Skip to content
← Notebook · 37 essays

Contents

  1. The threshold has moved without the conversation moving with it
  2. What the inspection truly tests
  3. The governance question worth putting on the agenda
  4. Where the next NED conversation should go

When the Accountable Person Is You

22 January 2026·6 min read

The Building Safety Act 2022 introduced a role into UK social housing called the Accountable Person. For most registered providers with higher-risk buildings on the books, the Accountable Person is the chief executive or a named board member. They are personally liable, in criminal law, for the building safety information their organisation holds, the integrity of its golden thread record, and the safety case for every higher-risk building in the portfolio.

The legislation is three years old. The compliance deadlines are not theoretical. And the population of boards which are confidently able to evidence the records the Act requires is, by sector estimates, a small minority of the providers in scope.

The threshold has moved without the conversation moving with it

Until recently, the conversation about data in housing was a conversation about operations. Performance dashboards, KPI accuracy, the quality of the management information feeding the board pack. Useful, important, and unconnected to anything resembling a regulatory or legal threat. The audit committee asked about it once a year, the IT team replied, and the matter was filed.

This conversation is now obsolete, and it has been since the Social Housing (Regulation) Act 2023 received royal assent. The Regulator of Social Housing inspects against consumer standards, publishes its findings, and judges providers on the reliability of the data they submit. The Tenant Satisfaction Measures are statutory. Awaab's Law requires every report of damp and mould to be investigated and remediated within prescribed timescales, with an audit trail per case. The Building Safety Act requires the golden thread to be live, structured, and produceable on request. And the Information Commissioner's Office holds enforcement powers over the same data the Regulator is now scrutinising, with fines reaching seventeen and a half million pounds.

Each of these pieces of legislation alone would be a board-level matter. Together, they have redefined what data quality is for. It is not an operational concern with regulatory consequences. It is a governance posture with operational expressions, and the legal exposure now attaches to named individuals.

Most boards have not yet absorbed the shift. The board pack still leads with performance metrics. The audit committee still treats data as one item among many. The Accountable Person, if they have been formally identified, has often not been told what their personal liability looks like in concrete terms.

What the inspection truly tests

The Regulator's inspection methodology is worth reading carefully, because it does not test what most boards expect it to test.

Inspectors do not start with the headline figures. They start with the data underneath. They request the methodology document for each Tenant Satisfaction Measure. They ask which person produces the figure and where the documentation lives if the named individual is unavailable. They ask the asset team to produce, on the spot, a list of every property whose gas safety certificate is within thirty days of expiry, and they observe whether the answer comes from a system query or from a spreadsheet someone has been maintaining manually for six years.

The inspection is, in substance, an examination of whether the organisation's data infrastructure is fit to evidence the claims its board has been signing off on. The Regulator's published findings make the pattern explicit. Providers receiving C2 or C3 judgements are not, in the main, providers with worse outcomes than their peers. They are providers whose data does not stand up to inspection.

This matters because the consequences are public. The Regulator publishes the judgement. The judgement appears on funder dashboards, in tenant communications, and in the press. A C3 judgement triggers a regulatory engagement plan and the possibility of a board appointment by the Regulator. The reputational and operational cost of a poor judgement is disproportionate to the underlying performance gap, because the gap is not in performance. The gap is in evidence.

The governance question worth putting on the agenda

For a board which has not yet had this conversation in detail, the diagnostic question is direct. Is your organisation able to produce the following on request, today, without warning.

A reconciled list of every property in the portfolio with its current gas safety certificate status, electrical inspection status, fire risk assessment status, and asbestos survey status, drawn from a single source of truth rather than four spreadsheets.

The methodology document for each of the ten management information measures the Regulator requires, including the precise extract logic, the exclusions applied, and the named officer accountable for production.

The audit trail for every report of damp or mould received in the last twelve months, with investigation date, severity assessment, and remediation date for each case.

The golden thread information for every higher-risk building in the portfolio, structured, version-controlled, and aligned to the Building Safety Regulator's specification.

The Records of Processing Activities under UK GDPR, current within the last twelve months, with the lawful basis documented for each processing activity.

If the answer to any of these is no, the question is not whether the organisation has a data problem. It does. The question is how exposed the Accountable Person currently is, and whether the board has accepted the exposure as a deliberate strategic choice or has inherited it as an unacknowledged default.

There is no good third option. The legislation does not distinguish between a provider which has chosen to under-invest in data infrastructure and one which has under-invested without realising it. The Regulator does not soften its judgement for an Accountable Person who was unaware of what was being asked of them.

Where the next NED conversation should go

The board agenda needs a new standing item, and the audit committee needs to take ownership of it. Data governance, in the post-Act 2023 environment, is not a delegated matter. It sits alongside financial viability, safeguarding, and health and safety as a domain in which the board carries direct, personal, and increasingly criminal accountability.

For boards taking this seriously, the priorities are not technical. They are governance priorities, in the order they need to be addressed. A senior responsible owner for data, designated at executive level, with the authority to require compliance across service areas. A documented data accountability structure with named owners for each critical dataset. A regular data quality report to the audit committee, presented in plain English, against measurable standards. An annual external review of the governance framework, to provide the board with assurance independent of the people producing the data.

These are not the elements of a transformation programme. They are the conditions under which the Accountable Person is in a position to defensibly sign off on the safety case, the golden thread, and the regulatory return. Without them, the signature is being asked to carry weight the data underneath cannot support.

The conversation in most board rooms is overdue. The legislation has already moved. The question every chair should be putting to the executive team this quarter is the one the Regulator will eventually put to them under inspection conditions: show me, today, with the records you genuinely hold.

Richard Sutcliffe · CTO at ThinkTribal · field notes on AI in regulated sectors

Non-executive interest

Currently exploring Non-Executive Director roles where AI governance, regulated-sector delivery, and a generalist technical lens are useful at board level — social housing in particular, plus adjacent regulated sectors.

richard.sutcliffe@gmail.com · credentials · what I’m on now

  • social housing
  • governance
  • data governance
  • board readiness
  • awaabs law
← OlderTwo Boards, One Tenant, No ConversationNewer →The Theory-First Product Hire Is a Governance Risk

Adjacent

  1. 01
    28 May 2026

    The Data Is Not the Gap

  2. 02
    22 May 2026

    The Reporting Layer Is the Last Thing to Fail

  3. 03
    15 May 2026

    Your Board Is Flying Blind on Complaints Data