Work at Height Regulations 2005 Compliance
A roof may look unchanged from ground level while its safety systems have become unfit for use. A corroded anchor, a damaged safety-line tensioner, an unprotected rooflight or an out-of-date inspection certificate can turn routine maintenance into an avoidable fall risk. Work at Height Regulations 2005 compliance is therefore not a certificate chase. It is the controlled management of every task, access route and fall-protection asset used above ground level.
For facilities and estates teams, the practical test is straightforward: could you show an auditor, investigator or insurer why work at height was necessary, how it was planned, what equipment was selected, who verified its condition and what happened when defects were found? If the records are incomplete, the control is incomplete.
What Work at Height Regulations 2005 compliance requires
The Regulations apply where a person could fall a distance liable to cause personal injury. This includes roofs, ladders, plant platforms, loading areas, fragile surfaces, internal voids and temporary access arrangements. The dutyholder must ensure work at height is properly planned, appropriately supervised and carried out by competent people.
The starting point is the hierarchy of control. Avoid work at height where reasonably practicable. Where it cannot be avoided, prevent a fall using collective protection such as guardrails, roof walkways, protected access and suitable working platforms. Only where prevention is not reasonably practicable should personal fall protection be used to minimise the distance and consequences of a fall.
That hierarchy matters because a harness and lanyard are not a default answer. A personal fall-arrest system depends on correct user behaviour, compatible equipment, a verified anchor point, sufficient clearance below the user and a credible rescue plan. A guardrail protects everyone using the route without relying on each person to connect correctly. The right control depends on the roof layout, task frequency, access requirements and foreseeable users, but the reasoning must be documented.
Planning must cover the real task
A generic risk assessment for ‘roof work’ will rarely withstand scrutiny. The plan should account for the specific work being undertaken: changing air-handling filters, servicing solar panels, inspecting gutters, accessing telecoms equipment or maintaining lightning protection. Each task changes where people travel, what they carry, how long they remain exposed and whether they need to work near edges or fragile rooflights.
It should also identify weather limits, access restrictions, exclusion zones, lone-working controls and emergency arrangements. If a worker could be suspended after a fall, a rescue plan must explain who will recover them, with what equipment and within what timeframe. Calling the emergency services alone is not a rescue plan.
Assess the roof and its safety assets together
Fall protection is a system, not a collection of individual products. A compliant roof-access strategy considers the route from the point of entry to the work area, including fixed ladders, hatches, parapets, walkways, edge protection, anchors, safety lines and rooflight protection.
An apparently serviceable safety line may offer little protection if the access ladder is unsafe or the route to the line crosses fragile roof sheeting. Equally, an anchor may pass a visual check but still be unsuitable because its structural fixing has not been verified, its identification tag is missing or the required clearance for fall arrest is unavailable.
A specialist inspection should establish what assets exist, where they are located, their condition, their intended use and whether they work together. Asset registers need to be site-specific and unambiguous. ‘Two anchors on roof’ is not adequate. Each item should have a unique reference, location, equipment type, inspection result, test history and supporting photographs.
British Standards support the evidence base
The Work at Height Regulations 2005 are law. British Standards do not replace those legal duties, but they provide recognised technical benchmarks for design, installation, testing and inspection. The standards that apply depend on the equipment and system configuration.
For example, permanent anchor devices are commonly assessed against BS EN 795, while roof safety systems may also require consideration of CEN/TS 16415 where more than one user is intended. Guardrail systems are assessed against relevant product and structural requirements. Fixed ladders, walkways, rooflights and access equipment each need their own technical assessment rather than a blanket statement that the roof is compliant.
The key point is traceability. A report should state the equipment standard, inspection method, pass or fail result, limitations of use and any action required. A certificate without equipment references, photographs or identifiable locations leaves too much room for doubt.
Inspection intervals are not optional reminders
Many permanent fall-protection systems require formal periodic inspection, often at least every 12 months, although manufacturer instructions, site conditions and risk assessments may require more frequent checks. PPE used for work at height also needs pre-use checks by the user and thorough examination at intervals appropriate to the equipment and its use. Lifting equipment or components used for lifting may introduce separate LOLER duties.
There is no safe assumption that last year’s certificate remains valid because the equipment has not visibly changed. Weather exposure, unauthorised use, corrosion, roof works and altered building fabric can all affect an installation. Missing certificates, expired inspection dates and untraceable assets should be treated as non-compliant by default until a competent inspection proves otherwise.
This is particularly relevant on multi-building estates. Inspection dates can drift when responsibility moves between managing agents, maintenance providers and capital-project teams. A controlled recertification schedule removes that ambiguity, provided it is tied to an accurate asset register rather than a spreadsheet copied forward each year.
Turn findings into controlled corrective action
A useful inspection does more than identify defects. It prioritises them. A loose guardrail fixing or failed anchor point may require immediate isolation and a clear instruction that the asset must not be used. Damaged labels, minor corrosion or incomplete drawings may need scheduled action, but should not be allowed to disappear into a general maintenance backlog.
Reports should distinguish between immediate safety-critical failures, defects requiring remediation before the next use, and improvement actions that strengthen longer-term compliance. Photographic evidence is essential. It prevents disputes about condition, helps procurement teams scope works accurately and gives contractors a clear basis for repair.
Where an asset fails, the response must be proportionate but decisive. Isolation signage, restricted access, alternative safe routes and a written remediation plan may all be required. Replacing a component without checking the wider system can simply move the risk elsewhere. The repair needs to be inspected, tested where applicable and recorded before the system returns to service.
Avoid gaps between inspection and handover
One common failure is fragmented responsibility. One contractor inspects the system, another quotes a repair, a third completes the work and nobody confirms whether the repair restored the original design intent. The building is left with paperwork, but no accountable chain of evidence.
A stronger approach keeps the inspection findings, remediation specification, installation records and recertification outcome connected. The same asset references should follow the work from initial survey to certified handover. This gives facilities managers a clean audit trail: what was found, why it mattered, what was done and when it was verified.
Sky Height Safety applies this approach through specialist in-house engineers, risk-prioritised pass/fail reporting and a written report issued within 48 hours. The objective is not to create more paperwork. It is to provide the certifications your auditor actually wants to see, with no missing paperwork and no subcontracted gaps in the chain.
What an audit-ready compliance file should contain
A defensible file combines operational planning with technical evidence. At minimum, it should contain the current risk assessment and method statement for routine roof work, an asset register, inspection and test certificates, defect reports with photographs, records of remedial work, user information and rescue arrangements. Training and competence records should also be available for those expected to use personal fall-protection equipment.
Keep installation drawings, manufacturer instructions and any structural verification records with the same file. They are frequently needed when a system is altered, extended or investigated after an incident. If the original information cannot be located, do not guess at capacities or permitted use. Arrange a competent survey and establish what can be verified.
Digital records are useful only when they remain current and accessible. A certificate stored in an inbox is not a management system. Assign ownership, set review dates and make sure site teams know where to find the latest status before authorising access.
Compliance is proved before somebody climbs
The strongest work-at-height control is the one that makes an unsafe decision difficult to take. Clear access rules, current certification, visible asset identification and a defined response to defects give managers control before a contractor reaches the roof hatch.
Treat every inspection as a decision point, not an annual administrative task. When the system is known, the limitations are clear and the evidence is current, work can proceed with purpose rather than assumption.