Redefining Technology

Construction & InfrastructureAI Implementation & Best Practices

AI compliance site documentation in construction: from Friday write-ups to a live golden thread

AI compliance site documentation is the practice of capturing a construction site's statutory and contractual records — diaries, permits, inspection evidence, registers — at the point of work, then using models to classify, link and gap-check them, so the compliance record becomes a live, queryable asset rather than a reconstruction assembled after the event for an audit.

Construction site office with compliance documentation being captured and classified against a digital record set
Construction & Infrastructure · AI Implementation & Best Practices

Key takeaways

  1. Compliance site documentation fails at capture, not at filing. A record written on Friday about Tuesday's pour is testimony, not evidence — and no document management system downstream can add back the timestamps, locations and photographs that were never taken.
  2. The ladder runs Retrospective → Digitised → Captured → Linked → Continuous, and the industry's plateau is stage 2: forms moved to tablets, a CDE that is really a shared drive, records searchable but unlinked. Digitised is not captured.
  3. AI has four jobs in the compliance record — drafting, classification, linking and gap detection — and drafting is the least valuable and most dangerous of the four. Every AI-drafted record needs a named human signature before it becomes the record.
  4. The Building Safety Act 2022 makes a live, queryable record — the golden thread — a statutory duty on higher-risk buildings, with duties in force since October 2023. The same capability wins delay and defect disputes on every other job.
  5. The most honest KPI is retrieval time: how long it takes to produce the full evidence chain for one named requirement. Days at stage 1, hours at stage 2, minutes at stage 4 — and it is measurable this week with ten mock audit queries.

Abbreviations used on this page

CDE
Common data environment (the ISO 19650 information store)
CDM 2015
Construction (Design and Management) Regulations 2015
RAMS
Risk assessment and method statement
ITP
Inspection and test plan
PTW
Permit to work (hot works, confined space, excavation, lifting)
NCR
Non-conformance report
RIDDOR
Reporting of Injuries, Diseases and Dangerous Occurrences Regulations 2013
HRB
Higher-risk building under the Building Safety Act 2022
BSR
Building Safety Regulator
DPIA
Data protection impact assessment
QHSE
Quality, health, safety and environment function
LOLER
Lifting Operations and Lifting Equipment Regulations 1998

Free · 8 questions · ~3 minutes

Score your site documentation on the ladder

Eight questions, one at a time, about three minutes. Answer them and we build your personalised documentation report — your stage on the ladder, your score on each of the four dimensions, and the specific gap standing between you and the next stage — and send it to your inbox. Your result doubles as the baseline for the 90-day plan further down this page.

0 of 8 answered

Question 1 of 8Capture at source

When is a site diary entry actually written?

The gap between event and record is the gap between evidence and testimony. Nothing downstream can close it.

How the score maps to a stage
  • 05 — Stage 1, Retrospective. Compliance records are written after the work, from memory, and live wherever the person who wrote them happened to put them.
  • 611 — Stage 2, Digitised. Forms have moved to tablets and a CDE exists, but records are still authored after the event and filed by hand — searchable, unlinked, and unverified in coverage.
  • 1216 — Stage 3, Captured. Evidence is captured at the workface — photos, dictation, digital permits — and models classify and file it against a requirement register, with a named author verifying every record.
  • 1721 — Stage 4, Linked. Every record is linked to the requirement, location, person and plant it evidences, so audit questions are answered by query rather than search, and gaps are detected while they can still be closed.
  • 2224 — Stage 5, Continuous. Compliance status is computed continuously from the evidence graph: gaps surface daily, the golden thread is a live dataset, and inspection-readiness is a property of the system rather than an event.

What AI compliance site documentation is — and why capture beats filing

A definition, the four jobs AI actually does in a compliance record, and the evidence chain that separates a defensible record from a Friday write-up.

AI compliance site documentation is the use of machine learning to create, organise and assure the records a construction site is required to keep — the diary, permits to work, RAMS and briefing records, ITP hold-point evidence, plant and lifting certificates, NCRs, environmental records and, on higher-risk buildings, the golden thread. The AI does four distinct jobs: it drafts records from dictation and imagery, classifies them into the common data environment, links each record to the requirement, location and party it evidences, and detects gaps between what the register demands and what the record contains.

The order of those four jobs matters, because the industry's instinct is to buy the first and the value is concentrated in the last three. A drafted diary saves a foreman ten minutes; a linked, gap-checked record set changes what a dispute, an audit or a Building Safety Regulator (opens in a new tab) gateway submission costs. And all four jobs sit on one precondition no model can supply: the record must be captured at the point of work, with time and place attached, because a record written after the event is testimony — and no classifier, however good, can turn testimony back into evidence.

Defensible coverage against position on the ladder

The curve is not linear. Coverage you could actually defend on demand stays close to flat through stages 1 and 2 — where most contractors are — and inflects at stage 3, when records start being born at the workface instead of reconstructed after it. Filing improvements without capture improvements move a site along the flat part.

Share of the record set defensible on demand by stage

  • Stage 1 · Retrospective — 26% of operators. Compliance records are written after the work, from memory, and live wherever the person who wrote them happened to put them.
  • Stage 2 · Digitised — 38% of operators. Forms have moved to tablets and a CDE exists, but records are still authored after the event and filed by hand — searchable, unlinked, and unverified in coverage.
  • Stage 3 · Captured — 22% of operators. Evidence is captured at the workface — photos, dictation, digital permits — and models classify and file it against a requirement register, with a named author verifying every record.
  • Stage 4 · Linked — 11% of operators. Every record is linked to the requirement, location, person and plant it evidences, so audit questions are answered by query rather than search, and gaps are detected while they can still be closed.
  • Stage 5 · Continuous — 3% of operators. Compliance status is computed continuously from the evidence graph: gaps surface daily, the golden thread is a live dataset, and inspection-readiness is a property of the system rather than an event.

Curve shape: logistic, plotted from the stage data above. Distribution: Consistent with McKinsey's construction digitisation research.

How a site event becomes compliance evidence, stage by stage

The evidence path at each stage of the ladder. The stage is determined by where the record is born: stages 1–2 author it after the event from memory, stages 3–4 capture it at the workface and verify it before it becomes the record, and stage 5 computes compliance continuously against the requirement register. Most contractors are in the top lane.

  • Data & feeds
  • Where value leaks
  • Human in the loop
  • AI / model
  • System-of-record action

The process, in words

  • At stages 1–2, the only workface record is memory and a notebook. The diary is written on Friday, photographs scatter across phones and WhatsApp, and when an auditor, adjudicator or inspector asks a precise question, the answer is a reconstruction measured in days. This is where evidential value leaks.
  • At stages 3–4, the same events are captured as they happen — photographs with time and location, dictated diaries, digital permits. A model classifies each capture and extracts its structure, a named author reviews and signs it, and the signed record enters the CDE linked to the requirement, location and party it evidences.
  • At stage 5, a versioned requirement register defines what a complete record set looks like. Gap detection compares the register against the linked record daily and routes missing or expiring evidence to a named owner — so an inspector's question is answered by query, and audit-readiness is a property of the system rather than an event.
Step-by-step insights
The Friday write-up is testimony, not evidence
A record's evidential weight comes from its proximity to the event: contemporaneity, provenance, and metadata that ties it to a time, a place and an author. A diary entry composed days later from recollection has none of these — it is one person's account, written when the outcome may already be known. Courts and adjudicators discount it accordingly, and opposing counsel knows to ask exactly one question: 'when was this actually written?'. Everything else on this page exists to make the honest answer to that question harmless.
Capture at source changes who carries the burden
When the record is born at the workface, the burden of documentation shifts from the person to the workflow. The foreman does not 'do paperwork'; he dictates ninety seconds while walking to the van. The engineer does not 'file photos'; the capture app already knows the hold point she is standing at. This is not a convenience argument — it is a quality argument. Records created inside the work are more accurate, more complete and better-timed than records created after it, for the same reason that telemetry beats a survey.
What the classifier actually does — and its ceiling
The classification model reads each capture — image, transcript, form, scanned certificate — and assigns record type, project, location reference, trade and plant, then files it into the CDE's structure under an ISO 19650-style naming discipline instead of asking a human to pick a folder. Its ceiling is the metadata it is given: a photo with GPS and a hold-point context classifies almost perfectly; a bare scan of a handwritten permit is hard for the model for the same reason it is hard for a person. This is why capture design, not model choice, dominates accuracy.
The verification signature — why draft is never record
Every AI-drafted record passes through a named human who reviews, corrects and signs it, and the system retains all three artefacts: the draft, the edits and the signature. The reasons are practical before they are legal. Models transcribe imperfectly and occasionally confabulate; a wrong gang size is an annoyance, but an invented sentence in a record that later reaches RIDDOR territory or disclosure is a catastrophe that discredits the entire archive. The signature also creates the accountability a regulator expects: a person stands behind the record, with the model as their instrument.
The requirement register — the hinge artefact of the whole ladder
The register is the machine-readable list of everything this project must be able to prove: each statutory duty (CDM 2015, RIDDOR, LOLER, environmental duty of care, Building Safety Act where it applies), each contractual obligation (ITP hold points, warranty evidence, client ESG reporting), with an owner, an evidence type and a retention rule per line. It is the difference between 'we keep good records' and 'we can compute what is missing'. Without it, gap detection has nothing to detect against — which is why it appears at stage 3 and everything above depends on it.
Gap detection and the golden thread as a query
Gap detection is a join, not magic: the register says a released hold point requires photographs and a signature; the graph shows the release exists and the photographs do not; a task lands on the owner's list the same day. Run daily, this converts compliance from an audit event into an operating rhythm. On a higher-risk building, the same machinery is what makes the golden thread real — the Building Safety Act's expectation of a current, accurate, accessible record stops being a binder assembled for a gateway and becomes a query the accountable person can run any afternoon.

The five stages in detail

For each stage: what it looks like on the ground, the diagnostic signals a reviewer can check in an afternoon, the anti-pattern that traps contractors there, and what leaving costs.

Each stage below is written for a practitioner rather than a buyer. The hallmarks describe observable conditions, the diagnostic signals are checks you can run against your own CDE and site this week, and the anti-pattern is the specific mistake most often made trying to leave that stage. Note that the ladder is about the record, not the technology: a site with no AI at all but same-day, signed, located records outranks a site with a model drafting fiction into an unowned folder.

Select a stage

Every stage's full detail is in the page source — the selector only changes which panel is visible, so nothing here depends on JavaScript to exist.

Stage 1

Retrospective

26% of operators sit here

Compliance records are written after the work, from memory, and live wherever the person who wrote them happened to put them.

Stage 1 is not the absence of documentation — construction produces more paper per pound of revenue than almost any industry. It is the absence of evidential value in the documentation that exists. The diary entry written three days after the pour, the briefing register signed in a batch at the end of the month, the photo that proves the rebar was inspected but sits undated in a leaver's phone: each record exists, and almost none of it would survive cross-examination, because nothing ties it to the time, place and person it claims to describe.

The tell is what happens when someone asks a precise question. A client's engineer asks for the evidence that the fire-stopping in riser 3 was inspected before it was boarded over. At stage 1 the answer is a reconstruction: emails are searched, subcontractors are phoned, a foreman is asked what he remembers about a Tuesday eleven months ago. The record set the project needs exists in fragments across twenty inboxes and eight phones, and the person assembling it is doing archaeology, not retrieval.

This stage is expensive in a way that rarely appears on a cost report. Disputes settle worse because the diary is thin exactly where the delay happened. Insurance claims drag because the condition photographs cannot be dated. And when the HSE investigates an incident, the gap between what was done and what can be proven was done becomes the story. The work was usually done; the site just cannot demonstrate it.

In practice

The pour that had no photographs

A groundworks subcontractor poured a transfer slab on a Friday afternoon. The reinforcement was inspected — two people remember standing on it — but the photographs were on the phone of an engineer who left in the spring, and the diary entry, written the following Monday, says only 'slab poured as planned'. Fourteen months later a crack appears and the dispute turns on cover depth. The contractor is not wrong; the contractor simply cannot prove it is right, and the settlement reflects the difference.

What it looks like

  • The site diary is written on Friday for the whole week, from recollection
  • Photographic evidence lives in personal phone galleries and WhatsApp groups
  • Permits to work are paper, filed in the site cabin until the box is full
  • Audit or claim preparation is an archaeology project measured in days

Diagnostic signals you can check this week

  • Ask when the current site diary entry was actually written — watch, don't ask the policy
  • Pick one hold point from last month and ask for its evidence; time the answer
  • Count the WhatsApp groups that carry site photographs a claim would need
  • Ask who owns the compliance record set. If the answer is a job title, not a name, nobody does

Anti-pattern · Scanning the backlog

The instinctive first move is a scanning project: digitise the cabin's filing cabinets, upload the archive, buy licences. It feels like progress and changes nothing, because the problem is not where old records sit but how new ones are born. A scanned Friday write-up is still a Friday write-up. Leave the archive where it is, and fix capture on live work — the archive only matters if a dispute reaches back into it, and scanning will not add the metadata that makes it useful anyway.

What holds you here

Records are created after the event, so no amount of filing, scanning or software downstream can make them evidential.

Highest-leverage next move

Pick one project and two record types — the diary and one inspection record — and move their creation to the workface, same day, with time and location attached.

Cost of leaving

Effort
2–4 months
Team
A QHSE lead and a site manager, part-time, with one digital-savvy engineer
Risk
Low — capture-at-source pilots are additive and touch no system of record
To next stage
2–4 months

If this is you, the next step is

A 2-week exercise: define the record set for one project and time ten retrieval drills.

Baseline your record set

Stage 2

Digitised

38% of operators sit here

Forms have moved to tablets and a CDE exists, but records are still authored after the event and filed by hand — searchable, unlinked, and unverified in coverage.

Stage 2 is where most of the industry sits, and it is a comfortable place to be stuck because every visible artefact of modernity is present. There are tablets on site, a CDE in the contract, forms with dropdowns, a dashboard for management. What has actually happened is that the Friday write-up has been typed instead of handwritten. The record is still authored after the event, still from memory, still filed by a person deciding which folder it belongs in — the medium changed and the epistemology did not.

The structural problem at stage 2 is that digitisation was scoped as a forms project rather than a capture project. Each compliance demand became another form; each form became another end-of-shift chore; and the quality of what goes into the forms degrades in exact proportion to their number. Site teams are rational: when the paperwork burden rises and the working day does not lengthen, the entries get shorter, later and more generic. A stage-2 CDE fills up with records whose consistency looks like rigour and whose content is boilerplate.

The second problem is coverage blindness. A shared drive full of PDFs can answer 'show me documents about riser 3' but not 'which requirements have no current evidence?' — because nothing links a record to the obligation it discharges. Stage 2 operators discover their gaps at exactly the wrong moment: in an audit, in a gateway submission, in disclosure. The records were searchable all along; what was missing was any definition of what a complete record set would look like.

In practice

The 4,000-photo folder

A regional contractor rolled out a photo app across its sites. Eighteen months later one project's CDE holds 4,000 images: batch-uploaded, auto-named, some geotagged, most not. The client's engineer asks for evidence that penetration seals in the plant room were installed to specification before the ceiling closed. The QA manager's honest answer is that the evidence is probably in the folder. Three people spend two days scrolling. The photographs existed; the record did not.

What it looks like

  • Site forms are digital and the project has a named CDE
  • Folder structures mirror the old paper filing, one level deeper
  • Photos are uploaded in batches, named IMG_4711 onward
  • Nobody can say which requirements currently have no evidence

Diagnostic signals you can check this week

  • Open the CDE and count how many of the last 50 records carry a location reference a system could resolve
  • Ask for the requirement register. At stage 2 there isn't one — there is a folder template
  • Compare diary timestamps against the shifts they describe; measure the lag
  • Ask which subcontractors file into the CDE and which email PDFs monthly

Anti-pattern · Adding more forms

When a stage-2 operator fails an audit, the reflex is a new form — one more end-of-shift obligation with three more mandatory fields. Every added form degrades the ones that already exist, because form-filling time competes with supervision time and supervision wins. The fix runs the other way: reduce what a human authors and increase what the workflow captures. A dictated 90-second diary with model-extracted structure beats a 14-field form completed at 6pm, on every axis a court or regulator cares about.

What holds you here

Records are digital but still authored after the event and filed by hand, so the CDE accumulates volume without gaining evidential value or measurable coverage.

Highest-leverage next move

Stand up a requirement register for one project and move the diary and one inspection record to same-day, at-source capture with automatic classification.

Cost of leaving

Effort
3–6 months
Team
One integration engineer, the document controller, a pilot site's QHSE advisor
Risk
Medium — capture tooling meets site culture here, and culture wins unless the tooling saves time visibly
To next stage
3–6 months

If this is you, the next step is

The stage 2→3 transition, scoped to one project. Typically 90 days.

Move one record to capture-at-source

Stage 3

Captured

22% of operators sit here

Evidence is captured at the workface — photos, dictation, digital permits — and models classify and file it against a requirement register, with a named author verifying every record.

Stage 3 inverts the relationship between work and record: documentation becomes a by-product of doing the work rather than a task performed after it. The foreman dictates ninety seconds at the gate and a model drafts the diary entry with plant, labour, weather and delays already structured. The engineer photographs the hold point and the image arrives in the CDE already classified — record type, location, ITP reference — because the capture app knew where it was and what was scheduled there. Nobody 'does the paperwork'; the paperwork condenses out of the workflow.

The discipline that makes stage 3 defensible rather than merely fast is the verification signature. A model's draft is not the record; the record is what a named person reviewed, corrected and signed, with the draft, the edits and the signature all retained. This distinction — draft versus record — is the single most important design decision on the whole ladder. It is what a lawyer will ask about first, it is what keeps a hallucinated sentence out of a document that might one day reach the HSE, and it is cheap: a review takes a fraction of the time the write-up used to.

Stage 3 is also where the requirement register appears, and it changes the site's self-knowledge more than any model does. The register is the list of what this project must be able to prove — by regulation, by contract, by ITP — with an owner and a retention rule per line. It is the first time the site knows what complete looks like, which means it is the first time anyone can honestly say how complete the record is. Most operators are startled by the initial number.

In practice

The dictated diary

On an RC-frame job, the section foreman records a voice note walking to his van: two gangs on level 4, pump down ninety minutes, north crane wind-limited from 2pm, one near miss at the loading bay. The model drafts the diary entry, tags plant and subcontractors, flags the near miss for the QHSE lead, and queues it for signature. The foreman corrects one gang size and signs from his phone. Elapsed time: four minutes. The entry is timestamped the same day, location-tagged, and the near miss did not wait for Friday.

What it looks like

  • Diary entries are dictated at the gate and drafted by a model the same day
  • Photographs carry time, location and hold-point references at creation
  • A requirement register defines what a complete record set looks like
  • Every AI-drafted record shows a named human signature and an edit trail

Diagnostic signals you can check this week

  • Measure capture latency: record timestamp minus event timestamp, across a week of records
  • Pick five AI-drafted records and check each shows an author, an edit trail and a signature
  • Ask to see the requirement register and the name against each line
  • Check whether the near-miss count rose after capture went mobile — it should

Anti-pattern · Trusting the transcript

After a month of accurate drafts, someone proposes removing the signature step — the model is 'basically always right' and the review feels like friction. Then a draft places a subcontractor on site on a day they were not, or summarises a near miss into something milder, and the error enters a record that RIDDOR or a dispute later reaches. One fabricated line, discovered by an opponent, taints every record the system ever produced. The signature is not friction; it is what makes the archive worth having.

What holds you here

Records are well-captured but stand alone, so audit questions still mean search rather than query, and coverage is asserted rather than computed.

Highest-leverage next move

Link every new record to the requirement, location and party it evidences, and turn gap detection on against the register — forward-looking, live project first.

Cost of leaving

Effort
6–12 months
Team
One ML/integration engineer, the document controller as product owner, pilot-site supervision
Risk
Medium — the failure mode is cultural: if capture costs the site time, the site will quietly stop
To next stage
6–12 months

If this is you, the next step is

We build the draft-to-signature pipeline and the register it files against.

Design the verification workflow

Stage 4

Linked

11% of operators sit here

Every record is linked to the requirement, location, person and plant it evidences, so audit questions are answered by query rather than search, and gaps are detected while they can still be closed.

Stage 4 is the difference between a pile of good records and an evidence graph. Each captured record now carries machine-followable links — this photo evidences that ITP hold point, at this grid reference, released by this engineer, using this plant with this LOLER certificate. Once those links exist, the questions that used to take days become queries: show the full chain for fire-stopping on level 3; show every permit active in zone B on 14 March; show which lifting operations ran on certificates within thirty days of expiry. The record set has become a database with documents attached, rather than documents with a database aspiration.

Linking changes the temporality of compliance. At every earlier stage, gaps are discovered by audits — which is to say, too late, by the least sympathetic possible reader. At stage 4 a gap detector runs daily against the requirement register: a hold point released without its photographs, a RAMS briefing with no attendance record, a permit expiring on work that has not closed out. The gap surfaces as a task on a named person's list while the scaffold is still up and the subcontractor is still on site — when closing it costs minutes instead of a claim.

The frontier at stage 4 is the supply chain. A principal contractor's own records link cleanly; the steel erector's inspection sheets arrive as monthly PDF bundles and the piling contractor has its own app. Flow-down — putting the capture standard and CDE obligation into subcontract schedules, and providing the tools that make compliance easier than non-compliance — is slower than any engineering task on this ladder, and it is what separates a stage-4 project from a stage-4 business.

In practice

The gateway submission built in a fortnight

A contractor delivering a higher-risk residential building faced its golden thread obligations at gateway 3. On previous jobs, assembling as-built compliance evidence had been a three-month, two-person crawl through folders. This time the fire-safety information was a set of queries against the linked record: every penetration seal by location with installation evidence and inspection sign-off, every fire door with its certificates chained to installed locations. The submission took two weeks, most of it review — because the assembly was retrieval, not reconstruction.

What it looks like

  • A record carries structured links: requirement, location or element, party, plant
  • Gap detection runs daily against the register and pages the line's owner
  • An audit query returns an evidence chain in minutes, on demand
  • Subcontractor records land in the same CDE under the same register

Diagnostic signals you can check this week

  • Run three unrehearsed audit queries and time them — minutes is stage 4, hours is not
  • Ask for the current gap list and the age of the oldest open gap
  • Check what fraction of subcontractor records arrive linked versus emailed
  • Ask whether coverage — requirements with current evidence — is a number on a dashboard or a feeling

Anti-pattern · Linking everything retroactively

Once the graph proves its value, someone proposes back-linking three years of legacy records so the whole archive can be queried. The project consumes a data team for two quarters, the old records lack the metadata that makes linking reliable, and the error rate of inferred links quietly poisons trust in the graph. Link forward: every new record born linked, the live project fully covered. Reach into the archive only when a dispute or a specific obligation demands it, and label inferred links as inferred.

What holds you here

Coverage is computed but still project-shaped: assurance is produced when someone asks a question, and the supply chain's records join the graph unevenly.

Highest-leverage next move

Turn coverage into a continuously computed property with daily gap detection across all live projects, and make the register a maintained artefact that tracks regulatory change.

Cost of leaving

Effort
12–18 months
Team
Platform engineer, document controller, commercial team for subcontract flow-down
Risk
Medium — the engineering is tractable; the subcontract flow-down is the long pole
To next stage
12–18 months

If this is you, the next step is

We model the register, the links and the gap rules against one live project.

Map your evidence graph

Stage 5

Continuous

3% of operators sit here

Compliance status is computed continuously from the evidence graph: gaps surface daily, the golden thread is a live dataset, and inspection-readiness is a property of the system rather than an event.

Stage 5 is narrower and less glamorous than 'AI-run compliance'. It means one specific thing: audit-readiness is a steady state, not a mobilisation. Coverage against the requirement register is a number computed daily for every live project; gaps have owners and ages; the golden thread on an HRB is a maintained dataset the BSR could query rather than a binder the project would assemble. Nothing about this requires exotic models — it requires the register, the graph and the verification discipline of stages 3 and 4 running as an operating rhythm rather than a project.

The work that sustains stage 5 is register maintenance, and it is a governance discipline, not an engineering one. Regulations move: Building Safety Act secondary legislation lands, approved documents are amended, a client's ESG reporting adds a duty. Each change must be triaged into the register — new lines, changed retention rules, new evidence types — on a cadence someone owns, or the system drifts into confidently computing coverage against last year's obligations. A stale register is more dangerous than no register, because it wears the costume of assurance.

The same rigour turns inward on the AI itself. By stage 5 the models that draft, classify and link records are part of the compliance estate and need their own file: what the model does, what data it saw, its error profile, its version history — the shape of discipline that ISO/IEC 42001 formalises for AI management systems and that the NIST AI RMF describes for risk. When a record is challenged, the operator must be able to say which model version touched it, what the human changed, and who signed. Stage 5 operators can. That answer, more than any capture technology, is what makes the whole ladder defensible.

In practice

The unannounced visit

An HSE inspector arrives at a stage-5 contractor's infrastructure site after a public complaint about a crane operation. The requests: lift plans, the appointed person's records, LOLER thorough-examination certificates for the crane, and the permits for the affected zone, for a specific fortnight. The document controller runs four queries while the inspector has coffee. Every certificate chains to the specific crane, every permit shows its sign-on record. The visit closes the same day. The site's readiness was not a scramble — it was a property of the system.

What it looks like

  • Every live project shows computed evidence coverage, refreshed daily
  • Regulatory change is triaged into register updates on a defined cadence
  • DPIAs, retention schedules and deletion run as automated policy
  • An inspector's question is answered the same afternoon, from the system

Diagnostic signals you can check this week

  • Ask for evidence coverage per live project as of this morning — a number, not a shrug
  • Ask who triaged the last regulatory change into the register, and when
  • Check the imagery retention queue: is deletion happening on schedule, with a log
  • Ask which model version drafted a given record six months ago — and time the answer

Anti-pattern · Letting the register fossilise

The system runs, coverage is green, and the register review quietly falls off the calendar — nobody notices because the dashboards keep updating. A year later the operator is computing perfect coverage against an obsolete obligation set: a new tranche of secondary legislation has changed golden thread expectations and two clients' contracts now demand embodied-carbon records the register never heard of. Assurance that measures the wrong thing is worse than none. The register review is the compliance system's own compliance, and it needs an owner with a date.

What holds you here

Sustaining the state is governance: register currency, model accountability and retention discipline — the constraint is ownership, not engineering.

Highest-leverage next move

Treat the requirement register and the model file as versioned, owned artefacts with a review cadence — the same rigour the records themselves get.

Cost of leaving

Effort
Continuous
Team
Document control as a product function, plus a standing register-review forum with QHSE and commercial
Risk
Concentrated — low frequency, high consequence: regulatory drift and challenged records

If this is you, the next step is

We stress-test register currency, link integrity and one challenged record end to end.

Audit your evidence chain

Where contractors actually sit on the ladder

The distribution across the five stages, why 'digitised' is the industry's plateau, and what the research says the far side is worth.

Most contractors sit at stage 2. The industry has bought the tablets, named a CDE in the contract and digitised its forms — and still authors most records after the event, files them by hand and cannot compute coverage. The plateau is structural rather than technological: digitisation projects are scoped and funded as forms projects, capture-at-source requires changing how supervision spends its day, and nothing in a standard audit forces the difference into view until a dispute or a gateway does.

Distribution of contractors across the five stages

Stage 2 is the mode and the plateau: visible modernity, unchanged epistemology. The drop from stage 2 to stage 3 is the largest single transition loss on the ladder — it is where the work changes from buying tools to changing capture.

Share of contractors

  • 26% — 1 · Retrospective
  • 38% — 2 · Digitised (the plateau)
  • 22% — 3 · Captured
  • 11% — 4 · Linked
  • 3% — 5 · Continuous

Source: Illustrative distribution, synthesised from McKinsey construction-productivity and cross-industry AI adoption research

The gap between experimenting with AI and getting value from it is not construction-specific — McKinsey's State of AI research (opens in a new tab) has tracked it across industries for years. What is construction-specific is the shape of the prize. A contractor's documentation is simultaneously its statutory defence under CDM 2015 (opens in a new tab), its commercial ammunition in every delay and defect dispute, and — on higher-risk buildings — a regulated product in its own right under the Building Safety Act. Few industries get paid three times for the same capability; documentation maturity is one of the places construction does.

The compliance record map: what a site must prove, and what AI can touch

The record set of a working site — who demands each record, its statutory or contractual basis, what AI genuinely does well with it, and the line that stays human.

A construction site's compliance record set is broader than most digitisation projects assume, and each record type has a different demander, a different statutory basis and a different safe role for AI. The map below is the version we use to scope capture programmes with contractors. Two patterns run through it: AI is consistently strong at drafting, extraction, linking, expiry-tracking and gap-chasing; and the judgement acts — issuing a permit, releasing a hold point, deciding RIDDOR reportability, dispositioning an NCR — stay human on every row, not because models could not attempt them but because accountability for them cannot be delegated.

RecordWho demands itBasisWhat AI does wellWhat stays human
Site diary / daily recordPM; adjudicators and courts in disputeContract (NEC/JCT); primary delay evidenceDraft from dictation; extract plant, labour, weather, delay events; timestamp and locateAuthorship and signature — the account is a person's
Permits to work (hot works, confined space, excavation)Principal contractor QHSE; HSE after incidentsHSWA 1974 / CDM 2015 safe systems of workExpiry tracking; conflict checks across zones; completeness checks before issueIssue, sign-on, gas tests, closure — every safety-critical act
RAMS and briefing recordsPrincipal contractor; HSE on inspectionCDM 2015Version control; attendance capture; flagging briefings that outdate their method statementThe risk judgement itself; delivering the briefing
ITP hold and witness pointsClient's engineer; warranty providersContract specification; ISO 9001 QMSSchedule points from the programme; chase evidence; link photos to the point at captureThe inspection; the release of a hold point
Temporary works registerTemporary works coordinator; designerBS 5975 regime under CDM 2015Register upkeep; chasing permit-to-load and permit-to-strike statusDesign checks; category decisions; load/strike permissions
Plant and lifting inspectionsSite management; insurers; HSELOLER 1998 / PUWER 1998Certificate expiry detection; cross-checking plant on site against current certificatesThe thorough examination by a competent person
NCRs and closeout evidenceClient QA; the engineerISO 9001; contractDraft from photos; link to drawing revision and location; chase closeout evidenceThe disposition — accept, repair, reject
RIDDOR reportables and near missesHSERIDDOR 2013Flag reportability candidates from incident and diary records — never auto-reportThe reportability judgement and the report
Waste transfer and environmental recordsEnvironment Agency; client ESGEnvironmental Protection Act duty of careExtract from weighbridge tickets; reconcile carrier registrations; assemble returnsDuty-of-care declarations
Golden thread submissions (HRBs)Building Safety Regulator; accountable personBuilding Safety Act 2022 and secondary legislationAssemble by query from linked records; completeness checks against gateway requirementsAccountable-person sign-off; the design decisions recorded
The construction compliance record map. 'What stays human' is a floor, not a ceiling — on regulated judgements, the model prepares and the person decides. Statutory references are Great Britain; the pattern transfers.

Where to start is a narrower question than the map suggests. The best first candidates share three properties: the record is created frequently (so capture habits form in weeks, not quarters), the evidence window closes fast (so the value of at-source capture is visible), and the demander is internal (so no client approval gates the change). By those tests, the site diary and photographic hold-point evidence are the right first pair on almost every project — daily creation, cover-up deadlines, internal ownership. Permits come next; the golden thread record set comes once the register and linking machinery exist, because a gateway submission is precisely a query against them.

One row deserves a health warning. RIDDOR sits on this map because incident records are part of the site's documentation, and a model reading diaries and near-miss reports can usefully flag candidate reportables that a busy QHSE function might triage late. It must never do more than flag. Reportability under RIDDOR 2013 (opens in a new tab) is a legal judgement with criminal exposure attached, and an auto-filed report — or a model quietly deciding something is not reportable — puts an algorithm inside a duty that belongs to a person. The pattern generalises: wherever a row of this map touches a statutory decision, the model's output is an input to a named human, and the record shows both.

What captured, linked documentation looks like in public

Two published programmes, read against the ladder. Neither is an Atomic Loops engagement — each links to the vendor's own published material, and outcomes are theirs as stated.

The clearest public evidence for the capture-first thesis is in what the successful products chose to build. In both examples below, the differentiator is not model sophistication — it is where the evidence is born and what each output carries with it. One captures the as-built record at the workface as a by-product of walking the site; the other refuses to emit a compliance finding without attaching the evidence that lets a human verify it. Those are stage-3 and stage-4 disciplines, productised.

Two programmes read against the ladder

Outcomes as published by the vendors themselves — verify against the linked source before reusing figures. Card images are generated industry scenes from this page's library, not the vendors' own photography.

Generated scene: site engineer capturing a 360-degree walkthrough record on an active structureBuildotsConstruction intelligence platform · deployed by major contractors24
Challenge
Progress and as-built condition on large projects were documented through manual photo folders, marked-up drawings and weekly reports — after-the-event records that could not settle what was actually built, where, by when, when a delay or defect dispute needed them.
Approach
Helmet-mounted 360° cameras capture the site as engineers walk it anyway; AI compares the captured imagery against the model and programme, producing a continuous, location-referenced visual record with progress verification, deviation detection and site documentation among its published uses.
Reported outcome
Buildots publishes that its verified progress data and delay-risk analytics can reduce schedule delays by up to 50% on an average project — the vendor's own published claim.
What it shows about the curveCapture at source works when it is a by-product of work already being done. Nobody 'does documentation' — the walk the engineer was making anyway becomes a dated, located, queryable record, which is precisely the stage-3 to stage-4 move.

Buildots — construction intelligence platform (opens in a new tab)

Generated scene: engineer reviewing AI-flagged compliance findings against construction drawingsInspectMind AIAI plan check · drawings, specifications and building codes13
Challenge
Code-compliance review of construction drawings is slow, manual and inconsistently documented: findings arrive as marked-up sheets and comment logs whose reasoning cannot be traced back to the code clause or drawing detail that triggered them.
Approach
The platform reviews drawings, specifications and code libraries (IBC, CBC, NFPA and others) and — per its published description — attaches to every finding the drawing snippet, code section or specification reference that produced it, so each machine-generated finding ships with its own verifiable evidence.
Reported outcome
The vendor publishes that teams receive evidence-backed, prioritised findings in hours, used for QA/QC before permit submittal to reduce plan-check comments, RFIs and rework — the vendor's own published positioning.
What it shows about the curveMachine-generated compliance output is only usable because every finding carries its evidence reference for a human to verify — the same draft-versus-record discipline this page's verification stages require of diaries and inspection reports.

InspectMind AI (opens in a new tab)

The deeper problem: when is an AI-touched record defensible?

Capture automation without verification discipline produces fast fiction. The three tests a challenged record must pass, and the data-protection lane a camera-heavy site cannot skip.

An AI-touched compliance record is defensible when it passes three tests: provenance (what the model saw — the dictation, the images, the form data — is retained and reconstructable), verification (a named person reviewed, corrected and signed the draft before it became the record, and the edits are auditable), and governance (the model itself is versioned and accountable, so the operator can say which system touched which record and how it was known to behave). Miss any of the three and the record's weight collapses under challenge — and, worse, the challenge infects sibling records produced the same way.

  • Provenance — keep what the model saw

    Retain the source dictation, imagery and form data alongside the draft and the signed record, with the model version that processed them. When a diary entry is challenged in adjudication three years on, the difference between 'here is the voice note, the draft, the edits and the signature' and 'the system generated it' is the difference between evidence and an apology. Storage is cheap; reconstruction is not possible retroactively.

  • Verification — the signature that makes it a record

    The named-author signature is the load-bearing wall of the whole system, which is why it appears at stage 3 of this ladder and never leaves. It answers the accountability question every regulator asks of AI-assisted work — a person stands behind this record — and it is the mechanism that catches confabulation before it enters the archive. Frameworks like the NIST AI Risk Management Framework (opens in a new tab) and the management-system discipline of ISO/IEC 42001 (opens in a new tab) formalise the same principle: human accountability at the point where AI output becomes consequential.

  • The data-protection lane — the evidence system must not become the liability

    Site cameras, 360° walkthroughs and progress photography document the works and, unavoidably, the workforce — which makes them personal-data processing under UK GDPR (opens in a new tab). A camera-heavy documentation programme needs a DPIA before deployment, defined retention with automated deletion, access controls, and workforce transparency — the ICO's video surveillance guidance (opens in a new tab) is the operating reference, and the EDPB (opens in a new tab) publishes the equivalent guidance for EU sites. One boundary matters most: imagery captured to evidence the works must not quietly become worker-performance monitoring. Under the EU AI Act (opens in a new tab), AI systems used for monitoring and evaluating workers sit in the high-risk class with obligations to match — keep the documentation purpose written down, and keep the system on the right side of it.

Capture automation against verification discipline

Plot your sites. The dangerous quadrant is the top-left: heavily automated capture with no verification discipline produces records at volume that nobody stands behind — fast fiction, archived permanently.

Fast fiction

  • Volume without accountability
  • One challenged record taints the archive
  • Fix: verification workflow before more capture

Defensible at scale

  • Stage 4–5 operating state
  • Evidence is a by-product of work
  • Maintain: register currency and model governance

The Friday reconstruction

  • Stage 1–2 default
  • Testimony, not evidence
  • Fix: capture at source on two record types

Diligent but starved

  • Well-verified records of too little
  • Coverage gaps despite discipline
  • Fix: automate capture, keep the signatures
Capture automation — top: At-source, automated capture, bottom: Manual write-ups
Verification discipline — left: AI output filed unchecked, right: Every record signed, edits auditable

The matrix explains a pattern we see repeatedly: the contractors most enthusiastic about capture technology are often the least prepared for the verification question, because the tooling demos brilliantly without it. The demo never shows the adjudication three years later. Build the signature workflow first, then scale the capture — the reverse order produces an archive that grows faster than anyone can stand behind it.

The reference architecture: from capture to audit query

The five layers a captured, linked, continuously assured record set actually requires — stage-annotated, vendor-neutral, and defined by what each layer must guarantee.

A stage-4 documentation capability requires five layers, and the build order determines whether the programme compounds or stalls. The architecture below is deliberately unfashionable: nothing in it names a vendor, and each layer is defined by the guarantee it must provide rather than the product that provides it. Two layers are chronically underbuilt — the requirement register, because it looks like admin rather than architecture, and the verification layer, because it looks like friction rather than the thing that makes the archive worth having.

The documentation stack, layer by layer

Each layer is annotated with the ladder stage that first requires it. A programme attempting gap detection without a requirement register is building a stage-2 folder structure with extra steps.

  1. Capture layer

    Stage 2+

    • Mobile forms & dictationDiary, inspections, near misses — at the workface, same day
    • Imagery & walkthroughsPhotos, 360° capture, fixed viewpoints — time and location at creation
    • Digital PTW & plant systemsPermits, certificates and registers born digital, not scanned
  2. Classification & extraction

    Stage 3+

    • Record classifierType, project, location, trade, plant — filed without a human picking folders
    • Entity extractionSpeech-to-text, structure from dictation, data from certificates and tickets
    • Naming & filing disciplineISO 19650-style conventions applied by the system, not by memory
  3. Requirement register

    Stage 3+

    • Record-set definitionEvery obligation this project must evidence — statutory, contractual, client
    • Statutory mapCDM 2015, RIDDOR, LOLER, environmental duty of care, BSA where it applies
    • Owners & retention rulesA name and a retention period per line, versioned
  4. Evidence graph & CDE integration

    Stage 4+

    • Link modelRecord ↔ requirement ↔ location/element ↔ party ↔ plant
    • CDE write-backThe linked record lives in the project's system of record, not beside it
    • Query interfaceEvidence chains by element, zone, date range or requirement — in minutes
  5. Verification, gap detection & governance

    Stage 3+

    • Signature workflowDraft → named author review → signed record; edits auditable
    • Gap detectionRegister vs graph, daily, routed to owners with ages tracked
    • DPIA, retention & model fileAutomated deletion, access controls, model versions per record (stage 5)

Pipeline described

  1. Capture layer (stage 2+) — Mobile forms & dictation: Diary, inspections, near misses — at the workface, same day; Imagery & walkthroughs: Photos, 360° capture, fixed viewpoints — time and location at creation; Digital PTW & plant systems: Permits, certificates and registers born digital, not scanned
  2. Classification & extraction (stage 3+) — Record classifier: Type, project, location, trade, plant — filed without a human picking folders; Entity extraction: Speech-to-text, structure from dictation, data from certificates and tickets; Naming & filing discipline: ISO 19650-style conventions applied by the system, not by memory
  3. Requirement register (stage 3+) — Record-set definition: Every obligation this project must evidence — statutory, contractual, client; Statutory map: CDM 2015, RIDDOR, LOLER, environmental duty of care, BSA where it applies; Owners & retention rules: A name and a retention period per line, versioned
  4. Evidence graph & CDE integration (stage 4+) — Link model: Record ↔ requirement ↔ location/element ↔ party ↔ plant; CDE write-back: The linked record lives in the project's system of record, not beside it; Query interface: Evidence chains by element, zone, date range or requirement — in minutes
  5. Verification, gap detection & governance (stage 3+) — Signature workflow: Draft → named author review → signed record; edits auditable; Gap detection: Register vs graph, daily, routed to owners with ages tracked; DPIA, retention & model file: Automated deletion, access controls, model versions per record (stage 5)
Step-by-step insights
Capture layer — design for the person holding the phone
Every decision in this layer is won or lost on site-team time. Dictation beats forms because talking is faster than typing with gloves on; automatic time and location beat manual fields because nobody back-fills metadata at 6pm; capture embedded in existing walks beats dedicated documentation tasks because the walk was happening anyway. The test for any capture tool is brutal and simple: does the foreman's day get shorter or longer? If longer, adoption will decay to zero within a season regardless of what management mandates.
Classification & extraction — accuracy is set upstream
Classification accuracy is dominated by capture context, not model quality. A photo taken inside a hold-point workflow arrives knowing its ITP reference; the model only confirms. A bare image from a camera roll forces the model to guess location and purpose from pixels. This is why the capture and classification layers must be designed together: every piece of context attached at creation is a guess the classifier does not have to make, and a percentage point of filing error the document controller does not have to find later.
The requirement register — small artefact, load-bearing
The register is typically a few hundred lines per project, maintained by the document controller, and it is the difference between a folder structure and a compliance system. Building it is mostly transcription — the ITP, the construction phase plan, the subcontract schedules and the statutory baseline already imply it — and the discipline is keeping it versioned with a named owner per line. Everything above stage 3 consumes it: classification files against it, gap detection joins against it, and a gateway submission is a query over it.
Evidence graph — link at birth, not in a project
The graph is created one record at a time, at capture, when context is free — this photo, this hold point, this engineer, this crane. Attempting the same links retroactively is a data project with an error rate. The payoff compounds quietly: each link is individually trivial, and collectively they turn 'search the CDE' into 'query the record'. The practical test of a working graph is an unrehearsed question answered in minutes — which is also, not coincidentally, this page's headline KPI.
Verification & governance — the layer disputes are won in
This layer holds the three artefacts a challenge will demand: the provenance chain (what the model saw), the signature trail (who stood behind the record and what they changed), and the model file (which system version touched it and how it was known to behave). It also carries the data-protection machinery — DPIA, retention automation, access control — that keeps a camera-heavy documentation estate on the right side of UK GDPR and the ICO's surveillance guidance. It is the least demo-friendly layer and the one that decides whether the archive is an asset or a liability.

Sequencing follows from the annotations: capture first (stage 2→3 needs it), register and verification together (stage 3 is not real without both), graph and gap detection next (stage 4), governance automation last (stage 5). Programmes that buy the stack in one procurement almost always invert this — the graph and dashboards demo well, the register looks like admin — and spend a year linking records that were never verifiably captured.

A 90-day plan: covered-up work evidence on one RC-frame project

The stage 2 → 3 transition made concrete on one specific problem — proving that work you can no longer see was inspected before it disappeared. One project, two record types, no new platform.

Moving one stage takes about 90 days when it is scoped to one project and two record types, and multiple years when it is scoped to 'digital transformation'. The plan below runs the transition on the sharpest version of the documentation problem: covered-up work on a reinforced-concrete frame — reinforcement before pours, fire-stopping before boarding, services before screed — where the evidence window closes permanently with the work, and where stage-2 contractors discover at dispute that the photographs they assumed existed do not. The quarter deploys no new platform: it changes where two records are born and adds a register to file them against.

Stage 2 → stage 3 on covered-up work evidence, in one quarter

One project, one named owner, two record types: the site diary and photographic hold-point evidence. If any phase needs more than its window, narrow the scope — fewer hold-point types, one section of the frame — rather than extending the plan.

  1. Days 1–15

    Baseline retrieval and build the register

    Write the requirement register for the project: every obligation from the ITP, the construction phase plan and the statutory baseline (CDM 2015, RIDDOR, LOLER, environmental duty of care), with an owner and retention rule per line. Then run ten unrehearsed retrieval drills against the current CDE — 'show the evidence for X' — and time each one. Name the document controller as owner of both numbers.

    A versioned register, a timed baseline, one named owner

  2. Days 16–45

    Move capture to the workface

    Diary entries move to dictation at the gate, model-drafted, signed by the section foreman the same day. Hold-point photography moves into the ITP workflow: the capture app presents today's scheduled points, each photo arrives with time, location and point reference attached, and the classifier files it against the register. Both run alongside the old process for two weeks, then replace it.

    Two record types born at source, classified automatically

  3. Days 46–70

    Verification, linking and the DPIA

    Turn on the signature workflow — draft, named-author review, signed record, edits retained — and begin linking each new record to its register line and location at capture. Complete the DPIA for site imagery, set retention periods with automated deletion, and brief the workforce on what is captured and why, per ICO video surveillance guidance.

    Signed, linked records; imagery governed

  4. Days 71–90

    Re-drill, measure, decide

    Re-run the same ten retrieval drills and report the deltas: retrieval time, capture latency (record timestamp minus event timestamp), coverage of hold points with linked photographic evidence, and verification rate on AI-drafted entries. Present the before/after to the board with the scale-out decision: next project, next two record types.

    A measured delta the next project inherits

The order matters

  1. Register before models

    The register is a fortnight of document-controller work and it is what every model files against. Deploying capture tooling without it recreates the 4,000-photo folder with better cameras — volume without computable coverage.

  2. Verification before volume

    Turn on the signature workflow while the record count is small and the habit is forming. Retrofitting verification onto six months of unsigned AI drafts leaves an archive with two classes of record, and a cross-examiner will find the boundary.

  3. Two record types before twenty

    The diary and hold-point photography prove the pattern on the records with the fastest feedback and the sharpest evidence windows. Permits, RAMS and the golden thread set inherit working capture habits and a live register — each addition is configuration, not a new change programme.

Instrumenting the record: formula, source, cadence

The seven metrics that tell you the truth about your documentation system — where each comes from, how often to read it, and the stage at which it first measures something real.

A documentation KPI you cannot name a source system for is an opinion. Every metric below reduces to timestamps, counts and joins that the capture apps, the CDE and the register already record — the instrumentation work is connecting them, not creating them. Retrieval time is the headline because it is the one an outsider can test unannounced; capture latency is the leading indicator because everything else decays when it rises.

MetricFormula / readSourceCadenceHonest from
Retrieval timeAudit query asked → evidence chain produced, elapsedDrill log (ten standard queries)Monthly drillStage 1
Capture latencyRecord timestamp − event timestampCapture app metadataPer recordStage 3
Verification rateAI-drafted records signed by a named author ÷ AI-drafted recordsSignature workflow logWeeklyStage 3
Evidence coverageRegister lines with current linked evidence ÷ all register linesRegister × evidence graph joinDailyStage 4
Gap ageMedian days a detected gap stays openGap detector task logWeeklyStage 4
Subcontractor coverageSub records landing linked in the CDE ÷ sub records the register expectsCDE × subcontract schedulesMonthlyStage 4
Retention complianceImagery past retention deleted on schedule ÷ imagery due for deletionRetention automation logMonthlyStage 3
Instrumentation build sheet for the compliance documentation metrics. 'Honest from' is the ladder stage at which the metric first measures something real rather than something aspirational.

Read the seven as a system, not a scorecard. Capture latency rising predicts coverage falling a month later — the site is drifting back to write-ups. Verification rate falling while volume grows is the fast-fiction quadrant forming. Gap age is the cultural metric: a mature operation closes gaps in days because the person named on the register line treats the daily list as work, not noise. And subcontractor coverage is the honest ceiling on all of it — a principal contractor's own records at 95% coverage with the supply chain at 40% is a stage-4 project wrapped around a stage-1 risk.

Stage 3 readiness checklist

If you cannot tick all seven, the site is still at stage 2 regardless of what tooling is deployed. Tick as you go — this list works without JavaScript.

0 of 7 ticked

Tick honestly — the blank list is data too

Most stage-2 contractors can genuinely tick one or two of these, not zero. If none apply yet, don't start with tooling: pick one project and run the 90-day covered-up-work plan above. Five of the seven fall out of doing that once, on one job.

Failure modes that turn the record against you

Documentation maturity is not monotonic — and unlike most AI failures, these ones are archived, discoverable and dated. Four regressions account for almost all of it.

Documentation failures have a property most AI failures lack: they are permanent, timestamped and discoverable. A bad routing decision evaporates; a fabricated diary entry sits in the archive waiting for the dispute that finds it. The four failure modes below are the ones that convert a documentation system from an asset into a liability, and each has a cheap prevention that costs a fraction of its consequence.

Likelihood: mediumImpact: high

The model writes fiction into the record

A transcription error or confabulated detail — a subcontractor placed on site on the wrong day, a near miss summarised into something milder — enters a signed-looking record because the verification step was skipped or rubber-stamped. Discovered by an opponent in disclosure, one fabricated line taints every record the system produced, and the archive built to defend the contractor becomes the exhibit against it.

PreventionNamed-author signature on every AI-drafted record, with draft, edits and model version retained — and spot-audits of the signing discipline itself.

Likelihood: highImpact: high

Capture outlives its data-protection basis

Cameras deployed for progress documentation quietly accumulate years of workforce footage; retention is 'forever' by default; someone starts using walkthrough imagery to score gang productivity. The documentation programme is now unlawful worker monitoring with an ICO exposure attached, and the workforce goodwill that capture-at-source depends on evaporates.

PreventionDPIA before deployment, retention with automated deletion, and a written purpose boundary — documentation of the works, never performance monitoring of the people.

Likelihood: highImpact: medium

Subcontractor evidence never joins the record

The principal contractor's own records are captured and linked; the supply chain's arrive as monthly PDF bundles, or not at all. Coverage dashboards show green because the register only counts what the PC self-performs. The gap surfaces at handover or in a defect claim, when the fire-stopping evidence turns out to belong to a subcontractor whose app was never connected and whose retention lapsed with the final account.

PreventionCapture and CDE obligations in the subcontract schedule, tools provided rather than mandated, and subcontractor coverage measured as its own metric.

Likelihood: mediumImpact: high

The register fossilises while the dashboards stay green

Regulation moves — Building Safety Act secondary legislation, amended approved documents, new client ESG duties — and nobody triages the change into the requirement register. The system keeps computing perfect coverage against last year's obligations, which is worse than no assurance because it anaesthetises exactly the people who would otherwise ask questions.

PreventionA quarterly register review with a named owner, triggered additionally by any regulatory change notice — treated as the compliance system's own compliance.

Glossary

Hover a term for its definition — or expand the map full screen. The full definitions are written out below.

Golden thread
The Building Safety Act 2022's requirement for a current, accurate, digitally accessible record of a higher-risk building's design, construction and safety information, maintained through the building's life and available to the Building Safety Regulator.
Common data environment (CDE)
The single agreed information store for a project under ISO 19650 — the system of record where documentation lives, with naming, status and revision discipline. At stage 2 it is a shared drive with a rebrand; from stage 4 it holds the linked evidence graph.
Requirement register
The machine-readable list of everything a project must be able to prove — statutory, contractual and client obligations — with an owner, an evidence type and a retention rule per line. The hinge artefact that makes coverage computable.
Capture at source
Creating the record at the point of work — dictation at the gate, photographs inside the hold-point workflow, digital permits — so time, place and author attach at birth rather than being reconstructed afterwards.
Evidence chain
The linked set of records that together prove one obligation was discharged: the requirement, the work location, the inspection record, the imagery, the signatures and the certificates, followable by query.
Hold point
A point in an inspection and test plan beyond which work must not proceed until an inspection is completed and released — typically where the work is about to be covered up. Witness points are the softer variant: notification required, progress not gated.
Permit to work (PTW)
A formal authorisation for high-risk activities — hot works, confined spaces, excavations, lifting — recording controls, sign-on and closure. The record an incident investigation asks for first.
Non-conformance report (NCR)
The quality record raised when work departs from specification, carrying the defect description, its location and drawing revision, the disposition decision and the closeout evidence.
Verification signature
The named-author review and sign-off that turns an AI draft into a record, with the draft, the edits and the model version retained. The boundary a challenged record is examined against.
Gap detection
The daily comparison of the requirement register against the linked record set, flagging obligations with missing or expiring evidence to a named owner while closing the gap still costs minutes.
Retention schedule
The defined period each record class is kept before deletion, driven by statute, contract and limitation periods — automated at maturity, and applied with particular care to imagery that contains workforce personal data.
DPIA
A data protection impact assessment — the structured evaluation UK GDPR requires before high-risk processing such as systematic site surveillance, covering purpose, lawful basis, retention, access and workforce transparency.

Frequently asked questions

The questions contractors ask most often when moving their compliance documentation onto this ladder.

What is AI compliance site documentation?

AI compliance site documentation is the use of machine learning to capture, classify, link and gap-check the records a construction site must keep — diaries, permits, inspection evidence, registers and, on higher-risk buildings, the golden thread. The AI drafts records from dictation and imagery, files them into the common data environment automatically, links each record to the requirement and location it evidences, and flags obligations whose evidence is missing or expiring. The judgement acts — issuing permits, releasing hold points, deciding RIDDOR reportability — stay with named people.

Is an AI-written site diary legally acceptable?

An AI-drafted diary can be defensible; an AI-authored one is a liability. The distinction is verification: a named person must review, correct and sign the draft before it becomes the record, with the dictation, the draft, the edits and the model version all retained. What gives a diary evidential weight is contemporaneity and accountable authorship — dictated at the workface the same day and signed by the foreman, an AI-drafted entry is typically stronger than the traditional Friday write-up it replaces, because it is closer to the event and carries better metadata.

What is the golden thread, and does it apply to my projects?

The golden thread is the Building Safety Act 2022's requirement for a current, accurate, digitally accessible record of a higher-risk building's design and construction, maintained through its life. It applies in full to higher-risk buildings — broadly, residential buildings at least 18 metres or seven storeys — with duties in force since October 2023 and the Building Safety Regulator able to demand the record at gateways and beyond. If you never touch HRBs the statute does not bind you, but the capability it demands — a live, queryable, complete record — is exactly what wins disputes and audits on every other project.

Do site cameras and 360° walkthroughs need a DPIA?

Yes, in almost all cases. Systematic capture of imagery on a working site records identifiable people, which makes it personal-data processing under UK GDPR, and systematic monitoring of a workplace is exactly the category the ICO expects a data protection impact assessment for. The DPIA needs to cover purpose, lawful basis, retention with deletion, access controls and workforce transparency. The boundary to hold is purpose: imagery captured to document the works must not drift into scoring the people — under the EU AI Act, worker-monitoring AI sits in the high-risk class with heavy obligations attached.

How long does it take to get from scanned PDFs to captured-at-source records?

About 90 days for the first project, scoped to two record types — typically the site diary and photographic hold-point evidence — plus a requirement register to file them against. That quarter covers the capture change, automatic classification, the verification signature workflow and a measured before/after on retrieval time. Scaling to further record types and projects goes faster because the register, habits and pipeline already exist. What turns 90 days into two years is scoping the change as a company-wide platform programme instead of one project's capture problem.

What should a compliance requirement register contain?

One line per obligation the project must evidence, drawn from four sources: statute (CDM 2015 records, RIDDOR, LOLER and PUWER inspections, environmental duty of care, Building Safety Act duties where they apply), the contract (ITP hold points, warranty evidence, notice provisions), the client (ESG reporting, security requirements), and your own management system. Each line carries the evidence type expected, a named owner, and a retention rule. A few hundred lines is typical. It is a fortnight of document-controller work, and it is the artefact every model on this page files and checks against.

How do we handle subcontractor records?

Contractually, practically and measurably. Put the capture standard and CDE obligation into the subcontract schedule at package let — retrofitting it mid-project fails. Provide the tools rather than mandating formats: a subcontractor given the capture app and register access complies by default; one asked to restructure its own PDFs complies annually. Then measure subcontractor coverage as its own metric, because it is the honest ceiling on your record: a principal contractor at 95% self-performed coverage with the supply chain at 40% is carrying a stage-1 risk inside a stage-4 dashboard.

What retention periods apply to construction site records?

It varies by record class, which is why the register carries a retention rule per line rather than one policy. Contractual and quality records are generally governed by limitation periods — six years for simple contracts, twelve under deed in England and Wales — while statutory records like RIDDOR reports and health surveillance carry their own periods, and golden thread information persists for a higher-risk building's life. Imagery is the special case: workforce personal data should be kept no longer than its documented purpose needs, so blanket 'keep everything forever' policies fail UK GDPR while blanket short deletion destroys defence evidence. Set retention per class, automate deletion, and log it.

Can AI find gaps in our compliance evidence before an audit does?

Yes — that is gap detection, and it is the highest-value job on this page. It requires two things a model cannot supply alone: a requirement register defining what complete looks like, and records linked to the obligations they evidence. Given both, the detector is a daily join: hold points released without photographs, briefings without attendance records, permits expiring against open work, certificates lapsing on plant still on site. Each gap routes to the named owner while closing it costs minutes. Without the register and the links, 'AI gap detection' is a search box with ambition.

What does poor site documentation actually cost?

Three ways, in ascending severity. Commercially: delay and defect disputes are decided on the documentary record, and on McKinsey Global Institute figures 80% of large projects run over budget — a thin diary at the wrong fortnight settles a claim badly. Regulatory: HSE investigations reconstruct events from permits, briefings and diaries, and the gap between what was done and what can be proven becomes the story; construction recorded 25 worker deaths in Great Britain in 2025/26 on provisional HSE figures. Statutory: on higher-risk buildings an inadequate golden thread now blocks gateways — the record itself is regulated.

Should the record live in the CDE or in the specialist systems that create it?

Create where the workflow is best, record where the project can query it. Permit systems, capture apps and plant registers are good at their workflows and poor as archives; the CDE is the contractual system of record. The pattern that works is write-back: the specialist system runs the workflow, and the signed record — with its links to register line, location and party — lands in the CDE automatically. What fails is federation by goodwill, where evidence stays scattered across five vendors' databases and the evidence chain crosses three logins. One queryable record, many capture front-ends.

Does ISO 19650 require any of this?

ISO 19650 gives you the information-management frame — a common data environment, naming and status conventions, defined information requirements and delivery cycles — and BSI publishes UK guidance around the series. It does not require AI, capture-at-source or gap detection; it standardises the container and the discipline this page's ladder fills. The practical relationship: a contractor already operating ISO 19650 well has the CDE, the conventions and the information-requirements habit that the requirement register formalises, and typically starts at stage 2 rather than stage 1. The ladder is what turns that container from a filing standard into computed compliance.

About the author

Atomic Loops Engineering

Industrial AI practice

Atomic Loops builds production AI systems for construction, manufacturing, logistics and energy operators — capture pipelines, document classification, evidence linking and decision support running against live operational data, integrated into the CDE and field systems rather than delivered as dashboards.

  • · Production document-intelligence deployments across regulated industries
  • · Capture-to-CDE pipelines built jointly with contractor QHSE and digital teams
  • · Integration-first delivery: requirement registers, verification workflows, audit trails
  • · 16 cited sources on this page

Sources

  1. HSECDM 2015 — Construction (Design and Management) Regulations (opens in a new tab)
  2. HSERIDDOR — reporting of injuries, diseases and dangerous occurrences (opens in a new tab)
  3. HSEBuilding safety — the Building Safety Regulator (opens in a new tab)
  4. HSEWork-related fatal injury statistics (opens in a new tab)
  5. ISOISO 19650-1 — information management using BIM (opens in a new tab)
  6. ISOISO/IEC 42001 — AI management systems (opens in a new tab)
  7. Information Commissioner's OfficeVideo surveillance guidance (opens in a new tab)
  8. European CommissionRegulatory framework for AI (EU AI Act) (opens in a new tab)
  9. gdpr-info.eu (Intersoft Consulting)UK/EU General Data Protection Regulation text (opens in a new tab)
  10. NISTAI Risk Management Framework (opens in a new tab)
  11. EDPBEuropean Data Protection Board (opens in a new tab)
  12. BSIBSI Group — standards for the built environment (opens in a new tab)
  13. McKinsey Global InstituteReinventing construction: a route to higher productivity (opens in a new tab)
  14. McKinsey & CompanyThe state of AI (opens in a new tab)
  15. BuildotsConstruction intelligence platform (opens in a new tab)
  16. InspectMind AIAI plan check for construction drawings (opens in a new tab)

Find out exactly where your record stands — then make it defensible

We run the assessment with your QHSE and digital leads, time live retrieval drills against your current CDE, and leave you with a costed 90-day plan for your weakest dimension. You keep the plan whether or not we build it.

Published · Last updated

Benchmark request

Tell us where to send it

Benchmark for this page

Used once, to send this benchmark and follow it up personally. No newsletter, no automated sequences.