Skip to main content
Rules Mate

Contractor and supplier compliance: due diligence, flow-down clauses and ongoing monitoring

Rules Mate Editorial8 min read

Managing compliance risk in the supply chain: supplier tiering, pre-contract due diligence, flow-down clauses that work, and monitoring after signature.

Where supplier compliance risk actually lands

Outsourcing a function does not outsource the obligation. In almost every Australian regime, the duty stays with the entity that holds it, and using a supplier simply adds a party whose conduct the entity must now manage.

The clearest statutory expressions of that principle are in work health and safety, where the primary duty under section 19 of the model WHS Act extends to workers whose activities the business influences or directs — covered in the WHS primary duty — and in the heavy vehicle chain of responsibility, where parties across the transport chain each carry a duty regardless of who physically drove. Privacy carries the same logic: disclosing personal information to a service provider does not transfer the entity's obligations under the Australian Privacy Principles.

The consequence for the compliance program is that every material supplier relationship should appear on the obligations register as a control dependency, not as somebody else's problem.

Tiering the supplier base

Applying the same diligence to every supplier is unaffordable and unnecessary. Tier the base on two axes — criticality to the business and compliance exposure created — and set the required diligence per tier.

TierDefinitionDiligence requiredReview cadence
CriticalFailure interrupts a core service, or the supplier handles personal information, customer money, or safety-critical workFull pre-contract assessment, evidence-backed, contract with full flow-down, named relationship ownerAnnual formal review plus event-driven
SignificantMaterial spend, or handles regulated activity without being business-criticalStandard questionnaire with evidence for key claims, standard clause setAnnual attestation, biennial review
StandardRoutine goods and services with no regulated exposureRegistration checks, standard termsContract renewal only
LowIncidental spendStandard termsNone

Two rules keep the tiering honest. First, tier by exposure rather than spend — a low-cost supplier with access to a customer database is critical. Second, re-tier when scope changes, because supplier scope creep is how uncontrolled relationships form.

APRA-regulated entities have a prescribed version of this exercise. CPS 230 operational risk management commenced 1 July 2025 and requires regulated entities to identify material service providers, maintain a register of them, and meet specified contractual requirements; APRA set a transition to July 2026 for existing material service provider contracts and finalised targeted amendments in April 2026 (checked August 2026). See APRA's CPS 230 page.

Pre-contract due diligence

Diligence should collect evidence, not assertions. A questionnaire returned with every box ticked and no attachments has told you nothing.

Core evidence set for a critical supplier:

  • Identity and standing. ABN and entity name, company extract, ownership, whether the trading entity is the contracting entity. Insolvency and disqualification checks where the engagement is material.
  • Licences and registrations. The specific licences the work requires, verified against the issuing register rather than a supplied certificate. Labour hire is the common trap — see labour hire licensing by state and the labour hire licence check.
  • Insurances. Certificates of currency with policy limits, expiry dates and named insured matching the contracting entity.
  • Work health and safety. Safety management system evidence, incident history, high risk work licences where relevant.
  • Workforce arrangements. Whether the supplier engages employees or subcontractors, and how far down the chain the work is subcontracted. Engagement-model risk is discussed in the employee versus contractor test.
  • Information security and privacy. Where the supplier handles personal information or connects to systems: security controls, hosting locations, subprocessors, incident notification capability. The Essential Eight assessment and the ISO 27001 gap assessment provide a structure.
  • Modern slavery and ethical sourcing. Where the entity is a reporting entity, supplier responses feed the statement.
  • Financial capacity. Proportionate to criticality and contract term.

Record the outcome, including any conditions imposed and the date, in the contract register. Diligence performed and undocumented is diligence you cannot rely on later.

Flow-down clauses that do real work

Most supply contracts contain a general compliance clause requiring the supplier to comply with all applicable laws. That clause is close to worthless on its own: it creates a contractual right but no visibility, no evidence and no ability to act before failure.

Clauses that actually function:

ClauseWhat it must doFailure mode when weak
Specific obligation complianceName the regimes that matter for this engagement, not "all applicable laws"Generic clause gives no basis to request specific evidence
Evidence and audit rightsRight to request records, attend site, and audit on notice, at a stated frequencyRight exists but is never exercisable in practice
Notification of non-complianceSupplier must notify breaches, incidents and regulator contact within a stated timeframeYou learn about the breach from the regulator
Subcontracting controlConsent required, and flow-down of the same terms to subcontractorsObligations evaporate at the second tier
Personnel standardsLicences, screening checks, inductions, training, with evidence on requestUnlicensed or unscreened personnel on site
Data and privacy termsPurpose limits, security requirements, subprocessor consent, breach notification, return or destruction on exitNo ability to meet your own notification clock
Insurance maintenanceTypes, limits, currency evidence at renewalCover lapses mid-term and nobody notices
Step-in and terminationRight to remedy, suspend or terminate for compliance failureOnly remedy is damages after the harm
Records and retentionRetention aligned to your own statutory periods, survival past terminationRecords destroyed before your retention period expires

Two clauses matter more than the rest in practice. Notification of non-compliance is what allows your incident register to start its clocks on time — see incident and breach registers. Subcontracting control with flow-down is what stops the terms disappearing one tier down, which is where most supply chain failures are found.

Ongoing monitoring after signature

Diligence at onboarding decays. Monitoring should be proportionate to tier and mostly automatable.

ActivityTierFrequencyEvidence produced
Licence and registration re-verificationCritical, SignificantAt expiry, plus annuallyRegister check screenshot with date
Insurance certificate refreshCritical, SignificantAt each policy renewalCertificate on file
Compliance attestationCritical, SignificantAnnualSigned attestation naming the regimes
Performance and incident reviewCriticalQuarterly or semi-annualMeeting record with actions
Control testing or site visitCriticalAnnual, risk-basedTest working paper
Assurance report reviewCritical where availableOn issueReviewed report, findings tracked
Adverse media and enforcement checkCriticalAnnualSearch record
Register refreshAllAnnualUpdated tiering and contract register

Expiry dates are the highest-value automation in the whole process. Licences, insurances, certifications and contract terms all expire, and the contract register plus the compliance calendar should be driving reminders well before the date rather than after it.

Supplier failures should be logged in your own incident register with the supplier named, so that repeat patterns are visible at renewal.

Regimes that name suppliers explicitly

Several Australian regimes reach into the supply chain directly, and these should be mapped on the obligations register with the supplier dependency noted:

  • Modern slavery reporting. Entities with consolidated revenue of at least $100 million must report on modern slavery risks in their operations and supply chains, with statements due within six months of the end of the entity's own financial year (checked August 2026); statements are published on the Modern Slavery Statements Register. See when a modern slavery statement is due and the threshold checker. The Modern Slavery Act 2018 sets out the mandatory criteria.
  • Chain of responsibility. Under the Heavy Vehicle National Law, parties across the transport chain — consignors, packers, loaders, schedulers — carry duties for conduct they influence. See chain of responsibility.
  • Work health and safety. The primary duty extends to workers whose activities the business influences or directs, and officers carry a due diligence duty that covers contractor arrangements; see Safe Work Australia's model code on managing WHS risks.
  • Labour hire licensing. Several states require providers to be licensed and place duties on hosts who engage unlicensed providers.
  • Prudential outsourcing and service provider management. Material service provider identification, registers and contractual requirements under APRA standards.
  • Privacy. Disclosure to a service provider does not transfer obligations, and cross-border disclosure carries additional requirements; see APP 11 reasonable steps to secure personal information.
  • Commonwealth procurement. Suppliers to government carry conditions flowing from the procurement framework; see the Commonwealth Procurement Rules.

Offboarding and the exit file

Termination is where supplier compliance obligations are most often dropped. Build an exit checklist and hold the evidence in a single file:

  1. Access revoked — systems, physical access, credentials, and evidence of revocation with a date.
  2. Data returned or destroyed — with a certificate of destruction where personal information was involved, and confirmation for subprocessors.
  3. Records transferred — anything you are required to retain that sits in the supplier's systems, obtained before the relationship ends.
  4. Outstanding compliance matters closed — open incidents, remediation, unresolved audit findings.
  5. Surviving obligations identified — confidentiality, retention, insurance run-off, indemnities. These outlive the contract and should be recorded as such.
  6. Register updated — supplier status changed, tiering removed, calendar reminders retired.
  7. Lessons recorded — where the exit followed a compliance failure, the root cause belongs in the incident register.

The exit file matters most when a regulator asks about conduct that occurred during the relationship, months after it ended. Everything you did not collect at termination is unavailable by then.

Frequently asked

Does using a contractor transfer the compliance obligation?

No. In Australian regimes the duty generally stays with the entity that holds it. The work health and safety primary duty extends to workers whose activities the business influences or directs; chain of responsibility duties attach to each party across the transport chain; and disclosing personal information to a service provider does not transfer obligations under the Australian Privacy Principles. Engaging a supplier adds a party whose conduct must be managed, rather than removing the duty.

What should a compliance clause say beyond 'comply with all applicable laws'?

It should name the specific regimes relevant to the engagement, give a right to request evidence and to audit on notice, require notification of breaches and regulator contact within a stated timeframe, require consent for subcontracting with flow-down of the same terms, set personnel licensing and screening standards, address data handling and destruction, require insurance maintenance with evidence, and provide step-in or termination rights for compliance failure. A general clause creates a right without visibility.

How should suppliers be tiered?

By compliance exposure and business criticality rather than spend. A supplier is critical if failure interrupts a core service, or if it handles personal information, customer money or safety-critical work — regardless of contract value. Re-tier whenever scope changes, because expanding scope under an existing low-tier contract is the most common way uncontrolled relationships form.

When is a modern slavery statement due?

Entities with annual consolidated revenue of at least $100 million must report, and the statement is due within six months of the end of that entity's own financial year or accounting period, then published on the Modern Slavery Statements Register (checked August 2026). Because the deadline runs from each entity's own year end, there is no single national due date.

What does CPS 230 require in relation to service providers?

APRA-regulated entities must identify material service providers, maintain a register of them, and meet specified contractual requirements for material arrangements. The standard commenced on 1 July 2025, with a transition period to July 2026 for existing material service provider contracts, and APRA finalised targeted amendments introducing limited exemptions from certain contractual requirements in April 2026 (checked August 2026).

What belongs in a supplier exit file?

Evidence of access revocation with dates, data return or destruction certificates including subprocessors, transfer of any records you are required to retain, closure of open incidents and audit findings, an identified list of obligations that survive termination such as confidentiality and retention, updated registers and retired calendar reminders, and root cause notes where the exit followed a compliance failure.

Related

Related reading