Guide · UK HSE · 10 September 2026

Suitable and Sufficient: What the Law Means by Risk Assessment

The UK law does not say “do a risk assessment”; it says “make a suitable and sufficient assessment” — MHSWR 1999, regulation 3. The two words are the standard, and the standard is what the audit and the investigation check. This guide is the suitable and sufficient in working form.

Suitable and Sufficient: What the Law Means by Risk Assessment — HSE guide
The bottom line: Suitable and sufficient is the UK law standard for the risk assessment (the MHSWR 1999, regulation 3). The suitable is the content: the hazard identified, the who decided, the risk evaluated, the control decided, the review planned — the five elements. The sufficient is the quality: the thorough, the up-to-date, the reviewed — the three standards. The assessment that has the five and the three passes the audit and the investigation.

The two words: the standard

The UK law (MHSWR 1999, regulation 3) sets the standard: the suitable and sufficient assessment. The standard is what passes the audit and the investigation — not the length of the document, not the template, the two words.

The suitable is the right thing: the hazard identified, the who decided, the control evaluated. The sufficient is the right depth: the thorough, the up-to-date, the reviewed. An assessment that is suitable but not sufficient is the thin one; an assessment that is sufficient but not suitable is the wrong one. Both fail the audit.

The suitable: the right thing

The suitable is the content, and the content is the five elements. The hazard is identified — the six families, the walk-over, the crew question. The who is decided — the employee, the contractor, the visitor, the vulnerable. The risk is evaluated — the likelihood, the consequence, the matrix, the score. The control is decided — the hierarchy: eliminate, substitute, engineer, manage, PPE. The review is planned — the calendar, the change, the incident.

An assessment that misses an element is not suitable, and the audit is where it shows. An assessment that has the five is the assessment with the right content.

The sufficient: the right depth

The sufficient is the quality, and the quality is the three standards. The thorough: every hazard — the six families, the who, the control, the one not missed. The up-to-date: the change is re-assessed — the new machine, the new product, the new shift. The reviewed: the calendar and the event — the annual, the incident, the change.

An assessment that is thorough but not up-to-date is the old one; an assessment that is up-to-date but not reviewed is the forgotten one. The three standards together are the assessment that is alive.

The assessment that passes

The assessment that passes is the one that is both: the suitable (the content is right) and the sufficient (the quality is right). The audit checks the content — the hazard, the who, the risk, the control, the review — and the quality — the thorough, the up-to-date, the reviewed. The investigation checks the control that is in place and working, and the review that follows the incident.

The suitable and sufficient is the standard, and the standard is what the law is done by. The two words, held together, are the assessment that passes both the audit and the investigation.

Practical use of suitable and sufficient: what the law means by risk assessment in the workplace

Need the sign-off, not just the guide?

The guide is the preparation; the sign-off is the professional. For the ISO 45001 implementation and audits, the RIDDOR and CDM work, the statutory assessments and the training that comes with them, ask Muhammad Umer — 8+ years across Iraq, KSA and Pakistan, and the programme runs through umer-hse.pro. One message gets the written scope.

Common questions

Suitable and Sufficient — answered

What is a suitable and sufficient risk assessment?

The UK law standard (MHSWR 1999, regulation 3). The suitable is the content: the hazard identified, the who decided, the risk evaluated, the control decided, the review planned — the five elements. The sufficient is the quality: the thorough, the up-to-date, the reviewed — the three standards.

What makes a risk assessment suitable?

The content: the hazard is identified (the six families, the walk-over, the crew question), the who is decided (the employee, the contractor, the visitor, the vulnerable), the risk is evaluated (the likelihood, the consequence, the matrix, the score), the control is decided (the hierarchy — eliminate, substitute, engineer, manage, PPE), and the review is planned (the calendar, the change, the incident).

What makes a risk assessment sufficient?

The quality: the thorough (every hazard, none missed), the up-to-date (the change is re-assessed — the new machine, the new product, the new shift), and the reviewed (the calendar and the event — the annual, the incident, the change).

What is the difference between suitable and sufficient?

The suitable is the content — the right thing: the hazard, the who, the risk, the control, the review. The sufficient is the quality — the right depth: the thorough, the up-to-date, the reviewed. Suitable but not sufficient is the thin one; sufficient but not suitable is the wrong one. Both fail the audit.

Is a generic risk assessment suitable and sufficient?

No. The generic is the template from the internet, and the template is not site-specific. The suitable is the site-specific — the content is the right thing for this site. The generic assessment is where the audit fails and the enforcement starts.

What does the MHSWR require for the risk assessment?

The MHSWR 1999, regulation 3: a suitable and sufficient assessment of the risk to the health and safety of the people. The assessment is written where the business has five or more people — the written is the record.

Safety disclaimer

The guides on this site are practical guidance, built to the UK baseline with the US equivalents named in the text. They do not replace a competent person assessment for high-risk work, a statutory assessment, or the advice of your insurer. Where a duty has legal force — the RIDDOR report, the CDM plan, the ISO 45001 system — the responsible person or the responsible owner carries it. Read the guide as the preparation, and take the sign-off from the competent person.