
Risk Assessment vs Method Statement (RAMS): What’s the Difference?
A risk assessment identifies what could cause harm and how likely it is. A method statement sets out, step by step, how the work will actually be done safely. The first is about the hazards; the second is about the method. Together they are usually called RAMS.
If you have ever been asked for "your RAMS" before starting on site and wondered whether that meant one document or two, you are in good company. The two are related, frequently bundled, and routinely confused — including by people who produce them every week. The distinction matters, because only one of them is explicitly required by law.
Risk assessment vs method statement at a glance
| Risk assessment | Method statement | |
|---|---|---|
| Question it answers | What could go wrong, and how bad could it be? | How exactly will we carry out this task safely? |
| Focus | Hazards, who might be harmed, likelihood and severity, control measures | Sequence of work, equipment, people, permits, emergency arrangements |
| Legal status (UK) | Explicitly required by the Management of Health and Safety at Work Regulations 1999 | Not named in legislation, but the practical way of demonstrating a safe system of work |
| Typical format | Matrix or table scoring each hazard before and after controls | Numbered, chronological narrative of the job |
| Audience | Assessors, managers, auditors, enforcing authorities | The crew doing the work, and the client or principal contractor |
| Comes first? | Yes — it informs the method | No — it is written around the controls the assessment identified |
What is a risk assessment?
A risk assessment is a systematic examination of what, in your work, could cause harm to people — so you can weigh up whether you have taken enough precautions or should do more.
In Great Britain the duty comes from regulation 3 of the Management of Health and Safety at Work Regulations 1999, which requires every employer to make a "suitable and sufficient" assessment of the risks to employees and to anyone else affected by the work. If you employ five or more people, you must record the significant findings.
The HSE's familiar five steps still describe the process well: identify the hazards, decide who might be harmed and how, evaluate the risks and decide on precautions, record your findings and implement them, then review and update. Most organisations score each hazard on a matrix — commonly 5x5 — both before and after controls are applied, which makes it obvious where the residual risk is still unacceptable.
Crucially, a risk assessment does not tell anyone how to do the job. It tells you what you are up against.
What is a method statement?
A method statement is a written description of how a specific task will be carried out safely, from start to finish. It takes the control measures your risk assessment identified and turns them into practical instructions the crew can follow.
A useful method statement usually covers the scope of work and location, the sequence of operations in order, the plant, tools and materials involved, who is doing what and what competence or training they need, the PPE required, any permits such as hot works or confined space entry, arrangements for others affected nearby, and what to do in an emergency.
No UK regulation says "you must produce a method statement" in those words. What the law requires is a safe system of work — under the Health and Safety at Work etc. Act 1974 and, on construction projects, the Construction (Design and Management) Regulations 2015. The method statement is simply how that safe system is written down and communicated. That is why principal contractors ask for one before letting you on site.
So what does RAMS mean?
RAMS stands for Risk Assessment and Method Statement — the two documents supplied together as a package. It is a convention of practice rather than a legal term. When a client asks for RAMS, they want to see both that you understand the hazards and that you have a credible plan for controlling them.
Read in that order, the pair tells a complete story: here is what could hurt someone, and here is exactly how we will stop it happening.
Is a method statement the same as an SOP?
Not quite, though the two overlap. SOP stands for Standard Operating Procedure: a repeatable instruction for a routine activity, often written primarily for quality, consistency or efficiency, and typically reused unchanged across many jobs.
A method statement is narrower and more situational. It is written for a particular task in a particular place at a particular time, and it exists specifically to control the risks that task presents. Replacing a pump in your own workshop might be covered by an SOP; replacing the same pump nine metres up on a live site with other trades working below needs a method statement.
In practice many organisations keep a library of SOPs and adapt them into task-specific method statements when the setting demands it.
Do you always need both?
You always need the risk assessment. It is a legal duty, and it applies to every employer regardless of sector or size.
You need a method statement when the work is complex, high risk, non-routine, or carried out somewhere you do not control. In practical terms, produce one when the task involves work at height, confined spaces, hot works, excavation, lifting operations, live electrical work, asbestos, or demolition — and whenever a client or principal contractor asks for RAMS as a condition of access.
Straightforward, low-risk, familiar work is usually adequately covered by the risk assessment alone. Writing a method statement for changing a lightbulb helps nobody, and the paperwork nobody reads is a genuine hazard in itself.
Four mistakes worth avoiding
- Writing the method statement first. If the method was not derived from the assessed risks, the controls in it are guesswork.
- Generic copy-paste. A template with the site name changed will not survive contact with an inspector, or with the actual site.
- Never reviewing them. Both documents should be revisited when the work, the people, the equipment or the location changes — not filed and forgotten.
- Leaving them in a drawer. A method statement the crew has not read and signed is not a safe system of work; it is a document about one.
Managing RAMS without the paperwork spiral
The administrative burden is what breaks most RAMS processes. Assessments live in one folder and method statements in another, versions diverge, and nobody can prove who signed what.
LifeSafety.ai keeps them linked. Risk assessments are built on a 5x5 matrix with a hazard library and automatic review reminders, and method statements are generated from the controls those assessments identify — so the method always reflects the current assessment. Crews acknowledge them on mobile, and every version and signature is timestamped for when a client or the HSE asks.
If your work involves permits, the same records feed straight into permit to work, so the permit, the assessment and the method all reference one another.
Frequently asked questions
Which comes first, the risk assessment or the method statement?
The risk assessment. It identifies the hazards and the control measures, and the method statement then describes how those controls will be applied in practice. Writing them the other way round produces a method built on assumptions rather than assessed risk.
Are method statements a legal requirement in the UK?
Not by name. UK law requires employers to provide a safe system of work, and on construction projects CDM 2015 requires the work to be planned and managed. A method statement is the accepted way of documenting that, which is why clients and principal contractors treat it as mandatory even though the words do not appear in the regulations.
Who should write a method statement?
Someone competent in the work being described — usually the contractor, supervisor or manager responsible for delivering the task, supported by whoever carried out the risk assessment. Competence here means practical knowledge of the job, not just a safety qualification.
How often should RAMS be reviewed?
Whenever something material changes: the method, the equipment, the people, the location or the conditions. Many organisations also set a fixed review period, commonly annually, and always review after an incident or near miss involving the task.
Does a risk assessment have to be written down?
If you employ five or more people, yes — you must record the significant findings. Smaller employers still have to carry out the assessment; they simply are not obliged to record it. Recording it anyway is sensible, because an assessment you cannot produce is very hard to evidence.
Can one method statement cover several tasks?
It can cover a sequence of closely related operations within the same job, but a single document stretched across genuinely different tasks becomes too generic to be useful. If the hazards differ materially, write separate statements.
The short version
The risk assessment is your analysis; the method statement is your plan. One is a legal duty in its own right, the other is how you prove the work will be done safely. Get the assessment right first, build the method from it, keep both current — and make sure the people doing the work have actually read them.
Related Articles

Employee incident report form: RIDDOR-ready template for safety managers
Ensure workplace safety with our RIDDOR-ready employee incident report form. Download the template and streamline your incident reporting today!

OSHA regulations explained for UK safety managers
Learn how OSHA regulations differ from UK safety laws. Discover essential actions for compliance and protect your workplace effectively.

Compliance monitoring examples for safety professionals
Discover practical compliance monitoring examples to enhance safety, protect workers, and ensure regulatory compliance in your organization.