← Back to the blog

The Golden Thread in Fire Safety: What Fire and Security Engineers Need to Know

by Ryan Bishop

Every engineer has attended a building where nobody seems to know what is actually installed.

The drawings show devices that were removed years ago. The cause and effect is missing. The panel configuration exists only on an old laptop belonging to a previous contractor. Doors release differently from the fire strategy. Smoke control interfaces have been altered, but nobody can explain why.

This is not just inconvenient paperwork. It is a building safety problem.

The golden thread principle is intended to prevent exactly this situation. It creates a reliable record of what was designed, what was installed, what has changed, who made those decisions and what evidence supports them.

For higher-risk buildings in England, parts of this principle are now a legal requirement. For other buildings, wider changes to building regulations and fire safety law mean that designers, contractors, building owners and Responsible Persons are expected to produce and preserve far better information than many have done historically.

Legal scope: This article focuses primarily on England. The higher-risk building regime operated by the Building Safety Regulator is England-specific. Fire and building safety legislation differs in Wales, Scotland and Northern Ireland.

What is the golden thread?

The golden thread is the controlled record of information needed to understand a building and manage its safety throughout its life.

It should allow someone to establish:

  • what the building and its safety systems were intended to do
  • what was actually installed
  • whether the completed work complied with the relevant requirements
  • what has subsequently been changed
  • why each significant change was made
  • who designed, approved, installed, commissioned and verified the work
  • what tests, inspections and calculations support those decisions
  • what defects, limitations and temporary measures remain outstanding

For higher-risk buildings, government guidance requires the information to be kept digitally, protected from unauthorised access, available when needed, usable, understandable and maintained as the building's reliable source of truth. The record-keeping system should also include version control so that changes can be identified.

That last point matters.

A folder containing 4,000 unstructured PDFs is not automatically a golden thread. Neither is a service management system containing editable notes with no revision history. The information must be current, organised and capable of showing what changed.

The purpose is not to create more paperwork. It is to remove dangerous assumptions.

Why does it matter?

Fire safety systems rarely operate in isolation.

A fire alarm may control smoke dampers, smoke extract fans, lifts, access-controlled doors, shutters, gas valves, plant shutdowns, evacuation alert systems and building management systems. A change made by one contractor can therefore affect several other systems.

Consider a simple access control alteration. A contractor changes a door from fail-safe to fail-secure because the existing lock is causing nuisance releases. The access control system still works. The door still opens when authorised. The service sheet may even say that the system was tested successfully.

But what now happens during a fire?

Does the door release from the fire alarm? Is there a compliant emergency release device? Can it be opened following a power supply fault? Is the arrangement consistent with the fire strategy? Has the change affected an escape route?

Without a reliable record of the original design and the subsequent alteration, the next engineer is left to guess.

The fire strategy does not care which trade package owns the door.

The Building Safety Regulator

The Building Safety Regulator, usually shortened to BSR, was created as part of the reforms introduced following the Grenfell Tower fire and the subsequent review of the building safety system.

Since 27 January 2026, BSR has operated as a standalone executive non-departmental public body sponsored by the Ministry of Housing, Communities and Local Government. It was previously established within the Health and Safety Executive.

BSR has several functions, including:

  • acting as the building control authority for higher-risk buildings in England
  • regulating building safety in occupied high-rise residential buildings
  • overseeing standards within the building control profession
  • improving competence across the built environment
  • taking enforcement action where building safety duties are breached

BSR can issue compliance notices, stop notices and notices requiring non-compliant work to be altered or removed. It can also prosecute. Failure to comply with an enforcement notice can itself be a criminal offence.

What is a higher-risk building?

During design and construction, a higher-risk building will generally be a building that is at least:

  • 18 metres in height or seven storeys, and
  • contains at least two residential units, or is a hospital or care home.

For the occupied building regime, the Accountable Person and Principal Accountable Person duties apply to high-rise residential buildings meeting the height or storey threshold and containing at least two residential units.

A qualifying residential higher-risk building must be registered with BSR before it is occupied.

The distinction is important. A hospital or care home can fall within the higher-risk regime during design and construction, but the occupied building duties involving Accountable Persons are principally concerned with high-rise residential buildings.

Building control has changed for higher-risk buildings

BSR is the building control authority for higher-risk building work in England.

Building control approval must normally be obtained before construction or relevant building work begins. Starting higher-risk building work without the required approval is a criminal offence. BSR will consider whether the proposed work complies with building regulations, whether the project will be managed properly and whether competent people have been appointed.

The process is commonly described through the gateway system.

At Gateway 2, detailed approval is required before the relevant building work begins. At Gateway 3, the completed work must be evidenced and accepted before the building can move into occupation through the relevant completion and registration process.

This changes the old approach where designs could remain partially developed while work continued on site.

For higher-risk buildings, “we will sort that drawing later” is no longer an acceptable project strategy.

The new dutyholder regime applies more widely

The higher-risk building regime receives most of the attention, but the changes are not limited to tower blocks.

The Building Regulations etc. (Amendment) (England) Regulations 2023 introduced a dutyholder and competence regime for building work generally. The requirements have applied to building work in England since 1 October 2023.

The recognised dutyholders include:

  • clients
  • designers
  • principal designers
  • contractors
  • principal contractors

Clients must provide relevant building information and appoint people with the necessary competence or organisational capability. Designers must take reasonable steps to ensure that their designs would comply with the relevant requirements if built. Contractors must plan, manage and monitor their work, cooperate with others and provide sufficient information to support compliance.

This matters to specialist fire and security companies.

A company does not avoid design responsibility simply because its quotation says “supply and installation”.

Where a company produces detector layouts, selects equipment, modifies a cause and effect, decides how an interface will operate, chooses a locking arrangement, approves a product substitution or calculates a power supply requirement, it may be carrying out design work for that part of the project.

The title printed on a business card does not determine the legal role. The work being undertaken does.

Who is responsible for the golden thread?

During higher-risk building work, the formal duties are distributed between the client, principal designer and principal contractor.

The client must provide the digital record-keeping system and make building information available. The principal designer is responsible for capturing and maintaining design information. The principal contractor must keep the construction information current, preserve evidence of compliance and work with the design team to manage changes.

At completion, the relevant information must be handed over to the Accountable Person, Principal Accountable Person or Responsible Person, depending on the building and the part concerned. The receiving person must confirm that the information has been received in a usable format.

Once an occupied high-rise residential building is in use, the Accountable Persons and Principal Accountable Person must maintain the information required to understand and manage its fire and structural safety risks.

That does not mean a specialist contractor can say, “The golden thread belongs to the principal contractor, so our paperwork is not our problem.”

The principal contractor cannot produce an accurate golden thread unless the fire alarm, smoke control, access control, PAVA, sprinkler and other specialist contractors provide accurate information.

Formal accountability and practical responsibility are not the same thing. Engineers and specialist contractors create much of the evidence on which the formal dutyholders rely.

The Fire Safety Order has changed as well

Section 156 of the Building Safety Act 2022 amended the Regulatory Reform (Fire Safety) Order 2005 from 1 October 2023.

These changes apply broadly to premises regulated by the Fire Safety Order, including workplaces, non-domestic premises and the common parts of buildings containing two or more domestic premises.

Responsible Persons must now:

  • record their fire risk assessment in full
  • record their fire safety arrangements
  • record the identity of anyone appointed to undertake or review the fire risk assessment
  • record and update their own contact information
  • identify other Responsible Persons and, where applicable, Accountable Persons
  • cooperate and coordinate with those people
  • provide relevant information to residents where required
  • pass relevant fire safety information to an incoming Responsible Person

Relevant information passed to an incoming Responsible Person can include fire risk assessments, review records, information about other dutyholders and information originally provided under Regulation 38 of the Building Regulations.

This is a form of golden thread thinking extending beyond the formal higher-risk building information regime.

The legal requirement is increasingly clear: important fire safety information should follow the building, not disappear when the managing agent, maintenance company or building owner changes.

The Fire Safety (England) Regulations 2022

The Fire Safety (England) Regulations 2022 came into force on 23 January 2023 and introduced additional information and inspection duties for residential buildings.

For high-rise residential buildings, Responsible Persons must provide the fire and rescue service with electronic building plans and information about the external wall system. They must maintain plans and Responsible Person details in a secure information box, install appropriate wayfinding signage and arrange monthly checks of relevant lifts and essential firefighting equipment.

Where relevant equipment remains defective for more than 24 hours, the fire and rescue service must be informed.

The regulations also introduced fire door inspection duties for multi-occupied residential buildings over 11 metres and resident information requirements for multi-occupied residential buildings generally.

These requirements depend on accurate records.

A monthly check stating only “firefighting equipment checked” is of limited value if it does not identify the equipment, its location, the test performed, the result, the defect found and the action taken.

What should fire and security engineers be recording?

The exact record will depend on the system and the engineer's role, but the principle is consistent.

System Information that should be preserved
Fire detection and alarm Design category, design assumptions, zone and address schedules, as-fitted drawings, loop topology, cause and effect, interface details, battery and voltage-drop calculations, panel configuration backups, firmware versions, commissioning results, variations and unresolved defects
Smoke control Fire strategy requirements, operating modes, control philosophy, cause and effect, fan and damper references, vent positions, pressure or airflow results, override controls, fire alarm interfaces, configuration files and commissioning evidence
Access control and door release Lock type, normal state, fail state, emergency release method, fire alarm interface, power supply arrangements, standby period, escape route implications, door references, test results and the reason for any alteration
PAVA and evacuation systems Loudspeaker zoning, message sets, priorities, cause and effect, sound pressure or intelligibility results, amplifier loading, configuration backups and interfaces with the fire alarm or other systems
Networked life safety systems Network topology, node addresses, cable routes, isolator locations, software versions, configuration backups, communication dependencies and the effect of a network failure
Fire and security interfaces Input and output references, normal and alarm states, monitored conditions, delays, latching behaviour, reset requirements, fault response and evidence that both sides of the interface were tested

This information should describe the system that was actually left in operation, not the system shown on the tender drawing six months earlier.

Record why something changed

One of the most common documentation failures is recording the result without recording the decision.

For example:

“Detector moved due to site conditions.”

That does not explain:

  • what the site condition was
  • whether the new location remains compliant
  • who approved the change
  • whether the drawing was updated
  • whether the spacing and coverage were reassessed
  • whether another system was affected

A useful change record would identify the original arrangement, the proposed change, the reason for the change, the compliance assessment, the person accepting it and the documents updated as a result.

The same applies to cause and effect changes.

“Output delay changed to 60 seconds” is not enough. The record should explain what required the delay, whether it is permitted by the fire strategy, which devices and outputs are affected, who approved it and how the revised operation was tested.

The golden thread must record the reasoning, not just the final number.

Configuration files are safety records

Modern life safety systems are software-controlled.

The configuration file may contain more useful information about the building's actual operation than the printed drawings. It can determine evacuation zones, output delays, door releases, smoke control interfaces, network behaviour, fault monitoring and phased evacuation sequences.

Configuration data should therefore be treated as a controlled safety record.

A suitable record should normally identify:

  • the system and site
  • the panel or controller
  • the software and firmware version
  • the date of upload or download
  • the engineer responsible
  • the revision or issue number
  • the reason for the change
  • the previous version
  • the associated test and approval records

Saving files as final, final2, latest and latest-fixed is not version control.

The company should be able to prove which configuration was installed at a particular time and what changed between revisions.

Do not silently alter signed records

Service reports, commissioning certificates and test sheets form part of the evidence showing what an engineer observed and did.

Once completed and signed, the original record should be preserved.

Where an error is discovered, it should be corrected through a visible amendment, addendum or superseding revision. The system should show what was changed, who changed it, when it was changed and why.

A service management platform that allows office staff to silently rewrite an engineer's signed report creates a serious evidential problem. Even where the change is innocent, the company may later be unable to prove what the engineer originally recorded.

The regulations do not prescribe one specific software platform or require every record to be technically immutable. They do, however, require secure, usable information and, for higher-risk building records, version control.

An audit trail is therefore far stronger than an editable document with no history.

Record limitations and incomplete testing

Engineers are often pressured to make reports look cleaner than the site really was.

That undermines the golden thread.

If equipment could not be accessed, record it. If an interface could not be tested because another contractor was absent, record it. If part of a building remained occupied and sounder testing was restricted, record the limitation. If an isolation was left in place, identify exactly what was isolated, why, who accepted it and what temporary measures were introduced.

“System tested and operating correctly” should never be used where only part of the system was tested.

A future engineer must be able to tell the difference between:

  • tested and passed
  • visually inspected only
  • functionally tested without full cause and effect
  • inaccessible
  • isolated
  • defective
  • not included within the instructed scope

A limitation hidden in an engineer's memory is not part of the building record.

Change control on higher-risk buildings

Changes to higher-risk building work are subject to a formal change control process.

BSR guidance states that major changes require approval, and work on the affected part must stop until that approval has been given. Other changes may be notifiable and must still be recorded and communicated through the correct process.

For work on an existing higher-risk building, current BSR guidance identifies work involving active fire safety measures, such as alarms and sprinklers, as capable of falling within Category A work.

Most routine repairs, replacements and maintenance may be exempt from a separate building control application, but that exemption should not be treated as a blanket rule. Exempt work forming part of a wider building project must still be included within that project's application.

Before altering a fire alarm, smoke control system or safety-related door arrangement in a higher-risk building, the company should establish:

  1. whether the proposed activity is building work
  2. whether it is genuinely repair or maintenance
  3. whether it is part of a wider project
  4. whether the approved design is being changed
  5. who is responsible for change control
  6. whether BSR notification or approval is required

An informal instruction from a site manager does not override the approved building control process.

“Like for like” does not remove the need for evidence

A replacement product may have the same basic description as the original but operate differently.

A new fire alarm panel may use different firmware, output logic, fault monitoring or network behaviour. A replacement access control power supply may have a different standby capacity. A newer smoke control actuator may move at a different speed or provide different positional feedback.

Even where work is correctly treated as maintenance or replacement, the building record should be updated to show what was removed and what was installed.

Like for like is a technical conclusion, not a phrase to put on a purchase order.

What about emergency repairs?

Higher-risk building rules include a route for genuine emergency repairs where urgent work is required to manage an immediate risk and it is not practical to obtain approval first.

Where that route applies, BSR must generally be notified by the end of the first working day after the repair starts. The repair, the reason for its urgency and any temporary risk controls must be documented. Relevant information must also be supplied to the Responsible Person and retained with the building information.

This does not mean every emergency call-out is automatically subject to BSR notification. Many routine repairs may be exempt or may not amount to building work.

It does mean that companies working on higher-risk buildings need a procedure for distinguishing:

  • routine maintenance
  • planned building work
  • a genuine emergency repair
  • temporary measures that do not constitute the permanent repair

The engineer attending at 2am should not be expected to make that legal assessment alone. There should be an escalation route to a competent manager, designer or dutyholder.

Mandatory occurrence reporting

Higher-risk building projects and occupied high-rise residential buildings are also subject to mandatory occurrence reporting requirements.

During design and construction, the principal designer and principal contractor operate the reporting system. During occupation, the relevant Accountable Person duties apply.

A mandatory occurrence is not every fault or non-conformance.

The reporting threshold concerns incidents or risks involving structural failure, fire safety or the spread of fire and smoke that have caused, or would be likely to create, a risk of death or serious injury to a significant number of people.

Where the threshold is met, an occurrence may need to be reported even if it was corrected immediately.

A specialist engineer may not be the person responsible for submitting the report, but they may be the first person to discover the issue.

Potential examples requiring immediate internal escalation could include:

  • a systemic cause and effect error affecting several floors
  • a smoke control design or configuration incapable of providing the intended mode
  • widespread failures in fire alarm coverage or warning
  • repeated loss of a critical life safety network
  • a door control arrangement capable of preventing escape
  • numerous unsealed penetrations associated with system installation
  • evidence that completion or commissioning records materially misrepresent what was installed

These examples are not automatically mandatory occurrences. The circumstances and potential consequences must be assessed against the legal threshold.

The important point is that engineers need a clear route for raising serious concerns. A defect must not disappear into an ordinary service report simply because the engineer does not personally submit reports to BSR.

Security contractors are not outside the regime

The phrase “building safety” is sometimes treated as if it only concerns structural engineers, fire alarm companies and passive fire contractors.

That is a mistake.

Security systems can directly affect:

  • means of escape
  • firefighter access
  • evacuation routes
  • lift operation
  • smoke control sequences
  • door closing
  • compartmentation
  • emergency access to plant rooms
  • the ability to isolate or override safety systems

Access control is the clearest example, but it is not the only one.

Turnstiles, speed gates, automated doors, intercom systems, lift destination controls and security shutters can all affect evacuation or emergency response.

A security engineer altering a lock or output may therefore need to understand the fire strategy, approved door arrangement and emergency release sequence. Testing only the security function is not enough where the equipment also performs a life safety function.

Where two contractors share an interface, both sides should be identified and tested. “Fire alarm output operated” does not prove that the door released. “Door released locally” does not prove that the fire alarm correctly initiated it.

The complete function must be verified.

What should companies change?

A company does not need a vast document management department to improve its records. It does need a controlled process.

1. Identify the building and the dutyholders

Before starting work, establish whether the building is a higher-risk building, who the client is, who controls the design, who controls the work and who will receive the completed information.

Do not assume the managing agent, main contractor and Principal Accountable Person are the same organisation.

2. Define the required evidence before pricing

Handover information should not be an afterthought.

The quotation and project plan should identify the drawings, schedules, calculations, software backups, certificates, photographs, test records and interface information that will be produced.

Allow time for this work.

3. Use controlled revisions

Every important drawing, cause and effect, specification and configuration should have a clear revision, date, status and author.

Superseded information should be retained rather than deleted.

4. Preserve original engineer records

Completed service sheets and test results should be locked or otherwise protected from silent editing.

Corrections should be visible and attributable.

Variations should show who requested the change, why it was necessary, who assessed it, who accepted it and which documents were updated.

A quotation variation is not the same as technical approval.

6. Maintain competence records

Companies should be able to show why a person was considered competent for the work allocated to them.

That may include training, qualifications, manufacturer approvals, experience, supervision arrangements and the limits placed on their role.

7. Control configuration data

Panel and controller data should be stored centrally, not only on individual engineers' laptops.

Access should be controlled and downloads should be linked to the relevant job, change and test records.

8. Confirm handover

Do not assume that emailing a ZIP file completes the process.

Record what was issued, its revision, who received it and whether the recipient confirmed that it could be accessed and used.

Good records also protect engineers

The golden thread is primarily about building safety, but accurate records also protect the people doing the work.

If an engineer identifies a defect, records it clearly and escalates it through the correct route, there is evidence that the concern was raised.

If a company records the limitations of its instruction and the information on which its design was based, it is better placed to explain its decisions.

If a configuration change is version-controlled, the company can demonstrate when the change occurred and who authorised it.

The Building Safety Act also extended limitation periods for certain claims under the Defective Premises Act 1972. For qualifying work, the period was extended retrospectively from six years to 30 years and prospectively to 15 years. Not every fire or security contract will fall within those provisions, but the wider direction is clear: construction and building safety decisions may be examined many years after the engineer has left the company.

A record retention policy based only on how long the service contract lasts may therefore be inadequate.

The golden thread is not just a handover exercise

A common mistake is to treat the golden thread as a set of documents produced at the end of construction.

By that point, much of the useful information may already have been lost.

The record needs to be maintained while decisions are being made. It should capture design changes, product substitutions, access limitations, test failures, corrective work and approvals as they occur.

It must then continue through occupation.

Maintenance findings, alterations, isolations, repeated faults and revised operating arrangements all affect the current understanding of the building.

A perfect construction handover followed by ten years of undocumented modifications is no longer a reliable record.

Final thoughts

The golden thread does not make a building safe by itself.

It makes the building understandable.

It allows the next engineer to see what was intended, what was installed, what changed and what still requires attention. It allows building owners and dutyholders to make decisions using evidence rather than assumption. It allows regulators to establish whether work complies with the law.

For fire and security engineers, the practical change is straightforward:

Do not only prove that something operated during today's visit. Record what it is supposed to do, what you actually tested, what changed and what the next person needs to know.

For companies, documentation can no longer be treated as an administrative task completed after the real work is finished.

The information is part of the safety system.