Skip to content

HSE inspections up 47% - HSE carried out over 13,200 workplace inspections in 2024/25.

Health and Safety for IT and Software Companies: DSE, Hybrid Working,Due Diligence, and Compliance

Qualified IT and software health and safety consultants. DSE assessments for software engineers · Hybrid and remote working risk assessments · Investor and customer due diligence support · Fire risk assessments · Psychosocial risk · Compliance for SaaS, software, and IT services businesses across the UK and 50+ countries.

IT and software companies typically discover workplace health and safety the hard way: an enterprise customer's procurement team requests it during onboarding, an investor's due diligence pack asks for the documentation, a tribunal claim references a missing DSE assessment, or a Series B legal review flags the absence of an appointed competent person. The physical risk is genuinely low. The legal obligation is not. HSWA 1974, MHSWR 1999, the DSE Regulations 1992, and the RRO 2005 apply identically regardless of risk level. Arinite provides the documentation set that satisfies the duty without consuming engineering time, configured specifically for distributed and growth-stage software businesses.

1,500+ businesses
50+ countries
95%+ retention
Qualified Consultants
UK & International
Free Gap Analysis
Get in Touch

Contact Arinite Today

Fill out the form below and our team will get back to you within 24 hours.

By submitting, you agree to our Privacy Policy and consent to Arinite contacting you.

ABOUT

About This Sector

IT and software covers a wide spectrum: pre-seed and seed-stage SaaS startups, growth-stage software businesses, scale-ups, publicly listed software companies, IT services and managed service providers, IT consultancies, cyber security firms, fintech and insurtech, devtools businesses, and the in-house IT functions of larger employers. The compliance profile is almost entirely office and hybrid, with several patterns common across the sector:

A distributed engineering workforce working from home, office, co-working spaces, and travel locations. Investor and customer due diligence cycles that periodically require documented H&S evidence. Office moves between WeWork-style serviced offices that complicate fire risk and DSE documentation. A workforce culture that often deprioritises workplace H&S until commercial pressure forces it onto the roadmap. And a leadership team that wants the duty discharged with minimum drag on engineering and product velocity.

Arinite provides Qualified consultants and compliance software to IT and software businesses across the UK and 50+ countries, from early-stage SaaS startups through to publicly listed software companies and global IT services firms.

COMPLIANCE GAPS

Common Compliance Failures We Find in
IT and Software Companies

These are the IT and software health and safety failures Arinite's Qualified consultants find most frequently. Each one is a real exposure to HSE enforcement, civil claims, customer audit failure, investor due diligence findings, and director liability under Section 37 HSWA 1974.

No DSE assessment for home and hybrid workers

The single most common gap. Every habitual screen user, regardless of work location, is in scope under the Display Screen Equipment Regulations 1992. For most software companies, that is the entire engineering, product, design, and commercial team.

No competent person appointed

Particularly common in seed and Series A businesses. The duty under MHSWR Regulation 7 applies regardless of headcount or sector.

Risk assessment never updated for hybrid working or office move

Last reviewed before the shift to flexible working, or before the company moved between serviced offices. Not "suitable and sufficient" under MHSWR Regulation 3.

Psychosocial risk treated as wellbeing benefits, not statutory risk

Headspace subscriptions and EAPs in place; no documented psychosocial risk assessment under MHSWR.

Worker Protection Act 2023 reasonable steps not documented

Harassment policy exists but no specific risk assessment or documented reasonable steps in force from 26 October 2024.

Fire risk assessment out of date for serviced office occupants

Where the company has moved between WeWork-style serviced offices without commissioning a new fire risk assessment for each demised area.

No accident, near-miss, or incident reporting culture

"We are a software company, nothing happens to us." Then a courier delivers a parcel, an engineer trips over a cable in the office, a remote worker reports back pain, or an employee reports harassment from a customer at a conference. The system catches none of it.

Investor or customer due diligence forces emergency compliance

Series B+ funding rounds and enterprise customer security reviews routinely demand H&S documentation that did not previously exist. Reactive scrambles produce thin, defensive documentation rather than a coherent management system.

DSE FOR SOFTWARE ENGINEERS

DSE Assessment for Software Engineers
and Distributed Engineering Teams

For IT and software companies, DSE assessment is the most operationally impactful workplace H&S activity. Engineers, product managers, designers, customer success, and commercial staff are all habitual screen users by any reasonable interpretation of the Display Screen Equipment Regulations 1992.

Why Software Engineers Carry Elevated DSE Risk

1

High screen time

Software engineering routinely involves seven to ten hours of screen time per day, often with limited breaks, sometimes extended further during release cycles or production incidents.

2

Multi-monitor configurations

Two, three, and four-monitor setups are common, with positioning and viewing distance frequently outside HSE-recommended parameters.

3

Intense visual focus

Code review, debugging, and pattern-matching activities involve sustained close visual attention rather than the variable focus of mixed administrative work.

4

Variable workstation quality

Office workstations may be well configured. Home setups vary dramatically, from dedicated home offices to kitchen tables, sofas, and bed-based working.

5

Travel and event working

Conferences, customer visits, off-sites, and team events all involve extended laptop-only working in suboptimal ergonomic conditions.

What a Compliant Software Company DSE Programme Looks Like

1

A self-declaration questionnaire deployed to every habitual screen user covering workstation, environment, software, and user-specific factors.

2

Assessor-level escalation for any reported discomfort, equipment issue, or self-declared concern.

3

A documented equipment provision policy covering monitor, keyboard, mouse, chair, peripherals, and where reasonable, ergonomic accessories, with a defined allowance and a documented adjustment process.

4

Specific provision for home and hybrid workers, including a route for them to escalate inadequate home setups without stigma.

5

Software-managed renewal cycles with automatic triggers on workstation change, role change, location change, and time elapsed.

6

Integration with new-starter onboarding so every new engineer is DSE-assessed within their first two weeks.

INVESTOR AND CUSTOMER DUE DILIGENCE

Investor Due Diligence and
Enterprise Customer Audits

For IT and software companies, the most common forcing function for workplace H&S compliance is not HSE enforcement. It is commercial pressure. Investors and enterprise customers increasingly include workplace H&S in their due diligence and procurement processes.

What Investors Typically Ask For

Series B and later funding rounds frequently include H&S in the legal and operational due diligence pack. The typical request set covers:

1

Current health and safety policy signed by a director.

2

Evidence of competent person appointment under MHSWR Regulation 7.

3

Current risk assessment covering all activities and locations.

4

Fire risk assessment for occupied premises.

5

DSE compliance evidence: assessment records, training records, equipment provision policy.

6

Accident and incident reporting records, including any RIDDOR-reportable events.

7

Insurance certificates including employers' liability.

8

Any open enforcement notices, prosecutions, or claims (typically nil for software companies, but the question is asked).

9

ISO 45001 status where relevant.

What Enterprise Customers Typically Ask For

Enterprise customer procurement reviews (particularly in financial services, public sector, and regulated industries) routinely include H&S as part of the supplier security and compliance review. The typical questionnaire covers everything in the investor list above plus supplier-specific questions on:

1

Subcontractor management and worker safety in any subcontracted delivery work.

2

Site safety arrangements for any on-customer-site work.

3

Mental health and wellbeing arrangements.

4

Worker Protection Act 2023 reasonable steps documentation.

5

Modern slavery and ethical procurement statements (separate but typically requested in the same pack).

How Arinite Supports the Cycle

Arinite produces a single integrated H&S documentation pack at onboarding, designed to satisfy both investor due diligence and enterprise customer procurement questions out of the box. The pack is maintained as a live system through the year so it is always current when a request lands, rather than rebuilt under pressure each time.

SERVER ROOM AND COMPUTE

Server Room, On-Premises Compute,
and Office IT Safety

Where the company operates on-premises servers, GPU clusters, network infrastructure, or experimental hardware, additional risk applies that goes beyond the standard office:

1

Electrical safety

Under the Electricity at Work Regulations 1989, including PAT testing, isolation procedures, and competent person electrical work for server room maintenance.

2

Fire risk

Specific to high-density compute environments including any suppression systems (FM-200, Novec, water mist) and their inspection schedule.

3

Heat and ventilation

HVAC adequacy for the heat load, alarm thresholds, and out-of-hours monitoring.

4

Access control and lone working

In machine rooms, particularly during out-of-hours maintenance windows.

5

Manual handling

Of heavy equipment during rack installation, replacement, and decommissioning. Servers, switches, and PDUs are heavier than they look.

6

Cable management and trip hazards

In active build environments, demo rooms, and lab spaces.

7

Laser safety

Where the business operates fibre optic or laser-based equipment beyond standard datacomms.

Even fully cloud-native software companies routinely operate small on-premises compute or networking estates (office routers, switches, UPS, NAS, build servers) that deserve a brief risk assessment, electrical safety check, and inclusion in the wider documentation set.

EMPLOYER DUTIES

Core Employer Duties for
IT and Software Companies

Every IT and software employer must:

1

Conduct a documented risk assessment under MHSWR Regulation 3 covering office, home, hybrid, and travel activities, plus on-premises compute and server room activities where applicable.

2

Conduct DSE assessments for every habitual screen user under the Display Screen Equipment Regulations 1992. For most software companies, that is the entire workforce.

3

Maintain a documented psychosocial risk assessment using the HSE Management Standards or equivalent.

4

Document Worker Protection Act 2023 reasonable steps on the prevention of sexual harassment, including by third parties.

5

Maintain a documented fire risk assessment for every occupied premises under the Regulatory Reform (Fire Safety) Order 2005.

6

Appoint one or more competent persons under MHSWR Regulation 7.

7

Maintain a written health and safety policy signed by a director and reviewed annually, mandatory for any employer with five or more employees.

8

Comply with the Electricity at Work Regulations 1989 for office and server room electrical equipment, including PAT testing.

9

Report specified injuries, diseases, and dangerous occurrences under RIDDOR.

10

Maintain reasonable adjustments processes under the Equality Act 2010, particularly for mental health conditions and neurodiverse employees common in software workforces.

11

Provide information, instruction, training, and supervision appropriate to the risks under MHSWR Regulation 10 and 13.

12

Maintain accident, incident, and near-miss reporting arrangements.

REGULATIONS

Sector-Specific Regulations for IT
and Software Companies

The full UK legislative framework applying to IT and software employers.

The Health and Safety at Work etc. Act 1974

Sections 2 and 3 general duties; Section 37 director and manager liability.

The Management of Health and Safety at Work Regulations 1999

Risk assessment, competent person, training, worker information.

The Health and Safety (Display Screen Equipment) Regulations 1992

DSE assessment, eyesight tests, breaks, training, information for every habitual user.

The Regulatory Reform (Fire Safety) Order 2005

Fire risk assessment for non-domestic premises.

The Workplace (Health, Safety and Welfare) Regulations 1992

Minimum standards for temperature, ventilation, lighting, space, sanitation.

The Electricity at Work Regulations 1989

Including PAT testing of portable electrical equipment.

The Worker Protection Act 2023

Preventative duty on sexual harassment in force from 26 October 2024.

The Equality Act 2010

Reasonable adjustments for disabled workers including mental health and neurodiverse conditions.

RIDDOR 2013

Reporting of specified workplace injuries, diseases, and dangerous occurrences.

The Corporate Manslaughter and Corporate Homicide Act 2007

Corporate liability for gross failures of senior management leading to a death.

OUR SERVICES

Our Health and Safety Services for
IT and Software Companies

Arinite delivers the full range of IT and software health and safety services through Qualified consultants and integrated health and safety software.

Software company risk assessments

Documented MHSWR Regulation 3 risk assessment covering office, home, hybrid, distributed, and travel activities.

DSE assessments for software engineers

Workstation-level DSE for office, home, hybrid, co-working, and travel-based workers, with assessor escalation and software-managed renewal cycles.

Investor and customer due diligence pack

Integrated H&S documentation pack ready for Series B+ legal review and enterprise customer procurement.

Psychosocial risk assessment

HSE Management Standards-aligned psychosocial risk assessment with HSE Stress Indicator Tool deployment.

Worker Protection Act 2023 compliance

Risk assessment, policy, training, and documented reasonable steps including third-party harassment.

Fire risk assessments

PAS 79:2020 fire risk assessments for office and serviced office premises.

Server room and on-premises compute safety

Electrical safety, fire risk, manual handling, and access control assessment for server rooms and lab environments.

Competent person retainer

External Qualified competent person satisfying MHSWR Regulation 7.

Health and safety policy

Documented policy signed by a director and reviewed annually.

Health and safety audits

Documented audits identifying gaps against the IT and software regulatory framework.

Health and safety software

Centralised platform for risk assessments, DSE records, fire risk assessments, training, incidents, and audits.

Mental health and reasonable adjustments

Mental health awareness training and Equality Act 2010 reasonable adjustments advisory, including for neurodiverse employees.

TRAINING

Health and Safety Training for
IT and Software Companies

The core IT and software training stack covers:

DSE awareness

For every habitual screen user, covering posture, multi-monitor setup, breaks, eyesight tests, and reporting discomfort.

Manager and director training

On Section 37 duties, MHSWR Regulation 7 competent person, and director-level H&S responsibilities.

Mental health awareness

For all employees and dedicated mental health training for line managers.

Worker Protection Act 2023 training

On harassment prevention and bystander intervention.

Fire safety induction

And fire warden training appropriate to the premises.

First aid at work

For designated first aiders.

Equality Act 2010 reasonable adjustments

Training for line managers and people teams, including for neurodiverse employees.

Training is documented in Arinite's software platform with individual certificates and attendance records.

TYPICAL ENGAGEMENT

A Typical IT and
Software Engagement With Arinite

The following is an illustrative example of how Arinite engagement typically runs for a software company, drawn from common patterns across our IT and software client base.

A growth-stage SaaS company approaches Arinite shortly before a Series B raise. The legal team has flagged that the data room needs H&S documentation. The company has 80 employees across two UK offices and a distributed engineering team across five countries. The existing documentation is a one-page H&S policy written for a previous office.

Mo
1

Arinite's free gap analysis call identifies the priority gaps: no DSE assessment for any of the 80 employees, no documented competent person, a stale risk assessment, no fire risk assessment for the current London office, and no Worker Protection Act 2023 documentation. We agree a 90-day remediation programme. In month one, we deliver: a refreshed health and safety policy signed by the CEO, a current MHSWR Regulation 3 risk assessment covering office, home, hybrid, and international working, and a competent person appointment. We deploy DSE self-declarations to all 80 employees through our software platform, with assessor escalation for any issues identified.

Mo
2

In month two: we deliver the fire risk assessment for the London office to PAS 79:2020, run the psychosocial risk assessment using HSE Stress Indicator Tool, document the Worker Protection Act 2023 reasonable steps, and put accident and near-miss reporting into the software platform.

Mo
3

In month three: we deliver the investor due diligence H&S pack as a single integrated document set, train the senior leadership team on their Section 37 duties, and hand over to ongoing competent person retainer with quarterly reviews.

The Series B raise closes without H&S being a line item in the disclosure. The competent person retainer continues, satisfying MHSWR Regulation 7 for the year ahead. When an enterprise customer requests H&S documentation six months later, the pack is already current.

WHY ARINITE

Why IT and Software
Companies Choose Arinite

Five practical reasons software companies appoint Arinite as their outsourced competent person:

Built for distributed workforces

Our software platform manages DSE, training, and incident reporting across home, office, and hybrid teams in 50+ countries. One platform, one audit trail.

Investor and customer due diligence-ready by default

The integrated documentation pack is designed to satisfy both Series B+ legal review and enterprise customer procurement out of the box.

Minimum drag on engineering and product velocity

Self-declaration questionnaires, software-managed renewals, and assessor escalation keep founders, engineers, and product staff out of the compliance critical path.

Qualified consultants, not generalists

MHSWR Regulation 7 requires competent advice. We deliver it through Qualified health and safety consultants under a documented appointment.

International coverage

For software companies with employees in multiple jurisdictions, Arinite coordinates UK employer duty with local law in 50+ countries.

Book a Free Gap Analysis Call

Book a free gap analysis call with one of our Qualified health and safety consultants. In 30 minutes, we will assess your current arrangements, identify the compliance gaps that matter most for your investor and customer due diligence cycle, and give you a clear recommendation and indicative cost.