Capptions
Back to blog

Contract Compliance Audit: Managing Contractor Risk at Seveso

July 13, 2026

A contract compliance audit checks whether the parties to an agreement are actually doing what the agreement says. On a Seveso or BRZO-classified site, that question isn't only commercial - it's a safety question. Contractors and subcontractors working on or around major-hazard installations are bound by safety obligations written into their contracts: competency requirements, permit-to-work procedures, PPE standards, incident-reporting duties, training prerequisites. When those obligations aren't being met, the gap doesn't show up as a billing dispute. It shows up as someone without the right training standing next to a process they don't fully understand.

This is where contract compliance overlaps directly with your veiligheidsbeheersysteem (VBS) - the Seveso III-mandated safety management system built around seven Annex III elements. Contractor management sits mainly under element (a), organization and personnel, but it also touches element (c), operational control, since most day-to-day work on safety-critical equipment is carried out by contractors, not direct employees.

What a Contract Compliance Audit Covers on a Major-Hazard Site

A generic contract audit looks at three things: financial terms (do invoices and payments match the agreement), operational terms (is the work delivered to spec), and legal terms (does the contract comply with applicable law). On a Seveso site, a fourth layer sits on top of all three: safety compliance - the clauses requiring a contractor to meet the site's safety standards, not just deliver the contracted scope.

That means the audit has to check things a standard commercial review wouldn't think to look for:

  • Are the workers on site the ones who actually hold the certifications listed in the contract, or has the contractor swapped in less-qualified staff without notice?
  • Is the subcontractor chain disclosed? A prime contractor bringing in a subcontractor without the site's knowledge is a compliance gap even if the subcontractor's work itself is fine - the site never got the chance to vet them.
  • Are permit-to-work and lockout/tagout procedures followed as written, or as a shortcut version that gets the job done faster?
  • Does incident and near-miss reporting from contractor personnel actually reach the site's log, or does it stay inside the contractor's own internal system?

Why This Matters More With Contractors Than With Direct Employees

Direct employees sit inside your training records, your induction process, and your day-to-day supervision. Contractors - especially subcontractors two or three layers removed from the prime agreement - don't. A site can run an excellent internal safety culture and still carry a blind spot at the contractor boundary, simply because the visibility that exists for employees doesn't automatically extend to everyone wearing a hard hat on site that day.

Regulators know this. When DCMR or the Nederlandse Arbeidsinspectie inspect a Seveso site, contractor management is a standard line of questioning: can you show that everyone working on safety-critical systems was competent, authorized, and covered by a current contract specifying the safety obligations they were bound by? "We assumed the contractor handled it" doesn't hold up as an answer.

Key Components of a Contractor Compliance Audit

Contract review. Confirm the safety clauses are actually in the contract - not just referenced as "contractor shall comply with site safety rules," but specific: which procedures, which training, which reporting obligations, which escalation path if something goes wrong.

Competency and certification checks. Cross-reference the people actually on site against the certifications and training the contract requires. This is the check most likely to fail quietly - a contractor's workforce turns over and the paperwork doesn't always keep pace.

Subcontractor transparency. Verify the full chain of who's doing the work, not just who signed the prime contract. Undisclosed subcontracting is one of the more common ways a compliance gap enters a site unnoticed.

Operational adherence. Spot-check whether permits, isolations, and access controls are followed as documented, using the same inspection and audit tools used for internal operations - not a separate, lighter process for contractors.

Incident and near-miss integration. Confirm contractor-reported incidents flow into the same log as everything else on site. A contractor incident that never reaches the site's central record can't feed the trend analysis your VBS monitoring (Annex III element g) depends on.

Preparing for the Audit

Start by pulling every active contract touching safety-critical work and confirming the safety clauses are current - contracts renewed or extended without review can quietly drift out of date with actual site procedures. Next, set the audit scope: which contractors, which sites or installations, what time period, who conducts the review. Then build the evidence checklist - training records, permit logs, incident reports, subcontractor disclosures - so the audit is a structured comparison against that checklist rather than an open-ended search.

Conducting and Reviewing the Audit

Work through each contract systematically: obligation stated, evidence gathered, gap identified or not. Document findings as you go rather than reconstructing them afterward. Once the review is complete, findings should go back to both the contractor and the internal team managing that relationship, with a clear owner and deadline for closing any gap - the same corrective-action discipline your VBS already applies to internal findings.

Best Practices

Audit contractor compliance on a schedule, not only when something goes wrong - by the time an incident forces the review, the gap has already cost you. Involve the people who supervise contractors day to day, not just procurement or legal, since they're the ones who notice when practice has quietly diverged from paperwork. Keep audit criteria consistent across contractors so results are comparable, and keep the evidence in the same system used for internal inspections and audits - a contractor compliance record living in a separate spreadsheet is a record that won't be found when an inspector asks for it.

Where This Fits Your VBS

Contract compliance auditing isn't a side process to your safety management system. For any site that relies on contractors for safety-critical work, it's part of demonstrating the system runs as designed, not just that it exists on paper. For a broader look at why standard safety management software often can't carry this kind of Seveso-specific requirement, see why generic safety management software falls short for Seveso III companies.

Capptions supports this with custom inspection and audit workflows, corrective-action tracking that assigns owners and deadlines, and the Clara AI assistant to help structure and surface findings - so contractor compliance evidence lives in the same system as the rest of your VBS, not in a folder that only gets opened before an audit.