Building a Contractor Governance Model: Risk Tiers, Lifecycle, and Assurance
The model isn't a new safety program. It's a way of connecting the safety work that already exists, so risk, ownership, and oversight finally line up.

Not a new program, a missing layer
Parts 1 and 2 of this series set up the problem: contractor safety that's operationally solid but structurally ungoverned, and seven specific gaps that kept surfacing in the research regardless of who I asked. The natural next question is what you actually do about it, and that's what the second half of my MSc project was for: designing a contractor governance model as a direct response to those findings, not as a theoretical exercise sitting next to them.
The most important design decision I made early on was that this couldn't be a new standalone safety program. Organizations like mine don't need more processes bolted onto an already busy site. What was missing was a layer that connects the processes that already exist, pre-qualification, risk assessment, site supervision, incident investigation, into something that behaves like a system instead of a collection of separately maintained habits. That framing owes a lot to ISO 45001's emphasis on risk-based thinking applied to how an organization manages its external providers, not just its own workforce (ISO, 2018).
Six principles instead of one big idea
Rather than one clever mechanism, the model rests on six design principles, each one answering directly to one of the gaps from Part 2. Risk-based governance means the depth of oversight scales with actual hazard exposure, not a flat process applied to everyone equally. Clear accountability means roles are explicitly assigned across functions instead of left to be worked out informally on each project. Separation of execution and oversight means the people delivering the work are not also the sole check on whether it's safe. Lifecycle integration means governance travels with the contractor from selection through close-out, not just through the construction phase. Integration with existing standards means the organization's own critical safety rules, whatever they're called locally, get built into pre-qualification and monitoring rather than living in a separate document nobody cross-references. And continuous learning means contractor performance data actually gets tracked centrally, instead of evaporating at the end of each project.
None of these six ideas are individually radical. What they do together, when actually connected, is close the specific gap between how the organization thinks it's managing risk and how it's actually distributing attention.
Sorting contractors by what they're actually doing
The risk-tiering piece is probably the simplest part of the model to explain and the one I think matters most. Instead of one pre-qualification process applied uniformly, contractors get classified into three tiers based on the risk of the work itself.
Tier one covers the highest-risk activities: heavy mechanical lifting, confined space entry, high-energy systems, commissioning work. These contractors go through enhanced, capability-based pre-qualification, have their competency validated for key roles before they start, get audited more frequently, and sit under direct oversight from both operations and HSE. Tier two covers medium-risk work like general installation and maintenance, with a standardized pre-qualification process, a defined supervision structure, and periodic audits rather than continuous direct oversight. Tier three covers limited-scope, low-hazard activities, where the governance requirement is basic compliance checking and nothing more elaborate than that.
The point isn't to make the process heavier everywhere. It's the opposite: concentrating real governance effort where the consequences of getting it wrong are actually severe, and not spending the same effort on work where they aren't. A uniform process either over-governs low-risk work or under-governs high-risk work, usually both at once, and tiering is the mechanism that fixes that misalignment.
Governance that doesn't stop at handover
To address the lifecycle gap from Part 2, the model tracks contractors through five phases rather than treating "onboarding" as the only governance moment that matters. Pre-qualification and selection is where risk tiering and capability assessment happen. Contracting and planning is where HSE requirements and the organization's conduct standards get built into the actual agreement, not just referenced. Mobilisation and execution is where competence gets verified on arrival, onboarding happens properly, and supervision is established. Monitoring and assurance covers the ongoing audits, inspections, and performance reviews while the work is underway. And review and close-out is where the contractor's safety performance actually gets formally evaluated and the lessons get captured, rather than the relationship just quietly ending when the invoice is paid.
The phase that most organizations underinvest in, based on what I found in the research, is the transition into commissioning and outage work. That's exactly where the lifecycle model is meant to keep governance active instead of letting it taper off once the main construction phase looks done.
Three lines instead of one
The assurance gap from Part 2, where the people delivering the work were often the same people checking whether it was safe, gets addressed through a three-line structure. The first line is operational execution: daily site supervision, toolbox talks, immediate hazard control, run by the project team. The second line is HSE oversight: independent auditing, compliance verification, and performance monitoring run by the safety function rather than the project team. The third line is organizational assurance: higher-level corporate or internal audits that check whether the whole governance system, not just one project, is actually working.
What this structure buys you is real independence at each level, rather than assurance that quietly reports to the people it's supposed to be checking. It's a standard internal-audit concept borrowed into a safety context, and it works for the same reason it works in finance: the person checking the control can't also own the control.
Who owns what
The last piece is a straightforward allocation of responsibility across four groups. Supply chain owns contractor selection and commercial terms. Operations owns execution and day-to-day supervision. HSE owns independent oversight and assurance, the second line described above. And senior management owns governance review and accountability at the organizational level, closing the visibility gap that Part 2 described, where leadership was seeing summaries rather than patterns.
Writing this down explicitly sounds almost too simple to matter. In practice, the ambiguity in Part 2 wasn't caused by anyone disagreeing about these roles in principle. It was caused by nobody ever writing them down clearly enough that a disagreement could even surface. Explicit allocation doesn't invent new authority, it just stops authority from defaulting to whoever's most present in the room.
What the model doesn't solve on its own
I want to be honest about something here: none of this works just because it's well designed on paper. A risk-tiering model, a lifecycle map, and a three-line assurance structure are all necessary, but they're still just architecture. Whether an organization actually adopts them, resources them, and defends them under schedule pressure is a separate question entirely, and it's the one I spend the most time on in Part 4.
Sources & Further Reading
Author: Myaser Ibrahim, MSc Occupational Health and Safety Management, University of Portsmouth.
Last reviewed: August 31, 2026.
Disclaimer: This article reflects a personal governance model and views developed through independent MSc research and does not name, describe, or represent any specific employer. It provides general HSE education and does not replace applicable law, standards, or competent professional advice for your specific operation.