How Auditors Assess Contractor Compliance

Whether you’re managing contractors on a construction site, engaging specialist trades, or outsourcing services, contractor compliance is a critical part of running a safe and legally compliant business in Australia. Regulators, clients, and insurers increasingly expect businesses to demonstrate that contractors meet the same standards as employees when it comes to safety, qualifications, and legal obligations.

Auditors play a key role in verifying that these standards are being met. Rather than simply checking paperwork, they assess whether your contractor management processes are effective, consistent, and aligned with Australian legislation and industry best practice.

What Is Contractor Compliance?

Contractor compliance refers to the process of ensuring that contractors meet all legal, regulatory, contractual, and organisational requirements before and throughout their engagement.

Depending on your industry, this may include:

  • Valid licences and certifications
  • Appropriate insurance coverage
  • Work health and safety (WHS) compliance
  • Induction and training records
  • Right-to-work documentation
  • Risk assessments and Safe Work Method Statements (SWMS)
  • Ongoing competency and qualification verification

Effective contractor compliance helps reduce workplace incidents, legal exposure, project delays, and reputational risk.

Why Auditors Review Contractor Compliance

Auditors assess contractor compliance to determine whether an organisation has adequate systems in place to manage contractor risks. This may form part of:

  • Internal compliance audits
  • WHS management system audits
  • ISO certification audits
  • Client prequalification assessments
  • Regulatory inspections
  • Due diligence reviews

Their objective is to identify gaps before they result in safety incidents, legal breaches, or financial consequences.

Key Areas Auditors Assess

  1. Contractor Prequalification

One of the first areas auditors examine is how contractors are approved before they begin work.

They typically review whether your organisation verifies:

  • Business registration details
  • Relevant licences and trade qualifications
  • Public liability and workers’ compensation insurance
  • Professional certifications
  • Previous safety performance
  • Financial stability where applicable

A documented prequalification process demonstrates that contractor selection is based on objective criteria rather than convenience.

  1. Documentation and Record Keeping

Accurate and up-to-date records are essential during any audit.

Auditors often request evidence of:

  • Contractor agreements
  • Insurance certificates
  • Licence expiry dates
  • Induction records
  • Training certificates
  • SWMS
  • Risk assessments
  • Incident reports
  • Compliance checklists

Missing, expired, or inconsistent documentation is one of the most common audit findings.

  1. Work Health and Safety Compliance

Under Australia’s WHS legislation, businesses have a duty to ensure contractors can perform their work safely.

Auditors assess whether contractors:

  • Complete site inductions
  • Understand workplace hazards
  • Follow safety procedures
  • Wear appropriate personal protective equipment (PPE)
  • Participate in toolbox talks where required
  • Report hazards and incidents

They may also interview supervisors and contractors to verify that documented procedures are followed in practice.

  1. Licence and Competency Verification

Many industries require workers to maintain specific licences or competencies.

Auditors check whether your organisation has systems to:

  • Verify qualifications before work begins
  • Monitor expiry dates
  • Reassess competencies where required
  • Prevent unqualified contractors from accessing worksites

Automated reminders and digital compliance systems can significantly improve ongoing licence management.

  1. Contractor Inductions

A contractor induction is more than a sign-in sheet.

Auditors evaluate whether inductions cover:

  • Site-specific hazards
  • Emergency procedures
  • Incident reporting
  • Environmental requirements
  • Security procedures
  • Company policies
  • WHS responsibilities

They also check that contractors understand the information provided and that records are retained.

  1. Ongoing Monitoring

Compliance isn’t a one-time exercise.

Auditors look for evidence that organisations continuously monitor contractor performance through:

  • Site inspections
  • Safety observations
  • Performance reviews
  • Incident investigations
  • Corrective actions
  • Compliance reviews

Regular monitoring demonstrates active contractor management rather than relying solely on initial approvals.

  1. Insurance Verification

Insurance compliance is another major audit focus.

Auditors confirm that contractors maintain current:

  • Public liability insurance
  • Workers’ compensation insurance (where applicable)
  • Professional indemnity insurance
  • Motor vehicle insurance
  • Plant and equipment insurance

Expired insurance certificates can expose businesses to significant financial risk.

  1. Risk Management Processes

Auditors assess whether contractor-related risks are formally identified and managed.

They review:

  • Risk assessments
  • Control measures
  • SWMS for high-risk construction work
  • Hazard reporting processes
  • Emergency response procedures

They also examine whether identified risks are regularly reviewed as work progresses.

Common Audit Findings

Many contractor compliance audits reveal recurring issues, including:

  • Expired licences or insurance certificates
  • Missing induction records
  • Incomplete contractor files
  • Outdated SWMS
  • Inconsistent document reviews
  • Poor contractor performance monitoring
  • Lack of documented corrective actions

Addressing these issues proactively can significantly improve audit outcomes.

How Digital Compliance Systems Help

Many Australian organisations now use digital contractor management platforms to streamline compliance.

These systems can:

  • Automatically track document expiry dates
  • Store compliance records securely
  • Verify licences and certifications
  • Automate contractor onboarding
  • Generate audit-ready reports
  • Send renewal reminders
  • Provide real-time compliance dashboards

Digital systems reduce administrative effort while improving visibility across contractor workforces.

Preparing for a Contractor Compliance Audit

Preparation should be an ongoing process rather than a last-minute exercise.

Consider the following best practices:

  • Maintain a centralised contractor register.
  • Review licences and insurance regularly.
  • Update contractor documentation promptly.
  • Conduct periodic internal compliance reviews.
  • Keep induction records current.
  • Monitor contractor performance throughout each engagement.
  • Document corrective actions and follow-up activities.
  • Train managers responsible for contractor oversight.

Businesses that maintain strong compliance practices throughout the year are generally better prepared for both scheduled and unannounced audits.

Final Thoughts

Contractor compliance is about more than satisfying auditors, it is a fundamental component of effective risk management. Strong compliance systems help protect workers, support legal obligations, reduce operational disruptions, and build confidence with clients and stakeholders.

Auditors assess whether your organisation has robust processes that consistently verify contractor qualifications, monitor ongoing performance, and maintain accurate records. By adopting a proactive approach and leveraging modern compliance tools where appropriate, Australian businesses can improve audit readiness while creating safer and more efficient workplaces.

Learn more about Audit Readiness and use our free checklist to see how audit ready your business is.

Falls from Heights Remain One of Queensland Construction’s Biggest Safety Risks

Construction sites across Queensland are constantly evolving environments, with workers regularly required to perform tasks on roofs, scaffolding, ladders, elevated work platforms, and partially completed structures. While working at heights is often unavoidable, falls from height continue to be one of the leading causes of serious injuries and fatalities in the construction industry.

Whether it’s a fall from a roof edge, through a skylight, from scaffolding, or from an unsecured ladder, the consequences can be devastating for workers, their families, and businesses. Understanding the risks and implementing effective controls is essential for creating safer construction sites and meeting workplace health and safety obligations.

The Reality of Falls from Heights

A fall from height can occur whenever a person works in a position where there is a risk of falling from one level to another. Even falls from relatively low heights can result in serious injuries such as fractures, spinal injuries, traumatic brain injuries, and, in some cases, fatalities.

Common scenarios that lead to falls on Queensland construction sites include:

  • Working near unprotected edges
  • Roof installation and maintenance activities
  • Inadequately secured scaffolding
  • Misuse of ladders
  • Falls through fragile roofing materials or skylights
  • Unsafe use of elevated work platforms
  • Poor housekeeping creating trip hazards near edges
  • Lack of fall protection systems

Many incidents occur because hazards were not properly identified, controls were missing, or workers were not adequately trained and supervised.

Legal Responsibilities for Managing Fall Risks

Under Queensland workplace health and safety laws, persons conducting a business or undertaking (PCBUs) have a duty to eliminate risks to health and safety so far as is reasonably practicable. Where elimination is not possible, risks must be minimised using appropriate control measures.

Construction businesses must assess the risk of falls before work begins and implement controls that provide the highest level of protection possible.

Controlling the Risk of Falls: The Hierarchy of Controls

Managing fall hazards should follow the hierarchy of controls, prioritising the most effective measures first.

  1. Eliminate the Need to Work at Height

The most effective control is to remove the hazard entirely.

Examples include:

  • Prefabricating components at ground level before installation
  • Using extendable tools to perform tasks from the ground
  • Redesigning work processes to avoid elevated access

If the work can be completed safely without leaving the ground, the risk of falling is eliminated.

  1. Use Passive Fall Prevention Systems

Passive controls provide protection without requiring active worker intervention.

Examples include:

  • Edge protection and guardrails
  • Scaffold systems with integrated guardrails
  • Safety mesh beneath roof structures
  • Temporary barriers around openings
  • Covered floor penetrations and service openings

These controls are generally preferred because they provide continuous protection for all workers on site.

  1. Use Work Positioning or Fall Restraint Systems

Where passive protection is not reasonably practicable, fall restraint systems may be used to prevent workers from reaching a fall hazard.

Examples include:

  • Travel restraint systems
  • Anchored restraint lines
  • Work positioning systems

These systems are designed to prevent a worker from reaching an exposed edge rather than arresting a fall after it occurs.

  1. Implement Fall Arrest Systems

Fall arrest systems should only be used when higher-level controls are not reasonably practicable.

Examples include:

  • Safety harnesses and lanyards
  • Inertia reel systems
  • Anchor points and lifelines
  • Catch platforms
  • Safety nets

It is important to remember that fall arrest systems do not prevent a fall, they reduce the consequences if one occurs. Rescue procedures must also be in place to ensure a suspended worker can be recovered quickly.

  1. Use Administrative Controls

Administrative controls support physical safety measures and help ensure work is performed safely.

Examples include:

  • Safe work method statements (SWMS)
  • Site-specific risk assessments
  • Permit-to-work systems
  • Worker training and competency verification
  • Toolbox talks
  • Regular inspections and maintenance
  • Effective supervision
  • Clear exclusion zones

Administrative controls should never be relied upon as the sole method of protection where a risk of falling exists.

Ladder Safety: A Common Area of Concern

Ladders are involved in many fall-related incidents on construction sites. While ladders can be useful for short-duration tasks, they should not be used as a primary work platform where safer alternatives are available.

To improve ladder safety:

  • Select the correct ladder for the task
  • Ensure ladders are in good condition
  • Place ladders on stable ground
  • Maintain three points of contact
  • Secure ladders where possible
  • Avoid overreaching
  • Use scaffolding or elevated work platforms for longer-duration work

Planning Is Critical

Effective planning is one of the most important factors in preventing falls.

Before commencing work at height, construction businesses should consider:

  • The height at which work will occur
  • The duration and complexity of the task
  • Environmental conditions such as wind and rain
  • Access and egress requirements
  • Emergency and rescue procedures
  • The competency of workers performing the task
  • Inspection requirements for equipment and systems

A well-planned job significantly reduces the likelihood of incidents occurring.

Creating a Strong Safety Culture

Physical controls alone cannot prevent every fall. A strong safety culture encourages workers to identify hazards, report concerns, and stop work when conditions become unsafe.

Construction companies that prioritise safety typically experience:

  • Fewer incidents and injuries
  • Reduced project disruptions
  • Improved workforce morale
  • Better regulatory compliance
  • Lower financial and reputational risk

When workers feel empowered to raise concerns and safety is embedded into everyday operations, fall risks are more effectively managed.

Final Thoughts

Falls from heights remain one of the most significant hazards on Queensland construction sites. However, many incidents are preventable through proper planning, risk assessment, worker training, and the implementation of effective control measures.

By prioritising elimination, using appropriate fall prevention systems, maintaining equipment, and fostering a strong safety culture, construction businesses can significantly reduce the risk of serious injury and ensure workers return home safely at the end of every shift.

From July 2026, Workplace Health and Safety Queensland (WHSQ) inspectors will visit construction sites across Queensland as part of a compliance campaign focused of work at heights, where they will assess workplace health and safety and take action if non-compliance is identified.

Sherm Software can help you to ensure your business has the right controls in place to manage the risk of falls when working at heights. Training and competency verification can be completed with notification sent when it is due, permits are maintained within the workers profile, regular workplace inspections can be completed electronically using Sherm’s Mobile App, SWMS are made readily available anywhere at any time, and many other features to help keep your business compliant.

Contractor Inductions: Why Compliance Slips Through the Cracks

Across Australian worksites, from construction and mining to logistics and facilities management, contractor inductions are a routine part of onboarding. They’re meant to ensure every worker understands site rules, hazards, and responsibilities before starting work. On paper, the process looks solid. In practice, however, contractor inductions are one of the most common points where compliance quietly breaks down.

This isn’t usually due to negligence or bad intent. More often, it’s the result of rushed processes, fragmented systems, and assumptions that don’t hold up under scrutiny. Understanding where things go wrong is the first step to tightening compliance and reducing risk.

The “Tick-and-Flick” Mentality

One of the biggest pitfalls is treating inductions as a box-ticking exercise. When deadlines loom and contractors are needed on-site quickly, the focus shifts from comprehension to completion. Workers may click through online modules or skim documents just to gain site access.

The problem? Completion doesn’t equal understanding. If a contractor hasn’t genuinely absorbed key safety procedures, the business is exposed, not just to regulatory penalties, but to real-world incidents.

Inconsistent Induction Standards Across Sites

Many organisations operate across multiple locations, each with slightly different induction requirements. While some variation is necessary due to site-specific risks, inconsistency can create confusion, especially for contractors moving between sites.

Without a standardised baseline, important information can fall through the cracks. Contractors may assume they’ve “already done this before,” while site managers assume prior knowledge that may not exist.

Poor Record-Keeping and Verification

In an audit or incident investigation, documentation is everything. Yet many businesses still rely on scattered systems like emails, spreadsheets and paper forms to track inductions.

This fragmentation leads to common issues:

  • Missing or incomplete records
  • Difficulty verifying who completed what training
  • Expired inductions going unnoticed

When regulators come knocking, these gaps quickly become liabilities.

Language and Literacy Barriers

Australia’s workforce is diverse, and not all contractors will have the same level of English proficiency or literacy. Standard induction materials often fail to account for this.

If critical safety information isn’t clearly understood, the induction has effectively failed, even if it’s been “completed.” Visual aids, translated materials, and interactive formats can make a significant difference here, but they’re not always implemented.

Lack of Engagement and Relevance

Generic inductions that cover broad policies without tailoring to specific roles or risks tend to lose attention quickly. Contractors may struggle to see how the information applies to their actual tasks.

Effective inductions need to answer a simple question: What does this mean for me, today, on this site? Without that connection, retention drops and compliance weakens.

No Ongoing Reinforcement

Induction shouldn’t be a one-off event. Over time, people forget procedures, become complacent, or develop shortcuts. Yet many organisations fail to reinforce key messages after the initial onboarding.

Toolbox talks, refresher training, and periodic assessments are critical to maintaining compliance, not just establishing it.

Overreliance on Contractors to Self-Manage

It’s common for businesses to assume that contractors, especially experienced ones, will manage their own compliance. While contractors do carry responsibilities under Australian work health and safety laws, the host organisation still has a duty of care.

Assumptions like “they’ve done this before” or “they know the risks” can lead to dangerous gaps in oversight.

Closing the Gaps

Improving contractor induction compliance doesn’t necessarily mean adding more content, it means improving how it’s delivered, tracked, and reinforced.

Some practical steps include:

  • Standardising core induction requirements across sites
  • Using digital systems for real-time tracking and verification
  • Designing content for clarity, engagement, and accessibility
  • Incorporating site-specific, role-relevant information
  • Scheduling regular refreshers and compliance checks

Ultimately, contractor inductions are more than a procedural step, they’re a frontline defence against incidents and non-compliance. When done well, they set clear expectations, build safety culture, and protect both workers and businesses.

When done poorly, they create a false sense of security.

That’s where the real risk lies.

For a broader explanation of how inductions fit into defensible contractor management, see our Contractor and Supplier Compliance Management Guide.

Sherm Software can help close the gaps using the Contractor and Supplier Register by maintaining records and sending automatic notifications when scheduled refreshers and compliance checks are due.

Use our Checklist to assess whether your contractor compliance approach would stand up to audit, investigation, or client scrutiny.

Contractor Prequalification in Australia, More Than a Paper Chase

Across Australia, contractor prequalification is often treated as a compliance exercise—collect the required documents, tick the boxes, and move on. With strict regulatory frameworks and a strong focus on workplace safety, it’s understandable why documentation plays such a central role.

But here’s the reality, collecting documents alone doesn’t ensure a contractor is safe, capable, or reliable. In fact, over-reliance on paperwork can create blind spots that expose businesses to serious operational and legal risks.

Compliance Doesn’t Equal Capability

In the Australian context, contractors are typically required to provide:

  • Public liability and workers’ compensation insurance
  • Relevant licences and tickets (e.g. White Cards, high-risk work licences)
  • Safe Work Method Statements (SWMS)
  • Safety management plans and policies

These are all essential. However, they only confirm that a contractor meets minimum requirements at a specific point in time. They don’t guarantee that work will be carried out safely on-site or that systems are actively followed.

A contractor might submit a compliant SWMS, but is it actually used in day-to-day operations? Are workers properly trained, supervised, and accountable?

Documentation alone can’t answer these questions.

The Risks of a “Set and Forget” Approach

Many businesses adopt a “set and forget” model—documents are collected during onboarding and rarely revisited. In a fast-moving environment like construction, mining, or infrastructure, this approach can quickly become outdated.

Common issues include:

  • Expired insurances or licences going unnoticed
  • Generic SWMS that don’t reflect actual site conditions
  • Changes in subcontractors or workforce capability
  • Deterioration in safety performance over time

Under Australian Work Health and Safety (WHS) laws, businesses (PCBUs) have a duty to ensure, so far as reasonably practicable, the health and safety of workers—including contractors. Simply collecting documents is unlikely to meet this obligation if something goes wrong.

Bridging the Gap Between Paper and Practice

The key challenge is ensuring that what’s documented is actually implemented.

To bridge this gap, organisations need to go beyond collection and focus on validation. This might include:

  • Reviewing SWMS for task-specific relevance, not just completeness
  • Verifying licences with issuing authorities where applicable
  • Confirming insurance coverage directly with providers
  • Conducting site observations or audits
  • Speaking with referees about past performance

These steps help ensure that contractors are not just compliant on paper, but competent in practice.

Prequalification Should Be Ongoing

In Australia’s high-risk industries, conditions can change rapidly. That’s why contractor prequalification should be treated as a continuous process, not a one-off task.

A more effective approach includes:

  • Regular reviews of contractor documentation
  • Automated alerts for expiring licences and insurances
  • Monitoring incident reports and near misses
  • Periodic reassessment based on project risk

This dynamic model aligns more closely with WHS expectations and helps organisations stay ahead of potential issues.

Using Technology the Right Way

Digital prequalification platforms are becoming increasingly common across Australia, particularly in sectors like construction and energy. While these systems can streamline administration, they shouldn’t be used as a shortcut.

The real value of technology lies in:

  • Providing visibility over contractor compliance status
  • Enforcing document currency through automated reminders
  • Highlighting gaps or inconsistencies in submissions
  • Supporting ongoing monitoring and reporting

Technology should enhance decision-making—not replace critical thinking.

A Shift Towards Risk-Based Thinking

To strengthen contractor prequalification, Australian businesses need to shift their mindset from compliance to risk management.

Instead of asking, “Have we collected everything?”, the better question is, “Is this contractor genuinely capable of doing the job safely and effectively?”

This means considering factors such as:

  • The complexity and risk level of the work
  • The contractor’s track record and experience
  • Their safety culture and leadership
  • Their ability to adapt to changing site conditions

A risk-based approach ensures that higher-risk work receives greater scrutiny, rather than treating all contractors the same.

Building a More Robust System

A stronger contractor prequalification framework in Australia should include:

  1. Baseline document collection to meet regulatory requirements
  2. Verification processes to confirm accuracy and authenticity
  3. Ongoing monitoring aligned with WHS obligations
  4. Risk-based assessments tailored to specific work activities
  5. Continuous improvement driven by performance data

This approach not only supports compliance but actively reduces the likelihood of incidents and disruptions.

Final Thoughts

In Australia’s regulatory environment, paperwork is essential—but it’s only the starting point.

True contractor prequalification goes beyond documents to assess real-world capability, behaviour, and risk over time. Businesses that move past the “paper chase” mindset are better equipped to protect their workers, meet their WHS duties, and deliver successful projects.

Because when it comes to contractor management, what happens on-site matters far more than what’s sitting in a folder.

This is explored further in our Contractor and Supplier Compliance Management Guide.

Sherm Software manages all of your Contractor and Supplier requirements, from monitoring incidents reported to notifications sent when expiry dates are approaching for documentation supplied.  Get in touch and let us help you make periodic reassessment much easier.

Queensland Repeals HSR Access to WHSQ Enforcement Information

The Queensland State Government has made a significant—and controversial—change to the state’s work health and safety (WHS) framework. By repealing provisions that would have allowed Health and Safety Representatives (HSRs) to request and obtain enforcement information from Workplace Health and Safety Queensland (WHSQ), the government has reshaped the balance between transparency, regulatory control, and workplace power dynamics.

This development raises important questions about accountability, worker representation, and the future of safety oversight in Queensland workplaces.

Understanding the Repealed Rights

Under the now-repealed provisions, HSRs—and in some cases union officials—would have been able to request detailed compliance and enforcement information from WHSQ. This included data on:

  • Improvement notices
  • Prohibition notices
  • Non-disturbance notices

These notices are key regulatory tools. Improvement notices require employers to fix safety breaches within a timeframe, while prohibition notices address serious and immediate risks by halting unsafe activities. Non-disturbance notices preserve incident sites for investigation.

Access to this information would have given HSRs greater visibility into an employer’s safety history and regulatory interactions—potentially strengthening their ability to advocate for safer conditions.

Why the Government Repealed the Laws

The repeal forms part of broader amendments to Queensland’s WHS legislation. According to government statements, the decision was driven by concerns about misuse and overreach.

The repealed laws were criticised for:

  • Allowing unlimited requests for information
  • Lacking requirements for justification or relevance
  • Potentially enabling misuse by unions or representatives

The government argued that such provisions could be “weaponised” in industrial disputes, shifting the focus away from safety and toward workplace conflict.

In this context, the repeal is framed as an effort to restore balance and ensure that WHSQ remains focused on its core function: enforcing safety laws and preventing harm.

Implications for Workplace Safety

The removal of HSR access to enforcement data has sparked debate across industry, unions, and legal circles.

Potential Benefits:

  • Reduces administrative burden on WHSQ
  • Limits risk of sensitive information being used for non-safety purposes
  • Reinforces the regulator’s independence

Potential Risks:

  • Decreases transparency around employer compliance history
  • Limits HSR capacity to proactively identify systemic safety issues
  • May weaken worker participation in safety oversight

HSRs still retain important powers, including issuing provisional improvement notices (PINs) within their workgroups and participating in consultation processes.

However, without access to regulator-held information, their ability to form a complete picture of workplace risks may be constrained.

A Broader Policy Direction

This repeal reflects a broader policy direction within Queensland’s WHS reforms—one that appears to prioritise regulatory control and safeguards against perceived misuse over expanded information-sharing.

It also aligns Queensland more closely with the national model WHS framework, which does not provide equivalent broad access rights for HSRs to regulator enforcement data.

At the same time, the move highlights an ongoing tension in workplace safety law: how to balance transparency and worker empowerment with fairness, privacy, and the prevention of misuse.

Conclusion

The repeal of HSR rights to access WHSQ enforcement information marks a pivotal shift in Queensland’s approach to workplace safety governance. While the government frames the change as a necessary safeguard, critics argue it may reduce transparency and weaken frontline safety advocacy.

Ultimately, the long-term impact will depend on how effectively existing mechanisms—consultation processes, inspections, and enforcement actions—continue to protect workers without the added layer of information-sharing that has now been removed.

As Queensland’s WHS landscape evolves, this decision will likely remain a focal point in debates about the role of workers, regulators, and employers in maintaining safe workplaces.

Common Reasons Businesses Fail WHS, ISO or Principal Contractor Audits

Workplace audits, whether for Work Health and Safety (WHS), ISO certification, or principal contractor compliance, are designed to ensure businesses operate safely, legally, and systematically.

Audits may be conducted under state-based WHS regulators such as Safe Work Australia (policy body), enforcement authorities like SafeWork NSW, or as part of ISO certification through standards developed by International Organisation for Standardisation. Principal contractors on construction projects also conduct prequalification and ongoing compliance audits to manage site risk.

Despite good intentions, many businesses fail these audits for preventable reasons. Below are the most common causes, and how to avoid them.

Incomplete or Outdated Safety Management Systems

A common failure point is having a WHS or ISO system that looks good on paper but hasn’t been updated, or implemented, in practice.

Typical issues include:

  • Policies not reviewed annually
  • Procedures that don’t reflect current operations
  • Missing version control
  • Documents that reference outdated legislation

Auditors look for evidence that your system is live, current, and embedded, not just a template stored in a folder.

How to avoid it:

Schedule annual management reviews and document revisions. Ensure procedures match actual site practices.

Poor Hazard Identification and Risk Assessments

Under harmonised WHS laws, businesses must identify hazards and implement effective controls.

Audit failures often arise from:

  • Generic, copy-paste risk assessments
  • Missing Safe Work Method Statements (SWMS)
  • No evidence of site-specific risk review
  • Controls not aligned with the hierarchy of control

Principal contractors in construction are especially strict about SWMS compliance and site-specific risk management.

How to avoid it:

Ensure risk assessments are task-specific, signed, dated, and reviewed when conditions change.

Inadequate Training and Competency Records

You may have competent workers, but if you can’t prove it, you can fail the audit.

Common documentation gaps include:

  • Expired high-risk work licences
  • Missing VOC (Verification of Competency) records
  • No training matrix
  • No induction records
  • No refresher training evidence

ISO standards such as ISO 9001 and ISO 45001 require documented competency evidence.

How to avoid it:

Maintain a live training register and monitor expiry dates proactively.

Lack of Consultation and Worker Participation

WHS laws require consultation with workers on safety matters.

Auditors may ask:

  • How are workers consulted about hazards?
  • Are toolbox talks documented?
  • Is there evidence of safety meetings?
  • Are HSRs (Health and Safety Representatives) involved?

If consultation is informal and undocumented, it may not meet compliance requirements.

How to avoid it:

Keep minutes of toolbox talks and safety meetings. Record attendance and action items.

Incident Reporting and Investigation Failures

Many businesses fail audits not because incidents occurred, but because they weren’t managed correctly.

Red flags include:

  • No incident register
  • No investigation reports
  • No root cause analysis
  • Corrective actions not tracked
  • Notifiable incidents not reported

Regulators expect a structured approach to incident management and corrective actions.

How to avoid it:

Use a formal incident reporting system and track corrective actions through to completion.

Contractor Management Gaps

Principal contractor audits often focus heavily on subcontractor compliance.

Common issues:

  • No contractor prequalification process
  • Missing insurances
  • No SWMS review process
  • No evidence of subcontractor induction
  • Lack of monitoring and supervision

If you can’t demonstrate oversight of subcontractors, you may fail site audits.

How to avoid it:

Implement a documented contractor management procedure with checklists and approval records.

Internal Audits Not Conducted (or Not Effective)

For ISO-certified businesses, internal audits are mandatory.

Frequent problems include:

  • No internal audit schedule
  • Superficial audits with no findings
  • No evidence of corrective action follow-up
  • Management reviews not conducted

Auditors expect to see continuous improvement, not just compliance.

How to avoid it:

Conduct structured internal audits annually and document management review outcomes.

Poor Document Control

Document control is a major ISO audit focus area.

Typical failures:

  • Uncontrolled forms in circulation
  • Staff using outdated procedures
  • Missing document registers
  • No approval signatures

Even strong systems can fail audits if document control is weak.

How to avoid it:

Use a controlled document register with version numbers and review dates.

Leadership and Due Diligence Gaps

Under WHS laws, company officers must exercise due diligence.

Auditors may question:

  • How leadership monitors WHS performance
  • Whether safety KPIs are reviewed
  • If directors receive safety reports
  • How compliance obligations are tracked

If leadership cannot demonstrate active involvement, this can result in major non-conformances.

How to avoid it:

Document board-level WHS reporting and decision-making processes.

“Paper Compliance” Without Real Implementation

One of the biggest audit failures is when systems exist, but workers don’t follow them.

Auditors commonly:

  • Interview workers
  • Observe work practices
  • Compare procedures against actual behaviour

If there’s a disconnect between documentation and practice, it’s a serious red flag.

How to avoid it:

Ensure supervisors enforce procedures and conduct regular site inspections.

Final Thoughts

Most WHS, ISO, and principal contractor audit failures aren’t caused by catastrophic breaches, they’re caused by:

  • Inconsistent documentation
  • Lack of follow-through
  • Poor monitoring
  • Weak leadership engagement

The key to passing audits is embedding safety and compliance into everyday operations, not treating audits as one-off events.

If your systems are current, documented, implemented, and regularly reviewed, audits become far less stressful, and far more predictable.

Proactive compliance doesn’t just help you pass audits, it strengthens your business resilience, protects workers, and enhances your reputation in competitive industries like construction, manufacturing, and civil works.

This article expands on concepts covered in our Audit Readiness pillar page, which explains how these failures can be prevented structurally.

What Audit Readiness Actually Means

When organisations say they’re “audit ready,” it often means very different things. For some, it’s a last-minute scramble before the auditor arrives. For others, it’s a year-round discipline embedded in governance, finance, IT, and operations.

True audit readiness isn’t about having neat folders or polished financial statements. It’s about being able to demonstrate compliance, accuracy, and control at any time—under regulatory and accounting standards.

Let’s break down what audit readiness really means in context.

Understanding the Regulatory Landscape

Audit readiness starts with knowing which rules apply to your organisation.

Financial reporting and audit requirements are shaped by:

  • The Australian Securities and Investments Commission (ASIC)
  • The Australian Accounting Standards Board (AASB)
  • The Australian Prudential Regulation Authority (APRA) (for financial institutions)
  • The Australian Charities and Not-for-profits Commission (ACNC) (for charities)

Depending on your structure (company, charity, public sector entity, financial institution), different standards and reporting obligations apply.

Being audit ready means you:

  • Know which standards apply to you
  • Understand reporting deadlines
  • Maintain documentation that aligns with Australian Accounting Standards (AAS)

It’s More Than Just the Annual Audit

Many organisations treat audit readiness as a seasonal project—usually starting a few months before year-end.

In reality, audit readiness means:

  • Clean reconciliations completed monthly
  • Controls operating consistently throughout the year
  • Policies reviewed and updated regularly
  • Evidence retained in real time

If documentation is only assembled when auditors ask for it, you’re not audit ready—you’re audit reactive.

Strong Internal Controls (Not Just Good Intentions)

Auditors focus heavily on internal controls. That includes:

  • Segregation of duties
  • Delegations of authority
  • Approval workflows
  • IT access management
  • Change management processes

For APRA-regulated entities, expectations are even higher around risk governance and operational resilience.

Audit readiness means controls are:

  • Documented
  • Tested
  • Understood by staff
  • Consistently applied

And importantly—evidence exists to prove it.

Documentation Is Everything

In audits, if it isn’t documented, it didn’t happen.

That includes:

  • Board minutes approving financial statements
  • Signed contracts
  • Revenue recognition support
  • Grant acquittals
  • Asset valuations
  • Lease calculations under AASB 16

Being audit ready means documentation is:

  • Centralised
  • Version controlled
  • Accessible
  • Complete

Auditors should not need to chase multiple departments repeatedly for basic evidence.

Alignment with Australian Accounting Standards

Australian Accounting Standards (AAS) align closely with IFRS but have specific local requirements.

Common areas where organisations struggle include:

  • Revenue recognition (AASB 15)
  • Leases (AASB 16)
  • Financial instruments (AASB 9)
  • Impairment assessments
  • Consolidations

Audit readiness means technical accounting positions are:

  • Clearly documented
  • Supported by calculations
  • Reviewed internally
  • Consistent year to year

If your team cannot explain why a treatment was adopted, auditors will flag it.

Governance and Board Oversight

Governance expectations are strong—particularly for public companies, large charities, and regulated entities.

Audit readiness includes:

  • Active audit and risk committees
  • Clear financial oversight
  • Documented risk management frameworks
  • Regular internal reporting

Board members should understand key financial judgments—not just sign off at year-end.

Data Integrity and Systems Reliability

Modern audits increasingly assess:

  • ERP system controls
  • Cybersecurity controls
  • Backup and disaster recovery
  • Data accuracy and integrity

Poor system controls often lead to expanded audit testing, higher fees, and delayed signoffs.

Audit readiness means your systems can:

  • Produce reliable reports
  • Track changes
  • Restrict unauthorised access
  • Maintain audit trails

Being Ready for Regulator Scrutiny

Audit readiness also means being prepared beyond the auditor.

Regulators such as ASIC, APRA, or the ACNC can request documentation, explanations, or supporting materials.

Organisations that are genuinely audit ready can:

  • Produce requested documents quickly
  • Demonstrate compliance clearly
  • Show consistent governance practices

This reduces regulatory risk and reputational damage.

Audit Readiness Reduces Cost and Stress

Audit fees continue to rise—particularly for regulated industries and larger organisations.

Poor readiness leads to:

  • Extended audit timelines
  • Multiple information requests
  • Rework and corrections
  • Increased audit fees

Strong readiness typically results in:

  • Faster fieldwork
  • Fewer audit adjustments
  • Cleaner audit reports
  • Better internal financial confidence

What Audit Readiness Is Not

Let’s be clear about common misconceptions.

Audit readiness is not:

  • A last-minute clean-up
  • Outsourcing responsibility to auditors
  • Relying on one finance team member
  • Assuming “we’ve always done it this way” is sufficient

It’s a structured, organisation-wide discipline.

The Real Definition of Audit Readiness

Audit readiness means:

Your organisation can demonstrate compliance, accuracy, governance, and control at any time—under regulatory and accounting standards—without scrambling for evidence.

It’s proactive, not reactive.

It’s embedded, not seasonal.

And it’s a competitive advantage.

If your organisation is preparing for growth, external funding, regulatory scrutiny, or board-level governance uplift, strengthening audit readiness is one of the most practical investments you can make.

Because when the auditor walks in, readiness shouldn’t start—it should already exist.

Learn more about Audit Readiness and use our free checklist to see how audit ready your organisation is.

Work Health and Safety Requirements in Australia for 2026

As Australia enters 2026, employers and safety officers must stay vigilant in implementing and adapting to updated Work Health and Safety (WHS) obligations. WHS laws across Australia are governed by the model WHS Act and supported by WHS Regulations and Codes of Practice, which are adopted by each state and territory. The national policy is shaped by Safe Work Australia, while individual regulators enforce the rules on the ground.

Ongoing Duty to Provide a Safe Workplace

At the foundation of WHS laws is the primary duty of care for Persons Conducting a Business or Undertaking (PCBUs). This duty requires PCBUs to ensure, so far as is reasonably practicable, the health and safety of workers and others affected by their work. This includes:

  • Identifying hazards and assessing risks in all work activities.
  • Implementing control measures, using the hierarchy of controls.
  • Maintaining and reviewing controls to ensure ongoing effectiveness.
  • Consulting with workers about WHS issues and risk management.

Failure to meet these duties can result in significant penalties and enforcement action by WHS regulators.

Regulatory Updates Taking Effect in 2026

Psychosocial Hazards and Mental Health

Mental health and psychosocial hazards — such as bullying, excessive job demands, fatigue, poor organisational change management, and harassment — are now explicitly part of WHS risk management in many jurisdictions. New codes of practice and updated guidance seek to help duty holders identify and control these risks, with practical steps to prevent both psychological and physical harm.

Sexual and Gender-Based Harassment Code of Practice

From March 2025, a national Code of Practice on Sexual and Gender-Based Harassment came into effect. Employers must take proactive steps to prevent harassment (in person or online) and to establish appropriate controls, handling, and reporting processes.

Indexation of Penalties

Under recent changes, penalties under the WHS Act are indexed annually to reflect economic conditions. This means fines for breaches increase regularly, making compliance even more critical for PCBUs and officers.

Industry and Hazard-Specific Requirements

Workplace Exposure Standards

Australia is transitioning from Workplace Exposure Standards (WES) to Workplace Exposure Limits (WEL) for airborne contaminants. While WEL won’t apply until 1 December 2026, employers must still comply with current WES limits and prepare for the transition to the new limits, which may be stricter and align more closely with international benchmarks.

State and Territory Regulation Changes

Several jurisdictions have updated or remade their WHS Regulations to clarify duties and operations:

  • New WHS Regulations commenced in NSW in August 2025 with updated procedural requirements and risk management duties, including strengthened psychosocial risk provisions.
  • The ACT has revised multiple WHS Codes of Practice effective from late 2025 to reflect national model updates, covering noise, confined spaces, construction work, and risk controls.

Practical Steps for WHS Compliance in 2026

To meet WHS requirements in the new year, PCBUs and safety officers should focus on the following:

Conduct comprehensive risk assessments

Evaluate physical, chemical, biological, and psychosocial hazards. Document risks and apply the hierarchy of controls to eliminate or minimise them.

Review and update WHS documentation

Ensure policies, procedures, and codes of practice references are current and aligned with 2026 Regulations. Update safety management systems accordingly.

Train and consult with workers

Engage workers on WHS issues, ensure they understand hazards and controls, and involve them in risk management and continuous improvement efforts.

Prepare for WEL transition

Review your chemical exposure assessments and adjust controls in anticipation of WEL adoption from December 2026.

Plan for emergency and first aid readiness

Establish emergency plans, maintain first-aid resources, and conduct regular drills consistent with business.gov.au guidance.

Enforcement and Culture

Regulators in each state and territory will continue to enforce WHS laws through inspections, notices, and potential prosecutions for non-compliance. Promoting a proactive safety culture, where workers feel empowered to raise concerns without fear of reprisal, is one of the most effective ways to meet legal obligations and reduce workplace harm.

Conclusion

The WHS framework in Australia for 2026 builds on existing laws that require PCBUs to protect workers and others from harm. Key areas of focus this year include managing psychosocial hazards, complying with updated codes of practice, preparing for changes to exposure limits, and maintaining dynamic risk management practices. Employers and safety officers should prioritise these updates to ensure legal compliance and foster safer, healthier workplaces.

Sherm Software is here to help with all of these requirements, from managing the health and safety of your workers, subcontractors and visitors to site, to ensuring you are complying with updated codes of practice by having them available at your fingertips anytime in your Legal Register.

Get in touch with us today and see how amazing Sherm is.

Work Health and Safety Risk Management Strategies

Introduction

Work Health and Safety (WHS) is a fundamental aspect of business operations, ensuring that workplaces remain safe and free from hazards that could cause injury, illness, or death. The WHS framework is governed primarily by the Model Work Health and Safety Act (2011), which has been adopted by most states and territories. This legislation places a legal obligation on businesses and individuals to identify, assess, and manage risks to protect workers and others from harm. Effective WHS risk management strategies are essential for compliance, employee wellbeing, and organisational sustainability.

  1. The Legislative Framework

The Model WHS Act and Regulations, developed by Safe Work Australia, provide a nationally consistent approach to managing workplace health and safety. Key elements include:

  • Primary Duty of Care: Employers, or Persons Conducting a Business or Undertaking (PCBUs), must ensure, as far as reasonably practicable, the health and safety of workers and others affected by their operations.
  • Consultation Requirements: PCBUs must consult with workers and health and safety representatives (HSRs) on matters that affect their health and safety.
  • Due Diligence: Officers (such as company directors) must demonstrate proactive management of WHS risks.

Each state and territory enforces these laws through its own regulatory authority, such as SafeWork NSW, WorkSafe Victoria, and WorkSafe Queensland.

  1. The Risk Management Process

The WHS risk management process follows a systematic approach outlined in the Code of Practice: How to Manage Work Health and Safety Risks. The four key steps are:

Step 1: Identify Hazards

This involves recognising potential sources of harm, such as physical hazards (machinery, noise), chemical hazards (toxic substances), biological hazards (infections), psychosocial hazards (stress, bullying), and ergonomic hazards (poor workstation design). Hazard identification can be done through workplace inspections, incident reports, and worker consultation.

Step 2: Assess Risks

Risk assessment determines the likelihood and consequence of harm occurring. Tools such as risk matrices help organisations prioritise which risks require immediate control. While not always mandatory, formal risk assessment is recommended for complex or high-risk tasks.

Step 3: Control Risks

The hierarchy of control is a key WHS principle used to eliminate or minimise risks. It prioritises control measures as follows:

  1. Elimination – Remove the hazard entirely.
  2. Substitution – Replace the hazard with something safer.
  3. Engineering Controls – Isolate people from the hazard.
  4. Administrative Controls – Change the way people work (e.g., procedures, training).
  5. Personal Protective Equipment (PPE) – Use protective gear as a last resort.

Step 4: Review and Monitor Controls

Risk control measures must be regularly reviewed to ensure they remain effective, particularly after incidents, workplace changes, or the introduction of new equipment or processes.

  1. Key Strategies for Effective WHS Risk Management

To embed WHS risk management within organisational culture, the following strategies are recommended:

  • Leadership and Commitment: Senior management must demonstrate visible commitment to WHS through policies, resources, and active participation.
  • Worker Involvement: Engaging workers in decision-making fosters a safety culture and improves hazard identification and compliance.
  • Training and Education: Ongoing WHS training ensures that workers understand risks and know how to manage them effectively.
  • Incident Reporting and Investigation: A transparent reporting system encourages early identification of hazards and prevents recurrence.
  • Use of Technology: Digital WHS management systems and real-time monitoring tools enhance data collection, risk assessment, and compliance tracking.
  • Continuous Improvement: Organisations should use performance indicators and audit results to improve their WHS systems continuously.
  1. Emerging WHS Challenges

Modern workplaces face new challenges that require adaptive risk management strategies, including:

  • Psychosocial Risks: Managing mental health, workplace stress, and harassment.
  • Remote and Hybrid Work: Ensuring home office safety and ergonomic compliance.
  • Automation and AI: Addressing safety risks linked to human-machine interaction.
  • Climate Change: Mitigating heat stress, air quality issues, and extreme weather impacts on outdoor workers.

Conclusion

Effective Work Health and Safety (WHS) risk management is not only a legal obligation but also a cornerstone of sustainable business practice. By systematically identifying, assessing, controlling, and reviewing workplace risks, organisations can protect their workforce, enhance productivity, and foster a positive safety culture. As the nature of work continues to evolve, businesses must remain proactive, innovative, and compliant in managing health and safety risks for all.

If you are unsure as to what potential risk exposures your organisation may be facing, get in touch with us today. At Safety for Life we provide practical assistance in the development of an effective Risk Management Program and strategies to assist you to minimise your risk exposures.

If you are considering a safety software application for the management of risk, then please consider Sherm. Sherm Software is an essential safety management system for your organisations WHS Risk Management. Worker involvement, training and incident reporting and investigation ensure real-time monitoring is easily achieved. Sherm’s new dashboard performance indicator helps with continuous improvement of your organisations WHS Management System without the need to go searching.

Sherm Software empowers businesses to prioritise safety, achieve compliance, and build a resilient workplace culture. Get in touch today and learn more.

Employer Obligations: Travel, Safety, and Pre-Shift Work – What You Need to Know

Employers have a legal responsibility to look after their workers, not just while they’re on site, but also when they’re travelling for work or carrying out tasks before their shift officially starts.

Getting these details right is essential for compliance with the Fair Work Act 2009 (Cth), Work Health and Safety (WHS) laws, and state and territory Workers’ Compensation Acts. Let’s unpack what this means in practice for employers and employees.

The Two Core Duties Every Employer Has

No matter the industry or job type, employers have two key obligations when it comes to travel and pre-shift work:

  1. Pay for all hours worked

Employees must be paid for any time they spend performing work-related duties, even if it happens outside rostered hours or before they officially “clock on.”

  1. Ensure health and safety for all work-related activities

Employers have a duty of care to protect workers’ health and safety while they are at work, and that includes time spent travelling as part of their job.

Health and Safety When Travelling for Work

Under the Work Health and Safety Act 2011 (Cth), employers must do everything reasonably practicable to keep workers safe. This doesn’t stop at the worksite gate, it extends to any work-related travel.

Employers should:

  • Provide safe vehicles and equipment.
  • Manage risks such as fatigue, weather conditions, and long driving hours.
  • Offer journey management plans and ensure rest breaks are built into schedules.
  • Have emergency communication and check-in systems for remote or regional travel.

If a worker is travelling between sites or visiting clients, that journey is part of their job, meaning both safety obligations and workers’ compensation coverage apply.

Do You Have to Pay for Travel Time?

Not all travel is created equal in the eyes of the law. Here’s how it breaks down:

Travel Type Paid Time? Covered by WHS / Workers’ Comp? Notes
Ordinary commute (home to regular workplace) No Usually not Normal commuting time isn’t paid or covered
Travel between worksites or to off-site duties Yes Yes Paid as work time and covered for safety and insurance
Collecting work vehicle or tools before shift Yes Yes Counts as pre-shift work
Overnight or interstate travel for work Yes Yes Paid for duties and travel within ordinary working hours

If the travel occurs after the employee has started work or is part of their duties, it must be paid.

Paying for Pre-Shift Work

Pre-shift work is one of the most common compliance blind spots for employers.

Under the Fair Work Act, if an employee performs any work-related activity before or after their rostered hours, and it’s required or expected, that time must be paid.

Examples include:

  • Attending pre-start or toolbox meetings.
  • Logging into computer systems or checking emails before a shift.
  • Setting up tools or workstations.
  • Conducting pre-start vehicle or safety checks.
  • Collecting materials or equipment for the day.

Even short pre-shift tasks count as “time worked” and must be recorded and paid at the appropriate rate (ordinary or overtime).

Failing to pay for this time can lead to Fair Work Ombudsman investigations, back-pay orders, and financial penalties.

Integrating Pay and Safety Obligations

Travel and pre-shift work policies should connect payroll, HR, and safety obligations. Here’s how they fit together:

Area Employer Responsibility Legal Basis
Safety during travel Manage driving and fatigue risks, ensure vehicle safety WHS Act 2011
Payment for work-related travel Pay for travel time when it’s part of duties Fair Work Act 2009
Payment for pre-shift work Pay for all duties performed outside rostered hours Fair Work Act 2009
Workers’ compensation Ensure cover for all work-related travel and duties State/Territory laws
Record keeping Maintain accurate timesheets and records of hours worked Fair Work Regulations 2009

Best Practices for Employers

To stay compliant and fair:

  • Define start and finish times clearly in contracts and policies.
  • Pay for any required work before or after official shifts.
  • Assess travel risks, especially for field staff and remote workers.
  • Keep records of all hours worked and travel time.
  • Maintain vehicles and equipment used for work-related travel.
  • Provide fatigue management training and schedule adequate rest breaks.

Real-World Example

A field technician collects a company ute from the depot at 7:30 a.m., attends a short safety meeting, then drives to the first job site. The rostered start time is 8:00 a.m.

In this case:

  • The pre-start meeting and vehicle checks are paid work.
  • The travel between the depot and job sites is paid time.
  • The employer must ensure the vehicle is safe and insured, allow adequate breaks, and provide workers’ compensation cover during travel.

Final Thoughts

Employer obligations around travel, safety, and pre-shift work go hand in hand. The key takeaway is simple, if a worker is performing duties or travelling as part of their job, that time is work time, and it must be both safe and paid.

By taking a proactive approach to managing travel risks, recording hours accurately, and compensating fairly, employers not only comply with the law but also build trust and protect their workforce.