Guide · UK HSE · 10 September 2026
Suitable and Sufficient: What the Law Means by Risk Assessment
The UK law does not say “do a risk assessment”; it says “make a suitable and sufficient assessment” — MHSWR 1999, regulation 3. The two words are the standard, and the standard is what the audit and the investigation check. This guide is the suitable and sufficient in working form.

The two words: the standard
The UK law (MHSWR 1999, regulation 3) sets the standard: the suitable and sufficient assessment. The standard is what passes the audit and the investigation — not the length of the document, not the template, the two words.
The suitable is the right thing: the hazard identified, the who decided, the control evaluated. The sufficient is the right depth: the thorough, the up-to-date, the reviewed. An assessment that is suitable but not sufficient is the thin one; an assessment that is sufficient but not suitable is the wrong one. Both fail the audit.
The suitable: the right thing
The suitable is the content, and the content is the five elements. The hazard is identified — the six families, the walk-over, the crew question. The who is decided — the employee, the contractor, the visitor, the vulnerable. The risk is evaluated — the likelihood, the consequence, the matrix, the score. The control is decided — the hierarchy: eliminate, substitute, engineer, manage, PPE. The review is planned — the calendar, the change, the incident.
An assessment that misses an element is not suitable, and the audit is where it shows. An assessment that has the five is the assessment with the right content.
The sufficient: the right depth
The sufficient is the quality, and the quality is the three standards. The thorough: every hazard — the six families, the who, the control, the one not missed. The up-to-date: the change is re-assessed — the new machine, the new product, the new shift. The reviewed: the calendar and the event — the annual, the incident, the change.
An assessment that is thorough but not up-to-date is the old one; an assessment that is up-to-date but not reviewed is the forgotten one. The three standards together are the assessment that is alive.
The assessment that passes
The assessment that passes is the one that is both: the suitable (the content is right) and the sufficient (the quality is right). The audit checks the content — the hazard, the who, the risk, the control, the review — and the quality — the thorough, the up-to-date, the reviewed. The investigation checks the control that is in place and working, and the review that follows the incident.
The suitable and sufficient is the standard, and the standard is what the law is done by. The two words, held together, are the assessment that passes both the audit and the investigation.

Need the sign-off, not just the guide?
The guide is the preparation; the sign-off is the professional. For the ISO 45001 implementation and audits, the RIDDOR and CDM work, the statutory assessments and the training that comes with them, ask Muhammad Umer — 8+ years across Iraq, KSA and Pakistan, and the programme runs through umer-hse.pro. One message gets the written scope.
Common questions
Suitable and Sufficient — answered
What is a suitable and sufficient risk assessment?
The UK law standard (MHSWR 1999, regulation 3). The suitable is the content: the hazard identified, the who decided, the risk evaluated, the control decided, the review planned — the five elements. The sufficient is the quality: the thorough, the up-to-date, the reviewed — the three standards.
What makes a risk assessment suitable?
The content: the hazard is identified (the six families, the walk-over, the crew question), the who is decided (the employee, the contractor, the visitor, the vulnerable), the risk is evaluated (the likelihood, the consequence, the matrix, the score), the control is decided (the hierarchy — eliminate, substitute, engineer, manage, PPE), and the review is planned (the calendar, the change, the incident).
What makes a risk assessment sufficient?
The quality: the thorough (every hazard, none missed), the up-to-date (the change is re-assessed — the new machine, the new product, the new shift), and the reviewed (the calendar and the event — the annual, the incident, the change).
What is the difference between suitable and sufficient?
The suitable is the content — the right thing: the hazard, the who, the risk, the control, the review. The sufficient is the quality — the right depth: the thorough, the up-to-date, the reviewed. Suitable but not sufficient is the thin one; sufficient but not suitable is the wrong one. Both fail the audit.
Is a generic risk assessment suitable and sufficient?
No. The generic is the template from the internet, and the template is not site-specific. The suitable is the site-specific — the content is the right thing for this site. The generic assessment is where the audit fails and the enforcement starts.
What does the MHSWR require for the risk assessment?
The MHSWR 1999, regulation 3: a suitable and sufficient assessment of the risk to the health and safety of the people. The assessment is written where the business has five or more people — the written is the record.
Keep reading
Related guides
practical-workplace-risk-assessment
practical-workplace-risk-assessment
UK HSE · 8 September 2026HSE Consultation: the Duty, the Workers, and the Method
HSE consultation, explained: the legal duty, the worker and the worker representative, the method (the safety
UK HSE · 2 September 2026RIDDOR Explained: the Full Form, the Duty, the Examples
RIDDOR explained: the full form (Reporting of Injuries, Diseases and Dangerous Occurrences Regulations 2013),
THE HEALTH AND SAFETY is an education and knowledge network. The guides are free and open; the professional assessments and the training run through umer-hse.pro.
Safety disclaimer
The guides on this site are practical guidance, built to the UK baseline with the US equivalents named in the text. They do not replace a competent person assessment for high-risk work, a statutory assessment, or the advice of your insurer. Where a duty has legal force — the RIDDOR report, the CDM plan, the ISO 45001 system — the responsible person or the responsible owner carries it. Read the guide as the preparation, and take the sign-off from the competent person.
