The risk assessment wasn't the failure. The open actions were

Written by The BlueWave team · Published 11 June 2026 · 6 min read

General information, not legal or regulatory advice — your duties need your own competent advice.

Read the enforcement notices closely and a pattern shows up. The legionella risk assessment is rarely the thing that gets a company prosecuted. What gets prosecuted is the list of actions that assessment produced, sitting untouched, while the risk it described carried on unchecked.

Amey Community Ltd is the case to sit with. A risk assessment carried out in 2016 identified the risk. Then, on the findings that mattered, nothing happened: no written scheme of control, and water temperatures not monitored in October and November 2017. Graham Butterworth, 71, contracted Legionnaires' disease at HMP Lincoln and died. The fine was £600,000. The assessment existed. It had even found the problem. It was treated as the finish line rather than the starting gun.

The gap is where the prosecutions live

BUPA Care Homes tells the same story on a longer timeline. The company was fined £3,000,000 in 2019 after 86-year-old Kenneth Ibbetson died of Legionnaires' disease contracted at one of its homes. The court heard there was no proper system for flushing, records had been faked, the responsible manager was untrained, and warnings had gone unheeded since 2012. Seven years of warnings. The problem was never a lack of knowledge. It was that knowing changed nothing.

Sanctuary Housing shows the pattern is not a relic of the 2010s. In October 2024 the housing provider was fined £900,000 after all 44 samples taken at a sheltered housing scheme came back positive for legionella, in a building full of exactly the older residents the regime exists to protect. Positives at that scale do not appear overnight. They accumulate while a control scheme is nominally in place and nobody acts on what the results are saying.

Across these cases the assessment, or the warning, did its job. It named the hazard. The organisation then behaved as though naming the hazard reduced it, which it does not. A risk you have documented and not acted on is arguably worse than one you never assessed, because now there is a written record of you knowing.

Why the fines stopped being survivable

If these numbers look larger than legionella fines used to be, they are, and the change was deliberate. The Definitive Guideline for health and safety offences that came into force in February 2016 bases the fine on the organisation's turnover and on the risk of harm created, not solely on the harm that actually happened. You do not need a death for the numbers to hurt. Under the guideline, median fines for large organisations rose from around £25,000 to £370,800.

The guideline is not reserved for the giants. Tendring District Council was fined £27,000 over some ten years of inadequate legionella training, and the judge was pointed about the discount it received for being public: the fine "would have been 10 times higher, had it not been a public body". Ten years of a known training gap is an open action of a different kind, left open until enforcement closed it for them.

That is the point that should change behaviour. The old mental model, no outbreak so no real exposure, is gone. A monitoring programme with a year of gaps in it creates risk of harm whether or not anyone fell ill, and that is now what the fine is calculated against.

Run an open-actions register and actually close it

The fix is unglamorous and it works. Every finding from a risk assessment, and every failed monitoring result, whether a temperature reading out of parameter or a positive sample, becomes an action with two things attached: a named owner and a due date. No owner means no one is doing it. No date means it is not scheduled, which means it is not happening.

What goes in a row should be specific enough to act on without a phone call. "TMV issue, upstairs" is not a row. "TMV3 on the second-floor washroom failing at 41°C, owner J. Ross, re-check due in 14 days" is a row. And "closed" has to mean verified, not "the engineer says it is done". An action you marked closed on trust is an open action wearing a disguise, and it is the one that surfaces in an investigation. A register at that resolution also survives a change of staff, because the next person can read it, which a shared memory cannot.

Then it needs a review rhythm. Once a month, someone senior enough to chase people looks at the open actions and asks what has moved. The review does not need to be long. It needs someone with authority reading the overdue items back to the people who own them, because discomfort is the mechanism, and a register that never embarrasses anyone is decoration. An action log nobody reads is the same as no log, with extra filing.

A short, honest register beats a long, aspirational one. Ten open actions with real dates and a person against each is a controlled site. Forty vague "ongoing" items is a site that has stopped counting.

Be careful who marks their own homework

One structural weakness deserves naming. It is common for the same contractor to carry out the risk assessment and then win the remedial work it recommends. That is not automatically wrong, and often the assessor is the right firm to do the fixing. But the findings still deserve follow-through that someone other than the contractor can see and check.

If the assessor's report lists twelve actions and the duty holder never reads past the summary, the loop is closed by the one party with a commercial interest in how it is closed. Keep the actions in your own register rather than in the assessor's PDF. Sign them off yourself. The duty to control the risk stays with the duty holder no matter who holds the clipboard, and the duties under ACOP L8 do not transfer with it. The assessment is not a permanent artefact either; it needs review when the building changes, which is its own widely misunderstood rule.

None of this is complicated, which is what makes the prosecutions so bleak. Amey did not lack the knowledge. It lacked the follow-through, and a man died in the gap.

This is the specific gap BlueWave is built to close. Findings and failed checks become actions with an owner and a date, and they stay on the compliance record until someone marks them done, carrying the timestamp of who closed them and when. Overdue actions surface as overdue rather than sinking to the bottom of an inbox, so the monthly review has something concrete to chase instead of a vague sense that things are probably fine.

If you do one thing after reading this, open your last risk assessment and count the actions it raised. Then find out, from a record and not from memory, how many are closed. The distance between those two numbers is your actual exposure.

The work these posts describe, run properly

BlueWave books the work in, captures the evidence on site, and turns it into records a client or an auditor can actually use. See it on your own workflow.

The risk assessment wasn't the failure. The open actions were | BlueWave