Compliance
What Is a RAMS? Risk Assessment Method Statements

A risk assessment method statement (RAMS) pairs the hazards of a job with the steps to do it safely. Here is what a RAMS is, when it's required, who writes one, and what to put in it.
Ask a contractor for their paperwork before they start work on your site and, more often than not, the answer comes back as one word: RAMS. It is one of those terms that gets used constantly in construction, facilities and maintenance, and rarely explained. If you manage buildings or bring contractors on site, it helps to know exactly what a RAMS is, when you can ask for one, and what a good one looks like.
What is a RAMS?
A RAMS is a single document that combines a risk assessment with a method statement for a specific piece of work. The risk assessment identifies what could cause harm during the job and how likely it is; the method statement sets out, step by step, how the work will be carried out safely. Put them together and you get a practical brief that tells everyone involved what the hazards are and exactly how the task will be managed from start to finish.
It is used most heavily for higher-risk or non-routine work: working at height, hot works, confined spaces, demolition, electrical isolation, lifting operations and similar tasks. A RAMS is not a legal document type in its own right; it is the industry's shorthand for two legal duties, assessing risk and planning safe work, packaged into one readable file.
What does RAMS stand for, and how does a risk assessment differ from a method statement?
RAMS stands for Risk Assessment Method Statement (sometimes written as Risk Assessment and Method Statement). The two halves answer different questions, which is why they are usually produced together but should never be confused.
A risk assessment answers "what could go wrong, and how bad could it be?" It lists the hazards of the task, who might be harmed, the likelihood and severity, and the controls that reduce the risk to an acceptable level. A method statement answers "how, precisely, will this job be done?" It describes the sequence of work, the equipment and materials used, the people involved, and the safety measures applied at each stage.
The relationship is straightforward: the risk assessment identifies the controls, and the method statement shows those controls being applied in practice. A method statement without an underlying assessment is just a plan; a risk assessment with no method statement leaves the safe system of work undefined. A RAMS ties the two so the controls you promised on paper actually appear in the way the work is done.
When is a RAMS required?
What the law actually requires is that you assess significant risks and plan work so it can be carried out safely. There is no single regulation that says "produce a RAMS", and a RAMS or method statement is not mandated by name for work in general. A written RAMS is simply the proportionate way most contractor, construction, high-risk and client-controlled work meets those two duties in one document, which is why it is so commonly expected on commercial and construction sites even though it is not a legal requirement in its own right.
Under the Management of Health and Safety at Work Regulations 1999, every employer must carry out a suitable and sufficient risk assessment, and record the significant findings if they employ five or more people. For construction work, the Construction (Design and Management) Regulations 2015 (CDM 2015) require contractors to plan, manage and monitor work so it is carried out safely, which for anything non-trivial usually means a written method statement backed by an assessment. Principal contractors also produce a construction phase plan, and individual RAMS feed into it.
In day-to-day terms, you should expect a RAMS when: the work is high-risk (height, hot works, confined spaces, asbestos-adjacent tasks, heavy lifting); a contractor or sub-contractor is carrying out the work on your premises; a client, principal contractor or insurer asks for one as a condition of access; or the task is complex enough that "everyone knows how to do it" is not a safe assumption. Lower-risk, routine tasks may only need a standard risk assessment rather than a full RAMS. The test is proportionality, not paperwork for its own sake.
Who is responsible for writing a RAMS?
The organisation carrying out the work is responsible for writing the RAMS, which usually means the contractor or their employer, not the client whose site they are visiting. Whoever controls how the task is done owns the method, so they are best placed to describe it and to assess its risks.
That does not let the client off the hook. If you are the duty holder for a site, you are responsible for checking that any RAMS you receive is relevant to the actual job, current, and specific to your premises rather than a generic template with the wrong site name on it. On construction projects, the principal contractor coordinates and reviews the RAMS submitted by each contractor and makes sure they fit together, so one trade's method does not create a hazard for another.
A RAMS should be written, or at least signed off, by someone competent: a person with the knowledge, training and experience to understand the hazards and specify realistic controls. It should then be briefed to everyone doing the work, and they should sign to confirm they have read and understood it. A document nobody on the tools has seen is not a safe system of work.
What should a RAMS include?
A good RAMS includes enough detail for someone unfamiliar with the job to understand the hazards and follow the safe method. Use this as a checklist:
- Project and site details: the client, the address, the specific location on site, and the dates the work covers.
- Task description: a clear scope of exactly what work is and is not included.
- The risk assessment: hazards identified, who might be harmed, likelihood and severity, existing controls, and any further controls needed, with residual risk after controls.
- The method statement: the sequence of work, step by step, in the order it will actually happen.
- People and responsibilities: who is doing the work, who is supervising, and named competent persons for specialist tasks.
- Plant, equipment and materials: what is being used, including inspection or certification status where relevant.
- Control measures: the personal protective equipment (PPE), permits to work, isolations, exclusion zones and any other safeguards.
- Emergency arrangements: first aid, fire and rescue provisions, and what to do if something goes wrong, including any confined-space or rescue plan.
- Welfare and environmental considerations: where relevant to the task and site.
- Sign-off: the author, the review date, and space for the operatives to confirm they have been briefed.
If the work involves hazardous substances, the RAMS should reference the relevant COSHH assessment rather than duplicate it. Knowing what is on site and how it is controlled is a job in itself, as we covered in COSHH compliance starts with knowing what you've got on site.
Many teams work from a RAMS template to make sure nothing on that list is missed. A template is a useful backbone, but a RAMS is only valid when it is genuinely specific to the task and site in front of you, not a generic form with the address swapped. Use a template for structure, then do the real thinking for the actual job.
RAMS example: how to structure one
The clearest way to structure a RAMS is to run the two halves in order: assess the risks first, then describe the method that controls them. Take a simple example, replacing a rooftop extract fan on a commercial building.
The risk assessment section would identify working at height, manual handling of the unit, electrical isolation, and dropped objects; note that operatives, other trades and people below could be harmed; and set controls such as edge protection, a mobile access platform, a safe isolation procedure and an exclusion zone at ground level. The method statement section would then walk through the job in sequence: isolate and prove dead, set up the exclusion zone, position the access equipment, disconnect and lower the old unit, lift and fix the replacement, reconnect, test, and remove equipment. Each step names the controls from the assessment as they apply.
Structured this way, anyone reading it can see not just what will be done, but why each precaution is there. That connection between the identified risk assessments and the practical steps is what separates a genuine safe system of work from a form filled in to get through the gate. On sites where contractor work is constant, such as construction and facilities, keeping that link intact across dozens of jobs is the real challenge.
Keeping RAMS current
The hardest part of RAMS is not writing one; it is keeping the right version live, briefed and evidenced as jobs, people and sites change. A RAMS approved three months ago for a slightly different task, or briefed to a crew who have since been swapped out, quietly stops being a safe system of work even though the paperwork still exists.
This is where a live approach beats a folder of PDFs. Purpose-built risk assessment software keeps each assessment and method statement tied to the work, the people and the location, so reviews are prompted before they lapse, sign-offs are recorded, and the current version is the one people actually see on site. The document stops being a snapshot from access day and becomes something you can rely on for as long as the work is going on.
Keep reading
Get the next article before everyone else
Join the weekly brief for new posts, product updates, and guides you can use on site straight away.
- New posts
- Product Updates
- Practical guides
We care about your data. Read our privacy policy.