top of page

Compliance - Doing the right thing

  • rachelratty
  • 21 hours ago
  • 7 min read

© Copyright 2026: The Intelligent Business Company Ltd, publisher of Housing Technology
© Copyright 2026: The Intelligent Business Company Ltd, publisher of Housing Technology

What are housing providers’ main hurdles around regulatory compliance (i.e. doing the right thing)?


The regulatory environment for social housing providers has become both broader and more exacting, with increasing demand for transparency, evidentiary assurance and timely performance information. The challenge is no longer simply whether landlords are undertaking the right activities, but whether they can demonstrate, in a reliable and auditable way, that those activities are complete, effective and appropriately governed.


One of the central hurdles is the scale and complexity of the compliance landscape. Compliance responsibilities span a wide range of operational areas, from gas, electrical, fire, asbestos, legionella and lifts, through to damp and mould, stock condition, tenant safety and broader asset governance. Each area brings its own data requirements, specialist processes, evidentiary demands and reporting expectations.


Often, Specialist teams, contractors and external assessors may all hold parts of the picture, sometimes in their own systems or through manual reporting arrangements. This creates obvious difficulties in achieving a comprehensive, current and trusted view of compliance across the organisation.


Another significant hurdle is the continued reliance on manual processes, spreadsheets and fragmented systems, which are increasingly unsuited to the scrutiny now placed on landlords. Manual systems are time-consuming to maintain, vulnerable to error, difficult to audit and rarely provide the real-time visibility needed to manage risk effectively.


The key issue for providers is therefore not simply completing individual compliance tasks, but embedding robust, repeatable and evidence-led processes that support timely action, clear ownership and meaningful oversight.



And what are their main hurdles around regulatory reporting (i.e. reporting the right thing)?

 

Regulatory reporting presents a different but closely related challenge. Compliance is concerned with doing the right thing; reporting is concerned with proving it accurately, consistently and at the right level of detail.


The central reporting hurdle is appropriate information availability. Many providers hold substantial quantities of data, but this does not necessarily mean that the right information is available in the right format, at the right time, and with the necessary level of confidence.


Where data is held across multiple systems, contractor portals, spreadsheets and departmental records, producing a reliable report can become a labour-intensive exercise in reconciliation. This not only creates delay, but also introduces scope for inconsistency, duplication and interpretation. In such circumstances, the reported position may be open to challenge, even where considerable effort has gone into producing it.


There is also the issue of timeliness. Boards, executives and regulators increasingly expect reporting that reflects the current position, not a snapshot assembled weeks later. Manual reporting processes can introduce delays, increase the risk of error, and make it harder to explain the source of the numbers.


Definitions are another recurring issue. If teams are not aligned on what constitutes completion, failure, no access, overdue status, risk level or remedial closure, then performance reporting may appear precise while masking inconsistency underneath. Regulatory reporting requires common definitions, controlled processes and clear audit trails.


The reporting burden is also intensified by the need for granularity. Senior teams, boards and regulators increasingly require not just headline performance, but the ability to understand exceptions, trends, risk concentrations and the evidence behind reported figures. A single percentage figure is rarely sufficient. Providers must be able to explain what sits beneath the number and what action is being taken.

 

How does the role of technology differ between regulatory compliance and regulatory reporting

 

Technology plays a critical role in both areas, but the emphasis differs.


For regulatory compliance, technology should support action. It helps providers identify risk, allocate responsibility, trigger workflows, monitor progress, capture evidence and escalate issues before they become failures. In this context, technology is about operational control and assurance.


For regulatory reporting, technology should support confidence. It brings data together, standardises definitions, automates calculations, creates audit trails and enables consistent reporting across teams and time periods. In this context, technology is about transparency, accuracy and trust.


The two should not be separated completely. Good reporting depends on good compliance processes, and good compliance is strengthened by reliable reporting. The most effective systems connect the two: operational activity creates the evidence, and reporting draws directly from that evidence rather than from separate spreadsheets or manual exercises.


Technology is therefore most valuable when it bridges the operational and assurance requirements: supporting the management of day-to-day compliance while also producing trusted, auditable and timely information for internal and external reporting.

 

What is the best way to minimise manual processes?

 

The best way to minimise manual processes is not simply to automate existing inefficiencies. It is to first understand the strengths and weaknesses of current processes, then design a more robust operating model around clear ownership, structured data and repeatable workflows.


A common mistake is to transfer spreadsheet-based thinking into a new system. This can result in technology being used to replicate manual work rather than remove it. Providers should instead identify where information is first created, how it should be validated, who needs to act on it, what evidence is required and how it should feed reporting.


Single data entry should be an important objective. Where information is captured once, at the point of activity, and then reused for operational management, assurance and reporting, the scope for duplication and error is significantly reduced.


Integration is also essential. In a sector where no single system can realistically address every specialist requirement to the same standard, providers should focus on ensuring that proven systems can communicate effectively. Modern APIs, well-designed interfaces and clear data ownership can support a much more reliable operating environment than disconnected spreadsheets or manual uploads.


Automation should then be applied sensibly: reminders, escalations, exception reporting, validation checks, workflow triggers and dashboarding can all reduce administrative burden. However, automation must be underpinned by sound business processes and relevant sector expertise. Without that, there is a danger of producing more data, but not necessarily more insight.

 

How can housing providers get accurate, comprehensive and trustworthy data for regulatory compliance and reporting?

 

Accurate and trustworthy data depends on governance as much as technology and trustworthy data starts with clear ownership. Providers need to know who is responsible for each data set, how it is maintained, and how quality is checked.


They also need common definitions. Compliance and reporting data must be based on common terminology and consistent rules. Dates, statuses, outcomes, risk categories and completion measures should mean the same thing across the organisation. Without this consistency, even sophisticated reporting tools can produce unreliable outputs.

Robust validation is essential. Data arriving from contractors, surveyors, assessors or internal teams should not simply be accepted into the reporting environment without appropriate checks. Validation of incoming data and evidence is fundamental to maintaining confidence in the reported position.


Evidentiary management is vital. Providers must be able to demonstrate not only that a task is marked as complete, but why it is considered complete. Certificates, photographs, survey outputs, action records, correspondence, no-access evidence and remedial histories all form part of the assurance picture.


Auditability is key. Providers should be able to trace a reported figure back to the underlying records and evidence. That includes knowing when data was entered, who changed it, what supporting evidence exists, and whether any assumptions or exclusions were applied.


Comprehensiveness also requires integration. Providers need a joined-up view across properties, assets, components, risks, inspections, actions, residents and contractors. Without this, it becomes difficult to understand the full compliance position or identify where risk is concentrated.


Finally, data quality should be treated as an ongoing discipline, not a one-off cleansing exercise. Regular validation, exception reporting and governance are essential if providers want confidence in both day-to-day compliance and formal regulatory submissions.


Technology can provide the platform, but trusted data depends on disciplined processes and clear organisational ownership.

 

What are the common pitfalls to avoid around a. regulatory compliance and b. regulatory reporting?


One common pitfall is treating compliance as a checklist exercise rather than an active risk management process. Completing a task is important, but providers also need to understand whether the outcome was satisfactory, whether remedial works are required, whether those works have been completed, and whether the supporting evidence justifies the recorded status.


A related challenge is over-reliance on informal knowledge and manual processes. Many organisations have experienced staff who understand where risks exist, but that knowledge is not always captured within formal systems. Spreadsheets, email trails and informal updates may support short-term workarounds, but they rarely provide the transparency, auditability and real-time oversight now expected by regulators. Where assurance depends on individual knowledge rather than robust evidence, it becomes inherently fragile.


Siloed working presents a further risk. Compliance disciplines often require specialist expertise, but this should not result in isolated systems, disconnected datasets or fragmented accountability. When information is dispersed across teams and platforms, organisations struggle to develop a comprehensive view of performance, compliance and risk, making effective oversight more difficult.


In the context of regulatory reporting, one of the most significant pitfalls is excessive reliance on spreadsheets. While spreadsheets remain useful tools, they frequently introduce version-control issues, hidden formulas, inconsistent definitions, extensive manual manipulation and limited audit trails. Providers should also be cautious of reporting that is overly high-level. Headline indicators can be helpful, but on their own they rarely provide sufficient insight. Effective reporting should enable users to drill down into exceptions, understand trends, identify root causes and assess whether corrective actions are delivering the intended outcomes.


It is also important not to confuse data volume with data quality. Organisations may hold large quantities of information, but if that information is inconsistent, poorly structured or insufficiently validated, it cannot provide a reliable foundation for reporting or decision-making.


Equally, providers should avoid assuming that technology alone will resolve compliance weaknesses. Implementing a new system will not improve a poorly defined process. Organisations must first understand their obligations, establish clear workflows and ensure that responsibilities are embedded and consistently applied across the business.

Finally, compliance management and reporting should be forward-looking rather than focused solely on historic performance. Effective systems should help organisations identify emerging risks, overdue actions, recurring failures and areas requiring intervention before they become significant issues.


Ultimately, good reporting should drive better decisions. The value is not just in submitting information to a regulator, but in helping the organisation understand performance, identify risk and improve outcomes for residents.


Summary

Regulatory compliance and regulatory reporting are closely connected, but they are not the same challenge. Compliance requires providers to undertake the right activities, manage risk and maintain evidence. Reporting requires them to present that position accurately, consistently and with confidence.


The organisations best placed to respond will be those that invest in robust processes, trusted data, appropriate specialist systems and meaningful integration. In a sector facing increasing scrutiny and continuing pressure to do more with less, reliance on manual processes and fragmented information is no longer sustainable.



Click here to read the latest edition of Housing Technology - Magazine


 
 
 

Comments


© 2024 by Asprey Management Solutions. 

bottom of page