We accept Apple Pay Google Pay & 3 interest-free instalments via Klarna · 0330 124 2165
Health & Safety Consultancy

How to Write a Health and Safety Policy

Five or more employees means the policy has to be written down. The three parts HSE asks for, what belongs in each, the mistakes that make a policy worthless, and how often to review it.

Published 19 August 2024 Updated 20 September 2026 5 min read

If you employ five or more people you must write your health and safety policy down. That is the line HSE draws, and it comes from the Health and Safety at Work etc. Act 1974. Under five and you are not required to put it on paper, though most businesses find it easier to have one anyway, because the first person who asks to see it is usually a client rather than an inspector.

A policy has three parts and nothing else is mandatory: a statement of intent, a list of who is responsible for what, and the arrangements that put it into practice. Everything below is about making those three parts true rather than decorative.

Part 1: the statement of intent

One page. It says what you are committing to and it is signed and dated by the most senior person in the business, because a policy signed by a health and safety consultant tells a reader that the business has outsourced the commitment along with the paperwork.

A statement of intent that works says something specific about this business. A statement that could be pasted onto any company in the country is the commonest failing in the whole document. If yours mentions the actual hazards of your actual work, you are ahead of most.

  • Your general commitment to health and safety, in plain words.
  • The main things you are committing to: assessing risk, consulting employees, providing training, maintaining equipment, reviewing what happens.
  • A signature, a job title and a date. Redate it when you review it.

Part 2: responsibilities

Names, positions and what each of them is actually responsible for. Not a chart of the whole company. The test is whether an employee reading it could work out who to tell about a broken guard, who signs off a risk assessment and who is responsible for first aid cover.

  • Overall responsibility, which is the most senior person and cannot be delegated away.
  • Day to day responsibility, which is usually a named manager.
  • Specific duties: first aid, fire wardens, plant and equipment, contractor control, accident reporting.
  • What every employee is responsible for, which is a short list and should read as a short list.

Update this part when people leave. A policy naming a first aider who left two years ago is the fastest way to tell an inspector the document is not being used.

Auditor and manager reviewing printed procedures and a checklist at an office desk

Part 3: arrangements

This is the long part, and the part that separates a policy that works from a policy that exists. Arrangements describe how the commitment in part one actually happens. Each arrangement should answer three things: what you do, who does it and how often.

Write arrangements only for what applies to you. A joinery shop does not need a page on working at height over water, and padding the document with clauses lifted from a template makes the real arrangements harder to find.

  • Risk assessment. Who carries them out, how they are recorded, when they get reviewed and how findings reach the people doing the work.
  • Training and competence. What each role needs before starting, refresher intervals, and where the records live.
  • Consultation. How employees raise concerns and how they hear back.
  • Accidents and incidents. Reporting, the accident book, investigation, and who decides whether something is reportable under RIDDOR.
  • First aid. Numbers, names, kit locations and how cover is maintained during holidays and shifts.
  • Fire and emergency. Detection, means of escape, wardens, drill frequency, and where people assemble.
  • Equipment and maintenance. Inspection regimes, statutory examinations, and who takes a defective item out of use.
  • Substances. COSHH assessments, storage, and the control measures people are meant to use.
  • Contractors and visitors. Selection, induction, sign in, and who supervises them on your site.
  • Specific hazards. Whatever yours are: manual handling, noise, vibration, work at height, confined spaces, lone working, driving for work.

What goes wrong

Policies fail for a small number of repeated reasons, and none of them are about the wording.

  • It was downloaded, not written. The hazards described are not the hazards present.
  • It names people who have left, or roles that no longer exist.
  • Nobody who has to follow it has read it, because it was never issued or explained.
  • It has not been reviewed since it was created, so it describes a business that has changed.
  • The arrangements describe an ideal rather than what actually happens, which is worse than having no policy, because the gap between the two is evidence.

How often to review it

HSE says review it regularly, without setting a number, because the trigger is change rather than the calendar. Annual is the usual working rhythm, plus a review whenever something moves: new premises, new equipment, new process, a significant incident, a change in the law, or a change in who is responsible. Record the date of each review on the document itself, because the date is the first thing a reader looks at.

Templates, and what they are good for

HSE publishes a free policy template and a worked example on its own website, and they are the two most useful documents you can start from. We point at them rather than offering our own, for a simple reason: a template written by the regulator carries more weight with a reader than one written by a training provider, and it will not quietly commit you to something that does not apply.

Use the template for structure. Do not use anybody’s wording for part three. The arrangements are the part that has to be yours.

Who should write it

Somebody who knows the work. That is usually a manager inside the business rather than a consultant outside it, with the senior person signing it off. A consultant can be genuinely useful for the structure and for spotting what is missing, but a policy written entirely by somebody who has never walked the floor ends up describing a generic workplace.

If nobody in the business has the grounding to write part three, that is a training gap rather than a documentation gap. The qualifications below are the usual routes to closing it.

Where training fits

A short checklist before you sign it

  • Does the statement of intent describe this business, not a business?
  • Is every name in part two still employed and still doing that job?
  • Does every arrangement in part three describe what actually happens this week?
  • Is there an arrangement for each significant hazard, and nothing padding it out that does not apply?
  • Has everyone who has to follow it been given it and walked through it?
  • Is it signed, dated, and is the date recent?
Not sure which

Tell us what the job is

Say what the work involves and who is doing it, and we will say honestly which course or card it needs, including when the answer is that you do not need one.

Real people, quick answers. 0330 124 2165.

Tell us what the job is and who is doing it, and we will point you at the right thing rather than the dearest thing.
Skip to main content