From Paper to Practice: What Contractor Governance Actually Takes
A good governance model can still fail for entirely ordinary reasons. This is the part of the research I think about the most.

The part the diagram doesn't show
By the time I'd finished designing the model in Part 3, I had something that looked complete: risk tiers, a five-phase lifecycle, three lines of assurance, clear ownership. It's the kind of thing that looks finished on a slide. But I've sat through enough safety initiatives to know that a well-designed model and a model that actually survives contact with a live project are two very different things, and the last part of my research was about being honest about that gap rather than pretending it away.
It will look like extra work, because at first, it is
The most immediate resistance I anticipated, and heard echoes of directly in interviews, is that a project team under schedule pressure will experience risk-tiering, formal assurance layers, and lifecycle checkpoints as added complexity, not added value. That reaction is not irrational. From where a project manager sits, mid-delivery, a new governance requirement genuinely does look like one more thing standing between them and the deadline.
Andrew Hopkins has written about exactly this pattern: organizations under pressure tend to comply with the letter of a new system while missing the point of it, especially when the existing arrangement already feels good enough to the people running it (Hopkins, 2019). That's the real risk with a model like this. Not rejection, but a hollowed-out version of it: the paperwork gets done, the tiering gets applied on paper, and none of it changes what actually happens on site. I don't think that risk goes away with good design. I think it only goes away with how the model gets introduced and defended.
It costs real time and real people
The second honest challenge is resourcing. Increased audits, structured assurance activity, lifecycle reviews, and centralized data tracking all require time and competence that doesn't currently exist in most HSE teams, mine included. This isn't a footnote. If a governance model gets approved without anyone seriously accounting for the extra capacity it needs, the most likely outcome is inconsistent application: the tier-one contractors on the highest-profile project get the full treatment, and everyone else gets whatever's left over. That's not a failure of the model, it's a failure of resourcing it honestly from the start.
There's a related, more global version of the same problem. Any organization operating across multiple countries deals with wildly different contractor markets and different access to mature HSE regulation. A model that assumes uniform contractor capability everywhere will break the first time it meets a region where it doesn't hold. Where local regulation is thin or inconsistently enforced, international frameworks like the ILO's database of national occupational safety legislation become a useful baseline (ILO, 2023), but the honest answer is that the model has to flex by region while keeping certain non-negotiables constant everywhere. Deciding which is which is a judgment call, not something the model can settle for you.
The culture question underneath all of it
Here's the thing I keep coming back to, and it's the part of the research that felt least like an academic exercise. None of the structural fixes, the tiering, the lifecycle, the three lines, will hold up on their own if the underlying behavior in the organization doesn't change alongside them. Reason's point about latent organizational conditions applies just as much here as it did to explaining the original gap in Part 1: safety performance is shaped by systemic and cultural factors, not by whether a procedure exists on paper (Reason, 1997).
In practice, that means leaders have to actually demonstrate accountability for contractor safety themselves, not delegate the appearance of it. Governance expectations need to be reinforced consistently, project after project, rather than announced once and left to decay. And when someone deviates from the model, under pressure or otherwise, that has to be addressed directly instead of quietly tolerated because the deadline mattered more that week. A governance model without that behavioral backing isn't really a governance model. It's a document.
What I'd actually tell someone trying to build this
If you're a safety leader looking at something like this and wondering where to start, my honest advice is not to launch it everywhere at once. Pilot it on a small number of projects first, learn what breaks, and adjust before rolling it out more broadly. Roll it into existing processes rather than sitting it alongside them as a parallel system, because a parallel system is exactly what gets treated as optional the first time things get busy. And get visible commitment from senior leadership before you start, not after the first resistance shows up, because that's the moment the model's survival actually gets decided.
I'd also say this plainly: don't expect the case for this to be self-evident to people outside safety. Contractor governance isn't a hard sell on safety grounds, most people already agree it matters in principle. The harder sell is resourcing and patience, because the payoff is largely the absence of a systemic failure you can't point to yet. That's a genuinely difficult thing to build a business case around, and I don't think safety professionals should pretend otherwise.
Where this leaves me
I started this research because a fairly small, nagging observation at work turned into a question I couldn't answer confidently. Two years later, I don't think the answer is that contractor safety is broken anywhere I've looked. I think most organizations, including my own, have built strong operational safety and simply haven't built the governance layer above it yet, largely because nobody was forced to notice the gap until something exposed it.
If there's one thing I'd want another HSE professional to take from this series, it's that the absence of an incident is not the same as the presence of governance. Those are two different questions, and it's entirely possible to be doing well on the first while having no real answer to the second. I didn't have one, before this project. I have a clearer picture now, and I'd rather share the shape of it generally than let it sit in a dissertation nobody outside a university reads.
Sources & Further Reading
- Hopkins, A. (2019). Organisational Culture and Major Hazard Risk: Interpreting Concepts and Practices.
- Reason, J. (1997). Managing the Risks of Organizational Accidents. Ashgate.
- International Labour Organization: NATLEX database of national OSH legislation (2023)
Author: Myaser Ibrahim, MSc Occupational Health and Safety Management, University of Portsmouth.
Last reviewed: August 31, 2026.
Disclaimer: This article reflects personal views and reflections drawn from independent MSc research and does not name, describe, or represent any specific employer. It provides general HSE education and does not replace applicable law, standards, or competent professional advice for your specific operation.