What the early refusal rates tell us about safety cases under the Building Safety Act

Of the validated Building Assessment Certificate applications assessed so far, 73% have been refused. That points to something deeper than administrative delay.

Cascade Risk

The early outcomes from the Building Safety Regulator present a stark picture. Of 1,679 validated Building Assessment Certificate applications, only 567 have been assessed. Of those assessed, 73% have been refused, and more than half of those refusals are subject to enforcement action.

These figures point to something deeper than administrative delay or minor deficiencies. They suggest a systemic problem: a widespread difficulty in demonstrating compliance with the duties imposed by the Building Safety Act 2022.

What the law requires. Part 4 of the Act is clear. Section 83 requires Accountable Persons to identify and assess building safety risks. Section 84 requires the Principal Accountable Person to take all reasonable steps to prevent those risks materialising and to reduce their impact if they do. Section 85 requires a safety case report that draws those assessments together and explains the steps taken. In short: assess risk, manage risk, and show your working.

The BAC is neither the law nor the goal of the safety case. It is the regulator's opportunity to determine whether you have met the intent of the regulation, at that moment in time.

Some BACs are now being issued with a two-year review cycle, yet no building remains static for two years. If the safety case exists only as a report prepared for the BAC application, how will it remain aligned with the building over that period? How will changes be integrated, and how will the organisation demonstrate it has continued to take all reasonable steps?

The real test of a safety case may come after an incident. In that context the question will not be whether a BAC was obtained, but whether the organisation complied with Sections 83 and 84. Lawyers will examine whether hazards were recognised, whether foreseeable risks were identified, and whether controls were effective. If the safety case has not evolved with the building, a historic certificate will offer limited protection.

Why so many applications are failing. The 73% refusal rate suggests many submissions are not convincingly demonstrating that risk has been properly assessed and managed. Too many of the safety case reports we see resemble descriptive inventories: a catalogue of systems, inspections and policies.

The regulator is testing something else. It wants to know whether duty holders understand how their buildings would perform in the event of a building safety risk, how they could fail, and how controls address those risks in a proportionate and sustained way. It is looking for structured reasoning, not volume. Our experience is that a better articulated report significantly reduces the number of requests for information.

A safety case is a system, not a report. The safety case report required under Section 85 is the expression of the safety case; it is not the safety case itself. A mature safety case is embedded within the safety management system and connected to change management, maintenance, incident reporting and governance oversight. When something changes, that change should trigger a review of the relevant risk assessments and control measures. The message from the regulator is simple: show us that you understand what could go wrong, and that you are in control.

From reactive compliance to demonstrable control. Some organisations are waiting to be called in and then assembling a report. That is an increasingly risky approach, and the pressure it places on the people involved is intense and unsustainable.

Organisations navigating the regime successfully recognise that a safety case is precisely that — a structured, defensible case for safety. Not a bundle of documents, but a coherent set of reasoned arguments about the building's specific hazards and foreseeable risks, explaining why the building is acceptably safe, what assumptions underpin that position, and how control measures address identified risks proportionately. Crucially, they treat the safety case as live, embedded in day-to-day safety and change management, so that when the building or its operation changes, the safety arguments are revisited and tested.

The strategic choice. The Building Safety Act places responsibility firmly on organisational leadership. The regulator does not assume ownership of risk when it issues a BAC; the risk remains with the duty holder. So the essential question for every Principal Accountable Person is this: if an incident occurred tomorrow, could I demonstrate that I had identified all reasonably foreseeable risks and taken all reasonable steps to manage them? If the answer depends on a document written months ago and rarely revisited, the likely answer is no.

Across the sector we see the same practical challenges. Teams are snowed under yet still uncertain whether the safety case is any good. Organisational churn makes continuity difficult, there is limited consistency across portfolios, and boards lack clarity of oversight.

This is precisely the gap Cascade addresses. Cascade lets you structure the safety case as a live system, linking risk assessments, control measures, assumptions and evidence in a way that is reviewable and repeatable. It standardises formatting, reduces duplication, supports continuity, and embeds the safety case within everyday management processes.

We know the process — we have supported organisations through regulatory scrutiny and helped secure BACs. If the symptoms sound familiar, fragmented information, overworked teams, concern about keeping the report up to date and uncertainty about whether your approach is right, it may be time to get in touch.

Share with your team

LinkedInEmail