is applied.  

Clarity, Consistency, Confidence: HCPC Unveils Key Updates to FTP Decision-Making

On 5 February 2026, the Health and Care Professions Council (HCPC) published an important update outlining significant changes to its Fitness to Practise (FTP) decision-making framework. The HCPC has said that these changes represent a step forward in enhancing consistency, transparency and public protection within the regulatory process.

Press Round-Up: Regulatory and Professional Discipline – January 2026

In this blog, we cover the press round-up in the regulatory and professional discipline – January 2026

The GPhC issues updated inspection decision making framework: what pharmacy teams need to know

On 13 January 2026, the GPhC published an update to its inspection decision‑making framework, marking an important shift in how pharmacy inspections will be conducted and evaluated going forward. This revised framework seeks to strengthen regulatory clarity, incorporate recent legislative developments, and support more consistent, transparent decision‑making across the sector.

Skip to content Home About Us Insights Services Contact Accessibility