A Gateway 2 application lands at the Building Safety Regulator. Somewhere in the submission, a fire door's rating in the door schedule doesn't match the one in the fire strategy. The rating changed six weeks ago, in an email thread, and the spreadsheet never caught up. The application is returned, and the twelve-week clock resets.
This is not a rare failure. It is the ordinary output of how most project teams still keep their records: a Common Data Environment full of nested folders, spreadsheets, and version-stamped PDFs, each one a static snapshot of a building that keeps changing underneath it.
The Building Safety Act 2022 was built to end exactly this. For Higher-Risk Buildings, defined as those at least 18 metres or 7 storeys tall with two or more residential units, the Act creates a legal duty on the client, principal designer, and principal contractor to establish and maintain a continuous, accurate digital record: the Golden Thread. Not a folder of documents that describes the building. A live record that stays true to it.
What static files break
Keep safety records in spreadsheets, folders, and emails, and three things go wrong.
Decisions separate from the model. When that door rating changed, the 3D model, the door schedule, and the procurement spreadsheet were all meant to update to match. In practice they update manually, sometimes, eventually. The gap between what was decided and what the documents say is specification drift, and it stays invisible until someone goes looking for it.
There is no tamper-evident history. A spreadsheet can be edited at any time by anyone with access, and it carries no record of what it looked like an hour ago. In a regulatory audit, that means you cannot prove when a decision was logged, who approved it, or what evidence they had in front of them at the time.
Handover becomes a dead end. At Gateway 3, a ZIP file of several thousand unlinked PDFs is not a transferable record. It is an index the building's next Accountable Person cannot query, cannot verify, and in practice will struggle to use.
What the Act actually asks for
The regulations behind the Act are more precise than most summaries of the Golden Thread suggest, and worth naming correctly. Under Regulation 19 of the Building (Higher-Risk Buildings Procedures) (England) Regulations 2023, the principal contractor must create and maintain a live record of every controlled change made to the project: the change control log. Each change is classified as Recordable, Notifiable, or Major, depending on its safety impact, and that classification determines whether it simply needs recording, needs to be reported to the regulator, or needs the regulator's approval before work can proceed. This is the mechanism, not a metaphor for it. Teams that treat the Golden Thread as a philosophy rather than a specific record-keeping obligation are the ones who find themselves explaining a gap to the BSR.
Three gates, one thread
Getting a Higher-Risk Building built runs through three checkpoints, and the thread has to survive all of them.
Gateway 1, at planning, requires a Fire Statement setting out how fire safety has shaped the design. That statement should not be a one-off PDF filed and forgotten. It is the baseline every later decision gets checked against.
Gateway 2, before construction starts, requires a full digital description of the building: structural calculations, fire strategy, the detail of key components. Change any of it once work has begun, and that change has to route through the change control log described above.
Gateway 3, at completion, requires the as-built record, every inspection sign-off, every compliance document, consolidated into a single account of the building that was actually built, not the one that was originally designed.
The state of play in 2026
The Regulator's own data is worth being accurate about, because it has moved. Rejection rates of around 70% were widely quoted through 2024 and into early 2025. On the BSR's 12-week rolling figures to 1 August 2026, building control approvals across all categories stood at 82%, with new higher-risk buildings and conversions at 91% and external remediation at 85%. The system is working substantially better than it was a year ago, and anyone still quoting the old rejection rates is quoting history.
What has not changed is the character of the applications that still fail. Industry analysis of rejected submissions points to five recurring gaps: unevidenced Principal Designer competence, designs too immature to assess, fire strategies never coordinated with the rest of the design, confusion between CDM and Building Safety Act dutyholder roles, and golden thread information that exists but isn't structured or attributed well enough for a regulator to interrogate it. That last one is an information problem, and it has an information answer. The other four are process and competence problems no software solves on its own.
A record instead of a filing system
The direction of travel is away from documents and towards structured data, and there is more than one way to move. Disciplined teams already run their CDEs to ISO 19650, with naming conventions, version control, and access rules that go some way towards the duty. Others are taking the further step of moving the building information itself into structured, queryable form, so that a fire wall, a pipe penetration, or a door rating becomes a single record that every schedule and strategy reads from, rather than a fact copied by hand into five places.
The Act does not mandate a method. It mandates outcomes: that you can show who changed what, and when, and that you can prove nothing has been altered since. That is the bar to judge any record-keeping system against, whether you build it, buy it, or already have it. A folder of PDFs cannot meet it. A well-run CDE gets closer, though its audit trail still lives at the level of files, not facts. A structured record with a tamper-evident history, where each entry is linked to the one before it, meets it by construction: alter history after the fact and the chain breaks, and shows exactly where.
Get the record right and compliance checking stops being a separate task. It becomes a side effect of how the information is kept. The fire door from the opening of this article never gets the chance to disagree with itself. Its rating lives in one place, the schedule and the strategy both read from it, and the moment it changes, the log records who changed it and why.
If you are preparing a Gateway submission or handing over a completed HRB, the question to ask of your record-keeping is not whether it is tidy. It is whether it can prove itself.
Ready to secure your project's compliance?
Ditch error-prone spreadsheets and fragmented PDFs. Win Win Designs creates an automated, immutable audit trail of your building record, natively aligned with BSA 2022 expectations.

