Blog • Expansive FM

Why do FM teams struggle to centralise compliance records?

Written by Tom Wilcock | Sep 3, 2026, 9:00:00 AM

FM teams struggle to centralise compliance records because the evidence is created by different people, at different sites, through different workflows. Documents become separated from the assets, inspections and remedial actions they relate to. A central system helps, but only when the organisation also defines ownership, evidence standards, review processes and escalation routes.

Key takeaways

  • Centralising compliance requires one controlled process, not merely one large document folder.
  • Records become fragmented when sites, contractors and internal teams use different systems and naming conventions.
  • A certificate alone does not prove that the work was satisfactory or that remedial actions were completed.
  • Clear ownership must cover scheduling, completion, evidence review, remediation and escalation.
  • CAFM software can provide portfolio visibility, but inconsistent data entered into a new platform remains inconsistent data.
  • The best starting point is a compliance register showing what is required, who owns it, how often it occurs, and what evidence must be retained.

Contents

Why is centralising compliance evidence so difficult?

Is this really a document-storage problem?

Why do different sites develop different processes?

How do contractors contribute to fragmented records?

What does unclear ownership look like in practice?

Why are certificates not enough?

How does poor asset data weaken compliance assurance?

What should a central compliance record contain?

How should FM teams approach centralisation?

What should compliance software provide?

FAQs 

Why is centralising compliance evidence so difficult?

Every FM has experienced the moment when somebody asks for a certificate and everyone agrees that it definitely exists.

The less certain part is whether it lives in an inbox from 2022, a contractor portal, a shared drive, a paper site file or the downloads folder of somebody who left six months ago. In a multi-site estate, “somewhere” can cover an impressive amount of territory.

This fragmentation is rarely caused by carelessness. Compliance evidence is produced through dozens of separate operational processes: inspections, planned maintenance visits, risk assessments, remedial works, internal checks and contractor appointments. Different people commission the work, attend the site, complete it, receive the paperwork and decide what happens next.

Unless those stages are connected, the record tends to stop wherever the last person left it.

That is why centralising compliance records is not primarily a filing exercise. It is an information-management problem involving ownership, workflows, asset data, evidence standards and access. Moving every PDF into one folder may make the disorder more geographically convenient, but it does not establish whether the records are complete, current or usable.

Is this really a document-storage problem?

No. The deeper problem is that many organisations centralise files without centralising the process that creates and controls them.

A shared repository can tell you where a document has been saved. It cannot automatically tell you:

  • whether every required inspection has taken place;
  • whether the certificate relates to the correct site and asset;
  • whether the document has been reviewed;
  • whether identified defects have been assigned;
  • whether remedial work has been completed;
  • whether the current version has replaced an obsolete one;
  • or whether another site has no evidence at all.

The distinction matters because audit readiness depends on more than retrieval. A strong compliance record should show the obligation, the planned activity, the completed work, the resulting evidence and the response to any findings.

Without that chain, a folder full of certificates may create reassurance without providing much assurance.

The official golden-thread guidance for in-scope higher-risk buildings in England makes this distinction particularly clear. It describes building information as something that must be digital, secure, available, usable, current and capable of acting as a single source of truth. These specific duties do not apply to every building or FM team, but the information-management principles are useful across an estate. 

Why do different sites develop different compliance processes?

Sites develop their own processes because local teams need to keep the operation moving, often before anybody has established an estate-wide standard.

One building may have a diligent facilities coordinator with a carefully maintained folder structure. Another may depend on its maintenance contractor’s portal. A recently acquired site may still use the previous owner’s spreadsheet, while a smaller location emails everything to head office and hopes somebody there knows what to do with it.

Each method can appear workable in isolation. The difficulty emerges when the organisation needs to answer a portfolio-level question.

For example, a compliance manager may need to know which sites have current water-hygiene risk assessments, whether the required monitoring is taking place and which recommended actions remain open. If every location labels, stores and reports that information differently, producing the answer becomes a manual reconciliation exercise.

The spreadsheet everyone is afraid to delete normally appears at this stage. Nobody is entirely sure whether it is authoritative, but it contains three columns that exist nowhere else, so it continues its distinguished career.

Common causes of site-level variation include:

  • acquisitions and changes in building ownership;
  • inherited maintenance providers;
  • different landlord and tenant responsibilities;
  • local purchasing arrangements;
  • regional contractor networks;
  • inconsistent mobilisation processes;
  • and the absence of an agreed compliance data standard.

Centralisation therefore requires some standardisation, but not the pretence that every building is identical. Sites may have different risks, assets and legal responsibilities. The common process should define how those differences are recorded and governed.

How do contractors contribute to fragmented records?

Contractors often create the evidence that FM teams need, but they do not necessarily create it in the format, system or timeframe the client requires.

One contractor uploads certificates to its own portal. Another sends a PDF with an invoice. A third emails the site contact, while a fourth promises to send the paperwork later. “Later” is a flexible unit of time in contractor administration.

This becomes a centralisation problem when the contract defines the technical work but says little about information handover. The visit may have taken place, yet the FM team still lacks the evidence needed to confirm completion, assess findings or demonstrate compliance.

Contractor requirements should specify:

  • which documents must be provided;
  • the required naming and file format;
  • the site, location and asset identifiers that must appear;
  • whether photographs, readings or test results are required;
  • who receives and reviews the evidence;
  • how quickly it must be submitted;
  • how defects and recommendations must be classified;
  • and whether payment or job closure depends on accepted evidence.

Direct contractor access to a CAFM platform can reduce email handling and duplicate entry, particularly where evidence can be attached to the relevant work order or asset. It only works, however, if somebody checks what has been uploaded. A photograph of a certificate taken from the other side of a plant room is technically a document submission, but it is not a useful compliance record.

What does unclear ownership look like in practice?

Unclear ownership means several people are involved, but nobody is explicitly accountable for the complete outcome.

An estates team may own the compliance policy, a site manager may provide access, a contractor may complete the inspection and an administrator may receive the certificate. If the inspection identifies remedial work, responsibility may pass to a maintenance manager, capital-project team, landlord or another contractor.

At every handover, information can stall.

Effective ownership should cover at least five stages:

  1. Planning: Who identifies the obligation and schedules the required activity?
  2. Completion: Who ensures that the inspection or maintenance work takes place?
  3. Evidence review: Who confirms that the resulting record is correct and complete?
  4. Remediation: Who assigns and tracks defects, recommendations or follow-up work?
  5. Escalation: Who acts when work is overdue, evidence is rejected or risk remains unresolved?

Assigning one named owner to the overall obligation does not mean that person performs every task. It means somebody can see the complete chain and intervene when it breaks.

This ownership should sit in the operating process and system, rather than in an employee’s memory. Experienced people will always carry valuable contextual knowledge, but “ask Priya, she knows” is not a control. Priya may be on leave precisely when the auditor arrives, because facilities management occasionally has a sense of timing.

Why are certificates not enough?

A certificate is evidence of an activity, not automatically evidence that the compliance position is satisfactory.

The document may show that an inspection took place, but it can also contain limitations, failed items, observations, recommended actions or exclusions. If the workflow ends when the PDF is uploaded, the organisation may successfully centralise proof that it has more work to do.

A useful review asks:

  • Does the record relate to the correct premises, system and asset?
  • Was the work completed by an appropriately competent person?
  • Does the document cover the required scope?
  • Are dates and inspection intervals clear?
  • Were defects or limitations recorded?
  • Has follow-up work been raised and prioritised?
  • When is the next activity due?

This is particularly important where records are generated automatically or in high volumes. A green dashboard can show that documents have been received while saying very little about what those documents contain.

The goal is not a complete certificate library. It is reliable evidence that obligations are understood, activities are completed, findings are reviewed and risks are acted upon.

How does poor asset data weaken compliance assurance?

Compliance records become much harder to control when they are not connected to reliable site and asset data.

A certificate labelled “Boiler 2” is only useful if everyone agrees which boiler that means. The same problem appears with fire doors, lifts, pressure systems, electrical installations, water outlets and other maintainable items. Duplicate asset records, missing identifiers and inconsistent location names make it difficult to match evidence to the physical estate.

This is why the asset register suddenly becomes important the moment something fails, changes contractor or appears in an audit sample.

A connected record should ideally link:

  • the property and precise location;
  • the relevant asset or system;
  • the planned inspection or maintenance task;
  • the work order and attending contractor;
  • the resulting evidence;
  • any identified defects;
  • the remedial action;
  • and the next required date.

Not every compliance activity is asset-based. Some records apply to a building, activity, risk or responsible person. The data model must support those differences rather than forcing every obligation into the nearest convenient equipment record.

What should a central compliance record contain?

A central record should provide enough information to understand the obligation, verify its current status and follow the evidence trail without relying on a separate spreadsheet.

A practical compliance register normally needs:

Information Why it matters
Obligation or control Defines what must be managed
Applicable site, area or asset Prevents evidence being attached to the wrong item
Required activity and frequency Supports scheduling and monitoring
Last completed date Shows when activity occurred
Accepted evidence Demonstrates what was reviewed
Findings and defects Prevents certificates from becoming dead-end documents
Remedial actions Connects evidence to risk reduction
Next due date Supports forward planning
Status and escalation history Shows how overdue or rejected work was handled
Retention and access rules Keeps records available to the right people

The required fields will vary according to the obligation and estate. The important point is to agree the structure before importing years of historic files.

Otherwise, a migration project can consume a remarkable amount of time while faithfully recreating the same confusion in a more modern interface.

How should FM teams approach centralisation?

The most reliable approach is to define the compliance model first, then configure technology around it.

1. Establish the scope

Identify which buildings, assets, systems and operational activities are included. Confirm boundaries between owner, landlord, tenant, managing agent and service provider responsibilities.

This prevents teams from centralising only the records they already know about while leaving responsibility gaps untouched.

2. Build a compliance register

List each obligation, its operational control, frequency, evidence requirement and accountable owner. This should become the governing dataset rather than another reference document that is updated once and respectfully ignored.

Relevant legal and technical advice may be needed to confirm obligations. CAFM software can manage an agreed control framework; it should not be treated as a substitute for competent interpretation.

3. Agree evidence standards

Define what acceptable evidence looks like for each activity. Include naming conventions, review requirements and rejection criteria.

The Health and Safety Executive’s guidance on work-equipment inspections, for example, explains that inspection results should be recorded and kept at least until the next inspection, with computerised records held securely and available to enforcing authorities. Retention requirements differ by regime, so FM teams should avoid applying one blanket period to every record.

4. Clean the current data

Remove obvious duplicates, identify missing information and map records to consistent site and asset identifiers. Historical evidence of uncertain quality should be labelled accordingly rather than silently treated as verified.

The objective is not to produce a cosmetically perfect archive. It is to establish a trustworthy operational baseline.

5. Configure workflows and escalation

Create recurring activities, evidence-review stages, remedial workflows and escalation rules. Overdue work should be visible before it becomes an audit discovery.

6. Control contractor submissions

Give contractors clear requirements and, where appropriate, direct access to submit evidence against assigned work. Monitor rejected, incomplete and late documentation alongside technical performance.

7. Test with real questions

Before declaring the project complete, ask the system questions an auditor or operational leader might ask:

  • Which sites have overdue statutory activity?
  • Which completed visits are still awaiting evidence?
  • Which certificates contain unresolved defects?
  • Who reviewed this record?
  • Can the evidence be retrieved without contacting the contractor?

If the answers still require manual detective work, the records may be stored centrally without being managed centrally.

What should compliance software provide?

A useful platform should connect schedules, responsibility, work completion, evidence and remedial actions. Document storage is necessary, but it is the minimum requirement.

For a multi-site team, relevant capabilities may include:

  • portfolio, site and asset-level views;
  • recurring inspection and maintenance scheduling;
  • reminders and escalations;
  • clear task ownership;
  • evidence submission and review;
  • version history and audit trails;
  • contractor access;
  • links between findings and remedial work;
  • overdue and exception reporting;
  • role-based access;
  • and exportable evidence for audit or investigation.

The better fit depends on the organisation’s actual responsibilities. A team mainly coordinating a small number of recurring checks may need a simpler system than an FM provider managing multiple clients, contractor networks, asset registers, service levels and approval workflows.

The buying decision should therefore start with the compliance workflow, not the length of the feature list. Software demonstrations have a natural tendency to take place in a spotless fictional estate where every asset has a serial number and every contractor uploads perfect paperwork on time. Your own data may offer a more demanding plot.

What does effective compliance management look like?

FM teams have difficulty centralising compliance records because the evidence crosses too many organisational boundaries without one controlled workflow joining it together.

The strongest approach is to:

  • define the obligations and responsibilities;
  • agree what acceptable evidence looks like;
  • connect records to sites, assets and completed work;
  • review findings rather than merely collecting certificates;
  • track remedial actions through to closure;
  • and use CAFM software to make exceptions visible across the estate.

A central repository answers “Where is the document?” A mature compliance process also answers “Is it correct, what did it find, what happened next and who knows about it?”

That is the difference between an electronic filing cabinet and operational assurance.

FAQs