IT Brief Australia - Technology news for CIOs & IT decision-makers
Australia
The risk you thought you transferred

The risk you thought you transferred

Fri, 4th Sep 2026 (Today)
Site360
SITE360

Engaging a contractor is, among other things, a risk transfer decision. The work gets done by someone else, and if something goes wrong, the contract says the consequences sit with them. There is an indemnity. There is a requirement to hold insurance to an agreed limit. There is a certificate of currency in the file confirming they do.

It is a sound commercial structure, and it is why the arrangement is attractive in the first place. It is also more conditional than the paperwork suggests, and the conditions are not the ones finance teams usually track.

An indemnity is only as good as what stands behind it

A contractual indemnity is a promise to pay. Whether it is worth anything depends entirely on the counterparty's capacity to honour it, which in practice means their insurer.

That introduces several points of failure that sit outside the contract. A policy can lapse for non-payment. It can be cancelled. It can renew on different terms, with a lower limit, a higher excess, or an exclusion that was not there last year. The work being performed can fall outside the scope of what the policy actually covers, which matters particularly for higher risk activities that insurers treat differently. And the contractor who was assessed may subcontract portions of the work to a party who was never assessed at all.

None of these are exotic scenarios. They are ordinary features of how small and medium contracting businesses operate and how insurance markets behave. What they have in common is that they occur after onboarding, silently, and nothing in a conventional filing process surfaces them.

If the indemnity fails, what remains is a promise from a business that may have no capacity to fund it. Many contracting entities are thinly capitalised by design. The practical answer for organisations engaging contractors at any scale is a contractor management platform that treats insurance and licence currency as a live status rather than a document collected once, because the moment that matters is not the day of onboarding but the day of the incident.

A certificate of currency is a photograph

This is the part worth sitting with. A certificate of currency is evidence of a state of affairs on the date it was issued. It is not a subscription. It does not update, and it does not notify anyone when the underlying policy changes.

An organisation holding a certificate issued in March has evidence about March. It has nothing about November beyond an assumption that nothing changed in the intervening eight months. For a single contractor engaged on a single job, that assumption is usually fine. Across several hundred contractors, engaged intermittently, across multiple sites, over years, it stops being a reasonable basis for a risk position worth millions.

The gap is not a failure of diligence. The check was done properly. It was simply done once, against a fact that does not hold still.

The duty that was never transferable

There is a second issue, and it is more fundamental than the insurance question.

Under Australian work health and safety legislation, a duty cannot be transferred to another person. A business that engages a contractor does not thereby hand over its own primary duty. Both parties hold duties concurrently, and where more than one person has a duty for the same matter, each retains responsibility and must consult, cooperate and coordinate with the others.

This is well understood by safety professionals and less well understood in commercial functions, where the intuition is that engaging a specialist moves the risk to the specialist. Contractually, a good deal of the financial risk can be allocated. The statutory duty cannot be allocated at all.

The consequence is that a principal can be exposed on two fronts simultaneously. The indemnity may fail because the contractor's cover lapsed, and the regulatory exposure was never contingent on the contractor's position in the first place.

Where the exposure actually lands

If a contractor causes loss and their cover has failed, the claim looks for the next available balance sheet. Often that is the principal's own insurance program, which responds with an excess, a claims history, and a conversation at renewal that costs money for years afterwards.

Insurers and brokers are also increasingly interested in how principals verify third-party compliance, because it speaks directly to the quality of the risk they are pricing. An organisation that can demonstrate systematic, ongoing verification of contractor insurance and licensing is presenting a materially different risk to one that can produce a folder of certificates of varying vintage.

For a finance leader, that is a straightforward argument. The verification capability is not only a control against a tail event. It is an input into the cost of the insurance program every year, whether or not anything goes wrong.

What is worth verifying

The questions here are short and answerable.

For every contractor currently engaged, is their public liability and workers compensation cover current today, and how do we know without asking them? Which policies expire in the next ninety days, and what happens when they do? Do the limits we require still match the exposure of the work being performed, or were they set years ago? Where contractors subcontract, do we have visibility of who is actually performing the work? And if an incident occurred tomorrow, how long would it take to establish what cover was in force at that moment?

An organisation that can answer those inside a day has a risk transfer that is likely to hold. One that cannot has a risk transfer it believes in, which is a different thing, and the difference only becomes apparent at the worst possible moment.

The contract allocates the risk. Verification is what makes the allocation real.