Skip to content
PIAGOGO! Site Approved
All insights
GO! Site ApprovedRisk · Compliance

Officer due diligence: the contracting company questions a board should be asking

30 June 2026 · 4 min read · PIAGO

The officer duty under Australia's WHS laws is unusual in that the law spells out what it involves. It is not a general obligation to be responsible. It is a list.

An officer must exercise due diligence, which includes:

  • acquiring and keeping up to date knowledge of work health and safety matters;
  • gaining an understanding of the nature of the operations and the hazards and risks associated with them;
  • ensuring the business has and uses appropriate resources and processes to eliminate or minimise risks;
  • ensuring there are processes for receiving and considering information about incidents, hazards and risks, and responding in a timely way;
  • ensuring processes are in place for complying with duties; and
  • verifying the provision and use of those resources and processes.

The last one is the one that catches people. Verification is an active word. An officer who has read a well-written safety management system and has no idea whether anyone follows it has not discharged the duty.

Contracting companies are where this gets hardest, because the people doing the work are not the organisation's employees and the records are not the organisation's records.

Six questions worth putting on the agenda

These are written to be asked in a board or executive meeting, and each is designed so that a comfortable answer is a bad sign.

1. How many contracting company workers were on our sites last month, and how many were verified before they arrived?

Two numbers. If the second is not available, that is the finding.

The question is deliberately about before they arrived. Verification at the gate is a control. Verification in advance is a system, and the difference shows up in how often work stops.

2. When did we last find a contracting company worker on site without a current credential — and how did we find out?

"Never" is not a good answer. On any site of scale it happens, and a business that has never detected one is more likely to have poor detection than perfect contracting companies.

How you found out is the real question. If the answer is always "at the gate", detection is working and prevention is not.

3. What is our exposure window between a credential lapsing and access being withdrawn?

Almost nobody has measured this. When it is measured it is usually days, occasionally weeks.

It is the cleanest single metric of whether contractor compliance is a live system or a periodic one, and it can be worked out from existing records in an afternoon.

4. Can we produce, for a named contracting company worker on a named past date, the evidence we held that they were competent for their task?

This is the question an investigation asks, phrased the way it gets asked.

Note that it is retrospective. Current status is easy. What matters after an incident is what you held on that day — which requires records with dates rather than a system that overwrites.

5. Does that answer survive one person being on leave?

Almost every organisation has somebody who genuinely holds the picture. They are usually excellent, and they are usually the reason the answer exists.

If the honest answer is that the picture goes with them, then the business does not have a process — it has a person. That is a finding an officer is specifically required to look for, because "appropriate resources and processes" is the wording of the duty.

6. What does our contracting company plant position look like, and who owns it?

Usually a longer pause than the others.

Since 1 June 2026, Queensland operators have had to verify their critical controls, and a control is not verified unless the plant involved is fit as well as the operator competent. If the plant answer comes from a different part of the business than the people answer, the organisation cannot currently evidence half of its own control.

What a good answer sounds like

Not "yes, we have a system". Every organisation has a system.

A good answer has numbers and dates in it: this many contracting company workers, this proportion verified in advance, this many exceptions found last quarter, this is what we did about them, this is the trend.

It also has bad news in it. An officer receiving only good news about contractor compliance is receiving a filtered picture, and the duty to ensure processes for receiving and considering information about hazards is precisely a duty to make sure the filter is not there.

Why this is different from being briefed

The duty is not discharged by receiving a report. It is discharged by verifying.

Practically, that means an officer should occasionally look at the underlying thing rather than the summary of it — pull one contracting company, one date, and ask to see the evidence that was held. Not as an audit, and not to catch anybody. To find out whether the report and the reality are the same document.

They usually are. The occasions they are not are the ones worth knowing about early, and the only way to find out is to look.

Rather talk it through than read about it?

Thirty to forty-five minutes on your sites and your requirements, with the people who build it.