A design coordinator is told, in a tender return for a higher-risk building, that the golden thread must be delivered to ISO 19650. She asks where that is written down. Her BIM lead points to the Construction Playbook. Her QS points to a client information requirement document. Nobody points to the Building Safety Act 2022, because it is not there.
The direct answer: the Act and the regulations made under it require a golden thread of building information, and they set out in detail what that information has to do. They do not name BIM, ISO 19650, COBie, IFC, or any other standard, schema or piece of software. Not once, anywhere, and this is checkable directly by searching the legislation itself rather than taking it on trust. It stays true whether the building is still on site or has been occupied for five years.
What the law actually says, in full
The design and construction phase golden thread duty sits in regulation 31 of the Building (Higher-Risk Buildings Procedures) (England) Regulations 2023, SI 2023/909. It requires the client to ensure the golden thread information is kept in an electronic format, is capable of being transferred electronically to other people without being lost or corrupted, is accurate and up to date, is available in a readable format that its intended readers can actually use, is made available as soon as reasonably practicable when a principal designer or principal contractor needs it, is secure from unauthorised access, is only changed through procedures that record who changed it and when, and as far as reasonably practicable uses consistent language and terminology. That is the complete list. Eight standards, all of them about what the information does, none of them about what software produced it.
Once a building is occupied, the equivalent duty moves to regulation 7 of the Higher-Risk Buildings (Management of Safety Risks etc) (England) Regulations 2023, SI 2023/907, made under section 88 of the Act. It repeats the same shape: electronic format, transferable without corruption, accurate, intelligible, accessible on request, secure, and changed only through an auditable procedure. What must actually be kept, item by item, is listed separately in Schedule 1 to the Higher-Risk Buildings (Keeping and Provision of Information etc.) (England) Regulations 2024, SI 2024/41. None of the three instruments names a technical standard. The closest either comes to a format requirement is that information must be electronic and must survive being sent to someone else without corruption.
This can be checked directly rather than taken on trust. A full text search of legislation.gov.uk for “19650” returns exactly one result across the whole of UK law, an EU cosmetics ingredient glossary with a coincidental case number. A search for “building information model” returns three results, none of them about building safety. Search for “golden thread” itself and SI 2023/909 and SI 2024/41, the two instruments quoted above, are what comes back, alongside the Welsh equivalents and, unhelpfully, the Silver and Gold Thread Act 1697. ISO 19650 does not appear in UK building safety law because it has never been put there.
Two different definitions of “higher-risk building”, and why it matters here
A separate trap sits underneath this one and is worth flagging while we are being precise. Section 65 of the Building Safety Act 2022 defines a higher-risk building at least 18 metres or 7 storeys with at least two residential units, but that definition is scoped, in its own words, to Part 4 of the Act, which is the occupation regime. The design and construction definition lives instead in section 120D of the Building Act 1984, supplemented by the descriptions in SI 2023/275. That instrument brings care homes and hospitals into scope for design and construction that are not in scope once the building is occupied. None of this changes the answer on standards, but it is the kind of distinction that separates a guide someone can actually rely on from one that will be wrong on the next project it is applied to.
Where the confusion is actually coming from
Nobody is inventing this out of nothing. Three real things are being blurred into one, and pulling them apart explains almost every conversation like the one the design coordinator had in her tender meeting.
The first is a genuine government mandate, just not this one. In September 2021 the Infrastructure and Projects Authority published Transforming Infrastructure Performance: Roadmap to 2030, which does require clients of major infrastructure projects to implement the UK BIM Framework and expressly names BS EN ISO 19650-1 and 19650-5. That is a real, binding requirement, and BSI has written about it in exactly those terms. It applies to government infrastructure procurement. It has no connection to the Building Safety Act or to residential higher-risk buildings.
The second is the Construction Playbook, the government’s procurement policy, which the Building Safety Regulator’s own consultation response leans on. NBS quotes the relevant paragraph precisely: the government “strongly encourages the use of Building Information Management (BIM) standards through the Construction Playbook”. Strongly encourages is doing real work in that sentence. It is procurement policy, not a building regulation, and NBS’s own conclusion, in the same piece, is that the government “has not mandated the use of BIM Standards”.
The third is how the first two get repeated in trade coverage. A respected industry title, reporting on the newest part of the ISO 19650 suite in January 2025, described it as a standard that will help manage the golden thread “that is now required by the Building Safety Act”. Read quickly, the sentence says the standard is required by the Act. Read carefully, the clause that is required by the Act is the golden thread, and the standard is one way of managing it. That single sentence, repeated in slightly different forms across enough articles, is a plausible account of how an entire industry ends up believing something the statute does not say.
The strongest evidence that this is a real misconception, not a fringe one
The clearest confirmation does not come from a law firm or a regulator. It comes from the industry’s own guidance writers, who felt the need to say so explicitly. The Construction Leadership Council’s 85 page guide for dutyholders and accountable persons, Delivering the Golden Thread, mentions ISO 19650, BIM, COBie and IFC exactly zero times across the whole document, while citing several other standards by name where they are actually relevant. Its own list of what the golden thread is not includes, verbatim, “a particular format” and “simply a product or software solution”. A guidance document does not warn against a belief that nobody holds. It states directly that “no particular format or software is prescribed for the golden thread, however the information should be managed and stored effectively”, and that existing systems, including information held across more than one source or file management platform, “may be able to be used to meet the golden thread requirements”.
The government’s own earlier factsheet said much the same thing in plainer language, that the golden thread will have to be kept digitally and that “we will not be mandating the use of specific software or tools”. That factsheet was withdrawn in July 2022 and should not be cited as current guidance, but it is directionally consistent with everything that followed it into law.
What this means for the system you actually build
None of this is an argument against ISO 19650. The standard is a well-tested, defensible way of discharging a duty that Parliament deliberately wrote to be discharged in more than one way, and a client is entirely free to specify it in a contract, an information requirement, or a tender. What it is not is a legal floor. Confusing the two has a real cost in the other direction as well: a small contractor who is told, wrongly, that the golden thread means buying a BIM authoring seat and running a full common data environment may conclude the whole regime is unaffordable and disengage from a duty that a well-organised spreadsheet, a version-controlled document store and a clear access log could satisfy.
What the regulations actually test is behaviour, not software. Can the information be handed to another person electronically without corruption. Is it accurate and current. Can the person who needs it read it without a key nobody gave them. Can it be produced when asked, without a scramble. Is it locked down from people who should not see it. Does every change carry a name and a date. A system built to pass those six or eight tests, in whatever software actually does that reliably for the size of business running it, is a compliant system under the Act. A system that cannot answer them is not rescued by being built on the correct standard.
Where to check this yourself
Every claim above traces to a source below, and the following places are worth going to directly rather than taking any summary, including this one, on trust.
- “What must I keep in a golden thread under the Building Safety Act?” The Building Safety Regulator’s own guidance sets out the duty in plain terms, free to read, at gov.uk.
- “What does the Building Safety Act mean for architects?” RIBA has published its own initial guide for members, covering the gateway process and the principal designer role, at architecture.com.
- “What does the Building Safety Act mean for contractors and project managers?” CIOB maintains a dedicated advice and guidance hub, including its own FAQ answers for members, at ciob.org.
- “Does the Building Safety Act apply to my project?” RICS answers this and related scoping questions directly in its own FAQ at rics.org.
The underlying standard referenced throughout this guide, BS EN ISO 19650, is published and sold by BSI rather than by government, and is not itself a legal document. Its scope can be checked without purchase at BSI’s own product page.
