Co-authored with Dr Krish Parmar, Founder of Elevate Building Safety, a Building Safety Act compliance consultancy working with developers, asset owners, and duty holders on safety case delivery.
TL;DR: A safety case is not a document you write. It is the outcome of a structured process, and four phases come before anyone drafts the safety case report: a golden thread gap analysis, a workshopped risk assessment, an audit of how the building is actually managed, and a review of resident engagement and occurrence reporting. Skip a phase and the report may not withstand regulatory scrutiny.
See the full Safety Case Report guide →
A Safety Case Is a Process, Not a Document
The most common mistake we see with higher-risk buildings is treating the safety case as a writing exercise: open a template, describe the building, attach the fire risk assessment, submit. That version fails because it demonstrates nothing about how risk is actually understood and managed.
A safety case is not just a document. It is the outcome of a structured process that helps the PAP and managing agent understand the building and its inherent risks in a clear and evidence-based way. — Dr Krish Parmar, Elevate Building Safety
The legal duties behind this are split deliberately. Accountable persons must assess and manage building safety risks (Building Safety Act 2022, s.83 and s.84). The principal accountable person must prepare the safety case report (s.85), supported by the wider building information and evidence maintained through the Golden Thread arrangements (s.88). The report is the last step, not the first: it summarises a safety case that must already exist.
In most blocks, the PAP is a residents' company or freeholder, but the managing agent operates the building day to day. That split is where safety cases quietly fall apart: the duty sits with one party while the evidence sits with another. This piece walks through the four phases in order, and for each one, what the managing agent specifically needs to have in place, because that is the side directors usually cannot see.
Phase 1: Golden Thread Gap Analysis
Phase 1 establishes what information exists, what is missing, and whether the current evidence base is reliable enough to support risk assessment. — Dr Krish Parmar
Before anyone assesses risk, you need to know what you actually know about the building. That means cataloguing the structural and fire safety information you hold (drawings, fire risk assessments, O&M manuals, remediation records, fire door and damper surveys) and honestly recording what is missing, outdated, or unverifiable. A 1970s block whose original plans are lost is not unusual; a safety case that pretends otherwise is.
A thorough gap analysis does more than create a list of documents. It tests whether the information is relevant, current, traceable, and consistent with the building as it exists today. The review should cover the building's design and construction, fire and structural safety information, refurbishment and remediation history, inspection and maintenance records, resident information, previous incidents, risk assessments, and any assumptions relied upon in the building's management arrangements.
Reliable enough does not mean every historic document must be available. It means the PAP and managing agent understand the limitations of the evidence, have tested important assumptions, and have made proportionate decisions about how gaps will be addressed. Some gaps may require new surveys or specialist advice. Others may be managed through interim controls, monitoring, or clearly recorded assumptions. What matters is that uncertainty is visible, assessed, and actively managed rather than hidden within the report.
What the managing agent needs in place:
- A single, organised repository of building information, not a folder of spreadsheets and inbox attachments. Section 88 requires the information to be kept, current, and transferable.
- A documented inventory of what is held, with dates and provenance: who produced each document, when, and whether it reflects the building as it stands today.
- A gap register: every missing or unreliable item logged, with a decision on each. Commission a survey, accept and mitigate, or escalate to the PAP.
- Handover discipline. When agents change, the golden thread must move intact; a gap analysis that has to start from zero after every re-tender is a structural failure.
Phase 2: Hazard Identification and Risk Assessment
Phase 2 is where you build a clear picture of the building's inherent risks, taking into account the building itself and the residents who live there. — Dr Krish Parmar
This is the phase software cannot perform on its own, and the phase most often shortcut. A building's risk picture cannot be produced by one person filling in a form for an hour. It has to be workshopped: fire engineering, structural knowledge, management reality, and resident profile in the same room, working through the scenarios government guidance sets out. Two identical towers with different resident populations have different risk pictures. Evacuation capability, vulnerability, and behaviour are part of the assessment, not an afterthought.
Elevate approaches the hazard identification and risk assessment as a structured, multidisciplinary exercise rather than a desktop form-filling task. The workshop should bring together the people who understand the building's fire and structural design, its day-to-day operation, its maintenance history, and the residents who may be affected by an incident. Depending on the building, this may include the PAP, managing agent, building manager, fire risk assessor or fire engineer, structural engineer, maintenance representatives, and people responsible for resident engagement and emergency arrangements.
The workshop examines credible fire and structural failure scenarios, how each event could develop, who may be exposed, what existing controls are relied upon, and whether those controls are effective and evidenced. It should also consider interactions between hazards, failures in management arrangements, changes to the building, and the needs of residents who may require assistance. The output is not simply a risk score. It is an agreed risk picture that identifies the significant hazards, the controls relied upon, evidence gaps, further actions, and the people responsible for maintaining the assessment.
What the managing agent needs in place:
- The Phase 1 outputs, ready to hand: the risk workshop runs on the evidence base, and arrives dead if participants spend the session hunting for documents.
- Operational knowledge on tap: incident history, near-misses, recurring defects, contractor observations. The agent is usually the only party who holds this.
- What the agent knows about residents relevant to evacuation and vulnerability, gathered and handled lawfully, including PEEPs status.
- A route to commission competent external input. Assessing whether risk assessors are competent is itself a duty; "the cheapest quote" is not a competency assessment.
Phase 3: The Building Safety Management System Audit
Phase 3 tests whether the operational controls, processes and responsibilities are mature enough to manage the risks identified. — Dr Krish Parmar
Knowing the risks is half the case. The other half is proving the building is run in a way that controls them, day in, day out. That means auditing the management system itself: are alarms, sprinklers, dampers and the premises information box maintained on schedule? Are responsibilities assigned to named roles? Are contractors competent and their work evidenced? An FRA action closed with no record of who did what, when, is not evidence. It is an assertion.
This is the phase where good tooling earns its keep: a building where 35 of 40 FRA actions are complete with evidence, 3 are in progress with contractors assigned, and 2 are overdue with escalation records visibly demonstrates active management. A building where the answer lives in someone's memory demonstrates the opposite.
A Building Safety Management System audit examines whether the organisation can demonstrate that its stated arrangements operate consistently in practice. It should test governance, accountability, competence, inspection and maintenance, contractor control, change management, action tracking, document control, emergency arrangements, incident management, and assurance. A mature system has clear ownership, defined escalation routes, and records that show how safety-critical decisions were made. Important controls are connected to the hazards identified in the risk assessment, with named responsibilities, frequencies, evidence requirements, and review arrangements.
Common weaknesses include policies that are not reflected in day-to-day practice, actions closed without supporting evidence, unclear responsibility between the PAP and managing agent, incomplete contractor competence records, inconsistent document control, and limited assurance that critical systems remain effective. Maturity is therefore not measured by the number of procedures an organisation holds. It is measured by whether people understand their responsibilities and whether the organisation can demonstrate that risks are being controlled, monitored, and reviewed.
What the managing agent needs in place:
- A maintenance and inspection regime mapped to the risk picture from Phase 2: every control the risk assessment relies on has an inspection frequency, a named owner, and a record trail.
- Fire risk assessment actions tracked to closure with evidence attached to each action: date, contractor, photos, sign-off.
- Competency records for staff and contractors doing safety-critical work.
- Audit trails that survive staff turnover: the system, not the person, holds the knowledge.
Phase 4: Resident Engagement and Mandatory Occurrence Reporting
Phase 4 ensures the building has the right mechanisms for transparency, reporting and learning. — Dr Krish Parmar
The final phase before the report looks outward. The PAP must have a resident engagement strategy: how residents are informed about building safety, how they raise concerns, and how those concerns are handled. And the building needs a working mandatory occurrence reporting system under s.87, so structural and fire safety occurrences reach the Building Safety Regulator through a defined route rather than depending on someone knowing who to phone.
Good resident engagement goes beyond publishing a strategy. Residents should be able to understand the building's significant safety arrangements, raise concerns through accessible channels, and see that those concerns are acknowledged, assessed, and acted upon. The organisation should also be able to demonstrate how resident feedback has influenced decisions, communications, or risk controls.
Mandatory occurrence reporting requires the organisation to recognise events or situations that could create a significant risk of death or serious injury arising from fire spread or structural failure. Potential triggers can be missed when staff treat reporting as relevant only after a major incident. Serious defects, repeated failure of safety-critical systems, unexpected structural movement, compromised compartmentation, or information suggesting that an important control cannot be relied upon may all require formal assessment. Staff and contractors therefore need a clear route for raising potential occurrences, with competent review, escalation, record keeping, and timely reporting where the statutory threshold is met. The system should also capture lessons and demonstrate what changed as a result.
What the managing agent needs in place:
- The engagement strategy operationalised: publication channels, a complaints and concerns route with response times, and records showing both are used. A strategy PDF written once and filed does not count.
- A defined MOR pathway every site and office staff member knows: what counts as a reportable occurrence, who assesses it, who submits, within what timescale.
- Evidence of learning: concerns raised, occurrences reported, and what changed as a result. Regulators read Phase 4 as a test of culture.
Then, and Only Then, the Report
Only once these phases are complete should the safety case report be written. The report uses the claim, argument and evidence structure to demonstrate how the PAP manages the building's major fire and structural risks in a coherent and regulator-ready way. — Dr Krish Parmar
Done in this order, the safety case report becomes a coherent synthesis of the risk picture, management arrangements, and supporting evidence, rather than a narrative assembled retrospectively: the claims are the risk picture from Phase 2, the argument is the management system from Phase 3, and the evidence is the golden thread from Phase 1, kept honest by the transparency mechanisms in Phase 4. Done in reverse, report first and evidence retrofitted, it reads exactly like what it is.
One more thing the report is not: finished. The safety case is a living picture of the building. When the FRA is renewed, a major work completes, or the resident profile shifts, the case moves and the report must follow (BSR guidance on preparing a safety case report).
Where the division of labour lands. Phases 1, 3 and 4 are systematic: cataloguing, tracking, evidencing, engaging. That is what a platform like Brocade is built for. Phase 2 is judgment: multi-disciplinary, building-specific, and human. That is consultant territory. A tool alone gives you an organised building with an unassessed risk picture; a consultant alone produces an assessment resting on evidence nobody maintains. A real safety case needs both.
Read the complete Golden Thread guide →
Common Mistakes
- Writing the report first. The template gets filled, the process never happens, and BSR assessment exposes the difference.
- Treating the FRA as the safety case. The fire risk assessment is one input to Phase 2, not a substitute for the whole process.
- One person, one hour, one spreadsheet. Risk assessment done in isolation misses the interactions between building, management, and residents that workshops exist to surface.
- Evidence by assertion. Alarms are tested weekly with no test log is a claim, not evidence. Every control needs a record trail.
- Parking the case after submission. A safety case dated three years ago describing a building that has since had major works is worse than no case: it proves the process is not live.
Questions
Is the safety case the same thing as the safety case report? No. The safety case is the ongoing body of evidence and risk management for the building. The safety case report is the document that summarises it for the Building Safety Regulator, required by section 85 of the Building Safety Act 2022. You can have a report without a safety case; it just will not survive assessment.
Can software produce a safety case on its own? No. Software is the right tool for Phase 1 (organising the golden thread), Phase 3 (tracking controls and evidence), and Phase 4 (engagement and reporting records). Phase 2, hazard identification and risk assessment, must be workshopped by competent people who know the building, its management, and its residents.
Who is responsible for the safety case in a leasehold block? The principal accountable person holds the legal duty under Part 4 of the Building Safety Act 2022. In practice the managing agent operates most of the controls and holds most of the evidence, so the PAP's compliance depends on the agent being organised at every phase.
How often does a safety case need updating? Continuously. The safety case is a living picture of the building's risks and controls. The report must be revised when anything material changes (a renewed FRA, completed works, a changed resident profile), not parked on a five-year cycle.
What happens if the evidence base is weak? A report built on missing or unreliable information will not stand up to Building Safety Regulator assessment. That is what the Phase 1 gap analysis is for: finding the holes and deciding how to fill them before the report is written, not discovering them when the regulator asks.
This guide is for informational purposes. For building-specific advice, consult a qualified fire safety professional.

