How to Set Up an ITM Compliance Program: A Fire Marshal’s Guide

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

Most fire marshals imagine one of two extremes: a fully manual process that drains staff time or a fully automated system that overwhelms the team with data before they’re ready. It doesn’t have to be either.

Here’s what happens when a department launches an inspection, testing, and maintenance (ITM) compliance program with First Due ITM — from the first submittal to the first measurable win.

The ITM Submission and Review Process, Step by Step

An ITM program has two sides working at the same time: the AHJ side and the service provider side.

On the service provider side, a contractor submits a report through First Due ITM's business portal. They can upload the report attachment first, and the system pulls out the key fields — address, contact info, deficiency type, severity — automatically. That cuts down on manual entry and reduces the chance of a typo turning into a rejected report.

On the AHJ side, that submittal lands as an intake item for review. This is where quality control happens: confirming the address matches, the jurisdiction is right, the systems reported are the systems that are actually in the building, and the severity classification holds up. From there, the report gets accepted or rejected.

If something's off, it goes back to the submitter with a note. That might feel like it slows things down at first, but it does real work: it teaches your service providers what "correct" looks like, so the reports coming in six months from now need a lot less correcting.

Start Small, On Purpose

The instinct with a new compliance program is to flip it on for everyone at once. Don't. The departments that get the most out of ITM start with a partial rollout, not full enforcement on day one.

The playbook that works:

  1. Start with your best contractors. The ones you already have a relationship with, doing the systems you most want enforced first.
  1. Give your team room to learn the workflow before the volume ramps up.
  1. Add systems and requirements gradually — hood cleaning, fire extinguishers, emergency lighting — as your team gets comfortable.

This isn't just about pacing your workload. It's about avoiding the failure mode where deficiencies pile up because nobody's confident in the data anymore, and staff quietly stop chasing them. A controlled ramp-up builds the habit and the trust in the system at the same time.

What a first win looks like: your first five contractors onboarded, and your first five reports accepted. That's it. Small, concrete, and it's usually reachable inside the first couple of weeks.

How to Configure ITM Notifications and Alerts

An ITM program generates a lot of information. The goal of notification setup isn't to see everything — it's to see the right things, at the right urgency, without burying your team in alerts they'll start tuning out.

A few principles that hold up across departments:

  • Match the audience to the severity. Low-level, non-critical deficiencies (a missing wrench in a sprinkler box, a gauge reading slightly off) should route narrowly — to a specific inspector or region, not a department-wide blast.
  • Widen the net as severity increases. Critical deficiencies typically warrant an email and a scheduled follow-up. Impairments — where the system genuinely won't work — should reach the AHJ immediately, often via text or phone, and can trigger an automatic inspection.
  • Set reminders on both sides of the compliance date. Standard cadences run 30/60/90 days before a test is due, and 30/60/90 days after, if it's missed.

The failure mode to avoid: a text alert for a non-critical deficiency, or — worse — no meaningful notification when an impairment comes in. Get the tiers right once, and the system does the filtering for you going forward.

Service Provider Onboarding: Letters, Portals, and Materials

The last piece of getting a program running is making sure the people submitting reports have what they need to do it right in First Due ITM — and this is meant to be a light lift on your end.

That typically includes:

  • A landing page for service providers, with access to a knowledge base and AHJ-specific information.
  • Contact info, logo, and a message from your department, so submitters know exactly who they're working with.
  • A pre-built notification letter, sent on your behalf, explaining what's changing and what's expected — whether you're standing up a new program or transitioning from an existing one.

None of this requires building materials from scratch. The heavy lift of drafting letters and setting up the provider-facing profile is handled during implementation — you're reviewing and approving, not authoring.

Where This Leaves You

None of the above depends on your department's size, your current tooling, or how sophisticated your review process is today. With First Due ITM, it's the foundation: a documented process, a ramp-up plan, notifications tuned to actual risk, and provider-facing materials that set expectations from day one.

Once that foundation is in place, the next question is what happens after reports start coming in — how review actually gets triaged day to day, and what your data starts telling you after month one. That's where we're headed next.

Most fire marshals imagine one of two extremes: a fully manual process that drains staff time or a fully automated system that overwhelms the team with data before they’re ready. It doesn’t have to be either.

Here’s what happens when a department launches an inspection, testing, and maintenance (ITM) compliance program with First Due ITM — from the first submittal to the first measurable win.

The ITM Submission and Review Process, Step by Step

An ITM program has two sides working at the same time: the AHJ side and the service provider side.

On the service provider side, a contractor submits a report through First Due ITM's business portal. They can upload the report attachment first, and the system pulls out the key fields — address, contact info, deficiency type, severity — automatically. That cuts down on manual entry and reduces the chance of a typo turning into a rejected report.

On the AHJ side, that submittal lands as an intake item for review. This is where quality control happens: confirming the address matches, the jurisdiction is right, the systems reported are the systems that are actually in the building, and the severity classification holds up. From there, the report gets accepted or rejected.

If something's off, it goes back to the submitter with a note. That might feel like it slows things down at first, but it does real work: it teaches your service providers what "correct" looks like, so the reports coming in six months from now need a lot less correcting.

Start Small, On Purpose

The instinct with a new compliance program is to flip it on for everyone at once. Don't. The departments that get the most out of ITM start with a partial rollout, not full enforcement on day one.

The playbook that works:

  1. Start with your best contractors. The ones you already have a relationship with, doing the systems you most want enforced first.
  1. Give your team room to learn the workflow before the volume ramps up.
  1. Add systems and requirements gradually — hood cleaning, fire extinguishers, emergency lighting — as your team gets comfortable.

This isn't just about pacing your workload. It's about avoiding the failure mode where deficiencies pile up because nobody's confident in the data anymore, and staff quietly stop chasing them. A controlled ramp-up builds the habit and the trust in the system at the same time.

What a first win looks like: your first five contractors onboarded, and your first five reports accepted. That's it. Small, concrete, and it's usually reachable inside the first couple of weeks.

How to Configure ITM Notifications and Alerts

An ITM program generates a lot of information. The goal of notification setup isn't to see everything — it's to see the right things, at the right urgency, without burying your team in alerts they'll start tuning out.

A few principles that hold up across departments:

  • Match the audience to the severity. Low-level, non-critical deficiencies (a missing wrench in a sprinkler box, a gauge reading slightly off) should route narrowly — to a specific inspector or region, not a department-wide blast.
  • Widen the net as severity increases. Critical deficiencies typically warrant an email and a scheduled follow-up. Impairments — where the system genuinely won't work — should reach the AHJ immediately, often via text or phone, and can trigger an automatic inspection.
  • Set reminders on both sides of the compliance date. Standard cadences run 30/60/90 days before a test is due, and 30/60/90 days after, if it's missed.

The failure mode to avoid: a text alert for a non-critical deficiency, or — worse — no meaningful notification when an impairment comes in. Get the tiers right once, and the system does the filtering for you going forward.

Service Provider Onboarding: Letters, Portals, and Materials

The last piece of getting a program running is making sure the people submitting reports have what they need to do it right in First Due ITM — and this is meant to be a light lift on your end.

That typically includes:

  • A landing page for service providers, with access to a knowledge base and AHJ-specific information.
  • Contact info, logo, and a message from your department, so submitters know exactly who they're working with.
  • A pre-built notification letter, sent on your behalf, explaining what's changing and what's expected — whether you're standing up a new program or transitioning from an existing one.

None of this requires building materials from scratch. The heavy lift of drafting letters and setting up the provider-facing profile is handled during implementation — you're reviewing and approving, not authoring.

Where This Leaves You

None of the above depends on your department's size, your current tooling, or how sophisticated your review process is today. With First Due ITM, it's the foundation: a documented process, a ramp-up plan, notifications tuned to actual risk, and provider-facing materials that set expectations from day one.

Once that foundation is in place, the next question is what happens after reports start coming in — how review actually gets triaged day to day, and what your data starts telling you after month one. That's where we're headed next.

See how First Due ITM would fit your department's process.
learn moreschedule a demoSchedule a Demo