Skip to main content
Create Free Account

Contractor Compliance

Site Documents Management: Keeping the Right Version in the Right Hands

Site documents belong to a place rather than a person: the WHS management plan, safe work method statements, permits, plant and chemical registers, safety data sheets, induction records, emergency plans, and traffic management plans. Manage them by attaching 4 things to each one: a currency rule, a version history, a named owner, and the list of people who must be able to read it on site rather than at a desk.

  • Published
  • Updated
  • 10 min read
A man with folded arms and a woman holding a tablet talking beside an office window, the Sydney Harbour Bridge and harbour visible behind them
Site documents are decided in rooms like this one and used somewhere else entirely, which is the whole problem.

Site documents are the ones that belong to a place rather than to a worker or a company. That sounds like a filing distinction and it is not. A worker takes their licence with them; a site keeps its emergency plan whoever is standing on it this morning, and the people who need that plan are almost never the people who wrote it.

Which is why the question that decides whether a site’s documents are managed is not “where are they stored”. It is: which version was in force on the day, who was entitled to read it, and could they actually get to it. Here is how to answer all 3, document type by document type.

What Counts as a Site Document.

The list is more specific than “site paperwork”, and each item has its own rules.

  • The WHS management plan. Required in writing for a construction project, prepared by the principal contractor before the project starts.2
  • Safe work method statements. One for each high risk construction work activity, prepared before the work starts.1
  • Permits to work. Confined space entry permits, energised electrical work permits, and the risk assessments behind them.1
  • The plant register and its inspection records. Tests, inspections, maintenance, commissioning, decommissioning, dismantling, and alterations for plant required to be registered.1
  • The hazardous chemicals register and its safety data sheets. A list of every hazardous chemical used, handled, or stored at the workplace, with the current safety data sheet for each one.1
  • The asbestos register and asbestos management plan, where asbestos is identified or likely to be present.1
  • Induction records, general and site-specific.2
  • The emergency plan and its evacuation arrangements.1
  • Traffic management plans, which Safe Work Australia treats as an administrative control and lists among the things a WHS management plan may cover.2
  • The site diary. Worth naming for what it is not: neither the model Act nor the model Regulations require one or set a retention period for it. It is a contractual and evidentiary habit, not a statutory duty, and it should be kept for the reasons a contract gives you rather than because a compliance list said so.

The WHS management plan is the one most often treated as a formality, so it is worth saying what has to be in it: the names, positions, and health and safety responsibilities of people with specific responsibilities; the arrangements for consultation, cooperation, and coordination; the arrangements for managing incidents; site-specific health and safety rules and how people will be told about them; and the arrangements to collect, assess, monitor, and review safe work method statements.2

The Version Question Gets Asked After the Incident.

This is the spine of the whole subject. Nobody asks which revision of a method statement was current while work is going well. It is asked by an inspector, an insurer, or a lawyer, months later, about one particular morning.

The law is built around that moment. A safe work method statement must be kept until the high risk construction work it relates to is completed, and if a notifiable incident occurs in connection with that work, for at least 2 years after the incident. The WHS management plan works the same way: kept until the project is complete, and at least 2 years after a notifiable incident.1 Section 38 of the model Work Health and Safety Act separately requires a record of the notifiable incident itself to be kept for at least 5 years from the day the regulator is notified.4

Safe Work Australia’s construction code adds the line that settles the argument in practice: where a safe work method statement is revised, every version should be kept.2 A folder cannot do that, because saving a new file over an old one is what a folder is for.

What answers the question is a superseded version that is still readable, with a date and a person against it. In ComplyFlow, superseding a site document uploads the replacement, increments the version number automatically, and leaves every earlier version readable under the document’s history.3 The mechanism is unremarkable. Having it is the difference between an answer and a reconstruction.

Currency Rules Differ by Document Type.

There is no single retention period for site documents, and any advice that gives you one is wrong. These are the rules I would write on the wall, each from the regulation that sets it.

  • Safe work method statement. Until the work is complete; at least 2 years after a notifiable incident. Reviewed and revised whenever the control measures are revised. Work must stop if it is not being carried out in accordance with the statement, and resume only in accordance with it.1
  • WHS management plan. Until the project is complete; at least 2 years after a notifiable incident. Reviewed by the principal contractor to keep it current.1
  • Confined space entry permit. At least until the work it relates to is complete. The risk assessment behind it runs longer: at least 28 days after the work is completed. Both go to at least 2 years if a notifiable incident occurs.1
  • Energised electrical work. The same shape: the risk assessment for at least 28 days after the work, the method statement until the work is complete, both to 2 years after a notifiable incident, and the statement readily accessible to any worker doing that electrical work.1
  • Registered plant records. For the whole period the plant is used, or until you relinquish control of it.1 Not a fixed number of years; a decade of history on a single item is normal.
  • Safety data sheets. The current sheet must be obtained no later than when the chemical is first supplied to the workplace, and the manufacturer or importer must review it at least once every 5 years. A chemical counts as first supplied if it is the first supply to that workplace for 5 years, which is how a shelf of old sheets quietly goes stale.1
  • Asbestos management plan. Reviewed at least once every 5 years, and sooner if the register or a control measure is reviewed, or asbestos is removed, disturbed, sealed, or enclosed.1
  • General construction induction. Not a retention rule but a currency rule, and the one most often missed: a worker who completed the training more than 2 years ago and has carried out no construction work in the 2 years since must be trained again.2

Set those side by side and the pattern is clear. Almost every period is defined by an event rather than a calendar: when the work finishes, when an incident happens, when control changes hands. A system that only understands expiry dates will handle the safety data sheets and miss everything else.

Available at the Point of Use, Not on a Server.

A document nobody can reach is not a control. Safe Work Australia is unusually practical here: if a safe work method statement is not kept at the workplace, it should be stored at a location from which it can be delivered to the workplace quickly, and it may be kept electronically.2 The code on managing risks adds that everyone in the workplace should know which records are accessible and where they are kept.9

Several documents carry an explicit access duty rather than a storage duty. The current safety data sheet must be readily accessible to any worker using, handling, or storing the chemical and to an emergency service worker likely to be exposed. The hazardous chemicals register must be readily accessible to workers involved and to anyone else likely to be affected. The emergency plan must provide for effective communication between the person coordinating the response and everyone at the workplace.1 For the WHS management plan, the principal contractor must take reasonable steps to make every person doing construction work aware of its content and of their right to inspect it at any time, by giving subcontractors a copy, displaying it on site, or handing each worker one.2

None of that is satisfied by a corporate login on a laptop in a demountable. The honest test is a person standing at a gate at 6am, on a phone, possibly with one bar of signal. That is why site access and document delivery belong together: ComplyFlow lets a site document be set to display at sign-in, so a contractor scanning a QR code sees the documents for that location as part of signing on, rather than being told where they are filed.5

Who Owns Each Document, and Why One Shared Drive Never Works.

The reason a single folder never holds a site together is not size. It is that the documents belong to different parties, and the duty follows the party.

The principal contractor prepares and keeps the WHS management plan. Each business carrying out high risk construction work prepares its own safe work method statement and must give the principal contractor a copy before the work starts, and the principal contractor must take all reasonable steps to obtain it.1 The person with management or control of the workplace prepares and keeps the asbestos register, and must make it readily accessible to workers, to health and safety representatives, and to any business that carries out or intends to carry out work there, with a copy given to anyone whose work involves a risk of exposure to airborne asbestos.1

Read that last duty carefully. It is not a courtesy extended to a subcontractor. It is an access obligation owed to another business, which means the register has to be shareable outside your own organisation without handing over everything else on the drive.

That is the real design requirement. A site document needs a named owner, a category, and its own visibility rules. In ComplyFlow the person who uploads a document becomes its default owner, documents are hidden from contractors unless you choose otherwise, and access can be restricted to particular staff categories for anything sensitive.68 Plant documents work the same way at the asset level, requested against the plant category with their own expiry dates and approvers.7 On a construction site with 40 subcontractors, per-folder permissions are simply the wrong shape for the duty.

What Happens After the Job Finishes.

Most of the mistakes I see happen here, because attention leaves a site the week the work does.

Three things should happen at handover. The event-based clocks start: a safe work method statement can be closed out once the work is complete unless a notifiable incident attaches to it, and the 2-year and 5-year clocks then run from the incident, not from the job. Plant records run with control of the plant, kept for as long as it is used or until the person with management or control relinquishes it. And a person relinquishing management or control of a workplace must ensure, so far as is reasonably practicable, that the asbestos register is given to whoever takes over.1

The failure mode is a project folder archived whole, then forgotten, with a live retention obligation buried in it and nobody named against it. Archive by document, with its period and its owner attached, and a project closure becomes a tidy-up rather than a liability.

One Site, Four Questions, Answered From What You Hold.

Pick one active site and answer 4 questions about it, using only what you could produce today.

Can you show the version of the method statement that was in force on a nominated date 3 months ago, with the date it was superseded. Can a subcontractor’s supervisor reach the emergency plan and the asbestos register from a phone at the gate. Does every site document have a named owner who is still employed. And for each one, can you say which event, not which date, ends its retention period.

Most sites fail on the first and the last. The fix is not a bigger drive; it is attaching the currency rule, the version history, the owner, and the audience to the document itself, which is what site documents in ComplyFlow does, alongside digital permits for the permits and plant and equipment for the asset records.

If the question behind yours is why a folder cannot do this at all, read what a compliance document management system does that a shared drive cannot. If it is about the documents that belong to a person rather than a place, what employee records you must keep and for how long has the periods. And if safe work method statement review is the specific thing eating your week, the SWMS review bottleneck is about exactly that.

Sources

  1. Model Work Health and Safety Regulations Safe Work Australia, 5 December 2025
  2. Construction Work: Code of Practice Safe Work Australia, November 2024
  3. How to Supersede Site Document ComplyFlow Help Centre, 6 May 2025
  4. Model Work Health and Safety Bill Safe Work Australia, 5 December 2025
  5. Site Document Advanced Settings (including Live Access) ComplyFlow Help Centre, 7 May 2025
  6. How to Upload Site Document ComplyFlow Help Centre, 6 May 2025
  7. Plant and Vehicle Documents ComplyFlow Help Centre, 24 July 2025
  8. Site Document Permissions and Feature Overview ComplyFlow Help Centre, 9 June 2026
  9. How to manage work health and safety risks: Code of Practice Safe Work Australia, November 2024
Mitchell Bourne

Written by

Mitchell BourneManaging Director, ComplyFlow

Mitch has run ComplyFlow since 2009 and has spent that time inside the contractor, site, and safety problems of Australian operators. He writes about where compliance actually fails, and what the people responsible for it can do about it.

Writes about: Contractor compliance, WHS duty and proof, Running a compliance program

Questions

Questions People Ask About This.

What are site documents?

The documents that belong to a place rather than to a worker or a company. On a typical Australian site that means the WHS management plan, safe work method statements, permits to work, the plant register and its inspection records, the hazardous chemicals register and its safety data sheets, induction records, the emergency plan and evacuation diagrams, traffic management plans, the asbestos register, and the site diary.

How do I prove which version of a document was in force on a given day?

By keeping every superseded version with the date it was replaced, rather than overwriting the file. Safe Work Australia's construction code says that where a safe work method statement is revised, every version should be kept. A version history that records who replaced what and when is what answers the question months later, when an investigator asks it.

How long do site documents have to be kept?

It depends entirely on the document. A safe work method statement and a WHS management plan are kept until the work or project is complete, and for at least 2 years after a notifiable incident. A confined space risk assessment runs to at least 28 days after the work. Records for registered plant run for as long as the plant is used. A notifiable incident record runs at least 5 years.

Who owns site documents when several companies work on one site?

Different parties own different documents, which is why one shared drive never works. The principal contractor prepares the WHS management plan. Each business carrying out high risk construction work prepares its own safe work method statement and gives the principal contractor a copy. The person with management or control of the workplace keeps the asbestos register and the chemicals register.

Do site documents have to be available on site?

They have to be readily accessible to the people who need them, which is not the same as stored somewhere. Safe Work Australia says a safe work method statement not kept at the workplace should be stored where it can be delivered to the workplace quickly, and that it may be kept electronically. The practical test is whether a supervisor at a gate can open it.

See it against your own contractors, sites, and rules.

Book a 30-minute demo. We will show ComplyFlow working with your kind of sites, your kind of contractors, and your requirements. No slides, no hard sell.

  • ISO 27001
  • Hosted on AWS
  • Microsoft & Okta SSO
  • API & MCP
  • Data in Australia

Compliance you can prove, instantly.