The Building Safety Act 2022: What It Means for Your Organisation

The Grenfell Tower tragedy changed everything. In its wake, the UK government faced an undeniable reckoning with decades of inadequate oversight, unclear accountability, and systemic failures in how buildings were designed, constructed, and managed. The result was landmark legislation that reshapes the entire landscape of building safety across the country.

The Building Safety Act 2022 represents the most significant overhaul of building regulations in a generation. For organisations involved in residential development, property management, or construction, understanding this legislation is no longer optional. It is a fundamental operational requirement.

This analysis breaks down what the Act actually means in practice. We examine the new duty holder framework, the expanded regulatory oversight for higher-risk buildings, and the accountability structures that now place legal responsibilities firmly on named individuals within your organisation. We also look at the practical steps you need to take to achieve and maintain compliance.

Whether you are a developer, building owner, or facilities manager, this piece will give you a clear and grounded understanding of how the Building Safety Act 2022 affects your responsibilities and what you need to prioritise right now.

What Is the Building Safety Act 2022?

The Building Safety Act 2022 represents the most significant overhaul of building regulation in England in decades. Its origins lie in the Grenfell Tower fire of June 2017, a tragedy that claimed 72 lives and exposed deep, systemic failures in how buildings were designed, constructed, and managed across the UK. Crucially, it also revealed that accountability for building safety had been fragmented, inconsistent, and largely unenforceable for years. The Act was Parliament’s direct response to those failures, closing gaps that had quietly existed across the entire built environment for a generation.

At the heart of the legislation sits the Building Safety Regulator (BSR), a new statutory body established under the Health and Safety Executive. The BSR acts as the central authority for building safety oversight across England, with powers to regulate higher-risk buildings, enforce compliance, and set the competence standards that professionals across the industry must now meet. As the Institution of Civil Engineers explains, the Act fundamentally changes the relationship between regulators, duty holders, and the built environment.

One of the Act’s most transformative principles is that accountability follows a building throughout its entire lifecycle. Obligations do not end when a contractor packs up and leaves site. Developers, designers, and building managers carry continuing legal duties, supported by the requirement to maintain a living “Golden Thread” of safety information at every stage of a building’s existence.

It is also worth emphasising that the Act is not limited to high-rise residential towers. While buildings over 18 metres or seven storeys face the most demanding requirements, the Act applies broadly across all building types, making it directly relevant to commercial landlords, facilities managers, housing associations, and public sector operators. For any organisation responsible for a built asset in England, this legislation creates real and enforceable obligations that cannot be ignored.

Who Does the BSA Apply To? More People Than You Think

One of the most consequential misconceptions about the Building Safety Act 2022 is that it applies only to housing associations, large residential developers, and the tallest buildings on the skyline. That assumption is wrong, and acting on it carries genuine legal risk.

The Act formally establishes named duty holder roles that carry specific, personal legal accountability throughout a building’s lifecycle. The Client, Principal Designer, and Principal Contractor are each legally accountable for building safety decisions in their domain. These are not corporate formalities or delegable administrative tasks. They represent individual exposure to enforcement action, prosecution, and unlimited fines under the regime overseen by the Health and Safety Executive’s Building Safety Regulator (BSR). If your organisation commissions construction work, someone within it holds the Client duty holder role, regardless of the scale of your business.

For occupied higher-risk buildings, the Act goes further still. Accountable Persons (APs) and the Principal Accountable Person (PAP) bear direct personal legal liability for building safety failures. These are genuinely high-stakes appointments. An AP who fails to assess and manage building safety risks, maintain required documentation, or engage residents appropriately faces enforcement notices and prosecution. The role cannot be treated as an administrative title assigned to the most junior person available.

Critically, this is not a framework that stops at residential tower blocks. Facilities managers, managing agents, and building owners operating in commercial, retail, hospitality, and public sector settings are all within scope. A mixed-use building with residential floors above retail premises, a care home, or purpose-built student accommodation of seven or more storeys all meet the higher-risk building definition. Most BSA guidance has focused narrowly on housing associations and large developers, leaving a significant knowledge gap in these sectors.

SMEs are not exempt. If your organisation owns, manages, or maintains a building and employs contractors to carry out work on it, the Act places obligations on you. Company size provides no protection under the legislation. For a mid-sized business with a lean compliance function and informal contractor management processes, that exposure is very real indeed.

The Three-Gateway System: What Developers and Contractors Must Know

For developers and contractors working on Higher-Risk Buildings (HRBs), the three-gateway system is the most operationally significant element of the Building Safety Act 2022. Each gateway is a formal, mandatory checkpoint, and missing or mismanaging any one of them carries serious legal consequences.

Gateway 1 operates at the planning stage. Before detailed design work begins, a fire statement must be submitted alongside the planning application, demonstrating that fire safety principles have been embedded into the building’s concept from the outset. The Health and Safety Executive reviews this submission and provides advice to the Local Planning Authority before planning permission can be granted. This is not a tick-box exercise; it signals a fundamental shift in how early-stage design conversations must happen between clients, architects, and principal designers.

Gateway 2 is arguably the most consequential hold point in the entire process. No construction work can legally commence on a Higher-Risk Building until the Building Safety Regulator (BSR) has granted Building Control Approval. Developers must submit full architectural drawings, a Fire Strategy Report, a Construction Control Plan, and a Competency Declaration, alongside named duty holders. The statutory determination period is 12 weeks, but practical guidance for developers indicates the actual average runs to 16 to 20 weeks. For principal contractors operating on fixed-programme design-and-build contracts, that gap of up to two months can have serious knock-on effects for procurement, subcontractor scheduling, and cost planning.

Gateway 3 creates an equally firm checkpoint before occupation. The BSR requires an 8-week assessment period to verify that all work complies with building regulations, though again, real-world timelines average 10 to 14 weeks. Crucially, preparation for Gateway 3 must begin at the project’s start, with Golden Thread documentation collected continuously rather than assembled at practical completion.

Perhaps the most underestimated aspect of this system is the criminal liability attached to non-compliance. Failure to register an HRB with the BSR is a criminal offence, not an administrative oversight. This extends obligations deep into the supply chain, including subcontractors who may assume responsibility sits solely with the principal contractor or developer. The cumulative message is clear: the three-gateway model demands that documentation, competence verification, and audit trails are managed as live, ongoing processes throughout every project phase.

The Golden Thread of Information: What It Actually Requires

The Golden Thread is not a filing cabinet. It is not a shared drive of scanned PDFs, a folder of as-built drawings, or a spreadsheet updated sporadically when someone remembers. Under the Building Safety Act 2022, the Golden Thread is a living, version-controlled record that spans the entire lifecycle of a higher-risk building, covering initial design decisions, safety case reports, changes made during construction, installed product certifications, and ongoing maintenance records. Its purpose, as the Building Safety Regulator frames it, is to ensure that the right information exists to understand a building and to keep the people inside it safe. That is an active, continuous obligation, not a box to tick at handover.

What the Building Safety Act’s golden thread really requires from your software is a question the industry is still working out how to answer, and the uncertainty itself carries risk. The BSR’s expectation is a dynamic, auditable system capable of demonstrating the current safety status of a building at any point in time. That means the record must be queryable, traceable, and current. A system that cannot show who made a change, when they made it, and what it replaced is not meeting the standard. This is where many organisations are currently exposed.

Version control is where legal liability quietly accumulates. If a design change is made during construction but the Golden Thread is not updated to reflect it, that gap is not merely an administrative inconvenience. It directly undermines the safety case report that the Accountable Person must submit to the BSR to justify continued occupation. An incomplete or outdated record does not just create paperwork problems; it weakens the entire legal foundation on which a building’s safety status rests. The legislation, reinforced by three pieces of secondary regulation introduced between 2023 and 2024, is explicit: the record must be updated wherever plans change, and responsibility for that accuracy shifts formally from construction duty holders to Accountable Persons at occupation.

For occupied buildings, maintaining the Golden Thread is an ongoing operational responsibility. It does not conclude at practical completion or at Gateway 3 sign-off. Accountable Persons must keep it continuously updated and accessible to both themselves and the BSR. This is a live management task, built into day-to-day building operations.

The practical implication for organisations still relying on spreadsheets, paper logs, or static document stores is significant. These approaches are identified as common compliance failures, and they carry meaningful legal risk. The BSR expects a demonstrable building safety management system with audit trail functionality. Organisations that cannot evidence that system are not simply behind on admin; they are operating outside the requirements of the Act.

Contractor Obligations Under the BSA: Managing Competence at Scale

Competence sits at the heart of the Building Safety Act’s duty holder framework, and it carries a critical distinction that organisations must internalise. The obligation is not simply to hire contractors who are competent; it is to demonstrate that you verified that competence before work began. The Act mandates that every person carrying out work on a higher-risk building possesses the necessary Skills, Knowledge, Experience and Behaviours (SKEB), and this standard runs the full length of the supply chain, from principal contractors through to specialist subcontractors and individual tradespeople. The CIOB has published client-facing guidance specifically covering pre-project competence checks, signalling that institutional expectations around pre-verification are now considered a baseline, not a best practice. If you cannot produce evidence that verification occurred before a contractor set foot on site, the verification, for regulatory purposes, may as well not have happened.

The documentation requirements for contractor site visits have become substantially more demanding as a result. Under the BSA, organisations need to be able to produce records of who attended site and when, what work was carried out and with which materials, what qualifications and certifications were held by the individuals doing the work, and what sign-offs, test certificates, and inspection records were generated. As the Building Safety Act 2022 trades guide from Complys makes explicit, paper records, lost email threads, and documents stored on a contractor’s personal phone are not acceptable. The information must be findable years or even decades later, and it must be structured, not scattered. That is the standard against which contractor visit documentation will be judged in any BSR scrutiny or enforcement action.

The practical risk for organisations managing large contractor supply chains becomes obvious at scale. Across multiple sites, with dozens of contractors rotating through at different intervals, tracking onboarding documents, insurance renewals, qualification expiry dates, and site visit records across spreadsheets or email chains creates an evidential gap that the BSR will scrutinise at each of the three Gateway checkpoints. This is not a theoretical risk; it is an avoidable one. BESA’s guidance on roles and responsibilities under the BSA confirms that industry bodies are actively developing Competence Assessment Standards aligned to the Act, reflecting a sector-wide shift toward structured, verifiable compliance processes.

A scalable contractor management system needs to consolidate several functions in one auditable location: onboarding documentation, competence verification records, insurance checks, site visit logs, renewal alerts, and sign-off trails. This is precisely the challenge that Contractor Genie is built to address. Rather than reconstructing a contractor’s compliance history from scattered sources under regulatory pressure, organisations using Contractor Genie maintain a single, timestamped record of every contractor relationship and site visit. That maps directly to what the BSA expects from a demonstrable safety management system, and it removes the audit risk that paper-based approaches inevitably carry.

Mandatory Occurrence Reporting and Resident Engagement

Mandatory Occurrence Reporting: A Legal Obligation, Not a Best Practice

Under the Building Safety Act 2022, the Mandatory Occurrence Reporting framework requires that prescribed dangerous occurrences in higher-risk buildings are reported to the Building Safety Regulator within specified timeframes. This is a discrete, named legal obligation within the BSA compliance architecture, and the framing matters. MOR is not guidance, it is not advisory, and it is not something organisations can defer until their next review cycle. Failure to report within the required window constitutes a direct breach of the Act, exposing Accountable Persons and organisations to enforcement action including contravention notices from the BSR.

The operational implication is immediate. Organisations need a system that captures incidents at the point of discovery, records the reporting action taken, and preserves a clear, timestamped audit trail that can be retrieved on demand. Paper logs and shared drives do not meet this standard reliably. When the BSR requests evidence of reporting, the question is not whether an incident was eventually noted somewhere, it is whether it was captured promptly, reported within the required window, and documented in a way that demonstrates compliance. That is a process and documentation challenge as much as it is a notification task.

Resident Engagement: Documented, Reviewable, and BSR-Scrutinised

The Principal Accountable Person for every higher-risk building is legally required under Section 91 of the BSA to produce, implement, and regularly review a Resident Engagement Strategy. Critically, this is not a communications exercise. Residents are positioned under the Act as active participants in building safety, described in industry guidance as “the eyes and ears of the building,” best placed to identify emerging issues such as fire doors failing to close or missing extinguishers. The strategy must set out what information residents receive, what they are consulted on, how their input is collected, and how participation is measured. Both the written strategy and the live evidence of its implementation must be maintained in your safety records, because the BSR can examine both.

This is where digitising your health and safety processes creates a measurable compliance advantage. Incident logs, resident communications, and engagement records stored within a single auditable system can be timestamped, retrieved, and presented as coherent evidence at short notice. Tools like the Compliance Genie, which digitise and centralise H&S processes, put organisations in a fundamentally stronger position across both MOR and resident engagement obligations, because the audit trail is built into the workflow rather than reconstructed after the fact.

Digitising BSA Compliance: What Your System Needs to Do

The Building Safety Act 2022 does not simply require you to manage your building safely. It requires you to prove it, continuously, with a living record that can withstand regulatory scrutiny at any point in the building lifecycle. That distinction changes everything about how you approach your internal systems. Paper files, shared drives of scanned documents, and disconnected spreadsheets are not just administratively inconvenient under the BSA; they represent a structural compliance risk. The Golden Thread requirement demands information that is kept digitally, kept securely, and available as a single source of truth, accessible to residents, contractors, and emergency responders as appropriate. If your health and safety processes and your contractor records live in separate places, you do not have a Golden Thread. You have fragments.

What a Compliant System Actually Needs to Support

The functional requirements for a BSA-ready digital system are specific. Version-controlled documentation is non-negotiable, because every change to a safety-critical record needs to be traceable, with a clear timestamp and an identifiable author. Role-based access controls matter because the BSA specifies who should be able to see, edit, and confirm information at each stage of the building lifecycle. Real-time incident logging is required to meet Mandatory Occurrence Reporting timelines. Contractor competence tracking must be verifiable within the information chain itself, not held in a separate system that nobody can easily cross-reference. Audit-ready reporting has to be available on demand, not assembled under pressure when the Building Safety Regulator comes calling. The Golden Thread Building Safety guide from Brocade identifies the most common failure modes for building managers as paper-only records, absent version control, information scattered across systems, and poorly calibrated access permissions. A compliant digital architecture needs to eliminate all of these simultaneously.

The ‘Good Software’ Question Is Not Yet Settled

It is worth being direct about something: the industry debate around what acceptable Golden Thread software looks like is still very much live. The Fire Safety Event has flagged significant ongoing uncertainty about what the BSR will consider sufficient in practice, meaning that prescriptive feature requirements remain unsettled at the regulatory level. In that context, flexibility and auditability are the safest baseline to build around, rather than betting on a narrow interpretation of compliance that the regulator may revise. Organisations selecting or reviewing their systems now should prioritise platforms that can adapt as regulatory expectations crystallise, while ensuring the audit trail is unambiguous and defensible from day one.

A Connected Compliance Layer, Not a Collection of Tools

This is where the architecture of your tooling becomes a strategic decision rather than a procurement detail. Compliance Genie from be-safetech.com is built to digitise health and safety processes end to end, replacing manual workflows with structured, auditable digital records that hold up under regulatory scrutiny. When combined with Contractor Genie for contractor oversight and site visit management, organisations gain a unified operational compliance layer that addresses both the internal process side and the supply chain side of BSA obligations together. There is no need to stitch together multiple disconnected tools and then manually reconcile the outputs. The competence verification that the BSA demands from your contractors and the documented H&S processes that demonstrate safe building management sit within the same connected system, producing the kind of coherent, retrievable record the Act actually requires.

BSA Compliance for SMEs: A Proportionate and Practical Approach

Much of the published guidance on the Building Safety Act 2022 has been written with large housing associations, local authorities, and enterprise construction firms in mind. The legal analysis is thorough, the frameworks are detailed, and the compliance checklists are comprehensive, but they are consistently calibrated for organisations with dedicated compliance teams, in-house legal counsel, and substantial operational budgets. For a mid-sized regional contractor, a specialist trades business, or a smaller developer, this creates a genuine practical gap: the legal obligations are identical, but the accessible, right-sized direction simply does not exist in the same volume. This is a signal Tier 1 contractors have already recognised, with principal contractors now pushing BSA compliance expectations directly downstream to their subcontractor supply chains.

Start With a Three-Area Gap Analysis

For a mid-sized organisation, the most proportionate starting point is an honest gap analysis across three specific areas: your current documentation practices, your contractor management processes, and your incident reporting workflows. These three areas map directly to the BSA’s core operational requirements and represent the foundations any audit or BSR inspection would examine first. You do not need a consultant to conduct this initial review. A structured internal assessment, comparing what you currently do against what the Act requires in each area, will surface the priority gaps quickly and help you allocate resource where it is genuinely needed.

Training Is More Accessible Than You Think

Getting your team to a functional baseline understanding of the Act is achievable without significant time or budget investment. CPD-accredited BSA awareness training is available and can be completed in around 45 minutes, at a cost of approximately £20 plus VAT per person. That is a meaningful intervention for a small team, not a programme requiring months of planning. Prioritise anyone in a duty holder role, anyone managing contractor relationships, and anyone responsible for incident reporting.

Demonstrability Matters as Much as Perfection

The most important principle for SMEs approaching BSA compliance is this: build systems that are demonstrable from day one. Even if you are not yet fully compliant across every obligation, being able to show the BSR a structured, actively improving system carries significant weight compared to presenting no system at all. Document your gap analysis, record the steps you are taking, and ensure your processes create an auditable trail.

Starting with digital tools that are flexible and scalable, rather than enterprise platforms priced for housing associations, means SMEs can build genuinely compliant processes without overcomplicating them or overspending. Tools like Compliance Genie and Contractor Genie are designed precisely for this: digitising your health and safety processes and centralising contractor management in a single, auditable system, at a scale and price point that makes sense for organisations that are not managing thousands of units or hundreds of site visits per week.

Where Does Your Organisation Stand?

Every relevant organisation should now be able to evidence five core obligations without hesitation: clearly defined duty holder roles with active accountability, verified contractor competence linked to scope of work, a living Golden Thread of digitally maintained records, a functioning incident and Mandatory Occurrence Reporting process, and a structured resident engagement strategy where applicable. These are not aspirational standards. They are the baseline the Building Safety Regulator expects to see demonstrated, not simply declared.

The Act is not approaching. It is already here and actively enforced. The gap between organisations operating structured, auditable digital compliance systems and those still relying on spreadsheets, shared drives, and disconnected paper records is widening with every month that passes. That gap is a live compliance exposure, not a future risk to manage later.

The most impactful single step your organisation can take right now is straightforward: ask honestly whether your H&S and contractor management processes are auditable and connected. If the answer is uncertain, that is where to focus first.

Compliance Genie and Contractor Genie are built to close exactly that gap. Book a free demo to find out whether they are the right fit for your specific compliance needs.

Conclusion

The Building Safety Act 2022 is not simply new legislation to file away. It represents a fundamental shift in how safety accountability is assigned, monitored, and enforced across the built environment.

The key takeaways are clear: duty holders now carry named legal responsibilities, higher-risk buildings face significantly expanded regulatory scrutiny, and organisations that fail to adapt face serious consequences. Compliance is no longer a background concern; it sits at the heart of operational decision-making.

The buildings we create and manage house real people. Getting this right matters beyond regulatory obligation.

Start by auditing your current compliance position, identifying your designated duty holders, and reviewing your safety case documentation. If gaps exist, address them now rather than under pressure later.

The organisations that treat this legislation as an opportunity to build stronger systems will be better positioned, more trusted, and genuinely safer for the people they serve.

Which Service Would You Like to Know More About?

The award-winning Compliance Genie - to digitise all of your Health & Safety processes - or the software platform The Contractor Genie - that helps you manage all of your contractors and their site visits in one place?