Skip to main content
Create Free Account

Buying & Rollout

How to Transform Your Contractor Management System

Moving off a contractor management system that is not working starts with auditing what the old one was asking for, because migrating a bad requirement list only reproduces it in better software. Migrate contractor identities, in-date documents with real expiry dates, and your live site structure. Leave expired records, dormant contractors and imported statuses behind. Roll out by site or by contractor tier, never everywhere at once, and settle the trigger that ends parallel running before you start it.

  • Published
  • Updated
  • 8 min read
Two workers in yellow hi-vis jackets and white hard hats inside a large industrial shed, looking together at an open laptop held by one of them
Most of the difficulty in replacing a system is a disagreement between departments wearing a data migration costume.

A contractor management rebuild almost never opens with a software problem. It opens with a sentence like “we have the system, it is all in there, and I still cannot tell you who is on site at Rosehill this morning.” The system is not what failed. What failed was the set of decisions underneath it, and if you carry those decisions to a new platform you will be having this conversation again in three years with a different logo on the screen.

So here is the part nobody puts in a proposal: what to move, what to leave, what order, and how to tell whether it worked.

Start With What the Old System Was Actually Asking For.

Before you look at a replacement, export the requirement list from the system you have and read it line by line with the people who own each line. That meeting is the project.

You will find three kinds of entry: requirements somebody can justify in one sentence, requirements that exist because a contractor failed an audit years ago, and requirements nobody in the room can explain at all, usually inherited from a template or a departed manager.

That third group is why the old system is not trusted. Every unexplainable requirement teaches your supply chain that the list is arbitrary, and once they believe that they stop treating any of it as urgent. Migrating those lines into better software gives them a faster way to be ignored.

Rebuild the list from the duty rather than from the export. Section 19 of the model Work Health and Safety Act requires a business to ensure, so far as is reasonably practicable, the health and safety of workers it engages or causes to be engaged.1 Every requirement should trace to that, or to a contractual obligation you can point at. How to set up your own contractor portal covers building the sets themselves, and the build order is the same whether you are replacing or starting.

Decide What to Migrate, and What to Leave Behind.

Migration is not a data problem. It is a decision about what you are willing to stand behind on day one.

Move these:

  • Contractor identities, deduplicated against the ABN. Most old systems carry the same trading entity three times under three spellings.
  • Documents that are in date, each with a real expiry. A document with no expiry is one nobody can act on.
  • The site and project structure as it actually operates, not as the org chart describes it.
  • Records you are obliged to keep. A principal contractor on a construction project must prepare a written WHS management plan before work starts and keep it until the project is complete, and that plan must document the arrangements for collecting, assessing, monitoring and reviewing safe work method statements at the workplace.2

Leave these, deliberately:

  • Expired documents. Keep the full export as an archive; do not load history into a live register where it competes for attention with what is current.
  • Dormant contractors. Set a last-engagement date and be honest about it. Half the list is usually people you have not used in years.
  • Imported statuses. This is the one I would go to the wall over. A status is a claim about the present tense, and one lifted from an old export was true on the day it was taken. Re-derive every status from the documents the new system actually holds.

One warning while you are configuring. In ComplyFlow a document category carries settings that change who is asked for it and when, and changing the project setting after documents have already been provided causes the document to be requested again.3 Get the category definitions right before the load, or your first week is a wave of duplicate requests landing on contractors you have just asked to trust a new system.

Roll Out by Site or by Contractor Tier, Never Everywhere at Once.

There are two sensible orders and one bad one. The bad one is everywhere at once, because the first fortnight surfaces every question your configuration got wrong at the same time, with no way to fix it quietly.

Go by site when your requirements genuinely differ by location, when the gate is where enforcement happens, and when one site manager can own the outcome and be seen to own it. A site rollout gives you a contained population, a visible deadline, and a person whose reputation is attached.

Go by contractor tier when the same national suppliers work across every site and the requirement sets are broadly the same everywhere. Start with the tier you engage most often rather than the one carrying the most risk, because the point of the first wave is to find your own mistakes cheaply.

Most businesses with more than a handful of sites do both: site order on the outside, tier order within each site. What matters is that somebody can say which sites are live and which are not, and that the answer is never “partly”.

Three Teams Want Three Different Things.

This gets called a change management issue and is actually a design decision.

Procurement wants fewer suppliers, faster onboarding, and the commercial position right: the correct entity, the ABN, the insurance at the required sum. Safety wants evidence rather than assurance: the competency of the individual worker, the safe work method statement for the specific job, and a trail that survives an inspector. Operations wants the crew through the gate this morning, and treats all of the above as an obstacle.

All three are right, and the law says so. Section 16 of the model WHS Act says more than one person can concurrently hold the same duty, and section 46 requires each of them to consult, co-operate and co-ordinate activities with the others so far as is reasonably practicable.1 The consultation Code of Practice puts the practical version well: each duty holder should exchange information to find out who is doing what, and work together so risks are minimised.6 Safe Work Australia is blunter still in its construction guidance, which states that a person cannot eliminate their health and safety duties by sub-contracting all or part of the work to another business.5

So the resolution is not to pick a winner. It is one record with three views off it. Give each function its own report, its own dashboard and its own alerts, and refuse the request to give each function its own requirement list, because that is three systems wearing one login.

The move that settles most of these arguments is deciding which team owns each requirement set. In ComplyFlow the sets are already split by audience, with a separate bundle for the supplier company at prequalification, for the individual worker at induction, and per site.4 That split maps onto the three teams almost exactly, so use it as the ownership map rather than inventing one.

Run Both Systems in Parallel, and Name the Trigger That Stops It.

Parallel running is necessary and it is also where these projects go to die, because nobody set the condition that ends it.

Run in one direction only. For any contractor live in the new system, the new system is the source of truth and the old one is read-only for them. Never dual-key the same contractor in both. Once two systems are both authoritative, the answer to “is this crew cleared” is “it depends which screen you are looking at”, which is the problem you started with.

Write the stop trigger down before you begin, and make it a condition rather than a date: parallel running ends when every contractor at the live sites is cleared in the new system and the gate check runs off it. Then the old system goes read-only, and you keep the export for as long as your record-keeping obligations require.

For the last handful who will not move, ComplyFlow lets a staff member with the right permission upload a document on behalf of a supplier, with the category, expiry date and a comment recorded against it.7 Use it as a safety valve for the final stretch rather than a habit, because a record your own team maintains on a contractor’s behalf is one the contractor has no reason to keep current.

Settle one thing with your IT and procurement reviewers early, because it holds up more of these projects than anything technical: where the data lives, and how you would leave. ComplyFlow hosts all data in Australia, has held ISO 27001 certification since 2019, has been GDPR compliant since 2020, completed the AWS Foundation Technical Review in 2023, and publishes a transition out plan alongside its architecture and security documentation.8 Ask any vendor for that last document before you sign; you are currently living through the cost of the last one not having one. Identity and system integration belongs in the same conversation, not a later phase.

Measure the Things That Say It Worked.

Logins are not a measure. Neither is the number of documents held, which mostly measures how much you asked for.

Four numbers tell you the truth:

  1. The share of workers cleared before their first shift, rather than on the morning or afterwards. This is the one the exercise exists to move.
  2. Time from invitation to approval, split by contractor tier. If it is climbing, your review queue is the bottleneck, not your contractors.
  3. Expiries actioned before the date versus after. Almost every emergency here is an expiry that was visible for 11 months and dealt with in the twelfth.
  4. The age of the oldest item in the review queue. One number, and the fastest early warning you will get.

None of these mean anything without a baseline, so take one in the old system before you touch anything. ComplyFlow will export a worker list to CSV with the alerts column showing what is outstanding, which gives you a repeatable snapshot to compare against.9

The numbers are not there to prove the project succeeded. They are there so that when a crew is turned away at the gate in month four, you can tell whether that is the system working or the system failing, because those two look identical from a distance.

The businesses that get this right are not the ones with the cleanest migration. They are the ones who cut the requirement list to what they could justify, gave one team ownership of each part of it, and stopped running two systems on a condition agreed in advance. Do those three things and the rest of workforce compliance becomes maintenance rather than a project.

Sources

  1. Model Work Health and Safety Act, sections 16, 19, and 46 Safe Work Australia, 5 December 2025 edition
  2. Model Work Health and Safety Regulations, regulations 309, 312, and 313 Safe Work Australia, 5 December 2025 edition
  3. Document Categories ComplyFlow Help Centre, 14 November 2023
  4. Onboarding Requirements ComplyFlow Help Centre, Read 12 September 2026
  5. Construction: WHS duties Safe Work Australia, Undated page, read 12 September 2026
  6. Model Code of Practice: Work health and safety consultation, cooperation and coordination Safe Work Australia, July 2023 edition
  7. Uploading Documents on Behalf of Suppliers ComplyFlow Help Centre, 6 May 2025
  8. Platform Architecture and Hosting ComplyFlow Help Centre, 29 August 2025
  9. Checking Compliance Status for all Workers in Bulk ComplyFlow Help Centre, 9 February 2023
Bart Crowther

Written by

Bart CrowtherDirector of Sales, ComplyFlow

Bart leads sales at ComplyFlow and spends his week with the safety, procurement, and facilities teams deciding how to manage contractors. He writes about what buyers ask, and what separates a system that gets used from one that gets ignored.

Writes about: Choosing a compliance system, Rollout and adoption, What buyers ask

Questions

Questions People Ask About This.

What should we migrate from our old contractor management system?

Contractor identities deduplicated against the ABN, documents that are currently in date and carry a real expiry, and the site and project structure as it actually operates today. Everything else is an archive question rather than a migration question. Export the old system in full, keep the export against your record-keeping obligations, and load only what the new system has to act on.

Should we run the old and new systems in parallel?

Yes, but in one direction only. The new system is the source of truth for every contractor who is live in it from day one, and the old one becomes read-only for the rest. Dual-keying the same contractor in both is how a parallel period turns into a permanent second system, and it is the single most common way these projects stall.

Is it better to roll out by site or by contractor tier?

Go by site when your requirements differ by location, when the gate is the enforcement point, and when one site manager can own the result. Go by contractor tier when the same national suppliers work across every site and the requirements are broadly the same everywhere. Most businesses with more than a handful of sites end up doing site order first and tier order inside it.

How do we handle procurement, safety and operations wanting different things?

Do not give each of them a separate requirement list, which is how you end up with three systems inside one. Give them one record and three views off it. Procurement needs the company-level position, safety needs per-worker competency and evidence, and the site needs a yes or no at the gate this morning. All three are answerable from the same data.

How do we know the new system is working?

Take a baseline in the old system before you start, because none of the measures mean anything without one. Then track the share of workers cleared before their first shift, the time from invitation to approval by contractor tier, the proportion of expiries actioned before the date, and the age of the oldest item in the review queue.

See it against your own contractors, sites, and rules.

Book a 30-minute demo. We will show ComplyFlow working with your kind of sites, your kind of contractors, and your requirements. No slides, no hard sell.

  • ISO 27001
  • Hosted on AWS
  • Microsoft & Okta SSO
  • API & MCP
  • Data in Australia

Compliance you can prove, instantly.