All Blog Posts

Is Your Health and Safety Policy Out of Date? 9 Signs to Look For

Jamie Corish

Jamie Corish

12 August 2026

A health and safety manager reviewing a printed policy document at her desk beside a laptop, in a bright UK office.

There is no legal deadline for updating your health and safety policy. The Health and Safety at Work etc. Act 1974 asks employers to revise it “as often as may be appropriate”, which deliberately puts the judgement on you rather than on a calendar.

That wording is more demanding than a fixed date would be. A policy reviewed every January can still be out of date by March. What matters is whether the document still describes how your organisation actually manages risk today, and whether you can show why your review interval is the right one.

This guide covers what the law requires, how often to review in practice, the nine signs that should send you back to the document before the annual date comes round, and the step most organisations miss: proving the revision reached the people it applies to.

Short answer

Baseline: review the whole policy at least once a year, and record that you did.

Revise sooner whenever the law changes, your organisation changes shape, the work or the working patterns change, or an incident, audit or tender exposes a gap.

Every time you revise: date it, version it, get it signed off at senior level, tell everyone it applies to, and keep a record that they saw it. A revision nobody has seen does not meet the duty in section 2(3).

What the Law Actually Says

Most guidance on this subject opens with “review annually”. That is sensible practice, but it is not what the legislation says, and the difference matters if you are ever asked to justify your approach.

Section 2(3) of the Health and Safety at Work etc. Act 1974 sets out two duties in a single sentence. Employers must:

“prepare and as often as may be appropriate revise a written statement of his general policy with respect to the health and safety at work of his employees and the organisation and arrangements for the time being in force for carrying out that policy, and to bring the statement and any revision of it to the notice of all of his employees.”

Three things follow from that.

There is no statutory interval. No provision in the Act or its regulations names a frequency. “As often as may be appropriate” is a proportionality test, judged against your own risks and how quickly they change. A twelve-month cycle is defensible for a low-hazard office. The same cycle on a multi-site construction business that opened four new sites in a year is not.

The arrangements are part of the policy. The duty covers the statement of intent and the “organisation and arrangements for the time being in force”. In other words, the practical detail of who does what and how. This is the part that goes stale first, because it is the part tied to real people, real sites and real procedures.

Revising is only half of it. The final clause requires you to bring the statement and any revision of it to the notice of all employees. An updated file sitting on a shared drive that nobody has been told about satisfies the first half of the duty and fails the second.

Under five employees, you need a policy but not a written one. The Employers' Health and Safety Policy Statements (Exception) Regulations 1975 except employers with fewer than five employees from section 2(3). The HSE puts the practical version plainly: “If you have five or more employees, you must write your policy down”. Two points catch people out. The count is a head count, not full-time equivalents, so eight part-timers put you over the line. And every other duty in the Act applies regardless of size. If you are near the threshold, our guide to what a small business policy should include is the better starting point.

The test an inspector will apply. For the arrangements your policy describes, the more useful yardstick sits in the Management of Health and Safety at Work Regulations 1999. Regulation 3(3) requires a risk assessment to be reviewed where “there is reason to suspect that it is no longer valid” or “there has been a significant change in the matters to which it relates”. That is the same logic as section 2(3), expressed as a test you can actually apply. The assessments it governs are usually the evidence base your policy's arrangements rest on, so when they move, the policy should move with them.

How Often Should a Health and Safety Policy Be Reviewed?

An annual full review is the widely accepted baseline and the one the HSE recommends as good practice. Treat it as a floor rather than a target, and set your real cadence against your risk profile.

Risk profileFull reviewLighter check
Low hazard, single site, office basedAnnuallyNot usually needed
Mixed, with some higher-risk workAnnuallyEvery six months
Higher hazard or heavily regulatedAnnually, with formal sign-offQuarterly
Multi-site or frequently reorganisingAnnuallyQuarterly, plus every structural change

The lighter check is not a rewrite. It is a short, minuted question at a management meeting: has anything changed that the policy does not reflect? Most of the time the answer is no, and recording that is itself useful evidence that you are managing the document rather than ignoring it.

The Two Review Clocks

What this produces is two clocks running side by side. Organisations that only run the first are compliant on paper for up to eleven months at a time while the document drifts away from the work.

Scheduled: you set the date

  • Quarterly or six-monthly light check
  • Annual full review of all three parts
  • Senior sign-off, and the document re-dated
  • Owned by one named person

Triggered: the event sets the date

  • The law changes
  • New site, structure, equipment or task
  • An incident, near miss or RIDDOR report
  • An audit, tender or insurer finding

Both clocks produce the same output: a dated, version-controlled revision, signed off at senior level, communicated to everyone it applies to, with a record that it landed. If this looks like Plan, Do, Check, Act, that is because it is. The HSE's Managing for health and safety (HSG65) framework treats policy as something the Check and Act stages feed back into, not a document you write once and file. ISO 45001 takes the same view, tying policy review to management review rather than to an anniversary. Our guide to building a health and safety management system covers how the cycle fits together.

9 Signs It Is Time to Revise Your Policy

These are the triggers worth writing into your own procedure. Any one of them is reason enough to open the document before the scheduled date.

When Your Context Has Changed

1. The law or official guidance has changed. Legal change is the trigger most people think of first, and the easiest to miss in practice because it rarely arrives with a letter addressed to you. Two live examples as of August 2026:

  • Harassment duties widen in October 2026. Under the Employment Rights Act 2025, the duty to prevent sexual harassment rises from taking “reasonable steps” to taking “all reasonable steps”, and employer liability for harassment by third parties such as customers, clients and members of the public is reintroduced. If your people deal with the public, this is a risk assessment and policy question as much as an HR one, and it connects directly to how you handle violence and aggression at work.
  • Martyn's Law is coming, but is not yet enforceable. The Terrorism (Protection of Premises) Act 2025 received Royal Assent in April 2025 and statutory guidance began appearing in 2026, but the duties themselves are expected to commence in spring 2027. ProtectUK is the authoritative source for the timetable. If you are in scope, this is a plan-now trigger rather than a revise-now one, and our overview of what Martyn's Law requires sets out the thresholds.

Lower-profile changes matter just as much. The HSE revises workplace exposure limits in EH40 periodically, and a single revised limit can invalidate a COSHH assessment your policy points to. The practical answer is a standing horizon-scanning item rather than heroic vigilance: our 2026 compliance calendar and list of UK health and safety legislation are built for exactly that.

2. Your organisation has changed shape. Structural change is the trigger that most reliably breaks a policy, because the policy names structures. A new site, a merger or acquisition, a TUPE transfer, a restructure that moves a function under a different director, or simply crossing the five-employee threshold all leave a policy describing an organisation that no longer exists. Growth causes a subtler version of the same problem: arrangements that worked when one person could see the whole operation stop working when there are three sites and two shifts, even though nothing in the document is technically wrong.

Two engineers in hi-vis and safety helmets commissioning newly installed machinery in a UK warehouse while a supervisor records notes on a tablet.

3. There is new work, new equipment or new substances. A new machine, a new process, a new service line or a new substance changes the hazard profile the policy's arrangements were written against. This is squarely the “significant change” limb of regulation 3(3), and the sequence matters: assess the new risk first, then update the policy to reflect the arrangements you have actually put in place. Doing it the other way round produces a policy that promises controls nobody has built. Our risk assessment module exists to keep that link visible.

4. People are working differently. Changes to how and where people work are easy to overlook because no new equipment appears. Moving to hybrid working, sending staff to visit clients or service users alone, adding a night shift, or taking on your first field-based team all introduce risks your existing arrangements were never written for. Lone and remote working is the most common gap we see: if any of your people now work alone, unsupervised or out of hours, the policy needs to say what the arrangements are, and you probably need a lone working policy and a lone working risk assessment to sit underneath it.

The same applies to health risks that do not announce themselves. Work-related stress, depression or anxiety accounted for an estimated 964,000 cases in Great Britain and 52% of all work-related ill health, against 1.9 million people reporting a work-related illness overall. If your policy is silent on psychosocial risk, the HSE's Management Standards for work-related stress are the framework to bring it in line with.

When Something Has Gone Wrong

5. An incident or near miss exposed a gap. Any incident serious enough to be reportable under RIDDOR should prompt a look at the policy, not only at the immediate cause. So should a cluster of near misses pointing at the same control. Where a formal investigation produces recommendations, at least some of them usually belong in the policy rather than in the report, because a recommendation that lives only in a closed investigation file will not survive a staff change. Consistent incident reporting is what makes this trigger visible in the first place: you cannot spot the cluster if the reports never arrive.

6. An audit, inspection or enforcement visit found something. Findings from internal safety inspections, an external audit, a certification body, or an HSE or local authority visit are direct evidence that something in your system is not working. Improvement notices and formal advice obviously demand a response. So do repeated internal audit findings against the same clause, which usually mean the arrangement described in the policy is unworkable in practice rather than simply ignored. Running audits and inspections on a fixed schedule is what turns this trigger from luck into a system.

7. A client, insurer or tender asked for evidence you could not produce. Pre-qualification questionnaires, SSIP and CHAS assessments, insurer reviews and client audits all ask for the current signed policy, and increasingly for evidence of when it was last reviewed and how it was communicated. If answering that question involved a scramble, an argument about which file was current, or a document dated three years ago, the gap is real whether or not you won the work. It tells you something about your document control even when the policy content is sound.

When the Document Has Drifted

8. The names in your policy are out of date. This is the most common silent failure, and the easiest to fix. The HSE expects a policy to “clearly say who does what, when and how”. Named individuals leave, change role or take on different duties, and the responsibilities section quietly becomes fiction. Walk it line by line and confirm that each named person still exists, still works here and still holds that duty. If your policy names roles rather than people, and maintains a separate current list of postholders, the problem largely disappears. Our guide to who is responsible for health and safety covers how to structure it.

9. Your risk assessments have moved on but the policy has not. Over time, assessments get updated in response to real conditions while the policy above them stays still. The result is drift: a policy describing arrangements that the people doing the work stopped following two years ago, often for good reasons. The tell is usually a mismatch in language. The policy refers to a form, a role or a committee that no longer exists, or omits the dynamic risk assessment your teams now do as a matter of course. When the document and the practice disagree, the document is the liability, because it is the version a regulator or a claimant will read.

Decision test

Does the change actually reach the policy?

Does it change who is responsible for anything? Revise the responsibilities section and reissue it.

Does it change how a risk is actually controlled? Update the risk assessment first, then the arrangements.

Does it change your legal duties or the standards you work to? Review all three parts, and every document beneath them.

Does it change what your organisation is committing to? Revise the statement of intent and get fresh senior sign-off.

No to all four? No revision is needed. Record the decision, the date and who made it, then carry the item into the next scheduled review. A documented decision not to revise is evidence of control. Silence is not.

What a Policy Review Should Cover

A review is not a proofread. Work through each of the three conventional parts and ask whether it is still true, rather than whether it still reads well. Our breakdown of the components of a health and safety policy covers the structure in full; these are the review questions for each part.

Statement of intent. Is it signed and dated by someone currently in post at the top of the organisation? Does it commit to anything you have quietly stopped doing? Does it reflect the risks you actually run, rather than generic wording that would fit any employer?

Responsibilities. Does every named person still hold that duty? Are there duties nobody owns, particularly for newer risks such as lone working, contractor management or psychosocial risk? Do the people named know they are named, and do they have the time and authority to discharge it?

Arrangements. Does each arrangement describe what happens now? Do the referenced procedures, forms and assessments still exist under those names? Can someone new follow this and get it right? Have you consulted employees or their safety representatives on changes that affect them, as you are required to?

Proving the Revision Landed

Section 2(3) requires you to bring the statement and any revision of it to the notice of all employees. In practice this is where most policies fail, and it is a failure that only becomes visible at the worst possible moment: after an incident, when someone asks which version was in force and who had seen it.

A manager handing a printed policy document across a meeting room table to a colleague, while another colleague signs an acknowledgement form on a clipboard.

A revision has to travel through five steps before the duty is discharged.

StepWhat it involves
1. ReviseDraft the change and date it.
2. ApproveSigned off at senior level, with a version number issued.
3. CommunicateReaches everyone it applies to, including new starters and contractors.
4. AcknowledgeA record that each person actually received it.
5. RetainSuperseded versions kept, so you can show what applied when.

Steps 3 and 4 are where the chain breaks. Most organisations can produce a current policy on request. Far fewer can show who had read the version that was in force on the day of an incident. Four habits close the gap:

  • Version and date every issue, including minor amendments, and keep a short revision history on the document itself showing what changed and why.
  • Retain superseded versions. You may need to demonstrate what your policy said on a specific date years ago, which is impossible if each revision overwrites the last.
  • Record distribution and acknowledgement, not just publication. A read receipt or a signature is the difference between asserting that people were told and showing it.
  • Build it into induction. New starters and contractors are the group most often missed, and the group least able to fall back on knowing how things are done.

Shared drives and email attachments make all four of these hard, because they hold documents without holding the trail around them. This is the specific problem document management in Vatix is built for: version control, distribution and acknowledgement recorded against the document itself. Our guide to choosing a document management system covers what to look for more generally.

Build a Review Schedule You Will Keep

Good intentions do not survive a busy quarter. What survives is a schedule with a name against it.

  • Name an owner. One person accountable for the review happening, with the seniority to get sign-off.
  • Put both clocks in the calendar. The annual full review, plus the lighter checks your risk profile justifies.
  • Keep a trigger register. A running list of the nine signs above, where anyone can log an event that might need a policy change. Most entries will not lead to a revision, and that is fine.
  • Make it a standing agenda item. Health and safety at management meetings should include an explicit question about whether anything has changed.
  • Close the loop with actions. Every review should end in either a dated revision or a recorded decision that none was needed, with any follow-up tracked to completion.

The wider point is that the policy should be downstream of what your organisation already knows. When incidents, audits, inspections and risk assessments live in one place and report together, the triggers surface on their own. When they live in separate spreadsheets and inboxes, someone has to remember, and eventually nobody does.

Keep the Policy Close to the Work

“As often as may be appropriate” is not a loophole. It is a standard that asks you to know your own risks well enough to judge when the document describing them has stopped being true. An annual review meets the floor. Watching for the nine signs is what keeps the policy honest in between.

Elevate Safety & Operations with Vatix

Share your requirements with us, and our Vatix experts will show you how to keep your policy, assessments and records in step.

Contact Sales

Frequently Asked Questions

At least once a year is the widely accepted baseline and the frequency the HSE recommends as good practice. There is no statutory interval. Section 2(3) of the Health and Safety at Work etc. Act 1974 requires you to revise the policy "as often as may be appropriate", which means your risk profile sets the cadence. Higher-hazard or fast-changing organisations should add a lighter quarterly check between full reviews.
No. Annual review is good practice rather than law. The legal test is whether you revise the policy as often as is appropriate for your organisation, and whether you can justify the interval you have chosen. A twelve-month cycle is defensible for a low-hazard office and hard to defend for a business that has opened several new sites in the same period.
A change in the law or official guidance, a change in your organisation's structure or size, new work, equipment or substances, a change in how or where people work, an incident or a cluster of near misses, a change to the people named in the responsibilities section, findings from an audit, inspection or enforcement visit, a failed evidence request from a client or insurer, and any drift between your risk assessments and the arrangements the policy describes.
No. The Employers' Health and Safety Policy Statements (Exception) Regulations 1975 except employers with fewer than five employees from the duty to put the policy in writing. You still need a policy for managing health and safety, and every other duty under the Act still applies. The threshold is a head count rather than full-time equivalents, so part-time staff count individually.
Yes, and this is a distinct legal duty. Section 2(3) requires employers to bring the statement "and any revision of it" to the notice of all employees. Updating the file is not enough on its own. You should be able to show who was told, when, and ideally that they acknowledged it, including new starters and contractors.
Keep the dated and version-numbered policy with senior sign-off, a short revision history showing what changed and why, a record of how the revision was communicated and who acknowledged it, and all superseded versions. Retaining old versions matters because you may need to demonstrate what your policy said on a specific date. Also record reviews that concluded no change was needed, since a documented decision is evidence of control.
Jamie Corish

Jamie Corish

Jamie Corish is Demand Generation Manager at Vatix, where he creates content to help EHS professionals stay ahead of regulatory changes and industry developments. He writes about health and safety trends, compliance, and the technology shaping modern safety management.

Elevate Safety & Operations with Vatix

Ready to see how Vatix can help your organisation? Get a personalised demo today.