Most businesses run more outsourced processes than they realise. Payroll, IT, plant maintenance, calibration, waste removal, labour hire, training, even the safety audits themselves. Each decision made sense on its own. However, nobody stepped back and asked what happened to the management system once the work left the building.
That is the trap. The activity moves to an external provider, and the paperwork often moves with it. Yet the duty stays exactly where it was. Section 16 of the Work Health and Safety Act 2011 is blunt: a duty cannot be transferred to another person. The same logic runs through ISO 9001, ISO 14001 and ISO 45001. You can outsource the activity. You cannot outsource the outcome.
This week sits alongside Week 38 on contractors and Week 39 on suppliers, but it asks a narrower question. When a whole process your IMS depends on is performed by someone else, how do you keep it inside the system?
What ISO and the WHS Act require of outsourced processes
ISO 9001:2015 covers this in Clause 8.4, control of externally provided processes, products and services. Clause 8.4.1 names outsourcing specifically. Clause 8.4.2 then asks for the type and extent of control, matched to the impact on your customer and legal requirements. In addition, Clause 8.4.3 requires you to tell the provider what you expect before the work starts. That includes competence, monitoring and any verification you plan to do at their premises.
ISO 45001:2018 goes further in Clause 8.1.4.3, Outsourcing. Outsourced functions and processes must be controlled. Moreover, the type and degree of control must be defined within the OH&S management system itself. Similarly, ISO 14001:2015 Clause 8.1 requires outsourced processes to be controlled or influenced. Notice the common thread. All three standards expect you to decide, in writing, how much control each arrangement needs.
The WHS Act then supplies the teeth. Section 19 places the primary duty on the business for every worker it engages, causes to be engaged, or directs. Under section 7, that includes labour hire workers and the employees of your contractors. Section 46 adds the duty to consult, cooperate and coordinate with every other duty holder on the same matter. Consequently, an outsourced process is a shared duty, not a transferred one.
Why outsourced processes quietly break an IMS
Three patterns show up in almost every audit of outsourced processes. None of them involve a bad provider.
First, the process disappears from the system map. The procedure that described it gets retired because nobody internal performs it any more. As a result, the IMS no longer says who owns the outcome or what evidence proves it happened. The auditor asks how calibration is controlled. The honest answer is that a company comes once a year.
Second, the acceptance criteria were never written down. The contract describes the service and the price. It rarely describes the standard the output must meet or the records the provider must hand back. Therefore, verification becomes a matter of trust rather than evidence.
Third, the interface owner is a company name, not a position. The provider changes a method or swaps a technician. Nobody inside the business is accountable for noticing. Meanwhile, the legal duty under sections 16 and 19 has not moved an inch.
Decide the type and extent of control first
Every one of the three standards uses the same phrase: type and extent of control. Treat that as a deliberate decision for each arrangement, and record it. Start by rating two things. How much QHSE risk does the process carry if it fails? And how much of your own legal or customer obligation depends on it?
A payroll provider carries a compliance risk and a data risk, but not a physical one. A labour hire firm supplying plant operators carries a fatality risk and a shared section 19 duty. An outsourced waste contractor carries an environmental duty that, in most states, stays with the generator until lawful disposal is proven. For example, the general environmental duty in Queensland and the waste offences in New South Wales both keep the generator exposed if waste ends up in the wrong place.
Once you have the rating, match the controls to it. Low-risk arrangements need a specification, a signed agreement and an annual review of records. High-risk arrangements need embedded procedures, competency verification, planned observation of the work and a formal periodic review with the provider in the room. In short, the higher the retained duty, the closer the control.
Five controls that keep outsourced processes inside your IMS
The first control is the specification. Write the standard the process must meet into the contract or scope of works. Reference your own procedure where one exists. For a calibration provider that means certificates traceable to national standards, which is what ISO 9001 Clause 7.1.5.2 asks for. For a training provider it means the unit of competency, the assessment method and the record you receive.
The second control is acceptance criteria and evidence. Define what the provider hands back after every job, and who checks it. A service report, a test certificate, a waste tracking docket, a training statement. Then verify a sample, rather than filing everything unread.
The third control is the interface owner. Assign a named position inside your business to each outsourced process. That position receives the evidence, raises the issues and runs the review. Likewise, the provider names a counterpart. The section 46 duty to consult and coordinate now has two real people attached to it.
The fourth control is competency and induction. Where the provider’s people work at your sites or on your plant, they are your workers under section 7. Verify licences before the first shift. Induct them to your site rules. Include them in your consultation arrangements. Labour hire workers in particular must sit inside your hazard reporting and toolbox processes, not outside them.
The fifth control is the review cycle. Every arrangement gets a review frequency, a last-reviewed date and a next-due date. Review performance against the acceptance criteria, incidents involving the provider, and changes to their methods or people. Finally, record the outcome so management review under Clause 9.3 sees the full picture.
Practical Application
Consider an Australian manufacturing business with forty staff and a single production site. Its register of outsourced processes runs to fourteen entries. Labour hire, forklift and racking inspections, electrical test and tag, fire equipment servicing, calibration, waste removal, chemical supply, IT backup, payroll, first aid training, drug and alcohol testing, internal audits, the annual noise survey, and cleaning.
The QHSE Manager rates each one for QHSE risk and retained duty. Labour hire, forklift inspection, electrical test and tag and waste removal all land as high. For each of those, the business writes acceptance criteria into the agreement and assigns a supervisor-level interface owner. It verifies competencies before work starts and sets a quarterly review. For instance, the waste contractor must return a tracking docket for every regulated waste movement. The Production Supervisor checks it against the manifest before filing.
Payroll, IT and cleaning land as moderate or low. Consequently, they get a specification, a signed agreement, an annual records review and an administrative owner. Nothing more, because nothing more is warranted.
Every arrangement carries a Next Review Due date. When the labour hire provider changes its induction method mid-year, the interface owner logs it and reviews the impact. At the next management review, the register shows fourteen arrangements, the control applied to each, two overdue reviews and one provider under corrective action. That is control the auditor can see and the board can trust.
Conclusion
Outsourcing changes who does the work. It never changes who owns the duty. ISO 9001 Clause 8.4, ISO 45001 Clause 8.1.4.3 and ISO 14001 Clause 8.1 all expect you to decide the type and extent of control for each arrangement. Sections 16, 19 and 46 of the WHS Act make that decision a legal one. The fix is a single register of outsourced processes with a deliberate control level, a named interface owner, written acceptance criteria and a review cycle with real dates.
Do that and outsourcing becomes an extension of your IMS rather than a hole in it. The MiSAFE All-in-One QHSE subscription includes configuration of your outsourced process register inside your QHSE platform. It also includes provider evidence uploads, review reminders to interface owners, and performance reporting ready for management review.
Ready to act? Contact us today or book a free 45-minute consultation.
Download the Free Template
Download the free Outsourced Process Register (.xlsx) and put every process an external provider runs for you back under your own control.
Recent Comments