Skip to main content
Got a site safety question? Ask UAE HSE practitioners in the community Q&A.Ask the community
Site Safety UAE — construction site safety software logoSite Safety UAE
Login

Article

MSRA, HIRA and RAMS: What Each One Is For on a UAE Site

MSRA, HIRA and RAMS are often used interchangeably on UAE sites. Here is what each document is for, what belongs in it, and what a client HSE reviewer or authority inspector opens first.

6 October 2026 6 min readBy Site Safety UAE
MSRA, HIRA and RAMS: What Each One Is For on a UAE Site

On the same UAE project you can be asked three different things in one week: the client's HSE manager asks for the MSRA before a high-risk activity starts, a consultant sends a transmittal demanding RAMS for the same work, and an ISO 45001 auditor wants to see the project HIRA and how it was used.

They are not competitors, and they are not three versions of the same paperwork. They sit at different levels of the same system. Sites that treat them as interchangeable end up producing three documents that contradict each other — and that contradiction is what gets picked apart in an audit or after an incident.

This guide sets out what each one is for, what belongs in it, and what actually gets opened when someone comes to review your project.

The three documents in one sentence each

  • HIRA — Hazard Identification and Risk Assessment. The project-level analysis: everything on this site that can hurt someone, ranked, with the controls and the owners. It is the map.
  • MSRA — Method Statement Risk Assessment. The task-level pack for a specific activity or high-risk operation: how the work will be done, step by step, and the risk assessment that goes with each step. It is the route.
  • RAMS — Risk Assessment and Method Statement. The same pairing under a different name, used widely across GCC contracting and client document-control systems. In practice, if a client asks for "RAMS", they are asking for the method statement and its risk assessment issued as one controlled document.

The acronyms travel because of who wrote the client's procedures. The substance underneath is the same three questions: what can go wrong here, how are we doing the work, and what stops it going wrong.

What belongs in each

DocumentLevelCore contentReviewed when
HIRAProjectAll identified hazards, initial and residual ratings, controls in hierarchy order, owners, review triggersMobilisation, scope change, quarterly, after any serious event
MSRAActivitySequence of work, plant and materials, people and competence, permits required, step-by-step hazards and controls, emergency arrangements, signaturesBefore the activity starts, and whenever the method, crew, plant or conditions change
RAMSActivitySame as MSRA where the client uses that term — method plus assessment, controlled and revision-numberedSame triggers as MSRA

A practical rule: one HIRA per project, one MSRA or RAMS per high-risk activity. If you are writing a HIRA for each task, you are writing method statements with the wrong title. If you have a single document covering the whole site as a "risk assessment", you do not have a HIRA — you have a summary nobody can act on.

When a site needs all three

Most UAE projects can run on two layers:

  1. The project HIRA as the master picture, owned by the project HSE lead and reviewed on a fixed cadence.
  2. An MSRA or RAMS per high-risk activity, raised before the activity and named in the permit that authorises it.

You only need a third artefact when the client's own document-control system requires a specific format — for example, a RAMS transmittal with a client comment-resolution sheet. That is a formatting requirement, not a different assessment. Never let it become a second, silently diverging picture of the same risk.

What gets opened first

When a client HSE reviewer, a consultant or an authority inspector visits, the documents are almost never read cover to cover. The sequence is usually:

  • The permit or high-risk work authorisation for what is happening on site today
  • The method statement and its risk assessment referenced by that permit, including the revision and approval date
  • The briefing record showing the crew who are doing the work received it, with names and signatures
  • The competence and certification for the operators, riggers, scaffolders or entrants named in the pack
  • The inspection or verification records for the controls the assessment relies on — scaffold handover, lifting accessory inspection, isolation, gas testing
  • The close-out, showing the work finished and the controls were removed in a controlled way

If any one of those links is missing, the assessment stops being evidence and becomes an assertion. That is the moment a well-run site starts looking disorganised.

The five failures that cause most rejections

  1. Copy-paste between projects. A method statement from a different high-rise, with different access, different plant and a different crane, is transparent to anyone who knows the site.
  2. Controls that ignore the hierarchy. "Trained operatives, PPE and supervision" is not a control set. Say what physically changes — the sequence, the guarding, the exclusion, the isolation.
  3. No revision when the method changed. The pack says one formwork system; the site is using another, or the lift plan changed after a plant substitution. The document must carry the change.
  4. No briefing record, or a signature sheet with 40 names and no task. Inducted-on-site is not briefed-on-this-method.
  5. No linkage to the permit. A perfect MSRA for hot work that is not referenced by the hot work permit, or does not list the fire-watch arrangements the permit conditions depend on, breaks the chain at exactly the point where enforcement happens.

A pattern that works

  • Keep one master HIRA that is genuinely current, with named owners for the top-ranked items.
  • Raise an MSRA/RAMS per high-risk activity from a controlled template with the right sections already present.
  • Attach the assessment to the permit conditions, so the person issuing and the person receiving both see it.
  • Record the briefing against the task and the crew, not against the site induction.
  • File the verification records for critical controls alongside the pack, so the evidence is in one place when it is asked for.
  • Revise and re-issue when plant, crew, method, sequence or season changes — and say in the revision note what changed.

That structure also survives the interrogation that follows an incident: what was assessed, who knew about it, what was physically in place, and who verified it.

The evidence pack worth keeping

For each high-risk activity, a reviewer should be able to find, without asking anyone: the current method statement and risk assessment with revisions, the approval and the briefed crew, the permit that authorised it, the competence records, the control verification records, the monitoring during the work, and the close-out.

Where that pack exists in one place, inspection is a retrieval exercise rather than an argument. Where it is scattered across a shared drive, a WhatsApp group and a folder on a supervisor's laptop, every review costs days.

If the project-level risk picture and the task-level packs are drifting apart, the fix is usually structural — controlled documents with revisions, expiry alerts on certificates, and permits that cannot be issued without the assessment attached.

"Reference material, not legal advice. Requirements differ by emirate, authority and client."

Continue with

  • Documents & MSRA/RAMS module — https://sitesafetyuae.com/modules/documents — controlled documents, HIRA/MSRA library, revision control and expiry alerts
  • Permits & High-Risk Work module — https://sitesafetyuae.com/modules/permits — permit-to-work, hot work, confined space, LOTO and SIMOPS
  • Risk Register Best Practice — https://sitesafetyuae.com/resources/site-risk-register-best-practices — keeping the project register live rather than archived
  • UAE Construction HSE Documentation Checklist — https://sitesafetyuae.com/resources/uae-construction-hse-documentation-checklist — what a document-controlled HSE file should contain
  • ISO 45001 Implementation Guide (UAE, 2026) — https://sitesafetyuae.com/resources/iso-45001-implementation-guide-uae-2026 — where hazard identification sits in the management system

Site Safety UAE builds the HSE Operations Dashboard for UAE and GCC construction projects. Documents, permits, inspections, training and audit evidence in one place — start free, no card required — https://sitesafetyuae.com/get-started.

UAE HSE Legal Guide 2026

The consolidated PDF: federal and emirate-level HSE obligations, authority responsibilities and the evidence each inspection expects. Sent to your inbox.

Get the free guide

Browse everything in the UAE HSE Compliance Hub.

For safety officers

Sign in to the safety officer portal for your daily reports, the hazards whose controls still need verifying, and the authority forms waiting on a decision.

See it in action

Site Safety UAE is a software-only platform. Watch the recorded demo to see the modules covering your project scope and authority mix.

Watch the demo
Risk AssessmentMSRARAMSHIRAUAE RegulationsHigh-Risk Work

Next step

Turn this into evidence you can hand over

Practical UAE HSE guides, worked examples and authority walkthroughs — written for people who have to produce the evidence.

  • Built around UAE authoritiesADOSH-SF, Trakhees, DM, DCD, MOIAT and ISO 45001 structures.
  • Usable the same dayTemplates and registers are pre-filled with your company details.
  • Evidence, not just formsEvery record carries dates, signatures and an export you can hand over.