An annual survey gives you one dated data point a year, which satisfies the "we looked" part of the duty and struggles with the "we kept it under review" part; continuous measurement gives you a dated series, which answers both, at the cost of asking fewer questions each time. Neither is legally required, and anyone telling you otherwise is selling one of them.
Regulation 3(1) of the Management of Health and Safety at Work Regulations 1999 requires a suitable and sufficient assessment of the risks to employees' health. Regulation 3(6) requires the significant findings to be recorded in writing at five or more employees. Regulation 3(3) requires the assessment to be reviewed if there is reason to suspect it is no longer valid, or after a significant change. All three sit inside a wider duty, set out with the statutory text and the case law in the employer duty of care guide.
Note what is missing from all three. No method. No instrument. No cadence. No score.
HSE is explicit about this in relation to its own survey: "A survey is not an essential step and for smaller organisations it would not be proportionate to run such a survey, particularly where the same data can be gathered in other ways." It publishes a Talking Toolkit of six structured conversation templates for organisations that would rather talk, on the basis that those conversations "can replace the 'focus group' element of the Management Standards approach".
So this is not a compliance question with a right answer. It is a question about which method leaves you holding something you would be comfortable showing a claimant's solicitor.
An inspector, or a solicitor, asks the same four things in some order. What is your assessment of psychosocial risk? What were the significant findings? What did you do in response, and when? When did you last review it?
Foreseeability is why the third and fourth matter more than people expect. Under Hatton v Sutherland [2002] EWCA Civ 76, liability turns on what the employer knew or ought reasonably to have known, and to trigger a duty to act "the indications of impending harm to health arising from stress at work must be plain enough for any reasonable employer to realise that he should do something about it" (proposition (7), as reproduced in Easton v B&Q plc [2015] EWHC 880 (QB) at [50]).
That test is about sequence. Knowledge, then action, in that order, with dates on both. Any method that produces a picture but not a sequence is answering half the question.
Depth, mainly, and it is a real advantage.
HSE's Management Standards Indicator Tool runs to 35 items across a six-month reference period, mapping to seven subscales: demands, control, managerial support, peer support, relationships, role and change. Support splits in two because the factor analysis said it should, which is the sort of detail you only get from a long instrument. Nothing short reproduces that resolution. If you want to know whether your problem is the workload or the line managers, a long annual instrument will tell you and a three-question pulse will not.
A well-run annual survey also produces a genuine assessment artefact, and if it is framed, owned and filed as a risk assessment, it satisfies regulation 3(6) on its own terms.
Four things, and the first is the one that costs employers cases.
Currency. Regulation 3(3) makes the assessment an ongoing duty, and an annual instrument is current for a fraction of the year. Psychosocial conditions move with restructures, workload cycles and leadership turnover, which are exactly the events that make an assessment stale.
Sequence. One timestamp a year gives you twelve months of nothing between readings. Foreseeability cases turn on when you knew, and a single annual reading gives a very coarse answer to that question.
Framing. Most organisations run an engagement survey rather than a risk assessment. Engagement surveys measure different constructs on a different cadence, and are rarely owned or filed as risk assessments, so the regulation 3(6) record may not exist in a form an inspector would recognise even though the work was done.
Comparability. Change the questions, the scale or the supplier and no two years are comparable. This is not a hypothetical hazard: even national statistics suffer from it, and HSE's own stress series for 2018/19 to 2023/24 was revised in November 2025 when the underlying survey was reweighted. If your own series breaks every time procurement runs a tender, you have a set of snapshots and no trend.
There is also a quieter problem with response rates. HSE's own rule of thumb for its Indicator Tool treats above 50% as adequate and below 50% as data that "should be considered as indicative only, and treated with extreme caution". A once-a-year all-staff survey is a single roll of the dice on that number.
It answers regulation 3(3) by construction. Every round is dated, so the review cycle is not an activity you have to remember to schedule; it is a by-product of the thing running.
It produces the sequence the foreseeability test asks about: what you knew and when, then what you did next, with the dates already attached.
And it makes the evidence a residue rather than a project. The commonest gap we see is an annual survey with no actions log: the survey proves you knew, and nothing shows what followed, which is close to the worst evidential position available. Assembling that record retrospectively is a project, and projects get deferred until the week somebody asks. When the measurement runs continuously there is nothing to assemble, because the record already exists.
Three things, and they are real.
Breadth per round. A short pulse cannot carry 35 items. If you need to know precisely which of the six Management Standards areas is failing and by how much, a short instrument will point you at the neighbourhood and a long one will give you the address. A pulse works as the continuous layer, with a deeper instrument or structured conversations when it flags something.
Response rates still bite. Running more often does not make a low response rate acceptable; it just gives you more low-response readings. HSE's caution about treating sub-50% data as indicative only applies to any instrument, however frequent.
And no benchmarks. We do not publish norms, and we do not compare your results against other employers, because we do not have a defensible basis for it. Benchmarking is the standard upsell in this market. HSE's own free Analysis Tool contains no benchmark or percentile function at all; benchmarking sits in the paid product. The "85%" and "65%" figures that circulate as Management Standards targets were provisional thresholds from a 2004 pilot whose own HSE authors wrote that they "were essentially based on research that was indicative, rather than grounded", and no target percentage appears on any current HSE page. If a supplier shows you a benchmark, ask what population it came from and when.
One more caution that applies to both methods, and comes from the people who built the benchmarks: comparing mean scores means "it is possible to overlook individuals who believe they have poor working conditions". Averages are the right unit for a risk assessment and the wrong unit for noticing a person.
| Annual survey | Continuous measurement | |
|---|---|---|
| Legally required? | No | No |
| Depth per reading | High, if you use a full instrument | Low by design |
| Currency against reg. 3(3) | Weak for most of the year | Strong |
| Produces a dated sequence | No | Yes |
| Comparable over time | Only if nothing changes | Only if nothing changes |
| Tells you about an individual | No | No |
| Needs a budget | Usually | Not necessarily |
The row that decides it for most organisations is the sequence row, because that is the one the foreseeability test reads.
Run something continuous so the record exists, and go deeper when it points somewhere. That order matters: a deep instrument on an annual cycle tells you a great deal about one day, and a continuous instrument tells you when to look harder.
If you have no budget and few people, HSE's Talking Toolkit is a legitimate answer to the whole question. It is six conversation templates, one for each of the six HSE Management Standards, built so that smaller organisations "can gather data that larger organisations may gather through surveys". Recorded, dated conversations are evidence. HSE's own caveat is worth carrying: the Toolkit "should not be used in isolation as an employer's only response if there is an existing problem with work-related stress in the organisation".
Whatever you choose, the part that decides whether the record holds is not the instrument. It is the actions log underneath it, with owners, dates and closure notes, and someone senior who has seen the findings.
The full evidence picture is in how to evidence your duty of care, and the working document is the duty of care checklist.
The free strategy audit takes twenty minutes and gives you your gaps in writing. No card, no call booked at the end of it unless you ask for one.
Start the free audit →