QEHS EthosEHS Ethos
industry

Contractor management without the PDF

Insurance certs, site inductions, JSA sign-offs, permit eligibility — four separate PDF trails most programs maintain by hand. Here is the pattern that merges them into one record per contractor company.

QEHS safety desk

Safety practitioners on staff

Practising QEHS professionals who write how-to guides, regulatory breakdowns, and field-tested program playbooks.


12 min read

Large sites routinely host 30–300 contractor companies, each with its own insurance certificates, trained operators, and current permits. The failure mode is predictable: an expired certificate lets a crew onto a high-risk task, and the incident investigation finds the evidence buried in an email thread.

The fix is a Contractor Company record with three linked capabilities: insurance tracking (expiry-aware), training matrix (by person × skill), and active permits. Each capability is a standard Composer block — no new module needed. The workflow gate at permit issuance checks all three before it lets the permit be issued.

Contractors cause 30 to 50% of workplace fatalities despite representing a much smaller fraction of the workforce. The root cause is almost always upstream of the incident: the contractor was not properly pre-qualified, their competency was not verified, and their work was not linked to the permit-to-work system that would have blocked it.

An effective pre-qualification program runs four layers: insurance verification, safety statistics (TRIR and EMR), program documentation, and competency verification. The data has to gate the permit system — an expired qualification should make it impossible to issue a permit, not just embarrassing after the fact. For the playbook, see the contractor management guide.

The four layers are not four separate processes; they are one record with four tabs. The insurance tab carries the certificates of insurance, each with a carrier, a policy number, an effective and expiry date, and the additional-insured and waiver-of-subrogation endorsements the host requires. The safety-statistics tab carries the contractor TRIR and EMR for the last three years, against the host thresholds. The program-documentation tab carries the contractor safety management plan, the substance program if the work touches process safety, and the most recent audit. The competency tab carries the training matrix by person and by skill, with currency dates and the verification method. One record, four tabs, one gate at the permit.

The insurance layer is the one that pages people. A certificate of insurance that expires on a Friday and is not renewed by Monday leaves a crew on a high-risk task with no coverage, and the host site carries the gap. The endorsement language is the part most programs miss: the host must be named additional insured, the certificate must waive subrogation against the host, and the coverage limits must meet the contract minimum. A certificate without the endorsements is a certificate that does not transfer the risk it appears to transfer, and the gap is found at the claim, not at the gate.

The safety-statistics layer is the one that filters at onboarding. The contractor TRIR and EMR are the two numbers a host can compare against a published threshold — a TRIR above the industry average or an EMR above 1.0 is a flag, not an automatic disqualifier, and the flag is the opening for a pre-qualification interview and a written improvement plan. The threshold is the host position, set in advance, applied to every contractor the same way; a threshold applied selectively is a threshold a plaintiff will cite after an incident.

  • Insurance current — every certificate the work requires is within its effective period and carries the required endorsements. An expired certificate blocks the permit; a renewal in progress does not.
  • Training current — every worker on the crew is current on every role-required course for the task. A worker whose confined-space training lapsed is a worker who cannot enter the confined space, regardless of employer.
  • Permit eligibility — the contractor company is approved for the permit type (hot work, confined space, height, electrical). Approval is task-specific, not blanket.
  • Competency verified — the person doing the work has the verified skill, not just the recorded training. Currency of training and competency of the worker are different checks, and the second is the one that survives an incident investigation.

The competency-versus-training distinction is the one that decides whether the matrix is a control or a register. Training is attendance; competency is the demonstrated ability to do the task safely. A matrix that records training dates without a competency verification — a sign-off, a practical assessment, a supervised first execution — is a register of who sat in a room. The defensible matrix records both, and the permit gate reads the competency date, not the training date, for the safety-critical skills.

The permit linkage is what closes the loop. A contractor crew on a hot-work permit is a crew whose company insurance, whose training, and whose permit eligibility were all checked at the moment the permit was issued — and the check was a system check, not a binder check. The permit carries the contractor company, the workers on the crew, the controls in place, and the issuer, and the permit is linked to the company record so that an expiry mid-shift re-runs the gate. The day-of-work gate is the one that catches the certificate that expired yesterday, which the annual onboarding gate could not.

  1. Create the Contractor Company record with the four tabs and the host thresholds for TRIR, EMR, and insurance limits pre-loaded.
  2. Onboard the certificate, the safety statistics, the program documentation, and the training matrix; the platform flags the expiries and the threshold misses on entry.
  3. Approve the company for the permit types it qualifies for — task-specific, with an approval expiry that re-triggers onboarding.
  4. Wire the permit-to-work gate so every permit issuance checks the four layers against the company record at the moment of issue, and re-checks on any expiry mid-shift.
  5. Review the contractor population quarterly against the incident record; a contractor with a clean gate and a dirty incident record is the one whose onboarding needs re-examination.

The audit evidence for a contractor program is the one a regulator asks for after a contractor event, and it is the one a host site cannot reconstruct from memory. The evidence is the company record at the time of the permit, the permit itself, the training and competency for the specific workers on the crew, and the insurance in force on the day. A platform that holds these on one tenant produces the evidence in a query; a paper program produces it in a week of email, and the week is the gap during which the host site has no defensible position. For the playbook, see the contractor management guide; for the permit-to-work system the gate plugs into, the permit-to-work deep dive.

The process-safety layer is the one that separates a general contractor program from a PSM-governed one. When the contractor work touches a covered process, 29 CFR 1910.119(h) requires the host to evaluate the contractor safety performance, to inform the contractor of the known potential fire, explosion, or toxic release hazards related to the work, and to maintain an injury and illness log for the contractor work in the covered process. The host also has to ensure the contract employees are trained for the procedures they perform, that the training is documented, and that the host advises the contractor of the unique hazards of the process. A contractor program that runs the four-tab record for general work and a fifth process-safety tab for covered-process work is the one that holds the PSM evidence at the audit, and the fifth tab is the one most general programs omit until the RMP inspector asks for it.

The contract is the risk-transfer document, and the four-tab record is the operational evidence the contract relied on. A master service agreement that requires the contractor to carry the insurance, to maintain the training, and to submit to the host gate is the agreement that makes the gate enforceable — and the gate, not the agreement, is what the crew meets on the day of work. The audit that follows a contractor event reads the contract for the obligation and the record for the performance, and the program that has only the contract and not the record has the obligation without the evidence. For the contract template and the gate configuration, see the contractor management guide and the permit-to-work deep dive; for the process-safety extension, the PSM 14 elements post.

  • Insurance — carrier, policy number, type, effective date, expiry date, limits, and the additional-insured and waiver-of-subrogation endorsements. The gate reads the expiry and the endorsement flags.
  • Safety statistics — contractor TRIR and EMR for the last three years, against the host threshold. The gate reads the threshold-comparison result.
  • Program documentation — safety management plan, substance program for covered-process work, most recent audit. The gate reads the presence and the date.
  • Competency — training matrix by person and by skill, with currency date and verification method. The gate reads the competency date for the safety-critical skills, not the training date.
Contractor management without the PDF | QEHS Ethos