FM teams struggle to centralise compliance records because the evidence is created by different people, at different sites, through different workflows. Documents become separated from the assets, inspections and remedial actions they relate to. A central system helps, but only when the organisation also defines ownership, evidence standards, review processes and escalation routes.
Why is centralising compliance evidence so difficult?
Is this really a document-storage problem?
Why do different sites develop different processes?
How do contractors contribute to fragmented records?
What does unclear ownership look like in practice?
Why are certificates not enough?
How does poor asset data weaken compliance assurance?
What should a central compliance record contain?
How should FM teams approach centralisation?
What should compliance software provide?
Every FM has experienced the moment when somebody asks for a certificate and everyone agrees that it definitely exists.
The less certain part is whether it lives in an inbox from 2022, a contractor portal, a shared drive, a paper site file or the downloads folder of somebody who left six months ago. In a multi-site estate, “somewhere” can cover an impressive amount of territory.
This fragmentation is rarely caused by carelessness. Compliance evidence is produced through dozens of separate operational processes: inspections, planned maintenance visits, risk assessments, remedial works, internal checks and contractor appointments. Different people commission the work, attend the site, complete it, receive the paperwork and decide what happens next.
Unless those stages are connected, the record tends to stop wherever the last person left it.
That is why centralising compliance records is not primarily a filing exercise. It is an information-management problem involving ownership, workflows, asset data, evidence standards and access. Moving every PDF into one folder may make the disorder more geographically convenient, but it does not establish whether the records are complete, current or usable.
No. The deeper problem is that many organisations centralise files without centralising the process that creates and controls them.
A shared repository can tell you where a document has been saved. It cannot automatically tell you:
The distinction matters because audit readiness depends on more than retrieval. A strong compliance record should show the obligation, the planned activity, the completed work, the resulting evidence and the response to any findings.
Without that chain, a folder full of certificates may create reassurance without providing much assurance.
The official golden-thread guidance for in-scope higher-risk buildings in England makes this distinction particularly clear. It describes building information as something that must be digital, secure, available, usable, current and capable of acting as a single source of truth. These specific duties do not apply to every building or FM team, but the information-management principles are useful across an estate.
Sites develop their own processes because local teams need to keep the operation moving, often before anybody has established an estate-wide standard.
One building may have a diligent facilities coordinator with a carefully maintained folder structure. Another may depend on its maintenance contractor’s portal. A recently acquired site may still use the previous owner’s spreadsheet, while a smaller location emails everything to head office and hopes somebody there knows what to do with it.
Each method can appear workable in isolation. The difficulty emerges when the organisation needs to answer a portfolio-level question.
For example, a compliance manager may need to know which sites have current water-hygiene risk assessments, whether the required monitoring is taking place and which recommended actions remain open. If every location labels, stores and reports that information differently, producing the answer becomes a manual reconciliation exercise.
The spreadsheet everyone is afraid to delete normally appears at this stage. Nobody is entirely sure whether it is authoritative, but it contains three columns that exist nowhere else, so it continues its distinguished career.
Common causes of site-level variation include:
Centralisation therefore requires some standardisation, but not the pretence that every building is identical. Sites may have different risks, assets and legal responsibilities. The common process should define how those differences are recorded and governed.
Contractors often create the evidence that FM teams need, but they do not necessarily create it in the format, system or timeframe the client requires.
One contractor uploads certificates to its own portal. Another sends a PDF with an invoice. A third emails the site contact, while a fourth promises to send the paperwork later. “Later” is a flexible unit of time in contractor administration.
This becomes a centralisation problem when the contract defines the technical work but says little about information handover. The visit may have taken place, yet the FM team still lacks the evidence needed to confirm completion, assess findings or demonstrate compliance.
Contractor requirements should specify:
Direct contractor access to a CAFM platform can reduce email handling and duplicate entry, particularly where evidence can be attached to the relevant work order or asset. It only works, however, if somebody checks what has been uploaded. A photograph of a certificate taken from the other side of a plant room is technically a document submission, but it is not a useful compliance record.
Unclear ownership means several people are involved, but nobody is explicitly accountable for the complete outcome.
An estates team may own the compliance policy, a site manager may provide access, a contractor may complete the inspection and an administrator may receive the certificate. If the inspection identifies remedial work, responsibility may pass to a maintenance manager, capital-project team, landlord or another contractor.
At every handover, information can stall.
Effective ownership should cover at least five stages:
Assigning one named owner to the overall obligation does not mean that person performs every task. It means somebody can see the complete chain and intervene when it breaks.
This ownership should sit in the operating process and system, rather than in an employee’s memory. Experienced people will always carry valuable contextual knowledge, but “ask Priya, she knows” is not a control. Priya may be on leave precisely when the auditor arrives, because facilities management occasionally has a sense of timing.
A certificate is evidence of an activity, not automatically evidence that the compliance position is satisfactory.
The document may show that an inspection took place, but it can also contain limitations, failed items, observations, recommended actions or exclusions. If the workflow ends when the PDF is uploaded, the organisation may successfully centralise proof that it has more work to do.
A useful review asks:
This is particularly important where records are generated automatically or in high volumes. A green dashboard can show that documents have been received while saying very little about what those documents contain.
The goal is not a complete certificate library. It is reliable evidence that obligations are understood, activities are completed, findings are reviewed and risks are acted upon.
Compliance records become much harder to control when they are not connected to reliable site and asset data.
A certificate labelled “Boiler 2” is only useful if everyone agrees which boiler that means. The same problem appears with fire doors, lifts, pressure systems, electrical installations, water outlets and other maintainable items. Duplicate asset records, missing identifiers and inconsistent location names make it difficult to match evidence to the physical estate.
This is why the asset register suddenly becomes important the moment something fails, changes contractor or appears in an audit sample.
A connected record should ideally link:
Not every compliance activity is asset-based. Some records apply to a building, activity, risk or responsible person. The data model must support those differences rather than forcing every obligation into the nearest convenient equipment record.
A central record should provide enough information to understand the obligation, verify its current status and follow the evidence trail without relying on a separate spreadsheet.
A practical compliance register normally needs:
| Information | Why it matters |
|---|---|
| Obligation or control | Defines what must be managed |
| Applicable site, area or asset | Prevents evidence being attached to the wrong item |
| Required activity and frequency | Supports scheduling and monitoring |
| Last completed date | Shows when activity occurred |
| Accepted evidence | Demonstrates what was reviewed |
| Findings and defects | Prevents certificates from becoming dead-end documents |
| Remedial actions | Connects evidence to risk reduction |
| Next due date | Supports forward planning |
| Status and escalation history | Shows how overdue or rejected work was handled |
| Retention and access rules | Keeps records available to the right people |
The required fields will vary according to the obligation and estate. The important point is to agree the structure before importing years of historic files.
Otherwise, a migration project can consume a remarkable amount of time while faithfully recreating the same confusion in a more modern interface.
The most reliable approach is to define the compliance model first, then configure technology around it.
Identify which buildings, assets, systems and operational activities are included. Confirm boundaries between owner, landlord, tenant, managing agent and service provider responsibilities.
This prevents teams from centralising only the records they already know about while leaving responsibility gaps untouched.
List each obligation, its operational control, frequency, evidence requirement and accountable owner. This should become the governing dataset rather than another reference document that is updated once and respectfully ignored.
Relevant legal and technical advice may be needed to confirm obligations. CAFM software can manage an agreed control framework; it should not be treated as a substitute for competent interpretation.
Define what acceptable evidence looks like for each activity. Include naming conventions, review requirements and rejection criteria.
The Health and Safety Executive’s guidance on work-equipment inspections, for example, explains that inspection results should be recorded and kept at least until the next inspection, with computerised records held securely and available to enforcing authorities. Retention requirements differ by regime, so FM teams should avoid applying one blanket period to every record.
Remove obvious duplicates, identify missing information and map records to consistent site and asset identifiers. Historical evidence of uncertain quality should be labelled accordingly rather than silently treated as verified.
The objective is not to produce a cosmetically perfect archive. It is to establish a trustworthy operational baseline.
Create recurring activities, evidence-review stages, remedial workflows and escalation rules. Overdue work should be visible before it becomes an audit discovery.
Give contractors clear requirements and, where appropriate, direct access to submit evidence against assigned work. Monitor rejected, incomplete and late documentation alongside technical performance.
Before declaring the project complete, ask the system questions an auditor or operational leader might ask:
If the answers still require manual detective work, the records may be stored centrally without being managed centrally.
A useful platform should connect schedules, responsibility, work completion, evidence and remedial actions. Document storage is necessary, but it is the minimum requirement.
For a multi-site team, relevant capabilities may include:
The better fit depends on the organisation’s actual responsibilities. A team mainly coordinating a small number of recurring checks may need a simpler system than an FM provider managing multiple clients, contractor networks, asset registers, service levels and approval workflows.
The buying decision should therefore start with the compliance workflow, not the length of the feature list. Software demonstrations have a natural tendency to take place in a spotless fictional estate where every asset has a serial number and every contractor uploads perfect paperwork on time. Your own data may offer a more demanding plot.
FM teams have difficulty centralising compliance records because the evidence crosses too many organisational boundaries without one controlled workflow joining it together.
The strongest approach is to:
A central repository answers “Where is the document?” A mature compliance process also answers “Is it correct, what did it find, what happened next and who knows about it?”
That is the difference between an electronic filing cabinet and operational assurance.