Three changes in the last three years moved building compliance from an operational task to a governance one. None of them are reversible.
An officer's due diligence duty already includes verifying that safety processes are provided and used. The 2026 amendment rewrites that duty into an exhaustive three step definition ending in exactly that verification step, commencing 1 April 2027.
Verification is an evidence obligation. It is not satisfied by a policy. And under HSWA s29, insurance against a fine is unlawful, so the exposure lands on the balance sheet directly.
The Building Act carries a specific offence for certifying that inspection, maintenance and reporting procedures were complied with when they were not. Maximum fine of NZD 50,000 for an individual and NZD 150,000 for a body corporate.
For failure to comply with a notice to fix, the maximum is NZD 200,000, plus NZD 20,000 for every day it continues.
NSW fire safety amendments make AS 1851-2012 routine servicing mandatory, restrict signing to accredited practitioners, set a seven year minimum record retention period, and require that testing logs, defects and rectifications be digitally tracked and accessible.
A regulator has written the requirement for a system of record into law.
Most compliance failures are not failures of intent. They are failures of continuity. Data survives one stage and dies at the next. GoldnThread is built around the four transitions where that happens.
Practical completion is where most building information dies. Models, warranties and asset registers arrive as a hard drive full of PDFs, and the operations team starts again from nothing.
GoldnThread ingests IFC and JSON directly from the model, maps assets to real locations, and shows a completeness meter against what the compliance schedule will require. What was handed over is what you operate.
A flat asset register tells you a chiller exists. It does not tell you which plant room, which riser feeds it, or who last touched it.
GoldnThread holds assets spatially, using LiDAR capture from an iPhone, so the record has context. Service history, warranty position and contractor attendance all attach to a thing in a place.
A Building Warrant of Fitness falls due on the anniversary of the compliance schedule issue date, not at year end. Each building needs a Form 12A from every IQP covering every specified system before the Form 12 can be issued.
GoldnThread tracks each system against its own procedure and its own date, and gives your IQPs a portal to file directly. Australia adds four more artefacts on four more clocks. One view holds them all.
Every action carries a timestamp, an attributed person and an unalterable entry in the record. When someone asks what was inspected, when, by whom and what was found, that is a query, not an archaeology project.
This is what a due diligence data room needs, what an insurer asks for after an event, and what an officer relies on to show they verified rather than assumed.
Not a folder. Not a shared drive. Not a spreadsheet somebody renamed FINAL_v3. A queryable, timestamped, attributed record of every inspection, defect, rectification and signature, held for the life of the building.
| When | Who | Action | Evidence |
|---|---|---|---|
| 14 Aug 2026 · 10:42 | M. Tuiloma · IQP | Monthly inspection completed · IQP procedure 4.2 · no defects | 3 photos · signed |
| 14 Aug 2026 · 10:44 | M. Tuiloma · IQP | Form 12A certified for period Sep 2025 to Aug 2026 | Cert #12A-4471-26 |
| 03 Jul 2026 · 14:08 | R. Fenton · Argus Fire | Defect rectified · replaced pressure switch, retest passed | Test log · invoice |
| 28 Jun 2026 · 09:15 | System | Defect raised from IoT threshold · low pressure zone 3 | Sensor trace |
| 12 Jun 2026 · 11:30 | M. Tuiloma · IQP | Monthly inspection completed · IQP procedure 4.2 | 2 photos · signed |
Global platforms treat compliance as a configurable checklist. Australia and New Zealand do not work that way. The artefact has a different name in every jurisdiction, a different signatory, a different deadline and a different recipient.
| Jurisdiction | Annual artefact | Who signs | When | Lodged with |
|---|---|---|---|---|
| New Zealand | Building Warrant of Fitness Form 12 + Form 12A per system | Owner, on IQP certification for each specified system | Anniversary of the compliance schedule issue date | Territorial authority |
| NSW | Annual Fire Safety Statement AFSS | Owner, with accredited practitioner endorsement per measure | Annually · assessment within the prior 3 months | Council and NSW Fire Brigades |
| Victoria | Annual Essential Safety Measures Report AESMR | Owner or authorised agent | Annually | Held by owner · produced on request within 24 hours |
| Queensland | Occupier's Statement | The occupier, not the owner | Copy to the Commissioner within 10 business days | Queensland Fire Department |
| South Australia | Form 3 ESP maintenance certificate | Owner and the person who performed the maintenance | Within 60 business days of calendar year end | Council |
Western Australia, the Northern Territory and the ACT have no equivalent annual regime, so a national portfolio does not have a single compliance calendar. GoldnThread gives it one dashboard anyway.
You carry the liability and the asset value. You need portfolio level evidence you can put in front of a board, and a compliance position that survives due diligence.
You carry the operational reality. You need every asset, every service history and every contractor in one place, and a handover that does not lose half the building.
You carry the handover. A building delivered with its digital record intact settles faster, closes out the defects period cleaner and holds its value at sale.
You carry both sides: a public portfolio with its own compliance obligations, and the register that everyone else's certificates land in.
And if you are the IQP or accredited practitioner who signs, there is a portal built for you. For certifiers →
Your compliance record is evidence. It is treated that way.
Hosted in AWS Sydney · ap-southeast-2. Replication disclosed in full in our security documentation.
TLS 1.2 in transit. AES 256 at rest. Every access event logged, timestamped and attributed.
Single sign on, SAML, SCIM provisioning, role based access control and IP allowlisting.
Handled under the NZ Privacy Act 2020, including IPP 12, and the Australian Privacy Principles, including APP 8.
Book thirty minutes. Bring one real building, with its real compliance schedule and its real mess. We will show you what it looks like held properly.