Skip to main content
SubComply

RAMS Software: What to Look For (UK 2026)

By Brian Crocker

Most RAMS software is built for the company writing the risk assessment and method statement. If you are a principal contractor, that is not your problem. Your problem is the forty RAMS documents arriving from fourteen subcontractors, each in a different format, several of them recycled from another site, and no reliable way to show which ones you actually read before the work started.

Those are two different products, and the distinction matters more than any feature list. Authoring tools help a subcontractor produce a RAMS faster. Review and tracking tools help a principal contractor receive, assess, record and retrieve them. Most of what ranks for "RAMS software" is the first kind. This guide covers what the second kind needs to do.

Why the authoring/review split decides your shortlist

A subcontractor writing RAMS wants templates, a hazard library, and a quick route to a professional-looking PDF. Perfectly reasonable, and there are good tools for it.

A principal contractor has the opposite job. You are not producing the document — you are the control point. Under CDM 2015 Regulation 8(3), "a person who is responsible for appointing a designer or contractor to carry out work on a project must take reasonable steps to satisfy themselves that the designer or contractor fulfils the conditions in paragraph (1)" — the skills, knowledge, experience and organisational capability test. Reviewing a subcontractor's RAMS is one of the clearest ways you evidence those reasonable steps.

And under Regulation 15(2), every contractor "must plan, manage and monitor construction work carried out either by the contractor or by workers under the contractor's control, to ensure that, so far as is reasonably practicable, it is carried out without risks to health and safety." Their RAMS is how they demonstrate that. Your record of reviewing it is how you demonstrate yours.

If a tool cannot answer "what did we receive, who looked at it, and when" for any subcontractor on any project, it is an authoring tool with a filing cabinet bolted on.

A jurisdiction note. Regulation 3 applies CDM 2015 "in Great Britain". Northern Ireland has its own instrument — the Construction (Design and Management) Regulations (Northern Ireland) 2016, in operation since 1 August 2016 — so if you work there, check the NI position rather than assuming the regulation numbers cited here apply.

Eight criteria that actually separate tools

1. Inbound submission without an account. The single biggest determinant of whether a system survives contact with reality. If each subcontractor has to create a login, remember a password, and learn an interface to send you one PDF, adoption collapses and you go back to email. Look for a link-based upload that works from a phone on site.

2. A dated review record, not just a storage date. Storage tells you a file exists. What you need at an audit is that the RAMS was received on the 3rd, reviewed by a named person on the 4th, and accepted before the operatives arrived on the 8th. A file timestamp does not prove a review happened.

3. Version handling when scope changes. Subcontractor scope changes constantly. A RAMS approved for groundworks does not cover the drainage that got added in week three. The tool should let a revised RAMS supersede the original while keeping both — you need to show what was in force at the time of an incident, not just what is current.

4. Expiry and review-date tracking across the whole subcontractor base. RAMS themselves do not usually expire, but the documents that sit alongside them do — insurance, CSCS cards, trade certifications. If the tool tracks RAMS in isolation from those, you are running two systems.

5. Linking RAMS to the construction phase plan. Regulation 15(3) requires contractors on a multi-contractor project to comply with "the parts of the construction phase plan that are relevant to that contractor's work." A method statement that conflicts with your CPP sequencing needs to be caught at review. Tools that treat RAMS as standalone documents make that comparison a manual job.

6. Retrieval under pressure. The real test is an HSE inspector or a Tier 1 client auditor asking for the RAMS for a specific trade on a specific date. If that takes more than a minute, the system has not replaced the shared drive — it has become a second shared drive.

7. Export you own. Ask what happens to your documents if you stop paying. Bulk export in a standard format, on demand, without a support ticket, is the answer you want.

8. Honest scope about what it does not do. A tool that claims to assess whether a RAMS is adequate is overselling. Software can check that a document arrived, that it is the current version, that someone recorded a review, and that it covers the right scope and dates. Judging whether the control measures are sufficient for the hazard is a competent person's job. Be sceptical of anything implying otherwise.

Questions worth asking on a demo

  • Show me the subcontractor's side of an upload, on a phone, without an account.
  • Show me the audit trail for a document that was revised after approval.
  • How do I find every RAMS in force for one trade on one date?
  • What does the export contain, and can I trigger it myself?
  • What happens when a subcontractor sends a RAMS by email anyway?

That last one matters more than it sounds. Some subcontractors will always email. A system that has no route for a document arriving outside the process leaves a gap exactly where your evidence needs to be complete.

What this costs you if you get it wrong

The failure mode is not usually a missing document — it is an unprovable review. You had the RAMS. Somebody looked at it. Nobody recorded that. When the question is asked six months later, "we always review them" is not evidence, and Regulation 8(3) asks for reasonable steps you can point to.

The second failure mode is generic RAMS accepted at volume. When reviewing forty documents is painful, review quality degrades, and a template with another project's name edited out passes through. A tool that makes the review itself faster — surfacing scope, dates and revision status without opening every PDF — is worth more than one that simply stores them tidily.

Where to start if you are not buying yet

You do not need software to fix the evidence gap. A dated log with four columns — subcontractor, document, date received, date reviewed and by whom — closes most of it, and it will tell you within a month whether your volume genuinely justifies a tool.

If it does, use the criteria above rather than a feature grid. Most RAMS tools compete on how fast they produce a document. Very few compete on how well they prove you checked one.

For what a method statement must actually contain and how to review it properly, see our method statements in construction guide. For the risk assessment half of RAMS, see our construction risk assessment guide. For the wider document set you collect before a subcontractor mobilises, see our subcontractor onboarding documents guide.


SubComply is being built for the receiving side of this problem — collecting subcontractor documents including RAMS, recording who reviewed what and when, and producing an audit-ready pack per project. Join the waitlist to be notified when it launches.

Sources

This guide is for informational purposes and does not constitute legal advice. For project-specific compliance questions, consult a qualified health and safety professional.

Last reviewed: 9 September 2026

Stop chasing subcontractor paperwork

We're building SubComply to automate document collection, insurance tracking, and audit-ready compliance reports for UK contractors. Join the waitlist for early access.

No spam. Unsubscribe any time. Privacy policy