Almost every operator we talk to holds contractor compliance declarations. A statement, signed by someone senior at the contracting business, confirming that its workers hold what the site requires and that its plant is fit for purpose.
They are collected diligently, filed properly, and renewed annually. And they are close to worthless as evidence, for a reason that has nothing to do with the honesty of the person who signed.
What the duty actually asks
Every safety duty in Australia is qualified by what is reasonably practicable, and that phrase is defined rather than left to argument. Among the factors is what the duty holder knows or ought reasonably to know, and the availability and suitability of ways to eliminate or minimise the risk.
Applied to contracting company competency, the question is not whether you obtained an assurance. It is whether checking was available to you and whether it was reasonably practicable to do it.
For an operator that controls site access, checking is not merely available — it is the easiest thing in the world to justify. You decide who comes through the gate. You set the requirements. You can decline entry. The capacity to influence and control the matter is close to total.
Which makes "the contracting company told us" a difficult position to hold, because the obvious follow-up is: and what stopped you from confirming it?
The declaration is accurate on the day it is signed
Here is the mechanical problem, separate from the legal one.
A declaration is a statement about a moment. It says that on the day it was signed, to the best of the signatory's knowledge, the workforce was compliant.
Credentials expire continuously. Tickets lapse. Medicals fall due. People leave and are replaced by people the declaration never contemplated. A machine goes overdue for service. None of that is dishonesty — it is the ordinary operation of time on a document that has no mechanism for noticing.
Twelve months after signing, a declaration describes a workforce that in many cases no longer exists.
And the signatory usually knows this. Ask a contracting business owner whether they could produce, right now, evidence that every person on their books is current for every site they attend, and the honest ones will say they would need to check. They signed in good faith about a state of affairs they could not fully see either.
Both parties are relying on the same missing system
This is the part that gets missed when operators treat this as a contracting company problem.
The declaration is only as good as the contracting company's own visibility of their workforce. If the contracting company is running a spreadsheet maintained between other duties — which is the normal case, not the exceptional one — then their assurance to you is built on the same fragile thing your assurance to a regulator would be.
So a chain of two organisations, both with genuine duties, is resting on one under-resourced records process that neither controls.
That is why the more sophisticated operators have stopped treating contractor compliance as something to extract from suppliers and started treating it as something to make possible. A requirement a contracting company cannot practically maintain is a requirement that will be met on paper.
What a defensible position looks like
Not a bigger declaration. Not an annual audit, which has the same moment-in-time problem at a lower frequency.
What survives examination is a live view: the site's requirements held against the actual people and the actual plant, with dates, refreshed by the underlying records rather than by somebody remembering to ask.
The practical tests:
Can you answer for a named person on a named day? Not "is this contracting company compliant" — is this person, for this task, on this date.
Does the answer include the plant? A cleared operator with a machine overdue for service is still a stopped job, and since June 2026 an operator has to verify the control, which means both halves.
Does a lapse surface before the person travels? If the first thing that notices is the gate, you have a detection system rather than a prevention one, and it detects in front of the client.
Does the answer survive one person being on leave? If it does not, you do not have a system.
The objection, and the answer
The usual objection is scale. An operator with sixty contracting companies and two thousand contracting company workers cannot personally verify each credential, and asking them to is unreasonable.
Correct — and it is not what the duty asks. The duty asks whether it was reasonably practicable to know. Verifying two thousand credentials by hand is not reasonably practicable. Holding those credentials as dated records against the requirements of each work area, so the exceptions surface, is entirely practicable and is what the industry now does.
Which brings the argument back around to the third factor in the reasonably practicable test: what you ought reasonably to know. As continuous verification becomes normal practice, the defensibility of a declaration-based approach declines — not because the law changed, but because the standard did.
The declarations are not useless. They establish that the contracting company accepts the requirement, and that has contractual value. They are just not evidence that anybody checked.

