Updated 7 October 2026: legal references, supporting evidence and reviewer decisions clarified.
Take a RAMS for erecting a twelve-storey steel frame. It has a scope, a crew of six, a CPCS crane operator, four hazards with a control each, a paragraph of method, and an emergency section that says the first aider will be told and the emergency services called as required. It has no programme. It has no rescue plan for someone left hanging in a harness. It does not mention the temporary bracing design, or who checks it. It does not mention the occupied office building next door, the noise restriction, the lift plan, LOLER, or the lifting permit the site requires.
It is not a bad RAMS because it is short. It is a bad RAMS because the things missing from it are the things that kill steel erectors. And I would bet most people reading this have seen one like it get a signature, because the reviewer was checking that the document existed, was for the right trade, and had a risk assessment attached. All three were true.
That is the gap this article is about. A RAMS review is supposed to be a test. Checking only that the paperwork arrived does not establish whether the work can be carried out safely. I want to set out, in full, what we think a competent review tests, how much each test is worth, and how the result is scored, and I want to publish it in a form you can use on paper on Monday without ever speaking to us. The standard itself is on its own page. This is the argument for it.
What a review is legally for
There is no general statutory requirement for a document with the title "RAMS". The industry uses risk assessments and method statements to help plan safe work and communicate the controls. That does not remove activity-specific written requirements: HSE identifies demolition, dismantling and structural alteration as work whose arrangements must be recorded in writing before it begins.
Regulation 3 of MHSWR 1999 requires a suitable and sufficient risk assessment. Regulation 4 and Schedule 1 set out the general principles of prevention, including avoiding risks, tackling them at source and prioritising collective protection over individual protection.
CDM 2015 adds duties to plan, manage and monitor construction work. Regulation 15 covers contractors' work, including competence, supervision and information. Regulation 13 requires the principal contractor to manage and coordinate the construction phase. A RAMS review can support these duties; the principal contractor's responsibilities continue throughout the work. A signature does not replace checking that the controls are implemented and remain effective.
For building work in England, Building Regulations Part 2A also sets competence and appointment duties. These concern compliance with building regulations, which is distinct from managing construction workplace safety under CDM. The Building Safety Regulator explains both roles and their different competence requirements. A RAMS review is one source of evidence, not a complete assessment of an individual's competence or an organisation's capability.
The current core competence framework is BS 8670-1:2024, developed from BSI Flex 8670. BSI expressly excludes workplace health and safety during construction from its scope. PAS 8671 and PAS 8672 address building-regulations principal designer and principal contractor competence respectively. In Wales, Part 2B duties and competence requirements took effect from 1 July 2026; check the applicable regime and transitional arrangements for the project. Different legislation applies in Northern Ireland.
A useful review records what was checked, the evidence considered, the gaps and how they were resolved. It supports an accountable decision without claiming that a completed checklist proves compliance.
Four parts, twenty tests
So here is what we test. The full standard, with weights and wording, is on the standard page. This is the walk-through.
The review splits into four parts, and the split matters because each part asks a different kind of question.
Part 1 asks whether the risk assessment is real. Two tests, and they are the heaviest in the standard at nine points each. Does every safety-significant step of the method rest on an assessed risk, with the risk assessment and method statement clearly connected rather than stapled side by side? And does the assessment cover the hazards this activity actually presents, on this site, with controls that follow the hierarchy? That second test is where generic RAMS die. A risk assessment that lists "working at height, control: harness" for a twelve-storey frame has identified the category and skipped the work. These two carry the weight they do because the whole review rests on a suitable and sufficient risk assessment. Everything else in the document is built on them.
Part 2 asks whether the method statement says enough. Eleven tests, fifty-six points between them, each asking the same shape of question: is this section present, specific and adequate? Scope stated with locations, boundaries, exclusions and interfaces. Programme with duration, sequence and hours. Resources, competence evidence and equipment named. Task-specific hazards, with competent input where needed and review under the contractor's own arrangements. Controls that follow the hierarchy and are workable: elimination and substitution where practicable, engineering and collective protection, supported by supervision, permits, inspections, briefings and suitable PPE. Emergency arrangements specific to this task and this place. Temporary works coordination, design and checks where the activity involves them. The interface with other trades and the public. Training, induction and cards where applicable. Environmental controls where the activity or project requires them. Monitoring and change control.
The weights inside Part 2 are an argument, not an accident. Controls are worth eight, hazards and emergency arrangements seven each, temporary works six. Programme, environmental and monitoring are three each. That is not a statement that programme does not matter. It is a statement about what kills people when it is missing. A RAMS with no rescue plan is a RAMS under which someone can die in a harness while the site works out what to do. A thin programme may be less serious, but inadequate sequencing or time for safety-critical work can itself create a serious risk. Severity follows the consequences of the particular gap, not just the section heading. The standard is weighted to say so, and every criterion has an evidence basis: emergency arrangements to CDM regulations 30 and 31 and first-aid duties, temporary works to regulation 19 and BS 5975-1:2024 recognised practice, training and induction to regulation 15(7) to (9), the public interface to regulation 13 coordination and section 3 of the 1974 Act.
Part 3 asks whether this RAMS answers the question you actually asked. Six tests, twenty-two points, and a different kind of test from everything before it. Parts 1 and 2 can be judged from the document alone; every criterion from here on is a comparison, and it needs the reviewer to hold the requirement in one hand and the submission in the other. The standard makes that split explicit: a review run without the requirement and organisation rules can assess at most thirteen document-only criteria, and has to say so. This comparison makes the issued requirement part of the review record. When the principal contractor issued the requirement for this activity, it named a risk category, cited the legislation that applies, said whether a permit is needed, referenced any temporary works, described the activity, and recorded a risk level. Part 3 checks each of those against the submission. Does it engage the risk category? Does it reflect each piece of legislation cited, not in general but specifically? Does it reference raising and closing the permit? Does it address the temporary works you referenced, not the ones it chose to mention? Does its scope match the activity described, neither falling short nor overrunning? Are the controls proportionate to the actual risk, taking account of the risk level on the requirement, rather than falling back to a generic baseline?
Part 3 is where the steel-frame RAMS fails hardest, because the requirement said tower crane operations, lifting, LOLER, BS 7121, a lifting permit and a crane foundation, and the submission answered none of it. It is also the part that makes the review site-specific: the PC has to coordinate the work, and this standard uses the requirement as the practical check that the RAMS is the right one for the right activity.
Part 4 asks whether it meets your own rules. One test, four points, for the organisation's own requirements: the client's standards, the framework conditions, the PC's site rules that go beyond the regulations. It only applies if you have issued such rules. If you have not, the criterion is marked as not applicable and comes out of the score entirely, so nobody is marked down for a rule that was never set. And the standard is explicit that the reviewer must not invent organisation rules to fill the gap.
Why it is scored, and how
The obvious objection to scoring a RAMS is that safety is not a percentage. I agree, and that is why the score is designed the way it is.
Every criterion gets a verdict (met, partially met, not met, or does not apply) and a severity (critical, major, minor, or none). The verdict and severity are judgements, made by a reviewer or, in our case, by an AI reviewer working from the document. The score is never a judgement. It is arithmetic over the verdicts. A criterion's deduction is its weight multiplied by how far short it fell (not met counts in full, partially met counts half) multiplied by how much it matters (critical in full, major at six tenths, minor at a quarter). Criteria that do not apply come out of the denominator. Because no deduction can exceed the criterion's own weight, the result sits inside 0 to 100 by construction.
That gives you a number where every point lost is traceable to a named criterion. If a subcontractor challenges a score of 61, the answer is not "the reviewer felt it was about a 61". The answer is a table: criterion 8, emergency arrangements, not met, critical, seven points; criterion 16, permit process, not met, major, 1.8 points; and so on to the total.
Then there are three caps, and the caps are the most important design decision in the standard.
Weighted arithmetic on its own has a flaw. A RAMS that is excellent everywhere and has no rescue plan scores in the high eighties or nineties, because one criterion out of twenty can only take so many points. That is the wrong answer. Where the work depends on a rescue arrangement and none is evidenced, that material gap must determine the outcome. So the standard says: if any criterion is not met at critical severity, the score is capped at 49, the bottom band, whatever else the document does well. If any criterion is partially met at critical severity, the cap is 69. And if any criterion is not met or partially met at major severity, the cap is 89.
A capped score of 49 is not a statement that the work is 49% safe or compliant. Read the findings, the reason for any cap and the scope of the assessment together. Equal scores can represent different hazards and different sets of applicable criteria.
One thing to hold onto when reading the bands: a band describes the document as a whole, never an individual finding. One major finding caps the document at 89, into the band called gaps to close, precisely because the top band is defined by the absence of material gaps.
The last cap exists because of a specific failure we found when testing the arithmetic. A submission with two major findings on low-weight criteria scored 96, which put it in the top band next to a written review that listed material gaps. The top band is defined as "no material gaps; any findings are minor". A major finding contradicts that definition, so a major finding has to put the score below 90, however small the criterion's weight. The arithmetic therefore cannot put a review containing a major finding into the top band.
Two more rules, both about refusing to produce a number. A score built on a partial assessment is not a score: if any criterion has no verdict, the review reports the score as unavailable and names the criteria that were missed. And a score of zero is never used to mean "we could not read the output". Zero is a real score, reserved for a submission that fails every applicable criterion at critical severity. When the review could not be read, the score is null with a reason. The reason that matters is that a silent zero and a real zero look identical on a dashboard, and only one of them should have someone reaching for the phone. This is the same principle as the content gate in the hallucination article: an assessment of nothing must be impossible.
The steel frame, scored
Run the RAMS from the opening through the standard. Scope stated: met. Risk assessment generic: partially met, major. No programme: not met, major. No competence evidence: partially met, major. Hazard register generic, structural instability during erection unaddressed: not met, critical. No briefings: partially met, major. No rescue plan: not met, critical. No temporary works design, no TWC: not met, critical. Adjacent occupied building unaddressed: not met, major. No environmental controls: not met, major. Monitoring thin: partially met, minor. Lifting risk category unaddressed: not met, critical. LOLER and BS 7121 unaddressed: not met, critical. Permit not referenced: not met, major. Crane foundation temporary works partly addressed: partially met, major. Scope broadly matches: partially met, minor. Controls not proportionate to a high risk level: not met, major. No organisation rules supplied: does not apply.
The deductions come to 47.2 points against 96 applicable, which is 50.9 out of 100 before caps. Then five criteria failed at critical severity, so the cap bites: 49. Bottom band: serious gaps. Back to the subcontractor.
Look at what the arithmetic did and did not do there. It did not decide the RAMS had to go back; the five critical verdicts did that, and they are each defensible on their own. What the arithmetic did was make the result reproducible. Two reviewers with the same verdicts get the same number. And when the subcontractor's revision comes back with a TWC appointed, a rescue plan, a lift plan and the adjacent building addressed, the same twenty tests show exactly which points came back.
Supporting documents and the acceptance decision
A RAMS may refer to a lift plan, rescue plan, survey or COSHH assessment without supplying it. That is a limitation in the evidence available for review. It does not establish that the arrangement does not exist, and the reference alone does not establish that it is adequate.
The review should distinguish documents assessed, references not supplied and supplied files that could not be read. A missing safety-critical document should identify the affected finding and what needs checking. If the reviewer has checked it elsewhere, record its identity and revision, where it is held and how it resolves the finding. Otherwise, obtain the evidence or revise the proposed work before the affected activity proceeds.
Inside PlanOps, acceptance is the reviewer's recorded decision on the RAMS for the work and site. The reviewer should explain how material findings were resolved: corrected in a revision, answered by further evidence, or disputed with a reason specific to this work. A reason for accepting is not automatically a reason to mark the underlying criterion as not applicable. Preserve the original AI assessment alongside the human decision and any later assessment.
Acceptance does not replace a required permit, briefing, site check or continuing supervision. Nor does it transfer the contractor's responsibilities to the person pressing Accept. The practical purpose is a decision supported by evidence that people can understand and act on.
The two scope tests
Someone will notice that scope appears twice, as criterion 3 in Part 2 and criterion 18 in Part 3, and will reasonably ask whether that is a double count. It was, nearly, in the first version. Up to v1.0.0 the two were worded so similarly that a scope mismatch could be penalised twice. In v1.1.0 we reworded them rather than merging them, because they test different things and the remedies are different.
Criterion 3 asks the Part 2 question: does the method statement state a scope at all, with locations, boundaries, exclusions and interfaces, specifically enough that the rest of the document can be audited against it? A vague scope means rewrite the method statement. Criterion 18 asks the Part 3 question: does that scope conform to the activity the requirement describes? A mismatched scope means you have been sent the wrong RAMS for this work. Most audit checklists separate contents from conformity for the same reason, and the published wording now says explicitly which test each one is and which it is not.
I mention it because a standard that has been argued over is worth more than one that has not, and because if you adopt this on paper, that is the line your own reviewers will ask about first.
What this standard does not do
It does not test whether the controls will work on the day. A RAMS can pass all twenty tests and be ignored by the gang at seven on Monday morning. That is supervision and monitoring, criterion 13 only tells you whether the document describes it.
It does not replace judgement on severity. Whether a missing briefing is major or minor on this job is a call, and the standard gives the reviewer the arithmetic to make that call count, not a rule that makes it for them. Reviewers should explain severity against the foreseeable consequences and available evidence. Differences should be resolved through competent review, rather than treating seniority as a reason for a different score.
It is not a legal opinion. The evidence basis on the standard page says why each criterion matters. It may point to a legal duty, recognised guidance or good practice, or a project or contract requirement. It does not say that passing the test discharges the duty. That is for you, your advisers and, in the worst case, a court.
And it is not a British Standard. It is a published review standard, version-controlled and open, offered for adoption and for criticism. We will change it when someone shows us it is wrong, and the changelog will say who did.
Adopt it, then, if you want, automate it
The standard page carries the twenty criteria with their weights, the evidence basis for each, the verdict and severity factors, the caps, the bands and the refusal rules, plus the worked example above. There is a two-page checklist you can print. It is licensed for free use with attribution. If your reviewers use it on paper and never buy anything from us, it has done its job: there will be one more site where the RAMS review is a test and not a receipt.
There is also a free version of the review you can run right now at ramsreview.co.uk: upload a RAMS, no account, and it is considered against the thirteen document-only criteria in Parts 1 and 2 of this standard, with the applicable subset stated. It cannot run Parts 3 and 4, because those compare the submission with the requirement you issued and your own rules, and a public page has neither. The result must identify that limited scope. Within a project review, an existing requirement with blank fields is handled under the standard's per-criterion rules; it is different from having no requirement at all.
Inside PlanOps, where the requirement and your organisation rules exist on the project, all twenty criteria are considered on each RAMS that arrives. Any the work does not engage are recorded as not applicable with the reason stated, every verdict is written into the report, every point is traceable to its criterion, and the AI is never asked for a number. The plain-English tour of how that fits into the rest of the job is at planops.ai/workflows.
Either way, the question to ask of any RAMS review, whoever does it, is the same. What did it test? If the answer is a list, you have a review. If the answer is a signature, you have a receipt.
We write about what we are learning building AI for UK construction, the failures included, in the Construction AI Brief. If this was useful, you can get it monthly.
Ian Yeo is the founder of PlanOps, an AI-native planning operations platform for UK construction.
Read next: How we stop AI making things up and Why can't we just use a chatbot?
