What this is
What is a vendor and contractor register?
What is a vendor and contractor register?
It is the single list of every external organisation you trade with or admit to site, each with an identifier, a type, a risk tier, an approved scope and an approval state. It is master data rather than an event record: one row per organisation, maintained for as long as the relationship exists. Prequalification questionnaires, insurance certificates, audits, permits and performance scorecards all hang off that row rather than duplicating it.
How is a register different from an approved vendor list?
The register holds everyone, including the suspended, the expired and the historic. An approved vendor list is a view of the register filtered to those currently permitted to work, in a stated scope. Confusing the two is the origin of most register problems: teams delete or overwrite rows to keep the list clean, which destroys the history you need when an incident is investigated two years later.
Who owns the register?
Procurement or an administrator maintains the rows, but they cannot own the approval state, because approval is a judgement about safety, quality and legal exposure. Practically the row is maintained centrally while the authority to set it to approved, suspended or expired sits with the function that carries the risk. A register where the buyer can approve their own vendor is not a control.
Scope
When is a vendor and contractor register required?
This register is foundation master data, and its most common misuse is being asked to carry the evidence rather than to index it. Prequalification answers, insurance certificates, audit findings and performance scores each have their own template; the register holds the identity, the tier, the scope and the current state.
Use this template when
- A workspace is being set up and the external organisations already in use need to exist as rows
- A new supplier, contractor, haulier, laboratory or agency is about to be engaged for the first time
- An existing vendor's legal entity, scope, risk tier or approval state has changed
- A relationship is ending and the row must be moved out of the approved population without being deleted
- A downstream record needs the vendor to exist before it can be raised: a permit, an order, an induction or an insurance review
Do not use it for
- Recording the prequalification answers themselves, which belong in Contractor Prequalification Questionnaire (CON-001) and Supplier Questionnaire (QUA-039) where they can be scored and re-run
- Holding the approval decision and its evidence, which belong in Supplier Approval Record (QUA-038) and Contractor Approval Record (CON-004)
- Tracking insurance certificates and their expiry, which belong in Insurance Certificate Record (CON-020) and Insurance Adequacy Review (CON-022)
- Listing the individual workers a contractor sends, which belongs in Contractor Worker Register (CON-009) and Contractor Competency Verification (CON-010)
- Recording customers, which belongs in Customer Register (FDN-021), and internal departments, which are not external providers at all
Compliance mapping
Which ISO 45001 cl.8.1.4 requirements does this satisfy?
Regulation almost never names a vendor register, and almost always requires what one produces: criteria applied before engagement, information exchanged with the other duty holder, and records showing both. The register is the artefact that makes those duties auditable rather than anecdotal.
| Clause | Requirement | Where it lands |
|---|---|---|
| ISO 45001 cl.8.1.4.1 | Procurement processes established to ensure conformity of purchased products and services with the management system | Approval and review |
| ISO 45001 cl.8.1.4.2 | Procurement coordinated with contractors to identify hazards and control the risks arising from their activities, and from theirs on your workers | Identification |
| ISO 45001 cl.8.1.4.3 | Outsourced functions and processes controlled, with the type and degree of control defined | Identification |
| ISO 9001 cl.8.4.1 | Criteria for evaluation, selection, monitoring of performance and re-evaluation of external providers, with documented information retained | Approval and review |
| ISO 9001 cl.8.4.3 | Requirements communicated to the external provider, including competence, interaction and control to be applied | Contact |
| OSHA 1910.119(h)(2) | Host employer to obtain and evaluate information on a contract employer's safety performance and programmes before selection | Approval and review |
| 21 CFR 117.420 | Receiving facility to approve suppliers before receiving raw materials, and to document the approval | Approval and review |
| BRCGS Food Safety cl.3.5.1 | Documented supplier approval and ongoing monitoring procedure based on risk, covering raw material and packaging suppliers | Identification |
What it does not cover
- Prequalification, which needs a questionnaire that is answered, scored and re-run on a cycle, not a tier chosen by the person creating the row.
- Insurance verification, which requires the certificate itself, a check that the cover and limits suit the work, and an expiry that is monitored independently of the approval date.
- Worker-level competency and induction, which attaches to named individuals; an approved company is not an inducted crew.
- The contract, indemnities and service levels, which live in Indemnity and Contract Record (CON-024) and Service Level Agreement Record (CON-042); the register's uploaded contract document is a copy, not the obligation.
- Supply-chain human rights and modern slavery due diligence, which requires the assessment in Modern Slavery and Labour Standards Assessment (CMP-042) and reaches beyond your direct provider.
Global
Vendor and Contractor Register requirements by country
No jurisdiction mandates the register as a document. Several mandate the duties it evidences, and they diverge on how far your responsibility extends into another employer's workforce.
OSH Act multi-employer citation policy; 29 CFR 1910.119(h); 21 CFR 117 subpart G
Controlling and host employers carry duties for hazards affecting another employer's workers, and PSM covered processes require documented evaluation of contract employers.
A host can be cited for a contractor's exposure it could reasonably have prevented, so evidence of what you knew about the contractor before engagement is a defence, not paperwork.
CDM 2015 reg.8; Management of Health and Safety at Work Regulations 1999, reg.11
Appointments may only be made where the appointee has the necessary skills, knowledge and experience, and employers sharing a workplace must co-operate and co-ordinate.
The client must be able to show how it satisfied itself of competence before appointment, which is exactly the record a register indexes.
Framework Directive 89/391/EEC art.6(4); Construction Sites Directive 92/57/EEC
Where several undertakings share a workplace, employers must co-operate, co-ordinate protective measures and inform each other of risks.
The exchange has to be two-way and evidenced, so a register that records only what you demanded of them misses half the duty.
Provincial OHS legislation with prime contractor duties; Canada Labour Code Part II
On multi-employer workplaces one party is designated prime contractor and carries co-ordination duties for everyone on site.
Whoever holds prime contractor status needs a current, accurate list of who is on site and in what scope, which makes register drift a legal exposure rather than an administrative one.
Model WHS Act ss.19 and 46
A PCBU's primary duty extends to workers whose activities it influences or directs, and duty holders must consult, co-operate and co-ordinate with each other.
Engaging a contractor does not transfer the duty, so the register has to support co-ordination during the work and not just selection before it.
ISO 45001 cl.8.1.4; ISO 9001 cl.8.4
Management system requirements for procurement, contractors, outsourcing and the evaluation and re-evaluation of external providers.
Certification auditors sample the register against live site activity, and a row for a contractor working today with no approval evidence is a straightforward nonconformity.
How to complete it
How to complete a vendor and contractor register, step by step
Creating a row takes two minutes and the form prompts for almost everything it needs. What decides whether the register is defensible is a set of judgements the fields do not ask about.
Approved Scope is optional in the form and is the field that carries the whole meaning of approval. Write it as the work the vendor may do, in the language a supervisor would use at the gate, and accept that this defines what they may not do. A scope reading general maintenance authorises everything and controls nothing, which is why the first question after a contractor incident is always what scope they had been approved for.
Every register drifts in one direction, because progress states advance and nobody advances a vendor into trouble. Decide now who can suspend a row, on what evidence, and what happens to the work already scheduled against it. A register with no suspension path will keep presenting a vendor as usable through an insurance lapse, a failed audit and a fatality investigation, because there is no value the form allows you to set.
Risk Tier drives induction depth, audit frequency and supervision, so it must reflect the hazard of the work on your site rather than the size of the company or the value of the spend. A one-person roofing firm on a live production roof outranks a national stationery supplier on every axis that matters. Where a vendor holds several scopes, tier the highest-hazard one and say so in the notes.
Offboarding is a data act as much as a commercial one: the row moves out of the approved population, the approval expiry is set, access is revoked and the history stays readable. Deleting the row instead breaks every finished record that pointed at it and removes the evidence that the relationship was ever controlled. The register's value in an investigation is the state it was in on the day, not the state it is in now.
What auditors find
Most common vendor and contractor register findings
Vendor register findings are rarely that the register is absent. They are that it does not describe the population currently on site, and that the approval state it publishes is not one anybody maintains.
| Finding | Clause | What fixes it |
|---|---|---|
| Contractor working on site with no row in the register, engaged directly by an operational department. | ISO 45001 cl.8.1.4.2 | Route every engagement through a purchase or access step that requires an existing row, so no gate pass exists without one. |
| Approval Expiry passed while the vendor continued to work and hold site access. | ISO 9001 cl.8.4.1 | Drive access suspension from the expiry date rather than from a person noticing, and review before the date, not after. |
| Approved Scope blank or generic, so no boundary exists on what the vendor may be asked to do. | ISO 45001 cl.8.1.4.3 | Make scope mandatory and write it as permitted work, then check it at permit issue rather than at approval. |
| Several rows exist for the same legal entity under variant names, with different states. | ISO 9001 cl.8.4.1 | Deduplicate against the business number and ERP vendor number, then enforce uniqueness on the entity, not the display name. |
| Risk Tier assigned but nothing downstream differs between tiers. | ISO 45001 cl.8.1.4.3 | Bind tier to induction depth, audit frequency and supervision, and publish the mapping so the tier is a decision. |
| Approval recorded with no evidence behind it: no questionnaire, audit or safety performance information. | OSHA 1910.119(h)(2) | Require the approval record and its supporting assessment to exist before the row may be set to approved. |
| Approved By names the buyer who requested the vendor, not an independent approver. | ISO 9001 cl.8.4.1 | Separate requester from approver in the workflow, and restrict who may change the status field. |
| Register still lists vendors that stopped trading years ago, and no evidence of re-evaluation for those that remain. | ISO 9001 cl.8.4.1 | Run a periodic re-evaluation of the active population and retire the rest with a dated state change. |
| Subcontractors used by an approved contractor are not in the register and were never assessed. | ISO 45001 cl.8.1.4.3 | Require a subcontractor declaration before work and register each entity that will be on site. |
| Performance history, violations and incidents are not reflected in the vendor's state or tier at re-award. | ISO 9001 cl.8.4.1 | Feed scorecards, corrective requests and incidents into the re-evaluation, and record the tier change they produce. |
Case in point
Case in point: the contractor that existed three times
A manufacturer with four plants held its vendor register centrally. A mechanical contractor had been set up separately by three of the plants over six years, as ABC Mechanical Ltd, ABC Mechanical and A B C Mechanical Services, each with its own identifier, its own primary contact and its own approval date. The business number field was blank on two of them and the ERP vendor number on one.
After a hot-work fire at the second plant, that plant suspended the contractor: the row it had created was set to a non-usable state and site access was revoked. Nine days later the same crew was working under permit at the third plant, selected from the vendor picker without difficulty, because the picker showed the third plant's row, which was untouched and still current. Nobody had lied and no control had been bypassed. The suspension had been applied to a row rather than to an organisation.
The corrective action was not more diligent suspension. It was making the legal entity the key: deduplicating on business number, enforcing uniqueness at creation, and moving the ability to change approval state out of the plants and onto the function that carried the risk. The register had been treated as each plant's address book, and an address book cannot carry a suspension.
The template
The template, field by field
The form exactly as it installs. Every field, option, score and conditional rule is editable, and the links to other templates come with it.
3 sections
- Reference
- FDN-005
- Archetype
- Register
- Record ID
- VEN-2026-000
- Scoring
- None
- Direction
- n/a
- Singleton
- Yes
- Basis
- ISO 45001 cl.8.1.4
- Links
- Referenced by KnowContractor, KnowQuality
- Tags
- Master data
- Sections
- 3
- Fields
- 18
- Follow up fields
- 0
- Repeating sections
- 0
- Links out
- 0
Identification
6 fieldsVendor ID*
Format VEN-0000.
The record's own ID. Other templates point at this value.
Status*
Only Approved vendors appear in Pick Lists.
Vendor Name*
This is what Pick Lists display.
Vendor Type*
Supplier, contractor, service provider, waste carrier or transport.
Risk Tier*
Drives induction depth, audit frequency and supervision.
- Low3 pts
- Medium2 pts
- High1 pt
- Very high0 pts
Approved Scope
What they are approved to do, and by implication what they are not.
Contact
6 fieldsPrimary Contact Name*
Contact Email*
Contact Phone*
Address
Business Number
ERP Vendor Number
Links to External system reference
Approval and review
6 fieldsApproval Date
Approval Expiry
Access is suspended when this lapses.
Last Audit Date
Approved By
Contract Document
Notes
FDN-005 · record IDs look like VEN-2026-000 · Referenced by KnowContractor, KnowQuality
Open in KnowellaRun it with agents
From a document you fill in to a programme that runs itself
The register is a table. What fails around it is the joins: the engagement that never created a row, the expiry nobody watched, the suspension that reached one row of three, and the pick list filtering on a state that does not exist.
Holds prequalification, insurance, induction and permit records against the register row, and blocks site access where the evidence behind the row has lapsed.
Feeds supplier audits, material rejections, scorecards and corrective requests back into the row so re-evaluation reflects performance rather than memory.

Watches approval expiry, duplicate entities and vendors active on site without a current state, and raises the review before the gate opens rather than after.
Tracks the obligations that attach to the relationship, indemnities, contract terms and labour standards due diligence, against the same entity the register keys on.
This template lives in General — control tower. The orchestration layer. Registries and engines every other workspace reads from.
Meet General→Glossary
Vendor and Contractor Register definitions and key terms
- Approved scope
- The work a vendor is permitted to perform for you, stated positively, and by implication the work they are not permitted to perform.
- Prequalification
- The assessment carried out before engagement, covering safety performance, systems, insurance, competence and financial standing, which supports but does not constitute approval.
- Risk tier
- A banding of vendors by the hazard of the work they do on your site, used to set induction depth, audit frequency and supervision level.
- Approval expiry
- The date on which approval ceases unless renewed, after which site access and selection in downstream records should be suspended automatically.
- Host employer
- The employer whose workplace another employer's workers enter, carrying duties for hazards it creates or controls regardless of who employs the person exposed.
- Prime contractor
- The party designated on a multi-employer workplace as responsible for co-ordinating health and safety across all employers present, a statutory role in most Canadian provinces.
- Outsourced process
- A function performed by an external provider that would otherwise be part of your own management system, which remains within your scope and must be controlled.
- Master data
- Reference data referred to by many records rather than created per event, where a single change propagates and a single error propagates equally.
FAQ
Frequently asked questions about vendor and contractor register
Should a vendor row be created before or after prequalification?+
Before. Prequalification is about a specific organisation, so the organisation has to be identifiable while it is being assessed, and the questionnaire, the audit and the eventual decision all need something to attach to. Create the row in a state that does not permit work, and let approval be a change of state rather than an act of creation.
Do we need every supplier in here, including stationery and software?+
Every one you want to be able to reference, but not every one at the same depth. Tier drives the evidence: a low-tier office supplier needs a row, a contact and a scope, while a high-tier contractor entering a live process area needs prequalification, insurance, audits and induction hanging off the same row. The mistake is not breadth, it is applying high-tier evidence expectations uniformly and then abandoning the exercise.
Can we delete a vendor we no longer use?+
No. Move the row out of the approved population and set the expiry. Every finished record that referenced the vendor, permits, orders, inspections, incidents, points at that row, and deleting it turns each of those into an orphan at the exact moment somebody asks who did the work. Retention of the row is part of retention of the record.
Who should be allowed to set a vendor to approved?+
Not the person who wants to use them. Approval is a risk judgement, so the authority belongs with the function that owns the exposure, quality for materials, safety for site work, and the register should restrict the status field accordingly. Where procurement maintains the row, it maintains identity and contact data, not permission.
How do we handle a vendor approved at one site but not another?+
Keep one row per legal entity and express the difference in the scope, not by creating a second row. Site-level duplication is how suspensions get lost, as the case above shows. If site-specific approval genuinely differs, hold the site permissions in the approval record and let the register carry the entity-level state.
What is the right review interval for a register entry?+
The interval is a backstop; the triggers do the work. Re-evaluate on approval expiry, on a change of legal entity, ownership or insurer, after an incident, violation or failed audit, and when the scope of work changes. An annual sweep with no triggers guarantees the register is examined once a year and guarantees nothing in between.
Keep going
Related templates and programmes
Industries this is written for
Programmes this belongs to
Supplier Quality Assurance
Approved suppliers with evidence, and rejections that actually change behaviour.
Contractor Onboarding and Management
Nobody through the gate without evidence, and performance that feeds the next award.
Master Data and Foundations
One place for each thing, so a change updates everywhere rather than in eight lists.
Inbound and Receiving
Problems refused at the dock rather than found in a finished pallet.
Contracts and Purchasing
Nothing renewing by default, and no supplier trading before onboarding completes.
Supplier Onboarding and Lifecycle
No supplier trading before onboarding completes, and none left active after it ends.
Used together in Supplier Quality Assurance
Modern Slavery and Labour Standards Assessment
Assesses the site and its labour supply chain for forced labour, debt bondage, withheld documents and unlawful deductions
Transport Provider Assessment
Assesses a haulier for licensing, driver management, vehicle standards, temperature capability and load security
Supplier Environmental Assessment
Assesses a supplier's environmental performance and certifications
Material Rejection Report
Rejects incoming material that fails inspection
Supplier Approval Record
Records the decision to approve a new supplier, with the evidence behind it
Supplier Questionnaire
Collects information about a supplier's systems, certifications and controls
More in Registries
Site and Location Register
Holds every site, building, area and zone your organisation operates
Asset Register
Holds every piece of equipment, machine, vehicle and tool you track
Worker Profile
Holds a record for each worker, including role, department, site and start date
Job and Task Register
Lists the jobs and tasks people perform, so risk assessments and ergonomic assessments can be tied to real work rather than job titles
Chemical and Substance Register
Lists every chemical and hazardous substance held on site, with quantity, location and hazard class
Course Catalog
Lists every training course available, with its length, validity period and who needs it

Written and reviewed by
Siddarth Singh
Founder & Chief Executive Officer, Knowella
Certified Safety Professional and industrial and systems engineer with more than a decade inside food supply chain, freight and manufacturing operations. This page was written against the current text of the standards it cites, not against secondary summaries of them.
- Certified Safety Professional (CSP), Board of Certified Safety Professionals
- MBA, University of Chicago Booth School of Business
- MS and BS, The Ohio State University, Industrial and Systems Engineering
- Six Sigma Black Belt
Sources and last review. Reviewed 16 August 2026 against:
- ISO 45001:2018 clause 8.1.4, procurement, contractors and outsourcing
- ISO 9001:2015 clause 8.4, control of externally provided processes, products and services
- 29 CFR 1910.119(h), contractors in process safety management
- 21 CFR 117 subpart G, supply-chain program, including 117.420 approval of suppliers
- Construction (Design and Management) Regulations 2015, regulation 8 (GB)
- Management of Health and Safety at Work Regulations 1999, regulation 11 (GB)
- Model WHS Act sections 19 and 46, and the code of practice on work health and safety consultation, co-operation and co-ordination (Australia)
This page is general guidance, not legal advice. Confirm requirements with your jurisdiction’s regulator.