Contributors:
- Ali Palizi – Asset Management & Building Safety Lead, Project Four
- Melanie Robinson – Strategy Director, Okana
- Sam Walton – Group Head of Facilities and Health and Safety, Moda Living
Safety doesn’t wait, so why do you?
Around 70% of Building Assessment Certificate applications are being rejected or withdrawn – meaning the majority of PAPs directed to apply are not yet positioned to demonstrate compliance.
When your team get the notification that your report is due, are you ready, or are you waiting until day 28, scrambling to gather what you need? Are you confident in your building, or are you just waiting for someone else to validate it?
A common misconception within the industry is that Building Safety Case Reports represent the end of the process, when realistically, they’re simply the starting point.
The 28-day window is already starting to surface weaknesses in information management processes, governance and culture within owner-operators. The safety case should already be in existence before that alert arrives. That 28 days should be used for submission, not data collection, reconstruction, or compilation.
The real challenge begins once a building enters occupation and those responsible for its safety must continually demonstrate that risks are being identified, assessed, managed, and reviewed throughout the building’s operational life.
This requires far more than documentation.
It requires governance.
It requires ownership.
It requires operational teams, managing agents, asset managers, facilities managers, and Principal Accountable Persons working from a consistent and reliable evidence base.
The strongest organisations are moving beyond a compliance-led approach and towards operational assurance frameworks that embed building safety into day-to-day asset management.
Data management: why overcomplication causes complications
There are so many factors that contribute to poor information architecture. These include, but are not limited to:
- Information being fragmented across multiple systems, folders, inboxes, with no clear view of what is current, approved, suitable for use, or reliable
- Information requirements not defined, or defined too late
- Not being aligned to safety cases, regulatory criteria or the evidence needed to demonstrate active risk management
- A lack of clear ownership – who is responsible for it?
- Information is often stored rather than managed, which means organisations may ‘have’ data, but cannot easily evidence its completion status and how up to date it is
- Digital systems are often implemented in isolation, without the governance, workflows, and interoperability needed to create a reliable source of truth
What this means – your safety case should not be framed as a document, but as a live digital evidence environment that reflects the as-maintained condition of the building and demonstrates that risk is being actively managed.
You need to demonstrate you are in control of your data, it isn’t enough to just say you have it.
Different systems will have different purposes, and the priority should be to govern how information flows between them through clear information management principles. Information requirements will be key to defining and maintaining the safety case, because they clarify what information is needed, why it is needed, who provides it, how it is assured, and when it needs to be updated.
There is a clear need to advocate for the Common Data Environment being understood as the ecosystem in which information is managed, rather than a perceived utopia of “one solution to rule them all”.
The consequences of poor information architecture are not just felt at desk level. They land squarely with the people who inherit the building at handover, and who are then expected to manage and evidence safety for its entire operational life.
The operator’s view: safety cases are not handover packs
One of the biggest shifts created by the Building Safety Act is not simply the introduction of new duties, gateways, safety cases or regulatory processes. It is the shift in accountability.
From an operational standpoint, the Act does not in itself make buildings safer. Buildings become safer when the people responsible for them understand the risk, hold the right information, maintain that information, and can demonstrate that decisions have been made, recorded and acted upon throughout the life of the asset.
The Building Safety Act increases accountability. Safety comes from how seriously we respond to that accountability.
Too often, building safety is still treated as something that happens near the end of a project. A Gateway 3 issue. A practical completion issue. A handover issue. A document pack to be assembled before occupation.
That approach is no longer fit for purpose.
By the time a building is approaching practical completion, the opportunity to resolve fundamental gaps properly has often narrowed. At that stage, teams are no longer shaping the information strategy; they are trying to recover it.
Common issues include:
- Information spread across multiple platforms and common data environments.
- Construction records sitting in systems such as Viewpoint, Boris or contractor-led portals, while O&M information sits separately in platforms such as Zutec.
- No single, agreed Golden Thread structure.
- Design information being treated as evidence of what exists, rather than confirming what has actually been installed.
- Gaps between RIBA Stage 4 intent, RIBA Stage 5 delivery, and RIBA Stage 6 as-built reality.
- Fire and structural safety information being held in separate silos.
- Principal Accountable Person and Responsible Person duties not being clearly understood early enough.
- Operators being asked to accept information that they have had little involvement in shaping.
These are not just administrative issues. They affect the operator’s ability to understand, manage and evidence building safety risk.
A well-written safety case cannot compensate for a poorly managed information journey.
At occupation, operators need confidence that the information being handed over reflects the physical building. They need evidence that design changes have been captured, substitutions have been assessed, commissioning records are complete, critical fire and structural systems are understood, and any residual risks or limitations are clearly recorded.
Without that, the operator inherits uncertainty.
And uncertainty is difficult to manage, difficult to evidence and difficult to defend.
The continuous cycle: as-built to as-maintained
Handover is only one moment in the life of a building.
The more important question is how information is maintained after handover. A building that is accurate on day one will not remain accurate unless there is a clear process for updating information as the asset changes.

Refurbishments, repairs, replacements, inspections, fire door works, façade interventions, plant changes, compartmentation repairs and resident-led alterations all have the potential to affect the building safety picture.
The Golden Thread therefore must move beyond static records. It needs to operate as a continuous cycle:
Design intent → construction evidence → as-built record → operational management → as-maintained record → future change control → updated safety case.
That cycle continues until the building is sold, transferred, redeveloped, or disposed of. Even then, the information has value, because the next owner or operator needs to understand what they are inheriting.
A safety case is not a document that sits on a shelf. It is the operational memory of the building.






