Two landlords own similar homes in similar condition. One is graded C1. The other is graded C3. The difference is not the brick and mortar. It is whether each can describe, with evidence, the state of every home it holds.
That distinction used to be invisible. Before April 2024, a provider with weak data had an internal efficiency problem it could manage in its own time. Since the Regulator of Social Housing began programmed inspections under the Social Housing (Regulation) Act 2023, the same weak data produces a published grade, a regulatory engagement plan, and a board-level assurance failure. Data quality runs through the published judgements as one of the most frequently cited weaknesses, in the Regulator's own language.
This is a change in kind, not degree. And it lands on the board, not the IT team.
The grade measures what you can prove, not what you own
When the Regulator grades a landlord C1, it is not certifying the housing stock. It is certifying that the organisation can describe its stock accurately and produce the evidence on demand. The published 2026 judgements make the point plainly: providers awarded the top grade are consistently those with an accurate record of the condition of tenants' homes and a clear plan for the surveys still outstanding. Providers downgraded to C3 are those relying on stock surveys carried out a decade ago, unable to give assurance on the accuracy of their own compliance data.
The homes in both cases may be comparable. The records are not. Assurance is a data capability before it is anything else, and no amount of operational commitment substitutes for it at the point an inspector asks how a figure was derived.
Every new obligation is a new data obligation
The regulatory calendar between 2024 and 2027 reads, on inspection, as a sequence of data requirements wearing different names.
Awaab's Law, in force since October 2025, converts repairs from a service standard into a statutory clock that starts at a recorded moment of landlord awareness. The reformed Decent Homes Standard, confirmed in January 2026, replaces age-based decency with a condition-based test across five criteria, which means a provider can no longer compute decency from installation dates in a spreadsheet. From October 2026, a standalone Competence and Conduct Standard requires an auditable record of who holds which qualification, and the Social Tenant Access to Information Requirements begin with a duty to publish information the organisation already holds. The second half follows in April 2027, when private registered providers must find and release information on a resident's request, within thirty days.
The scale of the condition-based shift alone is easy to underestimate. A provider with 12,000 homes on a five-year survey cycle needs to complete 2,400 surveys a year, each captured as structured attribute data against five decency criteria rather than filed as a PDF on a network drive. Enforcement of the reformed standard begins in 2035, which sounds distant until the survey volume is set against the years available.
Each of these obligations rests on the organisation knowing something reliably, in advance, and being able to produce it later. None is achievable through effort alone at the point of demand. A landlord that does not already hold the data cannot assemble it once the request, the inspection, or the incident has arrived.
The cheapest climb removes the most risk
The relationship between data maturity and regulatory exposure is not linear, and boards setting ambition should understand its shape.
The move from an unmanaged state, where risk is present but unmeasured and invisible to the board, to a basic managed state removes a disproportionate share of exposure for a modest investment. It does so by converting unknown risk into known and managed risk, which is the whole of what an inspector, an ombudsman, or a court is testing. The later climb, from good to excellent, generates real operational and financial value but removes comparatively little further regulatory risk.
The practical consequence for a board under pressure is clear. The first target is not a sophisticated analytics capability. It is a defined owner for data quality, a reconciled asset register, a certificate register that alerts before expiry, and management information that traces back to a source. Reach that quickly. Weigh anything beyond it on value, not on fear.
Where this belongs
The uncomfortable conclusion is that seven of the eight obligations set out in our own Data Maturity Model, from the consumer standards through to the Building Safety Act, depend on the same underlying thing: accurate, structured data about homes, tenants, and the organisation's own activity, produced on demand with an explanation of how it was derived. The count is ours rather than the sector's, and the eight are listed in the Model with the data each one requires.
That is not a technology procurement question, and no product named in a vendor brochure moves an organisation up the scale on its own. It is a question of accountability and definition, and it sits with the board and the audit committee. The organisations that understand this early will spend the next regulatory cycle demonstrating control. The ones that do not will spend it explaining why they cannot.
The first move is the least glamorous and the most valuable: find out, honestly, where you actually stand.
Regulatory dates cited here are drawn from published GOV.UK guidance current at 16 August 2026. This article describes the public position and is not legal advice.