The 5 Statutory Compliance Blindspots Exposing UK Directors to Legal Risk
There's a belief that runs through most UK facilities operations.
"We've got a contractor. We're covered."
It's understandable. You've got someone on retainer, invoices are coming in, work is getting done. From the outside, it looks like compliance.
But here's what auditors — and more importantly, regulators — actually look at.
Not whether you have a contractor.
Whether your records prove the right work happened, at the right intervals, documented correctly, with signed certificates and accessible logs.
That gap — between "we've got someone" and "we can prove we're compliant" — is where most UK directors are quietly exposed.
And when a prosecution, an insurance claim, or an HSE visit arrives, the gap becomes a liability.
This post identifies the five statutory compliance areas where that gap is most common. Not to alarm you — to help you check.
Why UK Directors Are Legally on the Hook for Asset Compliance
Under the Health and Safety at Work Act 1974 and the Management of Health and Safety at Work Regulations 1999, the duty holder for workplace premises isn't the contractor.
It's the person responsible for the building.
That's the Operations Director. The Health & Safety Lead. The Managing Director.
The contractor's job is to perform the work. Your job — legally — is to ensure it was done, that it's documented, and that you can demonstrate that documentation on demand.
According to Health and Safety Executive guidance on workplace compliance, organisations failing to demonstrate adequate inspection records face improvement notices, prohibition notices, unlimited fines, and in cases involving serious harm, personal prosecution of duty holders.
The question isn't whether your contractor is competent.
The question is: could you prove compliance in the next 48 hours if you had to?
For most UK directors, the honest answer is no.
Here's why.
Blindspot 1: Fire Safety Log Gaps That Invalidate Your Policy
The Regulatory Reform (Fire Safety) Order 2005 requires duty holders to keep a fire safety logbook containing evidence of:
Regular fire alarm tests (weekly)
Emergency lighting checks (monthly)
Fire extinguisher inspections (annual minimum)
Fire risk assessment reviews (frequency risk-dependent)
Evacuation drill records
The compliance failure here isn't usually that these tasks aren't completed.
It's that the records are fragmented, inconsistent, or don't follow a format acceptable to your insurer or a fire safety inspector.
A contractor visits, scribbles something in a paper log, and leaves.
Three years later, your insurer or a fire safety officer asks for a clear audit trail. You can't produce one.
The fix isn't a new contractor. It's a structured logging and certification system that captures every visit, every test, every outcome — and makes that record retrievable on demand.
Blindspot 2: Legionella Risk with No Demonstrable Control Scheme
Legionella is misunderstood.
Most operations leads assume a quarterly flush is enough. It isn't.
Under HSE's Approved Code of Practice L8 and Technical Guidance HSG274, any premises with hot and cold water systems, cooling towers, or evaporative condensers must have:
A current written Legionella risk assessment
A named responsible person
A documented control scheme with defined check frequencies
Temperature monitoring records (cold below 20°C, hot above 50°C)
Remedial action logs for any out-of-spec readings
The critical word is documented.
Most building occupants can say they "have legionella checks done." Almost none can produce a complete control scheme with compliant records for the last 24 months.
If a case is traced to your building, the HSE will ask for those records on day one.
Absence of records is treated as absence of control. The liability falls squarely on the duty holder.
Blindspot 3: Fixed Wire Electrical Testing Without Certificate Currency
Every commercial premises requires periodic inspection and testing (PIRT) of its fixed electrical installations — commonly called a Fixed Wire Test or EICR (Electrical Installation Condition Report).
Recommended frequencies under BS 7671 are every 3–5 years for commercial premises, more frequently for industrial environments.
The gap most operations leads don't catch?
The EICR was completed. The certificate was issued. It was filed somewhere.
Then it expired. Or the recommended remedial works were never formally closed out. Or a subsequent tenancy change reset the test obligations and nobody updated the schedule.
An expired EICR — or one with open 'C2' observations unresolved — means your electrical installation is not demonstrably safe. Insurers and HSE investigators treat this as a significant compliance failure.
If something happens, "we had a test a few years ago" won't hold.
Blindspot 4: Commercial Gas Safety Certificates With No PPM Schedule Behind Them
Commercial gas safety — covering boilers, gas-fired plant, catering equipment, and pipework — requires annual inspection under Gas Safety (Installation and Use) Regulations 1998.
The compliance failure here is usually one of three things:
The Gas Safe certificate exists, but it's over 12 months old and the renewal wasn't flagged.
The inspection covers the boiler, but other gas-fired assets on site were overlooked.
The PPM (planned preventive maintenance) schedule doesn't align with the actual asset register — so there are assets in the building that nobody is formally responsible for testing.
This last one is more common than most directors realise: Buildings change.
Equipment is added, moved, or forgotten about. The asset register doesn't update. And an asset that nobody is officially checking is a liability nobody has priced.
Blindspot 5: Lifts and Hoists Without Current LOLER Certification
The Lifting Operations and Lifting Equipment Regulations 1998 (LOLER) require all lifting equipment — including passenger lifts, goods lifts, scissor lifts, and hoists — to be thoroughly examined at statutory intervals:
Passenger lifts: every 6 months
Goods lifts and platform lifts: every 12 months
Any lifting equipment used to lift people: every 6 months
The statutory examination must be carried out by a competent person (typically a specialist inspection body), and a written report must be produced and retained.
The common failure: the lift engineer services the lift. But the statutory LOLER thorough examination — which is a separate legal obligation from routine maintenance — hasn't been commissioned or hasn't been done on time.
In one scenario, the lift is well-maintained. In the other scenario, the legal obligation is unmet.
These are not the same thing. Regulators don't treat them as the same thing.
The Pattern Across All Five
Read those five areas again and you'll notice a pattern.
The compliance failure isn't usually negligence. The contractor exists. The work is broadly happening. But the logging, certification, scheduling, and verification framework that proves compliance — to an auditor, an insurer, an HSE inspector — isn't in place.
That distinction matters enormously.
Because legal liability doesn't hinge on whether the work was done.
It hinges on whether you can prove it.
How Most UK Facilities Operations Are Actually Running
One or two contractors per asset type, each with their own paperwork format.
Certificates stored in email threads, physical folders, or nowhere retrievable.
No central dashboard showing RAG status across all five statutory areas.
No automated renewal alerts. No formal PPM schedule tied to an asset register.
And a director who, if asked today, couldn't say with certainty when the next fixed wire test is due, or whether the LOLER certificate on the service lift expired last month.
This isn't unusual. It's the default.
It becomes a problem the moment something goes wrong.
What a Properly Governed Compliance Operation Actually Looks Like:
A live asset register covering all five statutory categories.
Every certificate stored centrally, retrievable in under 60 seconds.
Automated renewal alerts triggered 90, 60, and 30 days before any expiry.
A vetted contractor network with SLAs that guarantee inspection turnaround times.
A named responsible person for each asset class, with documented oversight records.
A real-time compliance status view — Green, Amber, Red — across your entire portfolio.
That's not a fantasy. It's an operational standard. And it's achievable without adding headcount, without a software subscription that just hands you a login, and without asking your team to learn another system.
It does require one thing: a structured deployment that sets it up properly, onsite, from day one.
If you want to check where your operation stands against all five of these areas right now, we've built a free tool to help.
Start Here: The UK Statutory Compliance Self-Audit Checklist
Download the UK Statutory Compliance Self-Audit Checklist — a structured audit across Fire, Water/Legionella, Electrical, Gas, and Lifts/Hoists.
It'll show you exactly where your current compliance records are solid and where the gaps are.
No obligation. No sales call unless you want one.
If the audit reveals gaps you'd rather not manage yourself, that's what our Zero Legal Risk Compliance Tier is designed for. £3,000. Onsite deployment. Zero ongoing client labour.
Or read next: The Hidden Cost of Asset Downtime: £3k Compliance vs £5k Core Protection