Are we safer? Rethinking compliance in a data-rich world
18th August 2026
Jenny Danson
Nearly ten years on from Grenfell, the sector has more regulation, data, technology and reporting than ever. So why are we still asking questions about safety?
Ryan Dempsey, a former Head of Compliance at Leeds City Council who now runs the compliance and asset-data company TCW, opened his breakout at this year's Summer Ideas Exchange by asking the question:
“How many people think our residents are safer today than they were 10 years ago?”
His own answer was blunt: more activity, dashboards and reporting have not, on their own, made homes safer. What followed was a hard-hitting look at the gap between looking compliant and being safe...and at the people, not the platforms, who close it.
The great illusion: activity is not safety
Inspections, reports, dashboards, audits and meetings all create a sense of motion. Ryan’s challenge: which of them prevents someone dying in a fire? Activity can demonstrate assurance, but assurance is not safety. He made it concrete with a live screen from TCW’s “inbox” dashboard: 238 actions in total, 143 open - every one more than 30 days overdue, nothing closed in the previous 30 days, 105 sitting at amber. A tidy, well-populated dashboard that was really a picture of risk logged but not acted on.
“Real world”: the night the data was already there
To show why interpretation matters, Ryan told a story from his own time in housing. A 3am call from West Yorkshire Fire Service sent him to one of his estates (he called it Sussex Green); he arrived to fire engines, ambulances and a fire officer telling him there had been four fatalities. Back in the office, his team pulled the property file and found an EICR completed just six weeks before the fire and marked UNSATISFACTORY. Its observations included:
five C2 (potentially dangerous) items, all flagging missing 30mA RCD protection; and
a C3 item noting high resistance on the neutral conductor on ring continuity - a loose termination or broken conductor - with the note “Property requires rewire.”
The RCD findings had been fed into next year’s capital programme, and the team believed they’d done their job. But the circuit test schedule told a different story. When the fire service confirmed the fire started in the kitchen behind the washing machine, the loose-neutral warning became clear.
“We had the information to prevent four people dying in a house fire. That’s the importance of data - if you’re willing to go into it.”
- Ryan Dempsey
Confidence is not competence
Ryan walked through his “Confidence Gap” model - the Dunning–Kruger effect applied to safety, mapping six stages from novice to true expert. The dangerous point is not the novice (who knows they don’t know) but the next stage along: people who’ve done a course, read the guidance and suddenly feel qualified to make decisions outside their competence. Further up the curve, the genuinely experienced grow comfortable saying “I don’t know, let’s ask someone who does.”
His warning: confidence is not evidence of competence, and in safety-critical environments confusing the two can be catastrophic.
Post-Grenfell, the sector rightly put fire-safety specialists in charge of compliance. But compliance spans dozens of disciplines e.g. gas, electrical, fire, asbestos, lifts, the ISO and British Standards, and, notably for this audience, energy performance, net-zero obligations, Awaab’s Law and the Housing Health and Safety Rating System. Being excellent at fire safety does not make someone competent across all of it.
He paired this with normalisation of deviance - small things done slightly wrong until they become the norm - and a blunt line: opinions don’t save lives, facts do; which report would you want to defend in court?
The “digital Dunning–Kruger” effect
Ryan runs a software company and called AI “amazing” - his warning was about how we use it. AI answers confidently whether or not it’s right, which makes over-trust dangerous; the same goes for off-the-shelf “rule-based” platforms, where a confident-but-not-competent person sets rules that simply stamp the wrong decision.
As one slide put it: the next Grenfell-type disaster won’t happen because someone lacked a dashboard - it will happen because someone believed they understood what a dashboard was telling them.
Five core principles
From Ryan’s free framework document, “The Workbook by TCW” (he stressed the session was not a sales pitch):
If we already hold the information to prevent an incident, failing to act on it is not just a compliance failure - it’s a moral one.
Compliance is no longer a technical box to tick; it’s a leadership discipline.
Centralised systems and analytics let organisations shift from reactive to predictive - from technical to strategic compliance.
AI won’t replace competent decision-makers; it will expose organisations relying on decisions unsupported by evidence.
Risk can only be accepted by someone who truly understands it.
Why this matters for healthy homes
Reading the data we already hold and acting on it, protects residents’ health, not just their lives in a fire. Ryan’s own “compliance universe” placed energy performance, net-zero, Awaab’s Law and the HHSRS alongside gas and electrical safety, a reminder that damp, mould, ventilation and cold are competence questions too.
Two examples bridged the two directly: “labels” generated from drone imagery flagging an air-pollution risk for homes beside a busy road; and using combustion analysis to band boilers by real efficiency rather than replacing on a blanket 15-year rule, directing money at the infrastructure genuinely failing residents on comfort, bills and health.
Questions & discussion
On getting data to the right people, Ryan agreed the problem is rarely the data but where it sits: push it at people who can’t interpret it and it gets deferred and forgotten. On education, he was clear, you won’t become compliant without competent interpreters. (Pointing to the ASCP’s Level 2–4 qualifications as a baseline -accreditation is required to do much of the work, but not to manage it).
On a single source of truth, he described work on a unified knowledge layer between the organisation and AI models, while warning the sector is nowhere near ready: around 9% of properties in TCW’s system still have no RCD protection (required since 1993). On culture, his sharpest example, a bid to rewire properties lost out to repainting tower blocks so spending looked impressive to a local MP.
Others raised data ownership (the business should define the decisions and own the data, not leave it to the tech team) and the human reality of residents... rightly the focus, but sometimes a barrier through refused access or a wish for new kit over repairs. Amalgamating works is held back as much by contractor culture and lowest-cost, tick-box contractsas by technology.
Three questions for housing providers to reflect on
Do the people interpreting your compliance data truly understand it and where would they honestly sit on the confidence-versus-competence curve?
If a certificate flagged a subtle warning today - like a high-resistance neutral - are you confident it would trigger action, not just be filed for next year?
Looking at your dashboard honestly: how much is risk actioned versus risk simply logged and sitting amber and overdue?
Key takeaways
Safety is about interpretation, not the volume of data. The information to prevent a tragedy is often already in the file - the gap is the competence and culture to act on it.
Confidence is not evidence of competence. The next disaster is more likely to come from believing a dashboard than from lacking one.
The same data that proves compliance can protect health and target retrofit. Read combustion, voltage, ventilation and pollution signals - not just pass/fail dates.
Unlock all content
This is the 1 of 3 articles you can access for free. Become a member to unlock unlimited access to our full content library.