Skip to content
AI Metric

Chris M.

Golden thread compliance and Gateway 3 readiness

Gateway 3 is where higher-risk building projects stall, because it is the first point at which somebody external checks whether the record actually exists. The building cannot be occupied until the Building Safety Regulator has verified the evidence, and no amount of good construction compensates for a record that was never kept.

Under the Building Safety Act 2022, every higher-risk building must maintain a golden thread: a continuous record of accurate, accessible and up-to-date building information across its whole lifecycle, linking design intent, construction evidence and completion certification into one traceable chain.

What do the three gateways actually check?

Different things at different moments, and only one of them is a genuine bottleneck.

GatewayWhen it appliesWhat is assessedWhere projects come unstuck
Gateway 1Before planning permissionFire safety considered at design stageRarely a stalling point
Gateway 2Before building work beginsFull plans assessed by the Building Safety RegulatorApproval duration, not evidence
Gateway 3At completion, before occupationWhether the golden thread evidence is complete, verified and traceableAlmost always here

The reason is structural rather than bad luck. Gateways 1 and 2 assess a proposal, which is a document you are actively writing. Gateway 3 assesses a history, which either was or was not recorded as the work happened. You cannot draft a history retrospectively, and that is the whole problem.

Why does manual compliance fail at Gateway 3?

Because the completion package demands evidence that had to be captured continuously, and manual processes capture it in bursts.

What is required: as-built documentation matching what was actually built, a full change-control trail for every design change and material substitution, competence declarations linking key decisions to suitably qualified people, fire safety certificates and test reports, dated inspection records with photographic evidence, and the prescribed documents including Regulation 38 evidence and handover packs.

The failure points are consistent, and none of them are exotic:

  • Documents scattered across SharePoint, Outlook, CDE platforms and local drives
  • Inconsistent file naming, with ISO 19650 conventions breaking down across the supply chain within weeks
  • Missing certificates discovered during the completion audit rather than during construction
  • No link between a design decision and the competence of the person who made it
  • Incomplete change control, with material substitutions undocumented
  • Weeks lost compiling evidence by hand for each submission

Every one of those is the same failure as a site record that lives on somebody's phone: the information existed at the time and was never captured in a form the business could later produce.

What does the delay actually cost?

Honestly, the published data on Gateway 3 delay is thin, and figures circulating in the industry should be treated with caution. What can be said without inventing a statistic:

Regulatory delay at completion is expensive because of what it delays, not because of the compliance work itself. Occupation is the moment revenue starts. Prelims continue running, finance costs continue accruing, and on a residential scheme handover dates carry contractual consequences. Any delay at that specific point in the programme is the most expensive kind, because everything else has already been spent.

Rather than quote a number, run your own: take your weekly prelims plus finance cost, and multiply by the number of weeks you would lose assembling evidence at the end. That figure is specific to your project and you can check every input, which is more useful than a benchmark from someone else's.

What does the alternative look like?

Making Gateway readiness a continuous state rather than a completion scramble. Not a heroic document-chasing exercise in the final month.

Ingest and structure what already exists. Legacy project data is indexed and aligned to ISO 19650 and golden thread principles from the outset, rather than reorganised retrospectively.

Automate file governance. Naming, metadata and classification are enforced on upload, so the standard survives contact with a busy supply chain rather than decaying within weeks.

Monitor continuously. The system scans SharePoint, Outlook and the CDE on a short cycle, checking naming, revisions, signatures and certificates, and flags what is missing the moment it is missing, per work package.

Keep the audit trail human. Every decision is linked to the qualified professional who made it, which is exactly what the competence declaration requirement demands. This is not a step to automate away.

Compile evidence packs automatically. The completion package assembles itself from records validated as they were created, rather than being reconstructed at the end.

Is the commercial case separate from the safety case?

They point the same way, which is unusual and worth saying plainly.

The safety argument for the golden thread stands entirely on its own and does not need a business case. The commercial argument happens to agree: recovered project management time, a faster Gateway 3 submission, and near-zero risk of an incomplete audit trail at the exact moment a regulator is looking at you.

The same continuous capture also produces the daily record that decides ordinary commercial arguments, so the compliance work is not a cost centre sitting on its own. It is the same records discipline that protects margin, applied to a regulatory audience instead of a commercial one.

On buildings where occupation dates carry real money, knowing the record is complete is worth more than any dashboard.

AI Metric is a construction-native AI consultancy. If your team is spending more time operating software than doing their job, get in touch or book a call.