The Building Safety Act 2022: What It Means for Your Business

The Grenfell Tower tragedy reshaped how the UK thinks about building safety forever. In its wake, legislators, developers, and building owners faced an uncomfortable truth: existing regulations were simply not fit for purpose. The Building Safety Act 2022 represents the most significant overhaul of construction and building management legislation in a generation, and its implications stretch far beyond the residential high-rise sector many assumed it would target.

If your business operates anywhere within the built environment, whether as a developer, contractor, landlord, or building manager, this legislation directly affects your responsibilities, your liabilities, and your legal obligations. Understanding it is no longer optional.

In this analysis, we break down the core provisions of the building safety act, examine who falls within its scope, and explore what practical steps businesses need to take to achieve and maintain compliance. We will also highlight the significant penalties for those who fail to act. By the end, you will have a clear picture of where your business stands and what needs to happen next.

Background: Why the Building Safety Act Was Created

The story of the Building Safety Act 2022 begins with a tragedy that shocked the nation. On 14 June 2017, a fire tore through Grenfell Tower in West London, killing 72 people and exposing catastrophic failures in how residential buildings were regulated, maintained, and signed off as safe. The disaster did not simply reveal one isolated mistake; it laid bare deep, systemic problems running throughout the construction and building management sectors, from the way buildings were designed and clad to the way responsibility and accountability were diffused across fragmented supply chains.

The subsequent Grenfell Tower Public Inquiry, alongside Dame Judith Hackitt’s independent review of building regulations and fire safety, confirmed what many had long suspected: existing legislation was structurally inadequate. The inquiry found critical gaps in how buildings were designed, constructed, managed, and certified, demonstrating that a patchwork of outdated rules was wholly unfit to prevent a repeat. As the Institution of Civil Engineers explains in its overview of the Act, the legislation that followed was specifically designed to close those gaps across the entire lifecycle of a building.

Parliament’s response was the Building Safety Act 2022, described by government as the biggest overhaul of building and fire safety regulation in a generation. This was not a minor amendment to existing rules. The Act restructured the regulatory landscape from the ground up, introducing the Building Safety Regulator, establishing named duty-holder roles carrying personal liability, and creating new Gateway approval processes for higher-risk buildings. For any business operating in construction or building management, understanding this origin matters enormously. The obligations the Act creates are treated with seriousness by regulators precisely because they were born from avoidable loss of life, and enforcement consequences are explicitly described as real and serious.

Who Does the Building Safety Act Apply To?

The Act’s most intensive obligations centre on higher-risk buildings (HRBs), defined as residential buildings standing at least 18 metres tall, or with at least 7 storeys, containing a minimum of two residential units. It is worth noting, however, that the dutyholder regime introduced under Sections 34 and 35 of the Act (which came into force on 6 April 2023) applies to all notifiable building work, not just HRBs. The 18-metre threshold triggers additional, more intensive obligations on top of the baseline requirements that apply across the board.

At the heart of the Act’s accountability framework sit three named duty-holders. The Accountable Person holds legal responsibility for managing building safety risks during the occupation phase of an HRB, and where multiple Accountable Persons exist, a Principal Accountable Person must be designated to carry overarching responsibility. The Principal Designer is responsible for planning and coordinating safety during the design phase, ensuring that completed designs will comply with building regulations. The Principal Contractor carries equivalent responsibility during construction. Crucially, as Womble Bond Dickinson’s dutyholder guidance confirms, these roles mirror CDM 2015 appointments and the same person or organisation can hold duties under both regimes where they have the necessary competence.

Each named duty-holder carries personal liability under the Act. This means that individuals face potential criminal prosecution for failures to meet their statutory obligations, not just the organisations they represent. The Building Safety Regulator has powers to issue contravention notices and pursue enforcement action directly against individuals, making this a significant and personal compliance responsibility.

Perhaps the most underappreciated dimension of the Act is how far its influence now reaches beyond the HRB threshold. Tier-1 contractors are actively cascading Building Safety Act-aligned documentation and competence requirements down their supply chains to Tier-2 and SME subcontractors, regardless of whether those businesses have ever worked on a building above 18 metres. Smaller contractors are being required to demonstrate BSA-compatible competence frameworks simply to remain eligible for work.

Finally, the Act is not exclusively a concern for those involved in design and construction. Facilities managers, building owners, and property management companies overseeing occupied HRBs carry ongoing legal duties under the Accountable Person regime, including registering buildings with the BSR and continuously managing structural and fire safety. The Act is directly relevant to a considerably wider professional audience than many businesses currently assume.

The Building Safety Regulator: Powers and What 2026 Changes

The Building Safety Regulator was established under the Building Safety Act and initially housed within the Health and Safety Executive, a deliberate decision that gave the BSR immediate access to HSE’s enforcement infrastructure, legal powers, and decades of regulatory credibility. This institutional foundation was not accidental; Dame Judith Hackitt’s review had found that previous enforcement was chronically under-pursued, and penalties were too small to act as meaningful deterrents. Embedding the BSR within HSE addressed both problems from day one.

In terms of practical powers, the BSR controls the development lifecycle of higher-risk buildings through a Gateway system. Gateway 2 approval must be obtained before construction on an HRB can lawfully begin, and Gateway 3 approval is required before a new or refurbished HRB can be occupied. These are hard legislative stops, not advisory checkpoints. The BSR can refuse, pause, or impose conditions on either approval if design documentation, safety cases, or supporting evidence falls short. This gives the regulator genuine leverage at the two most commercially sensitive moments in any HRB project.

From April 2023 to March 2026, the BSR operated under a formally published three-phase strategic plan: Year 1 focused on implementation, Year 2 on consolidation, and Year 3 on reaching steady state. This was a deliberate capacity-building period, and many organisations in scope treated it accordingly, watching and preparing rather than facing immediate enforcement pressure.

That period is now over. A new BSR Strategic Plan published on 31 March 2026 marks a decisive shift into mature enforcement, with defined priority workstreams and an active regulatory posture. Critically, in 2026 the BSR is also being reconstituted as a standalone body sponsored by the Ministry of Housing, Communities and Local Government, sharpening its political accountability and independence. Two recent cases illustrate the new reality: in August 2025, the BSR secured a without-notice injunction preventing occupation of a building citing serious fire safety deficiencies. Gateway refusals, prosecutions, and enforcement actions are now live risks for any business in scope.

The Golden Thread: What It Is and What It Actually Requires

The Golden Thread is grounded in hard law. Under Section 88 of the Building Safety Act 2022, supported by four sets of secondary regulations, it is a statutory duty to create and maintain a structured digital record of key building information across a building’s entire lifecycle. This is not guidance, and it is not best practice. It is a legal obligation, and the distinction matters enormously for anyone operating in or around higher-risk buildings.

In practical terms, the Golden Thread functions as a building’s single source of truth. It must capture structural and fire safety information, construction methods and materials, details of installed plant and equipment, operation and maintenance records, fire safety documentation, and a full log of any changes made through the change control process. Critically, it must also record the identities and responsibilities of named duty-holders at each stage of the building’s life. The legislation describes this as enabling duty-holders to demonstrate ongoing regulatory compliance and to identify, understand, and manage fire spread and structural collapse risks throughout the entire lifecycle of the building.

The storage requirement is equally specific. The Golden Thread must be kept digitally, with version control, in a secure and accessible format. Paper files, scattered email chains, and shared spreadsheets do not meet this standard. The Client must establish the electronic format from the outset, and where BIM tools are in use, they may provide a foundation, but only where the structure allows all relevant information to be cleanly identified and extracted. Understanding the golden thread makes clear that accessibility extends beyond duty-holders to include residents and emergency responders, raising the bar further.

A common misconception among SMEs and Tier-2 contractors is that the Golden Thread only concerns building owners during occupation. The legislation directly contradicts this. Principal Contractors and Principal Designers carry active obligations during their respective project phases, and the thread must be started before building work begins. At Gateway 3, the completed Golden Thread must be formally handed to the Principal Accountable Person, making that handover a hard compliance trigger rather than an administrative formality.

This is precisely what the Building Safety Act’s golden thread really requires from your software: a system that is accessible, auditable, structured, and transferable. A well-configured digital compliance platform that captures safety records, documents contractor activity, and maintains a traceable audit trail is not a convenience. Under the Building Safety Act, it is the mechanism through which the legislation expects the Golden Thread to be delivered.

Gateway 2 and Gateway 3: What Documentation Do You Actually Need?

Understanding exactly what the BSR expects at each gateway is where many projects run into trouble. The requirements are precise, sequential, and unforgiving if documentation is incomplete or poorly structured.

What Gateway 2 Requires

Gateway 2 replaces the old building control deposit-of-plans stage and acts as a hard stop before any construction work begins on a higher-risk building. The Principal Designer or developer must submit a full building control approval application to the BSR, and the statutory determination period is 12 weeks from receipt of a valid application. That word “valid” carries real weight: data from RICS indicates that more than 40% of submissions have been invalidated at the initial stage due to missing or inadequate information. The required documentation includes detailed design drawings, a fire and structural safety strategy, identification of all named duty-holders, a site location plan, and a construction control plan. Critically, a change control log must also be established at this stage, creating a live record of any design modifications made during the build that may require formal BSR notification.

What Gateway 3 Requires

Gateway 3 is the final statutory checkpoint before any higher-risk building can be occupied. The BSR has eight weeks from receipt of a valid completion certificate application to make its determination. The submission must include a completed Golden Thread information package, a safety case report demonstrating the building is safe to occupy, and documented evidence that the building as constructed matches the Gateway 2-approved design. Crucially, the preparation for Gateway 3 must begin from day one of the building control process, not in the weeks before handover.

The Documentation Gap That Catches SME Operators Out

The most common point of failure is straightforward: changes made during construction that were not systematically recorded. If your change control log has gaps, if contractor visits went undocumented, or if safety decisions were made verbally without a written audit trail, the Gateway 3 package will be incomplete. The BSR can and will refuse occupation approval on this basis, leaving a completed building legally unoccupiable.

This is precisely where a structured digital compliance platform earns its value. A system that captures design change requests, logs contractor site visits, records inspection outcomes, and attaches supporting evidence in real time builds your Gateway 3 package continuously, not retrospectively. Compliance Genie, be-safetech.com’s health and safety platform, is built around exactly this workflow, giving Principal Contractors and building owners an auditable evidence trail that maps directly to what both gateway submissions require, removing the last-minute scramble that leaves so many projects exposed.

Contractor Management and Competence Under the Building Safety Act

The Building Safety Act places explicit competence obligations on anyone appointing contractors for higher-risk building work. The appointing party must take reasonable steps to ensure that any contractor they engage has the skills, knowledge, experience, and behaviours necessary to carry out the work safely and in full compliance with the Act. Crucially, competence under the Act is not a binary checkbox; it is defined across four distinct dimensions, codified in PAS 8672:2022, and it extends down the supply chain. Principal Contractors are explicitly expected to assess subcontractor competencies before appointment, meaning this obligation does not stop at the client level.

This shifts contractor vetting from a procurement convenience into a hard legal requirement. A contractor’s compliance history, training currency, incident record, and site visit documentation are now items that the appointing party must be able to demonstrate they actively checked. The HSE’s guidance for Principal Contractors and Principal Designers makes clear that clients should also consider a contractor’s history of previous enforcement action, reinforcing that verification must be active, documented, and defensible.

Tier-1 contractors are already responding to this environment by tightening pre-qualification standards. Contractors without structured digital records covering incident statistics, training certificates, and audit histories are increasingly unable to pre-qualify for high-value work, regardless of their actual on-site safety performance. Pre-qualification platforms have already built specific Building Safety Act assessment tools to reflect this shift, treating BSA compliance as a distinct, assessable data category.

For SME and Tier-2 contractors, the message is clear and urgent. If your compliance records cannot be shared digitally and presented to a client during pre-qualification, you risk losing work that your safety record should win. Paper-based systems and spreadsheets simply cannot produce the structured, auditable evidence packages that the Act and modern procurement processes now require.

This is precisely the gap that Contractor Genie, be-safetech.com’s contractor management platform, is built to close. It enables businesses to manage their entire contractor base, including qualifications, site visits, and compliance evidence, in one centralised place, producing the kind of structured, auditable record that both the Building Safety Act and Tier-1 pre-qualification processes demand.

The Cost of Non-Compliance: Personal Liability and Enforcement Risk

One of the most consequential shifts introduced by the Building Safety Act is the deliberate move away from purely organisational liability. Named duty-holders, including Accountable Persons, Principal Designers, and Principal Contractors, carry personal criminal liability for failures to meet their statutory obligations. Prosecution does not stop at the company; it targets the individuals directing it. Where a breach is committed with the consent, connivance, or neglect of a director, manager, or senior officer, that individual faces prosecution alongside, or instead of, the corporate entity.

The sentencing exposure is substantial. Prior to the Act, building regulations breaches were summary-only offences carrying a maximum fine of £5,000. Post-BSA, the penalty is an unlimited fine and up to two years’ imprisonment. The window for issuing rectification notices has also been extended from 12 months to 10 years, dramatically increasing the period of personal exposure for anyone involved in construction decisions on a higher-risk building. Directors and senior officers cannot rely on organisational distance as a shield; if they cannot demonstrate they took reasonable steps to ensure compliance, including maintaining appropriate records and governance systems, they are exposed.

The BSR’s enforcement toolkit is wide-ranging. It includes compliance notices, stop-work directions, Gateway refusals, and criminal prosecution. With the BSR’s new 2026 to 2027 strategic plan published on 31 March 2026, the regime has formally entered its active enforcement phase. The probability of enforcement action is materially higher now than during the implementation years of 2023 to 2025. Organisations that treated compliance as a future problem should treat it as a present one.

Against that backdrop, defensible records are your most important asset. If an investigation occurs, those who can produce a clear, timestamped, auditable trail of compliance decisions, contractor checks, and safety actions are in a substantially better position than those relying on email threads and shared drives. This is precisely where digital compliance systems provide direct, practical value, enabling organisations to evidence due diligence in the structured format regulators and courts expect.

The commercial dimension of non-compliance is equally serious. Increased liability for stakeholders extends to Gateway refusals, delayed occupations, and failed contractor pre-qualifications, all of which carry direct financial consequences. As regulatory impact analysis from TLT confirms, liability risks now extend across the supply chain and into corporate transactions. Compliance investment is not simply a legal obligation; it is a business-critical operational priority with measurable commercial upside.

Does the Building Safety Act Affect You If You Are Not in High-Rise?

The formal threshold of 18 metres or 7 storeys defines where the Building Safety Act’s statutory obligations begin, but it does not define where its influence ends. The compliance culture, supply chain expectations, and digital record-keeping standards the Act has introduced are cascading well beyond that boundary, reshaping how the entire construction and facilities management sector operates, regardless of building height.

Facilities managers and building owners responsible for lower-rise residential or commercial properties are encountering this shift through their insurers, lenders, and institutional clients. These market counterparties are applying Building Safety Act-aligned documentation standards even where no statutory obligation exists. This is a market-led compliance cascade rather than a regulatory one, but the practical effect on how you must manage and evidence your safety obligations is identical. If your insurer or lender expects structured, auditable records, the absence of a statutory mandate offers little comfort.

For Principal Contractors managing mixed portfolios of HRB and non-HRB work, the operational reality is straightforward. Maintaining two parallel compliance regimes, one digitised and auditable for high-rise projects and one paper-based for everything else, is neither practical nor sustainable. The logic of a single, consistently applied higher standard is winning, and it is winning quickly.

The same pattern is visible in contractor vetting. The competence assessment obligations the Act introduced for HRB appointments are now being adopted as baseline practice by safety-conscious organisations at every tier. Contractors whose work never touches a qualifying high-rise building are expected to demonstrate equivalent standards simply to remain competitive and win work from compliant clients.

This is precisely where Compliance Genie and Contractor Genie deliver value that extends well beyond any 18-metre threshold. Any business that appoints contractors, manages site safety, or operates within the construction and facilities management sector benefits from the structured, auditable approach both tools enable, providing the defensible evidence trail that the market now demands.

What Should You Do Now? A Practical Building Safety Act Checklist

The following steps cut through the complexity and give you a clear, prioritised action list.

Start by identifying your buildings and your role. Check whether any building you own, manage, design, or are contracted to construct meets the higher-risk building threshold: 18 metres or seven storeys in height, with at least two residential units. For each building that qualifies, map precisely which duty-holder role applies to you. Are you an Accountable Person responsible for the occupied building, a Principal Designer shaping its safety case during design, or a Principal Contractor delivering it on site? These are not interchangeable labels; each carries distinct personal legal obligations, and confusing them is itself a compliance risk.

Audit your documentation systems honestly. If your safety records, inspection logs, contractor information, and design change history live in spreadsheets, email folders, or paper files, you are not meeting the Golden Thread standard. The legislation requires structured, digitally accessible, auditable records, not organised paperwork. Treat closing this gap as urgent, particularly given the BSR’s active enforcement posture from 2026 onwards.

Review your contractor pre-qualification process. Can you produce structured, auditable evidence that you assessed the competence of every contractor appointed on HRB-related work? Informal referencing or verbal checks are not sufficient. This is both a direct legal exposure under the Act and a growing commercial risk: organisations that cannot demonstrate proper pre-qualification are increasingly unable to secure appointments with Tier-1 clients themselves.

Confirm your Gateway status if you have active HRB projects. If any project is at design or construction stage, verify your Gateway 2 approval and begin assembling Gateway 3 documentation now. Retrospective documentation assembly at practical completion is operationally difficult and, critically, unconvincing to the BSR when scrutinised.

Finally, evaluate your current tools against what the Act actually requires. Health and safety management and contractor oversight platforms must be capable of producing structured, shareable, audit-ready digital records on demand. If your current systems cannot do this, exploring purpose-built solutions, such as a dedicated health and safety app or contractor management platform, is no longer optional; it is the practical foundation of defensible compliance.

Staying on the Right Side of the Building Safety Act in 2026

The Building Safety Act is no longer a compliance task sitting on the horizon. With the BSR now operating as a standalone enforcement body and its active enforcement phase firmly underway from April 2026, accountability is the operating reality for every relevant duty-holder. The preparation window has closed.

The practical steps remain clear: confirm your duty-holder roles, close any documentation gaps in your Golden Thread records, digitise your compliance evidence, and ensure your contractor management processes meet the competence assessment standards the Act demands. These are not aspirational goals; they are the baseline the BSR will measure you against.

For Tier-2 operators and SMEs, the challenge is meeting enterprise-level compliance obligations without enterprise-level resources. That is precisely the gap that be-safetech.com’s Compliance Genie and Contractor Genie are built to address. Compliance Genie digitises your health and safety processes into structured, auditable records that hold up under regulatory scrutiny. Contractor Genie centralises contractor management, site visits, and competence verification in one place, giving you the documented due-diligence trail the Act requires. Both tools bring serious compliance capability within reach for businesses without dedicated compliance teams.

If you would like to understand exactly how either product maps to your specific Building Safety Act obligations, get in touch with the be-safetech.com team for a straightforward, no-pressure conversation about where you currently stand and what would genuinely help.

Conclusion

The Building Safety Act 2022 is not simply another regulatory hurdle. It represents a fundamental shift in accountability across the entire built environment. To summarise the essentials: the Act introduces stricter duty holder responsibilities, establishes a robust new regulatory framework for higher-risk buildings, significantly increases penalties for non-compliance, and extends the timeframe for legal liability claims.

The message is clear. Businesses that treat compliance as an afterthought do so at serious financial and reputational risk.

Now is the time to audit your current practices, identify gaps in your obligations, and invest in the training and processes needed to meet the new standards. Whether you are a developer, contractor, or building manager, proactive compliance protects your business and, more importantly, the people who occupy your buildings.

Do not wait for enforcement to force your hand. Lead the change.

Which Service Would You Like to Know More About?

The award-winning Compliance Genie - to digitise all of your Health & Safety processes - or the software platform The Contractor Genie - that helps you manage all of your contractors and their site visits in one place?