← Back to blog

How property safety legislation affects firms: 2026 guide

August 5, 2026
How property safety legislation affects firms: 2026 guide

Property-safety law now places named, legally accountable individuals at the centre of every compliance decision — and the consequences of getting it wrong range from unlimited fines to criminal prosecution. How property safety legislation affects firms has shifted dramatically since the Building Safety Act 2022 came into force, and the 2026 regulatory picture is sharper still, with person-centred fire rules and strengthened recordkeeping obligations adding new layers of duty for landlords, employers, and property managers alike.

Three things to do right now:

  1. Confirm who holds the Responsible Person and Accountable Person roles for every building you manage — in writing.
  2. Check that your CP12 gas safety certificate and EICR are current and on file for each property.
  3. Start a centralised digital record (a Golden Thread equivalent) for every asset, even if it falls below the higher-risk building threshold.

The stakes are concrete:

  • Criminal liability can attach to individuals, not just companies, under the Health and Safety at Work etc. Act 1974 and the Building Safety Act 2022.
  • A missing or expired CP12 or EICR is one of the most common triggers for local authority enforcement action.
  • Resident-focused fire risk assessments (PCFRAs) became a legal requirement for specified residential buildings from 6 April 2026, adding a social-care dimension to what was previously a structural exercise.
  • Fragmented recordkeeping is the single most cited weakness when regulators investigate incidents.

Table of Contents

Which UK safety laws and regulators apply to your property?

Understanding the full legislative picture is the starting point for any compliance programme. The laws below are not alternatives to one another; most buildings will be subject to several simultaneously.

LegislationCore obligationEnforcing body
Regulatory Reform (Fire Safety) Order (FSO)Fire risk assessment, fire-precaution maintenance, cooperation dutiesLocal fire and rescue authority
Fire Safety (England) Regulations 2022Recorded FRAs, floor plans, information box, resident engagementLocal fire and rescue authority
Fire Safety (Residential Evacuation Plans) Regulations 2025PCFRAs and PEEPs for specified residential buildings from 6 April 2026Local fire and rescue authority
Building Safety Act 2022Registration of higher-risk buildings, Golden Thread, Accountable PersonBuilding Safety Regulator (HSE)
Health and Safety at Work etc. Act 1974Employer duty of care for employees and others affected by work activitiesHSE
Gas Safety (Installation and Use) RegulationsAnnual CP12 by a Gas Safe registered engineerHSE / Gas Safe Register
Electrical Safety Standards in the Private Rented Sector (England) Regulations 2020EICR every five years for most rental propertiesLocal housing authority
Control of Asbestos Regulations 2012 (CAR 2012)Asbestos management survey, management plan, contractor notificationHSE
HHSRS / Renters' Rights Act 2025Fitness for human habitation, hazard remediationLocal housing authority

Infographic showing UK property safety laws overview

A few points worth noting. The Building Safety Act 2022 applies specifically to higher-risk buildings (generally residential buildings of 18 metres or more, or at least seven storeys, with two or more dwellings), but its Golden Thread principle is increasingly treated as best practice for any multi-occupied asset. The Fire Safety (England) Regulations 2022 commenced on 23 January 2023 and supplement, rather than replace, the FSO. The Renters' Rights Act 2025 strengthens the Housing Health and Safety Rating System (HHSRS) framework, and landlord safety responsibilities under it now carry heavier penalties than the previous regime.


Who is legally responsible, and can you transfer that liability?

Legal responsibility under UK property-safety law is layered, and the roles are not interchangeable.

Over-shoulder hands pointing at legal roles table

Responsible Person (FSO): The employer, freeholder, or person in control of non-domestic premises. In a multi-occupied residential building, this is typically the building owner or managing agent. The Responsible Person must carry out and record a fire risk assessment, maintain fire-precaution measures, and cooperate with other Responsible Persons in the same building.

Accountable Person / Principal Accountable Person (Building Safety Act 2022): Applies to higher-risk buildings. The Accountable Person holds the legal interest in the common parts; where there are multiple Accountable Persons, the one with the greatest obligation for the structure and exterior is the Principal Accountable Person. Both roles carry registration duties with the Building Safety Regulator and ongoing obligations to maintain the Golden Thread.

Employer (Health and Safety at Work etc. Act 1974): Any employer with staff working in or around a property carries a duty of care to those workers and to others affected by the work. This duty cannot be contracted away.

Landlord: Responsible for statutory certificates (CP12, EICR, EPC) and for ensuring the property is fit for human habitation under the Landlord and Tenant Act 1985 as amended.

The table below summarises the key roles, their scope, and whether liability can be transferred.

RoleLegal basisCan liability be transferred?
Responsible PersonRegulatory Reform (Fire Safety) OrderNo — ultimate liability stays; tasks can be outsourced
Accountable PersonBuilding Safety Act 2022No — statutory duty is non-delegable
EmployerHealth and Safety at Work etc. Act 1974No — duty of care is non-delegable
Landlord (safety certificates)Gas Safety Regs; Electrical Safety Regs 2020Civil-penalty liability can transfer to agent by written agreement

The written-transfer point matters in practice. Under the Right to Rent code of practice, if an agent accepts written responsibility for a specific duty, civil-penalty liability for that duty transfers to the agent. Without that written agreement, the landlord retains responsibility for safety certificates such as the CP12 and EICR. The lesson is straightforward: verbal arrangements and informal understandings carry no legal weight. You can outsource the execution of safety checks to a third party, but ultimate legal liability remains with the named duty-holder.


What compliance actions must your firm actually carry out?

The obligations below apply across most commercial and residential property portfolios. Frequencies are statutory minimums; some assets or tenancy types require more frequent checks.

Statutory tasks and typical frequencies:

  • Fire risk assessment (FRA): — No fixed statutory interval, but must be reviewed after any significant change and kept under regular review. Must be recorded in full for premises with five or more employees or where a licence is required.
  • CP12 gas safety check: — Annually, by a Gas Safe registered engineer.
  • EICR: Every five years for most private rented sector properties, or at change of tenancy if sooner. Commercial properties follow a different schedule set by BS 7671.
  • Smoke and CO alarm checks: Required at the start of each tenancy; alarm requirements for rental properties have been strengthened under the Renters' Rights Act 2025.

Recordkeeping standard:

DocumentMinimum retentionFormat expected by regulators
Fire risk assessmentUntil superseded plus review historyWritten, dated, signed
CP12 gas safety recordTwo years (landlord copy); give to tenant within two daysPaper or digital
EICRUntil next inspectionWritten report with remedial actions
Asbestos management planLife of buildingWritten, updated on change
Golden Thread (higher-risk buildings)Ongoing live recordDigital, accessible to BSR on request
PCFRA and PEEP recordsOngoing, reviewed on change of resident needsDigital, GDPR-compliant

UKAS-accredited laboratory evidence materially strengthens a firm's legal defence during inspections and insurance claims. Regulators and courts increasingly expect empirical, accredited analysis for specialist risks such as asbestos identification and water microbiology, rather than subjective visual checks by non-specialists.


How do shared buildings create extra compliance complexity?

Multi-occupied and multi-tenanted buildings are where compliance gaps most often appear, because the question of who is responsible for what in common areas can become genuinely ambiguous without explicit agreements.

Article 22 of the FSO requires every Responsible Person in a shared building to cooperate and coordinate with every other Responsible Person. In practice, this means sharing relevant fire-safety information, aligning inspection schedules, and ensuring that no common area falls into a gap between two parties' assumed responsibilities. The Fire Safety (England) Regulations 2022 add further requirements: electronic floor plans must be shared with the local fire and rescue service, a single-page building plan must be placed in a secure information box on site, and external-wall design information must be recorded.

Common failures in multi-tenanted buildings include:

  • No written agreement specifying which Responsible Person covers which common areas.
  • Inspection schedules that differ between occupiers, leaving gaps in fire-door and emergency-lighting checks.
  • Poor data sharing between the structural FRA assessor and the PCFRA assessor, resulting in conflicting evacuation plans.
  • Failure to update the fire service when building layout or occupancy changes.

A minimum cooperation agreement for a shared building should cover: the identity and contact details of each Responsible Person; a schedule of common-area inspections and who commissions them; the process for sharing FRA findings and PCFRA data; and a protocol for notifying the fire service of material changes. This does not need to be a lengthy legal document, but it does need to exist in writing and be reviewed annually.

Pro Tip: If your building has a managing agent, confirm in writing which compliance tasks the agent accepts responsibility for. Without that written allocation, the statutory duty defaults to the building owner.


What operational changes should firms expect?

The shift from periodic box-ticking to continuous, evidence-backed safety management has real cost and resource implications. Property managers and business owners should plan for the following.

Team discussing property compliance operations

Recordkeeping and data systems: The Golden Thread obligation for higher-risk buildings requires a live digital record of all safety-relevant information, accessible to the Building Safety Regulator on request. Even for buildings below the higher-risk threshold, maintaining a continuous digital audit trail materially improves the ability to defend against HSE audits or insurance claims. A centralised compliance portal, rather than a folder of PDFs, is now the practical standard.

Contractor procurement: Every contractor carrying out safety-critical work must hold the appropriate accreditation. Gas Safe registration for CP12 engineers, NICEIC or equivalent for EICR electricians, and UKAS-accredited laboratories for asbestos and water-microbiology analysis. Contract clauses should require contractors to provide evidence of accreditation, retain chain-of-custody documentation, and submit reports in a format compatible with your digital records system.

Staffing and training: The PCFRA requirement introduces a social-care dimension that most property management teams have not previously needed to manage. Assessors must be trained to engage sensitively with residents, and GDPR-compliant processes must be in place to handle the personal data gathered during resident engagement. This may require either upskilling existing staff or commissioning specialist assessors.

Budget drivers:

  • Remediation of external walls and cladding (where required by the Building Safety Act regime) represents the largest potential cost for affected buildings.
  • UKAS-accredited testing for asbestos and water systems adds cost compared with non-accredited alternatives, but the legal risk of relying on non-accredited analysis is substantially higher.
  • Increased maintenance frequency for fire doors, emergency lighting, and alarm systems adds to annual running costs.
  • Managed-service or outsourced compliance support carries a fee, but eliminates the overhead of in-house scheduling, contractor vetting, and certificate tracking.

The commercial case for compliance extends beyond avoiding penalties. Properties with documented, up-to-date safety records command stronger insurance terms and are easier to let and sell.


How do regulators enforce these rules, and what penalties apply?

Enforcement of property-safety legislation in the UK is not theoretical. Local fire and rescue authorities, the HSE, local housing authorities, and the Building Safety Regulator all have active inspection and prosecution programmes.

Common enforcement tools:

  • Inspection: Unannounced or scheduled visits to check FRAs, maintenance logs, contractor evidence, and resident engagement records.
  • Enforcement notice: Requires specific remedial action within a set timeframe.
  • Prohibition notice: Restricts or prohibits use of a building or part of it until specified conditions are met.
  • Alteration notice: Requires the Responsible Person to notify the fire authority before making changes to the building.
  • Prosecution: Can result in unlimited fines and, in the most serious cases, custodial sentences.

What inspectors specifically look for: a current, recorded FRA with evidence of review; maintenance logs for fire doors, emergency lighting, and alarms; Gas Safe and NICEIC certificates for recent work; UKAS-accredited lab reports for asbestos and water systems; and, from April 2026, PCFRA records with evidence of resident engagement and consented data-sharing.

The regulatory landscape shifted significantly in 2025–2026. Under the updated HHSRS and Renters' Rights Act 2025 regime, penalties for safety failures range from fixed financial penalties to unlimited fines and possible custodial sentences in severe cases. The Building Safety Act 2022 also introduced personal liability for the Principal Accountable Person, meaning company directors and senior managers can face prosecution as individuals, not just as officers of a corporate entity.

The corporate manslaughter threshold, under the Corporate Manslaughter and Corporate Homicide Act 2007, applies where a gross breach of a duty of care by senior management causes death. Several high-profile prosecutions in the construction and facilities sectors have demonstrated that regulators are prepared to pursue this charge where the evidence supports it.


Your 30/90/365-day compliance plan

A structured timeline prevents the paralysis that often follows a compliance audit. The tasks below are sequenced by urgency and by the lead time required to commission specialist work.

30 days: document audit and urgent gaps

  1. Identify the Responsible Person and Accountable Person (where applicable) for every building in writing.
  2. Pull all current CP12, EICR, EPC, and FRA records and flag any that are expired or missing.
  3. Check whether any buildings are higher-risk under the Building Safety Act 2022 and confirm registration status with the Building Safety Regulator.
  4. Review cooperation agreements for any shared buildings; identify gaps in common-area responsibility.
  5. Confirm that all gas appliances have been checked by a Gas Safe registered engineer within the past 12 months. Book urgent CP12 inspections for any that have not.

90 days: schedule and commission

  1. Commission outstanding EICRs from a qualified electrician (NICEIC or equivalent). For most rental properties, the five-year EICR cycle applies.
  2. Engage a competent fire-risk assessor to review or produce FRAs for all premises, and commission PCFRA assessments for any specified residential buildings.
  3. Commission a Legionella risk assessment and water-management plan if not current.
  4. Arrange asbestos management surveys for any pre-2000 buildings where surveys are not on file.
  5. Begin building or migrating to a centralised digital compliance record for all assets.

365 days: embed and maintain

  1. Implement a Golden Thread-style digital record for higher-risk buildings; extend the same system to the wider portfolio as best practice.
  2. Update procurement contracts to require UKAS accreditation evidence from all specialist contractors.
  3. Schedule annual CP12 renewals, six-monthly fire-door checks, and quarterly emergency-lighting tests as recurring calendar events.
  4. Review all cooperation agreements and service-level clauses in shared buildings annually.
  5. Train relevant staff on PCFRA processes, GDPR obligations for resident data, and the firm's emergency evacuation procedures.

For rough cost orientation: a CP12 inspection for a single property typically costs a moderate fee; an EICR for a standard flat generally costs a modest amount; a professional fire risk assessment for a small commercial premises starts at a base fee. Cladding and external-wall remediation for affected higher-risk buildings can vary widely depending on scope. These figures are indicative; always obtain quotes from accredited contractors for your specific assets.

This article provides general information, not legal or professional advice. Confirm current obligations with the relevant primary sources or a qualified professional.


Common compliance gaps and how to fix them

The same weaknesses appear repeatedly when property managers and business owners review their compliance position. Recognising them early is considerably cheaper than encountering them during an inspection.

Gap 1: treating compliance as a one-off event. Booking a CP12 or EICR and filing the certificate is not compliance; it is the start of a cycle. Treating safety as ongoing operational priority backed by data is the standard regulators now expect.

Gap 2: fragmented contractor records. When different contractors carry out gas, electrical, and fire-safety work, their reports often live in separate email inboxes or paper files. A single incident investigation can expose the absence of a coherent audit trail very quickly.

Gap 3: poor resident engagement for PCFRAs and PEEPs. The transition from structural-only fire safety to person-centred assessment requires assessors who can engage sensitively with residents and GDPR-compliant processes for handling the personal data gathered. Many firms have not yet built this capability.

Gap 4: overreliance on visual checks. Regulators and courts increasingly expect UKAS-accredited laboratory analysis for specialist risks such as asbestos identification and water microbiology, rather than subjective in-house assessments. A visual check that misses a risk does not provide a legal defence.

Gap 5: unclear common-area responsibility. Article 22 cooperation duties are frequently overlooked in multi-tenanted buildings. Without an explicit written agreement, each Responsible Person tends to assume the other is covering shared spaces.

Practical fixes:

  • Centralise all compliance records in a single digital system, even a well-structured shared drive, before migrating to a purpose-built portal.
  • Insist on UKAS-accredited analysis for asbestos and water-system testing; include this as a contract requirement.
  • Appoint a named compliance lead within the organisation with authority to commission work and sign off records.
  • Build PCFRA and PEEP processes into your standard resident-onboarding workflow, with a GDPR-compliant consent mechanism from day one.
  • Review cooperation agreements in shared buildings at every lease renewal or management contract renewal.

Pro Tip: A property management firm that centralised its compliance records into a single portal and introduced accredited contractor requirements across its portfolio found that its insurance renewal process became significantly faster and its premium more competitive. The insurer's surveyor cited the quality of the audit trail as the primary reason.


Key takeaways

UK property-safety legislation now requires named, legally accountable individuals to maintain continuous, evidence-backed safety management across all premises — and the penalties for failing to do so extend to unlimited fines and personal criminal liability for directors and senior managers.

PointDetails
Confirm legal roles in writingIdentify your Responsible Person and Accountable Person for every building before any other action.
Keep certificates currentCP12 annually, EICR every five years for most rental properties; expired certificates are a primary enforcement trigger.
Build a centralised digital recordA Golden Thread-style audit trail is mandatory for higher-risk buildings and best practice for all assets.
Commission PCFRAs for specified buildingsPerson-centred fire risk assessments became a legal requirement for specified residential buildings from 6 April 2026.
777pcm for end-to-end compliance777pcm provides CP12, EICR, fire risk assessments, and remedial works through in-house engineers, with portfolio-level digital records management.

Why the shift from reactive to data-driven safety management is overdue

The most persistent misconception in property safety is that compliance is a paperwork problem. Get the certificates, file them, move on. What the Building Safety Act 2022 and the 2026 fire-safety regulations have done is make that approach legally untenable. The Golden Thread is not a filing system; it is a live record of a building's safety state, expected to be accurate at any given moment and accessible to the regulator on demand. The PCFRA is not a form; it is an ongoing relationship with residents that requires trained assessors, consented data-sharing, and regular review.

The firms that will navigate this environment well are those that treat safety management the way they treat financial management: continuous, data-driven, and owned by a named individual with real authority. The ones that will struggle are those still operating on the assumption that an annual certificate visit constitutes a compliance programme.

There is also a commercial dimension that often gets overlooked. Properties with documented, current safety records are easier to insure, easier to let, and easier to sell. A well-maintained compliance position is not just a legal obligation; it is a tangible asset in a portfolio's value.

The 2026 regulatory picture is the clearest signal yet that the direction of travel is towards greater accountability, more granular evidence, and heavier consequences for those who treat safety as an afterthought. The time to build the systems and relationships that make continuous compliance possible is before an inspector arrives, not after.


777pcm handles your compliance so you can focus on your portfolio

Keeping pace with CP12 renewals, EICR cycles, fire risk assessments, and the new PCFRA requirements across a property portfolio is a significant operational commitment, and the cost of a missed certificate or a fragmented audit trail is now measurably higher than the cost of getting it right.

777pcm

777pcm provides end-to-end property compliance and maintenance for landlords, letting agents, and property managers across the UK. In-house Gas Safe registered engineers handle CP12 gas safety certificates; qualified electricians carry out EICRs; and the team covers Legionella checks, asbestos surveys, fire risk assessments, remedial works, and ongoing maintenance through a single point of contact. Every job is managed through a compliance portal that gives you a clear, up-to-date record of every certificate and inspection across your portfolio, with no reliance on third-party subcontractors.

For firms managing multiple properties, 777pcm's bulk-booking capability and emergency-response service mean that urgent gaps in your compliance position can be addressed quickly. Whether you need a single CP12 or a full portfolio audit, the process starts with a straightforward conversation. Request a portfolio compliance review or book a CP12 inspection directly to get your compliance position confirmed and documented.


Useful sources and further reading