What the record has to survive
British Standards decide what your software must store, not just what it should show
Most inspection products are designed around a generic checklist. UK compliance work is not generic, and the gap usually shows up on the day somebody asks for the file.
- Anchor testing, BS 8539 and BS 7883
- BS 8539 covers the selection, supply, installation and testing of post-installed anchors in concrete and masonry, and it draws a line most software ignores: the proof load is not invented on site. It comes from the designer, the specification, the manufacturer or a competent person. A system that lets an engineer type any number has already failed the standard. The sampling rules matter too, since testing one in forty fixings and one in twenty-five carry different load factors.
- Lifts, LOLER 1998 and BS EN 81
- Regulation 9 requires a thorough examination by a competent person, at least every six months for anything that lifts people. The report is a statutory document with a defined list of items it must contain, and where the equipment lifts people it has to be kept for the working life of that equipment rather than a couple of years. Software that treats the report as a printout rather than as a retained record is the wrong shape.
- Calibration, UKAS and BS EN ISO/IEC 17025
- Your torque wrench comes back from a laboratory with a certificate that names a parameter, a range and an uncertainty, tied to that laboratory's schedule of accreditation. What the software has to do is hold that certificate against the instrument, know when it expires, and refuse a reading taken after that date rather than accepting it and flagging it in a report a fortnight later.
- Quality management, BS EN ISO 9001
- Clause 7.1.5 on monitoring and measuring resources is the one that reaches the software. An auditor asks for the reading, the instrument it came from and evidence that instrument was fit to use on the day. A system that answers all three in one screen turns a difficult hour into a short one.
- Public sector bidding, Cyber Essentials and UK GDPR
- Cyber Essentials has been a condition of central government contracts handling personal data since 2014, and every G-Cloud supplier needs it. The technical controls behind it are ordinary engineering: access enforced on the server, credentials in a vault, patching that happens, and a boundary somebody can describe. We build those during the project, and your certification body does the assessment.
- Data residency under UK GDPR
- Article 32 asks for appropriate technical measures, and in practice UK buyers ask a simpler question: where does the data physically sit. We deploy into your own tenant in a UK region, Azure UK South in London or UK West in Cardiff, or AWS in London, so the answer is one sentence rather than a paragraph about safeguards.