Take a free self-guided product tour to see our solutions in action Take a tour

Plan, Do, Check, Act (PDCA)

Glossary

Not found what you're looking for? Return back to the glossary index to find more business terms.

Return

Access a quick summary of the Plan, Do, Check, Act cycle (PDCA) with AI.

ChatGPT | Perplexity | Google AI

 

Plan, Do, Check, Act (PDCA) is a four-stage cycle for managing health and safety, recommended by the Health and Safety Executive (HSE) in its guidance HSG65. You plan what you want to achieve, do it by controlling risks, check whether those controls are working, then act on what you learn. The cycle then repeats.

The point of the cycle is the repetition. A risk assessment written once and filed is a document. The same risk assessment tested, measured, and revised each year is a management system.

 

What is Plan, Do, Check, Act?

Plan, Do, Check, Act is the framework the HSE uses to describe how effective health and safety management actually works. The HSE documented the move to it in the 2013 revision of HSG65, replacing the older POPMAR model. In the HSE’s own words, the change “achieves a balance between the systems and behavioural aspects of management” and treats health and safety “as an integral part of good management generally, rather than as a stand-alone system.”

Each stage answers a different question.

StageThe question it answersWhat it produces
PlanWhere are we now, and where do we need to be?Policy, objectives, responsibilities, and a measurement plan
DoWhat could harm people, and what are we doing about it?A risk profile, competent people, and controls in place
CheckAre those controls actually working?Monitoring data, audit findings, incident investigations
ActWhat have we learned, and what changes as a result?Reviewed plans, closed actions, updated risk assessments

Read down that final column, and you have a health and safety management system. PDCA is not a separate initiative that sits alongside your safety work. It is a description of the shape that work should take.

 

Is Plan, Do, Check, Act a legal requirement?

The cycle itself is not written into law, but what it describes almost is.

Regulation 5 of the Management of Health and Safety at Work Regulations 1999 requires every employer to make arrangements for the “effective planning, organisation, control, monitoring and review of the preventive and protective measures.” Line those five words up against the cycle and the overlap is hard to miss – planning and organisation sit in Plan and Do, control sits in Do, monitoring sits in Check, and review sits in Act.

An inspector may ask how you plan, monitor, and review. Following the cycle is a straightforward way of being able to answer.

Above that sits the Health and Safety at Work etc. Act 1974, which places the general duty on employers to ensure the health, safety and welfare of employees so far as is reasonably practicable. PDCA is the HSE’s own answer to the obvious follow-up question – how?

 

The four stages of Plan, Do, Check, Act

The HSE sets out what belongs in each stage in HSG65. Here is what each one covers, and what it looks like when it is working.

Plan

Decide where you are going, who is responsible, and how you will know if you got there.

In practice, the Plan stage covers:

  • Determining your policy. What your organisation commits to, who wrote it, and who was consulted. The HSE is clear that a policy is only useful if it is a live part of how the organisation runs, not a signed page in a folder.
  • Setting objectives and responsibilities. What you want to achieve, and who owns each part of it.
  • Deciding how you will measure performance. This is the part most often skipped. The HSE specifically warns against relying on accident figures alone and asks for “active indicators as well as reactive indicators” – what we would now call leading and lagging indicators.
  • Planning for change and for emergencies. Including fire, and co-ordinating with anyone who shares your workplace.
  • Identifying the legal requirements that apply to you. Which regulations, approved codes of practice and standards bite in your sector.

If you cannot say how you will measure success before you start, you have not finished planning.

 

Do

Understand your risks, organise your people, and put the controls in place.

The HSE splits ‘Do’ into three parts.

Profile your organisation’s health and safety risks. Identify what could cause harm, who it could harm and how, and what you will do about it. Then decide priorities and identify the biggest risks. This is risk assessment, and the output is a ranked picture of exposure rather than a pile of paperwork.

Organise for health and safety. HSG65 covers control within the organisation and the role of supervisors, managing contractors, co-operation, communication, competence, capabilities and training, and getting specialist help where you need it. Four of those – control, co-operation, communication and competence – are widely taught as the “four Cs” of safety management, and the HSE uses that shorthand in its workplace transport guidance.

Implement your plan. Put the preventive and protective control measures in place, provide the right tools and equipment, and deliver the training, instruction and supervision that make them stick. This is where safe systems of work, method statements and permits to work sit.

Do is the largest stage by volume of work. It is also the one that generates the evidence the next stage depends on.

 

Check

Find out whether what you planned is actually happening, and whether it is working.

There are two distinct jobs in Check, and they answer different questions.

Measure performance. The HSE asks you to confirm that “your plan has been implemented” and to “assess how well the risks are being controlled and if you are achieving your aims.” That splits into:

  • Active monitoring – checking before anything goes wrong. Inspections, safety observations, audits, checklists, and training records.
  • Reactive monitoring – checking what already went wrong. Incidents, near misses, RIDDOR reports, ill-health data, and lost time incidents.

Investigate the causes of accidents, incidents and near misses. Not just what happened, but why. A good incident investigation gets to root cause, because a cause you have not identified is a cause you cannot control.

Check is the stage POPMAR was accused of under-weighting, and it is still the stage where most organisations are weakest. More on that below.

 

Act

Decide what changes, change it, and prove it changed.

Act has two parts in HSG65.

Review performance. Learn from accidents and incidents, ill-health data, errors and relevant experience. Then revisit plans, policy documents and risk assessments to see whether they need updating. This is the board-level and senior-management conversation – the one where safety data meets decisions about resources.

Learn lessons and act on them. Including lessons from audit and inspection reports. HSG65 talks about organisational learning and human factors here.

Act is where the cycle either closes or stops. If a review produces findings that never become owned, dated actions, the loop is broken, and next year’s review will find the same things.

 

Plan, Do, Check, Act example: reducing manual handling injuries

Abstract cycles can be difficult to picture; here is a worked example.

StageWhat you doWhat you can show for it
PlanManual handling is the largest injury category. Set an objective to cut manual handling injuries by 30% over 12 months. Name the operations director as owner. Decide the measures up front – injury rate as the lagging indicator, observation volume and action closure rate as the leading ones.A written objective with an owner, a target, a deadline, and named measures
DoReassess manual handling tasks site by site. Reduce the heaviest lifts through mechanical aids and repackaging. Retrain teams on the revised safe system of work. Brief supervisors on what to look for.Updated risk assessments, purchase records, training records, briefing sign-offs
CheckSupervisors run weekly task observations. Monthly inspections check aids are available and in use. Every manual handling incident and near miss is investigated to root cause. Report the four measures monthly.Observation and inspection records, investigation reports, a trend dashboard
ActThe review finds injuries down, but concentrated on one shift where aids are shared between two areas. Buy a second set. Update the risk assessment. Fold the finding into next year's plan.A dated review record, closed corrective actions, a revised risk assessment

Menzies Distribution Solutions worked through this pattern with Notify and reduced LTAs and RIDDOR incidents by 40%. City Plumbing Supplies took the same approach to lifting and handling and saw a 75% reduction in manual handling incidents.

 

What to measure at each stage of the cycle

The Plan stage asks you to decide your measures before you start. This is the part safety leaders most often ask for help with, so here is a starting set.

StageLeading indicatorsLagging indicators
PlanObjectives with named owners and dates; % of risk assessments in dateN/A
DoTraining completion rate; % of high-risk tasks with a current assessment; contractor inductions completedN/A
CheckObservations submitted per 100 workers; inspections completed vs scheduled; audit non-conformances raised; % of incidents investigated to root causeInjury rate; accident frequency rate; RIDDOR count; days lost
ActAction closure rate; average time to close a corrective action; % of reviews producing dated actionsRepeat incidents by cause; recurrence of the same audit finding

Two of these deserve special attention, because they are the ones that tell you whether the cycle is actually turning.

Action closure rate tells you whether Act is real. Actions raised but not closed mean the loop is open.

Repeat findings tell you whether learning is sticking. The same audit non-conformance appearing two years running is not an audit problem. It is an Act problem.

 

Plan, Do, Check, Act vs POPMAR

Before the 2013 revision of HSG65, the HSE described safety management through POPMAR – Policy, Organising, Planning, Measuring performance, Auditing and Review.

The elements didn’t disappear; they were regrouped.

POPMAR elementWhere it sits in PDCA
PolicyPlan
PlanningPlan
OrganisingDo
Measuring performanceCheck
AuditingCheck
ReviewAct

The HSE’s stated reason for the change was balance. The move to Plan, Do, Check, Act, HSG65 says, “achieves a balance between the systems and behavioural aspects of management” and “treats health and safety management as an integral part of good management generally, rather than as a stand-alone system.”

In other words, the problem was not that POPMAR listed the wrong things. It was that a list invites you to work through it once, whereas a cycle does not let you stop. The change also aligns UK guidance with the ISO standards, which reduces duplicated effort for organisations certified to more than one.

If your safety management system documentation still uses POPMAR headings, it is not wrong. It is just harder to map onto ISO 45001 during an audit.

 

How Plan, Do, Check, Act maps to ISO 45001

ISO 45001 is built on the PDCA cycle, which is why certification and the HSE-aligned practice pull in the same direction.

StageISO 45001 clauses
PlanClause 6 – Planning (hazard identification, risk and opportunity assessment, objectives)
DoClause 7 – Support (resources, competence, awareness, communication, documented information) and Clause 8 – Operation
CheckClause 9 – Performance evaluation (monitoring, measurement, internal audit, management review inputs)
ActClause 10 – Improvement (incident, nonconformity and corrective action, continual improvement)

Two clauses sit around the cycle rather than inside a single stage. Clause 4 establishes the context of the organisation, and Clause 5 – leadership and worker participation – runs through all four stages. That placement is deliberate. A cycle without leadership behind it turns slowly, and one without worker participation turns on bad data.

If you are working towards certification, the practical implication is useful – the evidence you generate by running PDCA properly is very close to the evidence an ISO 45001 audit asks for.

 

Where the cycle breaks down

These are the five failure patterns we see most often in the safety functions we work with.

1. The cycle straightens into a line. Act produces a review document, the review document is filed, and next year’s Plan starts from scratch rather than from last year’s findings. The test is simple – can you trace a specific change in this year’s plan back to a specific finding from last year’s review?

2. Check runs on lagging indicators only. Injury rates tell you what already happened. They are also a poor sample – a quiet quarter may mean your controls are working or may mean you got lucky. Active monitoring gives you a bigger, earlier dataset to steer with.

3. Actions are raised but never closed. This is the single most common break, and the most damaging, because it teaches people that reporting achieves nothing. When someone reports a hazard and nothing visibly changes, they stop reporting – and your Check stage loses its best source of data.

4. The plan is written for the auditor. A policy nobody in operations has read cannot shape behaviour. The HSE’s insistence that policy be part of the organisation’s culture and values, not a document, is aimed squarely at this.

5. The evidence lives in five different places. Risk assessments in a shared drive, inspections on paper, incidents in a spreadsheet, actions in someone’s inbox. Each stage may be running, but nobody can see the cycle as a whole – so nobody can tell whether it is turning. This is usually the underlying cause of failures one to three rather than a separate problem.

 

How does Notify support each stage of Plan, Do, Check, Act?

Notify is a health and safety software solution built for proactive risk management. The cycle maps onto the platform stage by stage.

Plan. Set objectives and hold your policy and supporting documents in Document Management, with version control and read receipts so you can show who has seen what. Configure the measures you decided on as dashboards before the work starts, rather than assembling them retrospectively.

Do. Build and issue risk assessments and RAMS from reusable templates, so a control added once can be applied everywhere the same task is done. Assign and evidence training through ISO training.

Check. Frontline teams submit observations, hazards and incidents from the mobile app in seconds, with photos and geo-tags, online or offline. Scheduled audits and inspections run from custom templates with non-conformance logging. Investigations capture root cause rather than just description.

Act. Action Tracking gives every corrective action an owner, a due date and an escalation path, so closure is visible rather than assumed. Safety Intelligence Dashboards show all four stages in one place, and Notify Spark, our AI companion, surfaces the trends and repeat causes worth putting in front of the board.

 

What that looks like in practice:

  • Menzies Distribution Solutions – 40% reduction in LTAs and RIDDOR incidents
  • City Plumbing Supplies – 75% reduction in manual handling incidents
  • Product Care Group – 200% increase in positive observations
  • NWF Agriculture – 230% increase in hazard reporting
  • Regional Water Authority – 300% increase in near-miss reports

Every one of those numbers came from the same place – making the Check stage easy enough that people actually use it, and the Act stage visible enough that they trust it. Check out our case studies to learn more.

Book a free, no-obligation demo to see how Notify evidences each stage of the cycle.

FAQs

No. PDCA is guidance, not law. However, Regulation 5 of the Management of Health and Safety at Work Regulations 1999 requires employers to make arrangements for the effective planning, organisation, control, monitoring and review of preventive and protective measures, which is what the cycle describes. Following PDCA is a practical way to meet that duty and to evidence it.

Nothing. PDCA is the acronym for Plan, Do, Check, Act.

Plan, Do, Check, Act replaced POPMAR (Policy, Organising, Planning, Measuring performance, Auditing and Review), a change the HSE documented in the 2013 revision of HSG65. The elements were regrouped rather than removed. The HSE’s stated reason was that PDCA “achieves a balance between the systems and behavioural aspects of management” and treats health and safety as part of good management generally rather than a stand-alone system.

There is no fixed interval, and in practice several cycles run at once at different speeds. A full management review typically runs annually, aligned to your reporting year. Monitoring in the Check stage runs continuously – daily or weekly observations, monthly inspections, quarterly audits. Individual issues turn much faster: a near miss reported on Monday can produce a control change the same week.

Responsibility is shared, which is the point. The HSE places accountability for direction and review with the employer’s board and senior leadership. Managers and supervisors own delivery in the Do stage and much of the monitoring in Check. Frontline workers supply the majority of Check-stage data through observations, near-miss reports and incident reporting. A cycle owned only by the safety team is a cycle running on partial information.

Yes. ISO 45001:2018 is structured around PDCA. Clause 6 covers Plan, clauses 7 and 8 cover Do, clause 9 covers Check, and clause 10 covers Act. Clause 4 (context of the organisation) and clause 5 (leadership and worker participation) sit around the cycle rather than within a single stage.

HSG65 is the HSE’s guidance publication Managing for health and safety, currently in its 2013 revision. It is aimed at directors, managers and health and safety professionals, and sets out the Plan, Do, Check, Act approach in detail. The HSE also publishes a shorter free introduction, INDG275, titled Plan, Do, Check, Act: An introduction to managing for health and safety.