Home → Guides → Contractor risk rating methodology: a practical approach for UK buyers
Guides

Contractor risk rating methodology: a practical approach for UK buyers

**A useful contractor risk rating measures the risk of a *specific appointment*, not whether a company is inherently “safe” or “unsafe”.** Start with the work and the site, then assess the contractor's demonstrated capability for that work. Use the outcome to decide which evidence to request, what controls to agree, and how closely to supervise. Re-rate when the scope, people, site or performance changes. A green badge or expired spreadsheet score cannot replace a job-specific judgement.

The Health and Safety Executive's Using contractors guide says the depth of enquiries about competence should match the risk and complexity of the job. It also distinguishes choosing a suitable contractor from agreeing how the work will be managed. This is the organising principle for the method below. It is an editorial framework, not an HSE-prescribed formula or a substitute for the employer's or contractor's legal duties.

What should a contractor risk rating answer?

For a buyer, the question is: What could go wrong if this contractor performs this scope at this site, how capable are they of controlling it, and what assurance must the client provide? That question differs from the contractor's own risk assessment of hazards during the task. The two should connect, but a buyer's supplier score does not approve a particular risk assessment or method statement.

Consider four layers:

  1. Inherent task hazard. What is the potential severity and exposure before the planned controls? Work at height, electrical isolation, excavation, confined spaces, hot work, asbestos disturbance and traffic interaction can require very different assurance. Do not label all maintenance “low risk”.
  2. Site and interface risk. Is the work near the public, live services, patients, food production, occupied offices or other contractors? Does it involve night work, lone work or a shutdown? An otherwise familiar task can become higher risk in a constrained environment.
  3. Contractor capability and evidence. Are the organisation and named people competent for the specific scope? Are supervision, equipment, subcontracting and recent relevant performance credible? HSE describes competence as training, skills, experience and knowledge, plus the ability to apply them safely; the level needed is proportionate to the work.
  4. Residual assurance need. After controls and capability are assessed, what client review, permit, induction, inspection or monitoring is still needed? The answer might be high even for a competent contractor if the work is hazardous or the site interface is sensitive.

Keep those layers visible. Combining them into one mysterious number can conceal a critical failure. A highly competent contractor doing high-hazard work may still need strict controls. Conversely, a low-hazard office visit should not generate a construction-grade evidence burden because the supplier is new.

Step 1: define the appointment before scoring

Write a brief scope statement: work to be done, location, dates, operating conditions, equipment, materials, subcontractors, client contact and dependencies on other teams. Specify whether the assessment applies to a company, a framework agreement, a particular site or one work package. If the scope is vague, the score will be vague.

Identify who is affected: workers, other contractors, employees, visitors, neighbours and the public. HSE's risk-assessment steps ask who might be harmed, how, what controls exist, what more is needed, who owns the action and when it is due. That process informs the buyer's assessment, but the buyer should still obtain the contractor's task-specific controls where appropriate.

For construction, role matters. Under CDM 2015, HSE says a commercial client must make suitable project arrangements and appoint contractors with the relevant skills, knowledge, experience and organisational capability. The client's duties include maintaining and reviewing arrangements during the project. A procurement score alone cannot discharge that role. Identify the principal contractor, principal designer and relevant interface before making a decision.

Step 2: set an inherent risk band

An uncomplicated model uses low, medium and high, supported by written criteria rather than a pseudo-precise decimal. For example:

BandIllustrative situationMinimum review question
LowRoutine low-hazard work in a controlled area with little interactionIs the scope genuinely limited and is basic competence clear?
MediumWork with meaningful plant, access or interface hazards that need planned controlsAre task controls, responsible people and site coordination agreed?
HighA serious-harm potential, complex isolation or multiple interacting partiesWho independently checks the method, authorises the work and monitors critical controls?

These examples are not legal categories. A cleaning visit could be high risk if it involves a hazardous chemical, an occupied healthcare area or work at height. A technically complex job might be low exposure after effective engineering isolation, but the isolation needs evidence. The owner of the method should define bands against the organisation's actual work and test them using past jobs.

If a numerical matrix is useful, score severity and likelihood of the hazardous event under the circumstances separately. Do not assume that multiplying two numbers creates a legally meaningful threshold. HSE describes assessment as considering how likely harm is and how serious it could be, then deciding what further controls are needed. Record the rationale in words. A single “5 out of 5” score without the hazard, exposed people and control owner is a weak audit trail.

Step 3: assess capability against the exact work

Ask for evidence that resolves a decision, rather than a fixed pile of documents. HSE's Using contractors suggests enquiries about management arrangements, competence, supervision, subcontractors, relevant health and safety performance, similar-work assessments, training and required insurance. It also notes that a written health and safety policy and written significant findings of a risk assessment have general five-or-more-employee thresholds; do not use a missing document to infer that a one-person contractor is automatically incapable.

A proportionate capability review can cover:

An SSIP assessment or scheme badge can be useful organisational evidence, but it is not proof that a particular method is safe on a particular site. HSE's CDM guidance recognises third-party assessment as one way to demonstrate organisational capability, not the only way. Record what the assessment covers and what still needs job-specific review.

Step 4: choose an assurance plan, not only a score

The output should specify the next control. A buyer might set one of these review levels:

OutcomePossible assuranceTrigger for escalation
RoutineVerify identity, scope, relevant competence and local rules; confirm a contact and close-outScope or location changes
EnhancedReview task-specific controls, induction, interfaces, supervisor and agreed check pointsA failed control, new subcontractor or simultaneous work
CriticalRequire competent technical review, authorisation/permit where applicable, hold points, active monitoring and a stop-work routeAny material departure from the agreed method

The review level is a policy choice, not a substitute for the underlying risk assessment. A permit is needed only where the work/site control system calls for one; it does not make unsafe work safe. Confirm that the contractor and client both understand who provides welfare, isolates services, coordinates other work and signs off completion. If these responsibilities are unresolved, defer the job rather than papering over the gap with a medium score.

Step 5: record a defensible decision

Keep a concise assessment record with the work package, reviewer, date, evidence checked, inherent band, capability findings, unresolved questions, assurance level, approver, review trigger and decision. If an assessor overrides the usual band or accepts an alternative form of evidence, record why. The decision should be reproducible by a colleague who was not in the meeting.

Consider a short example. A small electrical contractor is asked to replace lighting in an occupied school. The company has relevant experience and current insurance, but the job requires isolation while pupils and staff use adjoining rooms. The buyer records the inherent electrical and occupancy hazards, checks the named electrician's competence, agrees isolation and access boundaries, and sets a site supervisor hold point before re-energising. The contractor's good general history does not downgrade the need for this job-specific control. If work shifts to an unplanned distribution board, the original approval no longer covers the changed scope.

When to re-rate and how to avoid common errors

Re-rate when the scope, site, contractor entity, key personnel, equipment, subcontracting, controls or performance changes materially. A scheduled annual supplier review can be useful for continuing contracts, but a project change can require a same-day decision. Preserve the original rating and the reason for revision; a later green result should not erase an earlier exception.

Avoid three traps. First, do not equate approval with zero risk. Approval is conditional on agreed controls and competent execution. Second, do not create a black-box score. Explain the hazard and evidence behind the category. Third, do not use a generic score to displace client and contractor duties. HSE expects contractors to plan, manage and monitor their work, and clients to make suitable arrangements in applicable construction projects. Risk rating is one input to those duties.

If a digital system stores a named worker's sensitive data or profiles people, assess data protection and access separately. The ICO's employment monitoring guidance discusses high-risk processing and impact assessments. This guide recommends human review of supplier decisions; it does not imply Complys operates automated profiling or makes legal eligibility decisions.

Where Complys fits

The practical value of contractor management software is a consistent place to request evidence, record review decisions, identify expiries and revisit conditions as work changes. Before specifying a workflow, ask Complys to demonstrate the current contractor-management product against your risk bands, reviewer roles and site approval steps. Do not assume a built-in scoring engine, automated legal judgement or third-party accreditation. Link to the verified contractor compliance management software page after the exact route and host are confirmed.

For adjacent tasks, use the existing contractor offboarding owner after work ends and the appropriate incident or corrective-action owner when a failure occurs. Keep this page focused on the method for deciding assurance before and during an appointment.

Source and writer-side QA record

Material claimPrimary sourceBoundary
Depth of contractor competence enquiries should reflect risk and complexityHSE Using contractorsHSE guidance, not a prescribed three-band matrix
Competence includes training, skills, experience, knowledge and applicationHSE What is competence?Task and place of work matter
Construction client appointment and review dutiesHSE commercial clients under CDM 2015Construction and role specific
Risk assessment considers likelihood, severity and controlsHSE steps to manage riskNo statutory score claimed
Independent assessment can support organisational capabilityHSE CDM guidance L153Does not approve job-specific controls

Intent/cannibalisation: Distinct buyer methodology. Do not retitle as generic contractor onboarding, RAMS or offboarding. Search on 6 October 2026 found no exact public Complys guide at this proposed path; repository and canonical-owner check remains a publication gate. Product truth: no built-in risk engine, automated decision or accreditation claim. Links: proposed money and adjacent routes require host/implementation validation. Writer-side disposition: READY.