Vulnerability assessments under Awaab’s Law: a contractor’s guide

Awaab Ishak was two years old when he died. He had a respiratory condition. His parents had reported the mould in their flat repeatedly for three years. The hazard report was treated as a routine maintenance issue, processed through the normal queue, and resolved on the normal timeline.

It is impossible to read the inquest record and not see that the catastrophic failure was not the mould itself. It was the system that received the report. Awaab’s vulnerability, his age, his respiratory condition, the duration of the family’s complaints, never entered the operational decision about how quickly to respond or how seriously to treat the case.

Awaab’s Law is named after him because the legislation is fundamentally about that failure. The regulation introduces specific timeframes for investigation and resolution, but the deeper change is structural: vulnerability data has to enter the operational decision about every reported hazard, in real time, in a way that drives prioritisation and response.

For contractors and landlords building Phase 2 readiness during 2026, vulnerability assessment is the part of the operating model that is least visible in existing maintenance contracts and most consequential when something goes wrong. This article sets out how it should work.


What the regulation actually requires

The Hazards in Social Housing (Prescribed Requirements) (England) Regulations 2025, which give Awaab’s Law its operational shape, use the threshold of “significant risk of harm” throughout. Not “hazard.” Not “defect.” Significant risk of harm to the tenant or to anyone living in the property.

That phrasing does the work of bringing vulnerability into the regulatory framework. The same defect — a failed boiler in February, a damp patch in a bathroom, a faulty fuse in the consumer unit — presents a materially different risk of harm depending on who is living in the property. An elderly resident with reduced thermoregulation faces a different cold exposure risk than a working-age adult. A child with asthma faces a different mould exposure risk than a healthy adult. A wheelchair user trapped on the second floor by a faulty lift faces a different risk than someone who can use the stairs.

The regulation does not enumerate vulnerability categories. It does not provide a checklist of “who counts as vulnerable.” Instead, it builds vulnerability into the risk threshold itself, which means that any operational system that responds identically to hazards regardless of who the household is, is by definition not aligned with the regulation’s logic.

This is the part of Awaab’s Law that procurement teams often underestimate. The timeframes are visible. The hazard categories are listed. The vulnerability framework is implicit, and it changes how every other part of the regulation should be implemented.


Who the operational definition of vulnerability covers

Although the regulation declines to enumerate, an operational vulnerability framework has to. A maintenance contractor cannot triage in real time on an undefined risk threshold. The categories below are the ones that meaningfully change the harm profile of a reported hazard and that should be captured in tenant-level data and surfaced in the contractor’s triage process.

Age-related vulnerability

  • Children under five, particularly under two
  • Adults over 65, with progressively higher risk above 75
  • Immunocompromised conditions
  • Mobility limitations, including wheelchair use, frailty, and conditions that affect evacuation in fire or emergency
  • Mental health conditions that affect a tenant’s ability to communicate, report hazards, or grant access
  • Pregnancy

Situational vulnerability

  • Households with infants on home oxygen, dialysis, or other home-medical equipment that requires electricity or heating
  • Single-parent households where loss of heating or hot water affects the entire household’s daily function
  • Properties with a known history of repeat hazard reports that have not been definitively resolved
  • Properties where the tenant has been recently bereaved, has experienced domestic abuse, or is in any other circumstance that affects their capacity to chase repairs

None of these categories should be treated as a simple binary. A property with one risk factor is meaningfully different from a property with three. The triage system should be able to surface compound vulnerability, not just flag the presence of a single factor.


Capturing vulnerability data: where it sits, where it should sit

In most social housing operations, vulnerability data exists, but it sits in the wrong places. Housing officers know which of their tenants are vulnerable. Repairs reception teams sometimes know. Health visitors and tenancy support workers definitely know. But that knowledge is fragmented across people, paper records, and disconnected systems, and it does not flow into the contractor’s intake at the moment a hazard is reported.

The operational target is straightforward to describe and structurally difficult to deliver: every reported hazard should arrive at the contractor’s triage system with the property’s vulnerability profile already attached, in a form the triage operator can see at the same moment they are deciding how quickly to dispatch.

Three things have to be in place for that to work.

1.Vulnerability data at the property level, not just the tenant level

A tenant moves out, the household composition changes, the vulnerability profile of the property shifts. A vulnerability flag attached to a person rather than to a property creates exposure every time the data does not keep up with the household. The operational record needs to live at the property level, with regular update cadence built in (typically annual review, plus triggered updates at tenancy change, household composition change, or any disclosed health event).

Landlords typically hold this data inside the housing management system. The contractor needs structured access to the relevant subset of it, refreshed in near real time, surfaced inside the job intake system.

2.Vulnerability questions at the point of report

The contractor’s intake process — phone line, online form, app, however the report arrives — should ask vulnerability questions explicitly. “Is anyone in the household elderly, very young, or living with a long-term health condition that this hazard might affect?” That question, asked at the moment the report comes in, captures the situation as it stands today, not as it was last time the housing officer updated the file.

There is a real concern about tenant fatigue and intrusive questioning, particularly for tenants who have to report the same circumstances repeatedly. The right answer is that the contractor’s system asks the questions once, stores the answers against the property, and only re-asks when something material has changed. The first report from a new tenant takes longer. The second report from the same tenant is faster. The data accrues with use.

3. Real-time visibility for the triage operator

The most well-designed vulnerability data is useless if the operator dispatching the engineer cannot see it at the point of decision. The triage screen should show, alongside the reported hazard, the property’s vulnerability profile and the recommended attendance window. A boiler failure in a household with an 80-year-old resident and an infant should not look identical to a boiler failure in a single-occupant working-age household on the dispatcher’s screen. The visual hierarchy of the system should make the difference impossible to miss.

This is where many maintenance operations fall short, not for lack of data, but because the data exists in the housing system and the triage operator works in the maintenance system, and the two do not speak.


How vulnerability changes triage in practice

Consider two scenarios, both reported on the same Saturday morning in February.

Scenario one: a tenant reports a boiler failure. The property is a two-bedroom flat occupied by a single 28-year-old working-age tenant. No flagged vulnerability. Outside temperature: 4°C. Under a vulnerability-blind system, this is an emergency: heating failure in cold weather. Under a vulnerability-aware system, this is still treated as an emergency, but the operational threshold is the standard four-hour window. The tenant is asked whether they have alternative heating available, given a clear time commitment, and the job is dispatched into the emergency queue.

Scenario two: a tenant reports the same boiler failure. The property is a three-bedroom house occupied by a 76-year-old grandmother, her adult daughter, and three children, the youngest of whom has asthma. The grandmother has reduced thermoregulation. Outside temperature: 4°C. Under a vulnerability-blind system, this is the same emergency, dispatched into the same queue with the same priority as scenario one. Under a vulnerability-aware system, this is an Awaab’s Law-grade emergency: dispatched immediately, target attendance under two hours, with alternative heating arranged as a precaution while the engineer is in route. The job is flagged for management oversight from the point of dispatch.

The difference between the two systems is not a small operational refinement. It is the difference between a contractor who is structurally Awaab’s Law ready and a contractor who is going to face an enforcement action the first time a vulnerability case is not triaged correctly.



Practical steps for landlords and contractors

For landlords reviewing their operational readiness, the questions worth asking internally are concrete:

  • Where does your vulnerability data live, and how current is it?
  • Is it accessible to the contractor’s triage system in real time, or does it live in the housing system and surface only when a housing officer manually intervenes?
  • When was the last review cycle? What proportion of the portfolio has been updated in the last 12 months?
  • How is vulnerability captured for new tenants at the point of allocation? Is it captured at all?

For contractors building or reviewing Phase 2 readiness:

  • Does the intake process ask vulnerability questions, and is the data captured against the property in a structured form?
  • Can the triage operator see vulnerability information at the point of dispatch decision, or does it surface only retrospectively?
  • Are attendance windows differentiated by vulnerability profile, or does every emergency get the same response regardless of household?
  • Is the vulnerability information audited at job closure, and does the audit trail capture the role vulnerability played in the response timeline?

These are not theoretical questions. The first enforcement actions under Phase 2 will examine precisely these operational decisions, asking whether the contractor’s system knew the household was vulnerable, whether the dispatcher acted on that knowledge, and whether the response timeline reflected the risk profile of the property rather than a generic emergency template.


How VHL Mechanical operates

VHL Mechanical maintains vulnerability data at the property level across all active social housing contracts, refreshed through landlord data feeds and through tenant-facing intake questions at the point of report. The triage system surfaces vulnerability flags alongside the hazard description at the moment the dispatcher decides where the job goes. Attendance windows are differentiated by vulnerability profile, with vulnerable-household emergencies dispatched ahead of standard emergencies and with management oversight from the point of dispatch. Every job records the vulnerability data in the audit trail at closure.

The full operating model is set out on our Social Housing page. If you are reviewing how your current maintenance arrangement handles vulnerability-aware triage and want to discuss what Phase 2 readiness looks like in practice, the team is available on 020 8102 9898 or via the contact form.


Frequently asked questions

Q. Does Awaab’s Law specify who counts as vulnerable?

A. No. The regulation uses the threshold of “significant risk of harm” rather than an enumerated list of vulnerability categories. The operational interpretation has to be built by the landlord and the contractor working together, typically covering age, health conditions, mobility, and situational factors that change the harm profile of a reported hazard.

Q. Whose responsibility is it to capture vulnerability data — the landlord’s or the contractor’s?

A. Both. Landlords typically hold the structured vulnerability data through housing management systems and tenant support records. Contractors capture in-the-moment vulnerability through intake questions when a hazard is reported. The operational target is for both data sources to flow into the contractor’s triage decision in real time.

Q. How often should vulnerability data be reviewed?

A. Annually at minimum, with triggered updates at tenancy change, household composition change, or any disclosed health event. Data captured once and never refreshed creates a false sense of coverage; the regulator will not accept stale vulnerability records as evidence of an active assessment process.

Q. Can vulnerability data be shared with the contractor under data protection rules?

A. Yes, where the data sharing is necessary for the landlord to fulfil its statutory obligation to ensure the property is fit for habitation. The landlord should have a documented data-sharing agreement with the contractor, with the relevant subset of vulnerability data made available on a need-to-know basis. The Information Commissioner’s Office has published guidance for social housing providers on lawful processing of vulnerability information.

Q. What happens if a tenant declines to disclose vulnerability information?

A. The tenant has a right to decline. The operational response is to default to the precautionary treatment, that is, to treat the property as potentially vulnerable until information indicates otherwise. The audit trail should record the decline and the default treatment, so the contractor’s response remains defensible.

Q. Should vulnerability-aware triage apply to all hazard categories or only to heating and gas?

A. All hazard categories within the Awaab’s Law scope. Electrical hazards, fire hazards, falls, hygiene hazards, and damp and mould all present materially different risks depending on who is in the household. A vulnerability-aware system applies the same triage logic across all hazard types, with the specific timeline thresholds calibrated to the hazard category.


About the author

Malika Khan is Head of Business Strategy, Commercial Systems & Technology at VHL Mechanical, where she leads the commercial systems and compliance technology programme across heating, gas safety, and mechanical maintenance contracts for social housing, local authorities, and commercial estates across London. She works directly with housing associations, ALMOs, facilities managers, and procurement teams on the operational systems that underpin Awaab’s Law readiness, CP12 compliance, and SLA-backed delivery.

Connect on LinkedIn


VHL Mechanical is a Gas Safe registered, ISO 9001 certified contractor based in Harrow, serving social housing providers and commercial clients across Greater London. We are approved to operate under multiple social housing procurement frameworks.

Areas We Cover

West London: Ealing, Hillingdon, Uxbridge, Harrow, Wembley, Brentford, Acton, Southall, Hayes, Ruislip

North London: Barnet, Enfield, Haringey, Islington, Camden, Hampstead, Finchley, Edgware, Tottenham

Central London: Westminster, Kensington, Chelsea, Mayfair, Paddington, Marylebone, Pimlico, Waterloo, Lambeth

East London: Ilford, Stratford, Hackney, Tower Hamlets, Romford, Barking, Walthamstow

South London: Croydon, Bromley, Lewisham, Greenwich, Wandsworth, Merton

VHL Mechanical
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.