We Had the Risk Assessments — We Just Couldn’t Prove Anyone Was Using Them
“We had the risk assessments in place.” That’s what Kilmarnock Leisure Centre Trust said after a 25-year-old autistic swimmer lay face down in their pool for one minute and 52 seconds. They were right. The documents existed. What didn’t exist was any proof they were being followed on the day it mattered. The Trust had been prosecuted at the same pool four years earlier for almost identical failures. They updated their paperwork. The problem is, paperwork doesn’t save anyone.
Five trustees of Kilmarnock Leisure Centre Trust were found out at Kilmarnock Sheriff Court in June 2025 — including the local Provost. Personal fines. Not the organisation in the abstract. Them, individually, for a gap between what the Trust’s paperwork said and what was actually happening on the pool deck. The documents existed. The failure was in daily execution. And the board — who provided strategic oversight but not operational control — was held personally liable for that gap.
This is what everyone says before they are caught.
Before we go any further, here’s an easy test. Pull up your board papers from the last quarter. Do they tell you what was actually checked on poolside this week — or just that “health and safety was discussed”? If it’s the second, you’ve just found your Kilmarnock gap. That’s not a criticism. It’s where every trust starts.
What Board Oversight Actually Means
Here’s where it gets uncomfortable for trust boards across the UK.
You are not running the poolside sessions. You’re not checking the lifeguard positions. You’re not signing off on whether the inflatable risk assessment was followed during Tuesday’s fun swim. That’s operational management. Your job is governance — strategic oversight.
But HSE and the courts don’t draw the same clean line you might. When something goes wrong at the operational level, the question they ask is, ‘What governance systems did the board have in place to know it was happening?’
If your answer is “we received a quarterly report from the operations manager”, that’s not going to be enough. That’s strategic oversight of a document trail. It’s not live visibility of what’s actually happening on the ground.
The Kilmarnock trustees said they had internal arrangements in place for appropriate governance. The sheriff disagreed that those arrangements were sufficient. Five of them — sitting councillors doing their civic duty — walked out of court with personal fines.
They were lucky. Section 37 of the Health and Safety at Work Act carries up to two years’ imprisonment for directors and senior managers found to have consented to, connived in, or been neglectful about a breach. Not always a fine. Prison. The five Kilmarnock trustees paid money. Under the same law, in a case judged more serious, the next person in that position won’t be treated the same way.
If that’s genuinely on the table, shouldn’t you have the right to see what’s actually happening — live, with proof — rather than whatever summary somebody else decided was worth passing up the chain?
I have a rule for most things in life: if I am going to die on a sword, it must be my sword — not someone else’s. Handed to me by a mistake I never saw, buried in a summary I never got the chance to question it three months after it happened. If your liberty is what’s on the line, not just your reputation, live visibility isn’t a nice-to-have. It’s the minimum you should insist on before you agree to sit on that board at all.
The Problem With Paper-Based Compliance
Most leisure trusts in the UK are responsible organisations. They employ people who care. They write risk assessments. They run training. They have procedures.
What they often can’t do is prove, in real time, that any of it is being followed.
Paper-based compliance creates a dangerous illusion. The folder exists; therefore, compliance exists. But a risk assessment filed in a cabinet on the 3rd of January doesn’t tell you whether the procedure it describes was followed on the 10th of January. A training record signed six months ago doesn’t tell you whether that staff member is applying what they learned in today’s session. A checklist completed on the morning shift doesn’t tell you what happened at 3pm.
HSE inspections are up 47% in 2024/25. Enforcement is increasingly intelligence-led — RIDDOR reports, complaints, and near misses flag organisations for scrutiny. When an inspector walks in, or when something goes wrong and investigators start asking questions, the question is always the same: can you prove it?
Not “Do you have a document that says you should do it?” Can you prove it was done?
What Would Have Been Different With OpsPal
This is the bit that matters for anyone reading this who wants to make sure their trust doesn’t become the next case study.
OpsPal gives boards and senior leadership something paper systems physically cannot: live visibility of what is actually happening, across every site, in real time.
When a risk assessment is due for review, it turns amber in the dashboard 30 days out. When it goes overdue, it turns red. Every board member and senior manager with access can see that right now, not in next month’s report. There is no scenario in which an overdue risk assessment quietly sits in a cabinet unnoticed for weeks, because it’s visible to everyone who needs to see it.
When a procedure is updated — say, the inflatable session protocol following a near-miss — staff receive an in-app notification and must read and acknowledge the new version before they can proceed. OpsPal records who read it, when they read it, and which version they read. That’s your audit trail. That’s your proof.
When a problem is logged — a concern raised by a lifeguard, an equipment issue spotted during a check, a session that didn’t run to protocol — it’s assigned immediately, tracked through to resolution, and visible to managers. It cannot be ignored without this also being visible. A problem raised on a Tuesday and unresolved by Friday turns red on the dashboard and triggers a notification. Nobody can say they didn’t know.
For trust boards specifically, the organisation-level dashboard shows compliance status across all sites at a glance. Red risk assessments. Overdue tasks. Unresolved problems. The board doesn’t need to wait for a quarterly report to know something is wrong. They can see it — and crucially, they can act before it becomes a prosecution.
That’s the difference. Not documents. Live visibility. The proof that the system is working, every day, not just when someone checks.
A Closing Thought
Kilmarnock Leisure Centre Trust had been to court once and come back. They updated their processes. They genuinely believed they were compliant. The failure wasn’t malicious. It was invisible — gaps in daily operations that nobody at board level could see, because the systems they had weren’t designed to show them.
If your trust runs on paper or on a shared drive full of PDFs, ask yourself the question HSE will ask if something goes wrong tomorrow morning: can you prove your procedures were followed today?
If you’re not certain of the answer, that uncertainty is the risk you’re taking.
OpsPal gives your board the live operational visibility to close that gap — before someone else closes it for you.
Book a demo and see what live compliance looks like. →