How to Audit Building Compliance Properly
A compliance audit often starts when a managing agent requests documents for a tenant move, an insurer asks for evidence, or a contractor cannot produce a current certificate. By that point, the issue may have existed for months. Knowing how to audit building compliance before a trigger event gives facilities and property teams control over risk, cost and operational continuity.
For commercial buildings, compliance is not a single folder of certificates. It is a managed process covering the asset, its use, the people who occupy it and the contractors who maintain it. A worthwhile audit tests whether required controls are in place, whether the evidence is current and whether identified actions are genuinely being closed.

Start with the building, not a generic checklist
A checklist is useful, but it should not be the starting point. First establish what the building is, how it is used and who is responsible for each area. An office with a small plant room has a different risk profile from a mixed-use property, warehouse, retail unit or multi-let industrial estate.
Create a clear site profile that records the address, occupancy, floor area, hours of operation, landlord and tenant responsibilities, significant plant, access arrangements and any higher-risk activities. Include vacant areas, roof spaces, external plant compounds and shared services. These are commonly missed when documentation is reviewed remotely.
The compliance scope should then reflect the property. Typical areas include fire safety, electrical safety, gas systems, water hygiene, asbestos management, lifting equipment, pressure systems, emergency lighting, ventilation, accessibility, waste and workplace health and safety. Not every obligation applies in the same way to every site, so the audit must distinguish between non-applicable items and missing evidence.
This first stage also prevents a frequent problem: a document may be valid but relate to the wrong unit, an obsolete installation or a previous occupier’s responsibility.
Set accountability before reviewing the evidence
A compliance gap is rarely caused by a lack of technical knowledge alone. More often, responsibility is unclear. The landlord assumes a tenant has arranged a service, the tenant expects the managing agent to do it, and neither party holds the supporting record.
Before inspecting the evidence, map each duty to a named accountable party. This should identify the duty holder, the person who arranges inspections, the person who retains records and the person authorised to approve remedial works. Where a facilities management provider coordinates activity, it should still be clear who carries the legal responsibility and who needs to receive escalations.
A simple responsibility matrix is particularly valuable for multi-occupied buildings. It should cover common parts, demised areas, shared plant and specialist systems. If the answer to “who owns this action?” is uncertain, treat that uncertainty as a control weakness rather than an administrative detail.
How to audit building compliance in a structured way
The most effective approach combines document review, physical verification and action management. Reviewing certificates alone can create false assurance. A current inspection report does not confirm that the recommendations were completed, and a site walk-through does not prove that statutory testing has been carried out at the required interval.

Build a live compliance register
Create one register for the site or portfolio, rather than relying on separate contractor folders and email chains. For each requirement, record the asset or area covered, relevant inspection frequency, last completion date, next due date, certificate or report reference, responsible party and remedial status.
The register should also state the source of the requirement, such as legislation, an approved code of practice, an insurer condition, a lease obligation, manufacturer guidance, or an internal standard. This provides context when priorities are challenged and helps prevent teams treating all overdue items as equal.
Use consistent status labels. For example, compliant, due soon, overdue, remedial action open, not applicable and evidence required. Avoid marking an item compliant simply because a visit has been booked. Compliance requires completed activity and satisfactory evidence.
Review documents for validity and completeness
For each record, check more than the date. Confirm that it identifies the correct premises or asset, has been completed by a competent person, includes the inspection outcome and records any defects or recommendations. Check that the report is complete, signed where required and held in a format that can be retrieved quickly.
Pay close attention to reports that identify limitations. An electrical inspection, for example, may exclude areas that could not be accessed. A fire risk assessment may depend on specific management controls being maintained. These are not necessarily failures, but they must be understood, assigned and monitored.
Look for patterns across the evidence. Repeated advisory defects, certificates issued after their due dates, missing service sheets and reports with no recorded follow-up are signs that the process needs attention. A building can appear well documented while still carrying unresolved risk.
Walk the site with the register in hand
A physical audit brings the record set into contact with reality. Sample representative areas and critical systems rather than attempting to inspect every component personally. The purpose is to verify condition, management controls and evidence of routine attention.
Walk escape routes, communal areas, plant rooms, electrical cupboards, risers, welfare spaces, loading areas and external grounds. Check whether fire doors close correctly, safety signage remains legible, access to panels is clear, plant rooms are secure, and housekeeping is preventing avoidable hazards. Compare asset labels with the register and note equipment that has been replaced, removed or added without the records being updated.
The site walk should also test how staff respond. Can the reception or site team locate the fire logbook? Do they know how to report a defect? Is there a clear route for contractors to sign in, receive site information and report issues? Compliance is maintained through day-to-day behaviours, not just periodic inspections.
Prioritise findings by risk and operational impact
An audit report containing twenty actions is only useful if the next decision is obvious. Categorise findings by the seriousness of the risk, legal exposure, likelihood of harm and operational consequence. A blocked fire exit or dangerous electrical defect requires immediate action. A missing historic record may need investigation but is unlikely to carry the same urgency.
A practical priority framework can include four levels:
- Immediate: Make safe at once, restrict access where needed and escalate to the accountable person.
- Urgent: Complete within a defined short period because a statutory duty, life-safety control or critical asset is affected.
- Planned: Include in a scheduled maintenance or minor works programme with a clear target date.
- Improvement: Address to strengthen management standards, record quality or future resilience.
Record the required action, owner, target date, cost estimate and closure evidence for every finding. Photographs, updated certificates, contractor reports and completion sign-off may all be needed. An action is not closed because someone says the work has been done.
Cost is a legitimate consideration, particularly where remedial works are extensive. However, delaying a high-risk action without an interim control can create a much greater exposure. If work cannot proceed immediately, document the reason, assess the risk and put proportionate temporary measures in place. This might include isolating equipment, increasing inspections, restricting access or arranging a specialist assessment.
Treat contractors as part of the compliance control
Many compliance records are generated by external providers, making contractor management central to the audit. Verify that contractors are competent for the work, insured where appropriate, inducted to the site and clear on reporting requirements. Their paperwork needs to be checked promptly, not filed until the next annual review.
Set expectations for what a completed visit must provide: service records, test results, defect details, recommendations, photographs where useful and confirmation of any assets not accessed. Require contractors to flag critical defects immediately rather than waiting for a report to be issued.

For portfolios, standardising these requirements reduces variation between sites and suppliers. It also makes it easier for a central facilities team to identify overdue work, recurring defects and locations receiving inconsistent service.
Build audit findings into routine management
A compliance audit should not become an annual scramble. The strongest result is a regular control cycle: review the register, chase upcoming due dates, inspect open actions, sample evidence and report exceptions to the right people. The frequency will depend on the building and its risks, but monthly review is often appropriate for active commercial sites.
Management reporting should be concise and decision-focused. Show overall compliance status, overdue statutory items, high-risk actions, actions approaching deadline and recurring issues. Separate genuine exceptions from minor administration, so senior stakeholders can focus on decisions that require approval, funding or escalation.
Precision FM’s approach to facilities support is based on this type of coordinated oversight: bringing maintenance activity, contractor performance and compliance evidence into one operational view. For property teams managing several suppliers or sites, central visibility is often what turns a collection of certificates into a controlled compliance system.
The most useful audit leaves the building team with clear ownership, credible evidence and a manageable action plan. When the next insurer query, tenant request or incident occurs, the response should not be a search through inboxes. It should be a current record, a known process and the confidence that outstanding risks are being actively managed.
Frequently Asked Questions
What’s the first step in auditing building compliance?
Start with the building itself, not a generic checklist. Establish what the property is, how it’s used and who’s responsible for each area, then build a site profile covering occupancy, plant, access arrangements and higher-risk activities before deciding which compliance obligations actually apply.
Why does compliance auditing need a responsibility matrix?
Compliance gaps are rarely caused by lack of technical knowledge alone; more often, responsibility is unclear between landlord, tenant and managing agent. Mapping each duty to a named accountable party turns uncertainty over ownership into a visible control weakness to fix.
What should a live compliance register include?
For each requirement, record the asset or area, inspection frequency, last completion date, next due date, certificate reference, responsible party and remedial status. It should also note the source of the requirement, legislation, insurer condition or lease obligation, so priorities can be challenged with context.
How should compliance audit findings be prioritised?
Use a four-level framework: immediate action for anything requiring an instant safety response, urgent for statutory or life-safety items needing quick resolution, planned for scheduled maintenance programmes, and improvement for strengthening management standards and record quality over time.
How often should a building compliance audit be reviewed?
Frequency depends on the building and its risks, but monthly review is often appropriate for active commercial sites. The strongest approach is a regular control cycle, reviewing the register, chasing due dates, inspecting open actions and reporting exceptions, rather than treating compliance as an annual scramble.


