The problem
In many organisations, contractor compliance is managed as a folder. Insurance certificates, method statements, training records and equipment inspection reports are requested, uploaded and stored, often in a shared drive or an email thread. When the folder looks full, the contractor is considered compliant.
A full folder answers the wrong question. It shows that documents were received. It does not show whether they are the right documents, whether anyone checked them, whether they are still valid or whether they cover the people and equipment actually coming to site.
Why it matters
Contractor work often involves higher-risk activities, unfamiliar people and equipment brought onto site from elsewhere. The organisation relies on its compliance process to know that the contractor, its people and its equipment meet the requirements for the work.
When compliance is a folder:
Missing requirements are hard to see, because nobody defined what should be there.
Expired documents remain in the folder and still look like evidence.
A company-level document is taken as proof for individuals it does not cover.
Equipment and vehicle certification is separated from the job it relates to.
Nobody can easily explain why a contractor was, or was not, considered ready.
A practical approach
A more reliable approach starts from requirements rather than documents.
Define requirements first. For each type of contractor, service or engagement, decide what is required: insurance, qualifications, competency records, equipment certification, site-specific documents. A requirement is a statement of what must be true, not just a file name.
Attach evidence to each requirement. Documents become evidence for a specific requirement, at contractor, person or equipment level.
Verify, don't just collect. Someone competent should check each piece of evidence and record the result. An unverified upload is a claim, not proof.
Track expiry. Insurance, certificates and inspections expire. Each requirement should carry its validity period, so expired evidence is visible as a gap.
Cover people and equipment, not only companies. Personnel competency, equipment and vehicles each have their own requirements and expiry dates.
Make readiness explainable. When a contractor is not ready to mobilise, the reasons should be listed clearly, not hidden in a percentage. "82% complete" does not say which missing item matters.
What a good system should provide
A good contractor compliance system should:
Hold requirement definitions and track an instance of each requirement per contractor, person or equipment item.
Record evidence, verification status and expiry for each requirement.
Manage personnel and their competencies alongside the contractor record.
Include equipment and vehicle records with their own certification.
Show mobilisation readiness with the specific blockers that apply.
Keep calculated readiness separate from the human decision to mobilise, as explained in Ready to Mobilise Is Not the Same as Authorised to Enter.
Work in the field, including when connectivity is limited.
How Contractor Management addresses it
Contractor Management is a module of the Sospita HSE Platform. It is currently coming soon.
The module is built around requirement definitions and requirement instances. Each instance holds its evidence, verification status and expiry, so gaps and expired evidence are visible rather than hidden in a folder. Compliance and insurance records carry their own expiry dates.
People and personnel are managed with their competencies, alongside a workforce plan showing planned versus assigned people. Equipment and vehicles have their own records. Mobilisation readiness is shown as Ready, Conditionally Ready or Not Ready, with the blockers listed, so it is clear what stands between a contractor and mobilisation.
The module is designed for multi-site organisations, with records shared across the platform, and its mobile app supports offline work with synchronisation and conflict handling.
Limitations and human responsibility
Defining requirements well is the organisation's responsibility. A system can track requirements, but if the requirements themselves are incomplete or wrong, readiness will be calculated against the wrong standard.
Verification still depends on people. The system records that evidence was verified and by whom; it cannot judge whether a certificate is genuine or a competency is sufficient for a specific task.
Contractor Management does not control physical access. It does not connect to turnstiles, gates or badge readers. Site access arrangements remain a separate process.
Finally, compliance is not the same as safe performance on site. A contractor that meets every documented requirement still needs supervision, coordination with other work and a clear understanding of site rules.