rulesmate.com.au — Compliance reference
https://rulesmate.com.au/insights/contractor-supplier-compliance-due-diligence-flow-down
Printed 28 August 2026
Contractor and supplier compliance: due diligence, flow-down clauses and ongoing monitoring
Managing compliance risk in the supply chain: supplier tiering, pre-contract due diligence, flow-down clauses that work, and monitoring after signature.
Where supplier compliance risk actually lands
Outsourcing a function does not outsource the obligation. In almost every Australian regime, the duty stays with the entity that holds it, and using a supplier simply adds a party whose conduct the entity must now manage.
The clearest statutory expressions of that principle are in work health and safety, where the primary duty under section 19 of the model WHS Act extends to workers whose activities the business influences or directs — covered in the WHS primary duty — and in the heavy vehicle chain of responsibility, where parties across the transport chain each carry a duty regardless of who physically drove. Privacy carries the same logic: disclosing personal information to a service provider does not transfer the entity's obligations under the Australian Privacy Principles.
The consequence for the compliance program is that every material supplier relationship should appear on the obligations register as a control dependency, not as somebody else's problem.
Tiering the supplier base
Applying the same diligence to every supplier is unaffordable and unnecessary. Tier the base on two axes — criticality to the business and compliance exposure created — and set the required diligence per tier.
| Tier | Definition | Diligence required | Review cadence |
|---|---|---|---|
| Critical | Failure interrupts a core service, or the supplier handles personal information, customer money, or safety-critical work | Full pre-contract assessment, evidence-backed, contract with full flow-down, named relationship owner | Annual formal review plus event-driven |
| Significant | Material spend, or handles regulated activity without being business-critical | Standard questionnaire with evidence for key claims, standard clause set | Annual attestation, biennial review |
| Standard | Routine goods and services with no regulated exposure | Registration checks, standard terms | Contract renewal only |
| Low | Incidental spend | Standard terms | None |
Two rules keep the tiering honest. First, tier by exposure rather than spend — a low-cost supplier with access to a customer database is critical. Second, re-tier when scope changes, because supplier scope creep is how uncontrolled relationships form.
APRA-regulated entities have a prescribed version of this exercise. CPS 230 operational risk management commenced 1 July 2025 and requires regulated entities to identify material service providers, maintain a register of them, and meet specified contractual requirements; APRA set a transition to July 2026 for existing material service provider contracts and finalised targeted amendments in April 2026 (checked August 2026). See APRA's CPS 230 page.
Pre-contract due diligence
Diligence should collect evidence, not assertions. A questionnaire returned with every box ticked and no attachments has told you nothing.
Core evidence set for a critical supplier:
- Identity and standing. ABN and entity name, company extract, ownership, whether the trading entity is the contracting entity. Insolvency and disqualification checks where the engagement is material.
- Licences and registrations. The specific licences the work requires, verified against the issuing register rather than a supplied certificate. Labour hire is the common trap — see labour hire licensing by state and the labour hire licence check.
- Insurances. Certificates of currency with policy limits, expiry dates and named insured matching the contracting entity.
- Work health and safety. Safety management system evidence, incident history, high risk work licences where relevant.
- Workforce arrangements. Whether the supplier engages employees or subcontractors, and how far down the chain the work is subcontracted. Engagement-model risk is discussed in the employee versus contractor test.
- Information security and privacy. Where the supplier handles personal information or connects to systems: security controls, hosting locations, subprocessors, incident notification capability. The Essential Eight assessment and the ISO 27001 gap assessment provide a structure.
- Modern slavery and ethical sourcing. Where the entity is a reporting entity, supplier responses feed the statement.
- Financial capacity. Proportionate to criticality and contract term.
Record the outcome, including any conditions imposed and the date, in the contract register. Diligence performed and undocumented is diligence you cannot rely on later.
Flow-down clauses that do real work
Most supply contracts contain a general compliance clause requiring the supplier to comply with all applicable laws. That clause is close to worthless on its own: it creates a contractual right but no visibility, no evidence and no ability to act before failure.
Clauses that actually function:
| Clause | What it must do | Failure mode when weak |
|---|---|---|
| Specific obligation compliance | Name the regimes that matter for this engagement, not "all applicable laws" | Generic clause gives no basis to request specific evidence |
| Evidence and audit rights | Right to request records, attend site, and audit on notice, at a stated frequency | Right exists but is never exercisable in practice |
| Notification of non-compliance | Supplier must notify breaches, incidents and regulator contact within a stated timeframe | You learn about the breach from the regulator |
| Subcontracting control | Consent required, and flow-down of the same terms to subcontractors | Obligations evaporate at the second tier |
| Personnel standards | Licences, screening checks, inductions, training, with evidence on request | Unlicensed or unscreened personnel on site |
| Data and privacy terms | Purpose limits, security requirements, subprocessor consent, breach notification, return or destruction on exit | No ability to meet your own notification clock |
| Insurance maintenance | Types, limits, currency evidence at renewal | Cover lapses mid-term and nobody notices |
| Step-in and termination | Right to remedy, suspend or terminate for compliance failure | Only remedy is damages after the harm |
| Records and retention | Retention aligned to your own statutory periods, survival past termination | Records destroyed before your retention period expires |
Two clauses matter more than the rest in practice. Notification of non-compliance is what allows your incident register to start its clocks on time — see incident and breach registers. Subcontracting control with flow-down is what stops the terms disappearing one tier down, which is where most supply chain failures are found.
Ongoing monitoring after signature
Diligence at onboarding decays. Monitoring should be proportionate to tier and mostly automatable.
| Activity | Tier | Frequency | Evidence produced |
|---|---|---|---|
| Licence and registration re-verification | Critical, Significant | At expiry, plus annually | Register check screenshot with date |
| Insurance certificate refresh | Critical, Significant | At each policy renewal | Certificate on file |
| Compliance attestation | Critical, Significant | Annual | Signed attestation naming the regimes |
| Performance and incident review | Critical | Quarterly or semi-annual | Meeting record with actions |
| Control testing or site visit | Critical | Annual, risk-based | Test working paper |
| Assurance report review | Critical where available | On issue | Reviewed report, findings tracked |
| Adverse media and enforcement check | Critical | Annual | Search record |
| Register refresh | All | Annual | Updated tiering and contract register |
Expiry dates are the highest-value automation in the whole process. Licences, insurances, certifications and contract terms all expire, and the contract register plus the compliance calendar should be driving reminders well before the date rather than after it.
Supplier failures should be logged in your own incident register with the supplier named, so that repeat patterns are visible at renewal.
Regimes that name suppliers explicitly
Several Australian regimes reach into the supply chain directly, and these should be mapped on the obligations register with the supplier dependency noted:
- Modern slavery reporting. Entities with consolidated revenue of at least $100 million must report on modern slavery risks in their operations and supply chains, with statements due within six months of the end of the entity's own financial year (checked August 2026); statements are published on the Modern Slavery Statements Register. See when a modern slavery statement is due and the threshold checker. The Modern Slavery Act 2018 sets out the mandatory criteria.
- Chain of responsibility. Under the Heavy Vehicle National Law, parties across the transport chain — consignors, packers, loaders, schedulers — carry duties for conduct they influence. See chain of responsibility.
- Work health and safety. The primary duty extends to workers whose activities the business influences or directs, and officers carry a due diligence duty that covers contractor arrangements; see Safe Work Australia's model code on managing WHS risks.
- Labour hire licensing. Several states require providers to be licensed and place duties on hosts who engage unlicensed providers.
- Prudential outsourcing and service provider management. Material service provider identification, registers and contractual requirements under APRA standards.
- Privacy. Disclosure to a service provider does not transfer obligations, and cross-border disclosure carries additional requirements; see APP 11 reasonable steps to secure personal information.
- Commonwealth procurement. Suppliers to government carry conditions flowing from the procurement framework; see the Commonwealth Procurement Rules.
Offboarding and the exit file
Termination is where supplier compliance obligations are most often dropped. Build an exit checklist and hold the evidence in a single file:
- Access revoked — systems, physical access, credentials, and evidence of revocation with a date.
- Data returned or destroyed — with a certificate of destruction where personal information was involved, and confirmation for subprocessors.
- Records transferred — anything you are required to retain that sits in the supplier's systems, obtained before the relationship ends.
- Outstanding compliance matters closed — open incidents, remediation, unresolved audit findings.
- Surviving obligations identified — confidentiality, retention, insurance run-off, indemnities. These outlive the contract and should be recorded as such.
- Register updated — supplier status changed, tiering removed, calendar reminders retired.
- Lessons recorded — where the exit followed a compliance failure, the root cause belongs in the incident register.
The exit file matters most when a regulator asks about conduct that occurred during the relationship, months after it ended. Everything you did not collect at termination is unavailable by then.
Frequently asked
Does using a contractor transfer the compliance obligation?
No. In Australian regimes the duty generally stays with the entity that holds it. The work health and safety primary duty extends to workers whose activities the business influences or directs; chain of responsibility duties attach to each party across the transport chain; and disclosing personal information to a service provider does not transfer obligations under the Australian Privacy Principles. Engaging a supplier adds a party whose conduct must be managed, rather than removing the duty.
What should a compliance clause say beyond 'comply with all applicable laws'?
It should name the specific regimes relevant to the engagement, give a right to request evidence and to audit on notice, require notification of breaches and regulator contact within a stated timeframe, require consent for subcontracting with flow-down of the same terms, set personnel licensing and screening standards, address data handling and destruction, require insurance maintenance with evidence, and provide step-in or termination rights for compliance failure. A general clause creates a right without visibility.
How should suppliers be tiered?
By compliance exposure and business criticality rather than spend. A supplier is critical if failure interrupts a core service, or if it handles personal information, customer money or safety-critical work — regardless of contract value. Re-tier whenever scope changes, because expanding scope under an existing low-tier contract is the most common way uncontrolled relationships form.
When is a modern slavery statement due?
Entities with annual consolidated revenue of at least $100 million must report, and the statement is due within six months of the end of that entity's own financial year or accounting period, then published on the Modern Slavery Statements Register (checked August 2026). Because the deadline runs from each entity's own year end, there is no single national due date.
What does CPS 230 require in relation to service providers?
APRA-regulated entities must identify material service providers, maintain a register of them, and meet specified contractual requirements for material arrangements. The standard commenced on 1 July 2025, with a transition period to July 2026 for existing material service provider contracts, and APRA finalised targeted amendments introducing limited exemptions from certain contractual requirements in April 2026 (checked August 2026).
What belongs in a supplier exit file?
Evidence of access revocation with dates, data return or destruction certificates including subprocessors, transfer of any records you are required to retain, closure of open incidents and audit findings, an identified list of obligations that survive termination such as confidentiality and retention, updated registers and retired calendar reminders, and root cause notes where the exit followed a compliance failure.
Related
Related reading
Modern Slavery Statement: when each entity's statement is due
Reporting entities under the Modern Slavery Act 2018 (Cth) must publish a statement within 6 months of their reporting period ending. Here's how the calendar works for the common year-ends.
Heavy Vehicle National Law: Chain of Responsibility explained
Under the HVNL, every party in the heavy-vehicle supply chain owes a primary duty to do what's reasonably practicable to ensure safety. Here's who's in the chain and what the duty looks like.
Labour hire licensing in Australia: Victoria, Queensland, South Australia and the ACT
State labour hire licensing schemes, who they apply to, the host obligation not to engage unlicensed providers, and 2025 changes.
Building a compliance obligations register: artefacts, owners and review cadence
What belongs in an Australian compliance obligations register: minimum fields, a named owner per row, review cadence, and the evidence auditors ask to see.
Obligations covered
© Rules Mate · Source citations at the end · Information current as at 28 August 2026
Printed from https://rulesmate.com.au/insights/contractor-supplier-compliance-due-diligence-flow-down