Ask any facilities manager how many statutory inspections their portfolio is due this month and you will usually get a confident answer. Ask how many were due last March and were actually completed, by whom, with what result, and where the certificate is stored, and the confidence drops sharply. Statutory compliance rarely fails because somebody decided to skip a fixed wire test. It fails because the obligation lived in one person's calendar, the certificate landed in one person's inbox, the remedial action was verbally agreed on site, and none of those three things ever met each other. The gap only surfaces during an audit, an insurance claim or a change of managing agent, when the evidence has to be produced rather than described. Bringing every obligation, certificate and remedial into a single tracked register is what OxMaint was built to do for facilities teams managing multi-site estates.
The Real Shape of a Statutory Compliance Failure
Compliance failures almost never look like negligence from the inside. They look like a sequence of individually reasonable decisions. The emergency lighting test was moved because the tenant had an event. The contractor promised to email the certificate and got pulled onto another job. The remedial C2 observation on the electrical report was quoted, the quote sat awaiting approval over a holiday period, and by the time it was approved the purchase order referenced a different scope. Nobody did anything wrong at any single step. The estate is still non-compliant.
What makes this pattern so persistent is that the information needed to spot it is distributed across systems that do not talk to each other. The schedule lives in a spreadsheet. The certificates live in a shared drive folder structure that made sense to whoever created it in 2019. The remedials live in email. The spend lives in finance. To see the truth, somebody has to manually reconcile four sources, and because that takes a full day, it gets done annually at best — which is to say, after the exposure has already existed for months.
Inspection due date slips by a few weeks. Nobody notices because the tracker is updated manually and only when somebody remembers.
The inspection happens but the certificate never arrives. The system shows it as complete because the date was ticked, not because evidence was filed.
The report contains observations requiring action. Those actions are never converted into tracked work with owners and deadlines.
The next cycle begins against a baseline nobody verified, and the original defect is now a year old and invisible.
Statutory Is Not One Thing — It Is Fourteen Overlapping Regimes
Part of what makes statutory compliance hard to manage is that the word describes a bundle of quite different obligations, each with its own frequency, its own competent person requirement, its own documentation standard and its own enforcing authority. A facilities manager running a mixed portfolio is effectively operating a dozen separate compliance programmes at once, and a failure in any one of them is a failure overall.
| Compliance Area | Typical Frequency | Evidence Produced | Common Failure Point |
|---|---|---|---|
| Fixed wire electrical inspection | Every 5 years, varies by use | Electrical installation condition report | C1 and C2 observations never converted to work orders |
| Portable appliance testing | Risk-based, often annual | Asset-level test register | New equipment entering site outside the test cycle |
| Gas safety inspection | Annual | Gas safety record | Access failures in tenanted areas not logged |
| Water hygiene and legionella | Monthly to biannual by task | Temperature logs, risk assessment review | Monthly logs kept on paper and never digitised |
| Emergency lighting | Monthly function, annual duration | Test log and defect list | Annual duration test skipped during occupancy |
| Fire alarm system | Weekly call point, quarterly service | Logbook entries and service certificate | Weekly test recorded inconsistently across sites |
| Lifting equipment and lifts | Every 6 or 12 months | Thorough examination report | Report defects with statutory deadlines missed |
| Pressure systems | Per written scheme of examination | Examination report | Written scheme itself out of date |
| Local exhaust ventilation | Every 14 months typically | Thorough examination and test record | Systems added after commissioning never registered |
| Fire risk assessment review | Annual or on significant change | Assessment document and action plan | Action plan treated as advisory rather than tracked |
Read that table as a facilities manager and the scale of the coordination problem becomes clear. Ten regimes, each with a different cadence, across every site in the portfolio, means several hundred discrete obligations in a mid-sized estate. Managing several hundred deadlines in a spreadsheet is not a tooling preference, it is a risk decision — and it is the decision that produces the audit findings.
The Certificate Is Not the Finish Line
The single most common structural mistake in compliance management is treating the arrival of a certificate as the completion of the obligation. It is not. A certificate is a snapshot of condition at a point in time, and most statutory reports contain observations, recommendations or coded defects that themselves carry duties. An electrical installation condition report marked unsatisfactory is not evidence of compliance; it is evidence that you knew about a problem on a specific date.
This is where regulators and insurers concentrate their attention, because it is where intent becomes visible. A missed inspection can be explained as an administrative lapse. A known C1 observation left open for eleven months cannot. The record shows the organisation was informed, understood the severity, and did not act. That is a materially different conversation.
The operational fix is to make every inspection produce two outputs rather than one: a filed certificate and a set of tracked actions derived from it. The actions must carry the same weight as any other work order — an owner, a priority, a target date and an evidenced completion. When that link is automatic rather than manual, the gap between knowing and doing closes on its own.
Obligation Registered
Each asset or site carries its statutory duties with frequency, standard and competent person requirement recorded once.
Inspection Scheduled
The next due date generates automatically from the last completion, with notice periods long enough to book a contractor.
Work Completed
The inspection is carried out and closed against the obligation, with the contractor and engineer identity captured.
Certificate Attached
The obligation cannot be marked compliant until the document is uploaded, which removes the ticked-but-unevidenced failure mode.
Remedials Raised
Observations become linked work orders with severity and deadlines, visible on the same dashboard as the inspection itself.
Cycle Reset
Completion recalculates the next due date, and the full history stays attached to the asset for the life of the estate.
A Maturity Model for Compliance Management
It helps to be honest about where an organisation currently sits, because the right next step depends entirely on the starting point. Most facilities functions fall into one of four levels, and the jump that delivers the most risk reduction is usually from level two to level three, not from level three to level four.
The reason the level two to level three jump matters most is that it is the point at which compliance stops depending on individual memory. A spreadsheet is only as reliable as the person maintaining it, and that person goes on holiday, changes role and occasionally leaves. Every organisation that has inherited a compliance tracker from a departed colleague knows the particular dread of trying to work out whether the blank cells mean not due, not done, or not known.
What Auditors Actually Ask For
Whether the scrutiny comes from an enforcing authority, an insurer, a client under a managed services contract or an internal audit function, the line of questioning is remarkably consistent. Being able to answer these five questions quickly is a reasonable working definition of compliance readiness.
Show me the register
A complete list of statutory obligations across the estate, with frequency and the responsible party for each. Not a list of what was done — a list of what is required.
Show me this asset's history
Every inspection on one named asset over several years, in sequence, with certificates and outcomes, without gaps you have to explain verbally.
Show me your overdue items
A current list of anything past its due date, with the reason and the recovery plan. An empty list is good. An honest list with dates is nearly as good.
Show me your open remedials
Actions arising from reports, by severity and age. This is where most organisations are weakest and where findings most often land.
Show me who did the work
Contractor and engineer identity, with evidence of competence or accreditation appropriate to the discipline, attached to the record.
Show me the change history
Who altered a due date, closed an action or amended a record, and when. Editable spreadsheets cannot answer this at all.
Our estate had about four hundred statutory obligations across nine sites and they were tracked in a workbook with eleven tabs. It worked until the person who built it moved on. The first month after that, we genuinely could not tell an auditor whether two of our sites were current on emergency lighting. That was the moment we stopped treating a spreadsheet as a system.
How OxMaint Handles Statutory Compliance
OxMaint approaches compliance as a subset of asset management rather than a separate discipline, which matters more than it sounds. When the statutory inspection, the resulting remedial, the reactive repair and the planned replacement of a given asset all sit on one record, the compliance picture and the maintenance picture stop contradicting each other.
Obligation Register By Asset
Statutory duties attach to assets and sites with frequency, standard and competent person requirements, so the register is generated from reality rather than maintained by hand.
Automatic Scheduling And Escalation
Next due dates calculate from last completion, with configurable lead times and escalation before an item becomes overdue rather than after.
Evidence-Gated Completion
An obligation cannot be closed as compliant without an attached certificate or record, which eliminates the ticked-but-unevidenced entry entirely.
Linked Remedial Actions
Observations from reports become work orders linked to the originating inspection, with severity-based deadlines and full visibility of open age.
Contractor And Competence Records
Engineer identity, accreditation and insurance details sit against the work, so proving who did what and whether they were qualified is immediate.
Portfolio Compliance Dashboard
Current position by site, discipline and severity, with overdue and open-remedial counts refreshed continuously rather than assembled quarterly.
Moving an Estate Onto a Single Register
The migration is less daunting than most teams expect, largely because the hardest part is a decision rather than a data exercise. The decision is to accept that the first accurate compliance picture will look worse than the current one. It will show overdue items that the spreadsheet did not surface and open remedials that nobody had counted. That is not a deterioration, it is the first honest measurement.
Practically, start by importing the obligations rather than the history. A register of what is required, by asset and site, is achievable in days and immediately more useful than years of scattered certificates. Attach historical documents opportunistically as each obligation comes round for its next cycle, and within one full compliance year the system holds a complete, self-maintained record without anyone ever running a bulk document migration project.
Sequence the disciplines by consequence. Fire, electrical, gas and lifting equipment first, because those carry the sharpest enforcement and insurance exposure. Water hygiene and ventilation next. Lower-consequence regimes can follow once the pattern is established and the team is comfortable with the workflow.
Frequently Asked Questions
What is statutory compliance software?
It is a system that holds every legally required inspection, test and certificate against the assets and sites they apply to, schedules them automatically and evidences completion. OxMaint provides this as part of its maintenance platform.
Is a spreadsheet enough for a small estate?
It can work for a handful of obligations on a single site. It stops working once the register exceeds what one person can hold in their head, or when that person leaves and the blank cells become ambiguous.
How should remedial actions from reports be tracked?
As work orders linked to the report that generated them, with a severity, an owner and a deadline proportionate to the observation code. Tracking them separately from the inspection is how they get lost.
How long should statutory records be retained?
Retention varies by regime, but a practical policy is to keep records for the life of the asset plus any limitation period. Digital storage against the asset makes indefinite retention cheap and searchable.
Can compliance and general maintenance share one system?
Yes, and separating them creates the reconciliation gap most audits find. One asset record carrying both statutory and reactive history gives a single version of the truth. Book a demo to see a combined asset view.







