A risk assessment establishes what could cause harm in a piece of work and what must be done about it. A method statement sets out how that work will actually be carried out, in sequence, by whom, with what equipment. One is analysis. The other is a plan. They answer different questions, they are organised differently, they are read by different people, and neither substitutes for the other. If you take one thing from this page, take that: you cannot satisfy a request for a risk assessment with a method statement, or the other way round, because the two documents are not alternative formats for the same content.
The message up front: the two documents are not parallel, they are sequential. The risk assessment's conclusions are inputs to the method statement. Assess first, then write the method that the assessment permits. Doing it the other way round, writing the method and then producing an assessment to accompany it, inverts the logic and is one of the most common defects in this paperwork.
This is a general explanation of the two documents and how they relate. What a specific job or contract actually requires is set by the law applicable where the work is done, the terms of the contract, and the site's own safety management system, and competent advice on the particular work should come from someone who can see it.
1. The two questions the documents answer
Start with the question each document exists to answer, because everything else follows from that.
The risk assessment answers: what about this work could hurt someone, how likely and how serious is that, and what controls reduce it to an acceptable level? Its unit of organisation is the hazard. It works through hazards one at a time, records who is at risk from each, and records the controls decided on. It produces a set of conclusions, and the important thing about those conclusions is that they are decisions rather than descriptions. A risk assessment that concludes "use a mobile elevating work platform rather than a ladder" has decided something about the work. The process behind it, the identification, evaluation and control selection, is covered properly in the risk assessment guide.
The method statement answers: how will this specific job be done, in what order, with what plant, by whom, and at what points does something have to be checked or handed over? Its unit of organisation is the step. It is a narrative of the work from arrival to completion, and it exists so that the people doing the job and the people supervising it share one version of how the job runs. The document in full, including what a good one contains, is covered in the method statement guide.
Put crudely: the risk assessment is the argument, the method statement is the instruction. You can have a sound argument and no instruction, in which case nobody knows how the work runs. You can have a detailed instruction resting on no argument, in which case nobody knows whether the way the work runs is defensible. Both situations are common.
2. The dependency: the assessment feeds the method
This is the part most comparisons miss, and it is the most useful thing on this page. The two documents are not a matched pair produced side by side. They are sequential, and the order runs one way only: the risk assessment's conclusions are inputs to the method statement.
The reason is simple. An assessment can change the method. It can conclude that the access arrangement should be different, that the equipment should be different, that the work should happen at a different time or with the plant isolated, or that the task should not be done that way at all. Those conclusions are not annotations on a method, they are constraints on what the method is allowed to say. If you write the method first, you have written a plan that has not been tested against the hazards it creates, and the assessment that follows can only do one of two things: rubber-stamp the plan, or invalidate it. In practice it rubber-stamps it, because by then the plan has been priced, resourced and promised to the client.
The controls the assessment selects also have a ranking behind them. Elimination and substitution sit above engineering controls, which sit above administrative controls and personal protective equipment. That ordering is a principle rather than a standard in its own right, though it is required by ISO 45001:2018, as amended by Amd 1:2024, clause 8.1.2 and by ANSI/ASSP Z10.0-2019 section 8.4 in the United States, and both are voluntary management system documents rather than law anywhere. The practical consequence for this article is that the higher-order controls are precisely the ones that rewrite a method. Eliminating a task, or substituting the equipment, changes the sequence. If the assessment is written after the method, those controls are effectively off the table, and what is left is a list of gloves and goggles appended to a plan that was never questioned. See the hierarchy of controls guide for why the ordering matters as much as the list.
The test
Read the method statement and ask: is there anything here that the risk assessment caused? A specific access method, an isolation, a sequencing constraint, a reduced crew, a change of tool. If the method would read identically with the assessment deleted, the assessment did not inform it, and the pair was assembled rather than produced.
There is a legitimate iteration here, and it is worth naming so the sequence does not sound naive. In real planning you sketch a likely method, assess it, discover something that will not work, revise the method, and reassess the parts you changed. That loop is correct practice. What is not correct is a single pass in which the method is fixed and the assessment is generated to match. Iteration means the method changed. If nothing changed, nothing was assessed.
3. The differences, dimension by dimension
With the dependency established, the differences are easier to hold in your head. The table sets them out; the paragraphs after it deal with the two dimensions that cause the most trouble.
| Dimension | Risk assessment | Method statement |
|---|---|---|
| Question answered | What could cause harm, and what must be done about it? | How will the work actually be carried out? |
| Nature | Analysis and judgement | Plan and instruction |
| Output | Hazards, who is affected, evaluated risk, control decisions, residual risk | An ordered sequence of steps with plant, people, supervision and hold points |
| Organised by | Hazard | Sequence of work |
| Primary audience | The employer, the safety function, the reviewer, the regulator | The work crew, the supervisor, the site team affected by the work |
| Named in law? | Commonly yes, as a duty (see next section) | Usually not by name; largely industry practice and contract |
| Reviewed by | A competent person for the hazards involved, usually the safety function | The person accountable for the work, plus the receiving site or client |
| Trigger for revision | Change in hazard, incident, new information, periodic review | Change in method, plant, crew, site conditions or sequence |
| What makes it bad | Generic hazards, no evaluation, controls that restate the hazard, no named responsibility | Vague steps, no sequence, no hold points, no named roles, copied from another job |
| What it cannot do | Tell anyone how to do the job | Demonstrate that the chosen method is justified |
Hazard-organised versus sequence-organised is the difference that shows up fastest when you read the documents. A risk assessment moves sideways across the job: working at height, then manual handling, then electrical, then dust, then the public. It does not care in what order those hazards arise. A method statement moves forwards through the job: set up the exclusion zone, isolate and prove dead, erect the access, carry out the work, reinstate, hand back. It cares very much about order, because order is what makes the work safe or unsafe. A document that tries to be both usually ends up as a chronological narrative with hazards scattered through it, which serves neither purpose.
What each cannot do is the dimension worth memorising, because it disposes of the substitution question entirely. A risk assessment cannot tell anyone how to do the job; it was never structured to. A method statement cannot demonstrate that the chosen method is justified; it asserts a method rather than arguing for it. Asking one to perform the other's function produces a document that fails at both.
4. Why the law usually names one and not the other
There is an asymmetry here that explains a lot of the confusion. Legislation in many jurisdictions imposes a duty to assess risk. Very little legislation names a method statement as a document you must produce.
In Great Britain, the general duty to assess risk sits in Regulation 3 of the Management of Health and Safety at Work Regulations 1999 (SI 1999/3242), with subject-specific assessment duties elsewhere, for example under the Control of Substances Hazardous to Health Regulations 2002, as amended, and under the Work at Height Regulations 2005 (SI 2005/735). Construction planning duties in Great Britain sit in the Construction (Design and Management) Regulations 2015 (SI 2015/51). Note that Northern Ireland has its own instruments, with different years in several cases, so a Great Britain citation should not be applied there without checking.
In the United States, federal OSHA requirements are in 29 CFR and apply in the United States only. There is no federal OSHA standard requiring a written job-level safety analysis as such; the relevant OSHA publication, OSHA 3071, "Job Hazard Analysis", 2002 revision, is guidance. Where written hazard assessment is mandated, the clearest general-industry example is 29 CFR 1910.132(d), which requires a written certification of the hazard assessment identifying the workplace, the certifying person and the date. Individual State Plan states may impose their own, different requirements.
In the United Arab Emirates, the binding instrument for most private sector employment is Federal Decree-Law No. 33 of 2021 on the regulation of employment relationships, administered by MOHRE, with occupational safety duties in Article 13, alongside emirate-level frameworks such as the Abu Dhabi Occupational Safety and Health System Framework (ADOSH-SF), Version 4.0, administered by the Abu Dhabi Public Health Centre. United States OSHA regulations and British HSE law have no legal force in the UAE; they function as voluntary benchmarks, and ISO 45001 is the usual international reference point. Whatever the jurisdiction, the pattern holds: the assessment is the thing with a legal name, and the method statement is the thing the industry and the contract demand.
What the asymmetry does not mean
It does not mean the method statement is optional. Duties to plan work, to provide a safe system of work and to give adequate information and instruction are met in practice by something that looks very much like a method statement, whatever it is called. And the contract will usually require one by name regardless of what the legislation says. "The law does not name it" is a point about drafting, not a defence.
On the standards side, be careful with what is often cited loosely. ISO 31000:2018 is risk management guidance and is not certifiable, so there is no accredited organisational certification against it. Risk assessment techniques are catalogued in IEC 31010:2019, which is IEC 31010 and not "ISO 31010". None of these documents is law in any jurisdiction by itself; they bind through contracts and management systems.
5. Which you need, and when
The honest answer is that this is driven by the hazard and by the contract, not by a rule that produces the same answer everywhere. What follows is a set of situations rather than a decision tree, because the boundaries are genuinely fuzzy.
| Situation | What is typically needed | Why |
|---|---|---|
| Routine, familiar task in your own premises | Risk assessment, commonly a generic or task-based one, kept current | The hazards are understood and the sequence is not contentious. A method statement adds paperwork without adding control, and one written for form's sake will not be read. |
| Contractor working on someone else's site | Both, near-universally, and usually required by contract | The receiving site cannot see your competence or your intentions. The assessment shows you understood the hazards; the method shows the site what will happen to it and when. |
| Complex or multi-trade work | Both, with the method statement carrying the weight | Sequencing is the actual control. Who works when, what is isolated, who hands over to whom. That is the method statement's job and nothing else does it. |
| Higher-hazard work: confined space, hot work, live electrical, lifting over occupied areas | Both, feeding a permit to work | The permit authorises the work at a point in time and relies on both documents having already established the hazards and the sequence it is authorising. |
| Short, unplanned reactive job on your own site | Assessment coverage plus a brief point-of-work check | A full method statement cannot be produced at the speed the work happens. The realistic control is existing assessment coverage and a short pre-task check by the person doing it. |
| Work the assessment concludes should not be done this way | Neither, yet | The output is a changed scope or a different approach. Writing a method statement for a method the assessment rejected is the failure mode this article is about. |
Two honest notes on that table. First, "do I need both?" is very often answered by a procurement document rather than by a hazard judgement, and pretending otherwise wastes time. If the contract asks for the pair, you produce the pair. Second, where you genuinely have discretion, the question to ask is whether anybody needs to be told the order of the work. If the answer is no, a method statement is ceremony. If the answer is yes, it is the document that carries the control.
6. How they relate to the other documents in this space
These two sit in a small family of documents that are constantly mistaken for each other. Briefly, and with the detail left where it belongs:
- The job safety analysis sits closer to the method statement in that it is task-and-step based, but in structure it is a hazard analysis: it breaks the job into steps and then analyses each step's hazards and controls. It is not a plan of how the work runs. See the JSA guide, and the JSA versus JHA distinction if the naming is what is confusing you.
- RAMS is not a third document. It is the risk assessment and method statement submitted together as one package. Everything about how the pair is used, submitted, reviewed and accepted belongs to the RAMS guide, not here.
- The permit to work authorises specific work at a specific time under specific conditions, and it is informed by both documents rather than replacing either. Note that no international standard specifies a permit system; the widely used reference is British HSE guidance HSG250, which is guidance and creates no duties itself. See the permit to work guide, and for how the paperwork lands in a maintenance system, permit to work integration with CMMS.
- The toolbox talk briefs them. It is how the crew comes to know what the assessment concluded and what the method requires, delivered verbally at the point of work. See the toolbox talk guide. For where all of this sits in the wider function, the introduction to HSE is the orientation piece.
7. What goes wrong when they are treated as one thing
Collapse the distinction and the failures are predictable. All of these turn up in submitted packs, and often more than one of them in the same pack.
- A risk assessment written as a narrative of the method. "Operative will erect tower scaffold and install luminaire." That is a step, not a hazard. A document made of steps identifies no hazards, because it never asks the question.
- A method statement with a generic hazard list bolted on the back. Slips, trips, manual handling, noise, every job, every time, unrelated to the work described above it. The giveaway is that the list would be identical for a different job.
- Controls in one document and not the other. The assessment specifies a rescue plan; the method statement's sequence has no rescue step. Whichever document the crew actually reads, a control has gone missing.
- The two documents contradicting each other. The assessment says the plant is isolated; the method describes live testing. The assessment specifies a powered platform; the method has a ladder. This is common, and it is a reliable sign that neither document was read after it was written.
- A reviewer who checks both are present. The pack has a risk assessment and it has a method statement, so it is compliant. Presence was verified; consistency was not. That review catches nothing the two documents disagree about, which is where the risk actually is.
The limitation of consistency as a measure
Two documents can be perfectly consistent and both wrong. A method built on a poor assessment will agree with it beautifully. Consistency is a fast, cheap signal that the pair was produced together; it is not evidence that the assessment was competent or the method sound. Treat it as the first filter, not the whole review.
8. Reading the pair as a reviewer
Much of the audience for this receives these documents rather than writes them, and that is a different skill. You are not re-doing the contractor's assessment. You are judging whether the pair was produced as a planning exercise or assembled to satisfy a requirement. A small number of cross-checks tells you most of what you need.
| Check across the pair | What a mismatch tells you |
|---|---|
| Does every significant control in the assessment appear as an action in the method? | Controls decided and then not planned for. The assessment was written for the file. |
| Does the method use plant, access or isolation the assessment never mentions? | The method was written first, or changed after the assessment and never reassessed. |
| Do the two describe the same scope, location and duration? | One of them was reused from another job. |
| Are the hazards in the assessment recognisable in the work the method describes? | A generic assessment attached to a specific method. |
| Do the named roles match, and do those people exist on the crew? | Responsibility was assigned on paper only. |
| Do the revision dates and version numbers relate to each other sensibly? | A method updated without the assessment following, which is the usual direction of drift. |
| Does the method contain any constraint that only an assessment would have produced? | If not, the assessment did not inform the method at all. |
The practical point is that inconsistency between the two is the fastest available signal of a document produced to satisfy a requirement rather than to plan work. It takes a few minutes, it needs no specialist knowledge of the trade, and it is far more revealing than checking that both documents are present and signed. When the pair disagrees, the conversation to have with the contractor is not about the paperwork. It is about whether anyone planned the job.
The idea to walk away with
A risk assessment establishes what could cause harm and what must be done about it. A method statement sets out how the work will be carried out. Analysis and plan. Hazard-organised and sequence-organised. Named in law and named in contracts. Neither one does the other's job, and no amount of formatting turns one into the other.
The order matters more than the distinction. Assess, then write the method the assessment permits, and be willing to let the assessment change the method, because that willingness is the only thing that makes the assessment worth doing. Everything else in this space, the JSA, the RAMS pack, the permit, the toolbox talk, is built on those two documents being sound and saying the same thing.
Final thoughts
The reason this comparison is worth getting right is not documentary tidiness. It is that the confusion has a direction. It typically collapses toward the method statement, because the method is what the job needs to proceed and the assessment is what the file needs. Once the assessment becomes a companion document produced to accompany a plan already fixed, it has stopped being an assessment, and the higher-order controls that would have changed the work are quietly out of reach.
So if you write these, write them in order and let the first one change the second. If you receive them, read them against each other rather than counting them. And if they disagree, you have learned something more useful than anything either document says on its own.
Disclosure
Alongside advisory work I also build a CMMS and CAFM platform, so I have a commercial interest in this category. Nothing above is a recommendation for it, and no vendor named here has paid for inclusion or had any editorial input. Weigh the analysis accordingly.
Reviewing contractor safety documentation?
Independent advisory on safe-system-of-work documentation, permit and work order workflow, and how the paperwork is structured so it is read rather than filed. 22+ years across utilities, oil and gas, manufacturing, government and facility operations.
Book a conversationRelated reading: What is a method statement, Risk assessment guide with examples, RAMS explained, Job safety analysis, Permit to work, Facilities maintenance management. Primary sources: HSE (Great Britain) , ISO .
Muhammad Abbas
CMMS / CAFM Manager & Independent Advisor · 22+ years across enterprise CMMS, EAM, CAFM and ERP implementations in utilities, oil and gas, manufacturing, government and facility operations.
Work with me