Why This Question Comes Up on Every Job
Ask a principal contractor for "the RAMS" and you'll get a slightly different answer depending on who you're talking to. Sometimes they mean the risk assessment, sometimes the method statement, sometimes both stapled together. It's a fair mix-up, because RAMS is short for Risk Assessment and Method Statement, two documents that live under one acronym and nearly always get submitted as a pair. RAMS isn't one document. It's two, doing two different jobs.
A risk assessment asks: what could go wrong here, who could get hurt, and what are we doing to stop it? A method statement asks a completely different question: how are we actually going to do this job, step by step, from turning up on site to packing away? Mix the two up, or write one document that tries to do both jobs at once, and you've got one of the most common reasons RAMS get bounced back for revision. They usually travel together, often under one document number with a shared header and version control, but a principal contractor reading them is looking for different things in each one, and if you blur the line between them it shows.
What a Risk Assessment Is Actually For
A risk assessment is the thinking document. Its job is to work out what can go wrong, who's at risk, and what needs to be in place to stop them getting hurt. It's answering "what are the risks here, and how are we controlling them?" This is where you show you've actually thought about the specific hazards of this job, not a generic list, worked out how likely and how serious they are, and put controls in place in the right order.
The structure follows the HSE's five-step approach: spot the hazards, work out who might be harmed and how, weigh up the risk and decide on precautions, write it down, then review it and keep it updated. For each hazard you've spotted, the risk assessment needs to show the hazard itself described properly, not generically, who's at risk, whether that's your own operatives, other trades on site, or members of the public, the initial risk rating before any controls go on, the controls you've applied working through the hierarchy properly, and the residual risk once those controls are in place. That rating is what sets a risk assessment apart from a method statement. It's not just a list of hazards and controls, it's a tool that measures how big each risk actually is on a consistent scale, and shows the controls bring it down to something acceptable. Most UK sites use a 5x5 matrix, likelihood from 1 to 5 multiplied by severity from 1 to 5. Anything scoring 15 or above is high and needs action straight away. 8 to 14 is medium and needs controls in place. Below 8 is generally low. Skip the numbers and a risk assessment is just an opinion. Put them in and it's evidence.
Every hazard also needs to show the hierarchy of controls has actually been worked through in order: eliminate, reduce, isolate, control, then PPE as the last resort. If PPE is the only thing standing between an operative and a serious hazard, that hierarchy hasn't been applied properly, and it's usually the first thing a principal contractor spots. A risk assessment is a legal requirement under the Management of Health and Safety at Work Regulations 1999 for any work that carries a risk to health and safety. CDM 2015 adds to that for construction work specifically: it has to be site-specific, written by someone competent to write it, and reviewed whenever things change on site.
What a Risk Assessment Doesn't Cover
A risk assessment doesn't tell anyone how the work gets done. It won't say "first do this, then do that, then finish with this." There's no step-by-step instruction in it, because that's the method statement's job entirely. A risk assessment that tries to squeeze in a work sequence usually ends up doing a poor job of both, not properly analysing the risk and not giving a usable set of instructions either.
What a Method Statement Is Actually For
A method statement is the planning document, written for whoever's actually doing the work. Its job is to lay out, step by step, how the job gets done safely. It answers "what are we doing, and in what order?" It needs to be specific enough that an experienced tradesperson can pick it up and know exactly what to do at each stage without having to ring you to ask what you meant. "Install the unit," "make safe," "carry out the work" aren't method statement steps. They're headings dressed up as instructions.
Where a risk assessment is built around hazards, one entry per hazard with likelihood, severity, and controls, a method statement is built around the sequence of the job itself. It runs through the work in the order it'll actually happen, and at each step it says what's being done, how it's done, what kit is used, what hazards come up at that particular stage, and what controls apply there. The method statement takes the risk assessment as read and turns its controls into practical steps on site.
A proper method statement covers the scope of the work, what's in and what's out, so there's no argument later about where your job ends. The sequence of work itself, numbered steps from arriving on site right through to demobilising, including how you get to the work area and how you leave it. The plant, tools and equipment, named specifically rather than just "tools." The materials being used, including anything that needs a COSHH assessment. Who's doing the work and what qualifies them, CSCS cards, trade tickets, specialist qualifications for particular kit. Emergency procedures specific to this job, not a generic line about site rules. Environmental controls like dust suppression, noise, and waste management. Quality checks and hold points, what gets inspected, by whom, and what evidence gets produced. And sign-off with a name, a version number, and a date. Of all of these, the sequence of work matters most. Every step needs to be a real instruction, numbered and detailed enough to be checked. "Set up access equipment, carry out works, make good" tells a principal contractor nothing. What access equipment? What works? What does making good actually involve on this job?
What a Method Statement Doesn't Cover
A method statement doesn't analyse risk. It doesn't work out likelihood or severity, and it doesn't apply the hierarchy of controls itself. It assumes that work's already been done in the risk assessment and turns those controls into steps you can follow on site. If a hazard's in the risk assessment but the method statement never says how that control actually gets used in practice, that's a gap, and it's exactly the kind of thing principal contractors are trained to spot. The method statement is where "PPE" from the risk assessment becomes "full face visor, EN 166 rated, worn during all drilling operations."
Why They Always Get Submitted as a Pair
The reason RAMS exists as a combined term is that the two documents need each other to make sense. A risk assessment on its own is a list of hazards and controls with nothing to tie them to the actual job. A method statement on its own is a sequence of steps with no explanation for why the controls in it are there. Put together, they cover what could go wrong, how it's being managed, and how the work actually gets done. When a principal contractor asks for RAMS, they mean both, whether that's two separate documents or one combined file with a risk assessment section and a method statement section under a shared header and version number.
The two documents should cross-refer to each other properly. The risk assessment should point to the method statement for the sequence of work, and the method statement should point back to the risk assessment for the controls behind each hazard. That cross-referencing is what tells a principal contractor these were written together as one piece of planning, rather than bolted together at the last minute. If you want a full breakdown of how the two fit into a single RAMS package, our guide on how to write RAMS for construction work covers that in more detail.
Do You Need a Risk Assessment, a Method Statement, or Both?
The one you can't avoid is the risk assessment. The Management of Health and Safety at Work Regulations 1999 require it for any work activity carrying risk, and the significant findings have to be written down. There's no blanket legal rule that always demands a separate method statement on top, but CDM 2015 arrangements, permits, and principal contractor review processes mean one's expected in practice on most jobs. For routine, low-risk work, a straightforward like-for-like repair with no major hazards and no need to coordinate with other trades, a risk assessment on its own might be enough. Replacing a single socket on an isolated circuit in an empty property is a good example. Limited hazards, simple work, straightforward controls. A principal contractor might accept the risk assessment with just a short note on method.
For most construction work though, you'll need both. The risk assessment covers the hazards and controls, the method statement shows the work's actually been planned in detail. Anything involving several hazards, major plant, access equipment, hazardous substances, or more than one worker on the job should have both documents, and a principal contractor bringing in a sub-contractor will almost always ask for both as standard.
CDM 2015 Notifiable Projects
On notifiable projects under CDM 2015, jobs running longer than 30 working days with more than 20 workers on site at once, or totalling more than 500 person-days, the principal contractor has to make sure contractors submit RAMS before work starts. Both documents are the minimum expectation. Regulation 15 of CDM 2015 requires every contractor to plan, manage, and monitor their own work, which covers carrying out a risk assessment before starting and preparing a method statement for anything beyond straightforward hazards. Work won't be allowed to start until the principal contractor is satisfied with what's been submitted.
The Mistake That Gets Both Documents Sent Back
The most common problem isn't a missing section, it's treating the two documents as separate paperwork that happens to be submitted together, rather than one piece of joined-up planning. Written independently, without checking they agree with each other, the gaps and contradictions that show up are exactly what a reviewer is trained to spot. A RAMS that reads like it was written by two different people at two different times, with nothing linking one document to the other, tells a principal contractor there wasn't much of a planning process behind it, just paperwork being assembled.
The specific version of this mistake worth watching for is listing hazards as if they were steps in the method statement, or writing step-by-step sequences into the risk assessment. It signals whoever wrote the RAMS isn't clear on what each document is for, and a principal contractor reads that as a sign the planning itself might not be up to scratch. A method statement that lists hazards next to each step, without the proper likelihood-times-severity analysis behind them, isn't a risk assessment, no matter how it's laid out. It doesn't give the reviewer the evidence of risk analysis they're actually looking for.
Keeping the Two Documents Consistent
Write the risk assessment first, then keep it open next to you while you write the method statement. Walk through the actual job to spot the hazards, rate each one for likelihood and severity, work through the hierarchy of controls, and calculate the residual risk with the 5x5 matrix. Then write the method statement using that risk assessment as your source, describing the sequence of work step by step and referencing the relevant hazard control at each stage where it applies.
Once both are drafted, check them against each other. Every hazard in the risk assessment should have a matching control described somewhere in the method statement. Every step in the method statement that introduces a hazard should have a corresponding entry back in the risk assessment. And the residual risk ratings should actually line up with what the method statement describes, if the residual risk is meant to be low, the controls in the method statement need to be enough to get it there. That connection is what makes a RAMS look credible rather than templated. A document with hazards that never show up in the method statement, or steps that introduce risks the risk assessment never mentions, reads as paperwork rather than planning, and a principal contractor can usually tell the difference at a glance.
If you'd rather work through the risk rating side properly before you start, our step-by-step risk assessment guide covers the five-step framework in full, and our guide on the hierarchy of controls goes into how to apply it properly rather than jumping straight to PPE.
Draft Both Documents Properly, Without Starting from a Blank Page
RAMS Builder helps you draft the risk assessment and the method statement from a single description of the job, structured so the two documents cross-reference each other the way a principal contractor expects to see. Describe the work in plain English, then review and tailor what comes out before it goes anywhere near a submission. It won't replace your own knowledge of the job, but it takes the blank page away and gives you a proper starting draft for both documents at once.
