CDM, RAMS and site safety
The construction phase plan, risk assessments, toolbox talks and who signed what — plus the F10 test, RIDDOR, and the decisions BuildFlow deliberately leaves to you.
Updated 16 September 2026
Most of the paperwork a builder is asked for after something goes wrong is paperwork that had to exist before it went wrong. A construction phase plan written the week after an accident is worth nothing; the same plan written before anybody set foot on site is the difference between a conversation and a prosecution.
So BuildFlow records safety the way it records money: with dates that cannot be moved afterwards. Everything here is on every plan, free included, because the duties do not scale with your subscription.
CDM 2015 on a domestic job
The Construction (Design and Management) Regulations 2015 apply to every construction project in Great Britain. Not just big ones, not just notifiable ones, not just commercial ones. A loft conversion for a homeowner is in scope on day one.
The part that catches people out is regulation 7. A domestic client — someone having work done on their own home, not in the course of a business — does have client duties under CDM, but those duties pass automatically to the contractor. There is no form to sign and no choice in the matter. Where there is more than one contractor, they pass to the principal contractor instead.
You are probably the client as well as the builder
On a typical extension for a homeowner, the contractor holds both sets of duties. Builders who have read that "the client is responsible for X" and assumed that means the homeowner have read it correctly and drawn the wrong conclusion — on a domestic job, X is yours.
Set the position on a job's Safety tab: whether the client is domestic or commercial, whether there is more than one contractor, and who the principal contractor and principal designer are. It prints on the front of the safety pack, which is usually the first thing anybody asks to see.
The construction phase plan
Every construction project needs one. Not every project needs a thick one — the plan for a single-contractor extension should be a few pages that somebody on site would actually read, and HSE has said as much repeatedly. What it must be is written, specific to this job, and in place before construction starts.
BuildFlow gives you nine sections with a prompt on each. Six are marked essential; the other three are there when they apply.
| Section | What goes in it |
|---|---|
| The work | What is being built, where, roughly when. |
| Who is responsible | Who runs the site, who to ring, how somebody raises a concern. Names, not job titles. |
| The significant risks on this job | The few that could actually hurt someone here. Not a list of everything imaginable. |
| Site rules | Hours, parking, deliveries, PPE, who may be on site. Children and pets are worth naming on a domestic job. |
| Welfare | Toilet, washing, somewhere to sit and eat, drinking water — and from when. |
| Emergencies and first aid | First aider, kit, nearest A&E, and the site address as an ambulance would need it. |
| Services and utilities | Gas, electricity, water, drains. Where they run, what has been isolated. |
| Neighbours and the public | Hoarding, scaffold over a footpath, shared access. The people who did not choose to be near this job. |
| Asbestos | Anything pre-2000 may contain it. What the survey found, and what happens if something turns up. |
Issuing, and why you cannot backdate it
A draft is yours to edit freely. Pressing Issue stamps it with the date and time from the server and freezes the wording. From then on the text cannot be altered — not by you, not by us, not through the API. If it needs to change, you issue a revision: version 2 becomes current, version 1 is kept as superseded, and each keeps its own signatures.
The stamp is the whole point
A plan you could date yourself would be evidence of nothing. If work started on the 9th and the plan was issued on the 14th, BuildFlow says so — on the safety tab, on your dashboard, and in the pack. That is uncomfortable, and it is the honest answer to a question somebody will eventually ask under oath.
This is also why signatures stay attached to a version. Somebody who signed version 1 signed the wording they read. Carrying that signature onto a revised version would make them appear to endorse text they have never seen.
Is the job notifiable? The F10 test
Notification is a separate question from everything above, and a narrower one. A project is notifiable under regulation 6 if it will either:
- last longer than 30 working days AND have more than 20 workers on site simultaneously at any point; or
- exceed 500 person days in total.
Both limbs, each in full. The first trips up people who remember only "30 days" — a five-month job with three lads on it is not notifiable on that limb, because it never has 21 people on site at once.
Give BuildFlow an estimated duration and a peak headcount on the Safety tab and it will apply the first limb for you. It will not decide the second. Person days is the sum of everybody's days, and all the app has is a peak — multiplying the two gives an upper bound, not an answer. So when that bound clears 500, BuildFlow says the job *may* be notifiable and that you should work it out properly. It does not guess.
Notifiable is not the same as needing a plan
Every project needs a construction phase plan. Only some need an F10. Deciding your job is not notifiable tells you nothing about the rest of your duties, and the relief people feel at that point has caused a lot of missing plans.
If it is notifiable, you notify HSE directly — the F10 form is on their website — and then record the reference and the date in BuildFlow so it appears on the pack. BuildFlow does not submit it for you.
Risk assessments and method statements
A risk assessment is required by the Management of Health and Safety at Work Regulations 1999. If you have five or more employees you must record the significant findings in writing; below that you still have to do it, and writing it down is how you show that you did.
In BuildFlow an assessment is a list of hazards, each scored twice: likelihood times severity before your controls, and again after them. The two numbers are the argument. A hazard that scores 15 before and 15 after says the control does nothing, and seeing that on screen is more useful than any wording.
| Score | Band | Roughly |
|---|---|---|
| 1–4 | Low | Get on with it, keep an eye on it. |
| 5–9 | Medium | Controls need to be real and somebody needs to check them. |
| 10–14 | High | Not acceptable as it stands. Change the method or the sequence. |
| 15–25 | Severe | Stop. This one kills people. |
The method statement sits on the same record — how the work is actually done, in order — along with PPE, what to do if it goes wrong, and a review date. Assessments past their review date are flagged.
The library, and why it copies rather than links
On Basic and above you can keep a company library of assessments and drop one onto a job. When you do, BuildFlow takes a copy. Editing the library version afterwards does not silently change what somebody signed on a job six months ago, and a job's assessment never changes under the feet of the people working to it.
A generic RAMS is not a RAMS
A library entry is a starting point. "Working at height" with nothing in it about this scaffold, this roof and this street is the kind of document that gets produced in evidence by the other side. Edit it for the job — that is what the copy is for.
Toolbox talks and who signed what
Record a talk with its topic, date and a note of what was actually said. Then the part that usually does not exist anywhere: everybody on site signs the documents that apply to them, by typing their name, and BuildFlow records the name, the exact document version and the time.
The Safety tab shows what is outstanding — people on site crossed with documents in force, minus what has been signed. Clients are not counted: a homeowner is not being asked to work safely, they are being shown that somebody is.
Incidents and RIDDOR
Record everything — injuries, near misses, dangerous occurrences, damage. A near miss log that has entries in it is a sign of a site where people speak up.
Whether something is reportable under RIDDOR 2013 is a different matter, and BuildFlow does not decide it. Instead it puts the tests in front of you and records your answer:
- Did anybody die?
- Was it a specified injury — fracture other than to fingers, thumbs or toes; amputation; permanent or likely permanent loss of sight; crush injury to head or torso; serious burns; scalping requiring hospital treatment; loss of consciousness from head injury or asphyxia; or anything from an enclosed space needing resuscitation or 24 hours in hospital?
- Was a worker unable to do their normal work for more than seven consecutive days, not counting the day of the accident?
- Was a member of the public taken from the site to hospital for treatment?
- Was it a listed dangerous occurrence — scaffold collapse, a structure collapsing, contact with overhead lines, an unintentional explosion, and so on?
Seven days to report, three days to record
An over-seven-day injury must be reported to HSE within 15 days of the accident. An injury keeping someone off their normal work for more than three days does not have to be reported, but it must be recorded. Those are two different thresholds and mixing them up is the single most common RIDDOR mistake.
Mark an incident reportable and BuildFlow will keep telling you it is outstanding — on the Safety tab and on your dashboard — until you enter the reference and the date you reported it. You report to HSE yourself; there is no integration and there should not be one.
Who can see the incident log
Only your own company's administrators. Not clients, not employees, not subcontractors — including the subcontractor whose labourer was hurt.
Incident records name a person and describe an injury, which makes them health data and therefore special category personal data under UK GDPR. The counts are restricted too: on a three-man site, "one open RIDDOR report" identifies somebody just as surely as their name does.
For the same reason the safety pack — the PDF you hand an inspector or a main contractor — carries the plan, the assessments, the talks and the signature record, but never the incident log. The pack says so on its last page, so nobody thinks something has been hidden from them.
The safety pack
Safety → Download safety pack on any job. One PDF: the CDM position on the cover, the current construction phase plan section by section, every risk assessment with its before-and-after scores, and the page people never have — who read what, which version, and when.
It is built to be sent to somebody outside your company, which is why it contains no incident records and no pricing.
What BuildFlow will not decide for you
This is deliberate and worth being explicit about, because a confident wrong answer here is worse than no answer at all — somebody acts on it.
- Whether your job is notifiable. It applies the 30-day/20-worker limb and flags when the person-day bound clears 500. The judgement is yours.
- Whether an incident is RIDDOR reportable. It states the tests and records your answer.
- Whether a control measure is adequate. It scores what you tell it and shows you the residual risk. It cannot see your site.
- What to put in your plan or your RAMS. The prompts ask the right questions. The answers have to be about this job.
FlowAI will read the record, not write the assessment
Ask it whether the plan is issued, what is outstanding, or how many talks have been given, and it will tell you from the live record — including, bluntly, when work started before the plan existed. Ask it to write a risk assessment, judge whether a control is enough, or decide whether something is reportable, and it will decline and point you here or at HSE. It also never describes an individual incident, whoever is asking.
Where the answer matters and you are not sure, HSE's own guidance is free and written for small builders: its CDM 2015 pages at hse.gov.uk/construction/cdm, and its RIDDOR pages.