UK Regulatory Framework
Great Britain’s workplace health and safety system is built on a hierarchy of legislation and regulations sitting under one enabling Act. Understanding which rules apply to your organisation — and how they relate to each other — helps you use SteadyOn more effectively.
This page is not legal advice. For specific compliance questions, consult a qualified health and safety advisor or lawyer.
A note on Great Britain and Northern Ireland
Section titled “A note on Great Britain and Northern Ireland”This page (and the pages it links to) describes the health and safety regime for Great Britain — that is, England, Scotland, and Wales. Northern Ireland has its own separate regime: it operates under the Health and Safety at Work (Northern Ireland) Order 1978 and its own regulations, enforced by the Health and Safety Executive for Northern Ireland (HSENI) rather than the HSE. If you operate in Northern Ireland, check the equivalent NI legislation and HSENI guidance.
The regulator in Great Britain is the Health and Safety Executive (HSE) — or, for many lower-risk premises (offices, shops, warehouses, hotels, catering, and similar), your local authority (the council’s environmental health team). The HSE and local authorities split enforcement by the type of premises and activity, not by region. There is no single combined national body: where this documentation says “report to the HSE”, check whether your premises are in fact enforced by your local authority instead.
A few areas of fire safety also differ within Great Britain — Scotland has its own fire-safety regime (see UK Fire Safety).
The legislation at a glance
Section titled “The legislation at a glance”| Legislation | What it covers | Who it applies to |
|---|---|---|
| Health and Safety at Work etc. Act 1974 | General duties of employers, the self-employed, and employees; enforcement | All employers |
| Management Regulations 1999 | Risk assessment, principles of prevention, competent persons, health surveillance | All employers |
| RIDDOR 2013 | Reporting deaths, specified injuries, diseases, and dangerous occurrences to the HSE | All employers and the self-employed |
| First-Aid Regulations 1981 | First-aid needs assessment, equipment, facilities, trained first-aiders | All employers |
| Fire Safety Order 2005 | Responsible person, fire risk assessment, escape routes, drills | Most non-domestic premises |
| UK GDPR & Data Protection Act 2018 | Handling incident data, health records, employee personal data | Most organisations handling personal data |
How the layers fit together
Section titled “How the layers fit together”The Health and Safety at Work etc. Act 1974 (HSWA 1974) is the foundation. It is an enabling Act: it sets the overarching general duties — that every employer must ensure, so far as is reasonably practicable, the health, safety, and welfare of its employees and of others affected by its work — and it gives Government the power to make detailed regulations beneath it.
Below the Act sit the regulations that translate its broad duties into specific requirements. The most significant for most workplaces are:
- Management of Health and Safety at Work Regulations 1999 — the engine room of modern H&S: the duty to carry out a suitable and sufficient risk assessment, the principles of prevention, appointing competent persons, health surveillance, and emergency procedures
- RIDDOR 2013 — when and how to report serious injuries, diseases, and dangerous occurrences to the HSE
- Health and Safety (First-Aid) Regulations 1981 — assessing and providing first aid
- Regulatory Reform (Fire Safety) Order 2005 — the responsible person’s fire-safety duties (with a separate regime in Scotland)
Alongside the regulations sit Approved Codes of Practice (ACOPs) and HSE guidance. An ACOP has a special legal status: if you are prosecuted for a breach and did not follow the relevant ACOP, you must show you complied in some other equally effective way. ACOPs are not regulations in themselves, but courts treat them as the standard expected.
Finally, the UK GDPR and Data Protection Act 2018 apply whenever you collect, store, or use personal data about workers or incident parties — including health data.
How SteadyOn addresses each area
Section titled “How SteadyOn addresses each area”| Area | SteadyOn module |
|---|---|
| Identifying and managing hazards | Hazards |
| Documenting risk controls | Hazards — Control measures field |
| Risk assessments (suitable and sufficient) | Hazards — risk matrix and review dates |
| Emergency procedures (documented) | Documents |
| Incident recording and investigation | Incidents |
| RIDDOR-reportable incident tracking | Incidents — Notifiable flag |
| Worker hazard reporting | Hazards and Incidents (any member can create) |
| Public / contractor incident reporting | The public reporting link |
| Corrective actions and follow-up | Actions |
| Workplace inspections | Inspections |
| First-aid training records | Training Courses + Enrollments (with a First Aider role and a course requirement) |
| Fire warden certification | Training Courses + Enrollments (with a Fire Warden role) |
| Audit trail for due diligence | The Log page + per-entity Log tab |
| Board / director compliance visibility | Dashboard and Reports (incl. Board Report) |
A note on “so far as is reasonably practicable”
Section titled “A note on “so far as is reasonably practicable””HSWA 1974 and most of the regulations beneath it use this phrase extensively. It means you are required to take precautions that a reasonable person in your position, with knowledge of the risks, would take — weighing the likelihood and degree of harm against the time, trouble, and cost of the measures needed to avert it. Where the risk is high, more is expected of you; where the cost of a control is grossly disproportionate to the risk it removes, you may not be required to take it.
SteadyOn’s risk assessment tools (the 5×5 risk matrix, BRAG status, and corrective action priority levels) are designed to help you make and document these judgements consistently. A documented risk assessment is evidence that you considered the risk and made a reasoned decision about how to manage it.
See Risk Assessment for full detail on how the risk matrix works.