Back to blog
    What Makes a Fire Risk Assessment "Suitable and Sufficient" — and Can a Tick-Box Report Get You There?

    What Makes a Fire Risk Assessment "Suitable and Sufficient" — and Can a Tick-Box Report Get You There?

    Risk Assessment23 April 2026· Jasper Bartlett

    If your fire risk assessment software works by having you tick boxes and select from dropdown menus, here's a question worth sitting with: could the report it produces actually withstand scrutiny from an enforcing authority?

    It's not a hypothetical. Since BS 9792:2025 replaced PAS 79-2 as the housing-specific standard, the expectations around how assessments are documented — and how professional reasoning is evidenced — have shifted. The nine-step methodology, the structured pro forma in Annex A, and the standard's emphasis on qualitative assessment all point in the same direction: assessors need to show their working, not just their answers.

    That has implications for the tools you use to produce your reports.

    The "suitable and sufficient" test isn't about coverage — it's about reasoning

    Most assessors understand the legal requirement. The Fire Safety Order requires the responsible person to ensure a suitable and sufficient fire risk assessment is carried out, kept under review, and its significant findings recorded. BS 9792, while not legislation, is the current recognised framework for demonstrating that a housing FRA meets that standard.

    But here's where a lot of assessment software creates a problem it doesn't acknowledge. Ticking a box that says "fire doors inspected" tells a reviewing officer that you looked at the fire doors. It doesn't tell them what you found, why it matters for this particular building, or how it informed your overall assessment of risk. A tick against "means of escape adequate" doesn't explain whether that judgement accounts for the mobility profile of residents on the third floor, the storage patterns in the communal hallway you walked past, or the fact that the building's stay-put strategy depends on compartmentation you couldn't visually verify.

    BS 9792 expects more than coverage. It expects the assessor to describe what they observed, explain the reasoning behind their risk judgements, and connect their findings to the specific characteristics of the building and its occupants. The pro forma in Annex A isn't a checklist to be completed — it's a structured framework for capturing professional narrative. Every section asks the assessor to record not just what was inspected but what was found, what was excluded and why, and what evidence supports the conclusions drawn.

    A tick-box report can demonstrate that an assessor visited a building and worked through a list. Whether it demonstrates a suitable and sufficient assessment is a different question — and increasingly, it's the question that matters.

    The checklist isn't the problem. The architecture is.

    To be fair, there's nothing inherently wrong with a checklist. Experienced assessors use mental checklists on every site visit to make sure they haven't missed a section of the building or a category of hazard. BS 9792 itself provides a structured pro forma that works through specific topics in sequence.

    The problem arises when the checklist becomes the assessment rather than a scaffold for it. When software is only built around agree/disagree statements and pre-populated comments and recommendations, the tool is making a structural decision about what kind of output is possible. The assessor's professional judgement — the part that actually makes an assessment suitable and sufficient — gets compressed into the gaps between predetermined options.

    Consider what happens on a site visit to a 1960s converted block with a stay-put strategy. The assessor notices that flat entrance doors on the second floor have been replaced with non-compliant units, the riser cupboard on the ground floor shows signs of poor fire stopping around service penetrations, and residents have mentioned that the communal fire alarm hasn't sounded during recent testing. These aren't three separate checklist items. They're interconnected findings that collectively shift the risk picture for the building. The significance of non-compliant entrance doors depends on whether compartmentation is otherwise intact. The fire stopping concern changes the assessor's confidence in the stay-put strategy. The alarm issue raises questions about management and maintenance regimes.

    A tick-box tool records them as three separate lines, each generating its own pre-populated action, with no mechanism for the assessor to explain how they relate to each other or why the overall risk rating reflects their combined effect. A qualitative assessment connects these observations into a coherent risk narrative.

    That distinction matters when an enforcing authority reviews the report. It matters even more if something goes wrong.

    What BS 9792 actually asks your report to demonstrate

    The standard's nine-step methodology isn't just a process to follow — it's a framework for the kind of thinking the report needs to evidence. A few elements are worth highlighting for what they demand of your documentation:

    Step 1: Information gathering. Before the site visit, the assessor should review previous FRAs, fire strategies, as-built plans, and maintenance records. The report needs to show what information was available, what was missing, and how gaps affected the scope of the assessment. A tick-box template typically doesn't have a section for "what I couldn't verify and why that matters."

    Steps 3 and 6: Assessing likelihood and consequence. BS 9792 provides for a transparent risk matrix, but it expects the methodology to be clearly documented — not just the outcome. Whatever system you use to express risk levels, each rating needs a definition of what it means in practice and a rationale connecting it to observed conditions.

    Step 8: Prioritised management action plan. Actions need to be linked to specific findings, ordered by urgency and risk significance, and accompanied by proposed timescales. This requires the assessor to exercise judgement about relative priority — something that auto-generated action lists struggle to support.

    Step 9: Review interval. The assessor must recommend when the FRA should next be reviewed, justified by the building's risk profile. BS 9792 provides guidance on intervals (annually for higher-risk buildings, every two years for lower-risk) but the assessor needs to explain why the recommended interval is appropriate for this building. That explanation belongs in the report.

    Each of these steps requires narrative. Not ticks. Not selections. Written reasoning that a competent person could follow and a reviewing officer could scrutinise.

    Where does technology actually help?

    If tick-box tools create a ceiling on report quality, the answer isn't to abandon technology and go back to pen, paper and Microsoft Word. The answer is technology that works with professional reasoning rather than replacing it.

    The most time-consuming part of a fire risk assessor's job isn't the site visit — it's turning site observations into a structured, well-written report. Assessors know what they've found. They can explain it clearly if you put them in front of a building manager. The bottleneck is the hours spent at a desk translating observations, photographs, and professional judgement into formal report language, organised under the right headings, expressed with the right precision.

    That's the problem FireCheckr is built to solve. Instead of funnelling your findings through a checklist, FireCheckr lets you capture your observations in your own words — on site, as you see them. You talk through what you've found, note the things that concern you, describe the conditions as they actually are. FireCheckr's AI then organises those findings into the correct sections of a structured report, drafted in clear professional language. It doesn't invent findings. It doesn't make risk judgements. It doesn't decide what matters and what doesn't. It takes what you've said and puts it where it belongs, in a format that reads like the report of a competent assessor — because it is.

    The result is a qualitative, narrative-driven assessment that evidences your reasoning, not a tick-box output that obscures it. And because you're spending less time on report formatting, you can spend more time on the bit that actually makes an assessment suitable and sufficient: being on site, looking at the building, and thinking.

    If you're an assessor who wants your reports to reflect the standard of work you actually deliver, book a demo and see how FireCheckr works in practice.