Contractor risk rating methodology: a practical approach for UK buyers
**A useful contractor risk rating measures the risk of a *specific appointment*, not whether a company is inherently “safe” or “unsafe”.** Start with the work and the site, then assess the contractor's demonstrated capability for that work. Use the outcome to decide which evidence to request, what controls to agree, and how closely to supervise. Re-rate when the scope, people, site or performance changes. A green badge or expired spreadsheet score cannot replace a job-specific judgement.
The Health and Safety Executive's Using contractors guide says the depth of enquiries about competence should match the risk and complexity of the job. It also distinguishes choosing a suitable contractor from agreeing how the work will be managed. This is the organising principle for the method below. It is an editorial framework, not an HSE-prescribed formula or a substitute for the employer's or contractor's legal duties.
What should a contractor risk rating answer?
For a buyer, the question is: What could go wrong if this contractor performs this scope at this site, how capable are they of controlling it, and what assurance must the client provide? That question differs from the contractor's own risk assessment of hazards during the task. The two should connect, but a buyer's supplier score does not approve a particular risk assessment or method statement.
Consider four layers:
- Inherent task hazard. What is the potential severity and exposure before the planned controls? Work at height, electrical isolation, excavation, confined spaces, hot work, asbestos disturbance and traffic interaction can require very different assurance. Do not label all maintenance “low risk”.
- Site and interface risk. Is the work near the public, live services, patients, food production, occupied offices or other contractors? Does it involve night work, lone work or a shutdown? An otherwise familiar task can become higher risk in a constrained environment.
- Contractor capability and evidence. Are the organisation and named people competent for the specific scope? Are supervision, equipment, subcontracting and recent relevant performance credible? HSE describes competence as training, skills, experience and knowledge, plus the ability to apply them safely; the level needed is proportionate to the work.
- Residual assurance need. After controls and capability are assessed, what client review, permit, induction, inspection or monitoring is still needed? The answer might be high even for a competent contractor if the work is hazardous or the site interface is sensitive.
Keep those layers visible. Combining them into one mysterious number can conceal a critical failure. A highly competent contractor doing high-hazard work may still need strict controls. Conversely, a low-hazard office visit should not generate a construction-grade evidence burden because the supplier is new.
Step 1: define the appointment before scoring
Write a brief scope statement: work to be done, location, dates, operating conditions, equipment, materials, subcontractors, client contact and dependencies on other teams. Specify whether the assessment applies to a company, a framework agreement, a particular site or one work package. If the scope is vague, the score will be vague.
Identify who is affected: workers, other contractors, employees, visitors, neighbours and the public. HSE's risk-assessment steps ask who might be harmed, how, what controls exist, what more is needed, who owns the action and when it is due. That process informs the buyer's assessment, but the buyer should still obtain the contractor's task-specific controls where appropriate.
For construction, role matters. Under CDM 2015, HSE says a commercial client must make suitable project arrangements and appoint contractors with the relevant skills, knowledge, experience and organisational capability. The client's duties include maintaining and reviewing arrangements during the project. A procurement score alone cannot discharge that role. Identify the principal contractor, principal designer and relevant interface before making a decision.
Step 2: set an inherent risk band
An uncomplicated model uses low, medium and high, supported by written criteria rather than a pseudo-precise decimal. For example:
| Band | Illustrative situation | Minimum review question |
|---|---|---|
| Low | Routine low-hazard work in a controlled area with little interaction | Is the scope genuinely limited and is basic competence clear? |
| Medium | Work with meaningful plant, access or interface hazards that need planned controls | Are task controls, responsible people and site coordination agreed? |
| High | A serious-harm potential, complex isolation or multiple interacting parties | Who independently checks the method, authorises the work and monitors critical controls? |
These examples are not legal categories. A cleaning visit could be high risk if it involves a hazardous chemical, an occupied healthcare area or work at height. A technically complex job might be low exposure after effective engineering isolation, but the isolation needs evidence. The owner of the method should define bands against the organisation's actual work and test them using past jobs.
If a numerical matrix is useful, score severity and likelihood of the hazardous event under the circumstances separately. Do not assume that multiplying two numbers creates a legally meaningful threshold. HSE describes assessment as considering how likely harm is and how serious it could be, then deciding what further controls are needed. Record the rationale in words. A single “5 out of 5” score without the hazard, exposed people and control owner is a weak audit trail.
Step 3: assess capability against the exact work
Ask for evidence that resolves a decision, rather than a fixed pile of documents. HSE's Using contractors suggests enquiries about management arrangements, competence, supervision, subcontractors, relevant health and safety performance, similar-work assessments, training and required insurance. It also notes that a written health and safety policy and written significant findings of a risk assessment have general five-or-more-employee thresholds; do not use a missing document to infer that a one-person contractor is automatically incapable.
A proportionate capability review can cover:
- Relevant experience: comparable jobs, environments and complexity, with a reference or completion evidence where justified.
- Named people: qualifications, authorisations and current competence for the equipment or regulated activity. A company certificate does not prove every person on site is authorised.
- Planning: a method that fits this work and site, not a generic RAMS file with another client's name.
- Supervision and subcontracting: who directs the job, who approves a change, and whether subcontractors are within the assessed scope.
- Plant and controls: inspection, maintenance, calibration, isolation and emergency arrangements where relevant.
- Recent performance: open corrective actions, repeated failures and evidence of learning, considered fairly and in context. An incident count alone can penalise honest reporting.
- Insurance and contract requirements: confirm policy type, activity scope, dates and buyer-specified limits where relevant. Do not invent a universal statutory public-liability minimum.
An SSIP assessment or scheme badge can be useful organisational evidence, but it is not proof that a particular method is safe on a particular site. HSE's CDM guidance recognises third-party assessment as one way to demonstrate organisational capability, not the only way. Record what the assessment covers and what still needs job-specific review.
Step 4: choose an assurance plan, not only a score
The output should specify the next control. A buyer might set one of these review levels:
| Outcome | Possible assurance | Trigger for escalation |
|---|---|---|
| Routine | Verify identity, scope, relevant competence and local rules; confirm a contact and close-out | Scope or location changes |
| Enhanced | Review task-specific controls, induction, interfaces, supervisor and agreed check points | A failed control, new subcontractor or simultaneous work |
| Critical | Require competent technical review, authorisation/permit where applicable, hold points, active monitoring and a stop-work route | Any material departure from the agreed method |
The review level is a policy choice, not a substitute for the underlying risk assessment. A permit is needed only where the work/site control system calls for one; it does not make unsafe work safe. Confirm that the contractor and client both understand who provides welfare, isolates services, coordinates other work and signs off completion. If these responsibilities are unresolved, defer the job rather than papering over the gap with a medium score.
Step 5: record a defensible decision
Keep a concise assessment record with the work package, reviewer, date, evidence checked, inherent band, capability findings, unresolved questions, assurance level, approver, review trigger and decision. If an assessor overrides the usual band or accepts an alternative form of evidence, record why. The decision should be reproducible by a colleague who was not in the meeting.
Consider a short example. A small electrical contractor is asked to replace lighting in an occupied school. The company has relevant experience and current insurance, but the job requires isolation while pupils and staff use adjoining rooms. The buyer records the inherent electrical and occupancy hazards, checks the named electrician's competence, agrees isolation and access boundaries, and sets a site supervisor hold point before re-energising. The contractor's good general history does not downgrade the need for this job-specific control. If work shifts to an unplanned distribution board, the original approval no longer covers the changed scope.
When to re-rate and how to avoid common errors
Re-rate when the scope, site, contractor entity, key personnel, equipment, subcontracting, controls or performance changes materially. A scheduled annual supplier review can be useful for continuing contracts, but a project change can require a same-day decision. Preserve the original rating and the reason for revision; a later green result should not erase an earlier exception.
Avoid three traps. First, do not equate approval with zero risk. Approval is conditional on agreed controls and competent execution. Second, do not create a black-box score. Explain the hazard and evidence behind the category. Third, do not use a generic score to displace client and contractor duties. HSE expects contractors to plan, manage and monitor their work, and clients to make suitable arrangements in applicable construction projects. Risk rating is one input to those duties.
If a digital system stores a named worker's sensitive data or profiles people, assess data protection and access separately. The ICO's employment monitoring guidance discusses high-risk processing and impact assessments. This guide recommends human review of supplier decisions; it does not imply Complys operates automated profiling or makes legal eligibility decisions.
Where Complys fits
The practical value of contractor management software is a consistent place to request evidence, record review decisions, identify expiries and revisit conditions as work changes. Before specifying a workflow, ask Complys to demonstrate the current contractor-management product against your risk bands, reviewer roles and site approval steps. Do not assume a built-in scoring engine, automated legal judgement or third-party accreditation. Link to the verified contractor compliance management software page after the exact route and host are confirmed.
For adjacent tasks, use the existing contractor offboarding owner after work ends and the appropriate incident or corrective-action owner when a failure occurs. Keep this page focused on the method for deciding assurance before and during an appointment.
Source and writer-side QA record
| Material claim | Primary source | Boundary |
|---|---|---|
| Depth of contractor competence enquiries should reflect risk and complexity | HSE Using contractors | HSE guidance, not a prescribed three-band matrix |
| Competence includes training, skills, experience, knowledge and application | HSE What is competence? | Task and place of work matter |
| Construction client appointment and review duties | HSE commercial clients under CDM 2015 | Construction and role specific |
| Risk assessment considers likelihood, severity and controls | HSE steps to manage risk | No statutory score claimed |
| Independent assessment can support organisational capability | HSE CDM guidance L153 | Does not approve job-specific controls |
Intent/cannibalisation: Distinct buyer methodology. Do not retitle as generic contractor onboarding, RAMS or offboarding. Search on 6 October 2026 found no exact public Complys guide at this proposed path; repository and canonical-owner check remains a publication gate. Product truth: no built-in risk engine, automated decision or accreditation claim. Links: proposed money and adjacent routes require host/implementation validation. Writer-side disposition: READY.