What goes in a legionella written scheme of control template?
On this page
Key points
- A written scheme template turns the idea of a scheme into a fillable document: one row per control measure, each with a target parameter, a monitoring task, a frequency, a named responsible person, and the action to take if control fails.
- The template is anchored on an up-to-date schematic of the system, so every outlet, tank, and calorifier on the drawing has a matching control in the scheme.
- It is a separate document from the risk assessment. The assessment identifies the risk, the scheme states what you will do, and the log book records that you did it. Three documents, one job.
- Standard figures go in the parameter column: store hot at 60°C, reach 50°C (55°C in healthcare) within a minute at the outlet, and keep cold below 20°C.
- A blank template only starts to control anything once you fill it from your own risk assessment findings and then actually follow it. ACOP L8 expects the scheme to be specific to your system, not generic.
A legionella written scheme of control template gives you a structured place to record, for each part of your water system, the control measure you rely on, its target parameter, the monitoring task that checks it, how often that task is done, who is responsible, and the action to take if control fails. It is the concept of a written scheme laid out as a document you can fill in.
This page is about the template itself: its structure and how you complete it. If you want the underlying concept, why a scheme is required and where it sits in law, start with the guide to the written scheme of control and come back here for the document.
The template is a table of control measures
At its core, a written scheme template is a table. Each control you depend on gets its own row, and the columns force you to answer the same six questions for every one of them. Fill in a row and you have described a control completely; leave a column blank and you have found a gap.
- The control measure. What you are relying on to keep the risk down. For example: hot water storage, hot water distribution, cold water temperature, flushing of little-used outlets, showerhead cleaning, calorifier inspection.
- The parameter. The specific value or state you are working to. Store hot water at 60°C. Deliver 50°C (55°C in healthcare) within one minute at the outlet. Keep cold water below 20°C. Legionella multiplies most readily between roughly 20°C to 45°C, which is why these numbers, not vaguer ones, belong in the column.
- The monitoring task. The physical check that confirms the parameter is being met: a temperature reading at a sentinel outlet, a flush run to full temperature, a showerhead dismantled and descaled.
- The frequency. How often the task is done. Monthly sentinel temperatures, weekly flushing, quarterly showerhead cleaning, annual calorifier inspection.
- The responsible person. A role and a name, not "someone". The person who carries out the task, and where relevant the competent person or contractor who reviews it.
- The action if control fails. What happens when a reading is out of range or a task is missed. This is the column most generic schemes leave blank, and it is the one that matters most on the day something goes wrong.
To see how a completed row reads, take hot water storage. The control measure is the calorifier; the parameter is stored at 60°C; the monitoring task is a flow and return temperature check; the frequency is monthly; the responsible person is your named maintenance lead; and the action if control fails is to investigate the cause, restore the store temperature, record the fault, and escalate to sampling if there is reason to. A cold water row would carry the below-20°C parameter and a sentinel temperature check; a little-used outlet row would carry a weekly flushing task. Every row follows the same shape.
Three documents, one job
The template only makes sense once you see how it sits between two other records. Legionella control runs on three documents that do one job between them, and confusing them is where schemes fall apart.
- The risk assessment finds the risk. It surveys the system, maps where legionella could grow or spread, and rates each finding.
- The written scheme says what you will do about each finding. Every risk the assessment raises should turn into a control row in the scheme.
- The log book records that you did it. Each time a monitoring task is carried out, the result is dated, signed, and kept.
Three documents do one job: the risk assessment finds the risk, the written scheme says what you will do about it, and the log book records that you did it.
The scheme is the hinge in the middle. Read on its own, a temperature reading in a log book means little; read against the scheme, it either meets the parameter or it does not. That is why the parameter column matters so much. It is the standard the log book is measured against.
Start from the schematic
A written scheme template should open with, or be built around, an up-to-date line diagram of the system: the incoming main, storage tanks, calorifiers, pumps, the pipework layout, and every outlet. The schematic is not decoration. It is the checklist that tells you which rows the table needs. If an outlet appears on the drawing, it needs a control in the scheme; if a control in the scheme refers to an outlet that is not on the drawing, one of the two is wrong. Where the pipes have changed and the drawing has not, the scheme is already out of date.
Free legionella risk assessment template
A structured Word document following the five-step approach in ACOP L8. Covers risk identification, written scheme, monitoring, and records. If it isn't written down, you can't evidence it.
Follows ACoP L8 and HSG274 Part 2. Free. No spam.
Filling the template from your risk assessment
A blank template is not a scheme, and it does not control anything by itself. You complete it by working through your risk assessment finding by finding and writing the answer to each one as a row. A finding of "calorifier running below temperature" becomes a hot water storage row with a 60°C parameter and a monthly check. A finding of "several outlets used less than weekly" becomes a flushing row. A finding of "showerheads scaled" becomes a cleaning row. Higher-risk assets such as calorifiers and cold water tanks get their own rows for periodic calorifier inspection and tank inspection.
The detail should be specific to your building. A scheme that names your outlets, your temperatures, and your people can be picked up and followed by someone else. One that could apply to any premises in the country cannot, and ACOP L8 expects the former. Filling the template in carefully is not the same as being compliant: it records your decisions and gives you something to evidence, but the control comes from actually carrying out the tasks and acting on the results.
Where the template comes from and where it points
Our free risk assessment template includes a written-scheme section built on exactly this row-per-control structure, alongside a log book and temperature chart to record the monitoring. Used together they give you the three documents in one place. The parameters they carry, and the reasons behind them, come straight from the guidance: the duty to prepare and follow a written scheme sits in ACOP L8, and the practical detail on temperatures, monitoring, and inspection frequencies is worked through across the three parts of HSG274. For the numbers behind the parameter column, see the guide to temperature control.
Free legionella risk assessment template
A structured Word document following the five-step approach in ACOP L8. Covers risk identification, written scheme, monitoring, and records. If it isn't written down, you can't evidence it.
Follows ACoP L8 and HSG274 Part 2. Free. No spam.
Frequently asked questions
What goes in a legionella written scheme of control?
A written scheme sets out, for each control measure in your water system, the parameter you are working to, the monitoring task that checks it, how often that task is done, who is responsible, and what to do if control fails. Typical rows cover hot water stored at 60°C, cold water kept below 20°C, flushing of little-used outlets, showerhead cleaning, and calorifier inspection. It also carries an up-to-date schematic of the system so every outlet on the drawing has a matching control. The detail should be specific to your building rather than generic.
Is the written scheme the same as the risk assessment?
No. They are two separate documents that do different jobs. The risk assessment surveys the system and identifies where legionella could grow or spread; the written scheme states what you will do about each of those findings, with the tasks, frequencies, and responsibilities. A useful way to hold them apart is that the assessment is the diagnosis and the scheme is the ongoing treatment plan, with the log book recording that the treatment was carried out.
Do I need a written scheme of control?
In effect, yes, wherever your risk assessment identifies a reasonably foreseeable risk. ACOP L8 requires you to prepare a scheme to control that risk and then to implement and manage it, under the wider duties of the Health and Safety at Work etc Act and COSHH. Following the Approved Code of Practice is not the only route to compliance, but if you depart from it you must be able to show you have controlled the risk to an equivalent standard. A scheme that is written but never followed would not meet the requirement.
Who prepares the written scheme of control?
Responsibility rests with the duty holder, usually the employer, landlord, or person in control of the premises, who must appoint a competent responsible person to manage it. For a simple, low-risk premises that responsible person may complete the scheme themselves using a structured template. Where the system is complex, serves vulnerable people, or includes higher-risk plant such as cooling towers, the scheme should be drawn up or reviewed by someone with the relevant competence.
Related water hygiene products and services from trusted UK providers will appear here.